QID 591007

Date Published: 2022-10-10

QID 591007: Siemens SIMATIC NMS and SINAMICS Stardrive (Update J) Multiple Vulnerabilities (ICSA-20-161-04)

Multiple vulnerabilities were discovered in Siemens SIMATIC NMS and SINAMICS Stardrive.
AFFECTED PRODUCTS
sinec nms all versions prior to 1.0.2
SINAMICS Stardrive: All versions prior to version 16 uodate 4

QID Detection Logic:(Authenticated):
The QID looks into the registry entries to check for the vulnerable versions of the product.

Successful exploitation of this vulnerability could allow authorized local users with administrative privileges to execute custom code with SYSTEM level privileges.

  • CVSS V3 rated as High - 6.7 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-20-161-04 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591007

    Software Advisories
    Advisory ID Software Component Link
    ICSA-20-161-04 URL Logo www.us-cert.gov/ics/advisories/ICSA-20-161-04