Insufficient Session Expiration in Siemens products - CVE-2024-45386
Published: March 7, 2025
Vulnerability identifier: #VU105437
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-45386
CWE-ID: CWE-613
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient session expiration issue. A remote non-authenticated attacker can obtain or guess session token and gain unauthorized access to session that belongs to another user.
Affected software
SIMATIC PCS neo
TIA Administrator (TIA Portal)
SIMOCODE ES
Totally Integrated Automation Portal (TIA Portal)
SIRIUS Safety ES
SIRIUS Soft Starter ES
TIA Administrator (TIA Portal)
SIMOCODE ES
Totally Integrated Automation Portal (TIA Portal)
SIRIUS Safety ES
SIRIUS Soft Starter ES
How to mitigate CVE-2024-45386
Install updates from vendor's website.
SIMATIC PCS neo - addressed in versions 4.1 Update 2, 5.0 Update 1
TIA Administrator (TIA Portal) - update to 3.0.4
Totally Integrated Automation Portal (TIA Portal) - update to 19 Update 1
SIMOCODE ES - update to 19 Update 1
SIRIUS Safety ES - update to 19 Update 1
SIRIUS Soft Starter ES - update to 19 Update 1
TIA Administrator (TIA Portal) - update to 3.0.4
Totally Integrated Automation Portal (TIA Portal) - update to 19 Update 1
SIMOCODE ES - update to 19 Update 1
SIRIUS Safety ES - update to 19 Update 1
SIRIUS Soft Starter ES - update to 19 Update 1