CERT-In Advisory
CIAD-2024-0028
Multiple Vulnerabilities in Siemens Products
Original Issue Date: May 24, 2024
Severity Rating: High
Systems Affected
- Parasolid
- SIMATIC RTLS
- Simcenter Nastran
- SIMATIC CN 4100
- RUGGEDCOM
- Solid Edge
- Teamcenter Visualization
- JT2Go
- CPC80
- CPCI85
- OPUPI0 AMQP/MQTT
- SICORE
- Tecnomatix Plant Simulation
- Cerberus PRO
- Desigo Fire Safety UL
- PS/IGES Parasolid Translator Component
Overview
Multiple vulnerabilities have been reported in Siemens Products which could allow an attacker to execute arbitrary code, escalate privileges or perform denial of service (DoS) conditions on the targeted system.
Description
Multiple vulnerabilities have been reported in Siemens products, details of which are provided below:

Solution
Apply appropriate fixes/workarounds as mentioned in Siemens Security Advisory:
https://cert-portal.siemens.com/productcert/html/ssa-046364.html
https://cert-portal.siemens.com/productcert/html/ssa-093430.html
https://cert-portal.siemens.com/productcert/html/ssa-258494.html
https://cert-portal.siemens.com/productcert/html/ssa-273900.html
https://cert-portal.siemens.com/productcert/html/ssa-292022.html
https://cert-portal.siemens.com/productcert/html/ssa-489698.html
https://cert-portal.siemens.com/productcert/html/ssa-589937.html
https://cert-portal.siemens.com/productcert/html/ssa-661579.html
https://cert-portal.siemens.com/productcert/html/ssa-871704.html
https://cert-portal.siemens.com/productcert/html/ssa-916916.html
https://cert-portal.siemens.com/productcert/html/ssa-923361.html
https://cert-portal.siemens.com/productcert/html/ssa-953710.html
https://cert-portal.siemens.com/productcert/html/ssa-976324.html
Vendor Information
Siemens
https://cert-portal.siemens.com/productcert/html/ssa-046364.html
https://cert-portal.siemens.com/productcert/html/ssa-093430.html
https://cert-portal.siemens.com/productcert/html/ssa-258494.html
https://cert-portal.siemens.com/productcert/html/ssa-273900.html
https://cert-portal.siemens.com/productcert/html/ssa-292022.html
https://cert-portal.siemens.com/productcert/html/ssa-489698.html
https://cert-portal.siemens.com/productcert/html/ssa-589937.html
https://cert-portal.siemens.com/productcert/html/ssa-661579.html
https://cert-portal.siemens.com/productcert/html/ssa-871704.html
https://cert-portal.siemens.com/productcert/html/ssa-916916.html
https://cert-portal.siemens.com/productcert/html/ssa-923361.html
https://cert-portal.siemens.com/productcert/html/ssa-953710.html
https://cert-portal.siemens.com/productcert/html/ssa-976324.html
References
Siemens
https://www.siemens.com/cert/advisories
CVE Name
CVE-2023-29409
CVE-2023-33953
CVE-2023-38039
CVE-2023-38545
CVE-2023-38546
CVE-2023-46218
CVE-2023-46219
CVE-2023-4807
CVE-2023-5363
CVE-2023-5678
CVE-2023-6916
CVE-2024-0218
CVE-2024-22039
CVE-2024-27940
CVE-2024-27941
CVE-2024-27942
CVE-2024-27943
CVE-2024-27944
CVE-2024-27945
CVE-2024-27946
CVE-2024-27947
CVE-2024-30206
CVE-2024-30207
CVE-2024-30208
CVE-2024-30209
CVE-2024-31484
CVE-2024-31485
CVE-2024-31486
CVE-2024-31980
CVE-2024-32055
CVE-2024-32057
CVE-2024-32058
CVE-2024-32059
CVE-2024-32060
CVE-2024-32061
CVE-2024-32062
CVE-2024-32063
CVE-2024-32064
CVE-2024-32065
CVE-2024-32066
CVE-2024-32635
CVE-2024-32636
CVE-2024-32637
CVE-2024-32639
CVE-2024-32740
CVE-2024-32741
CVE-2024-32742
CVE-2024-33489
CVE-2024-33490
CVE-2024-33491
CVE-2024-33492
CVE-2024-33493
CVE-2024-33494
CVE-2024-33495
CVE-2024-33496
CVE-2024-33497
CVE-2024-33498
CVE-2024-33499
CVE-2024-33577
CVE-2024-33583
CVE-2024-34085
CVE-2024-34086
CVE-2024-34771
CVE-2024-34772
CVE-2024-34773
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|