New Siemens Security Advisory (SSA) Formats

Siemens ProductCERT introduced new formats - namely HTML and CSAF - for its security advisories and will phase out the traditional formats (PDF, TXT, and CVRF) over time. This article gives a short overview on the reasoning behind this decision and what the future brings.

Current situation

Until recently, Siemens Security Advisories (SSA) were available in PDF and TXT format only. PDF has an appealing look and feel, could be printed out and is the format that is downloaded the most. The TXT files provide the data in raw format, e.g. for environments where PDF was considered as unnecessary overhead. It is also digitally signed to ensure authenticity. The advisories are also available in the CVRF format since December 2019. This machine-readable XML format was not widely known or used, but provided useful insights on the features and limitations of machine-readable advisories.

Why change a running system?

With the advance of digitalization in our products, the number of published Siemens Security Advisories grew steadily over the years. In 2021, 160 advisories were published and, coincidently, the same amount of advisories were updated.

There is an increase in the total number of affected products listed in the advisories. This is (at least partly) due to the fact that more and more product families, version lines and variants of an affected product are listed in order to uniquely identify an affected product. In addition, the total number of 3rd party vulnerabilities that got published as an advisory also increased significantly. So, not only do the number of published and updated advisories keep increasing - each document becomes significantly longer and the advantage of providing a quick overview is lost on screen or in printouts.

We expect this trend to continue as more products and more vulnerabilities will likely need to be published. The sheer amount of information requires an increased level of automation on the reader's side. Vulnerability handling systems can help in prioritizing vulnerabilities and products that are especially critical in the customer’s environment, while filtering out those which are not. Unfortunately, such systems cannot digest the current advisory formats.

CSAF format

The Common Security Advisory Framework Version 2.0 (CSAF) standard is the successor of the CVRF standard and was released in November 2021. This JSON-based, machine-readable format standardizes how security advisory information can be published and distributed, independently of the origin, distributor or industry segment. For large installations with many products, this is the way to keep track with the growing amount of vulnerability information. The information can be parsed and fed into asset management systems to quickly determine which parts of the installation are affected by which vulnerabilities.

HTML format

While CSAF does provide significant advantages, not all advisory readers will have an asset management system ready in 2022 to use together with CSAF. Thus it is a fair assumption that advisories will still be read by humans for quite some time. Therefore, advisories in HTML format are also available. Currently, the look and feel is closely aligned with the known PDF format to make it easy to switch from one to the other. This will change in the future as improvements for handling and readability are already planned for the HTML documents. Readers should be able to expand parts of the advisory that are especially relevant in their installation. A product family can be broken down into its single product names if required. If not, it could be collapsed back again to preserve readability.

The future

We expect other vendors, integrators, operators and tool manufacturers to adopt the CSAF standard. Much of the vulnerability handling process will possibly be automated and the workload for vulnerability handlers will become easier to handle once the integration into their asset management systems is completed. For smaller installations, the HTML format will provide detailed information with the comfort to the human reader which is not possible with the current PDF format.
As the PDF, TXT and CVRF formats become less relevant over time, support for them will eventually be removed.