ICSA-18-317-08
·
Published 2020-02-10
·
View on CISA ICS-CERT ↗
Siemens SIMATIC Panels
CVSS 7.5
HIGH
CVEs (2)
Remediations
- Restrict network access to the integrated web server.
- Deactivate the web server if not required. The web server is disabled by default.
- Update SIMATIC WinCC (TIA Portal) to V15 Update 4 or newer, and then update panel to V15 Update 4 or newer. https://support.industry.siemens.com/cs/ww/en/view/109755826
- Update to V15 Update 4 or newer https://support.industry.siemens.com/cs/ww/en/view/109755826
Affected Vendors
Siemens
Affected Products (7)
Siemens
·
SIMATIC HMI Comfort Panels 4" - 22" (incl. SIPLUS variants)
<V15_Update_4
Siemens
·
SIMATIC HMI Comfort Outdoor Panels 7" & 15" (incl. SIPLUS variants)
<V15_Update_4
Siemens
·
SIMATIC HMI KTP Mobile Panels KTP400F
KTP700
Siemens
·
SIMATIC WinCC Runtime Advanced
<V15_Update_4
Siemens
·
SIMATIC WinCC Runtime Professional
<V15_Update_4
Siemens
·
SIMATIC WinCC (TIA Portal)
<V15_Update_4
Siemens
·
SIMATIC HMI Classic Devices - TP/MP/OP/MP Mobile Panel (incl. SIPLUS variants)
vers:all/*
Affected Sectors
Multiple
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more