ID

VAR-202502-0219


CVE

CVE-2024-45386


TITLE

Siemens Product Session Expiration Insufficient Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2025-15315

DESCRIPTION

A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SIMOCODE ES V19 (All versions < V19 Update 1), SIRIUS Safety ES V19 (TIA Portal) (All versions < V19 Update 1), SIRIUS Soft Starter ES V19 (TIA Portal) (All versions < V19 Update 1), TIA Administrator (All versions < V3.0.4). Affected products do not correctly invalidate user sessions upon user logout. This could allow a remote unauthenticated attacker, who has obtained the session token by other means, to re-use a legitimate user's session even after logout. SIMATIC PCS neo is a new generation of distributed control system (DCS) launched by Siemens. It is designed based on the Web platform and HTML5 technology, specially designed for process industry, and supports multi-user collaborative work and digital management. TIA Administrator is a management tool in Siemens Industrial Automation Software Suite, mainly used for centralized management and maintenance of TIA Portal projects. Totally Integrated Automation Portal (TIA Portal) is a fully integrated automation software platform launched by Siemens, which aims to simplify the automation project development process through a unified engineering environment. Siemens SIMATIC PCS neo, TIA Administrator, and Totally Integrated Automation Portal have insufficient session expiration vulnerabilities

Trust: 1.44

sources: NVD: CVE-2024-45386 // CNVD: CNVD-2025-15315

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-15315

AFFECTED PRODUCTS

vendor:siemensmodel:simatic pcs neoscope: - version: -

Trust: 0.6

vendor:siemensmodel:totally integrated automation portalscope: - version: -

Trust: 0.6

vendor:siemensmodel:tia administratorscope:ltversion:v3.0.4

Trust: 0.6

sources: CNVD: CNVD-2025-15315

CVSS

SEVERITY

CVSSV2

CVSSV3

productcert@siemens.com: CVE-2024-45386
value: HIGH

Trust: 1.0

CNVD: CNVD-2025-15315
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-15315
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

productcert@siemens.com: CVE-2024-45386
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2025-15315 // NVD: CVE-2024-45386

PROBLEMTYPE DATA

problemtype:CWE-613

Trust: 1.0

sources: NVD: CVE-2024-45386

EXTERNAL IDS

db:NVDid:CVE-2024-45386

Trust: 1.6

db:SIEMENSid:SSA-342348

Trust: 1.6

db:CNVDid:CNVD-2025-15315

Trust: 0.6

sources: CNVD: CNVD-2025-15315 // NVD: CVE-2024-45386

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-342348.html

Trust: 1.6

sources: CNVD: CNVD-2025-15315 // NVD: CVE-2024-45386

SOURCES

db:CNVDid:CNVD-2025-15315
db:NVDid:CVE-2024-45386

LAST UPDATE DATE

2025-07-13T23:33:57.145000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-15315date:2025-07-08T00:00:00
db:NVDid:CVE-2024-45386date:2025-02-11T11:15:13.627

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-15315date:2025-02-18T00:00:00
db:NVDid:CVE-2024-45386date:2025-02-11T11:15:13.627