August 2018
Title
Crestron TSW-X60 and MC3
Published
Aug. 9, 2018, 4:05 p.m.
Summary
This advisory includes mitigation recommendations for OS command injection, improper access control, and insufficiently protected credentials vulnerabilities in Crestron's TSW-X60 and MC3 devices.
Title
NetComm Wireless 4G LTE Light Industrial M2M Router
Published
Aug. 9, 2018, 4 p.m.
Summary
This advisory includes mitigation recommendations for information exposure, cross-site forgery, cross-site scripting, and information exposure through directory listing vulnerabilities in NetComm Wireless' 4G LTE Light Industrial M2M Router.
Title
Medtronic MyCareLink 24950 Patient Monitor
Published
Aug. 7, 2018, 4:10 p.m.
Summary
This medical device advisory includes mitigation recommendations for insufficient verification of data authenticity and storing passwords in a recoverable format vulnerabilities in the Medtronic MyCareLink 24950 Patient Monitor.
Title
Medtronic MiniMed 508 Insulin Pump
Published
Aug. 7, 2018, 4:05 p.m.
Summary
This medical device advisory includes mitigation recommendations for cleartext transmission of sensitive information and authentication bypass by capture-replay vulnerabilities in the Medtronic MiniMed 508 Insulin Pump.
Title
Delta Electronics CNCSoft and ScreenEditor
Published
Aug. 7, 2018, 4 p.m.
Summary
This advisory includes mitigation recommendations for stack-based buffer overflow and out=of-bounds read vulnerabilities in Delta Electronics' CNCSoft and ScreenEditor software.
Title
SSA-920962 (Last Update: 2018-08-07): Vulnerabilities in Automation License Manager
Published
Aug. 7, 2018, 2 a.m.
Summary
The latest updates for Automation License Manager fix two vulnerabilities. One of them could allow an attacker to execute arbitrary code on the target device, the other one could allow an attacker to abuse the target system for basic network scanning.
Title
SSA-979106 (Last Update: 2018-08-07): Vulnerabilities in SIMATIC STEP 7 (TIA Portal) and SIMATIC WinCC (TIA Portal)
Published
Aug. 7, 2018, 2 a.m.
Summary
The latest updates for SIMATIC STEP 7 (TIA Portal) and SIMATIC WinCC (TIA Portal) fix two vulnerabilities. These two vulnerabilities could either allow an attacker with local file write access to manipulate files and cause a Denial-of-service-condition, or execute code both on the manipulated installation and on devices that are ...
Title
SSA-168644 (Last Update: 2018-08-07): Spectre and Meltdown Vulnerabilities in Industrial Products
Published
Aug. 7, 2018, 2 a.m.
Summary
Security researchers published information on vulnerabilities known as Spectre and Meltdown. These vulnerabilities affect many modern processors from different vendors to a varying degree. Several Industrial Products include affected processors and are affected by the vulnerabilities.
Title
SSA-179516 (Last Update: 2018-08-07): OpenSSL Vulnerability in Industrial Products
Published
Aug. 7, 2018, 2 a.m.
Summary
A vulnerability in OpenSSL affects several Siemens industrial products. Siemens has released updates for some affected products and is working on updates for others.
July 2018
Title
Davolink DVW-3200N
Published
July 31, 2018, 4:20 p.m.
Summary
This advisory includes mitigation recommendations for a use of password hash with insufficient computational effort vulnerability in the Davolink DVW-3200N networking switch.
Title
Johnson Controls Metasys and BCPro
Published
July 31, 2018, 4:15 p.m.
Summary
This advisory includes mitigation recommendations for an information exposure through an error message vulnerability in Johnson Controls' Metasys and BCPro products.
Title
WECON LeviStudioU
Published
July 31, 2018, 4:10 p.m.
Summary
This advisory includes mitigation recommendations for stack-based buffer overflow and heap-based buffer overflow vulnerabilities in WECON's LeviStudioU HMI editor.
Title
AVEVA InTouch Access Anywhere
Published
July 31, 2018, 4:05 p.m.
Summary
This advisory includes mitigation recommendations for a cross-site scripting vulnerability in the outdated and insecure third-party jQuery library used in the AVEVA InTouch Access Anywhere remote access software.
Title
AVEVA Wonderware License Server
Published
July 31, 2018, 4 p.m.
Summary
This advisory includes mitigation recommendations for an improper restriction of operations within the bounds of a memory buffer vulnerability in the Flexera lmgrd third-party component used by the AVEVA Wonderware License Server.
Title
AVEVA InduSoft Web Studio and InTouch Machine Edition
Published
July 19, 2018, 4:15 p.m.
Summary
This advisory includes mitigation recommendations for a stack-based buffer overflow vulnerability in AVEVA's InduSoft Web Studio and InTouch Machine Edition.
Title
AVEVA InTouch
Published
July 19, 2018, 4:10 p.m.
Summary
This advisory includes mitigation recommendations for a stack-based buffer overflow vulnerability in AVEVA's InTouch HMI software.
Title
Echelon SmartServer 1, SmartServer 2, SmartServer 3, i.LON 100, i.LON 600
Published
July 19, 2018, 4:05 p.m.
Summary
This advisory includes mitigation recommendations for information exposure, authentication bypass using an alternate path or channel, unprotected storage of credentials, cleartext transmission of sensitive information vulnerabilities in the Echelon SmartServer 1, SmartServer 2, i.LON 100, i.LON 600 products.
Title
Moxa NPort 5210 5230 5232
Published
July 19, 2018, 4 p.m.
Summary
This advisory includes mitigation recommendations for a resource exhaustion vulnerability in the Moxa NPort 5210, 5230, and 5232 products.
Title
ABB Panel Builder 800
Published
July 17, 2018, 4:10 p.m.
Summary
This advisory includes mitigation recommendations for an improper input validation vulnerability in the ABB Panel Builder 800.
Title
WAGO e!DISPLAY Web-Based-Management
Published
July 17, 2018, 4:05 p.m.
Summary
This advisory includes mitigation recommendations for cross-site scripting, unrestricted upload of file with dangerous type, and incorrect permissions for critical resource vulnerabilities in WAGO's e!DISPLAY web-based-management system.
Title
PEPPERL+FUCHS VisuNet RM, VisuNet PC, and Box Thin Client
Published
July 17, 2018, 4 p.m.
Summary
This advisory includes mitigation recommendations for an improper authentication vulnerability in the PEPPERL+FUCHS VisuNet RM, VisuNet PC, Box Thin Client.
Title
Eaton 9000X Drive
Published
July 12, 2018, 4 p.m.
Summary
This advisory includes mitigation recommendations for a stack-based buffer overflow vulnerability in the Eaton 9000X Drive.
Title
SSA-635129 (Last Update: 2018-07-11): Denial-of-Service Vulnerabilities in EN100 Ethernet Communication Module and SIPROTEC 5 relays
Published
July 11, 2018, 2 a.m.
Summary
The EN100 Ethernet communication module and SIPROTEC 5 relays are affected by security vulnerabilities which could allow an attacker to conduct a Denial-of-Service attack over the network. Siemens has released updates for several affected products, is working on updates for the remaining affected products, and recommends specific countermeasures until fixes ...
Title
Universal Robots Robot Controllers
Published
July 10, 2018, 4:10 p.m.
Summary
This advisory includes mitigation recommendations for use of hard-coded credentials and missing authentication for critical function vulnerabilities reported in the Universal Robots Robot Controllers.
Title
Schweitzer Engineering Laboratories, Inc. Compass and AcSELerator Architect
Published
July 10, 2018, 4 p.m.
Summary
This advisory includes mitigations for incorrect default permissions, XXE, and resource exhaustion vulnerabilities in Schweitzer Engineering's Compass and AcSELerator software.

Last Updates

BOSCH PSIRT
21.08.2024
SIEMENS CERT
12.09.2024
US CERT
19.09.2024
US CERT (ICS)
19.09.2024

By Source

Archive

2024
2023
2022
2021
2020
2019
2018
2017

Feeds