July 2018
Title
SSA-635129 (Last Update: 2018-07-11): Denial-of-Service Vulnerabilities in EN100 Ethernet Communication Module and SIPROTEC 5 relays
Published
July 11, 2018, 2 a.m.
Summary
The EN100 Ethernet communication module and SIPROTEC 5 relays are affected by security vulnerabilities which could allow an attacker to conduct a Denial-of-Service attack over the network. Siemens has released updates for several affected products, is working on updates for the remaining affected products, and recommends specific countermeasures until fixes ...
Title
SSA-197012 (Last Update: 2018-07-03): Vulnerabilities in SICLOCK central plant clocks
Published
July 3, 2018, 2 a.m.
Summary
SICLOCK TC devices are affected by multiple vulnerabilities that could allow an attacker to cause Denial-of-Service conditions, bypass the authentication, and modify the firmware of the device or the administrative client. SICLOCK TC devices are in a phase out process. Siemens recommends mitigations to reduce the risk.
June 2018
Title
SSA-168644 (Last Update: 2018-06-26): Spectre and Meltdown Vulnerabilities in Industrial Products
Published
June 26, 2018, 2 a.m.
Summary
Security researchers published information on vulnerabilities known as Spectre and Meltdown. These vulnerabilities affect many modern processors from different vendors to a varying degree. Several Industrial Products include affected processors and are affected by the vulnerabilities.
Title
SSA-755010 (Last Update: 2018-06-26): Vulnerability in RAPIDLab 1200 and RAPIDPoint 400/500 Blood Gas Analyzers
Published
June 26, 2018, 2 a.m.
Summary
Siemens Healthineers has become aware of two potential cybersecurity vulnerabilities for the RAPIDLab® 1200 Series and RAPIDPoint® 400/405/500 Blood Gas Analyzers and recommends specific countermeasures to mitigate the risk. At the time of advisory publication, no public exploitation of this security vulnerability is known.
Title
SSA-159860 (Last Update: 2018-06-26): Access Control Vulnerability in IEC 61850 system configurator, DIGSI 5, DIGSI 4, SICAM PAS/PQS, SICAM PQ Analyzer, and SICAM SCC
Published
June 26, 2018, 2 a.m.
Summary
IEC 61850 system configurator, DIGSI 5, DIGSI 4, SICAM PAS/PQS, SICAM PQ Analyzer, and SICAM SCC products are affected by a security vulnerability which could allow an attacker to either exfiltrate limited data from the system or to execute code with operating system user permissions. Siemens has released updates for ...
Title
SSA-966341 (Last Update: 2018-06-19): SMBv1 Vulnerabilities in Molecular Diagnostics Products from Siemens Healthineers
Published
June 19, 2018, 2 a.m.
Summary
Select Molecular Diagnostics products from Siemens Healthineers are affected by the Microsoft Windows SMBv1 vulnerabilities. The exploitability of the vulnerabilities depends on the actual configuration and deployment environment of each product. Siemens Healthineers has developed solutions for all affected products which are available via customer support. Siemens Healthineers also provides ...
Title
SSA-275839 (Last Update: 2018-06-12): Denial-of-Service Vulnerability in Industrial Products
Published
June 12, 2018, 2 a.m.
Summary
Several industrial products are affected by a vulnerability that could allow an attacker to cause a Denial-of-Service condition via PROFINET DCP network packets under certain circumstances. Precondition for this scenario is a direct Layer 2 access to the affected products. Siemens has released updates for several affected products, is working ...
Title
SSA-181018 (Last Update: 2018-06-12): Heap Overflow Vulnerability in SCALANCE X switches, RUGGEDCOM WiMAX, RFID 181-EIP, and SIMATIC RF182C
Published
June 12, 2018, 2 a.m.
Summary
SCALANCE X switches, RUGGEDCOM WiMAX, RFID 181-EIP, and SIMATIC RF182C are affected by a vulnerability that could allow an unprivileged attacker located in the same local network segment (OSI Layer 2) to gain system privileges by sending a specially crafted DHCP response to a client's DHCP request. Siemens has released ...
Title
SSA-523365 (Last Update: 2018-06-12): Vulnerability in SIMATIC PCS 7
Published
June 12, 2018, 2 a.m.
Summary
The latest software update for SIMATIC PCS 7 fixes a vulnerability, which could allow an attacker to cause a Denial-of-Service (DoS) condition under certain circumstances.
Title
SSA-566773 (Last Update: 2018-06-12): Vulnerabilities in Building Technologies Products
Published
June 12, 2018, 2 a.m.
Summary
The License Management System (LMS), which is used by multiple Siemens' building automation products, includes a vulnerable version of Gemalto Sentinel LDK RTE. Gemalto Sentinel LDK RTE is affected by two vulnerabilities that could allow denial-of-service and a cross-site-scripting vulnerability. Siemens recommends updating the affected dongle driver.
Title
SSA-480829 (Last Update: 2018-06-12): Cross-Site-Scripting Vulnerabilities in SCALANCE X Switches
Published
June 12, 2018, 2 a.m.
Summary
Two cross-site-scripting (XSS) vulnerabilities were found in the web server of SCALANCE X switches. Siemens recommends updating the firmware to the newest version as soon as possible.
Title
SSA-931064 (Last Update: 2018-06-12): Authentication Bypass in SIMATIC Logon
Published
June 12, 2018, 2 a.m.
Summary
The latest update for SIMATIC Logon fixes a security vulnerability that could allow attackers to circumvent user authentication under certain conditions. SIMATIC WinCC, SIMATIC PCS 7, SIMATIC PDM, and SIMATIC IT Production Suite provide SIMATIC Logon as component of the product. Installing the SIMATIC Logon update fixes the vulnerability for ...
Title
SSA-323211 (Last Update: 2018-06-12): Vulnerabilities in SIPROTEC 4 and SIPROTEC Compact Devices
Published
June 12, 2018, 2 a.m.
Summary
SIPROTEC 4 and SIPROTEC Compact devices are affected by several vulnerabilities. Two of the vulnerabilities could allow attackers to perform a denial-of-service attack under certain conditions. Siemens has released updates for the affected products and will update this advisory when new information becomes available.
Title
SSA-348629 (Last Update: 2018-06-12): Denial-of-Service Vulnerability in SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional and SIMATIC NET PC Software
Published
June 12, 2018, 2 a.m.
Summary
A Denial-of-Service vulnerability has been identified in SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional and SIMATIC NET PC-Software. Siemens has released updates for several affected products and recommends that customers update to the new version. Siemens is preparing further updates and recommends specific countermeasures until patches are available.
Title
SSA-755010 (Last Update: 2018-06-12): Vulnerability in RAPIDLab 1200 and RAPIDPoint 400/500 Blood Gas Analyzers
Published
June 12, 2018, 2 a.m.
Summary
Siemens Healthineers has become aware of two potential cybersecurity vulnerabilities for the RAPIDLab® 1200 Series and RAPIDPoint® 400/405/500 Blood Gas Analyzers and recommends specific countermeasures to mitigate the risk. At the time of advisory publication, no public exploitation of this security vulnerability is known.
Title
SSA-977428 (Last Update: 2018-06-12): Vulnerabilities in SCALANCE M875
Published
June 12, 2018, 2 a.m.
Summary
Multiple vulnerabilities have been identified in the web interface of SCALANCE M875. The web interface of SCALANCE M875 could allow Cross-Site Request Forgery (CSRF), stored Cross-Site Scripting (XSS), or command injection attacks if an attacker is authenticated or tricks a legitimate authenticated user into accessing a malicious link. Siemens recommends ...
Title
SSA-701708 (Last Update: 2018-06-12): Local Privilege Escalation in Industrial Products
Published
June 12, 2018, 2 a.m.
Summary
In non-default configurations several industrial products are affected by a vulnerability that could allow local Microsoft Windows operating system users to escalate their privileges. Siemens provides updates for several products and a temporary fix for the remaining affected products. Siemens is working on new versions for the remaining affected products ...
May 2018
Title
SSA-168644 (Last Update: 2018-05-29): Spectre and Meltdown Vulnerabilities in Industrial Products
Published
May 29, 2018, 2 a.m.
Summary
Security researchers published information on vulnerabilities known as Spectre and Meltdown. These vulnerabilities affect many modern processors from different vendors to a varying degree. Several Industrial Products include affected processors and are affected by the vulnerabilities.
Title
SSA-457058 (Last Update: 2018-05-23): .NET Security Vulnerability in Siveillance VMS
Published
May 23, 2018, 2 a.m.
Summary
Siemens has released software updates for Siveillance VMS which fix a security vulnerability with the .NET Remoting deserialization that could allow elevation of privileges and/or causing a Denial-of-Service, if affected ports are exposed.
Title
SSA-547990 (Last Update: 2018-05-15): Information Disclosure Vulnerabilities in SIPROTEC 4 and SIPROTEC Compact
Published
May 15, 2018, 2 a.m.
Summary
Information disclosure vulnerabilities in SIPROTEC 4 and SIPROTEC Compact devices could allow an attacker to extract sensitive device information under certain conditions. Siemens has released firmware updates for EN100 Ethernet module included in SIPROTEC 4 and SIPROTEC Compact devices. Siemens has also released a firmware update for SIPROTEC Compact 7SJ80 ...
Title
SSA-346262 (Last Update: 2018-05-15): Denial-of-Service in Industrial Products
Published
May 15, 2018, 2 a.m.
Summary
Several industrial products are affected by a vulnerability that could allow remote attackers to conduct a Denial-of-Service (DoS) attack by sending specially crafted packets to port 161/udp (SNMP). Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates ...
Title
SSA-203306 (Last Update: 2018-05-15): Password Vulnerabilities in SIPROTEC 4 and SIPROTEC Compact Relay Families
Published
May 15, 2018, 2 a.m.
Summary
SIPROTEC 4 and SIPROTEC Compact devices could allow access authorization passwords to be reconstructed or overwritten via engineering mechanisms that involve DIGSI 4 and EN100 Ethernet communication modules. Siemens has released updates for several affected products, is working on updates for the remaining affected products, and recommends specific countermeasures until ...
Title
SSA-914382 (Last Update: 2018-05-15): Denial-of-Service Vulnerability in SIMATIC S7-400
Published
May 15, 2018, 2 a.m.
Summary
SIMATIC S7-400 CPUs are affected by a security vulnerability which could lead to a Denial-of-Service condition of the PLC if specially crafted packets are received and processed. The affected SIMATIC S7-400 CPU hardware versions are in the product cancellation phase or already phased-out. Siemens recommends customers either upgrading to a ...
Title
SSA-689071 (Last Update: 2018-05-09): DNSMasq Vulnerabilities in SCALANCE W1750D, SCALANCE M800 and SCALANCE S615
Published
May 9, 2018, 2 a.m.
Summary
Multiple vulnerabilities have been identified in SCALANCE W1750D, SCALANCE M800, and SCALANCE S615 devices. The highest scored vulnerability could allow a remote attacker to crash the DNS service or execute arbitrary code. The attacker must be able to craft malicious DNS responses and inject them into the network in order ...
Title
SSA-346262 (Last Update: 2018-05-03): Denial-of-Service in Industrial Products
Published
May 3, 2018, 2 a.m.
Summary
Several industrial products are affected by a vulnerability that could allow remote attackers to conduct a Denial-of-Service (DoS) attack by sending specially crafted packets to port 161/udp (SNMP). Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates ...

Last Updates

BOSCH PSIRT
20.03.2024
CODESYS
28.06.2023
SIEMENS CERT
19.04.2024
US CERT
17.04.2024
US CERT (ICS)
18.04.2024

By Source

Archive

2024
2023
2022
2021
2020
2019
2018
2017

Feeds