Information Exposure Through Timing Discrepancy in Siemens products - CVE-2024-42512

 

Information Exposure Through Timing Discrepancy in Siemens products - CVE-2024-42512

Published: March 12, 2025


Vulnerability identifier: #VU105636
CSH Severity: High
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-42512
CWE-ID: CWE-208
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the an exploitable timing discrepancy issue in the OPC UA .NET Standard Stack. A remote attacker can bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled.


Affected software

SIMATIC Energy Manager PRO
Totally Integrated Automation Portal (TIA Portal)
SIMIT Simulation Platform

How to mitigate CVE-2024-42512

Install updates from vendor's website.

SIMATIC Energy Manager PRO - update to 7.5 Update 2

External References

Related Security Bulletins