PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-52571 Siemens CVE debrief

CVE-2024-52571 is a high-severity out-of-bounds write vulnerability in Siemens Teamcenter Visualization affecting versions V14.2, V14.3, V2312, and V2406. The flaw exists in the parsing of specially crafted WRL (VRML) files and can lead to arbitrary code execution in the context of the current process. The vulnerability was disclosed via CISA ICS Advisory ICSA-24-347-09 on December 10, 2024, with Siemens publishing coordinated security advisory SSA-645131. The issue was originally reported through the Zero Day Initiative (ZDI-CAN-24485). Siemens has released patched versions for all affected product lines, and CISA recommends updating to these fixed versions as the primary remediation. As a defense-in-depth measure, users should avoid opening untrusted WRL files in affected applications. No known exploitation in the wild has been reported, and this vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.

Vendor
Siemens
Product
Teamcenter Visualization V14.2
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-12-10
Original CVE updated
2025-05-06
Advisory published
2024-12-10
Advisory updated
2025-05-06

Who should care

Organizations using Siemens Teamcenter Visualization for CAD data visualization and collaboration, particularly in industrial and manufacturing environments. Security teams responsible for OT/ICS asset protection and patch management should prioritize this update due to the high impact potential and availability of proven fixes.

Technical summary

The vulnerability is an out-of-bounds write occurring during parsing of malformed WRL (VRML) files in Teamcenter Visualization. The affected versions are V14.2, V14.3, V2312, and V2406. Successful exploitation allows arbitrary code execution with the privileges of the current process. Attack vector is local, requiring user interaction to open a malicious file. CVSS 3.1 score: 7.8 (High).

Defensive priority

high

Recommended defensive actions

  • Update Teamcenter Visualization to the vendor-fixed version for your product line: V14.2.0.14 or later for V14.2, V14.3.0.12 or later for V14.3, V2312.0008 or later for V2312, or V2406.0005 or later for V2406
  • Implement application whitelisting and restrict execution of Teamcenter Visualization to authorized users only
  • Train users to avoid opening WRL files from untrusted sources and implement email filtering to block suspicious attachments
  • Apply defense-in-depth strategies for industrial control systems environments per CISA guidance
  • Monitor for anomalous process behavior or unexpected file parsing operations in Teamcenter Visualization deployments

Evidence notes

Vulnerability disclosed via CISA ICS Advisory ICSA-24-347-09 on December 10, 2024. Siemens security advisory SSA-645131 provides vendor fix information. Original discovery attributed to ZDI-CAN-24485. Advisory revised May 6, 2025 for typo corrections only.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-52571 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-52571

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-52571 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-52571

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-347-09.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-645131.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-645131.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-347-09

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.