Juli 2025
Titel
SSA-938066 V1.0: Remote Code Execution Vulnerability in SENTRON Powermanager and Desigo CC
Veröffentlicht
8. Juli 2025 02:00
Text
SENTRON Powermanager and Desigo CC devices are not affected by a remote code execution vulnerability in Apache Tomcat that can be triggered via a partial PUT request due to a path equivalence issue. It could allow a remote attacker to execute arbitrary code, disclose sensitive information, or inject malicious content.
Titel
SSA-876787 V1.8 (Last Update: 2025-07-08): Open Redirect Vulnerability in SIMATIC S7-1500 and S7-1200 CPUs
Veröffentlicht
8. Juli 2025 02:00
Text
Several SIMATIC S7-1500 and S7-1200 CPU versions are affected by an open redirect vulnerability that could allow an attacker to make the web server of affected devices redirect a legitimate user to an attacker-chosen URL. For a successful attack, the legitimate user must actively click on an attacker-crafted link. Siemens ...
Titel
SSA-864900 V1.1 (Last Update: 2025-07-08): Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices
Veröffentlicht
8. Juli 2025 02:00
Text
Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens is preparing fix versions and recommends to consult and implement the workarounds provided in Fortinet’s upstream security notifications.
Titel
SSA-091753 V1.0: Multiple Vulnerabilities in Solid Edge Before SE2025 Update 5
Veröffentlicht
8. Juli 2025 02:00
Text
Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in various formats such as PAR or CFG format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released a new version for Solid ...
Titel
SSA-083019 V1.0: Multiple Vulnerabilities in RUGGEDCOM ROS Devices
Veröffentlicht
8. Juli 2025 02:00
Text
Multiple vulnerabilities affect the RUGGEDCOM Operating System (ROS). Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.
Titel
SSB-104599 V1.0: Increasing Cyber Threats to Industrial Control Systems
Veröffentlicht
7. Juli 2025 02:00
Text
Juni 2025
Titel
SSB-295699 V1.0: Configuration of Microsoft Defender Antivirus for SIMATIC PCS 7 and SIMATIC PCS neo
Veröffentlicht
24. Juni 2025 02:00
Text
Titel
SSA-426509 V1.1 (Last Update: 2025-06-17): Multiple Local Code Execution Vulnerabilities in Questa and ModelSim
Veröffentlicht
17. Juni 2025 02:00
Text
Questa and ModelSim (incl. OEM Editions) are affected by multiple vulnerabilities that could allow a local attacker to inject arbitrary code and escalate privileges. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Titel
SSA-345750 V1.1 (Last Update: 2025-06-16): Default Credentials in Energy Services Using Elspec G5DFR
Veröffentlicht
16. Juni 2025 02:00
Text
Energy Services from Siemens (previously known as Managed Applications and Services), sell solutions using Elspec G5 Digital Fault Recorder which contains default credentials with admin privileges. A client configuration with remote access could allow an attacker to gain remote control of the G5DFR component and tamper outputs from the device.
Titel
SSA-726617 V1.2 (Last Update: 2025-06-12): Incorrect Privilege Assignment Vulnerability in Mendix OIDC SSO Module
Veröffentlicht
12. Juni 2025 02:00
Text
The Mendix OIDC SSO module grants read and write access to all tokens exclusively to the Administrator role and could result in privilege misuse by an adversary modifying the module during Mendix development. Siemens has released new versions for several affected products and recommends to update to the latest versions. ...
Titel
SSA-627195 V1.0: Zip Path Traversal Vulnerability in Mendix Studio Pro's Module Installation Process
Veröffentlicht
12. Juni 2025 02:00
Text
Mendix Studio Pro contains a vulnerability in the module installation process, that could allow an attacker to write or modify arbitrary files in directories outside a developer’s project directory. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further ...
Titel
SSA-082556 V1.0: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5
Veröffentlicht
10. Juni 2025 02:00
Text
Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends countermeasures for products where fixes are not, or not yet available.
Titel
SSA-216014 V1.1 (Last Update: 2025-06-10): Vulnerabilities in EFI variable of SIMATIC IPCs, SIMATIC Tablet PCs, and SIMATIC Field PGs
Veröffentlicht
10. Juni 2025 02:00
Text
Multiple vulnerabilities has been identified in Siemens SIMATIC IPCs, SIMATIC Tablet PCs, and SIMATIC Field PGs that can allow an authenticated attacker to alter the secure boot and password configurations. Siemens has released new versions of BIOS for several affected products and recommends to update to the latest versions. Siemens ...
Titel
SSA-162506 V1.4 (Last Update: 2025-06-10): DHCP Client Vulnerability in SIMOTICS CONNECT 400, Desigo PXC/PXM, APOGEE MEC/MBC/PXC, APOGEE PXC Series, and TALON TC Series
Veröffentlicht
10. Juni 2025 02:00
Text
SIMOTICS CONNECT 400, Desigo (Power PC-based), APOGEE MEC/MBC/PXC and TALON TC products are affected by a DHCP Client vulnerability as initially reported in SSA-434032 for the Mentor Nucleus Networking Module. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens recommends specific countermeasures ...
Titel
SSA-301229 V1.1 (Last Update: 2025-06-10): Client-Side Enforcement of Server-Side Security Vulnerabilities in RUGGEDCOM ROX II
Veröffentlicht
10. Juni 2025 02:00
Text
The web interface of RUGGEDCOM ROX II devices contain multiple Client-Side Enforcement of Server-Side Security vulnerabilities that could allow an attacker with a legitimate, highly privileged account on the web interface to get privileged code execution in the underlying OS of the affected products. Siemens has released new versions for ...
Titel
SSA-054046 V1.6 (Last Update: 2025-06-10): Unauthenticated Information Disclosure in Web Server of SIMATIC S7-1500 CPUs
Veröffentlicht
10. Juni 2025 02:00
Text
Several SIMATIC S7-1500 CPU versions are affected by an authentication bypass vulnerability that could allow an unauthenticated remote attacker to gain knowledge about actual and configured maximum cycle times and communication load of the CPU. Siemens has released new versions for several affected products and recommends to update to the ...
Titel
SSA-265688 V1.6 (Last Update: 2025-06-10): Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP V1.1
Veröffentlicht
10. Juni 2025 02:00
Text
Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP V1.1. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
Titel
SSA-398330 V2.6 (Last Update: 2025-06-10): Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP >= V3.1.0 and < V3.1.5
Veröffentlicht
10. Juni 2025 02:00
Text
Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version >= V3.1.0 and < V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). These GNU/Linux vulnerabilities have been externally identified. Siemens has released new versions for the affected products and recommends to update ...
Titel
SSA-497656 V1.1 (Last Update: 2025-06-10): Multiple NTP Vulnerabilities in TIM 4R-IE Devices
Veröffentlicht
10. Juni 2025 02:00
Text
TIM 4R-IE devices contain multiple vulnerabilities in the integrated NTP component as listed below. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.
Titel
SSA-486186 V1.0: Out of Bounds Read Vulnerability in Tecnomatix Plant Simulation Before 2404
Veröffentlicht
10. Juni 2025 02:00
Text
Siemens Tecnomatix Plant Simulation contains a out-of-bound read vulnerability that could be triggered when the application reads files in WRL format. If a user is tricked to open a malicious file with any of the affected products, this could lead the application to crash or potentially lead to arbitrary code ...
Titel
SSA-366067 V1.4 (Last Update: 2025-06-10): Multiple Vulnerabilities in Fortigate NGFW Before V7.4.1 on RUGGEDCOM APE1808 Devices
Veröffentlicht
10. Juni 2025 02:00
Text
Fortinet has published information on vulnerabilities in FORTIOS. This advisory lists the related Siemens Industrial products. Siemens has released a new version for RUGGEDCOM APE1808 and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or ...
Titel
SSA-354569 V1.5 (Last Update: 2025-06-10): Multiple Vulnerabilities in Palo Alto Networks PAN-OS on RUGGEDCOM APE1808 Devices
Veröffentlicht
10. Juni 2025 02:00
Text
Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Siemens is preparing fix versions and recommends countermeasures for products where fixes are not, or not yet available. [1] https://security.paloaltonetworks.com/
Titel
SSA-513708 V1.0: Reflected Cross-Site Scripting Vulnerability in Palo Alto Networks Virtual NGFW on RUGGEDCOM APE1808 Devices
Veröffentlicht
10. Juni 2025 02:00
Text
Palo Alto Networks has published [1] information on cross-site scripting vulnerability in PAN-OS. This advisory lists the related Siemens Industrial products affected by this vulnerability. Siemens is preparing fix versions and recommends countermeasures for products where fixes are not, or not yet available. Customers are advised to consult and implement ...
Titel
SSA-345750 V1.0: Default Credentials in Energy Services Using Elspec G5DFR
Veröffentlicht
10. Juni 2025 02:00
Text
Siemens Energy Services (previously known as Managed Applications and Services), sell solutions using Elspec G5 Digital Fault Recorder which contains default credentials with admin privileges. A client configuration with remote access could allow an attacker to gain remote control of the G5DFR component and tamper outputs from the device.
Titel
SSA-656895 V1.3 (Last Update: 2025-06-10): Open Redirect Vulnerability in Teamcenter
Veröffentlicht
10. Juni 2025 02:00
Text
The SSO login service in Teamcenter contains an open redirect vulnerability that could allow an attacker to redirect the legitimate user to an attacker-chosen URL to steal valid session data. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Letzte Updates

BOSCH PSIRT
14.08.2025
SIEMENS CERT
26.08.2025
US CERT
25.08.2025
US CERT (ICS)
02.09.2025

Nach Quelle

Archiv

2025
2024
2023
2022
2021
2020
2019
2018
2017

Feeds