September 2018
Title
SSA-346256 (Last Update: 2018-09-11): Vulnerability in SIMATIC WinCC OA V3.14 and prior
Published
Sept. 11, 2018, 2 a.m.
Summary
The latest update for SIMATIC WinCC OA V3.14 fixes a vulnerability that could allow an unauthenticated remote user to escalate its privileges in the context of SIMATIC WinCC OA V3.14. This vulnerability affects SIMATIC WinCC OA V3.14 and prior. SIMATIC WinCC OA V3.15 and V3.16 are not affected by this ...
Title
SSA-447396 (Last Update: 2018-09-11): Denial-of-Service in SCALANCE X300, SCALANCE X408 and SCALANCE X414
Published
Sept. 11, 2018, 2 a.m.
Summary
A vulnerability has been identified in the integrated web server of SCALANCE X300, SCALANCE X408, and SCALANCE X414. The vulnerability could allow an attacker with network access to the device to cause a Denial-of-Service condition. The vulnerability can be triggered with publicly available tools, including vulnerability scanners. Siemens provides updates ...
Title
SSA-198330 (Last Update: 2018-09-11): Local Privilege Escalation in TD Keypad Designer
Published
Sept. 11, 2018, 2 a.m.
Summary
All versions of the TD Keypad Designer for printing customized lamination sheets for Text Display devices are affected by a DLL hijacking vulnerability that could allow a local low-privileged attacker to escalate his privileges. Text Display devices and TD Keypad Designer have been discontinued in 2012 and were replaced by ...
Title
SSA-179516 (Last Update: 2018-09-11): OpenSSL Vulnerability in Industrial Products
Published
Sept. 11, 2018, 2 a.m.
Summary
A vulnerability in OpenSSL affects several Siemens industrial products. Siemens has released updates for some affected products and is working on updates for others.
Title
SSA-914382 (Last Update: 2018-09-11): Denial-of-Service Vulnerability in SIMATIC S7-400
Published
Sept. 11, 2018, 2 a.m.
Summary
SIMATIC S7-400 CPUs are affected by a security vulnerability which could lead to a Denial-of-Service condition of the PLC if specially crafted packets are received and processed. The affected SIMATIC S7-400 CPU hardware versions are in the product cancellation phase or already phased-out. Siemens recommends customers either upgrading to a ...
Title
SSA-346262 (Last Update: 2018-09-11): Denial-of-Service in Industrial Products
Published
Sept. 11, 2018, 2 a.m.
Summary
Several industrial products are affected by a vulnerability that could allow remote attackers to conduct a Denial-of-Service (DoS) attack by sending specially crafted packets to port 161/udp (SNMP). Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates ...
Title
SSA-268644 (Last Update: 2018-09-11): Spectre-NG (Variants 3a and 4) Vulnerabilities in Industrial Products
Published
Sept. 11, 2018, 2 a.m.
Summary
Security researchers published information on vulnerabilities known as Spectre-NG (Variants 3a and 4). These vulnerabilities affect many modern processors from different vendors to a varying degree. Several Industrial Products include affected processors and are affected by the vulnerabilities.
Title
SSA-168644 (Last Update: 2018-09-11): Spectre and Meltdown Vulnerabilities in Industrial Products
Published
Sept. 11, 2018, 2 a.m.
Summary
Security researchers published information on vulnerabilities known as Spectre and Meltdown. These vulnerabilities affect many modern processors from different vendors to a varying degree. Several Industrial Products include affected processors and are affected by the vulnerabilities.
Title
Ice Qube Thermal Management Center
Published
Sept. 6, 2018, 7:21 p.m.
Summary
This advisory includes mitigation recommendations for improper authentication and unprotected storage of credentials vulnerabilities in Ice Qube's Thermal Management Center, an environmental software management platform.
Title
Opto22 PAC Control Basic and PAC Control Professional
Published
Sept. 4, 2018, 4:30 p.m.
Summary
This advisory includes mitigation recommendations for a stack-based buffer overflow vulnerability in Opto22's PAC Control software.
August 2018
Title
Philips e-Alert Unit
Published
Aug. 30, 2018, 5:22 p.m.
Summary
This advisory includes mitigation recommendations for numerous vulnerabilities in Phillips' e-Alert Unit, a non-medical device.
Title
Qualcomm Life Capsule
Published
Aug. 28, 2018, 4:20 p.m.
Summary
This advisory includes mitigations for a code weakness vulnerability in the Qualcomm Life Capsule Datacaptor Terminal Server software.
Title
Schneider Electric Modicon M221
Published
Aug. 28, 2018, 4:10 p.m.
Summary
This advisory includes mitigation recommendations for an improper check for unusual or exceptional conditions vulnerability in Schneider Electric’s Modicon M221 programmable logic controller.
Title
Schneider Electric PowerLogic PM5560
Published
Aug. 28, 2018, 4:05 p.m.
Summary
This advisory includes mitigation recommendations for a cross-site scripting vulnerability in Schneider Electric's PowerLogic PM5560 power management system.
Title
ABB eSOMS
Published
Aug. 28, 2018, 4 p.m.
Summary
This advisory includes mitigation recommendations for an improper authentication vulnerability in ABB’s eSOMS.
Title
BD Alaris Plus
Published
Aug. 23, 2018, 4 p.m.
Summary
This medical device advisory includes mitigation recommendations for an improper authentication vulnerability in specific versions of BD’s Alaris Plus medical syringe pumps.
Title
Philips IntelliVue Information Center iX (Update A)
Published
Aug. 21, 2018, 4:05 p.m.
Summary
This updated medical device advisory is a follow-up to the original medical device advisory titled ICSMA-18-233-01 Philips IntilliVue Information Center iX that was published August 21, 2018, on the NCCIC/ICS-CERT website. This update includes mitigation recommendations for a resource exhaustion vulnerability in Philips' IntelliVue Information Center iX real-time central monitoring ...
Title
Philips IntelliVue Information Center iX
Published
Aug. 21, 2018, 4:05 p.m.
Summary
This medical device advisory includes mitigation recommendations for a resource exhaustion vulnerability in Philips' IntelliVue Information Center iX real-time central monitoring system.
Title
Yokogawa iDefine, STARDOM, ASTPLANNER, and TriFellows
Published
Aug. 21, 2018, 4 p.m.
Summary
This advisory includes mitigation recommendations for stack-based buffer overflow vulnerabilities in Yokogawa's iDefine, STARDOM, ASTPLANNER, and TriFellows products.
Title
SSB-068644 (Last Update: 2018-08-17): General Customer Information for Speculative Side-Channel Vulnerabilities in Microprocessors
Published
Aug. 17, 2018, 2 a.m.
Summary
Security researchers published information on vulnerabilities known as Spectre, Meltdown, Spectre-NG, Lazy FP State Restore, Spectre V1.1, and L1 Terminal Fault/Foreshadow. These vulnerabilities affect many modern processors from different vendors to a varying degree. Siemens is analyzing the impact of these vulnerabilities and of the mitigations released on its own ...
Title
Philips PageWriter TC10, TC20, TC30, TC50, and TC70 Cardiographs
Published
Aug. 16, 2018, 4:10 p.m.
Summary
This medical device advisory includes mitigation recommendations for improper input validation and use of hard-coded credentials vulnerabilities in Philips' PageWriter Cardiographs.
Title
Emerson DeltaV DCS Workstations
Published
Aug. 16, 2018, 4:05 p.m.
Summary
This advisory includes mitigation recommendations for uncontrolled search path element, relative path traversal, improper privilege management, and stack-based buffer overflow vulnerabilities in Emerson's Delta V workstations.
Title
Tridium Niagara
Published
Aug. 16, 2018, 4 p.m.
Summary
This advisory was originally posted to the HSIN ICS-CERT library on July 10, 2018, and is being released to the NCCIC/ICS-CERT website. This advisory includes mitigation recommendations for path traversal and improper authentication vulnerabilities in Tridum's Niagara systems.
Title
Philips IntelliSpace Cardiovascular Vulnerabilities
Published
Aug. 14, 2018, 4:15 p.m.
Summary
This medical advisory includes mitigation recommendations for improper privilege management and unquoted search path vulnerabilities in Philips' IntelliSpace Cardiovascular (ISCV) software.
Title
Siemens SIMATIC STEP 7 and SIMATIC WinCC
Published
Aug. 14, 2018, 4:10 p.m.
Summary
This advisory includes mitigation recommendations for incorrect default permissions vulnerabilities in Siemens' STEP 7 and SIMATIC WinCC TIA Portal software.

Last Updates

BOSCH PSIRT
31.10.2024
SIEMENS CERT
18.11.2024
US CERT
08.11.2024
US CERT (ICS)
21.11.2024

By Source

Archive

2024
2023
2022
2021
2020
2019
2018
2017

Feeds