PatchSiren cyber security CVE debrief
CVE-2024-47942 Siemens CVE debrief
A DLL hijacking vulnerability in Siemens Solid Edge SE2024 allows local attackers to execute arbitrary code by placing a crafted DLL file on the system. The vulnerability was disclosed on November 12, 2024, with a CVSS 3.1 score of 7.3 (HIGH). The attack requires local access, low privileges, and user interaction, but successful exploitation grants high impact across confidentiality, integrity, and availability. Siemens has released V224.0 Update 9 to address this issue.
- Vendor
- Siemens
- Product
- Solid Edge SE2024
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-11-12
- Original CVE updated
- 2024-11-12
- Advisory published
- 2024-11-12
- Advisory updated
- 2024-11-12
Who should care
Organizations using Siemens Solid Edge SE2024 for CAD/CAM operations, particularly in industrial and manufacturing environments where the software interfaces with production systems. Security teams responsible for endpoint protection in engineering workstations should prioritize this patch due to the high impact potential of successful exploitation.
Technical summary
The affected Solid Edge SE2024 application loads dynamic-link libraries (DLLs) without adequately verifying their origin or integrity. An attacker with local access and low privileges can place a malicious DLL in a location where the application will load it, resulting in arbitrary code execution within the application's security context. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H) reflects this local attack vector requiring user interaction but yielding complete system compromise potential.
Defensive priority
HIGH
Recommended defensive actions
- Apply Siemens Solid Edge V224.0 Update 9 or later to affected systems
- Restrict write permissions to application directories to prevent DLL placement
- Implement application whitelisting to control executable and library loading
- Monitor for unauthorized DLL files in Solid Edge installation directories
- Review and apply CISA ICS recommended practices for defense-in-depth strategies
Evidence notes
CVE published and modified 2024-11-12 per CISA CSAF advisory ICSA-24-319-05. Vendor fix confirmed by Siemens security advisory SSA-351178. CVSS vector AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H indicates local attack vector with high impact potential.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-47942 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-47942
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-47942 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-47942
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-319-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-351178.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-351178.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-05
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.