April 2020
Title
LCDS LAquis SCADA
Published
April 28, 2020, 4 p.m.
Summary
This advisory contains mitigations for exposure of sensitive information to an unauthorized actor, and improper input validation vulnerabilities in LCDS's LAquis SCADA software.
Title
Sierra Wireless AirLink ALEOS (Update B)
Published
April 23, 2020, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-19-122-03 Sierra Wireless AirLink ALEOS (Update A) that was published August 20, 2019, to the ICS webpage on us-cert.gov. This updated advisory includes mitigations for OS command injection, use of hard-coded credentials, unrestricted upload of file with dangerous type, ...
Title
Inductive Automation Ignition
Published
April 21, 2020, 4 p.m.
Summary
This advisory contains mitigations for an improper access control vulnerability in Inductive Automation's Ignition 8 Gateway web server software.
Title
Eaton HMiSoft VU3
Published
April 14, 2020, 5:05 p.m.
Summary
This advisory contains mitigations for stack-based buffer overflow and out-of-bounds read vulnerabilities in Eaton's HMiSoft VU3 human-machine interface (HMI).
Title
Triangle MicroWorks DNP3 Outstation Libraries
Published
April 14, 2020, 5 p.m.
Summary
This advisory contains mitigations for a stack-based buffer overflow vulnerability in Triangle MicroWorks DNP3 components and source code libraries.
Title
Triangle MicroWorks SCADA Data Gateway
Published
April 14, 2020, 4:55 p.m.
Summary
This advisory contains mitigations for stack-based buffer overflow, out-of-bounds read, and type confusion vulnerabilities in the Triangle MicroWorks SCADA Data Gateway.
Title
Siemens Climatix
Published
April 14, 2020, 4:50 p.m.
Summary
This advisory contains mitigations for cross-site scripting and basic XSS vulnerabilities in Siemens Climatix controllers.
Title
Siemens IE/PB-Link, RUGGEDCOM, SCALANCE, SIMATIC, SINEMA
Published
April 14, 2020, 4:45 p.m.
Summary
This advisory contains mitigations for uncontrolled resource consumption and improper input validation vulnerabilities in Siemens IE/PB-Link, RUGGEDCOM, SCALANCE, SIMATIC, and SINEMA products.
Title
Siemens SIMOTICS, Desigo, APOGEE, and TALON
Published
April 14, 2020, 4:40 p.m.
Summary
This advisory contains mitigations for a business logic errors vulnerability in Siemens' SIMOTICS, Desigo, APOGEE, and TALON products.
Title
Siemens SCALANCE & SIMATIC
Published
April 14, 2020, 4:35 p.m.
Summary
This advisory contains mitigations for a resource exhaustion vulnerability in Siemens' SCALANCE and SIMATIC products.
Title
Siemens KTK, SIDOOR, SIMATIC, and SINAMICS
Published
April 14, 2020, 4:30 p.m.
Summary
This advisory contains mitigations for an uncontrolled resource consumption vulnerability in Siemens' KTN, SIDOOR, SIMATIC, and SINAMICS products.
Title
Siemens TIM 3V-IE and 4R-IE Family Devices
Published
April 14, 2020, 4:25 p.m.
Summary
This advisory contains mitigations for an active debug code vulnerability in Siemens TIM 3V-IE and 4R-IE Family Devices.
Title
Siemens SIMATIC S7 (Update B)
Published
April 14, 2020, 4:20 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-20-042-05 Siemens SIMATIC S7 (Update A) that was published March 10, 2020, to the ICS webpage on us-cert.gov. This advisory contains mitigations for a resource exhaustion vulnerability in Siemens SIMATIC S7 devices.
Title
Advantech WebAccess/NMS
Published
April 7, 2020, 4:25 p.m.
Summary
This advisory contains mitigations for multiple vulnerabilities in Advantech's WebAccess/NMS network management system.
Title
GE Digital CIMPLICITY
Published
April 7, 2020, 4:20 p.m.
Summary
This advisory contains mitigations for a privilege escalation vulnerability in GE Digital CIMPLICITY HMI/SCADA products.
Title
HMS Networks eWON Flexy and Cosy
Published
April 7, 2020, 4:15 p.m.
Summary
This advisory contains mitigations for a cross-site scripting vulnerability in HMS Networks eWON Flexy and Cosy Industrial VPN routers.
Title
KUKA.Sim Pro
Published
April 7, 2020, 4:05 p.m.
Summary
This advisory contains mitigations for a ### vulnerability in ###, a ###
Title
Synergy Systems & Solutions HUSKY RTU (Update A)
Published
April 7, 2020, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-20-042-01 Synergy Systems & Solutions HUSKY RTU that was published February 11, 2020, to the ICS webpage on us-cert.gov. This advisory contains mitigations for improper authentication and improper input validation vulnerabilities in Synergy Systems & Solutions HUSKY RTU, a ...
Title
B&R Automation Studio
Published
April 2, 2020, 4 p.m.
Summary
This advisory contains mitigations for improper privilege management, missing required cryptographic step, and path traversal vulnerabilities in B&R Automation Studio software.
March 2020
Title
BD Pyxis MedStation and Pyxis Anesthesia (PAS) ES System
Published
March 31, 2020, 4:15 p.m.
Summary
This advisory contains mitigations for a protection mechanism failure vulnerability in BD Pyxis medical devices.
Title
Hirschmann Automation and Control HiOS and HiSecOS Products
Published
March 31, 2020, 4:10 p.m.
Summary
This advisory contains mitigations for a classic buffer overflow vulnerability in Hirschmann Automation and Control HiOS and HiSecOS software.
Title
Mitsubishi Electric MELSEC
Published
March 31, 2020, 4:05 p.m.
Summary
This advisory contains mitigations for an uncontrolled resource consumption vulnerability in Mitsubishi Electric MELSEC programmable controllers.
Title
Schneider Electric Modicon Controllers (Update A)
Published
March 31, 2020, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-20-016-01 Schneider Electric Modicon Controllers that was published January 16, 2020, to the ICS webpage on us-cert.gov. This advisory contains mitigations for several improper check for unusual or exceptional conditions vulnerabilities in Schneider Electric Modicon PLC controllers.
Title
VISAM Automation Base (VBASE)
Published
March 24, 2020, 3:05 p.m.
Summary
This advisory contains mitigations for several vulnerabilities in VISAM's VBASE automation platform.
Title
Insulet Omnipod
Published
March 19, 2020, 3:05 p.m.
Summary
This advisory contains mitigations for an improper access control vulnerability in Insulet's Omnipod insulin management system.

Last Updates

BOSCH PSIRT
21.08.2024
SIEMENS CERT
12.09.2024
US CERT
19.09.2024
US CERT (ICS)
19.09.2024

By Source

Archive

2024
2023
2022
2021
2020
2019
2018
2017

Feeds