Oktober 2022
Titel
Johnson Controls CKS CEVAS
Veröffentlicht
25. Oktober 2022 16:05
Text
Titel
Delta Electronics InfraSuite Device Master
Veröffentlicht
25. Oktober 2022 15:55
Text
Titel
B. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplus (Update A)
Veröffentlicht
22. Oktober 2022 16:00
Text
This advisory contains mitigations for Cross-site Scripting, Open Redirect, XPath Injection, Session Fixation, Use of a One-way Hash without a Salt, Relative Path Traversal, Improper Verification of Cryptographic Signature, Improper Privilege Management, Use of Hard-coded Credentials, Active Debug Code, and Improper Access Control vulnerabilities in B. Braun's SpaceCom, Battery Pack ...
Titel
AA22-294A: #StopRansomware: Daixin Team
Veröffentlicht
21. Oktober 2022 16:29
Text
Original release date: October 21, 2022SummaryActions to take today to mitigate cyber threats from ransomware: • Install updates for operating systems, software, and firmware as soon as they are released. • Require phishing-resistant MFA for as many services as possible. • Train users to recognize and report phishing attempts. Note: ...
Titel
SSA-640732 V1.0: Authentication Bypass Vulnerability in Siveillance Video Mobile Server
Veröffentlicht
21. Oktober 2022 02:00
Text
The mobile server component of Siveillance Video 2022 R2 contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to access the application without a valid account. Siemens has released a hotfix for Siveillance Video 2022 R2 and recommends to apply the hotfix on all installations of the ...
Titel
Bentley Systems MicroStation Connect
Veröffentlicht
20. Oktober 2022 16:10
Text
Titel
B. Braun Infusomat Space Large Volume Pump (Update A)
Veröffentlicht
20. Oktober 2022 16:05
Text
This advisory contains mitigation for Unrestricted Upload of File with Dangerous Type, Cleartext Transmission of Sensitive Information, Missing Authentication for Critical Function, Insufficient Verification of Data Authenticity, and Improper Input Validation vulnerabilities in the B. Braun Infusomat Space Large Volume Pump.
Titel
CVE-2021-3772 Linux Kernel Vulnerability in NetApp DSA E2800 series
Veröffentlicht
19. Oktober 2022 02:00
Text

BOSCH-SA-609377-BT: The Bosch DSA E2800 products are based on NetApp technology, which incorporate a Linux Kernel. Linux Kernel versions prior to 5.15.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS). Successful exploitation of this vulnerability could ...

Titel
Multiple Cross Site Scripting vulnerabilities in Bosch VIDEOJET multi 4000
Veröffentlicht
19. Oktober 2022 02:00
Text

BOSCH-SA-454166-BT: The possibility for a reflected Cross Site Scripting (XSS) and stored Cross Site Scripting (XSS) attack was discovered in the Bosch VIDEOJET multi 4000.For more details please see the description of the vulnerability in this advisory.Bosch rates this vulnerability with CVSSv3.1 base score 5.8 (medium) and 5.1 (medium), where ...

Titel
Siemens Industrial Edge Management
Veröffentlicht
13. Oktober 2022 16:46
Text
Titel
Hitachi Energy Lumada Asset Performance Management Prognostic Model Executor Service
Veröffentlicht
13. Oktober 2022 16:40
Text
This advisory contains mitigations for Allocation of Resources Without Limits or Throttling and Code Injection vulnerabilities in versions of Hitachi Energy Lumada Asset Performance Manager (APM) software.
Titel
Siemens Desigo PXM Devices
Veröffentlicht
13. Oktober 2022 16:38
Text
Titel
Siemens Nucleus RTOS FTP Server
Veröffentlicht
13. Oktober 2022 16:36
Text
Titel
Siemens TCP Event Service of SCALANCE And RUGGEDCOM Devices
Veröffentlicht
13. Oktober 2022 16:34
Text
Titel
Siemens SICAM P850 and P855 Devices
Veröffentlicht
13. Oktober 2022 16:32
Text
Titel
Altair HyperView Player
Veröffentlicht
11. Oktober 2022 16:20
Text
Titel
Daikin Holdings Singapore Pte Ltd. SVMPC1 and SVMPC2
Veröffentlicht
11. Oktober 2022 16:10
Text
Titel
SSB-898115 V1.0: Remarks Regarding SSA-568427 (Weak Key Protection Vulnerability in SIMATIC S7-1200 and S7-1500 CPU Families)
Veröffentlicht
11. Oktober 2022 02:00
Text
Titel
SSA-254054 V1.3 (Last Update: 2022-10-11): Spring Framework Vulnerability (Spring4Shell or SpringShell, CVE-2022-22965) - Impact to Siemens Products
Veröffentlicht
11. Oktober 2022 02:00
Text
A vulnerability in Spring Framework was disclosed, that could allow remote unauthenticated attackers to execute code on vulnerable systems. The vulnerability is tracked as CVE-2022-22965 and is also known as “Spring4Shell” or “SpringShell”. Siemens has released updates for the affected products and recommends to update to the latest versions.
Titel
SSA-568427 V1.0: Weak Key Protection Vulnerability in SIMATIC S7-1200 and S7-1500 CPU Families
Veröffentlicht
11. Oktober 2022 02:00
Text
SIMATIC S7-1200, S7-1500 CPUs and related products protect the built-in global private key in a way that cannot be considered sufficient any longer. The key is used for the legacy protection of confidential configuration data and the legacy PG/PC and HMI communication. This could allow attackers to discover the private ...
Titel
SSA-955858 V1.0: Multiple Vulnerabilities in LOGO! 8 BM Devices
Veröffentlicht
11. Oktober 2022 02:00
Text
LOGO! 8 BM (incl. SIPLUS variants) contains multiple web-related vulnerabilities. These could allow an attacker to execute code remotely, put the device into a denial of service state or retrieve parts of the memory. Siemens is preparing updates and recommends specific countermeasures for products where updates are not, or not ...
Titel
SSA-935500 V1.0: Denial of Service Vulnerability in FTP Server of Nucleus RTOS based APOGEE, TALON and Desigo PXC/PXM Products
Veröffentlicht
11. Oktober 2022 02:00
Text
A denial of service vulnerability has been identified in the Nucleus RTOS (real-time operating system) and reported in the Siemens Security Advisory SSA-313313: https://cert-portal.siemens.com/productcert/html/ssa-313313.html. The products listed below use affected versions of the Nucleus software and inherently contain the vulnerability. Siemens recommends specific countermeasures for products where updates are not, ...
Titel
SSA-280624 V1.1 (Last Update: 2022-10-11): Multiple Vulnerabilities in SCALANCE W1750D
Veröffentlicht
11. Oktober 2022 02:00
Text
The Scalance W1750D device contains multiple vulnerabilities that could allow an attacker to inject commands or exploit multiple buffer overflow vulnerabilities that could lead to denial of service or unauthenticated remote code execution. Siemens has released updates for the SCALANCE W1750D and recommends to update to the latest version. Siemens ...
Titel
SSA-384224 V1.0: Denial of Service Vulnerability in SIMATIC HMI Panels
Veröffentlicht
11. Oktober 2022 02:00
Text
Several SIMATIC HMI Panels are affected by a vulnerability that could allow an attacker to cause a permanent denial of service condition (requiring a device reboot) by sending specially crafted TCP packets. Siemens has released updates for the affected products and recommends to update to the latest versions.
Titel
SSA-360783 V1.0: Multiple Webserver Vulnerabilities in Desigo PXM Devices
Veröffentlicht
11. Oktober 2022 02:00
Text
Desigo PXM devices contain multiple vulnerabilities in the webserver application that could allow an attacker to potentially access sensitive information, execute arbitrary commands, cause a denial of service condition, or perform remote code execution. Siemens has released updates for the affected products and recommends to update to the latest versions.

Letzte Updates

BOSCH PSIRT
21.08.2024
SIEMENS CERT
12.09.2024
US CERT
19.09.2024
US CERT (ICS)
19.09.2024

Nach Quelle

Archiv

2024
2023
2022
2021
2020
2019
2018
2017

Feeds