The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0)
- SIMATIC Drive Controller CPU 1507D TF (6ES7615-7DF10-0AB0)
- SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SK03-0AB0)
- SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DK03-0AB0)
- SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SM03-0AB0)
- SIMATIC ET 200SP CPU 1512SP-1 PN (6ES7512-1DM03-0AB0)
- SIMATIC ET 200SP CPU 1514SP F-2 PN (6ES7514-2SN03-0AB0)
- SIMATIC ET 200SP CPU 1514SP-2 PN (6ES7514-2DN03-0AB0)
- SIMATIC ET 200SP CPU 1514SPT F-2 PN (6ES7514-2WN03-0AB0)
- SIMATIC ET 200SP CPU 1514SPT-2 PN (6ES7514-2VN03-0AB0)
- SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants)
- SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0)
- Summary
- The login functionality of the web server in affected devices does not normalize the response times of login attempts. An unauthenticated remote attacker could exploit this side-channel information to distinguish between valid and invalid usernames.
- Remediation
- Update to V3.1.2 or later version
