March 2018
Title
OSIsoft PI Data Archive
Published
March 13, 2018, 3:15 p.m.
Summary
This advisory includes mitigation recommendations for several reported vulnerabilities in the OSIsoft PI Data Archive.
Title
OSIsoft PI Vision
Published
March 13, 2018, 3:10 p.m.
Summary
This advisory includes mitigations for protection mechanism failure and information exposure vulnerabilities in the OSIsoft PI Vision.
Title
OSIsoft PI Web API
Published
March 13, 2018, 3:05 p.m.
Summary
This advisory includes mitigations for permissions, privileges, and access controls; and cross-site scripting vulnerabilities in the OSIsoft PI Web API.
Title
GE Medical Devices Vulnerability
Published
March 13, 2018, 3 p.m.
Summary
This medical device advisory was originally posted to the HSIN ICS-CERT library on February 6, 2018, and is being released to the NCCIC/ICS-CERT website. This advisory contains mitigations for an improper authentication vulnerability in several GE medical devices.
Title
Siemens SIPROTEC 4, SIPROTEC Compact, DIGSI 4, and EN100 Ethernet Module
Published
March 8, 2018, 4:05 p.m.
Summary
This advisory includes mitigations for missing authentication for critical function, and inadequate encryption strength vulnerabilities in Siemens' SIPROTEC 4, SIPROTEC Compact, DIGSI 4, and EN100 Ethernet module.
Title
Siemens SIPROTEC 4, SIPROTEC Compact, and Reyrolle Devices using the EN100 Ethernet Communication Module Extension
Published
March 8, 2018, 4 p.m.
Summary
This advisory includes mitigation details for a missing authentication for critical function vulnerability in the Siemens SIPROTEC 4, SIPROTEC Compact, and Reyrolle devices using the EN100 Ethernet communication module extension.
Title
SSA-203306 (Last Update: 2018-03-08): Password Vulnerabilities in SIPROTEC 4 and SIPROTEC Compact Relay Families
Published
March 8, 2018, 1 a.m.
Summary
SIPROTEC 4 and SIPROTEC Compact devices could allow access authorization passwords to be reconstructed or overwritten via engineering mechanisms that involve DIGSI 4 and EN100 Ethernet communication modules. Siemens has released updates for several affected products, is working on updates for the remaining affected products, and recommends specific countermeasures until ...
Title
SSA-845879 (Last Update: 2018-03-08): Firmware Downgrade Vulnerability in EN100 Ethernet Communication Module for SIPROTEC 4, SIPROTEC Compact and Reyrolle
Published
March 8, 2018, 1 a.m.
Summary
The EN100 Ethernet communication module, which is an optional extension for SIPROTEC 4, SIPROTEC Compact and Reyrolle devices, allows an unauthenticated upload of firmware updates to the communication module in affected versions. Siemens has released updates for several affected products, is working on updates for the remaining affected products, and ...
Title
Hirschmann Automation and Control GmbH Classic Platform Switches
Published
March 6, 2018, 4:10 p.m.
Summary
This advisory includes mitigation recommendations for session fixation, information exposure through query strings in GET request, cleartext transmission of sensitive information, inadequate encryption strength, and improper restriction of excessive authentication attempts vulnerabilities in the Hirschmann Automation and Control GmbH Classic Platform Switches.
Title
Schneider Electric SoMove Software and DTM Software Components
Published
March 6, 2018, 4:05 p.m.
Summary
This advisory includes mitigations for an uncontrolled search path element vulnerability in the Schneider Electric SoMove software and DTM software components.
Title
Eaton ELCSoft
Published
March 6, 2018, 4 p.m.
Summary
This advisory includes mitigation details for an improper input validation vulnerability in the Eaton ELCSoft programming software.
Title
SSA-293562 (Last Update: 2018-03-06): Vulnerabilities in Industrial Products
Published
March 6, 2018, 1 a.m.
Summary
Several industrial devices are affected by two vulnerabilities that could allow an attacker to cause a Denial-of-Service condition via PROFINET DCP network packets under certain circumstances. Precondition for this scenario is a direct Layer 2 access to the affected products. PROFIBUS interfaces are not affected. Siemens has released updates for ...
Title
Siemens SIMATIC, SIMOTION, and SINUMERIK
Published
March 1, 2018, 4:10 p.m.
Summary
This advisory contains mitigation details for stack-based buffer overflow and permissions, privileges, and access controls vulnerabilities in the Siemens' SIMATIC, SIMOTION, and SINUMERIK Industrial PCs.
Title
Moxa OnCell G3100-HSPA Series
Published
March 1, 2018, 4:05 p.m.
Summary
This advisory contains mitigation details for reliance on cookies without validation and integrity checking, improper handling of length parameter inconsistency, and NULL pointer dereference vulnerabilities in the Moxa OnCell G3100-HSPA Series IP gateway.
Title
Delta Electronics Delta Industrial Automation DOPSoft
Published
March 1, 2018, 4 p.m.
Summary
This advisory contains mitigation details for a stack-based buffer overflow vulnerability in the Delta Electronics Delta Industrial Automation DOPSoft human machine interface.
February 2018
Title
Siemens SIMATIC Industrial PCs (Update A)
Published
Feb. 27, 2018, 8:20 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-18-058-01 Siemens SIMATIC Industrial PCs that was published February 27, 2018, on the NCCIC/ICS-CERT website. This updated advisory contains mitigation details for cryptographic issue vulnerabilities in the Siemens' SIMATIC Industrial PCs.
Title
Siemens SIMATIC Industrial PCs
Published
Feb. 27, 2018, 8:20 p.m.
Summary
This advisory contains mitigation details for cryptographic issue vulnerabilities in the Siemens' SIMATIC Industrial PCs.
Title
Delta Electronics WPLSoft
Published
Feb. 27, 2018, 8:15 p.m.
Summary
This advisory contains mitigation details for stack-based buffer overflow, heap-based buffer overflow, out-of-bounds write vulnerabilities in the Delta Electronics WPLSoft PLC programming software.
Title
Emerson ControlWave Micro Process Automation Controller
Published
Feb. 27, 2018, 8:10 p.m.
Summary
This advisory includes mitigation recommendations for a stack-based buffer overflow vulnerability in the Emerson ControlWave Micro Process Automation Controller.
Title
Medtronic 2090 Carelink Programmer Vulnerabilities
Published
Feb. 27, 2018, 8:05 p.m.
Summary
This medical device advisory contains mitigation details for vulnerabilities in Medtronic’s 2090 CareLink Programmer and its accompanying software deployment network.
Title
Philips Intellispace Portal ISP Vulnerabilities
Published
Feb. 27, 2018, 8 p.m.
Summary
This medical device advisory contains mitigation details for vulnerabilities in the Philips’ IntelliSpace Portal (ISP), an advanced visualization and image analysis system.
Title
SSA-892715 (Last Update: 2018-02-22): ME, SPS and TXE Vulnerabilities in SIMATIC IPCs
Published
Feb. 22, 2018, 1 a.m.
Summary
Intel has identified vulnerabilities in Intel Management Engine (ME), Intel Server Platform Services (SPS), and Intel Trusted Execution Engine (TXE). As several Siemens Industrial PCs use Intel technology, they are also affected. Siemens has released updates for the affected Industrial PCs.
Title
SSA-127490 (Last Update: 2018-02-22): Vulnerabilities in SIMATIC WinCC Add-Ons
Published
Feb. 22, 2018, 1 a.m.
Summary
Multiple SIMATIC WinCC Add-Ons released in 2015 and earlier include a vulnerable version of Gemalto Sentinel LDK RTE. Gemalto Sentinel LDK RTE is affected by a vulnerability that could allow remote code execution. Siemens recommends to update the affected software component Gemalto Sentinel LDK RTE.
Title
SSA-346262 (Last Update: 2018-02-22): Denial-of-Service in Industrial Products
Published
Feb. 22, 2018, 1 a.m.
Summary
Several industrial products are affected by a vulnerability that could allow remote attackers to conduct a Denial-of-Service (DoS) attack by sending specially crafted packets to port 161/udp (SNMP). Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates ...
Title
SSA-470231 (Last Update: 2018-02-22): TPM Vulnerability in SIMATIC IPCs
Published
Feb. 22, 2018, 1 a.m.
Summary
Several SIMATIC IPCs include a version of Infineon's Trusted Platform Module (TPM) firmware that mishandles RSA key generation. This makes it easier for attackers to conduct cryptographic attacks against the key material. Siemens has released updates for the affected Industrial PCs.

Last Updates

BOSCH PSIRT
31.10.2024
SIEMENS CERT
18.11.2024
US CERT
08.11.2024
US CERT (ICS)
21.11.2024

By Source

Archive

2024
2023
2022
2021
2020
2019
2018
2017

Feeds