Siemens SIPROTEC 4 Improper Check for Unusual or Exceptional Conditions (CVE-2024-52504)

high Tenable OT Security Plugin ID 504809

Synopsis

The remote OT asset is affected by a vulnerability.

Description

Affected devices do not properly handle interrupted operations of file transfer. This could allow an unauthenticated remote attacker to cause a denial of service condition. To restore normal operations, the devices need to be restarted.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

https://cert-portal.siemens.com/productcert/html/ssa-400089.html

https://support.industry.siemens.com/cs/ww/en/view/109743560/

https://support.industry.siemens.com/cs/ww/en/view/109743563/

https://support.industry.siemens.com/cs/ww/en/view/109743573/

Plugin Details

Severity: High

ID: 504809

Version: 1.1

Type: remote

Family: Tenable.ot

Published: 11/18/2025

Updated: 11/18/2025

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Information

CPE: cpe:/o:siemens:siprotec_4_6md63_firmware, cpe:/o:siemens:siprotec_4_7um62_firmware, cpe:/o:siemens:siprotec_4_7sj61_firmware, cpe:/o:siemens:siprotec_4_6md66_firmware, cpe:/o:siemens:siprotec_4_compact_7sk81_firmware, cpe:/o:siemens:siprotec_4_6md665_firmware, cpe:/o:siemens:siprotec_4_7sj62_firmware, cpe:/o:siemens:siprotec_4_7ss52_firmware, cpe:/o:siemens:siprotec_4_7ut613_firmware, cpe:/o:siemens:siprotec_4_7um61_firmware, cpe:/o:siemens:siprotec_4_7st6_firmware, cpe:/o:siemens:siprotec_4_7ut63_firmware, cpe:/o:siemens:siprotec_4_compact_7sk80_firmware, cpe:/o:siemens:siprotec_4_7sd5_firmware, cpe:/o:siemens:siprotec_4_6md61_firmware, cpe:/o:siemens:siprotec_4_7sd610_firmware, cpe:/o:siemens:siprotec_4_7ut612_firmware, cpe:/o:siemens:siprotec_4_7sj63_firmware, cpe:/o:siemens:siprotec_4_7sa6_firmware, cpe:/o:siemens:siprotec_4_compact_7sj81_firmware, cpe:/o:siemens:siprotec_4_compact_7sd80_firmware, cpe:/o:siemens:siprotec_4_compact_7sj80_firmware, cpe:/o:siemens:siprotec_4_7sj66_firmware, cpe:/o:siemens:siprotec_4_7ve6_firmware, cpe:/o:siemens:siprotec_4_7sj64_firmware, cpe:/o:siemens:siprotec_4_7vk61_firmware, cpe:/o:siemens:siprotec_4_7vu683_firmware, cpe:/o:siemens:siprotec_4_7sa522_firmware, cpe:/o:siemens:siprotec_4_compact_7rw80_firmware

Required KB Items: Tenable.ot/Siemens

Exploit Ease: No known exploits are available

Patch Publication Date: 8/12/2025

Vulnerability Publication Date: 8/12/2025

Reference Information

CVE: CVE-2024-52504

CWE: 754