Publication Date: 2020-06-09
Last Update: 2021-04-13
Current Version: V1.3
CVSS v3.1 Base Score: 7.8

Affected Product and Versions Remediation
SIMATIC PCS 7 V8.2 and earlier:
All versions
See recommendations from section Workarounds and Mitigations or upgrade to a newer SIMATIC PCS 7 version
SIMATIC PCS 7 V9.0:
All versions < V9.0 SP3
Update to V9.0 SP3 or later version
To obtain SIMATIC PCS 7 V9.0 SP3 contact your local support.
SIMATIC PDM:
All versions < V9.2
Update to V9.2 or later version
https://support.industry.siemens.com/cs/ww/en/view/109794361/
SIMATIC STEP 7 V5.X:
All versions < V5.6 SP2 HF3
Update to V5.6 SP2 HF3 or later version
https://support.industry.siemens.com/cs/de/en/view/109779992/
SINAMICS STARTER (containing STEP 7 OEM version):
All versions < V5.4 HF2
Update to V5.4 HF2 or later version
https://support.industry.siemens.com/cs/us/en/view/109782792/

CVSS v3.1 Base Score 7.8
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-427: Uncontrolled Search Path Element

CVSS v3.1 Base Score 7.8
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-122: Heap-based Buffer Overflow

https://www.siemens.com/cert/advisories