März 2022
Titel
SSA-838121 V1.1 (Last Update: 2022-03-08): Multiple Denial of Service Vulnerabilities in Industrial Products
Veröffentlicht
8. März 2022 01:00
Text
Affected SIMATIC firmware contains three vulnerabilities that could allow an unauthenticated attacker to perform a denial-of-service attack under certain conditions. Siemens is preparing updates and recommends specific countermeasures for products where updates are not, or not yet available.
Titel
SSA-223353 V1.0: Multiple Vulnerabilities in Nucleus RTOS based SIMOTICS CONNECT 400
Veröffentlicht
8. März 2022 01:00
Text
Multiple vulnerabilities (also known as “NUCLEUS:13”) have been identified in the Nucleus RTOS (real-time operating system), originally reported in the Siemens Security Advisory SSA-044112: https://cert-portal.siemens.com/productcert/pdf/ssa-044112.pdf. SIMOTICS CONNECT 400 devices are affected by some of the vulnerabilities as documented below. Siemens has released an update for the SIMOTICS CONNECT 400 and ...
Titel
SSA-166747 V1.0: Scene File Parsing Vulnerability in Simcenter STAR-CCM+ Viewer before V2022.1
Veröffentlicht
8. März 2022 01:00
Text
Siemens Simcenter STAR-CCM+ Viewer is affected by a memory corruption vulnerability that could be triggered when the application reads scene (.sce) files. If a user is tricked to open a malicious file with the affected application, this could lead to a crash, and potentially also to arbitrary code execution or ...
Titel
SSA-134279 V1.0: Vulnerability in Mendix Forgot Password Appstore module
Veröffentlicht
8. März 2022 01:00
Text
Mendix Forgot Password Appstore module contains two vulnerabilities that could allow unauthorized users to take over accounts. Mendix has released an update for the Mendix Forgot Password Appstore module and recommends to update to the latest version.
Titel
SSA-155599 V1.0: File Parsing Vulnerabilities in COMOS
Veröffentlicht
8. März 2022 01:00
Text
COMOS uses Drawings SDK from Open Design Alliance that is affected by multiple vulnerabilities that could be triggered when the application reads files in DGN, DXF or DWG file formats. If a user is tricked to open a malicious file with the affected application, an attacker could leverage the vulnerability ...
Titel
SSA-703715 V1.1 (Last Update: 2022-03-08): Information Disclosure Vulnerability in Climatix POL909 (AWM and AWB)
Veröffentlicht
8. März 2022 01:00
Text
Climatix POL909 (AWM and AWB) contains an information disclosure vulnerability that could allow a man-in-the-middle attacker to read sensitive data, such as administrator credentials, or modify data in transit. Siemens has released an update for Climatix POL909 (AWM and AWB) and recommends to update to the latest version.
Titel
SSA-678983 V1.3 (Last Update: 2022-03-08): Vulnerabilities in Industrial PCs and CNC devices using Intel CPUs (November 2020)
Veröffentlicht
8. März 2022 01:00
Text
Intel has published information on vulnerabilities in Intel products in November 2020. This advisory lists the Siemens IPC related products, that are affected by these vulnerabilities. In this advisory we take a representative CVE from each advisory: “Intel CSME, SPS, TXE, AMT and DAL Advisory” Intel-SA-00391 is represented by CVE-2020-8745 ...
Titel
Trailer Power Line Communications (PLC) J2497
Veröffentlicht
4. März 2022 16:00
Text
This advisory contains mitigations for Missing Authentication for Critical Function, and Improper Protection against Electromagnetic Fault Injection vulnerabilities in Power Line Communications (PLC): J2497 (a.k.a. PLC4TRUCKS), a bidirectional, serial communications link over a vehicle power supply line.
Titel
BD Viper LT
Veröffentlicht
3. März 2022 16:05
Text
This advisory contains mitigations for a Use of Hard-coded Credentials vulnerability in the BD Viper LT automated molecular testing system.
Titel
IPCOMM ipDIO
Veröffentlicht
3. März 2022 16:00
Text
This advisory contains mitigations for a Cross-site Scripting, and Code Injection vulnerabilities in the IPCOMM ipDIO telecontrol communication device.
Februar 2022
Titel
AA22-057A: Update: Destructive Malware Targeting Organizations in Ukraine
Veröffentlicht
26. Februar 2022 16:00
Text
Original release date: February 26, 2022 | Last revised: April 28, 2022SummaryActions to Take Today: • Set antivirus and antimalware programs to conduct regular scans. • Enable strong spam filters to prevent phishing emails from reaching end users. • Filter network traffic. • Update software. • Require multifactor authentication. (Updated ...
Titel
AA22-057A: Destructive Malware Targeting Organizations in Ukraine
Veröffentlicht
26. Februar 2022 16:00
Text
Original release date: February 26, 2022SummaryActions to Take Today: • Set antivirus and antimalware programs to conduct regular scans. • Enable strong spam filters to prevent phishing emails from reaching end users. • Filter network traffic. • Update software. • Require multifactor authentication. Leading up to Russia’s unprovoked attack against ...
Titel
AA22-055A : Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks
Veröffentlicht
24. Februar 2022 17:00
Text
Original release date: February 24, 2022SummaryActions to Take Today to Protect Against Malicious Activity * Search for indicators of compromise. * Use antivirus software. * Patch all systems. * Prioritize patching known exploited vulnerabilities. * Train users to recognize and report phishing attempts. * Use multi-factor authentication. Note: this advisory ...
Titel
FATEK Automation FvDesigner
Veröffentlicht
24. Februar 2022 16:15
Text
This advisory contains mitigations for Stack-based Buffer Overflow, Out-of-bounds Write, and Out-of-bounds Read vulnerabilities in FATEK Automation FvDesigner HMI products.
Titel
Mitsubishi Electric EcoWebServerIII
Veröffentlicht
24. Februar 2022 16:10
Text
This advisory contains mitigations for Improper Neutralization of Input During Web Page Generation, Uncontrolled Resource Consumption, and Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerabilities in the Mitsubishi Electric EcoWebServerIII energy saving data collecting server.
Titel
Schneider Electric Easergy P5 and P3
Veröffentlicht
24. Februar 2022 16:05
Text
This advisory contains mitigations for Use of Hard-coded Credentials, and Classic Buffer Overflow vulnerabilities in Schneider Electric Easergy P5 and P3 medium voltage protection relays.
Titel
Baker Hughes Bently Nevada 3500
Veröffentlicht
24. Februar 2022 16:00
Text
This advisory was originally posted to the HSIN ICS library on August 19, 2021, and is being released to the ICS webpage on www.cisa.gov/uscert. This advisory contains mitigations for a Use of Password Hash with Insufficient Computational Effort vulnerability in the Bently Nevada 3500 machinery protection and monitoring systems.
Titel
AA22-054A: New Sandworm Malware Cyclops Blink Replaces VPNFilter
Veröffentlicht
23. Februar 2022 16:00
Text
Original release date: February 23, 2022SummaryThe Sandworm actor, which the United Kingdom and the United States have previously attributed to the Russian GRU, has replaced the exposed VPNFilter malware with a new more advanced framework. The United Kingdom's (UK) National Cyber Security Centre (NCSC), the Cybersecurity and Infrastructure Security Agency ...
Titel
GE Proficy CIMPLICITY-IPM
Veröffentlicht
22. Februar 2022 16:10
Text
This advisory contains mitigations for an Improper Privilege Management vulnerability in GE Proficy CIMPLICITY, a HMI and SCADA platform.
Titel
GE Proficy CIMPLICITY-Cleartext
Veröffentlicht
22. Februar 2022 16:05
Text
This advisory contains mitigations for a Cleartext Transmission of Sensitive Information vulnerability in GE Proficy CIMPLICITY, a HMI and SCADA platform.
Titel
WIN-911 2021
Veröffentlicht
22. Februar 2022 16:00
Text
This advisory contains mitigations for Incorrect Default Permissions vulnerabilities in WIN-911 2021 alarm notification platforms.
Titel
SSA-306654 V1.0: Insyde BIOS Vulnerabilities in Siemens Industrial Products
Veröffentlicht
22. Februar 2022 01:00
Text
Insyde has published information on vulnerabilities in Insyde BIOS in February 2022. This advisory lists the Siemens Industrial products affected by these vulnerabilities. Siemens is preparing updates and recommends specific countermeasures for products where updates are not, or not yet available.
Titel
SSA-244969 V1.1 (Last Update: 2022-02-17): OpenSSL Vulnerability in Industrial Products
Veröffentlicht
17. Februar 2022 01:00
Text
OpenSSL has published a security advisory [0] about a vulnerability in OpenSSL versions 1.1.1 < 1.1.1l and 1.0.2 < 1.0.2za that allows an attacker to cause a denial of service (DoS) or to disclose private memory content. Siemens has released updates for several affected products and recommends to update to ...
Titel
SSA-455843 V1.7 (Last Update: 2022-02-17): WIBU Systems CodeMeter Runtime Vulnerabilities in Siemens Products
Veröffentlicht
17. Februar 2022 01:00
Text
CISA and WIBU Systems disclosed six vulnerabilities in different versions of CodeMeter Runtime, a product provided by WIBU Systems and used in several Siemens products for license management. The vulnerabilities are described in the section “Vulnerability Classification” below and got assigned the CVE IDs CVE-2020-14509, CVE-2020-14513, CVE-2020-14515, CVE-2020-14517, CVE-2020-14519, and ...
Titel
SSA-772220 V1.7 (Last Update: 2022-02-17): OpenSSL Vulnerabilities in Industrial Products
Veröffentlicht
17. Februar 2022 01:00
Text
OpenSSL has published a security advisory [0] about a vulnerability in OpenSSL versions 1.1.1 < 1.1.1k, that allows an unauthenticated attacker to cause a Denial-of-Service (DoS) if a maliciously crafted renegotiation message is sent. Siemens has released updates for several affected products and recommends to update to the latest versions. ...

Letzte Updates

BOSCH PSIRT
21.08.2024
SIEMENS CERT
12.09.2024
US CERT
19.09.2024
US CERT (ICS)
19.09.2024

Nach Quelle

Archiv

2024
2023
2022
2021
2020
2019
2018
2017

Feeds