Vulnerability in SIMATIC Field PG M5 and Related SIMATIC Products by Siemens
CVE-2024-56181

8.4HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
11 March 2025

Summary

A significant security flaw exists in several Siemens SIMATIC products that exposes insufficient protections for EFI (Extensible Firmware Interface) variables stored on the devices. This vulnerability may allow an authenticated attacker to change the secure boot configuration by directly communicating with the flash controller, potentially leading to unauthorized access and manipulation of system integrity.

Affected Version(s)

SIMATIC Field PG M5 0

SIMATIC IPC BX-21A 0

SIMATIC IPC BX-32A 0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.