Siemens SIDIS Secured SmartPlug
Siemens SIDIS Secured SmartPlug versions prior to V7.26.0310 are affected by multiple vulnerabilities stemming from components like OpenSSL, OpenSSH, and libarchive. These vulnerabilities include side-channel attacks, integer overflows, and potential remote code execution. Siemens has released a new version and recommends updating to mitigate these risks. The vulnerabilities range from allowing a man-in-the-middle attack to enable key recovery, to enabling arbitrary code execution via heap buffer overflows.
Siemens has released a security advisory highlighting multiple vulnerabilities in the SIDIS Secured SmartPlug, a device used in critical infrastructure environments. The advisory states that versions prior to V7.26.0310 are affected by a range of issues. These vulnerabilities are linked to components including OpenSSL, OpenSSH, and libarchive.
Specifically, the device is vulnerable to side-channel attacks due to cache access patterns in hostapd and wpa_supplicant before 2.10. A related issue stems from an incomplete fix for CVE-2019-9494. Additionally, the implementation of EAP-pwd in hostapd and wpa_supplicant before 2.10 is vulnerable to side-channel attacks due to cache access patterns. The advisory also details a stack overflow vulnerability in ash.c:6030 in busybox before 1.35, leading to potential memory corruption and arbitrary code execution.
Furthermore, the SIDIS Secured SmartPlug is vulnerable to a double-free condition in libarchive due to an integer overflow in the zisofs block pointer allocation logic, potentially leading to heap buffer overflows and arbitrary code execution. The vulnerability is also linked to a flaw in OpenSSH when the VerifyHostKeyDNS option is enabled, allowing a machine-in-the-middle attack.
Siemens recommends updating to V7.26.0310 or a later version to address these vulnerabilities. The advisory emphasizes the importance of protecting network access to these devices and recommends implementing security measures such as isolating control system networks behind firewalls and using VPNs when remote access is necessary. Siemens ProductCERT reported these vulnerabilities to CISA. The advisory also provides links to Siemens' operational guidelines for Industrial Security and additional resources for ICS cybersecurity.