Virtual Event Today: CodeSecCon - Learn to Secure Your Software > Join Event
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

Siemens Releases Firmware Updates to Patch SIMATIC Flaws

Siemens has released firmware updates for some of its SIMATIC communications processors and controllers to address several medium-severity vulnerabilities discovered by researchers from various organizations.

Siemens has released firmware updates for some of its SIMATIC communications processors and controllers to address several medium-severity vulnerabilities discovered by researchers from various organizations.

The vendor disclosed the flaws in two advisories published on its website in the past few days. One of the advisories describes a couple of issues affecting SIMATIC S7-300 and S7-400 controllers, and SIMATIC CP 343-1 and CP 443-1 Advanced communication processors. The CP products are used to connect S7 devices to industrial Ethernet systems.

According to Siemens, the affected devices have an integrated web server on port 80/TCP or port 443/TCP, which allows a remote attacker to perform actions with the privileges of an authenticated user. The attack only works if the victim can be convinced to trigger a specially crafted request.

Another vulnerability is related to the web server delivering cookies without the “secure” flag. Browsers are designed to prevent the transmission of a cookie over an unencrypted channel if this flag is set. A similar issue was found recently in SCALANCE M-800 industrial routers and S615 firewalls.

These flaws have been discovered by Inverse Path auditors in collaboration with the Airbus ICT Industrial Security team. Siemens released firmware version 3.0.53 to patch the flaws in CP 343-1 products and provided mitigations for the other affected devices.

The second advisory published by Siemens describes two vulnerabilities affecting SIMATIC CP 1543-1 communications processors, which connect S7-1500 controllers to Ethernet networks. The CP is designed to protect S7-1500 stations against unauthorized access and it includes various security functions, including firewalls, VPNs and support for data encryption protocols.

Advertisement. Scroll to continue reading.

The product has a flaw that allows an attacker with elevated privileges in the TIA Portal on the engineering workstation to obtain privileged access to affected devices. Siemens also warned customers of an issue that can be used to cause a denial-of-service (DoS) condition.

The flaws affect versions of the firmware prior to 2.0.28, which patches the issues. Siemens has credited SOGETI and France’s agence nationale de la sécurité des systèmes d’information (ANSSI) for reporting these security holes.

Related: Siemens Patches Flaws in SIMATIC, License Manager Products

Related: Privilege Escalation Flaw Affects Several Siemens Products

Related: Siemens Patches Flaws in Industrial Automation Products

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Daniel Dubowski has been named Senior Vice President and Chief Information Security Officer at Marriott International.

Allied Universal has named Jordan Avnaim Global Chief Information Security Officer.

Cycode has promoted Seth Robbins to President and Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.