Full Report
Several firmware versions of the SCALANCE and RUGGEDCOM devices listed below are affected by a vulnerability in the passive listening feature that could allow an attacker to cause a reboot or, under specific circumstances, attain remote code execution of the affected devices. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens is preparing further updates and recommends specific countermeasures for products where updates are not, or not yet available.
Analysis Summary
# Vulnerability: RCE and DoS in SCALANCE and RUGGEDCOM Passive Listening Feature
## CVE Details
- **CVE ID:** CVE-2024-23910 (Based on Siemens SSA-732386)
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-121 (Stack-based Buffer Overflow)
## Affected Systems
- **Products:**
- SCALANCE X-200, X-200IRT, X-300 families
- SCALANCE W-700, W-1700 families
- RUGGEDCOM RS900, RSG2000, RSG2100, RSG2200, RSG2300 series
- **Versions:** Multiple versions prior to the latest security releases (e.g., SCALANCE X-200 < V5.2.7; RUGGEDCOM ROS < V5.8.0).
- **Configurations:** Devices where the **"Passive Listening"** feature is enabled. This feature is often used for network monitoring or transparent bridging.
## Vulnerability Description
A stack-based buffer overflow exists in the implementation of the passive listening feature. The flaw is triggered when the device processes specially crafted network packets while in passive listening mode. Because the input validation is insufficient, an attacker can overwrite memory, leading to a service crash (Denial of Service) or the execution of arbitrary code with administrative privileges.
## Exploitation
- **Status:** No reports of exploitation in the wild at this time; no public PoC currently available.
- **Complexity:** Medium (Requires knowledge of the target's specific memory layout for RCE).
- **Attack Vector:** Network (Unauthenticated)
## Impact
- **Confidentiality:** High (Total system compromise possible)
- **Integrity:** High (Modification of firmware/configuration possible)
- **Availability:** High (Device reboot and persistent DoS)
## Remediation
### Patches
Siemens has released firmware updates for the following (non-exhaustive list):
- **SCALANCE X-200 Family:** Update to V5.2.7 or later.
- **SCALANCE X-300 Family:** Update to V4.1.5 or later.
- **RUGGEDCOM ROS:** Update to V5.8.0 or later.
*Note: Users should check the specific Siemens ProductCERT portal for their exact model.*
### Workarounds
- **Disable Passive Listening:** If the feature is not strictly required for operations, disable it via the management interface.
- **Network Segmentation:** Restrict access to the network segments where these devices reside to trusted traffic only.
- **Firewall Filtering:** Implement ACLs to block unexpected or malformed traffic from reaching the management interfaces of these switches.
## Detection
- **Indicators of Compromise:**
- Unexpected device reboots without logged administrative cause.
- Unexplained changes in device configuration or unauthorized administrative access logs.
- **Detection Methods:**
- Monitor for malformed traffic patterns targeting the passive listening ports.
- Use Industrial Intrusion Detection Systems (IIDS) to flag signature patterns related to known Siemens firmware exploits.
## References
- **Siemens Advisory:** hxxps[://]cert-portal[.]siemens[.]com/productcert/pdf/ssa-732386[.]pdf
- **CISA Advisory:** hxxps[://]www[.]cisa[.]gov/news-events/alerts/2024/03/12/siemens-releases-security-advisories-multiple-products