July 2022
Title
Siemens Datalogics File Parsing Vulnerability
Published
July 14, 2022, 4:46 p.m.
Summary
This advisory contains mitigations for a Heap-based buffer Overflow vulnerability in the Siemens Teamcenter Visualization.
Title
Siemens PADS Standard/Plus Viewer
Published
July 14, 2022, 4:44 p.m.
Summary
This advisory contains mitigations for an Out-of-bounds Read, Out-of-bounds Write, Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the PADS Standard and Standard Plus, a PCB schematic design and layout environment.
Title
Simcenter Femap and Parasolid
Published
July 14, 2022, 4:42 p.m.
Summary
This advisory contains mitigations for an Out-of-bounds Read vulnerability Simcenter Femap, an advanced simulation application, and Parasolid, a 3D geometric modeling tool.
Title
Siemens Mendix Applications
Published
July 14, 2022, 4:40 p.m.
Summary
This advisory contains mitigations for an Out-of-bounds Read vulnerability in Siemens Mendix Applications, a high productivity app platform.
Title
Dahua ASI7213X-T1
Published
July 12, 2022, 4:05 p.m.
Summary
This advisory contains mitigations for Improper Input Validation, Unrestricted Upload of File with Dangerous Type, Authentication Bypass by Capture-replay, Generation of Error Message Containing Sensitive Information vulnerabilities in the Dahua ASI7213X-T1 facial recognition access controller.
Title
Schneider Electric Easergy P5 and P3 (Update A)
Published
July 12, 2022, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-22-055-03 Schneider Electric Easergy P5 and P3 that was published February 24, 2022, on the ICS webpage on cisa.gov/ics. This advisory contains mitigations for Use of Hard-coded Credentials, Classic Buffer Overflow, and Improper Input Validation vulnerabilities in Schneider Electric ...
Title
SSA-225578 V1.0: Improper Access Control in SICAM GridEdge
Published
July 12, 2022, 2 a.m.
Summary
The SICAM GridEdge software contains a improper access control vulnerability. This could allow persons with local access to the host system to inject an SSH key. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens recommends specific countermeasures for products where updates ...
Title
SSA-712929 V1.1 (Last Update: 2022-07-12): Denial of Service Vulnerability in OpenSSL (CVE-2022-0778) Affecting Industrial Products
Published
July 12, 2022, 2 a.m.
Summary
A vulnerability in the openSSL component (CVE-2022-0778, [0]) could allow an attacker to create a denial of service condition by providing specially crafted elliptic curve certificates to products that use a vulnerable version of openSSL. Siemens has released updates for several affected products and recommends to update to the latest ...
Title
SSA-840800 V1.0: Code Injection Vulnerability in RUGGEDCOM ROS
Published
July 12, 2022, 2 a.m.
Summary
RUGGEDCOM ROS-based devices are vulnerable to a web-based code injection attack. To execute this attack, it is necessary to access the system via the console. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens recommends specific countermeasures for products where updates are ...
Title
SSA-433782 V1.0: Improper Access Control Vulnerability in Mendix
Published
July 12, 2022, 2 a.m.
Summary
An improper access control vulnerability in Mendix applications was discovered. In case of access to an active user session, the vulnerability could allow to change that user’s password bypassing password validations within a Mendix application. Siemens has released updates for the affected products and recommends to update to the latest ...
Title
SSA-446448 V1.2 (Last Update: 2022-07-12): Denial of Service Vulnerability in PROFINET Stack Integrated on Interniche Stack
Published
July 12, 2022, 2 a.m.
Summary
The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, contains a vulnerability that could allow an attacker to cause a denial of service condition on affected industrial products. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens is preparing further ...
Title
SSA-321292 V1.1 (Last Update: 2022-07-12): Denial of Service in the OPC Foundation Local Discovery Server (LDS) in Industrial Products
Published
July 12, 2022, 2 a.m.
Summary
A vulnerability has been identified in the OPC Foundation Local Discovery Server (LDS) [0] of several industrial products. The vulnerability could cause a denial of service condition on the service or the device. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens ...
Title
SSA-244969 V1.6 (Last Update: 2022-07-12): OpenSSL Vulnerability in Industrial Products
Published
July 12, 2022, 2 a.m.
Summary
OpenSSL has published a security advisory [0] about a vulnerability in OpenSSL versions 1.1.1 < 1.1.1l and 1.0.2 < 1.0.2za that allows an attacker to cause a denial of service (DoS) or to disclose private memory content. Siemens has released updates for several affected products and recommends to update to ...
Title
SSA-865333 V1.0: Memory Corruption Vulnerability in EN100 Ethernet Module
Published
July 12, 2022, 2 a.m.
Summary
EN100 Ethernet module is affected by memory corruption vulnerability (CVE-2022-30938). Siemens has released an update for the EN100 Ethernet module IEC 61850 variant and recommends to update to the latest version. Siemens recommends specific countermeasures for products where updates are not, or not yet available.
Title
SSA-474231 V1.0: File Parsing Vulnerability in Simcenter Femap before V2022.2
Published
July 12, 2022, 2 a.m.
Summary
Siemens Simcenter Femap versions before V2022.2 are affected by an out of bounds write vulnerability that could be triggered when the application reads files in X_T format. If a user is tricked to open a malicious file with the affected application, an attacker could leverage the vulnerability to perform remote ...
Title
SSA-557804 V1.4 (Last Update: 2022-07-12): Mirror Port Isolation Vulnerability in SCALANCE X Switches
Published
July 12, 2022, 2 a.m.
Summary
A vulnerability was identified in several SCALANCE X switches that could allow an attacker to feed information into a network via the mirror port with the monitor barrier feature enabled. Siemens has released updates for the affected products and recommends to update to the latest versions.
Title
SSA-285795 V1.1 (Last Update: 2022-07-12): Denial of Service in OPC-UA in Industrial Products
Published
July 12, 2022, 2 a.m.
Summary
Vulnerability in the underlying third party component OPC UA ANSIC Stack (also called Legacy C-Stack) affects several industrial products. The vulnerability could cause a crash of the component that includes the vulnerable part of the stack. Siemens has released updates for several affected products and recommends to update to the ...
Title
SSA-310038 V1.0: Multiple Vulnerabilities in SCALANCE X Switch Devices
Published
July 12, 2022, 2 a.m.
Summary
Several SCALANCE X switches contain multiple vulnerabilities. An unauthenticated attacker could reboot, cause denial-of-service conditions and potentially impact the system by other means through heap and buffer overflow vulnerabilities. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens is preparing further updates ...
Title
SSA-220589 V1.1 (Last Update: 2022-07-12): Hard Coded Default Credential Vulnerability in Teamcenter
Published
July 12, 2022, 2 a.m.
Summary
Siemens has released updates for Teamcenter that fixes a security vulnerability related to unsecure storage of user credentials. This vulnerability affects Java EE Server Manager HTML Adaptor. This service is not installed by default and currently also obsoleted. Siemens has released updates for the affected products and recommends to update ...
Title
SSA-414513 V1.2 (Last Update: 2022-07-12): Information Disclosure Vulnerability in Mendix
Published
July 12, 2022, 2 a.m.
Summary
An information disclosure vulnerability in Mendix applications was discovered. The vulnerability could allow to read sensitive data. Siemens has released updates for the affected products and recommends to update to the latest versions.
Title
SSA-580125 V1.0: Multiple Vulnerabilities in SIMATIC eaSie Core Package
Published
July 12, 2022, 2 a.m.
Summary
SIMATIC eaSie PCS 7 Skill Package contains multiple vulnerabilities that could allow an attacker to send arbitrary messages to the underlying message passing framework of the affected system or crash the attached application. Siemens has released an update for the SIMATIC eaSie Core Package and recommends to update to the ...
Title
SSA-243317 V1.0: File Parsing Vulnerability in Simcenter Femap and Parasolid
Published
July 12, 2022, 2 a.m.
Summary
Simcenter Femap and Parasolid are affected by an out of bounds read vulnerability that could be triggered when the application reads files in NEU format. If a user is tricked to open a malicious file with the affected applications, an attacker could leverage the vulnerability to perform remote code execution ...
Title
SSA-492173 V1.0: Expression Injection Vulnerability in Mendix Applications
Published
July 12, 2022, 2 a.m.
Summary
An expression injection vulnerability was discovered in the Workflow processing of Mendix Runtime, that can affect the running applications. The vulnerability could allow a malicious user to leak sensitive information if the Workflow visual language of Mendix is used. Mendix has released updates for the affected product lines, recommends to ...
Title
SSA-309571 V1.4 (Last Update: 2022-07-12): IPU 2021.1 Vulnerabilities in Siemens Industrial Products using Intel CPUs (June 2021)
Published
July 12, 2022, 2 a.m.
Summary
Intel has published information on vulnerabilities in Intel products in June 2021. This advisory lists the related Siemens Industrial products affected by these vulnerabilities that can be patched by applying the corresponding BIOS update. In this advisory we summarize: “2021.1 IPU – Intel® CSME, SPS and LMS Advisory” Intel-SA-00459, “2021.1 ...
Title
SSA-429204 V1.0: Open Design Alliance Drawings SDK Vulnerabilities in JT2Go and Teamcenter Visualization
Published
July 12, 2022, 2 a.m.
Summary
JT2Go and Teamcenter Visualization are affected by multiple file parsing vulnerabilities in Drawings SDK from Open Design Alliance. If a user is tricked to open a malicious DWG file with any of the affected products, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens ...

Last Updates

BOSCH PSIRT
10.06.2025
SIEMENS CERT
21.07.2025
US CERT
29.07.2025
US CERT (ICS)
31.07.2025

By Source

Archive

2025
2024
2023
2022
2021
2020
2019
2018
2017

Feeds