← Back to home
ICSA-16-287-02  ·  Published 2025-06-05  ·  View on CISA ICS-CERT ↗

Siemens Automation License Manager Vulnerabilities

CVSS 9.1 CRITICAL

Remediations

  • Siemens has released ALM Version V5.3 SP3 Update 1, which fixes the vulnerabilities. Siemens strongly recommends users to update to the new version. It can be found on the Siemens web site at the following location: (https://support.industry.siemens.com/cs/ww/en/view/114358)
  • Siemens recommends only allowing connections from the local subnet to the ALM default Port 4410/TCP and blocking requests from other networks. These products should only be operated within trusted networks.
  • Siemens strongly recommends that users protect network access PC-based automation systems with appropriate mechanisms. Siemens also advises that users configure the operational environment according to Siemens’ operational guidelines for industrial security: (https://www.siemens.com/cert/operational-guidelines-industrial-security)
  • For more information on this vulnerability and more detailed mitigation instructions, please see Siemens Security Advisory SSA-284342 at the following location: (http://www.siemens.com/cert/advisories)

Affected Vendors

Siemens

Affected Products (1)

Siemens · ALM <V5.3_SP3_Update_1

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more