PatchSiren cyber security CVE debrief
CVE-2022-1015 Siemens CVE debrief
A local privilege escalation vulnerability exists in the Linux kernel's netfilter subsystem (nf_tables_api.c). An out-of-bounds write flaw allows a local attacker to escalate privileges or cause system instability. The vulnerability requires local access with low privileges and no user interaction. Siemens has confirmed this vulnerability affects TIM 1531 IRC industrial communication modules, which incorporate the vulnerable Linux kernel component.
- Vendor
- Siemens
- Product
- SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0)
- CVSS
- MEDIUM 6.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-06-13
- Original CVE updated
- 2024-04-09
- Advisory published
- 2023-06-13
- Advisory updated
- 2024-04-09
Who should care
Organizations operating Siemens TIM 1531 IRC (6GK7543-1MX00-0XE0) or SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) industrial communication modules in OT/ICS environments. System administrators responsible for Linux-based embedded systems in critical infrastructure. Security teams managing industrial control system patch cycles.
Technical summary
The vulnerability resides in nf_tables_api.c within the Linux kernel netfilter subsystem. The flaw permits a local, low-privileged user to trigger an out-of-bounds write condition. Successful exploitation could lead to privilege escalation, denial of service, or code execution. The attack vector is local with low attack complexity and no user interaction required. Availability impact is rated high, with low impacts to confidentiality and integrity.
Defensive priority
medium
Recommended defensive actions
- Apply vendor fix: Update TIM 1531 IRC firmware to V2.4.8 or later
- Restrict local access to affected industrial control systems
- Monitor for unauthorized local account creation or privilege escalation attempts
- Implement network segmentation for ICS environments per CISA recommended practices
- Review Siemens security advisory SSA-337522 for additional product-specific guidance
Evidence notes
CISA published advisory ICSA-24-165-06 on 2024-06-11, identifying CVE-2022-1015 as affecting Siemens TIM 1531 IRC products. The advisory references Siemens security advisory SSA-337522. The CVE description confirms the flaw is in linux/net/netfilter/nf_tables_api.c, allowing local out-of-bounds write. CVSS 3.1 vector: AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-1015 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-1015
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-1015 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-1015
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-165-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-337522.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-337522.html
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/pdf/ssa-337522.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/txt/ssa-337522.txt
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.