PatchSiren cyber security CVE debrief
CVE-2023-4807 Siemens CVE debrief
CVE-2023-4807 is a product-specific OpenSSL-related bug affecting Siemens SIDIS Prime deployments on Windows 64 when running on newer x86_64 processors that support AVX512-IFMA. The issue can corrupt application state because the POLY1305 path does not restore non-volatile XMM registers before returning, instead zeroing them. Impact depends on how the calling application uses those registers and whether an attacker can influence use of POLY1305/CHACHA20-POLY1305; vendor guidance says the most likely outcomes are incorrect results or a crash, and Siemens notes it is not aware of a concrete affected application.
- Vendor
- Siemens
- Product
- SIDIS Prime
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-12-12
- Original CVE updated
- 2025-08-12
- Advisory published
- 2023-12-12
- Advisory updated
- 2025-08-12
Who should care
Siemens SIDIS Prime operators, Windows 64 administrators, and developers who deploy SIDIS Prime or similar OpenSSL-based applications on AVX512-IFMA-capable x86_64 systems, especially where client input can influence whether CHACHA20-POLY1305 is negotiated or used.
Technical summary
The vulnerable code path is the OpenSSL POLY1305 MAC implementation used by SIDIS Prime. On Windows 64, for MAC calculations over 64 bytes on CPUs supporting AVX512-IFMA, the implementation fails to save and restore non-volatile XMM registers; before returning, the registers are zeroized instead of restored. Because the corruption affects internal application state rather than allowing attacker-controlled register contents, consequences are application-dependent and may range from no visible effect to incorrect computation, crash, or other process-level instability. The vendor states the FIPS provider is not affected.
Defensive priority
Medium
Recommended defensive actions
- Update Siemens SIDIS Prime to version V4.0.700 or later.
- If an immediate update is not possible, disable AVX512-IFMA support at runtime using the vendor-recommended OPENSSL_ia32cap=:~0x200000 setting.
- Inventory Windows 64 deployments that use OpenSSL on AVX512-IFMA-capable x86_64 processors and identify where clients can influence POLY1305 or CHACHA20-POLY1305 use.
- Validate application behavior after remediation, with attention to crashes or incorrect results that could indicate prior register-state dependency.
- Track the Siemens and CISA advisories for any follow-up guidance or scope clarification.
Evidence notes
Primary evidence comes from the CISA CSAF advisory ICSA-25-100-02 and Siemens advisory SSA-277137, both published on 2025-04-08 and revised on 2025-05-06 for typo fixes. The source states the issue is a POLY1305/OpenSSL bug on Windows 64 with AVX512-IFMA-capable x86_64 CPUs, recommends updating to V4.0.700 or later, and provides the OPENSSL_ia32cap workaround. The vendor notes that no concrete affected application is currently known, that the FIPS provider is not affected, and that practical impact is most likely incorrect results or denial of service. The supplied CVE metadata assigns CVSS 3.1 7.8/HIGH, while the vendor advisory characterizes real-world severity as low due to the narrow and application-dependent impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-4807 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-4807
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-4807 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-4807
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-100-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-277137.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-277137.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-100-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.