A set of 13 vulnerabilities were discovered by researchers in Siemens, which powers devices used in the medical, industrial, automotive, and aerospace sectors.

See also: Siemens: Announces vulnerability in its industrial equipment
Dubbed NUCLEUS:13, the set of flaws affects the Nucleus TCP/IP stack and could be exploited to perform remote code execution on vulnerable devices, create a denial of service condition, or obtain information that could lead to harmful consequences.
The NUCLEUS:13 vulnerabilities were discovered by researchers at cybersecurity firm Forescout, a company focused on device security for healthcare providers.
The research is the latest part of a broader Forescout initiative, called Project Memoria, which brought together industry colleagues, universities, and research institutions to analyze the security of multiple TCP/IP stacks.
Project Memoria lasted 18 months and led to the discovery of 78 vulnerabilities in 14 TCP/IP stacks.
See also: Russia arrests cybersecurity company CEO for treason
Twelve of the thirteen flaws in NUCLEUS:13 received medium and high severity ratings, while one that stands out is CVE-2021-31886, a critical bug affecting the FTP server component that could allow attackers to take control of a vulnerable device.

In a report published by Forescout, it is noted that the issue is due to improper validation of the “USER” command by the FTP server. This leads to stack-based buffer overflows, which could lead to DoS and remote code execution (RCE) conditions.
Since Nucleus RTOS is “deployed on over 3 billion devices” in healthcare systems, it is vital that it is secure.
Currently, more than 5,000 devices are running a vulnerable version of the Nucleus RTOS, most of them in the healthcare sector.
Siemens has released updates that fix the NUCLEUS:13 vulnerabilities in Nucleus ReadyStart versions 3 (updated to version 2017.02.4 or later) and 4 (updated to version 4.1.1 or later).
See also: Did the admin of the DDoS WireX botnet attack a hotel chain?
The U.S. Cybersecurity and Infrastructure Security Administration (CISA) also provides the following error mitigation measures:
- Minimize network exposure for all devices and/or control systems and ensure they are not accessible from the Internet.
- Locate control system networks and remote devices behind firewalls and isolate them from the enterprise network.
- When remote access is required, use secure methods such as virtual private networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the latest available version. Also, keep in mind that a VPN is only as secure as its connected devices.
