Feb. 8, 2022, midnight |

Siemens ProductCERT Security Advisories cert-portal.siemens.com

Security researchers discovered and disclosed 33 vulnerabilities in several open-source TCP/IP stacks for embedded devices, also known as “AMNESIA:33” vulnerabilities.


This advisory describes the impact of two of these vulnerabilities (CVE-2020-13987, CVE-2020-17437) to Siemens products.


Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens recommends specific countermeasures for products where updates are not available.


The impact of another “AMNESIA:33” vulnerability (CVE-2020-13988) is described in Siemens Security Advisory SSA-541017.

advisory cve devices embedded embedded devices impact ip stack pac products researchers security security researchers siemens ssa stack stacks tcp update updates vulnerabilities

More from cert-portal.siemens.com / Siemens ProductCERT Security Advisories

Technical Senior Manager, SecOps | Remote US

@ Coalfire | United States

Global Cybersecurity Governance Analyst

@ UL Solutions | United States

Security Engineer II, AWS Offensive Security

@ Amazon.com | US, WA, Virtual Location - Washington

Senior Cyber Threat Intelligence Analyst

@ Sainsbury's | Coventry, West Midlands, United Kingdom

Embedded Global Intelligence and Threat Monitoring Analyst

@ Sibylline Ltd | Austin, Texas, United States

Senior Security Engineer

@ Curai Health | Remote