• 1 (current)
  • 2
Thursday, 25.02.2021
Title
PerFact OpenVPN-Client
Published
Feb. 25, 2021, 4:15 p.m.
Summary
This advisory contains mitigations for an External Control of System or Configuration Setting vulnerability in the PerFact OpenVPN-Client.
Title
Fatek FvDesigner
Published
Feb. 25, 2021, 4:10 p.m.
Summary
This advisory contains mitigations for Use After Free, Access of Uninitialized Pointer, Stack-based Buffer Overflow, Out-of-Bounds Write, and Out-of-Bounds Read vulnerabilities in Fatek FvDesigner software.
Title
Rockwell Automation Logix Controllers
Published
Feb. 25, 2021, 4:05 p.m.
Summary
This advisory contains mitigations for a n Insufficiently Protected Credentials vulnerability in Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, and Logix Controllers.
Title
ProSoft Technology ICX35
Published
Feb. 25, 2021, 4 p.m.
Summary
This advisory contains mitigations for a Permissions, Privileges, and Access Controls vulnerability in ProSoft Technology ICX35 industrial cellular gateways.
Wednesday, 24.02.2021
Title
AA21-055A: Exploitation of Accellion File Transfer Appliance
Published
Feb. 24, 2021, 3 p.m.
Summary
Original release date: February 24, 2021 | Last revised: February 25, 2021SummaryThis joint advisory is the result of a collaborative effort by the cybersecurity authorities of Australia,[1] New Zealand,[2] Singapore,[3] the United Kingdom,[4] and the United States.[5][6] These authorities are aware of cyber actors exploiting vulnerabilities in Accellion File Transfer ...
Title
Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products
Published
Feb. 24, 2021, 1 a.m.
Summary

BOSCH-SA-372917: Linux kernel versions through 5.10.11 contain weaknesses which allow local users to execute code in the kernel with the potential to escalate privileges [1][2]. In versions of sudo before 1.9.5p2 there is a weakness present which allows privilege escalation to root for local users [3]. The ctrlX CORE and ...

Tuesday, 23.02.2021
Title
Advantech BB-ESWGP506-2SFP-T
Published
Feb. 23, 2021, 4:05 p.m.
Summary
This advisory contains mitigations for a Use of Hard-coded Credentials vulnerability in Advantech BB-ESWGP506-2SFP-T industrial ethernet switches.
Title
Advantech Spectre RT Industrial Routers
Published
Feb. 23, 2021, 4 p.m.
Summary
This advisory contains mitigations for Improper Neutralization of Input During Web Page Generation, Cleartext Transmission of Sensitive Information, Improper Restriction of Excessive Authentication Attempts, Use of a Broken or Risky Cryptographic Algorithm, and Use of Platform-Dependent Third-party Components vulnerabilities in Advantech Spectre RT Industrial Routers.
Wednesday, 17.02.2021
Title
AA21-048A: AppleJeus: Analysis of North Korea’s Cryptocurrency Malware
Published
Feb. 17, 2021, 5 p.m.
Summary
Original release date: February 17, 2021 | Last revised: March 2, 2021SummaryThis Advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework. See the ATT&CK for Enterprise for all referenced threat actor tactics and techniques. This joint advisory is the result of analytic efforts among the Federal Bureau ...
Thursday, 11.02.2021
Title
AA21-042A: Compromise of U.S. Water Treatment Facility
Published
Feb. 11, 2021, 8:15 p.m.
Summary
Original release date: February 11, 2021 | Last revised: February 12, 2021SummaryOn February 5, 2021, unidentified cyber actors obtained unauthorized access to the supervisory control and data acquisition (SCADA) system at a U.S. drinking water treatment facility. The unidentified actors used the SCADA system’s software to increase the amount of ...
Title
Multiple Embedded TCP/IP stacks
Published
Feb. 11, 2021, 4:10 p.m.
Summary
This advisory contains mitigations for Use of Insufficiently Random Values vulnerabilities in Nut/Net, CycloneTCP, NDKTCPIP, FNET, uIP-Contiki-OS, uC/TCP-IP, uIP-Contiki-NG, uIP, picoTCP-NG, picoTCP, MPLAB Net, Nucleus NET, Nucleus ReadyStart TCP/IP stacks.
Title
Rockwell Automation DriveTools SP and Drives AOP
Published
Feb. 11, 2021, 4:05 p.m.
Summary
This advisory contains mitigations for an Uncontrolled Search Path Element vulnerability in Rockwell Automation DriveTools SP and Drives AOP software.
Title
Wibu-Systems CodeMeter (Update E)
Published
Feb. 11, 2021, 4 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-20-203-01 Wibu-Systems CodeMeter (Update D) that was published December 3, 2020, to the ICS webpage on us-cert.gov. This advisory contains mitigations for Buffer Access with Incorrect Length Value, Inadequate Encryption Strength, Origin Validation Error, Improper Input Validation, Improper Verification ...
Tuesday, 09.02.2021
Title
GE Digital HMI/SCADA iFIX
Published
Feb. 9, 2021, 5:50 p.m.
Summary
This advisory contains mitigations for Incorrect Permission Assignment for Critical Resource vulnerabilities in the GE Digital HMI/SCADA iFIX software component.
Title
Siemens SINEMA Server & SINEC NMS
Published
Feb. 9, 2021, 5:40 p.m.
Summary
This advisory contains mitigations for a Path Traversal vulnerability in Siemens SINEMA server and SINEC NMS products.
Title
Siemens TIA Administrator
Published
Feb. 9, 2021, 5:30 p.m.
Summary
This advisory contains mitigations for an Improper Access Control vulnerability in Siemens TIA Administrator products.
Title
Siemens SCALANCE W780 and W740
Published
Feb. 9, 2021, 5:20 p.m.
Summary
This advisory contains mitigations for an Allocation of Resources Without Limits or Throttling vulnerability in Siemens SCALANCE W780 and W740 industrial wireless LAN products.
Title
SSA-944678 V1.0: Potential Password Protection Bypass in SIMATIC WinCC
Published
Feb. 9, 2021, 1 a.m.
Summary
A vulnerability in the SIMATIC WinCC Graphics Designer tool could allow an attacker that has physical access to a machine running the software to get access to the user’s private password-protected pictures. Siemens has released an update for SIMATIC WinCC and recommends to update to the latest version. Siemens recommends ...
Title
SSA-100232 V1.2 (Last Update: 2021-02-09): Denial-of-Service vulnerability in SCALANCE X Switches
Published
Feb. 9, 2021, 1 a.m.
Summary
A vulnerability in several SCALANCE X devices could allow an unauthenticated attacker with network access to an affected device to perform a denial-of-service. Siemens has released an update for SCALANCE X-200IRT and recommends to update to the latest version. Siemens recommends specific countermeasures for products where updates are not, or ...
Title
SSA-102233 V1.5 (Last Update: 2021-02-09): SegmentSmack in VxWorks-based Industrial Devices
Published
Feb. 9, 2021, 1 a.m.
Summary
The products listed below contain a vulnerability that could allow remote attackers to affect the availability of the devices under certain conditions. The underlying TCP stack can be forced to make very computation expensive calls for every incoming packet which can lead to a Denial-of-Service. Siemens has released an update ...
Title
SSA-139628 V1.1 (Last Update: 2021-02-09): Vulnerabilities in Web Server for Scalance X Products
Published
Feb. 9, 2021, 1 a.m.
Summary
Several SCALANCE X switches contain vulnerabilities in the web server of the affected devices. An unauthenticated attacker could reboot, cause denial-of-service conditions and potentially impact the system by other means through heap and buffer overflow vulnerabilities. Siemens has released updates for several affected products and recommends to update to the ...
Title
SSA-274900 V1.1 (Last Update: 2021-02-09): Use of hardcoded key in Scalance X devices under certain conditions
Published
Feb. 9, 2021, 1 a.m.
Summary
Scalance X devices might not generate a unique random key after factory reset, and use a private key shipped with the firmware Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens is preparing further updates and recommends specific countermeasures for products where ...
Title
SSA-349422 V1.5 (Last Update: 2021-02-09): Denial-of-Service in Industrial Real-Time (IRT) Devices
Published
Feb. 9, 2021, 1 a.m.
Summary
A vulnerability in the affected products could allow an unauthorized attacker with network access to perform a denial-of-service attack resulting in loss of real-time synchronization. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens is preparing further updates and recommends specific countermeasures ...
Title
SSA-398519 V1.5 (Last Update: 2021-02-09): Vulnerabilities in Intel CPUs (November 2019)
Published
Feb. 9, 2021, 1 a.m.
Summary
Intel has published information on vulnerabilities in Intel products in November 2019. In this advisory Siemens only explicitly mentions the vulnerabilities from the “Intel® CPU Security Advisory” and one vulnerability from “Intel® CSME, Intel® SPS, Intel® TXE, Intel® AMT, Intel® PTT and Intel® DAL Advisory” and lists the Siemens IPC ...
Title
SSB-439005 V3.1 (Last Update: 2021-02-09): Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
Published
Feb. 9, 2021, 1 a.m.
Summary
  • 1 (current)
  • 2

Last Updates

BOSCH PSIRT
11.08.2022
CODESYS
27.07.2022
SIEMENS CERT
09.08.2022
US CERT
16.08.2022
US CERT (ICS)
16.08.2022

By Source

Archive

2022
2021
2020
2019
2018
2017

Feeds