| Publication Date: |
2021-08-04 |
| Last Update: |
2022-01-11 |
| Current Version: |
V1.2 |
| CVSS v3.1 Base Score: |
7.5 |
| Affected Product and Versions |
Remediation |
|
SENTRON 3WA COM190:
All versions < V2.0.0
only affected by
CVE-2020-35684, CVE-2020-35685, CVE-2021-31401
|
Update to V2.0.0 or later version
https://support.industry.siemens.com/cs/ww/en/view/109782123/
|
|
SENTRON 3WL COM35:
All versions < V1.2.0
only affected by
CVE-2020-35684, CVE-2020-35685, CVE-2021-31401
|
Update to V1.2.0 or later version
https://support.industry.siemens.com/cs/ww/en/view/109766651/
|
|
SENTRON 7KM PAC Switched Ethernet PROFINET Expansion Module (7KM9300-0AE00-0AA0):
All versions
only affected by
CVE-2020-35683, CVE-2020-35684, CVE-2020-35685, CVE-2021-31401
|
Currently no remediation is planned
See recommendations from section Workarounds and Mitigations
|
|
SENTRON 7KM PAC Switched Ethernet PROFINET Expansion Module (7KM9300-0AE01-0AA0):
All versions < V2.1.6
only affected by
CVE-2020-35683, CVE-2020-35684, CVE-2020-35685, CVE-2021-31401
|
Update to V2.1.6 or later version
https://support.industry.siemens.com/cs/ww/en/view/109749555/
|
|
SENTRON 7KM PAC Switched Ethernet PROFINET Expansion Module (7KM9300-0AE02-0AA0):
All versions < V3.0.4
only affected by
CVE-2020-35683, CVE-2020-35684, CVE-2020-35685, CVE-2021-31401
|
Update to V3.0.4 or later version
https://support.industry.siemens.com/cs/ww/en/view/109777120/
|
| CVSS v3.1 Base Score |
7.5 |
| CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C |
| CWE: |
CWE-20: Improper Input Validation |
| CVSS v3.1 Base Score |
7.5 |
| CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
| CWE: |
CWE-20: Improper Input Validation |
| CVSS v3.1 Base Score |
7.5 |
| CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C |
| CWE: |
CWE-330: Use of Insufficiently Random Values |
| CVSS v3.1 Base Score |
7.5 |
| CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C |
| CWE: |
CWE-20: Improper Input Validation |
-
Bundesamt für Sicherheit in der Informationstechnik (BSI)
for coordination efforts
-
CERT Coordination Center (CERT/CC)
for coordination efforts
-
Daniel dos Santos, Jos Wetzels, and Amine Amri from
Forescout Technologies
for coordinated disclosure
-
Asaf Karas and Shachar Menashe from
Vdoo
for coordinated disclosure
-
HCC Embedded
for coordination efforts
https://www.siemens.com/cert/advisories