PatchSiren cyber security CVE debrief
CVE-2023-49441 Siemens CVE debrief
An integer overflow vulnerability in dnsmasq 2.9's forward_query function affects 26 Siemens SCALANCE and RUGGEDCOM router products. The flaw, published November 12, 2024, carries a HIGH severity CVSS 3.1 score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), indicating network-based attackers can trigger denial of service without authentication. Siemens has released firmware updates to address this issue.
- Vendor
- Siemens
- Product
- RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2)
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-11-12
- Original CVE updated
- 2025-05-06
- Advisory published
- 2024-11-12
- Advisory updated
- 2025-05-06
Who should care
Industrial control system operators, OT security teams, critical infrastructure defenders, and network administrators managing Siemens SCALANCE or RUGGEDCOM router deployments in manufacturing, energy, transportation, and other industrial environments.
Technical summary
The vulnerability exists in dnsmasq version 2.9 within the forward_query function, where an integer overflow can occur. This affects embedded dnsmasq implementations in Siemens industrial networking equipment. The CVSS vector indicates the attack vector is network-accessible, requires low attack complexity, no privileges, and no user interaction, resulting in high availability impact. Twenty-six distinct Siemens router products are affected across the SCALANCE M800/M800PB, M812, M816, M826, M874, M876, MUM853, MUM856 series, RUGGEDCOM RM1224, and SCALANCE S615 product lines.
Defensive priority
HIGH
Recommended defensive actions
- Update affected Siemens SCALANCE and RUGGEDCOM routers to firmware version 8.2 or later
- Verify dnsmasq component versions in deployed industrial routers
- Apply network segmentation for industrial control systems per CISA recommended practices
- Monitor for anomalous DNS query patterns that may indicate exploitation attempts
- Review Siemens security advisory SSA-354112 for additional product-specific guidance
Evidence notes
CISA ICS advisory ICSA-24-319-06 documents this vulnerability in Siemens SCALANCE M-800 family and related industrial routers. The advisory was revised May 6, 2025 to fix typos. The underlying dnsmasq 2.9 integer overflow in forward_query was disclosed with vendor fix availability.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-49441 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-49441
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-49441 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-49441
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-319-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-354112.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-354112.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.