• 1 (current)
  • 2
Donnerstag, 25.02.2021
Titel
PerFact OpenVPN-Client
Veröffentlicht
25. Februar 2021 16:15
Text
This advisory contains mitigations for an External Control of System or Configuration Setting vulnerability in the PerFact OpenVPN-Client.
Titel
Fatek FvDesigner
Veröffentlicht
25. Februar 2021 16:10
Text
This advisory contains mitigations for Use After Free, Access of Uninitialized Pointer, Stack-based Buffer Overflow, Out-of-Bounds Write, and Out-of-Bounds Read vulnerabilities in Fatek FvDesigner software.
Titel
Rockwell Automation Logix Controllers
Veröffentlicht
25. Februar 2021 16:05
Text
This advisory contains mitigations for a n Insufficiently Protected Credentials vulnerability in Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, and Logix Controllers.
Titel
ProSoft Technology ICX35
Veröffentlicht
25. Februar 2021 16:00
Text
This advisory contains mitigations for a Permissions, Privileges, and Access Controls vulnerability in ProSoft Technology ICX35 industrial cellular gateways.
Mittwoch, 24.02.2021
Titel
AA21-055A: Exploitation of Accellion File Transfer Appliance
Veröffentlicht
24. Februar 2021 15:00
Text
Original release date: February 24, 2021 | Last revised: February 25, 2021SummaryThis joint advisory is the result of a collaborative effort by the cybersecurity authorities of Australia,[1] New Zealand,[2] Singapore,[3] the United Kingdom,[4] and the United States.[5][6] These authorities are aware of cyber actors exploiting vulnerabilities in Accellion File Transfer ...
Titel
Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products
Veröffentlicht
24. Februar 2021 01:00
Text

BOSCH-SA-372917: Linux kernel versions through 5.10.11 contain weaknesses which allow local users to execute code in the kernel with the potential to escalate privileges [1][2]. In versions of sudo before 1.9.5p2 there is a weakness present which allows privilege escalation to root for local users [3]. The ctrlX CORE and ...

Dienstag, 23.02.2021
Titel
Rockwell Automation FactoryTalk Services Platform
Veröffentlicht
23. Februar 2021 16:10
Text
This advisory contains mitigations for a Use of Password Hash with Insufficient Computational Effort vulnerability in the Rockwell Automation FactoryTalk Services Platform.
Titel
Advantech BB-ESWGP506-2SFP-T
Veröffentlicht
23. Februar 2021 16:05
Text
This advisory contains mitigations for a Use of Hard-coded Credentials vulnerability in Advantech BB-ESWGP506-2SFP-T industrial ethernet switches.
Titel
Advantech Spectre RT Industrial Routers
Veröffentlicht
23. Februar 2021 16:00
Text
This advisory contains mitigations for Improper Neutralization of Input During Web Page Generation, Cleartext Transmission of Sensitive Information, Improper Restriction of Excessive Authentication Attempts, Use of a Broken or Risky Cryptographic Algorithm, and Use of Platform-Dependent Third-party Components vulnerabilities in Advantech Spectre RT Industrial Routers.
Mittwoch, 17.02.2021
Titel
AA21-048A: AppleJeus: Analysis of North Korea’s Cryptocurrency Malware
Veröffentlicht
17. Februar 2021 17:00
Text
Original release date: February 17, 2021 | Last revised: March 2, 2021SummaryThis Advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework. See the ATT&CK for Enterprise for all referenced threat actor tactics and techniques. This joint advisory is the result of analytic efforts among the Federal Bureau ...
Donnerstag, 11.02.2021
Titel
AA21-042A: Compromise of U.S. Water Treatment Facility
Veröffentlicht
11. Februar 2021 20:15
Text
Original release date: February 11, 2021 | Last revised: February 12, 2021SummaryOn February 5, 2021, unidentified cyber actors obtained unauthorized access to the supervisory control and data acquisition (SCADA) system at a U.S. drinking water treatment facility. The unidentified actors used the SCADA system’s software to increase the amount of ...
Titel
Multiple Embedded TCP/IP stacks
Veröffentlicht
11. Februar 2021 16:10
Text
This advisory contains mitigations for Use of Insufficiently Random Values vulnerabilities in Nut/Net, CycloneTCP, NDKTCPIP, FNET, uIP-Contiki-OS, uC/TCP-IP, uIP-Contiki-NG, uIP, picoTCP-NG, picoTCP, MPLAB Net, Nucleus NET, Nucleus ReadyStart TCP/IP stacks.
Titel
Rockwell Automation DriveTools SP and Drives AOP
Veröffentlicht
11. Februar 2021 16:05
Text
This advisory contains mitigations for an Uncontrolled Search Path Element vulnerability in Rockwell Automation DriveTools SP and Drives AOP software.
Titel
Wibu-Systems CodeMeter (Update E)
Veröffentlicht
11. Februar 2021 16:00
Text
This updated advisory is a follow-up to the advisory update titled ICSA-20-203-01 Wibu-Systems CodeMeter (Update D) that was published December 3, 2020, to the ICS webpage on us-cert.gov. This advisory contains mitigations for Buffer Access with Incorrect Length Value, Inadequate Encryption Strength, Origin Validation Error, Improper Input Validation, Improper Verification ...
Dienstag, 09.02.2021
Titel
GE Digital HMI/SCADA iFIX
Veröffentlicht
9. Februar 2021 17:50
Text
This advisory contains mitigations for Incorrect Permission Assignment for Critical Resource vulnerabilities in the GE Digital HMI/SCADA iFIX software component.
Titel
Siemens SINEMA Server & SINEC NMS
Veröffentlicht
9. Februar 2021 17:40
Text
This advisory contains mitigations for a Path Traversal vulnerability in Siemens SINEMA server and SINEC NMS products.
Titel
Siemens RUGGEDCOM ROX II
Veröffentlicht
9. Februar 2021 17:35
Text
This advisory contains mitigations for Improper Input Validation, NULL Pointer Dereference, Out-of-Bounds Write, Insufficient Verification of Data Authenticity, Improper Certificate Validation, and Out-of-bounds Read vulnerabilities in Siemens RUGGEDCOM ROX II products.
Titel
Siemens TIA Administrator
Veröffentlicht
9. Februar 2021 17:30
Text
This advisory contains mitigations for an Improper Access Control vulnerability in Siemens TIA Administrator products.
Titel
Siemens SCALANCE W780 and W740
Veröffentlicht
9. Februar 2021 17:20
Text
This advisory contains mitigations for an Allocation of Resources Without Limits or Throttling vulnerability in Siemens SCALANCE W780 and W740 industrial wireless LAN products.
Titel
SSA-100232 V1.2 (Last Update: 2021-02-09): Denial-of-Service vulnerability in SCALANCE X Switches
Veröffentlicht
9. Februar 2021 01:00
Text
A vulnerability in several SCALANCE X devices could allow an unauthenticated attacker with network access to an affected device to perform a denial-of-service. Siemens has released an update for SCALANCE X-200IRT and recommends to update to the latest version. Siemens recommends specific countermeasures for products where updates are not, or ...
Titel
SSA-102233 V1.5 (Last Update: 2021-02-09): SegmentSmack in VxWorks-based Industrial Devices
Veröffentlicht
9. Februar 2021 01:00
Text
The products listed below contain a vulnerability that could allow remote attackers to affect the availability of the devices under certain conditions. The underlying TCP stack can be forced to make very computation expensive calls for every incoming packet which can lead to a Denial-of-Service. Siemens has released an update ...
Titel
SSA-139628 V1.1 (Last Update: 2021-02-09): Vulnerabilities in Web Server for Scalance X Products
Veröffentlicht
9. Februar 2021 01:00
Text
Several SCALANCE X switches contain vulnerabilities in the web server of the affected devices. An unauthenticated attacker could reboot, cause denial-of-service conditions and potentially impact the system by other means through heap and buffer overflow vulnerabilities. Siemens has released updates for several affected products and recommends to update to the ...
Titel
SSA-274900 V1.1 (Last Update: 2021-02-09): Use of hardcoded key in Scalance X devices under certain conditions
Veröffentlicht
9. Februar 2021 01:00
Text
Scalance X devices might not generate a unique random key after factory reset, and use a private key shipped with the firmware Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens is preparing further updates and recommends specific countermeasures for products where ...
Titel
SSA-349422 V1.5 (Last Update: 2021-02-09): Denial-of-Service in Industrial Real-Time (IRT) Devices
Veröffentlicht
9. Februar 2021 01:00
Text
A vulnerability in the affected products could allow an unauthorized attacker with network access to perform a denial-of-service attack resulting in loss of real-time synchronization. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens is preparing further updates and recommends specific countermeasures ...
Titel
SSA-398519 V1.5 (Last Update: 2021-02-09): Vulnerabilities in Intel CPUs (November 2019)
Veröffentlicht
9. Februar 2021 01:00
Text
Intel has published information on vulnerabilities in Intel products in November 2019. In this advisory Siemens only explicitly mentions the vulnerabilities from the “Intel® CPU Security Advisory” and one vulnerability from “Intel® CSME, Intel® SPS, Intel® TXE, Intel® AMT, Intel® PTT and Intel® DAL Advisory” and lists the Siemens IPC ...
  • 1 (current)
  • 2

Letzte Updates

BOSCH PSIRT
04.10.2021
CODESYS
19.11.2021
SIEMENS CERT
09.11.2021
US CERT
17.11.2021
US CERT (ICS)
18.11.2021

Nach Quelle

Archiv

2021
2020
2019
2018
2017

Feeds