Wednesday, 27.04.2022
Title
AA22-117A: 2021 Top Routinely Exploited Vulnerabilities
Published
April 27, 2022, 4 p.m.
Summary
Original release date: April 27, 2022SummaryThis joint Cybersecurity Advisory (CSA) was coauthored by cybersecurity authorities of the United States, Australia, Canada, New Zealand, and the United Kingdom: the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI), Australian Cyber Security Centre (ACSC), Canadian Centre ...
Title
SSA-254054 V1.1 (Last Update: 2022-04-27): Spring Framework Vulnerability (Spring4Shell or SpringShell, CVE-2022-22965) - Impact to Siemens Products
Published
April 27, 2022, 2 a.m.
Summary
A vulnerability in Spring Framework was disclosed, that could allow remote unauthenticated attackers to execute code on vulnerable systems. The vulnerability is tracked as CVE-2022-22965 and is also known as “Spring4Shell” or “SpringShell”. Siemens is currently investigating to determine which products are affected and is continuously updating this advisory as ...
Title
Vulnerability in routers FL MGUARD and TC MGUARD
Published
April 27, 2022, 2 a.m.
Summary

BOSCH-SA-982696: The FL MGUARD and TC MGUARD safety devices sold by Bosch Rexroth are devices from Phoenix Contact that have been introduced as trade goods. A security advisory has been published by the manufacturer, which indicates that devices are affected by a possible infinite loop within an OpenSSL library method ...

Title
Improper Control of Generation of Code in Bosch MATRIX
Published
April 27, 2022, 2 a.m.
Summary

BOSCH-SA-309239-BT: The access control and time attendance management software Bosch MATRIX uses a version of the Java Spring Framework that is vulnerable to \"spring4shell\" (CVE-2022-22965). Bosch MATRIX does NOT use a configuration that is currently known to be exploitable using this vulnerability, but as the developers of Spring point out, ...

Tuesday, 26.04.2022
Title
Hitachi Energy System Data Manager
Published
April 26, 2022, 4:05 p.m.
Summary
This advisory contains mitigations for a Integer Overflow or Wraparound, Reachable Assertion, Type Confusion, Uncontrolled Recursion, and Observable Discrepancy vulnerabilities in Hitachi Energy System Data Manager products.
Title
Mitsubishi Electric MELSEC and MELIPC Series (Update B)
Published
April 26, 2022, 4 p.m.
Summary
This updated advisory is a follow up to the advisory update titled ICSA-21-334-02 Mitsubishi Electric MELSEC and MELIPC Series (Update A) that was published January 27, 2022, to the ICS webpage on www.cisa.gov/uscert. This advisory contains mitigations for Uncontrolled Resource Consumption, Improper Handling of Length Parameter Inconsistency, and Improper Input ...
Thursday, 21.04.2022
Title
Delta Electronics ASDA-Soft
Published
April 21, 2022, 4:10 p.m.
Summary
This advisory contains mitigations for Out-of-bounds Write, and Out-of-bounds Read vulnerabilities in Delta Electronics ASDA-Soft servo software.
Title
Johnson Controls Metasys SCT Pro
Published
April 21, 2022, 4:05 p.m.
Summary
This advisory contains mitigations for a Server-side Request Forgery vulnerability in Johnson Controls Metasys SCT Pro building automation software.
Title
Hitachi Energy MicroSCADA Pro/X SYS600
Published
April 21, 2022, 4 p.m.
Summary
This advisory contains mitigations for Observable Discrepancy, HTTP Request Smuggling, Classic Buffer Overflow, Improper Certificate Validation, Improper Restriction of Operations within the Bounds of a Memory Buffer, and Exposure of Sensitive Information to an Unauthorized Actor vulnerabilities in the Hitachi Energy MicroSCADA Pro/X SYS600 SCADA product.
Wednesday, 20.04.2022
Title
AA22-110A: Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
Published
April 20, 2022, 7 p.m.
Summary
Original release date: April 20, 2022SummaryActions critical infrastructure organizations should implement to immediately protect against Russian state-sponsored and criminal cyber threats: • Patch all systems. Prioritize patching known exploited vulnerabilities. • Enforce multifactor authentication. • Secure and monitor Remote Desktop Protocol and other risky services. • Provide end-user awareness and ...
Title
Multiple ctrlX CORE vulnerabilities
Published
April 20, 2022, 2 a.m.
Summary

BOSCH-SA-029150: The base operating system app core20, which is part of ctrlX CORE XCR (base system apps), includes vulnerable versions of expat, libc and OpenSSL. Furthermore, multiple ctrlX CORE apps use at least one of the libraries shipped with core20. An attacker might be able to escalate privileges, gain system ...

Tuesday, 19.04.2022
Title
Interlogix Hills ComNav
Published
April 19, 2022, 4:25 p.m.
Summary
This advisory contains mitigations for Improper Restriction of Excessive Authentication Attempts, and Inadequate Encryption Strength vulnerability in Interlogix Hills ComNav remote access integration modules.
Title
Automated Logic WebCTRL
Published
April 19, 2022, 4:20 p.m.
Summary
This advisory contains mitigations for n Open Redirect vulnerability inAutomated Logic WebCTRL building automation software.
Title
FANUC ROBOGUIDE Simulation Platform
Published
April 19, 2022, 4:15 p.m.
Summary
This advisory contains mitigations for Incorrect Permission Assignment for Critical Resource, Improper Access Control, Path Traversal, Improper Restriction of XML External Entity Reference, and Uncontrolled Resource Consumption vulnerabilities in FANUC ROBOGUIDE simulation software for FANUC robots.
Title
Elcomplus SmartPPT SCADA
Published
April 19, 2022, 4:10 p.m.
Summary
This advisory contains mitigations for Path Traversal, Unrestricted Upload of File with Dangerous Type, Improper Authorization, and Cross-site Scripting vulnerabilities in Elcomplus SmartPPT SCADA voice and data dispatch software.
Title
Elcomplus SmartPTT SCADA
Published
April 19, 2022, 4:10 p.m.
Summary
This advisory contains mitigations for Path Traversal, Unrestricted Upload of File with Dangerous Type, Improper Authorization, and Cross-site Scripting vulnerabilities in Elcomplus SmartPTT SCADA voice and data dispatch software.
Title
Elcomplus SmartPPT SCADA Server
Published
April 19, 2022, 4:05 p.m.
Summary
This advisory contains mitigations for Cross-site Scripting, Unauthorized Exposure to Sensitive Information, Unrestricted Upload of File with Dangerous Type, Path Traversal, and Cross-site Request Forgery vulnerabilities in the Elcomplus SmartPPT SCADA Server voice and data dispatch software.
Title
Elcomplus SmartPTT SCADA Server
Published
April 19, 2022, 4:05 p.m.
Summary
This advisory contains mitigations for Cross-site Scripting, Unauthorized Exposure to Sensitive Information, Unrestricted Upload of File with Dangerous Type, Path Traversal, and Cross-site Request Forgery vulnerabilities in the Elcomplus SmartPTT SCADA Server voice and data dispatch software.
Title
Multiple RTOS (Update E)
Published
April 19, 2022, 4 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-21-119-04 Multiple RTOS (Update D) that was published November 30, 2021, to the ICS webpage on www.cisa.gov/uscert. CISA is aware of a public report, known as “BadAlloc” that details vulnerabilities found in multiple real-time operating systems (RTOS) and supporting ...
Title
SSA-254054 V1.0: Spring Framework Vulnerability (Spring4Shell or SpringShell, CVE-2022-22965) - Impact to Siemens Products
Published
April 19, 2022, 2 a.m.
Summary
A vulnerability in Spring Framework was disclosed, that could allow remote unauthenticated attackers to execute code on vulnerable systems. The vulnerability is tracked as CVE-2022-22965 and is also known as “Spring4Shell” or “SpringShell”. Siemens is currently investigating to determine which products are affected and is continuously updating this advisory as ...
Monday, 18.04.2022
Title
AA22-108A: TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies
Published
April 18, 2022, 3:38 p.m.
Summary
Original release date: April 18, 2022SummaryActions to take today to mitigate cyber threats to cryptocurrency: • Patch all systems. • Prioritize patching known exploited vulnerabilities. • Train users to recognize and report phishing attempts. • Use multifactor authentication. The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency ...
Friday, 15.04.2022
Title
Siemens RUGGEDCOM Devices (Update A)
Published
April 15, 2022, 4:46 a.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-22-069-01 Siemens RUGGEDCOM Devices that was published March 10, 2022, to the ICS webpage on www.cisa.gov/uscert. This advisory contains mitigations for a Missing Encryption of Sensitive Data vulnerability in devices using the Siemens RUGGEDCOM software platform.
Thursday, 14.04.2022
Title
Delta Electronics DMARS
Published
April 14, 2022, 5:20 p.m.
Summary
This advisory contains mitigations for an Improper Restriction of XML External Entity Reference vulnerability in the Delta Electronics DMARS program development tool.
Title
Red Lion DA50N
Published
April 14, 2022, 5:16 p.m.
Summary
This advisory contains mitigation for Insufficient Verification of Data Authenticity, Weak Password Requirements, Use of Unmaintained Third-Party Components, and Insufficiently Protected Credentials vulnerabilities in the Red Lion DA50N networking gateway.
Title
Siemens SCALANCE FragAttacks
Published
April 14, 2022, 5:14 p.m.
Summary
This advisory contains mitigations for Improper Authentication, Injection, Improper Validation of Integrity Check, and Improper Input Validation vulnerabilities in the Siemens SCALANCE FragAttacks.

Last Updates

BOSCH PSIRT
19.10.2022
CODESYS
03.11.2022
SIEMENS CERT
08.11.2022
US CERT
01.12.2022
US CERT (ICS)
01.12.2022

By Source

Archive

2022
2021
2020
2019
2018
2017

Feeds