PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-5717 Siemens CVE debrief

CVE-2023-5717 is a high-severity Linux kernel performance events (perf) vulnerability that Siemens lists as affecting multiple SCALANCE WAB/WAM/WUB/WUM products. The issue is a heap out-of-bounds write in perf_read_group() that can lead to local privilege escalation. Siemens and CISA published the advisory on 2025-02-11 and later revised it on 2025-05-06 for typos; the remediation is to update to V3.0.0 or later.

Vendor
Siemens
Product
SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0)
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-12
Original CVE updated
2026-02-25
Advisory published
2025-08-12
Advisory updated
2026-02-25

Who should care

Operators, maintainers, and security teams responsible for the affected Siemens SCALANCE wireless devices should prioritize this advisory, especially where local user access or device shell access is possible. Industrial environments that allow shared access, maintenance accounts, or field-service workflows should pay particular attention because the underlying flaw can be used for local privilege escalation.

Technical summary

The vulnerability is described as a heap out-of-bounds write in the Linux kernel's perf subsystem. According to the advisory, if perf_read_group() is called when an event's sibling_list is smaller than its child's sibling_list, the code can increment or write beyond the allocated buffer. The source material states this can be exploited for local privilege escalation. Siemens maps the issue to 19 SCALANCE product variants and recommends upgrading past the fixed release.

Defensive priority

High. The advisory describes a local privilege-escalation path with CVSS 7.8 (HIGH), and Siemens provides a vendor fix. Systems that expose local access paths should be updated promptly.

Recommended defensive actions

  • Upgrade affected Siemens SCALANCE products to V3.0.0 or later, as recommended in the advisory.
  • Inventory the listed SCALANCE models and confirm whether any deployed devices match the affected product IDs or product names.
  • Restrict local access to the affected devices as a compensating control until patching is complete.
  • Review maintenance, service, and shared-access workflows for unnecessary local accounts or interactive access on affected devices.
  • Validate remediation against the Siemens advisory and associated CISA bulletin before returning devices to service.

Evidence notes

Source material identifies CVE-2023-5717 as a Linux kernel perf heap out-of-bounds write and states it can enable local privilege escalation. The Siemens/CISA CSAF advisory (ICSA-25-044-09 / SSA-769027) lists 19 affected SCALANCE products and recommends updating to V3.0.0 or later. Published and modified dates used here come from the supplied CVE and advisory timeline: 2025-02-11 and 2025-05-06.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-5717 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-5717

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-5717 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-5717

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-044-09.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-769027.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-769027.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-09

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.