-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 # SSA-377115: SegmentSmack in Linux IP-Stack based Industrial Devices Publication Date: 2020-04-14 Last Update: 2020-09-08 Current Version: 1.2 CVSS v3.1 Base Score: 7.5 SUMMARY ======= The latest updates for the affected products fix a vulnerability that could allow remote attackers to affect the availability of the devices under certain conditions. The underlying TCP stack can be forced to make very computation expensive calls for every incoming packet which can lead to a Denial-of-Service. Siemens has released updates for the affected products and recommends to update to the new versions. AFFECTED PRODUCTS AND SOLUTION ============================== * RUGGEDCOM RM1224 - Affected versions: All Versions < V6.1 - Remediation: Update to V6.1 - Download: https://support.industry.siemens.com/cs/ww/en/view/109778305/ * RUGGEDCOM ROX II - Affected versions: All versions < V2.13.3 - Affected by vulnerabilities: - CVE-2018-5391 - Remediation: Update to V2.13.3 - Download: https://support.industry.siemens.com/cs/ww/en/view/109778537/ * SCALANCE M-800 / S615 - Affected versions: All Versions < V6.1 - Remediation: Update to V6.1 - Download: https://support.industry.siemens.com/cs/ww/en/view/109778305/ * SCALANCE SC-600 - Affected versions: All Versions < V2.0 - Remediation: Update to V2.0 or a later version - Download: https://support.industry.siemens.com/cs/ww/en/view/109769665/ * SCALANCE W1700 IEEE 802.11ac - Affected versions: All Versions < V2.0 - Remediation: Update to V2.0 - Download: https://support.industry.siemens.com/cs/ww/en/view/109773734/ * SCALANCE W700 IEEE 802.11a/b/g/n - Affected versions: All Versions < V6.4 - Remediation: Update to V6.4 - Download: https://support.industry.siemens.com/cs/ww/en/view/109773308/ * SIMATIC NET CP 1242-7 - Affected versions: All versions < V3.2 - Remediation: Update to V3.2 - Download: https://support.industry.siemens.com/cs/ww/en/view/109775640/ * SIMATIC NET CP 1243-1 (incl. SIPLUS variants) - Affected versions: All versions < V3.2 - Remediation: Update to V3.2 - Download: https://support.industry.siemens.com/cs/ww/en/view/109775640/ * SIMATIC NET CP 1243-7 LTE EU - Affected versions: All versions < V3.2 - Remediation: Update to V3.2 - Download: https://support.industry.siemens.com/cs/ww/en/view/109775640/ * SIMATIC NET CP 1243-7 LTE US - Affected versions: All versions < V3.2 - Remediation: Update to V3.2 - Download: https://support.industry.siemens.com/cs/ww/en/view/109775640/ * SIMATIC NET CP 1243-8 IRC - Affected versions: All versions < V3.2 - Remediation: Update to V3.2 - Download: https://support.industry.siemens.com/cs/ww/en/view/109775640/ * SIMATIC NET CP 1542SP-1 - Affected versions: All versions < V2.1 - Remediation: Update to V2.1 - Download: https://support.industry.siemens.com/cs/ww/en/view/109774207/ * SIMATIC NET CP 1542SP-1 IRC (incl. SIPLUS variants) - Affected versions: All versions < V2.1 - Remediation: Update to V2.1 - Download: https://support.industry.siemens.com/cs/ww/en/view/109774207/ * SIMATIC NET CP 1543-1 (incl. SIPLUS variants) - Affected versions: All versions < V2.2 - Remediation: Update to V2.2 - Download: https://support.industry.siemens.com/cs/ww/en/view/109775642/ * SIMATIC NET CP 1543SP-1 (incl. SIPLUS variants) - Affected versions: All versions < V2.1 - Remediation: Update to V2.1 - Download: https://support.industry.siemens.com/cs/ww/en/view/109774207/ * SIMATIC RF185C - Affected versions: All versions < V1.3 - Remediation: Update to V1.3 or later version - Download: https://support.industry.siemens.com/cs/ww/en/view/109781665 * SIMATIC RF186C - Affected versions: All versions < V1.3 - Remediation: Update to V1.3 or later version - Download: https://support.industry.siemens.com/cs/ww/en/view/109781665 * SIMATIC RF186CI - Affected versions: All versions < V1.3 - Remediation: Update to V1.3 or later version - Download: https://support.industry.siemens.com/cs/ww/en/view/109781665 * SIMATIC RF188C - Affected versions: All versions < V1.3 - Remediation: Update to V1.3 or later version - Download: https://support.industry.siemens.com/cs/ww/en/view/109781665 * SIMATIC RF188CI - Affected versions: All versions < V1.3 - Remediation: Update to V1.3 or later version - Download: https://support.industry.siemens.com/cs/ww/en/view/109781665 * SINEMA Remote Connect Server - Affected versions: All versions >V1.1 and