IM
IronMonkey Threat Research
‹ Back to ICS Advisories

SSA-686975: IPU 2022.3 Vulnerabilities in Siemens Industrial Products using Intel CPUs

HIGH
CVSS 7.9
Date 2026-08-11T00:00:00+00:00
Source siemens-productcert
Published by Siemens ProductCERT

// Description

Intel has published information on vulnerabilities in Intel products in November 2022. This advisory lists the related Siemens Industrial products affected by these vulnerabilities that can be patched by applying the corresponding BIOS update ("2022.3 IPU – BIOS Advisory" Intel-SA-00688). Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2022-21198 7.9 high
CVE-2022-21198. Time-of-check time-of-use race condition in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

// Remediations (13)

Mitigation: As a prerequisite for an attack, an attacker must be able to run untrusted code on affected systems.
As a prerequisite for an attack, an attacker must be able to run untrusted code on affected systems. Siemens recommends limiting the possibilities to run untrusted code if possible.
Patch: Update to V25.02.14 or later version
Update to V25.02.14 or later version
Patch: Update to V21.01.19 or later version
Update to V21.01.19 or later version
Patch: Update to V26.01.11 or later version
Update to V26.01.11 or later version
Patch: Update to V21.01.19 or later version
Update to V21.01.19 or later version
Patch: Update to V29.01.03 or later version
Update to V29.01.03 or later version
Patch: Update to V22.01.11 or later version
Update to V22.01.11 or later version
Patch: Update to V25.02.14 or later version
Update to V25.02.14 or later version
Patch: Update to V26.01.11 or later version
Update to V26.01.11 or later version
Patch: Update to V22.01.11 or later version
Update to V22.01.11 or later version
Patch: Update to V29.01.03 or later version
Update to V29.01.03 or later version
Workaround: As a prerequisite for an attack, an attacker must be able to run untrusted code on affected systems.
As a prerequisite for an attack, an attacker must be able to run untrusted code on affected systems. Siemens recommends limiting the possibilities to run untrusted code if possible.
Patch: Update to V21.01.19 or later version
Update to V21.01.19 or later version

// References