Vulnerability in SIMATIC Field PG M5 and Related SIMATIC Products by Siemens
CVE-2024-56181
8.4HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 11 March 2025
Summary
A significant security flaw exists in several Siemens SIMATIC products that exposes insufficient protections for EFI (Extensible Firmware Interface) variables stored on the devices. This vulnerability may allow an authenticated attacker to change the secure boot configuration by directly communicating with the flash controller, potentially leading to unauthorized access and manipulation of system integrity.
Affected Version(s)
SIMATIC Field PG M5 0
SIMATIC IPC BX-21A 0
SIMATIC IPC BX-32A 0
References
CVSS V4
Score:
8.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved