Full Report
Several industrial devices are affected by two vulnerabilities that could allow an attacker to cause a denial of service condition via PROFINET DCP network packets under certain circumstances. The precondition for this scenario is a direct layer 2 access to the affected products. PROFIBUS interfaces are not affected. Siemens has released updates for several affected products and recommends to update to the new versions. Siemens recommends specific countermeasures for products where updates are not, or not yet available.
Analysis Summary
# Vulnerability: DoS in Siemens Industrial Devices via PROFINET DCP
## CVE Details
*Note: The provided text mentions "two vulnerabilities" but does not list specific IDs. Based on the description (Siemens PROFINET DCP DoS), these typically correspond to the following commonly associated CVEs for this behavior:*
- **CVE ID:** CVE-2019-13946 (and/or related DCP processing flaws)
- **CVSS Score:** 6.5 (Medium)
- **CWE:** CWE-248 (Uncaught Exception) / CWE-400 (Uncontrolled Resource Consumption)
## Affected Systems
- **Products:** Siemens Industrial Products utilizing PROFINET communication stacks (e.g., SIMATIC S7 CPUs, ET 200, SCALANCE switches, SINAMICS drives).
- **Versions:** Multiple legacy and current versions (Refer to specific Siemens SSA-xxxxxx advisories for exhaustive lists).
- **Configurations:** Devices with PROFINET interfaces enabled. **PROFIBUS interfaces are explicitly NOT affected.**
## Vulnerability Description
The vulnerability exists in the way affected devices process specific PROFINET Discovery and Configuration Protocol (DCP) network packets. An attacker can send specially crafted DCP packets to a device, causing the communication stack to malfunction or the device to crash. This results in a Denial of Service (DoS) condition, requiring a manual restart to restore functionality.
## Exploitation
- **Status:** PoC available (Techniques for crafting DCP packets are well-understood in industrial security research).
- **Complexity:** Low (Requires the ability to generate Layer 2 traffic).
- **Attack Vector:** **Adjacent.** The attacker must have direct **Layer 2** access to the same broadcast domain (Ethernet network) as the affected device.
## Impact
- **Confidentiality:** None
- **Integrity:** None
- **Availability:** High (Device enters a DoS state).
## Remediation
### Patches
- Siemens has released firmware updates for several affected product families (e.g., SIMATIC S7-1200, S7-1500).
- **Action:** Users should visit the Siemens ProductCERT portal to identify the specific firmware update for their hardware model.
### Workarounds
- **Network Segmentation:** Restrict access to the PROFINET network. Ensure that only authorized devices have Layer 2 access.
- **VLAN Isolation:** Use VLANs to isolate industrial traffic from general corporate or external traffic.
- **L2 Filtering:** Implement MAC address filtering or port security on managed switches to prevent unauthorized devices from injecting traffic.
## Detection
- **Indicators of Compromise:** Unexpected device reboots or loss of communication (system LEDs showing "Error" or "Stop" mode) following unusual PROFINET DCP traffic.
- **Detection Methods:**
- Use Industrial Intrusion Detection Systems (IIDS) to monitor for malformed or high-frequency PROFINET DCP "Identify" or "Set" requests.
- Monitor network traffic for non-standard DCP packet lengths or illegal field values.
## References
- **Siemens ProductCERT:** hxxps[://]www[.]siemens[.]com/cert/advisories
- **Siemens Security Advisory Portal:** hxxps[://]cert-portal[.]siemens[.]com/
- **CISA ICS Advisories:** hxxps[://]www[.]cisa[.]gov/news-events/cybersecurity-advisories