PT-2019-4317 · Siemens · Simatic S7-1200 Cpu+1
Published
2019-11-12
·
Updated
2020-10-09
·
CVE-2019-13945
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SIMATIC S7-1200 CPU family (incl. SIPLUS variants) versions prior to V4.x
SIMATIC S7-1200 CPU family V4.x (incl. SIPLUS variants) versions with Function State (FS) < 11
SIMATIC S7-200 SMART CPU CR20s (6ES7 288-1CR20-0AA1) versions <= V2.3.0 and Function State (FS) <= 3
SIMATIC S7-200 SMART CPU CR30s (6ES7 288-1CR30-0AA1) versions <= V2.3.0 and Function State (FS) <= 3
SIMATIC S7-200 SMART CPU CR40 (6ES7 288-1CR40-0AA0) versions <= V2.2.2 and Function State (FS) <= 8
SIMATIC S7-200 SMART CPU CR40s (6ES7 288-1CR40-0AA1) versions <= V2.3.0 and Function State (FS) <= 3
SIMATIC S7-200 SMART CPU CR60 (6ES7 288-1CR60-0AA0) versions <= V2.2.2 and Function State (FS) <= 10
SIMATIC S7-200 SMART CPU CR60s (6ES7 288-1CR60-0AA1) versions <= V2.3.0 and Function State (FS) <= 3
SIMATIC S7-200 SMART CPU SR20 (6ES7 288-1SR20-0AA0) versions <= V2.5.0 and Function State (FS) <= 11
SIMATIC S7-200 SMART CPU SR30 (6ES7 288-1SR30-0AA0) versions <= V2.5.0 and Function State (FS) <= 10
SIMATIC S7-200 SMART CPU SR40 (6ES7 288-1SR40-0AA0) versions <= V2.5.0 and Function State (FS) <= 10
SIMATIC S7-200 SMART CPU SR60 (6ES7 288-1SR60-0AA0) versions <= V2.5.0 and Function State (FS) <= 12
SIMATIC S7-200 SMART CPU ST20 (6ES7 288-1ST20-0AA0) versions <= V2.5.0 and Function State (FS) <= 9
SIMATIC S7-200 SMART CPU ST30 (6ES7 288-1ST30-0AA0) versions <= V2.5.0 and Function State (FS) <= 9
SIMATIC S7-200 SMART CPU ST40 (6ES7 288-1ST40-0AA0) versions <= V2.5.0 and Function State (FS) <= 8
SIMATIC S7-200 SMART CPU ST60 (6ES7 288-1ST60-0AA0) versions <= V2.5.0 and Function State (FS) <= 8
Description
The issue is related to an access mode used during manufacturing that allows additional diagnostic functionality. This could be exploited by an attacker with physical access to the UART interface during the boot process, potentially allowing them to gain extended diagnostic information.
Recommendations
For SIMATIC S7-1200 CPU family (incl. SIPLUS variants) versions prior to V4.x, update to version V4.x or later with Function State (FS) 11 or higher.
For SIMATIC S7-1200 CPU family V4.x (incl. SIPLUS variants) versions with Function State (FS) < 11, update the Function State (FS) to 11 or higher.
For SIMATIC S7-200 SMART CPU CR20s (6ES7 288-1CR20-0AA1) versions <= V2.3.0 and Function State (FS) <= 3, update to version V2.3.1 or later with Function State (FS) 4 or higher.
For SIMATIC S7-200 SMART CPU CR30s (6ES7 288-1CR30-0AA1) versions <= V2.3.0 and Function State (FS) <= 3, update to version V2.3.1 or later with Function State (FS) 4 or higher.
For SIMATIC S7-200 SMART CPU CR40 (6ES7 288-1CR40-0AA0) versions <= V2.2.2 and Function State (FS) <= 8, update to version V2.2.3 or later with Function State (FS) 9 or higher.
For SIMATIC S7-200 SMART CPU CR40s (6ES7 288-1CR40-0AA1) versions <= V2.3.0 and Function State (FS) <= 3, update to version V2.3.1 or later with Function State (FS) 4 or higher.
For SIMATIC S7-200 SMART CPU CR60 (6ES7 288-1CR60-0AA0) versions <= V2.2.2 and Function State (FS) <= 10, update to version V2.2.3 or later with Function State (FS) 11 or higher.
For SIMATIC S7-200 SMART CPU CR60s (6ES7 288-1CR60-0AA1) versions <= V2.3.0 and Function State (FS) <= 3, update to version V2.3.1 or later with Function State (FS) 4 or higher.
For SIMATIC S7-200 SMART CPU SR20 (6ES7 288-1SR20-0AA0) versions <= V2.5.0 and Function State (FS) <= 11, update to version V2.5.1 or later with Function State (FS) 12 or higher.
For SIMATIC S7-200 SMART CPU SR30 (6ES7 288-1SR30-0AA0) versions <= V2.5.0 and Function State (FS) <= 10, update to version V2.5.1 or later with Function State (FS) 11 or higher.
For SIMATIC S7-200 SMART CPU SR40 (6ES7 288-1SR40-0AA0) versions <= V2.5.0 and Function State (FS) <= 10, update to version V2.5.1 or later with Function State (FS) 11 or higher.
For SIMATIC S7-200 SMART CPU SR60 (6ES7 288-1SR60-0AA0) versions <= V2.5.0 and Function State (FS) <= 12, update to version V2.5.1 or later with Function State (FS) 13 or higher.
For SIMATIC S7-200 SMART CPU ST20 (6ES7 288-1ST20-0AA0) versions <= V2.5.0 and Function State (FS) <= 9, update to version V2.5.1 or later with Function State (FS) 10 or higher.
For SIMATIC S7-200 SMART CPU ST30 (6ES7 288-1ST30-0AA0) versions <= V2.5.0 and Function State (FS) <= 9, update to version V2.5.1 or later with Function State (FS) 10 or higher.
For SIMATIC S7-200 SMART CPU ST40 (6ES7 288-1ST40-0AA0) versions <= V2.5.0 and Function State (FS) <= 8, update to version V2.5.1 or later with Function State (FS) 9 or higher.
For SIMATIC S7-200 SMART CPU ST60 (6ES7 288-1ST60-0AA0) versions <= V2.5.0 and Function State (FS) <= 8, update to version V2.5.1 or later with Function State (FS) 9 or higher.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Simatic S7-1200 Cpu
Simatic S7-200 Smart Cpu