Memory disclosure and code execution via Session-ID mishandling
Published May 14, 2024 · Updated Feb 13, 2025
Improper null termination in Siemens SICAM device firmware allows local users to disclose memory through a crafted HTTP Session-ID header. The embedded web server either copies exactly 20 header bytes with strncpy without appending a null byte or formats an overlong value into a fixed BSS buffer with sprintf. Affected releases span CPC80 before 16.41, CPCI85 before 5.30, CPCX26 before 06.02, ETA4 before 10.46, ETA5 before 03.27, and PCCX26 before 06.05; exploitation requires user interaction and can expose process memory, crash the service, or enable code execution in the current process.
Summary
What happened
Improper null termination in Siemens SICAM device firmware allows local users to disclose memory through a crafted HTTP Session-ID header. The embedded web server either copies exactly 20 header bytes with strncpy without appending a null byte or formats an overlong value into a fixed BSS buffer with sprintf. Affected releases span CPC80 before 16.41, CPCI85 before 5.30, CPCX26 before 06.02, ETA4 before 10.46, ETA5 before 03.27, and PCCX26 before 06.05; exploitation requires user interaction and can expose process memory, crash the service, or enable code execution in the current process.
The record
- CVE
- CVE-2024-31484
- Published
- May 14, 2024
- Updated
- Feb 13, 2025
- Vendor
- Siemens
- Product
- CPCX26 Central Processing/Communication
- Classifications
- CWE-170
- Attack vector
- local
- Privileges
- unauthenticated
Timeline
How it unfolded
- May 14, 2024CVE publishedPublication date reported by the CVE source.
- Feb 13, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0 <V06.02
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- SEC Consult Session-ID proof of conceptproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo