December 2022
Title
SSA-588101 V1.0: Multiple File Parsing Vulnerabilities in Parasolid
Published
Dec. 13, 2022, 1 a.m.
Summary
Parasolid is affected by out of bounds read/write vulnerabilities that could be triggered when the application reads files in X_B format. If a user is tricked to open a malicious file with the affected applications, an attacker could leverage the vulnerability to perform remote code execution in the context of ...
Title
SSA-210822 V1.0: Improper Access Control Vulnerability in Mendix Workflow Commons Module
Published
Dec. 13, 2022, 1 a.m.
Summary
The Mendix Workflow Commons module improperly handles access control for some module entities. This could allow authenticated remote attackers to read or delete sensitive information. Mendix has released an update for the Mendix Workflow Commons module and recommends to update to the latest version. Note that the fix might slightly ...
Title
SSA-700053 V1.0: Multiple File Parsing Vulnerabilities in Teamcenter Visualization and JT2Go
Published
Dec. 13, 2022, 1 a.m.
Summary
Siemens Teamcenter Visualization and JT2Go are affected by multiple file parsing vulnerabilities that could be triggered when the application reads a malicious file in CGM or RAS format. If a user is tricked to open a malicious file with the affected products, this could lead the application to crash or ...
Title
SSA-223771 V1.0: SISCO Stack Vulnerability in SIPROTEC 5 Devices
Published
Dec. 13, 2022, 1 a.m.
Summary
A vulnerability in the third party component SISCO MMS-EASE could allow attackers to cause a denial of service condition with SIPROTEC 5 devices. Siemens has released updates for the affected products and recommends to update to the latest versions.
Title
Rockwell Automation Logix controllers
Published
Dec. 8, 2022, 4 p.m.
Summary
Title
Multiple Vulnerabilities in NetApp DSA E2800 series
Published
Dec. 7, 2022, 1 a.m.
Summary

BOSCH-SA-609377-BT: The Bosch DSA E2800 products are based on NetApp technology, which incorporates a Linux Kernel and other components such as the Oracle Java Platform Standard Edition (Java SE), OpenSSL, SANtricity OS Controller Software, E-Series SANtricity OS Controller Software, Docker, Eclipse Jetty, GNU C Library (aka glibc), Libnss, Zlib. These ...

Title
AA22-335A: #StopRansomware: Cuba Ransomware
Published
Dec. 1, 2022, 7:04 p.m.
Summary
Original release date: December 1, 2022SummaryActions to take today to mitigate cyber threats from ransomware: • Prioritize remediating known exploited vulnerabilities. • Train users to recognize and report phishing attempts. • Enable and enforce phishing-resistant multifactor authentication. Note: This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort ...
Title
BD BodyGuard Pumps
Published
Dec. 1, 2022, 4:10 p.m.
Summary
Title
Horner Automation Remote Compact Controller
Published
Dec. 1, 2022, 4 p.m.
Summary
November 2022
Title
Mitsubishi Electric GOT2000
Published
Nov. 29, 2022, 4:30 p.m.
Summary
Title
Hitachi Energy IED Connectivity Packages and PCM600 Products
Published
Nov. 29, 2022, 4:25 p.m.
Summary
Title
Hitachi Energy MicroSCADA Pro/X SYS600 Products
Published
Nov. 29, 2022, 4:20 p.m.
Summary
Title
Moxa UC Series
Published
Nov. 29, 2022, 4:15 p.m.
Summary
Title
Mitsubishi Electric MELSEC and MELIPC Series (Update E)
Published
Nov. 29, 2022, 4:05 p.m.
Summary
Title
Omron PLC CJ and CS Series (Update A)
Published
Nov. 29, 2022, 4 p.m.
Summary
This advisory includes information and mitigation recommendations for authentications vulnerabilities reported in the Omron PLC CJ and CS Series.
Title
AVEVA Edge
Published
Nov. 22, 2022, 4:35 p.m.
Summary
Title
Digital Alert Systems DASDEC
Published
Nov. 22, 2022, 4:30 p.m.
Summary
Title
Phoenix Contact Automation Worx
Published
Nov. 22, 2022, 4:25 p.m.
Summary
Title
GE CIMPLICITY
Published
Nov. 22, 2022, 4:20 p.m.
Summary
Title
Moxa Multiple ARM-Based Computers
Published
Nov. 22, 2022, 4:15 p.m.
Summary
Title
Mitsubishi Electric FA Engineering Software Products (Update G)
Published
Nov. 22, 2022, 4:10 p.m.
Summary
Title
Mitsubishi Electric Factory Automation Engineering Products (Update I)
Published
Nov. 22, 2022, 4:05 p.m.
Summary
Title
Hillrom Medical Device Management (Update C)
Published
Nov. 22, 2022, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSMA-21-152-01 Hillrom Medical Device Management (Update B) that was published September 8, 2022, to the ICS webpage at cisa.gov/ics. This advisory contains mitigations for Out-of-bounds Write, Out-of-bounds Read vulnerabilities in Welch Allyn medical device management tools.
Title
AA22-321A: #StopRansomware: Hive Ransomware
Published
Nov. 17, 2022, 6 p.m.
Summary
Original release date: November 17, 2022SummaryActions to Take Today to Mitigate Cyber Threats from Ransomware: • Prioritize remediating known exploited vulnerabilities. • Enable and enforce multifactor authentication with strong passwords • Close unused ports and remove any application not deemed necessary for day-to-day operations. Note: This joint Cybersecurity Advisory (CSA) ...
Title
Red Lion Crimson
Published
Nov. 17, 2022, 4:10 p.m.
Summary

Last Updates

BOSCH PSIRT
10.06.2025
SIEMENS CERT
21.07.2025
US CERT
29.07.2025
US CERT (ICS)
05.08.2025

By Source

Archive

2025
2024
2023
2022
2021
2020
2019
2018
2017

Feeds