Successful exploitation of these remotely exploitable vulnerabilities, discovered by Cyber Research Group from Raytheon UK, could allow an attacker to put the device into a denial-of-service state or retrieve parts of the memory.
Siemens reports these vulnerabilities affect all versions of LOGO! 8 BM (Base Module) devices.
In one issue, affected devices do not properly validate the structure of TCP packets in several methods. This could allow an attacker to cause buffer overflows, obtain control over the instruction counter, and run custom code.
CVE-2022-36361 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 9.8.
In addition, affected devices do not conduct certain validations during interaction. This could allow an unauthenticated remote attacker to manipulate the device’s IP address, making the device unreachable until the device could be power cycled.
CVE-2022-36362 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.5.
Also, affected devices do not properly validate an offset value, which can be defined in TCP packets when calling a method. This could allow an attacker to retrieve parts of memory content.
CVE-2022-36363 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 5.3.
The product sees use mainly in the chemical, energy, food and agriculture, and water and wastewater systems sectors, and on a global basis.
No known public exploits specifically target these vulnerabilities. However, an attacker with low skill level could leverage these low attack complexity vulnerabilities.
Siemens is preparing updates and recommends specific countermeasures for products where updates are not yet available:
- Only for versions prior to V8.3: Restrict access to port 10005/TCP to only trusted IP addresses.
- Only for versions including and since V8.3: Restrict access to port 8443/TCP to only trusted IP addresses.
- Restrict access to port 135/TCP to trusted IP addresses only.
As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens’ operational guidelines for industrial security and following the recommendations in the product manuals.
For more information, see the associated Siemens Security Advisory SSA-955858.

