{
  "document": {
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Disclosure is not limited. (TLPv2: TLP:CLEAR)",
      "tlp": {
        "label": "WHITE"
      }
    },
    "notes": [
      {
        "category": "summary",
        "text": "There are multiple vulnerabilities in an underlying Link Layer Discovery Protocol (LLDP) third party library.\n\nSiemens has released updates for the affected products and recommends to update to the latest versions.",
        "title": "Summary"
      },
      {
        "category": "general",
        "text": "As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: \nhttps://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals.\nAdditional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity",
        "title": "General Recommendations"
      },
      {
        "category": "general",
        "text": "For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories",
        "title": "Additional Resources"
      },
      {
        "category": "legal_disclaimer",
        "text": "Siemens Security Advisories are subject to the terms and conditions contained in Siemens' underlying license terms or other applicable agreements previously agreed to with Siemens (hereinafter \"License Terms\"). To the extent applicable to information, software or documentation made available in or through a Siemens Security Advisory, the Terms of Use of Siemens' Global Website (https://www.siemens.com/terms_of_use, hereinafter \"Terms of Use\"), in particular Sections 8-10 of the Terms of Use, shall apply additionally. In case of conflicts, the License Terms shall prevail over the Terms of Use.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "productcert@siemens.com",
      "name": "Siemens ProductCERT",
      "namespace": "https://www.siemens.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "SSA-941426: Multiple LLDP Vulnerabilities in Industrial Products - PDF Version",
        "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-941426.pdf"
      },
      {
        "category": "self",
        "summary": "SSA-941426: Multiple LLDP Vulnerabilities in Industrial Products - TXT Version",
        "url": "https://cert-portal.siemens.com/productcert/txt/ssa-941426.txt"
      },
      {
        "category": "self",
        "summary": "SSA-941426: Multiple LLDP Vulnerabilities in Industrial Products - CSAF Version",
        "url": "https://cert-portal.siemens.com/productcert/csaf/ssa-941426.json"
      }
    ],
    "title": "SSA-941426: Multiple LLDP Vulnerabilities in Industrial Products",
    "tracking": {
      "current_release_date": "2023-03-14T00:00:00Z",
      "generator": {
        "engine": {
          "name": "Siemens ProductCERT CSAF Generator",
          "version": "1"
        }
      },
      "id": "SSA-941426",
      "initial_release_date": "2021-07-13T00:00:00Z",
      "revision_history": [
        {
          "date": "2021-07-13T00:00:00Z",
          "legacy_version": "1.0",
          "number": "1",
          "summary": "Publication Date"
        },
        {
          "date": "2021-08-10T00:00:00Z",
          "legacy_version": "1.1",
          "number": "2",
          "summary": "Added solution for SINUMERIK ONE MCP and SIMATIC NET CP 1543-1"
        },
        {
          "date": "2022-06-14T00:00:00Z",
          "legacy_version": "1.2",
          "number": "3",
          "summary": "Added fix for SIMATIC CP 1545-1"
        },
        {
          "date": "2022-08-09T00:00:00Z",
          "legacy_version": "1.3",
          "number": "4",
          "summary": "Added fix for SIMATIC CP 1243-1 and CP 1243-8 IRC"
        },
        {
          "date": "2023-03-14T00:00:00Z",
          "legacy_version": "1.4",
          "number": "5",
          "summary": "Added fix for SIMATIC CP 1542SP-1, SIMATIC CP 1542SP-1 IRC, and SIMATIC CP 1543SP-1"
        }
      ],
      "status": "interim",
      "version": "5"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "< V3.3.46",
                "product": {
                  "name": "SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0)",
                  "product_id": "1",
                  "product_identification_helper": {
                    "model_numbers": [
                      "6GK7243-1BX30-0XE0"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "< V3.3.46",
                "product": {
                  "name": "SIMATIC CP 1243-8 IRC (6GK7243-8RX30-0XE0)",
                  "product_id": "2",
                  "product_identification_helper": {
                    "model_numbers": [
                      "6GK7243-8RX30-0XE0"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "SIMATIC CP 1243-8 IRC (6GK7243-8RX30-0XE0)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "< V2.2.28",
                "product": {
                  "name": "SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0)",
                  "product_id": "3",
                  "product_identification_helper": {
                    "model_numbers": [
                      "6GK7542-6UX00-0XE0"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "< V2.2.28",
                "product": {
                  "name": "SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0)",
                  "product_id": "4",
                  "product_identification_helper": {
                    "model_numbers": [
                      "6GK7542-6VX00-0XE0"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "< V3.0",
                "product": {
                  "name": "SIMATIC CP 1543-1 (6GK7543-1AX00-0XE0)",
                  "product_id": "5",
                  "product_identification_helper": {
                    "model_numbers": [
                      "6GK7543-1AX00-0XE0"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "SIMATIC CP 1543-1 (6GK7543-1AX00-0XE0)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "< V2.2.28",
                "product": {
                  "name": "SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0)",
                  "product_id": "6",
                  "product_identification_helper": {
                    "model_numbers": [
                      "6GK7543-6WX00-0XE0"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "< V1.1",
                "product": {
                  "name": "SIMATIC CP 1545-1 (6GK7545-1GX00-0XE0)",
                  "product_id": "7",
                  "product_identification_helper": {
                    "model_numbers": [
                      "6GK7545-1GX00-0XE0"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "SIMATIC CP 1545-1 (6GK7545-1GX00-0XE0)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "< V17",
                "product": {
                  "name": "SIMATIC HMI Unified Comfort Panels",
                  "product_id": "8"
                }
              }
            ],
            "category": "product_name",
            "name": "SIMATIC HMI Unified Comfort Panels"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "< V2.0.1",
                "product": {
                  "name": "SINUMERIK ONE MCP",
                  "product_id": "9"
                }
              }
            ],
            "category": "product_name",
            "name": "SINUMERIK ONE MCP"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "< V2.2.28",
                "product": {
                  "name": "SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0)",
                  "product_id": "10",
                  "product_identification_helper": {
                    "model_numbers": [
                      "6AG2542-6VX00-4XE0"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "< V2.2.28",
                "product": {
                  "name": "SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0)",
                  "product_id": "11",
                  "product_identification_helper": {
                    "model_numbers": [
                      "6AG1543-6WX00-7XE0"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "< V2.2.28",
                "product": {
                  "name": "SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0)",
                  "product_id": "12",
                  "product_identification_helper": {
                    "model_numbers": [
                      "6AG2543-6WX00-4XE0"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "< V3.0",
                "product": {
                  "name": "SIPLUS NET CP 1543-1 (6AG1543-1AX00-2XE0)",
                  "product_id": "13",
                  "product_identification_helper": {
                    "model_numbers": [
                      "6AG1543-1AX00-2XE0"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "SIPLUS NET CP 1543-1 (6AG1543-1AX00-2XE0)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "< V3.3.46",
                "product": {
                  "name": "SIPLUS S7-1200 CP 1243-1 (6AG1243-1BX30-2AX0)",
                  "product_id": "14",
                  "product_identification_helper": {
                    "model_numbers": [
                      "6AG1243-1BX30-2AX0"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "SIPLUS S7-1200 CP 1243-1 (6AG1243-1BX30-2AX0)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "< V3.3.46",
                "product": {
                  "name": "SIPLUS S7-1200 CP 1243-1 RAIL (6AG2243-1BX30-1XE0)",
                  "product_id": "15",
                  "product_identification_helper": {
                    "model_numbers": [
                      "6AG2243-1BX30-1XE0"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "SIPLUS S7-1200 CP 1243-1 RAIL (6AG2243-1BX30-1XE0)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "< V2.2",
                "product": {
                  "name": "SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0)",
                  "product_id": "16",
                  "product_identification_helper": {
                    "model_numbers": [
                      "6AG1543-1MX00-7XE0"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0)"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "< V2.2",
                "product": {
                  "name": "TIM 1531 IRC (6GK7543-1MX00-0XE0)",
                  "product_id": "17",
                  "product_identification_helper": {
                    "model_numbers": [
                      "6GK7543-1MX00-0XE0"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "TIM 1531 IRC (6GK7543-1MX00-0XE0)"
          }
        ],
        "category": "vendor",
        "name": "Siemens"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2015-8011",
      "cwe": {
        "id": "CWE-120",
        "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"
      },
      "notes": [
        {
          "category": "summary",
          "text": "Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries.",
          "title": "Summary"
        }
      ],
      "product_status": {
        "known_affected": [
          "1",
          "2",
          "3",
          "4",
          "5",
          "6",
          "7",
          "8",
          "9",
          "10",
          "11",
          "12",
          "13",
          "14",
          "15",
          "16",
          "17"
        ]
      },
      "remediations": [
        {
          "category": "mitigation",
          "details": "Disable LLDP protocol support on Ethernet port. This will potentially disrupt the network visibility.",
          "product_ids": [
            "1",
            "2",
            "3",
            "4",
            "5",
            "6",
            "7",
            "8",
            "9",
            "10",
            "11",
            "12",
            "13",
            "14",
            "15",
            "16",
            "17"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Update to V2.2.28 or later version",
          "product_ids": [
            "3",
            "4",
            "6",
            "10",
            "11",
            "12"
          ],
          "url": "https://support.industry.siemens.com/cs/ww/en/view/109817067/"
        },
        {
          "category": "vendor_fix",
          "details": "Update to V17 or later version",
          "product_ids": [
            "8"
          ],
          "url": "https://support.industry.siemens.com/cs/ww/en/view/109746530"
        },
        {
          "category": "vendor_fix",
          "details": "Update to V2.0.1 or later version\nPlease contact your Siemens representative for information on how to obtain the update.",
          "product_ids": [
            "9"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Update to V3.3.46 or later version",
          "product_ids": [
            "1",
            "2",
            "14",
            "15"
          ],
          "url": "https://support.industry.siemens.com/cs/ww/en/view/109812218"
        },
        {
          "category": "vendor_fix",
          "details": "Update to V1.1 or later version",
          "product_ids": [
            "7"
          ],
          "url": "https://support.industry.siemens.com/cs/ww/en/view/109811116/"
        },
        {
          "category": "vendor_fix",
          "details": "Update to V3.0 or later version",
          "product_ids": [
            "5",
            "13"
          ],
          "url": "https://support.industry.siemens.com/cs/ww/en/view/109800773/"
        },
        {
          "category": "vendor_fix",
          "details": "Update to V2.2 or later version",
          "product_ids": [
            "16",
            "17"
          ],
          "url": "https://support.industry.siemens.com/cs/ww/en/view/109798331/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
            "version": "3.1"
          },
          "products": [
            "1",
            "2",
            "3",
            "4",
            "5",
            "6",
            "7",
            "8",
            "9",
            "10",
            "11",
            "12",
            "13",
            "14",
            "15",
            "16",
            "17"
          ]
        }
      ],
      "title": "CVE-2015-8011"
    },
    {
      "cve": "CVE-2020-27827",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "summary",
          "text": "Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service.",
          "title": "Summary"
        }
      ],
      "product_status": {
        "known_affected": [
          "1",
          "2",
          "3",
          "4",
          "5",
          "6",
          "7",
          "8",
          "9",
          "10",
          "11",
          "12",
          "13",
          "14",
          "15",
          "16",
          "17"
        ]
      },
      "remediations": [
        {
          "category": "mitigation",
          "details": "Disable LLDP protocol support on Ethernet port. This will potentially disrupt the network visibility.",
          "product_ids": [
            "1",
            "2",
            "3",
            "4",
            "5",
            "6",
            "7",
            "8",
            "9",
            "10",
            "11",
            "12",
            "13",
            "14",
            "15",
            "16",
            "17"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Update to V2.2.28 or later version",
          "product_ids": [
            "3",
            "4",
            "6",
            "10",
            "11",
            "12"
          ],
          "url": "https://support.industry.siemens.com/cs/ww/en/view/109817067/"
        },
        {
          "category": "vendor_fix",
          "details": "Update to V17 or later version",
          "product_ids": [
            "8"
          ],
          "url": "https://support.industry.siemens.com/cs/ww/en/view/109746530"
        },
        {
          "category": "vendor_fix",
          "details": "Update to V2.0.1 or later version\nPlease contact your Siemens representative for information on how to obtain the update.",
          "product_ids": [
            "9"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Update to V3.3.46 or later version",
          "product_ids": [
            "1",
            "2",
            "14",
            "15"
          ],
          "url": "https://support.industry.siemens.com/cs/ww/en/view/109812218"
        },
        {
          "category": "vendor_fix",
          "details": "Update to V1.1 or later version",
          "product_ids": [
            "7"
          ],
          "url": "https://support.industry.siemens.com/cs/ww/en/view/109811116/"
        },
        {
          "category": "vendor_fix",
          "details": "Update to V3.0 or later version",
          "product_ids": [
            "5",
            "13"
          ],
          "url": "https://support.industry.siemens.com/cs/ww/en/view/109800773/"
        },
        {
          "category": "vendor_fix",
          "details": "Update to V2.2 or later version",
          "product_ids": [
            "16",
            "17"
          ],
          "url": "https://support.industry.siemens.com/cs/ww/en/view/109798331/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C",
            "version": "3.1"
          },
          "products": [
            "1",
            "2",
            "3",
            "4",
            "5",
            "6",
            "7",
            "8",
            "9",
            "10",
            "11",
            "12",
            "13",
            "14",
            "15",
            "16",
            "17"
          ]
        }
      ],
      "title": "CVE-2020-27827"
    }
  ]
}