PatchSiren cyber security CVE debrief
CVE-2022-45919 Siemens CVE debrief
A use-after-free vulnerability exists in the Linux kernel's DVB CA EN50221 driver (drivers/media/dvb-core/dvb_ca_en50221.c) through version 6.0.10. The flaw occurs when a disconnect happens after an open operation, due to the absence of a wait_event synchronization mechanism. This vulnerability affects Siemens TIM 1531 IRC industrial communication devices, which incorporate the vulnerable Linux kernel component. The issue was disclosed publicly on June 11, 2024, through CISA ICS advisory ICSA-24-165-06, though the underlying kernel vulnerability dates to 2022. Siemens has released firmware updates to address this issue in affected products.
- Vendor
- Siemens
- Product
- SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0)
- CVSS
- HIGH 7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-13
- Original CVE updated
- 2024-02-13
- Advisory published
- 2024-02-13
- Advisory updated
- 2024-02-13
Who should care
Organizations operating Siemens TIM 1531 IRC industrial communication modules, particularly in critical infrastructure and manufacturing environments. System administrators responsible for Linux-based industrial control systems and OT security teams monitoring kernel-level vulnerabilities in embedded industrial devices.
Technical summary
The vulnerability exists in the DVB CA (Common Interface) EN50221 driver within the Linux kernel media subsystem. The driver fails to properly synchronize between open and disconnect operations, lacking a wait_event call that would prevent race conditions. When a disconnect occurs after an open operation, the driver may access freed memory, resulting in a use-after-free condition. This vulnerability is exploitable with local access and low privileges, with high impact to confidentiality, integrity, and availability. The CVSS 3.1 vector indicates attack complexity is high due to race condition requirements, but successful exploitation yields complete system compromise.
Defensive priority
HIGH
Recommended defensive actions
- Apply vendor firmware update to version V2.4.8 or later for affected Siemens TIM 1531 IRC devices
- Review and implement CISA ICS recommended practices for industrial control system security
- Monitor Siemens ProductCERT portal for additional security advisories related to TIM 1531 IRC products
- Assess network segmentation to limit exposure of affected industrial communication devices
- Verify kernel version in use and ensure timely patching of Linux-based industrial systems
Evidence notes
The vulnerability is documented in CISA CSAF advisory ICSA-24-165-06, which references Siemens security advisory SSA-337522. The flaw stems from missing wait_event synchronization in the DVB CA EN50221 kernel driver, allowing use-after-free conditions during disconnect-after-open sequences.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-45919 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-45919
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-45919 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-45919
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-165-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-337522.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-337522.html
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/pdf/ssa-337522.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/txt/ssa-337522.txt
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.