Full Report
Intel has published information on vulnerabilities in Intel products in November 2020. This advisory lists the Siemens IPC related products, that are affected by these vulnerabilities. In this advisory we take a representative CVE from each advisory: “Intel CSME, SPS, TXE, AMT and DAL Advisory” Intel-SA-00391 is represented by CVE-2020-8745 “Intel RAPL Interface Advisory” Intel-SA-00389 is represented by CVE-2020-8694 “Intel Processor Advisory” Intel-SA-00381 is represented by CVE-2020-8698, and “BIOS Advisory” Intel-SA-00358 is represented by CVE-2020-0590. Siemens has released updates for the affected products and recommends to update to the latest versions.
Analysis Summary
# Vulnerability: Intel Component Vulnerabilities Impacting Siemens IPCs (Nov 2020)
## CVE Details
*This summary focuses on the representative CVEs provided in the advisory.*
* **CVE ID:** CVE-2020-8745 (Intel-SA-00391)
* **CVSS Score:** 8.2 (High)
* **CWE:** CWE-20 (Improper Input Validation)
* **CVE ID:** CVE-2020-8694 (Intel-SA-00389 - PLATYPUS)
* **CVSS Score:** 5.6 (Medium)
* **CWE:** CWE-200 (Information Exposure)
* **CVE ID:** CVE-2020-8698 (Intel-SA-00381)
* **CVSS Score:** 5.5 (Medium)
* **CWE:** CWE-200 (Information Exposure)
* **CVE ID:** CVE-2020-0590 (Intel-SA-00358)
* **CVSS Score:** 8.2 (High)
* **CWE:** CWE-20 (Improper Input Validation)
## Affected Systems
* **Products:** Siemens Industrial PCs (IPC) and related products utilizing affected Intel chipsets/processors.
* **Versions:** Multiple Siemens IPC models including SIMATIC IPC, SIMATIC Field PG, and SINUMERIK PCU.
* **Configurations:** Systems utilizing Intel Converged Security and Management Engine (CSME), Server Platform Services (SPS), Trusted Execution Engine (TXE), Active Management Technology (AMT), and Intel Running Average Power Limit (RAPL) interfaces.
## Vulnerability Description
* **Intel-SA-00391 (CSME/AMT):** Improper input validation allows an unauthenticated user to potentially enable escalation of privilege via physical access.
* **Intel-SA-00389 (RAPL/PLATYPUS):** A flaw in the Intel RAPL interface allows a local authenticated user to potentially enable information leakage via side-channel analysis of power consumption.
* **Intel-SA-00381 (Processor):** Improper isolation of shared resources in some Intel Processors may allow a local authenticated user to potentially enable information disclosure.
* **Intel-SA-00358 (BIOS):** Improper input validation in the BIOS firmware may allow an authenticated user to enable escalation of privilege via local access.
## Exploitation
* **Status:** Varies by CVE; PoC code exists for CVE-2020-8694 (PLATYPUS).
* **Complexity:** Medium to High (requires specific hardware knowledge or side-channel analysis).
* **Attack Vector:**
* **Physical:** CVE-2020-8745
* **Local:** CVE-2020-8694, CVE-2020-8698, CVE-2020-0590
## Impact
* **Confidentiality:** High (Side-channel attacks can leak sensitive data/keys).
* **Integrity:** High (Privilege escalation via firmware).
* **Availability:** Medium (Potential system instability).
## Remediation
### Patches
Siemens has released BIOS and firmware updates for affected SIMATIC and SINUMERIK products.
* **Recommendation:** Update to the latest version of the specific Siemens product firmware as identified in the Siemens ProductCERT advisory.
### Workarounds
* Limit physical access to IPC hardware.
* Apply the principle of least privilege to restrict local authenticated access.
* Disable Intel AMT if not required for operational management.
## Detection
* **Indicators of Compromise:** Non-standard power consumption monitoring patterns (specific to RAPL attacks) or unauthorized firmware modifications.
* **Detection methods and tools:** Use the Intel CSME Detection Tool to identify vulnerable firmware versions on affected assets.
## References
* Siemens Security Advisory (SSA-431802): hxxps[://]cert-portal[.]siemens[.]com/productcert/pdf/ssa-431802[.]pdf
* Intel-SA-00391: hxxps[://]www[.]intel[.]com/content/www/us/en/security-center/advisory/intel-sa-00391[.]html
* Intel-SA-00389: hxxps[://]www[.]intel[.]com/content/www/us/en/security-center/advisory/intel-sa-00389[.]html
* Intel-SA-00381: hxxps[://]www[.]intel[.]com/content/www/us/en/security-center/advisory/intel-sa-00381[.]html
* Intel-SA-00358: hxxps[://]www[.]intel[.]com/content/www/us/en/security-center/advisory/intel-sa-00358[.]html