Juni 2018
Titel
SSA-523365 (Last Update: 2018-06-12): Vulnerability in SIMATIC PCS 7
Veröffentlicht
12. Juni 2018 02:00
Text
The latest software update for SIMATIC PCS 7 fixes a vulnerability, which could allow an attacker to cause a Denial-of-Service (DoS) condition under certain circumstances.
Titel
SSA-323211 (Last Update: 2018-06-12): Vulnerabilities in SIPROTEC 4 and SIPROTEC Compact Devices
Veröffentlicht
12. Juni 2018 02:00
Text
SIPROTEC 4 and SIPROTEC Compact devices are affected by several vulnerabilities. Two of the vulnerabilities could allow attackers to perform a denial-of-service attack under certain conditions. Siemens has released updates for the affected products and will update this advisory when new information becomes available.
Titel
SSA-755010 (Last Update: 2018-06-12): Vulnerability in RAPIDLab 1200 and RAPIDPoint 400/500 Blood Gas Analyzers
Veröffentlicht
12. Juni 2018 02:00
Text
Siemens Healthineers has become aware of two potential cybersecurity vulnerabilities for the RAPIDLab® 1200 Series and RAPIDPoint® 400/405/500 Blood Gas Analyzers and recommends specific countermeasures to mitigate the risk. At the time of advisory publication, no public exploitation of this security vulnerability is known.
Titel
SSA-348629 (Last Update: 2018-06-12): Denial-of-Service Vulnerability in SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional and SIMATIC NET PC Software
Veröffentlicht
12. Juni 2018 02:00
Text
A Denial-of-Service vulnerability has been identified in SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional and SIMATIC NET PC-Software. Siemens has released updates for several affected products and recommends that customers update to the new version. Siemens is preparing further updates and recommends specific countermeasures until patches are available.
Titel
SSA-977428 (Last Update: 2018-06-12): Vulnerabilities in SCALANCE M875
Veröffentlicht
12. Juni 2018 02:00
Text
Multiple vulnerabilities have been identified in the web interface of SCALANCE M875. The web interface of SCALANCE M875 could allow Cross-Site Request Forgery (CSRF), stored Cross-Site Scripting (XSS), or command injection attacks if an attacker is authenticated or tricks a legitimate authenticated user into accessing a malicious link. Siemens recommends ...
Mai 2018
Titel
SSA-168644 (Last Update: 2018-05-29): Spectre and Meltdown Vulnerabilities in Industrial Products
Veröffentlicht
29. Mai 2018 02:00
Text
Security researchers published information on vulnerabilities known as Spectre and Meltdown. These vulnerabilities affect many modern processors from different vendors to a varying degree. Several Industrial Products include affected processors and are affected by the vulnerabilities.
Titel
SSA-457058 (Last Update: 2018-05-23): .NET Security Vulnerability in Siveillance VMS
Veröffentlicht
23. Mai 2018 02:00
Text
Siemens has released software updates for Siveillance VMS which fix a security vulnerability with the .NET Remoting deserialization that could allow elevation of privileges and/or causing a Denial-of-Service, if affected ports are exposed.
Titel
SSA-346262 (Last Update: 2018-05-15): Denial-of-Service in Industrial Products
Veröffentlicht
15. Mai 2018 02:00
Text
Several industrial products are affected by a vulnerability that could allow remote attackers to conduct a Denial-of-Service (DoS) attack by sending specially crafted packets to port 161/udp (SNMP). Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates ...
Titel
SSA-914382 (Last Update: 2018-05-15): Denial-of-Service Vulnerability in SIMATIC S7-400
Veröffentlicht
15. Mai 2018 02:00
Text
SIMATIC S7-400 CPUs are affected by a security vulnerability which could lead to a Denial-of-Service condition of the PLC if specially crafted packets are received and processed. The affected SIMATIC S7-400 CPU hardware versions are in the product cancellation phase or already phased-out. Siemens recommends customers either upgrading to a ...
Titel
SSA-547990 (Last Update: 2018-05-15): Information Disclosure Vulnerabilities in SIPROTEC 4 and SIPROTEC Compact
Veröffentlicht
15. Mai 2018 02:00
Text
Information disclosure vulnerabilities in SIPROTEC 4 and SIPROTEC Compact devices could allow an attacker to extract sensitive device information under certain conditions. Siemens has released firmware updates for EN100 Ethernet module included in SIPROTEC 4 and SIPROTEC Compact devices. Siemens has also released a firmware update for SIPROTEC Compact 7SJ80 ...
Titel
SSA-203306 (Last Update: 2018-05-15): Password Vulnerabilities in SIPROTEC 4 and SIPROTEC Compact Relay Families
Veröffentlicht
15. Mai 2018 02:00
Text
SIPROTEC 4 and SIPROTEC Compact devices could allow access authorization passwords to be reconstructed or overwritten via engineering mechanisms that involve DIGSI 4 and EN100 Ethernet communication modules. Siemens has released updates for several affected products, is working on updates for the remaining affected products, and recommends specific countermeasures until ...
Titel
SSA-689071 (Last Update: 2018-05-09): DNSMasq Vulnerabilities in SCALANCE W1750D, SCALANCE M800 and SCALANCE S615
Veröffentlicht
9. Mai 2018 02:00
Text
Multiple vulnerabilities have been identified in SCALANCE W1750D, SCALANCE M800, and SCALANCE S615 devices. The highest scored vulnerability could allow a remote attacker to crash the DNS service or execute arbitrary code. The attacker must be able to craft malicious DNS responses and inject them into the network in order ...
Titel
SSA-346262 (Last Update: 2018-05-03): Denial-of-Service in Industrial Products
Veröffentlicht
3. Mai 2018 02:00
Text
Several industrial products are affected by a vulnerability that could allow remote attackers to conduct a Denial-of-Service (DoS) attack by sending specially crafted packets to port 161/udp (SNMP). Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates ...
Titel
SSA-293562 (Last Update: 2018-05-03): Vulnerabilities in Industrial Products
Veröffentlicht
3. Mai 2018 02:00
Text
Several industrial devices are affected by two vulnerabilities that could allow an attacker to cause a Denial-of-Service condition via PROFINET DCP network packets under certain circumstances. Precondition for this scenario is a direct Layer 2 access to the affected products. PROFIBUS interfaces are not affected. Siemens has released updates for ...
Titel
SSA-546832 (Last Update: 2018-05-03): Vulnerabilities in Medium Voltage SINAMICS Products
Veröffentlicht
3. Mai 2018 02:00
Text
The latest updates for medium voltage SINAMICS products fix two security vulnerabilities that could allow an attacker to cause a Denial-of-Service condition either via specially crafted PROFINET DCP broadcast packets or by sending specially crafted packets to port 161/udp (SNMP). Precondition for the PROFINET DCP scenario is a direct Layer ...
Titel
SSA-457058 (Last Update: 2018-05-03): .NET Security Vulnerability in Siveillance VMS
Veröffentlicht
3. Mai 2018 02:00
Text
Siemens has released software updates for Siveillance VMS which fix a security vulnerability with the .NET Remoting deserialization that could allow elevation of privileges and/or causing a Denial-of-Service, if affected ports are exposed.
Titel
SSA-468514 (Last Update: 2018-05-03): Improper Certificate Validation Vulnerability in Siveillance VMS Video Mobile App for Android and iOS
Veröffentlicht
3. Mai 2018 02:00
Text
The latest update for the Siveillance VMS Video mobile app for Android and iOS fixes a security vulnerability that could allow an attacker in a privileged network position to read data from and write data to the encrypted communication channel between the app and a server. Precondition for this scenario ...
April 2018
Titel
SSA-348629 (Last Update: 2018-04-18): Denial-of-Service Vulnerability in SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional and SIMATIC NET PC Software
Veröffentlicht
18. April 2018 02:00
Text
A Denial-of-Service vulnerability has been identified in SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional and SIMATIC NET PC-Software. Siemens has released updates for several affected products and recommends that customers update to the new version. Siemens is preparing further updates and recommends specific countermeasures until patches are available.
Titel
SSA-892715 (Last Update: 2018-04-18): ME, SPS and TXE Vulnerabilities in SIMATIC IPCs
Veröffentlicht
18. April 2018 02:00
Text
Intel has identified vulnerabilities in Intel Management Engine (ME), Intel Server Platform Services (SPS), and Intel Trusted Execution Engine (TXE). As several Siemens Industrial PCs use Intel technology, they are also affected. Siemens has released updates for the affected Industrial PCs.
Titel
SSA-597741 (Last Update: 2018-04-18): Vulnerability in iOS App SIMATIC WinCC OA Operator
Veröffentlicht
18. April 2018 02:00
Text
The SIMATIC WinCC OA Operator iOS app is affected by a security vulnerability which could allow an attacker to read unencrypted data from the application’s directory. Precondition for this scenario is that an attacker has physical access to the mobile device.
Titel
SSA-168644 (Last Update: 2018-04-18): Spectre and Meltdown Vulnerabilities in Industrial Products
Veröffentlicht
18. April 2018 02:00
Text
Security researchers published information on vulnerabilities known as Spectre and Meltdown. These vulnerabilities affect many modern processors from different vendors to a varying degree. Several Industrial Products include affected processors and are affected by the vulnerabilities.
Titel
SSA-203306 (Last Update: 2018-04-17): Password Vulnerabilities in SIPROTEC 4 and SIPROTEC Compact Relay Families
Veröffentlicht
17. April 2018 02:00
Text
SIPROTEC 4 and SIPROTEC Compact devices could allow access authorization passwords to be reconstructed or overwritten via engineering mechanisms that involve DIGSI 4 and EN100 Ethernet communication modules. Siemens has released updates for several affected products, is working on updates for the remaining affected products, and recommends specific countermeasures until ...
Titel
SSA-845879 (Last Update: 2018-04-17): Firmware Downgrade Vulnerability in EN100 Ethernet Communication Module for SIPROTEC 4, SIPROTEC Compact and Reyrolle
Veröffentlicht
17. April 2018 02:00
Text
The EN100 Ethernet communication module, which is an optional extension for SIPROTEC 4, SIPROTEC Compact and Reyrolle devices, allows an unauthenticated upload of firmware updates to the communication module in affected versions. Siemens has released updates for several affected products, is working on updates for the remaining affected products, and ...
Titel
SSA-901333 (Last Update: 2018-04-05): KRACK Attacks Vulnerabilities in Industrial Products
Veröffentlicht
5. April 2018 02:00
Text
Multiple vulnerabilities affecting WPA/WPA2 implementations were identified by a researcher and publicly disclosed under the term "Key Reinstallation Attacks" (KRACK). These vulnerabilities could potentially allow an attacker within the radio range of the wireless network to decrypt, replay or inject forged network packets into the wireless communication. Several Siemens Industrial ...
Titel
SSA-689071 (Last Update: 2018-04-05): DNSMasq Vulnerabilities in SCALANCE W1750D, SCALANCE M800 and SCALANCE S615
Veröffentlicht
5. April 2018 02:00
Text
Multiple vulnerabilities have been identified in SCALANCE W1750D, SCALANCE M800, and SCALANCE S615 devices. The highest scored vulnerability could allow a remote attacker to crash the DNS service or execute arbitrary code. The attacker must be able to craft malicious DNS responses and inject them into the network in order ...

Letzte Updates

BOSCH PSIRT
15.05.2024
SIEMENS CERT
14.05.2024
US CERT
10.05.2024
US CERT (ICS)
23.05.2024

Nach Quelle

Archiv

2024
2023
2022
2021
2020
2019
2018
2017

Feeds