QID 590968

Date Published: 2022-08-05

QID 590968: Siemens Desigo PXC and DXR Devices (Update A) Multiple Vulnerabilities (ICSA-22-132-10) (ssa-662649) (ssa-626968)

AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following Desigo DXR and PXC controllers:
Desigo DXR2: All versions prior to v01.21.142.5-22
Desigo PXC3: All versions prior to v01.21.142.4-18
Desigo PXC4: All versions prior to v02.20.142.10-10884
Desigo PXC5: All versions prior to v02.20.142.10-10884

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities could allow an attacker to potentially intercept unencrypted transmission of sensitive information, cause a denial-of-service condition, perform remote code execution, or disable and reset a device to factory state.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as Critical - 8.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-22-132-10 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-22-132-10 URL Logo www.us-cert.gov/ics/advisories/ICSA-22-132-10