← Back to home
ICSA-21-350-06  ·  Published 2025-05-06  ·  View on CISA ICS-CERT ↗

Siemens Capital VSTAR

CVSS 8.2 HIGH

Remediations

  • Apply network segmentation and put the ECUs behind properly configured gateways/firewalls
  • Currently no fix is planned
  • Update to V2303 or later version
  • Disable the DHCP client and use static IP address configuration instead (Note that the DHCP client is disabled by default on APOGEE, Desigo, and TALON products.)
  • Disable DHCP client functionality, if feature not used, by deselecting the TcpIpIpV4General/TcpIpDhcpClientEnabled Pre-Compile configuration option

Affected Vendors

Siemens

Affected Products (2)

Siemens · Capital Embedded AR Classic 431-422 vers:all/*
Siemens · Capital Embedded AR Classic R20-11 <V2303

Affected Sectors

Critical Manufacturing, Transportation Systems, Energy, Healthcare and Public Health, Financial Services, Government Services and Facilities

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more