CVE-2024-54678

Aug. 12, 2025, 2:25 p.m.

8.6
High

Description

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All versions < V19 Update 4), SIMATIC STEP 7 V20 (All versions), SIMATIC WinCC V17 (All versions), SIMATIC WinCC V18 (All versions), SIMATIC WinCC V19 (All versions < V19 Update 4), SIMATIC WinCC V20 (All versions), SIMOCODE ES V17 (All versions), SIMOCODE ES V18 (All versions), SIMOCODE ES V19 (All versions), SIMOCODE ES V20 (All versions), SIMOTION SCOUT TIA V5.4 (All versions), SIMOTION SCOUT TIA V5.5 (All versions), SIMOTION SCOUT TIA V5.6 (All versions < V5.6 SP1 HF7), SIMOTION SCOUT TIA V5.7 (All versions), SINAMICS Startdrive V17 (All versions), SINAMICS Startdrive V18 (All versions), SINAMICS Startdrive V19 (All versions), SINAMICS Startdrive V20 (All versions), SIRIUS Safety ES V17 (TIA Portal) (All versions), SIRIUS Safety ES V18 (TIA Portal) (All versions), SIRIUS Safety ES V19 (TIA Portal) (All versions), SIRIUS Safety ES V20 (TIA Portal) (All versions), SIRIUS Soft Starter ES V17 (TIA Portal) (All versions), SIRIUS Soft Starter ES V18 (TIA Portal) (All versions), SIRIUS Soft Starter ES V19 (TIA Portal) (All versions), SIRIUS Soft Starter ES V20 (TIA Portal) (All versions), TIA Portal Cloud V17 (All versions), TIA Portal Cloud V18 (All versions), TIA Portal Cloud V19 (All versions < V5.2.1.1), TIA Portal Cloud V20 (All versions), TIA Portal Test Suite V20 (All versions). Affected products do not properly sanitize Interprocess Communication input received through a Windows Named Pipe accessible to all local users. This could allow an authenticated local attacker to cause a type confusion and execute arbitrary code within the affected application.

Product(s) Impacted

Vendor Product Versions
Siemens
  • Simatic Pcs Neo
  • Simatic S7 Plcsim
  • Simatic Step 7
  • Simatic Wincc
  • Symocode Es
  • S-motion Scout Tia
  • Sinamics Startdrive
  • Sirius Safety Es
  • Sirius Soft Starter Es
  • Tia Portal Cloud
  • Tia Portal Test Suite
  • 4.1, 5.0, 6.0
  • 17
  • 17, 18, 19, 20
  • 17, 18, 19, 20
  • 17, 18, 19, 20
  • 5.4, 5.5, 5.6, 5.7
  • 17, 18, 19, 20
  • 17, 18, 19, 20
  • 17, 18, 19, 20
  • 17, 18, 19, 20
  • 20

Weaknesses

Common security weaknesses mapped to this vulnerability.

CWE-502
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

*CPE(s)

Affected systems and software identified for this CVE.

Type Vendor Product Version Update Edition Language Software Edition Target Software Target Hardware Other Information
a siemens simatic_pcs_neo 4.1 / / / / / / /
a siemens simatic_pcs_neo 5.0 / / / / / / /
a siemens simatic_pcs_neo 6.0 / / / / / / /
a siemens simatic_s7_plcsim 17 / / / / / / /
a siemens simatic_step_7 17 / / / / / / /
a siemens simatic_step_7 18 / / / / / / /
a siemens simatic_step_7 19 <19.0 / / / / / /
a siemens simatic_step_7 20 / / / / / / /
a siemens simatic_wincc 17 / / / / / / /
a siemens simatic_wincc 18 / / / / / / /
a siemens simatic_wincc 19 <19.0 / / / / / /
a siemens simatic_wincc 20 / / / / / / /
a siemens symocode_es 17 / / / / / / /
a siemens symocode_es 18 / / / / / / /
a siemens symocode_es 19 / / / / / / /
a siemens symocode_es 20 / / / / / / /
a siemens s-motion_scout_tia 5.4 / / / / / / /
a siemens s-motion_scout_tia 5.5 / / / / / / /
a siemens s-motion_scout_tia 5.6 <5.6.SP1.HF7 / / / / / /
a siemens s-motion_scout_tia 5.7 / / / / / / /
a siemens sinamics_startdrive 17 / / / / / / /
a siemens sinamics_startdrive 18 / / / / / / /
a siemens sinamics_startdrive 19 / / / / / / /
a siemens sinamics_startdrive 20 / / / / / / /
a siemens sirius_safety_es 17 / tia_portal / / / / /
a siemens sirius_safety_es 18 / tia_portal / / / / /
a siemens sirius_safety_es 19 / tia_portal / / / / /
a siemens sirius_safety_es 20 / tia_portal / / / / /
a siemens sirius_soft_starter_es 17 / tia_portal / / / / /
a siemens sirius_soft_starter_es 18 / tia_portal / / / / /
a siemens sirius_soft_starter_es 19 / tia_portal / / / / /
a siemens sirius_soft_starter_es 20 / tia_portal / / / / /
a siemens tia_portal_cloud 17 / / / / / / /
a siemens tia_portal_cloud 18 / / / / / / /
a siemens tia_portal_cloud 19 <5.2.1.1 / / / / / /
a siemens tia_portal_cloud 20 / / / / / / /
a siemens tia_portal_test_suite 20 / / / / / / /

CVSS Score

8.6 / 10

CVSS Data - 4.0

  • Attack Vector: LOCAL
  • Attack Complexity: LOW
  • Attack Requirements: NONE
  • Privileges Required: LOW
  • User Interaction: PASSIVE
  • Scope:
  • Confidentiality Impact: HIGH
  • Integrity Impact: HIGH
  • Availability Impact: HIGH
  • Exploit Maturity: NOT_DEFINED
  • CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

    View Vector String

Timeline

Published: Aug. 12, 2025, 12:15 p.m.
Last Modified: Aug. 12, 2025, 2:25 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

productcert@siemens.com

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.