Information Exposure Through Timing Discrepancy in Siemens products - CVE-2024-42512
Published: March 12, 2025
Vulnerability identifier: #VU105636
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/U:Amber
CVE-ID: CVE-2024-42512
CWE-ID: CWE-208
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vendor: Siemens
Affected software:
SIMATIC Energy Manager PRO
Totally Integrated Automation Portal (TIA Portal)
SIMIT Simulation Platform
SIMATIC Energy Manager PRO
Totally Integrated Automation Portal (TIA Portal)
SIMIT Simulation Platform
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the an exploitable timing discrepancy issue in the OPC UA .NET Standard Stack. A remote attacker can bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled.
How to mitigate CVE-2024-42512
Install updates from vendor's website.