VDB
ICSA-21-159-11
ICSA-21-159-11
PUBLISHED
CVSS 9.800000190734863 CRITICAL
All versions of the SIMATIC CP 443-1 OPC UA contain multiple vulnerabilities in the underlying third party component NTP. Siemens recommends specific countermeasures for products where updates are not, or not yet available.
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SIMATIC CP 443-1 OPC UA (6GK7443-1UX00-0XE0) |
Timeline
- Jun 8, 2021 CVE Published
- May 6, 2025 CVE Updated
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-211752.pdf advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-21-159-11 advisory
- https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf url
- https://www.cisa.gov/topics/industrial-control-systems url
- https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf url
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2021/icsa-21-159-11.json advisory
- https://cert-portal.siemens.com/productcert/csaf/ssa-211752.json advisory
- https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B url
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices url
- https://cert-portal.siemens.com/productcert/txt/ssa-211752.txt advisory
- https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01 url