Publication Date: 2021-05-28
Last Update: 2021-09-14
Current Version: V1.1
CVSS v3.1 Base Score: 8.1

Affected Product and Versions Remediation
SIMATIC Drive Controller family:
All versions < V2.9.2
Update to V2.9.2 or later version
https://support.industry.siemens.com/cs/ww/en/view/109773914/
SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants):
All versions < V21.9
Update to V21.9 or later version
https://support.industry.siemens.com/cs/ww/en/view/109759122/
SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants):
All versions
See recommendations from section Workarounds and Mitigations
SIMATIC S7-1200 CPU family (incl. SIPLUS variants):
All versions < V4.5.0
Update to V4.5.0 or later version
https://support.industry.siemens.com/cs/ww/en/view/109793280/
SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants):
All versions < V2.9.2
Update to V2.9.2 or later version
https://support.industry.siemens.com/cs/ww/en/view/109478459/
SIMATIC S7-1500 Software Controller:
All versions < V21.9
Update to V21.9 or later version
https://support.industry.siemens.com/cs/ww/en/view/109478528/
SIMATIC S7-PLCSIM Advanced:
All versions < V4.0
Update to V4.0 or later version
https://support.industry.siemens.com/cs/ww/en/view/109795016/

CVSS v3.1 Base Score 8.1
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer

https://www.siemens.com/cert/advisories