Full Report
Intel has published information on vulnerabilities in Intel products in November 2020. This advisory lists the Siemens Controllers that are affected by these vulnerabilities. In this advisory we take a representative CVE from each advisory: “Intel CSME, SPS, TXE, AMT and DAL Advisory” Intel-SA-00391 is represented by CVE-2020-8744 “BIOS Advisory” Intel-SA-00358 is represented by CVE-2020-0591. Siemens is currently working on BIOS updates that include chipset microcode updates and recommends specific countermeasures for products where updates are not, or not yet available.
Analysis Summary
# Vulnerability: Intel Chipset and BIOS Flaws Affecting Siemens Controllers (Nov 2020)
## CVE Details
**Advisory 1: Intel-SA-00391**
- **CVE ID:** CVE-2020-8744
- **CVSS Score:** 8.4 (High)
- **CWE:** CWE-20 (Improper Input Validation)
**Advisory 2: Intel-SA-00358**
- **CVE ID:** CVE-2020-0591
- **CVSS Score:** 7.5 (High)
- **CWE:** CWE-20 (Improper Input Validation)
## Affected Systems
- **Products:** Siemens Industrial Controllers (SIMATIC, SINUMERIK, SIMOTION) utilizing affected Intel Chipsets.
- **Versions:** Specific versions are dependent on the integrated Intel hardware (CSME, SPS, TXE, AMT, and DAL).
- **Configurations:** Systems using Intel Converged Security and Management Engine (CSME), Server Platform Services (SPS), Trusted Execution Engine (TXE), Active Management Technology (AMT), and Dynamic Application Loader (DAL).
## Vulnerability Description
These vulnerabilities stem from improper input validation within the firmware of several Intel subsystems.
- **CVE-2020-8744 (CSME/AMT):** A flaw in the subsystem firmware may allow a privileged user to potentially enable escalation of privilege via local access.
- **CVE-2020-0591 (BIOS):** A vulnerability in the BIOS firmware could allow a privileged user to potentially enable escalation of privilege, information disclosure, or denial of service via local access.
## Exploitation
- **Status:** Not exploited (at the time of the advisory release).
- **Complexity:** Medium to High (requires specific system knowledge).
- **Attack Vector:** Local (requires authenticated/local access to the controller).
## Impact
- **Confidentiality:** High (Potential for unauthorized information disclosure).
- **Integrity:** High (Potential for escalation of privilege).
- **Availability:** High (Potential for Denial of Service).
## Remediation
### Patches
- **Status:** Siemens is currently working on BIOS updates that include the necessary Intel chipset microcode updates.
- **Action:** Users should monitor Siemens ProductCERT for specific firmware update releases for their respective controller models.
### Workarounds
- **Disable Unused Services:** Disable Intel AMT and network-based management features if not required for operations.
- **Access Control:** Restrict physical and local administrative access to the controllers to authorized personnel only.
- **Defense-in-Depth:** Implement strict network segmentation to ensure controllers are not reachable from untrusted networks.
## Detection
- **Indicators of compromise:** Unauthorized changes to BIOS settings or unexpected system reboots.
- **Detection methods and tools:** Use the **Intel CSME Detection Tool** to verify if the underlying hardware is vulnerable to the SA-00391 advisory suite.
## References
- Intel Security Advisory SA-00391: hxxps[://]www[.]intel[.]com/content/www/us/en/security-center/advisory/intel-sa-00391[.]html
- Intel Security Advisory SA-00358: hxxps[://]www[.]intel[.]com/content/www/us/en/security-center/advisory/intel-sa-00358[.]html
- Siemens ProductCERT: hxxps[://]new[.]siemens[.]com/global/en/products/services/cert[.]html