Full Report
Intel has published information on vulnerabilities in Intel products in June 2021. This advisory lists the related Siemens Industrial products affected by these vulnerabilities that can be patched by applying the corresponding BIOS update. In this advisory we summarize: “2021.1 IPU – Intel® CSME, SPS and LMS Advisory” Intel-SA-00459, “2021.1 IPU – BIOS Advisory” Intel-SA-00463, “2021.1 IPU – Intel® Processor Advisory” Intel-SA-00464, and “2021.1 IPU - Intel Atom® Processor Advisory” Intel-SA-00465. Siemens has released updates for several affected products and is currently working on BIOS updates that include chipset microcode updates for further products.
Analysis Summary
# Vulnerability: June 2021 Intel IPU (Intel Platform Update) affecting Siemens Industrial Products
## CVE Details
*This advisory covers multiple CVEs bundled in the 2021.1 IPU. Key highlights include:*
* **CVE-2020-24586, CVE-2020-24587, CVE-2020-24588** (CSME/SPS)
* **CVE-2020-24511, CVE-2020-24512** (Processor Microcode)
* **CVSS Score:** Up to **8.2** (High) - *Score varies by specific CVE*
* **CWE:** CWE-20 (Improper Input Validation), CWE-125 (Out-of-bounds Read), CWE-287 (Improper Authentication)
## Affected Systems
* **Products:** Siemens SIMATIC Industrial PCs (IPC), SIMATIC Field PGs, SINUMERIK Control Units, and SIMOTION P320.
* **Specific Models (Partial List):**
* SIMATIC IPC227E / IPC277E
* SIMATIC IPC427E / IPC477E
* SIMATIC IPC627E / IPC677E / IPC827E
* SIMATIC Field PG M5 / M6
* SINUMERIK MC / ONE / 840D sl
* **Versions:** All BIOS versions prior to the 2021.1 IPU integration.
* **Configurations:** Systems utilizing Intel Converged Security and Management Engine (CSME), Server Platform Services (SPS), Local Manageability Service (LMS), and affected Intel Processors (including Core and Atom families).
## Vulnerability Description
The 2021.1 Intel Platform Update (IPU) addresses four main areas of concern:
1. **Intel-SA-00459 (CSME/SPS/LMS):** Multiple security vulnerabilities in Intel CSME and SPS may allow for escalation of privilege, information disclosure, or denial of service.
2. **Intel-SA-00463 (BIOS):** Vulnerabilities in the BIOS firmware may allow escalation of privilege or denial of service.
3. **Intel-SA-00464 & SA-00465 (Processor/Atom):** Flaws in processor microcode, such as improper hardware bus locking or speculative execution side-channels, could lead to information disclosure or denial of service.
## Exploitation
* **Status:** Not widely exploited in the wild at the time of advisory release; however, technical details for some microcode flaws are publicly known.
* **Complexity:** Medium to High (Many flaws require local access or specific hardware states).
* **Attack Vector:** Primarily **Local** or **Adjacent** (some LMS vulnerabilities may involve network components).
## Impact
* **Confidentiality:** High (Potential for sensitive data leakage via side-channel attacks).
* **Integrity:** High (Potential for unauthorized privilege escalation to BIOS/SMM levels).
* **Availability:** High (Potential for system crashes or permanent denial of service).
## Remediation
### Patches
* **BIOS Updates:** Siemens is releasing updated BIOS versions for each specific IPC and Controller model. Users must visit the Siemens Online Support (SIOS) portal, search for their specific hardware model, and download the latest BIOS update containing the "Intel 2021.1 IPU" fixes.
### Workarounds
* Minimize network exposure for industrial control systems.
* Ensure the "Principle of Least Privilege" is applied to all users accessing the affected IPCs to prevent local exploitation of microcode flaws.
* Disable Intel AMT/LMS features if they are not required for operational needs.
## Detection
* **Indicators of Compromise:** Unusual system instability, unexpected BIOS setting changes, or unauthorized privilege escalation events.
* **Detection methods:** Utilize the **Intel CSME Detection Tool** to verify if the management engine is vulnerable. Check BIOS version strings against the Siemens compatibility matrix.
## References
* Siemens Security Advisory SSA-301220: hxxps[://]cert-portal[.]siemens[.]com/productcert/pdf/ssa-301220[.]pdf
* Intel-SA-00459: hxxps[://]www[.]intel[.]com/content/www/us/en/security-center/advisory/intel-sa-00459[.]html
* Intel-SA-00463: hxxps[://]www[.]intel[.]com/content/www/us/en/security-center/advisory/intel-sa-00463[.]html
* Intel-SA-00464: hxxps[://]www[.]intel[.]com/content/www/us/en/security-center/advisory/intel-sa-00464[.]html