PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-38545 Siemens CVE debrief

CVE-2023-38545 is a critical heap-based buffer overflow in curl/libcurl's SOCKS5 proxy handshake path. If a handshake is slow and curl mis-evaluates whether the proxy should resolve a hostname, it can copy an overlong hostname into a heap buffer instead of only the resolved address. The CVSS v3.1 score is 9.8, reflecting network reachability, no privileges or user interaction, and high impact.

Vendor
Siemens
Product
Desigo CC family V6
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-06-10
Original CVE updated
2026-05-14
Advisory published
2025-06-10
Advisory updated
2026-05-14

Who should care

Teams running curl/libcurl directly, and vendors or application owners shipping products that embed libcurl, should care most. Risk is highest where SOCKS5 proxying is enabled or where downstream packages inherit the vulnerable library build.

Technical summary

The flaw is a CWE-787 out-of-bounds write in curl's SOCKS5 proxy handshake logic. According to the CVE description, hostnames longer than 255 bytes should trigger local name resolution, but during a slow handshake a local variable controlling that choice could take the wrong value. When that happens, curl may copy the too-long hostname into a heap-based target buffer instead of the resolved address, creating a remote heap buffer overflow. NVD lists affected libcurl versions from 7.69.0 up to, but not including, 8.4.0, and also includes several downstream products and operating system builds that bundle vulnerable curl components.

Defensive priority

Urgent. This is a remotely reachable, unauthenticated, no-user-interaction memory corruption issue with critical impact potential.

Recommended defensive actions

  • Upgrade curl/libcurl to 8.4.0 or later in all directly managed systems.
  • Patch or replace downstream products and OS packages that bundle affected libcurl builds.
  • Inventory where SOCKS5 proxy support is used, since that is the vulnerable handshake path described in the CVE.
  • Validate vendor advisories and package notices for embedded curl updates before assuming a system is safe.
  • Monitor for unexpected crashes or instability in applications that use libcurl through proxy connections.

Evidence notes

The CVE was published on 2023-10-18 and later modified on 2026-05-12 in the supplied NVD record. The supplied NVD data describes the issue as a heap-based buffer overflow in curl's SOCKS5 proxy handshake and marks libcurl 7.69.0 through 8.3.x as affected, with 8.4.0 as the exclusion boundary. No KEV listing was supplied.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-38545 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-38545

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-38545 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-38545

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-043-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-507364.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-507364.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.