Number: AV20-474
Date: 15 December 2020
On 8 December 2020 Siemens published Security Advisories to address vulnerabilities in the following products:
- SICAM A8000 CP-8000, CP-8021 and CP-8022 – versions prior to V16
- TightVNC within SIMATIC – multiple products and versions
- LOGO! 8 BM (including SIPLUS variants) and LOGO! Soft Comfort – versions prior to V8.3
- Embedded TCP/IP Stack Vulnerabilities (AMNESIA:33) in:
- SIRIUS 3RW5 Modbus TCP – all versions
- SENTRON PAC3200 – versions prior to V2.4.5
- SENTRON PAC4200 – versions prior to V2.0.1
- SIMATIC ET 200SP Open Controller and S7-1500 Software Controller – versions prior to V21.8
- XHQ Operations Intelligence – versions prior to V6.1
The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates where available.
Siemens Security Advisories
https://new.siemens.com/global/en/products/services/cert.html#SecurityPublications
Note to Readers
The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada’s national authority on cyber security and we lead the government’s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.