PatchSiren cyber security CVE debrief
CVE-2023-52891 Siemens CVE debrief
A vulnerability in Unified Automation's .NET-based OPC UA Server SDK (versions prior to 3.2.2), as used in multiple Siemens industrial products, can allow an attacker to cause high CPU load and memory exhaustion, potentially blocking server operations. The issue is related to CVE-2023-27321 affecting the OPC Foundation UA .NET Standard implementation. The vulnerability was published on July 9, 2024, with the advisory last modified on May 6, 2025. Siemens has released patches for some affected products, while others have no planned fix.
- Vendor
- Siemens
- Product
- SIMATIC Energy Manager Basic
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-07-09
- Original CVE updated
- 2025-05-06
- Advisory published
- 2024-07-09
- Advisory updated
- 2025-05-06
Who should care
Organizations operating Siemens SIMATIC Energy Manager, SIMATIC IPC diagnostic tools, or SIMIT simulation software with OPC UA server functionality enabled. Industrial control system operators in manufacturing, energy, and process industries relying on these products for operations or diagnostics.
Technical summary
The vulnerability stems from the Unified Automation .NET-based OPC UA Server SDK before version 3.2.2, which is incorporated into Siemens SIMATIC Energy Manager Basic, SIMATIC Energy Manager PRO, SIMATIC IPC DiagBase, SIMATIC IPC DiagMonitor, SIMIT V10, and SIMIT V11. A successful attack can trigger a high-load situation leading to memory exhaustion and server blocking. The issue is analogous to CVE-2023-27321 in the OPC Foundation UA .NET Standard implementation. CVSS 3.1 score: 5.3 (Medium).
Defensive priority
medium
Recommended defensive actions
- For SIMIT V11: Update to version 11.1 or later
- For SIMATIC Energy Manager Basic/PRO: Update to version 7.5 or later
- For SIMATIC IPC DiagBase, SIMATIC IPC DiagMonitor, and SIMIT V10: No vendor fix is planned; apply compensating controls
- Disable the OPC UA server if it is not required
- Restrict OPC UA interface access to trusted clients only
- Monitor OPC UA servers for anomalous memory consumption or connection patterns
- Implement network segmentation to limit OPC UA exposure
- Apply defense-in-depth strategies per CISA ICS recommended practices
Evidence notes
CVE published 2024-07-09; modified 2025-05-06. CISA ICS advisory ICSA-24-193-07. Siemens security advisory SSA-088132. CVSS 5.3 (Medium). Not in CISA KEV.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-52891 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-52891
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-52891 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-52891
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-193-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-088132.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-088132.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-193-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.