CVE-2024-49775: Unauthenticated Heap-Based Buffer Overflow in Siemens User Management Component (UMC) Enables Remote Code Execution
CVE-2024-49775 (TL-2026-2488) is a critical-severity software vulnerability scored CVSS 9.8, first published 2024-12-16. It has no confirmed attribution, affects Siemens Opcenter Execution Foundation, references 1 CVE (CVE-2024-49775), maps to 5 MITRE ATT&CK techniques (T0819, T0822, T0859), and is covered by 9 detection rules and 15 indicators of compromise.
Key facts for TL-2026-2488
- Threat ID
- TL-2026-2488
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2024-12-16
- Last reviewed
- 2024-12-16
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- critical manufacturing
- Target regions
- Worldwide
- Detection rules
- 9
- Indicators of compromise
- 15
Siemens disclosed CVE-2024-49775, a heap-based buffer overflow (CWE-122) in the shared User Management Component (UMC) used across SIMATIC PCS neo, TIA Portal, SINEC NMS, and the Opcenter MES product line. An unauthenticated remote attacker can send crafted input to the network-exposed UMC service to execute arbitrary code, with no user interaction required (CVSS v3.1: 9.8, CVSS v4.0: 9.3). TIA Portal V16 and SIMATIC PCS neo V4.0 have no fix planned and must rely permanently on firewall-based port mitigations.
How CVE-2024-49775 works
CVE-2024-49775 is a critical, unauthenticated, remotely exploitable heap-based buffer overflow (CWE-122) discovered by Tenable in the User Management Component (UMC), the shared authentication/authorization service embedded across a wide swath of Siemens' industrial engineering and manufacturing-execution software: SIMATIC PCS neo (DCS engineering/operations client), TIA Portal (PLC/automation engineering suite), SINEC NMS (network management), and the Opcenter Execution Foundation/Intelligence/Quality/RDnL manufacturing-execution-system (MES) modules.
Because UMC is the component Siemens itself designates as responsible for centralized user authentication across these products, a memory-corruption bug in it is disproportionately significant: successful exploitation does not merely compromise one application instance, it compromises the trust anchor that gates access to engineering and process-control tooling used to program and operate PLCs and DCS controllers. Tenable's technical naming ("um.atbipc.dll") ties the flaw to UMC's inter-process-communication handling, consistent with the vulnerability being reachable over UMC's own network listener rather than requiring local access.
CVSS v3.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, 9.8) and v4.0 (AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H, 9.3) both reflect network attack vector, low attack complexity, zero privileges, zero user interaction, and full confidentiality/integrity/availability impact -- the textbook profile of an unauthenticated, wormable-class RCE primitive in an OT-adjacent environment.
Tenable privately disclosed the flaw to Siemens on October 7, 2024. Siemens initially targeted a December 12, 2024 patch, requested an extension to January 6, 2025, then released the fix and Security Advisory SSA-928984 unexpectedly early on December 16, 2024; Tenable's TRA-2024-49 and CISA's ICSA-24-354-04 followed the next day. Patched builds exist for Opcenter Execution Foundation/Intelligence (V2501.0001+), Opcenter Quality (V2512+), Opcenter RDnL (V2410+), SIMATIC PCS neo V4.1 (Update 3+) and V5.0 (Update 1+), and SINEC NMS / TIA Portal V17-V19 (via UMC V2.15.1.1+). Critically, TIA Portal V16 and SIMATIC PCS neo V4.0 have NO fix planned at all -- Siemens' only guidance for those lines is to firewall UMC's network ports (4002/tcp, and 4004/tcp where no RT server machines are deployed), a permanent compensating control rather than a remediation.
As of this research (September 2026), CVE-2024-49775 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no verified public proof-of-concept or exploit code has surfaced; both Siemens and CISA describe no known exploitation in the wild. This is a sibling disclosure to the earlier CVE-2024-33698 (also a UMC heap-based buffer overflow, publicly disclosed September 10, 2024 via CISA ICSA-24-256-03), indicating the shared UMC codebase has now had at least two independently discovered unauthenticated heap-overflow RCE bugs within a single vendor-disclosure cycle -- a pattern worth flagging for defenders auditing UMC-dependent deployments regardless of which specific CVE they have patched.
MITRE ATT&CK techniques used in TL-2026-2488
Initial Access
T0819 Exploit Public-Facing Application; T0822 External Remote Services; T1190 Exploit Public-Facing Application
persistence
Credential Access
Affected products and versions in CVE-2024-49775
- Siemens — Opcenter Execution Foundation
Vulnerable versions: < V2501.0001
Fixed in: V2501.0001 and later - Siemens — Opcenter Intelligence
Vulnerable versions: < V2501.0001
Fixed in: V2501.0001 and later - Siemens — Opcenter Quality
Vulnerable versions: < V2512
Fixed in: V2512 and later - Siemens — Opcenter RDnL
Vulnerable versions: < V2410
Fixed in: V2410 and later - Siemens — SIMATIC PCS neo
Vulnerable versions: V4.0 (all versions)
Fixed in: No fix planned - Siemens — SIMATIC PCS neo
Vulnerable versions: V4.1 < Update 3
Fixed in: V4.1 Update 3 and later - Siemens — SIMATIC PCS neo
Vulnerable versions: V5.0 < Update 1
Fixed in: V5.0 Update 1 and later - Siemens — SINEC NMS
Vulnerable versions: with integrated UMC < V2.15
Fixed in: UMC V2.15.1.1 and later - Siemens — TIA Portal (Totally Integrated Automation Portal)
Vulnerable versions: V16 (all versions)
Fixed in: No fix planned - Siemens — TIA Portal (Totally Integrated Automation Portal)
Vulnerable versions: V17, V18, V19 (all versions)
Fixed in: Integrated UMC upgraded to V2.15.1.1 or later
Remediation for CVE-2024-49775
Patches
- Opcenter Execution Foundation V2501.0001 and later
- Opcenter Intelligence V2501.0001 and later
- Opcenter Quality V2512 and later
- Opcenter RDnL V2410 and later
- SIMATIC PCS neo V4.1 Update 3 and later
- SIMATIC PCS neo V5.0 Update 1 and later
- SINEC NMS and TIA Portal V17-V19: upgrade integrated UMC to V2.15.1.1 or later
Immediate actions
- Restrict network access to UMC's ports 4002/tcp and 4004/tcp via firewall/ACL, permitting only authorized UMC and RT-server machines
- Block port 4004/tcp entirely on any host where no RT server machines are deployed
- Apply Siemens' general industrial-security network guidelines: segment OT/engineering networks from IT and the internet, use VPN with restrictive configuration for any remote access
Workarounds
- TIA Portal V16 and SIMATIC PCS neo V4.0 (no fix planned): the only available mitigation is firewall-restricting network access to UMC ports 4002 and 4004
Longer-term hardening
- Plan migration off SIMATIC PCS neo V4.0 and TIA Portal V16, which have no fix planned and remain permanently exposed to this vulnerability class
- Upgrade all SINEC NMS and TIA Portal V17-V19 installations to integrate UMC V2.15.1.1 or later
- Deploy OT-aware network monitoring/EDR capable of flagging heap-exploitation indicators and anomalous UMC process behavior
- Audit all UMC-dependent deployments for exposure given the second unauthenticated UMC heap-overflow RCE (after CVE-2024-33698) disclosed in the same product line within a few months
CVEs associated with CVE-2024-49775
CVE-2024-49775
Weaknesses (CWE) in CVE-2024-49775
CWE-122
Timeline of CVE-2024-49775
- Tenable privately disclosed the heap-based buffer overflow in Siemens UMC (later assigned CVE-2024-49775) to Siemens; Siemens acknowledged receipt.
- Tenable requested a status update from Siemens; Siemens indicated a tentative patch release date of December 12, 2024.
- Siemens requested a disclosure extension; the coordinated deadline was moved to January 6, 2025.
- NVD published the CVE-2024-49775 record with CVSS v3.1 (9.8) and CVSS v4.0 (9.3) scores.
- Siemens released the fix and published Security Advisory SSA-928984, ahead of the agreed extended deadline.
- Tenable published Research Advisory TRA-2024-49 and CISA published ICS Advisory ICSA-24-354-04, making CVE-2024-49775 fully public.
- Siemens updated SSA-928984 to version 1.4.
- As of this research, CVE-2024-49775 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public proof-of-concept exploit code has been identified; TIA Portal V16 and SIMATIC PCS neo V4.0 remain permanently exposed with no fix planned.
Sources cited for CVE-2024-49775
- SSA-928984: Heap-based Buffer Overflow Vulnerability in User Management Component (UMC)
- ICSA-24-354-04: Siemens User Management Component
- TRA-2024-49: Siemens User Management Component um.atbipc.dll Heap-based Buffer Overflow
- CVE-2024-49775 Detail
- ICSA-24-256-03: Siemens User Management Component (UMC) - related prior UMC heap-overflow disclosure (CVE-2024-33698)
- CVE-2024-49775: Siemens UMC Component RCE Vulnerability
More in vulnerability
- Click2Shell WordPress Exploit Chain Lets Attackers Gain RCE With a Single Malicious Link
- SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCE
- CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables SNAT Privilege Escalation, and AF_ALG Race Condition (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964)
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform (CVE-2026-58138) Exploited in the Wild
- "LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow, PPPoEject, DiagSpill)
Detection coverage for TL-2026-2488
As of 2024-12-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2488 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.