CVE-2024-56181

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Mar 11, 2025
CWE ID 693

Summary

CVE-2024-56181 is a vulnerability affecting multiple Siemens industrial automation devices, including SIMATIC Field PG M5, SIMATIC IPC BX-xxA series, SIMATIC IPC PX-xxA series, SIMATIC IPC127E, SIMATIC IPC227E, SIMATIC IPC3000 SMART V3, and others. The issue lies in the insufficient protection mechanism for Extensible Firmware Interface (EFI) variables on these devices. An authenticated attacker can exploit this vulnerability by directly communicating with the flash controller, allowing them to alter the secure boot configuration without proper authorization. Devices affected include all versions of the listed devices, except for specific versions of some models that have received updates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share