| Publication Date: |
2019-01-08 |
| Last Update: |
2020-02-10 |
| Current Version: |
V1.1 |
| CVSS v3.1 Base Score: |
7.5 |
| Affected Product and Versions |
Remediation |
|
SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants):
All versions >= V2.0 and < V2.5
|
Update to V2.5 or newer
https://support.industry.siemens.com/cs/de/en/view/109478459
|
|
SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants):
All versions <= V1.8.5
|
Update to V2.5 or higher or when this is not possible (because of Hardware restrictions) see recommendations from section workarouns and mitigations
|
- Protect network access to port 80/tcp and port 443/tcp of affected devices.
- Apply cell protection concept
- Apply defense-in-depth
| CVSS v3.1 Base Score |
7.5 |
| CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
| CWE: |
CWE-20: Improper Input Validation |
| CVSS v3.1 Base Score |
7.5 |
| CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
| CWE: |
CWE-20: Improper Input Validation |
-
Artem Zinenko from
Kaspersky
for pointing out that SIPLUS should also be mentioned
https://www.siemens.com/cert/advisories