ICSA-19-344-06
·
Published 2020-03-10
·
View on CISA ICS-CERT ↗
Siemens SIMATIC S7-1200 and S7-1500 CPU Families (Update B)
CVSS 5.3
MEDIUM
Risk Summary
Successful exploitation of these vulnerabilities may allow an attacker to modify network traffic or impact the perceived integrity of the user program stored on the CPU.
CVEs (2)
Remediations
- SIMATIC S7 PLCSIM Advanced: Update to v3.0
- SIMATIC S7-1200 CPU family: Update to v4.4.0
- SIMATIC S7-1500 CPU family: Update to v2.8.1
- SIMATIC S7-1500 Software Controller: Update to v20.8
- SIMATIC ET 200SP Open Controller CPU 1515SP PC2: Update to v20.8
- All affected devices contain a feature called “Access Protection” that prohibits unauthorized modifications of user code. Siemens recommends using access protection to protect affected devices from unauthorized modifications.
- Minimize network exposure for all control system devices and/or systems, and ensure that they are not accessible from the Internet.
- Locate control system networks and remote devices behind firewalls, and isolate them from the business network.
- When remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize that VPN is only as secure as the connected devices.
- As a general security measure, Siemens strongly recommends users protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends users configure the environment according to Siemens ' operational guidelines for industrial security, and follow the recommendations in the product manuals. Additional information on industrial security by Siemens can be found at: https://www.siemens.com/industrialsecurity.
Affected Vendors
Siemens
Affected Products (13)
Siemens
·
SIMATIC Drive Controller family
* (only affected by CVE-2019-10943)
Siemens
·
SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants)
< 2.8.1
Siemens
·
SIMATIC S7-PLCSIM Advanced
< 3.0
Siemens
·
SIMATIC S7-1500 Software Controller
< 20.8
Siemens
·
SIMATIC S7-1200 CPU family (incl. SIPLUS variants)
< 4.4.0
Siemens
·
SIMATIC ET200SP (incl. SIPLUS variants) Open Controller CPU 1515SP PC
vers:all/*
Siemens
·
SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants)
>= 2.8.1 (only affected by CVE-2019-10943)
Siemens
·
SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants)
>= 20.8 (only affected by CVE-2019-10943)
Siemens
·
SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants)
vers:all/*
Siemens
·
SIMATIC S7-PLCSIM Advanced
>= 3.0 (only affected by CVE-2019-10943)
Siemens
·
SIMATIC S7-1200 CPU family (incl. SIPLUS variants)
>= 4.4.0 (only affected by CVE-2019-10943)
Siemens
·
SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants)
< 20.8
Siemens
·
SIMATIC S7-1500 Software Controller
>= 20.8 (only affected by CVE-2019-10943)
Affected Sectors
Chemical, Critical Manufacturing, Energy, Food and Agriculture, Water and Wastewater Systems
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more