Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2024-0390

Published Oct 8, 2024·Last modified Oct 8, 2024
Description
Feiten

Siemens heeft kwetsbaarheden verholpen in diverse producten als Questa/ModelSIM, RUGGEDCOM, SENTRON, SIMATIC, SINEC, Tecnomatix en Teamcenter.

Interpretaties

De kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:

  • Denial-of-Service (DoS)
  • Manipulatie van gegevens
  • Omzeilen van een beveiligingsmaatregel
  • Omzeilen van authenticatie
  • (Remote) code execution (Administrator/Root rechten)
  • (Remote) code execution (Gebruikersrechten)
  • Toegang tot systeemgegevens
  • Verhoogde gebruikersrechten

De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.

Oplossingen

Siemens heeft beveiligingsupdates uitgebracht om de kwetsbaarheden te verhelpen. Voor de kwetsbaarheden waar nog geen updates voor zijn, heeft Siemens mitigerende maatregelen gepubliceerd om de risico's zoveel als mogelijk te beperken. Zie de bijgevoegde referenties voor meer informatie.

Kans

medium

Schade

high

CWE-754

Improper Check for Unusual or Exceptional Conditions

CWE-312

Cleartext Storage of Sensitive Information

CWE-476

NULL Pointer Dereference

CWE-863

Incorrect Authorization

CWE-121

Stack-based Buffer Overflow

CWE-183

Permissive List of Allowed Inputs

CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

CWE-427

Uncontrolled Search Path Element

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

CWE-288

Authentication Bypass Using an Alternate Path or Channel

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-125

Out-of-bounds Read

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-787

Out-of-bounds Write

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard