ICSA-24-256-14
·
Published 2025-01-14
·
View on CISA ICS-CERT ↗
Siemens SIMATIC SCADA and PCS 7 Systems
CVSS 9.1
CRITICAL
CVEs (1)
Remediations
- Currently no fix is planned
- Update to V18 Update 5 or later version
- Update to V19 Update 3 or later version
- Update to V2020 SP2 Update 5 or later version
- Update to V2022 SP1 Update 2 or later version To update, use the Process Historian version as bundled with PCS neo V5.0 Update 1 (<https://support.industry.siemens.com/cs/ww/en/view/109977244/>)
- Update to V2022 SP1 Update 2 or later version To update, use the Information Server version as bundled with PCS neo V5.0 Update 1 (<https://support.industry.siemens.com/cs/ww/en/view/109977244/>)
- Update to V7.5 SP2 Update 18 or later version
- Update to V8.0 Update 5 or later version
- Update to V9.1 SP2 UC06 or later version
- Update to PCS7 V9.1 SP2 UC06 or later version https://support.industry.siemens.com/cs/ww/en/view/109812242/
Affected Vendors
Siemens
Affected Products (11)
Siemens
·
SIMATIC BATCH V9.1
vers:all/*
Siemens
·
SIMATIC Information Server 2020
<V2020_SP2_Update_5
Siemens
·
SIMATIC Information Server 2022
<V2022_SP1_Update_2
Siemens
·
SIMATIC PCS 7 V9.1
<V9.1_SP2_UC06
Siemens
·
SIMATIC Process Historian 2020
<V2020_SP2_Update_5
Siemens
·
SIMATIC Process Historian 2022
<V2022_SP1_Update_2
Siemens
·
SIMATIC WinCC Runtime Professional V18
<V18_Update_5
Siemens
·
SIMATIC WinCC Runtime Professional V19
<V19_Update_3
Siemens
·
SIMATIC WinCC V7.4
vers:all/*
Siemens
·
SIMATIC WinCC V7.5
<V7.5_SP2_Update_18
Siemens
·
SIMATIC WinCC V8.0
<V8.0_Update_5
Affected Sectors
Chemical, Energy, Food and Agriculture, and Water and Wastewater Systems
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more