CVE-2024-45386: Siemens SIMATIC Pcs Neo v4.0

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SIMOCODE ES V19 (All versions < V19 Update 1), SIRIUS Safety ES V19 (TIA Portal) (All versions < V19 Update 1), SIRIUS Soft Starter ES V19 (TIA Portal) (All versions < V19 Update 1), TIA Administrator (All versions < V3.0.4). Affected products do not correctly invalidate user sessions upon user logout. This could allow a remote unauthenticated attacker, who has obtained the session token by other means, to re-use a legitimate user's session even after logout.

Affected products

  • Siemens SIMATIC Pcs Neo v4.0: any version
  • Siemens SIMATIC Pcs Neo v4.1: before V4.1 Update 2 (fixed in V4.1 Update 2)
  • Siemens SIMATIC Pcs Neo v5.0: before V5.0 Update 1 (fixed in V5.0 Update 1)
  • Siemens Simocode Es v19: before V19 Update 1 (fixed in V19 Update 1)
  • Siemens Sirius Safety Es v19 Tia Portal: before V19 Update 1 (fixed in V19 Update 1)
  • Siemens Sirius Soft Starter Es v19 Tia Portal: before V19 Update 1 (fixed in V19 Update 1)
  • Siemens Tia Administrator: before V3.0.4 (fixed in V3.0.4)

Published 2025-02-11. Last modified 2026-06-17.