CVE-2024-56181 describes an insufficient protection mechanism in the EFI variables of numerous Siemens SIMATIC IPC and Field PG devices, allowing an authenticated attacker to alter secure boot configurations. This vulnerability carries a high severity CVSS score of 8.2, indicating that a high-privileged local attacker can achieve high impact on confidentiality, integrity, and availability by directly communicating with the flash controller. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Siemens | SIMATIC Field PG M5 | >= 0, < *CNA affecteddefault unknown | |
| Siemens | SIMATIC IPC BX-21A | >= 0, < V31.01.07CNA affecteddefault unknown | |
| Siemens | SIMATIC IPC BX-32A | >= 0, < V29.01.07CNA affecteddefault unknown | |
| Siemens | SIMATIC IPC BX-39A | >= 0, < V29.01.07CNA affecteddefault unknown | |
| Siemens | SIMATIC IPC BX-59A | >= 0, < V32.01.04CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.