ICSA-22-132-13: Siemens Industrial Devices using libcurl
CISA advisory · released 2022-05-10
Source record Collected from CISA's CSAF advisory feed
- Distribution label in the document: TLP:WHITE
- Revision 3, 2022-08-09 (final)
CISA's summary
Summary: Vulnerabilities in third-party component cURL could allow an attacker to interfere with the affected products in various ways. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens recommends countermeasures for products where updates are not, or not yet available.
Products, as the advisory lists them
| Vendor | Product | Version |
|---|---|---|
| Siemens | LOGO! CMR family | vers:all/* |
| Siemens | RUGGEDCOM RM1224 LTE(4G) EU | <V7.1 |
| Siemens | RUGGEDCOM RM1224 LTE(4G) NAM | <V7.1 |
| Siemens | SCALANCE M804PB | <V7.1 |
| Siemens | SCALANCE M812-1 ADSL-Router (Annex A) | <V7.1 |
| Siemens | SCALANCE M812-1 ADSL-Router (Annex B) | <V7.1 |
| Siemens | SCALANCE M816-1 ADSL-Router (Annex A) | <V7.1 |
| Siemens | SCALANCE M816-1 ADSL-Router (Annex B) | <V7.1 |
| Siemens | SCALANCE M826-2 SHDSL-Router | <V7.1 |
| Siemens | SCALANCE M874-2 | <V7.1 |
| Siemens | SCALANCE M874-3 | <V7.1 |
| Siemens | SCALANCE M876-3 (EVDO) | <V7.1 |
| Siemens | SCALANCE M876-3 (ROK) | <V7.1 |
| Siemens | SCALANCE M876-4 (EU) | <V7.1 |
| Siemens | SCALANCE M876-4 (NAM) | <V7.1 |
| Siemens | SCALANCE MUM856-1 (EU) | <V7.1 |
| Siemens | SCALANCE MUM856-1 (RoW) | <V7.1 |
| Siemens | SCALANCE S615 | <V7.1 |
| Siemens | SIMATIC CP 1242-7 V2 | <V3.3.46 |
| Siemens | SIMATIC CP 1243-1 | <V3.3.46 |
| Siemens | SIMATIC CP 1243-7 LTE EU | <V3.3.46 |
| Siemens | SIMATIC CP 1243-7 LTE US | <V3.3.46 |
| Siemens | SIMATIC CP 1243-8 IRC | <V3.3.46 |
| Siemens | SIMATIC CP 1543-1 | <V3.0.22 |
| Siemens | SIMATIC CP 1545-1 | <V1.1 |
| Siemens | SIMATIC RTU3010C | <V5.0.14 |
| Siemens | SIMATIC RTU3030C | <V5.0.14 |
| Siemens | SIMATIC RTU3031C | <V5.0.14 |
| Siemens | SIMATIC RTU3041C | <V5.0.14 |
| Siemens | SINEMA Remote Connect Client | <V3.1 |
| Siemens | SIPLUS NET CP 1242-7 V2 | <V3.3.46 |
| Siemens | SIPLUS NET CP 1543-1 | <V3.0.22 |
| Siemens | SIPLUS S7-1200 CP 1243-1 | <V3.3.46 |
| Siemens | SIPLUS S7-1200 CP 1243-1 RAIL | <V3.3.46 |
DeSpy has not checked any unit, hardware revision or firmware.
Vulnerabilities in this advisory
- CVE-2021-22901 — CVE-2021-22901 · CWE-416
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at run-time sets up support for TLS 1.3 session tickets on a connection using OpenSSL, it stores pointers to the transfer in-memory object for later retrieval when a session ticket arrives. If the connection is used by multiple transfers (like with a reused HTTP/1.1 connection or multiplexed HTTP/2 connection) that first transfer object might be freed before the new session is established on that connection and then the function will access a memory buffer that might be freed. When using that memory, libcurl might even call a function pointer in the object, making it possible for a remote code execution if the server could somehow manage to get crafted memory content into the correct place in memory.
- CVE-2021-22924 — CVE-2021-22924 · CWE-706
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse, if one of them matches the setup. Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*, which could lead to libcurl reusing wrong connections. File paths are, or can be, case sensitive on many systems but not all, and can even vary depending on used file systems. The comparison also didn't include the 'issuer cert' which a transfer can set to qualify how to verify the server certificate.
Acknowledgments, as the advisory lists them
- Siemens ProductCERT: reporting these vulnerabilities to CISA.
The advisory's legal notice
Siemens Security Advisories are subject to the terms and conditions contained in Siemens' underlying license terms or other applicable agreements previously agreed to with Siemens (hereinafter "License Terms"). To the extent applicable to information, software or documentation made available in or through a Siemens Security Advisory, the Terms of Use of Siemens' Global Website (https://www.siemens.com/terms_of_use, hereinafter "Terms of Use"), in particular Sections 8-10 of the Terms of Use, shall apply additionally. In case of conflicts, the License Terms shall prevail over the Terms of Use.
Sources
DeSpy's copy of this version is dated 2026-09-28.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.