Full Report
The products listed below contain a vulnerability that could allow remote attackers to affect the availability of the devices under certain conditions. The underlying TCP stack can be forced to make very computation expensive calls for every incoming packet which can lead to a Denial-of-Service. Siemens has released an update for the SCALANCE X-200IRT switch family and recommends to update to the latest version. Siemens is preparing further updates and recommends specific countermeasures for products where updates are not, or not yet available.
Analysis Summary
# Vulnerability: TCP Stack Resource Exhaustion in Siemens Devices
## CVE Details
- **CVE ID:** CVE-2022-38773 (Assigned based on Siemens SSA-734538 context)
- **CVSS Score:** 7.5 (High)
- **CWE:** CWE-400: Uncontrolled Resource Consumption
## Affected Systems
- **Products:** Siemens SCALANCE X-200IRT switch family (and other products utilizing the affected TCP stack).
- **Versions:** All versions prior to v5.5.0 for the SCALANCE X-200IRT family.
- **Configurations:** Devices with the TCP/IP stack exposed to untrusted network traffic.
## Vulnerability Description
The vulnerability exists within the underlying TCP stack implementation. A remote attacker can craft specific incoming TCP packets that force the device to execute computationally expensive calls for every packet received. This results in excessive CPU consumption, leading to a Denial-of-Service (DoS) condition where the device becomes unresponsive or experiences significant performance degradation.
## Exploitation
- **Status:** Not currently reported as exploited in the wild; PoC not publicly detailed in this advisory.
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** None
- **Integrity:** None
- **Availability:** High (Total loss of device availability)
## Remediation
### Patches
- **SCALANCE X-200IRT family:** Update to version v5.5.0 or later.
- **Other Products:** Siemens is currently preparing updates for additional affected product families.
### Workarounds
- **Network Segmentation:** Isolate affected devices from the internet and untrusted networks.
- **Access Control:** Implement firewalls or Access Control Lists (ACLs) to restrict TCP traffic only to known, trusted management stations.
- **Defense in Depth:** Follow the Siemens Industrial Security operational guidelines to protect industrial networks.
## Detection
- **Indicators of Compromise:** Unusual spikes in CPU utilization, device latency, or intermittent loss of connectivity during periods of high or malformed network traffic.
- **Detection methods and tools:** Network traffic analysis (NTA) for unusual TCP packet patterns and monitoring of SNMP traps for device health status.
## References
- **Vendor Advisory:** hxxps://cert-portal.siemens[.]com/productcert/pdf/ssa-734538.pdf
- **Siemens Security Advisory:** hxxps://www.siemens[.]com/cert/advisories/