Siemens does not have a fix available to handle time-of-check time-of-use (TOCTOU) race condition vulnerabilities in its RUGGEDCOM APE1808 product line where public exploits are available, according to a report with CISA.
Exploitation of these vulnerabilities, which Siemens self-reported, could lead to system crashing or escalation of privileges.
The following software suffers from the vulnerabilities:
- RUGGEDCOM APE1808 ADM (6GK6015-0AL20-0GL0) – vers:all/*
- RUGGEDCOM APE1808 ADM CC (6GK6015-0AL20-0GL1) – vers:all/*
- RUGGEDCOM APE1808 CKP (6GK6015-0AL20-0GK0) – vers:all/*
- RUGGEDCOM APE1808 CKP CC (6GK6015-0AL20-0GK1) – vers:all/*
- RUGGEDCOM APE1808 CLOUDCONNECT (6GK6015-0AL20-0GM0) – vers:all/*
- RUGGEDCOM APE1808 CLOUDCONNECT CC (6GK6015-0AL20-0GM1) – vers:all/*
- RUGGEDCOM APE1808 ELAN (6GK6015-0AL20-0GP0) – vers:all/*
- RUGGEDCOM APE1808 ELAN CC (6GK6015-0AL20-0GP1) – vers:all/*
- RUGGEDCOM APE1808 SAM-L (6GK6015-0AL20-0GN0) – vers:all/*
- RUGGEDCOM APE1808 SAM-L CC (6GK6015-0AL20-0GN1) – vers:all/*
- RUGGEDCOM APE1808CLA-P (6GK6015-0AL20-1AA0) – vers:all/*
- RUGGEDCOM APE1808CLA-P CC (6GK6015-0AL20-1AA1) – vers:all/*
- RUGGEDCOM APE1808CLA-S1 (6GK6015-0AL20-1AB0) – vers:all/*
- RUGGEDCOM APE1808CLA-S1 CC (6GK6015-0AL20-1AB1) – vers:all/*
- RUGGEDCOM APE1808CLA-S3 (6GK6015-0AL20-1AD0) – vers:all/*
- RUGGEDCOM APE1808CLA-S3 CC (6GK6015-0AL20-1AD1) – vers:all/*
- RUGGEDCOM APE1808CLA-S5 (6GK6015-0AL20-1AF0) – vers:all/*
- RUGGEDCOM APE1808CLA-S5 CC (6GK6015-0AL20-1AF1) – vers:all/*
- RUGGEDCOM APE1808LNX (6GK6015-0AL20-0GH0) – vers:all/*
- RUGGEDCOM APE1808LNX CC (6GK6015-0AL20-0GH1) – vers:all/*
- RUGGEDCOM APE1808W10 (6GK6015-0AL20-0GJ0) – vers:all/*
- RUGGEDCOM APE1808W10 CC (6GK6015-0AL20-0GJ1) – vers:all/*
In one issue, DMA attacks on the PnpSmm shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges.
CVE-2022-32469 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 8.2.
In addition, DMA attacks on the FwBlockServiceSmm shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges.
CVE-2022-32470 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 8.2.
Also, DMA attacks on the IHISI command buffer could cause TOCTOU issues, which could lead to corruption of SMRAM and escalation of privileges.
CVE-2022-32471 is the case number assigned to this vulnerability, which has as CVSS v3 base score of 8.2.
Further, DMA attacks on the VariableRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges.
CVE-2022-32475 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 8.2.
In another issue, DMA attacks on the FvbServicesRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges.
CVE-2022-32477 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 8.2.
In addition, DMA attacks on the SdHostDriver buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges.
CVE-2022-32953 is the case number assigned to this vulnerability, which has as CVSS v3 base score of 7.8.
Also, DMA attacks on the SdMmcDevice buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges.
CVE-2022-32954 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.8.
The product sees use in the critical manufacturing, energy, and water and wastewater sectors, and on a global basis.
No known public exploits specifically target these vulnerabilities. However, an attacker could leverages these low complexity vulnerabilities.
In terms of mitigations, no fix is currently available for these vulnerabilities. Siemens recommends users follow its general security recommendations.
As a general security measure, Siemens recommends users protect network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends users configure the environment according to Siemens’ operational guidelines for Industrial Security.
Click here for more information on Siemens security advisory SSA-957369.

