Publication Date: 2020-07-14
Last Update: 2022-02-17
Current Version: V1.1
CVSS v3.1 Base Score: 10.0

Affected Product and Versions Remediation
SPPA-T3000 APC UPS with NMC card AP9630 or AP9631:
All versions
only affected by CVE-2020-11896

APS UPS systems are affected by multiple Ripple20 vulnerabilities, including CVE-2020-11896 and 14 more.

The T3000 specific CVSS Environmental Score is 3.6 (Severity: low).

Please contact your Siemens Energy service management organisation how to mitigate the Ripple20 vulnerabilities in T3000 solutions.
See further recommendations from section Workarounds and Mitigations
SPPA-T3000 Application Server:
All versions
only affected by CVE-2020-0545

When running on a HP ProLiant DL360 Gen10 server, the SPPA-T3000 Application Server is affected in the Intel Server Platform Services (SPS) included in the server hardware.

The T3000 specific CVSS Environmental Score is 3.6 (Severity: low).

Please contact your Siemens Energy service management organisation how to obtain the patch for the Intel SPS system of the server hardware.
See further recommendations from section Workarounds and Mitigations
SPPA-T3000 Terminal Server:
All versions
only affected by CVE-2020-0545

When running on a HP ProLiant DL360 Gen10 server, the SPPA-T3000 Terminal Server is affected in the Intel Server Platform Services (SPS) included in the server hardware.

The T3000 specific CVSS Environmental Score is 3.6 (Severity: low).

Please contact your Siemens Energy service management organisation how to obtain the patch for the Intel SPS system of the server hardware.
See further recommendations from section Workarounds and Mitigations

CVSS v3.1 Base Score 4.4
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
CWE: CWE-190: Integer Overflow or Wraparound

CVSS v3.1 Base Score 10.0
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-130: Improper Handling of Length Parameter Inconsistency

https://www.siemens.com/cert/advisories