QID 591192

Date Published: 2022-11-18

QID 591192: Siemens Linux-based Products (Update J) Vulnerability (ICSA-21-131-03, SSA-324955)

AFFECTED PRODUCTS
The following Siemens Linux-based products are affected:
RUGGEDCOM RM1224: All versions between v5.0 and v6.4
SCALANCE M-800: All versions between v5.0 and v6.4
SCALANCE S615: All versions between v5.0 and v6.4
SCALANCE SC-600: All versions prior to v2.1.3
SCALANCE W1750D: v8.3.0.1, v8.6.0, and v8.7.0
SIMATIC MV500 Family: All versions
SIMATIC CP 1243-7 LTE EU: Versions 3.1.39 and later, and prior to Version 3.3
SIMATIC CP 1243-7 LTE US: Versions 3.1.39 and later, and prior to Version 3.3
SIMATIC CP 1242-7 GPRS V2: Versions 3.1.39 and prior to Version 3.3
SIMATIC CP 1542SP-1 IRC (incl. SIPLUS variants): Versions 2.0 and later
SIMATIC CP 1542SP-1: Versions 2.0 and later
SIMATIC CP 1543-1 (incl. SIPLUS variants): Versions prior to 3.0
SIMATIC CP 1543SP-1 (incl SIPLUS variants): Versions 2.0 and later
SIMATIC CP 1545-1: All versions prior to v1.1
SIPLUS NET CP 1242-7 V2 (6AG1242-7KX31-7XE0): Versions between and including v3.1.39 and v3.3
SIPLUS S7-1200 CP 1243-1 (6AG1243-1BX30-2AX0): Versions between and including v3.1.39 and v3.3.46
SIPLUS S7-1200 CP 1243-1 RAIL (6AG2243-1BX30-1XE0): Versions between and including v3.1.39 and v3.3.46
SIMATIC CP 1243-1 (incl. SIPLUS variants): All versions 3.1.39 and newer to those prior to v3.3.3
SIMATIC CP 1243-8 IRC: All versions 3.1.39 and newer to those prior to v3.3.46
SIMATIC MV540 H (6GF3540-0GE10): All versions prior to 3.1
SIMATIC MV540 S (6GF3540-0CD10): All versions prior to 3.1
SIMATIC MV550 H (6GF3550-0GE10): All versions prior to 3.1
SIMATIC MV550 S (6GF3550-0CD10): All versions prior to 3.1
SIMATIC MV560 U (6GF3560-0LE10): All versions prior to 3.1
SIMATIC MV560 X (6GF3560-0HE10): All versions prior to 3.1
SIMATIC Cloud Connect 7 CC712 (6GK1411-1AC00): All versions from 1.0 to those prior to v1.6
SIMATIC Cloud Connect 7 CC716 (6GK1411-5AC00): All versions from 1.0 to those prior to v1.6
TIM 1531 IRC (6GK7543-1MX00-0XE0): All versions prior to 2.2 Update 1
SIPLUS TIM 1532 (6AG1543-1MX00-7XE0): All versions prior to 2.2 Update 1
SINEMA Remote Connect Server: All versions prior to v3.0 SP1

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could compromise confidentiality and integrity.

  • CVSS V3 rated as High - 7.4 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section icsa-21-131-03 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591192

    Software Advisories
    Advisory ID Software Component Link
    icsa-21-131-03 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-21-131-03
    ssa-324955 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-324955.pdf