Skip to content

News

Remarks by ETM regarding SSA-111512 for SIMATIC WinCC OA

This article written by ETM, the company that develops SIMATIC WinCC OA, provides additional insights related to SSA-111512:

On April 6, 2022, "FORESCOUT Vedere Labs" informed us about the intended publication of an article dubbed "OT:ICEFALL" mentioning two vulnerabilities regarding WinCC OA:

  • "FSCT-2022-0060: Siemens WinCC OA / ETM PVSS II proprietary protocol with unauthenticated functionality" and
  • "FSCT-2022-0059: Siemens WinCC OA Desktop UI Authentication Bypass".

ETM immediately analyzed the claims made in these reports. Based on our level of information, they are based on WinCC Open Architecture (OA) version 3.15.

Siemens S7-1200 4.5 Unauthenticated Access

On March 10, 2022, a researcher dubbed "RoseSecurity", published an exploit on PacketStorm, titled "Siemens S7-1200 4.5 Unauthenticated Access". The exploit is demonstrated by curl commands that show how CPU start/stop commands can be triggered on Siemens S7-1200 devices without prior authentication.

New Siemens Security Advisory (SSA) Formats

Siemens ProductCERT introduced new formats - namely HTML and CSAF - for its security advisories and will phase out the traditional formats (PDF, TXT, and CVRF) over time. This article gives a short overview on the reasoning behind this decision and what the future brings.

Apply Defense in Depth

As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' Operational Guidelines for Industrial Security, and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity

Vulnerabilities in the Apache Log4j ("Log4Shell")

Siemens is aware of the security vulnerabilities in Apache Log4j (CVE-2021-44228 and CVE-2021-45046), also named "Log4Shell". For Siemens products, a security advisory (SSA-661247) was issued on 2021-12-13 and will be updated in the following days as more information becomes available.

Vulnerabilities in the Nucleus TCP/IP Stack ("NUCLEUS:13")

Today, in coordination with Forescout, CISA and other contributors, Siemens has disclosed the security vulnerabilities CVE-2021-31344 through CVE-2021-31346 and CVE-2021-31881 through CVE-2021-31890, also named "NUCLEUS:13". The impact and remediations of these vulnerabilities in Nucleus RTOS (a real-time operating system provided by Siemens EDA, formerly Mentor Graphics) is described in SSA-044112: Multiple Vulnerabilities (NUCLEUS:13) in the TCP/IP Stack of Nucleus RTOS.