# Multiple vulnerabilities in Siemens industrial products

Published: 2019-09-10 · Severity: high · Sectors: manufacturing, infrastructure
Canonical: https://vorant.io/reports/fecc2efc-2d78-5cff-b7de-6127c50a35bd/multiple-vulnerabilities-in-siemens-industrial-products

> CERT-FR advises of multiple vulnerabilities in Siemens CloudConnect, SCALANCE, SIMATIC, SINEMA, and SINETPLAN products allowing remote code execution, denial of service, and security policy bypass.

CERT-FR has published an advisory detailing multiple vulnerabilities affecting several Siemens industrial automation and connectivity products. The affected products include CloudConnect 712 (before V1.1.5), SCALANCE SC-600 (before V2.0.1), SIMATIC TDC CP51M1 (before V1.1.7), SINEMA Remote Connect Server (before V2.0 SP1), and SINETPLAN V2.0. The vulnerabilities carry a range of impacts including remote code execution, denial of service, security policy bypass, data confidentiality violations, and cross-site scripting (XSS) and cross-site request forgery (CSRF) flaws. The advisory references seven Siemens security bulletins published on 10 September 2019, indicating this was a coordinated disclosure event covering multiple product lines. Defenders operating these Siemens products in industrial control, connectivity, and network infrastructure contexts should prioritize patching to the specified fixed versions.

## Mentioned in this report

- Vulnerabilities: CVE-2019-10915, CVE-2019-10937, CVE-2019-11477, CVE-2019-11478, CVE-2019-11479, CVE-2019-1181, CVE-2019-1182, CVE-2019-1222, CVE-2019-12255 (poc), CVE-2019-12256, CVE-2019-12257, CVE-2019-12258 (weaponized), CVE-2019-12259, CVE-2019-1226, CVE-2019-12260, CVE-2019-12261, CVE-2019-12262, CVE-2019-12263, CVE-2019-12264, CVE-2019-12265, CVE-2019-13918, CVE-2019-13919, CVE-2019-13920, CVE-2019-13922, CVE-2019-13923

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2019-AVI-429

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/fecc2efc-2d78-5cff-b7de-6127c50a35bd/multiple-vulnerabilities-in-siemens-industrial-products.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
