{"document":{"acknowledgments":[{"organization":"CERTVDE","summary":"coordination","urls":["https://certvde.com"]}],"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"Improper buffer restrictions in the webserver used in SIMA² Master Station software versions < V 2.6 may allow an unauthenticated network-based attacker to stop the cyclic program on the device and cause a denial of service.","title":"Summary"},{"category":"description","text":"The webserver component of the automation runtime used implements insufficient checks on handling file uploads. This implementation could result in a memory violation, which in turn affects the stability of automation runtime.\nAn attacker could leverage this vulnerability to potentially cause a denial of service of the device.","title":"Impact"},{"category":"description","text":"AUMA recommends the following specific workarounds and mitigations: The access to the SIMA² should be restricted to legitimate network partners, using e.g. a sufficient firewall setup and robust network segmentation. In general, AUMA recommends implementing the Product Security Guideline for uses on Cybersecurity for the SIMA² Master Station.","title":"Mitigation"},{"category":"description","text":"The described vulnerabilities have been fixed in the product versions with software version V 2.6 or higher. SIMA² Master Stations with software versions < V 2.6 can be upgraded. AUMA recommends applying a product update at the earliest convenience","title":"Remediation"}],"publisher":{"category":"vendor","contact_details":"psirt@auma.com","name":"AUMA Riester GmbH & Co. KG","namespace":"https://auma.com"},"references":[{"category":"self","summary":"VDE-2022-024: Auma: SIMA² Master Station Denial of Service Vulnerability on Automation Runtime Webserver - HTML","url":"https://certvde.com/de/advisories/VDE-2022-024/"},{"category":"external","summary":"CERT@VDE Security Advisories for AUMA Riester GmbH & Co. KG","url":"https://certvde.com/en/advisories/vendor/auma/"},{"category":"self","summary":"VDE-2022-024: Auma: SIMA² Master Station Denial of Service Vulnerability on Automation Runtime Webserver - CSAF","url":"https://auma.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2022-024.json"}],"title":"Auma: SIMA² Master Station Denial of Service Vulnerability on Automation Runtime Webserver","tracking":{"aliases":["VDE-2022-024"],"current_release_date":"2025-05-14T13:00:15.000Z","generator":{"date":"2025-03-19T15:02:36.926Z","engine":{"name":"Secvisogram","version":"2.5.21"}},"id":"VDE-2022-024","initial_release_date":"2022-06-15T10:00:00.000Z","revision_history":[{"date":"2022-06-15T10:00:00.000Z","number":"1","summary":"initial revision"},{"date":"2025-05-14T13:00:15.000Z","number":"2","summary":"Fix: added distribution"}],"status":"final","version":"2"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"SIMA² Master Station","product":{"name":"SIMA² Master Station","product_id":"CSAFPID-11001"}}],"category":"product_family","name":"Hardware"},{"branches":[{"category":"product_version_range","name":"<v2.6","product":{"name":"Firmware <v2.6","product_id":"CSAFPID-21001"}},{"category":"product_version","name":"v2.6","product":{"name":"Firmware v2.6","product_id":"CSAFPID-22001"}}],"category":"product_family","name":"Firmware"}],"category":"vendor","name":"AUMA Riester GmbH & Co. KG"}],"relationships":[{"category":"installed_on","full_product_name":{"name":"Firmware <v2.6 installed on SIMA² Master Station","product_id":"CSAFPID-31001"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"Firmware v2.6 installed on SIMA² Master Station","product_id":"CSAFPID-32001"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11001"}]},"vulnerabilities":[{"cve":"CVE-2021-22275","cwe":{"id":"CWE-120","name":"Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"},"notes":[{"category":"summary","text":"Buffer Overflow vulnerability in B&R Automation Runtime webserver allows an unauthenticated network-based attacker to stop the cyclic program on the device and cause a denial of service."}],"product_status":{"fixed":["CSAFPID-32001"],"known_affected":["CSAFPID-31001"]},"remediations":[{"category":"mitigation","details":"AUMA recommends the following specific workarounds and mitigations:\n\nThe access to the SIMA² should be restricted to legitimate network partners, using e.g. a sufficient firewall setup and robust network segmentation.\nIn general, AUMA recommends implementing the Product Security Guideline for uses on Cybersecurity for the SIMA² Master Station.","product_ids":["CSAFPID-31001"]},{"category":"vendor_fix","details":"The described vulnerabilities have been fixed in the product versions with software version V 2.6 or\nhigher. SIMA² Master Stations with software versions < V 2.6 can be upgraded. AUMA recommends applying a product update at the earliest convenience","product_ids":["CSAFPID-31001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.6,"baseSeverity":"HIGH","confidentialityImpact":"NONE","environmentalScore":8.6,"environmentalSeverity":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"CHANGED","temporalScore":8.6,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","version":"3.1"},"products":["CSAFPID-31001"]}],"title":"CVE-2021-22275"}]}