CVE-2024-35783
Last modified
CVE-2024-35783 is a critical-severity vulnerability rated 9.4/10 on the CVSS scale. A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions < V2020 SP2 Update 5), SIMATIC Information Server 2022 (All versions < V2022 SP1 Update 2), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC06), SIMATIC Process Historian 2020 (All versions < V2020 SP2 Update 5), SIMATIC Process Historian 2022 (All versions < V2022 SP1 Update 2), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 5), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 3), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 18), SIMATIC WinCC V8.0 (All versions < V8.0 Update 5). The affected products run their DB server with elevated privileges which could allow an authenticated attacker to execute arbitrary OS commands with administrative privileges.. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions < V2020 SP2 Update 5), SIMATIC Information Server 2022 (All versions < V2022 SP1 Update 2), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC06), SIMATIC Process Historian 2020 (All versions < V2020 SP2 Update 5), SIMATIC Process Historian 2022 (All versions < V2022 SP1 Update 2), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 5), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 3), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 18), SIMATIC WinCC V8.0 (All versions < V8.0 Update 5). The affected products run their DB server with elevated privileges which could allow an authenticated attacker to execute arbitrary OS commands with administrative privileges.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-35783?
How severe is CVE-2024-35783?
How do I fix CVE-2024-35783?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-35777Improper Neutralization of Special Elements in Output Used b…3.5
- CVE-2024-35778Improper Limitation of a Pathname to a Restricted Directory …8.8
- CVE-2024-35779Improper Neutralization of Input During Web Page Generation …5.4
- CVE-2024-35780Deserialization of Untrusted Data vulnerability in Live Comp…8.5
- CVE-2024-35781Improper Limitation of a Pathname to a Restricted Directory …6.5
- CVE-2024-35782Improper Neutralization of Input During Web Page Generation …5.4
- CVE-2024-35784In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-35785In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2024-35786In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-35787In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-35788Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2024-35789In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2024-35783?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
