CVE-2024-54017

MEDIUM

View CSAF Summary The SIPROTEC 5 devices do not use sufficiently random numbers to generate session identifiers. This could facilitate a brute-force attack against a valid session identifier which ...

Affects 0 products across 2 vendors.

BCS3.91
CVSS 3.15.3
CVSS v46.9
EPSS0.3%
Percentile23th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, no integrity impact, no availability impact.
CWE Weakness Definitions
CWE-334: CWE-334
◆ SAGE Intelligence — CITED Relevance Research Team

Siemens SIPROTEC 5 devices are vulnerable to session hijacking due to insufficient randomness in session identifier generation, which could be exploited by an unauthenticated remote attacker.

BSID: BS-2026-GLOBAL-221464-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-54017?
Siemens SIPROTEC 5 devices are vulnerable to session hijacking due to insufficient randomness in session identifier generation, which could be exploited by an unauthenticated remote attacker.
What is the CVSS score for CVE-2024-54017?
CVE-2024-54017 has CVSS 5.3 (Medium). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. EPSS: 0.3%.
Is CVE-2024-54017 actively exploited?
No confirmed active exploitation of CVE-2024-54017 as of 2026-05-30.
How do I remediate CVE-2024-54017?
Priority: MEDIUM.
What systems are affected by CVE-2024-54017?
CVE-2024-54017 affects: Fujitsu-Siemens, Siemens.
Vulnerability Details
CVE IDCVE-2024-54017
BSIDBS-2026-GLOBAL-221464-M BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Published2026-05-14
Last Modified2026-05-14
ICS Relevance55%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

View CSAF Summary The SIPROTEC 5 devices do not use sufficiently random numbers to generate session identifiers. This could facilitate a brute-force attack against a valid session identifier which could allow an unauthenticated remote attacker to hijack a valid user session. The affected session identifiers are only used in a subset of the endpoints that are provided by the affected products. Siemens is preparing fix versions and recommends countermeasures for products where fixes are not, or no

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker could perform a brute-force attack to guess valid session identifiers, potentially hijacking a user session. This attack is possible due to the predictable nature of the session identifiers.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Fujitsu-Siemens —
Siemens —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 72 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hasha9e20230628595ad35332acfa6be677725751fdcc1f7f91898fad5b124427b7dcea603f402bbeaa18697d4b265fd162b3913958adaaabdc303bcbfeda0685706
Related CVEs affecting Fujitsu-Siemens
CVE-2024-32741 10.0 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0).... CVE-2024-44102 10.0 A vulnerability has been identified in PP TeleControl Server Basic 1000 to 50... CVE-2008-5810 10.0 WBPublish (aka WBPublish.exe) in Fujitsu-Siemens WebTransactions 7.0, 7.1, an... CVE-2024-30207 10.0 A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780... CVE-2025-32433 10.0 Erlang/OTP is a set of libraries for the Erlang programming language. Prior t...
View all Fujitsu-Siemens CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →