PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-1015 Siemens CVE debrief

A local privilege escalation vulnerability exists in the Linux kernel's netfilter subsystem (nf_tables_api.c). An out-of-bounds write flaw allows a local attacker to escalate privileges or cause system instability. The vulnerability requires local access with low privileges and no user interaction. Siemens has confirmed this vulnerability affects TIM 1531 IRC industrial communication modules, which incorporate the vulnerable Linux kernel component.

Vendor
Siemens
Product
SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0)
CVSS
MEDIUM 6.6
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-13
Original CVE updated
2024-02-13
Advisory published
2024-02-13
Advisory updated
2024-02-13

Who should care

Organizations operating Siemens TIM 1531 IRC (6GK7543-1MX00-0XE0) or SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) industrial communication modules in OT/ICS environments. System administrators responsible for Linux-based embedded systems in critical infrastructure. Security teams managing industrial control system patch cycles.

Technical summary

The vulnerability resides in nf_tables_api.c within the Linux kernel netfilter subsystem. The flaw permits a local, low-privileged user to trigger an out-of-bounds write condition. Successful exploitation could lead to privilege escalation, denial of service, or code execution. The attack vector is local with low attack complexity and no user interaction required. Availability impact is rated high, with low impacts to confidentiality and integrity.

Defensive priority

medium

Recommended defensive actions

  • Apply vendor fix: Update TIM 1531 IRC firmware to V2.4.8 or later
  • Restrict local access to affected industrial control systems
  • Monitor for unauthorized local account creation or privilege escalation attempts
  • Implement network segmentation for ICS environments per CISA recommended practices
  • Review Siemens security advisory SSA-337522 for additional product-specific guidance

Evidence notes

CISA published advisory ICSA-24-165-06 on 2024-06-11, identifying CVE-2022-1015 as affecting Siemens TIM 1531 IRC products. The advisory references Siemens security advisory SSA-337522. The CVE description confirms the flaw is in linux/net/netfilter/nf_tables_api.c, allowing local out-of-bounds write. CVSS 3.1 vector: AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H.

Official resources

2024-06-11