PatchSiren cyber security CVE debrief
CVE-2024-58071 Siemens CVE debrief
CVE-2024-58071 is a medium-severity vulnerability (CVSS 5.5) affecting the Siemens SIMATIC S7-1500 TM MFP GNU/Linux subsystem. The issue, described as preventing the addition of a device that is already a team device at a lower level, was published on April 9, 2024, and last modified on May 14, 2026. The vulnerability has a local attack vector with low attack complexity, requiring low privileges but no user interaction, and can result in high availability impact. No fix is currently available from the vendor.
- Vendor
- Siemens
- Product
- SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-04-09
- Original CVE updated
- 2026-05-14
- Advisory published
- 2024-04-09
- Advisory updated
- 2026-05-14
Who should care
Organizations operating Siemens SIMATIC S7-1500 TM MFP controllers in industrial environments, particularly those utilizing the GNU/Linux subsystem for custom applications. OT security teams, plant engineers, and asset owners in manufacturing, process control, and critical infrastructure sectors should prioritize access controls and application integrity measures until a vendor fix becomes available.
Technical summary
The vulnerability exists in the GNU/Linux subsystem of the Siemens SIMATIC S7-1500 TM MFP industrial controller. The issue relates to improper handling of team device configurations where a device already configured as a team device at a lower level could be improperly added, potentially causing system instability or denial of service. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) indicates a local attack with low complexity and privileges, resulting in high availability impact but no confidentiality or integrity impact.
Defensive priority
medium
Recommended defensive actions
- Limit access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only
- Only build and run applications from trusted sources
- Monitor for vendor security updates from Siemens CERT
- Apply defense-in-depth strategies for industrial control systems per CISA guidance
Evidence notes
CVE description and CVSS vector derived from CISA CSAF advisory ICSA-24-102-01. Vendor confirmed as Siemens with high confidence via CSAF product tree. No KEV listing or known ransomware campaign use identified.
Official resources
-
CVE-2024-58071 CVE record
CVE.org
-
CVE-2024-58071 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2024-04-09