PatchSiren cyber security CVE debrief
CVE-2024-9143 Siemens CVE debrief
CVE-2024-9143 is a medium-severity memory-corruption issue in Siemens SIDIS Prime that can arise when low-level GF(2m) elliptic-curve APIs are fed untrusted explicit field-polynomial values. The advisory says the practical exposure is low in typical ECC deployments, but affected applications using exotic binary curve encodings could still face crashes and, in some cases, possible remote code execution. Siemens published the advisory on 2025-04-08 and later revised it on 2025-05-06 for typo fixes.
- Vendor
- Siemens
- Product
- SIDIS Prime
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-12-12
- Original CVE updated
- 2025-08-12
- Advisory published
- 2023-12-12
- Advisory updated
- 2025-08-12
Who should care
Siemens SIDIS Prime operators, integrators, and developers who handle explicit binary GF(2m) elliptic-curve parameters. Most environments that rely on named curves or X9.62/X.509 certificate encodings are not expected to be exposed.
Technical summary
The advisory describes out-of-bounds reads and writes triggered by low-level GF(2m) elliptic-curve APIs when they receive untrusted explicit values for the field polynomial. The affected APIs include EC_GROUP_new_curve_GF2m(), EC_GROUP_new_from_params(), and supporting BN_GF2m_*() functions. The source notes that applications using exotic explicit binary curve parameters may be able to represent invalid field polynomials with a zero constant term, which can cause memory access outside array bounds. Impact can include application termination and, less likely, remote code execution. The advisory also states that common ECC use cases are generally not exposed because named curves and X9.62 encodings used in X.509 certificates cannot represent the problematic inputs, and that FIPS modules in versions 3.3, 3.2, 3.1, and 3.0 are not affected.
Defensive priority
Medium
Recommended defensive actions
- Update Siemens SIDIS Prime to V4.0.700 or later.
- Inventory any code paths that accept explicit binary GF(2m) curve parameters from untrusted sources.
- Prefer named curves or X9.62-encoded inputs and reject exotic encodings that could represent invalid field polynomials.
- Review custom certificate, key import, or parameter-parsing logic for use of the affected GF(2m) APIs.
- Treat crashes during ECC parameter handling as security-relevant until patched.
Evidence notes
Source evidence is from Siemens/CISA advisory ICSA-25-100-02 for Siemens SIDIS Prime, published 2025-04-08 and revised 2025-05-06. The advisory explicitly says the issue is low-likelihood in standard ECC deployments, especially for named curves and X.509/X9.62 processing, and identifies only exotic explicit binary curve encodings as potentially problematic. It also lists the remediation as V4.0.700 or later and notes that FIPS modules 3.3/3.2/3.1/3.0 are not affected.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-9143 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-9143
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-9143 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-9143
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-100-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-277137.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-277137.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-100-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.