Publication Date: 2018-11-13
Last Update: 2020-02-10
Current Version: V1.1
CVSS v3.1 Base Score: 7.5

Affected Product and Versions Remediation
SIMATIC HMI Comfort Panels 4" - 22" (incl. SIPLUS variants):
All versions < V15 Update 4
Update SIMATIC WinCC (TIA Portal) to V15 Update 4 or newer, and then update panel to V15 Update 4 or newer.
https://support.industry.siemens.com/cs/ww/en/view/109755826
SIMATIC HMI Comfort Outdoor Panels 7" & 15" (incl. SIPLUS variants):
All versions < V15 Update 4
Update SIMATIC WinCC (TIA Portal) to V15 Update 4 or newer, and then update panel to V15 Update 4 or newer.
https://support.industry.siemens.com/cs/ww/en/view/109755826
SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F:
All versions < V15 Update 4
Update SIMATIC WinCC (TIA Portal) to V15 Update 4 or newer, and then update panel to V15 Update 4 or newer.
https://support.industry.siemens.com/cs/ww/en/view/109755826
SIMATIC WinCC Runtime Advanced:
All versions < V15 Update 4
Update to V15 Update 4 or newer
https://support.industry.siemens.com/cs/ww/en/view/109755826
SIMATIC WinCC Runtime Professional:
All versions < V15 Update 4
Update to V15 Update 4 or newer
https://support.industry.siemens.com/cs/ww/en/view/109755826
SIMATIC WinCC (TIA Portal):
All versions < V15 Update 4
Update to V15 Update 4 or newer
https://support.industry.siemens.com/cs/ww/en/view/109755826
SIMATIC HMI Classic Devices - TP/MP/OP/MP Mobile Panel (incl. SIPLUS variants):
All versions
See recommendations from Section Workaround and Mitigations

CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
CWE: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSS v3.1 Base Score 6.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C
CWE: CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

https://www.siemens.com/cert/advisories