# CVE-2024-31484

## Summary

- **CVE ID:** CVE-2024-31484
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-170
- **Published:** May 14, 2024
- **Last Modified:** Mar 13, 2026

## Description

A vulnerability has been identified in CPC80 Central Processing/Communication (All versions < V16.41), CPCI85 Central Processing/Communication (All versions < V5.30), CPCX26 Central Processing/Communication (All versions < V06.02), ETA4 Ethernet Interface IEC60870-5-104 (All versions < V10.46), ETA5 Ethernet Int. 1x100TX IEC61850 Ed.2 (All versions < V03.27), PCCX26 Ax 1703 PE, Contr, Communication Element (All versions < V06.05). The affected devices contain an improper null termination vulnerability while parsing a specific HTTP header. This could allow an attacker to execute code in the context of the current process or lead to denial of service condition.

## Affected Products

- Siemens — CPC80 Central Processing/Communication (0)
- Siemens — CPCI85 Central Processing/Communication (0)
- Siemens — CPCX26 Central Processing/Communication (0)
- Siemens — ETA4 Ethernet Interface IEC60870-5-104 (0)
- Siemens — ETA5 Ethernet Int. 1x100TX IEC61850 Ed.2 (0)
- Siemens — PCCX26 Ax 1703 PE, Contr, Communication Element (0)

## References

- [CNA](https://cert-portal.siemens.com/productcert/html/ssa-871704.html)
- [CNA](https://cert-portal.siemens.com/productcert/html/ssa-620338.html)
- [CNA](http://seclists.org/fulldisclosure/2024/Jul/4)
- [CVE](http://seclists.org/fulldisclosure/2024/Nov/18)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.47%
- **EPSS Percentile:** 39.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._