März 2025
Titel
SSA-073066 V1.0: Multiple Vulnerabilities in SINEMA Remote Connect Server Before V3.2 SP3
Veröffentlicht
11. März 2025 01:00
Text
SINEMA Remote Connect Server before V3.2 SP3 is affected by multiple vulnerabilities. Siemens has released a new version for SINEMA Remote Connect Server and recommends to update to the latest version.
Titel
SSA-248289 V1.3 (Last Update: 2025-03-11): Denial of Service Vulnerabilities in the IPv6 Stack of Nucleus RTOS
Veröffentlicht
11. März 2025 01:00
Text
The IPv6 stack of the networking component (Nucleus NET) in Nucleus Real-Time Operating System (RTOS) contains two vulnerabilities when processing IPv6 headers which could allow an attacker to cause a denial of service condition. Siemens has released new versions for several affected products and recommends to update to the latest ...
Titel
SSA-194557 V1.2 (Last Update: 2025-03-11): Improper Limitation of Filesystem Access through Web Server Vulnerability in SIPROTEC 5
Veröffentlicht
11. März 2025 01:00
Text
Affected SIPROTEC 5 devices do not properly limit the access of the web server to the filesystem. This could allow an authenticated remote attacker to read arbitrary files or the entire filesystem of the device. Siemens has released new versions for several affected products and recommends to update to the ...
Titel
SSA-620288 V1.3 (Last Update: 2025-03-11): Multiple Vulnerabilities (NUCLEUS:13) in Capital Embedded AR Classic
Veröffentlicht
11. März 2025 01:00
Text
Multiple vulnerabilities (also known as “NUCLEUS:13”) have be identified in the Nucleus RTOS (real-time operating system) and reported in the Siemens Security Advisory SSA-044112: https://cert-portal.siemens.com/productcert/html/ssa-044112.html. Capital Embedded AR Classic uses an affected version of the Nucleus software and inherently contains several of these vulnerabilities. Siemens has released a new version ...
Titel
SSA-434032 V1.2 (Last Update: 2025-03-11): Input Validation Vulnerability in the DHCP Client of Nucleus RTOS
Veröffentlicht
11. März 2025 01:00
Text
The DHCP implementation of the networking component (Nucleus NET) in Nucleus Real-Time Operating System (RTOS) contains a vulnerability that could allow an attacker to change the IP address of an affected device to an invalid value. Siemens has released new versions for several affected products and recommends to update to ...
Titel
SSA-265688 V1.4 (Last Update: 2025-03-11): Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP V1.1
Veröffentlicht
11. März 2025 01:00
Text
Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP V1.1. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
Titel
SSA-216014 V1.0: Vulnerabilities in EFI variable of SIMATIC IPCs, SIMATIC Tablet PCs, and SIMATIC Field PGs
Veröffentlicht
11. März 2025 01:00
Text
Multiple vulnerabilities has been identified in Siemens SIMATIC IPCs, SIMATIC Tablet PCs, and SIMATIC Field PGs that can allow an authenticated attacker to alter the secure boot and password configurations. Siemens has released new versions of BIOS for several affected products and recommends to update to the latest versions. Siemens ...
Titel
SSA-195895 V1.1 (Last Update: 2025-03-11): User Enumeration Vulnerability in the Webserver of SIMATIC Products
Veröffentlicht
11. März 2025 01:00
Text
The webserver of several SIMATIC products is affected by a user enumeration vulnerability that could allow an unauthenticated remote attacker to identify valid usernames. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific ...
Titel
SSA-787280 V1.0: Unlocked Bootloader Vulnerability in SINAMICS S200
Veröffentlicht
11. März 2025 01:00
Text
A specific range of produced SINAMICS S200 devices contains an unlocked bootloader vulnerability that could allow an attacker to download untrusted firmware that could damage or compromise the device. For delivered products listed below Siemens recommends countermeasures.
Titel
SSA-723487 V1.5 (Last Update: 2025-03-11): RADIUS Protocol Susceptible to Forgery Attacks (CVE-2024-3596) - Impact to SCALANCE, RUGGEDCOM and Related Products
Veröffentlicht
11. März 2025 01:00
Text
This advisory documents the impact of CVE-2024-3596 (also dubbed “Blastradius”), a vulnerability in the RADIUS protocol, to SCALANCE, RUGGEDCOM and related products. The vulnerability could allow on-path attackers, located between a Network Access Server (the RADIUS client, e.g., SCALANCE or RUGGEDCOM devices) and a RADIUS server (e.g., SINEC INS), to ...
Titel
SSA-507653 V1.0: Improper Access Control Vulnerabilities in Tecnomatix Plant Simulation
Veröffentlicht
11. März 2025 01:00
Text
Siemens Tecnomatix Plant Simulation do not properly limit the access of the simulation model to the filesystem. This could allow an unauthorized attacker to read or delete arbitrary files or the entire filesystem of the device. Siemens has released new versions for the affected products and recommends to update to ...
Titel
SSA-503939 V1.0: Vulnerabilities in the BIOS of the SIMATIC S7-1500 TM MFP
Veröffentlicht
11. März 2025 01:00
Text
Multiple vulnerabilities have been identified in the BIOS of the SIMATIC S7-1500 TM MFP. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
Titel
SSA-398330 V2.4 (Last Update: 2025-03-11): Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Veröffentlicht
11. März 2025 01:00
Text
Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). These GNU/Linux vulnerabilities have been externally identified. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not ...
Titel
SSA-280834 V1.0: Improper OpenVPN Credential Validation Vulnerability in SCALANCE M-800 and SC-600 Families
Veröffentlicht
11. März 2025 01:00
Text
SCALANCE M-800 and SC-600 families are affected by improper input validation in the OpenVPN authentication. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not ...
Titel
SSA-615740 V1.0: Multiple Vulnerabilities in SINEMA Remote Connect Client Before V3.2 SP3
Veröffentlicht
11. März 2025 01:00
Text
SINEMA Remote Connect Client before V3.2 SP3 is affected by multiple vulnerabilities. Siemens has released a new version for SINEMA Remote Connect Client and recommends to update to the latest version.
Titel
SSA-858251 V1.0: Authentication Bypass Vulnerabilities in OPC UA
Veröffentlicht
11. März 2025 01:00
Text
The products listed below contain two authentication bypass vulnerabilities that could allow an attacker to gain access to the data managed by the server. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures ...
Titel
SSA-876787 V1.4 (Last Update: 2025-03-11): Open Redirect Vulnerability in SIMATIC S7-1500 and S7-1200 CPUs
Veröffentlicht
11. März 2025 01:00
Text
Several SIMATIC S7-1500 and S7-1200 CPU versions are affected by an open redirect vulnerability that could allow an attacker to make the web server of affected devices redirect a legitimate user to an attacker-chosen URL. For a successful attack, the legitimate user must actively click on an attacker-crafted link. Siemens ...
Titel
SSA-928984 V1.1 (Last Update: 2025-03-11): Heap-based Buffer Overflow Vulnerability in User Management Component (UMC)
Veröffentlicht
11. März 2025 01:00
Text
Siemens User Management Component (UMC) is affected by a heap-based buffer overflow vulnerability which could allow an unauthenticated remote attacker arbitrary code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures ...
Titel
SSA-075201 V1.0: Multiple Vulnerabilities in SCALANCE LPE9403 Before V4.0
Veröffentlicht
11. März 2025 01:00
Text
SCALANCE LPE9403 is affected by multiple vulnerabilities that could allow an attacker to impact its confidentiality, integrity and availability. Siemens has released a new version for SCALANCE LPE9403 and recommends to update to the latest version.
Titel
SSA-832273 V1.7 (Last Update: 2025-03-11): Multiple Vulnerabilities in Fortigate NGFW Before V7.4.3 on RUGGEDCOM APE1808 Devices
Veröffentlicht
11. März 2025 01:00
Text
Fortinet has published information on vulnerabilities in FORTIOS. This advisory lists the related Siemens Industrial products. Siemens has released a new version of Fortigate NGFW for RUGGEDCOM APE1808 and recommends to update to the latest version. Siemens recommends to consult and implement the workarounds provided in Fortinet’s upstream security notifications.
Titel
SSA-770770 V1.1 (Last Update: 2025-03-11): Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices
Veröffentlicht
11. März 2025 01:00
Text
Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens is preparing fix versions and recommends to consult and implement the workarounds provided in Fortinet’s upstream security notifications.
Titel
SSA-767615 V1.1 (Last Update: 2025-03-11): Information Disclosure Vulnerability in SIPROTEC 5 Devices
Veröffentlicht
11. März 2025 01:00
Text
An information disclosure vulnerability in SIPROTEC 5 devices could allow an unauthenticated, remote attacker to retrieve sensitive information of the device. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products ...
Titel
SSA-593272 V2.4 (Last Update: 2025-03-11): SegmentSmack in Interniche IP-Stack based Industrial Devices
Veröffentlicht
11. März 2025 01:00
Text
A vulnerability exists in affected products that could allow remote attackers to affect the availability of the devices under certain conditions. The underlying TCP stack can be forced to make very computation expensive calls for every incoming packet which can lead to a Denial-of-Service. Siemens has released new versions for ...
Titel
SSA-515903 V1.0: Multiple Vulnerabilities in SiPass integrated AC5102 / ACC-G2 and ACC-AP
Veröffentlicht
11. März 2025 01:00
Text
SiPass integrated ACC (Advanced Central Controller) devices contain multiple vulnerabilities that could allow attackers to execute commands on the devices with root privileges and access sensitive data. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Titel
SSA-054046 V1.3 (Last Update: 2025-03-11): Unauthenticated Information Disclosure in Web Server of SIMATIC S7-1500 CPUs
Veröffentlicht
11. März 2025 01:00
Text
Several SIMATIC S7-1500 CPU versions are affected by an authentication bypass vulnerability that could allow an unauthenticated remote attacker to gain knowledge about actual and configured maximum cycle times and communication load of the CPU. Siemens has released new versions for several affected products and recommends to update to the ...

Letzte Updates

BOSCH PSIRT
15.01.2025
SIEMENS CERT
11.03.2025
US CERT
19.02.2025
US CERT (ICS)
11.03.2025

Nach Quelle

Archiv

2025
2024
2023
2022
2021
2020
2019
2018
2017

Feeds