PT-2019-4317 · Siemens · Simatic S7-1200 Cpu+1

Publicado

2019-11-12

·

Atualizado

2020-10-09

·

CVE-2019-13945

CVSS v3.1

6.8

Média

VetorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SIMATIC S7-1200 CPU family (incl. SIPLUS variants) versions prior to V4.x SIMATIC S7-1200 CPU family V4.x (incl. SIPLUS variants) versions with Function State (FS) < 11 SIMATIC S7-200 SMART CPU CR20s (6ES7 288-1CR20-0AA1) versions <= V2.3.0 and Function State (FS) <= 3 SIMATIC S7-200 SMART CPU CR30s (6ES7 288-1CR30-0AA1) versions <= V2.3.0 and Function State (FS) <= 3 SIMATIC S7-200 SMART CPU CR40 (6ES7 288-1CR40-0AA0) versions <= V2.2.2 and Function State (FS) <= 8 SIMATIC S7-200 SMART CPU CR40s (6ES7 288-1CR40-0AA1) versions <= V2.3.0 and Function State (FS) <= 3 SIMATIC S7-200 SMART CPU CR60 (6ES7 288-1CR60-0AA0) versions <= V2.2.2 and Function State (FS) <= 10 SIMATIC S7-200 SMART CPU CR60s (6ES7 288-1CR60-0AA1) versions <= V2.3.0 and Function State (FS) <= 3 SIMATIC S7-200 SMART CPU SR20 (6ES7 288-1SR20-0AA0) versions <= V2.5.0 and Function State (FS) <= 11 SIMATIC S7-200 SMART CPU SR30 (6ES7 288-1SR30-0AA0) versions <= V2.5.0 and Function State (FS) <= 10 SIMATIC S7-200 SMART CPU SR40 (6ES7 288-1SR40-0AA0) versions <= V2.5.0 and Function State (FS) <= 10 SIMATIC S7-200 SMART CPU SR60 (6ES7 288-1SR60-0AA0) versions <= V2.5.0 and Function State (FS) <= 12 SIMATIC S7-200 SMART CPU ST20 (6ES7 288-1ST20-0AA0) versions <= V2.5.0 and Function State (FS) <= 9 SIMATIC S7-200 SMART CPU ST30 (6ES7 288-1ST30-0AA0) versions <= V2.5.0 and Function State (FS) <= 9 SIMATIC S7-200 SMART CPU ST40 (6ES7 288-1ST40-0AA0) versions <= V2.5.0 and Function State (FS) <= 8 SIMATIC S7-200 SMART CPU ST60 (6ES7 288-1ST60-0AA0) versions <= V2.5.0 and Function State (FS) <= 8
Description The issue is related to an access mode used during manufacturing that allows additional diagnostic functionality. This could be exploited by an attacker with physical access to the UART interface during the boot process, potentially allowing them to gain extended diagnostic information.
Recommendations For SIMATIC S7-1200 CPU family (incl. SIPLUS variants) versions prior to V4.x, update to version V4.x or later with Function State (FS) 11 or higher. For SIMATIC S7-1200 CPU family V4.x (incl. SIPLUS variants) versions with Function State (FS) < 11, update the Function State (FS) to 11 or higher. For SIMATIC S7-200 SMART CPU CR20s (6ES7 288-1CR20-0AA1) versions <= V2.3.0 and Function State (FS) <= 3, update to version V2.3.1 or later with Function State (FS) 4 or higher. For SIMATIC S7-200 SMART CPU CR30s (6ES7 288-1CR30-0AA1) versions <= V2.3.0 and Function State (FS) <= 3, update to version V2.3.1 or later with Function State (FS) 4 or higher. For SIMATIC S7-200 SMART CPU CR40 (6ES7 288-1CR40-0AA0) versions <= V2.2.2 and Function State (FS) <= 8, update to version V2.2.3 or later with Function State (FS) 9 or higher. For SIMATIC S7-200 SMART CPU CR40s (6ES7 288-1CR40-0AA1) versions <= V2.3.0 and Function State (FS) <= 3, update to version V2.3.1 or later with Function State (FS) 4 or higher. For SIMATIC S7-200 SMART CPU CR60 (6ES7 288-1CR60-0AA0) versions <= V2.2.2 and Function State (FS) <= 10, update to version V2.2.3 or later with Function State (FS) 11 or higher. For SIMATIC S7-200 SMART CPU CR60s (6ES7 288-1CR60-0AA1) versions <= V2.3.0 and Function State (FS) <= 3, update to version V2.3.1 or later with Function State (FS) 4 or higher. For SIMATIC S7-200 SMART CPU SR20 (6ES7 288-1SR20-0AA0) versions <= V2.5.0 and Function State (FS) <= 11, update to version V2.5.1 or later with Function State (FS) 12 or higher. For SIMATIC S7-200 SMART CPU SR30 (6ES7 288-1SR30-0AA0) versions <= V2.5.0 and Function State (FS) <= 10, update to version V2.5.1 or later with Function State (FS) 11 or higher. For SIMATIC S7-200 SMART CPU SR40 (6ES7 288-1SR40-0AA0) versions <= V2.5.0 and Function State (FS) <= 10, update to version V2.5.1 or later with Function State (FS) 11 or higher. For SIMATIC S7-200 SMART CPU SR60 (6ES7 288-1SR60-0AA0) versions <= V2.5.0 and Function State (FS) <= 12, update to version V2.5.1 or later with Function State (FS) 13 or higher. For SIMATIC S7-200 SMART CPU ST20 (6ES7 288-1ST20-0AA0) versions <= V2.5.0 and Function State (FS) <= 9, update to version V2.5.1 or later with Function State (FS) 10 or higher. For SIMATIC S7-200 SMART CPU ST30 (6ES7 288-1ST30-0AA0) versions <= V2.5.0 and Function State (FS) <= 9, update to version V2.5.1 or later with Function State (FS) 10 or higher. For SIMATIC S7-200 SMART CPU ST40 (6ES7 288-1ST40-0AA0) versions <= V2.5.0 and Function State (FS) <= 8, update to version V2.5.1 or later with Function State (FS) 9 or higher. For SIMATIC S7-200 SMART CPU ST60 (6ES7 288-1ST60-0AA0) versions <= V2.5.0 and Function State (FS) <= 8, update to version V2.5.1 or later with Function State (FS) 9 or higher.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-00032
CVE-2019-13945

Produtos afetados

Simatic S7-1200 Cpu
Simatic S7-200 Smart Cpu