This content is restricted.
Brief
Summary
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. A vulnerability has been discovered in Siemens' Spectrum Power 7, with a CVSS v3 score of 7.8, allowing an authenticated local attacker to inject arbitrary code and gain root access. The vulnerability, CVE-2023-44120, affects all versions of Spectrum Power 7 prior to V23Q4. To mitigate this risk, Siemens recommends updating to V23Q4 or later, and CISA recommends implementing defensive measures such as minimizing network exposure, locating control systems behind firewalls, and using more secure remote access methods.
Highlights content goes here...
This content is restricted.
