• 1
  • 2 (current)
  • 3
Donnerstag, 11.05.2023
Titel
Siemens SCALANCE LPE9403
Veröffentlicht
11. Mai 2023 14:00
Text
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global). 1. EXECUTIVE SUMMARY CVSS v3 ...
Mittwoch, 10.05.2023
Titel
Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG
Veröffentlicht
10. Mai 2023 23:35
Text
SUMMARY The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint Cybersecurity Advisory (CSA) in response to the active exploitation of CVE-2023-27350. This vulnerability occurs in certain versions of PaperCut NG and PaperCut MF and enables an unauthenticated actor to execute malicious code ...
Dienstag, 09.05.2023
Titel
Hitachi Energy MSM
Veröffentlicht
9. Mai 2023 14:00
Text
1. EXECUTIVE SUMMARY CVSS v3 9.8 ATTENTION: Exploitable remotely/low attack complexity Vendor: Hitachi Energy Equipment: Modular Switchgear Monitoring (MSM) Vulnerabilities: Improper Restriction of Excessive Authentication Attempts, Authentication Bypass by Capture-replay, Code Injection, Improper Restriction of Operations within the Bounds of a Memory Buffer, NULL Pointer Dereference, Insufficient Entropy 2. RISK ...
Titel
SSA-113131 V1.5 (Last Update: 2023-05-09): Denial of Service Vulnerabilities in SIMATIC S7-400 CPUs
Veröffentlicht
9. Mai 2023 02:00
Text
Two vulnerabilities have been identified in the SIMATIC S7-400 CPU family that could allow an attacker to cause a denial of service condition. In order to exploit the vulnerabilities, an attacker must have access to the affected devices on port 102/tcp via Ethernet, PROFIBUS or Multi Point Interfaces (MPI). Siemens ...
Titel
SSA-932528 V1.0: Multiple File Parsing Vulnerabilities in Solid Edge
Veröffentlicht
9. Mai 2023 02:00
Text
Solid Edge is affected by multiple memory corruption vulnerabilities that could be triggered when the application reads specially crafted files in various formats such as IFC, OBJ or STP format. If a user is tricked to open a malicious file with the affected application, an attacker could leverage the vulnerability ...
Titel
SSA-892048 V1.0: Third-Party Component Vulnerabilities in SINEC NMS before V1.0.3.1
Veröffentlicht
9. Mai 2023 02:00
Text
Multiple vulnerabilities affecting third-party components libexpat and libcurl of SINEC NMS before V1.0.3.1 could allow an attacker to impact SINEC NMS confidentiality, integrity and availability. Siemens has released an update for SINEC NMS and recommends to update to the latest version.
Titel
SSA-789345 V1.0: Code Execution Vulnerabilities in Siveillance Video Event and Management Servers
Veröffentlicht
9. Mai 2023 02:00
Text
Both the Event Server and the Management Server components of Siveillance Video deserialize data without sufficient validations. This could allow an authenticated remote attacker to execute code on the affected system. Siemens has released updates for the affected products and recommends to update to the latest versions. The provided cumulative ...
Titel
SSA-712929 V2.0 (Last Update: 2023-05-09): Denial of Service Vulnerability in OpenSSL (CVE-2022-0778) Affecting Industrial Products
Veröffentlicht
9. Mai 2023 02:00
Text
A vulnerability in the openSSL component (CVE-2022-0778, [0]) could allow an attacker to create a denial of service condition by providing specially crafted elliptic curve certificates to products that use a vulnerable version of openSSL. Siemens has released updates for several affected products and recommends to update to the latest ...
Titel
SSA-686975 V1.1 (Last Update: 2023-05-09): IPU 2022.3 Vulnerabilities in Siemens Industrial Products using Intel CPUs
Veröffentlicht
9. Mai 2023 02:00
Text
Intel has published information on vulnerabilities in Intel products in November 2022. This advisory lists the related Siemens Industrial products affected by these vulnerabilities that can be patched by applying the corresponding BIOS update (“2022.3 IPU – BIOS Advisory” Intel-SA-00688). Siemens is preparing updates and recommends specific countermeasures for products ...
Titel
SSA-640968 V1.1 (Last Update: 2023-05-09): Untrusted Search Path Vulnerability in TIA Project-Server formerly known as TIA Multiuser Server
Veröffentlicht
9. Mai 2023 02:00
Text
TIA Project-Server formerly known as TIA Multiuser Server contains an untrusted search path vulnerability that could allow an attacker to escalate privileges, when tricking a legitimate user to start the service from an attacker controlled path. Siemens has released updates for several affected products and recommends to update to the ...
Titel
SSA-632164 V1.1 (Last Update: 2023-05-09): External Entity Injection Vulnerability in Polarion ALM
Veröffentlicht
9. Mai 2023 02:00
Text
Polarion ALM is vulnerable to XML External Entity (XXE) injection attack that could allow an attacker to potentially disclose confidential data. Siemens has released an update for Polarion ALM and recommends to update to the latest version.
Titel
SSA-592007 V2.1 (Last Update: 2023-05-09): Denial of Service Vulnerability in Industrial Products
Veröffentlicht
9. Mai 2023 02:00
Text
Several industrial controllers are affected by a security vulnerability that could allow an attacker to cause a denial of service condition via PROFINET DCP network packets under certain circumstances. Precondition for this scenario is a direct OSI Layer 2 access to the affected products. PROFIBUS interfaces are not affected. Siemens ...
Titel
SSA-566905 V1.1 (Last Update: 2023-05-09): Multiple Denial of Service Vulnerabilities in the Webserver of Industrial Products
Veröffentlicht
9. Mai 2023 02:00
Text
Multiple vulnerabilities in the affected products could allow an unauthorized attacker with network access to the webserver of an affected products to perform a denial of service attack. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens is preparing further updates and ...
Titel
SSA-555292 V1.0: Security Vulnerabilities Fixed in SIMATIC Cloud Connect 7 V2.1
Veröffentlicht
9. Mai 2023 02:00
Text
SIMATIC Cloud Connect 7 contains multiple vulnerabilities that could allow an attacker to impact its confidentiality, integrity and availability. Siemens has released updates for the affected products and recommends to update to the latest versions.
Titel
SSA-552874 V1.1 (Last Update: 2023-05-09): Denial of Service Vulnerability in SIPROTEC 5 Devices
Veröffentlicht
9. Mai 2023 02:00
Text
Devices of the SIPROTEC 5 family contain a vulnerability related to secure client-initiated renegotiation. This could allow an unauthenticated attacker to cause a denial of service condition for the duration of the attack. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens ...
Titel
SSA-516174 V1.0: Wi-Fi Encryption Bypass Vulnerabilities in SCALANCE W1750D
Veröffentlicht
9. Mai 2023 02:00
Text
The SCALANCE W1750D device is affected by Wi-Fi encryption bypass vulnerabilities (“Framing Frames”) that could allow an attacker to disclose sensitive information or to steal the victims session. Siemens is preparing updates and recommends countermeasures for products where updates are not, or not yet available.
Titel
SSA-480230 V2.7 (Last Update: 2023-05-09): Denial of Service Vulnerability in Webserver of Industrial Products
Veröffentlicht
9. Mai 2023 02:00
Text
A vulnerability in the affected devices could allow an unauthorized attacker with network access to the webserver of an affected device to perform a denial of service attack. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens recommends specific countermeasures for products ...
Titel
SSA-478960 V1.4 (Last Update: 2023-05-09): Missing CSRF Protection in the Web Server Login Page of Industrial Controllers
Veröffentlicht
9. Mai 2023 02:00
Text
The web server login page of affected products does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack.. Siemens has released updates for several affected products and recommends to update to the latest versions. ...
Titel
SSA-473245 V2.6 (Last Update: 2023-05-09): Denial of Service Vulnerability in Profinet Devices
Veröffentlicht
9. Mai 2023 02:00
Text
A vulnerability in affected devices could allow an attacker to perform a denial of service attack if a large amount of specially crafted UDP packets are sent to the device. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens recommends specific countermeasures ...
Titel
SSA-382653 V1.3 (Last Update: 2023-05-09): Multiple Denial of Service Vulnerabilities in Industrial Products
Veröffentlicht
9. Mai 2023 02:00
Text
Affected SIMATIC firmware contains multiple vulnerabilities that could allow an unauthenticated attacker to perform a denial of service attack under certain conditions. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens is preparing further updates and recommends countermeasures for products where updates ...
Titel
SSA-349422 V2.0 (Last Update: 2023-05-09): Denial of Service Vulnerability in Industrial Real-Time (IRT) Devices
Veröffentlicht
9. Mai 2023 02:00
Text
A vulnerability in the affected products could allow an unauthorized attacker with network access to perform a denial-of-service attack resulting in loss of real-time synchronization. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens recommends specific countermeasures for products where updates are ...
Titel
SSA-325383 V1.0: Multiple Vulnerabilities in SCALANCE LPE9403 before V2.1
Veröffentlicht
9. Mai 2023 02:00
Text
SCALANCE LPE9403 is affected by multiple vulnerabilities that could allow an attacker to impact its confidentiality, integrity and availability. Siemens has released an update for the SCALANCE LPE9403 and recommends to update to the latest version.
Titel
SSA-322980 V1.1 (Last Update: 2023-05-09): Denial of Service Vulnerability in SIPROTEC 5 Devices
Veröffentlicht
9. Mai 2023 02:00
Text
SIPROTEC 5 devices contain a null pointer dereference vulnerability in the web service. This could allow an attacker to send unauthenticated maliciously crafted http request that could cause denial of service condition of the device. Siemens has released updates for several affected products and recommends to update to the latest ...
Titel
SSA-309571 V1.8 (Last Update: 2023-05-09): IPU 2021.1 Vulnerabilities in Siemens Industrial Products using Intel CPUs (June 2021)
Veröffentlicht
9. Mai 2023 02:00
Text
Intel has published information on vulnerabilities in Intel products in June 2021. This advisory lists the related Siemens Industrial products affected by these vulnerabilities that can be patched by applying the corresponding BIOS update. In this advisory we summarize: “2021.1 IPU – Intel® CSME, SPS and LMS Advisory” Intel-SA-00459, “2021.1 ...
Titel
SSA-116924 V1.1 (Last Update: 2023-05-09): Path Traversal Vulnerability in TIA Portal
Veröffentlicht
9. Mai 2023 02:00
Text
TIA Portal contains a path traversal vulnerability that could allow the creation or overwrite of arbitrary files in the engineering system. If the user is tricked to open a malicious PC system configuration file, an attacker could exploit this vulnerability to achieve arbitrary code execution. Siemens has released an update ...
  • 1
  • 2 (current)
  • 3

Letzte Updates

BOSCH PSIRT
20.03.2024
CODESYS
28.06.2023
SIEMENS CERT
09.04.2024
US CERT
26.02.2024
US CERT (ICS)
11.04.2024

Nach Quelle

Archiv

2024
2023
2022
2021
2020
2019
2018
2017

Feeds