CVE-2024-31484
A vulnerability has been identified in CPC80 Central Processing/Communication (All versions < V16.41), CPCI85 Central Processing/Communication (All versions < V5.30), CPCX26 Central Processing/Communication (All versions < V06.02), ETA4 Ethernet Interface IEC60870-5-104 (All versions < V10.46), ETA5 Ethernet Int. 1x100TX IEC61850 Ed.2 (All versions < V03.27), PCCX26 Ax 1703 PE, Contr, Communication Element (All versions < V06.05). The affected devices contain an improper null termination vulnerability while parsing a specific HTTP header. This could allow an attacker to execute code in the context of the current process or lead to denial of service condition.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.47%
- CWE
- CWE-170
- Published
- 2024-05-14
- Last modified
- 2026-03-13
Affected products
- Siemens CPC80 Central Processing/Communication
- Siemens CPCI85 Central Processing/Communication
- Siemens CPCX26 Central Processing/Communication
- Siemens ETA4 Ethernet Interface IEC60870-5-104
- Siemens ETA5 Ethernet Int. 1x100TX IEC61850 Ed.2
- Siemens PCCX26 Ax 1703 PE, Contr, Communication Element
Weakness type
Related vulnerabilities
- CVE-2021-1418 — Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
- CVE-2021-1411 — Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
- CVE-2021-1471 — Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
- CVE-2021-1469 — Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
- CVE-2021-1417 — Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
- CVE-2026-8721 — Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs
- CVE-2026-5067 — Out-of-bounds read/write in HTTP WebSocket upgrade via non-null-terminated Sec-WebSocket-Key
- CVE-2026-34464 — Sandboxie-Plus NamedPipeServer OpenHandler stack overflow via unterminated server field