Publication Date: 2021-01-19
Last Update: 2021-05-11
Current Version: V1.3
CVSS v3.1 Base Score: 4.0

Affected Product and Versions Remediation
RUGGEDCOM RM1224:
All versions < V6.4
Update to V6.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109794349/
SCALANCE M-800:
All versions < V6.4
Update to V6.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109794349/
SCALANCE S615:
All versions < V6.4
Update to V6.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109794349/
SCALANCE SC-600:
All versions < V2.1.3
Update to V2.1.3 or later version
https://support.industry.siemens.com/cs/ww/en/view/109793041/
SCALANCE W1750D:
All versions
See recommendations from section Workarounds and Mitigations

CVSS v3.1 Base Score 4.0
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N/E:P/RL:U/RC:C
CWE: CWE-290: Authentication Bypass by Spoofing

CVSS v3.1 Base Score 4.0
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N/E:P/RL:U/RC:C
CWE: CWE-290: Authentication Bypass by Spoofing

CVSS v3.1 Base Score 4.0
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N/E:P/RL:U/RC:C
CWE: CWE-330: Use of Insufficiently Random Values

https://www.siemens.com/cert/advisories