CVE-2024-33698

CRITICAL

Opcenter Quality <V2406, Opcenter RDnL <V2410, SIMATIC PCS neo V4.0...

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SINEC NMS (All versions), SINEMA Remote Connect Client (All versions < V3.2 SP3), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 8), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 5), Totally Integrated Automation Portal (TIA Portal) V19 (All versions < V19 Update 3). Affected products contain a heap-based buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to execute arbitrary code.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0329
EPSS Percentile 87.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-122
Status published
Products (11)
Siemens/Opcenter Quality < V2406
Siemens/Opcenter RDnL < V2410
Siemens/SIMATIC PCS neo V4.0
Siemens/SIMATIC PCS neo V4.1 < V4.1 Update 2
Siemens/SIMATIC PCS neo V5.0 < V5.0 Update 1
Siemens/SINEC NMS
Siemens/SINEMA Remote Connect Client < V3.2 SP3
Siemens/Totally Integrated Automation Portal (TIA Portal) V16
Siemens/Totally Integrated Automation Portal (TIA Portal) V17 < V17 Update 8
Siemens/Totally Integrated Automation Portal (TIA Portal) V18 < V18 Update 5
... and 1 more
Published Sep 10, 2024
Tracked Since Feb 18, 2026