PatchSiren cyber security CVE debrief
CVE-2022-39189 Siemens CVE debrief
A vulnerability in the x86 KVM subsystem of the Linux kernel before version 5.18.17 allows unprivileged guest users to compromise the guest kernel. The issue stems from mishandled TLB (Translation Lookaside Buffer) flush operations in specific KVM_VCPU_PREEMPTED situations. This vulnerability affects Siemens SIPLUS TIM 1531 IRC and TIM 1531 IRC industrial communication devices, which incorporate the vulnerable Linux kernel component. The flaw enables local privilege escalation within guest virtual machines, potentially allowing attackers to gain full control of the guest kernel. Siemens has released firmware version V2.4.8 or later to address this vulnerability. Organizations should apply the vendor-provided update and follow CISA's recommended practices for securing industrial control systems.
- Vendor
- Siemens
- Product
- SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0)
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-13
- Original CVE updated
- 2024-02-13
- Advisory published
- 2024-02-13
- Advisory updated
- 2024-02-13
Who should care
Organizations operating Siemens TIM 1531 IRC or SIPLUS TIM 1531 IRC industrial communication modules in virtualized environments; OT security teams managing KVM-based virtualization infrastructure; system administrators responsible for Linux kernel maintenance in industrial control systems; compliance officers tracking CVE remediation for critical infrastructure assets.
Technical summary
The vulnerability exists in the x86 KVM (Kernel-based Virtual Machine) subsystem where TLB flush operations are improperly handled when KVM_VCPU_PREEMPTED conditions occur. This race condition allows unprivileged guest users to manipulate memory translation caching mechanisms, leading to guest kernel compromise. The flaw is local to the guest environment with low attack complexity, requiring only low privileges but no user interaction. Impact is severe with high ratings for confidentiality, integrity, and availability breaches within the affected guest system.
Defensive priority
HIGH
Recommended defensive actions
- Apply Siemens firmware update V2.4.8 or later to affected TIM 1531 IRC devices
- Validate guest kernel versions in virtualized environments are 5.18.17 or later
- Review and implement CISA ICS recommended practices for defense-in-depth
- Monitor for anomalous privilege escalation activity within guest VMs
- Assess exposure of affected devices to untrusted guest users or workloads
Evidence notes
CVE published 2024-06-11; modified 2024-07-09. CISA ICS advisory ICSA-24-165-06 published same date. Siemens SSA-337522 provides vendor remediation guidance. CVSS 7.8 HIGH severity with local attack vector, low attack complexity, and high impact to confidentiality, integrity, and availability.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-39189 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-39189
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-39189 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-39189
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-165-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-337522.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-337522.html
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/pdf/ssa-337522.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/txt/ssa-337522.txt
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.