ICSA-20-042-02: Siemens Industrial Products SNMP (Update F)
CISA advisory · released 2020-02-11
Source record Collected from CISA's CSAF advisory feed
- Distribution label in the document: TLP:WHITE
- Revision 10, 2025-05-06 (final)
CISA's summary
Summary: Several industrial products are affected by a vulnerability that could allow remote attackers to conduct a denial of service attack by sending specially crafted packets to port 161/udp (SNMP). Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens recommends specific countermeasures for products where updates are not, or not yet available.
Products, as the advisory lists them
| Vendor | Product | Version |
|---|---|---|
| Siemens | IE/PB link PN IO (6GK1411-5AB10) | <V4.0.1 |
| Siemens | SCALANCE S602 | <V4.1 |
| Siemens | SCALANCE S612 | <V4.1 |
| Siemens | SCALANCE S623 | <V4.1 |
| Siemens | SCALANCE S627-2M | <V4.1 |
| Siemens | SIMATIC CP 1623 (6GK1162-3AA00) | <V14.00.15.00_51.25.00.01 |
| Siemens | SIMATIC CP 1626 (6GK1162-6AA01) | <V1.1.1 |
| Siemens | SIMATIC CP 1628 (6GK1162-8AA00) | <V14.00.15.00_51.25.00.01 |
| Siemens | SIMATIC CP 343-1 Advanced (6GK7343-1GX31-0XE0) | vers:all/* |
| Siemens | SIMATIC CP 443-1 (6GK7443-1EX30-0XE0) | <V3.3 |
| Siemens | SIMATIC CP 443-1 (6GK7443-1EX30-0XE1) | <V3.3 |
| Siemens | SIMATIC CP 443-1 Advanced (6GK7443-1GX30-0XE0) | <V3.3 |
| Siemens | SIMATIC CP 443-1 OPC UA (6GK7443-1UX00-0XE0) | vers:all/* |
| Siemens | SIPLUS NET CP 343-1 Advanced (6AG1343-1GX31-4XE0) | vers:all/* |
| Siemens | SIPLUS NET CP 443-1 (6AG1443-1EX30-4XE0) | <V3.3 |
| Siemens | SIPLUS NET CP 443-1 Advanced (6AG1443-1GX30-4XE0) | <V3.3 |
| Siemens | SIPLUS NET IE/PB link PN IO (6AG1411-5AB10-2AA0) | <V4.0.1 |
| Siemens | SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) | <V2.0 |
| Siemens | TIM 1531 IRC (6GK7543-1MX00-0XE0) | <V2.0 |
DeSpy has not checked any unit, hardware revision or firmware.
Vulnerabilities in this advisory
- CVE-2015-5621 — CVE-2015-5621 · CWE-20
An error in the message handling of SNMP messages allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted packet sent on port 161/udp (SNMP). The security vulnerability could be exploited by an attacker with network access to the affected device. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the affected system.
- CVE-2018-18065 — CVE-2018-18065 · CWE-476
A NULL Pointer Exception bug within the SMNP handling code allows authenticated attacker to remotely cause a denial of service via a crafted packet sent on port 161/udp (SNMP). The security vulnerability could be exploited by an attacker with network access to the affected device. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the affected system.
Acknowledgments, as the advisory lists them
- Siemens ProductCERT: reporting these vulnerabilities to CISA.
The advisory's legal notice
Siemens Security Advisories are subject to the terms and conditions contained in Siemens' underlying license terms or other applicable agreements previously agreed to with Siemens (hereinafter "License Terms"). To the extent applicable to information, software or documentation made available in or through a Siemens Security Advisory, the Terms of Use of Siemens' Global Website (https://www.siemens.com/terms_of_use, hereinafter "Terms of Use"), in particular Sections 8-10 of the Terms of Use, shall apply additionally. In case of conflicts, the License Terms shall prevail over the Terms of Use.
Sources
DeSpy's copy of this version is dated 2026-09-28.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.