March 2021
Title
TCP/IP Stack Vulnerabilities–AMNESIA:33 in SENTRON PAC / 3VA Devices
Published
March 9, 2021, 5:15 p.m.
Summary
This advisory contains mitigations for Out-of-bounds Read, and Out-of-bounds Write vulnerabilities in Siemens SENTRON PAC / 3VA Devices power monitoring devices.
Title
Siemens TCP Stack of SIMATIC MV400
Published
March 9, 2021, 5:10 p.m.
Summary
This advisory contains mitigations for Improper Validation of Specified Index, Position, or Offset in Input; and Use of Insufficiently Random Values vulnerabilities in Siemens SIMATIC MV400 optical code reader software.
Title
Siemens Energy PLUSCONTROL 1st Gen
Published
March 9, 2021, 5:05 p.m.
Summary
This advisory contains mitigations for a Predictable Exact Value from Previous Values vulnerability in Siemens Energy PLUSCONTROL 1st Gen energy management systems.
Title
Siemens Solid Edge File Parsing
Published
March 9, 2021, 5 p.m.
Summary
This advisory contains mitigations for a Out-of-bounds Write, Improper Restriction of XML External Entity Reference, and Out-of-bounds Read vulnerabilities in Siemens Solid Edge portfolio software tools.
Title
Hitachi ABB Power Grids Ellipse EAM
Published
March 2, 2021, 4:10 p.m.
Summary
This advisory contains mitigations for Cross-site Scripting, and User Interface Misrepresentation of Critical Information vulnerabilities in Hitachi ABB Power Grids Ellipse EAM software products.
Title
Rockwell Automation CompactLogix 5370 and ControlLogix 5570 Controllers
Published
March 2, 2021, 4:05 p.m.
Summary
This advisory contains mitigations for an Improper Input Validation vulnerability in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 controllers.
Title
MB connect line mbCONNECT24, mymbCONNECT24
Published
March 2, 2021, 4 p.m.
Summary
This advisory contains mitigations for several vulnerabilities in the MB connect line mbCONNECT24, mymbCONNECT24 remote service portal products.
February 2021
Title
PerFact OpenVPN-Client
Published
Feb. 25, 2021, 4:15 p.m.
Summary
This advisory contains mitigations for an External Control of System or Configuration Setting vulnerability in the PerFact OpenVPN-Client.
Title
Fatek FvDesigner
Published
Feb. 25, 2021, 4:10 p.m.
Summary
This advisory contains mitigations for Use After Free, Access of Uninitialized Pointer, Stack-based Buffer Overflow, Out-of-Bounds Write, and Out-of-Bounds Read vulnerabilities in Fatek FvDesigner software.
Title
Rockwell Automation Logix Controllers
Published
Feb. 25, 2021, 4:05 p.m.
Summary
This advisory contains mitigations for a n Insufficiently Protected Credentials vulnerability in Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, and Logix Controllers.
Title
ProSoft Technology ICX35
Published
Feb. 25, 2021, 4 p.m.
Summary
This advisory contains mitigations for a Permissions, Privileges, and Access Controls vulnerability in ProSoft Technology ICX35 industrial cellular gateways.
Title
Advantech BB-ESWGP506-2SFP-T
Published
Feb. 23, 2021, 4:05 p.m.
Summary
This advisory contains mitigations for a Use of Hard-coded Credentials vulnerability in Advantech BB-ESWGP506-2SFP-T industrial ethernet switches.
Title
Advantech Spectre RT Industrial Routers
Published
Feb. 23, 2021, 4 p.m.
Summary
This advisory contains mitigations for Improper Neutralization of Input During Web Page Generation, Cleartext Transmission of Sensitive Information, Improper Restriction of Excessive Authentication Attempts, Use of a Broken or Risky Cryptographic Algorithm, and Use of Platform-Dependent Third-party Components vulnerabilities in Advantech Spectre RT Industrial Routers.
Title
Multiple Embedded TCP/IP stacks
Published
Feb. 11, 2021, 4:10 p.m.
Summary
This advisory contains mitigations for Use of Insufficiently Random Values vulnerabilities in Nut/Net, CycloneTCP, NDKTCPIP, FNET, uIP-Contiki-OS, uC/TCP-IP, uIP-Contiki-NG, uIP, picoTCP-NG, picoTCP, MPLAB Net, Nucleus NET, Nucleus ReadyStart TCP/IP stacks.
Title
Rockwell Automation DriveTools SP and Drives AOP
Published
Feb. 11, 2021, 4:05 p.m.
Summary
This advisory contains mitigations for an Uncontrolled Search Path Element vulnerability in Rockwell Automation DriveTools SP and Drives AOP software.
Title
Wibu-Systems CodeMeter (Update E)
Published
Feb. 11, 2021, 4 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-20-203-01 Wibu-Systems CodeMeter (Update D) that was published December 3, 2020, to the ICS webpage on us-cert.gov. This advisory contains mitigations for Buffer Access with Incorrect Length Value, Inadequate Encryption Strength, Origin Validation Error, Improper Input Validation, Improper Verification ...
Title
GE Digital HMI/SCADA iFIX
Published
Feb. 9, 2021, 5:50 p.m.
Summary
This advisory contains mitigations for Incorrect Permission Assignment for Critical Resource vulnerabilities in the GE Digital HMI/SCADA iFIX software component.
Title
Siemens SINEMA Server & SINEC NMS
Published
Feb. 9, 2021, 5:40 p.m.
Summary
This advisory contains mitigations for a Path Traversal vulnerability in Siemens SINEMA server and SINEC NMS products.
Title
Siemens TIA Administrator
Published
Feb. 9, 2021, 5:30 p.m.
Summary
This advisory contains mitigations for an Improper Access Control vulnerability in Siemens TIA Administrator products.
Title
Siemens SCALANCE W780 and W740
Published
Feb. 9, 2021, 5:20 p.m.
Summary
This advisory contains mitigations for an Allocation of Resources Without Limits or Throttling vulnerability in Siemens SCALANCE W780 and W740 industrial wireless LAN products.
January 2021
Title
SOOIL Dana Diabecare RS Products
Published
Jan. 12, 2021, 5 p.m.
Summary
This advisory contains mitigations for Use of Hard Coded Credentials, Insufficiently Protected Credentials, Use of Insufficiently Random Values, Use of Client-side Authentication, Client-side Enforcement of Server-side Security, Authentication Bypass by Capture-Replay, Unprotected Transport of Credentials, Key Exchange Without Entity Authentication, and Authentication Bypass by Spoofing vulnerabilities in SOOIL Dana Diabecare ...
Title
Schneider Electric EcoStruxure Power Build-Rapsody
Published
Jan. 12, 2021, 4:55 p.m.
Summary
This advisory contains mitigations for an Unrestricted Upload of File with Dangerous Type vulnerability in the Schneider Electric EcoStruxure Power Build-Rapsody software.
Title
Siemens JT2Go and Teamcenter Visualization
Published
Jan. 12, 2021, 4:45 p.m.
Summary
This advisory contains mitigations for a Type Confusion, Improper Restriction of XML External Entity Reference, Out-of-bounds Write, Heap-based Buffer Overflow, Stack-based Buffer Overflow, Untrusted Pointer Dereference, and Out-of-bounds Read vulnerabilities in Siemens JT2Go and Teamcenter Visualization software products.
Title
Siemens Solid Edge
Published
Jan. 12, 2021, 4:40 p.m.
Summary
This advisory contains mitigations for Out-of-bounds Write, and Stack-based Buffer Overflow vulnerabilities in Siemens Solid Edge software tools.
Title
Siemens SCALANCE X Products
Published
Jan. 12, 2021, 4:35 p.m.
Summary
This advisory contains mitigations for Missing Authentication for Critical Function, and Heap-based Buffer Overflow vulnerabilities in Siemens SCALANCE X switches.

Last Updates

BOSCH PSIRT
21.08.2024
SIEMENS CERT
12.09.2024
US CERT
19.09.2024
US CERT (ICS)
19.09.2024

By Source

Archive

2024
2023
2022
2021
2020
2019
2018
2017

Feeds