PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-3545 Siemens CVE debrief

A use-after-free vulnerability in the Linux Kernel's Netronome NFP driver affects Siemens SIMATIC and SIPLUS industrial communication processors. The flaw resides in the area_cache_get function within drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c, specifically impacting IPsec functionality. With a CVSS 3.1 score of 7.8 (HIGH), this local privilege escalation vulnerability requires low attack complexity and low privileges but no user interaction, enabling attackers to achieve high confidentiality, integrity, and availability impact. The vulnerability was disclosed publicly on June 11, 2024, through coordinated CISA and Siemens advisories. Siemens has released firmware updates to address this issue in affected industrial control system products.

Vendor
Siemens
Product
SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0)
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2023-06-13
Original CVE updated
2024-04-09
Advisory published
2023-06-13
Advisory updated
2024-04-09

Who should care

Organizations operating Siemens SIMATIC CP 1542SP-1, CP 1542SP-1 IRC, CP 1543SP-1, or SIPLUS ET 200SP communication processors in industrial automation environments. System integrators and OT security teams responsible for maintaining firmware in industrial control systems. Organizations utilizing IPsec functionality on affected Siemens network devices.

Technical summary

The vulnerability exists in the area_cache_get function of the Netronome NFP (Network Flow Processor) driver's core CPP (Chip Peripheral Port) implementation. The use-after-free condition in IPsec processing can be triggered through memory manipulation, potentially allowing local attackers to escalate privileges. The affected code path is in drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c. This kernel-level vulnerability propagates to Siemens industrial products that incorporate the vulnerable Netronome networking components.

Defensive priority

HIGH

Recommended defensive actions

  • Apply vendor-provided firmware updates to version 2.3 or later for all affected Siemens SIMATIC CP 1542SP-1, CP 1542SP-1 IRC, CP 1543SP-1, and SIPLUS ET 200SP communication processor variants
  • Verify firmware version through Siemens Industry Online Support portal before and after update deployment
  • Implement network segmentation for industrial control systems to limit exposure of affected communication processors
  • Monitor for anomalous IPsec-related activity or unexpected process behavior on affected devices
  • Review and apply CISA ICS recommended practices for defense-in-depth strategies in industrial environments

Evidence notes

Vulnerability affects Linux Kernel Netronome NFP driver function area_cache_get in IPsec component. CISA advisory ICSA-24-165-10 and Siemens SSA-625862 provide coordinated disclosure. Six Siemens SIMATIC/SIPLUS communication processor products confirmed affected.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-3545 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-3545

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-3545 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-3545

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-165-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-625862.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-625862.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/pdf/ssa-625862.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/txt/ssa-625862.txt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.