Your review has been sent successfully

Siemens Updates

2546
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

9 December, 2020

● Critical

2020-2168

All

Description:

Siemens has released security updates to address several vulnerabilities in the following products:

  • KTP900F All versions < V16 Update 3
  • LOGO! 8 BM (incl. SIPLUS variants) All versions < V8.3
  • LOGO! Soft Comfort All versions < V8.3
  • SENTRON PAC3200 All versions < V2.4.5
  • SENTRON PAC4200 All versions < V2.0.1
  • SICAM A8000 CP-8000 All versions < V16
  • SICAM A8000 CP-8021 All versions < V16
  • SICAM A8000 CP-8022 All versions < V16
  • SIMATIC ET 200SP Open Controller (incl. SIPLUS variants) V20.8
  • SIMATIC HMI Comfort Outdoor Panels 7" & 15" (incl. SIPLUS variants) All versions < V16 Update 3
  • SIMATIC HMI Comfort Panels 4" - 22" (incl. SIPLUS variants) All versions < V16 Update 3
  • SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and
  • SIMATIC ITC1500 V3.1 All versions
  • SIMATIC ITC1500 V3.1 PRO All versions
  • SIMATIC ITC1900 V3.1 All versions
  • SIMATIC ITC1900 V3.1 PRO All versions
  • SIMATIC ITC2200 V3.1 All versions
  • SIMATIC ITC2200 V3.1 PRO All versions
  • SIMATIC S7-1500 Software Controller V20.8
  • SIMATIC WinCC Runtime Advanced All versions < V16 Update 3
  • SIMATIC WinCC Runtime Professional All versions < V16 Update 3
  • SIRIUS 3RW5 communication module Modbus TCP All versions
  • XHQ All Versions < 6.1

Threats:

Attacker could exploit these vulnerabilities by doing the following:

  • Sensitive information disclosure
  • Code injection
  • Cross-site request forgery (CSRF)
  • Denial of service attack (DoS)
  • Authentication bypass
  • Buffer overflow

Best practice and Recommendations:

The CERT team encourages users to review Siemens security advisory and apply the necessary updates:

Last updated at 9 December, 2020

Rate the content

rate-icon
up icon