ICSA-22-167-17: Siemens OpenSSL Affecting Industrial Products
CISA advisory · released 2022-06-14
Source record Collected from CISA's CSAF advisory feed
- Distribution label in the document: TLP:WHITE
- Revision 2, 2024-07-09 (final)
CISA's summary
Summary: SINEMA Remote Connect Server is affected by multiple vulnerabilities, including - A cross-site scripting vulnerability in an error message pop up window (CVE-2022-29034) - Several authentication bypass, privilege escalation and integrity check vulnerabilities (CVE-2022-32251 through -32261) - A command injection vulnerability in the file upload service (CVE-2022-32262) - A chosen-plaintext attack against HTTP over TLS ("BREACH", CVE-2022-27221) - Information disclosure vulnerabilities in the curl component (CVE-2021-22924 through -22925) - Several vulnerabilities in the libexpat library, that could be exploited when the server is parsing untrusted XML files (CVE-2021-45960, CVE-2021-46143, CVE-2022-22822 through -22827, CVE-2022-23852, CVE-2022-23990, CVE-2022-25235 through -25236, CVE-2022-25313 through -25315. Siemens has released an update for the SINEMA Remote Connect Server and recommends to update to the latest version. Note that the update also contains additional fixes for vulnerabilities documented in Siemens Security Advisories SSA-244969, SSA-539476, SSA-685781 and SSA-712929.
Products, as the advisory lists them
| Vendor | Product | Version |
|---|---|---|
| Siemens | SINEMA Remote Connect Server | <V3.1 |
DeSpy has not checked any unit, hardware revision or firmware.
Vulnerabilities in this advisory
- CVE-2021-22924 — CVE-2021-22924 · CWE-706
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse, if one of them matches the setup. Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*, which could lead to libcurl reusing wrong connections. File paths are, or can be, case sensitive on many systems but not all, and can even vary depending on used file systems. The comparison also didn't include the 'issuer cert' which a transfer can set to qualify how to verify the server certificate.
- CVE-2021-22925 — CVE-2021-22925 · CWE-908
curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl. This rarely used option is used to send variable=content pairs to TELNET servers. Due to flaw in the option parser for sending `NEW_ENV` variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server. Therefore potentially revealing sensitive internal information to the server using a clear-text network protocol. This could happen because curl did not call and use sscanf() correctly when parsing the string provided by the application.
- CVE-2021-45960 — CVE-2021-45960 · CWE-400
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).
- CVE-2021-46143 — CVE-2021-46143 · CWE-190
In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.
- CVE-2022-22822 — CVE-2022-22822 · CWE-190
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
- CVE-2022-22823 — CVE-2022-22823 · CWE-190
build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
- CVE-2022-22824 — CVE-2022-22824 · CWE-190
defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
- CVE-2022-22825 — CVE-2022-22825 · CWE-190
lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
- CVE-2022-22826 — CVE-2022-22826 · CWE-190
nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
- CVE-2022-22827 — CVE-2022-22827 · CWE-190
storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
- CVE-2022-23852 — CVE-2022-23852 · CWE-190
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
- CVE-2022-23990 — CVE-2022-23990 · CWE-190
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
- CVE-2022-25235 — CVE-2022-25235 · CWE-116
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
- CVE-2022-25236 — CVE-2022-25236 · CWE-668
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
- CVE-2022-25313 — CVE-2022-25313 · CWE-400
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
- CVE-2022-25314 — CVE-2022-25314 · CWE-190
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
- CVE-2022-25315 — CVE-2022-25315 · CWE-190
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
- CVE-2022-27221 — CVE-2022-27221 · CWE-203
An attacker in machine-in-the-middle could obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially matches an unknown string in an HTTP response body, aka a "BREACH" attack.
- CVE-2022-29034 — CVE-2022-29034 · CWE-79
An error message pop up window in the web interface of the affected application does not prevent injection of JavaScript code. This could allow attackers to perform reflected cross-site scripting (XSS) attacks.
- CVE-2022-32251 — CVE-2022-32251 · CWE-306
There is a missing authentication verification for a resource used to change the roles and permissions of a user. This could allow an attacker to change the permissions of any user and gain the privileges of an administrative user.
- CVE-2022-32252 — CVE-2022-32252 · CWE-345
The application does not perform the integrity check of the update packages. Without validation, an admin user might be tricked to install a malicious package, granting root privileges to an attacker.
- CVE-2022-32253 — CVE-2022-32253 · CWE-20
Due to improper input validation, the OpenSSL certificate's password could be printed to a file reachable by an attacker.
- CVE-2022-32254 — CVE-2022-32254 · CWE-532
A customized HTTP POST request could force the application to write the status of a given user to a log file, exposing sensitive user information that could provide valuable guidance to an attacker.
- CVE-2022-32255 — CVE-2022-32255 · CWE-284
The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to unauthorized access to limited information.
- CVE-2022-32256 — CVE-2022-32256 · CWE-284
The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to low privileged users accessing privileged information.
- CVE-2022-32258 — CVE-2022-32258 · CWE-448
The affected application contains an older feature that allows to import device configurations via a specific endpoint. An attacker could use this vulnerability for information disclosure.
- CVE-2022-32259 — CVE-2022-32259 · CWE-1244
The system images for installation or update of the affected application contain unit test scripts with sensitive information. An attacker could gain information about testing architecture and also tamper with test configuration.
- CVE-2022-32261 — CVE-2022-32261 · CWE-233
The affected application contains a misconfiguration in the APT update. This could allow an attacker to add insecure packages to the application.
- CVE-2022-32262 — CVE-2022-32262 · CWE-77
The affected application contains a file upload server that is vulnerable to command injection. An attacker could use this to achieve arbitrary code execution.
Acknowledgments, as the advisory lists them
- Siemens ProductCERT: reporting these vulnerabilities to CISA.
The advisory's legal notice
Siemens Security Advisories are subject to the terms and conditions contained in Siemens' underlying license terms or other applicable agreements previously agreed to with Siemens (hereinafter "License Terms"). To the extent applicable to information, software or documentation made available in or through a Siemens Security Advisory, the Terms of Use of Siemens' Global Website (https://www.siemens.com/terms_of_use, hereinafter "Terms of Use"), in particular Sections 8-10 of the Terms of Use, shall apply additionally. In case of conflicts, the License Terms shall prevail over the Terms of Use.
Sources
DeSpy's copy of this version is dated 2026-09-28.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.