A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN Fire Panel FC72x IP7 (All versions), Cerberus PRO EN Fire Panel FC72x IP8 (All versions < IP8 SR4), Cerberus PRO EN X200 Cloud Distribution IP7 (All versions), Cerberus PRO EN X200 Cloud Distribution IP8 (All versions < V4.3.5618), Cerberus PRO EN X300 Cloud Distribution IP7 (All versions), Cerberus PRO EN X300 Cloud Distribution IP8 (All versions < V4.3.5617), Cerberus PRO UL Compact Panel FC922/924 (All versions < MP4), Cerberus PRO UL Engineering Tool (All versions < MP4), Cerberus PRO UL X300 Cloud Distribution (All versions < V4.3.0001), Desigo Fire Safety UL Compact Panel FC2025/2050 (All versions < MP4), Desigo Fire Safety UL Engineering Tool (All versions < MP4), Desigo Fire Safety UL X300 Cloud Distribution (All versions < V4.3.0001), Sinteso FS20 EN Engineering Tool (All versions), Sinteso FS20 EN Fire Panel FC20 MP6 (All versions), Sinteso FS20 EN Fire Panel FC20 MP7 (All versions), Sinteso FS20 EN Fire Panel FC20 MP8 (All versions < MP8 SR4), Sinteso FS20 EN X200 Cloud Distribution MP7 (All versions), Sinteso FS20 EN X200 Cloud Distribution MP8 (All versions < V4.3.5618), Sinteso FS20 EN X300 Cloud Distribution MP7 (All versions), Sinteso FS20 EN X300 Cloud Distribution MP8 (All versions < V4.3.5617), Sinteso Mobile (All versions). The network communication library in affected systems insufficiently validates HMAC values which might result in a buffer overread.
This could allow an unauthenticated remote attacker to crash the network service.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-19643 A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN Fire Panel FC72x IP7 (All versions), Cerberus PRO EN Fire Panel FC72x IP8 (All versions < IP8 SR4), Cerberus PRO EN X200 Cloud Distribution IP7 (All versions), Cerberus PRO EN X200 Cloud Distribution IP8 (All versions < V4.3.5618), Cerberus PRO EN X300 Cloud Distribution IP7 (All versions), Cerberus PRO EN X300 Cloud Distribution IP8 (All versions < V4.3.5617), Cerberus PRO UL Compact Panel FC922/924 (All versions < MP4), Cerberus PRO UL Engineering Tool (All versions < MP4), Cerberus PRO UL X300 Cloud Distribution (All versions < V4.3.0001), Desigo Fire Safety UL Compact Panel FC2025/2050 (All versions < MP4), Desigo Fire Safety UL Engineering Tool (All versions < MP4), Desigo Fire Safety UL X300 Cloud Distribution (All versions < V4.3.0001), Sinteso FS20 EN Engineering Tool (All versions), Sinteso FS20 EN Fire Panel FC20 MP6 (All versions), Sinteso FS20 EN Fire Panel FC20 MP7 (All versions), Sinteso FS20 EN Fire Panel FC20 MP8 (All versions < MP8 SR4), Sinteso FS20 EN X200 Cloud Distribution MP7 (All versions), Sinteso FS20 EN X200 Cloud Distribution MP8 (All versions < V4.3.5618), Sinteso FS20 EN X300 Cloud Distribution MP7 (All versions), Sinteso FS20 EN X300 Cloud Distribution MP8 (All versions < V4.3.5617), Sinteso Mobile (All versions). The network communication library in affected systems insufficiently validates HMAC values which might result in a buffer overread. This could allow an unauthenticated remote attacker to crash the network service.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 16 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens cerberus Pro En Engineering Tool
Siemens cerberus Pro En Fire Panel Fc72x
Siemens cerberus Pro En X200 Cloud Distribution
Siemens cerberus Pro En X300 Cloud Distribution
Siemens cerberus Pro Ul Compact Panel
Siemens cerberus Pro Ul Engineering Tool
Siemens cerberus Pro Ul X300 Cloud
Siemens desigo Fire Safety Ul Compact Panel
Siemens desigo Fire Safety Ul Engineering Tool
Siemens sinteso Fs20 En Engineering Tool
Siemens sinteso Fs20 En Fire Panel Fc20
Siemens sinteso Fs20 En X200 Cloud Distribution
Siemens sinteso Fs20 En X300 Cloud Distribution
Siemens sinteso Mobile
CPEs cpe:2.3:a:siemens:cerberus_pro_en_engineering_tool:-:*:*:*:*:*:*:*
cpe:2.3:a:siemens:cerberus_pro_en_fire_panel_fc72x:-:*:*:*:*:*:*:*
cpe:2.3:a:siemens:cerberus_pro_en_x200_cloud_distribution:-:*:*:*:*:*:*:*
cpe:2.3:a:siemens:cerberus_pro_en_x300_cloud_distribution:-:*:*:*:*:*:*:*
cpe:2.3:a:siemens:cerberus_pro_ul_compact_panel:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:cerberus_pro_ul_engineering_tool:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:cerberus_pro_ul_x300_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:desigo_fire_safety_ul_compact_panel:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:desigo_fire_safety_ul_engineering_tool:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinteso_fs20_en_engineering_tool:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinteso_fs20_en_fire_panel_fc20:-:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinteso_fs20_en_x200_cloud_distribution:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinteso_fs20_en_x300_cloud_distribution:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinteso_mobile:*:*:*:*:*:*:*:*
Vendors & Products Siemens
Siemens cerberus Pro En Engineering Tool
Siemens cerberus Pro En Fire Panel Fc72x
Siemens cerberus Pro En X200 Cloud Distribution
Siemens cerberus Pro En X300 Cloud Distribution
Siemens cerberus Pro Ul Compact Panel
Siemens cerberus Pro Ul Engineering Tool
Siemens cerberus Pro Ul X300 Cloud
Siemens desigo Fire Safety Ul Compact Panel
Siemens desigo Fire Safety Ul Engineering Tool
Siemens sinteso Fs20 En Engineering Tool
Siemens sinteso Fs20 En Fire Panel Fc20
Siemens sinteso Fs20 En X200 Cloud Distribution
Siemens sinteso Fs20 En X300 Cloud Distribution
Siemens sinteso Mobile
Metrics ssvc

{'options': {'Automatable': 'Yes', 'Exploitation': 'None', 'Technical Impact': 'Total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2025-12-16T18:13:22.656Z

Reserved: 2024-01-04T13:24:07.552Z

Link: CVE-2024-22040

cve-icon Vulnrichment

Updated: 2024-08-01T22:35:34.860Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-12T11:15:48.637

Modified: 2024-11-21T08:55:26.510

Link: CVE-2024-22040

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses