Full Report
Products that include the Siemens PROFINET-IO (PNIO) stack in versions prior V06.00 are potentially affected by a denial of service vulnerability when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. Siemens has released updates for several affected products and recommends to update to the new versions. Siemens is preparing further updates and recommends specific countermeasures for products where updates are not, or not yet available. Additionally, Siemens recommends other vendors of PROFINET devices to check if their products have incorporated a vulnerable version of the Siemens PNIO stack as part of the Siemens Development/Evaluation Kits.
Analysis Summary
# Vulnerability: Siemens PROFINET-IO Stack Denial of Service
## CVE Details
- **CVE ID:** CVE-2019-13946 (Note: Based on the Siemens PNIO stack DCE-RPC vulnerability description)
- **CVSS Score:** 7.5 (High)
- **CWE:** CWE-400 (Uncontrolled Resource Consumption)
## Affected Systems
- **Products:** Devices incorporating the Siemens PROFINET-IO (PNIO) stack and Siemens Development/Evaluation Kits.
- **Versions:** All versions prior to V06.00.
- **Configurations:** Systems with the DCE-RPC interface exposed and active for diagnostic requests. This affects both Siemens branded products and third-party vendors who integrated the vulnerable stack into their own hardware.
## Vulnerability Description
The vulnerability exists in the way the Siemens PROFINET-IO stack processes Distributed Computing Environment / Remote Procedure Calls (DCE-RPC). When the stack receives multiple legitimate diagnostic package requests in a short timeframe, it fails to handle the resource allocation or processing queue correctly. This leads to a resource exhaustion state, resulting in a Denial of Service (DoS) of the PROFINET communication functions.
## Exploitation
- **Status:** PoC concepts exist; generally categorized as "Not exploited in the wild" at the time of initial disclosure, though it relies on "legitimate" traffic patterns.
- **Complexity:** Low (Requires sending standard, legitimate diagnostic requests).
- **Attack Vector:** Network (Adjacent/Network depending on network topology).
## Impact
- **Confidentiality:** None
- **Integrity:** None
- **Availability:** High (Total loss of PROFINET communication and diagnostic capabilities).
## Remediation
### Patches
- **Siemens PNIO Stack:** Update to **V06.00** or later.
- **Affected Products:** Siemens has released firmware updates for specific SIMATIC, SINAMICS, and SCALANCE product lines. Users should consult the Siemens ProductCERT portal for specific firmware download links for their device models.
- **Third-Party Vendors:** Vendors using Siemens Development/Evaluation Kits must integrate PNIO stack V06.00 and issue their own firmware updates.
### Workarounds
- **Network Segmentation:** Isolate the PROFINET network from the corporate network and the internet.
- **Access Control:** Restrict access to the DCE-RPC interface to authorized management stations only.
- **Defense in Depth:** Implement a cell protection concept and use industrial security appliances (e.g., SCALANCE S) to filter traffic.
## Detection
- **Indicators of Compromise:** Unexpected loss of PROFINET IO communication; device unresponsiveness to diagnostic queries; repeated crashing of the communication stack.
- **Detection methods and tools:**
- Monitor network traffic for high volumes of DCE-RPC diagnostic packets originating from unauthorized or unexpected IP addresses.
- Utilize Industrial Intrusion Detection Systems (IIDS) to flag anomalous bursts of PROFINET diagnostic traffic.
## References
- **Siemens ProductCERT:** hxxps[://]cert-portal[.]siemens[.]com/productcert/txt/ssa-782927[.]txt
- **CISA Advisory:** hxxps[://]www[.]cisa[.]gov/news-events/ics-advisories/icsa-19-253-03