A critical security vulnerability has been discovered in Siemens' User Management Component (UMC), potentially exposing many industrial control systems to remote attacks.
See also: 145,000 ICS systems exposed online

The vulnerability, identified as CVE-2024-49775, allows unauthenticated, remote attackers to execute arbitrary code on affected systems, posing a serious risk to industrial and enterprise environments.
The buffer overflow vulnerability affects several Siemens products that integrate the UMC component. These include Opcenter Execution Foundation, Opcenter Intelligence, Opcenter Quality, Opcenter RDL, SIMATIC PCS neo, SINEC NMS , and Totally Integrated Automation Portal (TIA Portal).
With a CVSS v3.1 base score of 9.8 and a CVSS v4.0 score of 9.3, the vulnerability is classified as critical, reflecting its potential for widespread exploitation and severe impact. The remote attack vector does not require authentication or user interaction, making it particularly dangerous.
See also: Siemens Industrial Edge Management: Warning! Critical vulnerability
Siemens has acknowledged the vulnerability and is actively working on permanent fixes for affected products. In the meantime, the company has issued specific workarounds and mitigations to reduce the risk.

The impact of the UMC vulnerability in Siemens products extends beyond immediate security concerns. If exploited, it could lead to unauthorized control of industrial processes, data theft , or operational disruption. Given the critical nature of industrial control systems and automation software, the potential consequences of a successful attack are severe.
There is currently no evidence of a public proof-of-concept exploit or active exploitation of this vulnerability, but cybersecurity experts warn that the window to patch before malicious actors strike could be closing quickly.
Siemens strongly advises customers to implement recommended mitigations promptly and remain vigilant for upcoming patches and updates.
See also: Sony: Creates wireless headset in industrial metaverse
Arbitrary code execution refers to the ability of a program or malicious agent to run code that was not originally intended by the system. This vulnerability can create serious security risks, as it allows the execution of commands that can lead to data loss, system compromise, or the spread of malware. It is often found in applications that do not have adequate input control measures or have not been updated for known security vulnerabilities.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
