CVE-2024-52051: Input Validation

Published Dec 10, 2024
·
Updated

A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC S7-PLCSIM V18 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 9), SIMATIC STEP 7 Safety V18 (All versions), SIMATIC STEP 7 Safety V19 (All versions < V19 Update 4), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All versions < V19 Update 4), SIMATIC WinCC Unified PC Runtime V18 (All versions), SIMATIC WinCC Unified PC Runtime V19 (All versions < V19 Update 4), SIMATIC WinCC Unified V17 (All versions < V17 Update 9), SIMATIC WinCC Unified V18 (All versions), SIMATIC WinCC Unified V19 (All versions < V19 Update 4), SIMATIC WinCC V17 (All versions < V17 Update 9), SIMATIC WinCC V18 (All versions), SIMATIC WinCC V19 (All versions < V19 Update 4), SIMOCODE ES V17 (All versions), SIMOCODE ES V18 (All versions), SIMOCODE ES V19 (All versions), SIMOTION SCOUT TIA V5.4 (All versions), SIMOTION SCOUT TIA V5.5 (All versions), SIMOTION SCOUT TIA V5.6 (All versions < V5.6 SP1 HF7), SINAMICS Startdrive V17 (All versions), SINAMICS Startdrive V18 (All versions), SINAMICS Startdrive V19 (All versions), SIRIUS Safety ES V17 (TIA Portal) (All versions), SIRIUS Safety ES V18 (TIA Portal) (All versions), SIRIUS Safety ES V19 (TIA Portal) (All versions), SIRIUS Soft Starter ES V17 (TIA Portal) (All versions), SIRIUS Soft Starter ES V18 (TIA Portal) (All versions), SIRIUS Soft Starter ES V19 (TIA Portal) (All versions), TIA Portal Cloud V17 (All versions), TIA Portal Cloud V18 (All versions), TIA Portal Cloud V19 (All versions < V5.2.1.1). The affected devices do not properly sanitize user-controllable input when parsing user settings. This could allow an attacker to locally execute arbitrary commands in the host operating system with the privileges of the user.

Affected Software

8 affected components
Siemens Simatic S7-plcsim<V17, <V18
Siemens SIMATIC STEP 7 Safety<V17 Update 9, <V18, <V19 Update 4
Siemens SIMATIC STEP 7<V17 Update 9, <V18, <V19 Update 4
Siemens SIMATIC WinCC Unified PC Runtime<V18, <V19 Update 4
Siemens SIMATIC WinCC Unified<V17 Update 9, <V18, <V19 Update 4
Siemens SIMATIC WinCC<V17 Update 9, <V18, <V19 Update 4
Siemens Simocode Es
Siemens SIMOTION SCOUT TIA

Event History

Dec 10, 2024
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:30 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-52051?

The severity of CVE-2024-52051 is classified as critical.

2

How do I fix CVE-2024-52051?

To fix CVE-2024-52051, update all affected Siemens software to the latest version provided by Siemens.

3

Which products are affected by CVE-2024-52051?

The affected products include SIMATIC S7-PLCSIM V17-V18, SIMATIC STEP 7 Safety V17-V19, and SIMATIC STEP 7 V17-V19.

4

Is there a patch available for CVE-2024-52051?

Yes, Siemens has released patches to mitigate the vulnerability CVE-2024-52051.

5

What are the potential impacts of CVE-2024-52051?

The potential impacts of CVE-2024-52051 include unauthorized access and control of affected systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
CVE-2024-52051 - Input Validation - SecAlerts