QID 591110

Date Published: 2022-10-14

QID 591110: Siemens SIMATIC S7-1200 Multiple Vulnerabilities (ICSA-14-079-02, SSA-654382)

AFFECTED PRODUCTS
SIMATIC S7-1200 CPU family (incl. SIPLUS variants): V2.X and V3.x, Update to V4.0

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

The six vulnerabilities discovered in the SIMATIC S7-1200 CPU firmware may allow attackers to perform denial-of-service (DoS) attacks with specially crafted HTTP(S), ISO-TSAP, or Profinet network packets. The integrated web server may also be vulnerable to cross-site request forgery (CSRF) and privilege escalation. The vulnerabilities could be exploited over the network without authentication.

  • CVSS V3 rated as Low - 0 severity.
  • CVSS V2 rated as Critical - 8.3 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-14-079-02 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-14-079-02 URL Logo www.cisa.gov/uscert/ics/advisories/ICSA-14-079-02
    ssa-654382 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-654382.pdf