The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC Field PG M5
- SIMATIC Field PG M6
- SIMATIC IPC3000 SMART V3
- SIMATIC IPC347G
- SIMATIC IPC427E
- SIMATIC IPC477E
- SIMATIC IPC477E Pro
- SIMATIC IPC527G
- SIMATIC IPC547G
- SIMATIC IPC627E
- SIMATIC IPC647E
- SIMATIC IPC677E
- Summary
- Improper buffer restrictions in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32 and 15.0.22 may allow a privileged user to potentially enable escalation of privilege via local access.
- Remediation
- Update BIOS to V22.01.10 or later version
