Publication Date: 2020-09-08
Last Update: 2022-02-17
Current Version: V1.7
CVSS v3.1 Base Score: 10.0

Affected Product and Versions Remediation
PSS CAPE Protection Simulation Platform:
CAPE 14 installations installed from material dated earlier than 2020-09-15
CAPE 14 installations installed from material dated 2020-09-15 or later are not affected, as they contain a fixed version of CodeMeter Runtime

If CAPE 14 was initially installed using earlier material, see the recommendations from section Workarounds and Mitigations
See further recommendations from section Workarounds and Mitigations
SICAM 230:
All versions
Currently no remediation is planned
Update to SICAM 230 V8.00 or later version. Install WIBU Systems CodeMeter Runtime V7.10a to fix all issues
See also the recommendations from section Workarounds and Mitigations
See further recommendations from section Workarounds and Mitigations
SIMATIC Information Server 2019:
Version 2019 SP1
only affected by CVE-2020-14509, CVE-2020-14517, CVE-2020-14519, CVE-2020-16233
Update to Information Server 2019 SP1 Update 1 contained in PCS neo V3.0 SP1 Update 1
https://support.industry.siemens.com/cs/ww/en/view/109784449/
See further recommendations from section Workarounds and Mitigations
SIMATIC PCS neo:
All versions < V3.0 SP1 Update 1
Update to V3.0 SP1 Update 1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109784449/
See further recommendations from section Workarounds and Mitigations
SIMATIC Process Historian 2019 (incl. Process Historian OPC UA Server):
All versions < SP1 Update 1
Update to Process Historian 2019 SP1 Update 1 contained in PCS neo V3.0 SP1 Update 1
https://support.industry.siemens.com/cs/ww/en/view/109784449/
See further recommendations from section Workarounds and Mitigations
SIMATIC WinCC OA:
All versions < V3.17 P007
only affected by CVE-2020-14509, CVE-2020-14517, CVE-2020-14519, CVE-2020-16233
Update to V3.17 P007 or later version
https://www.winccoa.com/downloads/category/versions-patches.html
See further recommendations from section Workarounds and Mitigations
SIMIT Simulation Platform:
All versions >= V10.0 and < V10.2 Upd1
Update to V10.2 Upd1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109794248/

For earlier versions see the recommendations from section Workarounds and Mitigations
See further recommendations from section Workarounds and Mitigations
SINEC INS:
All versions < V1.0 SP1
only affected by CVE-2020-14509, CVE-2020-14517, CVE-2020-14519, CVE-2020-16233
Update to V1.0 SP1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109793469/

For earlier versions see the recommendations from section Workarounds and Mitigations
See further recommendations from section Workarounds and Mitigations
SINEMA Remote Connect:
All versions < V3.0
only affected by CVE-2020-14513, CVE-2020-14515, CVE-2020-14519
Update to V3.0 or later version
https://support.industry.siemens.com/cs/ww/en/view/109793790/

For earlier versions see the recommendations from section Workarounds and Mitigations
See further recommendations from section Workarounds and Mitigations

CVSS v3.1 Base Score 10.0
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-805: Buffer Access with Incorrect Length Value

CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
CWE: CWE-20: Improper Input Validation

CVSS v3.1 Base Score 7.4
CVSS Vector CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-347: Improper Verification of Cryptographic Signature

CVSS v3.1 Base Score 9.4
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-326: Inadequate Encryption Strength

CVSS v3.1 Base Score 8.1
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-346: Origin Validation Error

CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:T/RC:C
CWE: CWE-404: Improper Resource Shutdown or Release

https://www.siemens.com/cert/advisories