PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-38380 Siemens CVE debrief

A memory management flaw in the webserver implementation of Siemens SIMATIC and SIPLUS communication processors allows remote, unauthenticated attackers to trigger denial-of-service conditions. The vulnerability stems from improper memory release after use, enabling network-based attackers to exhaust webserver resources without requiring credentials or user interaction. Published on June 11, 2024, this HIGH severity issue (CVSS 7.5) affects six industrial communication module variants used in OT environments. Siemens has released firmware updates to address the flaw.

Vendor
Siemens
Product
SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0)
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-06-11
Original CVE updated
2024-06-11
Advisory published
2024-06-11
Advisory updated
2024-06-11

Who should care

Industrial control system operators, OT security teams, and manufacturing infrastructure managers deploying Siemens SIMATIC ET 200SP distributed I/O systems with affected communication processors. Organizations in critical manufacturing, energy, and process industries relying on these modules for PLC-to-network connectivity should prioritize patching.

Technical summary

The embedded webserver in affected Siemens SIMATIC CP and SIPLUS ET 200SP communication processors fails to properly deallocate memory after processing requests. This implementation flaw allows remote attackers to trigger cumulative memory exhaustion, resulting in webserver unavailability. The vulnerability is network-exploitable without authentication, presenting significant risk to OT environments where these modules provide Ethernet connectivity for distributed I/O systems. Attack vectors require only TCP/IP connectivity to the device's webserver port.

Defensive priority

high

Recommended defensive actions

  • Apply Siemens firmware update to V2.3 or later for affected SIMATIC CP 1542SP-1, CP 1542SP-1 IRC, CP 1543SP-1, and SIPLUS ET 200SP variants
  • Restrict network access to affected communication processors using firewall rules or network segmentation
  • Monitor webserver availability and memory utilization on affected devices for signs of resource exhaustion
  • Implement defense-in-depth strategies per CISA ICS recommended practices for industrial control systems
  • Verify firmware version through Siemens Industry Online Support portal before and after remediation

Evidence notes

Memory exhaustion vulnerability in embedded webserver; no authentication required; affects industrial control system communication modules. CISA ICS advisory ICSA-24-165-10 coordinates with Siemens SSA-625862.

Official resources

2024-06-11