The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC CP 343-1 Advanced (incl. SIPLUS variants)
- SIMATIC CP 443-1 Advanced (incl. SIPLUS variants)
- SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants)
- SIMATIC S7-400 PN/DP CPU family (incl. SIPLUS variants)
- Summary
- The integrated web server at port 80/TCP or port 443/TCP of the affected devices could allow remote attackers to perform actions with the permissions of an authenticated user, provided the targeted user has an active session and is induced to trigger the malicious request.
- Remediation
- Update to V3.X.18 or later version
