QID 591127

Date Published: 2022-10-21

QID 591127: Siemens SIMATIC S7-1200 and S7-1500 CPU Families Weak Key Protection Vulnerability (SSA-568427,icsa-22-286-04)

AFFECTED PRODUCTS
SIMATIC Drive Controller family: All versions prior to 2.9.2
SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (including SIPLUS variants): All versions prior to 21.9
SIMATIC ET 200SP Open controller CPU 1515SP PC (including SIPLUS variants): All versions
SIMATIC S7-1200 CPU family (including SIPLUS variants): All versions prior to V4.5.0
SIMATIC S7-1500 CPU family (including related ET200 CPUs and SIPLUS variants): All versions prior to 2.9.2
SIMATIC S7-1500 Software Controller: All version prior to 21.9

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could expose confidential configuration data.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Low - 0 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ssa-568427 for affected packages and patching details.

    CVEs related to QID 591127

    Software Advisories
    Advisory ID Software Component Link
    icsa-22-286-04 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-286-04
    ssa-568427 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-568427.pdf