February 2022
Title
SSA-473245 V2.2 (Last Update: 2022-02-08): Denial-of-Service Vulnerability in Profinet Devices
Published
Feb. 8, 2022, 1 a.m.
Summary
A vulnerability in affected devices could allow an attacker to perform a denial-of-service attack if a large amount of specially crafted UDP packets are sent to the device. Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates ...
Title
SSA-669737 V1.0: Improper Access Control Vulnerability in SICAM TOOLBOX II
Published
Feb. 8, 2022, 1 a.m.
Summary
SICAM TOOLBOX II contains a vulnerability that could allow an attacker access through a circumventable access control. Siemens is preparing updates and recommends countermeasures for products where updates are not, or not yet available.
Title
SSA-211752 V1.1 (Last Update: 2022-02-08): Multiple NTP-Client Related Vulnerabilities in SIMATIC CP 443-1 OPC UA
Published
Feb. 8, 2022, 1 a.m.
Summary
All versions of the SIMATIC CP 443-1 OPC UA contain multiple vulnerabilities in the underlying third party component NTP. Siemens recommends specific countermeasures for products where updates are not, or not yet available.
Title
SSA-346262 V3.2 (Last Update: 2022-02-08): Denial-of-Service in Industrial Products
Published
Feb. 8, 2022, 1 a.m.
Summary
Several industrial products are affected by a vulnerability that could allow remote attackers to conduct a Denial-of-Service (DoS) attack by sending specially crafted packets to port 161/udp (SNMP). Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates ...
Title
SSA-675303 V1.3 (Last Update: 2022-02-08): WIBU Systems CodeMeter Runtime Vulnerabilities in Siemens Products
Published
Feb. 8, 2022, 1 a.m.
Summary
WIBU Systems published information about two vulnerabilities and an associated fix release version of CodeMeter Runtime, a product provided by WIBU Systems and used in several Siemens products for license management. The vulnerabilities are described in the section “Vulnerability Classification” below and got assigned the CVE IDs CVE-2021-20093 and CVE-2021-20094. ...
Title
SSB-439005 V4.0 (Last Update: 2022-02-08): Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
Published
Feb. 8, 2022, 1 a.m.
Summary
Title
SSA-462066 V2.6 (Last Update: 2022-02-08): Vulnerability known as TCP SACK PANIC in Industrial Products
Published
Feb. 8, 2022, 1 a.m.
Summary
Multiple industrial products are affected by a vulnerability in the kernel known as TCP SACK PANIC. The vulnerability could allow a remote attacker to cause a denial of service condition. Siemens has released updates for several affected products and recommends to update to the new versions. Siemens is preparing further ...
Title
SSA-309571 V1.1 (Last Update: 2022-02-08): IPU 2021.1 Vulnerabilities in Siemens Industrial Products using Intel CPUs (June 2021)
Published
Feb. 8, 2022, 1 a.m.
Summary
Intel has published information on vulnerabilities in Intel products in June 2021. This advisory lists the related Siemens Industrial products affected by these vulnerabilities that can be patched by applying the corresponding BIOS update. In this advisory we summarize: “2021.1 IPU – Intel® CSME, SPS and LMS Advisory” Intel-SA-00459, “2021.1 ...
Title
SSA-995338 V1.1 (Last Update: 2022-02-08): Multiple Vulnerabilities in COMOS Web
Published
Feb. 8, 2022, 1 a.m.
Summary
Multiple vulnerabilities were identified in the web components of COMOS that could allow an attacker to conduct code injections, store data in undesired locations, execute arbitrary SQL statements, and run cross-site request forgery attacks. Siemens has released updates for several affected products and recommends to update to the latest versions. ...
Title
SSA-913875 V1.2 (Last Update: 2022-02-08): Frame Aggregation and Fragmentation Vulnerabilities in 802.11
Published
Feb. 8, 2022, 1 a.m.
Summary
Twelve vulnerabilities in the implementation of frame aggregation and fragmentation of the 802.11 standard, under the name of FragAttacks, have been published. Successful exploitation of these vulnerabilities could allow an attacker within Wi-Fi range to forge encrypted frames, which could result in sensitive data disclosure and possibly traffic manipulation. The ...
Title
SSA-831168 V1.0: Cross-Site Scripting Vulnerability in Spectrum Power 4
Published
Feb. 8, 2022, 1 a.m.
Summary
A Cross-Site Scripting (XSS) vulnerability is found in the integrated web application “Online Help” of Spectrum Power 4. Siemens has released an update for the Spectrum Power 4 and recommends to update to the latest version.
Title
SSA-102233 V1.7 (Last Update: 2022-02-08): SegmentSmack in VxWorks-based Industrial Devices
Published
Feb. 8, 2022, 1 a.m.
Summary
The products listed below contain a vulnerability that could allow remote attackers to affect the availability of the devices under certain conditions. The underlying TCP stack can be forced to make very computation expensive calls for every incoming packet which can lead to a Denial-of-Service. Siemens has released an update ...
Title
SSA-293562 V3.4 (Last Update: 2022-02-08): Denial of Service Vulnerabilities in PROFINET DCP Implementation of Industrial Products
Published
Feb. 8, 2022, 1 a.m.
Summary
Several industrial devices are affected by two vulnerabilities that could allow an attacker to cause a denial of service condition via PROFINET DCP network packets under certain circumstances. The precondition for this scenario is a direct layer 2 access to the affected products. PROFIBUS interfaces are not affected. Siemens has ...
Title
SSA-661247 V2.5 (Last Update: 2022-02-08): Apache Log4j Vulnerabilities (Log4Shell, CVE-2021-44228, CVE-2021-45046) - Impact to Siemens Products
Published
Feb. 8, 2022, 1 a.m.
Summary
On 2021-12-09, a vulnerability in Apache Log4j (a logging tool used in many Java-based applications) was disclosed, that could allow remote unauthenticated attackers to execute code on vulnerable systems. The vulnerability is tracked as CVE-2021-44228 and is also known as “Log4Shell”. On 2021-12-14 an additional denial of service vulnerability (CVE-2021-45046) ...
Title
SSA-301589 V1.0: Multiple File Parsing Vulnerabilities in Solid Edge, JT2Go and Teamcenter Visualization
Published
Feb. 8, 2022, 1 a.m.
Summary
Siemens has released updates for Solid Edge and Teamcenter Visualization to fix multiple file parsing vulnerabilities. If a user is tricked to open a malicious file (crafted as PDF, DXF or PAR) with any of the affected products, this could lead the application to crash or potentially lead to arbitrary ...
Title
SSA-541018 V1.4 (Last Update: 2022-02-08): Embedded TCP/IP Stack Vulnerabilities (AMNESIA:33) in SENTRON PAC / 3VA Devices (Part 2)
Published
Feb. 8, 2022, 1 a.m.
Summary
Security researchers discovered and disclosed 33 vulnerabilities in several open-source TCP/IP stacks for embedded devices, also known as “AMNESIA:33” vulnerabilities. This advisory describes the impact of two of these vulnerabilities (CVE-2020-13987, CVE-2020-17437) to Siemens products. Siemens has released updates for several affected products and recommends to update to the latest ...
Title
Sensormatic PowerManage
Published
Feb. 3, 2022, 4:10 p.m.
Summary
This advisory contains mitigations for an Improper Input Validation vulnerability in the Sensormatic PowerManage operating platform.
Title
Airspan Networks Mimosa
Published
Feb. 3, 2022, 4:05 p.m.
Summary
This advisory contains mitigations for Improper Authorization, Incorrect Authorization, Server-side Request Forgery, SQL Injection, Deserialization of Untrusted Data, OS Command Injection, and Use of a Broken or Risky Cryptographic Algorithm vulnerabilities in Airspan Networks Mimosa network management software.
Title
FANUC Robot Controllers (Update A)
Published
Feb. 3, 2022, 4 p.m.
Summary
This advisory is a follow-up to the original advisory titled ICSA-21-243-02P FANUC Robot Controllers that was posted to the HSIN ICS library on August 31, 2021 and subsequently published December 7, 2021, to the ICS webpage on www.cisa.gov/uscert/ics.This advisory contains mitigations for Integer Coercion Error, and Out-of-bounds Write vulnerabilities in ...
Title
Ricon Mobile Industrial Cellular Router
Published
Feb. 1, 2022, 4:10 p.m.
Summary
This advisory contains mitigations for an OS Command Injection vulnerability in the Ricon Mobile Industrial Cellular Router mobile network router.
Title
Advantech ADAM-3600
Published
Feb. 1, 2022, 4:05 p.m.
Summary
This advisory contains mitigations for a Use of Hard-coded Cryptographic Key vulnerability in Advantech ADAM-3600 remote terminal units.
Title
Multiple Data Distribution Service (DDS) Implementations (Update A)
Published
Feb. 1, 2022, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-21-315-02 Multiple Data Distribution Service (DDS) Implementations that was published November 11, 2021, to the ICS webpage on www.cisa.gov/uscert. This advisory contains mitigations for several vulnerabilities in Multiple Data Distribution Service (DDS) Implementations developed by a number of different ...
January 2022
Title
Neues CODESYS Security Advisory 2022-01
Published
Jan. 31, 2022, 9:05 a.m.
Summary
Please check source url for more information.
Title
SSA-661247 V2.4 (Last Update: 2022-01-28): Apache Log4j Vulnerabilities (Log4Shell, CVE-2021-44228, CVE-2021-45046) - Impact to Siemens Products
Published
Jan. 28, 2022, 1 a.m.
Summary
On 2021-12-09, a vulnerability in Apache Log4j (a logging tool used in many Java-based applications) was disclosed, that could allow remote unauthenticated attackers to execute code on vulnerable systems. The vulnerability is tracked as CVE-2021-44228 and is also known as “Log4Shell”. On 2021-12-14 an additional denial of service vulnerability (CVE-2021-45046) ...
Title
Fresenius Kabi Agilia Connect Infusion System (Update A)
Published
Jan. 27, 2022, 4:05 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSMA-21-355-01 Fresenius Kabi Agilia Connect Infusion System that was published December 21, 2021, to the ICS webpage on www.cisa.gov/uscert. This advisory contains mitigations for several vulnerabilities in the Fresenius Kabi Agilia Connect Infusion System.

Last Updates

BOSCH PSIRT
20.03.2024
CODESYS
28.06.2023
SIEMENS CERT
19.04.2024
US CERT
17.04.2024
US CERT (ICS)
30.04.2024

By Source

Archive

2024
2023
2022
2021
2020
2019
2018
2017

Feeds