June 13, 2023, midnight |

Siemens ProductCERT Security Advisories cert-portal.siemens.com

The know-how protection feature in Totally Integrated Automation Portal (TIA Portal) does not properly update the encryption of existing program blocks when a project file is updated. This could allow attackers with access to the project file to recover previous - yet unprotected - versions of the project without the knowledge of the know-how protection password.


Siemens recommends specific countermeasures for products where updates are not, or not yet available.

access attackers automation encryption failure feature file knowledge mechanism portal program project protection recover ssa tia tia portal update

More from cert-portal.siemens.com / Siemens ProductCERT Security Advisories

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Senior - Penetration Tester

@ Deloitte | Madrid, España

Associate Cyber Incident Responder

@ Highmark Health | PA, Working at Home - Pennsylvania

Senior Insider Threat Analyst

@ IT Concepts Inc. | Woodlawn, Maryland, United States