Full Report
CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
Analysis Summary
# Vulnerability: Zlib and Foxit Vulnerabilities in CADRA
## CVE Details
- **CVE ID:** CVE-2023-45853, CVE-2022-37434, CVE-2018-25032, CVE-2017-14919, CVE-2016-9842, CVE-2016-9841, CVE-2016-9840, CVE-2005-2096, CVE-2025-10585, CVE-2025-13223, CVE-2026-22184
- **CVSS Score:** Up to 9.8 (Critical)
- **CWE:** CWE-20 (Improper Input Validation), CWE-190 (Integer Overflow), CWE-843 (Type Confusion), CWE-787 (Out-of-bounds Write), CWE-1335
## Affected Systems
- **Products:** Siemens CADRA
- **Versions:**
- All versions < V2511 (Affected by legacy zlib/Node.js CVEs)
- All versions (Affected by Foxit/Chrome V8 and recent zlib CVEs)
- **Configurations:** Systems processing untrusted compressed streams, PNG files, or accessing external web content.
## Vulnerability Description
CADRA integrates third-party components, specifically **zlib** and **Foxit**, which contain multiple security flaws.
- **zlib Flaws:** Include heap-based buffer overflows (MiniZip), integer overflows, and improper pointer arithmetic. These allow for memory corruption when processing malformed ZIP archives or compressed streams.
- **Foxit/Chrome V8 Flaws:** (CVE-2025-10585, CVE-2025-13223) Type confusion vulnerabilities in the V8 engine that can lead to heap corruption and potential arbitrary code execution when rendering crafted HTML content.
- **Utility Flaws:** CVE-2026-22184 involves an out-of-bounds write in the `untgz` demonstration utility via long archive names.
## Exploitation
- **Status:** PoC available for several older zlib CVEs; Foxit/V8 vulnerabilities are typically high-value targets for exploitation.
- **Complexity:** Low to High (Depending on the specific CVE).
- **Attack Vector:** Network (Remote attackers can trigger flaws via malicious files or web content).
## Impact
- **Confidentiality:** High (Potential for memory disclosure and code execution).
- **Integrity:** High (Potential for unauthorized data modification).
- **Availability:** High (Denial of Service via application crashes).
## Remediation
### Patches
- **CADRA V2511 or later:** Addresses the primary set of legacy zlib and Node.js vulnerabilities.
- **Future Fixes:** Siemens is currently preparing further updates to address the 2025 and 2026 CVEs (Foxit/V8 and latest zlib issues).
### Workarounds
- **Web Access Restriction:** Block access to untrusted or external web content from sensitive systems to mitigate CVE-2025-10585 and CVE-2025-13223.
- **Network Isolation:** Protect network access to devices and follow Siemens' operational guidelines for Industrial Security.
## Detection
- **Indicators of Compromise:** Unusual application crashes when opening specific file types (PNG, ZIP, TGZ) or browsing internal help/web interfaces.
- **Detection methods:** Use vulnerability scanners to identify outdated CADRA installations (< V2511) and monitor for unauthorized outbound traffic to untrusted domains from CADRA workstations.
## References
- **Vendor Advisory:** hxxps://cert-portal[.]siemens[.]com/productcert/html/ssa-470355[.]html
- **Operational Guidelines:** hxxps://www[.]siemens[.]com/cert/operational-guidelines-industrial-security
- **Siemens ProductCERT:** hxxps://www[.]siemens[.]com/cert/advisories