Siemens Alert
2892Warning Date
Severity Level
Warning Number
Target Sector
10 February, 2022
● Critical
2022-4363
All
Description:
Siemens has released security alerts to address several vulnerabilities in the following products:
- JT2Go
- RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2)
- RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2)
- RUGGEDCOM ROX MX5000
- RUGGEDCOM ROX MX5000RE
- RUGGEDCOM ROX RX1400
- RUGGEDCOM ROX RX1500
- RUGGEDCOM ROX RX1501
- RUGGEDCOM ROX RX1510
- RUGGEDCOM ROX RX1511
- RUGGEDCOM ROX RX1512
- RUGGEDCOM ROX RX1524
- RUGGEDCOM ROX RX1536
- RUGGEDCOM ROX RX5000
- SCALANCE M804PB (6GK5804-0AP00-2AA2)
- SCALANCE M812-1 ADSL-Router (Annex A) (6GK5812-1AA00-2AA2)
- SCALANCE M812-1 ADSL-Router (Annex B) (6GK5812-1BA00-2AA2)
- SCALANCE M816-1 ADSL-Router (Annex A) (6GK5816-1AA00-2AA2)
- SCALANCE M816-1 ADSL-Router (Annex B) (6GK5816-1BA00-2AA2)
- SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2)
- SCALANCE M874-2 (6GK5874-2AA00-2AA2)
- SCALANCE M874-3 (6GK5874-3AA00-2AA2)
- SCALANCE M876-3 (6GK5876-3AA02-2BA2)
- SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2)
- SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2)
- SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2)
- SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1)
- SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1)
- SCALANCE S615 (6GK5615-0AA00-2AA2)
- SCALANCE SC622-2C (6GK5622-2GS00-2AC2)
- SCALANCE SC632-2C (6GK5632-2GS00-2AC2)
- SCALANCE SC636-2C (6GK5636-2GS00-2AC2)
- SCALANCE SC642-2C (6GK5642-2GS00-2AC2)
- SCALANCE SC646-2C (6GK5646-2GS00-2AC2)
- SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0)
- SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0)
- SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0)
- SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0)
- SCALANCE W1788-2 M12 (6GK5788-2GY01-0AA0)
- SCALANCE W1788-2IA M12 (6GK5788-2HY01-0AA0)
- SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0)
- SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0)
- SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0)
- SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0)
- SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0)
- SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0)
- SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6)
- SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0)
- SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6)
- SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0)
- SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0)
- SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0)
- SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0)
- SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0)
- SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0)
- SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0)
- SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0)
- SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0)
- SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0)
- SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0)
- SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6)
- SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0)
- SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0)
- SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6)
- SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0)
- SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0)
- SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0)
- SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0)
- SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0)
- SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0)
- SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0)
- SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0)
- SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0)
- SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0)
- SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0)
- SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0)
- SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0)
- SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0)
- SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0)
- SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0)
- SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0)
- SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0)
- SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0)
- SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0)
- SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0)
- SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0)
- SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0)
- SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0)
- SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0)
- SCALANCE WAM766-1 (6GK5766-1GE00-7DA0)
- SCALANCE WAM766-1 (6GK5766-1GE00-7DB0)
- SCALANCE WAM766-1 6GHz (6GK5766-1JE00-7DA0)
- SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0)
- SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TB0)
- SCALANCE WAM766-1 EEC 6GHz (6GK5766-1JE00-7TA0)
- SCALANCE WUM766-1 (6GK5766-1GE00-3DA0)
- SCALANCE WUM766-1 (6GK5766-1GE00-3DB0)
- SCALANCE WUM766-1 6GHz (6GK5766-1JE00-3DA0)
- SCALANCE X200-4 P IRT
- SCALANCE X201-3P IRT
- SCALANCE X201-3P IRT PRO
- SCALANCE X202-2 IRT
- SCALANCE X202-2P IRT (incl. SIPLUS NET variant)
- SCALANCE X202-2P IRT PRO
- SCALANCE X204 IRT
- SCALANCE X204 IRT PRO
- SCALANCE X204-2 (6GK5204-2BB10-2AA3)
- SCALANCE X204-2FM (6GK5204-2BB11-2AA3)
- SCALANCE X204-2LD (6GK5204-2BC10-2AA3)
- SCALANCE X204-2LD TS (6GK5204-2BC10-2CA2)
- SCALANCE X204-2TS (6GK5204-2BB10-2CA2)
- SCALANCE X206-1 (6GK5206-1BB10-2AA3)
- SCALANCE X206-1LD (6GK5206-1BC10-2AA3)
- SCALANCE X208 (6GK5208-0BA10-2AA3)
- SCALANCE X208PRO (6GK5208-0HA10-2AA6)
- SCALANCE X212-2 (6GK5212-2BB00-2AA3)
- SCALANCE X212-2LD (6GK5212-2BC00-2AA3)
- SCALANCE X216 (6GK5216-0BA00-2AA3)
- SCALANCE X224 (6GK5224-0BA00-2AA3)
- SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants)
- SCALANCE X302-7 EEC (230V) (6GK5302-7GD00-3EA3)
- SCALANCE X302-7 EEC (230V, coated) (6GK5302-7GD00-3GA3)
- SCALANCE X302-7 EEC (24V) (6GK5302-7GD00-1EA3)
- SCALANCE X302-7 EEC (24V, coated) (6GK5302-7GD00-1GA3)
- SCALANCE X302-7 EEC (2x 230V) (6GK5302-7GD00-4EA3)
- SCALANCE X302-7 EEC (2x 230V, coated) (6GK5302-7GD00-4GA3)
- SCALANCE X302-7 EEC (2x 24V) (6GK5302-7GD00-2EA3)
- SCALANCE X302-7 EEC (2x 24V, coated) (6GK5302-7GD00-2GA3)
- SCALANCE X304-2FE (6GK5304-2BD00-2AA3)
- SCALANCE X306-1LD FE (6GK5306-1BF00-2AA3)
- SCALANCE X307-2 EEC (230V) (6GK5307-2FD00-3EA3)
- SCALANCE X307-2 EEC (230V, coated) (6GK5307-2FD00-3GA3)
- SCALANCE X307-2 EEC (24V) (6GK5307-2FD00-1EA3)
- SCALANCE X307-2 EEC (24V, coated) (6GK5307-2FD00-1GA3)
- SCALANCE X307-2 EEC (2x 230V) (6GK5307-2FD00-4EA3)
- SCALANCE X307-2 EEC (2x 230V, coated) (6GK5307-2FD00-4GA3)
- SCALANCE X307-2 EEC (2x 24V) (6GK5307-2FD00-2EA3)
- SCALANCE X307-2 EEC (2x 24V, coated) (6GK5307-2FD00-2GA3)
- SCALANCE X307-3 (6GK5307-3BL00-2AA3)
- SCALANCE X307-3 (6GK5307-3BL10-2AA3)
- SCALANCE X307-3LD (6GK5307-3BM00-2AA3)
- SCALANCE X307-3LD (6GK5307-3BM10-2AA3)
- SCALANCE X308-2 (6GK5308-2FL00-2AA3)
- SCALANCE X308-2 (6GK5308-2FL10-2AA3)
- SCALANCE X308-2LD (6GK5308-2FM00-2AA3)
- SCALANCE X308-2LD (6GK5308-2FM10-2AA3)
- SCALANCE X308-2LH (6GK5308-2FN00-2AA3)
- SCALANCE X308-2LH+ (6GK5308-2FP00-2AA3)
- SCALANCE X308-2LH+ (6GK5308-2FP10-2AA3)
- SCALANCE X308-2M (6GK5308-2GG00-2AA2)
- SCALANCE X308-2M (6GK5308-2GG10-2AA2)
- SCALANCE X308-2M PoE (6GK5308-2QG10-2AA2)
- SCALANCE X308-2M TS (6GK5308-2GG00-2CA2)
- SCALANCE X308-2M TS (6GK5308-2GG10-2CA2)
- SCALANCE X310 (6GK5310-0FA00-2AA3)
- SCALANCE X310 (6GK5310-0FA10-2AA3)
- SCALANCE X310FE (6GK5310-0BA10-2AA3)
- SCALANCE X320-1 FE (6GK5320-1BD00-2AA3)
- SCALANCE X320-1-2LD FE (6GK5320-3BF00-2AA3)
- SCALANCE X408-2 (6GK5408-2FD00-2AA2)
- SCALANCE XF201-3P IRT
- SCALANCE XF202-2P IRT
- SCALANCE XF204 (6GK5204-0BA00-2AF2)
- SCALANCE XF204 IRT
- SCALANCE XF204-2 (6GK5204-2BC00-2AF2)
- SCALANCE XF204-2BA IRT
- SCALANCE XF206-1 (6GK5206-1BC00-2AF2)
- SCALANCE XF208 (6GK5208-0BA00-2AF2)
- SCALANCE XR324-12M (230V, ports on front) (6GK5324-0GG00-3AR2)
- SCALANCE XR324-12M (230V, ports on front) (6GK5324-0GG10-3AR2)
- SCALANCE XR324-12M (230V, ports on rear) (6GK5324-0GG00-3HR2)
- SCALANCE XR324-12M (230V, ports on rear) (6GK5324-0GG10-3HR2)
- SCALANCE XR324-12M (24V, ports on front) (6GK5324-0GG00-1AR2)
- SCALANCE XR324-12M (24V, ports on front) (6GK5324-0GG10-1AR2)
- SCALANCE XR324-12M (24V, ports on rear) (6GK5324-0GG00-1HR2)
- SCALANCE XR324-12M (24V, ports on rear) (6GK5324-0GG10-1HR2)
- SCALANCE XR324-12M TS (24V) (6GK5324-0GG00-1CR2)
- SCALANCE XR324-12M TS (24V) (6GK5324-0GG10-1CR2)
- SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front) (6GK5324-4GG00-3ER2)
- SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front) (6GK5324-4GG10-3ER2)
- SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG00-3JR2)
- SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG10-3JR2)
- SCALANCE XR324-4M EEC (24V, ports on front) (6GK5324-4GG00-1ER2)
- SCALANCE XR324-4M EEC (24V, ports on front) (6GK5324-4GG10-1ER2)
- SCALANCE XR324-4M EEC (24V, ports on rear) (6GK5324-4GG00-1JR2)
- SCALANCE XR324-4M EEC (24V, ports on rear) (6GK5324-4GG10-1JR2)
- SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front) (6GK5324-4GG00-4ER2)
- SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front) (6GK5324-4GG10-4ER2)
- SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG00-4JR2)
- SICAM TOOLBOX II
- SIMATIC CP 1242-7 GPRS V2 (6GK7242-7KX31-0XE0)
- SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0)
- SIMATIC CP 1243-7 LTE EU (6GK7243-7KX30-0XE0)
- SIMATIC CP 1243-7 LTE US (6GK7243-7SX30-0XE0)
- SIMATIC CP 1243-8 IRC (6GK7243-8RX30-0XE0)
- SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0)
- SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0)
- SIMATIC CP 1543-1 (6GK7543-1AX00-0XE0)
- SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0)
- SIMATIC CP 1545-1 (6GK7545-1GX00-0XE0)
- SIMATIC Drive Controller family
- SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants)
- SIMATIC PCS neo
- SIMATIC Process Historian OPC UA Server
- SIMATIC S7-1200 CPU family (incl. SIPLUS variants)
- SIMATIC S7-1200 CPU family (incl. SIPLUS variants)
- SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS
- SIMATIC S7-1500 Software Controller
- SIMATIC S7-PLCSIM Advanced
- Simcenter Femap V2020.2
- Simcenter Femap V2021.1
- SINEC NMS
- SINEMA Remote Connect Server
- SINEMA Remote Connect Server (6GK1720-1AH01-0BV0)
- SINEMA Server V14
- SINUMERIK Operate
- SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0)
- SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0)
- SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0)
- SIPLUS NET CP 1543-1 (6AG1543-1AX00-2XE0)
- SIPLUS S7-1200 CP 1243-1 (6AG1243-1BX30-2AX0)
- SIPLUS S7-1200 CP 1243-1 RAIL (6AG2243-1BX30-1XE0)
- Solid Edge SE2021
- Solid Edge SE2022
- Teamcenter Visualization V12.4
- Teamcenter Visualization V13.1
- Teamcenter Visualization V13.2
- Teamcenter Visualization V13.3
- TIA Administrator
- TIM 1531 IRC (incl. SIPLUS NET variants)
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Execute arbitrary code remotely
Best practice and Recommendations:
The CERT team encourages users to review Amazon security advisory:
- https://cert-portal.siemens.com/productcert/txt/ssa-914168.txt
- https://cert-portal.siemens.com/productcert/txt/ssa-838121.txt
- https://cert-portal.siemens.com/productcert/txt/ssa-831168.txt
- https://cert-portal.siemens.com/productcert/txt/ssa-669737.txt
- https://cert-portal.siemens.com/productcert/txt/ssa-654775.txt
- https://cert-portal.siemens.com/productcert/txt/ssa-609880.txt
- https://cert-portal.siemens.com/productcert/txt/ssa-539476.txt
- https://cert-portal.siemens.com/productcert/txt/ssa-301589.txt
- https://cert-portal.siemens.com/productcert/txt/ssa-244969.txt