Februar 2020
Titel
Honeywell INNCOM INNControl 3
Veröffentlicht
18. Februar 2020 16:10
Text
This advisory contains mitigations for an improper privilege management vulnerability in Honeywell's INNCOM INNControl 3 energy management platform.
Titel
Emerson OpenEnterprise
Veröffentlicht
18. Februar 2020 16:05
Text
This advisory contains mitigations for a heap-based buffer overflow vulnerability in Emerson's OpenEnterprise SCADA Server software.
Titel
Interpeak IPnet TCP/IP Stack (Update C)
Veröffentlicht
18. Februar 2020 16:00
Text
This updated advisory is a follow-up to the updated advisory titled ICSA-19-274-01 Interpeak IPnet TCP/IP Stack (Update B) that was published December 10, 2019, to the ICS webpage on us-cert.gov. This advisory contains mitigations for stack-based buffer overflow, heap-based buffer overflow, integer underflow, improper restriction of operations within the bounds ...
Titel
AA20-049A: Ransomware Impacting Pipeline Operations
Veröffentlicht
18. Februar 2020 14:06
Text
Original release date: February 18, 2020 | Last revised: June 30, 2020SummaryNote: This Activity Alert uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK™) framework. See the MITRE ATT&CK for Enterprise and ATT&CK for Industrial Control Systems (ICS) frameworks for all referenced threat actor techniques and mitigations. The Cybersecurity ...
Titel
Schneider Electric Modicon Ethernet Serial RTU
Veröffentlicht
13. Februar 2020 16:05
Text
This advisory contains mitigations for improper check for unusual or exceptional conditions, and improper access control vulnerabilities in Schneider Electric's Modicon's BMXNOR0200H Ethernet Serial RTU, a remote terminal unit.
Titel
Schneider Electric Magelis HMI Panels
Veröffentlicht
13. Februar 2020 16:00
Text
This advisory contains mitigations for an improper check for unusual or exceptional conditions vulnerability in Schneider's Magelis HMI Panels.
Titel
Synergy Systems & Solutions HUSKY RTU
Veröffentlicht
11. Februar 2020 17:30
Text
This advisory contains mitigations for improper authentication and improper input validation vulnerabilities in Synergy Systems & Solutions HUSKY RTU, a remote terminal unit.
Titel
Siemens Industrial Products SNMP Vulnerabilities
Veröffentlicht
11. Februar 2020 17:25
Text
This advisory contains mitigations for data processing errors and NULL pointer dereference vulnerabilities in Siemens vulnerability in various industrial products, including SCALANCE, SIMATIC, and SIPLUS.
Titel
Siemens SIMATIC CP 1543-1
Veröffentlicht
11. Februar 2020 17:20
Text
This advisory contains mitigations for improper access control and loop with unreachable exit condition vulnerabilities in the Siemens SIMATIC CP 1543-1 communications processor.
Titel
Siemens PROFINET-IO Stack
Veröffentlicht
11. Februar 2020 17:15
Text
This advisory contains mitigations for an internal resource allocation vulnerability in the Siemens PROFINET-IO Stack, which could be exploited to create a denial-of-service condition in products that include the vulnerable stack.
Titel
Siemens SIMATIC PCS 7, SIMATIC WinCC, and SIMATIC NET PC
Veröffentlicht
11. Februar 2020 17:05
Text
This advisory contains mitigations for an incorrect calculation of buffer size vulnerability in some Siemens SIMATIC software products.
Titel
Siemens SIPORT MP
Veröffentlicht
11. Februar 2020 16:55
Text
This advisory contains mitigations for an insufficient logging vulnerability in Siemens SIPORT MP access control and time tracking system.
Titel
Siemens OZW Web Server
Veröffentlicht
11. Februar 2020 16:50
Text
This advisory contains mitigations for an information disclosure vulnerability in the Siemens OZW Web Server.
Titel
Siemens SCALANCE S-600
Veröffentlicht
11. Februar 2020 16:45
Text
This advisory contains mitigations for resource exhaustion and cross-site scripting vulnerabilities in Siemens SCALANCE S-600 industrial security appliance.
Titel
SSA-591405 (Last Update: 2020-02-11): Web Vulnerabilities in SCALANCE S-600 family
Veröffentlicht
11. Februar 2020 01:00
Text
The firmware for SCALANCE S-600 family devices contains multiple web vulnerabilities. The vulnerabilities could allow an remote attacker to conduct Denial-of-Service attacks or perform Cross-Site Scripting attacks. Siemens recommends to migrate to SCALANCE SC-600 Industrial Security Appliances.
Titel
SSB-439005 (Last Update: 2020-02-11): Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
Veröffentlicht
11. Februar 2020 01:00
Text
Titel
SSA-270778 (Last Update: 2020-02-11): Denial-of-Service Vulnerability in SIMATIC PCS 7, SIMATIC WinCC and SIMATIC NET PC Software
Veröffentlicht
11. Februar 2020 01:00
Text
A Denial-of-Service vulnerability was found in SIMATIC PCS 7, SIMATIC WinCC and SIMATIC NET PC software when encrypted communication is enabled. The vulnerability could allow an attacker with network access to cause a Denial-of-Service condition under certain circumstances (versions prior to SIMATIC WinCC V7.3 or SIMATIC PCS 7 V8.1 are ...
Titel
SSA-951513 (Last Update: 2020-02-11): Clickjacking Vulnerability in SCALANCE X-300, X-200IRT, and X-200 Switch Families
Veröffentlicht
11. Februar 2020 01:00
Text
Several SCALANCE X switches contain a vulnerability that could allow an attacker to perform administrative actions if the victim is tricked into clicking on a website controlled by the attacker. The attack only works if the victim has an authenticated session on the administrative interface of the switch. Siemens has ...
Titel
SSA-974843 (Last Update: 2020-02-11): Denial-of-Service Vulnerability in SIPROTEC 4 and SIPROTEC Compact Relay Families
Veröffentlicht
11. Februar 2020 01:00
Text
The SIPROTEC 4 and SIPROTEC Compact devices are affected by a security vulnerability which could allow an attacker to conduct a Denial-of-Service attack over the network when equipped with EN100 Ethernet communication modules. Siemens recommends specific countermeasures to mitigate the issue.
Titel
SSA-780073 (Last Update: 2020-02-11): Denial-of-Service Vulnerability in PROFINET Devices via DCE-RPC Packets
Veröffentlicht
11. Februar 2020 01:00
Text
Products that include the Siemens PROFINET-IO (PNIO) stack in versions prior V06.00 are potentially affected by a denial-of-service vulnerability when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is ...
Titel
SSA-940889 (Last Update: 2020-02-11): Vulnerabilities in the embedded FTP server of SIMATIC CP 1543-1
Veröffentlicht
11. Februar 2020 01:00
Text
The latest update for SIMATIC CP 1543-1 contains two fixes for vulnerabilities within its embedded ProFTPD FTP server. The more severe of these vulnerabilities could allow for remote code execution and information disclosure without authentication. Siemens has released updates for SIMATIC CP 1543-1 modules.
Titel
SSA-978220 (Last Update: 2020-02-11): Denial-of-Service Vulnerability over SNMP in Multiple Industrial Products
Veröffentlicht
11. Februar 2020 01:00
Text
Several industrial products are affected by a vulnerability that could allow remote attackers to conduct a Denial-of-Service (DoS) attack by sending specially crafted packets to port 161/udp (SNMP). Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates ...
Titel
SSA-462066 (Last Update: 2020-02-11): Vulnerability known as TCP SACK PANIC in Industrial Products
Veröffentlicht
11. Februar 2020 01:00
Text
Multiple industrial products are affected by a vulnerability in the kernel known as TCP SACK PANIC. The vulnerability could allow a remote attacker to cause a denial of service condition. Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing ...
Titel
SSA-431678 (Last Update: 2020-02-11): Denial-of-Service Vulnerability in SIMATIC S7 CPU Families
Veröffentlicht
11. Februar 2020 01:00
Text
S7-300/S7-400 and S7-1200 CPU families are affected by a vulnerability that could allow remote attackers to perform a Denial-of-Service attack by sending a specially crafted HTTP request to the web server of an affected device. Siemens has released updates for several affected products, is working on updates for the remaining ...
Titel
SSA-349422 (Last Update: 2020-02-11): Denial-of-Service in Industrial Real-Time (IRT) Devices
Veröffentlicht
11. Februar 2020 01:00
Text
A vulnerability in the affected products could allow an unauthorized attacker with network access to perform a denial-of-service attack resulting in loss of real-time synchronization. Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates and recommends specific ...

Letzte Updates

BOSCH PSIRT
21.08.2024
SIEMENS CERT
12.09.2024
US CERT
19.09.2024
US CERT (ICS)
19.09.2024

Nach Quelle

Archiv

2024
2023
2022
2021
2020
2019
2018
2017

Feeds