Januar 2021
Titel
SSA-274900 V1.0: Use of hardcoded key in Scalance X devices under certain conditions
Veröffentlicht
12. Januar 2021 01:00
Text
Scalance X devices might not generate a unique random key after factory reset, and use a private key shipped with the firmware Siemens has released updates for some devices, is working on updates for the remaining affected products and recommends specific countermeasures until fixes are available.
Titel
SSA-979834 V1.0: Multiple vulnerabilities in Solid Edge
Veröffentlicht
12. Januar 2021 01:00
Text
Solid Edge is affected by multiple vulnerabilities that could allow arbitrary code execution on an affected system. Siemens has released an update for Solid Edge and recommends to update to the latest version.
Titel
SSA-604937 V1.2 (Last Update: 2021-01-12): Multiple Web Server Vulnerabilities in Opcenter Execution Core
Veröffentlicht
12. Januar 2021 01:00
Text
Opcenter Execution Core (formerly known as Camstar Enterprise Platform) contains a cross-site scripting (CVE-2020-7576), an SQL injection (CVE-2020-7577), a privilege escalation (CVE-2020-7578), and an information disclosure vulnerability (CVE-2020-28930) in various versions of the product. Siemens has released an update for Opcenter Execution Core and recommends to update to the latest ...
Titel
SSA-473245 V1.9 (Last Update: 2021-01-12): Denial-of-Service Vulnerability in Profinet Devices
Veröffentlicht
12. Januar 2021 01:00
Text
A vulnerability in affected devices could allow an attacker to perform a denial-of-service attack if a large amount of specially crafted UDP packets are sent to the device. Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates ...
Titel
SSA-455843 V1.3 (Last Update: 2021-01-12): WIBU Systems CodeMeter Runtime Vulnerabilities in Siemens and Siemens Energy Products
Veröffentlicht
12. Januar 2021 01:00
Text
CISA and WIBU Systems disclosed six vulnerabilities in different versions of CodeMeter Runtime, a product provided by WIBU Systems and used in several Siemens and Siemens Energy products for license management. The vulnerabilities are described in the section “Vulnerability Classification” below and got assigned the CVE IDs CVE-2020-14509, CVE-2020-14513, CVE-2020-14515, ...
Titel
SSA-162506 V1.1 (Last Update: 2021-01-12): DHCP Client Vulnerability in SIMOTICS CONNECT 400, Desigo PXC/PXM, APOGEE MEC/MBC/PXC, APOGEE PXC Series, and TALON TC Series
Veröffentlicht
12. Januar 2021 01:00
Text
SIMOTICS CONNECT 400, Desigo (Power PC-based), APOGEE MEC/MBC/PXC and TALON TC products are affected by a DHCP Client vulnerability as initially reported in SSA-434032 for the Mentor Nucleus Networking Module. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens recommends countermeasures for ...
Titel
SSA-139628 V1.0: Vulnerabilities in Web Server for Scalance X Products
Veröffentlicht
12. Januar 2021 01:00
Text
Several SCALANCE X switches contain vulnerabilities in the web server of the affected devices. An unauthenticated attacker could reboot, cause denial-of-service conditions and potentially impact the system by other means through heap and buffer overflow vulnerabilities. Siemens has released updates for several affected products and recommends to update to the ...
Titel
SSA-270778 V1.6 (Last Update: 2021-01-12): Denial-of-Service Vulnerability in SIMATIC PCS 7, SIMATIC WinCC and SIMATIC NET PC Software
Veröffentlicht
12. Januar 2021 01:00
Text
A Denial-of-Service vulnerability was found in SIMATIC PCS 7, SIMATIC WinCC and SIMATIC NET PC software when encrypted communication is enabled. The vulnerability could allow an attacker with network access to cause a Denial-of-Service condition under certain circumstances (versions prior to SIMATIC WinCC V7.3 or SIMATIC PCS 7 V8.1 are ...
Titel
SSA-312271 V1.5 (Last Update: 2021-01-12): Unquoted Search Path Vulnerabilities in Windows-based Industrial Software Applications
Veröffentlicht
12. Januar 2021 01:00
Text
The latest update for affected products fix local privilege escalation vulnerabilities that could allow authorized local users with administrative privileges to execute custom code with SYSTEM level privileges. Siemens has released updates for some of the affected products, and is working on further updates. For the remaining affected products, Siemens ...
Dezember 2020
Titel
SSA-102233 V1.3 (Last Update: 2020-12-08): SegmentSmack in VxWorks-based Industrial Devices
Veröffentlicht
8. Dezember 2020 01:00
Text
The products listed below contain a vulnerability that could allow remote attackers to affect the availability of the devices under certain conditions. The underlying TCP stack can be forced to make very computation expensive calls for every incoming packet which can lead to a Denial-of-Service. Siemens is working on software ...
Titel
SSA-102144 V1.1 (Last Update: 2020-12-08): Code Execution Vulnerability in LOGO! Soft Comfort
Veröffentlicht
8. Dezember 2020 01:00
Text
A vulnerability was identified in LOGO! Soft Comfort. The vulnerability could allow an attacker to execute arbitrary code if the attacker tricks a legitimate user to open a manipulated project. Siemens has released an update for the LOGO! Soft Comfort and recommends that customers update to the latest version.
Titel
SSA-87240 V1.2 (Last Update: 2020-12-08): Vulnerabilities in SIEMENS LOGO!
Veröffentlicht
8. Dezember 2020 01:00
Text
Two vulnerabilities have been identified in SIEMENS LOGO!8 BM devices. The most severe vulnerability could allow an attacker to hijack existing web sessions. Siemens has released updates for the affected products and recommends that customers update to the latest version.
Titel
SSA-712690 V1.0: Vulnerabilities in XHQ Operations Intelligence
Veröffentlicht
8. Dezember 2020 01:00
Text
Multiple vulnerabilities have been identified in the XHQ Operations Intelligence product line. These vulnerabilities could allow for data injection in the XHQ’s web interfaces. Siemens recommends to update XHQ Operations Intelligence product line to the newest version.
Titel
SSA-700697 V1.0: Denial-of-Service Vulnerability in Web Server of SIMATIC Controllers
Veröffentlicht
8. Dezember 2020 01:00
Text
SIMATIC ET 200SP Open Controller V20.8 and SIMATIC S7-1500 Software Controller V20.8 are affected by a denial-of-service vulnerability in the web server. Siemens has released updates for the affected products and recommends to update to the latest version.
Titel
SSA-541017 V1.0: Embedded TCP/IP Stack Vulnerabilities (AMNESIA:33) in SIRIUS 3RW5 Modbus TCP and SENTRON PAC Devices
Veröffentlicht
8. Dezember 2020 01:00
Text
Recently security researchers discovered and disclosed 33 vulnerabilities in several open-source TCP/IP stacks for embedded devices, also known as “AMNESIA:33” vulnerabilities. The Siemens products mentioned below are affected by one of these vulnerabilities (CVE-2020-13988). Siemens has released updates for SENTRON PAC devices, is working on updates for SIRIUS 3RW5 communication ...
Titel
SSA-480824 V1.0: Multiple Vulnerabilities in LOGO! 8 BM
Veröffentlicht
8. Dezember 2020 01:00
Text
The latest update for LOGO! 8 BM fixes multiple vulnerabilities. The most severe could allow an attacker with network access to gain full control over the device. Siemens has released updates for the affected products and recommends that customers update to the latest version.
Titel
SSA-478893 V1.0: TightVNC Vulnerabilities in Industrial Products
Veröffentlicht
8. Dezember 2020 01:00
Text
Multiple TightVNC (V1.x) vulnerabilities in the affected products could allow remote code execution and Denial-of-Service attacks under certain conditions. Siemens has released updates for several affected products, is working on updates for the remaining affected products and recommends specific countermeasures until fixes are available.
Titel
SSA-415783 V1.0: Insecure SSL configuration in SICAM A8000 CP-8000, CP-8021 and CP-8022
Veröffentlicht
8. Dezember 2020 01:00
Text
Some firmware versions of the affected products use outdated and insecure ciphers or can be downgraded to use outdated and insecure ciphers.
Titel
SSA-087240 V1.2 (Last Update: 2020-12-08): Vulnerabilities in SIEMENS LOGO!
Veröffentlicht
8. Dezember 2020 01:00
Text
Two vulnerabilities have been identified in SIEMENS LOGO!8 BM devices. The most severe vulnerability could allow an attacker to hijack existing web sessions. Siemens has released updates for the affected products and recommends that customers update to the latest version.
Titel
SSA-542701 V1.2 (Last Update: 2020-12-08): Vulnerabilities in SIEMENS LOGO!
Veröffentlicht
8. Dezember 2020 01:00
Text
Multiple vulnerabilities have been identified in SIEMENS LOGO!8 BM devices. The most severe vulnerability could lead to an attacker reading and modifying the device configuration if the attacker has access to port 10005/tcp. Siemens has released an update for the LOGO! 8 BM (incl. SIPLUS variants) and recommends that customers ...
Titel
SSA-841348 V1.4 (Last Update: 2020-12-08): Multiple Vulnerabilities in the UMC Stack
Veröffentlicht
8. Dezember 2020 01:00
Text
The latest update for the below listed products fixes two security vulnerabilities that could allow an attacker to cause a partial Denial-of-Service on the UMC component of the affected devices under certain circumstances, and one vulnerability that could allow an attacker to locally escalate privileges from a user with administrative ...
Titel
SSA-817401 V1.1 (Last Update: 2020-12-08): Missing Authentication Vulnerability in SIEMENS LOGO!
Veröffentlicht
8. Dezember 2020 01:00
Text
A missing authentication vulnerability has been identified in SIEMENS LOGO!8 BM devices. The vulnerability could lead to an attacker reading and modifying the device configuration and obtain project files from the devices if the attacker has access to port 135/tcp.
Titel
SSA-780073 V1.6 (Last Update: 2020-12-08): Denial-of-Service Vulnerability in PROFINET Devices via DCE-RPC Packets
Veröffentlicht
8. Dezember 2020 01:00
Text
Products that include the Siemens PROFINET-IO (PNIO) stack in versions prior V06.00 are potentially affected by a denial-of-service vulnerability when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. Siemens has released updates for several affected products and recommends to update to the new versions. Siemens is preparing ...
Titel
SSA-712518 V1.1 (Last Update: 2020-12-08): Information Disclosure Vulnerability (Kr00k) in Industrial Wi-Fi Products
Veröffentlicht
8. Dezember 2020 01:00
Text
An information disclosure vulnerability (CVE-2019-15126, also known as Kr00k) could allow an attacker to read a discrete set of traffic over the air after a Wi-Fi device state change. Siemens is preparing updates and recommends specific countermeasures for products where updates are not, or not yet available.
Titel
SSA-689942 V1.2 (Last Update: 2020-12-08): Denial-of-Service and DLL Hijacking Vulnerabilities in Multiple SIMATIC Software Products
Veröffentlicht
8. Dezember 2020 01:00
Text
Multiple SIMATIC Software products are affected by two vulnerabilities that could allow an attacker to manipulate project files that may lead to Remote Code Execution or Denial-of-Service attacks. Siemens has released updates to some of the affected products and recommends that customers update to the latest version. Siemens is preparing ...

Letzte Updates

BOSCH PSIRT
21.08.2024
SIEMENS CERT
12.09.2024
US CERT
19.09.2024
US CERT (ICS)
19.09.2024

Nach Quelle

Archiv

2024
2023
2022
2021
2020
2019
2018
2017

Feeds