SSA-478960 V1.3 (Last Update: 2023-04-11): Missing CSRF Protection in the Web Server Login Page of Industrial Controllers

Affected Product and Versions Remediation SIMATIC Drive Controller family
All versions < V3.0.1

Update to V3.0.1 or later version

https://support.industry.siemens.com/cs/ww/en/view/109773914/ See further recommendations from section Workarounds and Mitigations SIMATIC ET 200pro IM154-8 PN/DP CPU (6ES7154-8AB01-0AB0)
All versions < V3.2.19

Update to V3.2.19 or later version

https://support.industry.siemens.com/cs/ww/en/view/47354502/ See further recommendations from section Workarounds and Mitigations SIMATIC ET 200pro IM154-8F PN/DP CPU (6ES7154-8FB01-0AB0)
All versions < V3.2.19

Update to V3.2.19 or later version

https://support.industry.siemens.com/cs/ww/en/view/47354578/ See further recommendations from section Workarounds and Mitigations SIMATIC ET 200pro IM154-8FX PN/DP CPU (6ES7154-8FX00-0AB0)
All versions < V3.2.19

Update to V3.2.19 or later version

https://support.industry.siemens.com/cs/ww/en/view/62612377/ See further recommendations from section Workarounds and Mitigations SIMATIC ET 200S IM151-8 PN/DP CPU (6ES7151-8AB01-0AB0)
All versions < V3.2.19

Update to V3.2.19 or later version

https://support.industry.siemens.com/cs/ww/en/view/47353723/ See further recommendations from section Workarounds and Mitigations SIMATIC ET 200S IM151-8F PN/DP CPU (6ES7151-8FB01-0AB0)
All versions < V3.2.19

Update to V3.2.19 or later version

https://support.industry.siemens.com/cs/ww/en/view/47354354/

Read more

Explore the site

More from the blog

Latest News