März 2025
Titel
SSA-039007 V1.4 (Last Update: 2025-03-11): Heap-based Buffer Overflow Vulnerability in User Management Component (UMC)
Veröffentlicht
11. März 2025 01:00
Text
Siemens User Management Component (UMC) is affected by a heap-based buffer overflow vulnerability which could allow an unauthenticated remote attacker arbitrary code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures ...
Titel
SSA-593272 V2.4 (Last Update: 2025-03-11): SegmentSmack in Interniche IP-Stack based Industrial Devices
Veröffentlicht
11. März 2025 01:00
Text
A vulnerability exists in affected products that could allow remote attackers to affect the availability of the devices under certain conditions. The underlying TCP stack can be forced to make very computation expensive calls for every incoming packet which can lead to a Denial-of-Service. Siemens has released new versions for ...
Titel
SSA-195895 V1.1 (Last Update: 2025-03-11): User Enumeration Vulnerability in the Webserver of SIMATIC Products
Veröffentlicht
11. März 2025 01:00
Text
The webserver of several SIMATIC products is affected by a user enumeration vulnerability that could allow an unauthenticated remote attacker to identify valid usernames. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific ...
Titel
SSA-507653 V1.0: Improper Access Control Vulnerabilities in Tecnomatix Plant Simulation
Veröffentlicht
11. März 2025 01:00
Text
Siemens Tecnomatix Plant Simulation do not properly limit the access of the simulation model to the filesystem. This could allow an unauthorized attacker to read or delete arbitrary files or the entire filesystem of the device. Siemens has released new versions for the affected products and recommends to update to ...
Titel
SSA-054046 V1.3 (Last Update: 2025-03-11): Unauthenticated Information Disclosure in Web Server of SIMATIC S7-1500 CPUs
Veröffentlicht
11. März 2025 01:00
Text
Several SIMATIC S7-1500 CPU versions are affected by an authentication bypass vulnerability that could allow an unauthenticated remote attacker to gain knowledge about actual and configured maximum cycle times and communication load of the CPU. Siemens has released new versions for several affected products and recommends to update to the ...
Titel
SSA-928984 V1.1 (Last Update: 2025-03-11): Heap-based Buffer Overflow Vulnerability in User Management Component (UMC)
Veröffentlicht
11. März 2025 01:00
Text
Siemens User Management Component (UMC) is affected by a heap-based buffer overflow vulnerability which could allow an unauthenticated remote attacker arbitrary code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures ...
Februar 2025
Titel
SSA-656895 V1.1 (Last Update: 2025-02-25): Open Redirect Vulnerability in Teamcenter
Veröffentlicht
25. Februar 2025 01:00
Text
The SSO login service in Teamcenter contains an open redirect vulnerability that could allow an attacker to redirect the legitimate user to an attacker-chosen URL to steal valid session data. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
Titel
SSA-354569 V1.2 (Last Update: 2025-02-19): Multiple Vulnerabilities in Palo Alto Networks PAN-OS on RUGGEDCOM APE1808 Devices
Veröffentlicht
19. Februar 2025 01:00
Text
Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Siemens is preparing fix versions and recommends countermeasures for products where fixes are not, or not yet available. [1] https://security.paloaltonetworks.com/
Titel
SSA-992434 V1.0: Directory Traversal Vulnerability in Third-Party Component in SiPass integrated
Veröffentlicht
17. Februar 2025 01:00
Text
SiPass integrated is affected by a directory traversal vulnerability in the third-party component DotNetZip. The vulnerability could allow an attacker to execute arbitrary code on the application server, if a specially crafted backup set is used for a restore. Siemens has released a new version for SiPass integrated and recommends ...
Titel
SSA-246355 V1.1 (Last Update: 2025-02-14): Multiple Vulnerabilities in Tableau Server Component of Opcenter Intelligence
Veröffentlicht
14. Februar 2025 01:00
Text
The Tableau Server component in Opcenter Intelligence contains multiple vulnerabilities as described below. Siemens has released a new version for Opcenter Intelligence and recommends to update to the latest version and to install the latest available version of Tableau Server as described in https://support.sw.siemens.com/knowledge-base/PL8822108.
Titel
SSA-398330 V2.3 (Last Update: 2025-02-11): Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Veröffentlicht
11. Februar 2025 01:00
Text
Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). These GNU/Linux vulnerabilities have been externally identified. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not ...
Titel
SSA-369369 V1.0: Weak Registry Permission Vulnerability in SIMATIC IPC DiagBase and SIMATIC IPC DiagMonitor
Veröffentlicht
11. Februar 2025 01:00
Text
SIMATIC IPC DiagBase and SIMATIC IPC DiagMonitor contain a weak registry permission vulnerability that could allow an authenticated attacker to perform privilege escalation or bypass security measures. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.
Titel
SSA-246355 V1.0: Multiple Vulnerabilities in Tableau Server Component of Opcenter Intelligence
Veröffentlicht
11. Februar 2025 01:00
Text
The Tableau Server component in Opcenter Intelligence contains multiple vulnerabilities as described below. Siemens has released a new version for Opcenter Intelligence and recommends to update to the latest version and to install the latest available version of Tableau Server as described in https://support.sw.siemens.com/knowledge-base/PL8822108.
Titel
SSA-354569 V1.1 (Last Update: 2025-02-11): Multiple Vulnerabilities in Palo Alto Networks Virtual NGFW on RUGGEDCOM APE1808 Devices
Veröffentlicht
11. Februar 2025 01:00
Text
Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Siemens is preparing fix versions and recommends countermeasures for products where fixes are not, or not yet available. [1] https://security.paloaltonetworks.com/
Titel
SSA-224824 V1.0: Denial of Service Vulnerabilities in SIMATIC S7-1200 CPU Family Before V4.7
Veröffentlicht
11. Februar 2025 01:00
Text
SIMATIC S7-1200 CPU family before V4.7 is affected by two denial of service vulnerabilities. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Titel
SSA-687955 V1.0: Accessible Development Shell via Physical Interface in SIPROTEC 5
Veröffentlicht
11. Februar 2025 01:00
Text
Affected SIPROTEC 5 devices contain a development shell which is accessible via a physical interface which is not properly restricted. This could allow an unauthenticated attacker with physical access to an affected device to execute arbitrary commands on the device. Siemens has released new versions for several affected products and ...
Titel
SSA-656895 V1.0: Open Redirect Vulnerability in Teamcenter Before V14.3
Veröffentlicht
11. Februar 2025 01:00
Text
The SSO login service in Teamcenter contains an open redirect vulnerability that could allow an attacker to redirect the legitimate user to an attacker-chosen URL to steal valid session data. Siemens has released a new version for Teamcenter and recommends to update to the latest version.
Titel
SSA-647005 V1.0: Memory Corruption Vulnerability in OpenV2G
Veröffentlicht
11. Februar 2025 01:00
Text
The open source software OpenV2G contains a buffer overflow vulnerability that could allow an attacker to trigger a memory corruption. Siemens has released an update for the OpenV2G and recommends to update to the latest version.
Titel
SSA-697140 V1.3 (Last Update: 2025-02-11): Denial of Service Vulnerability in the TCP Event Service of SCALANCE and RUGGEDCOM Products
Veröffentlicht
11. Februar 2025 01:00
Text
The products listed below contain a denial of service vulnerability in the TCP event interface that could allow an unauthenticated remote attacker to render the device unusable. Siemens has released updates for the affected products and recommends to update to the latest versions.
Titel
SSA-637914 V1.0: Local Code Execution Vulnerability in Questa and ModelSim Before V2025.1
Veröffentlicht
11. Februar 2025 01:00
Text
Questa and ModelSim (incl. OEM Editions) are affected by a vulnerability that could allow a local attacker to inject arbitrary code and escalate privileges. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Titel
SSA-698820 V1.5 (Last Update: 2025-02-11): Multiple Vulnerabilities in Fortigate NGFW Before V7.4.4 on RUGGEDCOM APE1808 Devices
Veröffentlicht
11. Februar 2025 01:00
Text
Fortinet has published information on vulnerabilities in FORTIOS. This advisory lists the related Siemens Industrial products. Siemens has released a new version of Fortigate NGFW for RUGGEDCOM APE1808 and recommends to update to the latest version. Siemens recommends to consult and implement the workarounds provided in Fortinet’s upstream security notifications.
Titel
SSA-615116 V1.0: Multiple Vulnerabilities in Apogee PXC and Talon TC Devices
Veröffentlicht
11. Februar 2025 01:00
Text
Apogee PXC and Talon TC contain a vulnerability that could allow an attacker to perform a denial of service using a out-of-bounds read forcing the device to enter a cold state and a vulnerability that would allow an attacker to decrypt the passwords of the device. Siemens recommends countermeasures for ...
Titel
SSA-769027 V1.0: Multiple Vulnerabilities fixed in SCALANCE W700 IEEE 802.11ax devices before V3.0.0
Veröffentlicht
11. Februar 2025 01:00
Text
SCALANCE W-700 IEEE 802.11ax family devices are affected by multiple vulnerabilities. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Titel
SSA-111547 V1.0: Cleartext Storage of Sensitive Information Vulnerability in SIPROTEC 5
Veröffentlicht
11. Februar 2025 01:00
Text
Affected SIPROTEC 5 devices do not encrypt certain data within the on-board flash storage on their PCB. This could allow an attacker with physical access to read the sensitive information from the filesystem of the device. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are ...
Titel
SSA-832273 V1.6 (Last Update: 2025-02-11): Multiple Vulnerabilities in Fortigate NGFW Before V7.4.3 on RUGGEDCOM APE1808 Devices
Veröffentlicht
11. Februar 2025 01:00
Text
Fortinet has published information on vulnerabilities in FORTIOS. This advisory lists the related Siemens Industrial products. Siemens has released a new version of Fortigate NGFW for RUGGEDCOM APE1808 and recommends to update to the latest version. Siemens recommends to consult and implement the workarounds provided in Fortinet’s upstream security notifications.

Letzte Updates

BOSCH PSIRT
15.01.2025
SIEMENS CERT
14.04.2025
US CERT
01.04.2025
US CERT (ICS)
15.04.2025

Nach Quelle

Archiv

2025
2024
2023
2022
2021
2020
2019
2018
2017

Feeds