← Back to home
ICSA-15-099-01E  ·  Published 2025-06-18  ·  View on CISA ICS-CERT ↗

Siemens SIMATIC HMI Devices Vulnerabilities (Update E)

CVSS 6.8 MEDIUM

CVEs (1)

Remediations

  • SIMATIC HMI Basic Panels 2nd Generation: Update to WinCC (TIA Portal) V13 SP1 Upd2: (https://support.industry.siemens.com/cs/ww/en/view/109311724)
  • SIMATIC HMI Comfort Panels: Update to WinCC (TIA Portal) V12 SP1 Upd5: (https://support.industry.siemens.com/cs/ww/en/view/78683919)
  • Update to WinCC (TIA Portal) V13 SP1 Upd2: (https://support.industry.siemens.com/cs/ww/en/view/109311724)
  • SIMATIC WinCC Runtime Advanced: Update to V12 SP1 Upd5: (https://support.industry.siemens.com/cs/ww/en/view/79684570)
  • Update to V13 SP1 Upd2: (https://support.industry.siemens.com/cs/ww/en/view/109311423)
  • SIMATIC WinCC Runtime Professional: Update to V13 SP1 Upd2: (https://support.industry.siemens.com/cs/ww/en/view/109439573)
  • SIMATIC HMI Basic Panels 1st Generation (WinCC TIA Portal): Update to WinCC (TIA Portal) V12 SP1 Upd5: (https://support.industry.siemens.com/cs/ww/en/view/78683919)
  • Update to WinCC (TIA Portal) V13 SP1 Upd4: (https://support.industry.siemens.com/cs/ww/en/view/109311724)
  • SIMATIC HMI Mobile Panel 277 (WinCC TIA Portal): Update to WinCC (TIA Portal) V12 SP1 Upd5: (https://support.industry.siemens.com/cs/ww/en/view/78683919)
  • SIMATIC HMI Multi Panels (WinCC TIA Portal): Update to WinCC (TIA Portal) V12 SP1 Upd5: (https://support.industry.siemens.com/cs/ww/en/view/78683919)
  • SIMATIC NET PC-Software V12: Update to V12 SP2 HF3: (https://support.industry.siemens.com/cs/ww/en/view/109475388)
  • SIMATIC NET PC-Software V13: Update to V13 HF1: (https://support.industry.siemens.com/cs/ww/en/view/109475388)
  • SIMATIC WinCC V7.X: Update to V7.2 Upd11: (https://support.industry.siemens.com/cs/de/en/view/109478834)
  • Update to V7.3 Upd4: (https://support.industry.siemens.com/cs/de/en/view/109475497)
  • SIMATIC Automation Tool: Update to V1.0.2: (https://support.industry.siemens.com/cs/ww/en/view/98161300)
  • SIMATIC PCS 7 V8.1: Update to SP1: (https://support.industry.siemens.com/cs/ww/en/view/108463041)
  • SIMATIC PCS 7 V8.0: Update to SP2: (https://support.industry.siemens.com/cs/de/en/view/109478834)
  • For WinCC (TIA Portal) V12 or V13 devices, Siemens recommends updating the configuration to WinCC (TIA Portal) V13 SP1 and also updating the device version of the HMI to its latest version (provided with WinCC (TIA Portal) V13 SP1 Upd4). Until patches can be applied, Siemens recommends customers to mitigate the risk of their products by implementing the following steps: Apply cell protection concept, discussed at: (https://www.siemens.com/cert/operational-guidelines-industrial-security)
  • Use VPN for protecting network communication between cells
  • Apply defense-in-depth strategies, which are discussed at: (http://www.industry.siemens.com/topics/global/en/industrial-security/concept/Pages/defense-in-depth.aspx).

Affected Vendors

Siemens

Affected Products (17)

Siemens · SIMATIC HMI Basic Panels 2nd Generation V13 <WinCC_TIA_Portal_V13_SP1_Upd2
Siemens · SIMATIC HMI Comfort Panels V12 <WinCC_TIA_Portal_V12_SP1_Upd5
Siemens · SIMATIC HMI Comfort Panels V13 <WinCC_TIA_Portal_V13_SP1_Upd2
Siemens · SIMATIC WinCC Runtime Advanced V12 <WinCC_Runtime_Advanced_V12_SP1_Upd5
Siemens · SIMATIC WinCC Runtime Advanced V13 <WinCC_Runtime_Advanced_V13_SP1_Upd2
Siemens · SIMATIC WinCC Runtime Professional V13 <WinCC_TIA_Portal_V13_SP1_Upd2
Siemens · SIMATIC HMI Basic Panels 1st Generation (WinCC TIA Portal) V12 <WinCC_TIA_Portal_V12_SP1_Upd5
Siemens · SIMATIC HMI Basic Panels 1st Generation (WinCC TIA Portal) V13 <WinCC_TIA_Portal_V13_SP1_Upd4
Siemens · SIMATIC HMI Mobile Panel 277 (WinCC TIA Portal) V12 <WinCC_TIA_Portal_V12_SP1_Upd5
Siemens · SIMATIC HMI Mobile Panel 277 (WinCC TIA Portal) V13 <WinCC_TIA_Portal_V13_SP1_Upd4
Siemens · SIMATIC HMI Multi Panels (WinCC TIA Portal) V12 <WinCC_TIA_Portal_V12_SP1_Upd5
Siemens · SIMATIC HMI Multi Panels (WinCC TIA Portal) V13 <WinCC_TIA_Portal_V13_SP1_Upd4
Siemens · SIMATIC NET PC-Software V12 <V12_SP2_HF3
Siemens · SIMATIC NET PC-Software V13 <V13_HF1
Siemens · SIMATIC WinCC V7.2 <V7.2_Upd11
Siemens · SIMATIC WinCC V7.3 <V7.3_Upd4
Siemens · SIMATIC PCS 7 <V8.1_SP1

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more