Full Report
SCALANCE W-700 IEEE 802.11ax family devices are affected by multiple vulnerabilities. Siemens has released a new version for SCALANCE W-700 IEEE 802.11ax family and recommends to update to the latest version. Siemens recommends countermeasures for vulnerabilities where fixes are not, or not yet available.
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in Siemens SCALANCE W-700 IEEE 802.11ax Family
## CVE Details
The advisory covers multiple vulnerabilities. Specific details for three are provided below:
- **CVE ID:** CVE-2023-44317
- **CVSS Score:** 7.2 (High) [Based on the advisory's general high score, though specific 3.1/3.0 details for this CVE are not fully provided, other related CVEs have CVSS 3.1 scores.]
- **CWE:** Not explicitly listed for CVE-2023-44317 in the provided text section.
Additionally, details for other listed CVEs are captured below:
- **CVE ID:** CVE-2023-44318
- **CVSS Score:** 4.9 (Medium) (CVSS 3.1) / 6.9 (Medium) (CVSS 4.0)
- **CWE:** CWE-321: Use of Hard-coded Cryptographic Key Vulnerability
- **CVE ID:** CVE-2023-44319
- **CVSS Score:** 4.9 (Medium) (CVSS 3.1) / 6.9 (Medium) (CVSS 4.0)
- **CWE:** CWE-328: Use of Weak Hash Vulnerability
- **CVE ID:** CVE-2023-44374
- **CVSS Score:** 6.5 (Medium) (CVSS 3.1) / 7.1 (High) (CVSS 4.0)
- **CWE:** CWE-567: Unsynchronized Access to Shared Data in a Multithreaded Context
## Affected Systems
- **Products:** SCALANCE W-700 IEEE 802.11ax family, specifically:
- SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0)
- SCALANCE WAM763-1 (6GK5763-1AL00-7DA0)
- SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0)
- SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0)
- SCALANCE WAM766-1 (6GK5766-1GE00-7DA0)
- **Versions:** All versions **less than V3.0.0** are affected by CVE-2023-44317, CVE-2023-44319, and CVE-2023-44374. Specific versions depend on the CVE.
- **Configurations:** Authentication is often required for exploitation (e.g., administrative privileges).
## Vulnerability Description
The advisory addresses multiple flaws:
1. **CVE-2023-44317 (Improper Export/Import of Configuration):** An attacker with administrative privileges or access to an exported configuration backup can extract configuration information due to the weak protection mechanism used on the exported file.
2. **CVE-2023-44318 (Weak Checksum Algorithm for Configuration Backup):** A weak checksum algorithm protecting configuration backups allows an authenticated attacker (with admin rights) or an attacker tricking an admin into uploading a modified configuration file to alter the device configuration.
3. **CVE-2023-44319 (Weak Checksum Algorithm for Configuration Backup):** Similar to CVE-2023-44318, this flaw relates to a weak checksum algorithm protecting configuration backups, allowing an authenticated attacker to potentially change the configuration if they can upload a modified file.
4. **CVE-2023-44374 (Insecure Password Change):** The device insufficiently checks which password is being changed when an authenticated attacker attempts to modify passwords, potentially allowing an attacker to change the password of *another* user, including an admin, leading to privilege escalation.
## Exploitation
- **Status:** Not explicitly stated as exploited in the wild, but the nature of the flaws suggests potential for exploitation upon gaining initial network access or administrative credentials.
- **Complexity (Based on CVE-2023-44318/44319 and CVE-2023-44374):** Low/Medium. Several require authenticated access (PR:H or PR:L).
- **Attack Vector (Based on scoring):** Network (AV:N) is a primary vector for several flaws.
## Impact
The specific impact varies per CVE, but aggregated potential impact includes loss of confidentiality (configuration data extraction) and high risk to integrity (configuration modification, privilege escalation).
- **Confidentiality:** High (for CVE-2023-44317 - configuration extraction).
- **Integrity:** High (for CVE-2023-44318, CVE-2023-44319 - configuration modification, and CVE-2023-44374 - privilege escalation).
- **Availability:** Not explicitly stated as the primary impact for the detailed CVEs.
## Remediation
### Patches
- **For CVE-2023-44317, CVE-2023-44319, CVE-2023-44374:** Update to **V3.0.0 or later version**.
- **Fix Availability:** A fix for CVE-2023-44317, CVE-2023-44319, and CVE-2024-44374 was added in an update (V1.2 of the advisory).
### Workarounds
- **For CVE-2023-44318:** **Currently no fix is planned.** (Countermeasures/workarounds are recommended by the vendor for such cases, details must be checked in the full advisory).
## Detection
- Detection methods are not specified in the summary provided, but generally involve monitoring for unexpected configuration changes, unauthorized configuration exports, or abnormal administrative login attempts.
## References
- **Vendor Advisories:** SSA-690517 (Siemens Security Advisory)
- **Patch Link (General):** hxxps://support.industry.siemens.com/cs/ww/en/view/109977720/
- **ProductCERT:** hxxps://www.siemens.com/cert/advisories