QID 590717

Date Published: 2022-06-03

QID 590717: Siemens LOGO! CMR and SIMATIC RTU 3000 Multiple Vulnerabilities (ICSA-21-257-20)

AFFECTED PRODUCTS
The following versions of LOGO! CMR and SIMATIC RTU 3000 are affected:
LOGO! CMR2020 all versions prior to v2.2
LOGO! CMR2040 all versions prior to v2.2
SIMATIC RTU 3000 family all versions

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities could allow an attacker with access to any of the interfaces of an affected device to impact the availability or to communicate with invalid certificates.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-257-20 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590717

    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-257-20 URL Logo www.us-cert.gov/ics/advisories/ICSA-21-257-20