PatchSiren cyber security CVE debrief
CVE-2023-6237 Siemens CVE debrief
CVE-2023-6237 is a denial-of-service issue in OpenSSL RSA public key validation. When applications call EVP_PKEY_public_check() on RSA keys from an untrusted source, checking an excessively large invalid modulus can take a long time and create operational delays. Siemens mapped this issue to 19 SCALANCE W-series products in its 2025 advisory and recommends updating to V3.0.0 or later. The OpenSSL SSL/TLS implementation is not affected, but the OpenSSL pkey command-line tool is affected when used with -pubin and -check on untrusted data.
- Vendor
- Siemens
- Product
- SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0)
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-04-09
- Original CVE updated
- 2026-05-14
- Advisory published
- 2024-04-09
- Advisory updated
- 2026-05-14
Who should care
Operators and maintainers of the listed Siemens SCALANCE WAB/WAM/WUB/WUM devices, plus developers and administrators who rely on OpenSSL EVP_PKEY_public_check() or the pkey -pubin -check workflow for untrusted RSA public keys.
Technical summary
The issue is caused by expensive primality/compositeness checking during RSA public key validation. For valid RSA keys, the modulus is composite and the check finishes quickly; for an excessively large prime modulus, validation can take much longer than expected. The result is a denial-of-service condition via resource consumption or long delays, with impact limited to availability. Siemens’ CSAF advisory associates the issue with 19 product variants and points to a vendor fix at V3.0.0 or later.
Defensive priority
High for affected Siemens deployments that are still below V3.0.0; otherwise medium, because the issue is availability-focused and the affected OpenSSL paths are limited to explicit public-key checking workflows.
Recommended defensive actions
- Update affected Siemens SCALANCE products to V3.0.0 or later, as directed by the vendor advisory.
- Review any software that calls EVP_PKEY_public_check() and ensure untrusted RSA public keys are not validated on latency-sensitive or single-threaded paths.
- Avoid running OpenSSL pkey -pubin -check on untrusted input sources.
- Apply standard ICS defense-in-depth guidance for availability protection and input validation around externally supplied keys.
- Track the advisory revision history and re-verify deployed firmware or package versions after remediation.
Evidence notes
Source data indicates publication on 2025-02-11 and a later revision on 2025-05-06 for typo fixes. The Siemens/CISA advisory lists 19 affected SCALANCE product variants and recommends updating to V3.0.0 or later. The advisory text states that OpenSSL SSL/TLS is not affected, while the pkey command line application is affected when used with -pubin and -check on untrusted data. CVSS is 5.9/Medium with AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-6237 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-6237
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-6237 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-6237
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-044-09.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-769027.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-769027.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-09
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.