PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-50868 Siemens CVE debrief

CVE-2023-50868 is a HIGH severity (CVSS 7.5) denial-of-service vulnerability affecting Siemens SINEC INS. The issue stems from the Closest Encloser Proof mechanism in DNSSEC NSEC3 (RFC 5155) when RFC 9276 guidance is not followed. Remote attackers can exploit this via DNSSEC responses in a random subdomain attack, forcing the target to perform thousands of SHA-1 hash iterations and causing excessive CPU consumption. The vulnerability was published on November 12, 2024, with Siemens providing a vendor fix in V1.0 SP2 Update 3 or later. This is not a KEV-listed vulnerability and has no known ransomware campaign use.

Vendor
Siemens
Product
SINEC INS
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-11-12
Original CVE updated
2024-11-12
Advisory published
2024-11-12
Advisory updated
2024-11-12

Who should care

Organizations running Siemens SINEC INS for industrial network management, OT security teams managing DNSSEC infrastructure, and defenders responsible for DNS availability in industrial control environments.

Technical summary

The vulnerability exists in the DNS protocol's NSEC3 implementation when RFC 9276 guidance is skipped. The Closest Encloser Proof algorithm in RFC 5155 requires iterative hash computations that can be exploited through malicious DNSSEC responses. Attackers using random subdomain attacks can force targets to perform thousands of SHA-1 iterations, resulting in CPU exhaustion and denial of service. This affects Siemens SINEC INS industrial network management software.

Defensive priority

HIGH

Recommended defensive actions

  • Update Siemens SINEC INS to V1.0 SP2 Update 3 or later version per vendor guidance
  • Monitor DNS query patterns for signs of random subdomain attacks targeting DNSSEC infrastructure
  • Apply network segmentation for industrial control systems per CISA ICS recommended practices
  • Review DNSSEC configuration to ensure RFC 9276 guidance is implemented where applicable

Evidence notes

CVE published 2024-11-12. CISA CSAF advisory ICSA-24-319-08 confirms Siemens SINEC INS affected. Vendor fix available in V1.0 SP2 Update 3.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-50868 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-50868

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-50868 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-50868

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-319-08.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-915275.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-915275.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-08

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.