OTPulse

IPU 2021.1 Vulnerabilities in Siemens Industrial Products using Intel CPUs (June 2021)

Monitor7.5SSA-309571Aug 10, 2021
Attack VectorLocal
Auth RequiredHigh
ComplexityHigh
User InteractionNone needed
Summary

Intel published information on vulnerabilities in Intel products in June 2021. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. The affected products include SIMATIC IPCs (industrial computers), SINUMERIK CNC controllers, SIMATIC S7-1500 CPUs, field programmable units, and handheld terminals used in manufacturing automation. Many of these products contain Intel CPUs or firmware components (BIOS, CSME, SPS, LMS) susceptible to the 2021.1 IPU vulnerabilities. Siemens has released BIOS updates for some products; others have no fix available.

What this means
What could happen
An attacker with local access to a vulnerable Siemens industrial computer or controller could bypass security boundaries and gain high-privilege execution, potentially altering production parameters, disabling safety functions, or disrupting manufacturing operations. This affects programmable logic controllers, CNC machine controllers, and field engineering workstations used to manage critical manufacturing processes.
Who's at risk
Manufacturing facilities using Siemens SIMATIC industrial computers (IPC models 127E through 847E series), SIMATIC field programmable units (PG M5/M6), SIMATIC S7-1500 programmable logic controllers (CPUs 1518-4, 1518F-4, 1504D, 1507D, 1515SP), handheld terminals (HT 10), and SINUMERIK CNC machine controllers (828D, MC MCU 1720, NCU 1740, PPU 1740). These are core devices in manufacturing automation, used for machine control, process monitoring, and engineering access.
How it could be exploited
An attacker with physical or local network access to a vulnerable Siemens IPC or SINUMERIK controller could exploit Intel CPU or firmware vulnerabilities to escalate privileges and break security isolation boundaries. From there, they could modify process setpoints, disable safety interlocks, or halt production. The attack requires high privilege (user with administrator or engineering access) but could occur during maintenance windows or from a compromised engineering workstation on the plant network.
Prerequisites
  • Local or privileged network access to the affected Siemens IPC, PG, or SINUMERIK controller
  • Administrator or engineering workstation credentials to interact with the device
  • Physical access or remote access via engineering network (not exposed to Internet)
No authentication required (Intel CPU/firmware vulnerability)Low complexity exploitation (Intel firmware flaw)High privileges needed to trigger (limits exposure)Affects production control systems (S7-1500 PLC, CNC controllers)Many products have no patch available
Exploitability
Low exploit probability (EPSS 0.3%)
Affected products (25)
25 pending
ProductAffected VersionsFix Status
SIMATIC Field PG M6<V26.01.08No fix yet
SIMATIC IPC3000 SMART V3<V01.04.00No fix yet
SIMATIC IPC347G<V01.04.00No fix yet
SIMATIC IPC427E<V21.01.16No fix yet
SIMATIC IPC477E<V21.01.16No fix yet
Remediation & Mitigation
0/16
Schedule — requires maintenance window
0/15

Patching may require device reboot — plan for process interruption

SIMATIC IPC627E
HOTFIXUpdate SIMATIC IPC627E, IPC647E, IPC677E, and IPC847E BIOS to version V25.02.10 or later
SIMATIC Field PG M6
HOTFIXUpdate SIMATIC Field PG M6 BIOS to version V26.01.08 or later
SIMATIC IPC3000 SMART V3
HOTFIXUpdate SIMATIC IPC3000 SMART V3, IPC347G BIOS to version V01.04.00 or later
SIMATIC IPC427E
HOTFIXUpdate SIMATIC IPC427E, IPC477E, IPC477E Pro BIOS to version V21.01.16 or later
SIMATIC IPC527G
HOTFIXUpdate SIMATIC IPC527G BIOS to version V1.4.3 or later
SIMATIC ITP1000
HOTFIXUpdate SIMATIC ITP1000 BIOS to version V23.01.10 or later
SIMATIC Field PG M5
HOTFIXUpdate SIMATIC Field PG M5 BIOS to version V22.01.10 or later
SIMATIC IPC127E
HOTFIXUpdate SIMATIC IPC127E BIOS to version V27.01.07 or later
SINUMERIK 828D HW PU.4
HOTFIXUpdate SINUMERIK 828D HW PU.4 firmware to version V08.00.00.00 or later
SINUMERIK MC MCU 1720
HOTFIXUpdate SINUMERIK MC MCU 1720 firmware to version V05.00.00.00 or later
SINUMERIK ONE / SINUMERIK 840D sl Handheld Terminal HT 10
HOTFIXUpdate SINUMERIK ONE / SINUMERIK 840D sl Handheld Terminal HT 10 to version V08.00.00.00 or later
SINUMERIK ONE NCU 1740
HOTFIXUpdate SINUMERIK ONE NCU 1740 firmware to version V05.00.00.00 or later
SINUMERIK ONE PPU 1740
HOTFIXUpdate SINUMERIK ONE PPU 1740 firmware to version V06.00.00.00 or later
All products
HOTFIXUpdate SIMATIC ET 200SP Open Controller CPU 1515SP PC2 to version V0209_0105 or later
HOTFIXApply Intel BIOS microcode updates independently from Siemens vendor patches where available for hardware not on Siemens EOL products
Long-term hardening
0/1
SIMATIC IPC547G
HARDENINGFor products with no fix available (SIMATIC IPC547G, S7-1500 CPU 1518-4/1518F-4/1504D/1507D), restrict local and remote access to engineering workstations; isolate devices on a dedicated engineering network with firewall rules limiting access to necessary management protocols only
↑↓ Navigate · Esc Close
API: /api/v1/advisories/a2624144-e6d6-4127-a6c2-1b4aba3d2b20
IPU 2021.1 Vulnerabilities in Siemens Industrial Products using Intel CPUs (June 2021) | CVSS 7.5 - OTPulse