← Back to home
ICSA-24-256-04  ·  Published 2024-09-10  ·  View on CISA ICS-CERT ↗

Siemens SINUMERIK Systems

CVSS 5.5 MEDIUM

CVEs (1)

Remediations

  • Delete the file(s) manually (after using CMC): - on an NCU: /card/user/sinumerik/hmi/log/sltrc/uptrace.out - on an IPC: c:\ProgramData\Siemens\MotionControl\user\sinumerik\hmi\log\sltrc\uptrace.out and the corresponding backup of the tracefile, uptrace.out.bak. Replace trace configuration to switch off trace for the future.
  • Update to V4.95 SP3 or later version
  • Update to V6.15 SP4 or later version
  • Update to V6.23 or later version

Affected Vendors

Siemens

Affected Products (4)

Siemens · SINUMERIK 828D V4 <V4.95_SP3
Siemens · SINUMERIK 840D sl V4 <=<_V4.95_SP3_in_connection_with_using_Create_MyConfig_CMC_V4.8_SP1_HF6
Siemens · SINUMERIK ONE <=<_V6.23_in_connection_with_using_Create_MyConfig_CMC_V6.6
Siemens · SINUMERIK ONE <=<_V6.15_SP4_in_connection_with_using_Create_MyConfig_CMC_V6.6

Affected Sectors

Multiple

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more