CVE-2024-22041

Description

A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN Fire Panel FC72x IP7 (All versions), Cerberus PRO EN Fire Panel FC72x IP8 (All versions < IP8 SR4), Cerberus PRO EN X200 Cloud Distribution IP7 (All versions), Cerberus PRO EN X200 Cloud Distribution IP8 (All versions < V4.3.5618), Cerberus PRO EN X300 Cloud Distribution IP7 (All versions), Cerberus PRO EN X300 Cloud Distribution IP8 (All versions < V4.3.5617), Cerberus PRO UL Compact Panel FC922/924 (All versions < MP4), Cerberus PRO UL Engineering Tool (All versions < MP4), Cerberus PRO UL X300 Cloud Distribution (All versions < V4.3.0001), Desigo Fire Safety UL Compact Panel FC2025/2050 (All versions < MP4), Desigo Fire Safety UL Engineering Tool (All versions < MP4), Desigo Fire Safety UL X300 Cloud Distribution (All versions < V4.3.0001), Sinteso FS20 EN Engineering Tool (All versions), Sinteso FS20 EN Fire Panel FC20 MP6 (All versions), Sinteso FS20 EN Fire Panel FC20 MP7 (All versions), Sinteso FS20 EN Fire Panel FC20 MP8 (All versions < MP8 SR4), Sinteso FS20 EN X200 Cloud Distribution MP7 (All versions), Sinteso FS20 EN X200 Cloud Distribution MP8 (All versions < V4.3.5618), Sinteso FS20 EN X300 Cloud Distribution MP7 (All versions), Sinteso FS20 EN X300 Cloud Distribution MP8 (All versions < V4.3.5617), Sinteso Mobile (All versions). The network communication library in affected systems improperly handles memory buffers when parsing X.509 certificates. This could allow an unauthenticated remote attacker to crash the network service.

Category

7.5
CVSS
Severity: High
CVSS 3.1 •
EPSS 0.20%
Affected: Siemens Cerberus PRO EN Engineering Tool
Affected: Siemens Cerberus PRO EN Fire Panel FC72x IP6
Affected: Siemens Cerberus PRO EN Fire Panel FC72x IP7
Affected: Siemens Cerberus PRO EN Fire Panel FC72x IP8
Affected: Siemens Cerberus PRO EN X200 Cloud Distribution IP7
Affected: Siemens Cerberus PRO EN X200 Cloud Distribution IP8
Affected: Siemens Cerberus PRO EN X300 Cloud Distribution IP7
Affected: Siemens Cerberus PRO EN X300 Cloud Distribution IP8
Affected: Siemens Cerberus PRO UL Compact Panel FC922/924
Affected: Siemens Cerberus PRO UL Engineering Tool
Affected: Siemens Cerberus PRO UL X300 Cloud Distribution
Affected: Siemens Desigo Fire Safety UL Compact Panel FC2025/2050
Affected: Siemens Desigo Fire Safety UL Engineering Tool
Affected: Siemens Desigo Fire Safety UL X300 Cloud Distribution
Affected: Siemens Sinteso FS20 EN Engineering Tool
Affected: Siemens Sinteso FS20 EN Fire Panel FC20 MP6
Affected: Siemens Sinteso FS20 EN Fire Panel FC20 MP7
Affected: Siemens Sinteso FS20 EN Fire Panel FC20 MP8
Affected: Siemens Sinteso FS20 EN X200 Cloud Distribution MP7
Affected: Siemens Sinteso FS20 EN X200 Cloud Distribution MP8
Affected: Siemens Sinteso FS20 EN X300 Cloud Distribution MP7
Affected: Siemens Sinteso FS20 EN X300 Cloud Distribution MP8
Affected: Siemens Sinteso Mobile
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2024-22041?
CVE-2024-22041 has been scored as a high severity vulnerability.
How to fix CVE-2024-22041?
To fix CVE-2024-22041, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2024-22041 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2024-22041 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2024-22041?
CVE-2024-22041 affects Siemens Cerberus PRO EN Engineering Tool, Siemens Cerberus PRO EN Fire Panel FC72x IP6, Siemens Cerberus PRO EN Fire Panel FC72x IP7, Siemens Cerberus PRO EN Fire Panel FC72x IP8, Siemens Cerberus PRO EN X200 Cloud Distribution IP7, Siemens Cerberus PRO EN X200 Cloud Distribution IP8, Siemens Cerberus PRO EN X300 Cloud Distribution IP7, Siemens Cerberus PRO EN X300 Cloud Distribution IP8, Siemens Cerberus PRO UL Compact Panel FC922/924, Siemens Cerberus PRO UL Engineering Tool, Siemens Cerberus PRO UL X300 Cloud Distribution, Siemens Desigo Fire Safety UL Compact Panel FC2025/2050, Siemens Desigo Fire Safety UL Engineering Tool, Siemens Desigo Fire Safety UL X300 Cloud Distribution, Siemens Sinteso FS20 EN Engineering Tool, Siemens Sinteso FS20 EN Fire Panel FC20 MP6, Siemens Sinteso FS20 EN Fire Panel FC20 MP7, Siemens Sinteso FS20 EN Fire Panel FC20 MP8, Siemens Sinteso FS20 EN X200 Cloud Distribution MP7, Siemens Sinteso FS20 EN X200 Cloud Distribution MP8, Siemens Sinteso FS20 EN X300 Cloud Distribution MP7, Siemens Sinteso FS20 EN X300 Cloud Distribution MP8, Siemens Sinteso Mobile.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.