ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Critical Bug in Siemens SIMATIC PLCs Could Let Attackers Steal Cryptographic Keys

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-15782
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl.

A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions < V4.5.0), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V2.9.2), SIMATIC S7-1500 Software Controller (All versions < V21.9), SIMATIC S7-PLCSIM Advanced (All versions < V4.0), SINAMICS PERFECT HARMONY GH180 Drives (Drives manufactured before 2021-08-13), SINUMERIK MC (All versions < V6.15), SINUMERIK ONE (All versions < V6.15). Affected devices are vulnerable to a memory protection bypass through a specific operation. A remote unauthenticated attacker with network access to port 102/tcp could potentially write arbitrary data and code to protected memory areas or read sensitive data to launch further attacks.

NVD description · AI analysis pending
9.85%
  • siemens simatic driver controller firmware
  • siemens s7-1200 cpu firmware
  • siemens s7-1500 cpu firmware
  • +1 more
CVE-2021-22681
Authentication Bypass in Rockwell Automation Studio 5000 Logix Designer and Logix PLCs

Rockwell Automation's Studio 5000 Logix Designer (versions 21 and later) and RSLogix 5000 (versions 16 through 20) use a shared key to verify that they are communicating with genuine Allen-Bradley Logix controllers, and an unauthenticated remote attacker can bypass this verification mechanism (CWE-522, insufficient protection of credentials). The attack requires only network access to the affected software or controllers - no credentials, no user interaction, and no special conditions (CVSS 3.1: 9.8). By bypassing the verification, an attacker can authenticate to CompactLogix, ControlLogix, DriveLogix, Compact GuardLogix, GuardLogix and SoftLogix controllers and interact with the PLCs, potentially tampering with industrial processes. Any deployment running the affected engineering software versions with the listed Logix controller families is in scope, which spans a very large share of Rockwell's installed base. CISA added this flaw to its Known Exploited Vulnerabilities catalog on 2026-03-05 (ransomware use unknown), and EPSS puts the 30-day exploitation probability at roughly 64%; no public proof-of-concept is known.

Do: Apply mitigations per Rockwell's instructions - the vendor has advised disconnecting internet-facing connections, so remove internet exposure from affected controllers and engineering workstations and segment OT networks. Follow applicable CISA BOD 22-01 guidance, and inventory for Studio 5000 Logix Designer v21+ or RSLogix 5000 v16-20 used with the listed controllers; upgrade per vendor guidance or discontinue use if mitigations are unavailable.

9.864% KEV
  • Rockwell Automation Studio 5000 Logix Designer v21 and later
  • Rockwell Automation RSLogix 5000 v16 through v20
  • Rockwell Automation FactoryTalk Services Platform
  • +6 more
massroughly 1 million or more Logix controller installations (tens of thousands likely internet-exposed)
CVE-2022-1159
Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation running Studio

Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation running Studio 5000 Logix Designer could inject controller code undetectable to a user.

NVD description · AI analysis pending
7.23%
  • rockwellautomation controllogix 5580 firmware
  • rockwellautomation guardlogix 5580 firmware
  • rockwellautomation compactlogix 5380 firmware
  • +1 more
CVE-2022-1161
An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems.

An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the other.

NVD description · AI analysis pending
9.85%
  • rockwellautomation compactlogix 1768-l43 firmware
  • rockwellautomation compactlogix 1768-l45 firmware
  • rockwellautomation compactlogix 1769-l31 firmware
  • +1 more
CVE-2022-38465
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl.

A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions < V4.5.0), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V2.9.2), SIMATIC S7-1500 Software Controller (All versions < V21.9), SIMATIC S7-PLCSIM Advanced (All versions < V4.0), SINUMERIK MC (All versions < V6.21), SINUMERIK ONE (All versions < V6.21). Affected products protect the built-in global private key in a way that cannot be considered sufficient any longer. The key is used for the legacy protection of confidential configuration data and the legacy PG/PC and HMI communication. This could allow attackers to discover the private key of a CPU product family by an offline attack against a single CPU of the family. Attackers could then use this knowledge to extract confidential configuration data from projects that are protected by that key or to perform attacks against legacy PG/PC and HMI communication.

NVD description · AI analysis pending
7.8<1%
  • siemens simatic et 200 sp open controller cpu 1515sp pc2 firmware
  • siemens simatic et 200 sp open controller cpu 1515sp pc firmware
  • siemens simatic drive controller cpu 1504d tf firmware
  • +1 more
Full article519 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananOct 12, 2022

A vulnerability in Siemens Simatic programmable logic controller (PLC) can be exploited to retrieve the hard-coded, global private cryptographic keys and seize control of the devices.

"An attacker can use these keys to perform multiple advanced attacks against Siemens SIMATIC devices and the related TIA Portal, while bypassing all four of its access level protections," industrial cybersecurity company Claroty said in a new report.

"A malicious actor could use this secret information to compromise the entire SIMATIC S7-1200/1500 product line in an irreparable way."

The critical vulnerability, assigned the identifier CVE-2022-38465, is rated 9.3 on the CVSS scoring scale and has been addressed by Siemens as part of security updates issued on October 11, 2022.

The list of impacted products and versions is below -

  • SIMATIC Drive Controller family (all versions before 2.9.2)
  • SIMATIC ET 200SP Open Controller CPU 1515SP PC2, including SIPLUS variants (all versions before 21.9)
  • SIMATIC ET 200SP Open Controller CPU 1515SP PC, including SIPLUS variants (all versions)
  • SIMATIC S7-1200 CPU family, including SIPLUS variants (all versions before 4.5.0)
  • SIMATIC S7-1500 CPU family, including related ET200 CPUs and SIPLUS variants (all versions before V2.9.2)
  • SIMATIC S7-1500 Software Controller (all versions before 21.9), and
  • SIMATIC S7-PLCSIM Advanced (all versions before 4.0)

Claroty said it was able to get read and write privileges to the controller by exploiting a previously disclosed flaw in Siemens PLCs (CVE-2020-15782), allowing for the recovery of the private key.

Doing so would not only permit an attacker to circumvent access controls and override native code, but also obtain full control over every PLC per affected Siemens product line.

CVE-2022-38465 mirrors another severe shortcoming that was identified in Rockwell Automation PLCs (CVE-2021-22681) last year and which could have enabled an adversary to remotely connect to the controller, and upload malicious code, download information from the PLC, or install new firmware.

"The vulnerability lies in the fact that Studio 5000 Logix Designer software may allow a secret cryptographic key to be discovered," Claroty noted in February 2021.

As workarounds and mitigations, Siemens is recommending customers to use legacy PG/PC and HMI communications only in trusted network environments and secure access to TIA Portal and CPU to prevent unauthorized connections.

The German industrial manufacturing company has also taken the step of encrypting the communications between engineering stations, PLCs and HMI panels with Transport Layer Security (TLS) in TIA Portal version 17, while warning that the "likelihood of malicious actors misusing the global private key as increasing."

The findings are the latest in a series of major flaws that have been discovered in software used in industrial networks. Earlier this June, Claroty detailed over a dozen issues in Siemens SINEC network management system (NMS) that could be abused to gain remote code execution capabilities.

Then in April 2022, the company unwrapped two vulnerabilities in Rockwell Automation PLCs (CVE-2022-1159 and CVE-2022-1161) that could be exploited to modify user programs and download malicious code to the controller.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/10/critical-bug-in-siemens-simatic-plcs.html