ICSA-20-042-06
·
Published 2023-04-11
·
View on CISA ICS-CERT ↗
Siemens SIMATIC PCS 7, SIMATIC WinCC, and SIMATIC NET PC (Update G)
CVSS 7.5
HIGH
CVEs (1)
Remediations
- Use VPN for protecting network communication between cells
- The vulnerability is fixed if SIMATIC WinCC V7.4 SP1 Update 14 or later version is installed on the same system
- Currently no fix is planned
- Update to V8.2 Upd12 or later version
- See remediation for SIMATIC PCS 7 V9.0
- Update to V8.2 SP1; then update SIMATIC WinCC to V7.4 SP1 Update 14 or later version on the same system
- Update to V9.0 SP3 or later version
- Update to V13 SP2 or later version
- Update to V15.1 Update 5 or later version
- Update to V16 Update 1 or later version
- Update to V7.4 SP1 Update 14 or later version
- Update to V7.5 SP1 Update 1 or later version
- Update to V14 SP1 Update 10 or later version
- Update to V14 SP1 Update 14 or later version
Affected Vendors
Siemens
Affected Products (22)
Siemens
·
OpenPCS 7 V8.1
vers:all/*
Siemens
·
OpenPCS 7 V8.2
vers:all/*
Siemens
·
OpenPCS 7 V9.0
<V9.0_Upd3
Siemens
·
SIMATIC BATCH V8.1
vers:all/*
Siemens
·
SIMATIC BATCH V8.2
<vers:/_V8.2_Upd12
Siemens
·
SIMATIC BATCH V9.0
<V9.0_SP1_Upd5
Siemens
·
SIMATIC NET PC Software V14
<V14_SP1_Update_14
Siemens
·
SIMATIC NET PC Software V15
vers:all/*
Siemens
·
SIMATIC NET PC Software V16
<V16_Update_1
Siemens
·
SIMATIC PCS 7 V8.1
vers:all/*
Siemens
·
SIMATIC PCS 7 V8.2
vers:all/*
Siemens
·
SIMATIC PCS 7 V9.0
<V9.0_SP3
Siemens
·
SIMATIC Route Control V8.1
vers:all/*
Siemens
·
SIMATIC Route Control V8.2
vers:all/*
Siemens
·
SIMATIC Route Control V9.0
<V9.0_Upd4
Siemens
·
SIMATIC WinCC (TIA Portal) V13
<V13_SP2
Siemens
·
SIMATIC WinCC (TIA Portal) V14
<V14_SP1_Update_10
Siemens
·
SIMATIC WinCC (TIA Portal) V15.1
<V15.1_Update_5
Siemens
·
SIMATIC WinCC (TIA Portal) V16
<V16_Update_1
Siemens
·
SIMATIC WinCC V7.3
vers:all/*
Siemens
·
SIMATIC WinCC V7.4
<V7.4_SP1_Update_14
Siemens
·
SIMATIC WinCC V7.5
<V7.5_SP1_Update_1
Affected Sectors
Multiple
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more