QID 590694
Date Published: 2022-03-17
QID 590694: Siemens LOGO! CMR and SIMATIC RTU 3000 (Update A) Vulnerability (ICSA-21-257-13)
AFFECTED PRODUCTS
The following versions of LOGO! controllers and SIMATIC monitors are affected:
LOGO! CMR2020 (6GK7142-7BX00-0AX0): All versions prior to v2.2
LOGO! CMR2040 (6GK7142-7EX00-0AX0): All versions prior to v2.2
SIMATIC RTU 3000 family: All versions
SIMATIC RTU3010C (6NH3112-0BA00-0XX0): All versions prior to v4.0.9
SIMATIC RTU3030C (6NH3112-3BA00-0XX0): All versions prior to v4.0.9
SIMATIC RTU3031C (6NH3112-3BB00-0XX0): All versions prior to v4.0.9
SIMATIC RTU3041C (6NH3112-4BB00-0XX0): All versions prior to v4.0.9
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
Successful exploitation of this vulnerability could allow an attacker with network access to the LAN interface of an affected device to hijack an ongoing connection or spoof a new one.
Customers are advised to refer to CERT MITIGATIONS section ICSA-21-257-13 for affected packages and patching details.
- ICSA-21-257-13 -
www.us-cert.gov/ics/advisories/ICSA-21-257-13
CVEs related to QID 590694
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-21-257-13 |
|