PatchSiren cyber security CVE debrief
CVE-2024-47783 Siemens CVE debrief
CVE-2024-47783 is a high-severity local privilege escalation vulnerability in Siemens SIPORT, an industrial control system access management solution. Published on November 12, 2024, and last modified on May 6, 2025, this vulnerability stems from improper file permission assignments on installation folders. The flaw allows a local attacker with an unprivileged account to modify or override service executables, subsequently gaining elevated privileges on the affected system. The vulnerability carries a CVSS 3.1 score of 7.8 (HIGH), with the attack vector being local, requiring low attack complexity and low privileges, with no user interaction needed. The impact is severe across confidentiality, integrity, and availability dimensions. Siemens has addressed this issue in SIPORT version 3.4.0 and later. CISA published advisory ICSA-24-319-02 to coordinate disclosure and mitigation guidance for critical infrastructure operators.
- Vendor
- Siemens
- Product
- SIPORT
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-11-12
- Original CVE updated
- 2025-05-06
- Advisory published
- 2024-11-12
- Advisory updated
- 2025-05-06
Who should care
Organizations operating Siemens SIPORT access control systems in industrial, commercial, or critical infrastructure environments. Security teams responsible for OT/ICS security, system administrators managing SIPORT deployments, and compliance officers overseeing physical access control system security should prioritize this vulnerability. The local attack vector is particularly relevant in multi-user environments or where insider threats are a concern. Organizations subject to NERC CIP, IEC 62443, or similar industrial security standards should address this as part of secure configuration management requirements.
Technical summary
The vulnerability exists due to improper access control configuration during SIPORT installation, where installation folders are assigned permissions that allow non-administrative users to write to directories containing service executables. A local attacker with an unprivileged account can exploit this by replacing or modifying legitimate service binaries with malicious versions. When the service executes (potentially at system startup or during restart), the attacker's code runs with elevated privileges, achieving privilege escalation from standard user to SYSTEM or equivalent administrative context. The attack requires local access to the system but no user interaction, making it exploitable by any authenticated user with interactive logon rights.
Defensive priority
HIGH
Recommended defensive actions
- Apply vendor fix: Update SIPORT to version 3.4.0 or later
- Apply interim mitigation: Remove write permissions for non-administrative users on files and folders under the SIPORT installation path
- Review and audit file system permissions on all SIPORT installations
- Monitor for unauthorized modifications to service executables in SIPORT installation directories
- Implement principle of least privilege for all accounts with access to SIPORT systems
- Follow CISA ICS recommended practices for defense-in-depth strategies
- Review Siemens ProductCERT security advisory SSA-064257 for additional technical details
Evidence notes
Vulnerability confirmed through Siemens ProductCERT security advisory SSA-064257 and CISA ICS advisory ICSA-24-319-02. The issue was identified in the CSAF product tree with high confidence attribution to Siemens SIPORT.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-47783 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-47783
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-47783 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-47783
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-319-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-064257.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-064257.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.