PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-3623 Siemens CVE debrief

A race condition vulnerability in the Linux Kernel's BPF component, specifically in the follow_page_pte function within mm/gup.c, affects Siemens SIMATIC and SIPLUS industrial communication processors. The vulnerability allows remote attackers to exploit a race condition, potentially leading to integrity, confidentiality, and availability impacts. Siemens has released firmware updates to address this issue.

Vendor
Siemens
Product
SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0)
CVSS
MEDIUM 5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-06-11
Original CVE updated
2024-06-11
Advisory published
2024-06-11
Advisory updated
2024-06-11

Who should care

Organizations operating Siemens SIMATIC CP 1542SP-1, CP 1542SP-1 IRC, CP 1543SP-1, and SIPLUS ET 200SP communication processors in industrial environments should prioritize patching. System integrators, OT security teams, and asset owners in manufacturing, energy, and critical infrastructure sectors using these devices for industrial Ethernet communications are affected.

Technical summary

The vulnerability exists in the follow_page_pte function of mm/gup.c within the Linux Kernel's BPF (Berkeley Packet Filter) component. A race condition can be triggered remotely, potentially allowing attackers to manipulate system state. The CVSS 3.1 vector indicates network attack vector with high attack complexity, requiring low privileges and no user interaction, with low impacts to confidentiality, integrity, and availability.

Defensive priority

medium

Recommended defensive actions

  • Apply vendor-provided firmware updates to version 2.3 or later for affected Siemens SIMATIC and SIPLUS communication processors
  • Review and implement CISA ICS recommended practices for industrial control system security
  • Monitor Siemens ProductCERT portal for additional security updates and guidance
  • Assess network segmentation to limit remote attack vectors against affected devices
  • Validate that security patches have been successfully applied through firmware version verification

Evidence notes

The vulnerability was disclosed in CISA advisory ICSA-24-165-10 on June 11, 2024, with Siemens publishing security advisory SSA-625862. The issue stems from a race condition in the Linux Kernel's BPF subsystem that was previously identified as VDB-211921.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-3623 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-3623

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-3623 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-3623

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-165-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-625862.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-625862.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/pdf/ssa-625862.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/txt/ssa-625862.txt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.