Junglewise Threat Intelligence

CVE-2024-56181: Siemens SIMATIC IPC and Field PG Secure Boot bypass via EFI variables

CVE-2024-56181 · Severity: high · CVSS 8.2 · Published 2025-03-11

Vendors: Siemens.

Executive brief

A vulnerability in several Siemens industrial computing devices could allow an authorized user to bypass critical security protections. These devices are used in industrial environments for automation, data processing, and control tasks. An attacker with administrative access could modify the system's startup configuration, potentially allowing them to run unauthorized software or permanently compromise the integrity of the device.

Technical details

A protection mechanism failure (CWE-693) exists in the handling of EFI (Extensible Firmware Interface) variables across multiple SIMATIC IPC, Tablet PC, and Field PG product lines. The vulnerability stems from insufficient protection of EFI variables stored on the device, which allows an authenticated attacker with high privileges to communicate directly with the flash controller. By doing so, the attacker can alter the Secure Boot configuration without proper authorization. This bypasses the intended security boundary between the operating system and the firmware, potentially leading to persistent rootkits or unauthorized firmware modifications. Siemens has released BIOS updates for many affected models, though some versions currently have no fix available.

Affected products

  • Siemens SIMATIC Field PG M5 All versions
  • Siemens SIMATIC IPC BX-21A < V31.01.07
  • Siemens SIMATIC IPC BX-32A < V29.01.07
  • Siemens SIMATIC IPC BX-39A < V29.01.07
  • Siemens SIMATIC IPC BX-59A < V32.01.04
  • Siemens SIMATIC IPC PX-32A < V29.01.07
  • Siemens SIMATIC IPC PX-39A < V29.01.07
  • Siemens SIMATIC IPC PX-39A PRO < V29.01.07
  • Siemens SIMATIC IPC RC-543A < V36.01.03
  • Siemens SIMATIC IPC RC-543B < V35.01.12
  • Siemens SIMATIC IPC RW-543A < V1.1.4
  • Siemens SIMATIC IPC RW-543B < V35.02.10
  • Siemens SIMATIC IPC127E < V27.01.11
  • Siemens SIMATIC IPC227E All versions
  • Siemens SIMATIC IPC227G < V28.01.14
  • Siemens SIMATIC IPC277E All versions
  • Siemens SIMATIC IPC277G < V28.01.14
  • Siemens SIMATIC IPC277G PRO < V28.01.14
  • Siemens SIMATIC IPC3000 SMART V3 All versions
  • Siemens SIMATIC IPC327G < V28.01.14
  • Siemens SIMATIC IPC347G All versions
  • Siemens SIMATIC IPC377G < V28.01.14
  • Siemens SIMATIC IPC427E All versions
  • Siemens SIMATIC IPC477E All versions
  • Siemens SIMATIC IPC477E PRO All versions
  • Siemens SIMATIC IPC527G All versions
  • Siemens SIMATIC IPC627E < V25.02.15
  • Siemens SIMATIC IPC647E < V25.02.15
  • Siemens SIMATIC IPC677E < V25.02.15
  • Siemens SIMATIC IPC847E < V25.02.15
  • Siemens SIMATIC ITP1000 All versions

Timeline

  • 2025-03-11: advisory: Initial publication by Siemens
  • 2026-05-12: other: Last update to the advisory

References

Related threats