Brief

Summary:

CISA has released a security advisory regarding Siemens SIMATIC CN 4100 product vulnerabilities. The vulnerabilities, which include Authorization Bypass Through User-Controlled Key, Improper Input Validation, and Use of Default Credentials, have a CVSS v3 score of 9.8, 7.5, and 9.8 respectively. These vulnerabilities could allow an attacker to remotely login as root, cause denial of service, or gain complete control of the device.

Mitigations include updating to version V2.7 or later, applying specific workarounds, and following general security measures such as protecting network access, configuring the environment according to Siemens' operational guidelines, and using secure remote access methods.

CISA recommends organizations perform proper impact analysis and risk assessment, implement recommended cybersecurity strategies, and report suspected malicious activity.

As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens’ ProductCERT Security Advisories (CERT Services | Services | Siemens Global).  View CSAF 1. EXECUTIVE SUMMARY CVSS v3 9.8 ATTENTION: Exploitable remotely/low attack

This content is restricted.

Highlights content goes here...

As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens’ ProductCERT Security Advisories (CERT Services | Services | Siemens Global).  View CSAF 1. EXECUTIVE SUMMARY CVSS v3 9.8 ATTENTION: Exploitable remotely/low attack

This content is restricted.

Cybersecurity and Infrastructure Security Agency

Quick Insight
RADA.AI
RADA.AI
Hello! I'm RADA.AI - Regulatory Analysis and Decision Assistance. Your Intelligent guide for compliance and decision-making. How can i assist you today?
Suggested

Form successfully submitted. One of our GRI rep will contact you shortly

Thanking You!

Enter your Email

Enter your registered username/email id.

Enter your Email

Enter your email id below to signup.
Individual Plan
$125 / month OR $1250 / year
Features
Best for: Researchers, Legal professionals, Academics
Enterprise Plan
Contact for Pricing
Features
Best for: Law Firms, Corporations, Government Bodies