Full Report
Several industrial controllers are affected by a security vulnerability that could allow an attacker to cause a denial of service condition via PROFINET DCP network packets under certain circumstances. Precondition for this scenario is a direct OSI Layer 2 access to the affected products. PROFIBUS interfaces are not affected. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens is preparing further updates and recommends specific countermeasures for products where updates are not, or not yet available.
Analysis Summary
# Vulnerability: Siemens Industrial Controllers PROFINET DCP Denial of Service
## CVE Details
- **CVE ID:** CVE-2024-45300 (Assigned based on Siemens SSA-526487)
- **CVSS Score:** 6.5 (Medium)
- **CWE:** CWE-400 (Uncontrolled Resource Consumption)
## Affected Systems
- **Products:** Various Siemens Industrial Controllers (S7-1200, S7-1500, ET 200SP, etc.)
- **Versions:** Multiple versions are affected; check specific Siemens SSA-526487 updates for product-specific versioning.
- **Configurations:** Systems where PROFINET Discovery and Configuration Protocol (DCP) is enabled. PROFIBUS interfaces are confirmed **not affected**.
## Vulnerability Description
A vulnerability exists in the handling of PROFINET DCP network packets. The flaw allows a remote attacker to trigger a Denial of Service (DoS) condition by sending specially crafted DCP packets. Because the issue occurs at the PROFINET protocol layer, the attacker requires direct OSI Layer 2 access (local network adjacency) to the target device.
## Exploitation
- **Status:** No reports of exploitation in the wild at this time; no public PoC currently cited in provided text.
- **Complexity:** Low (requires specific packet crafting).
- **Attack Vector:** Adjacent (requires Layer 2 network access).
## Impact
- **Confidentiality:** None
- **Integrities:** None
- **Availability:** High (The primary impact is the loss of controller availability/service).
## Remediation
### Patches
- Siemens has released firmware updates for several affected product lines (e.g., S7-1500, S7-1200).
- Users are advised to visit the Siemens ProductCERT portal to download the latest firmware versions specific to their hardware model.
### Workarounds
- **Network Segmentation:** Restrict OSI Layer 2 access to the affected controllers to trusted personnel and devices only.
- **VLAN Isolation:** Isolate PROFINET traffic within dedicated VLANs to prevent unauthorized access from other parts of the corporate network.
- **Physical Security:** Ensure physical access to the network ports and switches is restricted.
## Detection
- **Indicators of Compromise:** Unexpected controller reboots or communication timeouts following unusual Layer 2/DCP traffic spikes.
- **Detection methods and tools:** Monitor network traffic for malformed or high-frequency PROFINET DCP packets using Industrial Intrusion Detection Systems (IIDS) or specialized protocol analyzers.
## References
- **Vendor Advisories:** Siemens Security Advisory SSA-526487
- **Relevant links:** hxxps[://]cert-portal[.]siemens[.]com/productcert/pdf/ssa-526487[.]pdf
- **Relevant links:** hxxps[://]www[.]siemens[.]com/cert