PT-2019-2107 · Siemens · Simatic Hmi Classic Devices+6

Publicado

2019-05-14

·

Atualizado

2019-05-22

·

CVE-2019-6576

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SIMATIC HMI Comfort Panels 4" - 22" versions prior to V15.1 Update 1 SIMATIC HMI Comfort Outdoor Panels 7" & 15" versions prior to V15.1 Update 1 SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 und KTP900F versions prior to V15.1 Update 1 SIMATIC WinCC Runtime Advanced versions prior to V15.1 Update 1 SIMATIC WinCC Runtime Professional versions prior to V15.1 Update 1 SIMATIC WinCC (TIA Portal) versions prior to V15.1 Update 1 SIMATIC HMI Classic Devices (TP/MP/OP/MP Mobile Panel) versions prior to V15.1 Update 1
Description The issue is related to errors in the use of cryptography in the software of SIMATIC devices. An attacker with network access to the affected devices could potentially obtain a TLS session key by observing TLS traffic between a legitimate user and the device. This could impact the confidentiality of the communication between the affected device and a legitimate user. At the time of advisory publication, no public exploitation of the security issue was known.
Recommendations For SIMATIC HMI Comfort Panels 4" - 22" versions prior to V15.1 Update 1, update to V15.1 Update 1 or later. For SIMATIC HMI Comfort Outdoor Panels 7" & 15" versions prior to V15.1 Update 1, update to V15.1 Update 1 or later. For SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 und KTP900F versions prior to V15.1 Update 1, update to V15.1 Update 1 or later. For SIMATIC WinCC Runtime Advanced versions prior to V15.1 Update 1, update to V15.1 Update 1 or later. For SIMATIC WinCC Runtime Professional versions prior to V15.1 Update 1, update to V15.1 Update 1 or later. For SIMATIC WinCC (TIA Portal) versions prior to V15.1 Update 1, update to V15.1 Update 1 or later. For SIMATIC HMI Classic Devices (TP/MP/OP/MP Mobile Panel) versions prior to V15.1 Update 1, update to V15.1 Update 1 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-01863
CVE-2019-6576

Produtos afetados

Simatic Hmi Classic Devices
Simatic Hmi Comfort Outdoor Panels
Simatic Hmi Comfort Panels
Simatic Hmi Ktp Mobile Panels
Simatic Wincc
Simatic Wincc Runtime Advanced
Simatic Wincc Runtime Professional