ICSA-15-034-02
·
Published 2025-06-06
·
View on CISA ICS-CERT ↗
Siemens Ruggedcom WIN Vulnerability
CVSS 10.0
CRITICAL
CVEs (3)
Remediations
- Siemens has produced a firmware update that mitigates these vulnerabilities and recommends updating as soon as possible. The firmware update for the affected products can be obtained for free by the following methods:
- Submit a support request online at: https://support.automation.siemens.com/WW/llisapi.dll?func=cslib.csinfoandlang=enandobjid=38718979andcaller=view
- Call a local hotline center. Location search is available at: http://www.automation.siemens.com/mcms/aspa-db/en/automationtechnology/Pages/default.aspx
- Siemens also recommends protecting network access to all products except for perimeter devices with appropriate mechanisms. It is advised to follow recommended security practices and to configure the environment according to operational guidelines in order to run the devices in a protected IT environment. Siemens operational guidelines are available at: https://www.industry.siemens.com/topics/global/en/industrial-security/Documents/operational_guidelines_industrial_security_en.pdf.
- For more information on these vulnerabilities and detailed instructions, please see Siemens Security Advisory SSA-753139 at the following location: http://www.siemens.com/cert/advisories
Affected Vendors
Siemens
Affected Products (4)
Siemens
·
WIN51xx
<SS4.4.4624.35
Siemens
·
WIN52xx
<SS4.4.4624.35
Siemens
·
WIN70xx
<BS4.4.4621.32
Siemens
·
WIN72xx
<BS4.4.4621.32
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more