PatchSiren cyber security CVE debrief
CVE-2023-28578 Siemens CVE debrief
CVE-2023-28578 is a critical memory-corruption vulnerability in Siemens Core Services affecting multiple SCALANCE W700 device models. Siemens and CISA describe the issue as occurring while executing the command for removing a single event listener. The advisory assigns a CVSS v3.1 score of 9.3 and recommends updating affected products to V3.0.0 or later.
- Vendor
- Siemens
- Product
- SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0)
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-02-11
- Original CVE updated
- 2025-05-06
- Advisory published
- 2025-02-11
- Advisory updated
- 2025-05-06
Who should care
OT and industrial network teams using Siemens SCALANCE WAB/WAM/WUB/WUM devices, especially operators, asset owners, and maintainers responsible for device firmware and access control.
Technical summary
The advisory states that Core Services can experience memory corruption when executing the command used to remove a single event listener. The supplied CVSS vector is AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, indicating severe impact once the vulnerable path is reached. The affected product set spans 19 Siemens SCALANCE device variants listed in the CSAF advisory.
Defensive priority
Critical. Treat as a high-priority remediation for affected deployments because the issue is scored 9.3/Critical and the vendor provides a firmware update path for all listed products.
Recommended defensive actions
- Update affected Siemens SCALANCE devices to V3.0.0 or later, per the vendor remediation guidance.
- Inventory SCALANCE WAB/WAM/WUB/WUM models and confirm whether any listed product IDs are deployed.
- Restrict and monitor local or administrative access paths to affected devices until patching is complete.
- Schedule firmware updates during a controlled maintenance window and verify backups or rollback plans before changes.
- Review Siemens and CISA advisory references for model-specific guidance and any additional operational notes.
Evidence notes
Source corpus points to the CISA CSAF advisory ICSA-25-044-09 and Siemens advisory SSA-769027. The source item was published on 2025-02-11 and revised on 2025-05-06 for typo fixes only. The advisory names 19 affected Siemens SCALANCE product variants and recommends upgrading to V3.0.0 or later. The supplied enrichment indicates no KEV listing and no known ransomware campaign use.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-28578 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-28578
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-28578 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-28578
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-044-09.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-769027.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-769027.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-09
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.