SIEMENS CERT
07/09/2019
The latest update for TIA Administrator (TIA Portal) fixes a vulnerability that could allow local users to execute arbitary application commands without proper authentication. Siemens has released an update for the affected software and provides workarounds and mitigations until the update can be applied.
SIEMENS CERT
07/09/2019
A Cross-Site Scripting (XSS) vulnerability was found in the WebSDK component of Spectrum Power™ 3, 4, 5 and 7. A software update is available to address the issue and Siemens recommends installing the patch.
SIEMENS CERT
07/09/2019
Microsoft has released updates for several versions of Microsoft Windows, which fix a vulnerability in the Remote Desktop Service. The vulnerability could allow an unauthenticated remote attacker to execute arbitrary code on the target system if the system exposes the service to the network. The majority of Laboratory Diagnostic products …
SIEMENS CERT
07/09/2019
The SIPROTEC 5 relays and their corresponding engineering software DIGSI 5 are affected by two security vulnerabilities which could allow an attacker to upload or download files to the device or to conduct a Denial-of-Service attack over the network. Siemens has released updates for some affected products, is working on …
SIEMENS CERT
06/11/2019
A vulnerability was identified in several SCALANCE X switches that could allow an attacker to feed information into a network via the mirror port with the monitor barrier feature enabled. The monitor barrier implementation in various SCALANCE products does allow traffic to be directed back into the mirroring network. This …
SIEMENS CERT
06/11/2019
The latest update for the Siveillance VMS line fixes three security vulnerabilities that can cause remote privilege escalation. Siemens has released updates for the affected products and recommends to update affected devices as soon as possible.
SIEMENS CERT
06/11/2019
A vulnerability exists in the affected devices that could allow external entities to reconstruct passwords for users of the affected devices if an attacker is able to obtain a backup of the device configuration. Siemens has released updates for some of the affected devices and is working on updates for …