Rewterz

Rewterz Threat Advisory – ICS: Multiple Siemens Solid Edge Vulnerabilities

August 11, 2021
Rewterz

Rewterz Threat Alert – Kimsuky APT Group – Active IOCs

August 11, 2021

Rewterz Threat Advisory – ICS: Multiple Siemens SIMATIC NET CP Vulnerability

Severity

High

Analysis Summary

CVE-2020-9272

The affected products are vulnerable to an out-of-bounds read vulnerability in mod_cap via the cap_text.ccap_to_text function, which could lead to information disclosure.

CVE-2020-9273

A malicious attacker could corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free condition in alloc_pool in pool.c, which could lead to remote code execution.

Impact

  • Information Disclosure
  • Code Execution

Affected Vendors

Siemens

Affected Products

  • SIMATIC NET CP 1543-1
  • SIMATIC NET CP 1545-1: All versions

Remediation

Refer to CISA advisory for the complete list of affected products and their respective patches at:

https://us-cert.cisa.gov/ics/advisories/icsa-21-222-07

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.