Publication Date: 2019-11-12
Last Update: 2019-11-12
Current Version: V1.0
CVSS v3.1 Base Score: 5.3

Affected Product and Versions Remediation
Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D with Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2:
All firmware versions < V6.00.320
Install V6.00.320 or a later version
https://support.industry.siemens.com/cs/document/109772802
Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U with Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2:
All firmware versions < V6.00.320
Install V6.00.320 or a later version
https://support.industry.siemens.com/cs/document/109772802
Desigo PX automation controllers PXC22.1-E.D, PXC36-E.D, PXC36.1-E.D with activated web server:
All firmware versions < V6.00.320
Install V6.00.320 or a later version
https://support.industry.siemens.com/cs/document/109772802

CVSS v3.1 Base Score 5.3
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:H/RL:O/RC:C
CWE: CWE-472: External Control of Assumed-Immutable Web Parameter

https://www.siemens.com/cert/advisories