ICSA-17-194-01
·
Published 2017-07-13
·
View on CISA ICS-CERT ↗
Siemens SiPass integrated
CVSS 9.8
CRITICAL
Risk Summary
ATTENTION: Remotely exploitable/low skill level to exploit.
Remediations
- Siemens provides SiPass integrated V2.70, which fixes the vulnerabilities, and recommends users update to the new version. The new version can be obtained from Siemens customer support or from authorized partners.
- For more information on these vulnerabilities and more detailed mitigation instructions, please see Siemens Security Advisory SSA-339433 at the following location:
- http://www.siemens.com/cert/advisories
- In addition, ICS-CERT recommends that users take the following measures to protect themselves from social engineering attacks:
Affected Vendors
Siemens
Affected Products (1)
Siemens
·
SiPass integrated
< 2.70
Affected Sectors
Energy, Healthcare and Public Health, Transportation Systems
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more