QID 590761

QID 590761: Siemens Industrial Products Intel CPUs (Update B) Multiple Vulnerabilities (ICSA-21-222-05)

AFFECTED PRODUCTS
The following Siemens products are affected:
SIMATIC Drive Controller Family: All versions
SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions
SIMATIC Field PG M5: All versions
SIMATIC Field PG M6: All versions
SIMATIC IPC127E: All versions
SIMATIC IPC427E: All versions
SIMATIC IPC477E: All versions
SIMATIC IPC477E Pro: All versions
SIMATIC IPC527GE: All versions
SIMATIC IPC547G: All versions
SIMATIC IPC627E: All versions
SIMATIC IPC647E: All versions
SIMATIC IPC677E: All versions
SIMATIC IPC847E: All BIOS versions prior to v25.02.10
SIMATIC ITP1000: All versions
SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (MLFB: 6ES7518-4AX00-1AC0, 6AG1518-4AX00-4AC0, incl. SIPLUS variant): All versions
SIMATIC S7-1500 CPU 1518F-4 PN-DP MFP (MLFB: 6ES7518-4FX00-1AC0): All versions
SINUMERIK 828D HW PPU.4: All versions
SINUMERIK MC MCU 1720: All versions
SINUMERIK ONE / SINUMERIK 840D sl Handheld Terminal HT 10: All versions
SINUMERIK ONE PPU 1740: All versions
SINUMERIK ONE NCU 1740: All versions prior to v05.00.00.00
SIMATIC IPC127E: All versions prior to v21.01.07
SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions prior to v0209_0105

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities could lead to unauthorized access to sensitive data, privilege escalation, and configuration change.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-222-05 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-222-05 URL Logo www.us-cert.gov/ics/advisories/ICSA-21-222-05