April 2018
Title
SSA-689071 (Last Update: 2018-04-05): DNSMasq Vulnerabilities in SCALANCE W1750D, SCALANCE M800 and SCALANCE S615
Published
April 5, 2018, 2 a.m.
Summary
Multiple vulnerabilities have been identified in SCALANCE W1750D, SCALANCE M800, and SCALANCE S615 devices. The highest scored vulnerability could allow a remote attacker to crash the DNS service or execute arbitrary code. The attacker must be able to craft malicious DNS responses and inject them into the network in order ...
Title
SSA-901333 (Last Update: 2018-04-05): KRACK Attacks Vulnerabilities in Industrial Products
Published
April 5, 2018, 2 a.m.
Summary
Multiple vulnerabilities affecting WPA/WPA2 implementations were identified by a researcher and publicly disclosed under the term "Key Reinstallation Attacks" (KRACK). These vulnerabilities could potentially allow an attacker within the radio range of the wireless network to decrypt, replay or inject forged network packets into the wireless communication. Several Siemens Industrial ...
Title
Siemens Building Technologies Products (Update A)
Published
April 3, 2018, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-18-093-01 Siemens Building Technologies Products that was published April 3, 2018, on the NCCIC/ICS-CERT website. This advisory update includes mitigations for a series of vulnerabilities in Siemens' Building Technologies Products, including stack-based buffer overflows, security features, improper restriction of ...
Title
Siemens Building Technologies Products
Published
April 3, 2018, 4 p.m.
Summary
This advisory includes mitigations for a series of vulnerabilities in Siemens' Building Technologies Procucts, including stack-based buffer overflow, external control of system or configuration setting, improper restriction ofoperations within the bounds of a memory buffer, NULL pointer deference, XML entity expansion, heap-based buffer overflow, and improper access control.
Title
SSA-727467 (Last Update: 2018-04-03): Vulnerabilities in Building Technologies Products
Published
April 3, 2018, 2 a.m.
Summary
The License Management System (LMS), which is used by multiple Siemens' building automation products, includes a vulnerable version of Gemalto Sentinel LDK RTE. Gemalto Sentinel LDK RTE is affected by multiple vulnerabilities that could allow remote code execution. Siemens recommends to update the License Management System used by these products ...
March 2018
Title
Philips iSite/IntelliSpace PACS Vulnerabilities
Published
March 29, 2018, 8:35 p.m.
Summary
This advisory includes mitigation recommendations for vulnerabilities identified in the Philips Philips iSite and IntelliSpace PACS.
Title
WAGO 750 Series
Published
March 29, 2018, 6:15 p.m.
Summary
This advisory includes mitigations for an improper resource shutdown or release vulnerability in the WAGO 750 series PLC.
Title
Siemens TIM 1531 IRC
Published
March 29, 2018, 6:10 p.m.
Summary
This advisory includes mitigations for an incorrect implementation of authentication algorithm vulnerability in the Siemens TIM 1531 IRC communications modules.
Title
Siemens SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional, and SIMATIC NET PC Software
Published
March 29, 2018, 6:05 p.m.
Summary
This advisory includes mitigations for an improper input validation vulnerability in the Siemens SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional, and SIMATIC NET PC Software.
Title
SSA-727467 (Last Update: 2018-03-28): Vulnerabilities in Building Technologies Products
Published
March 28, 2018, 2 a.m.
Summary
The License Management System (LMS), which is used by multiple Siemens' building automation products, includes a vulnerable version of Gemalto Sentinel LDK RTE. Gemalto Sentinel LDK RTE is affected by multiple vulnerabilities that could allow remote code execution. Siemens recommends to update the License Management System used by these products ...
Title
Schneider Electric Modicon Premium, Modicon Quantum, Modicon M340, and Modicon BMXNOR0200
Published
March 27, 2018, 4:05 p.m.
Summary
This advisory includes mitigations for several vulnerabilities in the Schneider Electric Modicon Premium, Modicon Quantum, Modicon M340, and Modicon BMXNOR0200 PLCs.
Title
Philips Alice 6 Vulnerabilities
Published
March 27, 2018, 4 p.m.
Summary
This advisory includes mitigation recommendations for improper authentication and missing data encryption vulnerabilities identified in the Philips Alice 6 System product.
Title
SSA-592007 (Last Update: 2018-03-27): Denial-of-Service Vulnerability in Industrial Products
Published
March 27, 2018, 2 a.m.
Summary
Several industrial controllers are affected by a security vulnerability that could allow an attacker to cause a Denial-of-Service condition via PROFINET DCP network packets under certain circumstances. Precondition for this scenario is a direct OSI Layer 2 access to the affected products. PROFIBUS interfaces are not affected. Siemens has released ...
Title
SSA-110922 (Last Update: 2018-03-27): Web Vulnerability in TIM 1531 IRC
Published
March 27, 2018, 2 a.m.
Summary
The latest update for TIM 1531 IRC fixes a security vulnerability that could allow unauthorized remote attackers to perform administrative operations on the device. Siemens recommends updating as soon as possible.
Title
SSA-348629 (Last Update: 2018-03-27): Denial-of-Service Vulnerability in SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional and SIMATIC NET PC Software
Published
March 27, 2018, 2 a.m.
Summary
A Denial-of-Service vulnerability has been identified in SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional and SIMATIC NET PC-Software. Siemens has released updates for several affected products and recommends that customers update to the new version. Siemens is preparing further updates and recommends specific countermeasures until patches are available.
Title
Siemens SIMATIC WinCC OA UI Mobile App
Published
March 22, 2018, 3:05 p.m.
Summary
This advisory includes mitigations for an improper access control vulnerability in the Siemens WinCC OA UI mobile app for Android and IOS.
Title
Beckhoff TwinCAT
Published
March 22, 2018, 3 p.m.
Summary
This advisory includes mitigations for an untrusted pointer dereference vulnerability in the Beckhoff TwinCAT PLC products.
Title
Geutebruck IP Cameras
Published
March 20, 2018, 3:05 p.m.
Summary
This advisory includes mitigations for several vulnerabilities in the Geutebrück IP Cameras.
Title
Siemens SIMATIC, SINUMERIK, and PROFINET IO
Published
March 20, 2018, 3 p.m.
Summary
This advisory includes mitigations for an improper input validation vulnerability in the Siemens SIMATIC, SINUMERIK, and PROFINET IO products.
Title
SSA-822928 (Last Update: 2018-03-20): Access Control Vulnerability in SIMATIC WinCC OA UI Mobile App for Android and iOS
Published
March 20, 2018, 1 a.m.
Summary
The latest update for the Android app and iOS app SIMATIC WinCC OA UI fix a security vulnerability which could allow read and write access from one HMI project cache folder to other HMI project cache folders within the app's sandbox on the same mobile device. This includes HMI project ...
Title
SSA-168644 (Last Update: 2018-03-20): Spectre and Meltdown Vulnerabilities in Industrial Products
Published
March 20, 2018, 1 a.m.
Summary
Security researchers published information on vulnerabilities known as Spectre and Meltdown. These vulnerabilities affect many modern processors from different vendors to a varying degree. Several Industrial Products include affected processors and are affected by the vulnerabilities.
Title
SSA-592007 (Last Update: 2018-03-20): Denial-of-Service Vulnerability in Industrial Products
Published
March 20, 2018, 1 a.m.
Summary
Several industrial controllers are affected by a security vulnerability that could allow an attacker to cause a Denial-of-Service condition via PROFINET DCP network packets under certain circumstances. Precondition for this scenario is a direct OSI Layer 2 access to the affected products. PROFIBUS interfaces are not affected. Siemens has released ...
Title
SSA-824231 (Last Update: 2018-03-20): Unauthenticated Firmware Upload Vulnerability in Desigo PX Controllers
Published
March 20, 2018, 1 a.m.
Summary
The latest update for Desigo PXC devices fixes a vulnerability that could allow unauthenticated remote attackers to upload malicious firmware without prior authentication. Siemens recommends updating to the new version.
Title
SSA-470231 (Last Update: 2018-03-15): TPM Vulnerability in SIMATIC IPCs
Published
March 15, 2018, 1 a.m.
Summary
Several SIMATIC IPCs include a version of Infineon's Trusted Platform Module (TPM) firmware that mishandles RSA key generation. This makes it easier for attackers to conduct cryptographic attacks against the key material. Siemens has released updates for the affected Industrial PCs.
Title
SSA-168644 (Last Update: 2018-03-15): Spectre and Meltdown Vulnerabilities in Industrial Products
Published
March 15, 2018, 1 a.m.
Summary
Security researchers published information on vulnerabilities known as Spectre and Meltdown. These vulnerabilities affect many modern processors from different vendors to a varying degree. Several Industrial Products include affected processors and are affected by the vulnerabilities.

Last Updates

BOSCH PSIRT
11.08.2022
CODESYS
27.07.2022
SIEMENS CERT
09.08.2022
US CERT
16.08.2022
US CERT (ICS)
16.08.2022

By Source

Archive

2022
2021
2020
2019
2018
2017

Feeds