PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-28450 Siemens CVE debrief

A vulnerability in Dnsmasq before version 2.90 affects Siemens SCALANCE M-800 family industrial routers. The default maximum EDNS.0 UDP packet size was incorrectly set to 4096 bytes instead of the recommended 1232 bytes per DNS Flag Day 2020 specifications. This misconfiguration can lead to DNS resolution failures or availability issues when communicating with DNS servers that enforce stricter packet size limits. The vulnerability has a CVSS 3.1 score of 7.5 (HIGH severity) with an attack vector of network-based, low attack complexity, and no required privileges or user interaction. The primary impact is to availability. Siemens has released firmware version 8.2 or later to address this issue across 26 affected product variants including RUGGEDCOM RM1224, SCALANCE M804PB, M812-1, M816-1, M826-2, M874-2, M874-3, M876-3, M876-4, MUM853-1, MUM856-1, and S615 series devices. CISA published advisory ICSA-24-319-06 on November 12, 2024, with a revision on May 6, 2025.

Vendor
Siemens
Product
RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2)
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-13
Original CVE updated
2024-02-13
Advisory published
2024-02-13
Advisory updated
2024-02-13

Who should care

Organizations operating Siemens SCALANCE M-800, RUGGEDCOM RM1224, or S615 series industrial routers in manufacturing, energy, transportation, and critical infrastructure sectors. Network administrators responsible for DNS infrastructure in OT/ICS environments. Security teams managing industrial control system asset inventory and patch management programs.

Technical summary

The vulnerability stems from Dnsmasq's default EDNS.0 UDP packet size of 4096 bytes, which exceeds the 1232-byte recommendation established by DNS Flag Day 2020. When Dnsmasq sends queries with large UDP payloads to DNS servers that enforce stricter limits or have path MTU issues, responses may be dropped or fragmented, causing DNS resolution failures. This affects availability of name resolution services on embedded devices using affected Dnsmasq versions. The Siemens SCALANCE M-800 family incorporates this vulnerable component, impacting industrial network infrastructure. Resolution requires firmware update to version 8.2 or later which incorporates Dnsmasq 2.90 or newer with corrected defaults.

Defensive priority

HIGH

Recommended defensive actions

  • Update affected Siemens SCALANCE M-800 family devices to firmware version 8.2 or later
  • Review DNS infrastructure for compatibility with EDNS.0 packet size limitations
  • Monitor DNS resolution performance and availability on affected industrial networks
  • Apply network segmentation for industrial control systems per CISA recommended practices
  • Verify DNS server configurations support fallback to TCP for large responses

Evidence notes

CVE published 2024-11-12; modified 2025-05-06. CISA CSAF advisory ICSA-24-319-06 published same date. Siemens SSA-354112 referenced as primary vendor advisory. CVSS 3.1 vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C. Affects 26 Siemens industrial router products. Vendor fix available: update to V8.2 or later.

Official resources

2024-11-12