PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-27321 Siemens CVE debrief

A high-severity denial-of-service vulnerability in OPC Foundation UA .NET Standard's ConditionRefresh request handling allows unauthenticated remote attackers to exhaust server resources. The flaw, originally reported as ZDI-CAN-20505, affects Siemens TIM 1531 IRC industrial communication modules. Attackers can trigger resource exhaustion by sending a high volume of ConditionRefresh requests without authentication, causing complete service unavailability. Siemens has released firmware version 2.4.8 to address this vulnerability.

Vendor
Siemens
Product
SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0)
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-06-11
Original CVE updated
2024-07-09
Advisory published
2024-06-11
Advisory updated
2024-07-09

Who should care

Organizations operating Siemens TIM 1531 IRC industrial communication modules in manufacturing, energy, water/wastewater, or other OT environments. Security teams responsible for OPC UA infrastructure and industrial control system availability. Asset owners requiring continuous operation of alarm and condition monitoring systems.

Technical summary

The vulnerability resides in OPC Foundation UA .NET Standard's implementation of the ConditionRefresh service, which allows clients to request updated status of active alarms and conditions. The implementation fails to properly limit resource consumption when processing these requests. An unauthenticated remote attacker can send a large number of ConditionRefresh requests to exhaust server memory, CPU, or connection resources, resulting in complete denial of service. The attack requires no authentication and has low complexity, making it suitable for automated exploitation. Affected Siemens products include SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) and TIM 1531 IRC (6GK7543-1MX00-0XE0) when running vulnerable OPC UA .NET Standard versions.

Defensive priority

high

Recommended defensive actions

  • Apply vendor fix: Update affected Siemens TIM 1531 IRC devices to firmware version 2.4.8 or later
  • Implement network segmentation to restrict OPC UA server access to authorized clients only
  • Deploy rate limiting on OPC UA ConditionRefresh requests at network or application layer
  • Monitor for anomalous volumes of ConditionRefresh requests as potential exploitation indicators
  • Review and apply CISA ICS recommended practices for defense-in-depth strategies
  • Validate that OPC UA servers implement proper resource quotas and connection limits

Evidence notes

CISA published advisory ICSA-24-165-06 on June 11, 2024, identifying this vulnerability in Siemens TIM 1531 IRC products. The underlying flaw exists in OPC Foundation UA .NET Standard's handling of ConditionRefresh requests. Siemens confirmed affected products and remediation in security advisory SSA-337522. CVSS 3.1 score of 7.5 reflects network attack vector, low complexity, no privileges required, and high availability impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-27321 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-27321

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-27321 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-27321

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-165-06.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-337522.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-337522.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/pdf/ssa-337522.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/txt/ssa-337522.txt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-06

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.