contains security-relevant product improvements which increase the robustness.
Firmware update for SCALANCE XB-200, XC-200, XP-200, XF-200BA and XR-300WG, Firmware V4.7
Firmware version V4.7 is now provided as a download for the SCALANCE XB-200, XC-200, XP-200, XF-200BA, XF-200BA DNA and XR-300WG.
The latest firmware update for SCALANCE XB-200, XC-200, XP-200, XF-200BA and XR-300WG, Firmware V4.7, implements security fixes and improvements.
Security Fixes and Improvements:
- This version contains security-relevant product improvements which increase the robustness. Upgrading to this version is recommended.
- Please subscribe to the Siemens Security Advisories on: https://www.siemens.com/global/en/products/services/cert.html
Features
- Topology change notices for STP/RSTP environments now include critical port and MAC address details for enhanced troubleshooting.
- RADIUS user logins and test authentication now send NAS-ID
- RADIUS now supports TLS encryption
- CMP Client functionality is integrated for secure certificate management and renewal
- DHCP server now offers BOOTP client support
- Certificate expiration monitoring now provides proactive alerts
- C-PLUG can now be activated / deactivated
- Central device can now be configured as client when using multiple MRP rings
IEC 62443-4-2 SL2 Requirements
- FW V4.7 lays the essential groundwork for an advanced cybersecurity feature: integrity of the boot process. This capability, vital for meeting IEC 62443-4-2 CR 3.14 + RE1 (Integrity of the Boot Process), will be activated exclusively at the factory at a later date for future product deployments, providing additional protection for devices.
More details on the activation timeline and important considerations can be found here: 109999457 - For a summary of all other fulfilled IEC 62443-4-2 requirements, please refer to the Declaration of Conformity for SCALANCE X devices: 109977121
The following functions/improvements were implemented:
Support of additional SFPs
- B-SFP991-1 6GK5991-1AD01-8AA0
- B-SFP991-1LD 6GK5991-1AF01-8AA0
- B-SFP992-1 6GK5992-1AL01-8AA0
- B-SFP992-1LD 6GK5992-1AM01-8AA0
- B-SFP993-1LD 6GK5993-1AU01-8AA0
Known Errors:
- If operating two XF204 DNA devices in a redundant configuration, deactivate neighbor monitoring on switch ports connected to DNA client ports. Failure to do so may prevent proper neighbor detection.
Workaround: revert to FW V4.6.

