CVE-2024-31484

HIGH

CPC80 Central Processing/Communication <V16.41 - Buffer Overflow

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in CPC80 Central Processing/Communication (All versions < V16.41), CPCI85 Central Processing/Communication (All versions < V5.30), CPCX26 Central Processing/Communication (All versions < V06.02), ETA4 Ethernet Interface IEC60870-5-104 (All versions < V10.46), ETA5 Ethernet Int. 1x100TX IEC61850 Ed.2 (All versions < V03.27), PCCX26 Ax 1703 PE, Contr, Communication Element (All versions < V06.05). The affected devices contain an improper null termination vulnerability while parsing a specific HTTP header. This could allow an attacker to execute code in the context of the current process or lead to denial of service condition.

Scores

CVSS v3 7.8
EPSS 0.0006
EPSS Percentile 19.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-170
Status published
Products (6)
Siemens/CPC80 Central Processing/Communication < V16.41
Siemens/CPCI85 Central Processing/Communication < V5.30
Siemens/CPCX26 Central Processing/Communication < V06.02
Siemens/ETA4 Ethernet Interface IEC60870-5-104 < V10.46
Siemens/ETA5 Ethernet Int. 1x100TX IEC61850 Ed.2 < V03.27
Siemens/PCCX26 Ax 1703 PE, Contr, Communication Element < V06.05
Published May 14, 2024
Tracked Since Feb 18, 2026