VDB
ICSA-23-166-12
ICSA-23-166-12
PUBLISHED
CVSS 7.5 HIGH
SINAMICS PERFECT HARMONY GH180 is affected by multiple vulnerabilities in the integrated SCALANCE S615 device, as documented in SSA-419740 ( https://cert-portal.siemens.com/productcert/html/ssa-419740.html). Siemens recommends to update the firmware of the integrated SCALANCE S615 device to the latest version. Siemens recommends specific countermeasures for products where the firmware update is not, or not yet applied. Additional considerations regarding the specific impact of the vulnerabilities to SINAMICS MV products can be found in the chapter "Additional Information".
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SINAMICS PERFECT HARMONY GH180 6SR5 |
Timeline
- Jun 13, 2023 CVE Published
- Jun 14, 2023 CVE Updated
References
- https://www.cisa.gov/topics/industrial-control-systems url
- https://cert-portal.siemens.com/productcert/html/ssa-942865.html advisory
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices url
- https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01 url
- https://cert-portal.siemens.com/productcert/pdf/ssa-942865.pdf advisory
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2023/icsa-23-166-12.json advisory
- https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B url
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-166-12 advisory
- https://cert-portal.siemens.com/productcert/csaf/ssa-942865.json advisory
- https://cert-portal.siemens.com/productcert/txt/ssa-942865.txt advisory
- https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf url
- https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf url