Siemens has some workaround available to handle a series of time-of-check time-of-use (TOCTOU) race condition vulnerabilities in its RUGGEDCOM APE1808 Product Family, according to a report with CISA.
Successful exploitation of these vulnerabilities, which Simens self reported, could allow an attacker to take full control of the product and its data. The vulnerability can have a high impact on confidentiality, integrity, and availability of the product.
The following software from Siemens suffers from the vulnerabilities:
- RUGGEDCOM APE1808 ADM (6GK6015-0AL20-0GL0): All versions
- RUGGEDCOM APE1808 ADM CC (6GK6015-0AL20-0GL1): All versions
- RUGGEDCOM APE1808 CKP (6GK6015-0AL20-0GK0): All versions
- RUGGEDCOM APE1808 CKP CC (6GK6015-0AL20-0GK1): All versions
- RUGGEDCOM APE1808 CLOUDCONNECT (6GK6015-0AL20-0GM0): All versions
- RUGGEDCOM APE1808 CLOUDCONNECT CC (6GK6015-0AL20-0GM1): All versions
- RUGGEDCOM APE1808 ELAN (6GK6015-0AL20-0GP0): All versions
- RUGGEDCOM APE1808 ELAN CC (6GK6015-0AL20-0GP1): All versions
- RUGGEDCOM APE1808 SAM-L (6GK6015-0AL20-0GN0): All versions
- RUGGEDCOM APE1808 SAM-L CC (6GK6015-0AL20-0GN1): All versions
- RUGGEDCOM APE1808CLA-P (6GK6015-0AL20-1AA0): All versions
- RUGGEDCOM APE1808CLA-P CC (6GK6015-0AL20-1AA1): All versions
- RUGGEDCOM APE1808CLA-S1 (6GK6015-0AL20-1AB0): All versions
- RUGGEDCOM APE1808CLA-S1 CC (6GK6015-0AL20-1AB1): All versions
- RUGGEDCOM APE1808CLA-S3 (6GK6015-0AL20-1AD0): All versions
- RUGGEDCOM APE1808CLA-S3 CC (6GK6015-0AL20-1AD1): All versions
- RUGGEDCOM APE1808CLA-S5 (6GK6015-0AL20-1AF0): All versions
- RUGGEDCOM APE1808CLA-S5 CC (6GK6015-0AL20-1AF1): All versions
- RUGGEDCOM APE1808LNX (6GK6015-0AL20-0GH0): All versions
- RUGGEDCOM APE1808LNX CC (6GK6015-0AL20-0GH1): All versions
- RUGGEDCOM APE1808W10 (6GK6015-0AL20-0GJ0): All versions
- RUGGEDCOM APE1808W10 CC (6GK6015-0AL20-0GJ1): All versionsIn one vulnerability, DMA attacks on the parameter buffer used by the PnpSmm driver could change the contents after parameter values have been checked, but before they are used (e.g. a TOCTOU attack). This issue was discovered by Insyde engineering during a security review.
CVE-2022-30774 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.4.
In addition, update description and links – DMA transactions that are targeted at input buffers used for the software SMI handler used by the FvbServicesRuntimeDxe driver – could cause SMRAM corruption through a TOCTOU attack. This issue was discovered by Insyde engineering based on the general description provided by Intel’s iSTARE group.
CVE-2022-31243 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.4.
Also, DMA transactions that are targeted at input buffers used for the FwBlockServiceSmm software SMI handler could cause SMRAM corruption through a TOCTOU attack. This issue was discovered by Insyde engineering based on the general description provided by Intel’s iSTARE group.
CVE-2022-33906 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.4.
In another issue, DMA transactions that are targeted at input buffers used for the software SMI handler used by the IdeBusDxe driver could cause SMRAM corruption through a TOCTOU attack. This issue was discovered by Insyde engineering based on the general description provided by Intel’s iSTARE group.
CVE-2022-33907 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.4.
In addition, DMA transactions that are targeted at input buffers – used for the SdHostDriver software SMI handler – could cause SMRAM corruption through a TOCTOU attack. This issue was discovered by Insyde engineering based on the general description provided by Intel’s iSTARE group.
CVE-2022-33908 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.0.
Also, DMA attacks on the parameter buffer used by the Int15ServiceSmm software SMI handler could lead to a TOCTOU attack on the SMI handler and lead to corruption of SMRAM. This issue was discovered by Insyde engineering during a security review.
CVE-2022-33982 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.4.
In another issue, DMA transactions that are targeted at input buffers – used for the SdMmcDevice software SMI handler – could cause SMRAM corruption through a TOCTOU attack. This issue was discovered by Insyde engineering based on the general description provided by Intel’s iSTARE group.
CVE-2022-33984 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.0.
The product sees use in multiple industrial sectors, and on a global basis.
No known public exploits specifically target these vulnerabilities. These vulnerabilities are not exploitable remotely. These vulnerabilities have a high attack complexity.
Siemens has identified the following specific workarounds and mitigations users can apply to reduce risk: Currently no fix is available, however, users should follow the security recommendations below.
As a security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens’ operational guidelines for industrial security and following recommendations in the product manuals.
For more information, click on the associated Siemens security advisory SSA-450613.

