The vendor explicitly identifies these products as affected by this CVE.
- Industrial Edge Own Device (IEOD)
- Industrial Edge Virtual Device
- SCALANCE LPE9413 (6GK5998-3GS01-2AC2)
- SIMATIC IPC127E Industrial Edge Device
- SIMATIC IPC227E Industrial Edge Device
- SIMATIC IPC427E Industrial Edge Device
- SIMATIC IPC847E Industrial Edge Device
- SIMATIC IPC BX-39A Industrial Edge Device
- SIMATIC IPC BX-59A Industrial Edge Device
- Summary
- Affected devices do not properly enforce user authentication on specific API endpoints when identity federation is used. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that identity federation is currently or has previously been used and the attacker has learned the identity of a legitimate user.
- Remediation
- Update to V1.21.1-1-a or later version
