January 2021
Title
Siemens Opcenter Execution Core (Update B)
Published
Jan. 12, 2021, 4:30 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-20-196-07 Siemens Opcenter Execution Core (Update A) that was published August 11, 2020, to the ICS webpage on us-cert.cisa.gov. This advisory contains mitigations for Cross-site Scripting, SQL Injection, and Improper Access Control vulnerabilities in Siemens Opcenter Execution Core software.
Title
Siemens SIMATIC, SINAMICS, SINEC, SINEMA, SINUMERIK (Update E)
Published
Jan. 12, 2021, 4:25 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-20-161-04 Siemens SIMATIC, SINAMICS, SINEC, SINEMA, SINUMERIK (Update D) that was published December 8, 2020, to the ICS webpage on us-cert.cisa.gov. This advisory contains mitigations for an Unquoted Search Path or Element vulnerability in Siemens SIMATIC, SINAMICS, SINEC, SINEMA, ...
Title
Siemens SIMOTICS, Desigo, APOGEE, and TALON (Update A)
Published
Jan. 12, 2021, 4:20 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-20-105-06 Siemens SIMOTICS, Desigo, APOGEE, and TALON that was published April 14, 2020, to the ICS webpage on us-cert.cisa.gov. This advisory contains mitigations for a business logic errors vulnerability in Siemens SIMOTICS, Desigo, APOGEE, and TALON products.
Title
Siemens SCALANCE & SIMATIC (Update C)
Published
Jan. 12, 2021, 4:15 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-20-105-07 Siemens SCALANCE & SIMATIC (Update B) that was published September 8, 2020, to the ICS webpage on us-cert.cisa.gov. This advisory contains mitigations for a resource exhaustion vulnerability in Siemens SCALANCE and SIMATIC products.
December 2020
Title
Schneider Electric EcoStruxure Operator Terminal Expert runtime (Vijeo XD)
Published
Dec. 1, 2020, 4 p.m.
Summary
This advisory contains mitigations for an Improper Privilege Management vulnerability in Schneider Electric EcoStruxure Operator Terminal Expert products.
November 2020
Title
Rockwell Automation FactoryTalk Linx
Published
Nov. 24, 2020, 4:05 p.m.
Summary
This advisory contains mitigations for Improper Input Validation, and Heap-based Buffer Overflow vulnerabilities in Rockwell Automation FactoryTalk Linx software.
Title
Mitsubishi Electric MELSEC iQ-R Series
Published
Nov. 19, 2020, 4 p.m.
Summary
This advisory contains mitigations for an Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric's MELSEC iQ-R series CPU module products.
Title
Johnson Controls Sensormatic Electronics American Dynamics victor Web Client
Published
Nov. 17, 2020, 4:15 p.m.
Summary
This advisory contains mitigations for an Improper Authorization vulnerability in Sensormatic Electronics (a subsidiary of Johnson Controls) American Dynamics victor Web Client products.
Title
Paradox IP150
Published
Nov. 17, 2020, 4:10 p.m.
Summary
This advisory contains mitigations for Stack-based Buffer Overflow, and Classic Buffer Overflow vulnerabilities in Paradox IP150 Internet module LAN devices.
Title
Real Time Automation EtherNet/IP
Published
Nov. 17, 2020, 4:05 p.m.
Summary
This advisory contains mitigations for a Stack-based Buffer Overflow vulnerability in Real Time Automation 499ES EtherNet/IP Adaptor Source Code, a TCP/IP stack.
Title
Schneider Electric Interactive Graphical SCADA System (IGSS)
Published
Nov. 17, 2020, 4 p.m.
Summary
This advisory contains mitigations for Improper Restriction of Operations within the Bounds of a Memory Buffer, Out-of-bounds Write, and Out-of-bounds Read vulnerabilities in Schneider Electric's Interactive Graphical SCADA System (IGSS).
Title
BD Alaris 8015 PC Unit and BD Alaris Systems Manager
Published
Nov. 12, 2020, 4:05 p.m.
Summary
This advisory contains mitigations for an Improper Authentication vulnerability in BD Alaris 8015 PC Unit and BD Alaris Systems Manager. BD Alaris is an infusion pump system.
Title
Mitsubishi Electric GT14 Model of GOT1000 Series
Published
Nov. 5, 2020, 4:10 p.m.
Summary
This advisory contains mitigations for Improper Restriction of Operations within the Bounds of a Memory Buffer, Session Fixation, NULL Pointer Dereference, Improper Access Control, Argument Injection, and Resource Management Errors vulnerabilities in Mitsubishi Electric GT14 model of GOT1000 Series graphic operation terminals.
Title
Mitsubishi Electric Factory Automation Engineering Products (Update A)
Published
Nov. 5, 2020, 4:05 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-20-212-04 Mitsubishi Electric Factory Automation Engineering Products that was published July 30, 2020, to the ICS webpage to us-cert.cisa.gov. This advisory contains mitigations for an Unquoted Search Path or Element vulnerability in Mitsubishi Electric Factory Automation Engineering products.
Title
Mitsubishi Electric MELSEC iQ-R Series (Update B)
Published
Nov. 5, 2020, 4 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-20-161-02 Mitsubishi Electric MELSEC iQ-R Series (Update A) that was published June 16, 2020 to the ICS webpage to us-cert.cisa.gov. This advisory contains mitigations for a resource exhaustion vulnerability in the Mitsubishi Electric MELSEC iQ-R series programmable logic controllers.
Title
WAGO Series 750-88x and 750-352
Published
Nov. 3, 2020, 4:10 p.m.
Summary
This advisory contains mitigations for an Uncontrolled Resource Consumption vulnerability in the WAGO Fieldbus Ethernet coupler.
Title
NEXCOM NIO50
Published
Nov. 3, 2020, 4:05 p.m.
Summary
This advisory contains mitigations for Improper Input Validation, and Cleartext Transmission of Sensitive Information vulnerabilities in NEXCOM's NIO50 IoT Gateway.
Title
ARC Informatique PcVue
Published
Nov. 3, 2020, 4 p.m.
Summary
This advisory contains mitigations for Deserialization of Untrusted Data, Access to Critical Private Variable via Public Method, and Information Exposure of Sensitive Information to an Unauthorized Actor vulnerabilities in ARC Information PcVue SCADA products.
October 2020
Title
Mitsubishi Electric MELSEC iQ-R, Q and L Series
Published
Oct. 29, 2020, 3:15 p.m.
Summary
This advisory contains mitigations for an Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric's MELSEC iQ-R, Q and L Series programmable logic controllers.
Title
Mitsubishi Electric MELSEC iQ-R
Published
Oct. 29, 2020, 3:10 p.m.
Summary
This advisory contains mitigations for Improper Restriction of Operations within the Bounds of a Memory Buffer, Session Fixation, NULL Pointer Dereference, Improper Access Control, Argument Injection, and Resource Management Errors vulnerabilities in Mitsubishi Electric's iQ-R programmable logic controllers.
Title
Mitsubishi Electric MELSEC iQ-R Series (Update A)
Published
Oct. 29, 2020, 3:05 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-20-282-02 Mitsubishi Electric MELSEC iQ-R Series that was published October 8, 2020, to the ICS webpage on us-cert.cisa.gov. This advisory contains mitigations for an Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R Series modules.
Title
B. Braun OnlineSuite
Published
Oct. 22, 2020, 4:05 p.m.
Summary
This advisory contains mitigations for Relative Path Traversal, Uncontrolled Search Path Element, and Improper Neutralization of Formula Elements in a CSV File vulnerabilities in B. Braun's OnlineSuite.
Title
B. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplus
Published
Oct. 22, 2020, 4 p.m.
Summary
This advisory contains mitigations for Cross-site Scripting, Open Redirect, XPath Injection, Session Fixation, Use of a One-way Hash without a Salt, Relative Path Traversal, Improper Verification of Cryptographic Signature, Improper Privilege Management, Use of Hard-coded Credentials, Active Debug Code, and Improper Access Control vulnerabilities in B. Braun's SpaceCom, Battery Pack ...
Title
Rockwell Automation 1794-AENT Flex I/O Series B
Published
Oct. 20, 2020, 4:15 p.m.
Summary
This advisory contains mitigations for several Classic Buffer Overflow vulnerabilities in Rockwell Automation's 1794-AENT Flex I/O Series B Ethernet/IP adapter.
Title
Hitachi ABB Power Grids XMC20 Multiservice-Multiplexer
Published
Oct. 20, 2020, 4:10 p.m.
Summary
This advisory contains mitigations for an Improper Authentication vulnerability in Hitachi ABB Power Grids' XMC20 Multiservice-Multiplexer telecommunication elements.

Last Updates

BOSCH PSIRT
21.08.2024
SIEMENS CERT
12.09.2024
US CERT
19.09.2024
US CERT (ICS)
19.09.2024

By Source

Archive

2024
2023
2022
2021
2020
2019
2018
2017

Feeds