Canadian Centre for Cyber Security · English · AV18-045[Control systems] Siemens SIMATIC, SIMOTION and SINUMERIK VulnerabilitiesMultiple vulnerabilities were identified in Siemens SIMATIC, SIMOTION and SINUMERIK products. Exploitation of these vulnerabilities could allow a user to remotely execute arbitrary code, elevate privileges, gain unauthenticated access to sensitive data, abuse cryptographic functions and cause a denial of service under certain conditions.
Affected Products:
Siemens reports that the vulnerabilities affect the following Industrial PCs and BIOS versions:
-SIMATIC Field-PG M3: ME prior to V6.2.61.3535,
-SIMATIC Field-PG M4: BIOS prior to V18.01.06,
-SIMATIC Field-PG M5: BIOS prior to V22.01.04,
-SIMATIC HMI IPC677C: ME prior to V6.2.61.3535,
-SIMATIC IPC427D: BIOS prior to V17.0?.10,
-SIMATIC IPC427E: BIOS prior to V21.01.07,
-SIMATIC IPC477D: BIOS prior to V17.0?.10,
-SIMATIC IPC477D PRO: BIOS prior to V17.0?.10,
-SIMATIC IPC477E: BIOS prior to V21.01.07,
-SIMATIC IPC547D: ME prior to V7.1.91.3272,
-SIMATIC IPC547E: ME prior to V9.1.41.3024,
-SIMATIC IPC547G: ME prior to V11.8.50.3425 and BIOS Siemens reports that the vulnerability affects the following versions of SIMATIC Industrial PCs using a version of Infineon’s Trusted Platform Module (TPM):
-SIMATIC Field-PG M5 all versions prior to v22.01.04,
-SIMATIC IPC227E all versions prior to v20.01.10,
-SIMATIC IPC277E all versions prior to v20.01.10,
-SIMATIC IPC427E all versions prior to v21.01.07,
-SIMATIC IPC477E all versions prior to v21.01.07,
-SIMATIC IPC547G all versions, and
-SIMATIC ITP1000 all versions prior to v23.01.03
Siemens reports that the vulnerabilities affect the following versions of SIMATIC WinCC Add-On:
-SIMATIC WinCC Add-On Historian CONNECT ALARM all versions prior to and including v5.x,
-SIMATIC WinCC Add-On PI CONNECT ALARM all versions prior to and including v2.x,
-SIMATIC WinCC Add-On PI CONNECT AUDIT TRAIL all versions prior to and including v1.x,
-SIMATIC WinCC Add-On PM-AGENT all versions prior to and including v5.x,
-SIMATIC WinCC Add-On PM-ANALYZE all versions prior to and including v7.x,
-SIMATIC WinCC Add-On PM-CONTROL all versions prior to and including v10.x,
-SIMATIC WinCC Add-On PM-MAINT all versions prior to and including v9.x,
-SIMATIC WinCC Add-On PM-OPEN EXPORT all versions prior to and including v7.x,
-SIMATIC WinCC Add-On PM-OPEN HOST-S all versions prior to and including v7.x,
-SIMATIC WinCC Add-On PM-OPEN IMPORT all versions prior to and including v6.x,
-SIMATIC WinCC Add-On PM-OPEN PI all versions prior to and including v7.x,
-SIMATIC WinCC Add-On PM-OPEN PV02 all versions prior to and including v1.x,
-SIMATIC WinCC Add-On PM-OPEN TCP/IP all versions prior to and including v8.x,
-SIMATIC WinCC Add-On PM-QUALITY all versions prior to and including v9.x,
-SIMATIC WinCC Add-On SICEMENT IT MIS all versions prior to and including v7.x, and
-SIMATIC WinCC Add-On SIPAPER IT MIS all versions prior to and including v7.x
Siemens reports the vulnerability affects the following industrial products:
-SIMATIC S7-200 Smart: All versions prior to V2.03.01,
-SIMATIC S7-400 PN V6: All versions prior to V6.0.6,
-SIMATIC S7-400 H V6: All versions prior to V6.0.8,
-SIMATIC S7-400 PN/DP V7: All versions prior to V7.0.2,
-SIMATIC S7-410 V8: All versions,
-SIMATIC S7-300: All versions,
-SIMATIC S7-1200: All versions,
-SIMATIC S7-1500: All versions prior to V2.0,
-SIMATIC S7-1500 Software Controller: All versions prior to V2.0,
-SIMATIC WinAC RTX 2010 incl. F: All versions,
-SIMATIC ET 200 Interface modules for PROFINET IO:-SIMATIC ET 200AL: All versions,
-SIMATIC ET 200ecoPN: All versions,
-SIMATIC ET 200M: All versions,
-SIMATIC ET 200MP IM155-5 PN BA: All versions prior to V4.0.2,
-SIMATIC ET 200MP IM155-5 PN ST: All versions prior to V4.1,
-SIMATIC ET 200MP (except IM155-5 PN BA and IM155-5 PN ST): All versions,
-SIMATIC ET 200pro: All versions,
-SIMATIC ET 200S: All versions, and
-SIMATIC ET 200SP: All versions.
-Development/Evaluation Kits for PROFINET IO:-DK Standard Ethernet Controller: All versions prior to V4.1.1 Patch 05,
-EK-ERTEC 200P: All versions prior to V4.5, and
-EK-ERTEC 200 PN IO: All versions prior to V4.5
-SIMOTION Firmware:-SIMOTION D: All versions prior to V5.1 HF1,
-SIMOTION C: All versions prior to V5.1 HF1,
-SIMOTION P V4.4 and V4.5: All versions prior to V4.5 HF5, and
-SIMOTION P V5: All versions prior to V5.1 HF1
-SINAMICS:-SINAMICS DCM: All versions,
-SINAMICS DCP: All versions,
-SINAMICS G110M / G120(C/P/D) w. PN: All versions prior to V4.7 SP9 HF1,
-SINAMICS G130 and G150 w. PN: All versions,
-SINAMICS S110 w. PN: All versions prior to V4.4 SP3 HF6,
-SINAMICS S120 w. PN: All versions prior to V4.8 HF5,
-SINAMICS S150 w. PN:-V4.7: All versions, and
-V4.8: All versions.
-SINAMICS V90 w. PN: All versions prior to V1.02
-SINUMERIK 840D sl: All versions,
-SIMATIC Compact Field Unit: All versions,
-SIMATIC PN/PN Coupler: All versions,
-SIMOCODE pro V PROFINET: All versions, and
-SIRIUS Soft starter 3RW44 PN: All versions.
CVE References: CVE-2017-5705, CVE-2017-5706, CVE-2017-5707, CVE-2017-5708, CVE-2017-5709, CVE-2017-5710, CVE-2017-5711, CVE-2017-5712, CVE-2017-15361, CVE-2017-12741
Official advisory ↗Canadian Centre for Cyber Security · English · AV17-173Intel® security updateIntel® has released a security update to address multiple vulnerabilities in Intel® Management Engine (ME), Intel® Server Platform Services (SPS), and Intel® Trusted Execution Engine (TXE) products.
Products Affected:
6th, 7th & 8th Generation Intel® Core™ Processor Family
Intel® Xeon® Processor E3-1200 v5 & v6 Product Family
Intel® Xeon® Processor Scalable Family
Intel® Xeon® Processor W Family
Intel® Atom® C3000 Processor Family
Apollo Lake Intel® Atom Processor E3900 series
Apollo Lake Intel® Pentium™
Celeron™ N and J series Processors
CVE References: CVE-2017-5705, CVE-2017-5706, CVE-2017-5707, CVE-2017-5708, CVE-2017-5709, CVE-2017-5710, CVE-2017-5711, CVE-2017-5712
Official advisory ↗CERT-FR · French · CERTFR-2017-AVI-423Multiples vulnérabilités dans les microgiciels IntelLe 1er mai 2017 [1], une vulnérabilité concernant Intel AMT permettait
à un attaquant de provoquer une exécution de code arbitraire à distance
et une élévation de privilèges sur des machines comportant un modèle de
processeur Intel habituellement utilisé par les entreprises.
Le 20 novembre 2017 [2][3], un article annonce l’identification de
nouvelles vulnérabilités critiques dans IME et AMT pour les processeurs
Intel. Les processeurs concernés correspondent autant à des modèles
d’entreprise qu'à des modèles pour particuliers.
Intel propose un outil permettant de détecter les processeurs affectés
par cette vulnérabilité [4].
L’exploitation de ces vulnérabilités permet à un attaquant ayant un
accès local à la machine d’altérer l’intégrité de la chaîne de démarrage
et d’exécuter du code arbitraire à l’insu du système d’exploitation,
même lorsque la machine est éteinte.
Ces vulnérabilités concernent une vaste gamme de processeurs : des
versions de processeurs récentes disponible pour les particuliers dont
la vente commence début 2016, comme de plus anciens destinés aux
entreprises datant de 2011.
A ce jour, il n’existe pas de code disponible publiquement exploitant
ces vulnérabilités. Potentiellement, un tel code pourrait permettre :
Une exécution de code arbitraire dans le contexte d’IME et, par
conséquent, des modules basés dessus, tels que AMT ou PTT (Plateform
Trust Technology) ;
d’impacter les mécanismes d’attestation de validité de la machine,
tel que la désactivation du Secure Boot, grâce à la compromission
d’AMT ;
de charger et exécuter du code arbitraire dans le contexte d’AMT,
par exemple pour charger une session VNC à l’insu du système
d’exploitation ;
de récupérer des informations contenues dans la plateforme Intel
PTT, telles que des clés de Bitlocker.
Official advisory ↗