April 2018
Titel
Rockwell Automation Stratix Industrial Managed Ethernet Switch
Veröffentlicht
17. April 2018 16:00
Text
This advisory includes mitigations for improper imput validation, resource managment, 7PK, memory buffer and externally-controlled format string vulnerabilities in Rockwell Automation's Stratix Industrial Managed Switch.
Titel
SSA-203306 (Last Update: 2018-04-17): Password Vulnerabilities in SIPROTEC 4 and SIPROTEC Compact Relay Families
Veröffentlicht
17. April 2018 02:00
Text
SIPROTEC 4 and SIPROTEC Compact devices could allow access authorization passwords to be reconstructed or overwritten via engineering mechanisms that involve DIGSI 4 and EN100 Ethernet communication modules. Siemens has released updates for several affected products, is working on updates for the remaining affected products, and recommends specific countermeasures until ...
Titel
SSA-845879 (Last Update: 2018-04-17): Firmware Downgrade Vulnerability in EN100 Ethernet Communication Module for SIPROTEC 4, SIPROTEC Compact and Reyrolle
Veröffentlicht
17. April 2018 02:00
Text
The EN100 Ethernet communication module, which is an optional extension for SIPROTEC 4, SIPROTEC Compact and Reyrolle devices, allows an unauthenticated upload of firmware updates to the communication module in affected versions. Siemens has released updates for several affected products, is working on updates for the remaining affected products, and ...
Titel
Yokogawa CENTUM and Exaopc
Veröffentlicht
12. April 2018 16:05
Text
This advisory includes mitigations for a permissions, privileges, and access controls vulnerability in the Yokogawa CENTUM series and Exaopc products.
Titel
ATI Systems Emergency Mass Notification Systems
Veröffentlicht
10. April 2018 16:05
Text
This advisory includes mitigations for improper authentication and missing encryption of sensitive data vulnerabilities in the ATI Systems Emergency Mass Notification Systems.
Titel
Omron CX-One
Veröffentlicht
10. April 2018 16:00
Text
This advisory includes mitigations for heap-based buffer overflow, stack-based buffer overflow, and type confusion vulnerabilities in Omron CX-One software.
Titel
Rockwell Automation MicroLogix
Veröffentlicht
5. April 2018 17:26
Text
This advisory includes mitigations for an improper authentication vulnerability in the Rockwell MicroLogix Controller.
Titel
Moxa MXview
Veröffentlicht
5. April 2018 16:05
Text
This advisory includes mitigations for an information exposure vulnerability in the Moxa MXview network management software.
Titel
SSA-901333 (Last Update: 2018-04-05): KRACK Attacks Vulnerabilities in Industrial Products
Veröffentlicht
5. April 2018 02:00
Text
Multiple vulnerabilities affecting WPA/WPA2 implementations were identified by a researcher and publicly disclosed under the term "Key Reinstallation Attacks" (KRACK). These vulnerabilities could potentially allow an attacker within the radio range of the wireless network to decrypt, replay or inject forged network packets into the wireless communication. Several Siemens Industrial ...
Titel
SSA-689071 (Last Update: 2018-04-05): DNSMasq Vulnerabilities in SCALANCE W1750D, SCALANCE M800 and SCALANCE S615
Veröffentlicht
5. April 2018 02:00
Text
Multiple vulnerabilities have been identified in SCALANCE W1750D, SCALANCE M800, and SCALANCE S615 devices. The highest scored vulnerability could allow a remote attacker to crash the DNS service or execute arbitrary code. The attacker must be able to craft malicious DNS responses and inject them into the network in order ...
Titel
Siemens Building Technologies Products (Update A)
Veröffentlicht
3. April 2018 16:00
Text
This updated advisory is a follow-up to the original advisory titled ICSA-18-093-01 Siemens Building Technologies Products that was published April 3, 2018, on the NCCIC/ICS-CERT website. This advisory update includes mitigations for a series of vulnerabilities in Siemens' Building Technologies Products, including stack-based buffer overflows, security features, improper restriction of ...
Titel
Siemens Building Technologies Products
Veröffentlicht
3. April 2018 16:00
Text
This advisory includes mitigations for a series of vulnerabilities in Siemens' Building Technologies Procucts, including stack-based buffer overflow, external control of system or configuration setting, improper restriction ofoperations within the bounds of a memory buffer, NULL pointer deference, XML entity expansion, heap-based buffer overflow, and improper access control.
Titel
SSA-727467 (Last Update: 2018-04-03): Vulnerabilities in Building Technologies Products
Veröffentlicht
3. April 2018 02:00
Text
The License Management System (LMS), which is used by multiple Siemens' building automation products, includes a vulnerable version of Gemalto Sentinel LDK RTE. Gemalto Sentinel LDK RTE is affected by multiple vulnerabilities that could allow remote code execution. Siemens recommends to update the License Management System used by these products ...
März 2018
Titel
Philips iSite/IntelliSpace PACS Vulnerabilities
Veröffentlicht
29. März 2018 20:35
Text
This advisory includes mitigation recommendations for vulnerabilities identified in the Philips Philips iSite and IntelliSpace PACS.
Titel
WAGO 750 Series
Veröffentlicht
29. März 2018 18:15
Text
This advisory includes mitigations for an improper resource shutdown or release vulnerability in the WAGO 750 series PLC.
Titel
Siemens TIM 1531 IRC
Veröffentlicht
29. März 2018 18:10
Text
This advisory includes mitigations for an incorrect implementation of authentication algorithm vulnerability in the Siemens TIM 1531 IRC communications modules.
Titel
Siemens SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional, and SIMATIC NET PC Software
Veröffentlicht
29. März 2018 18:05
Text
This advisory includes mitigations for an improper input validation vulnerability in the Siemens SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional, and SIMATIC NET PC Software.
Titel
SSA-727467 (Last Update: 2018-03-28): Vulnerabilities in Building Technologies Products
Veröffentlicht
28. März 2018 02:00
Text
The License Management System (LMS), which is used by multiple Siemens' building automation products, includes a vulnerable version of Gemalto Sentinel LDK RTE. Gemalto Sentinel LDK RTE is affected by multiple vulnerabilities that could allow remote code execution. Siemens recommends to update the License Management System used by these products ...
Titel
Schneider Electric Modicon Premium, Modicon Quantum, Modicon M340, and Modicon BMXNOR0200
Veröffentlicht
27. März 2018 16:05
Text
This advisory includes mitigations for several vulnerabilities in the Schneider Electric Modicon Premium, Modicon Quantum, Modicon M340, and Modicon BMXNOR0200 PLCs.
Titel
Philips Alice 6 Vulnerabilities
Veröffentlicht
27. März 2018 16:00
Text
This advisory includes mitigation recommendations for improper authentication and missing data encryption vulnerabilities identified in the Philips Alice 6 System product.
Titel
SSA-592007 (Last Update: 2018-03-27): Denial-of-Service Vulnerability in Industrial Products
Veröffentlicht
27. März 2018 02:00
Text
Several industrial controllers are affected by a security vulnerability that could allow an attacker to cause a Denial-of-Service condition via PROFINET DCP network packets under certain circumstances. Precondition for this scenario is a direct OSI Layer 2 access to the affected products. PROFIBUS interfaces are not affected. Siemens has released ...
Titel
SSA-348629 (Last Update: 2018-03-27): Denial-of-Service Vulnerability in SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional and SIMATIC NET PC Software
Veröffentlicht
27. März 2018 02:00
Text
A Denial-of-Service vulnerability has been identified in SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional and SIMATIC NET PC-Software. Siemens has released updates for several affected products and recommends that customers update to the new version. Siemens is preparing further updates and recommends specific countermeasures until patches are available.
Titel
SSA-110922 (Last Update: 2018-03-27): Web Vulnerability in TIM 1531 IRC
Veröffentlicht
27. März 2018 02:00
Text
The latest update for TIM 1531 IRC fixes a security vulnerability that could allow unauthorized remote attackers to perform administrative operations on the device. Siemens recommends updating as soon as possible.
Titel
Siemens SIMATIC WinCC OA UI Mobile App
Veröffentlicht
22. März 2018 15:05
Text
This advisory includes mitigations for an improper access control vulnerability in the Siemens WinCC OA UI mobile app for Android and IOS.
Titel
Beckhoff TwinCAT
Veröffentlicht
22. März 2018 15:00
Text
This advisory includes mitigations for an untrusted pointer dereference vulnerability in the Beckhoff TwinCAT PLC products.

Letzte Updates

BOSCH PSIRT
04.10.2021
CODESYS
19.11.2021
SIEMENS CERT
09.11.2021
US CERT
17.11.2021
US CERT (ICS)
18.11.2021

Nach Quelle

Archiv

2021
2020
2019
2018
2017

Feeds