QID 590929

Date Published: 2022-07-22

QID 590929: Siemens SIMATIC Industrial Thin Client V3 Multiple Vulnerabilities (SSA-505225)

Affected Product and Versions
SIMATIC ITC1500 V3 All versions prior to V3.1 Update to V3.1
SIMATIC ITC1500 V3 PRO All versions prior to V3.1 Update to V3.1
SIMATIC ITC1900 V3 All versions prior to V3.1 Update to V3.1
SIMATIC ITC1900 V3 PRO All versions prior to V3.1 Update to V3.1
SIMATIC ITC2200 V3 All versions prior to V3.1 Update to V3.1
SIMATIC ITC2200 V3 PRO All versions prior to V3.1 Update to V3.1

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

An attacker with local access to the system could potentially disclose information from protected memory areas via a side-channel attack on the processor cache.

  • CVSS V3 rated as Medium - 5.6 severity.
  • CVSS V2 rated as Medium - 4.7 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ssa-505225 for affected packages and patching details.

    CVEs related to QID 590929

    Software Advisories
    Advisory ID Software Component Link
    ssa-505225 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-505225.pdf