PatchSiren cyber security CVE debrief
CVE-2023-38380 Siemens CVE debrief
A memory management flaw in the webserver implementation of Siemens SIMATIC and SIPLUS communication processors allows remote, unauthenticated attackers to trigger denial-of-service conditions. The vulnerability stems from improper memory release after use, enabling network-based attackers to exhaust webserver resources without requiring credentials or user interaction. Published on June 11, 2024, this HIGH severity issue (CVSS 7.5) affects six industrial communication module variants used in OT environments. Siemens has released firmware updates to address the flaw.
- Vendor
- Siemens
- Product
- SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0)
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-12-12
- Original CVE updated
- 2024-03-12
- Advisory published
- 2023-12-12
- Advisory updated
- 2024-03-12
Who should care
Industrial control system operators, OT security teams, and manufacturing infrastructure managers deploying Siemens SIMATIC ET 200SP distributed I/O systems with affected communication processors. Organizations in critical manufacturing, energy, and process industries relying on these modules for PLC-to-network connectivity should prioritize patching.
Technical summary
The embedded webserver in affected Siemens SIMATIC CP and SIPLUS ET 200SP communication processors fails to properly deallocate memory after processing requests. This implementation flaw allows remote attackers to trigger cumulative memory exhaustion, resulting in webserver unavailability. The vulnerability is network-exploitable without authentication, presenting significant risk to OT environments where these modules provide Ethernet connectivity for distributed I/O systems. Attack vectors require only TCP/IP connectivity to the device's webserver port.
Defensive priority
high
Recommended defensive actions
- Apply Siemens firmware update to V2.3 or later for affected SIMATIC CP 1542SP-1, CP 1542SP-1 IRC, CP 1543SP-1, and SIPLUS ET 200SP variants
- Restrict network access to affected communication processors using firewall rules or network segmentation
- Monitor webserver availability and memory utilization on affected devices for signs of resource exhaustion
- Implement defense-in-depth strategies per CISA ICS recommended practices for industrial control systems
- Verify firmware version through Siemens Industry Online Support portal before and after remediation
Evidence notes
Memory exhaustion vulnerability in embedded webserver; no authentication required; affects industrial control system communication modules. CISA ICS advisory ICSA-24-165-10 coordinates with Siemens SSA-625862.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-38380 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-38380
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-38380 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-38380
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-165-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-625862.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-625862.html
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/pdf/ssa-625862.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/txt/ssa-625862.txt
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.