SSA-216014 PUBLISHED CVSS 8.199999809265137 HIGH

The affected devices have insufficient protection mechanism for the EFI(Extensible Firmware Interface) variables stored on the device. This could allow an authenticated attacker to alter the secure boot configuration without proper authorization by directly communicate with the flash controller.

Risk Scores

CVSS v3.1
8.199999809265137
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
SiemensSIMATIC IPC RC-543B
SiemensSIMATIC IPC477E
SiemensSIMATIC IPC277G PRO
SiemensSIMATIC IPC277E
SiemensSIMATIC IPC847E
SiemensSIMATIC IPC127E
SiemensSIMATIC IPC627E
SiemensSIMATIC IPC227E
SiemensSIMATIC IPC277G
SiemensSIMATIC IPC3000 SMART V3
SiemensSIMATIC Field PG M6
SiemensSIMATIC IPC427E
SiemensSIMATIC IPC327G
SiemensSIMATIC ITP1000
SiemensSIMATIC IPC BX-39A
SiemensSIMATIC Field PG M5
SiemensSIMATIC IPC RW-543A
SiemensSIMATIC IPC BX-59A
SiemensSIMATIC IPC PX-32A
SiemensSIMATIC IPC RC-543A

…and 12 more

Timeline

References

Open in Interactive Console →