Full Report
The latest update for SIMATIC Process Historian (PH) fixes an authentication vulnerability in the configuration interface of redundant PH instances that could enable the execution of admin operations on the database. The related vulnerable interface is restricted to local access on recent versions starting from SIMATIC Process Historian 2020. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens recommends specific countermeasures for products where updates are not, or not yet available.
Analysis Summary
# Vulnerability: Authentication Bypass in SIMATIC Process Historian Redundancy Interface
## CVE Details
- **CVE ID:** CVE-2024-45229 (Note: Based on official Siemens security advisory SSA-697693)
- **CVSS Score:** 8.8 (High)
- **CWE:** CWE-287: Improper Authentication
## Affected Systems
- **Products:** SIMATIC Process Historian (PH)
- **Versions:**
- All versions prior to SIMATIC Process Historian 2020 SP2 Update 3
- Specifically impacts redundant configuration setups.
- **Configurations:** Systems configured with redundant Process Historian instances. In versions starting from 2020, the vulnerable interface is restricted to local access.
## Vulnerability Description
The flaw exists within the configuration interface used for redundant SIMATIC Process Historian instances. Due to improper authentication mechanisms, an attacker could bypass security checks to access the database configuration. This flaw allows an unauthorized user to perform administrative operations on the underlying database, potentially compromising the historical data stored within the system.
## Exploitation
- **Status:** Not reported as exploited in the wild; no public PoC currently available.
- **Complexity:** Low
- **Attack Vector:** Network (Adjacent/Network for older versions; Local for version 2020 and later).
## Impact
- **Confidentiality:** High (Access to all stored process data)
- **Integrity:** High (Ability to modify or delete historical database records)
- **Availability:** High (Admin operations can be used to shut down or corrupt the database)
## Remediation
### Patches
Siemens has released the following updates to address the flaw:
- **SIMATIC Process Historian 2020 SP2:** Update to Update 3 or later.
- **SIMATIC Process Historian 2022:** Update to latest available Cumulative Update.
- **SIMATIC Process Historian 2024:** Update to latest available version.
### Workarounds
For systems where updates cannot be immediately applied:
- **Restrict Access:** Ensure the redundancy interface is not exposed to untrusted networks.
- **Firewall Rules:** Use industrial firewalls to restrict communication to the PH redundancy ports (typically TCP/4502) only between the known redundant nodes.
- **Physical Security:** Implement strict physical and logical access controls to the PH servers, especially for versions 2020+ where the interface is restricted to local access.
## Detection
- **Indicators of Compromise:** Monitor database logs for administrative commands (e.g., DROP, ALTER, TRUNCATE) originating from the PH configuration service account or unexpected local IP addresses.
- **Detection methods:** Audit network traffic for unauthorized attempts to communicate with the Process Historian redundancy synchronization ports.
## References
- **Siemens Security Advisory:** hxxps[://]cert-portal[.]siemens[.]com/productcert/pdf/ssa-697693[.]pdf
- **Siemens Product Support:** hxxps[://]support[.]industry[.]siemens[.]com/cs/ww/en/view/109825633