OTPulse

Siemens Industrial Products with OPC UA (Update H)

Plan Patch7.5ICS-CERT ICSA-19-099-03Apr 9, 2019
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Denial-of-service vulnerability in OPC UA implementations across multiple Siemens industrial products. A remote attacker can send a specially crafted OPC UA request to crash the OPC UA service on affected devices. The vulnerability affects controllers (S7-1500, ET 200SP), HMI panels (Comfort, KTP Mobile), CNC systems (SINUMERIK), supervisory software (WinCC OA, WinCC Runtime Advanced), networking products (SINEMA Server, SINEC NMS), and I/O devices (RF188C, RF600R). SIMATIC CP 443-1 OPC UA, SIMATIC NET PC Software V13 and V15 have no vendor fix available. Successful exploitation disrupts communications between control system components.

What this means
What could happen
An attacker with network access to an affected OPC UA service could cause a denial-of-service condition, disrupting communications between controllers, HMI panels, and engineering workstations and potentially halting supervisory monitoring or automated process control.
Who's at risk
Manufacturing facilities using Siemens industrial automation products should care, specifically those deploying SIMATIC S7-1500 CPUs, ET 200SP controllers, HMI panels (Comfort, KTP Mobile), SINUMERIK CNC systems with OPC UA, WinCC supervisory software, and distributed I/O devices (RF188C, RF600R). Any facility relying on OPC UA for inter-device communication or remote engineering access is affected.
How it could be exploited
An attacker sends a specially crafted OPC UA request over the network to an affected service or device. If the device is exposed to a network the attacker can reach (directly or through compromised intermediate systems), the malicious request crashes the OPC UA service, making it unavailable for legitimate operations.
Prerequisites
  • Network access to OPC UA service port (typically 4840 or custom port)
  • OPC UA service enabled on the device
  • No authentication required to trigger the denial-of-service condition
remotely exploitableno authentication requiredlow complexityaffects availability of supervisory and control communicationssome affected products have no patch available
Exploitability
Moderate exploit probability (EPSS 1.1%)
Affected products (19)
16 with fix3 pending
ProductAffected VersionsFix Status
SIMATIC CP 443-1 OPC UAAll versionsNo fix yet
SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants)< V2.72.7
SIMATIC HMI Comfort Outdoor Panels 7" & 15" (incl. SIPLUS variants)< V15.1 Upd 415.1 Upd4
SIMATIC HMI Comfort Panels 4" - 22" (incl. SIPLUS variants)< V15.1 Upd 415.1 Upd4
SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F< V15.1 Upd 415.1 Upd4
Remediation & Mitigation
0/20
Do now
0/1
WORKAROUNDDisable OPC UA service on devices where it is not required for operations
Schedule — requires maintenance window
0/15

Patching may require device reboot — plan for process interruption

SIMATIC IPC DiagMonitor
HOTFIXUpdate SIMATIC IPC DiagMonitor to version 5.1.3 or later
SIMATIC NET PC Software V14
HOTFIXUpdate SIMATIC NET PC Software V14 to version 14 SP1 Update 14 or later
SIMATIC RF188C
HOTFIXUpdate SIMATIC RF188C to version 1.1.0 or later
SIMATIC RF600R family
HOTFIXUpdate SIMATIC RF600R family to version 3.2.1 or later
SIMATIC S7-1500 Software Controller
HOTFIXUpdate SIMATIC S7-1500 Software Controller to version 2.7 or later
SIMATIC WinCC OA
HOTFIXUpdate SIMATIC WinCC OA to version 3.15 P018 or later
SIMATIC WinCC Runtime Advanced
HOTFIXUpdate SIMATIC WinCC Runtime Advanced to version 15.1 Update 4 or later
SINEC NMS
HOTFIXUpdate SINEC NMS to version 1.0 SP1 or later
SINEMA Server
HOTFIXUpdate SINEMA Server to version 14 SP2 or later
SINUMERIK OPC UA Server
HOTFIXUpdate SINUMERIK OPC UA Server to version 2.1 or later
TeleControl Server Basic
HOTFIXUpdate TeleControl Server Basic to version 3.1.1 or later
All products
HOTFIXUpdate SIMATIC ET 200SP Open Controller CPU 1515SP PC2 to firmware version 2.7 or later
HOTFIXUpdate SIMATIC HMI Comfort Outdoor Panels 7" & 15" and Comfort Panels 4"-22" to version 15.1 Update 4 or later
HOTFIXUpdate SIMATIC HMI KTP Mobile Panels (KTP400F, KTP700, KTP700F, KTP900, KTP900F) to version 15.1 Update 4 or later
HOTFIXUpdate SIMATIC S7-1500 CPU family (including related ET200 CPUs) to version 2.6.1 or later
Long-term hardening
0/4
HARDENINGImplement cell protection concept to isolate control system networks and limit inter-cell communication
HARDENINGUse VPN to protect network communication between cells and between remote access points
HARDENINGApply Defense-in-Depth strategy: use firewalls to restrict OPC UA port access, network segmentation, and access controls on engineering workstations
HARDENINGIsolate all control system networks from the business network and the Internet
↑↓ Navigate · Esc Close
API: /api/v1/advisories/eb390484-f84a-4244-9c50-128084ed278c