PT-2025-32646 · Siemens · Sirius Safety Es+10

Published

2025-08-12

·

Updated

2025-08-17

·

CVE-2024-54678

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SIMATIC PCS neo versions 4.1 through 6.0 SIMATIC S7-PLCSIM version 17 SIMATIC STEP 7 versions 17 through 20 SIMATIC WinCC versions 17 through 20 SIMOCODE ES versions 17 through 20 SIMOTION SCOUT TIA versions 5.4 through 5.7 SINAMICS Startdrive versions 17 through 20 SIRIUS Safety ES versions 17 through 20 (TIA Portal) SIRIUS Soft Starter ES versions 17 through 20 (TIA Portal) TIA Portal Cloud versions 17 through 20 TIA Portal Test Suite version 20 SIMATIC STEP 7 versions prior to 19 Update 4 SIMOTION SCOUT TIA versions prior to 5.6 SP1 HF7 TIA Portal Cloud versions prior to 5.2.1.1
Description: Affected products do not properly sanitize Interprocess Communication input received through a Windows Named Pipe accessible to all local users. This could allow an authenticated local attacker to cause a type confusion and execute arbitrary code within the affected application.
Recommendations: SIMATIC PCS neo versions 4.1 through 6.0: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SIMATIC S7-PLCSIM version 17: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SIMATIC STEP 7 versions 17 through 20: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SIMATIC WinCC versions 17 through 20: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SIMOCODE ES versions 17 through 20: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SIMOTION SCOUT TIA versions 5.4 through 5.7: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SINAMICS Startdrive versions 17 through 20: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SIRIUS Safety ES versions 17 through 20 (TIA Portal): At the moment, there is no information about a newer version that contains a fix for this vulnerability. SIRIUS Soft Starter ES versions 17 through 20 (TIA Portal): At the moment, there is no information about a newer version that contains a fix for this vulnerability. TIA Portal Cloud versions 17 through 20: At the moment, there is no information about a newer version that contains a fix for this vulnerability. TIA Portal Test Suite version 20: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SIMATIC STEP 7 versions prior to 19 Update 4: At the moment, there is no information about a newer version that contains a fix for this vulnerability. SIMOTION SCOUT TIA versions prior to 5.6 SP1 HF7: At the moment, there is no information about a newer version that contains a fix for this vulnerability. TIA Portal Cloud versions prior to 5.2.1.1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2025-10826
CVE-2024-54678

Affected Products

Simatic Pcs Neo
Simatic S7-Plcsim
Simatic Step 7
Simatic Wincc
Simocode Es
Simotion Scout Tia
Sinamics Startdrive
Sirius Safety Es
Sirius Soft Starter Es
Tia Portal Cloud
Tia Portal Test Suite