VDB
ICSA-23-348-10
ICSA-23-348-10
PUBLISHED
CVSS 9.100000381469727 CRITICAL
Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version >= V3.1.0 and < V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). These GNU/Linux vulnerabilities have been externally identified. Siemens has released new versions for the affected products and recommends to update to the latest versions. Note: This SSA advises vulnerabilities for firmware version V3.1 only; for versions < V3.1 refer to Siemens Security Bulletin SSB-439005 ( https://cert-portal.siemens.com/productcert/html/ssb-439005.html).
Risk Scores
CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) | ||
| SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) | ||
| SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) | ||
| SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) | ||
| SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) |
Exploit Intelligence
- Scan for python installations on macOS, and run CVE-2015-20107.py script to report if patching is needed (github-poc)
- https://support.industry.siemens.com/cs/ww/en/view/109478459/ (circl)
- https://cert-portal.siemens.com/productcert/csaf/ssa-398330.json (circl)
- https://cert-portal.siemens.com/productcert/html/ssa-398330.html (circl)
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2023/icsa-23-348-10.json (circl)
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-348-10 (circl)
- https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01 (circl)
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices (circl)
- https://www.cisa.gov/topics/industrial-control-systems (circl)
- https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf (circl)
…and 2 more exploits
Timeline
- Dec 12, 2023 CVE Published
- Aug 12, 2025 CVE Updated
References
- https://support.industry.siemens.com/cs/ww/en/view/109478459/ fix
- https://cert-portal.siemens.com/productcert/csaf/ssa-398330.json advisory
- https://cert-portal.siemens.com/productcert/html/ssa-398330.html advisory
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2023/icsa-23-348-10.json advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-348-10 advisory
- https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01 url
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices url
- https://www.cisa.gov/topics/industrial-control-systems url
- https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf url
- https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf url
- https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B url