Publication Date: 2019-11-12
Last Update: 2020-07-14
Current Version: V1.2
CVSS v3.1 Base Score: 6.8

Affected Product and Versions Remediation
SIMATIC S7-1200 CPU family V4.x (incl. SIPLUS variants):
All versions with Function State (FS) < 11
Update to version >= V4.4.1 and Function State (FS) >= 11
SIMATIC S7-1200 CPU family < V4.x (incl. SIPLUS variants):
All versions

Firmware versions less than V4.x cannot be updated.

For remediation see the recommendations from section “Workarounds and Mitigations”.
SIMATIC S7-200 SMART CPU ST20 (6ES7 288-1ST20-0AA0):
All versions <= V2.5.0 and Function State (FS) <= 9
Update to version >= V2.5.1 and the latest boot loader version
SIMATIC S7-200 SMART CPU ST30 (6ES7 288-1ST30-0AA0):
All versions <= V2.5.0 and Function State (FS) <= 9
Update to version >= V2.5.1 and the latest boot loader version
SIMATIC S7-200 SMART CPU ST40 (6ES7 288-1ST40-0AA0):
All versions <= V2.5.0 and Function State (FS) <= 8
Update to version >= V2.5.1 and the latest boot loader version
SIMATIC S7-200 SMART CPU ST60 (6ES7 288-1ST60-0AA0):
All versions <= V2.5.0 and Function State (FS) <= 8
Update to version >= V2.5.1 and the latest boot loader version
SIMATIC S7-200 SMART CPU SR20 (6ES7 288-1SR20-0AA0):
All versions <= V2.5.0 and Function State (FS) <= 11
Update to version >= V2.5.1 and the latest boot loader version
SIMATIC S7-200 SMART CPU SR30 (6ES7 288-1SR30-0AA0):
All versions <= V2.5.0 and Function State (FS) <= 10
Update to version >= V2.5.1 and the latest boot loader version
SIMATIC S7-200 SMART CPU SR40 (6ES7 288-1SR40-0AA0):
All versions <= V2.5.0 and Function State (FS) <= 10
Update to version >= V2.5.1 and the latest boot loader version
SIMATIC S7-200 SMART CPU SR60 (6ES7 288-1SR60-0AA0):
All versions <= V2.5.0 and Function State (FS) <= 12
Update to version >= V2.5.1 and the latest boot loader version
SIMATIC S7-200 SMART CPU CR40 (6ES7 288-1CR40-0AA0):
All versions <= V2.2.2 and Function State (FS) <= 8
Update to version >= V2.2.3 and the latest boot loader version
SIMATIC S7-200 SMART CPU CR60 (6ES7 288-1CR60-0AA0):
All versions <= V2.2.2 and Function State (FS) <= 10
Update to version >= V2.2.3 and the latest boot loader version
SIMATIC S7-200 SMART CPU CR20s (6ES7 288-1CR20-0AA1):
All versions <= V2.3.0 and Function State (FS) <= 3

Update to version >= V2.3.0 and the latest boot loader version

Note that the firmware version currently remains at V2.3.0, only the boot loader is updated.
SIMATIC S7-200 SMART CPU CR30s (6ES7 288-1CR30-0AA1):
All versions <= V2.3.0 and Function State (FS) <= 3

Update to version >= V2.3.0 and the latest boot loader version

Note that the firmware version currently remains at V2.3.0, only the boot loader is updated.
SIMATIC S7-200 SMART CPU CR40s (6ES7 288-1CR40-0AA1):
All versions <= V2.3.0 and Function State (FS) <= 3

Update to version >= V2.3.0 and the latest boot loader version

Note that the firmware version currently remains at V2.3.0, only the boot loader is updated.
SIMATIC S7-200 SMART CPU CR60s (6ES7 288-1CR60-0AA1):
All versions <= V2.3.0 and Function State (FS) <= 3

Update to version >= V2.3.0 and the latest boot loader version

Note that the firmware version currently remains at V2.3.0, only the boot loader is updated.

CVSS v3.1 Base Score 6.8
CVSS Vector CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C
CWE: CWE-749: Exposed Dangerous Method or Function

https://www.siemens.com/cert/advisories