November 2020
Title
SSB-439005 (Last Update: 2020-11-10): Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
Published
Nov. 10, 2020, 1 a.m.
Summary
Title
Mitsubishi Electric GT14 Model of GOT1000 Series
Published
Nov. 5, 2020, 4:10 p.m.
Summary
This advisory contains mitigations for Improper Restriction of Operations within the Bounds of a Memory Buffer, Session Fixation, NULL Pointer Dereference, Improper Access Control, Argument Injection, and Resource Management Errors vulnerabilities in Mitsubishi Electric GT14 model of GOT1000 Series graphic operation terminals.
Title
Mitsubishi Electric Factory Automation Engineering Products (Update A)
Published
Nov. 5, 2020, 4:05 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-20-212-04 Mitsubishi Electric Factory Automation Engineering Products that was published July 30, 2020, to the ICS webpage to us-cert.cisa.gov. This advisory contains mitigations for an Unquoted Search Path or Element vulnerability in Mitsubishi Electric Factory Automation Engineering products.
Title
Mitsubishi Electric MELSEC iQ-R Series (Update B)
Published
Nov. 5, 2020, 4 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-20-161-02 Mitsubishi Electric MELSEC iQ-R Series (Update A) that was published June 16, 2020 to the ICS webpage to us-cert.cisa.gov. This advisory contains mitigations for a resource exhaustion vulnerability in the Mitsubishi Electric MELSEC iQ-R series programmable logic controllers.
Title
WAGO Series 750-88x and 750-352
Published
Nov. 3, 2020, 4:10 p.m.
Summary
This advisory contains mitigations for an Uncontrolled Resource Consumption vulnerability in the WAGO Fieldbus Ethernet coupler.
Title
NEXCOM NIO50
Published
Nov. 3, 2020, 4:05 p.m.
Summary
This advisory contains mitigations for Improper Input Validation, and Cleartext Transmission of Sensitive Information vulnerabilities in NEXCOM's NIO50 IoT Gateway.
Title
ARC Informatique PcVue
Published
Nov. 3, 2020, 4 p.m.
Summary
This advisory contains mitigations for Deserialization of Untrusted Data, Access to Critical Private Variable via Public Method, and Information Exposure of Sensitive Information to an Unauthorized Actor vulnerabilities in ARC Information PcVue SCADA products.
October 2020
Title
AA20-304A: Iranian Advanced Persistent Threat Actor Identified Obtaining Voter Registration Data
Published
Oct. 30, 2020, 7:11 p.m.
Summary
Original release date: October 30, 2020 | Last revised: November 3, 2020SummaryThis advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) version 8 framework. See the ATT&CK for Enterprise version 8 for all referenced threat actor techniques. This joint cybersecurity advisory was coauthored by the Cybersecurity and Infrastructure ...
Title
Mitsubishi Electric MELSEC iQ-R, Q and L Series
Published
Oct. 29, 2020, 3:15 p.m.
Summary
This advisory contains mitigations for an Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric's MELSEC iQ-R, Q and L Series programmable logic controllers.
Title
Mitsubishi Electric MELSEC iQ-R
Published
Oct. 29, 2020, 3:10 p.m.
Summary
This advisory contains mitigations for Improper Restriction of Operations within the Bounds of a Memory Buffer, Session Fixation, NULL Pointer Dereference, Improper Access Control, Argument Injection, and Resource Management Errors vulnerabilities in Mitsubishi Electric's iQ-R programmable logic controllers.
Title
Mitsubishi Electric MELSEC iQ-R Series (Update A)
Published
Oct. 29, 2020, 3:05 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-20-282-02 Mitsubishi Electric MELSEC iQ-R Series that was published October 8, 2020, to the ICS webpage on us-cert.cisa.gov. This advisory contains mitigations for an Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R Series modules.
Title
AA20-302A: Ransomware Activity Targeting the Healthcare and Public Health Sector
Published
Oct. 29, 2020, 12:07 a.m.
Summary
Original release date: October 28, 2020 | Last revised: November 2, 2020SummaryThis advisory was updated to include information on Conti, TrickBot, and BazarLoader, including new IOCs and Yara Rules for detection. This advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) version 7 framework. See the ATT&CK for ...
Title
AA20-301A: North Korean Advanced Persistent Threat Focus: Kimsuky
Published
Oct. 27, 2020, 6 p.m.
Summary
Original release date: October 27, 2020SummaryThis advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) version 7 framework. See the ATT&CK for Enterprise version 7 for all referenced threat actor tactics and techniques. This joint cybersecurity advisory was coauthored by the Cybersecurity and Infrastructure Security Agency (CISA), the ...
Title
AA20-296B: Iranian Advanced Persistent Threat Actors Threaten Election-Related Systems
Published
Oct. 22, 2020, 6 p.m.
Summary
Original release date: October 22, 2020SummaryThe Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) are warning that Iranian advanced persistent threat (APT) actors are likely intent on influencing and interfering with the U.S. elections to sow discord among voters and undermine public confidence in the ...
Title
B. Braun OnlineSuite
Published
Oct. 22, 2020, 4:05 p.m.
Summary
This advisory contains mitigations for Relative Path Traversal, Uncontrolled Search Path Element, and Improper Neutralization of Formula Elements in a CSV File vulnerabilities in B. Braun's OnlineSuite.
Title
B. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplus
Published
Oct. 22, 2020, 4 p.m.
Summary
This advisory contains mitigations for Cross-site Scripting, Open Redirect, XPath Injection, Session Fixation, Use of a One-way Hash without a Salt, Relative Path Traversal, Improper Verification of Cryptographic Signature, Improper Privilege Management, Use of Hard-coded Credentials, Active Debug Code, and Improper Access Control vulnerabilities in B. Braun's SpaceCom, Battery Pack ...
Title
AA20-296A: Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets
Published
Oct. 22, 2020, 2:44 p.m.
Summary
Original release date: October 22, 2020SummaryThis joint cybersecurity advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework. See the ATT&CK for Enterprise framework for all referenced threat actor tactics and techniques This joint cybersecurity advisory—written by the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure ...
Title
Rockwell Automation 1794-AENT Flex I/O Series B
Published
Oct. 20, 2020, 4:15 p.m.
Summary
This advisory contains mitigations for several Classic Buffer Overflow vulnerabilities in Rockwell Automation's 1794-AENT Flex I/O Series B Ethernet/IP adapter.
Title
Hitachi ABB Power Grids XMC20 Multiservice-Multiplexer
Published
Oct. 20, 2020, 4:10 p.m.
Summary
This advisory contains mitigations for an Improper Authentication vulnerability in Hitachi ABB Power Grids' XMC20 Multiservice-Multiplexer telecommunication elements.
Title
Capsule Technologies SmartLinx Neuron 2 (Update A)
Published
Oct. 20, 2020, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSMA-20-196-01 Capsule Technologies SmartLinx Neuron 2 that was published July 14, 2020, to the ICS webpage on us-cert.cisa.gov. This advisory contains mitigations for a Protection Mechanism Failure vulnerability in Capsule Technologies' SmartLinx Neuron 2, a bedside mobile clinical monitoring ...
Title
Advantech R-SeeNet
Published
Oct. 15, 2020, 4:05 p.m.
Summary
This advisory contains mitigations for an SQL Injection vulnerability in Advantech;s R-SeeNet monitoring application software.
Title
Wibu-Systems CodeMeter (Update C)
Published
Oct. 15, 2020, 4 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-20-203-01 Wibu-Systems CodeMeter (Update B) that was published October 1, 2020, to the ICS webpage on us-cert.gov. This advisory contains mitigations for Buffer Access with Incorrect Length Value, Inadequate Encryption Strength, Origin Validation Error, Improper Input Validation, Improper Verification ...
Title
MOXA NPort IAW5000A-I/O Series
Published
Oct. 13, 2020, 4:45 p.m.
Summary
This advisory contains mitigations for Session Fixation, Improper Privilege Management, Weak Password Requirements, Cleartext Transmission of Sensitive Information, Improper Restriction of Excessive Authentication Attempts, and Exposure of Sensitive Information to an Unauthorized Actor vulnerabilities in the MOXA NPort IAW5000A-I/O Series integrated serial device server.
Title
SSA-398519 (Last Update: 2020-10-13): Vulnerabilities in Intel CPUs (November 2019)
Published
Oct. 13, 2020, 2 a.m.
Summary
Intel has published information on vulnerabilities in Intel products in November 2019. In this advisory Siemens only explicitly mentions the vulnerabilities from the “Intel® CPU Security Advisory” and one vulnerability from “Intel® CSME, Intel® SPS, Intel® TXE, Intel® AMT, Intel® PTT and Intel® DAL Advisory” and lists the Siemens IPC ...
Title
Remote Desktop Services Remote Code Execution Vulnerability in Rexroth Industrial PCs
Published
Oct. 13, 2020, 2 a.m.
Summary

BOSCH-SA-856281: Microsoft has published information [1] for several versions of Microsoft Windows XP Microsoft Windows XP embedded Microsoft Windows 7 and Microsoft Windows 7 Embedded Standard regarding a vulnerability in the Remote Desktop Service. The vulnerability could allow an unauthenticated remote attacker to execute arbitrary code on the target system ...

Last Updates

BOSCH PSIRT
10.06.2025
SIEMENS CERT
10.07.2025
US CERT
12.06.2025
US CERT (ICS)
10.07.2025

By Source

Archive

2025
2024
2023
2022
2021
2020
2019
2018
2017

Feeds