← Back to home
ICSA-20-042-06  ·  Published 2023-04-11  ·  View on CISA ICS-CERT ↗

Siemens SIMATIC PCS 7, SIMATIC WinCC, and SIMATIC NET PC (Update G)

CVSS 7.5 HIGH

CVEs (1)

Remediations

  • Use VPN for protecting network communication between cells
  • The vulnerability is fixed if SIMATIC WinCC V7.4 SP1 Update 14 or later version is installed on the same system
  • Currently no fix is planned
  • Update to V8.2 Upd12 or later version
  • See remediation for SIMATIC PCS 7 V9.0
  • Update to V8.2 SP1; then update SIMATIC WinCC to V7.4 SP1 Update 14 or later version on the same system
  • Update to V9.0 SP3 or later version
  • Update to V13 SP2 or later version
  • Update to V15.1 Update 5 or later version
  • Update to V16 Update 1 or later version
  • Update to V7.4 SP1 Update 14 or later version
  • Update to V7.5 SP1 Update 1 or later version
  • Update to V14 SP1 Update 10 or later version
  • Update to V14 SP1 Update 14 or later version

Affected Vendors

Siemens

Affected Products (22)

Siemens · OpenPCS 7 V8.1 vers:all/*
Siemens · OpenPCS 7 V8.2 vers:all/*
Siemens · OpenPCS 7 V9.0 <V9.0_Upd3
Siemens · SIMATIC BATCH V8.1 vers:all/*
Siemens · SIMATIC BATCH V8.2 <vers:/_V8.2_Upd12
Siemens · SIMATIC BATCH V9.0 <V9.0_SP1_Upd5
Siemens · SIMATIC NET PC Software V14 <V14_SP1_Update_14
Siemens · SIMATIC NET PC Software V15 vers:all/*
Siemens · SIMATIC NET PC Software V16 <V16_Update_1
Siemens · SIMATIC PCS 7 V8.1 vers:all/*
Siemens · SIMATIC PCS 7 V8.2 vers:all/*
Siemens · SIMATIC PCS 7 V9.0 <V9.0_SP3
Siemens · SIMATIC Route Control V8.1 vers:all/*
Siemens · SIMATIC Route Control V8.2 vers:all/*
Siemens · SIMATIC Route Control V9.0 <V9.0_Upd4
Siemens · SIMATIC WinCC (TIA Portal) V13 <V13_SP2
Siemens · SIMATIC WinCC (TIA Portal) V14 <V14_SP1_Update_10
Siemens · SIMATIC WinCC (TIA Portal) V15.1 <V15.1_Update_5
Siemens · SIMATIC WinCC (TIA Portal) V16 <V16_Update_1
Siemens · SIMATIC WinCC V7.3 vers:all/*
Siemens · SIMATIC WinCC V7.4 <V7.4_SP1_Update_14
Siemens · SIMATIC WinCC V7.5 <V7.5_SP1_Update_1

Affected Sectors

Multiple

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more