März 2018
Titel
SSA-592007 (Last Update: 2018-03-20): Denial-of-Service Vulnerability in Industrial Products
Veröffentlicht
20. März 2018 01:00
Text
Several industrial controllers are affected by a security vulnerability that could allow an attacker to cause a Denial-of-Service condition via PROFINET DCP network packets under certain circumstances. Precondition for this scenario is a direct OSI Layer 2 access to the affected products. PROFIBUS interfaces are not affected. Siemens has released ...
Titel
SSA-822928 (Last Update: 2018-03-20): Access Control Vulnerability in SIMATIC WinCC OA UI Mobile App for Android and iOS
Veröffentlicht
20. März 2018 01:00
Text
The latest update for the Android app and iOS app SIMATIC WinCC OA UI fix a security vulnerability which could allow read and write access from one HMI project cache folder to other HMI project cache folders within the app's sandbox on the same mobile device. This includes HMI project ...
Titel
SSA-168644 (Last Update: 2018-03-15): Spectre and Meltdown Vulnerabilities in Industrial Products
Veröffentlicht
15. März 2018 01:00
Text
Security researchers published information on vulnerabilities known as Spectre and Meltdown. These vulnerabilities affect many modern processors from different vendors to a varying degree. Several Industrial Products include affected processors and are affected by the vulnerabilities.
Titel
SSA-470231 (Last Update: 2018-03-15): TPM Vulnerability in SIMATIC IPCs
Veröffentlicht
15. März 2018 01:00
Text
Several SIMATIC IPCs include a version of Infineon's Trusted Platform Module (TPM) firmware that mishandles RSA key generation. This makes it easier for attackers to conduct cryptographic attacks against the key material. Siemens has released updates for the affected Industrial PCs.
Titel
SSA-323211 (Last Update: 2018-03-15): Vulnerabilities in SIPROTEC 4 and SIPROTEC Compact Devices
Veröffentlicht
15. März 2018 01:00
Text
SIPROTEC 4 and SIPROTEC Compact devices are affected by several vulnerabilities. Two of the vulnerabilities could allow attackers to perform a denial-of-service attack under certain conditions. Siemens has released updates for several affected products, is working on updates for the remaining affected products, and recommends specific countermeasures until fixes are ...
Titel
Omron CX-Supervisor
Veröffentlicht
13. März 2018 15:20
Text
This advisory includes mitigations for missing authentication for stack-based buffer overflow, use after free, access of uninitialized pointer, double free, out-of-bounds write, untrusted pointer dereference, and heap-based buffer overflow vulnerabilities in Omron’s CX-Supervisor.
Titel
OSIsoft PI Data Archive
Veröffentlicht
13. März 2018 15:15
Text
This advisory includes mitigation recommendations for several reported vulnerabilities in the OSIsoft PI Data Archive.
Titel
OSIsoft PI Vision
Veröffentlicht
13. März 2018 15:10
Text
This advisory includes mitigations for protection mechanism failure and information exposure vulnerabilities in the OSIsoft PI Vision.
Titel
OSIsoft PI Web API
Veröffentlicht
13. März 2018 15:05
Text
This advisory includes mitigations for permissions, privileges, and access controls; and cross-site scripting vulnerabilities in the OSIsoft PI Web API.
Titel
GE Medical Devices Vulnerability
Veröffentlicht
13. März 2018 15:00
Text
This medical device advisory was originally posted to the HSIN ICS-CERT library on February 6, 2018, and is being released to the NCCIC/ICS-CERT website. This advisory contains mitigations for an improper authentication vulnerability in several GE medical devices.
Titel
Siemens SIPROTEC 4, SIPROTEC Compact, DIGSI 4, and EN100 Ethernet Module
Veröffentlicht
8. März 2018 16:05
Text
This advisory includes mitigations for missing authentication for critical function, and inadequate encryption strength vulnerabilities in Siemens' SIPROTEC 4, SIPROTEC Compact, DIGSI 4, and EN100 Ethernet module.
Titel
Siemens SIPROTEC 4, SIPROTEC Compact, and Reyrolle Devices using the EN100 Ethernet Communication Module Extension
Veröffentlicht
8. März 2018 16:00
Text
This advisory includes mitigation details for a missing authentication for critical function vulnerability in the Siemens SIPROTEC 4, SIPROTEC Compact, and Reyrolle devices using the EN100 Ethernet communication module extension.
Titel
SSA-203306 (Last Update: 2018-03-08): Password Vulnerabilities in SIPROTEC 4 and SIPROTEC Compact Relay Families
Veröffentlicht
8. März 2018 01:00
Text
SIPROTEC 4 and SIPROTEC Compact devices could allow access authorization passwords to be reconstructed or overwritten via engineering mechanisms that involve DIGSI 4 and EN100 Ethernet communication modules. Siemens has released updates for several affected products, is working on updates for the remaining affected products, and recommends specific countermeasures until ...
Titel
SSA-845879 (Last Update: 2018-03-08): Firmware Downgrade Vulnerability in EN100 Ethernet Communication Module for SIPROTEC 4, SIPROTEC Compact and Reyrolle
Veröffentlicht
8. März 2018 01:00
Text
The EN100 Ethernet communication module, which is an optional extension for SIPROTEC 4, SIPROTEC Compact and Reyrolle devices, allows an unauthenticated upload of firmware updates to the communication module in affected versions. Siemens has released updates for several affected products, is working on updates for the remaining affected products, and ...
Titel
Hirschmann Automation and Control GmbH Classic Platform Switches
Veröffentlicht
6. März 2018 16:10
Text
This advisory includes mitigation recommendations for session fixation, information exposure through query strings in GET request, cleartext transmission of sensitive information, inadequate encryption strength, and improper restriction of excessive authentication attempts vulnerabilities in the Hirschmann Automation and Control GmbH Classic Platform Switches.
Titel
Schneider Electric SoMove Software and DTM Software Components
Veröffentlicht
6. März 2018 16:05
Text
This advisory includes mitigations for an uncontrolled search path element vulnerability in the Schneider Electric SoMove software and DTM software components.
Titel
Eaton ELCSoft
Veröffentlicht
6. März 2018 16:00
Text
This advisory includes mitigation details for an improper input validation vulnerability in the Eaton ELCSoft programming software.
Titel
SSA-293562 (Last Update: 2018-03-06): Vulnerabilities in Industrial Products
Veröffentlicht
6. März 2018 01:00
Text
Several industrial devices are affected by two vulnerabilities that could allow an attacker to cause a Denial-of-Service condition via PROFINET DCP network packets under certain circumstances. Precondition for this scenario is a direct Layer 2 access to the affected products. PROFIBUS interfaces are not affected. Siemens has released updates for ...
Titel
Siemens SIMATIC, SIMOTION, and SINUMERIK
Veröffentlicht
1. März 2018 16:10
Text
This advisory contains mitigation details for stack-based buffer overflow and permissions, privileges, and access controls vulnerabilities in the Siemens' SIMATIC, SIMOTION, and SINUMERIK Industrial PCs.
Titel
Moxa OnCell G3100-HSPA Series
Veröffentlicht
1. März 2018 16:05
Text
This advisory contains mitigation details for reliance on cookies without validation and integrity checking, improper handling of length parameter inconsistency, and NULL pointer dereference vulnerabilities in the Moxa OnCell G3100-HSPA Series IP gateway.
Titel
Delta Electronics Delta Industrial Automation DOPSoft
Veröffentlicht
1. März 2018 16:00
Text
This advisory contains mitigation details for a stack-based buffer overflow vulnerability in the Delta Electronics Delta Industrial Automation DOPSoft human machine interface.
Februar 2018
Titel
Siemens SIMATIC Industrial PCs
Veröffentlicht
27. Februar 2018 20:20
Text
This advisory contains mitigation details for cryptographic issue vulnerabilities in the Siemens' SIMATIC Industrial PCs.
Titel
Siemens SIMATIC Industrial PCs (Update A)
Veröffentlicht
27. Februar 2018 20:20
Text
This updated advisory is a follow-up to the original advisory titled ICSA-18-058-01 Siemens SIMATIC Industrial PCs that was published February 27, 2018, on the NCCIC/ICS-CERT website. This updated advisory contains mitigation details for cryptographic issue vulnerabilities in the Siemens' SIMATIC Industrial PCs.
Titel
Delta Electronics WPLSoft
Veröffentlicht
27. Februar 2018 20:15
Text
This advisory contains mitigation details for stack-based buffer overflow, heap-based buffer overflow, out-of-bounds write vulnerabilities in the Delta Electronics WPLSoft PLC programming software.
Titel
Emerson ControlWave Micro Process Automation Controller
Veröffentlicht
27. Februar 2018 20:10
Text
This advisory includes mitigation recommendations for a stack-based buffer overflow vulnerability in the Emerson ControlWave Micro Process Automation Controller.

Letzte Updates

BOSCH PSIRT
31.10.2024
SIEMENS CERT
13.11.2024
US CERT
08.11.2024
US CERT (ICS)
12.11.2024

Nach Quelle

Archiv

2024
2023
2022
2021
2020
2019
2018
2017

Feeds