news.mlab.sh
Back to the feed
vulnerability

Siemens CADRA

High
Summary

Siemens CADRA is affected by multiple vulnerabilities within the zlib library, primarily stemming from improper input validation and integer overflows. These vulnerabilities could lead to denial-of-service crashes, heap corruption, and potentially allow remote attackers to exploit heap corruption via crafted HTML pages. Siemens has released a new version (V2511) to address these issues, and recommends updating immediately. Mitigation involves blocking access to untrusted web content from sensitive systems.

Siemens CADRA is experiencing security vulnerabilities due to issues within the underlying zlib library. These vulnerabilities could lead to denial-of-service crashes, heap corruption, and potentially allow remote attackers to exploit heap corruption via a crafted HTML page. Siemens has released a new version (V2511) to address these issues, and recommends updating immediately.

Several vulnerabilities exist, including:

  • **zlib 1.2 and later versions:** Allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, leading to a buffer overflow.
  • **Type Confusion in V8 in Google Chrome:** Allows a remote attacker to potentially exploit heap corruption via a crafted HTML page (Chromium security severity: High).
  • **Type Confusion in V8 in Google Chrome:** Allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High).
  • **zlib through 1.3.1.2:** Includes a global buffer overflow in the `untgz` utility due to excessively long archive names.
  • **zlib versions up to and including 1.2.12:** Has a heap-based buffer over-read or buffer overflow in `inflate` due to a large gzip header extra field.
  • **MiniZip in zlib through 1.3:** Has an integer overflow and resultant heap-based buffer overflow in `zipOpenNewFileInZip4_64` via a long filename, comment, or extra field.
  • **zlib versions up to and including 1.2.12:** Allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

Siemens recommends updating to version V2511 or later to resolve these issues. General security measures include protecting network access to devices, isolating control systems from business networks, and using secure remote access methods like VPNs.

Siemens ProductCERT reported these vulnerabilities to CISA. Further information and resources are available on the Siemens ProductCERT website and the CISA Industrial Control Systems (ICS) webpage.

Read the full article at CISA Advisories