Siemens has an update available to handle a deserialization of untrusted data vulnerability in its SINEC NMS, according to a report with CISA.

Successful exploitation of this remotely exploitable vulnerability, which Siemens self-reported, could allow attackers with write access to the logback configuration file to execute arbitrary code on the system.

All versions prior to v1.03 Siemens SINEC NMS, a network management system, suffer from the issue.

In the vulnerability, in Siemens SINEC NMS logback version 1.2.7 and prior, an attacker with the required privileges can edit configuration files to could craft malicious packages allowing the execution arbitrary code loaded from LDAP servers.

CVE-2021-42550 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.6.

Schneider Bold

The product sees use mainly in the energy sector, and on a global basis.

No known public exploits specifically target this vulnerability. This vulnerability has a high attack complexity.

Siemens recommends updating to version 1.0.3 or later.

Siemens identified the following workaround and mitigation customers can apply to reduce risk: Restrict the write access to the logback configuration file (logback.xml) to trusted personnel.

As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends  configuring the environment according to Siemens’ operational guidelines for industrial security and following the recommendations in the product manuals.

For more information, see Siemens Security Advisory SSA-371761.

ISSSource

Pin It on Pinterest

Share This