Siemens has updates available to handle multiple vulnerabilities in various third-party components used in SCALANCE W-700 devices, according to a report with CISA.

The vulnerabilities are generation of error message containing sensitive information, out-of-bounds write, NULL pointer dereference, out-of-bounds read, improper input validation, release of invalid pointer or reference, use after free, and prototype pollution.

Successful exploitation of these remotely exploitable vulnerabilities could allow an attacker to cause a denial-of-service condition or disclose sensitive data.

The following software suffers from the vulnerabilities:

  • SCALANCE WAM763-1 (6GK5763-1AL00-7DA0): All versions prior to v2.0
  • SCALANCE WAM766-1 (EU) (6GK5766-1GE00-7DA0): All versions prior to v2.0
  • SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0): All versions prior to v2.0
  • SCALANCE WAM766-1 EEC (EU) (6GK5766-1GE00-7TA0): All versions prior to v2.0
  • SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0): All versions prior to v2.0
  • SCALANCE WUM763-1 (6GK5763-1AL00-3DA0): All versions prior to v2.0
  • SCALANCE WUM763-1 (6GK5763-1AL00-3AA0): All versions prior to v2.0
  • SCALANCE WUM766-1 (EU) (6GK5766-1GE00-3DA0): All versions prior to v2.0
  • SCALANCE WUM766-1 (US) (6GK5766-1GE00-3DB0): All versions prior to v2.0

In one issue, Stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences when targeting ARM targets that spill the address of the stack protector guard, which allows an attacker to bypass the protection of -fstack-protector, -fstack-protector-all, fstack-protector-strong, and fstack-protector-explicit against stack overflow by controlling what the stack canary is compared against.

Schneider Bold

CVE-2018-12886 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 8.1.

In addition, Zlib versions before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

CVE-2018-25032 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.5.

Also, a NULL pointer dereference in Busybox’s man applet leads to a denial-of-service condition when a section name is supplied but no page argument is given.

CVE-2021-42373 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 5.1.

Further, an out-of-bounds heap read in Busybox’s unlzma applet leads to an information leak and a denial-of-service condition when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that internally supports LZMA compression.

CVE-2021-42374 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.5.

In another issue, an incorrect handling of a special element in Busybox’s ash applet leads to a denial-of-service condition when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This could be used for a denial-of-service attack under rare conditions of filtered command input.

CVE-2021-42375 is the case number assigned to this vulnerability, which has as CVSS v3 base score of 4.1.

In addition, a NULL pointer dereference in Busybox’s hush applet leads to a denial-of-service condition when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for a denial-of-service attack under very rare conditions of filtered command input.

CVE-2021-42376 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 4.1.

Also, an attacker-controlled pointer free in Busybox’s hush applet leads to a denial-of-service condition and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This could be used for remote code execution under rare conditions of filtered command input.

CVE-2021-42377 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.4.

Further, an use-after-free in Busybox’s awk applet leads to a denial-of-service condition and possibly code execution when processing a crafted awk pattern in the getvar_i function.

CVE-2021-42378 is the case number assigned to this vulnerability, which has as CVSS v3 base score of 6.6.

In another issue, an use-after-free in Busybox’s awk applet leads to a denial-of-service condition and possibly code execution when processing a crafted awk pattern in the next_input_file function.

CVE-2021-42379 is the case number assigned to this vulnerability, which has as CVSS v3 base score of 6.6.

In addition, an use-after-free in awk leads to a denial-of-service condition and possibly code execution when processing a crafted awk pattern in the clrvar function.

CVE-2021-42380 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.6.

Also, an use-after-free in awk leads to a denial-of-service condition and possibly code execution when processing a crafted awk pattern in the hash_init function.

CVE-2021-42381 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.6.

Further, an use-after-free in awk leads to a denial-of-service condition and possibly code execution when processing a crafted awk pattern in the getvar_s function.

CVE-2021-42382 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.6.

In another issue, an use-after-free in awk leads to a denial-of-service condition and possibly code execution when processing a crafted awk pattern in the evaluate function.

CVE-2021-42383 is the case number assigned to this vulnerability, which has as CVSS v3 base score of 6.6.

In addition, an use-after-free in Busybox’s awk applet leads to a denial-of-service condition and possibly code execution when processing a crafted awk pattern in the handle_special function.

CVE-2021-42384 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.6.

Also, an use-after-free in awk leads to a denial-of-service condition and possibly code execution when processing a crafted awk pattern in the evaluate function.

CVE-2021-42385 is the case number assigned to this vulnerability, which has as CVSS v3 base score of 6.6.

Further, an use-after-free in awk leads to a denial-of-service condition and possibly code execution when processing a crafted awk pattern in the nvalloc function.

CVE-2021-42386 is the case number assigned to this vulnerability, which has as CVSS v3 base score of 6.6.

In addition, jQuery Cookie 1.4.1 is affected by prototype pollution, which could lead to DOM cross-site scripting (XSS).

CVE-2022-23395 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.1.

The product sees use in multiple industrial sectors, and on a global basis.

No known public exploits specifically target these vulnerabilities. These vulnerabilities have a high attack complexity.

Siemens recommends updating the software to v2.0 or later.

As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends users configure the environment according to Siemens’ operational guidelines for Industrial Security.

For more information, click on Siemens security advisory SSA-565386.

ISSSource

Pin It on Pinterest

Share This