Siemens CADRA Software Vulnerable to Multiple Zlib and Foxit Flaws
Siemens has released an update for its CADRA software to address multiple critical vulnerabilities stemming from its use of the zlib and Foxit libraries, which could lead to denial-of-service or compromise data integrity and confidentiality.

Siemens has issued a security advisory detailing several vulnerabilities affecting its CADRA software, specifically versions prior to V2511. These flaws are primarily rooted in the software's reliance on the widely used zlib compression library, as well as components from Foxit.
The vulnerabilities span a range of issues including improper input validation, out-of-bounds writes, integer overflows, and buffer overflows. These weaknesses, when exploited, can allow remote attackers to cause denial-of-service conditions, leading to system crashes, or to impact the confidentiality and integrity of data processed by the CADRA software. The severity of these flaws is reflected in their CVSS scores, with some reaching as high as 9.8 (Critical).
Several specific CVEs are associated with these vulnerabilities. For instance, CVE-2018-25032 and CVE-2022-37434 highlight issues within zlib related to memory corruption and buffer overflows during compression and decompression, respectively. Additionally, CVE-2023-45853 points to an integer overflow and heap-based buffer overflow within the MiniZip component of zlib, which is used for handling ZIP archives. Other vulnerabilities, such as CVE-2005-2096 and CVE-2016-9840, also stem from improper handling of compressed data within zlib.
The advisory notes that these vulnerabilities affect CADRA versions prior to V2511. Siemens has addressed these issues by releasing version V2511 of CADRA, which incorporates fixes for the identified weaknesses. The company strongly recommends that users update to this latest version to mitigate the risks associated with these vulnerabilities.
For environments where immediate updates are not feasible, Siemens also suggests specific countermeasures. While the advisory does not detail these countermeasures, they typically involve network segmentation, access control, and monitoring to limit the potential attack surface and detect malicious activity.
The affected CADRA software is deployed globally across critical infrastructure sectors, including chemical, commercial facilities, and energy. The widespread use of this software underscores the importance of timely patching and security updates to protect these vital operational environments.
This advisory serves as a reminder of the ongoing security challenges associated with third-party libraries. Even widely adopted libraries like zlib can harbor vulnerabilities that, when integrated into larger applications, can expose critical systems to significant risks. Organizations relying on software that incorporates such libraries must maintain robust vulnerability management programs.