PatchSiren cyber security CVE debrief
CVE-2024-49704 Siemens CVE debrief
## Summary CVE-2024-49704 is a medium-severity XML External Entity (XXE) vulnerability affecting Siemens COMOS V10.3 and multiple V10.4.x versions. The flaw resides in the Generic Data Mapper, Engineering Adapter, and Engineering Interface components, which improperly handle XXE entries when parsing configuration and mapping files. An attacker could exploit this by persuading a user to open a maliciously crafted file, potentially extracting arbitrary files from the user's system or accessible network locations. ## Affected Products - COMOS V10.3 (patch available) - COMOS V10.4.0, V10.4.1, V10.4.2 (no fix planned) - COMOS V10.4.3 (patch available) - COMOS V10.4.4 (update to V10.4.4.2 or later) - COMOS V10.4.4.1 (update to V10.4.4.1.21 or later) ## Technical Details The vulnerability stems from improper XML parsing that allows external entity resolution. When a user opens a malicious configuration or mapping file in any of the three affected components, the XXE payload can trigger file disclosure from known paths on the local system or network shares. This represents a local attack vector requiring user interaction. ## Remediation Status Siemens has provided patches for most affected versions, though V10.4.0 through V10.4.2 have no planned fixes. Users on these versions should apply the documented mitigations. Patches for V10.3 and V10.4.3 are available upon request from Siemens customer support, while V10.4.4.x updates can be obtained through standard support channels. ## Recommended Actions 1. Apply vendor patches where available for supported versions 2. For versions without fixes, strictly control access to configuration and mapping files 3. Implement file integrity monitoring for critical configuration directories 4. Train users to avoid opening untrusted files from external sources 5. Apply principle of least privilege to file system and network share access
- Vendor
- Siemens
- Product
- COMOS V10.3
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-12-10
- Original CVE updated
- 2025-05-06
- Advisory published
- 2024-12-10
- Advisory updated
- 2025-05-06
Who should care
Organizations using Siemens COMOS for plant engineering and design, particularly those in critical infrastructure sectors. System administrators responsible for COMOS deployments and security teams managing industrial control system environments should prioritize patching and access control measures.
Technical summary
The Generic Data Mapper, Engineering Adapter, and Engineering Interface components in Siemens COMOS fail to properly disable XML external entity processing when parsing configuration and mapping files. This allows crafted XML documents to reference external entities that can read arbitrary files from the system or network shares accessible to the COMOS process. Exploitation requires convincing a user to open a malicious file in one of the affected components.
Defensive priority
medium
Recommended defensive actions
- Apply vendor-supplied patches for COMOS V10.3 (V10.3.3.5.8+), V10.4.3 (V10.4.3.0.47+), V10.4.4 (V10.4.4.2+), and V10.4.4.1 (V10.4.4.1.21+) through Siemens customer support
- For COMOS V10.4.0, V10.4.1, and V10.4.2 where no fix is planned, restrict file modification permissions to authorized administrators only
- Implement strict access controls preventing unauthorized users from modifying configuration and mapping files
- Establish user awareness training to prevent opening untrusted configuration or mapping files from external sources
- Apply defense-in-depth principles including network segmentation for systems running affected COMOS versions
- Monitor for anomalous file access patterns in COMOS configuration directories
Evidence notes
CVE published 2024-12-10 per CISA ICS advisory ICSA-24-347-08. Modified 2025-05-06 for typo corrections. CVSS 5.5 (MEDIUM) with local attack vector and user interaction required. No known exploitation in the wild. Not listed in CISA KEV catalog.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-49704 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-49704
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-49704 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-49704
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-347-08.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-701627.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-701627.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-347-08
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.