Bulletins

SIEMENS CERT
03/09/2021
Several industrial products are affected by a vulnerability that could allow remote attackers to conduct a Denial-of-Service (DoS) attack by sending specially crafted packets to port 161/udp (SNMP). Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates …
SIEMENS CERT
03/09/2021
The latest update for affected products fix local privilege escalation vulnerabilities that could allow authorized local users with administrative privileges to execute custom code with SYSTEM level privileges. Siemens has released updates for some of the affected products, and is working on further updates. For the remaining affected products, Siemens …
SIEMENS CERT
03/09/2021
Several industrial devices are affected by two vulnerabilities that could allow an attacker to cause a Denial-of-Service condition via PROFINET DCP network packets under certain circumstances. The precondition for this scenario is a direct layer 2 access to the affected products. PROFIBUS interfaces are not affected. Siemens has released updates …
SIEMENS CERT
03/09/2021
PLUSCONTROL 1st Gen devices are affected by a vulnerability as initially reported in SSA-362164 for the Mentor Nucleus TCP/IP stack. The vulnerability could allow an attacker located in the same network to hijack or terminate TCP/IP sessions of a vulnerable device. Siemens Energy recommends specific countermeasures for use cases of …
SIEMENS CERT
03/09/2021
Some firmware versions of the SCALANCE and RUGGEDCOM devices listed below are affected by a vulnerability in the SSH authentication that could allow an attacker to cause a Denial-of-Service under certain conditions. Siemens has released an update for the SCALANCE SC-600 family and recommends to update to the latest version. …
SIEMENS CERT
03/09/2021
Multiple vulnerabilities affecting SIMATIC S7-PLCSIM V5.4 could allow an attacker with local access to the system to craft special project files that may lead to denial-of-service attacks. Siemens recommends specific workarounds and mitigations.
SIEMENS CERT
03/09/2021
A vulnerability exists in affected products that could allow remote attackers to affect the availability of the devices under certain conditions. The underlying TCP stack can be forced to make very computation expensive calls for every incoming packet which can lead to a Denial-of-Service.
SIEMENS CERT
02/09/2021
Intel has published information on vulnerabilities in Intel products in November 2019. In this advisory Siemens only explicitly mentions the vulnerabilities from the “Intel® CPU Security Advisory” and one vulnerability from “Intel® CSME, Intel® SPS, Intel® TXE, Intel® AMT, Intel® PTT and Intel® DAL Advisory” and lists the Siemens IPC …