← Back to home
ICSA-22-349-10  ·  Published 2025-05-06  ·  View on CISA ICS-CERT ↗

Siemens APOGEE/TALON Field Panels

CVSS 7.5 HIGH

Risk Summary

Successful exploitation of this vulnerability could allow an attacker to hijack existing sessions or spoof future sessions.

Remediations

  • Siemens products that contain a vulnerable TLS server and have certificate-based client authentication enabled: do not configure trust for CA certificates, that contain a nameConstraint-extension (https://www.rfc-editor.org/rfc/rfc5280#section-4.2.1.10) with punycode-encoded internationalized domain names
  • Siemens products that contain a vulnerable TLS client: in cases where this option is configurable: ensure that TLS server certificate verification is turned on and do not configure trust for CA certificates, that contain a nameConstraint-extension (https://www.rfc-editor.org/rfc/rfc5280#section-4.2.1.10) with punycode-encoded internationalized domain names
  • As a mitigation for vulnerable versions: In the truststore, do not add CA certificates that contain a nameConstraint-extension ( https://www.rfc-editor.org/rfc/rfc5280#section-4.2.1.10) with punycode-encoded internationalized domain names
  • Ensure that only trusted (CA) certificates are contained in the Machine Agent's truststore
  • Currently no fix is available
  • Update to V2.20 or later version
  • Update to V2023.1 or later version
  • As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity

Affected Vendors

Siemens

Affected Products (5)

Siemens · Calibre ICE >=V2022.4<V2023.1
Siemens · Mcenter >=V5.2.1.0
Siemens · SCALANCE X-200RNA switch family >=V3.2.7
Siemens · SICAM GridPass (6MD7711-2AA00-1EA0) >=V1.80<V2.20
Siemens · SIMATIC RTLS Locating Manager (6GT2780-0DA00) >=V2.13

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more