PT-2025-32646 · Siemens · Sirius Safety Es+10
Published
2025-08-12
·
Updated
2025-08-17
·
CVE-2024-54678
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
SIMATIC PCS neo versions 4.1 through 6.0
SIMATIC S7-PLCSIM version 17
SIMATIC STEP 7 versions 17 through 20
SIMATIC WinCC versions 17 through 20
SIMOCODE ES versions 17 through 20
SIMOTION SCOUT TIA versions 5.4 through 5.7
SINAMICS Startdrive versions 17 through 20
SIRIUS Safety ES versions 17 through 20 (TIA Portal)
SIRIUS Soft Starter ES versions 17 through 20 (TIA Portal)
TIA Portal Cloud versions 17 through 20
TIA Portal Test Suite version 20
SIMATIC STEP 7 versions prior to 19 Update 4
SIMOTION SCOUT TIA versions prior to 5.6 SP1 HF7
TIA Portal Cloud versions prior to 5.2.1.1
Description:
Affected products do not properly sanitize Interprocess Communication input received through a Windows Named Pipe accessible to all local users. This could allow an authenticated local attacker to cause a type confusion and execute arbitrary code within the affected application.
Recommendations:
SIMATIC PCS neo versions 4.1 through 6.0: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SIMATIC S7-PLCSIM version 17: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SIMATIC STEP 7 versions 17 through 20: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SIMATIC WinCC versions 17 through 20: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SIMOCODE ES versions 17 through 20: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SIMOTION SCOUT TIA versions 5.4 through 5.7: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SINAMICS Startdrive versions 17 through 20: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SIRIUS Safety ES versions 17 through 20 (TIA Portal): At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SIRIUS Soft Starter ES versions 17 through 20 (TIA Portal): At the moment, there is no information about a newer version that contains a fix for this vulnerability.
TIA Portal Cloud versions 17 through 20: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
TIA Portal Test Suite version 20: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SIMATIC STEP 7 versions prior to 19 Update 4: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SIMOTION SCOUT TIA versions prior to 5.6 SP1 HF7: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
TIA Portal Cloud versions prior to 5.2.1.1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic Pcs Neo
Simatic S7-Plcsim
Simatic Step 7
Simatic Wincc
Simocode Es
Simotion Scout Tia
Sinamics Startdrive
Sirius Safety Es
Sirius Soft Starter Es
Tia Portal Cloud
Tia Portal Test Suite