PatchSiren cyber security CVE debrief
CVE-2023-44321 Siemens CVE debrief
A low-severity denial-of-service vulnerability in Siemens SCALANCE and RUGGEDCOM industrial routers allows authenticated attackers to crash the web interface by submitting oversized input during configuration changes. The device requires a manual restart to restore web interface functionality. The vulnerability stems from improper input length validation in the web-based management interface.
- Vendor
- Siemens
- Product
- RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2)
- CVSS
- LOW 2.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-13
- Original CVE updated
- 2024-02-13
- Advisory published
- 2024-02-13
- Advisory updated
- 2024-02-13
Who should care
Industrial network administrators, OT security teams, and organizations operating Siemens SCALANCE M-800/MUM800/S615 or RUGGEDCOM RM1224 routers in manufacturing, energy, transportation, or critical infrastructure environments.
Technical summary
The vulnerability exists in the web management interface of affected Siemens industrial routers. When processing certain configuration changes, the interface fails to validate input length, allowing an authenticated attacker to submit oversized data that crashes the web server process. This results in loss of web-based management capability until the device is physically or remotely restarted. The attack requires network access to the web interface and valid administrative credentials. No code execution or persistent compromise is achieved; impact is limited to temporary loss of management interface availability.
Defensive priority
low
Recommended defensive actions
- Upgrade affected Siemens SCALANCE and RUGGEDCOM devices to firmware version 8.1 or later
- Restrict web interface access to trusted administrative hosts only
- Monitor for unexpected device restarts or web interface unavailability
- Apply defense-in-depth practices for industrial control systems per CISA guidance
- Review and validate input length restrictions in custom management interfaces
Evidence notes
CISA published advisory ICSA-24-228-01 on 2024-08-13, disclosing CVE-2023-44321. The vulnerability affects 24 Siemens industrial router products across the SCALANCE M-800, MUM800, and S615 families, plus the RUGGEDCOM RM1224. Siemens released firmware version 8.1 to address the issue. CVSS 3.1 score of 2.7 (Low) reflects the requirement for authenticated access and limited availability impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-44321 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-44321
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-44321 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-44321
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-228-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-087301.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-087301.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-228-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.