QID 591201
Date Published: 2022-12-22
QID 591201: Siemens WinCC (TIA Portal), IPC Diagbase and Simatic Step 7 (TIA Portal) Open Secure Sockets Layer (OpenSSL) Multiple Vulnerabilities (SSA-179516)
Several Siemens industrial products are affected by a vulnerability in OpenSSL, that could result in data being sent out unencrypted by the SSL/TLS record layer.
AFFECTED PRODUCTS
SIMATIC IPC DiagBase: all versions prior to V2.1.1.0
SIMATIC WinCC (TIA Portal): all versions prior to V13 SP2 Update 2
SIMATIC WinCC (TIA Portal): all versions prior to V14 SP1 Update 6
SIMATIC WinCC (TIA Portal): all versions prior to V15 Update 2
SIMATIC STEP 7 (TIA Portal) v13: all versions prior to V13 SP2 Update 2
SIMATIC STEP 7 (TIA Portal) v14: all versions prior to V14 SP1 Update 6
SIMATIC STEP 7 (TIA Portal) v15: all versions prior to V15 Update 2
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"
Successful exploitation of the vulnerability could allow compromising confidentiality of data by transmitting it unencrypted over the network.
CVEs related to QID 591201
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SSA-179516 |
|