- What: Siemens has released security advisories addressing vulnerabilities in multiple products.
- Impact: Affected products include JT Open, JT2Go, Mendix Encryption, RUGGEDCOM, SCALANCE, and SIMATIC, potentially leading to security compromises.
[Control systems] Siemens security advisory (AV24-385) Serial number: AV24-385 Date: July 11, 2024 On July 9, 2024, Siemens published security advisories to address vulnerabilities in the following products: JT Open β versions prior to V11.5 JT2Go β versions prior to V14.3.0.8 Mendix Encryption β versions V10.0.0 and V10.0.1 JT Open β versions prior to V11.5 PLM XML SDK β versions prior to V7.1.0.014 RUGGEDCOM APE1808 (configured with Palo Alto Networks Virtual NGFW) β all versions RUGGEDCOM APE1808 (configured with Fortigate NGFW) β all versions RUGGEDCOM CROSSBOW β all versions RUGGEDCOM ROS V4.x, V5.x and II Families β multiple versions SCALANCE Family Devices β multiple versions and platforms SIMATIC Energy Manager Basic β versions prior to V7.5 SIMATIC Energy Manager PRO β versions prior to V7.5 SIMATIC IPC DiagBase β all versions SIMATIC IPC DiagMonitor β all versions SIMATIC WinCC Runtime Professional V19 β versions prior to V19 Update 1 SIMATIC WinCC Runtime Professional V18 β all versions SIMATIC WinCC V7.4 β versions prior to V7.4 SP1 Update 23 SIMATIC WinCC V7.5 β versions prior to V7.5 SP2 Update 16 SIMATIC WinCC V8.0 β versions prior to V8.0 Update 5 Simcenter Femap β versions prior to V2406 SIMIT V10 β all versions SIMIT V11 β all versions SINEC INS (with RADIUS Server feature enabled) β all versions SINEMA Remote Connect Server β versions prior to V3.2 SP1 SINEMA Remote Connect Client β versions prior to V3.2 HF1 SIPROTEC 5 CPxxx Devices β multiple versions and platforms SIPROTEC 5 Communication Modules β multiple versions and platforms Teamcenter Visualization V14.1 β versions prior to V14.1.0.14 Teamcenter Visualization V14.2 β versions prior to V14.2.0.10 Teamcenter Visualization V14.3 β versions prior to V14.3.0.8 Teamcenter Visualization V2312 β versions prior to V2312.0002 Totally Integrated Automation Portal (TIA Portal) β multiple versions The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates. Siemens Security Advisories Date modified: 2024-07-11