PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-35829 Siemens CVE debrief

A use-after-free vulnerability exists in the Rockchip VDEC driver (rkvdec) within the Linux kernel before version 6.3.2. The flaw occurs in the rkvdec_remove function located at drivers/staging/media/rkvdec/rkvdec.c. This vulnerability has been identified as affecting Siemens industrial control system products, specifically the TIM 1531 IRC communication modules used in industrial automation environments. The use-after-free condition could potentially allow an attacker with local access to execute arbitrary code or cause a denial of service condition. The vulnerability was published on June 11, 2024, and subsequently modified on July 9, 2024, with the modification reflecting updates to related CVE-2023-27321 information in the source advisory. Siemens has released a vendor fix requiring update to version 2.4.8 or later.

Vendor
Siemens
Product
SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0)
CVSS
HIGH 7
CISA KEV
Not listed in stored evidence
Original CVE published
2024-06-11
Original CVE updated
2024-07-09
Advisory published
2024-06-11
Advisory updated
2024-07-09

Who should care

Organizations operating Siemens TIM 1531 IRC industrial communication modules in critical infrastructure environments, including utilities, transportation, and manufacturing sectors. Security teams responsible for industrial control system (ICS) asset management and vulnerability remediation. System integrators deploying Siemens telecontrol solutions should prioritize firmware updates. Organizations subject to NERC CIP or other critical infrastructure cybersecurity regulations should assess exposure and document remediation timelines.

Technical summary

The vulnerability is a use-after-free in the rkvdec_remove function of the Rockchip VDEC driver in Linux kernel versions prior to 6.3.2. The rkvdec driver is part of the staging media subsystem and handles video decoding for Rockchip SoCs. A use-after-free in the remove path suggests that during driver unbinding or device removal, a memory resource may be accessed after it has been freed, potentially leading to memory corruption. In the context of Siemens TIM 1531 IRC devices, which are industrial telecontrol modules used for remote monitoring and control in critical infrastructure, this kernel-level vulnerability could be exploited if an attacker has local access to the underlying Linux-based system. The CVSS score of 7.0 (HIGH) reflects significant impact potential despite the local attack vector and high attack complexity. The vendor fix requires updating affected devices to firmware version 2.4.8 or later, available through the Siemens Industry Online Support portal.

Defensive priority

HIGH

Recommended defensive actions

  • Apply vendor-provided firmware update to version 2.4.8 or later for affected Siemens TIM 1531 IRC devices
  • Verify current firmware version on deployed SIPLUS TIM 1531 IRC and TIM 1531 IRC modules
  • Implement network segmentation for industrial control systems to limit exposure of affected devices
  • Follow CISA ICS recommended practices for defense-in-depth strategies
  • Monitor Siemens ProductCERT portal for additional security updates related to SSA-337522

Evidence notes

The vulnerability description is sourced from CISA ICS Advisory ICSA-24-165-06, which references Siemens Security Advisory SSA-337522. The affected products are SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) and TIM 1531 IRC (6GK7543-1MX00-0XE0). The CVSS 3.1 vector indicates local attack vector with high attack complexity, requiring low privileges but no user interaction, with high impact across confidentiality, integrity, and availability. The remediation specifies update to V2.4.8 or later version with reference to Siemens support portal.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-35829 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-35829

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-35829 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-35829

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-165-06.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-337522.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-337522.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/pdf/ssa-337522.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/txt/ssa-337522.txt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-06

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.