PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-38380 Siemens CVE debrief

A memory management flaw in the webserver implementation of Siemens SIMATIC and SIPLUS communication processors allows remote, unauthenticated attackers to trigger denial-of-service conditions. The vulnerability stems from improper memory release after use, enabling network-based attackers to exhaust webserver resources without requiring credentials or user interaction. Published on June 11, 2024, this HIGH severity issue (CVSS 7.5) affects six industrial communication module variants used in OT environments. Siemens has released firmware updates to address the flaw.

Vendor
Siemens
Product
SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0)
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2023-12-12
Original CVE updated
2024-03-12
Advisory published
2023-12-12
Advisory updated
2024-03-12

Who should care

Industrial control system operators, OT security teams, and manufacturing infrastructure managers deploying Siemens SIMATIC ET 200SP distributed I/O systems with affected communication processors. Organizations in critical manufacturing, energy, and process industries relying on these modules for PLC-to-network connectivity should prioritize patching.

Technical summary

The embedded webserver in affected Siemens SIMATIC CP and SIPLUS ET 200SP communication processors fails to properly deallocate memory after processing requests. This implementation flaw allows remote attackers to trigger cumulative memory exhaustion, resulting in webserver unavailability. The vulnerability is network-exploitable without authentication, presenting significant risk to OT environments where these modules provide Ethernet connectivity for distributed I/O systems. Attack vectors require only TCP/IP connectivity to the device's webserver port.

Defensive priority

high

Recommended defensive actions

  • Apply Siemens firmware update to V2.3 or later for affected SIMATIC CP 1542SP-1, CP 1542SP-1 IRC, CP 1543SP-1, and SIPLUS ET 200SP variants
  • Restrict network access to affected communication processors using firewall rules or network segmentation
  • Monitor webserver availability and memory utilization on affected devices for signs of resource exhaustion
  • Implement defense-in-depth strategies per CISA ICS recommended practices for industrial control systems
  • Verify firmware version through Siemens Industry Online Support portal before and after remediation

Evidence notes

Memory exhaustion vulnerability in embedded webserver; no authentication required; affects industrial control system communication modules. CISA ICS advisory ICSA-24-165-10 coordinates with Siemens SSA-625862.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-38380 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-38380

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-38380 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-38380

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-165-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-625862.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-625862.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/pdf/ssa-625862.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/txt/ssa-625862.txt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.