Publication Date: 2019-12-10
Last Update: 2022-04-12
Current Version: V1.3
CVSS v3.1 Base Score: 3.7

Affected Product and Versions Remediation
SIMATIC CP 1626 (6GK1162-6AA01):
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC HMI Panel (incl. SIPLUS variants):
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC NET PC Software V14:
All versions < V14 SP1 Update 14
Update to V14 SP1 Update 14 or later version
https://support.industry.siemens.com/cs/ww/en/view/109807351/
SIMATIC NET PC Software V15:
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC STEP 7 (TIA Portal):
All versions < V16
Update to version V16
https://support.industry.siemens.com/cs/document/109772803/
SIMATIC WinCC (TIA Portal):
All versions < V16
Update to version V16
https://support.industry.siemens.com/cs/document/109772803/
SIMATIC WinCC OA:
All versions < V3.16 P013
Update to V3.16 P013 or later version
https://www.winccoa.com/downloads/category/versions-patches.html
SIMATIC WinCC Runtime Advanced:
All versions < V16
Update to version V16
https://support.industry.siemens.com/cs/document/109771219/
SIMATIC WinCC Runtime Professional:
All versions < V16
Update to version V16
https://support.industry.siemens.com/cs/document/109771219/
TIM 1531 IRC (incl. SIPLUS NET variants):
All versions < V2.1
Update to V2.1
https://support.industry.siemens.com/cs/document/109774204/

CVSS v3.1 Base Score 3.7
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C
CWE: CWE-327: Use of a Broken or Risky Cryptographic Algorithm

https://www.siemens.com/cert/advisories