ICSA-22-349-09: Siemens Products affected by OpenSSL 3.0
CISA advisory · released 2022-12-13
Source record Collected from CISA's CSAF advisory feed
- Distribution label in the document: TLP:WHITE
- Revision 6, 2026-04-16 (final)
CISA's summary
Summary: The openSSL component, versions 3.0.0 through 3.0.6, contains two buffer overflow vulnerabilities (CVE-2022-3602, CVE-2022-3786) in the X.509 certificate verification [0]. They could allow an attacker to create a denial of service condition or execute arbitrary code on a vulnerable TLS server (if the server requests client certificate authentication), or on a vulnerable TLS client. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens is preparing further updates and recommends specific countermeasures for products where updates are not, or not yet available. [0] https://www.openssl.org/news/secadv/20221101.txt
Products, as the advisory lists them
| Vendor | Product | Version |
|---|---|---|
| Siemens | Calibre ICE | vers:intdot/>=2022.4|<2023.1 |
| Siemens | Mcenter | vers:intdot/>=5.2.1|<5.3.0 |
| Siemens | SCALANCE X204RNA (HSR) (6GK5204-0BA00-2MB2) | vers:intdot/>=3.2.7|<3.2.8 |
| Siemens | SCALANCE X204RNA (PRP) (6GK5204-0BA00-2KB2) | vers:intdot/>=3.2.7|<3.2.8 |
| Siemens | SCALANCE X204RNA EEC (HSR) (6GK5204-0BS00-2NA3) | vers:intdot/>=3.2.7|<3.2.8 |
| Siemens | SCALANCE X204RNA EEC (PRP) (6GK5204-0BS00-3LA3) | vers:intdot/>=3.2.7|<3.2.8 |
| Siemens | SCALANCE X204RNA EEC (PRP/HSR) (6GK5204-0BS00-3PA3) | vers:intdot/>=3.2.7|<3.2.8 |
| Siemens | SICAM GridPass | vers:intdot/>=1.80|<2.20 |
| Siemens | SIMATIC RTLS Locating Manager | vers:intdot/>=2.13.0.0|<2.13.0.3 |
DeSpy has not checked any unit, hardware revision or firmware.
Vulnerabilities in this advisory
- CVE-2022-3602 — CVE-2022-3602 · CWE-120
A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer. An attacker can craft a malicious email address to overflow four attacker-controlled bytes on the stack. This buffer overflow could result in a crash (causing a denial of service) or potentially remote code execution. Many platforms implement stack overflow protections which would mitigate against the risk of remote code execution. The risk may be further mitigated based on stack layout for any given platform/compiler. Pre-announcements of CVE-2022-3602 described this issue as CRITICAL. Further analysis based on some of the mitigating factors described above have led this to be downgraded to HIGH. Users are still encouraged to upgrade to a new version as soon as possible. In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects. Fixed in OpenSSL 3.0.7 (Affected 3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6).
- CVE-2022-3786 — CVE-2022-3786 · CWE-120
A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed a malicious certificate or for an application to continue certificate verification despite failure to construct a path to a trusted issuer. An attacker can craft a malicious email address in a certificate to overflow an arbitrary number of bytes containing the `.' character (decimal 46) on the stack. This buffer overflow could result in a crash (causing a denial of service). In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects. Fixed in OpenSSL 3.0.7 (Affected 3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6).
Acknowledgments, as the advisory lists them
- Siemens ProductCERT: reported these vulnerabilities to CISA.
The advisory's legal notice
The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.
Sources
DeSpy's copy of this version is dated 2026-09-28.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.