Publication Date: 2020-04-14
Last Update: 2022-06-14
Current Version: V1.7
CVSS v3.1 Base Score: 7.5

Affected Product and Versions Remediation
Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200:
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200P:
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
KTK ATE530S:
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIDOOR ATD430W:
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIDOOR ATE530S COATED:
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIDOOR ATE531S:
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC ET200AL IM157-1 PN:
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC ET200ecoPN, CM 8x IO-Link, M12-L (6ES7148-6JG00-0BB0):
All versions >= V5.1.1
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC ET200ecoPN, DI 8x24VDC, M12-L (6ES7141-6BG00-0BB0):
All versions >= V5.1.1
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC ET200ecoPN, DI 16x24VDC, M12-L (6ES7141-6BH00-0BB0):
All versions >= V5.1.1
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC ET200ecoPN, DIQ 16x24VDC/2A, M12-L (6ES7143-6BH00-0BB0):
All versions >= V5.1.1
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC ET200ecoPN, DQ 8x24VDC/0,5A, M12-L (6ES7142-6BG00-0BB0):
All versions >= V5.1.1
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC ET200ecoPN, DQ 8x24VDC/2A, M12-L (6ES7142-6BR00-0BB0):
All versions >= V5.1.1
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC ET200MP IM155-5 PN HF (incl. SIPLUS variants):
All versions >= V4.2
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC ET200SP IM155-6 MF HF:
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC ET200SP IM155-6 PN HA (incl. SIPLUS variants):
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC ET200SP IM155-6 PN HF (incl. SIPLUS variants):
All versions >= V4.2
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC ET200SP IM155-6 PN/2 HF (incl. SIPLUS variants):
All versions >= V4.2
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC ET200SP IM155-6 PN/3 HF (incl. SIPLUS variants):
All versions >= V4.2
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants):
All versions < V2.0
Update to V20.8 or later version
https://support.industry.siemens.com/cs/ww/en/view/109759122/
SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants):
All versions < V2.0
Update to V2.1.7 or later version
https://support.industry.siemens.com/cs/ww/en/view/109759122/
SIMATIC MICRO-DRIVE PDC:
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC PN/MF Coupler (6ES7158-3MU10-0XA0):
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC PN/PN Coupler (incl. SIPLUS NET variants):
All versions >= V4.2
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants):
All versions
Currently no fix is planned
As a mitigation, disable the ethernet ports on the CPU and use a communication module (like CP) for communication instead (not applicable for ET200 CPUs)
SIMATIC S7-400 H V6 CPU family and below (incl. SIPLUS variants):
All versions
Currently no fix is planned
As a mitigation, disable the ethernet ports on the CPU and use a communication module (like CP) for communication instead
SIMATIC S7-400 PN/DP V7 and below CPU family (incl. SIPLUS variants):
All versions
Currently no fix is planned
As a mitigation, disable the ethernet ports on the CPU and use a communication module (like CP) for communication instead
SIMATIC S7-410 CPU family (incl. SIPLUS variants):
All versions
Currently no fix is available
As a mitigation, disable the ethernet ports on the CPU and use a communication module (like CP) for communication instead
SIMATIC S7-1200 CPU family (incl. SIPLUS variants):
All versions < V4.4.0
Update to V4.5.2 or later version
https://support.industry.siemens.com/cs/ww/en/view/109793280/
SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants):
All versions < V2.0
Update to V2.8 or later version
https://support.industry.siemens.com/cs/ww/en/view/109773807/
SIMATIC S7-1500 Software Controller:
All versions < V2.0
Update to V20.8 or later version
https://support.industry.siemens.com/cs/ww/en/view/109772864/
SIMATIC TDC CP51M1:
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC TDC CPU555:
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SIMATIC WinAC RTX (F) 2010:
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations
SINAMICS S/G Control Unit w. PROFINET:
All versions
Currently no fix is planned
See recommendations from section Workarounds and Mitigations

CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
CWE: CWE-400: Uncontrolled Resource Consumption

https://www.siemens.com/cert/advisories