PatchSiren cyber security CVE debrief
CVE-2023-38380 Siemens CVE debrief
A memory management flaw in the webserver implementation of Siemens SIMATIC and SIPLUS communication processors allows remote, unauthenticated attackers to trigger denial-of-service conditions. The vulnerability stems from improper memory release after use, enabling network-based attackers to exhaust webserver resources without requiring credentials or user interaction. Published on June 11, 2024, this HIGH severity issue (CVSS 7.5) affects six industrial communication module variants used in OT environments. Siemens has released firmware updates to address the flaw.
- Vendor
- Siemens
- Product
- SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0)
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-06-11
- Original CVE updated
- 2024-06-11
- Advisory published
- 2024-06-11
- Advisory updated
- 2024-06-11
Who should care
Industrial control system operators, OT security teams, and manufacturing infrastructure managers deploying Siemens SIMATIC ET 200SP distributed I/O systems with affected communication processors. Organizations in critical manufacturing, energy, and process industries relying on these modules for PLC-to-network connectivity should prioritize patching.
Technical summary
The embedded webserver in affected Siemens SIMATIC CP and SIPLUS ET 200SP communication processors fails to properly deallocate memory after processing requests. This implementation flaw allows remote attackers to trigger cumulative memory exhaustion, resulting in webserver unavailability. The vulnerability is network-exploitable without authentication, presenting significant risk to OT environments where these modules provide Ethernet connectivity for distributed I/O systems. Attack vectors require only TCP/IP connectivity to the device's webserver port.
Defensive priority
high
Recommended defensive actions
- Apply Siemens firmware update to V2.3 or later for affected SIMATIC CP 1542SP-1, CP 1542SP-1 IRC, CP 1543SP-1, and SIPLUS ET 200SP variants
- Restrict network access to affected communication processors using firewall rules or network segmentation
- Monitor webserver availability and memory utilization on affected devices for signs of resource exhaustion
- Implement defense-in-depth strategies per CISA ICS recommended practices for industrial control systems
- Verify firmware version through Siemens Industry Online Support portal before and after remediation
Evidence notes
Memory exhaustion vulnerability in embedded webserver; no authentication required; affects industrial control system communication modules. CISA ICS advisory ICSA-24-165-10 coordinates with Siemens SSA-625862.
Official resources
-
CVE-2023-38380 CVE record
CVE.org
-
CVE-2023-38380 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2024-06-11