Publication Date: 2019-06-11
Last Update: 2020-02-10
Current Version: V1.1
CVSS v3.1 Base Score: 7.5

Affected Product and Versions Remediation
SIEMENS LOGO!8 (incl. SIPLUS variants):
6ED1052-xyyxx-0BA8 FS:01 to FS:06 / Firmware version V1.80.xx and V1.81.xx
See Workarounds and Mitigations below or upgrade to a new version
SIEMENS LOGO!8 (incl. SIPLUS variants):
6ED1052-xyy08-0BA0 FS:01 / Firmware version < V1.82.02
Update to V1.82.02 or higher
https://support.industry.siemens.com/cs/ww/en/view/109767410

CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
CWE: CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer

CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-384: Session Fixation

https://www.siemens.com/cert/advisories