CVE-2024-49775: Siemens Opcenter Execution Foundation
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2501.0001), Opcenter Intelligence (All versions < V2501.0001), Opcenter Quality (All versions < V2512), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SINEC NMS (All versions if operated in conjunction with UMC < V2.15), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions). Affected products contain a heap-based buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to execute arbitrary code.
Affected products
- Siemens Opcenter Execution Foundation: before V2501.0001 (fixed in V2501.0001)
- Siemens Opcenter Intelligence: before V2501.0001 (fixed in V2501.0001)
- Siemens Opcenter Quality: before V2512 (fixed in V2512)
- Siemens Opcenter Rdnl: before V2410 (fixed in V2410)
- Siemens SIMATIC Pcs Neo v4.0: any version
- Siemens SIMATIC Pcs Neo v4.1: before V4.1 Update 3 (fixed in V4.1 Update 3)
- Siemens SIMATIC Pcs Neo v5.0: before V5.0 Update 1 (fixed in V5.0 Update 1)
- Siemens Sinec Nms: any version
- Siemens Totally Integrated Automation Portal Tia Portal v16: any version
- Siemens Totally Integrated Automation Portal Tia Portal v17: any version
- Siemens Totally Integrated Automation Portal Tia Portal v18: any version
- Siemens Totally Integrated Automation Portal Tia Portal v19: any version
Published 2024-12-16. Last modified 2026-06-17.