The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants)
- SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants)
- SIMATIC S7-1200 CPU family (incl. SIPLUS variants)
- SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants)
- SIMATIC S7-1500 Software Controller
- SIMATIC S7-PLCSIM Advanced
- Summary
- Affected devices contain a message protection bypass vulnerability due to certain properties in the calculation used for integrity protection. This could allow an attacker in a Man-in-the-Middle position to modify network traffic sent on port 102/tcp to the affected devices.
- Remediation
- Update to V20.8 or later version
