A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All… (CVE-2024-56181)
A high-severity vulnerability (CVE-2024-56181) affects multiple Siemens SIMATIC industrial PC models and Field PG M5 devices. The issue involves insufficient protection of EFI variables, allowing an authenticated attacker with high privileges to alter the secure boot configuration by directly communicating with the flash controller. This vulnerability impacts device integrity and security, potentially enabling compromise of the boot process.
AI Analysis
Technical Summary
CVE-2024-56181 is a vulnerability in various Siemens SIMATIC industrial PCs and Field PG M5 devices where the EFI variables stored on the device lack sufficient protection mechanisms. An authenticated attacker with high privileges can exploit this weakness to modify the secure boot configuration without proper authorization by directly interacting with the flash controller. This could lead to a complete compromise of device integrity, affecting confidentiality, integrity, and availability. The vulnerability has a CVSS v3.1 score of 8.2 (high severity) with attack vector local, low attack complexity, high privileges required, no user interaction, scope changed, and high impact on confidentiality, integrity, and availability. No patch or remediation information is provided in the source data.
Potential Impact
The vulnerability allows an authenticated attacker with high privileges to alter the secure boot configuration of affected devices. This can compromise the device's boot integrity, potentially enabling persistent unauthorized code execution or disabling security features. The impact affects confidentiality, integrity, and availability of the affected systems.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to devices to trusted administrators only and monitor for unauthorized changes to EFI variables or secure boot settings. Follow Siemens' official security advisories for updates and remediation instructions.
A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All… (CVE-2024-56181)
Description
A high-severity vulnerability (CVE-2024-56181) affects multiple Siemens SIMATIC industrial PC models and Field PG M5 devices. The issue involves insufficient protection of EFI variables, allowing an authenticated attacker with high privileges to alter the secure boot configuration by directly communicating with the flash controller. This vulnerability impacts device integrity and security, potentially enabling compromise of the boot process.
CVSS v3.1
Score 8.2high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2024-56181 is a vulnerability in various Siemens SIMATIC industrial PCs and Field PG M5 devices where the EFI variables stored on the device lack sufficient protection mechanisms. An authenticated attacker with high privileges can exploit this weakness to modify the secure boot configuration without proper authorization by directly interacting with the flash controller. This could lead to a complete compromise of device integrity, affecting confidentiality, integrity, and availability. The vulnerability has a CVSS v3.1 score of 8.2 (high severity) with attack vector local, low attack complexity, high privileges required, no user interaction, scope changed, and high impact on confidentiality, integrity, and availability. No patch or remediation information is provided in the source data.
Potential Impact
The vulnerability allows an authenticated attacker with high privileges to alter the secure boot configuration of affected devices. This can compromise the device's boot integrity, potentially enabling persistent unauthorized code execution or disabling security features. The impact affects confidentiality, integrity, and availability of the affected systems.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to devices to trusted administrators only and monitor for unauthorized changes to EFI variables or secure boot settings. Follow Siemens' official security advisories for updates and remediation instructions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-wpmj-mx2h-xgfx
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2024-56181"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa005aaacd9273b49ab46a6
Added to database: 09/08/2026, 12:55:06 UTC
Last enriched: 09/08/2026, 13:05:28 UTC
Last updated: 09/10/2026, 19:42:38 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.