QID 590640

Date Published: 2022-01-04

QID 590640: Siemens Power Meters Urgent/11 Transmission Control Protocol/Internet Protocol (TCP/IP) Stack Multiple Vulnerabilities (SSA-352504)

AFFECTED PRODUCTS
Siemens Power Meters Series 9410:All versions prior to V2.2.1
Siemens Power Meters Series 9810: All versions prior to V2.2.1 .

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

The vulnerability could allow an attacker to execute a variety of exploits for the purpose of Denial-ofService (DoS), data extraction, RCE, etc. targeting both availability and confidentiality of the devices and data.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to update to latest versionSSA-352504: for affected packages and patching details.

    Software Advisories
    Advisory ID Software Component Link
    SSA-352504 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-352504.pdf