Publication Date: 2021-08-10
Last Update: 2021-09-14
Current Version: V1.1
CVSS v3.1 Base Score: 5.3

Affected Product and Versions Remediation
SIMATIC Drive Controller family:
All versions < V2.9.2
Update to V2.9.2 or later version
https://support.industry.siemens.com/cs/ww/en/view/109773914/
SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants):
All versions < V21.9
Update to V21.9 or later version
https://support.industry.siemens.com/cs/ww/en/view/109759122/
SIMATIC S7 PLCSIM Advanced:
All versions > V2 < V4
Updated to V4 or later version
https://support.industry.siemens.com/cs/de/en/view/109795016
SIMATIC S7-1200 CPU family (incl. SIPLUS variants):
Version V4.4
Update to V4.4.1 or later version
https://support.industry.siemens.com/cs/ww/en/view/109793280
SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants):
All versions > V2.5 < V2.9.2
Update to V2.9.2 or later version
https://support.industry.siemens.com/cs/ww/en/view/109478459/
SIMATIC S7-1500 Software Controller:
All versions > V2.5 < V21.9
Update to V21.9 or later version
https://support.industry.siemens.com/cs/de/en/view/109478528/
TIM 1531 IRC (incl. SIPLUS NET variants):
Version V2.1
Update to V2.2 or later version
https://support.industry.siemens.com/cs/ww/en/view/109798331

CVSS v3.1 Base Score 5.3
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
CWE: CWE-863: Incorrect Authorization

https://www.siemens.com/cert/advisories