Junglewise Threat Intelligence

CVE-2024-54678: Siemens Engineering Platforms code execution via Windows Named Pipe

CVE-2024-54678 · Severity: high · CVSS 8.2 · Published 2025-08-12

Technologies: Siemens Simatic Pcs Neo. Vendors: Siemens.

Executive brief

A vulnerability exists in several Siemens industrial engineering and automation software platforms, including SIMATIC PCS neo and TIA Portal. These tools are used to design, configure, and manage industrial control systems. An attacker with local access to a computer running this software could exploit the flaw to take full control of the application, potentially leading to unauthorized changes in industrial processes or theft of sensitive engineering data.

Technical details

A deserialization vulnerability (CWE-502) exists in multiple Siemens engineering products due to improper restriction of access permissions and lack of input sanitization on a local Windows Named Pipe used for Interprocess Communication (IPC). An authenticated local attacker can send specially crafted input to the Named Pipe, triggering a type confusion. This allows for arbitrary code execution within the context of the affected application. While some versions have received updates (e.g., TIA Portal V19 Update 4, SIMATIC PCS neo V6.0 SP1 Update 1), others currently have no planned fix and rely on general mitigations.

Affected products

  • Siemens SIMATIC PCS neo V4.1, V5.0, V6.0 < V6.0 SP1 Update 1
  • Siemens TIA Portal (STEP 7, WinCC, Test Suite) V17 < Update 9, V18, V19 < Update 4, V20 < Update 4
  • Siemens SIMOTION SCOUT TIA V5.4, V5.5, V5.6 < V5.6 SP1 HF7, V5.7
  • Siemens TIA Portal Cloud V19 < V5.2.1.1, V20 < V5.2.2.2

Timeline

  • 2025-08-12: disclosed
  • 2025-08-12: advisory
  • 2026-06-09: other: Last advisory update

References

Related threats