-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 # SSA-478960: Missing CSRF Protection in the Web Server Login Page of Industrial Controllers Publication Date: 2022-11-08 Last Update: 2023-09-12 Current Version: 1.7 CVSS v3.1 Base Score: 6.5 SUMMARY ======= The web server login page of affected products does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack.. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens recommends specific countermeasures for products where updates are not, or not yet available. AFFECTED PRODUCTS AND SOLUTION ============================== * SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109773914/ * SIMATIC Drive Controller CPU 1507D TF (6ES7615-7DF10-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109773914/ * SIMATIC ET 200pro IM154-8 PN/DP CPU (6ES7154-8AB01-0AB0) - Affected versions: All versions < V3.2.19 - Remediation: Update to V3.2.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/47354502/ * SIMATIC ET 200pro IM154-8F PN/DP CPU (6ES7154-8FB01-0AB0) - Affected versions: All versions < V3.2.19 - Remediation: Update to V3.2.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/47354578/ * SIMATIC ET 200pro IM154-8FX PN/DP CPU (6ES7154-8FX00-0AB0) - Affected versions: All versions < V3.2.19 - Remediation: Update to V3.2.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/62612377/ * SIMATIC ET 200S IM151-8 PN/DP CPU (6ES7151-8AB01-0AB0) - Affected versions: All versions < V3.2.19 - Remediation: Update to V3.2.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/47353723/ * SIMATIC ET 200S IM151-8F PN/DP CPU (6ES7151-8FB01-0AB0) - Affected versions: All versions < V3.2.19 - Remediation: Update to V3.2.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/47354354/ * SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) - Affected versions: All versions < V21.9.7 - Remediation: Update to V21.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109759122/ * SIMATIC PC Station - Affected versions: All versions >= V2.1 - Remediation: Currently no fix is planned Disable the web server. Note that this feature is disabled by default See further recommendations from section "Workarounds and Mitigations" * SIMATIC S7-300 CPU 314C-2 PN/DP (6ES7314-6EH04-0AB0) - Affected versions: All versions < V3.3.19 - Remediation: Update to V3.3.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/51466769/ * SIMATIC S7-300 CPU 315-2 PN/DP (6ES7315-2EH14-0AB0) - Affected versions: All versions < V3.2.19 - Remediation: Update to V3.2.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/40360647/ * SIMATIC S7-300 CPU 315F-2 PN/DP (6ES7315-2FJ14-0AB0) - Affected versions: All versions < V3.2.19 - Remediation: Update to V3.2.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/40944925/ * SIMATIC S7-300 CPU 315T-3 PN/DP (6ES7315-7TJ10-0AB0) - Affected versions: All versions < V3.2.19 - Remediation: Update to V3.2.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/85049260/ * SIMATIC S7-300 CPU 317-2 PN/DP (6ES7317-2EK14-0AB0) - Affected versions: All versions < V3.2.19 - Remediation: Update to V3.2.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/40362228/ * SIMATIC S7-300 CPU 317F-2 PN/DP (6ES7317-2FK14-0AB0) - Affected versions: All versions < V3.2.19 - Remediation: Update to V3.2.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/40945128/ * SIMATIC S7-300 CPU 317T-3 PN/DP (6ES7317-7TK10-0AB0) - Affected versions: All versions < V3.2.19 - Remediation: Update to V3.2.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/85059804/ * SIMATIC S7-300 CPU 317TF-3 PN/DP (6ES7317-7UL10-0AB0) - Affected versions: All versions < V3.2.19 - Remediation: Update to V3.2.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/85063017/ * SIMATIC S7-300 CPU 319-3 PN/DP (6ES7318-3EL01-0AB0) - Affected versions: All versions < V3.2.19 - Remediation: Update to V3.2.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/44442927/ * SIMATIC S7-300 CPU 319F-3 PN/DP (6ES7318-3FL01-0AB0) - Affected versions: All versions < V3.2.19 - Remediation: Update to V3.2.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/44443101/ * SIMATIC S7-400 PN/DP V6 CPU family (incl. SIPLUS variants) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIMATIC S7-1200 CPU family (incl. SIPLUS variants) - Affected versions: All versions < V4.6.0 - Remediation: Update to V4.6.0 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109814248/ * SIMATIC S7-1500 CPU 1510SP F-1 PN (6ES7510-1SJ00-0AB0) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIMATIC S7-1500 CPU 1510SP F-1 PN (6ES7510-1SJ01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1510SP-1 PN (6ES7510-1DJ00-0AB0) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIMATIC S7-1500 CPU 1510SP-1 PN (6ES7510-1DJ01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK00-0AB0) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK02-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK00-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK00-0AB0) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK02-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1511T-1 PN (6ES7511-1TK01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1511TF-1 PN (6ES7511-1UK01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK00-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1512SP F-1 PN (6ES7512-1SK00-0AB0) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIMATIC S7-1500 CPU 1512SP F-1 PN (6ES7512-1SK01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1512SP-1 PN (6ES7512-1DK00-0AB0) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIMATIC S7-1500 CPU 1512SP-1 PN (6ES7512-1DK01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL00-0AB0) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL02-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL00-0AB0) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL02-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1513R-1 PN (6ES7513-1RL00-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM00-0AB0) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM02-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM00-0AB0) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM02-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1515R-2 PN (6ES7515-2RM00-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1515T-2 PN (6ES7515-2TM01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1515TF-2 PN (6ES7515-2UM01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN00-0AB0) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN02-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN00-0AB0) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN01-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN02-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1516T-3 PN/DP (6ES7516-3TN00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1516TF-3 PN/DP (6ES7516-3UN00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1517-3 PN/DP (6ES7517-3AP00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1517F-3 PN/DP (6ES7517-3FP00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1517H-3 PN (6ES7517-3HP00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1517T-3 PN/DP (6ES7517-3TP00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1517TF-3 PN/DP (6ES7517-3UP00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1518-4 PN/DP (6ES7518-4AP00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1518F-4 PN/DP (6ES7518-4FP00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1518HF-4 PN (6ES7518-4JP00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1518T-4 PN/DP (6ES7518-4TP00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU 1518TF-4 PN/DP (6ES7518-4UP00-0AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU S7-1518-4 PN/DP ODK (6ES7518-4AP00-3AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 CPU S7-1518F-4 PN/DP ODK (6ES7518-4FP00-3AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 ET 200pro: CPU 1513PRO F-2 PN (6ES7513-2GL00-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 ET 200pro: CPU 1513PRO-2 PN (6ES7513-2PL00-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 ET 200pro: CPU 1516PRO F-2 PN (6ES7516-2GN00-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 ET 200pro: CPU 1516PRO-2 PN (6ES7516-2PN00-0AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIMATIC S7-1500 Software Controller V2 - Affected versions: All versions < V21.9.7 - Remediation: Update to V21.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478528/ * SIMATIC S7-PLCSIM Advanced - Affected versions: All versions < V5.0 - Remediation: Update to V5.0 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109809300/ * SIMATIC WinCC Runtime Advanced - Affected versions: All versions < V17 Update 5 - Remediation: Update to V17 Update 5 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109800912/ * SINUMERIK ONE - Affected versions: All versions < V6.22 - Remediation: Update to V6.22 or later version See further recommendations from section "Workarounds and Mitigations" - Download: SINUMERIK software can be obtained from your local Siemens account manager. * SIPLUS ET 200S IM151-8 PN/DP CPU (6AG1151-8AB01-7AB0) - Affected versions: All versions < V3.2.19 - Remediation: Update to V3.2.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/47353723/ * SIPLUS ET 200S IM151-8F PN/DP CPU (6AG1151-8FB01-2AB0) - Affected versions: All versions < V3.2.19 - Remediation: Update to V3.2.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/47354354/ * SIPLUS ET 200SP CPU 1510SP F-1 PN (6AG1510-1SJ01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1510SP F-1 PN RAIL (6AG2510-1SJ01-1AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1510SP-1 PN (6AG1510-1DJ01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1510SP-1 PN (6AG1510-1DJ01-7AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1510SP-1 PN RAIL (6AG2510-1DJ01-1AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1510SP-1 PN RAIL (6AG2510-1DJ01-4AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK00-2AB0) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK01-7AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL (6AG2512-1SK01-1AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL (6AG2512-1SK01-4AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1512SP-1 PN (6AG1512-1DK01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1512SP-1 PN (6AG1512-1DK01-7AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1512SP-1 PN RAIL (6AG2512-1DK01-1AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS ET 200SP CPU 1512SP-1 PN RAIL (6AG2512-1DK01-4AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-300 CPU 314C-2 PN/DP (6AG1314-6EH04-7AB0) - Affected versions: All versions < V3.3.19 - Remediation: Update to V3.3.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/51466769/ * SIPLUS S7-300 CPU 315-2 PN/DP (6AG1315-2EH14-7AB0) - Affected versions: All versions < V3.2.19 - Remediation: Update to V3.2.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/40360647/ * SIPLUS S7-300 CPU 315F-2 PN/DP (6AG1315-2FJ14-2AB0) - Affected versions: All versions < V3.2.19 - Remediation: Update to V3.2.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/40944925/ * SIPLUS S7-300 CPU 317-2 PN/DP (6AG1317-2EK14-7AB0) - Affected versions: All versions < V3.2.19 - Remediation: Update to V3.2.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/40362228/ * SIPLUS S7-300 CPU 317F-2 PN/DP (6AG1317-2FK14-2AB0) - Affected versions: All versions < V3.2.19 - Remediation: Update to V3.2.19 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/40945128/ * SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK00-2AB0) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK01-7AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK02-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK02-7AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL (6AG2511-1AK01-1AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL (6AG2511-1AK02-1AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1511-1 PN TX RAIL (6AG2511-1AK01-4AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1511-1 PN TX RAIL (6AG2511-1AK02-4AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK00-2AB0) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK02-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL00-2AB0) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL01-7AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL02-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL02-7AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL00-2AB0) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL02-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1515F-2 PN (6AG1515-2FM01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1515F-2 PN (6AG1515-2FM02-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1515F-2 PN RAIL (6AG2515-2FM02-4AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1515F-2 PN T2 RAIL (6AG2515-2FM01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1515R-2 PN (6AG1515-2RM00-7AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1515R-2 PN TX RAIL (6AG2515-2RM00-4AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN00-2AB0) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN00-7AB0) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN01-7AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN02-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN02-7AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1516-3 PN/DP RAIL (6AG2516-3AN02-4AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1516-3 PN/DP TX RAIL (6AG2516-3AN01-4AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN00-2AB0) - Affected versions: All versions - Remediation: Currently no fix is planned See recommendations from section "Workarounds and Mitigations" * SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN01-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN02-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL (6AG2516-3FN02-2AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL (6AG2516-3FN02-4AB0) - Affected versions: All versions < V2.9.7 - Remediation: Update to V2.9.7 or later version See recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1517H-3 PN (6AG1517-3HP00-4AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1518-4 PN/DP (6AG1518-4AP00-4AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1518F-4 PN/DP (6AG1518-4FP00-4AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ * SIPLUS S7-1500 CPU 1518HF-4 PN (6AG1518-4JP00-4AB0) - Affected versions: All versions < V3.0.1 - Remediation: Update to V3.0.1 or later version See further recommendations from section "Workarounds and Mitigations" - Download: https://support.industry.siemens.com/cs/ww/en/view/109478459/ WORKAROUNDS AND MITIGATIONS =========================== Siemens has identified the following specific workarounds and mitigations that customers can apply to reduce the risk: * Do not access the product's web service via URLs coming from untrusted sources * Disable the web server if possible Product-specific remediations or mitigations can be found in the section "Affected Products and Solution". Please follow the "General Security Recommendations". GENERAL SECURITY RECOMMENDATIONS ================================ As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial- security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity PRODUCT DESCRIPTION =================== SIMATIC Drive Controllers have been designed for the automation of production machines, combining the functionality of a SIMATIC S7-1500 CPU and a SINAMICS S120 drive control. SIMATIC ET 200SP Open Controller is a PC-based version of the SIMATIC S7-1500 Controller including optional visualization in combination with central I/Os in a compact device. SIMATIC PC Station is a software component that manages the SIMATIC software products and interfaces on a PC. SIMATIC S7-1200 CPU products have been designed for discrete and continuous control in industrial environments such as manufacturing, food and beverages, and chemical industries worldwide. SIMATIC S7-1500 CPU products have been designed for discrete and continuous control in industrial environments such as manufacturing, food and beverages, and chemical industries worldwide. SIMATIC S7-1500 ODK CPUs provide functionality of standard S7-1500 CPUs but additionally provide the possibility to run C/C++ Code within the CPU-Runtime for execution of own functions / algorithms implemented in C/C++. They have been designed for discrete and continuous control in industrial environments such as manufacturing, food and beverages, and chemical industries worldwide. SIMATIC S7-1500 Software Controller is a SIMATIC software controller for PC-based automation solutions. SIMATIC S7-300 controllers have been designed for discrete and continuous control in industrial environments such as manufacturing, food and beverages, and chemical industries worldwide. SIMATIC S7-400 controllers have been designed for discrete and continuous control in industrial environments such as manufacturing, food and beverages, and chemical industries worldwide. SIMATIC S7-PLCSIM Advanced simulates S7-1200, S7-1500 and a few other PLC derivatives. Includes full network access to simulate the PLCs, even in virtualized environments. SIMATIC WinCC Runtime Advanced is a visualization runtime platform used for operator control and monitoring of machines and plants. SINUMERIK ONE is a digital-native CNC system with an integrated SIMATIC S7-1500 CPU for automation. SIPLUS extreme products are designed for reliable operation under extreme conditions and are based on SIMATIC, LOGO!, SITOP, SINAMICS, SIMOTION, SCALANCE or other devices. SIPLUS devices use the same firmware as the product they are based on. VULNERABILITY CLASSIFICATION ============================ The vulnerability classification has been performed by using the CVSS scoring system in version 3.1 (CVSS v3.1) (https://www.first.org/cvss/). The CVSS environmental score is specific to the customer's environment and will impact the overall CVSS score. The environmental score should therefore be individually defined by the customer to accomplish final scoring. An additional classification has been performed using the CWE classification, a community-developed list of common software security weaknesses. This serves as a common language and as a baseline for weakness identification, mitigation, and prevention efforts. A detailed list of CWE classes can be found at: https://cwe.mitre.org/. * Vulnerability CVE-2022-30694 The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack. CVSS v3.1 Base Score: 6.5 CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C CWE: CWE-352: Cross-Site Request Forgery (CSRF) ACKNOWLEDGMENTS =============== Siemens thanks the following party for its efforts: * K Narahari from Sectrio for reporting the vulnerability ADDITIONAL INFORMATION ====================== SINUMERIK ONE: This vulnerability affects the integrated SIMATIC S7-1500 CPU. For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories HISTORY DATA ============ V1.0 (2022-11-08): Publication Date V1.1 (2022-12-13): Added fix for SIMATIC Drive Controller family, SIMATIC S7-PLCSIM Advanced, and SIMATIC S7-1500 and S7-1200 CPU families V1.2 (2023-01-10): No fix planned for SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants) V1.3 (2023-04-11): Replaced S7-1500 with list of individual devices and clarified individual fix state, added fix for SIMATIC WinCC Runtime Advanced V1.4 (2023-05-09): Added fix for SIMATIC S7-1500 Software Controller V1.5 (2023-07-11): Added fix for SIMATIC S7-1500 CPU V2 firmware versions; Fix for SIMATIC Drive Controller available already with V2.9.7 V1.6 (2023-08-08): Added fix for SINUMERIK ONE V1.7 (2023-09-12): Added the affected product SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants); Clarified SIMATIC S7-1500 Software Controller versions and adjusted fix for SIMATIC S7-1500 Software Controller V2 TERMS OF USE ============ Siemens Security Advisories are subject to the terms and conditions contained in Siemens' underlying license terms or other applicable agreements previously agreed to with Siemens (hereinafter "License Terms"). To the extent applicable to information, software or documentation made available in or through a Siemens Security Advisory, the Terms of Use of Siemens' Global Website (https://www.siemens.com/terms_of_use, hereinafter "Terms of Use"), in particular Sections 8-10 of the Terms of Use, shall apply additionally. In case of conflicts, the License Terms shall prevail over the Terms of Use. Copyright: Siemens 2023 -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEHyx/myPwjH9jB9tDlm7gTEmyujQFAmT/qgAACgkQlm7gTEmy ujSqnxAAmdtjdcoCxUTthl3I3oit/tYcMRPX5Y7bFIcWnvbbqziG7M7u4A6FZt8L yF+L80WtJ6lPlGuf1B0VMFmwS9HZi4RiPtcBeUs7gLmtNkTikz2wgJZ1+Wdf8mtj HOEf+l4vskp9cRV9SWzMieQyY2hxeI6eLVc39jvDTUG8ki7ARDE74j7b4xkfhGGc mkcYO51ZOWBgohVK3DUl3nQ6i/y1jjsOqHiuXzekvT+QfhHx8IAqI87jao5d9W6W WSnM3FxjdHhR07qoNsuqO/SELM+8WQPBgCMkFqwQSl1nknmmTdw/TDN5bU9rTt+u lCMh1Ef0qiqosGjRj5o0MM9FO3wSvwh7TXPri+jXUMrG5Y108aP2UUcP+NKoSK5E NZ8niaTQOUHcXkAK3ktrbXO60Sx52OP1GKIY5DhCULAsoPa3jmi9XpIN66wLhCTf OiSVAdY8ZvNnszwNLz7LhBgJsSbxGi3faAndYxtxcMyYm3lGXzTDvb9ENrBT3cUC 4V8T12IRvmTXFzkiqh6X5nL0ZJSh2Ho0BDbaKlvmdluENwEEXDp9v9G7HXN3Poif Qs+UJquU+sefQ/xomM8oL8sgxKKER260wREdFQAGNBzKrjrAvtPP5zagbTKppqQ3 aCgdejtpcfAEEL0N660z/yDQ5oEg0GZ0zRYTWdPzQc9LzCRPVcs= =ym8G -----END PGP SIGNATURE-----