ICSA-26-015-04
·
Published 2026-02-12
·
View on CISA ICS-CERT ↗
Siemens SIMATIC and SIPLUS products
CVSS 7.5
HIGH
CVEs (1)
Remediations
- Filter the port 102 of the devices to only accepted connections to/from the IP addresses of machines that are trusted e.g. with an external firewall.
- Restrict access to the network where S7 communication messages are exchanged.
- Currently no fix is planned
- Update to V1.3 or later version
- Update to V4.2.2 or later version
- Update to V6.0.0 or later version
- Update to V6.0.1 or later version
Affected Vendors
Siemens
Affected Products (17)
Siemens
·
SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0)
vers:all/*
Siemens
·
SIMATIC ET 200MP IM 155-5 PN HF (6ES7155-5AA00-0AC0)
vers:intdot/>=4.2.0
Siemens
·
SIMATIC ET 200SP IM 155-6 MF HF (6ES7155-6MU00-0CN0)
vers:all/*
Siemens
·
SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS variants)
vers:intdot/<1.3
Siemens
·
SIMATIC ET 200SP IM 155-6 PN R1 (6ES7155-6AU00-0HM0)
vers:intdot/<6.0.1
Siemens
·
SIMATIC ET 200SP IM 155-6 PN/2 HF (6ES7155-6AU01-0CN0)
vers:intdot/>=4.2.0
Siemens
·
SIMATIC ET 200SP IM 155-6 PN/3 HF (6ES7155-6AU30-0CN0)
vers:intdot/<4.2.2
Siemens
·
SIMATIC PN/MF Coupler (6ES7158-3MU10-0XA0)
vers:all/*
Siemens
·
SIMATIC PN/PN Coupler (6ES7158-3AD10-0XA0)
vers:intdot/<6.0.0
Siemens
·
SIPLUS ET 200MP IM 155-5 PN HF (6AG1155-5AA00-2AC0)
vers:intdot/>=4.2.0
Siemens
·
SIPLUS ET 200MP IM 155-5 PN HF (6AG1155-5AA00-7AC0)
vers:intdot/>=4.2.0
Siemens
·
SIPLUS ET 200MP IM 155-5 PN HF T1 RAIL (6AG2155-5AA00-1AC0)
vers:intdot/>=4.2.0
Siemens
·
SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-2CN0)
vers:intdot/>=4.2.0
Siemens
·
SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-7CN0)
vers:intdot/>=4.2.0
Siemens
·
SIPLUS ET 200SP IM 155-6 PN HF T1 RAIL (6AG2155-6AU01-1CN0)
vers:intdot/>=4.2.0
Siemens
·
SIPLUS ET 200SP IM 155-6 PN HF TX RAIL (6AG2155-6AU01-4CN0)
vers:intdot/>=4.2.0
Siemens
·
SIPLUS NET PN/PN Coupler (6AG2158-3AD10-4XA0)
vers:intdot/<6.0.0
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more