Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-44102

29
FAUCET Score

CVE-2024-44102 is a critical insecure deserialization vulnerability affecting multiple versions of Siemens TeleControl Server Basic, specifically when redundancy is configured. An unauthenticated remote attacker can exploit this by sending a maliciously crafted serialized object, leading to arbitrary code execution with SYSTEM privileges. With a CVSS score of 10.0, this vulnerability poses a severe risk due to its network-based attack vector and low attack complexity. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB) or indication of active exploitation (KEV, Hot List), the vulnerability has garnered significant community discussion and media coverage, including mention in Microsoft's November 2024 Patch Tuesday.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.1, < 3.1.2.1CPE matchmatch criteria
cpe:2.3:a:siemens:telecontrol_server_basic:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

10.0CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
1.00%
Probability of exploitation in next 30 days
EPSS Percentile
59.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0100 is in the 44th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

azurevendor investigatingvia llm_extracted
dotnetvendor investigatingvia llm_extracted
langgeniusvendor investigatingvia llm_extracted
phoenix_contactvendor investigatingvia llm_extracted

Vendor Advisories (4)

langgeniusllm-langgenius-1cc6c18a9a7a1ab9CRITICAL

Siemens TeleControl Server Basic Deserialization Vulnerability

Nov 12, 2024
dotnetllm-dotnet-08d922f5af6c772fCRITICAL

Siemens TeleControl Server Basic Deserialization Vulnerability

Nov 12, 2024
azurellm-azure-fb1b9a33bbe53a92CRITICAL

Siemens TeleControl Server Basic Deserialization Vulnerability

Nov 12, 2024
phoenix_contactllm-phoenix_contact-0f7b910522981db9CRITICAL

Siemens TeleControl Server Basic Deserialization Vulnerability

Nov 12, 2024

References

cert-portal.siemens.com / productcert/html/ssa-454789.html
PatchVendor Advisory