QID 590608

Date Published: 2021-12-06

QID 590608: Siemens SIMATIC HMI Devices (Update E) Multiple Vulnerabilities (ICSA-15-099-01E)

Affected products:
V13: All versions prior to WinCC (TIA Portal) V13 SP1 Upd2
V12: All versions prior to WinCC (TIA Portal) V12 SP1 Upd5
SIMATIC PCS 7: All versions prior to V8.1 SP1

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"

An attacker exploiting these vulnerabilities could conduct man-in-the-middle attacks, denialof service attacks, and possibly authenticate themselves as valid users.

  • CVSS V2 rated as High - 6.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-15-099-01E for affected packages and patching details.

    Vendor References

    CVEs related to QID 590608

    Software Advisories
    Advisory ID Software Component Link
    ICSA-15-099-01E URL Logo www.us-cert.gov/ics/advisories/ICSA-15-099-01E