QID 590738

Date Published: 2022-03-17

QID 590738: Siemens Industrial Products LLDP Multiple Vulnerabilities (ICSA-21-194-07)

AFFECTED PRODUCTS
Siemens reports these vulnerabilities affect the following products:
SIMATIC HMI Unified Comfort Panels: All versions prior to v17
SIMATIC NET CP 1243-1 (incl. SIPLUS variants): All versions
SIMATIC NET CP 1243-8 IRC: All versions
SIMATIC NET CP 1542SP-1: All versions
SIMATIC NET CP 1542SP-1 IRC (incl. SIPLUS variants): All versions
SIMATIC NET CP 1543-1 (incl. SIPLUS variants): All versions
SIMATIC NET CP 1543SP-1 (incl. SIPLUS variants): All versions
SIMATIC NET CP 1545-1: All versions
--------- Begin Update A Part 1 of 2 ---------
SINUMERIK ONE MCP: All versions prior to v2.0.1
--------- End Update A Part 1 of 2 ---------
TIM 1531 IRC (incl. SIPLUS NET variants): All versions prior to v2.2

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-194-07 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590738

    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-194-07 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-21-194-07