CVE-2024-41171 is a high-severity privilege escalation vulnerability affecting Siemens SINUMERIK 828D, 840D sl, and ONE industrial control systems. An authenticated local attacker can exploit improperly enforced access restrictions on system scripts to gain elevated privileges. With a CVSS score of 8.8, this vulnerability poses a significant risk of full compromise (confidentiality, integrity, availability). Currently, there is no public exploit code, active exploitation, or significant community discussion, suggesting it is not yet widely targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Siemens | SINUMERIK 828D V4 | >= 0, < *CNA affecteddefault unknown | |
| Siemens | SINUMERIK 828D V5 | >= 0, < V5.24CNA affecteddefault unknown | |
| Siemens | SINUMERIK 840D Sl V4 | >= 0, < *CNA affecteddefault unknown | |
| Siemens | SINUMERIK ONE | >= 0, < V6.24CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.