Siemens SRCS VPN Feature in SIMATIC CP Devices Improper Control of Generation of Code (CVE-2022-34821)

critical Tenable OT Security Plugin ID 500681

Synopsis

The remote OT asset is affected by a vulnerability.

Description

Multiple SCALANCE devices are affected by several vulnerabilities that could allow an attacker to inject code, retrieve data as debug information as well as user CLI passwords or set the CLI to an irresponsive state. Siemens has released updates for the affected products and recommends to update to the latest versions.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

The following text was originally created by the Cybersecurity and Infrastructure Security Agency (CISA). The original can be found at CISA.gov.

Siemens recommends updating to the latest version of its software if available:

- SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0): Update to V3.3.46 or later
- SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0): Update to V3.3.46 or later
- SIMATIC CP 1243-7 LTE EU (6GK7243-7KX30-0XE0): Update to V3.3.46 or later
- SIMATIC CP 1243-7 LTE US (6GK7243-7SX30-0XE0): Update to V3.3.46 or later
- SIMATIC CP 1243-8 IRC (6GK7243-8RX30-0XE0): Update to V3.3.46 or later
- SIMATIC CP 1543-1 (6GK7543-1AX00-0XE0): Update to V3.0.22 or later
- SIPLUS NET CP 1242-7 V2 (6AG1242-7KX31-7XE0): Update to V3.3.46 or later
- SIPLUS NET CP 1543-1 (6AG1543-1AX00-2XE0): Update to V3.0.22 or later
- SIPLUS S7-1200 CP 1243-1 (6AG1243-1BX30-2AX0): Update to V3.3.46 or later
- SIPLUS S7-1200 CP 1243-1 RAIL (6AG2243-1BX30-1XE0): Update to V3.3.46 or later

Siemens has identified the following specific workarounds and mitigations that customers can implement to reduce exploitation risk:

- Configure the CP to only connect to trusted SINEMA Remote Connect Server instances.
- Block access to port 5243/UDP with an external firewall if possible.
- Disable the SINEMA Remote Connect Server (SRCS) VPN feature.

As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens’ Operational Guidelines for Industrial Security and following recommendations in the product manuals.

Additional information on industrial security by Siemens can be found on the Siemens industrial security webpage.

For more information see Siemens Security Advisory SSA-517377.

See Also

https://www.cisa.gov/news-events/ics-advisories/icsa-22-195-12

http://www.nessus.org/u?d012e3af

Plugin Details

Severity: Critical

ID: 500681

File Name: tenable_ot_siemens_CVE-2022-34821.nasl

Version: 1.3

Type: Remote

Family: Tenable.ot

Published: 3/22/2024

Updated: 9/21/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.45

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/o:siemens:ruggedcom_rm1224_lte_firmware, cpe:/o:siemens:scalance_m_firmware, cpe:/o:siemens:scalance_s_firmware

Required KB Items: Tenable.ot/Siemens

Patch Publication Date: 12/13/2022

Vulnerability Publication Date: 12/13/2022

Reference Information

CVE: CVE-2022-34821

CWE: 94