QID 590739

Date Published: 2022-03-17

QID 590739: Siemens SIMATIC S7-1200 Improper Authentication Vulnerability (ICSA-21-222-09)

AFFECTED PRODUCTS
The following versions of SIMATIC are affected:
S7-1200 CPU family (incl. SIPLUS variants): Version 4.5.0

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could allow an attacker using TIA Portal v13 or later versions to bypass authentication and download arbitrary programs to the PLC.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-222-09 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590739

    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-222-09 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-21-222-09