Oktober 2018
Titel
SSA-179516 (Last Update: 2018-10-09): OpenSSL Vulnerability in Industrial Products
Veröffentlicht
9. Oktober 2018 02:00
Text
A vulnerability in OpenSSL affects several Siemens industrial products. Siemens has released updates for some affected products and is working on updates for others.
Titel
SSA-346262 (Last Update: 2018-10-09): Denial-of-Service in Industrial Products
Veröffentlicht
9. Oktober 2018 02:00
Text
Several industrial products are affected by a vulnerability that could allow remote attackers to conduct a Denial-of-Service (DoS) attack by sending specially crafted packets to port 161/udp (SNMP). Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates ...
Titel
SSA-268644 (Last Update: 2018-10-09): Spectre-NG (Variants 3a and 4) Vulnerabilities in Industrial Products
Veröffentlicht
9. Oktober 2018 02:00
Text
Security researchers published information on vulnerabilities known as Spectre-NG (Variants 3a and 4). These vulnerabilities affect many modern processors from different vendors to a varying degree. Several Industrial Products include affected processors and are affected by the vulnerabilities.
Titel
SSA-348629 (Last Update: 2018-10-09): Denial-of-Service Vulnerability in SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional and SIMATIC NET PC Software
Veröffentlicht
9. Oktober 2018 02:00
Text
A Denial-of-Service vulnerability has been identified in SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional and SIMATIC NET PC-Software. Siemens has released updates for several affected products and recommends that customers update to the new version. Siemens is preparing further updates and recommends specific countermeasures until patches are available.
Titel
SSA-507847 (Last Update: 2018-10-09): Cross-Site Request Forgery Vulnerability in SIMATIC S7-1200 CPU Family Version 4
Veröffentlicht
9. Oktober 2018 02:00
Text
The latest firmware update for S7-1200 CPU family version 4 fixes a Cross-Site Request Forgery vulnerability. Siemens recommends to update affected devices as soon as possible.
Titel
SSA-347726 (Last Update: 2018-10-09): Denial-of-Service Vulnerability in SIMATIC S7-1500, SIMATIC S7-1500 Software Controller and SIMATIC ET 200SP Open Controller
Veröffentlicht
9. Oktober 2018 02:00
Text
Versions of SIMATIC S7-1500, SIMATIC S7-1500 Software Controller and SIMATIC ET 200 SP Open Controller are affected by a denial-of-service vulnerability. An attacker with network access to the PLC can cause a Denial-of-Service condition on the network stack.
September 2018
Titel
SSA-447396 (Last Update: 2018-09-11): Denial-of-Service in SCALANCE X300, SCALANCE X408 and SCALANCE X414
Veröffentlicht
11. September 2018 02:00
Text
A vulnerability has been identified in the integrated web server of SCALANCE X300, SCALANCE X408, and SCALANCE X414. The vulnerability could allow an attacker with network access to the device to cause a Denial-of-Service condition. The vulnerability can be triggered with publicly available tools, including vulnerability scanners. Siemens provides updates ...
Titel
SSA-198330 (Last Update: 2018-09-11): Local Privilege Escalation in TD Keypad Designer
Veröffentlicht
11. September 2018 02:00
Text
All versions of the TD Keypad Designer for printing customized lamination sheets for Text Display devices are affected by a DLL hijacking vulnerability that could allow a local low-privileged attacker to escalate his privileges. Text Display devices and TD Keypad Designer have been discontinued in 2012 and were replaced by ...
Titel
SSA-168644 (Last Update: 2018-09-11): Spectre and Meltdown Vulnerabilities in Industrial Products
Veröffentlicht
11. September 2018 02:00
Text
Security researchers published information on vulnerabilities known as Spectre and Meltdown. These vulnerabilities affect many modern processors from different vendors to a varying degree. Several Industrial Products include affected processors and are affected by the vulnerabilities.
Titel
SSA-914382 (Last Update: 2018-09-11): Denial-of-Service Vulnerability in SIMATIC S7-400
Veröffentlicht
11. September 2018 02:00
Text
SIMATIC S7-400 CPUs are affected by a security vulnerability which could lead to a Denial-of-Service condition of the PLC if specially crafted packets are received and processed. The affected SIMATIC S7-400 CPU hardware versions are in the product cancellation phase or already phased-out. Siemens recommends customers either upgrading to a ...
Titel
SSA-346262 (Last Update: 2018-09-11): Denial-of-Service in Industrial Products
Veröffentlicht
11. September 2018 02:00
Text
Several industrial products are affected by a vulnerability that could allow remote attackers to conduct a Denial-of-Service (DoS) attack by sending specially crafted packets to port 161/udp (SNMP). Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates ...
Titel
SSA-179516 (Last Update: 2018-09-11): OpenSSL Vulnerability in Industrial Products
Veröffentlicht
11. September 2018 02:00
Text
A vulnerability in OpenSSL affects several Siemens industrial products. Siemens has released updates for some affected products and is working on updates for others.
Titel
SSA-346256 (Last Update: 2018-09-11): Vulnerability in SIMATIC WinCC OA V3.14 and prior
Veröffentlicht
11. September 2018 02:00
Text
The latest update for SIMATIC WinCC OA V3.14 fixes a vulnerability that could allow an unauthenticated remote user to escalate its privileges in the context of SIMATIC WinCC OA V3.14. This vulnerability affects SIMATIC WinCC OA V3.14 and prior. SIMATIC WinCC OA V3.15 and V3.16 are not affected by this ...
Titel
SSA-268644 (Last Update: 2018-09-11): Spectre-NG (Variants 3a and 4) Vulnerabilities in Industrial Products
Veröffentlicht
11. September 2018 02:00
Text
Security researchers published information on vulnerabilities known as Spectre-NG (Variants 3a and 4). These vulnerabilities affect many modern processors from different vendors to a varying degree. Several Industrial Products include affected processors and are affected by the vulnerabilities.
August 2018
Titel
SSB-068644 (Last Update: 2018-08-17): General Customer Information for Speculative Side-Channel Vulnerabilities in Microprocessors
Veröffentlicht
17. August 2018 02:00
Text
Security researchers published information on vulnerabilities known as Spectre, Meltdown, Spectre-NG, Lazy FP State Restore, Spectre V1.1, and L1 Terminal Fault/Foreshadow. These vulnerabilities affect many modern processors from different vendors to a varying degree. Siemens is analyzing the impact of these vulnerabilities and of the mitigations released on its own ...
Titel
SSA-979106 (Last Update: 2018-08-07): Vulnerabilities in SIMATIC STEP 7 (TIA Portal) and SIMATIC WinCC (TIA Portal)
Veröffentlicht
7. August 2018 02:00
Text
The latest updates for SIMATIC STEP 7 (TIA Portal) and SIMATIC WinCC (TIA Portal) fix two vulnerabilities. These two vulnerabilities could either allow an attacker with local file write access to manipulate files and cause a Denial-of-service-condition, or execute code both on the manipulated installation and on devices that are ...
Titel
SSA-179516 (Last Update: 2018-08-07): OpenSSL Vulnerability in Industrial Products
Veröffentlicht
7. August 2018 02:00
Text
A vulnerability in OpenSSL affects several Siemens industrial products. Siemens has released updates for some affected products and is working on updates for others.
Titel
SSA-920962 (Last Update: 2018-08-07): Vulnerabilities in Automation License Manager
Veröffentlicht
7. August 2018 02:00
Text
The latest updates for Automation License Manager fix two vulnerabilities. One of them could allow an attacker to execute arbitrary code on the target device, the other one could allow an attacker to abuse the target system for basic network scanning.
Titel
SSA-168644 (Last Update: 2018-08-07): Spectre and Meltdown Vulnerabilities in Industrial Products
Veröffentlicht
7. August 2018 02:00
Text
Security researchers published information on vulnerabilities known as Spectre and Meltdown. These vulnerabilities affect many modern processors from different vendors to a varying degree. Several Industrial Products include affected processors and are affected by the vulnerabilities.
Juli 2018
Titel
SSA-635129 (Last Update: 2018-07-11): Denial-of-Service Vulnerabilities in EN100 Ethernet Communication Module and SIPROTEC 5 relays
Veröffentlicht
11. Juli 2018 02:00
Text
The EN100 Ethernet communication module and SIPROTEC 5 relays are affected by security vulnerabilities which could allow an attacker to conduct a Denial-of-Service attack over the network. Siemens has released updates for several affected products, is working on updates for the remaining affected products, and recommends specific countermeasures until fixes ...
Titel
SSA-197012 (Last Update: 2018-07-03): Vulnerabilities in SICLOCK central plant clocks
Veröffentlicht
3. Juli 2018 02:00
Text
SICLOCK TC devices are affected by multiple vulnerabilities that could allow an attacker to cause Denial-of-Service conditions, bypass the authentication, and modify the firmware of the device or the administrative client. SICLOCK TC devices are in a phase out process. Siemens recommends mitigations to reduce the risk.
Juni 2018
Titel
SSA-168644 (Last Update: 2018-06-26): Spectre and Meltdown Vulnerabilities in Industrial Products
Veröffentlicht
26. Juni 2018 02:00
Text
Security researchers published information on vulnerabilities known as Spectre and Meltdown. These vulnerabilities affect many modern processors from different vendors to a varying degree. Several Industrial Products include affected processors and are affected by the vulnerabilities.
Titel
SSA-159860 (Last Update: 2018-06-26): Access Control Vulnerability in IEC 61850 system configurator, DIGSI 5, DIGSI 4, SICAM PAS/PQS, SICAM PQ Analyzer, and SICAM SCC
Veröffentlicht
26. Juni 2018 02:00
Text
IEC 61850 system configurator, DIGSI 5, DIGSI 4, SICAM PAS/PQS, SICAM PQ Analyzer, and SICAM SCC products are affected by a security vulnerability which could allow an attacker to either exfiltrate limited data from the system or to execute code with operating system user permissions. Siemens has released updates for ...
Titel
SSA-755010 (Last Update: 2018-06-26): Vulnerability in RAPIDLab 1200 and RAPIDPoint 400/500 Blood Gas Analyzers
Veröffentlicht
26. Juni 2018 02:00
Text
Siemens Healthineers has become aware of two potential cybersecurity vulnerabilities for the RAPIDLab® 1200 Series and RAPIDPoint® 400/405/500 Blood Gas Analyzers and recommends specific countermeasures to mitigate the risk. At the time of advisory publication, no public exploitation of this security vulnerability is known.
Titel
SSA-966341 (Last Update: 2018-06-19): SMBv1 Vulnerabilities in Molecular Diagnostics Products from Siemens Healthineers
Veröffentlicht
19. Juni 2018 02:00
Text
Select Molecular Diagnostics products from Siemens Healthineers are affected by the Microsoft Windows SMBv1 vulnerabilities. The exploitability of the vulnerabilities depends on the actual configuration and deployment environment of each product. Siemens Healthineers has developed solutions for all affected products which are available via customer support. Siemens Healthineers also provides ...

Letzte Updates

BOSCH PSIRT
21.08.2024
SIEMENS CERT
12.09.2024
US CERT
19.09.2024
US CERT (ICS)
19.09.2024

Nach Quelle

Archiv

2024
2023
2022
2021
2020
2019
2018
2017

Feeds