PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-44321 Siemens CVE debrief

A low-severity denial-of-service vulnerability in Siemens SCALANCE and RUGGEDCOM industrial routers allows authenticated attackers to crash the web interface by submitting oversized input during configuration changes. The device requires a manual restart to restore web interface functionality. The vulnerability stems from improper input length validation in the web-based management interface.

Vendor
Siemens
Product
RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2)
CVSS
LOW 2.7
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-13
Original CVE updated
2024-02-13
Advisory published
2024-02-13
Advisory updated
2024-02-13

Who should care

Industrial network administrators, OT security teams, and organizations operating Siemens SCALANCE M-800/MUM800/S615 or RUGGEDCOM RM1224 routers in manufacturing, energy, transportation, or critical infrastructure environments.

Technical summary

The vulnerability exists in the web management interface of affected Siemens industrial routers. When processing certain configuration changes, the interface fails to validate input length, allowing an authenticated attacker to submit oversized data that crashes the web server process. This results in loss of web-based management capability until the device is physically or remotely restarted. The attack requires network access to the web interface and valid administrative credentials. No code execution or persistent compromise is achieved; impact is limited to temporary loss of management interface availability.

Defensive priority

low

Recommended defensive actions

  • Upgrade affected Siemens SCALANCE and RUGGEDCOM devices to firmware version 8.1 or later
  • Restrict web interface access to trusted administrative hosts only
  • Monitor for unexpected device restarts or web interface unavailability
  • Apply defense-in-depth practices for industrial control systems per CISA guidance
  • Review and validate input length restrictions in custom management interfaces

Evidence notes

CISA published advisory ICSA-24-228-01 on 2024-08-13, disclosing CVE-2023-44321. The vulnerability affects 24 Siemens industrial router products across the SCALANCE M-800, MUM800, and S615 families, plus the RUGGEDCOM RM1224. Siemens released firmware version 8.1 to address the issue. CVSS 3.1 score of 2.7 (Low) reflects the requirement for authenticated access and limited availability impact.

Official resources

2024-08-13