Dienstag, 25.02.2020
Titel
Moxa MB3xxx Series Protocol Gateways
Veröffentlicht
25. Februar 2020 16:20
Text
This advisory contains mitigations for several vulnerabilities in Moxa's MB3xxx series Modbus protocol gateways.
Titel
Moxa ioLogik 2542-HSPA Series Controllers and IOs, and IOxpress Configuration Utility
Veröffentlicht
25. Februar 2020 16:15
Text
This advisory contains mitigations for cleartext storage of sensitive information, cleartext transmission of sensitive information, and incorrectly specified destination in a communication channel vulnerabilities in some Moxa's ioLogik controllers, and IOs and IOxpress configuration utilities.
Titel
Moxa PT-7528 and PT-7828 Series Ethernet Switches
Veröffentlicht
25. Februar 2020 16:10
Text
This advisory contains mitigations for stack-based buffer overflow, broken or risky cryptographic algorithm, hard-coded cryptographic key, hard-coded credentials, weak password requirements, and information exposure vulnerabilities in Moxa's PT-7528 and PT-7828 series Ethernet switches.
Titel
Moxa EDS-G516E and EDS-510E Series Ethernet Switches
Veröffentlicht
25. Februar 2020 16:05
Text
This advisory contains mitigations for several vulnerabilities in Moxa's EDS-G516E and EDS-510E series Ethernet switches.
Titel
Honeywell WIN-PAK
Veröffentlicht
25. Februar 2020 16:00
Text
This advisory contains mitigations for cross-site request forgery, improper neutralization of HTTP headers for scripting syntax, and use of obsolete function vulnerabilities in Honeywell's WIN-PAK monitoring platform.
Donnerstag, 20.02.2020
Titel
B&R Industrial Automation Automation Studio and Automation Runtime
Veröffentlicht
20. Februar 2020 16:15
Text
This advisory contains mitigations for an improper authorization vulnerability in B&R Industrial Automation's Automation Studio and Automation Runtime software.
Titel
B&R Automation Studio and Automation Runtime
Veröffentlicht
20. Februar 2020 16:15
Text
This advisory contains mitigations for an improper authorization vulnerability in B&R Automation Studio and Automation Runtime software.
Titel
Rockwell Automation FactoryTalk Diagnostics
Veröffentlicht
20. Februar 2020 16:10
Text
This advisory contains mitigations for a deserialization of untrusted data vulnerability in Rockwell Automation's FactoryTalk Diagnostics software.
Titel
Honeywell NOTI-FIRE-NET Web Server (NWS-3)
Veröffentlicht
20. Februar 2020 16:05
Text
This advisory contains mitigations for authentication bypass by capture relay, and path traversal vulnerabilities in Honeywell's NOTI-FIRE-NET web servers.
Titel
Auto-Maskin RP210E, DCU210E, and Marine Observer Pro (Android App)
Veröffentlicht
20. Februar 2020 16:00
Text
This advisory contains mitigations for cleartext transmission of sensitive information, origin validation error, use of hard-coded credentials, weak password recovery mechanism for forgotten password, and weak password requirements vulnerabilities in Auto-Maskin's RP 210E Remote Panels, DCU 210E Control Units, and Marine Observer Pro (Android App).
Dienstag, 18.02.2020
Titel
Spacelabs Xhibit Telemetry Receiver (XTR)
Veröffentlicht
18. Februar 2020 16:20
Text
This medical advisory contains mitigations for an improper input validation vulnerability in Spacelabs' Xhibit Telemetry Receiver hardware
Titel
GE Ultrasound products
Veröffentlicht
18. Februar 2020 16:15
Text
This medical advisory contains mitigations for a protection mechanism failure vulnerability in GE ultrasound products.
Titel
Honeywell INNCOM INNControl 3
Veröffentlicht
18. Februar 2020 16:10
Text
This advisory contains mitigations for an improper privilege management vulnerability in Honeywell's INNCOM INNControl 3 energy management platform.
Titel
Emerson OpenEnterprise
Veröffentlicht
18. Februar 2020 16:05
Text
This advisory contains mitigations for a heap-based buffer overflow vulnerability in Emerson's OpenEnterprise SCADA Server software.
Titel
Interpeak IPnet TCP/IP Stack (Update C)
Veröffentlicht
18. Februar 2020 16:00
Text
This updated advisory is a follow-up to the updated advisory titled ICSA-19-274-01 Interpeak IPnet TCP/IP Stack (Update B) that was published December 10, 2019, to the ICS webpage on us-cert.gov. This advisory contains mitigations for stack-based buffer overflow, heap-based buffer overflow, integer underflow, improper restriction of operations within the bounds ...
Titel
AA20-049A: Ransomware Impacting Pipeline Operations
Veröffentlicht
18. Februar 2020 14:06
Text
Original release date: February 18, 2020 | Last revised: June 30, 2020SummaryNote: This Activity Alert uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK™) framework. See the MITRE ATT&CK for Enterprise and ATT&CK for Industrial Control Systems (ICS) frameworks for all referenced threat actor techniques and mitigations. The Cybersecurity ...
Donnerstag, 13.02.2020
Titel
Schneider Electric Modicon Ethernet Serial RTU
Veröffentlicht
13. Februar 2020 16:05
Text
This advisory contains mitigations for improper check for unusual or exceptional conditions, and improper access control vulnerabilities in Schneider Electric's Modicon's BMXNOR0200H Ethernet Serial RTU, a remote terminal unit.
Titel
Schneider Electric Magelis HMI Panels
Veröffentlicht
13. Februar 2020 16:00
Text
This advisory contains mitigations for an improper check for unusual or exceptional conditions vulnerability in Schneider's Magelis HMI Panels.
Dienstag, 11.02.2020
Titel
Synergy Systems & Solutions HUSKY RTU
Veröffentlicht
11. Februar 2020 17:30
Text
This advisory contains mitigations for improper authentication and improper input validation vulnerabilities in Synergy Systems & Solutions HUSKY RTU, a remote terminal unit.
Titel
Siemens Industrial Products SNMP Vulnerabilities
Veröffentlicht
11. Februar 2020 17:25
Text
This advisory contains mitigations for data processing errors and NULL pointer dereference vulnerabilities in Siemens vulnerability in various industrial products, including SCALANCE, SIMATIC, and SIPLUS.
Titel
Siemens SIMATIC CP 1543-1
Veröffentlicht
11. Februar 2020 17:20
Text
This advisory contains mitigations for improper access control and loop with unreachable exit condition vulnerabilities in the Siemens SIMATIC CP 1543-1 communications processor.
Titel
Siemens PROFINET-IO Stack
Veröffentlicht
11. Februar 2020 17:15
Text
This advisory contains mitigations for an internal resource allocation vulnerability in the Siemens PROFINET-IO Stack, which could be exploited to create a denial-of-service condition in products that include the vulnerable stack.
Titel
Siemens SIMATIC PCS 7, SIMATIC WinCC, and SIMATIC NET PC
Veröffentlicht
11. Februar 2020 17:05
Text
This advisory contains mitigations for an incorrect calculation of buffer size vulnerability in some Siemens SIMATIC software products.
Titel
Siemens SIPORT MP
Veröffentlicht
11. Februar 2020 16:55
Text
This advisory contains mitigations for an insufficient logging vulnerability in Siemens SIPORT MP access control and time tracking system.
Titel
Siemens OZW Web Server
Veröffentlicht
11. Februar 2020 16:50
Text
This advisory contains mitigations for an information disclosure vulnerability in the Siemens OZW Web Server.

Letzte Updates

BOSCH PSIRT
31.10.2024
SIEMENS CERT
26.11.2024
US CERT
08.11.2024
US CERT (ICS)
03.12.2024

Nach Quelle

Archiv

2024
2023
2022
2021
2020
2019
2018
2017

Feeds