PatchSiren cyber security CVE debrief
CVE-2022-42328 Siemens CVE debrief
CVE-2022-42328 is a medium-severity vulnerability in the Linux netback driver that can be triggered by guest virtual machines to cause a deadlock condition. The vulnerability was introduced by the patch for XSA-392, which created a race condition when attempting to free the socket buffer (SKB) of a packet dropped due to XSA-392 handling. This results in a denial-of-service condition through system deadlock. The vulnerability affects Siemens SIMATIC and SIPLUS industrial control system products that incorporate the vulnerable Linux kernel components. The issue was published on June 11, 2024, with a CVSS 3.1 score of 5.5 (MEDIUM severity). Siemens has released firmware updates to address this vulnerability.
- Vendor
- Siemens
- Product
- SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0)
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-06-13
- Original CVE updated
- 2024-04-09
- Advisory published
- 2023-06-13
- Advisory updated
- 2024-04-09
Who should care
Organizations operating Siemens SIMATIC CP 1542SP-1, SIMATIC CP 1542SP-1 IRC, SIMATIC CP 1543SP-1, and SIPLUS ET 200SP CP industrial communication modules in virtualized Xen environments should prioritize this update. System administrators managing industrial control systems with guest VMs, security teams responsible for OT/ICS infrastructure, and organizations subject to NERC CIP or other industrial cybersecurity regulations should assess exposure and apply patches according to their change management procedures.
Technical summary
CVE-2022-42328 is a deadlock vulnerability in the Linux netback (xen-netback) driver that affects virtualized environments using Xen. The vulnerability was inadvertently introduced by the security patch for XSA-392, creating a race condition when freeing socket buffers (SKBs) of packets dropped during XSA-392 handling. A malicious or compromised guest virtual machine can trigger this deadlock, resulting in a denial-of-service condition. The vulnerability has a CVSS 3.1 score of 5.5 (MEDIUM) with a local attack vector, low attack complexity, and low privilege requirements. The primary impact is to availability (HIGH). Siemens has identified multiple SIMATIC and SIPLUS industrial communication processors as affected products, with firmware version 2.3 or later providing remediation.
Defensive priority
medium
Recommended defensive actions
- Apply vendor-provided firmware updates to version 2.3 or later for affected Siemens SIMATIC CP 1542SP-1, SIMATIC CP 1542SP-1 IRC, SIMATIC CP 1543SP-1, and SIPLUS ET 200SP CP products
- Review and implement CISA ICS recommended practices for defense-in-depth strategies in industrial control system environments
- Monitor for anomalous behavior in virtualized guest environments that may indicate exploitation attempts
- Consider network segmentation to limit exposure of vulnerable industrial control systems
- Evaluate the need for temporary workarounds if patches cannot be immediately applied, following organizational change management procedures
Evidence notes
The vulnerability description indicates this is a deadlock condition in the Linux netback driver introduced by a previous security patch (XSA-392). The source material from CISA CSAF advisory ICSA-24-165-10 identifies affected Siemens industrial control products. The CVSS vector indicates local attack vector with low attack complexity, requiring low privileges but no user interaction. The vulnerability results in high availability impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-42328 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-42328
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-42328 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-42328
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-165-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-625862.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-625862.html
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/pdf/ssa-625862.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/txt/ssa-625862.txt
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.