Publication Date:
Last Update:
Current Version: V1.3
CVSS v3.1 Base Score: 10.0
Affected Product and Versions Remediation

All versions < V9.1 SP2 UC04
affected by all CVEs
Update to V9.1 SP2 UC04 or later version

All versions < V5.7 SP1 HF1
affected by all CVEs
Update to V5.7 SP1 HF1 or later version
Or switch to "Single terminal system" (as described in the section Workarounds and Mitigations). Alternatively, consider migrating the STEP 7 project to the latest version of TIA Portal and uninstall S7-PM

All versions < V5.7 SP2 HF1
affected by all CVEs
Update to V5.7 SP2 HF1 or later version

All versions < V5.7
affected by all CVEs
  • If multiple Engineering Systems are in use limit remote access to port 2638/tcp to trusted systems only
  • If multiple Engineering Systems are in use ensure that the user accounts in use are restricted to the minimum required operating rights
  • If only one Engineering System is in use, consider changing to "Single terminal system" mode in the "Configure SIMATIC Workspace/Workstation" application, under the "Workstation Configuration" tab. Restart the computer. More details can be found in the following FAQ: https://support.industry.siemens.com/cs/ww/en/view/109821340/

Product-specific remediations or mitigations can be found in the section Affected Products and Solution.
Please follow the General Security Recommendations.

As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity

Un-/Collapse All

This chapter describes all vulnerabilities (CVE-IDs) addressed in this security advisory. Wherever applicable, it also documents the product-specific impact of the individual vulnerabilities.

CVSS v3.1 Base Score 10.0
CVSS v3.1 Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:T/RC:C
CWE CWE-94: Improper Control of Generation of Code ('Code Injection')

  • Thomas Riedmaier from Siemens Energy for reporting the vulnerability

https://www.siemens.com/cert/advisories
V1.0 (2023-06-13): Publication Date
V1.1 (2023-07-11): Added a new mitigations to all affected products, adjusted summary and CVSS score
V1.2 (2024-03-12): Added fix to SIMATIC PCS 7
V1.3 (2024-05-14): Added fix to SIMATIC S7-PM