PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-3313 Subnet Solutions Inc. CVE debrief

SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Server 2021 and Substation Server 2021. The vulnerabilities affect versions 4.07.00 and earlier of both products. The CVSS 3.1 vector indicates local attack vector with low attack complexity, no privileges required, and no user interaction needed, resulting in high impacts to confidentiality, integrity, and availability. The vendor has addressed these issues by identifying and replacing out-of-date libraries in affected versions.

Vendor
Subnet Solutions Inc.
Product
PowerSYSTEM Server
CVSS
HIGH 8.4
CISA KEV
Not listed in stored evidence
Original CVE published
2024-04-09
Original CVE updated
2024-04-09
Advisory published
2024-04-09
Advisory updated
2024-04-09

Who should care

Organizations operating SUBNET PowerSYSTEM Server or Substation Server 2021 in electrical utility substations or control center environments. Security teams responsible for OT/ICS asset management and patch coordination. Compliance officers tracking CISA ICS advisories for critical infrastructure protection.

Technical summary

The vulnerabilities reside in third-party libraries bundled with PowerSYSTEM Server 2021 and Substation Server 2021 versions 4.07.00 and earlier. The CVSS 3.1 score of 8.4 (HIGH) reflects a local attack vector with low complexity that can result in complete compromise of confidentiality, integrity, and availability without requiring privileges or user interaction. The attack surface is limited to local access, but the impact is severe. SUBNET Solutions has remediated by replacing outdated libraries in version 4.09.00.927.

Defensive priority

HIGH

Recommended defensive actions

  • Update PowerSYSTEM Server and Substation Server 2021 to version 4.09.00.927 or newer by contacting SUBNET Solutions Customer Service
  • Review and apply CISA ICS recommended practices for industrial control systems defense in depth
  • Verify no unauthorized local access exists on systems running affected versions
  • Monitor for vendor security advisories from SUBNET Solutions for future updates

Evidence notes

Evidence drawn from CISA CSAF advisory ICSA-24-100-01, which identifies affected product versions and remediation guidance. The advisory specifies that vulnerabilities exist in third-party components bundled with PowerSYSTEM Server and Substation Server 2021.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-3313 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-3313

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-3313 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-3313

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-100-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-100-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.