May 2018
Title
SSA-203306 (Last Update: 2018-05-15): Password Vulnerabilities in SIPROTEC 4 and SIPROTEC Compact Relay Families
Published
May 15, 2018, 2 a.m.
Summary
SIPROTEC 4 and SIPROTEC Compact devices could allow access authorization passwords to be reconstructed or overwritten via engineering mechanisms that involve DIGSI 4 and EN100 Ethernet communication modules. Siemens has released updates for several affected products, is working on updates for the remaining affected products, and recommends specific countermeasures until ...
Title
MatrikonOPC Explorer
Published
May 10, 2018, 6:10 p.m.
Summary
This advisory includes mitigations for a files or directories accessible to external parties vulnerability in the MatrikonOPC Explorer.
Title
Rockwell Automation Arena
Published
May 10, 2018, 6:05 p.m.
Summary
This advisory includes mitigations for a use after free vulnerability in the Rockwell Automation Arena simulation software.
Title
Rockwell Automation FactoryTalk Activation Manager
Published
May 10, 2018, 6 p.m.
Summary
This advisory was posted originally to the HSIN ICS-CERT library on April 12, 2018, and is being released to the NCCIC/ICS-CERT website. This advisory contains mitigations for cross-site scripting, and improper restriction of operations within the bounds of a memory buffer vulnerabilities in Rockwell Automation’s FactoryTalk Activation Manager products.
Title
Rockwell Automation FactoryTalk Activation Manager (Update A)
Published
May 10, 2018, 6 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-18-102-02 Rockwell Automation FactoryTalk Activation Manager that was published May 10, 2018, on the NCCIC/ICS-CERT website. This updated advisory contains mitigations for cross-site scripting, and improper restriction of operations within the bounds of a memory buffer vulnerabilities in Rockwell ...
Title
Rockwell Automation FactoryTalk
Published
May 10, 2018, 6 p.m.
Summary
This advisory was posted originally to the HSIN ICS-CERT library on April 12, 2018, and is being released to the NCCIC/ICS-CERT website. This advisory contains mitigations for cross-site scripting, and improper restriction of operations within the bounds of a memory buffer vulnerabilities in Rockwell Automation’s FactoryTalk HMI products.
Title
Rockwell Automation FactoryTalk Activation Manager (Update B)
Published
May 10, 2018, 6 p.m.
Summary
This updated advisory is a follow-up to the updated advisory titled ICSA-18-102-02 Rockwell Automation FactoryTalk Activation Manager (Update A) that was published May 24, 2018, on the NCCIC/ICS-CERT website. This updated advisory contains mitigations for cross-site scripting, and improper restriction of operations within the bounds of a memory buffer vulnerabilities ...
Title
SSA-689071 (Last Update: 2018-05-09): DNSMasq Vulnerabilities in SCALANCE W1750D, SCALANCE M800 and SCALANCE S615
Published
May 9, 2018, 2 a.m.
Summary
Multiple vulnerabilities have been identified in SCALANCE W1750D, SCALANCE M800, and SCALANCE S615 devices. The highest scored vulnerability could allow a remote attacker to crash the DNS service or execute arbitrary code. The attacker must be able to craft malicious DNS responses and inject them into the network in order ...
Title
Silex Technology SX-500/SD-320AN or GE Healthcare MobileLink
Published
May 8, 2018, 4:15 p.m.
Summary
This medical advisory includes mitigations for improper authentication and OS command injection vulnerabilities in Silex Technology SX-500, SD-320AN, and GE Healthcare MobileLink devices.
Title
Silex Technology SX-500/SD-320AN or GE Healthcare MobileLink (Update A)
Published
May 8, 2018, 4:15 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSMA-18-128-01 Silex Technology SX-500/SD-320AN or GE Healthcare MobileLink that was published May 8, 2018, on the NCCIC/ICS-CERT website. This updated medical advisory includes mitigations for improper authentication and OS command injection vulnerabilities in Silex Technology SX-500, SD-320AN, and GE ...
Title
Silex Technology SX-500/SD-320AN or GE Healthcare MobileLink (Update B)
Published
May 8, 2018, 4:15 p.m.
Summary
This updated advisory is a follow-up to the updated advisory titled ICSMA-18-128-01 Silex Technology SX-500/SD-320AN or GE Healthcare MobileLink (Update A) that was published May 31, 2018, on the NCCIC/ICS-CERT website. This updated medical advisory includes mitigations for improper authentication and OS command injection vulnerabilities in Silex Technology SX-500, SD-320AN, ...
Title
Siemens Medium Voltage SINAMICS Products
Published
May 8, 2018, 4:10 p.m.
Summary
This advisory includes mitigations for improper input validation vulnerabilities in Siemens' SINAMICS modular drive systems.
Title
Siemens Siveillance VMS (Update A)
Published
May 8, 2018, 4:05 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-18-128-02 Siemens Siveillance VMS that was published May 8, 2018, on the NCCIC/ICS-CERT website. This updated advisory includes mitigations for a deserialization of untrusted data vulnerability in the Siemens Siveillance Video Management Software.
Title
Siemens Siveillance VMS
Published
May 8, 2018, 4:05 p.m.
Summary
This advisory includes mitigations for a deserialization of untrusted data vulnerability in the Siemens Siveillance Video Management Software.
Title
Siemens Siveillance VMS Video Mobile App
Published
May 8, 2018, 4 p.m.
Summary
This advisory includes mitigations for an improper certificate validation vulnerability in the Siemens Siveillance VMS mobile app.
Title
Philips Brilliance Computed Tomography (CT) System
Published
May 3, 2018, 4:05 p.m.
Summary
This medical advisory includes mitigations for execution with unnecessary privileges, exposure of resource to wrong sphere, and use of hard-coded credentials vulnerabilities in Philips' Brillance CT Scanners.
Title
Lantech IDS 2102
Published
May 3, 2018, 4 p.m.
Summary
This advisory includes mitigations for improper input validation and stack-based buffer overflow vulnerabilities in the Lantech IDS 2102 Ethernet device server.
Title
SSA-293562 (Last Update: 2018-05-03): Vulnerabilities in Industrial Products
Published
May 3, 2018, 2 a.m.
Summary
Several industrial devices are affected by two vulnerabilities that could allow an attacker to cause a Denial-of-Service condition via PROFINET DCP network packets under certain circumstances. Precondition for this scenario is a direct Layer 2 access to the affected products. PROFIBUS interfaces are not affected. Siemens has released updates for ...
Title
SSA-468514 (Last Update: 2018-05-03): Improper Certificate Validation Vulnerability in Siveillance VMS Video Mobile App for Android and iOS
Published
May 3, 2018, 2 a.m.
Summary
The latest update for the Siveillance VMS Video mobile app for Android and iOS fixes a security vulnerability that could allow an attacker in a privileged network position to read data from and write data to the encrypted communication channel between the app and a server. Precondition for this scenario ...
Title
SSA-346262 (Last Update: 2018-05-03): Denial-of-Service in Industrial Products
Published
May 3, 2018, 2 a.m.
Summary
Several industrial products are affected by a vulnerability that could allow remote attackers to conduct a Denial-of-Service (DoS) attack by sending specially crafted packets to port 161/udp (SNMP). Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates ...
Title
SSA-546832 (Last Update: 2018-05-03): Vulnerabilities in Medium Voltage SINAMICS Products
Published
May 3, 2018, 2 a.m.
Summary
The latest updates for medium voltage SINAMICS products fix two security vulnerabilities that could allow an attacker to cause a Denial-of-Service condition either via specially crafted PROFINET DCP broadcast packets or by sending specially crafted packets to port 161/udp (SNMP). Precondition for the PROFINET DCP scenario is a direct Layer ...
Title
SSA-457058 (Last Update: 2018-05-03): .NET Security Vulnerability in Siveillance VMS
Published
May 3, 2018, 2 a.m.
Summary
Siemens has released software updates for Siveillance VMS which fix a security vulnerability with the .NET Remoting deserialization that could allow elevation of privileges and/or causing a Denial-of-Service, if affected ports are exposed.
April 2018
Title
Delta Electronics PMSoft
Published
April 26, 2018, 4:05 p.m.
Summary
This advisory includes mitigations for multiple stack-based overflow vulnerabilities in Delta Electronics' PMSoft, a software development tool.
Title
WECON Technology Co., Ltd. LeviStudio HMI Editor and PI Studio HMI Project Programmer
Published
April 26, 2018, 4 p.m.
Summary
This advisory includes mitigations for stack-based buffer overflow vulnerabilities in the WECON Technology Co., Ltd. LeviStudio HMI Editor and PI Studio HMI Project Programmer.
Title
BD Pyxis
Published
April 24, 2018, 4:20 p.m.
Summary
This medical advisory includes mitigations for a reusing a nonce vulnerability in certain BD Pyxis medication and supply management systems.

Last Updates

BOSCH PSIRT
31.10.2024
SIEMENS CERT
18.11.2024
US CERT
08.11.2024
US CERT (ICS)
21.11.2024

By Source

Archive

2024
2023
2022
2021
2020
2019
2018
2017

Feeds