November 2020
Titel
Mitsubishi Electric GT14 Model of GOT1000 Series
Veröffentlicht
5. November 2020 16:10
Text
This advisory contains mitigations for Improper Restriction of Operations within the Bounds of a Memory Buffer, Session Fixation, NULL Pointer Dereference, Improper Access Control, Argument Injection, and Resource Management Errors vulnerabilities in Mitsubishi Electric GT14 model of GOT1000 Series graphic operation terminals.
Titel
Mitsubishi Electric Factory Automation Engineering Products (Update A)
Veröffentlicht
5. November 2020 16:05
Text
This updated advisory is a follow-up to the original advisory titled ICSA-20-212-04 Mitsubishi Electric Factory Automation Engineering Products that was published July 30, 2020, to the ICS webpage to us-cert.cisa.gov. This advisory contains mitigations for an Unquoted Search Path or Element vulnerability in Mitsubishi Electric Factory Automation Engineering products.
Titel
Mitsubishi Electric MELSEC iQ-R Series (Update B)
Veröffentlicht
5. November 2020 16:00
Text
This updated advisory is a follow-up to the advisory update titled ICSA-20-161-02 Mitsubishi Electric MELSEC iQ-R Series (Update A) that was published June 16, 2020 to the ICS webpage to us-cert.cisa.gov. This advisory contains mitigations for a resource exhaustion vulnerability in the Mitsubishi Electric MELSEC iQ-R series programmable logic controllers.
Titel
WAGO Series 750-88x and 750-352
Veröffentlicht
3. November 2020 16:10
Text
This advisory contains mitigations for an Uncontrolled Resource Consumption vulnerability in the WAGO Fieldbus Ethernet coupler.
Titel
NEXCOM NIO50
Veröffentlicht
3. November 2020 16:05
Text
This advisory contains mitigations for Improper Input Validation, and Cleartext Transmission of Sensitive Information vulnerabilities in NEXCOM's NIO50 IoT Gateway.
Titel
ARC Informatique PcVue
Veröffentlicht
3. November 2020 16:00
Text
This advisory contains mitigations for Deserialization of Untrusted Data, Access to Critical Private Variable via Public Method, and Information Exposure of Sensitive Information to an Unauthorized Actor vulnerabilities in ARC Information PcVue SCADA products.
Oktober 2020
Titel
AA20-304A: Iranian Advanced Persistent Threat Actor Identified Obtaining Voter Registration Data
Veröffentlicht
30. Oktober 2020 19:11
Text
Original release date: October 30, 2020 | Last revised: November 3, 2020SummaryThis advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) version 8 framework. See the ATT&CK for Enterprise version 8 for all referenced threat actor techniques. This joint cybersecurity advisory was coauthored by the Cybersecurity and Infrastructure ...
Titel
Mitsubishi Electric MELSEC iQ-R, Q and L Series
Veröffentlicht
29. Oktober 2020 15:15
Text
This advisory contains mitigations for an Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric's MELSEC iQ-R, Q and L Series programmable logic controllers.
Titel
Mitsubishi Electric MELSEC iQ-R
Veröffentlicht
29. Oktober 2020 15:10
Text
This advisory contains mitigations for Improper Restriction of Operations within the Bounds of a Memory Buffer, Session Fixation, NULL Pointer Dereference, Improper Access Control, Argument Injection, and Resource Management Errors vulnerabilities in Mitsubishi Electric's iQ-R programmable logic controllers.
Titel
Mitsubishi Electric MELSEC iQ-R Series (Update A)
Veröffentlicht
29. Oktober 2020 15:05
Text
This updated advisory is a follow-up to the original advisory titled ICSA-20-282-02 Mitsubishi Electric MELSEC iQ-R Series that was published October 8, 2020, to the ICS webpage on us-cert.cisa.gov. This advisory contains mitigations for an Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R Series modules.
Titel
AA20-302A: Ransomware Activity Targeting the Healthcare and Public Health Sector
Veröffentlicht
29. Oktober 2020 00:07
Text
Original release date: October 28, 2020 | Last revised: November 2, 2020SummaryThis advisory was updated to include information on Conti, TrickBot, and BazarLoader, including new IOCs and Yara Rules for detection. This advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) version 7 framework. See the ATT&CK for ...
Titel
AA20-301A: North Korean Advanced Persistent Threat Focus: Kimsuky
Veröffentlicht
27. Oktober 2020 18:00
Text
Original release date: October 27, 2020SummaryThis advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) version 7 framework. See the ATT&CK for Enterprise version 7 for all referenced threat actor tactics and techniques. This joint cybersecurity advisory was coauthored by the Cybersecurity and Infrastructure Security Agency (CISA), the ...
Titel
AA20-296B: Iranian Advanced Persistent Threat Actors Threaten Election-Related Systems
Veröffentlicht
22. Oktober 2020 18:00
Text
Original release date: October 22, 2020SummaryThe Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) are warning that Iranian advanced persistent threat (APT) actors are likely intent on influencing and interfering with the U.S. elections to sow discord among voters and undermine public confidence in the ...
Titel
B. Braun OnlineSuite
Veröffentlicht
22. Oktober 2020 16:05
Text
This advisory contains mitigations for Relative Path Traversal, Uncontrolled Search Path Element, and Improper Neutralization of Formula Elements in a CSV File vulnerabilities in B. Braun's OnlineSuite.
Titel
B. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplus
Veröffentlicht
22. Oktober 2020 16:00
Text
This advisory contains mitigations for Cross-site Scripting, Open Redirect, XPath Injection, Session Fixation, Use of a One-way Hash without a Salt, Relative Path Traversal, Improper Verification of Cryptographic Signature, Improper Privilege Management, Use of Hard-coded Credentials, Active Debug Code, and Improper Access Control vulnerabilities in B. Braun's SpaceCom, Battery Pack ...
Titel
AA20-296A: Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets
Veröffentlicht
22. Oktober 2020 14:44
Text
Original release date: October 22, 2020SummaryThis joint cybersecurity advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework. See the ATT&CK for Enterprise framework for all referenced threat actor tactics and techniques This joint cybersecurity advisory—written by the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure ...
Titel
Rockwell Automation 1794-AENT Flex I/O Series B
Veröffentlicht
20. Oktober 2020 16:15
Text
This advisory contains mitigations for several Classic Buffer Overflow vulnerabilities in Rockwell Automation's 1794-AENT Flex I/O Series B Ethernet/IP adapter.
Titel
Hitachi ABB Power Grids XMC20 Multiservice-Multiplexer
Veröffentlicht
20. Oktober 2020 16:10
Text
This advisory contains mitigations for an Improper Authentication vulnerability in Hitachi ABB Power Grids' XMC20 Multiservice-Multiplexer telecommunication elements.
Titel
Capsule Technologies SmartLinx Neuron 2 (Update A)
Veröffentlicht
20. Oktober 2020 16:00
Text
This updated advisory is a follow-up to the original advisory titled ICSMA-20-196-01 Capsule Technologies SmartLinx Neuron 2 that was published July 14, 2020, to the ICS webpage on us-cert.cisa.gov. This advisory contains mitigations for a Protection Mechanism Failure vulnerability in Capsule Technologies' SmartLinx Neuron 2, a bedside mobile clinical monitoring ...
Titel
Advantech R-SeeNet
Veröffentlicht
15. Oktober 2020 16:05
Text
This advisory contains mitigations for an SQL Injection vulnerability in Advantech;s R-SeeNet monitoring application software.
Titel
Wibu-Systems CodeMeter (Update C)
Veröffentlicht
15. Oktober 2020 16:00
Text
This updated advisory is a follow-up to the advisory update titled ICSA-20-203-01 Wibu-Systems CodeMeter (Update B) that was published October 1, 2020, to the ICS webpage on us-cert.gov. This advisory contains mitigations for Buffer Access with Incorrect Length Value, Inadequate Encryption Strength, Origin Validation Error, Improper Input Validation, Improper Verification ...
Titel
MOXA NPort IAW5000A-I/O Series
Veröffentlicht
13. Oktober 2020 16:45
Text
This advisory contains mitigations for Session Fixation, Improper Privilege Management, Weak Password Requirements, Cleartext Transmission of Sensitive Information, Improper Restriction of Excessive Authentication Attempts, and Exposure of Sensitive Information to an Unauthorized Actor vulnerabilities in the MOXA NPort IAW5000A-I/O Series integrated serial device server.
Titel
SSA-398519 (Last Update: 2020-10-13): Vulnerabilities in Intel CPUs (November 2019)
Veröffentlicht
13. Oktober 2020 02:00
Text
Intel has published information on vulnerabilities in Intel products in November 2019. In this advisory Siemens only explicitly mentions the vulnerabilities from the “Intel® CPU Security Advisory” and one vulnerability from “Intel® CSME, Intel® SPS, Intel® TXE, Intel® AMT, Intel® PTT and Intel® DAL Advisory” and lists the Siemens IPC ...
Titel
SSA-534763 (Last Update: 2020-10-13): Special Register Buffer Data Sampling (SRBDS) aka Crosstalk in Industrial Products
Veröffentlicht
13. Oktober 2020 02:00
Text
Security researchers published information on a vulnerability known as Crosstalk (INTEL-SA-00320). This vulnerability affects modern Intel processors to a varying degree. Several Siemens Industrial Products contain processors that are affected by the vulnerability. Siemens is preparing updates and recommends specific countermeasures until fixes are available.
Titel
SSA-462066 (Last Update: 2020-10-13): Vulnerability known as TCP SACK PANIC in Industrial Products
Veröffentlicht
13. Oktober 2020 02:00
Text
Multiple industrial products are affected by a vulnerability in the kernel known as TCP SACK PANIC. The vulnerability could allow a remote attacker to cause a denial of service condition. Siemens has released updates for several affected products and recommends to update to the new versions. Siemens is preparing further ...

Letzte Updates

BOSCH PSIRT
20.03.2024
CODESYS
28.06.2023
SIEMENS CERT
19.04.2024
US CERT
17.04.2024
US CERT (ICS)
18.04.2024

Nach Quelle

Archiv

2024
2023
2022
2021
2020
2019
2018
2017

Feeds