December 2022
Title
SSA-382653 V1.0: Multiple Denial of Service Vulnerabilities in Industrial Products
Published
Dec. 13, 2022, 1 a.m.
Summary
Affected SIMATIC firmware contains multiple vulnerabilities that could allow an unauthenticated attacker to perform a denial-of-service attack under certain conditions. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens is preparing further updates and recommends countermeasures for products where updates are not, ...
Title
SSA-333517 V1.0: Multiple Vulnerabilities in SCALANCE SC-600 Family before V3.0
Published
Dec. 13, 2022, 1 a.m.
Summary
Multiple vulnerabilities affecting various third-party components of the SCALANCE SC-600 family could allow an attacker to cause a denial of service condition, corrupt memory or potentially execute custom code. Siemens has released updates for the affected products and recommends to update to the latest versions.
Title
SSA-321292 V1.3 (Last Update: 2022-12-13): Denial of Service in the OPC Foundation Local Discovery Server (LDS) in Industrial Products
Published
Dec. 13, 2022, 1 a.m.
Summary
A vulnerability has been identified in the OPC Foundation Local Discovery Server (LDS) [0] of several industrial products. The vulnerability could cause a denial of service condition on the service or the device. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens ...
Title
SSA-313313 V1.1 (Last Update: 2022-12-13): Denial of Service Vulnerability in the FTP Server of Nucleus RTOS
Published
Dec. 13, 2022, 1 a.m.
Summary
The FTP server of the networking component (Nucleus NET) in Nucleus Real-Time Operating System (RTOS) does not properly release memory resources that were reserved for incomplete connection attempts by FTP clients. This could allow a remote attacker to generate a denial of service condition on devices that incorporate a vulnerable ...
Title
Rockwell Automation Logix controllers
Published
Dec. 8, 2022, 4 p.m.
Summary
Title
Multiple Vulnerabilities in NetApp DSA E2800 series
Published
Dec. 7, 2022, 1 a.m.
Summary

BOSCH-SA-609377-BT: The Bosch DSA E2800 products are based on NetApp technology, which incorporates a Linux Kernel and other components such as the Oracle Java Platform Standard Edition (Java SE), OpenSSL, SANtricity OS Controller Software, E-Series SANtricity OS Controller Software, Docker, Eclipse Jetty, GNU C Library (aka glibc), Libnss, Zlib. These ...

Title
AA22-335A: #StopRansomware: Cuba Ransomware
Published
Dec. 1, 2022, 7:04 p.m.
Summary
Original release date: December 1, 2022SummaryActions to take today to mitigate cyber threats from ransomware: • Prioritize remediating known exploited vulnerabilities. • Train users to recognize and report phishing attempts. • Enable and enforce phishing-resistant multifactor authentication. Note: This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort ...
Title
BD BodyGuard Pumps
Published
Dec. 1, 2022, 4:10 p.m.
Summary
Title
Horner Automation Remote Compact Controller
Published
Dec. 1, 2022, 4 p.m.
Summary
November 2022
Title
Mitsubishi Electric GOT2000
Published
Nov. 29, 2022, 4:30 p.m.
Summary
Title
Hitachi Energy IED Connectivity Packages and PCM600 Products
Published
Nov. 29, 2022, 4:25 p.m.
Summary
Title
Hitachi Energy MicroSCADA Pro/X SYS600 Products
Published
Nov. 29, 2022, 4:20 p.m.
Summary
Title
Moxa UC Series
Published
Nov. 29, 2022, 4:15 p.m.
Summary
Title
Mitsubishi Electric MELSEC and MELIPC Series (Update E)
Published
Nov. 29, 2022, 4:05 p.m.
Summary
Title
Omron PLC CJ and CS Series (Update A)
Published
Nov. 29, 2022, 4 p.m.
Summary
This advisory includes information and mitigation recommendations for authentications vulnerabilities reported in the Omron PLC CJ and CS Series.
Title
AVEVA Edge
Published
Nov. 22, 2022, 4:35 p.m.
Summary
Title
Digital Alert Systems DASDEC
Published
Nov. 22, 2022, 4:30 p.m.
Summary
Title
Phoenix Contact Automation Worx
Published
Nov. 22, 2022, 4:25 p.m.
Summary
Title
GE CIMPLICITY
Published
Nov. 22, 2022, 4:20 p.m.
Summary
Title
Moxa Multiple ARM-Based Computers
Published
Nov. 22, 2022, 4:15 p.m.
Summary
Title
Mitsubishi Electric FA Engineering Software Products (Update G)
Published
Nov. 22, 2022, 4:10 p.m.
Summary
Title
Mitsubishi Electric Factory Automation Engineering Products (Update I)
Published
Nov. 22, 2022, 4:05 p.m.
Summary
Title
Hillrom Medical Device Management (Update C)
Published
Nov. 22, 2022, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSMA-21-152-01 Hillrom Medical Device Management (Update B) that was published September 8, 2022, to the ICS webpage at cisa.gov/ics. This advisory contains mitigations for Out-of-bounds Write, Out-of-bounds Read vulnerabilities in Welch Allyn medical device management tools.
Title
AA22-321A: #StopRansomware: Hive Ransomware
Published
Nov. 17, 2022, 6 p.m.
Summary
Original release date: November 17, 2022SummaryActions to Take Today to Mitigate Cyber Threats from Ransomware: • Prioritize remediating known exploited vulnerabilities. • Enable and enforce multifactor authentication with strong passwords • Close unused ports and remove any application not deemed necessary for day-to-day operations. Note: This joint Cybersecurity Advisory (CSA) ...
Title
Red Lion Crimson
Published
Nov. 17, 2022, 4:10 p.m.
Summary

Last Updates

BOSCH PSIRT
15.01.2025
SIEMENS CERT
17.04.2025
US CERT
01.04.2025
US CERT (ICS)
17.04.2025

By Source

Archive

2025
2024
2023
2022
2021
2020
2019
2018
2017

Feeds