PatchSiren cyber security CVE debrief
CVE-2022-1015 Siemens CVE debrief
A local privilege escalation vulnerability exists in the Linux kernel's netfilter subsystem (nf_tables_api.c). An out-of-bounds write flaw allows a local attacker to escalate privileges or cause system instability. The vulnerability requires local access with low privileges and no user interaction. Siemens has confirmed this vulnerability affects TIM 1531 IRC industrial communication modules, which incorporate the vulnerable Linux kernel component.
- Vendor
- Siemens
- Product
- SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0)
- CVSS
- MEDIUM 6.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-13
- Original CVE updated
- 2024-02-13
- Advisory published
- 2024-02-13
- Advisory updated
- 2024-02-13
Who should care
Organizations operating Siemens TIM 1531 IRC (6GK7543-1MX00-0XE0) or SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) industrial communication modules in OT/ICS environments. System administrators responsible for Linux-based embedded systems in critical infrastructure. Security teams managing industrial control system patch cycles.
Technical summary
The vulnerability resides in nf_tables_api.c within the Linux kernel netfilter subsystem. The flaw permits a local, low-privileged user to trigger an out-of-bounds write condition. Successful exploitation could lead to privilege escalation, denial of service, or code execution. The attack vector is local with low attack complexity and no user interaction required. Availability impact is rated high, with low impacts to confidentiality and integrity.
Defensive priority
medium
Recommended defensive actions
- Apply vendor fix: Update TIM 1531 IRC firmware to V2.4.8 or later
- Restrict local access to affected industrial control systems
- Monitor for unauthorized local account creation or privilege escalation attempts
- Implement network segmentation for ICS environments per CISA recommended practices
- Review Siemens security advisory SSA-337522 for additional product-specific guidance
Evidence notes
CISA published advisory ICSA-24-165-06 on 2024-06-11, identifying CVE-2022-1015 as affecting Siemens TIM 1531 IRC products. The advisory references Siemens security advisory SSA-337522. The CVE description confirms the flaw is in linux/net/netfilter/nf_tables_api.c, allowing local out-of-bounds write. CVSS 3.1 vector: AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H.
Official resources
-
CVE-2022-1015 CVE record
CVE.org
-
CVE-2022-1015 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2024-06-11