← Back to home
ICSA-24-256-14  ·  Published 2025-01-14  ·  View on CISA ICS-CERT ↗

Siemens SIMATIC SCADA and PCS 7 Systems

CVSS 9.1 CRITICAL

CVEs (1)

Remediations

  • Currently no fix is planned
  • Update to V18 Update 5 or later version
  • Update to V19 Update 3 or later version
  • Update to V2020 SP2 Update 5 or later version
  • Update to V2022 SP1 Update 2 or later version To update, use the Process Historian version as bundled with PCS neo V5.0 Update 1 (<https://support.industry.siemens.com/cs/ww/en/view/109977244/>)
  • Update to V2022 SP1 Update 2 or later version To update, use the Information Server version as bundled with PCS neo V5.0 Update 1 (<https://support.industry.siemens.com/cs/ww/en/view/109977244/>)
  • Update to V7.5 SP2 Update 18 or later version
  • Update to V8.0 Update 5 or later version
  • Update to V9.1 SP2 UC06 or later version
  • Update to PCS7 V9.1 SP2 UC06 or later version https://support.industry.siemens.com/cs/ww/en/view/109812242/

Affected Vendors

Siemens

Affected Products (11)

Siemens · SIMATIC BATCH V9.1 vers:all/*
Siemens · SIMATIC Information Server 2020 <V2020_SP2_Update_5
Siemens · SIMATIC Information Server 2022 <V2022_SP1_Update_2
Siemens · SIMATIC PCS 7 V9.1 <V9.1_SP2_UC06
Siemens · SIMATIC Process Historian 2020 <V2020_SP2_Update_5
Siemens · SIMATIC Process Historian 2022 <V2022_SP1_Update_2
Siemens · SIMATIC WinCC Runtime Professional V18 <V18_Update_5
Siemens · SIMATIC WinCC Runtime Professional V19 <V19_Update_3
Siemens · SIMATIC WinCC V7.4 vers:all/*
Siemens · SIMATIC WinCC V7.5 <V7.5_SP2_Update_18
Siemens · SIMATIC WinCC V8.0 <V8.0_Update_5

Affected Sectors

Chemical, Energy, Food and Agriculture, and Water and Wastewater Systems

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more