Full Report
SPPA-T3000 solutions are affected by vulnerabilities that were recently dislosed by JSOF research lab (“Ripple20”) for the TCP/IP stack used in APC UPS systems, and by Intel for the Server Platform Services (SPS) used in SPPA-T3000 Application Server and Terminal Server hardware. The advisory provides information to what amount SPAA-T3000 solutions are affected. Detailed information, including solution and mitigation measures, are available for SPPA-T3000 customers in the Siemens Energy Customer Portal.
Analysis Summary
Based on the context provided regarding the Siemens Energy SPPA-T3000 advisory, here is the vulnerability research summary.
*Note: Because the provided text is a high-level summary, specific CVE IDs from the Ripple20 and Intel SPS suites most relevant to SPPA-T3000 are identified based on the vulnerabilities referenced.*
# Vulnerability: SPPA-T3000 Vulnerabilities (Ripple20 and Intel SPS)
## CVE Details
- **CVE ID:** CVE-2020-11896, CVE-2020-11898 (Ripple20/Treck stack); CVE-2020-8752 (Intel SPS)
- **CVSS Score:** 10.0 (Critical) / 9.0 (Critical)
- **CWE:** CWE-122 (Heap-based Buffer Overflow), CWE-20 (Improper Input Validation)
## Affected Systems
- **Products:** Siemens Energy SPPA-T3000 Control System.
- **Versions:** All versions utilizing vulnerable Application Server and Terminal Server hardware components.
- **Configurations:**
- Systems utilizing APC UPS units integrated into the SPPA-T3000 infrastructure.
- Application and Terminal Servers utilizing specific Intel Server Platform Services (SPS) firmware.
## Vulnerability Description
The SPPA-T3000 is affected by two distinct sets of vulnerabilities:
1. **Ripple20 (Treck TCP/IP Stack):** A series of flaws in the low-level TCP/IP library used by APC UPS systems. The most severe flaws involve improper handling of IPv4 tunneling or IP fragmentation, leading to remote code execution.
2. **Intel SPS Vulnerability:** A security flaw in the Intel Server Platform Services (SPS) firmware. This resides in the out-of-band management subsystem, potentially allowing an unauthenticated attacker with network access to the management interface to execute arbitrary code.
## Exploitation
- **Status:** PoC available (Publicly disclosed by JSOF and Intel).
- **Complexity:** Medium (Requires specific network positioning to reach management interfaces/UPS).
- **Attack Vector:** Network (Targeting the TCP/IP stack or management firmware).
## Impact
- **Confidentiality:** High
- **Integrity:** High
- **Availability:** High
- **Overall Impact:** Full system compromise of the Application Server or disruption of power management via UPS.
## Remediation
### Patches
- **Siemens Energy Updates:** Customers are advised to log into the Siemens Energy Customer Portal to download specific firmware updates for SPPA-T3000 hardware components.
- **Intel SPS:** Apply firmware updates provided by the OEM for the specific Server Platform Services version used in the Application/Terminal servers.
### Workarounds
- **Network Segmentation:** Isolate the SPPA-T3000 network from the office network and the internet.
- **UPS Isolation:** Ensure APC UPS management interfaces are placed on a dedicated, restricted management VLAN with no external routing.
- **Disabling Services:** Disable unused management protocols (e.g., SNMP, HTTP) on integrated UPS devices if not strictly required.
## Detection
- **Indicators of Compromise:** Unusual network traffic originating from UPS units or Server Management interfaces; unexpected reboots of Application Servers.
- **Detection Methods:**
- Use Nmap or specialized vulnerability scanners to identify Treck-based TCP/IP stacks.
- Utilize the Intel CSME/SPS Detection Tool to verify firmware version vulnerability status.
## References
- **Vendor Advisory:** hxxps://cert-portal.siemens[.]com/
- **JSOF Ripple20 Research:** hxxps://www.jsof-tech[.]com/ripple20/
- **Intel Security Advisory:** hxxps://www.intel[.]com/content/www/us/en/security-center/advisory/intel-sa-00295[.]html