PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-26554 Siemens CVE debrief

CVE-2023-26554 is an out-of-bounds write vulnerability in the mstolfp function within libntp/mstolfp.c in NTP 4.2.8p15. The flaw occurs when adding a null terminator character, potentially allowing an adversary to attack a client ntpq process. The vulnerability does not affect ntpd. Siemens SITOP UPS1600 devices incorporate affected NTP components and are exposed to this issue. CISA published advisory ICSA-24-165-05 on June 11, 2024, identifying this vulnerability in Siemens industrial control products. The vulnerability carries a MEDIUM severity CVSS 3.1 score of 5.6, reflecting network attack vector with high attack complexity, no required privileges or user interaction, and low impacts across confidentiality, integrity, and availability.

Vendor
Siemens
Product
SITOP UPS1600 10 A Ethernet/ PROFINET (6EP4134-3AB00-2AY0)
CVSS
MEDIUM 5.6
CISA KEV
Not listed in stored evidence
Original CVE published
2024-06-11
Original CVE updated
2024-06-11
Advisory published
2024-06-11
Advisory updated
2024-06-11

Who should care

Organizations operating Siemens SITOP UPS1600 uninterruptible power supply systems in industrial environments, particularly those with exposed NTP client services. OT security teams, ICS asset owners, and infrastructure operators relying on time synchronization for critical control systems should prioritize firmware updates.

Technical summary

The mstolfp function in NTP 4.2.8p15's libntp/mstolfp.c contains an out-of-bounds write when adding a null terminator. This vulnerability is exploitable against client ntpq processes but not against ntpd. Siemens SITOP UPS1600 10A, 20A, 40A, and EX 20A Ethernet/PROFINET models are affected. The vulnerability requires network access and high attack complexity, with no privileges or user interaction needed. Successful exploitation may result in low impact to confidentiality, integrity, and availability of the affected client process.

Defensive priority

medium

Recommended defensive actions

  • Update affected Siemens SITOP UPS1600 devices to firmware version V2.5.4 or later
  • Verify NTP client configurations and restrict ntpq access to authorized administrative hosts
  • Monitor for anomalous NTP client process behavior or unexpected terminations
  • Apply network segmentation to limit exposure of industrial control system NTP services
  • Review CISA ICS recommended practices for defense-in-depth strategies

Evidence notes

The vulnerability description is sourced from CISA CSAF advisory ICSA-24-165-05, which references Siemens security advisory SSA-238730. The affected products are SITOP UPS1600 Ethernet/PROFINET devices with specific model numbers. The CVSS vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L confirms network accessibility with high attack complexity. The vendor fix requires updating to firmware version V2.5.4 or later.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-26554 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-26554

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-26554 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-26554

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-165-05.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-238730.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-238730.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/pdf/ssa-238730.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/txt/ssa-238730.txt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-05

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.