CVE-2024-56182

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Mar 11, 2025
CWE ID 693

Summary

CVE-2024-56182 is a vulnerability affecting multiple Siemens industrial automation devices, including SIMATIC Field PG M5, IPC BX series, IPC PX series, IPC127E, IPC227E, IPC277G, IPC3000 SMART V3, IPC327G, IPC347G, IPC377G, IPC427E, IPC477E, IPC477E PRO, IPC527G, IPC627E (versions < V25.02.15), IPC647E (versions < V25.02.15), IPC677E (versions < V25.02.15), IPC847E (versions < V25.02.15), and ITP1000 (all versions). The vulnerability arises due to insufficient protection mechanisms for EFI (Extensible Firmware Interface) variables stored on these devices. An authenticated attacker can exploit this weakness by directly communicating with the flash controller, enabling them to disable the BIOS password without proper authorization.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share