15 vulnerabilities discovered in Siemens industrial control management system – The Record by Recorded Future
Fifteen vulnerabilities affecting Siemens SINEC network management system (NMS) were unveiled this week, according to new research published by security company Claroty.
The bugs affect all versions before V1.0 SP2 Update 1 and Siemens urged users to update their versions as soon as possible.
Noam Moshe, vulnerability researcher with Claroty, told The Record that the most concerning of the 15 vulnerabilities which include denial-of-service attacks, credential leaks, and remote code execution in certain circumstances revolve around CVE-2021-33723 and CVE-2021-33722.
Moshe noted that network management systems are used to centrally monitor, manage, and configure industrial networks with tens of thousands of devices. They are used widely in industrial automation across several industries, including manufacturing, oil and gas, electrical grids, and more.
Most concerning is the chaining of CVE-2021-33723 and CVE-2021-33722, which creates a powerful exploit that could give an attacker elevated permissions on the SINEC system to NT AUTHORITYSYSTEM, full system access, Moshe said.
From there, an attacker could remotely execute code and also compromise other Siemens devices on the network managed by SINEC.
In a report on the vulnerabilities, Claroty showed how CVE-2021-33723 can be used to gain administrative access and CVE-2021-33722 can then be exploited to instigate a breach.
Siemens SINEC is an NMS built for OT networks and designed for centrally monitoring, managing, and configuring Siemens devices. The SINEC system is configured with all the necessary credentials for the devices in the network so it can communicate, monitor and eventually control the remote devices in the network.
Operators use SINEC to perform firmware upgrades or query the status of remote devices in the network from network switches to Siemens PLCs. It is also used to control and maintain other ICS related equipment.
From an attackers perspective, conquering the NMS is key to getting a strong foothold in the network, Moshe explained.
This is because the attacker could use the normal NMS functionality to take control over network devices by changing firmwares, shutting down remote devices, or even moving across the network while hacking the same remote devices that the SINEC system manages.
Some of the other vulnerabilities discovered, like CVE-2021-33727, authenticate an attacker so they can download the profile of any user, allowing them to leak confidential information. CVE-2021-33733 gives attackers the ability to execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.
Other industrial control security experts agreed with Moshes assessment that CVE-2021-33723 and CVE-2021-33722 are the most concerning of the 15 vulnerabilities.
Nozomi Networks Roya Gordon said the two bugs are worrying because they are the beginning of the chain of vulnerabilities in which successful exploitation of the two CVEs allows for the exploitation of the other 13 CVEs.
I will say that whenever you see a blog announcing a vulnerability and it includes the vendor advisory, thats a good sign. It means that there is a fix you can implement right away to prevent all possible exploits, Gordon said.
These vulnerabilities allow a threat actor to gain admin rights to the system and pretty much do whatever they want. They can even Live off the Land, which is a technique threat actors use to erase their steps, making it difficult for IR responders to trace their activity. This also makes it easier for the attacker to remain in the system undetected before even executing an attack, because they appear to be a privileged user. A threat actor with admin capabilities lurking in an OT environment is very alarming.
Ron Fabela, CTO of SynSaber, told The Record that the core vulnerabilities are in not only the control system applications themselves, but also with those subsystems that manage them.
If an adversary has network access to industrial control systems, they often do not need to exploit vulnerabilities in order to impact or disrupt operations, Fabela explained.
Fabela added that the NMS in this case could be a treasure trove of information and control, undoing network segmentation that may be in place and allowing deeper infiltration of the control system network.
Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Originally posted here:
15 vulnerabilities discovered in Siemens industrial control management system - The Record by Recorded Future
- Media bill wont give government direct editorial control, but risks putting press in biased, moneyed hands - The Times of Israel - November 5th, 2025 [November 5th, 2025]
- Likud ministers contentious media regulation bill passes first reading in Knesset - The Times of Israel - November 5th, 2025 [November 5th, 2025]
- From CBS to TikTok, US media are falling to Trumps allies. This is how democracy crumbles | Owen Jones - The Guardian - October 31st, 2025 [October 31st, 2025]
- Denmark reportedly withdraws Chat Control proposal following controversy - therecord.media - October 31st, 2025 [October 31st, 2025]
- Opinion | Crypto and Trump Corrupted America - The New York Times - October 26th, 2025 [October 26th, 2025]
- After internal struggle, Colorados Libertarians look to pivot. It could impact Congress. - The Denver Post - October 26th, 2025 [October 26th, 2025]
- Argentina goes to polls amid economic crisis and Trump interference - The Guardian - October 26th, 2025 [October 26th, 2025]
- Five things to know about Argentina's pivotal midterm election - Purdue Exponent - October 26th, 2025 [October 26th, 2025]
- Milei promised to drain Argentinas swamp. Now hes sinki... - The Observer - October 26th, 2025 [October 26th, 2025]
- After Tunisian shipwreck kills 40, archbishop urges world to tackle migration crisis - Catholic News Agency - October 26th, 2025 [October 26th, 2025]
- Migrant prison farce proves the system is out of control - The Telegraph - October 26th, 2025 [October 26th, 2025]
- Labour blasted as 'too weak' to deport small boat migrants while pressure mounts on Keir Starmer to adopt Rwanda-style plan - GB News - October 26th, 2025 [October 26th, 2025]
- France backing away from pledge to intercept migrant boats, sources tell BBC - BBC - October 26th, 2025 [October 26th, 2025]
- Migrants abandon children on Spanish holidays so they can claim asylum - The Telegraph - October 26th, 2025 [October 26th, 2025]
- Ireland is making a dangerous mistake on immigration - The Telegraph - October 26th, 2025 [October 26th, 2025]
- Migrant sent back to France in one in, one out deal returns to UK - The Independent - October 26th, 2025 [October 26th, 2025]
- Syrian migrant with 'deep voice and receding grey hair' is ruled to be a child - GB News - October 26th, 2025 [October 26th, 2025]
- Stop lecturing migrant hotel protesters, Dublin is more proof of this total betrayal - Adam Brooks - GB News - October 26th, 2025 [October 26th, 2025]
- 'It's a FARCE!' Tom Harwood up in arms while Labour 'takes the mickey' with 'one in, one out' scheme - GB News - October 26th, 2025 [October 26th, 2025]
- Secret report reveals Home Office culture of defeatism on migration - The Telegraph - October 26th, 2025 [October 26th, 2025]
- Lammy: Catching migrant shows one in, one out is working - The Telegraph - October 26th, 2025 [October 26th, 2025]
- Migrant guilty of murdering woman with screwdriver - The Telegraph - October 26th, 2025 [October 26th, 2025]
- If UK controlled its own borders, killer illegal migrant would never have been here - Rakib Ehsan - GB News - October 26th, 2025 [October 26th, 2025]
- Mark White's Migration Monitor: The small boats farce continues - and the next act looks even darker - GB News - October 26th, 2025 [October 26th, 2025]
- Epping migrant STILL on the loose as David Lammy admits Ethiopian sex offender is 'at large in London' - GB News - October 26th, 2025 [October 26th, 2025]
- Cal State Invited Tech Companies to Remake Learning With A.I. - The New York Times - October 26th, 2025 [October 26th, 2025]
- Artificial intelligence (AI) - The Guardian - October 26th, 2025 [October 26th, 2025]
- Banking and Finance Symposium to Address AI, Technology Issues - University of Mississippi | Ole Miss - October 26th, 2025 [October 26th, 2025]
- AI Is Even Putting Animal Actors Out of Work - Futurism - October 26th, 2025 [October 26th, 2025]
- Impacts of artificial intelligence (AI) in teaching and learning of built environment students in a developing country - Taylor & Francis Online - October 26th, 2025 [October 26th, 2025]
- 3 Top Artificial Intelligence (AI) Stocks Ready for a Bull Run - The Motley Fool - October 26th, 2025 [October 26th, 2025]
- Israel playing catch-up in AI after two years of war - JNS.org - October 26th, 2025 [October 26th, 2025]
- Why Analysts See Alibabas Growth Story Changing With Cloud and AI Driving New Optimism - Yahoo Finance - October 26th, 2025 [October 26th, 2025]
- The AI Bubble Is Poised to Burst, Yet the Next One Is in the Works - 36Kr - October 26th, 2025 [October 26th, 2025]
- Beyond Chips: AI Infrastructure Spending Is Projected to Hit $490 Billion -- Who Benefits Most? - Yahoo Finance - October 26th, 2025 [October 26th, 2025]
- Jordan to lead MSUs AI efforts in new role, Willard named interim VP for research, economic development - Mississippi State University - October 26th, 2025 [October 26th, 2025]
- Artificial Intelligence and Medical Translation: An Editorial on the Ethical Considerations for Emerging Technologies in Dermatology - Cureus - October 26th, 2025 [October 26th, 2025]
- Scientists spent years teaching a robot to play sports. It's still terrible - BBC Science Focus Magazine - October 26th, 2025 [October 26th, 2025]
- There is no life: Kupiansks slow demise reflects the fate of cities on Ukraines frontline - The Guardian - October 26th, 2025 [October 26th, 2025]
- Ukraines Coalition of the Willing Has the Wind at Its Back - The New York Times - October 26th, 2025 [October 26th, 2025]
- Russia arrests Ukrainian biologist for backing curbs on Antarctic krill fishing - The Guardian - October 26th, 2025 [October 26th, 2025]
- Six metres below ground: inside the secret hospital treating Ukrainian soldiers injured by Russian drones - The Guardian - October 26th, 2025 [October 26th, 2025]
- Jet-powered bombs and planes-turned-missiles: Ukrainian and Russian militaries improvise and adapt in a battle of wits - CNN - October 26th, 2025 [October 26th, 2025]
- 3 Years Ago It Was a Casting Agency. Now It Has $1 Billion in Drone Contracts. - The New York Times - October 26th, 2025 [October 26th, 2025]
- Russia targets Kyiv with drones, killing 3 and wounding 29 - ABC News - Breaking News, Latest News and Videos - October 26th, 2025 [October 26th, 2025]
- More than Tomahawks: what Ukraines soldiers say they actually need - The Kyiv Independent - October 26th, 2025 [October 26th, 2025]
- Ukraines ingenuity alone will not be enough to win the war - The Independent - October 26th, 2025 [October 26th, 2025]
- After War Turned Their Fields Into Frontlines, Ukraines Farmers Return to Reclaim Them - UNITED24 Media - October 26th, 2025 [October 26th, 2025]
- Turkey urges US to act after accusing Israel of breaching Gaza ceasefire - Sky News - October 26th, 2025 [October 26th, 2025]
- President Erdoan visits Oman, his last stopover in the Gulf | Daily Sabah - Daily Sabah - October 26th, 2025 [October 26th, 2025]
- Erdoan to meet with DEM Party delegation on terror-free process | Daily Sabah - Daily Sabah - October 26th, 2025 [October 26th, 2025]
- Erdoan renews call for UN reform over Gaza in 80th anniversary message | Daily Sabah - Daily Sabah - October 26th, 2025 [October 26th, 2025]
- Foreign media: Russia reiterated its stance on full control of Donbas to the US last weekend - Bitget - October 23rd, 2025 [October 23rd, 2025]
- Health Ministry and PAHO Host Media Session on Upcoming National Tobacco Control Bill - Love FM Belize - October 19th, 2025 [October 19th, 2025]
- Ask Lucas: My teens social media obsession is out of control - Cleveland.com - October 17th, 2025 [October 17th, 2025]
- Molding the Message - China Media Project - October 17th, 2025 [October 17th, 2025]
- From clicks to curation: How publishers can reclaim control of the media ecosystem - Digiday - October 15th, 2025 [October 15th, 2025]
- Orbans Propaganda State in Hungary Is Starting to Show Cracks - The New York Times - October 15th, 2025 [October 15th, 2025]
- How Chioma Ikeh is helping small businesses take back control of their social media - Businessday NG - October 13th, 2025 [October 13th, 2025]
- Germany will not support 'Chat Control' message scanning in the EU - The Record from Recorded Future News - October 11th, 2025 [October 11th, 2025]
- Media: IDF will control 53% of Gaza in the first phase of the agreement - Baku.ws - October 11th, 2025 [October 11th, 2025]
- Rob Reiner Says U.S. Will Become an Autocracy if Trump Is Allowed to Control the Media and Commandeer the Election: We Have a Year to Stop Him -... - October 7th, 2025 [October 7th, 2025]
- Rob Reiner Warns Trump Wants "Control Of Media" To Steal 2026 Election - Deadline - October 7th, 2025 [October 7th, 2025]
- Move over Murdochs, the Ellisons are the new family dynasty shaking up US media - BBC - September 30th, 2025 [September 30th, 2025]
- How Trumps TikTok Deal Could Change the Future of US Media - TODAY.com - September 30th, 2025 [September 30th, 2025]
- Meghan Markles Media Battles: Control, Conflicts, and the Struggle for Credibility - vocal.media - September 28th, 2025 [September 28th, 2025]
- Trump announces deal to put TikTok under control of US investors - ABC News - Breaking News, Latest News and Videos - September 28th, 2025 [September 28th, 2025]
- President Tebbounes Media Exchange: Inflation Control, Electoral Reform, and a Drive Toward Modernization - - September 28th, 2025 [September 28th, 2025]
- Raptors GM Bobby Webster meets with the media ahead of first season with full team control - Toronto Star - September 28th, 2025 [September 28th, 2025]
- Murdochs TikTok? Trump offers allies another lever of media control - The Guardian - September 25th, 2025 [September 25th, 2025]
- Even legacy media admit left-wing violence is out of control - The Heartlander - September 25th, 2025 [September 25th, 2025]
- Capture the Media, Control the Culture? - The American Prospect - September 23rd, 2025 [September 23rd, 2025]
- Whats actually in the Media Control Act? - Maldives Independent - September 23rd, 2025 [September 23rd, 2025]
- Power Play: Murdochs, Ellison, and Dell Join Forces for TikTok Bid - International Business Times UK - September 23rd, 2025 [September 23rd, 2025]
- Jimmy Kimmel and the MAGA strong-arming of American media - Media Matters for America - September 19th, 2025 [September 19th, 2025]
- Abbreviated Pundit Roundup: Controlling the media controls the message - Daily Kos - September 19th, 2025 [September 19th, 2025]
- The 31-day sprint: a timeline of the "media control law" - Maldives Independent - September 19th, 2025 [September 19th, 2025]
- Trump Admin Says Framework Reached for U.S. Owners to Take Control of TikTok - Gizmodo - September 17th, 2025 [September 17th, 2025]
- "We have a prime ministerial republic"/ Media: Changes to the Constitution, control of the Assembly and the opposition - cna.al - September 17th, 2025 [September 17th, 2025]
- Rupert Murdochs family reaches deal on who will control media empire after his death - Toronto Sun - September 15th, 2025 [September 15th, 2025]