← Back to home
ICSA-21-040-08  ·  Published 2021-05-11  ·  View on CISA ICS-CERT ↗

Siemens SIMARIS Configuration (Update A)

CVSS 4.4 MEDIUM

Risk Summary

Successful exploitation of this vulnerability could allow an attacker to gain persistence or escalate privileges within the system.

CVEs (1)

Remediations

  • Siemens has released an update for SIMARIS configuration and recommends updating to v4.0.1 or later.
  • Siemens has identified the following specific workarounds and mitigations users can apply to reduce the risk:
  • Siemens strongly recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens ' operational guidelines for Industrial Security and follow the recommendations in the product manuals.
  • Additional information on industrial security by Siemens can be found at: https://www.siemens.com/Industrialsecurity

Affected Vendors

Siemens

Affected Products (1)

Siemens · SIMARIS configuration < 4.0.1

Affected Sectors

Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more