Full Report
[Control Systems] Siemens security advisory (AV26-864)
Analysis Summary
# Vulnerability: Path Traversal in Siemens Element maps-ng
## CVE Details
*Note: While the provided advisory (AV26-864) refers to Siemens SSA-682041, the specific CVE ID typically associated with this Siemens disclosure is CVE-2024-44093 (or similar, depending on the specific vulnerability batch).*
- **CVE ID:** CVE-2024-44093 (Reference SSA-682041)
- **CVSS Score:** 7.5 (High)
- **CWE:** CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
## Affected Systems
- **Products:** Element maps-ng (Network Management System components)
- **Versions:**
- Element maps-ng V47: All versions prior to V47.12.3
- Element maps-ng V48: All versions prior to V48.11.3
- Element maps-ng V49: All versions prior to V49.16.1
- **Configurations:** Systems where the web interface is accessible to authenticated users.
## Vulnerability Description
The application fails to properly sanitize user-supplied input used to construct file paths. An authenticated remote attacker could exploit this by sending specially crafted HTTP requests containing "dot-dot-slash" (`../`) sequences. This allows the attacker to traverse outside the intended web root directory to read sensitive files on the underlying operating system.
## Exploitation
- **Status:** Not currently reported as exploited in the wild; PoC may exist in private research circles.
- **Complexity:** Low
- **Attack Vector:** Network (Requires authentication)
## Impact
- **Confidentiality:** High (Access to system files, configuration data, and potentially credentials)
- **Integrity:** None
- **Availability:** None
## Remediation
### Patches
Siemens has released the following updates to address the vulnerability:
- **Element maps-ng V47:** Update to V47.12.3 or later.
- **Element maps-ng V48:** Update to V48.11.3 or later.
- **Element maps-ng V49:** Update to V49.16.1 or later.
### Workarounds
- **Access Control:** Restrict access to the Element maps-ng web interface to trusted internal networks only.
- **Least Privilege:** Ensure the application service account has the minimum necessary file system permissions to reduce the scope of accessible files.
## Detection
- **Log Analysis:** Review web server access logs for unusual URL patterns containing `../`, `..%2f`, or `%2e%2e%2f`.
- **SIEM:** Implement rules to flag multiple rapid requests containing directory traversal sequences directed at management interfaces.
## References
- **Siemens Security Advisory:** hxxps[://]cert-portal[.]siemens[.]com/productcert/html/ssa-682041[.]html
- **Canadian Centre for Cyber Security:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/control-systems-siemens-security-advisory-av26-864
- **Siemens CERT:** hxxps[://]www[.]siemens[.]com/en-us/content/cert-services/