October 2023
Title
SSA-363107 V1.3 (Last Update: 2023-10-10): An Improper Initialization Vulnerability Affects SIMATIC WinCC Kiosk Mode
Published
Oct. 10, 2023, 2 a.m.
Summary
A vulnerability was found in SIMATIC WinCC that could allow authenticated attackers to escape the Kiosk Mode. Siemens has released updates for the affected products and recommends to update to the latest versions.
Title
SSA-134651 V1.0: Hard Coded SSH ID in CPCI85 Firmware of SICAM A8000 Devices
Published
Oct. 10, 2023, 2 a.m.
Summary
The CPCI85 firmware of SICAM A8000 CP-8031 and CP-8050 contains a hard-coded ID in the SSH authorized_keys configuration file. An attacker with knowledge of the corresponding credential could login to the device via SSH. Only devices with activated debug support are affected. Siemens has released updates for the affected products ...
Title
SSA-035466 V1.0: Incorrect Permission Assignment in SICAM PAS/PQS
Published
Oct. 10, 2023, 2 a.m.
Summary
SICAM PAS/PQS is affected by insecure permission assignments in application folders that could allow an authenticated local attacker to read and modify configuration data or to escalate privileges. Siemens has prepared a security patch and recommends to run it on affected systems to fix the permissions of the impacted folders. ...
Title
SSA-386812 V1.0: Remote Code Execution Vulnerability in Simcenter Amesim before V2021.1
Published
Oct. 10, 2023, 2 a.m.
Summary
Simcenter Amesim contains a vulnerable SOAP endpoint that could allow an unauthenticated remote attacker to perform DLL injection and execute arbitrary code in the context of the affected application process. Siemens has released an update for Simcenter Amesim and recommends to update to the latest version.
Title
SSA-413565 V1.3 (Last Update: 2023-10-10): Multiple Vulnerabilities in SCALANCE Products
Published
Oct. 10, 2023, 2 a.m.
Summary
Multiple SCALANCE devices are affected by several vulnerabilities that could allow an attacker to inject code, retrieve data as debug information as well as user CLI passwords or set the CLI to an irresponsive state. Siemens has released updates for the affected products and recommends to update to the latest ...
Title
SSA-843070 V1.0: Multiple Vulnerabilities in SCALANCE W1750D
Published
Oct. 10, 2023, 2 a.m.
Summary
The SCALANCE W1750D device contains multiple vulnerabilities that could allow an attacker to inject commands or exploit buffer overflow vulnerabilities which could lead to sensitive information disclosure, unauthenticated denial of service or unauthenticated remote code execution. Siemens has released updates for the affected products and recommends to update to the ...
Title
SSA-829656 V1.0: Stack Overflow Vulnerability in Xpedition Layout Browser
Published
Oct. 10, 2023, 2 a.m.
Summary
Siemens Xpedition Layout Browser consists of a stack overflow vulnerability that could be triggered when the application reads a malicious file in PCB format. If a user is tricked to open a malicious file with the affected product, this could lead the application to crash or potentially lead to arbitrary ...
Title
SSA-784849 V1.0: Direct Memory Access Vulnerabilities in SIMATIC CP Devices
Published
Oct. 10, 2023, 2 a.m.
Summary
Several SIMATIC CP devices contain direct memory access vulnerabilities that could allow an attacker to execute code, access the PROFINET network without restrictions or perform denial of service attacks. Siemens recommends specific countermeasures for products where updates are not, or not yet available.
Title
SSA-285795 V1.4 (Last Update: 2023-10-10): Denial of Service in OPC-UA in Industrial Products
Published
Oct. 10, 2023, 2 a.m.
Summary
A vulnerability in the underlying third party component OPC UA ANSIC Stack (also called Legacy C-Stack) affects several industrial products. The vulnerability could cause a crash of the component that includes the vulnerable part of the stack. Siemens has released updates for the affected products and recommends to update to ...
Title
SSA-240541 V1.1 (Last Update: 2023-10-10): WIBU Systems CodeMeter Heap Buffer Overflow Vulnerability in Industrial Products
Published
Oct. 10, 2023, 2 a.m.
Summary
WIBU Systems published information about a heap buffer overflow vulnerability and associated fix releases of CodeMeter Runtime, a product provided by WIBU Systems and used in several Siemens industrial products for license management. The vulnerability is described in the section “Vulnerability Classification” below and got assigned the CVE ID CVE-2023-3935. ...
Title
SSA-250085 V1.3 (Last Update: 2023-10-10): Multiple Vulnerabilities in SINEC NMS and SINEMA Server
Published
Oct. 10, 2023, 2 a.m.
Summary
SINEC NMS and SINEMA Server V14 contain multiple vulnerabilities that could allow an attacker to execute arbitrary code on the system, arbitrary commands on the local database or achieve privilege escalation. Siemens has released several updates for SINEC NMS and recommends to update to the latest version. Siemens recommends specific ...
Title
SSA-295483 V1.0: User Enumeration Vulnerability in Mendix Forgot Password Module
Published
Oct. 10, 2023, 2 a.m.
Summary
The Mendix Forgot Password module contains a user enumeration vulnerability that could allow an attacker to retrieve valid users. Siemens has released updates for the affected products and recommends to update to the latest versions.
Title
Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products
Published
Oct. 5, 2023, 2 p.m.
Summary
View CSAF 1. EXECUTIVE SUMMARY CVSS v3 9.8 ATTENTION: Exploitable remotely/low attack complexity Vendor: Hitachi Energy Equipment: AFS65x, AFF66x, AFS67x, AFR67x Series Vulnerabilities: Incorrect Calculation, Integer Overflow or Wraparound, Improper Encoding or Escaping of Output, Exposure of Resource to Wrong Sphere 2. RISK EVALUATION Successful exploitation of these vulnerabilities by ...
Title
Mitsubishi Electric CC-Link IE TSN Industrial Managed Switch
Published
Oct. 5, 2023, 2 p.m.
Summary
View CSAF 1. EXECUTIVE SUMMARY CVSS v3 6.5 ATTENTION: Exploitable remotely/low attack complexity Vendor: Mitsubishi Electric Equipment: CC-Link IE TSN Industrial Managed Switch Vulnerabilities: Observable Timing Discrepancy, Double Free 2. RISK EVALUATION Successful exploitation of these vulnerabilities could result in disclosure of information stored in the product by sending specially ...
Title
Qognify NiceVision
Published
Oct. 5, 2023, 2 p.m.
Summary
View CSAF 1. EXECUTIVE SUMMARY CVSS v3 10.0 ATTENTION: Exploitable remotely/low attack complexity Vendor: Qognify Equipment: NiceVision Vulnerability: Use of Hard-coded Credentials 2. RISK EVALUATION Successful exploitation of this vulnerability could allow an attacker to retrieve sensitive information about the cameras managed by the platform and its users. 3. TECHNICAL ...
Title
NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations
Published
Oct. 2, 2023, 9:42 p.m.
Summary
A plea for network defenders and software manufacturers to fix common problems. EXECUTIVE SUMMARY The National Security Agency (NSA) and Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint cybersecurity advisory (CSA) to highlight the most common cybersecurity misconfigurations in large organizations, and detail the tactics, techniques, and procedures ...
September 2023
Title
DEXMA DexGate
Published
Sept. 28, 2023, 2 p.m.
Summary
View CSAF 1. EXECUTIVE SUMMARY CVSS v3 8.0 ATTENTION: Exploitable remotely/low attack complexity Vendor: DEXMA Equipment: DEXGate Vulnerabilities: Cross-Site Scripting, Cross-Site Request Forgery, Improper Authentication, Cleartext Transmission of Sensitive Information, Exposure of Sensitive Information to an Unauthorized Actor 2. RISK EVALUATION Successful exploitation of these vulnerabilities could result in the ...
Title
People's Republic of China-Linked Cyber Actors Hide in Router Firmware
Published
Sept. 26, 2023, 9:45 p.m.
Summary
Executive Summary The United States National Security Agency (NSA), the U.S. Federal Bureau of Investigation (FBI), the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Japan National Police Agency (NPA), and the Japan National Center of Incident Readiness and Strategy for Cybersecurity (NISC) (hereafter referred to as the “authoring agencies”) ...
Title
Hitachi Energy Asset Suite 9
Published
Sept. 26, 2023, 2 p.m.
Summary
View CSAF 1. EXECUTIVE SUMMARY CVSS v3 6.9 ATTENTION: Exploitable remotely/low attack complexity Vendor: Hitachi Energy Equipment: Asset Suite 9 Vulnerability: Improper Authentication 2. RISK EVALUATION Successful exploitation of this vulnerability could allow an authenticated user to enter an arbitrary password to execute equipment tag out actions. 3. TECHNICAL DETAILS ...
Title
Suprema BioStar 2
Published
Sept. 26, 2023, 2 p.m.
Summary
View CSAF 1. EXECUTIVE SUMMARY CVSS v3 6.5 ATTENTION: Exploitable remotely/low attack complexity/public exploits are available/known public exploitation Vendor: Suprema Inc. Equipment: BioStar 2 Vulnerability: SQL Injection 2. RISK EVALUATION Successful exploitation of this vulnerability could allow an attacker to perform a SQL injection to execute arbitrary commands. 3. TECHNICAL ...
Title
Advantech EKI-1524-CE series
Published
Sept. 26, 2023, 2 p.m.
Summary
View CSAF 1. EXECUTIVE SUMMARY CVSS v3 5.4 ATTENTION: Exploitable remotely/low attack complexity/public exploits are available Vendor: Advantech Equipment: EKI-1524-CE, EKI-1522-CE, EKI-1521-CE Vulnerabilities: Cross-Site Scripting 2. RISK EVALUATION Successful exploitation of these vulnerabilities could allow an attacker to execute code in the context of the session. 3. TECHNICAL DETAILS 3.1 ...
Title
Rockwell Automation FactoryTalk View Machine Edition
Published
Sept. 21, 2023, 2 p.m.
Summary
View CSAF 1. EXECUTIVE SUMMARY CVSS v3 9.8 ATTENTION: Exploitable remotely/low attack complexity Vendor: Rockwell Automation Equipment: FactoryTalk View Machine Edition Vulnerability: Improper Input Validation 2. RISK EVALUATION Successful exploitation of this vulnerability could allow an attacker to execute code remotely with specially crafted malicious packets or by using a ...
Title
Rockwell Automation Select Logix Communication Modules
Published
Sept. 21, 2023, 2 p.m.
Summary
View CSAF 1. EXECUTIVE SUMMARY CVSS v3 9.8 ATTENTION: Exploitable remotely/low attack complexity Vendor: Rockwell Automation Equipment: 1756-EN2T, 1756-EN2TK, 1756-EN2TXT, 1756-EN2TP, 1756-EN2TPK, 1756-EN2TPXT, 1756-EN2TR, 1756-EN2TRK, 1756-EN2TRXT, 1756-EN2F, 1756-EN2FK, 1756-EN3TR, 1756-EN3TRK Vulnerability: Stack-based Buffer Overflow 2. RISK EVALUATION Successful exploitation of this vulnerability could allow an attacker to achieve remote code ...
Title
Siemens Spectrum Power 7
Published
Sept. 21, 2023, 2 p.m.
Summary
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global). View CSAF 1. EXECUTIVE SUMMARY ...
Title
Rockwell Automation Connected Components Workbench
Published
Sept. 21, 2023, 2 p.m.
Summary
View CSAF 1. EXECUTIVE SUMMARY CVSS v3 9.6 ATTENTION: Exploitable remotely/low attack complexity/public exploits are available/known public exploitation Vendor: Rockwell Automation Equipment: Connected Components Workbench Vulnerabilities: Use After Free, Out-of-bounds Write 2. RISK EVALUATION Successful exploitation of these vulnerabilities could allow an attacker to exploit heap corruption via a crafted ...

Last Updates

BOSCH PSIRT
15.01.2025
SIEMENS CERT
17.04.2025
US CERT
01.04.2025
US CERT (ICS)
17.04.2025

By Source

Archive

2025
2024
2023
2022
2021
2020
2019
2018
2017

Feeds