QID 591207

Date Published: 2022-11-24

QID 591207: Siemens SIMATIC Industrial Products Denial of Service (DoS) Multiple Vulnerabilities (ICSA-22-041-01, SSA-838121)

AFFECTED PRODUCTS
The following versions of Siemens Industrial Products with SIMATIC Firmware, a software platform, are affected:
SIMATIC Drive Controller family: All versions prior to v2.9.4
SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions
SIMATIC ET 200SP Open Controller CPU 1515SP PC2 Ready4Linux: All versions
SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants): All versions
SIMATIC S7-1200 CPU family (incl. SIPLUS variants): Version 4.5.0 and all following versions prior to v4.5.2
SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants): Version 2.9.2 and all following versions prior to v2.9.4
SIMATIC S7-1500 Software Controller: All versions
SIMATIC S7-PLCSIM Advanced: All versions v4.0 SP1
TIM 1531 IRC (incl. SIPLUS NET variants): Version 2.2 and all following versions

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities could allow an unauthenticated attacker to cause a denial-of-service condition.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.1 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section icsa-22-041-01 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591207

    Software Advisories
    Advisory ID Software Component Link
    icsa-22-041-01 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-041-01
    ssa-838121 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-838121.pdf