Insufficient Session Expiration in Siemens products - CVE-2024-45386
Published: March 7, 2025
Vulnerability identifier: #VU105437
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2024-45386
CWE-ID: CWE-613
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Siemens
Affected software:
SIMATIC PCS neo
TIA Administrator (TIA Portal)
SIMOCODE ES
Totally Integrated Automation Portal (TIA Portal)
SIRIUS Safety ES
SIRIUS Soft Starter ES
SIMATIC PCS neo
TIA Administrator (TIA Portal)
SIMOCODE ES
Totally Integrated Automation Portal (TIA Portal)
SIRIUS Safety ES
SIRIUS Soft Starter ES
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient session expiration issue. A remote non-authenticated attacker can obtain or guess session token and gain unauthorized access to session that belongs to another user.
How to mitigate CVE-2024-45386
Install updates from vendor's website.