Full Report
SCALANCE SC-600 Family before V3.1 is affected by multiple vulnerabilities. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens recommends countermeasures for products where fixes are not, or not yet available.
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in SCALANCE SC-600 Family
## CVE Details
- **CVE-2023-44373**: CVSS 9.1 (Critical) | CWE-74 (Injection)
- **CVE-2023-49691**: CVSS 7.2 (High) | CWE-78 (OS Command Injection)
- **CVE-2023-49692**: CVSS 7.2 (High) | CWE-78 (OS Command Injection)
- **CVE-2023-44317**: CVSS 4.9 (Medium) | CWE-79 (Cross-site Scripting)
- **CVE-2023-44319**: CVSS 4.9 (Medium) | CWE-79 (Cross-site Scripting)
- **CVE-2023-44320**: CVSS 4.9 (Medium) | CWE-79 (Cross-site Scripting)
- **CVE-2023-44322**: CVSS 4.9 (Medium) | CWE-79 (Cross-site Scripting)
- **CVE-2023-44321**: CVSS 4.4 (Medium) | CWE-601 (Open Redirect)
## Affected Systems
- **Products**: SCALANCE SC-600 Family (including SC622-2C, SC626-2C, SC632-2C, SC636-2C, SC642-2C, SC646-2C)
- **Versions**:
- All versions prior to V3.1 are affected by the majority of CVEs.
- Specific patches (V3.0.2) address a subset of vulnerabilities (44317, 44373, 49691, 49692).
- **Configurations**: Vulnerabilities often require administrative privileges or specific features enabled (DDNS, IPSEC, or Web-based Management).
## Vulnerability Description
The SCALANCE SC-600 family is subject to several security flaws:
1. **Code Injection (CVE-2023-44373)**: Improper sanitization of an input field allows an authenticated admin to spawn a system root shell (follow-up to CVE-2022-36323).
2. **OS Command Injection (CVE-2023-49691, CVE-2023-49692)**: Flaws in DDNS configuration handling and IPSEC configuration parsing allow administrators to execute commands at the system level with root privileges.
3. **Cross-site Scripting (Various)**: Multiple fields in the Web-based Management (WBM) do not properly neutralize user-supplied input, leading to stored or reflected XSS.
4. **URL Redirection (CVE-2023-44321)**: The WBM contains an open redirect vulnerability that could facilitate phishing attacks.
## Exploitation
- **Status**: PoC available (indicated by 'E:P' in CVSS vectors).
- **Complexity**: Low.
- **Attack Vector**: Network (for most); CVE-2023-49691/2 are attributed to "local administrators" but carry a Network attack vector in the CVSS string.
## Impact
- **Confidentiality**: High (Root shell access/Command execution).
- **Integrity**: High.
- **Availability**: High.
## Remediation
### Patches
Siemens recommends updating to the following versions:
- **V3.0.2**: Resolves CVE-2023-44317, CVE-2023-44373, CVE-2023-49691, CVE-2023-49692.
- **V3.1**: Resolves CVE-2023-44319, CVE-2023-44320, CVE-2023-44322.
- **Note**: No fix is currently planned for CVE-2023-44321 (Open Redirect).
### Workarounds
- Restrict access to the Web-based Management (WBM) to trusted IP addresses only.
- Do not click on suspicious links or follow redirects from the device interface.
- Implement the "Defense in Depth" concept as per Siemens security guidelines.
## Detection
- Monitor for unusual system-level commands executed on the device.
- Audit logs for administrative changes to DDNS or IPSEC configurations.
- Scan for unauthorized root-level shell activity.
## References
- Siemens Advisory SSA-602936: hxxps://cert-portal.siemens.com/productcert/pdf/ssa-602936.pdf
- Siemens Industrial Security Support: hxxps://support.industry.siemens.com/cs/ww/en/view/109827038/
- Siemens ProductCERT: hxxps://www.siemens.com/cert/advisories