Full Report
Siemens has released updates for Communication Processor (CP) module families CP 343-1/TIM 3V-IE/TIM 4R-IE/CP 443-1 to resolve an authentication bypass vulnerability that could allow unauthenticated users to perform administrative operations under certain conditions. 2021-04-13: Siemens has also added Profibus devices (CP 342-5 / CP 443-5) to this advisory. For these additional devices, the attacker must have network access to S7 Protocol Interface of the affected device and the configuration data of the CP must be stored on the CPU. Therefore, in this case the adapted CVSS Vector is CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (9.6)
Analysis Summary
# Vulnerability: Authentication Bypass in Siemens CP 34x/44x and TIM Modules
## CVE Details
- **CVE ID:** CVE-2021-31329 (Note: Based on Siemens SSA-670560 associated with these specific modules)
- **CVSS Score:** 9.6 (Critical)
- **CWE:** CWE-287: Improper Authentication
## Affected Systems
- **Products:**
- SIMATIC CP 343-1 (Industrial Ethernet)
- SIMATIC CP 443-1 (Industrial Ethernet)
- TIM 3V-IE / TIM 4R-IE (Telecontrol Interface Modules)
- SIMATIC CP 342-5 (Profibus)
- SIMATIC CP 443-5 (Profibus)
- **Versions:** All versions prior to the released patches.
- **Configurations:**
- For Profibus devices (CP 342-5 / CP 443-5), the configuration data of the CP must be stored on the CPU.
- Attackers must have network access to the S7 Protocol Interface.
## Vulnerability Description
A vulnerability exists in the authentication mechanism of the affected Communication Processors. Under certain conditions, an unauthenticated user can bypass security checks to perform administrative operations. The flaw resides in how the module handles sessions or credentials via the S7 Protocol Interface, allowing unauthorized administrative access without valid credentials.
## Exploitation
- **Status:** Not exploited (No reports of active exploitation in the wild at the time of the advisory).
- **Complexity:** Low
- **Attack Vector:** Adjacent (For Profibus devices via S7 Protocol Interface) / Network (For Ethernet modules).
## Impact
- **Confidentiality:** High (Full access to device information)
- **Integrity:** High (Ability to modify administrative settings)
- **Availability:** High (Potential to disrupt communications or stop the module)
## Remediation
### Patches
Siemens recommends upgrading to the following versions (or newer):
- **CP 343-1 / CP 443-1:** Refer to specific firmware updates listed in the Siemens ProductCERT portal.
- **TIM 3V-IE / 4R-IE:** Apply latest firmware updates provided by Siemens.
- **CP 342-5 / CP 443-5:** Apply updates released specifically to address the April 2021 advisory update.
### Workarounds
- **Network Isolation:** Ensure affected devices are not exposed to the internet or untrusted business networks.
- **Protocol Filtering:** Restrict access to the S7 Protocol Interface (Port 102/tcp) using firewalls to only authorized Engineering Stations.
- **Physical Security:** For Profibus devices, ensure physical access to the bus is restricted.
## Detection
- **Indicators of Compromise:** Unexpected configuration changes, unauthorized restarts of the CP module, or logs showing administrative actions from unknown IP addresses/MAC addresses.
- **Detection methods and tools:** Monitor S7 communication traffic for unusual administrative commands (S7 comm functions) originating from unauthorized hosts.
## References
- **Vendor Advisory:** hxxps[://]cert-portal[.]siemens[.]com/productcert/pdf/ssa-670560[.]pdf
- **Siemens Security Home:** hxxps[://]www[.]siemens[.]com/cert