February 2020
Title
SSA-742938 (Last Update: 2020-02-10): Open Ports in SINAMICS S/G Firmware
Published
Feb. 10, 2020, 1 a.m.
Summary
A potential vulnerability was discovered in the SINAMICS S/G converter family which might allow attackers to access administrative functions on the device without authentication. Siemens addresses the issue by a firmware update.
Title
SSA-233109 (Last Update: 2020-02-10): Web Vulnerabilities in SIMATIC Panels
Published
Feb. 10, 2020, 1 a.m.
Summary
The latest update for SIMATIC Panel software and SIMATIC WinCC (TIA Portal) fixes two web vulnerabilities. The most severe is a vulnerability which could allow an attacker with network access to the integrated webserver to download arbitrary files. Siemens recommends to update to the newest version.
Title
SSA-234763 (Last Update: 2020-02-10): OpenSSL Vulnerabilities in Siemens Industrial Products
Published
Feb. 10, 2020, 1 a.m.
Summary
Vulnerabilities in OpenSSL (see https://www.openssl.org/news/secadv_20140605.txt) affect several Siemens industrial products. Siemens has released updates for all affected products.
Title
SSA-584286 (Last Update: 2020-02-10): Denial-of-Service Vulnerability in SIMATIC S7-1200 CPU and SIMATIC S7-1500 CPU
Published
Feb. 10, 2020, 1 a.m.
Summary
A vulnerability was identified in SIMATIC S7-1200 and S7-1500 CPUs that could allow an attacker to cause a denial-of-service condition preventing HMI or engineering access to the PLC over port 102/tcp. Siemens has released an update for the S7-1500 product and recommends that customers update to the new version. Siemens ...
Title
SSA-470231 (Last Update: 2020-02-10): TPM Vulnerability in SIMATIC IPCs
Published
Feb. 10, 2020, 1 a.m.
Summary
Several SIMATIC IPCs include a version of Infineon's Trusted Platform Module (TPM) firmware that mishandles RSA key generation. This makes it easier for attackers to conduct cryptographic attacks against the key material. Siemens has released updates for the affected Industrial PCs.
Title
SSA-279823 (Last Update: 2020-02-10): Cross-Site Scripting vulnerability in the SIMATIC S7-1200 CPU family
Published
Feb. 10, 2020, 1 a.m.
Summary
Siemens SIMATIC S7-1200 CPUs, version 2 and higher, are capable of running an embedded web server. Web server functionality is disabled by default in the 1200 project configuration. However, if enabled, the web server is susceptible to Cross-Site Scripting (XSS). Siemens provides a firmware update which fixes this XSS vulnerability.
Title
SSA-293562 (Last Update: 2020-02-10): Vulnerabilities in Industrial Products
Published
Feb. 10, 2020, 1 a.m.
Summary
Several industrial devices are affected by two vulnerabilities that could allow an attacker to cause a Denial-of-Service condition via PROFINET DCP network packets under certain circumstances. The precondition for this scenario is a direct layer 2 access to the affected products. PROFIBUS interfaces are not affected. Siemens has released updates ...
Title
SSA-254686 (Last Update: 2020-02-10): Foreshadow / L1 Terminal Fault Vulnerabilities in Industrial Products
Published
Feb. 10, 2020, 1 a.m.
Summary
Security researchers published information on vulnerabilities known as Foreshadow and L1 Terminal Fault (L1TF). These vulnerabilities affect many modern processors from different vendors to a varying degree. Several Siemens Industrial Products contain processors that are affected by the vulnerabilities.
Title
SSA-892715 (Last Update: 2020-02-10): ME, SPS and TXE Vulnerabilities in SIMATIC IPCs
Published
Feb. 10, 2020, 1 a.m.
Summary
Intel has identified vulnerabilities in Intel Management Engine (ME), Intel Server Platform Services (SPS), and Intel Trusted Execution Engine (TXE). As several Siemens Industrial PCs use Intel technology, they are also affected. Siemens has released updates for the affected Industrial PCs.
Title
SSA-546832 (Last Update: 2020-02-10): Vulnerabilities in Medium Voltage SINAMICS and SIMOTION Products
Published
Feb. 10, 2020, 1 a.m.
Summary
The latest updates for medium voltage SINAMICS products fix two security vulnerabilities that could allow an attacker to cause a Denial-of-Service condition either via specially crafted PROFINET DCP broadcast packets or by sending specially crafted packets to port 161/udp (SNMP). Precondition for the PROFINET DCP scenario is a direct Layer ...
Title
SSA-113131 (Last Update: 2020-02-10): Denial-of-Service Vulnerabilities in SIMATIC S7-400 CPUs
Published
Feb. 10, 2020, 1 a.m.
Summary
Two vulnerabilities have been identified in the SIMATIC S7-400 CPU family that could allow an attacker to cause a Denial-of-Service condition. In order to exploit the vulnerability, an attacker must have access to the affected devices on port 102/tcp via Ethernet, PROFIBUS or Multi Point Interfaces (MPI). Siemens provides updates ...
Title
SSA-850708 (Last Update: 2020-02-10): Authentication Bypass in SCALANCE X-200 Switch Family
Published
Feb. 10, 2020, 1 a.m.
Summary
A potential vulnerability was discovered in the web server’s authentication of SCALANCE X-200 switches that might allow attackers to hijack web sessions over the network without authentication. Siemens addresses the issue with a firmware update.
Title
SSA-892012 (Last Update: 2020-02-10): Web Vulnerabilities in SIMATIC S7-1200 CPU Family
Published
Feb. 10, 2020, 1 a.m.
Summary
The latest product release of the SIMATIC S7-1200 CPU fixes two vulnerabilities. The more severe of these vulnerabilities could allow an attacker to inject HTTP headers if unsuspecting users are tricked to click on a malicious link. Another vulnerability resolved in this product release is discussed below.
Title
SSA-994726 (Last Update: 2020-02-10): GHOST Vulnerability in Siemens Industrial Products
Published
Feb. 10, 2020, 1 a.m.
Summary
The latest updates for the affected products fix the “GHOST” [1] vulnerability identified in glibc library (CVE-2015-0235). Incorrect parsing within the glibc library functions “gethostbyname()” and “gethostbyname2()” could cause a Denial-of-Service of the targeted system. [1] https://nvd.nist.gov/vuln/detail/CVE-2015-0235
Title
SSA-176087 (Last Update: 2020-02-10): Unauthenticated Access to Critical Services in SCALANCE X-200 Switch Family
Published
Feb. 10, 2020, 1 a.m.
Summary
A potential vulnerability was discovered in the web server authentication of SCALANCE X-200 and X-200IRT switches that might allow attackers to perform administrative operations over the network without authentication. This issue only applies to switches using older firmware versions and has been fixed from firmware V4.5.0 (non-IRT) and V5.1.0 (IRT) ...
Title
SSA-542701 (Last Update: 2020-02-10): Vulnerabilities in SIEMENS LOGO!
Published
Feb. 10, 2020, 1 a.m.
Summary
Multiple vulnerabilities have been identified in SIEMENS LOGO!8 BM devices. The most severe vulnerability could lead to an attacker reading and modifying the device configuration if the attacker has access to port 10005/tcp.
Title
SSA-833048 (Last Update: 2020-02-10): Vulnerability in SIMATIC S7-1200 CPU Family
Published
Feb. 10, 2020, 1 a.m.
Summary
Siemens became aware that the discontinued products SIMATIC S7-1200 CPUs prior to version 4 could allow for the circumvention of user program block protection under certain conditions.
Title
SSA-141614 (Last Update: 2020-02-10): Denial-of-Service in SIMOCODE pro V EIP
Published
Feb. 10, 2020, 1 a.m.
Summary
SIMOCODE pro V EIP is affected by a vulnerability that could allow remote attackers to conduct a Denial-of-Service (DoS) attack by sending specially crafted packets to port 161/udp (SNMP). Siemens has released an update for SIMOCODE pro V EIP and recommends that customers update to the new version.
Title
SSA-944083 (Last Update: 2020-02-10): HTTP Header Injection in SIMATIC Panels and SIMATIC WinCC (TIA Portal)
Published
Feb. 10, 2020, 1 a.m.
Summary
The latest update for SIMATIC Panel software and SIMATIC WinCC (TIA Portal) fixes a vulnerability that could allow an attacker with network access to the web server to perform a HTTP header injection attack.
Title
SSA-100232 (Last Update: 2020-02-10): Denial-of-Service vulnerability in SCALANCE X switches
Published
Feb. 10, 2020, 1 a.m.
Summary
A vulnerability in the affected devices could allow an unauthenticated attacker with network access to an affected device to perform a denial-of-service. Siemens is preparing updates and recommends specific countermeasures until patches are available.
Title
SSA-310688 (Last Update: 2020-02-10): Denial-of-Service Vulnerability in SIMATIC S7-1500 CPU
Published
Feb. 10, 2020, 1 a.m.
Summary
The latest firmware update for the SIMATIC S7-1500 CPU family fixes a vulnerability which could allow an attacker to perform a Denial-of-Service attack under certain conditions. The attacker must have network access to the device to exploit this vulnerability.
Title
SSA-954136 (Last Update: 2020-02-10): User Impersonation Vulnerability in SCALANCE X-200IRT Switch Family
Published
Feb. 10, 2020, 1 a.m.
Summary
The latest firmware update for the SCALANCE X-200IRT switch family fixes a vulnerability which could allow attackers to impersonate legitimate users of the web interface.
Title
SSA-321046 (Last Update: 2020-02-10): Denial-of-Service Vulnerability in SCALANCE X-300/X408 Switch Family
Published
Feb. 10, 2020, 1 a.m.
Summary
The latest firmware update for the Siemens SCALANCE X-300 switch family and SCALANCE X 408 fixes two vulnerabilities. The vulnerabilities could allow attackers to cause a device reboot under certain conditions. An attacker must have network access to the device to exploit this vulnerability.
Title
SSA-377318 (Last Update: 2020-02-10): Multiple vulnerabilities in Intel Active Management Technology (AMT) of SIMATIC IPCs
Published
Feb. 10, 2020, 1 a.m.
Summary
There are multiple vulnerabilities in the Intel Management Engine used in multiple SIMATIC IPC devices that may allow arbitrary code execution, a partial denial of service or information disclosure. For additional information see: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00141.html. Siemens provides updates for the affected devices.
Title
SSA-635659 (Last Update: 2020-02-10): Heartbleed Vulnerability in Siemens Industrial Products
Published
Feb. 10, 2020, 1 a.m.
Summary
The "Heartbleed" vulnerability in the OpenSSL cryptographic software library (CVE-2014-0160) affects several Siemens industrial products. Siemens has resolved the issue in all affected industrial products and provides updates which fix this vulnerability.

Last Updates

BOSCH PSIRT
31.10.2024
SIEMENS CERT
26.11.2024
US CERT
08.11.2024
US CERT (ICS)
03.12.2024

By Source

Archive

2024
2023
2022
2021
2020
2019
2018
2017

Feeds