August 2022
Titel
SSA-764417 V1.4 (Last Update: 2022-08-09): Weak Encryption Vulnerability in RUGGEDCOM ROS Devices
Veröffentlicht
9. August 2022 02:00
Text
The SSH server on RUGGEDCOM ROS devices is configured to offer weak ciphers by default. This could allow an unauthorized attacker in a man-in-the-middle position to read and modify any data passed over the connection between legitimate clients and the affected device. Siemens recommends specific countermeasures for products where updates ...
Titel
SSA-539476 V1.3 (Last Update: 2022-08-09): Siemens SIMATIC NET CP, SINEMA and SCALANCE Products Affected by Vulnerabilities in Third-Party Component strongSwan
Veröffentlicht
9. August 2022 02:00
Text
Vulnerabilities in the third-party component strongSwan could allow an attacker to cause a denial of service (DoS) condition in affected devices by exploiting integer overflow bugs. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens is preparing further updates and recommends countermeasures ...
Titel
SSA-592007 V1.8 (Last Update: 2022-08-09): Denial-of-Service Vulnerability in Industrial Products
Veröffentlicht
9. August 2022 02:00
Text
Several industrial controllers are affected by a security vulnerability that could allow an attacker to cause a Denial-of-Service condition via PROFINET DCP network packets under certain circumstances. Precondition for this scenario is a direct OSI Layer 2 access to the affected products. PROFIBUS interfaces are not affected. Siemens has released ...
Titel
AA22-216A: 2021 Top Malware Strains
Veröffentlicht
4. August 2022 20:10
Text
Original release date: August 4, 2022SummaryImmediate Actions You Can Take Now to Protect Against Malware: • Patch all systems and prioritize patching known exploited vulnerabilities. • Enforce multifactor authentication (MFA). • Secure Remote Desktop Protocol (RDP) and other risky services. • Make offline backups of your data. • Provide end-user ...
Titel
Digi ConnectPort X2D
Veröffentlicht
4. August 2022 16:05
Text
This advisory contains mitigations for an Execution with Unnecessary Privileges vulnerability in Digi ConnectPort X2D, a connection gateway.
Titel
Delta Electronics DIAEnergie (Update C)
Veröffentlicht
2. August 2022 16:20
Text
This updated advisory is a follow-up to the advisory update titled ICSA-21-238-03 Delta Electronics DIAEnergie (Update B) that was published March 22, 2022, on the ICS webpage at www.cisa.gov/ics. This advisory contains mitigations for Use of Password Hash with Insufficient Computational Effort, Authentication Bypass Using an Alternate Path or Channel, ...
Titel
Mitsubishi Electric FA Engineering Software Products (Update F)
Veröffentlicht
2. August 2022 16:10
Text
his updated advisory is a follow-up to the advisory update titled ICSA-21-049-02 Mitsubishi Electric FA Engineering Software Products (Update E) that was published May 24, 2022, to the ICS webpage on cisa.gov/ics. This advisory contains mitigations for Heap-based Buffer Overflow and Improper Handling of Length Parameter Inconsistency vulnerabilities in various ...
Titel
Mitsubishi Electric Factory Automation Engineering Products (Update H)
Veröffentlicht
2. August 2022 16:00
Text
This updated advisory is a follow-up to the advisory update titled ICSA-20-212-04 Mitsubishi Electric Factory Automation Engineering Products (Update E) that was published May 24, 2022, to the ICS webpage on cisa.gov/ics. This advisory contains mitigations for an Unquoted Search Path or Element vulnerability in various Mitsubishi Electric Factory Automation ...
Titel
Multiple Vulnerabilities in BF-OS
Veröffentlicht
1. August 2022 02:00
Text

BOSCH-SA-013924-BT: Multiple vulnerabilities were identified in BF-OS version 3.x up to and including 3.83 used by Bigfish V3 and PR21 (Energy Platform) devices and Bigfish VM image, which are part of the data collection infrastructure of the Energy Platform solution.The most critical vulnerability may allow an unauthenticated remote attacker to ...

Juli 2022
Titel
Rockwell Products Impacted by Chromium Type Confusion
Veröffentlicht
28. Juli 2022 16:10
Text
This advisory contains mitigations for a Type Confusion vulnerability in various Rockwell Automation products.
Titel
Mitsubishi Electric FA Engineering Software (Update B)
Veröffentlicht
28. Juli 2022 16:05
Text
This updated advisory is a follow-up to the advisory update titled ICSA-21-350-05 Mitsubishi Electric FA Engineering Software (Update A) that was published December 16, 2021, on the ICS webpage on cisa.gov/ics. This advisory contains mitigations for Out-of-bounds Read and Integer Underflow vulnerabilities in Mitsubishi Electric FA Engineering Software, an engineering ...
Titel
Mitsubishi Electric Factory Automation Engineering Software (Update C)
Veröffentlicht
28. Juli 2022 16:00
Text
This updated advisory is a follow-up to the advisory update titled ICSA-20-212-02 Mitsubishi Electric Factory Automation Engineering Software (Update B) that was published May 31, 2021, to the ICS webpage on ucisa.gov/ics.
Titel
MOXA NPort 5110
Veröffentlicht
26. Juli 2022 16:20
Text
This advisory contains mitigations for an Out-of-bounds Write vulnerability in MOXA NPort 5110, a device server.
Titel
Honeywell Saia Burgess PG5 PCD
Veröffentlicht
26. Juli 2022 16:15
Text
This advisory contains mitigations for Authentication Bypass and Use of a Broken or Risky Cryptographic Algorithm vulnerabilities in Honeywell Saia Burgess PG5 PCD, a PLC.
Titel
Honeywell Safety Manager
Veröffentlicht
26. Juli 2022 16:10
Text
This advisory contains mitigations for Insufficient Verification of Data Authenticity, Missing Authentication for Critical Function, and Use of Hard-coded Credentials vulnerabilities in Honeywell Safety Manager, a safety solution of the Experion Process Knowledge System.
Titel
Mitsubishi Electric MELSEC and MELIPC Series (Update D)
Veröffentlicht
26. Juli 2022 16:00
Text
This updated advisory is a follow up to the advisory update titled ICSA-21-334-02 Mitsubishi Electric MELSEC and MELIPC Series (Update C) that was published June 7, 2022, to the ICS webpage on cisa.gov/ics. This advisory contains mitigations for Uncontrolled Resource Consumption, Improper Handling of Length Parameter Inconsistency, and Improper Input ...
Titel
AutomationDirect Stride Field I/O
Veröffentlicht
22. Juli 2022 04:25
Text
This advisory contains mitigations for an Cleartext Transmission of Sensitive Information vulnerability in AutomationDirect products.
Titel
ICONICS Suite and Mitsubishi Electric MC Works64 Products
Veröffentlicht
21. Juli 2022 19:07
Text
This advisory contains mitigations for an Path Traversal, Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere, Out-of-Bounds Read vulnerabilities in the SCADA products.
Titel
Rockwell Automation ISaGRAF Update A
Veröffentlicht
21. Juli 2022 16:20
Text
This updated advisory is a follow-up to the original advisory titled Rockwell Automation ISaGRAF that was published March 29, 2022, on the ICS webpage on cisa.gov/ics. This advisory contains mitigations for an Improper Restriction of XML External Entity Reference vulnerability in Rockwell Automation ISaGRAF software products.
Titel
Rockwell Automation ISaGRAF Workbench
Veröffentlicht
21. Juli 2022 16:15
Text
This advisory contains mitigations for a Missing Authentication for Critical Function vulnerability in the ISaGRAF Workbench.
Titel
Johnson Controls Metasys ADS, ADX, OAS
Veröffentlicht
21. Juli 2022 16:10
Text
This advisory contains mitigations for an Missing Authentication for Critical Function vulnerability in the Metasys ADS, ADX, OAS.
Titel
ABB Drive Composer, Automation Builder, Mint Workbench
Veröffentlicht
21. Juli 2022 16:05
Text
This advisory contains mitigations for an Improper Privilege Management vulnerabilities in the ABB products.
Titel
MiCODUS MV720 GPS tracker
Veröffentlicht
19. Juli 2022 16:05
Text
This advisory contains mitigations for Use of Hard-coded Credentials, Improper Authentication, Cross-site Scripting, and Authorization Bypass Through User-controlled Key vulnerabilities in the MiCODUS MV720 GPS tracker.
Titel
Dahua ASI7213X-T1 (Update A)
Veröffentlicht
19. Juli 2022 16:00
Text
This updated advisory is a follow-up to the original advisory titled ICSA-22-193-01 Dahua ASI7213X-T1 that was published July 12, 2022, on the ICS webpage on cisa.gov/ics. This advisory contains mitigations for Unrestricted Upload of File with Dangerous Type, Authentication Bypass by Capture-replay, and Generation of Error Message Containing Sensitive Information ...
Titel
Siemens SCALANCE X Switch Devices
Veröffentlicht
14. Juli 2022 16:58
Text
This advisory contains mitigations for Use of Insufficiently Random Values, and Classic Buffer Overflow vulnerabilities in the Siemens SCALANCE X Switch Devices industrial ethernet switches.

Letzte Updates

BOSCH PSIRT
15.01.2025
SIEMENS CERT
17.04.2025
US CERT
01.04.2025
US CERT (ICS)
17.04.2025

Nach Quelle

Archiv

2025
2024
2023
2022
2021
2020
2019
2018
2017

Feeds