ICSA-23-257-06
·
Published 2024-05-14
·
View on CISA ICS-CERT ↗
Siemans WIBU Systems CodeMeter
CVSS 9.0
CRITICAL
CVEs (1)
Remediations
- If CodeMeter Runtime is configured as server: Limit remote access to systems where the CodeMeter Runtime network server is running
- For affected versions: Install WIBU Systems CodeMeter Runtime V7.60c or later version manually to fix the issue: Download the package from https://www.wibu.com/support/user/user-software.html and follow the installation instructions from WIBU Systems.
- For affected versions: Install WIBU Systems CodeMeter Runtime V7.60c or later version manually to fix the issue: Download the package from https://www.wibu.com/support/user/user-software.html and follow the installation instructions from WIBU Systems.
- Currently no fix is planned
- Update to V1.0 SP2 Update 2 or later version
- Update to V11.2 or later version
- Update to V13.1.12.1 or later version
- Update to V15.0.22 or later version
- Update to V3.17 P030 or later version
- Update to V3.18 P021 or later version
- Update to V3.19 P006 or later version
- Update to V34.9.6 or later version
- Update to V35.6.1 or later version
- CAPE V14 installations installed from material dated 2023-08-23 or later are not affected, as they contain a fixed version of CodeMeter Runtime. For installations of CAPE V14 using material earlier than 2023-08-23: Install WIBU Systems CodeMeter Runtime V7.60c or later version manually to fix the issue: Download the package from https://www.wibu.com/support/user/user-software.html and follow the installation instructions from WIBU Systems.
- Install WIBU Systems CodeMeter Runtime V7.60c or later version manually to fix the issue: Download the package from https://www.wibu.com/support/user/user-software.html and follow the installation instructions from WIBU Systems.
- If CodeMeter Runtime is configured as client only in the affected product: Ensure that only trusted persons have access to the system and avoid the configuration of additional local accounts
Affected Vendors
Siemens
Affected Products (14)
Siemens
·
PSS(R)CAPE V14
<V14.2023-08-23
Siemens
·
PSS(R)CAPE V15
<V15.0.22
Siemens
·
PSS(R)E V34
<V34.9.6
Siemens
·
PSS(R)E V35
<V35.6.1
Siemens
·
PSS(R)ODMS V13.0
vers:all/*
Siemens
·
PSS(R)ODMS V13.1
<V13.1.12.1
Siemens
·
SIMATIC PCS neo V3
vers:all/*
Siemens
·
SIMATIC PCS neo V4.0
vers:all/*
Siemens
·
SIMATIC WinCC OA V3.17
<V3.17_P030
Siemens
·
SIMATIC WinCC OA V3.18
<V3.18_P021
Siemens
·
SIMATIC WinCC OA V3.19
<V3.19_P006
Siemens
·
SIMIT Simulation Platform
>=V10.0<V11.2
Siemens
·
SINEC INS
<V1.0_SP2_Update_2
Siemens
·
SINEMA Remote Connect
vers:all/*
Affected Sectors
Multiple
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more