QID 590694

Date Published: 2022-03-17

QID 590694: Siemens LOGO! CMR and SIMATIC RTU 3000 (Update A) Vulnerability (ICSA-21-257-13)

AFFECTED PRODUCTS
The following versions of LOGO! controllers and SIMATIC monitors are affected:
LOGO! CMR2020 (6GK7142-7BX00-0AX0): All versions prior to v2.2
LOGO! CMR2040 (6GK7142-7EX00-0AX0): All versions prior to v2.2
SIMATIC RTU 3000 family: All versions
SIMATIC RTU3010C (6NH3112-0BA00-0XX0): All versions prior to v4.0.9
SIMATIC RTU3030C (6NH3112-3BA00-0XX0): All versions prior to v4.0.9
SIMATIC RTU3031C (6NH3112-3BB00-0XX0): All versions prior to v4.0.9
SIMATIC RTU3041C (6NH3112-4BB00-0XX0): All versions prior to v4.0.9

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could allow an attacker with network access to the LAN interface of an affected device to hijack an ongoing connection or spoof a new one.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 4.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-257-13 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590694

    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-257-13 URL Logo www.us-cert.gov/ics/advisories/ICSA-21-257-13