PatchSiren cyber security CVE debrief
CVE-2024-47808 Siemens CVE debrief
CVE-2024-47808 is a high-severity vulnerability in Siemens SINEC NMS, published on November 12, 2024. The affected application contains a database function that fails to properly restrict user permissions for writing to the host filesystem. An authenticated attacker with medium privileges can exploit this flaw to write arbitrary content to any location on the host filesystem, potentially leading to complete system compromise. The vulnerability carries a CVSS 3.1 score of 8.4 (HIGH severity) with the vector AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H, indicating local attack vector, low attack complexity, low privileges required, no user interaction, changed scope, and high impact to integrity and availability. Siemens has released a vendor fix: users should update to SINEC NMS V3.0 SP1 or later. CISA has coordinated disclosure through advisory ICSA-24-319-04.
- Vendor
- Siemens
- Product
- SINEC NMS
- CVSS
- HIGH 8.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-11-12
- Original CVE updated
- 2024-11-12
- Advisory published
- 2024-11-12
- Advisory updated
- 2024-11-12
Who should care
Organizations operating Siemens SINEC NMS for industrial network management, particularly in critical infrastructure environments. Security teams responsible for OT/ICS asset protection, database administrators managing SINEC NMS deployments, and compliance officers tracking industrial cybersecurity standards should prioritize this vulnerability for remediation.
Technical summary
The vulnerability exists in a database function within SINEC NMS that lacks proper permission restrictions for filesystem write operations. Authenticated users with medium privileges can leverage this function to write arbitrary content to any path on the host filesystem. This represents a significant security boundary violation in an industrial network management system, as filesystem write capabilities can enable further compromise including configuration tampering, malware deployment, or denial of service. The attack requires local access or existing authenticated session, with low complexity for exploitation.
Defensive priority
high
Recommended defensive actions
- Update Siemens SINEC NMS to V3.0 SP1 or later version as specified in vendor security advisory
- Review and restrict database user permissions to enforce principle of least privilege
- Monitor filesystem write operations for unauthorized or anomalous activity
- Apply network segmentation to limit access to SINEC NMS management interfaces
- Follow CISA ICS recommended practices for defense-in-depth strategies
Evidence notes
Vulnerability description and remediation guidance sourced from CISA CSAF advisory ICSA-24-319-04 and Siemens security advisory SSA-331112. CVSS vector and score confirmed in source metadata.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-47808 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-47808
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-47808 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-47808
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-319-04.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-331112.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-331112.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-04
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.