July 2022
Title
ABB Drive Composer, Automation Builder, Mint Workbench
Published
July 21, 2022, 4:05 p.m.
Summary
This advisory contains mitigations for an Improper Privilege Management vulnerabilities in the ABB products.
Title
MiCODUS MV720 GPS tracker
Published
July 19, 2022, 4:05 p.m.
Summary
This advisory contains mitigations for Use of Hard-coded Credentials, Improper Authentication, Cross-site Scripting, and Authorization Bypass Through User-controlled Key vulnerabilities in the MiCODUS MV720 GPS tracker.
Title
Dahua ASI7213X-T1 (Update A)
Published
July 19, 2022, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-22-193-01 Dahua ASI7213X-T1 that was published July 12, 2022, on the ICS webpage on cisa.gov/ics. This advisory contains mitigations for Unrestricted Upload of File with Dangerous Type, Authentication Bypass by Capture-replay, and Generation of Error Message Containing Sensitive Information ...
Title
Siemens SCALANCE X Switch Devices
Published
July 14, 2022, 4:58 p.m.
Summary
This advisory contains mitigations for Use of Insufficiently Random Values, and Classic Buffer Overflow vulnerabilities in the Siemens SCALANCE X Switch Devices industrial ethernet switches.
Title
Siemens SIMATIC MV500 Devices
Published
July 14, 2022, 4:54 p.m.
Summary
This advisory contains mitigations for Insufficient Session Expiration, and Missing Authentication for Critical Function vulnerabilities in the Siemens SIMATIC MV500 Devices Optical Readers.
Title
Siemens Mendix Excel Importer
Published
July 14, 2022, 4:48 p.m.
Summary
This advisory contains mitigations for an XML Entity Expansion vulnerability in the Mendix Excel Importer Module.
Title
Siemens Datalogics File Parsing Vulnerability
Published
July 14, 2022, 4:46 p.m.
Summary
This advisory contains mitigations for a Heap-based buffer Overflow vulnerability in the Siemens Teamcenter Visualization.
Title
Siemens PADS Standard/Plus Viewer
Published
July 14, 2022, 4:44 p.m.
Summary
This advisory contains mitigations for an Out-of-bounds Read, Out-of-bounds Write, Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the PADS Standard and Standard Plus, a PCB schematic design and layout environment.
Title
Simcenter Femap and Parasolid
Published
July 14, 2022, 4:42 p.m.
Summary
This advisory contains mitigations for an Out-of-bounds Read vulnerability Simcenter Femap, an advanced simulation application, and Parasolid, a 3D geometric modeling tool.
Title
Siemens Mendix Applications
Published
July 14, 2022, 4:40 p.m.
Summary
This advisory contains mitigations for an Out-of-bounds Read vulnerability in Siemens Mendix Applications, a high productivity app platform.
Title
Dahua ASI7213X-T1
Published
July 12, 2022, 4:05 p.m.
Summary
This advisory contains mitigations for Improper Input Validation, Unrestricted Upload of File with Dangerous Type, Authentication Bypass by Capture-replay, Generation of Error Message Containing Sensitive Information vulnerabilities in the Dahua ASI7213X-T1 facial recognition access controller.
Title
Schneider Electric Easergy P5 and P3 (Update A)
Published
July 12, 2022, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-22-055-03 Schneider Electric Easergy P5 and P3 that was published February 24, 2022, on the ICS webpage on cisa.gov/ics. This advisory contains mitigations for Use of Hard-coded Credentials, Classic Buffer Overflow, and Improper Input Validation vulnerabilities in Schneider Electric ...
Title
SSA-712929 V1.1 (Last Update: 2022-07-12): Denial of Service Vulnerability in OpenSSL (CVE-2022-0778) Affecting Industrial Products
Published
July 12, 2022, 2 a.m.
Summary
A vulnerability in the openSSL component (CVE-2022-0778, [0]) could allow an attacker to create a denial of service condition by providing specially crafted elliptic curve certificates to products that use a vulnerable version of openSSL. Siemens has released updates for several affected products and recommends to update to the latest ...
Title
SSA-492173 V1.0: Expression Injection Vulnerability in Mendix Applications
Published
July 12, 2022, 2 a.m.
Summary
An expression injection vulnerability was discovered in the Workflow processing of Mendix Runtime, that can affect the running applications. The vulnerability could allow a malicious user to leak sensitive information if the Workflow visual language of Mendix is used. Mendix has released updates for the affected product lines, recommends to ...
Title
SSA-711829 V1.1 (Last Update: 2022-07-12): Denial of Service Vulnerability in TIA Administrator
Published
July 12, 2022, 2 a.m.
Summary
In conjunction with the installation of the affected products listed in the table below, a vulnerability in TIA Administrator occurs that could allow an unauthenticated attacker to perform a denial of service attack. Siemens has released updates for the affected products and recommends to update to the latest versions.
Title
SSA-910883 V1.0: DHCP Client Vulnerability in SINAMICS PERFECT HARMONY GH180 Drives
Published
July 12, 2022, 2 a.m.
Summary
Several models of SINAMICS PERFECT HARMONY GH180 Drives are affected by a DHCP client vulnerability (CVE-2021-29998) in the integrated SCALANCE X206-1 device. The vulnerability could allow an attacker to cause a heap-based buffer overflow on that device and use it to get access to the drive’s internal network. The list ...
Title
SSA-321292 V1.1 (Last Update: 2022-07-12): Denial of Service in the OPC Foundation Local Discovery Server (LDS) in Industrial Products
Published
July 12, 2022, 2 a.m.
Summary
A vulnerability has been identified in the OPC Foundation Local Discovery Server (LDS) [0] of several industrial products. The vulnerability could cause a denial of service condition on the service or the device. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens ...
Title
SSA-433782 V1.0: Improper Access Control Vulnerability in Mendix
Published
July 12, 2022, 2 a.m.
Summary
An improper access control vulnerability in Mendix applications was discovered. In case of access to an active user session, the vulnerability could allow to change that user’s password bypassing password validations within a Mendix application. Siemens has released updates for the affected products and recommends to update to the latest ...
Title
SSB-439005 V4.5 (Last Update: 2022-07-12): Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
Published
July 12, 2022, 2 a.m.
Summary
Title
SSA-439148 V1.0: File Parsing Vulnerabilities in PADS Standard/Plus Viewer
Published
July 12, 2022, 2 a.m.
Summary
Siemens PADS Standard/Plus Viewer is affected by multiple memory corruption vulnerabilities that could be triggered when the application reads files in PCB format. If a user is tricked to open a malicious file with the affected application, an attacker could leverage the vulnerability to perform remote code execution in the ...
Title
SSA-838121 V1.2 (Last Update: 2022-07-12): Multiple Denial of Service Vulnerabilities in Industrial Products
Published
July 12, 2022, 2 a.m.
Summary
Affected SIMATIC firmware contains three vulnerabilities that could allow an unauthenticated attacker to perform a denial-of-service attack under certain conditions. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens is preparing further updates and recommends countermeasures for products where updates are not, ...
Title
SSA-310038 V1.0: Multiple Vulnerabilities in SCALANCE X Switch Devices
Published
July 12, 2022, 2 a.m.
Summary
Several SCALANCE X switches contain multiple vulnerabilities. An unauthenticated attacker could reboot, cause denial-of-service conditions and potentially impact the system by other means through heap and buffer overflow vulnerabilities. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens is preparing further updates ...
Title
SSA-243317 V1.0: File Parsing Vulnerability in Simcenter Femap and Parasolid
Published
July 12, 2022, 2 a.m.
Summary
Simcenter Femap and Parasolid are affected by an out of bounds read vulnerability that could be triggered when the application reads files in NEU format. If a user is tricked to open a malicious file with the affected applications, an attacker could leverage the vulnerability to perform remote code execution ...
Title
SSA-599506 V1.0: Command Injection in RUGGEDCOM ROX
Published
July 12, 2022, 2 a.m.
Summary
RUGGEDCOM ROX devices are affected by a command injection vulnerability that could allow an attacker with administrative privileges to gain root access. Siemens has released updates for the affected products and recommends to update to the latest versions.
Title
SSA-829738 V1.0: Datalogics File Parsing Vulnerability in Teamcenter Visualization and JT2Go
Published
July 12, 2022, 2 a.m.
Summary
Siemens has released a new version for Teamcenter Visualization and JT2Go that fixes an out of bounds write vulnerability in APDFL library from Datalogics. If a user is tricked to open a malicious PDF file with the affected products, this could lead the application to crash or potentially lead to ...

Last Updates

BOSCH PSIRT
10.06.2025
SIEMENS CERT
12.06.2025
US CERT
12.06.2025
US CERT (ICS)
12.06.2025

By Source

Archive

2025
2024
2023
2022
2021
2020
2019
2018
2017

Feeds