QID 591139

Date Published: 2022-10-21

QID 591139: Siemens Industrial Products LLDP (Update D) Multiple Vulnerabilities (icsa-21-194-07, SSA-941426)

AFFECTED PRODUCTS
Siemens reports these vulnerabilities affect the following products:
SIMATIC HMI Unified Comfort Panels: All versions prior to v17
SIMATIC NET CP 1542SP-1 (6GK7542-6UX00-0XE0): All versions
SIMATIC NET CP 1542SP-1 IRC (incl. SIPLUS variants) (6GK7243-8RX30-0XE0): All versions
SIMATIC NET CP 1543-1 (incl. SIPLUS variants): All versions
SIMATIC NET CP 1543SP-1 (incl. SIPLUS variants): All versions
SIMATIC NET CP 1545-1 (6GK7545-1GX00-0XE0): All versions prior to v1.1
SIPLUS S7-1200 CP 1243-1 (6AG1243-1BX30-2AX0): All versions prior to v3.3.46
SIPLUS S7-1200 CP 1243-1 RAIL (6AG2243-1BX30-1XE0): All versions prior to v3.3.46
SIMATIC NET 1243-1 (incl. SIPLUS variants) (6GK7243-1BX30-0XE0): All versions prior to v3.3.46
SIMATIC NET 1243-8 IRC (6GK7243-8RX30-0XE0): All versions prior to v3.3.46
SINUMERIK ONE MCP: All versions prior to v2.0.1
TIM 1531 IRC (incl. SIPLUS NET variants): All versions prior to v2.2

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section icsa-21-194-07 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591139

    Software Advisories
    Advisory ID Software Component Link
    icsa-21-194-07 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-21-194-07