Brief

Summary:

As of January 10, 2023, CISA will no longer update ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. The advisory details two vulnerabilities in Siemens SCALANCE XB200/XC200/XP200/XF200/ XR300WG products:

1. Use of Hard-coded Cryptographic Key (CVE-2023-44318): Affected devices use a hardcoded key to obfuscate configuration backups, allowing an authenticated attacker to extract configuration information.
2. Uncontrolled Resource Consumption (CVE-2023-44321): Affected devices do not properly validate input lengths, leading to a denial-of-service condition.

The vulnerabilities affect various Siemens products worldwide, including energy sector devices. Siemens recommends protecting network access to devices, configuring the environment according to industrial security guidelines, and following recommendations in product manuals. CISA recommends users perform an impact analysis, risk assessment, and implement defensive measures such as minimizing network exposure, using firewalls, and secure remote access.

View the full advisory for detailed information on affected products, vulnerability overview, and mitigation recommendations.

As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens’ ProductCERT Security Advisories (CERT Services | Services | Siemens Global).  View CSAF 1. EXECUTIVE SUMMARY CVSS v4 5.1 ATTENTION: Exploitable remotely/low attack

This content is restricted.

Highlights content goes here...

As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens’ ProductCERT Security Advisories (CERT Services | Services | Siemens Global).  View CSAF 1. EXECUTIVE SUMMARY CVSS v4 5.1 ATTENTION: Exploitable remotely/low attack

This content is restricted.

Cybersecurity and Infrastructure Security Agency

Quick Insight
RADA.AI
RADA.AI
Hello! I'm RADA.AI - Regulatory Analysis and Decision Assistance. Your Intelligent guide for compliance and decision-making. How can i assist you today?
Suggested

Form successfully submitted. One of our GRI rep will contact you shortly

Thanking You!

Enter your Email

Enter your registered username/email id.

Enter your Email

Enter your email id below to signup.
Individual Plan
$125 / month OR $1250 / year
Features
Best for: Researchers, Legal professionals, Academics
Enterprise Plan
Contact for Pricing
Features
Best for: Law Firms, Corporations, Government Bodies