PatchSiren cyber security CVE debrief
CVE-2022-3623 Siemens CVE debrief
A race condition vulnerability in the Linux Kernel's BPF component, specifically in the follow_page_pte function within mm/gup.c, affects Siemens SIMATIC and SIPLUS industrial communication processors. The vulnerability allows remote attackers to exploit a race condition, potentially leading to integrity, confidentiality, and availability impacts. Siemens has released firmware updates to address this issue.
- Vendor
- Siemens
- Product
- SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0)
- CVSS
- MEDIUM 5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-06-11
- Original CVE updated
- 2024-06-11
- Advisory published
- 2024-06-11
- Advisory updated
- 2024-06-11
Who should care
Organizations operating Siemens SIMATIC CP 1542SP-1, CP 1542SP-1 IRC, CP 1543SP-1, and SIPLUS ET 200SP communication processors in industrial environments should prioritize patching. System integrators, OT security teams, and asset owners in manufacturing, energy, and critical infrastructure sectors using these devices for industrial Ethernet communications are affected.
Technical summary
The vulnerability exists in the follow_page_pte function of mm/gup.c within the Linux Kernel's BPF (Berkeley Packet Filter) component. A race condition can be triggered remotely, potentially allowing attackers to manipulate system state. The CVSS 3.1 vector indicates network attack vector with high attack complexity, requiring low privileges and no user interaction, with low impacts to confidentiality, integrity, and availability.
Defensive priority
medium
Recommended defensive actions
- Apply vendor-provided firmware updates to version 2.3 or later for affected Siemens SIMATIC and SIPLUS communication processors
- Review and implement CISA ICS recommended practices for industrial control system security
- Monitor Siemens ProductCERT portal for additional security updates and guidance
- Assess network segmentation to limit remote attack vectors against affected devices
- Validate that security patches have been successfully applied through firmware version verification
Evidence notes
The vulnerability was disclosed in CISA advisory ICSA-24-165-10 on June 11, 2024, with Siemens publishing security advisory SSA-625862. The issue stems from a race condition in the Linux Kernel's BPF subsystem that was previously identified as VDB-211921.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-3623 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-3623
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-3623 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-3623
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-165-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-625862.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-625862.html
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/pdf/ssa-625862.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/txt/ssa-625862.txt
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.