ICSA-21-040-08
·
Published 2021-05-11
·
View on CISA ICS-CERT ↗
Siemens SIMARIS Configuration (Update A)
CVSS 4.4
MEDIUM
Risk Summary
Successful exploitation of this vulnerability could allow an attacker to gain persistence or escalate privileges within the system.
CVEs (1)
Remediations
- Siemens has released an update for SIMARIS configuration and recommends updating to v4.0.1 or later.
- Siemens has identified the following specific workarounds and mitigations users can apply to reduce the risk:
- Siemens strongly recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens ' operational guidelines for Industrial Security and follow the recommendations in the product manuals.
- Additional information on industrial security by Siemens can be found at: https://www.siemens.com/Industrialsecurity
Affected Vendors
Siemens
Affected Products (1)
Siemens
·
SIMARIS configuration
< 4.0.1
Affected Sectors
Energy
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more