PatchSiren cyber security CVE debrief
CVE-2023-50868 Siemens CVE debrief
CVE-2023-50868 is a HIGH severity (CVSS 7.5) denial-of-service vulnerability affecting Siemens SINEC INS. The issue stems from the Closest Encloser Proof mechanism in DNSSEC NSEC3 (RFC 5155) when RFC 9276 guidance is not followed. Remote attackers can exploit this via DNSSEC responses in a random subdomain attack, forcing the target to perform thousands of SHA-1 hash iterations and causing excessive CPU consumption. The vulnerability was published on November 12, 2024, with Siemens providing a vendor fix in V1.0 SP2 Update 3 or later. This is not a KEV-listed vulnerability and has no known ransomware campaign use.
- Vendor
- Siemens
- Product
- SINEC INS
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-11-12
- Original CVE updated
- 2024-11-12
- Advisory published
- 2024-11-12
- Advisory updated
- 2024-11-12
Who should care
Organizations running Siemens SINEC INS for industrial network management, OT security teams managing DNSSEC infrastructure, and defenders responsible for DNS availability in industrial control environments.
Technical summary
The vulnerability exists in the DNS protocol's NSEC3 implementation when RFC 9276 guidance is skipped. The Closest Encloser Proof algorithm in RFC 5155 requires iterative hash computations that can be exploited through malicious DNSSEC responses. Attackers using random subdomain attacks can force targets to perform thousands of SHA-1 iterations, resulting in CPU exhaustion and denial of service. This affects Siemens SINEC INS industrial network management software.
Defensive priority
HIGH
Recommended defensive actions
- Update Siemens SINEC INS to V1.0 SP2 Update 3 or later version per vendor guidance
- Monitor DNS query patterns for signs of random subdomain attacks targeting DNSSEC infrastructure
- Apply network segmentation for industrial control systems per CISA ICS recommended practices
- Review DNSSEC configuration to ensure RFC 9276 guidance is implemented where applicable
Evidence notes
CVE published 2024-11-12. CISA CSAF advisory ICSA-24-319-08 confirms Siemens SINEC INS affected. Vendor fix available in V1.0 SP2 Update 3.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-50868 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-50868
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-50868 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-50868
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-319-08.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-915275.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-915275.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-08
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.