ics-otregulatorNewsThe Broadside1 min read

CISA Flags Copy Fail Vulnerability in Siemens SIMATIC Panels

HMI Unified Comfort and Comfort Pro panels are patched at version 21.0.2.1; several other product lines, including AX Runtime and IoT2050, get only countermeasures while Siemens works on fixes.


TL;DR

CISA issued an advisory for CVE-2026-31431, a vulnerability in Siemens SIMATIC and SIPLUS products that Siemens calls "Copy Fail." Siemens has released version 21.0.2.1 for its HMI Unified Comfort and Comfort Pro panels, which resolves the flaw. For the SIMATIC AX Runtime, IoT2050, Industrial Edge Device OS, S7-1500 TM MFP, and CN 4100, no patch is yet available, Siemens recommends countermeasures while fixes are prepared.

The advisory covers a wide product range: dozens of SIMATIC HMI panel variants spanning the MTP400 through MTP2200 lines in Unified Comfort, Comfort Pro, and Unified Basic configurations, plus their SIPLUS ruggedized equivalents. All versions below 21.0.2.1 are affected for the HMI panels. The fix for those is straightforward: update to 21.0.2.1 or later.

Four additional product lines (SIMATIC AX Runtime Core Linux, IoT2050 Advanced, IPC Industrial Edge Device OS (IED-OS), and S7-1500 TM MFP) are affected across all versions, along with the SIMATIC CN 4100 below version 6.0. Siemens hasn't released patches for these and hasn't provided a timeline. The advisory recommends countermeasures, but CISA's summary doesn't detail what those countermeasures are. Operators of these devices should check Siemens' ProductCERT advisory directly for mitigations.

CISA's advisory doesn't include a CVSS score, attack vector, or description of what successful exploitation actually enables, just the "Copy Fail" label. That absence matters for organizations that triage by severity. Without a score, this one lands in the read-the-advisory-and-decide pile.


Published ·Deep Fathom