Siemens Alert
2720Warning Date
Severity Level
Warning Number
Target Sector
11 April, 2023
● Critical
2023-5537
All
Siemens has released security updates to address multiple vulnerabilities in the following products:
- JT Open
- JT Utilities
- JT2Go
- Teamcenter Visualization
- CP-8031 MASTER MODULE (6MF2803-1AA00)
- CP-8050 MASTER MODULE (6MF2805-0AA00)
- SIPROTEC 5
- TIA Portal
An attacker could exploit these vulnerabilities and achieve the following:
- Command Injection
- Denial of Service (DoS)
- Memory Corruption
- Unauthenticated Remote Code Execution
- Path Traversal
The CERT team encourages users to update affected products and review Siemens security advisory:
- https://cert-portal.siemens.com/productcert/html/ssa-642810.html
- https://cert-portal.siemens.com/productcert/html/ssa-629917.html
- https://cert-portal.siemens.com/productcert/html/ssa-472454.html
- https://cert-portal.siemens.com/productcert/html/ssa-322980.html
- https://cert-portal.siemens.com/productcert/html/ssa-116924.html