February 2020
Title
AA20-049A: Ransomware Impacting Pipeline Operations
Published
Feb. 18, 2020, 2:06 p.m.
Summary
Original release date: February 18, 2020 | Last revised: June 30, 2020SummaryNote: This Activity Alert uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK™) framework. See the MITRE ATT&CK for Enterprise and ATT&CK for Industrial Control Systems (ICS) frameworks for all referenced threat actor techniques and mitigations. The Cybersecurity ...
Title
Schneider Electric Modicon Ethernet Serial RTU
Published
Feb. 13, 2020, 4:05 p.m.
Summary
This advisory contains mitigations for improper check for unusual or exceptional conditions, and improper access control vulnerabilities in Schneider Electric's Modicon's BMXNOR0200H Ethernet Serial RTU, a remote terminal unit.
Title
Schneider Electric Magelis HMI Panels
Published
Feb. 13, 2020, 4 p.m.
Summary
This advisory contains mitigations for an improper check for unusual or exceptional conditions vulnerability in Schneider's Magelis HMI Panels.
Title
Synergy Systems & Solutions HUSKY RTU
Published
Feb. 11, 2020, 5:30 p.m.
Summary
This advisory contains mitigations for improper authentication and improper input validation vulnerabilities in Synergy Systems & Solutions HUSKY RTU, a remote terminal unit.
Title
Siemens Industrial Products SNMP Vulnerabilities
Published
Feb. 11, 2020, 5:25 p.m.
Summary
This advisory contains mitigations for data processing errors and NULL pointer dereference vulnerabilities in Siemens vulnerability in various industrial products, including SCALANCE, SIMATIC, and SIPLUS.
Title
Siemens SIMATIC CP 1543-1
Published
Feb. 11, 2020, 5:20 p.m.
Summary
This advisory contains mitigations for improper access control and loop with unreachable exit condition vulnerabilities in the Siemens SIMATIC CP 1543-1 communications processor.
Title
Siemens PROFINET-IO Stack
Published
Feb. 11, 2020, 5:15 p.m.
Summary
This advisory contains mitigations for an internal resource allocation vulnerability in the Siemens PROFINET-IO Stack, which could be exploited to create a denial-of-service condition in products that include the vulnerable stack.
Title
Siemens SIMATIC PCS 7, SIMATIC WinCC, and SIMATIC NET PC
Published
Feb. 11, 2020, 5:05 p.m.
Summary
This advisory contains mitigations for an incorrect calculation of buffer size vulnerability in some Siemens SIMATIC software products.
Title
Siemens SIPORT MP
Published
Feb. 11, 2020, 4:55 p.m.
Summary
This advisory contains mitigations for an insufficient logging vulnerability in Siemens SIPORT MP access control and time tracking system.
Title
Siemens OZW Web Server
Published
Feb. 11, 2020, 4:50 p.m.
Summary
This advisory contains mitigations for an information disclosure vulnerability in the Siemens OZW Web Server.
Title
Siemens SCALANCE S-600
Published
Feb. 11, 2020, 4:45 p.m.
Summary
This advisory contains mitigations for resource exhaustion and cross-site scripting vulnerabilities in Siemens SCALANCE S-600 industrial security appliance.
Title
SSA-750824 (Last Update: 2020-02-11): Denial-of-Service Vulnerability in Profinet Devices
Published
Feb. 11, 2020, 1 a.m.
Summary
SIMATIC S7-1500 CPU family devices are affected by a vulnerability that could allow an attacker to perform a Denial-of-Service attack if specially crafted UDP packets are sent to the device. Siemens has released updates for several affected products, is working on updates for the remaining affected products and recommends specific ...
Title
SSB-439005 (Last Update: 2020-02-11): Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
Published
Feb. 11, 2020, 1 a.m.
Summary
Title
SSA-940889 (Last Update: 2020-02-11): Vulnerabilities in the embedded FTP server of SIMATIC CP 1543-1
Published
Feb. 11, 2020, 1 a.m.
Summary
The latest update for SIMATIC CP 1543-1 contains two fixes for vulnerabilities within its embedded ProFTPD FTP server. The more severe of these vulnerabilities could allow for remote code execution and information disclosure without authentication. Siemens has released updates for SIMATIC CP 1543-1 modules.
Title
SSA-780073 (Last Update: 2020-02-11): Denial-of-Service Vulnerability in PROFINET Devices via DCE-RPC Packets
Published
Feb. 11, 2020, 1 a.m.
Summary
Products that include the Siemens PROFINET-IO (PNIO) stack in versions prior V06.00 are potentially affected by a denial-of-service vulnerability when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is ...
Title
SSA-462066 (Last Update: 2020-02-11): Vulnerability known as TCP SACK PANIC in Industrial Products
Published
Feb. 11, 2020, 1 a.m.
Summary
Multiple industrial products are affected by a vulnerability in the kernel known as TCP SACK PANIC. The vulnerability could allow a remote attacker to cause a denial of service condition. Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing ...
Title
SSA-431678 (Last Update: 2020-02-11): Denial-of-Service Vulnerability in SIMATIC S7 CPU Families
Published
Feb. 11, 2020, 1 a.m.
Summary
S7-300/S7-400 and S7-1200 CPU families are affected by a vulnerability that could allow remote attackers to perform a Denial-of-Service attack by sending a specially crafted HTTP request to the web server of an affected device. Siemens has released updates for several affected products, is working on updates for the remaining ...
Title
SSA-270778 (Last Update: 2020-02-11): Denial-of-Service Vulnerability in SIMATIC PCS 7, SIMATIC WinCC and SIMATIC NET PC Software
Published
Feb. 11, 2020, 1 a.m.
Summary
A Denial-of-Service vulnerability was found in SIMATIC PCS 7, SIMATIC WinCC and SIMATIC NET PC software when encrypted communication is enabled. The vulnerability could allow an attacker with network access to cause a Denial-of-Service condition under certain circumstances (versions prior to SIMATIC WinCC V7.3 or SIMATIC PCS 7 V8.1 are ...
Title
SSA-978558 (Last Update: 2020-02-11): Insufficient Logging Vulnerability in SIPORT MP
Published
Feb. 11, 2020, 1 a.m.
Summary
SIPORT MP version 3.1.4 fixes a vulnerability that allowed to create special accounts ("service users") which could enable an authenticated attacker to perform actions that are invisible to other users of the system. Siemens recommends customers to apply the update. For older versions, a hotfix and a tool are available ...
Title
SSA-273799 (Last Update: 2020-02-11): Vulnerability in SIMATIC products
Published
Feb. 11, 2020, 1 a.m.
Summary
A vulnerability has been identified in several SIMATIC products. The vulnerability could allow an attacker in a Man-in-the-Middle position to modify network traffic exchanged on port 102/tcp to PLCs of the SIMATIC S7-1200, SIMATIC S7-1500 and SIMATIC SoftwareController CPU families. Siemens has released updates for several affected products, and recommends ...
Title
SSA-591405 (Last Update: 2020-02-11): Web Vulnerabilities in SCALANCE S-600 family
Published
Feb. 11, 2020, 1 a.m.
Summary
The firmware for SCALANCE S-600 family devices contains multiple web vulnerabilities. The vulnerabilities could allow an remote attacker to conduct Denial-of-Service attacks or perform Cross-Site Scripting attacks. Siemens recommends to migrate to SCALANCE SC-600 Industrial Security Appliances.
Title
SSA-398519 (Last Update: 2020-02-11): Vulnerabilities in Intel CPUs (November 2019)
Published
Feb. 11, 2020, 1 a.m.
Summary
Intel has published information on vulnerabilities in Intel products in November 2019. In this advisory Siemens only explicitly mentions the vulnerabilities from the "Intel® CPU Security Advisory" and one vulnerability from "Intel® CSME, Intel® SPS, Intel® TXE, Intel® AMT, Intel® PTT and Intel® DAL Advisory" and lists the Siemens IPC ...
Title
SSA-616472 (Last Update: 2020-02-11): ZombieLoad and Microarchitectural Data Sampling Vulnerabilities in Industrial Products
Published
Feb. 11, 2020, 1 a.m.
Summary
Security researchers published information on vulnerabilities known as ZombieLoad and Microarchitectural Data Sampling (MDS). These vulnerabilities affect many modern processors from different vendors to a varying degree. Several Siemens Industrial Products contain processors that are affected by the vulnerabilities.
Title
SSA-349422 (Last Update: 2020-02-11): Denial-of-Service in Industrial Real-Time (IRT) Devices
Published
Feb. 11, 2020, 1 a.m.
Summary
A vulnerability in the affected products could allow an unauthorized attacker with network access to perform a denial-of-service attack resulting in loss of real-time synchronization. Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates and recommends specific ...
Title
SSA-307392 (Last Update: 2020-02-11): Denial-of-Service in OPC UA in Industrial Products
Published
Feb. 11, 2020, 1 a.m.
Summary
A vulnerability has been identified in the OPC UA server of several industrial products. The vulnerability could cause a Denial-of-Service condition on the service or the device. Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates and ...

Last Updates

BOSCH PSIRT
20.03.2024
CODESYS
28.06.2023
SIEMENS CERT
19.04.2024
US CERT
17.04.2024
US CERT (ICS)
18.04.2024

By Source

Archive

2024
2023
2022
2021
2020
2019
2018
2017

Feeds