PatchSiren cyber security CVE debrief
CVE-2024-50310 Siemens CVE debrief
A high-severity authorization bypass vulnerability in Siemens SIMATIC CP 1543-1 V4.0 industrial communication processors allows unauthenticated remote attackers to access the device filesystem. Published November 12, 2024, this flaw stems from improper authorization handling on TCP port 8448. The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with network attack vector, low complexity, and no privileges required. Siemens has released firmware version V4.0.50 or later to address the issue. CISA and Siemens recommend immediate network segmentation restricting port 8448/tcp to trusted systems as an interim mitigation.
- Vendor
- Siemens
- Product
- SIMATIC CP 1543-1 V4.0 (6GK7543-1AX10-0XE0)
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-11-12
- Original CVE updated
- 2025-05-06
- Advisory published
- 2024-11-12
- Advisory updated
- 2025-05-06
Who should care
Industrial control system operators, OT security teams, manufacturing security engineers, critical infrastructure defenders, and asset owners using Siemens SIMATIC CP 1543-1 V4.0 in production environments
Technical summary
The vulnerability exists in the authorization handling mechanism of Siemens SIMATIC CP 1543-1 V4.0 communication processors (part number 6GK7543-1AX10-0XE0). An unauthenticated remote attacker can exploit improper authorization checks on TCP port 8448 to gain unauthorized filesystem access. The attack requires network connectivity to the device but no authentication credentials or user interaction. Successful exploitation exposes sensitive configuration files and potentially enables further lateral movement within industrial networks. The CVSS 3.1 vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C confirms network exploitability with high confidentiality impact. Siemens addressed this in firmware V4.0.50; interim mitigation requires network-layer access controls on port 8448/tcp.
Defensive priority
HIGH
Recommended defensive actions
- Apply Siemens firmware update V4.0.50 or later to affected SIMATIC CP 1543-1 V4.0 devices
- Restrict network access to TCP port 8448 to trusted administrative hosts only
- Segment affected devices from untrusted networks using industrial firewall rules
- Monitor for unauthorized access attempts on port 8448/tcp
- Review device filesystem access logs for indicators of compromise prior to patching
Evidence notes
CVE published 2024-11-12; CISA CSAF advisory ICSA-24-319-11 issued same date; Siemens security advisory SSA-654798; firmware fix V4.0.50 available; advisory revised 2025-05-06 for typo corrections only.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-50310 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-50310
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-50310 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-50310
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-319-11.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-654798.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-654798.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-11
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.