Full Report
SCALANCE M-800 family before V8.0 is affected by multiple vulnerabilities. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens recommends countermeasures for products where fixes are not, or not yet available.
Analysis Summary
# Vulnerability: Multiple Critical Vulnerabilities in Siemens SCALANCE M-800 Family Before V8.0
## CVE Details
The advisory covers multiple CVEs, with specific details provided for three of them:
- **CVE ID:** CVE-2023-44374
- **CVSS Score:** 6.5 (CVSS v3.1) / 9.4 (CVSS v4.0)
- **CWE:** CWE-567 (Unsynchronized Access to Shared Data in a Multithreaded Context)
- **CVE ID:** CVE-2023-49691
- **CVSS Score:** 7.2 (CVSS v3.1)
- **CWE:** CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))
- **CVE ID:** Unknown (Associated with a critical vector leading to CVSS v3.1 9.1 / CVSS v4.0 9.4) - *Technical details for the highest scoring vector (CVSS 9.1/9.4) were not fully enumerated in the provided text, but it involves Injection (CWE-74).*
## Affected Systems
- **Products:** SCALANCE M-800 family (incl. S615, MUM-800, RM1224), RUGGEDCOM RM1224 family (6GK6108-4AM00), RUGGEDCOM RM1224 LTE(4G) EU, RUGGEDCOM RM1224 LTE(4G) NAM, SCALANCE M804PB (6GK5804-0AP00-2AA2), SCALANCE M812-1 ADSL-Router family.
- **Versions:** All versions **before V8.0**.
- **Configurations:** Specific details for each CVE/product are available in the full advisory by opening details. Note that CVE-2023-44318 affects RUGGEDCOM RM1224 LTE(4G) EU and NAM explicitly, with no planned fix at the time of reporting.
## Vulnerability Description
The advisory details several flaws impacting the SCALANCE M-800 series, including:
1. **Improper Neutralization/Injection (Related to CVSS 9.1/9.4):** A vulnerability classified under CWE-74, likely a form of Injection, exists, leading to critically high impact on Confidentiality, Integrity, and Availability for unauthenticated access under certain conditions (`CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C`).
2. **Privilege Escalation via Password Change (CVE-2023-44374):** An authenticated attacker (Low Privilege) can change the password of another user, potentially leading to privilege escalation, due to insufficient checking of which password is being modified.
3. **OS Command Injection (CVE-2023-49691):** A vulnerability in DDNS configuration handling, exploitable by a local administrator after a successful IP address update, could allow the attacker to execute system-level commands.
## Exploitation
- **Status:** **Exploited in the wild / PoC available** for the listed CVEs (indicated by the presence of the Exploit Maturity Code `E:P` in the CVSS vectors).
- **Complexity:** Generally **Low** to **Medium** risk, as some require authentication (`PR:H` or `PR:L`). The highest rated vulnerability vector seems to require High Privilege (`PR:H`) but has an easier attack complexity (`AC:L`).
- **Attack Vector:** Predominantly **Network (AV:N)** for the high-severity vectors.
## Impact
Impact levels are inferred from the highest provided CVSS vectors:
- **Confidentiality:** **High** (H)
- **Integrity:** **High** (H)
- **Availability:** **High** (H)
## Remediation
### Patches
- **General Recommendation:** Update affected products to **V8.0 or a later version**.
- **Specific Fix Links:** Siemens directs users to a specific support page for updates: `https://support.industry.siemens.com/cs/ww/en/view/109826372/`
### Workarounds
- **CVE-2023-44318:** For RUGGEDCOM RM1224 LTE(4G) EU and NAM, Siemens has **currently no fix planned**. Specific countermeasures for this vulnerability are not detailed in the summary but must be sought in the full advisory.
- **General Countermeasures:** Siemens recommends applying countermeasures for products where fixes are not yet available.
## Detection
Specific Indicators of Compromise (IOCs) or detection signatures were not provided in the summary text. Detection should focus on monitoring for:
- Unauthenticated attempts against configuration interfaces, especially if leading to high-severity access.
- Unusual password changes (CVE-2023-44374).
- Unexpected system-level command execution initiated after network interface changes (CVE-2023-49691).
## References
- Siemens ProductCERT Advisory: SSA-180704
- Vendor Advisory Link (General): `https://www.siemens.com/cert/advisories`