July 2022
Title
SSA-491621 V1.0: Denial of Service Vulnerability in CPC80 Firmware of SICAM A8000 Devices
Published
July 12, 2022, 2 a.m.
Summary
A vulnerability was identified in the CPC80 firmware of SICAM A8000 devices. It could allow an unauthenticated remote attacker to cause a permanent denial of service condition. Siemens has released updates for the affected products and recommends to update to the latest versions.
Title
SSA-414513 V1.2 (Last Update: 2022-07-12): Information Disclosure Vulnerability in Mendix
Published
July 12, 2022, 2 a.m.
Summary
An information disclosure vulnerability in Mendix applications was discovered. The vulnerability could allow to read sensitive data. Siemens has released updates for the affected products and recommends to update to the latest versions.
Title
SSA-439148 V1.0: File Parsing Vulnerabilities in PADS Standard/Plus Viewer
Published
July 12, 2022, 2 a.m.
Summary
Siemens PADS Standard/Plus Viewer is affected by multiple memory corruption vulnerabilities that could be triggered when the application reads files in PCB format. If a user is tricked to open a malicious file with the affected application, an attacker could leverage the vulnerability to perform remote code execution in the ...
Title
Bently Nevada ADAPT 3701/4X Series and 60M100
Published
July 7, 2022, 4:05 p.m.
Summary
1. EXECUTIVE SUMMARY CVSS v3 9.1 ATTENTION: Exploitable remotely/low attack complexity Vendor: Bently Nevada Equipment: 3701/4X series and 60M100 (3701/60) Condition Monitoring System Vulnerabilities: Use of Hard-coded Credentials, Missing Authentication for Critical Function CISA is aware of a public report, known as “OT:ICEFALL” that details vulnerabilities found in multiple operational ...
Title
Mitsubishi Electric MELSEC iQ-R Series C Controller Module (Update B)
Published
July 7, 2022, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-21-280-04 Mitsubishi Electric MELSEC iQ-R Series C Controller Module (Update A) that was published October 28, 2021, to the ICS webpage on us-cert.cisa.gov. This advisory contains mitigations for an Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R Series ...
Title
AA22-187A: North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector
Published
July 6, 2022, 4 p.m.
Summary
Original release date: July 6, 2022SummaryThe Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Department of the Treasury (Treasury) are releasing this joint Cybersecurity Advisory (CSA) to provide information on Maui ransomware, which has been used by North Korean state-sponsored cyber actors since at least ...
June 2022
Title
AA22-181A: #StopRansomware: MedusaLocker
Published
June 30, 2022, 7 p.m.
Summary
Original release date: June 30, 2022SummaryActions to take today to mitigate cyber threats from ransomware: • Prioritize remediating known exploited vulnerabilities. • Train users to recognize and report phishing attempts. • Enable and enforce multifactor authentication. Note: this joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to ...
Title
Exemys RME1
Published
June 30, 2022, 4:25 p.m.
Summary
This advisory contains mitigations for an Improper Authentication vulnerability in the Exemys RME1 analog acquisition module.
Title
Yokogawa Wide Area Communication Router
Published
June 30, 2022, 4:20 p.m.
Summary
This advisory contains mitigations for a Use of Insufficiently Random Values vulnerability in the Yokogawa Wide Area Communication Router.
Title
Emerson DeltaV Distributed Control System
Published
June 30, 2022, 4:15 p.m.
Summary
This advisory contains mitigations for a Missing Authentication for Critical Function, Use of Hard-coded Credentials, Insufficient Verification of Data Authenticity, and Use of a Broken or Risky Cryptographic Algorithm vulnerabilities in the Emerson DeltaV Distributed Control System software management platform.
Title
Mitsubishi Electric FA Engineering Software (Update A)
Published
June 30, 2022, 4:05 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-21-350-05 Mitsubishi Electric FA Engineering Software that was published December 16, 2021, on the ICS webpage on cisa.gov/ics. This advisory contains mitigations for Out-of-bounds Read, and Integer Underflow vulnerabilities in Mitsubishi Electric's FA Engineering Software products.
Title
CODESYS Gateway Server (Update A)
Published
June 30, 2022, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-15-258-02 3S CODESYS Gateway Server Buffer overflow Vulnerability that was published September 15, 2015, on the ICS webpage at cisa.gov/ics. This advisory provides mitigation details for a heap-based buffer overflow vulnerability in CODESYS Gateway Server products.
Title
ABB e-Design
Published
June 28, 2022, 4:25 p.m.
Summary
This advisory contains mitigations for an Incorrect Default Permissions vulnerability in ABB e-Design engineering software.
Title
Omron SYSMAC CS/CJ/CP Series and NJ/NX Series
Published
June 28, 2022, 4:20 p.m.
Summary
This advisory contains mitigations for Cleartext Transmission of Sensitive Information, Insufficient Verification of Data Authenticity, and Plaintext Storage of a Password vulnerabilities in Omron SYSMAC CS/CJ/CP Series and NJ/NX Series programmable logic controllers.
Title
Motorola Solutions MOSCAD IP and ACE IP Gateways
Published
June 28, 2022, 4:10 p.m.
Summary
This advisory contains mitigations for a missing authentication for critical function vulnerability in the Motorola Solutions MOSCAD IP and ACE IP Gateways products.
Title
Motorola Solutions MDLC
Published
June 28, 2022, 4:05 p.m.
Summary
This advisory contains mitigations for Use of a Broken or Risky Cryptographic Algorithm, and Plaintext Storage of a Password vulnerabilities in the Motorola Solutions MDLC protocol parser.
Title
Motorola Solutions ACE1000
Published
June 28, 2022, 4 p.m.
Summary
This advisory contains mitigations for Use of Hard-coded Cryptographic Key, Use of Hard-coded Credentials, and Insufficient Verification of Data Authenticity vulnerabilities in the Motorola Solutions ACE1000 remote terminal unit.
Title
AA22-174A: Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems
Published
June 23, 2022, 7 p.m.
Summary
Original release date: June 23, 2022SummaryActions to take today: • Install fixed builds, updating all affected VMware Horizon and UAG systems to the latest versions. If updates or workarounds were not promptly applied following VMware’s release of updates for Log4Shell in December 2021, treat all affected VMware systems as compromised. ...
Title
OFFIS DCMTK
Published
June 23, 2022, 4:25 p.m.
Summary
This advisory contains mitigations for a path traversal, relative path traversal, NULL pointer reference vulnerability in DCMTK, an OFFIS product.
Title
Yokogawa STARDOM
Published
June 23, 2022, 4:20 p.m.
Summary
This advisory contains mitigations for Cleartext Transmission of Sensitive Information, and Use of Hard-coded Credentials vulnerabilities in the Yokogawa STARDOM network control system.
Title
Yokogawa CAMS for HIS
Published
June 23, 2022, 4:15 p.m.
Summary
This advisory contains mitigations for a Violation of Secure Design Principles vulnerability in the Yokogawa Consolidation Alarm Management Software for Human Interface Station (CAMS for HIS).
Title
Secheron SEPCOS Control and Protection Relay
Published
June 23, 2022, 4:10 p.m.
Summary
This advisory contains mitigations for Improper Enforcement of Behavioral Workflow, Lack of Administrator Control over Security, Improper Privilege Management, and Insufficiently Protected Credentials vulnerabilities in the Secheron SEPCOS Control and Protection Relay.
Title
Pyramid Solutions EtherNet/IP Adapter Development Kit
Published
June 23, 2022, 4:05 p.m.
Summary
This advisory contains mitigations for an Out-of-bounds Write vulnerability in the Pyramid Solutions EtherNet/IP Adapter Development Kit.
Title
Elcomplus SmartICS
Published
June 23, 2022, 4 p.m.
Summary
This advisory contains mitigations for Improper Access Control, Relative Path Traversal, and Cross-site Scripting vulnerabilities in the Elcomplus SmartICS web-based HMI.
Title
Mitsubishi Electric MELSEC Q and L Series
Published
June 22, 2022, 4:25 a.m.
Summary
This advisory contains mitigations for an Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC Q and L Series CPUs.

Last Updates

BOSCH PSIRT
21.08.2024
SIEMENS CERT
12.09.2024
US CERT
19.09.2024
US CERT (ICS)
19.09.2024

By Source

Archive

2024
2023
2022
2021
2020
2019
2018
2017

Feeds