In 2022, Technion researchers reported that Siemens’ SIMATIC S7-1500 software controller running on the ET 200SP Open Controller had a boot process they could modify and firmware they could decrypt using a hardcoded key. They also described a separate route for replacing PLC firmware from a Windows virtual machine with local administrator access. Those findings concern the specific platform examined; they do not establish that every S7-1500 model, firmware version, or installation is affected.
Which Siemens controller did the researchers examine?
SecurityWeek reported on August 12, 2022, that researchers at Technion analyzed the SIMATIC S7-1500 software controller running on Siemens’ ET 200SP Open Controller. The report described this as a PC-based PLC platform combining industrial-PC flexibility with PLC security.
According to the report, the hardware used an Intel Atom CPU and a hypervisor that managed Windows and Adonis Linux virtual machines. The Adonis Linux environment, referred to as SWCPU, ran the PLC logic and functions. These are details reported about the platform in the 2022 account, not results of new testing. SecurityWeek’s August 12, 2022 report provides the original account.
What security issues did they report?
A modifiable boot process and decryptable firmware
SecurityWeek said the SWCPU firmware was encrypted and decrypted by the hypervisor during boot. The researchers reported that the boot process allowed filesystem reading and modification, including access to hypervisor binaries and encrypted SWCPU firmware. They said they could decrypt the firmware with a hardcoded key; Siemens confirmed the hardcoded-key point to the researchers, according to the report. Siemens characterized the encryption as a way to protect intellectual property.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
This describes the researchers’ 2022 findings and the confirmation attributed to Siemens in that reporting. It is not evidence of fresh independent testing or a statement that every Siemens PLC firmware image can be decrypted.
A firmware-replacement path requiring Windows administrator access
The report also described a way for someone with local administrator access on the Windows virtual machine to replace PLC firmware so a malicious version would run after reboot. SecurityWeek said the full details had not been disclosed at Black Hat 2022. According to the researchers’ account in the article, Siemens had been notified but had not fully assessed the issue at that time. The report does not establish whether the path was later disclosed, resolved, or remains exploitable.
What does the reported “99%” software overlap mean?
Technion researcher Sara Bitan told SecurityWeek that the open controller “shares 99% of software with S7-1500,” and argued that firmware decryption could expose the wider product line to attacks exploiting known vulnerabilities. The figure should be read narrowly: it is Bitan’s reported claim in a 2022 article, not an independently verified measurement here.
It does not show that every S7-1500 model, firmware version, or deployment has identical software or the same exposure. Nor does the reported overlap by itself establish that every vulnerability affecting one configuration applies to all others. Operators need to identify their exact product and software or firmware version and consult Siemens’ notices for that configuration.
Rank #3
What did Siemens say, and what should operators do?
In its statement to SecurityWeek in 2022, Siemens said customer installations were “not directly impacted by this research.” It recommended that customers monitor Siemens security advisories continuously, install the latest available patches, use defense-in-depth for plant operations, and configure environments according to Siemens’ industrial security guidelines. That statement is Siemens’ response at the time of the article, not a current assessment of every installation.
- Identify the installed equipment and version. Record the exact controller, product family, and software or firmware version; do not assume that a notice for one S7 product applies to every model.
- Check the relevant Siemens advisory. Compare the installed product and version with the affected-product details in the notice.
- Apply the specified fix or mitigation. Follow the advisory for the particular version. If a fix is pending, use the mitigation Siemens specifies; a universal remediation version is not established here.
- Maintain defense in depth. Configure the plant environment in line with Siemens’ operational guidance for industrial security and keep monitoring official advisories.
What is the current Siemens advisory context?
Siemens ProductCERT advisory SSA-688146, published May 12, 2026 and updated July 14, 2026, concerns multiple cross-site scripting vulnerabilities in SIMATIC S7 PLC web servers. It lists the ET 200SP Open Controller among affected product families and recommends updates where available, with mitigations where fixes are pending. Consult Siemens ProductCERT advisory SSA-688146 for the affected versions and current mitigation details.
Rank #4
This 2026 web-server advisory is separate from the Technion research reported in 2022. Its existence does not confirm the earlier hardcoded-key or firmware-replacement findings.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →

