CVE-2024-49775: Unauthenticated Heap-Based Buffer Overflow in Siemens User Management Component (UMC) Enables Remote Code Execution

CVE-2024-49775 (TL-2026-2488) is a critical-severity software vulnerability scored CVSS 9.8, first published 2024-12-16. It has no confirmed attribution, affects Siemens Opcenter Execution Foundation, references 1 CVE (CVE-2024-49775), maps to 5 MITRE ATT&CK techniques (T0819, T0822, T0859), and is covered by 9 detection rules and 15 indicators of compromise.

Key facts for TL-2026-2488

Threat ID
TL-2026-2488
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2024-12-16
Last reviewed
2024-12-16
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
critical manufacturing
Target regions
Worldwide
Detection rules
9
Indicators of compromise
15

Siemens disclosed CVE-2024-49775, a heap-based buffer overflow (CWE-122) in the shared User Management Component (UMC) used across SIMATIC PCS neo, TIA Portal, SINEC NMS, and the Opcenter MES product line. An unauthenticated remote attacker can send crafted input to the network-exposed UMC service to execute arbitrary code, with no user interaction required (CVSS v3.1: 9.8, CVSS v4.0: 9.3). TIA Portal V16 and SIMATIC PCS neo V4.0 have no fix planned and must rely permanently on firewall-based port mitigations.

How CVE-2024-49775 works

CVE-2024-49775 is a critical, unauthenticated, remotely exploitable heap-based buffer overflow (CWE-122) discovered by Tenable in the User Management Component (UMC), the shared authentication/authorization service embedded across a wide swath of Siemens' industrial engineering and manufacturing-execution software: SIMATIC PCS neo (DCS engineering/operations client), TIA Portal (PLC/automation engineering suite), SINEC NMS (network management), and the Opcenter Execution Foundation/Intelligence/Quality/RDnL manufacturing-execution-system (MES) modules.

Because UMC is the component Siemens itself designates as responsible for centralized user authentication across these products, a memory-corruption bug in it is disproportionately significant: successful exploitation does not merely compromise one application instance, it compromises the trust anchor that gates access to engineering and process-control tooling used to program and operate PLCs and DCS controllers. Tenable's technical naming ("um.atbipc.dll") ties the flaw to UMC's inter-process-communication handling, consistent with the vulnerability being reachable over UMC's own network listener rather than requiring local access.

CVSS v3.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, 9.8) and v4.0 (AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H, 9.3) both reflect network attack vector, low attack complexity, zero privileges, zero user interaction, and full confidentiality/integrity/availability impact -- the textbook profile of an unauthenticated, wormable-class RCE primitive in an OT-adjacent environment.

Tenable privately disclosed the flaw to Siemens on October 7, 2024. Siemens initially targeted a December 12, 2024 patch, requested an extension to January 6, 2025, then released the fix and Security Advisory SSA-928984 unexpectedly early on December 16, 2024; Tenable's TRA-2024-49 and CISA's ICSA-24-354-04 followed the next day. Patched builds exist for Opcenter Execution Foundation/Intelligence (V2501.0001+), Opcenter Quality (V2512+), Opcenter RDnL (V2410+), SIMATIC PCS neo V4.1 (Update 3+) and V5.0 (Update 1+), and SINEC NMS / TIA Portal V17-V19 (via UMC V2.15.1.1+). Critically, TIA Portal V16 and SIMATIC PCS neo V4.0 have NO fix planned at all -- Siemens' only guidance for those lines is to firewall UMC's network ports (4002/tcp, and 4004/tcp where no RT server machines are deployed), a permanent compensating control rather than a remediation.

As of this research (September 2026), CVE-2024-49775 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no verified public proof-of-concept or exploit code has surfaced; both Siemens and CISA describe no known exploitation in the wild. This is a sibling disclosure to the earlier CVE-2024-33698 (also a UMC heap-based buffer overflow, publicly disclosed September 10, 2024 via CISA ICSA-24-256-03), indicating the shared UMC codebase has now had at least two independently discovered unauthenticated heap-overflow RCE bugs within a single vendor-disclosure cycle -- a pattern worth flagging for defenders auditing UMC-dependent deployments regardless of which specific CVE they have patched.

MITRE ATT&CK techniques used in TL-2026-2488

Initial Access

T0819 Exploit Public-Facing Application; T0822 External Remote Services; T1190 Exploit Public-Facing Application

persistence

T0859 Valid Accounts

Credential Access

T1556 Modify Authentication Process

Affected products and versions in CVE-2024-49775

  • Siemens — Opcenter Execution Foundation
    Vulnerable versions: < V2501.0001
    Fixed in: V2501.0001 and later
  • Siemens — Opcenter Intelligence
    Vulnerable versions: < V2501.0001
    Fixed in: V2501.0001 and later
  • Siemens — Opcenter Quality
    Vulnerable versions: < V2512
    Fixed in: V2512 and later
  • Siemens — Opcenter RDnL
    Vulnerable versions: < V2410
    Fixed in: V2410 and later
  • Siemens — SIMATIC PCS neo
    Vulnerable versions: V4.0 (all versions)
    Fixed in: No fix planned
  • Siemens — SIMATIC PCS neo
    Vulnerable versions: V4.1 < Update 3
    Fixed in: V4.1 Update 3 and later
  • Siemens — SIMATIC PCS neo
    Vulnerable versions: V5.0 < Update 1
    Fixed in: V5.0 Update 1 and later
  • Siemens — SINEC NMS
    Vulnerable versions: with integrated UMC < V2.15
    Fixed in: UMC V2.15.1.1 and later
  • Siemens — TIA Portal (Totally Integrated Automation Portal)
    Vulnerable versions: V16 (all versions)
    Fixed in: No fix planned
  • Siemens — TIA Portal (Totally Integrated Automation Portal)
    Vulnerable versions: V17, V18, V19 (all versions)
    Fixed in: Integrated UMC upgraded to V2.15.1.1 or later

Remediation for CVE-2024-49775

Patches

  • Opcenter Execution Foundation V2501.0001 and later
  • Opcenter Intelligence V2501.0001 and later
  • Opcenter Quality V2512 and later
  • Opcenter RDnL V2410 and later
  • SIMATIC PCS neo V4.1 Update 3 and later
  • SIMATIC PCS neo V5.0 Update 1 and later
  • SINEC NMS and TIA Portal V17-V19: upgrade integrated UMC to V2.15.1.1 or later

Immediate actions

  • Restrict network access to UMC's ports 4002/tcp and 4004/tcp via firewall/ACL, permitting only authorized UMC and RT-server machines
  • Block port 4004/tcp entirely on any host where no RT server machines are deployed
  • Apply Siemens' general industrial-security network guidelines: segment OT/engineering networks from IT and the internet, use VPN with restrictive configuration for any remote access

Workarounds

  • TIA Portal V16 and SIMATIC PCS neo V4.0 (no fix planned): the only available mitigation is firewall-restricting network access to UMC ports 4002 and 4004

Longer-term hardening

  • Plan migration off SIMATIC PCS neo V4.0 and TIA Portal V16, which have no fix planned and remain permanently exposed to this vulnerability class
  • Upgrade all SINEC NMS and TIA Portal V17-V19 installations to integrate UMC V2.15.1.1 or later
  • Deploy OT-aware network monitoring/EDR capable of flagging heap-exploitation indicators and anomalous UMC process behavior
  • Audit all UMC-dependent deployments for exposure given the second unauthenticated UMC heap-overflow RCE (after CVE-2024-33698) disclosed in the same product line within a few months

CVEs associated with CVE-2024-49775

CVE-2024-49775

Weaknesses (CWE) in CVE-2024-49775

CWE-122

Timeline of CVE-2024-49775

  • Tenable privately disclosed the heap-based buffer overflow in Siemens UMC (later assigned CVE-2024-49775) to Siemens; Siemens acknowledged receipt.
  • Tenable requested a status update from Siemens; Siemens indicated a tentative patch release date of December 12, 2024.
  • Siemens requested a disclosure extension; the coordinated deadline was moved to January 6, 2025.
  • NVD published the CVE-2024-49775 record with CVSS v3.1 (9.8) and CVSS v4.0 (9.3) scores.
  • Siemens released the fix and published Security Advisory SSA-928984, ahead of the agreed extended deadline.
  • Tenable published Research Advisory TRA-2024-49 and CISA published ICS Advisory ICSA-24-354-04, making CVE-2024-49775 fully public.
  • Siemens updated SSA-928984 to version 1.4.
  • As of this research, CVE-2024-49775 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public proof-of-concept exploit code has been identified; TIA Portal V16 and SIMATIC PCS neo V4.0 remain permanently exposed with no fix planned.

Sources cited for CVE-2024-49775

More in vulnerability

Detection coverage for TL-2026-2488

As of 2024-12-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2488 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats