Siemens SIMATIC Products BIOS Password Bypass Vulnerability via EFI Variable Manipulation

Vulnerability

A vulnerability exists in various Siemens SIMATIC products, including Field PG M5, Field PG M6, IPC BX-21A, BX-32A, BX-39A, BX-59A, PX-32A, PX-39A, PX-39A PRO, IPC RC-543B, IPC RW-543A, IPC127E, IPC227E, IPC227G, IPC277E, IPC277G, IPC277G PRO, IPC3000 SMART V3, IPC327G, IPC347G, IPC377G, IPC427E, IPC477E, IPC477E PRO, IPC527G, IPC627E, IPC647E, IPC677E, IPC847E, and ITP1000, all versions. The vulnerability arises from inadequate protection of EFI (Extensible Firmware Interface) variables, allowing an authenticated attacker to disable the BIOS password without authorization by directly communicating with the flash controller.

Impact

Exploitation of this vulnerability could lead to unauthorized disabling of the BIOS password, allowing for potential bypass of BIOS security features.

Remediation

Siemens has released new BIOS versions for several affected products. For products where a fix is not yet available, it is recommended to restrict access to root or administrator permissions on the operating system. Specific product remediations can be found in the Siemens Security Advisory SSA-216014.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
2.5
exploitability
3.0
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.