QID 591255

Date Published: 2023-02-03

QID 591255: Siemens SIMATIC Controllers and TIM Denial of Service (DoS) Multiple Vulnerabilities (ICSA-22-349-03, SSA-382653)

AFFECTED PRODUCTS
SIMATIC Drive Controller family: All versions prior to V3.0.1
SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions.
SIMATIC S7-1200 CPU family (incl. SIPLUS variants): All versions prior to V4.6.0
SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions prior to V3.0.1
SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0): All versions.
TIM 1531 IRC (6GK7543-1MX00-0XE0): All versions.

QID Detection Logic:
This QID checks for the Vulnerable version of Siemens SIMATIC Controllers and TIM using passive scanning

Successful exploitation of these vulnerabilities could result in a remote attacker causing a denial-of-service condition on the affected devices.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-22-349-03 or Siemens MITIGATIONS section SSA-382653 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591255

    Software Advisories
    Advisory ID Software Component Link
    ICSA-22-349-03 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-349-03
    SSA-382653 URL Logo cert-portal.siemens.com/productcert/html/ssa-382653.html