SSA-486936 PUBLISHED CVSS 9.800000190734863 CRITICAL

SIMATIC ET 200SP communication processors (CP 1542SP-1, CP 1542SP-1 IRC and CP 1543SP-1, incl. SIPLUS variants) contain an authentication vulnerability that could allow an unauthenticated remote attacker to access the configuration data. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Risk Scores

CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0)
SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0)
SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0)
SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0)
SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0)
SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0)

Timeline

References

Open in Interactive Console →