April 2018
Title
SSA-348629 (Last Update: 2018-04-18): Denial-of-Service Vulnerability in SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional and SIMATIC NET PC Software
Published
April 18, 2018, 2 a.m.
Summary
A Denial-of-Service vulnerability has been identified in SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional and SIMATIC NET PC-Software. Siemens has released updates for several affected products and recommends that customers update to the new version. Siemens is preparing further updates and recommends specific countermeasures until patches are available.
Title
SSA-168644 (Last Update: 2018-04-18): Spectre and Meltdown Vulnerabilities in Industrial Products
Published
April 18, 2018, 2 a.m.
Summary
Security researchers published information on vulnerabilities known as Spectre and Meltdown. These vulnerabilities affect many modern processors from different vendors to a varying degree. Several Industrial Products include affected processors and are affected by the vulnerabilities.
Title
Abbott Laboratories Defibrillator
Published
April 17, 2018, 4:30 p.m.
Summary
This medical advisory includes mitigations for improper authentication and improper restriction of power consumption vulnerabilities identified in Abbott Laboratories' defibrillators.
Title
Biosense Webster Carto 3 System Vulnerabilities
Published
April 17, 2018, 4:25 p.m.
Summary
This medical advisory includes mitigations for a large number of vulnerabilties in the Biosense Webster Carto 3 cardiovascular mapping platform.
Title
Schneider Electric InduSoft Web Studio and InTouch Machine Edition
Published
April 17, 2018, 4:20 p.m.
Summary
This advisory includes mitigations for a stack-based buffer overflow vulnerability in the Schneider Electric's InduSoft Web Studio and InTouch Machine HMI.
Title
Schneider Electric Triconex Tricon
Published
April 17, 2018, 4:15 p.m.
Summary
This advisory includes mitigations for improper restriction of operations within the bounds of a memory buffer vulnerabilities in Schneider Electric's Triconex Tricon safety instrumented system.
Title
Schneider Electric Triconex Tricon (Update A)
Published
April 17, 2018, 4:15 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-18-107-02 Schneider Electric Triconex Tricon that was published April 17, 2018, on the NCCIC/ICS-CERT website. This updated advisory includes mitigations for improper restriction of operations within the bounds of a memory buffer vulnerabilities in Schneider Electric's Triconex Tricon safety ...
Title
Rockwell Automation Stratix Services Router
Published
April 17, 2018, 4:10 p.m.
Summary
This advisory includes mitigations for improper input validation, improper restriction of operations, and use of externally-controlled format string vulnerabilities in the Rockwell Automation Stratix 5900 router.
Title
Rockwell Automation Stratix and ArmorStratix Switches
Published
April 17, 2018, 4:05 p.m.
Summary
This advisory includes mitigations for improper improper input validation, resource management, memory buffer and externally-controlled format string vulnerabilities in Rockwell Automation's Allen-Bradley Stratix and ArmorStratix Switches.
Title
Rockwell Automation Stratix Industrial Managed Ethernet Switch
Published
April 17, 2018, 4 p.m.
Summary
This advisory includes mitigations for improper imput validation, resource managment, 7PK, memory buffer and externally-controlled format string vulnerabilities in Rockwell Automation's Stratix Industrial Managed Switch.
Title
SSA-845879 (Last Update: 2018-04-17): Firmware Downgrade Vulnerability in EN100 Ethernet Communication Module for SIPROTEC 4, SIPROTEC Compact and Reyrolle
Published
April 17, 2018, 2 a.m.
Summary
The EN100 Ethernet communication module, which is an optional extension for SIPROTEC 4, SIPROTEC Compact and Reyrolle devices, allows an unauthenticated upload of firmware updates to the communication module in affected versions. Siemens has released updates for several affected products, is working on updates for the remaining affected products, and ...
Title
SSA-203306 (Last Update: 2018-04-17): Password Vulnerabilities in SIPROTEC 4 and SIPROTEC Compact Relay Families
Published
April 17, 2018, 2 a.m.
Summary
SIPROTEC 4 and SIPROTEC Compact devices could allow access authorization passwords to be reconstructed or overwritten via engineering mechanisms that involve DIGSI 4 and EN100 Ethernet communication modules. Siemens has released updates for several affected products, is working on updates for the remaining affected products, and recommends specific countermeasures until ...
Title
Yokogawa CENTUM and Exaopc
Published
April 12, 2018, 4:05 p.m.
Summary
This advisory includes mitigations for a permissions, privileges, and access controls vulnerability in the Yokogawa CENTUM series and Exaopc products.
Title
ATI Systems Emergency Mass Notification Systems
Published
April 10, 2018, 4:05 p.m.
Summary
This advisory includes mitigations for improper authentication and missing encryption of sensitive data vulnerabilities in the ATI Systems Emergency Mass Notification Systems.
Title
Omron CX-One
Published
April 10, 2018, 4 p.m.
Summary
This advisory includes mitigations for heap-based buffer overflow, stack-based buffer overflow, and type confusion vulnerabilities in Omron CX-One software.
Title
Rockwell Automation MicroLogix
Published
April 5, 2018, 5:26 p.m.
Summary
This advisory includes mitigations for an improper authentication vulnerability in the Rockwell MicroLogix Controller.
Title
Moxa MXview
Published
April 5, 2018, 4:05 p.m.
Summary
This advisory includes mitigations for an information exposure vulnerability in the Moxa MXview network management software.
Title
SSA-689071 (Last Update: 2018-04-05): DNSMasq Vulnerabilities in SCALANCE W1750D, SCALANCE M800 and SCALANCE S615
Published
April 5, 2018, 2 a.m.
Summary
Multiple vulnerabilities have been identified in SCALANCE W1750D, SCALANCE M800, and SCALANCE S615 devices. The highest scored vulnerability could allow a remote attacker to crash the DNS service or execute arbitrary code. The attacker must be able to craft malicious DNS responses and inject them into the network in order ...
Title
SSA-901333 (Last Update: 2018-04-05): KRACK Attacks Vulnerabilities in Industrial Products
Published
April 5, 2018, 2 a.m.
Summary
Multiple vulnerabilities affecting WPA/WPA2 implementations were identified by a researcher and publicly disclosed under the term "Key Reinstallation Attacks" (KRACK). These vulnerabilities could potentially allow an attacker within the radio range of the wireless network to decrypt, replay or inject forged network packets into the wireless communication. Several Siemens Industrial ...
Title
Siemens Building Technologies Products
Published
April 3, 2018, 4 p.m.
Summary
This advisory includes mitigations for a series of vulnerabilities in Siemens' Building Technologies Procucts, including stack-based buffer overflow, external control of system or configuration setting, improper restriction ofoperations within the bounds of a memory buffer, NULL pointer deference, XML entity expansion, heap-based buffer overflow, and improper access control.
Title
Siemens Building Technologies Products (Update A)
Published
April 3, 2018, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-18-093-01 Siemens Building Technologies Products that was published April 3, 2018, on the NCCIC/ICS-CERT website. This advisory update includes mitigations for a series of vulnerabilities in Siemens' Building Technologies Products, including stack-based buffer overflows, security features, improper restriction of ...
Title
SSA-727467 (Last Update: 2018-04-03): Vulnerabilities in Building Technologies Products
Published
April 3, 2018, 2 a.m.
Summary
The License Management System (LMS), which is used by multiple Siemens' building automation products, includes a vulnerable version of Gemalto Sentinel LDK RTE. Gemalto Sentinel LDK RTE is affected by multiple vulnerabilities that could allow remote code execution. Siemens recommends to update the License Management System used by these products ...
March 2018
Title
Philips iSite/IntelliSpace PACS Vulnerabilities
Published
March 29, 2018, 8:35 p.m.
Summary
This advisory includes mitigation recommendations for vulnerabilities identified in the Philips Philips iSite and IntelliSpace PACS.
Title
WAGO 750 Series
Published
March 29, 2018, 6:15 p.m.
Summary
This advisory includes mitigations for an improper resource shutdown or release vulnerability in the WAGO 750 series PLC.
Title
Siemens TIM 1531 IRC
Published
March 29, 2018, 6:10 p.m.
Summary
This advisory includes mitigations for an incorrect implementation of authentication algorithm vulnerability in the Siemens TIM 1531 IRC communications modules.

Last Updates

BOSCH PSIRT
20.03.2024
CODESYS
28.06.2023
SIEMENS CERT
19.04.2024
US CERT
17.04.2024
US CERT (ICS)
07.05.2024

By Source

Archive

2024
2023
2022
2021
2020
2019
2018
2017

Feeds