Publication Date:
Last Update:
Current Version: V1.8
CVSS v3.1 Base Score: 8.4
Affected Product and Versions Remediation

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All Versions < V01.00.20_2N
Currently no fix is available

All versions < V22.01.10

V22.01.10
affected by CVE-2021-43613

All versions

All versions < V27.01.09
Update BIOS to V27.01.09 or later version

All versions < V28.01.04
Update BIOS to V28.01.04 or later version

All versions < V28.01.04
Update BIOS to V28.01.04 or later version

All versions < V28.01.04
Update BIOS to V28.01.04 or later version

All versions < V28.01.04
Update BIOS to V28.01.04 or later version

All versions < V21.01.17

All versions >= V21.01.17
affected by CVE-2021-43613
Currently no fix is available

All versions < V21.01.17

All versions >= V21.01.17
affected by CVE-2021-43613
Currently no fix is available

All versions < V21.01.17

All versions >= V21.01.17
affected by CVE-2021-43613
Currently no fix is available

All versions < V25.02.12

All versions >= V25.02.12
affected by CVE-2021-43613
Currently no fix is available

All versions < V25.02.12

All versions >= V25.02.12
affected by CVE-2021-43613
Currently no fix is available

All versions < V25.02.12

All versions >= V25.02.12
affected by CVE-2021-43613
Currently no fix is available

All versions < V25.02.12

All versions >= V25.02.12
affected by CVE-2021-43613
Currently no fix is available

All versions < V23.01.10
Update BIOS to V23.01.10 or later version

All versions >= V23.01.10
affected by CVE-2021-43613
Currently no fix is available
  • As a prerequisite for an attack, an attacker must be able to run untrusted code on affected systems. Siemens recommends limiting the possibilities to run untrusted code

Product-specific remediations or mitigations can be found in the section Affected Products and Solution.
Please follow the General Security Recommendations.

As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity

Un-/Collapse All

The vulnerability classification has been performed by using the CVSS scoring system in version 3.1 (CVSS v3.1) (https://www.first.org/cvss/). The CVSS environmental score is specific to the customer’s environment and will impact the overall CVSS score. The environmental score should therefore be individually defined by the customer to accomplish final scoring.

An additional classification has been performed using the CWE classification, a community-developed list of common software security weaknesses. This serves as a common language and as a baseline for weakness identification, mitigation, and prevention efforts. A detailed list of CWE classes can be found at: https://cwe.mitre.org/.

CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-822: Untrusted Pointer Dereference
CVSS v3.1 Base Score 6.7
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-269: Improper Privilege Management
CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSS v3.1 Base Score 7.8
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-829: Inclusion of Functionality from Untrusted Control Sphere
CVSS v3.1 Base Score 8.2
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSS v3.1 Base Score 7.8
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-256: Plaintext Storage of a Password
CVSS v3.1 Base Score 8.2
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSS v3.1 Base Score 8.2
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSS v3.1 Base Score 8.2
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-476: NULL Pointer Dereference
CVSS v3.1 Base Score 8.2
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-770: Allocation of Resources Without Limits or Throttling
CVSS v3.1 Base Score 8.2
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-829: Inclusion of Functionality from Untrusted Control Sphere
CVSS v3.1 Base Score 6.7
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-787: Out-of-bounds Write
CVSS v3.1 Base Score 8.2
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-20: Improper Input Validation
CVSS v3.1 Base Score 8.2
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-20: Improper Input Validation
CVSS v3.1 Base Score 8.4
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-787: Out-of-bounds Write
CVSS v3.1 Base Score 8.2
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-20: Improper Input Validation
CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-787: Out-of-bounds Write
CVSS v3.1 Base Score 5.2
CVSS Vector CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N/E:P/RL:O/RC:C
CWE CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVSS v3.1 Base Score 6.7
CVSS Vector CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:L/E:P/RL:O/RC:C
CWE CWE-400: Uncontrolled Resource Consumption
CVSS v3.1 Base Score 8.2
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-787: Out-of-bounds Write
CVSS v3.1 Base Score 8.4
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CVSS v3.1 Base Score 8.4
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CVSS v3.1 Base Score 8.4
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CVSS v3.1 Base Score 8.4
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-787: Out-of-bounds Write
CVSS v3.1 Base Score 8.2
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-787: Out-of-bounds Write
CVSS v3.1 Base Score 8.2
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-20: Improper Input Validation

https://www.siemens.com/cert/advisories

V1.0 (2022-02-22): Publication Date
V1.1 (2022-03-08): Corrected AV:L for all CVEs, added RUGGEDCOM APE1808 and SIMATIC IPC477E PRO
V1.2 (2022-07-12): Added CVE-2021-43613, CVE-2021-43614 and CVE-2021-38489, add fix for SIMATIC Field PG M6, SIMATIC ITP1000 for all CVEs except CVE-2021-43613
V1.3 (2022-08-09): Added fix for SIMATIC IPC227G, SIMATIC IPC277G, SIMATIC IPC327G, SIMATIC IPC377G, clarified affected versions for RUGGEDCOM APE1808
V1.4 (2022-10-11): Added partial fix for SIMATIC IPC427E, SIMATIC IPC477E, SIMATIC IPC477E Pro
V1.5 (2023-02-14): Added partial fix for SIMATIC IPC627E, SIMATIC IPC677E, SIMATIC IPC677E, and SIMATIC IPC847E
V1.6 (2023-07-11): Added fix SIMATIC Field PG M5
V1.7 (2023-08-08): Removed fix for SIMATIC Field PG M6 as fix version was withdrawn
V1.8 (2023-11-14): Added fix for SIMATIC IPC127E