April 2022
Titel
Elcomplus SmartPTT SCADA Server
Veröffentlicht
19. April 2022 16:05
Text
This advisory contains mitigations for Cross-site Scripting, Unauthorized Exposure to Sensitive Information, Unrestricted Upload of File with Dangerous Type, Path Traversal, and Cross-site Request Forgery vulnerabilities in the Elcomplus SmartPTT SCADA Server voice and data dispatch software.
Titel
Elcomplus SmartPPT SCADA Server
Veröffentlicht
19. April 2022 16:05
Text
This advisory contains mitigations for Cross-site Scripting, Unauthorized Exposure to Sensitive Information, Unrestricted Upload of File with Dangerous Type, Path Traversal, and Cross-site Request Forgery vulnerabilities in the Elcomplus SmartPPT SCADA Server voice and data dispatch software.
Titel
Multiple RTOS (Update E)
Veröffentlicht
19. April 2022 16:00
Text
This updated advisory is a follow-up to the advisory update titled ICSA-21-119-04 Multiple RTOS (Update D) that was published November 30, 2021, to the ICS webpage on www.cisa.gov/uscert. CISA is aware of a public report, known as “BadAlloc” that details vulnerabilities found in multiple real-time operating systems (RTOS) and supporting ...
Titel
Siemens RUGGEDCOM Devices (Update A)
Veröffentlicht
15. April 2022 04:46
Text
This updated advisory is a follow-up to the original advisory titled ICSA-22-069-01 Siemens RUGGEDCOM Devices that was published March 10, 2022, to the ICS webpage on www.cisa.gov/uscert. This advisory contains mitigations for a Missing Encryption of Sensitive Data vulnerability in devices using the Siemens RUGGEDCOM software platform.
Titel
Delta Electronics DMARS
Veröffentlicht
14. April 2022 17:20
Text
This advisory contains mitigations for an Improper Restriction of XML External Entity Reference vulnerability in the Delta Electronics DMARS program development tool.
Titel
Red Lion DA50N
Veröffentlicht
14. April 2022 17:16
Text
This advisory contains mitigation for Insufficient Verification of Data Authenticity, Weak Password Requirements, Use of Unmaintained Third-Party Components, and Insufficiently Protected Credentials vulnerabilities in the Red Lion DA50N networking gateway.
Titel
Siemens SCALANCE FragAttacks
Veröffentlicht
14. April 2022 17:14
Text
This advisory contains mitigations for Improper Authentication, Injection, Improper Validation of Integrity Check, and Improper Input Validation vulnerabilities in the Siemens SCALANCE FragAttacks.
Titel
Siemens OpenSSL Vulnerabilities in Industrial Products
Veröffentlicht
14. April 2022 17:12
Text
This advisory contains mitigations for a NULL Pointer Dereference vulnerability in the Siemens OpenSSL.
Titel
Siemens PROFINET Stack Integrated on Interniche Stack
Veröffentlicht
14. April 2022 17:10
Text
This advisory contains mitigations for an Uncontrolled Resource Consumption vulnerability in the Siemens PROFINET Stack Integrated on Interniche Stack.
Titel
Siemens Mendix
Veröffentlicht
14. April 2022 17:08
Text
This advisory contains mitigations for an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Siemens Mendix, a software platform to build mobile and web applications.
Titel
Siemens SCALANCE W1700
Veröffentlicht
14. April 2022 17:06
Text
This advisory contains mitigations for Race Condition, and Improper Input Validation vulnerabilities in the Siemens SCALANCE W1700 wireless communication device.
Titel
Siemens SCALANCE X-300 Switches
Veröffentlicht
14. April 2022 17:04
Text
This advisory contains mitigations for Improper Input Validation, Use of Insufficiently Random Values, Stack-based Buffer Overflow, Cross-site Request Forgery, Improper Access Control, Basic XSS, Classic Buffer Overflow, Out-of-bounds Read vulnerabilities in Siemens SCALANCE X-300 Switches.
Titel
Valmet DNA
Veröffentlicht
12. April 2022 16:20
Text
This advisory contains mitigations for an Inadequate Encryption Strength vulnerability in Valmet DNA distributed control system products.
Titel
Mitsubishi Electric MELSEC-Q Series C Controller Module
Veröffentlicht
12. April 2022 16:15
Text
This advisory contains mitigations for a Heap-based Buffer Overflow vulnerability in some MELSEC-Q Series C Controller Modules using Wind River VxWorks Version 6.4.
Titel
Mitsubishi Electric GT25-WLAN
Veröffentlicht
12. April 2022 16:05
Text
This advisory contains mitigations for Improper Removal of Sensitive Information Before Storage or Transfer, Inadequate Encryption Strength, Missing Authentication for Critical Function, Injection, and Improper Input Validation vulnerabilities in Mitsubishi Electric GT25-WLAN wireless communication units.
Titel
Aethon TUG Home Base Server
Veröffentlicht
12. April 2022 16:00
Text
This advisory contains mitigations for Missing Authorization, Channel Accessible by Non-endpoint, and Cross-site Scripting vulnerabilities in the Aethon TUG Home Base Server; a server used to control and communicate with autonomous mobile robots in hospitals.
Titel
Pepperl+Fuchs WirelessHART-Gateway
Veröffentlicht
7. April 2022 16:10
Text
This advisory contains mitigations for several vulnerabilities in Pepperl+Fuchs WirelessHART-Gateway industrial networking devices.
Titel
ABB SPIET800 and PNI800
Veröffentlicht
7. April 2022 16:05
Text
This advisory contains mitigations for Incomplete Internal State Distinction, Improper Handling of Unexpected Data Type, and Uncontrolled Resource Consumption vulnerabilities in ABB Symphony Plus SPIET800 and PNI800 network interface modules.
Titel
LifePoint Informatics Patient Portal
Veröffentlicht
5. April 2022 16:15
Text
This advisory contains mitigations for an Authentication Bypass Using Alternate Path or Channel vulnerability in the LifePoint Informatics Patient Portal, a website containing patient health data.
Titel
Philips Vue PACS (Update B)
Veröffentlicht
5. April 2022 16:00
Text
This updated advisory is a follow-up to the advisory update titled ICSMA-21-87-01 Philips Vue PACS (Update A) that was published January 20, 2022, to the ICS webpage on www.cisa.gov/uscert/ics. This advisory contains mitigations for numerous vulnerabilities in Philips Vue PACS products.
März 2022
Titel
Schneider Electric SCADAPack Workbench
Veröffentlicht
31. März 2022 16:40
Text
This advisory contains mitigations for an Improper Restriction of XML External Entity Reference vulnerability in Schneider Electric SCADAPack Workbench software.
Titel
Hitachi Energy e-mesh EMS
Veröffentlicht
31. März 2022 16:35
Text
This advisory contains mitigations for Improper Restriction of Operations Within the Bounds of a Memory Buffer, Use After Free, and Uncontrolled Resource Consumption vulnerabilities in Hitachi Energy e-mesh EMS, an optimizer software for energy resources.
Titel
Fuji Electric Alpha5
Veröffentlicht
31. März 2022 16:30
Text
This advisory contains mitigations for Access of Uninitialized Pointer, Out-of-bound Read, Stack-based Buffer Overflow, and Heap-based Buffer Overflow vulnerabilities in the Fuji Electric Alpha5 servo drive system.
Titel
Mitsubishi Electric FA Products
Veröffentlicht
31. März 2022 16:25
Text
This advisory contains mitigations for a Use of Password Hash Instead of Password for Authentication, Use of Weak Hash, Cleartext Storage of Sensitive Information, and Authentication Bypass by Capture-replay vulnerabilities in Mitsubishi Electric FA CPU module products.
Titel
General Electric Renewable Energy MDS Radios
Veröffentlicht
31. März 2022 16:15
Text
This advisory contains mitigations for Improper Input Validation, Hidden Functionality, Inadequate Encryption Strength, Uncontrolled Resource Consumption, Plaintext Storage of a Password, and Download of Code Without Integrity Check vulnerabilities in General Electric Renewable Energy MDS Radios.

Letzte Updates

BOSCH PSIRT
21.08.2024
SIEMENS CERT
12.09.2024
US CERT
19.09.2024
US CERT (ICS)
19.09.2024

Nach Quelle

Archiv

2024
2023
2022
2021
2020
2019
2018
2017

Feeds