Publication Date: 2020-09-08
Last Update: 2020-12-08
Current Version: V1.3
CVSS v3.1 Base Score: 5.9

Affected Product and Versions Remediation
SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants):
All versions
See recommendations from section Workarounds and Mitigations
SIMATIC S7-400 CPU family (incl. SIPLUS variants):
All versions
See recommendations from section Workarounds and Mitigations
SIMATIC WinAC RTX (F) 2010:
All versions
See recommendations from section Workarounds and Mitigations
SINUMERIK 840D sl:
All versions
See recommendations from section Workarounds and Mitigations

CVSS v3.1 Base Score 5.9
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:U/RC:C
CWE: CWE-522: Insufficiently Protected Credentials

https://www.siemens.com/cert/advisories