Yesterday, CISA’s NCCIC-ICS updated 11 control system security advisories for products from Siemens. There was also a 7th advisory published yesterday which I missed because it was buried in the list of updates.
Solid Edge Advisory
This advisory describes five vulnerabilities in the Siemens Solid Edge, JT2Go, and Teamcenter Visualization products. These are third-party vulnerabilities. The vulnerabilities were reported by Mat Powell of the Zero Day Initiative. Siemens has new versions for some of the affected products. There is no indication that Powell was provided an opportunity to verify the efficacy of the fix.
The five reported vulnerabilities are:
Improper restriction of operations within the bounds of a memory buffer - CVE-2021-38405 (Datalogic APDFL),
Out-of-bounds write (2) - CVE-2021-43336 (Open Design Aliance) and CVE-2021-44016 (pconlife ?),
Heap-based buffer overflow - CVE-2021-44000 (pconlife ?), and
Out-of-bounds read - CVE-2021-44018 (pconlife ?)
NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to lead the application to crash or potentially lead to arbitrary code execution.
PROFINET Update
This update provides additional information on an advisory that was originally published on May 9th, 2017 and most recently updated on October 14th, 2021. The new information included announcing that no remediation is planned for ET200 devices.
NOTE: The Siemens Advisory also announced that no remediation was planned for SIMATIC CP 443-1 OPC UA.
SCALANCE X Update #1
This update provides additional information on an advisory that was originally published on August 13th, 2019 and most recently updated on September 14th, 2021. The new information includes adding the SCALANCE X204RNA products to the list of affected products.
NOTE: The Siemens Advisory also announces that there is no fix planned for the newly added SCALANCE X204RNA products.
SCALANCE X Update #2
This update provides additional information on an advisory that was originally published on January 14th, 2020. The new information includes adding the SCALANCE X204RNA products to the list of affected products.
NOTE: The Siemens Advisory also announces that there is no fix planned for the newly added SCALANCE X204RNA products.
Industrial Products Update #1
This update provides additional information on an advisory that was originally published on February 11th, 2020 and most recently updated on April 13th, 2021. The new information includes adding:
SIMATIC CP 443-1 (6GK7443-1EX30-0XE0),
SIMATIC CP 1623 (6GK1162-3AA00),
SIMATIC CP 1626 (6GK1162-6AA01),
SIMATIC CP 1628(6GK1162-8AA00),
SIPLUS NET CP 343-1 Advanced (6AG1343-1GX31-4XE0),
SIPLUS NET CP 443-1 (6AG1443-1EX30-4XE0), and
SIPLUS NET CP 443-1 Advanced (6AG1443-1GX30-4XE0)
NOTE 1: The Siemens Advisory also notes that no remediation is planned for SIMATIC CP 443-1 OPC UA, SIMATIC CP 343-1 Advanced, and SIPLUS NET CP 343-1 Advanced.
NOTE 2: NCCIC-ICS incorrectly reports that the previous update was February 9th, 2021.
Industrial Products Update #2
This update provides additional information on an advisory that was originally published on August 10th, 2021. The new information includes adding SINUMERIK ONE NCU 1740 to the list of affected products.
SCALANCE Update
This update provides additional information on an advisory that was originally published on April 14th, 2020 and most recently updated on September 14th, 2021. The new information includes adding SIMATIC CP 442-1 RNA and SIMATIC CP 443-1 RNA to the list of affected products.
TCP/IP Stack Update
This update provides additional information on an advisory that was originally published on March 9th, 2021 and most recently updated on August 10th, 2021. The new information includes adding mitigation measures for SENTRON PAC2200.
LOGO! Update
This update provides additional information on an advisory that was originally published on September 14th, 2021. The new information includes expanding the SIMATIC RTU 3000 family to specific individual affected products.
SIMATIC Update
This update provides additional information on an advisory that was originally published on November 11th, 2021. The new information includes:
Adding a solution for SIMATIC WinCC V16 and V17, and
Adjusting solution for SIMATIC PCS 7 V9.1
Healthineers Update
This update provides additional information on an advisory that was originally published on December 16th, 2021. The new information includes adding CVE-2021-45465, write-what-where condition.
COMOS Update
This update provides additional information on an advisory that was originally published on January 13th, 2022. The new information includes:
Adding CVE-2021-37194 – unrestricted upload of file with dangerous type,
Updating affected version information, and
Adding mitigation measures for version 10.3
NOTE: The Siemens Advisory also notes that there are no plans to develop mitigation measures for versions 10.2 or 10.3.3.2.14 or later.
Other Siemens Updates
Siemens published 31 additional advisories on Tuesday. I will cover those this weekend.