QID 590701
Date Published: 2022-06-30
QID 590701: Siemens SINAMICS Medium Voltage Products Remote Access (Update B) Multiple Vulnerabilities (ICSA-21-131-04) (ssa-286838)
AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following SINAMICS products with remote access enabled on SIMATIC comfort HMI Panels:
SINAMICS GH150: All versions
SINAMICS GL150 (with option X30): All versions
SINAMICS GM150 (with option X30): All versions
SINAMICS SH150: All versions
SINAMICS SL150: All versions
SINAMICS SM120: All versions
SINAMICS SM150: All versions
SINAMICS SM150i: All versions
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
Successful exploitation of this vulnerability could allow an attacker to gain full remote access to the HMI.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-21-131-04 for affected packages and patching details.
Vendor References
- ICSA-21-131-04 -
www.us-cert.gov/ics/advisories/ICSA-21-131-04
CVEs related to QID 590701
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-21-131-04 |
|