October 2021
Title
SSA-538778 V1.2 (Last Update: 2021-10-12): SmartVNC Vulnerabilities in SIMATIC HMI/WinCC Products
Published
Oct. 12, 2021, 2 a.m.
Summary
Multiple SmartVNC vulnerabilities in the affected products listed below could allow remote code execution and Denial-of-Service attacks under certain conditions. Siemens has released updates for the affected products and recommends to update to the latest version.
Title
SSA-500748 V1.1 (Last Update: 2021-10-12): Denial-of-Service Vulnerabilities in SIPROTEC 5 Devices
Published
Oct. 12, 2021, 2 a.m.
Summary
The latest update for SIPROTEC 5 family devices fixes a vulnerability in the web interface which could allow unauthorized users to cause a Denial-of-Service situation by sending maliciously crafted web requests. Siemens has released an update for the SIPROTEC 5 and recommends to update to the latest version.
Title
SSA-473245 V2.1 (Last Update: 2021-10-12): Denial-of-Service Vulnerability in Profinet Devices
Published
Oct. 12, 2021, 2 a.m.
Summary
A vulnerability in affected devices could allow an attacker to perform a denial-of-service attack if a large amount of specially crafted UDP packets are sent to the device. Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates ...
Title
SSB-439005 V3.8 (Last Update: 2021-10-12): Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
Published
Oct. 12, 2021, 2 a.m.
Summary
Title
SSA-349422 V1.6 (Last Update: 2021-10-12): Denial-of-Service in Industrial Real-Time (IRT) Devices
Published
Oct. 12, 2021, 2 a.m.
Summary
A vulnerability in the affected products could allow an unauthorized attacker with network access to perform a denial-of-service attack resulting in loss of real-time synchronization. Siemens has released updates for several affected products and recommends to update to the latest versions. Siemens is preparing further updates and recommends specific countermeasures ...
Title
SSA-346262 V3.1 (Last Update: 2021-10-12): Denial-of-Service in Industrial Products
Published
Oct. 12, 2021, 2 a.m.
Summary
Several industrial products are affected by a vulnerability that could allow remote attackers to conduct a Denial-of-Service (DoS) attack by sending specially crafted packets to port 161/udp (SNMP). Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates ...
Title
SSA-324955 V1.5 (Last Update: 2021-10-12): SAD DNS Attack in Linux Based Products
Published
Oct. 12, 2021, 2 a.m.
Summary
A vulnerability made public under the name SAD DNS affects Domain Name System resolvers due to a vulnerability in the Linux kernel when handling ICMP packets. The Siemens products which are affected are listed below. For more information please see https://www.saddns.net/. Siemens has released updates for several affected products and ...
Title
SSA-293562 V3.3 (Last Update: 2021-10-12): Vulnerabilities in Industrial Products
Published
Oct. 12, 2021, 2 a.m.
Summary
Several industrial devices are affected by two vulnerabilities that could allow an attacker to cause a Denial-of-Service condition via PROFINET DCP network packets under certain circumstances. The precondition for this scenario is a direct layer 2 access to the affected products. PROFIBUS interfaces are not affected. Siemens has released updates ...
Title
SSA-150692 V1.1 (Last Update: 2021-10-12): Multiple Vulnerabilities in RUGGEDCOM ROX
Published
Oct. 12, 2021, 2 a.m.
Summary
Multiple vulnerabilities in RUGGEDCOM ROX devices have been detected, ranging from command injection to filesystem traversal. An attacker could exploit these to gain root access to the affected devices. Siemens has released updates for the affected products and recommends to update to the latest versions.
Title
SSA-766247 V1.0: Authentication Vulnerability in SIMATIC Process Historian
Published
Oct. 12, 2021, 2 a.m.
Summary
The latest update for SIMATIC Process Historian (PH) fixes an authentication vulnerability in the configuration interface of redundant PH instances that could enable the execution of admin operations on the database. The related vulnerable interface is restricted to local access on recent versions starting from SIMATIC Process Historian 2020. Siemens ...
Title
SSA-280624 V1.0: Multiple Vulnerabilities in SCALANCE W1750D
Published
Oct. 12, 2021, 2 a.m.
Summary
The Scalance W1750D device contains multiple vulnerabilities that could allow an attacker to inject commands or trigger buffer overflows. Siemens is preparing updates and recommends countermeasures for products where updates are not, or not yet available.
Title
SSA-178380 V1.0: Denial-of-Service Vulnerability in SINUMERIK Controllers
Published
Oct. 12, 2021, 2 a.m.
Summary
A Denial-of-Service vulnerability found in SINUMERIK Controllers could allow an unauthenticated attacker with network access to the affected devices to cause system failure with total loss of availability. Siemens has released an update for the SINUMERIK 828D and recommends to update to the latest version. Siemens recommends specific countermeasures for ...
September 2021
Title
SSA-728618 V1.0: Multiple Vulnerabilities in Solid Edge before SE2021MP8
Published
Sept. 28, 2021, 2 a.m.
Summary
Siemens has released a new version for Solid Edge that fixes multiple file parsing vulnerabilities which could be triggered when the application reads files in IFC, JT or OBJ formats. If a user is tricked to opening a malicious file using the affected application this could lead the application to ...
Title
SSA-549234 V1.0: Denial-of-Service Vulnerability in SIMATIC NET CP Modules
Published
Sept. 14, 2021, 2 a.m.
Summary
A Denial of Service vulnerability was identified in different types of Communication Processors. An attacker could exploit this vulnerability causing the device to become un-operational until the device is restarted. Siemens is preparing updates and recommends specific countermeasures for products where updates are not, or not yet available.
Title
SSA-187092 V1.1 (Last Update: 2021-09-14): Several Buffer-Overflow Vulnerabilities in Web Server of SCALANCE X-200
Published
Sept. 14, 2021, 2 a.m.
Summary
Several SCALANCE X-200 switches contain buffer overflow vulnerabilities in the web server. In the most severe case an attacker could potentially remotely execute code. Siemens is preparing updates and recommends specific countermeasures for products where updates are not, or not yet available.
Title
SSA-139628 V1.2 (Last Update: 2021-09-14): Vulnerabilities in Web Server for Scalance X Products
Published
Sept. 14, 2021, 2 a.m.
Summary
Several SCALANCE X switches contain vulnerabilities in the web server of the affected devices. An unauthenticated attacker could reboot, cause denial-of-service conditions and potentially impact the system by other means through heap and buffer overflow vulnerabilities. Siemens has released updates for several affected products and recommends to update to the ...
Title
SSA-102233 V1.6 (Last Update: 2021-09-14): SegmentSmack in VxWorks-based Industrial Devices
Published
Sept. 14, 2021, 2 a.m.
Summary
The products listed below contain a vulnerability that could allow remote attackers to affect the availability of the devices under certain conditions. The underlying TCP stack can be forced to make very computation expensive calls for every incoming packet which can lead to a Denial-of-Service. Siemens has released an update ...
Title
SSA-100232 V1.3 (Last Update: 2021-09-14): Denial-of-Service vulnerability in SCALANCE X Switches
Published
Sept. 14, 2021, 2 a.m.
Summary
A vulnerability in several SCALANCE X devices could allow an unauthenticated attacker with network access to an affected device to perform a denial-of-service. Siemens has released an update for SCALANCE X-200IRT and recommends to update to the latest version. Siemens recommends specific countermeasures for products where updates are not, or ...
Title
SSA-997732 V1.0: Modfem File Parsing Vulnerability in Simcenter Femap before V2021.2
Published
Sept. 14, 2021, 2 a.m.
Summary
Siemens Simcenter Femap is affected by a vulnerability that could be triggered when the application reads modfem files. If a user is tricked to open a malicious file with the affected application, an attacker could leverage this vulnerability to leak information in the context of the current process. Siemens recommends ...
Title
SSA-987403 V1.0: Multiple Vulnerabilities in Teamcenter
Published
Sept. 14, 2021, 2 a.m.
Summary
Teamcenter is affected by three vulnerabilities namely incorrect privilege assignment, Insecure Direct Object Reference (IDOR) and XML External Entity Injection (XXE). Siemens has released updates for the affected products and recommends to update to the latest versions.
Title
SSA-944498 V1.0: Buffer Overflow Vulnerability in Web Server of APOGEE and TALON Automation Devices
Published
Sept. 14, 2021, 2 a.m.
Summary
A buffer overflow vulnerability in the integrated web server of multiple APOGEE and TALON automation devices could allow a remote attacker to execute arbitrary code on the devices with root privileges. Affected devices include the APOGEE MBC/MEC/PXC P2 Ethernet devices with Power Open Processors (PPC), APOGEE PXC BACnet devices, and ...
Title
SSA-847986 V1.0: Denial-of-Service Vulnerabilities in SIPROTEC 5 relays
Published
Sept. 14, 2021, 2 a.m.
Summary
The latest update for SIPROTEC 5 relays fixes two vulnerabilities that could allow a remote attacker to cause a denial-of-service or potentially trigger a remote code execution under certain circumstances. Siemens has released an update for SIPROTEC 5 relays and recommends to update to the latest version.
Title
SSA-835377 V1.0: Missing Authentication Vulnerability in SINEMA Server
Published
Sept. 14, 2021, 2 a.m.
Summary
The latest update for SINEMA Server fixes a vulnerability that could allow an unauthenticated attacker to obtain encoded system configuration backup files under certain conditions. Siemens has released an update for the SINEMA Server and recommends to update to the latest version.
Title
SSA-756638 V1.0: Vulnerabilities in Third-Party Component Mbed TLS of LOGO! CMR Family and SIMATIC RTU 3000 Family
Published
Sept. 14, 2021, 2 a.m.
Summary
Devices of the LOGO! CMR family and the SIMATIC RTU 3000 family are affected by several vulnerabilities in the third party component Mbed TLS. They could allow an attacker with access to any of the interfaces of an affected device to impact the availability or to communicate with invalid certificates. ...
Title
SSA-692317 V1.0: Authorization Bypass Vulnerability in Industrial Edge
Published
Sept. 14, 2021, 2 a.m.
Summary
The latest update for Industrial Edge fixes a vulnerability that could allow an unauthenticated attacker to change the password of any user in the system. With this an attacker could impersonate any valid user on an affected system. Siemens has released updates for the affected products and recommends to update ...

Last Updates

BOSCH PSIRT
31.10.2024
SIEMENS CERT
22.11.2024
US CERT
08.11.2024
US CERT (ICS)
21.11.2024

By Source

Archive

2024
2023
2022
2021
2020
2019
2018
2017

Feeds