PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-47942 Siemens CVE debrief

A DLL hijacking vulnerability in Siemens Solid Edge SE2024 allows local attackers to execute arbitrary code by placing a crafted DLL file on the system. The vulnerability was disclosed on November 12, 2024, with a CVSS 3.1 score of 7.3 (HIGH). The attack requires local access, low privileges, and user interaction, but successful exploitation grants high impact across confidentiality, integrity, and availability. Siemens has released V224.0 Update 9 to address this issue.

Vendor
Siemens
Product
Solid Edge SE2024
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2024-11-12
Original CVE updated
2024-11-12
Advisory published
2024-11-12
Advisory updated
2024-11-12

Who should care

Organizations using Siemens Solid Edge SE2024 for CAD/CAM operations, particularly in industrial and manufacturing environments where the software interfaces with production systems. Security teams responsible for endpoint protection in engineering workstations should prioritize this patch due to the high impact potential of successful exploitation.

Technical summary

The affected Solid Edge SE2024 application loads dynamic-link libraries (DLLs) without adequately verifying their origin or integrity. An attacker with local access and low privileges can place a malicious DLL in a location where the application will load it, resulting in arbitrary code execution within the application's security context. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H) reflects this local attack vector requiring user interaction but yielding complete system compromise potential.

Defensive priority

HIGH

Recommended defensive actions

  • Apply Siemens Solid Edge V224.0 Update 9 or later to affected systems
  • Restrict write permissions to application directories to prevent DLL placement
  • Implement application whitelisting to control executable and library loading
  • Monitor for unauthorized DLL files in Solid Edge installation directories
  • Review and apply CISA ICS recommended practices for defense-in-depth strategies

Evidence notes

CVE published and modified 2024-11-12 per CISA CSAF advisory ICSA-24-319-05. Vendor fix confirmed by Siemens security advisory SSA-351178. CVSS vector AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H indicates local attack vector with high impact potential.

Official resources

2024-11-12