First published: Tue Apr 08 2025(Updated: )
A vulnerability has been identified in Industrial Edge Device Kit - arm64 V1.17 (All versions), Industrial Edge Device Kit - arm64 V1.18 (All versions), Industrial Edge Device Kit - arm64 V1.19 (All versions), Industrial Edge Device Kit - arm64 V1.20 (All versions < V1.20.2-1), Industrial Edge Device Kit - arm64 V1.21 (All versions < V1.21.1-1), Industrial Edge Device Kit - x86-64 V1.17 (All versions), Industrial Edge Device Kit - x86-64 V1.18 (All versions), Industrial Edge Device Kit - x86-64 V1.19 (All versions), Industrial Edge Device Kit - x86-64 V1.20 (All versions < V1.20.2-1), Industrial Edge Device Kit - x86-64 V1.21 (All versions < V1.21.1-1), Industrial Edge Own Device (IEOD) (All versions < V1.21.1-1-a), Industrial Edge Virtual Device (All versions < V1.21.1-1-a), SCALANCE LPE9413 (6GK5998-3GS01-2AC2) (All versions), SIMATIC IPC BX-39A Industrial Edge Device (All versions < V3.0), SIMATIC IPC BX-59A Industrial Edge Device (All versions < V3.0), SIMATIC IPC127E Industrial Edge Device (All versions < V3.0), SIMATIC IPC227E Industrial Edge Device (All versions < V3.0), SIMATIC IPC427E Industrial Edge Device (All versions < V3.0), SIMATIC IPC847E Industrial Edge Device (All versions < V3.0). Affected devices do not properly enforce user authentication on specific API endpoints when identity federation is used. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that identity federation is currently or has previously been used and the attacker has learned the identity of a legitimate user.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Industrial Edge Device Kit | =V1.17=V1.18=V1.19<V1.20.2-1<V1.21.1-1 | |
Industrial Edge Device Kit | =V1.17=V1.18=V1.19<V1.20.2-1<V1.21.1-1 | |
Industrial Edge Own Device | <V1.21.1-1-a | |
Siemens Industrial Edge Virtual Device | <V1.21.1-1-a | |
Siemens SCALANCE LPE9413 | =6GK5998-3GS01-2AC2 | |
Siemens SIMATIC IPC BX-39A | <V3.0 | |
Siemens SIMATIC IPC BX-59A | <V3.0 | |
Siemens Simatic IPC127E Firmware | <V3.0 | |
Siemens SIMATIC IPC227E | <V3.0 | |
Siemens Simatic IPC427E Firmware | <V3.0 | |
Siemens Simatic IPC847E Firmware | <V3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-54092 is considered a high-severity vulnerability affecting several versions of the Industrial Edge Device Kit and related devices.
To resolve CVE-2024-54092, update the affected devices to versions V1.20.2-1 or later, and ensure all specified hardware is updated accordingly.
CVE-2024-54092 affects Industrial Edge Device Kit - arm64 and x86-64 versions V1.17, V1.18, V1.19, and those prior to V1.20.2-1.
CVE-2024-54092 impacts the Industrial Edge Device Kit, including virtual and own devices from Siemens, among others.
Exploiting CVE-2024-54092 could allow unauthorized access or control over affected devices, leading to security breaches.