Successful exploitation of these remotely exploitable vulnerabilities, which Siemens self-reported, could allow an attacker to exploit buffer overflow and information disclosure vulnerabilities which could lead to information disclosure or unauthenticated remote code execution.
The following products of Siemens Scalance W1750D, a direct access point, suffer from the issue:
— Siemens SCALANCE W1750D (JP) (6GK5750-2HX01-1AD0): All versions prior to V8.10.0.9
— Siemens SCALANCE W1750D (ROW) (6GK5750-2HX01-1AA0): All versions prior to V8.10.0.9
— Siemens SCALANCE W1750D (USA) (6GK5750-2HX01-1AB0): All versions prior to V8.10.0.9
In one vulnerability, there e are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba’s access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
CVE-2023-35980 is the case number for this vulnerability, which has a CVSS v3.1 base score of 9.8.
In addition, there are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba’s access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
CVE-2023-35981 is the case number for this vulnerability, which has a CVSS v3.1 base score of 9.8.
Also, there are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba’s access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
CVE-2023-35982 is the case number for this vulnerability, which has a CVSS v3.1 base score of 9.8.
The product sees use mainly in the critical manufacturing sector, and on a global basis.
No known public exploit targets these vulnerabilities. However, an attacker could leverage these low complexity vulnerabilities.
Siemens identified the following specific workarounds and mitigations users can apply to reduce risk:
- Update to V8.10.0.9 or later version. The update is available upon request from customer support.
- The CLI and web-based management interfaces should end up restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above
- Enabling cluster-security via the cluster-security command will prevent the vulnerabilities from exploitation
As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens’ operational guidelines for industrial security and following recommendations in the product manuals.
Click here for more information on Siemens security advisory SSA-885980.

