Information Exposure Through Timing Discrepancy in Siemens products - CVE-2024-42512
Published: March 12, 2025
Vulnerability identifier: #VU105636
CSH Severity: High
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-42512
CWE-ID: CWE-208
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the an exploitable timing discrepancy issue in the OPC UA .NET Standard Stack. A remote attacker can bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled.
Affected software
SIMATIC Energy Manager PRO
Totally Integrated Automation Portal (TIA Portal)
SIMIT Simulation Platform
Totally Integrated Automation Portal (TIA Portal)
SIMIT Simulation Platform
How to mitigate CVE-2024-42512
Install updates from vendor's website.
SIMATIC Energy Manager PRO - update to 7.5 Update 2