| Publication Date: |
2021-10-12 |
| Last Update: |
2021-10-12 |
| Current Version: |
V1.0 |
| CVSS v3.1 Base Score: |
7.5 |
| Affected Product and Versions |
Remediation |
|
SINUMERIK 808D:
All versions
|
See recommendations from section Workarounds and Mitigations
|
|
SINUMERIK 828D:
All versions < V4.95
|
Update to V4.95 or later version
The update can be obtained from your Siemens representative or via Siemens customer service.
|
- Restrict access to port 102/tcp to trusted systems e.g. with an external firewall
- Apply general workarounds.
| CVSS v3.1 Base Score |
7.5 |
| CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
| CWE: |
CWE-122: Heap-based Buffer Overflow |
-
Industrial Control Security Laboratory of Qi An Xin Group Inc.
for reporting the vulnerability and coordination efforts
https://www.siemens.com/cert/advisories