VDB

ICSA-19-351-02

ICSA-19-351-02 PUBLISHED CVSS 7.5 HIGH

SPPA-T3000 Application Server and MS3000 Migration Server are affected by multiple vulnerabilities. Some of the vulnerabilities can allow an attacker to execute arbitrary code on the server. Exploitation of the vulnerabilities described in this advisory requires access to either Application- or Automation Highway. Both highways should not be exposed if the environment has been set up according to the recommended system configuration in the SPPA-T3000 security manual. In this case Siemens Energy considers the environmental score as CR:L/IR:L/AR:H/MAV:A for vulnerabilities related to the Application Server and CR:L/IR:L/AR:M/MAV:A for vulnerabilities related to the Migration Server. Siemens Energy provides a service pack to fix vulnerabilities on the Application Server and recommends configurations to mitigate the vulnerabilities in the Migration Server. Detailed information will be available for SPPA-T3000 customers in the Siemens Energy Customer Portal (https://cep.siemens-energy.com/).

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C

Affected Products

VendorProductVersions
SPPA-T3000 Application Server
SPPA-T3000 MS3000 Migration Server

Timeline

  • Dec 10, 2019 CVE Published
  • May 6, 2025 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›