Full Report
The SIPROTEC 5 Ethernet plug-in communication modules and devices are affected by multiple security vulnerabilities. These vulnerabilities could allow an attacker to leverage various attacks, e.g. to execute arbitrary code over the network. The underlying Wind River VxWorks network stack is affected by eleven vulnerabilities known as 'URGENT/11'. Of these, two DHCP-related vulnerabilities (CVE-2019-12257 and CVE-2019-12264) do not apply to this advisory as the listed products use a different DHCP stack. One further vulnerability affects the boot process of the device under certain conditions. Siemens has released updates and recommends that customers update to the new versions.
Analysis Summary
# Vulnerability: URGENT/11 Stack Flaws in Siemens SIPROTEC 5 Devices
## CVE Details
- **CVE ID:** CVE-2019-12255, CVE-2019-12256, CVE-2019-12258, CVE-2019-12259, CVE-2019-12260, CVE-2019-12261, CVE-2019-12262, CVE-2019-12263, CVE-2019-12265 (Collectively part of URGENT/11)
- **CVSS Score:** Up to 9.8 (Critical)
- **CWE:** CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), CWE-190 (Integer Overflow)
## Affected Systems
- **Products:** SIPROTEC 5 Ethernet plug-in communication modules and associated SIPROTEC 5 devices.
- **Versions:** All versions prior to the recommended firmware updates.
- **Configurations:** Devices utilizing the affected Wind River VxWorks network stack. Note: DHCP-related vulnerabilities (CVE-2019-12257 and CVE-2019-12264) are **excluded** as these devices use a custom DHCP stack.
## Vulnerability Description
The vulnerabilities stem from the Wind River VxWorks TCP/IP stack (IPnet). The flaws include buffer overflows, integer underflows, and memory corruption issues in the way the stack handles TCP options, IPv4 headers, and IGMP packets. A remote attacker can send specially crafted packets to the device, potentially resulting in Remote Code Execution (RCE), Denial of Service (DoS), or information disclosure. Additionally, one specific vulnerability affects the device boot process under certain network conditions.
## Exploitation
- **Status:** PoC available; URGENT/11 vulnerabilities have been extensively researched and demonstrated in security communities.
- **Complexity:** Low to Medium
- **Attack Vector:** Network (Unauthenticated)
## Impact
- **Confidentiality:** High (Potential for data exfiltration via RCE)
- **Integrity:** High (Potential for unauthorized configuration changes)
- **Availability:** High (System crash, reboot loops, or complete loss of protection/control functions)
## Remediation
### Patches
Siemens has released firmware updates for the affected SIPROTEC 5 modules.
- **Action:** Update to the latest firmware version available via the Siemens Energy support portal.
- **Specific Fix:** Ensure Ethernet plug-in modules are updated to versions that incorporate the Wind River VxWorks security patches.
### Workarounds
- **Network Segmentation:** Isolate SIPROTEC 5 devices from the enterprise network and the internet.
- **Firewall Filtering:** Block unsolicited incoming TCP/IP traffic and restrict access to authorized engineering workstations only.
- **Disable Unused Services:** Disable any unnecessary network protocols or services within the module configuration.
## Detection
- **Indicators of Compromise:** Unexpected device reboots, loss of communication with the substation automation system, or unusual network traffic originating from the field devices.
- **Detection Methods and Tools:**
- Use Intrusion Detection Systems (IDS) with signatures specifically designed for URGENT/11 (e.g., Snort/Suricata rules).
- Monitor for malformed TCP options or abnormal IGMP membership reports.
## References
- **Siemens Security Advisory:** hxxps[://]www[.]siemens[.]com/cert/advisories
- **Wind River URGENT/11 Information:** hxxps[://]www[.]windriver[.]com/security/announcements/tcp-ip-network-stack-vulnerabilities-critical-security-patches
- **CISA Advisory:** hxxps[://]www[.]cisa[.]gov/news-events/ics-advisories/icsa-19-211-01