Sept. 12, 2023, midnight |

Siemens ProductCERT Security Advisories cert-portal.siemens.com

Several Intel-CPU based SIMATIC IPCs are affected by an information exposure vulnerability (CVE-2022-40982) in the CPU that could allow an authenticated local user to potentially read other users’ data [1].


The issue is also known as “Gather Data Sampling” (GDS) or Downfall Attacks. For details refer to the chapter “Additional Information”.


Siemens is preparing updates and recommends specific countermeasures for products where updates are not, or not yet available.


[1] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00828.html

attacks cpu cpus cve data disclosure downfall exposure information information disclosure information disclosure vulnerability intel issue local simatic ssa vulnerability

More from cert-portal.siemens.com / Siemens ProductCERT Security Advisories

Azure DevSecOps Cloud Engineer II

@ Prudent Technology | McLean, VA, USA

Security Engineer III - Python, AWS

@ JPMorgan Chase & Co. | Bengaluru, Karnataka, India

SOC Analyst (Threat Hunter)

@ NCS | Singapore, Singapore

Managed Services Information Security Manager

@ NTT DATA | Sydney, Australia

Senior Security Engineer (Remote)

@ Mattermost | United Kingdom

Penetration Tester (Part Time & Remote)

@ TestPros | United States - Remote