QID 591261

Date Published: 2023-01-06

QID 591261: Siemens MindConnect, S7-1200/1500 CPU family, ET 200SP Open Controller Open Secure Sockets Layer (OpenSSL) Multiple Vulnerabilities (ICSA-18-226-02, SSA-179516)

AFFECTED PRODUCTS
MindConnect IoT2040: All versions prior to v03.01
MindConnect Nano (IPC227D): All versions prior to v03.01
SIMATIC ET 200SP Open Controller CPU 1515SP PC: All versions prior to v2.1.6
SIMATIC S7-1200: All versions prior to v4.2.3
SIMATIC S7-1500: All versions prior to v2.5.2

QID Detection Logic:
This QID checks for the Vulnerable version of Siemens MindConnect, S7-1200/1500 CPU family, ET 200SP Open Controller using passive scanning

Successful exploitation of this vulnerability could result in unencrypted data being transmitted by the SSL/TLS record layer.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-18-226-02 or CERT MITIGATIONS section SSA-179516 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591261

    Software Advisories
    Advisory ID Software Component Link
    ICSA-18-226-02 URL Logo www.cisa.gov/uscert/ics/advisories/ICSA-18-226-02
    SSA-179516 URL Logo cert-portal.siemens.com/productcert/html/ssa-179516.html