CVE-2024-54678: High severity Siemens Simatic Pcs Neo vulnerability

Published Aug 12, 2025
·
Updated

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All versions < V19 Update 4), SIMATIC STEP 7 V20 (All versions < V20 Update 4), SIMATIC WinCC V17 (All versions < V17 Update 9), SIMATIC WinCC V18 (All versions), SIMATIC WinCC V19 (All versions < V19 Update 4), SIMATIC WinCC V20 (All versions < V20 Update 4), SIMOCODE ES V17 (All versions), SIMOCODE ES V18 (All versions), SIMOCODE ES V19 (All versions), SIMOCODE ES V20 (All versions), SIMOTION SCOUT TIA V5.4 (All versions), SIMOTION SCOUT TIA V5.5 (All versions), SIMOTION SCOUT TIA V5.6 (All versions < V5.6 SP1 HF7), SIMOTION SCOUT TIA V5.7 (All versions), SINAMICS Startdrive V17 (All versions), SINAMICS Startdrive V18 (All versions), SINAMICS Startdrive V19 (All versions), SINAMICS Startdrive V20 (All versions), SIRIUS Safety ES V17 (TIA Portal) (All versions), SIRIUS Safety ES V18 (TIA Portal) (All versions), SIRIUS Safety ES V19 (TIA Portal) (All versions), SIRIUS Safety ES V20 (TIA Portal) (All versions), SIRIUS Soft Starter ES V17 (TIA Portal) (All versions), SIRIUS Soft Starter ES V18 (TIA Portal) (All versions), SIRIUS Soft Starter ES V19 (TIA Portal) (All versions), SIRIUS Soft Starter ES V20 (TIA Portal) (All versions), TIA Portal Cloud V17 (All versions), TIA Portal Cloud V18 (All versions), TIA Portal Cloud V19 (All versions < V5.2.1.1), TIA Portal Cloud V20 (All versions < V5.2.2.2), TIA Portal Test Suite V20 (All versions < V20 Update 4). Affected products do not properly sanitize Interprocess Communication input received through a Windows Named Pipe accessible to all local users. This could allow an authenticated local attacker to cause a type confusion and execute arbitrary code within the affected application.

Affected Software

11 affected components
Siemens Simatic Pcs Neo=V4.1, =V5.0, <V6.0 SP1 Update 1
Siemens Simatic S7-plcsim=V17
Siemens SIMATIC STEP 7<V17 Update 9, =V18, <V19 Update 4, <V20 Update 4
Siemens SIMATIC WinCC<V17 Update 9, =V18, <V19 Update 4, <V20 Update 4
Siemens Simocode Es=V17, =V18, =V19, =V20
Siemens SIMOTION SCOUT TIA=V5.4, =V5.5, <V5.6 SP1 HF7, =V5.7
Siemens SINAMICS Startdrive=V17, =V18, =V19, =V20
Siemens SIRIUS Safety ES (TIA Portal)=V17, =V18, =V19, =V20
Siemens SIRIUS Soft Starter ES (TIA Portal)=V17, =V18, =V19, =V20
Siemens TIA Portal Cloud=V17, =V18, <V5.2.1.1, <V5.2.2.2
Siemens TIA Portal Test Suite<V20 Update 4

Event History

Aug 12, 2025
CVE Published
via MITRE·11:16 AM
Data Sourced
via MITRE·11:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-54678?

CVE-2024-54678 has been classified with a severity level that warrants immediate attention due to potential risks associated with affected software.

2

How do I fix CVE-2024-54678?

To fix CVE-2024-54678, users should update to the latest patched versions of the affected software as recommended by Siemens.

3

Which products are affected by CVE-2024-54678?

CVE-2024-54678 impacts several Siemens products including SIMATIC PCS neo, SIMATIC S7-PLCSIM, and various versions of SIMATIC STEP 7.

4

What are the potential consequences of CVE-2024-54678?

Exploitation of CVE-2024-54678 could lead to unauthorized access, data manipulation, or disruption of critical automation processes.

5

Is there a workaround for CVE-2024-54678?

Currently, no specific workarounds have been published for CVE-2024-54678; applying the necessary updates is the primary mitigation strategy.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203