June 2018
Title
SSA-931064 (Last Update: 2018-06-12): Authentication Bypass in SIMATIC Logon
Published
June 12, 2018, 2 a.m.
Summary
The latest update for SIMATIC Logon fixes a security vulnerability that could allow attackers to circumvent user authentication under certain conditions. SIMATIC WinCC, SIMATIC PCS 7, SIMATIC PDM, and SIMATIC IT Production Suite provide SIMATIC Logon as component of the product. Installing the SIMATIC Logon update fixes the vulnerability for ...
Title
SSA-755010 (Last Update: 2018-06-12): Vulnerability in RAPIDLab 1200 and RAPIDPoint 400/500 Blood Gas Analyzers
Published
June 12, 2018, 2 a.m.
Summary
Siemens Healthineers has become aware of two potential cybersecurity vulnerabilities for the RAPIDLab® 1200 Series and RAPIDPoint® 400/405/500 Blood Gas Analyzers and recommends specific countermeasures to mitigate the risk. At the time of advisory publication, no public exploitation of this security vulnerability is known.
Title
Rockwell Automation RSLinx Classic and FactoryTalk Linx Gateway
Published
June 7, 2018, 5:55 p.m.
Summary
This advisory contains mitigation recommendations for an unquoted search path or element vulnerability in the Rockwell Automation RSLinix Classic software platform.
Title
Philips IntelliVue Patient and Avalon Fetal Monitors
Published
June 5, 2018, 4:05 p.m.
Summary
This medical device advisory includes mitigations for improper authentication, information exposure, and stack-based buffer overflow vulnerabilities in Philips' Intellivue and Avalon monitors.
Title
ABB IP Gateway
Published
June 5, 2018, 4 p.m.
Summary
This advisory contains mitigation recommendations for improper authentication, cross-site request forgery, and unprotected storage of credentials vulnerabilities in the ABB IP Gateway building management system.
May 2018
Title
GE MDS PulseNET and MDS PulseNET Enterprise
Published
May 31, 2018, 4:05 p.m.
Summary
This advisory includes mitigations for improper authentication, improper restriction of XML external entity reference ('XXE'), and relative path traversal vulnerabilities in General Electric's MDS PulseNET products.
Title
Yokogawa STARDOM Controllers
Published
May 31, 2018, 4 p.m.
Summary
This advisory includes mitigations for a hard-coded credentials vulnerability in the Yokogawa STARDOM Controller products.
Title
Delta Industrial Automation DOPSoft
Published
May 30, 2018, 4:10 p.m.
Summary
This advisory contains mitigation recommendations for out-of-bounds read, heap-based buffer overflow, and stack-based buffer overflow vulnerabilities discovered in the Delta Industrial Automation DOPSoft HIM editing software.
Title
SSA-168644 (Last Update: 2018-05-29): Spectre and Meltdown Vulnerabilities in Industrial Products
Published
May 29, 2018, 2 a.m.
Summary
Security researchers published information on vulnerabilities known as Spectre and Meltdown. These vulnerabilities affect many modern processors from different vendors to a varying degree. Several Industrial Products include affected processors and are affected by the vulnerabilities.
Title
BeaconMedaes TotalAlert Scroll Medical Air Systems
Published
May 24, 2018, 4:05 p.m.
Summary
This medical device advisory includes mitigations for improper access controls, insufficiently protected credentials, and unprotected storage of credentials vulnerabilities in the BeaconMedaes TotalAlert Scroll Medical Air Systems web application.
Title
Schneider Electric Floating License Manager
Published
May 24, 2018, 4 p.m.
Summary
This advisory includes mitigations for heap-based buffer overflow, improper restriction of operations within the bounds of a memory buffer, and open redirect vulnerabilities in the Schneider Electric Floating License Manager.
Title
SSA-457058 (Last Update: 2018-05-23): .NET Security Vulnerability in Siveillance VMS
Published
May 23, 2018, 2 a.m.
Summary
Siemens has released software updates for Siveillance VMS which fix a security vulnerability with the .NET Remoting deserialization that could allow elevation of privileges and/or causing a Denial-of-Service, if affected ports are exposed.
Title
BD Kiestra and InoquIA Systems
Published
May 22, 2018, 4:05 p.m.
Summary
This medical device advisory includes mitigations for vulnerabilities in which the product user interface does not warn the user of unsafe actions in the BD Kiestra and InoquIA systems.
Title
Martem TELEM-GW6/GWM
Published
May 22, 2018, 4 p.m.
Summary
This advisory includes mitigations for missing authentication for critical function, resource exhaustion, and cross-site scripting vulnerabilities in the Martem TELEM-GW6/GWM products.
Title
Martem TELEM-GW6/GWM (Update A)
Published
May 22, 2018, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-18-142-01 Martem TELEM-GW6/GWM that was published May 22, 2018, on the NCCIC/ICS-CERT website. This updated advisory includes mitigations for missing authentication for critical function, resource exhaustion, and cross-site scripting vulnerabilities in the Martem TELEM-GW6/GWM products.
Title
Medtronic NVision Clinician Programmer
Published
May 17, 2018, 4:25 p.m.
Summary
This medical advisory includes mitigations for a missing encryption of sensitive data vulnerability in Medtronic's N'Vision Clinician Programmer.
Title
GE PACSystems CPE305/310, CPE330, CPE400, RSTi-EP CPE 100, CPU320/CRU320, RXi
Published
May 17, 2018, 4:15 p.m.
Summary
This advisory includes mitigations for an improper input validation vulnerability in the GE PACSystems CPE305/310, CPE330, CPE400, RSTi-EP CPE 100, CPU320/CRU320, RXi industrial Internet controllers.
Title
PHOENIX CONTACT FL SWITCH 3xxx/4xxx/48xx Series
Published
May 17, 2018, 4:10 p.m.
Summary
This advisory includes mitigations for command injection, information exposure, and stack-based buffer overflow vulnerabilities in the PHOENIX CONTACT FL SWITCH 3xxx/4xxx/48xx Series.
Title
Siemens SIMATIC S7-400 CPU
Published
May 17, 2018, 4:05 p.m.
Summary
This advisory includes mitigations for an improper input validation vulnerability in the Siemens SINAMIC S7-400 CPU.
Title
Delta Electronics Delta Industrial Automation TPEditor
Published
May 17, 2018, 4 p.m.
Summary
This advisory includes mitigations for a heap-based buffer overflow vulnerability in the Delta Electronics Delta Industrial Automation TPEditor.
Title
Delta Electronics Delta Industrial Automation TPEditor (Update A)
Published
May 17, 2018, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-18-137-04 Delta Electronics Delta Industrial Automation TPEditor that was published May 17, 2018, on the NCCIC/ICS-CERT website. This updated advisory includes mitigations for a heap-based buffer overflow vulnerability in the Delta Electronics Delta Industrial Automation TPEditor.
Title
Advantech WebAccess
Published
May 15, 2018, 6:29 p.m.
Summary
This advisory includes mitigations for numerous vulnerabilities in Advantech's WebaAcess human-machine interface (HMI) software.
Title
SSA-346262 (Last Update: 2018-05-15): Denial-of-Service in Industrial Products
Published
May 15, 2018, 2 a.m.
Summary
Several industrial products are affected by a vulnerability that could allow remote attackers to conduct a Denial-of-Service (DoS) attack by sending specially crafted packets to port 161/udp (SNMP). Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates ...
Title
SSA-547990 (Last Update: 2018-05-15): Information Disclosure Vulnerabilities in SIPROTEC 4 and SIPROTEC Compact
Published
May 15, 2018, 2 a.m.
Summary
Information disclosure vulnerabilities in SIPROTEC 4 and SIPROTEC Compact devices could allow an attacker to extract sensitive device information under certain conditions. Siemens has released firmware updates for EN100 Ethernet module included in SIPROTEC 4 and SIPROTEC Compact devices. Siemens has also released a firmware update for SIPROTEC Compact 7SJ80 ...
Title
SSA-914382 (Last Update: 2018-05-15): Denial-of-Service Vulnerability in SIMATIC S7-400
Published
May 15, 2018, 2 a.m.
Summary
SIMATIC S7-400 CPUs are affected by a security vulnerability which could lead to a Denial-of-Service condition of the PLC if specially crafted packets are received and processed. The affected SIMATIC S7-400 CPU hardware versions are in the product cancellation phase or already phased-out. Siemens recommends customers either upgrading to a ...

Last Updates

BOSCH PSIRT
31.10.2024
SIEMENS CERT
18.11.2024
US CERT
08.11.2024
US CERT (ICS)
21.11.2024

By Source

Archive

2024
2023
2022
2021
2020
2019
2018
2017

Feeds