logo

Siemens PLC Software: Hardcoded Cryptographic Keys Uncovered

ID: 5f3dd9ee-8a12-57a9-82b7-2033406f574e

STIX ID: report--5f3dd9ee-8a12-57a9-82b7-2033406f574e

Feed Name: Claroty Team82

Threat Score
90/100

Date Published: 2023-07-25

Date Updated: 2026-04-17

...
...

Team82 disclosed a critical vulnerability chain allowing extraction of global hardcoded private keys from Siemens SIMATIC S7-1200/1500 PLCs by using an RCE to read protected memory; with the recovered keys an attacker can decrypt configurations and traffic, recover passwords, perform man-in-the-middle and passive decryption attacks, and gain full control of affected PLC families (CVE-2022-38465, CVSS 9.3). Siemens released firmware and TIA Portal updates (introducing a PKI/TLS-based system) to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.