-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 # SSA-382653: Multiple Denial of Service Vulnerabilities in Industrial Products Publication Date: 2022-12-13 Last Update: 2023-09-12 Current Version: 1.5 CVSS v3.1 Base Score: 7.5 SUMMARY ======= Affected SIMATIC firmware contains multiple vulnerabilities that could allow an unauthenticated attacker to perform a denial of service attack under certain conditions. Siemens has released updates for the affected products and recommends to update to the latest versions. AFFECTED PRODUCTS AND SOLUTION ============================== * SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109773914/ * SIMATIC Drive Controller CPU 1507D TF (6ES7615-7DF10-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109773914/ * SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) - Affected versions: All versions < V21.9.7 - Remediation: Update to V21.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109759122/ * SIMATIC S7-1200 CPU family (incl. SIPLUS variants) - Affected versions: All versions < V4.6.0 - Remediation: Update to V4.6.0 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109814248/ * SIMATIC S7-1500 CPU 1510SP F-1 PN (6ES7510-1SJ01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1510SP-1 PN (6ES7510-1DJ01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK02-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK00-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK02-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1511T-1 PN (6ES7511-1TK01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1511TF-1 PN (6ES7511-1UK01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK00-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1512SP F-1 PN (6ES7512-1SK01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1512SP-1 PN (6ES7512-1DK01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL02-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL02-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1513R-1 PN (6ES7513-1RL00-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM02-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM02-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1515R-2 PN (6ES7515-2RM00-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1515T-2 PN (6ES7515-2TM01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1515TF-2 PN (6ES7515-2UM01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN02-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN02-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1516T-3 PN/DP (6ES7516-3TN00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1516TF-3 PN/DP (6ES7516-3UN00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1517-3 PN/DP (6ES7517-3AP00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1517F-3 PN/DP (6ES7517-3FP00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1517H-3 PN (6ES7517-3HP00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1517T-3 PN/DP (6ES7517-3TP00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1517TF-3 PN/DP (6ES7517-3UP00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1518-4 PN/DP (6ES7518-4AP00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1518F-4 PN/DP (6ES7518-4FP00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1518HF-4 PN (6ES7518-4JP00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1518T-4 PN/DP (6ES7518-4TP00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1518TF-4 PN/DP (6ES7518-4UP00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU S7-1518-4 PN/DP ODK (6ES7518-4AP00-3AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU S7-1518F-4 PN/DP ODK (6ES7518-4FP00-3AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 ET 200pro: CPU 1513PRO F-2 PN (6ES7513-2GL00-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 ET 200pro: CPU 1513PRO-2 PN (6ES7513-2PL00-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 ET 200pro: CPU 1516PRO F-2 PN (6ES7516-2GN00-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 ET 200pro: CPU 1516PRO-2 PN (6ES7516-2PN00-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 Software Controller V2 - Affected versions: All versions < V21.9.7 - Remediation: Update to V21.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478528/ * SIMATIC S7-PLCSIM Advanced - Affected versions: All versions < V5.0 - Remediation: Update to V5.0 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109809300/ * SIPLUS ET 200SP CPU 1510SP F-1 PN (6AG1510-1SJ01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1510SP F-1 PN RAIL (6AG2510-1SJ01-1AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1510SP-1 PN (6AG1510-1DJ01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1510SP-1 PN (6AG1510-1DJ01-7AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1510SP-1 PN RAIL (6AG2510-1DJ01-1AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1510SP-1 PN RAIL (6AG2510-1DJ01-4AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK01-7AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL (6AG2512-1SK01-1AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL (6AG2512-1SK01-4AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1512SP-1 PN (6AG1512-1DK01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1512SP-1 PN (6AG1512-1DK01-7AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1512SP-1 PN RAIL (6AG2512-1DK01-1AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1512SP-1 PN RAIL (6AG2512-1DK01-4AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK01-7AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK02-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK02-7AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL (6AG2511-1AK01-1AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL (6AG2511-1AK02-1AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1511-1 PN TX RAIL (6AG2511-1AK01-4AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1511-1 PN TX RAIL (6AG2511-1AK02-4AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK02-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL01-7AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL02-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL02-7AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL02-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1515F-2 PN (6AG1515-2FM01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1515F-2 PN (6AG1515-2FM02-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1515F-2 PN RAIL (6AG2515-2FM02-4AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1515F-2 PN T2 RAIL (6AG2515-2FM01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1515R-2 PN (6AG1515-2RM00-7AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1515R-2 PN TX RAIL (6AG2515-2RM00-4AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN01-7AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN02-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN02-7AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1516-3 PN/DP RAIL (6AG2516-3AN02-4AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1516-3 PN/DP TX RAIL (6AG2516-3AN01-4AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN02-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL (6AG2516-3FN02-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL (6AG2516-3FN02-4AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1517H-3 PN (6AG1517-3HP00-4AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1518-4 PN/DP (6AG1518-4AP00-4AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1518F-4 PN/DP (6AG1518-4FP00-4AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1518HF-4 PN (6AG1518-4JP00-4AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) - Affected versions: All versions < V2.3.6 - Remediation: Update to V2.3.6 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109817397/ * TIM 1531 IRC (6GK7543-1MX00-0XE0) - Affected versions: All versions < V2.3.6 - Remediation: Update to V2.3.6 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109817397/ WORKAROUNDS AND MITIGATIONS =========================== Siemens has identified the following specific workarounds and mitigations that customers can apply to reduce the risk: * Restrict access to port 102/tcp to trusted systems e.g. with an external firewall Product-specific remediations or mitigations can be found in the section "Affected Products and Solution". Please follow the "General Security Recommendations". GENERAL SECURITY RECOMMENDATIONS ================================ As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial- security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity PRODUCT DESCRIPTION =================== SIMATIC Drive Controllers have been designed for the automation of production machines, combining the functionality of a SIMATIC S7-1500 CPU and a SINAMICS S120 drive control. SIMATIC ET 200SP Open Controller is a PC-based version of the SIMATIC S7-1500 Controller including optional visualization in combination with central I/Os in a compact device. SIMATIC S7-1200 CPU products have been designed for discrete and continuous control in industrial environments such as manufacturing, food and beverages, and chemical industries worldwide. SIMATIC S7-1500 CPU products have been designed for discrete and continuous control in industrial environments such as manufacturing, food and beverages, and chemical industries worldwide. SIMATIC S7-1500 ODK CPUs provide functionality of standard S7-1500 CPUs but additionally provide the possibility to run C/C++ Code within the CPU-Runtime for execution of own functions / algorithms implemented in C/C++. They have been designed for discrete and continuous control in industrial environments such as manufacturing, food and beverages, and chemical industries worldwide. SIMATIC S7-1500 Software Controller is a SIMATIC software controller for PC-based automation solutions. SIMATIC S7-PLCSIM Advanced simulates S7-1200, S7-1500 and a few other PLC derivatives. Includes full network access to simulate the PLCs, even in virtualized environments. SIPLUS extreme products are designed for reliable operation under extreme conditions and are based on SIMATIC, LOGO!, SITOP, SINAMICS, SIMOTION, SCALANCE or other devices. SIPLUS devices use the same firmware as the product they are based on. TIM 1531 IRC is a communication module for SIMATIC S7-1500, S7-400, S7-300 with SINAUT ST7, DNP3 and IEC 60870-5-101/104 with three RJ45 interfaces for communication via IP-based networks (WAN / LAN) and a RS 232/RS 485 interface for communication via classic WAN networks. VULNERABILITY CLASSIFICATION ============================ The vulnerability classification has been performed by using the CVSS scoring system in version 3.1 (CVSS v3.1) (https://www.first.org/cvss/). The CVSS environmental score is specific to the customer's environment and will impact the overall CVSS score. The environmental score should therefore be individually defined by the customer to accomplish final scoring. An additional classification has been performed using the CWE classification, a community-developed list of common software security weaknesses. This serves as a common language and as a baseline for weakness identification, mitigation, and prevention efforts. A detailed list of CWE classes can be found at: https://cwe.mitre.org/. * Vulnerability CVE-2021-40365 Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device. CVSS v3.1 Base Score: 7.5 CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C CWE: CWE-20: Improper Input Validation * Vulnerability CVE-2021-44693 Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device. CVSS v3.1 Base Score: 4.9 CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C CWE: CWE-1284: Improper Validation of Specified Quantity in Input * Vulnerability CVE-2021-44694 Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device. CVSS v3.1 Base Score: 5.5 CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H/E:P/RL:O/RC:C CWE: CWE-1287: Improper Validation of Specified Type of Input * Vulnerability CVE-2021-44695 Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device. CVSS v3.1 Base Score: 4.9 CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C CWE: CWE-1286: Improper Validation of Syntactic Correctness of Input ACKNOWLEDGMENTS =============== Siemens thanks the following party for its efforts: * Gao Jian for coordinated disclosure ADDITIONAL INFORMATION ====================== For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories HISTORY DATA ============ V1.0 (2022-12-13): Publication Date V1.1 (2023-01-10): Clarified SIMATIC S7-1500 CPU versions V1.2 (2023-04-11): Added fix for TIM 1531 family V1.3 (2023-05-09): Added fix for SIMATIC S7-1500 Software Controller V1.4 (2023-07-11): Added fix for SIMATIC S7-1500 CPU V2 firmware versions; Fix for SIMATIC Drive Controller available already with V2.9.7 V1.5 (2023-09-12): Clarified SIMATIC S7-1500 Software Controller versions and adjusted fix for SIMATIC S7-1500 Software Controller V2; Added fix for SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) TERMS OF USE ============ Siemens Security Advisories are subject to the terms and conditions contained in Siemens' underlying license terms or other applicable agreements previously agreed to with Siemens (hereinafter "License Terms"). To the extent applicable to information, software or documentation made available in or through a Siemens Security Advisory, the Terms of Use of Siemens' Global Website (https://www.siemens.com/terms_of_use, hereinafter "Terms of Use"), in particular Sections 8-10 of the Terms of Use, shall apply additionally. In case of conflicts, the License Terms shall prevail over the Terms of Use. Copyright: Siemens 2023 -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEHyx/myPwjH9jB9tDlm7gTEmyujQFAmT/qgAACgkQlm7gTEmy ujS4QBAAnENZnnxcUgGg6FE5HUK1/AA8/WyZdddCBXopuTGqKrgP8b8NRdmRecEA SO+2iJQmY1USRkERJSw8NMq+sQaGaLmrjJiAkZttr46GzgX20WthrICh9FpBsBFi TFKqCc2jOzgvKLD7iOdgQ3JjbZCpEGx3WE3KdQr7B63dQ6y8+sIYIhmdrxWfNZG6 LgoFw+iXLLqz8L+Su7NSdrN6ru1JPUscjumecFz1iHpaQmdmli800DcYMFJGklND EkrJmaurR/AzxZuod/ReZ2LJqEWeq6ZOqql65ETspiIOJe14CSArXEbyIxqLiQc8 EeLfQDwLY05uuUH+5iYUZYW5CYlluXlvmV851Kju+aOyxtynDTAxQA8yZYaW26JF ZkERl7aCtHS1NcMeTWI4dz6JFt5/JYYjosr8R+PoKdo7+D9FTDEmW+sHd/AGVcgo nyUuhEdjoPgeIibXFe9mMJDv8DsrdTYhigeH3GKkexV7XW5P9jdhlZR1fD7h7Dig 0h+AAp2a/VWmSRt+6TZoIImmNI3yAhbXwM1XpVJVL7IL4Gf3EIHg8BgSFwBk7AuD x9ZhduT75UOfU29sfboyqnimhR87Nhq6Ic6m7Z/qOEesCNHl7kWzinBbrbk7x6B1 fGgYLjMzM5eApILNrb9nyKQcXLDWL1BVjnJBC3TWChdgJ2LYOpg= =1Vas -----END PGP SIGNATURE-----