• 1 (current)
  • 2
  • 3
Thursday, 30.09.2021
Title
Boston Scientific Zoom Latitude
Published
Sept. 30, 2021, 4 p.m.
Summary
This advisory contains mitigations for Use of Password Hash with Insufficient Computational Effort, Missing Protection Against Hardware Reverse Engineering Using Integrated Circuit (IC) Imaging Techniques, Improper Access Control, Missing Support for Integrity Check, and Reliance on Component That is Not Updateable vulnerabilities in the Boston Scientific Zoom Latitude programmer/recorder/monitor (PRM) ...
Tuesday, 28.09.2021
Title
SSA-728618 V1.0: Multiple Vulnerabilities in Solid Edge before SE2021MP8
Published
Sept. 28, 2021, 2 a.m.
Summary
Siemens has released a new version for Solid Edge that fixes multiple file parsing vulnerabilities which could be triggered when the application reads files in IFC, JT or OBJ formats. If a user is tricked to opening a malicious file using the affected application this could lead the application to ...
Thursday, 23.09.2021
Title
Trane Symbio
Published
Sept. 23, 2021, 4:10 p.m.
Summary
This advisory contains mitigations for a Code Injection vulnerability in Trane Symbio 700 and Symbio 800 controllers.
Title
Trane Tracer
Published
Sept. 23, 2021, 4:05 p.m.
Summary
This advisory contains mitigations for a Code Injection vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge building automation products.
Title
Ovarro TBox (Update A)
Published
Sept. 23, 2021, 4 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-21-054-04 Ovarro TBox that was published March 23, 2021, to the ICS webpage on us-cert.cisa.gov. The original advisory was titled ICSA-21-054-04P Ovarro TBox and posted to the HSIN ICS library on February 23, 2021. This advisory contains mitigations for ...
Wednesday, 22.09.2021
Title
AA21-265A: Conti Ransomware
Published
Sept. 22, 2021, 7 p.m.
Summary
Original release date: September 22, 2021SummaryImmediate Actions You Can Take Now to Protect Against Conti Ransomware • Use multi-factor authentication. • Segment and segregate networks and functions. • Update your operating system and software. Note: This Alert uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework, version 9. ...
Thursday, 16.09.2021
Title
AA21-259A: APT Actors Exploiting Newly Identified Vulnerability in ManageEngine ADSelfService Plus
Published
Sept. 16, 2021, 7 p.m.
Summary
Original release date: September 16, 2021SummaryThis Joint Cybersecurity Advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework, Version 8. See the ATT&CK for Enterprise for referenced threat actor tactics and for techniques. This joint advisory is the result of analytic efforts between the Federal Bureau of Investigation ...
Title
Siemens RUGGEDCOM ROX
Published
Sept. 16, 2021, 4:05 p.m.
Summary
This advisory contains mitigations for Exposure of Sensitive Information to an Unauthorized Actor, Execution with Unnecessary Privileges, and Improper Handling of Insufficient Permissions or Privileges vulnerabilities in Siemens RUGGEDCOM ROX devices.
Title
Schneider Electric EcoStruxure and SCADAPack
Published
Sept. 16, 2021, 4 p.m.
Summary
This advisory contains mitigations for a Path Traversal vulnerability in Schneider Electric EcoStruxure Control Expert, EcoStruxure Process Expert, SCADAPack RemoteConnect software designed for the x70 SCADAPack system.
Tuesday, 14.09.2021
Title
Digi PortServer TS 16
Published
Sept. 14, 2021, 5:26 p.m.
Summary
This advisory contains mitigations for an Improper Authentication vulnerability in Digi PortServer TS 16 terminal servers.
Title
Johnson Controls Sensormatic Electronics KT-1
Published
Sept. 14, 2021, 5:24 p.m.
Summary
This advisory contains mitigations for an Authentication Bypass by Capture-replay vulnerability in Sensormatic Electronics KT-1 door controllers. Sensormatic Electronics is a subsidiary of Johnson Controls.
Title
Schneider Electric Struxureware Data Center Expert
Published
Sept. 14, 2021, 5:22 p.m.
Summary
This advisory contains mitigations for OS Command Injection, and Path Traversal vulnerabilities in Schneider Electric Struxureware Data Center Expert monitoring software.
Title
Siemens Simcenter Femap
Published
Sept. 14, 2021, 5:20 p.m.
Summary
This advisory contains mitigations for an Out-of-bounds Read vulnerability in the Siemens Simenter Femap simulation application.
Title
Siemens Simcenter STAR-CCM+ Viewer
Published
Sept. 14, 2021, 5:18 p.m.
Summary
This advisory contains mitigations for an Out-of-bounds Write vulnerability in the Siemens Simcenter Star-CCM+ Viewer simulation application.
Title
Siemens SIMATIC CP
Published
Sept. 14, 2021, 5:16 p.m.
Summary
This advisory contains mitigations for a Cleartext Storage of Sensitive Information vulnerability in Siemens SIMATIC CP communication processors.
Title
Siemens APOGEE and TALON
Published
Sept. 14, 2021, 5:14 p.m.
Summary
This advisory contains mitigations for a Classic Buffer Overflow vulnerability in Siemens APOGEE and TALON building automation systems.
Title
Siemens Teamcenter
Published
Sept. 14, 2021, 5:12 p.m.
Summary
This advisory contains mitigations for Privilege Defined with Unsafe Actions, Authorization Bypass Through User-Controlled Key, and Improper Restriction of XML External Entity Reference vulnerabilities in the Siemens Teamcenter virtualization platform.
Title
Siemens Teamcenter Active Workspace
Published
Sept. 14, 2021, 5:12 p.m.
Summary
This advisory contains mitigations for a Path Traversal vulnerability in the Siemens Teamcenter Active Workspace product lifecycle management system.
Title
Siemens NX
Published
Sept. 14, 2021, 5:10 p.m.
Summary
This advisory contains mitigations for Use After Free, and Out-of-bounds Read vulnerabilities in Siemens NX industrial software.
Title
Siemens SIPROTEC 5 relays
Published
Sept. 14, 2021, 5:08 p.m.
Summary
This advisory contains mitigations for Classic Buffer Overflow vulnerabilities in Siemens SIPROTEC 5 relays.
Title
SSA-535380 V1.0: Command Injection Vulnerability in Siveillance OIS Affecting Several Building Management Systems
Published
Sept. 14, 2021, 2 a.m.
Summary
The Siveillance Open Interface Services (OIS) application used for integration of different subsystems to several Siemens building management systems contains a command injection vulnerability that could allow a remote unauthenticated attacker to execute code on the affected system with root privileges. Siemens has released patches and updates for Siveillance OIS ...
Title
SSA-330339 V1.0: Web Vulnerabilities in SINEC NMS
Published
Sept. 14, 2021, 2 a.m.
Summary
A recent update for SINEC NMS fixed multiple vulnerabilities. The most severe of these vulnerabilities could allow an attacker to manipulate the SINEC NMS configuration by tricking an admin to click on a malicious link. Siemens has released an update for SINEC NMS and recommends to update to the latest ...
Title
SSA-316383 V1.0: NumberJack Vulnerability in LOGO! CMR family and SIMATIC RTU 3000 family
Published
Sept. 14, 2021, 2 a.m.
Summary
A vulnerability has been identified in the underlying TCP/IP stack of LOGO! CMR family and SIMATIC RTU 3000 family devices. It could allow an attacker with network access to the LAN interface of an affected device to hijack an ongoing connection or spoof a new one. The WAN interface, however, ...
Title
SSA-535997 V1.0: Cleartext Storage of Sensitive Information in Multiple SIMATIC Products
Published
Sept. 14, 2021, 2 a.m.
Summary
A cleartext vulnerability was found in the SIMATIC communication processors CP 1543-1 and CP 1545-1 that could allow an attacker to read sensitive information. Siemens has released an update for the SIMATIC CP 1543-1 (incl. SIPLUS variants) and recommends to update to the latest version. Siemens is preparing further updates ...
Title
SSA-549234 V1.0: Denial-of-Service Vulnerability in SIMATIC NET CP Modules
Published
Sept. 14, 2021, 2 a.m.
Summary
A Denial of Service vulnerability was identified in different types of Communication Processors. An attacker could exploit this vulnerability causing the device to become un-operational until the device is restarted. Siemens is preparing updates and recommends specific countermeasures for products where updates are not, or not yet available.
  • 1 (current)
  • 2
  • 3

Last Updates

BOSCH PSIRT
02.05.2022
CODESYS
14.04.2022
SIEMENS CERT
10.05.2022
US CERT
18.05.2022
US CERT (ICS)
24.05.2022

By Source

Archive

2022
2021
2020
2019
2018
2017

Feeds