← Back to home
ICSA-22-286-02  ·  Published 2022-10-13  ·  View on CISA ICS-CERT ↗

Siemens Industrial Edge Management

CVSS 7.4 HIGH

Risk Summary

Successful exploitation of this vulnerability could allow an attacker to inject malicious maintenance requests by exploiting improper certification validation. An attacker could exploit this vulnerability by sending statistics, activating remote support, exchanging the initial keys when onboarding, querying new extensions, or accessing sensitive data.

CVEs (1)

Remediations

  • Siemens recommends users to update to v1.5.1 or later (login required).
  • As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens ' operational guidelines for industrial security and to follow the recommendations in the product manuals.
  • For more information, see Siemens Security Advisory SSA-459643 in HTML or CSAF.

Affected Vendors

Siemens

Affected Products (1)

Siemens · Industrial Edge Management All versions prior to V1.5.1

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more