September 2020
Title
SSA-480230 (Last Update: 2020-09-08): Denial-of-Service in Webserver of Industrial Products
Published
Sept. 8, 2020, 2 a.m.
Summary
A vulnerability in the affected devices could allow an unauthorized attacker with network access to the webserver of an affected device to perform a denial-of-service attack. Siemens has released updates for several affected products and recommends to update to the new versions. Siemens is preparing further updates and recommends specific ...
Title
SSA-455843 (Last Update: 2020-09-08): WIBU Systems CodeMeter Runtime Vulnerabilities in Siemens and Siemens Energy Products
Published
Sept. 8, 2020, 2 a.m.
Summary
CISA and WIBU Systems disclosed six vulnerabilities in different versions of CodeMeter Runtime, a product provided by WIBU Systems and used in several Siemens and Siemens Energy products for license management. The vulnerabilities are described in the section “Vulnerability Classification” below and got assigned the CVE IDs CVE-2020-14509, CVE-2020-14513, CVE-2020-14515, ...
Title
SSA-841348 (Last Update: 2020-09-08): Multiple Vulnerabilities in the UMC Stack
Published
Sept. 8, 2020, 2 a.m.
Summary
The latest update for the below listed products fixes two security vulnerabilities that could allow an attacker to cause a partial Denial-of-Service on the UMC component of the affected devices under certain circumstances, and one vulnerability that could allow an attacker to locally escalate privileges from a user with administrative ...
Title
SSA-780073 (Last Update: 2020-09-08): Denial-of-Service Vulnerability in PROFINET Devices via DCE-RPC Packets
Published
Sept. 8, 2020, 2 a.m.
Summary
Products that include the Siemens PROFINET-IO (PNIO) stack in versions prior V06.00 are potentially affected by a denial-of-service vulnerability when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. Siemens has released updates for several affected products and recommends to update to the new versions. Siemens is preparing ...
Title
SSA-381684 (Last Update: 2020-09-08): Improper Password Protection during Authentication in SIMATIC S7-300 and S7-400 CPUs
Published
Sept. 8, 2020, 2 a.m.
Summary
A vulnerability has been identified in SIMATIC S7-300 and S7-400 CPU families, which could result in credential disclosure. Siemens recommends countermeasures as there are currently no fixes available.
Title
SSA-251935 (Last Update: 2020-09-08): Multiple Privilege Escalation Vulnerabilities in SIMATIC RTLS Locating Manager
Published
Sept. 8, 2020, 2 a.m.
Summary
The latest update for SIMATIC RTLS Locating Manager fixes various vulnerabilities that could allow a low-privileged local user to escalate privileges. Siemens recommends to apply the update of the SIMATIC RTLS Locating Manager.
Title
SSA-534763 (Last Update: 2020-09-08): Special Register Buffer Data Sampling (SRBDS) aka Crosstalk in Industrial Products
Published
Sept. 8, 2020, 2 a.m.
Summary
Security researchers published information on a vulnerability known as Crosstalk (INTEL-SA-00320). This vulnerability affects modern Intel processors to a varying degree. Several Siemens Industrial Products contain processors that are affected by the vulnerability. Siemens is preparing updates and recommends specific countermeasures until fixes are available.
Title
SSA-542525 (Last Update: 2020-09-08): Authentication Vulnerabilities in SIMATIC HMI Products
Published
Sept. 8, 2020, 2 a.m.
Summary
SIMATIC HMI Products are affected by two vulnerabilities that could allow a remote attacker to discover user passwords and obtain access to the Sm@rt Server via a brute-force attack. Siemens is preparing updates and recommends specific countermeasures for products where updates are not, or not yet available.
Title
SSA-568969 (Last Update: 2020-09-08): Insecure Storage of Sensitive Information in Spectrum Power™ 4
Published
Sept. 8, 2020, 2 a.m.
Summary
Vulnerabilities in Spectrum Power™ 4 could allow an unauthorized attacker to retrieve a list of software users, or in certain cases to list the contents of a directory. Siemens has released updates and configuration recommendations for Spectrum Power™ 4 in order to mitigate the issues.
Title
SSA-709003 (Last Update: 2020-09-08): Privilege Escalation Vulnerability in License Management Utility (LMU)
Published
Sept. 8, 2020, 2 a.m.
Summary
The latest update for the License Management Utility (LMU), which is used by multiple Siemens building technology products, fixes a vulnerability that could allow local users to escalate privileges and execute code as local SYSTEM user. Siemens has released an update version of LMU, recommends to install this update on ...
Title
SSA-770698 (Last Update: 2020-09-08): User Information Disclosure Vulnerability in Siveillance Video Client
Published
Sept. 8, 2020, 2 a.m.
Summary
The Siveillance Video Client contains an information disclosure vulnerability that could allow an attacker to obtain valid adminstrator login names and use this information to launch further attacks. Siemens recommends specific countermeasures and provides patches for released versions of the Siveillance Video Client.
Title
SSA-102233 (Last Update: 2020-09-08): SegmentSmack in VxWorks-based Industrial Devices
Published
Sept. 8, 2020, 2 a.m.
Summary
The latest updates for the affected products fix a vulnerability that could allow remote attackers to affect the availability of the devices under certain conditions. The underlying TCP stack can be forced to make very computation expensive calls for every incoming packet which can lead to a Denial-of-Service. Siemens is ...
August 2020
Title
SSA-370042 (Last Update: 2020-08-11): Cross-Site-Scripting (XSS) in SICAM A8000 RTUs
Published
Aug. 11, 2020, 2 a.m.
Summary
The latest update for SICAM A8000 RTUs fixes a vulnerability that could allow attackers with network access to the device’s web server to perform a stored Cross-Site-Scripting attack. Siemens has released an update for SICAM A8000 RTUs and recommends to update as soon as possible.
Title
SSA-978220 (Last Update: 2020-08-11): Denial-of-Service Vulnerability over SNMP in Multiple Industrial Products
Published
Aug. 11, 2020, 2 a.m.
Summary
Several industrial products are affected by a vulnerability that could allow remote attackers to conduct a Denial-of-Service (DoS) attack by sending specially crafted packets to port 161/udp (SNMP). Siemens has released updates for several affected products and recommends to update to the new versions. Siemens is preparing further updates and ...
Title
SSA-841348 (Last Update: 2020-08-11): Multiple Vulnerabilities in the UMC Stack
Published
Aug. 11, 2020, 2 a.m.
Summary
The latest update for the below listed products fixes two security vulnerabilities that could allow an attacker to cause a partial Denial-of-Service on the UMC component of the affected devices under certain circumstances, and one vulnerability that could allow an attacker to locally escalate privileges from a user with administrative ...
Title
SSA-780073 (Last Update: 2020-08-11): Denial-of-Service Vulnerability in PROFINET Devices via DCE-RPC Packets
Published
Aug. 11, 2020, 2 a.m.
Summary
Products that include the Siemens PROFINET-IO (PNIO) stack in versions prior V06.00 are potentially affected by a denial-of-service vulnerability when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is ...
Title
SSA-604937 (Last Update: 2020-08-11): Multiple Web Server Vulnerabilities in Opcenter Execution Core
Published
Aug. 11, 2020, 2 a.m.
Summary
Opcenter Execution Core (formerly known as Camstar Enterprise Platform) contains a Cross-Site-Scripting, an SQL injection and an information disclosure vulnerability. Siemens recommends to update to the latest version of Opcenter Execution Core that fixes two vulnerabilities and recommends specific countermeasures for the remaining vulnerability.
Title
SSA-591405 (Last Update: 2020-08-11): Web Vulnerabilities in SCALANCE S-600 Family
Published
Aug. 11, 2020, 2 a.m.
Summary
The firmware for SCALANCE S-600 family devices contains multiple web vulnerabilities. The vulnerabilities could allow an remote attacker to conduct Denial-of-Service attacks or perform Cross-Site Scripting attacks. Siemens recommends specific countermeasures for products where updates are not, or not yet available.
Title
SSA-535640 (Last Update: 2020-08-11): Vulnerability in Industrial Products
Published
Aug. 11, 2020, 2 a.m.
Summary
Various industrial products use the Discovery Service of the OPC UA protocol stack by the OPC foundation https://github.com/OPCFoundation/UA-.NETStandard and could therefore be affected by the remote resource consumption attacks (CVE-2017-12069).
Title
SSA-480230 (Last Update: 2020-08-11): Denial-of-Service in Webserver of Industrial Products
Published
Aug. 11, 2020, 2 a.m.
Summary
A vulnerability in the affected devices could allow an unauthorized attacker with network access to the webserver of an affected device to perform a denial-of-service attack. Siemens has released updates for several affected products and recommends to update to the new versions. Siemens is preparing further updates and recommends specific ...
Title
SSA-473245 (Last Update: 2020-08-11): Denial-of-Service Vulnerability in Profinet Devices
Published
Aug. 11, 2020, 2 a.m.
Summary
A vulnerability in affected devices could allow an attacker to perform a denial-of-service attack if a large amount of specially crafted UDP packets are sent to the device. Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates ...
Title
SSA-462066 (Last Update: 2020-08-11): Vulnerability known as TCP SACK PANIC in Industrial Products
Published
Aug. 11, 2020, 2 a.m.
Summary
Multiple industrial products are affected by a vulnerability in the kernel known as TCP SACK PANIC. The vulnerability could allow a remote attacker to cause a denial of service condition. Siemens has released updates for several affected products and recommends to update to the new versions. Siemens is preparing further ...
Title
SSB-439005 (Last Update: 2020-08-11): Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
Published
Aug. 11, 2020, 2 a.m.
Summary
Title
SSA-349422 (Last Update: 2020-08-11): Denial-of-Service in Industrial Real-Time (IRT) Devices
Published
Aug. 11, 2020, 2 a.m.
Summary
A vulnerability in the affected products could allow an unauthorized attacker with network access to perform a denial-of-service attack resulting in loss of real-time synchronization. Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates and recommends specific ...
Title
SSA-346262 (Last Update: 2020-08-11): Denial-of-Service in Industrial Products
Published
Aug. 11, 2020, 2 a.m.
Summary
Several industrial products are affected by a vulnerability that could allow remote attackers to conduct a Denial-of-Service (DoS) attack by sending specially crafted packets to port 161/udp (SNMP). Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates ...

Last Updates

BOSCH PSIRT
25.04.2025
SIEMENS CERT
23.05.2025
US CERT
20.05.2025
US CERT (ICS)
05.06.2025

By Source

Archive

2025
2024
2023
2022
2021
2020
2019
2018
2017

Feeds