PatchSiren cyber security CVE debrief
CVE-2023-27321 Siemens CVE debrief
A high-severity denial-of-service vulnerability in OPC Foundation UA .NET Standard's ConditionRefresh request handling allows unauthenticated remote attackers to exhaust server resources. The flaw, originally reported as ZDI-CAN-20505, affects Siemens TIM 1531 IRC industrial communication modules. Attackers can trigger resource exhaustion by sending a high volume of ConditionRefresh requests without authentication, causing complete service unavailability. Siemens has released firmware version 2.4.8 to address this vulnerability.
- Vendor
- Siemens
- Product
- SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0)
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-06-11
- Original CVE updated
- 2024-07-09
- Advisory published
- 2024-06-11
- Advisory updated
- 2024-07-09
Who should care
Organizations operating Siemens TIM 1531 IRC industrial communication modules in manufacturing, energy, water/wastewater, or other OT environments. Security teams responsible for OPC UA infrastructure and industrial control system availability. Asset owners requiring continuous operation of alarm and condition monitoring systems.
Technical summary
The vulnerability resides in OPC Foundation UA .NET Standard's implementation of the ConditionRefresh service, which allows clients to request updated status of active alarms and conditions. The implementation fails to properly limit resource consumption when processing these requests. An unauthenticated remote attacker can send a large number of ConditionRefresh requests to exhaust server memory, CPU, or connection resources, resulting in complete denial of service. The attack requires no authentication and has low complexity, making it suitable for automated exploitation. Affected Siemens products include SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) and TIM 1531 IRC (6GK7543-1MX00-0XE0) when running vulnerable OPC UA .NET Standard versions.
Defensive priority
high
Recommended defensive actions
- Apply vendor fix: Update affected Siemens TIM 1531 IRC devices to firmware version 2.4.8 or later
- Implement network segmentation to restrict OPC UA server access to authorized clients only
- Deploy rate limiting on OPC UA ConditionRefresh requests at network or application layer
- Monitor for anomalous volumes of ConditionRefresh requests as potential exploitation indicators
- Review and apply CISA ICS recommended practices for defense-in-depth strategies
- Validate that OPC UA servers implement proper resource quotas and connection limits
Evidence notes
CISA published advisory ICSA-24-165-06 on June 11, 2024, identifying this vulnerability in Siemens TIM 1531 IRC products. The underlying flaw exists in OPC Foundation UA .NET Standard's handling of ConditionRefresh requests. Siemens confirmed affected products and remediation in security advisory SSA-337522. CVSS 3.1 score of 7.5 reflects network attack vector, low complexity, no privileges required, and high availability impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-27321 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-27321
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-27321 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-27321
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-165-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-337522.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-337522.html
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/pdf/ssa-337522.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/txt/ssa-337522.txt
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.