CVE-2024-4367

HIGH ⚠ Exploit

View CSAF Summary Siemens Teamcenter is affected by multiple vulnerabilities which could potentially lead to a compromise in availability, integrity and confidentiality. Siemens has released new ve...

Affects 4 products across 5 vendors.

BCS9.23
CVSS 3.18.8
EPSS72.6%
Percentile99th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, requires user interaction, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-754: CWE-754
◆ SAGE Intelligence — CITED Relevance Research Team

CVE-2024-4367 affects Siemens Teamcenter, leading to potential compromise in availability, integrity, and confidentiality. The CVSS score is 8.8, indicating a high severity. Public exploits are available, increasing the risk of compromise. Immediate action is recommended to update to the latest versions to mitigate the risk.

BSID: BS-2026-GLOBAL-300281-H • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-4367?
CVE-2024-4367 affects Siemens Teamcenter, leading to potential compromise in availability, integrity, and confidentiality. The CVSS score is 8.8, indicating a high severity. Public exploits are available, increasing the risk of compromise. Immediate action is recommended to update to the latest versions to mitigate the risk.
What is the CVSS score for CVE-2024-4367?
CVE-2024-4367 has CVSS 8.8 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. EPSS: 72.6%.
Is CVE-2024-4367 actively exploited?
Public exploit available for CVE-2024-4367. Exploitation risk elevated.
How do I remediate CVE-2024-4367?
Priority: IMMEDIATE. Advisory: https://www.mozilla.org/security/advisories/mfsa2024-21/ PSIRT: [email protected]
What systems are affected by CVE-2024-4367?
CVE-2024-4367 affects: Debian, Fujitsu-Siemens, Mozilla, Mozilla, Open-Xchange, Siemens.
What NERC-CIP standard applies to CVE-2024-4367?
NERC CIP CIP-007 CIP-007-R2: This CVE could allow an attacker to compromise the availability and integrity of critical systems, violating the requirement for secure access to electronic security perimeters.
What IEC 62443 requirement maps to CVE-2024-4367?
IEC 62443 SR 7.6: This vulnerability impacts the security of the Teamcenter application, which is a critical component in the ICS environment, requiring robust security measures to prevent unauthorized access and data manipulation.
Vulnerability Details
CVE IDCVE-2024-4367
BSIDBS-2026-GLOBAL-300281-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Published2026-05-14
Last Modified2026-05-14
ICS Relevance55%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

View CSAF Summary Siemens Teamcenter is affected by multiple vulnerabilities which could potentially lead to a compromise in availability, integrity and confidentiality. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Teamcenter are affected: Teamcenter V2312 vers:intdot/<2312.0014, vers:intdot/<2312.0009 (CVE-2026-33862, CVE-2026-33893, CVE-2024-4367) Teamcenter V2406 vers:intdot/<2406.0012, vers:intd

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability can be exploited remotely over the network with low attack complexity and no required privileges. User interaction is required, which may involve clicking on a malicious link or opening a malicious file.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Debian Debian Linux
Fujitsu-Siemens &mdash;
Mozilla Firefox
Mozilla Thunderbird
Open-Xchange Open-Xchange Appsuite Frontend
Siemens &mdash;
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 72 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement network segmentation to isolate the affected Teamcenter instances from critical systems and monitor for suspicious activity.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE could allow an attacker to compromise the availability and integrity of critical systems, violating the requirement for secure access to electronic security perimeters.
IEC 62443: SR 7.6
This vulnerability impacts the security of the Teamcenter application, which is a critical component in the ICS environment, requiring robust security measures to prevent unauthorized access and data manipulation.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash7f37e948ce63f6dbc7ee9d48923b618ac93d2b8d41ed3b3cff1dfb74da0cd4b1433af70c02b3b34bbc98cac4500c861b8e7017ea63cb28cbc9278d6365ef28ac
Related CVEs affecting Debian
CVE-2001-0554 10.0 Buffer overflow in BSD-based telnetd telnet daemon on various operating syste... CVE-1999-0698 10.0 Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux. CVE-2004-0888 10.0 Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use x... CVE-2004-0980 10.0 Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3... CVE-2008-1673 10.0 The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 b...
View all Debian CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →