QID 590552
Date Published: 2021-10-21
QID 590552: Siemens SIMATIC Software Products (Update A) Incorrect Permission Assignment for Critical Resource Vulnerability (ICSA-21-194-06)
AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following SIMATIC software products:
SIMATIC STEP 7 V5.X: All versions prior to v5.7
SINAMICS STARTER (containing STEP 7 OEM version): All versions prior to 5.4 SP2 HF1
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"
Successful exploitation of this vulnerability could allow an attacker to manipulate parameters or the behavior of devices configured by the affected software products.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-21-194-06 for affected packages and patching details.
Vendor References
- ICSA-21-194-06 -
www.us-cert.gov/ics/advisories/ICSA-21-194-06
CVEs related to QID 590552
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-21-194-06 |
|