QID 590962

Date Published: 2022-08-05

QID 590962: Siemens SIMATIC MV500 Devices Multiple Vulnerabilities (ICSA-22-195-03) (SSA-348662)

AFFECTED PRODUCTS
The following versions of SIMATIC MV500 Devices, Optical Readers, are affected:
SIMATIC MV540 H (6GF3540-0GE10): All versions prior to v3.3
SIMATIC MV540 S (6GF3540-0CD10): All versions prior to v3.3
SIMATIC MV550 H (6GF3550-0GE10): All versions prior to v3.3
SIMATIC MV550 S (6GF3550-0CD10): All versions prior to v3.3
SIMATIC MV560 U (6GF3560-0LE10): All versions prior to v3.3
SIMATIC MV560 X (6GF3560-0HE10): All versions prior to v3.3

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities could allow attackers to hijack other users web-based management sessions or access data on the device without prior authentication.

  • CVSS V3 rated as High - 8 severity.
  • CVSS V2 rated as High - 6 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-22-195-03 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590962

    Software Advisories
    Advisory ID Software Component Link
    ICSA-22-195-03 URL Logo www.us-cert.gov/ics/advisories/ICSA-22-195-03