← Back to home
ICSA-18-345-02  ·  Published 2019-03-12  ·  View on CISA ICS-CERT ↗

ICSA-18-345-02 Siemens SINUMERIK Controllers (Update A)

CVSS 10.0 CRITICAL

Remediations

  • Update to V4.7 SP6 HF1 and follow recommendations from section Workarounds and Mitigations. - Download: SINUMERIK software can be obtained from your local Siemens account manager.
  • Update to V4.7 SP6 HF5 and follow recommendations from section Workarounds and Mitigations. - Download: SINUMERIK software can be obtained from your local Siemens account manager.
  • Update to V4.8 SP3 and follow recommendations from section Workarounds and Mitigations. - Download: SINUMERIK software can be obtained from your local Siemens account manager.
  • Siemens has identified the following specific workarounds and mitigations thatcustomers can apply to reduce the risk:firewall on port X130privilege approach Check and restore default settings (4842/tcp and 5900/tcp blocked) for
  • Siemens has identified the following specific workarounds and mitigations thatcustomers can apply to reduce the risk:firewall on port X130privilege approach Restrict system access to authorized personnel and follow a least
  • Siemens has identified the following specific workarounds and mitigations thatcustomers can apply to reduce the risk:firewall on port X130privilege approach Apply cell protection concept
  • Siemens has identified the following specific workarounds and mitigations thatcustomers can apply to reduce the risk:firewall on port X130privilege approach Use VPN for protecting network communication between cells
  • Siemens has identified the following specific workarounds and mitigations thatcustomers can apply to reduce the risk:firewall on port X130privilege approach Apply Defense-in-Depth
  • Update to V4.91 and follow recommendations from section Workarounds and Mitigations. - Download: SINUMERIK software can be obtained from your local Siemens account manager.

Affected Vendors

Siemens

Affected Products (5)

Siemens · SINUMERIK 808D V4.7 <V4.91
Siemens · SINUMERIK 808D V4.8 <V4.91
Siemens · SINUMERIK 828D V4.7 <V4.7_SP6_HF1
Siemens · SINUMERIK 840D sl V4.7 <V4.7_SP6_HF5
Siemens · SINUMERIK 840D sl V4.8 <V4.8_SP3

Affected Sectors

Multiple

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more