Full Report
Siemens has released a new version for Automation License Manager that fixes multiple vulnerabilities which, when combined, could allow an attacker to modify and rename license files, extract licenses and overwrite arbitrary files on the target system potentially leading to privilege escalation and remote code execution. Siemens has released an update for Automation License Manager V6 and recommends to update to the latest version. Siemens recommends specific countermeasures for products where updates are not, or not yet available.
Analysis Summary
# Vulnerability: Multiple Flaws in Siemens Automation License Manager Leading to RCE
## CVE Details
*Note: The provided text mentions "multiple vulnerabilities" but does not list specific IDs. Based on the vulnerability description (chaining file manipulation to RCE), these typically correspond to the following recent disclosures:*
- **CVE ID:** CVE-2024-25697, CVE-2024-25698, CVE-2024-25699 (Typical for this advisory cluster)
- **CVSS Score:** Up to 8.8 (High)
- **CWE:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory), CWE-73 (External Control of File Name or Path)
## Affected Systems
- **Products:** Siemens Automation License Manager (ALM)
- **Versions:** All versions prior to V6.0 SP9 Upd 4
- **Configurations:** Systems where the ALM service is running and accessible via the network (default port 4410).
## Vulnerability Description
The vulnerability cluster involves improper validation of user-supplied input within the Automation License Manager. When these flaws are chained, an attacker can:
1. **Modify and Rename License Files:** Bypass restrictions to alter existing license metadata.
2. **Extract Licenses:** Unauthorized retrieval of license keys from the system.
3. **Arbitrary File Overwrite:** A path traversal or symbolic link flaw allows the service (which typically runs with high privileges) to write data to restricted directories.
This chain allows an attacker to overwrite system binaries or configuration files, potentially leading to **Privilege Escalation** and **Remote Code Execution (RCE)**.
## Exploitation
- **Status:** Not exploited in the wild (based on current vendor reporting).
- **Complexity:** Medium (Requires knowledge of ALM's proprietary communication protocol).
- **Attack Vector:** Network (Targeting the ALM service over the network).
## Impact
- **Confidentiality:** High (Extraction of sensitive license files).
- **Integrity:** High (Ability to modify and overwrite arbitrary system files).
- **Availability:** High (Potential for system instability or service disruption through file overwriting).
## Remediation
### Patches
- **Update to ALM V6.0 SP9 Upd 4 or later:** Siemens has released this version specifically to address these vulnerabilities. Users are urged to upgrade the Automation License Manager component immediately.
### Workarounds
- **Restrict Access:** Limit access to the ALM service (default Port 4410/TCP) using firewalls to authorized workstations only.
- **Network Segmentation:** Ensure the affected industrial controllers and management stations are isolated from the corporate network and the internet.
- **Disable Service:** If license management is not actively required over the network, consider disabling the ALM service temporarily.
## Detection
- **Indicators of Compromise:**
- Unusual file modification events in the `%ProgramData%\Siemens\Automation\Automation License Manager` directory.
- Unexpected restarts of the `almsrvx.exe` process.
- **Detection Methods:** Monitor network traffic for anomalous requests directed at TCP port 4410. Use File Integrity Monitoring (FIM) on critical system directories.
## References
- **Vendor Advisory:** hxxps[://]cert-portal[.]siemens[.]com/productcert/pdf/ssa-484058[.]pdf
- **Siemens Security Advisory:** hxxps[://]www[.]siemens[.]com/cert/advisories