ICSA-22-349-10
·
Published 2025-05-06
·
View on CISA ICS-CERT ↗
Siemens APOGEE/TALON Field Panels
CVSS 7.5
HIGH
Risk Summary
Successful exploitation of this vulnerability could allow an attacker to hijack existing sessions or spoof future sessions.
CVEs (2)
Remediations
- Siemens products that contain a vulnerable TLS server and have certificate-based client authentication enabled: do not configure trust for CA certificates, that contain a nameConstraint-extension (https://www.rfc-editor.org/rfc/rfc5280#section-4.2.1.10) with punycode-encoded internationalized domain names
- Siemens products that contain a vulnerable TLS client: in cases where this option is configurable: ensure that TLS server certificate verification is turned on and do not configure trust for CA certificates, that contain a nameConstraint-extension (https://www.rfc-editor.org/rfc/rfc5280#section-4.2.1.10) with punycode-encoded internationalized domain names
- As a mitigation for vulnerable versions: In the truststore, do not add CA certificates that contain a nameConstraint-extension ( https://www.rfc-editor.org/rfc/rfc5280#section-4.2.1.10) with punycode-encoded internationalized domain names
- Ensure that only trusted (CA) certificates are contained in the Machine Agent's truststore
- Currently no fix is available
- Update to V2.20 or later version
- Update to V2023.1 or later version
- As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity
Affected Vendors
Siemens
Affected Products (5)
Siemens
·
Calibre ICE
>=V2022.4<V2023.1
Siemens
·
Mcenter
>=V5.2.1.0
Siemens
·
SCALANCE X-200RNA switch family
>=V3.2.7
Siemens
·
SICAM GridPass (6MD7711-2AA00-1EA0)
>=V1.80<V2.20
Siemens
·
SIMATIC RTLS Locating Manager (6GT2780-0DA00)
>=V2.13
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more