March 2021
Title
MB connect line mbCONNECT24, mymbCONNECT24
Published
March 2, 2021, 4 p.m.
Summary
This advisory contains mitigations for several vulnerabilities in the MB connect line mbCONNECT24, mymbCONNECT24 remote service portal products.
February 2021
Title
PerFact OpenVPN-Client
Published
Feb. 25, 2021, 4:15 p.m.
Summary
This advisory contains mitigations for an External Control of System or Configuration Setting vulnerability in the PerFact OpenVPN-Client.
Title
Fatek FvDesigner
Published
Feb. 25, 2021, 4:10 p.m.
Summary
This advisory contains mitigations for Use After Free, Access of Uninitialized Pointer, Stack-based Buffer Overflow, Out-of-Bounds Write, and Out-of-Bounds Read vulnerabilities in Fatek FvDesigner software.
Title
Rockwell Automation Logix Controllers
Published
Feb. 25, 2021, 4:05 p.m.
Summary
This advisory contains mitigations for a n Insufficiently Protected Credentials vulnerability in Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, and Logix Controllers.
Title
ProSoft Technology ICX35
Published
Feb. 25, 2021, 4 p.m.
Summary
This advisory contains mitigations for a Permissions, Privileges, and Access Controls vulnerability in ProSoft Technology ICX35 industrial cellular gateways.
Title
Advantech BB-ESWGP506-2SFP-T
Published
Feb. 23, 2021, 4:05 p.m.
Summary
This advisory contains mitigations for a Use of Hard-coded Credentials vulnerability in Advantech BB-ESWGP506-2SFP-T industrial ethernet switches.
Title
Advantech Spectre RT Industrial Routers
Published
Feb. 23, 2021, 4 p.m.
Summary
This advisory contains mitigations for Improper Neutralization of Input During Web Page Generation, Cleartext Transmission of Sensitive Information, Improper Restriction of Excessive Authentication Attempts, Use of a Broken or Risky Cryptographic Algorithm, and Use of Platform-Dependent Third-party Components vulnerabilities in Advantech Spectre RT Industrial Routers.
Title
Multiple Embedded TCP/IP stacks
Published
Feb. 11, 2021, 4:10 p.m.
Summary
This advisory contains mitigations for Use of Insufficiently Random Values vulnerabilities in Nut/Net, CycloneTCP, NDKTCPIP, FNET, uIP-Contiki-OS, uC/TCP-IP, uIP-Contiki-NG, uIP, picoTCP-NG, picoTCP, MPLAB Net, Nucleus NET, Nucleus ReadyStart TCP/IP stacks.
Title
Rockwell Automation DriveTools SP and Drives AOP
Published
Feb. 11, 2021, 4:05 p.m.
Summary
This advisory contains mitigations for an Uncontrolled Search Path Element vulnerability in Rockwell Automation DriveTools SP and Drives AOP software.
Title
Wibu-Systems CodeMeter (Update E)
Published
Feb. 11, 2021, 4 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-20-203-01 Wibu-Systems CodeMeter (Update D) that was published December 3, 2020, to the ICS webpage on us-cert.gov. This advisory contains mitigations for Buffer Access with Incorrect Length Value, Inadequate Encryption Strength, Origin Validation Error, Improper Input Validation, Improper Verification ...
Title
GE Digital HMI/SCADA iFIX
Published
Feb. 9, 2021, 5:50 p.m.
Summary
This advisory contains mitigations for Incorrect Permission Assignment for Critical Resource vulnerabilities in the GE Digital HMI/SCADA iFIX software component.
Title
Siemens SINEMA Server & SINEC NMS
Published
Feb. 9, 2021, 5:40 p.m.
Summary
This advisory contains mitigations for a Path Traversal vulnerability in Siemens SINEMA server and SINEC NMS products.
Title
Siemens TIA Administrator
Published
Feb. 9, 2021, 5:30 p.m.
Summary
This advisory contains mitigations for an Improper Access Control vulnerability in Siemens TIA Administrator products.
Title
Siemens SCALANCE W780 and W740
Published
Feb. 9, 2021, 5:20 p.m.
Summary
This advisory contains mitigations for an Allocation of Resources Without Limits or Throttling vulnerability in Siemens SCALANCE W780 and W740 industrial wireless LAN products.
January 2021
Title
SOOIL Dana Diabecare RS Products
Published
Jan. 12, 2021, 5 p.m.
Summary
This advisory contains mitigations for Use of Hard Coded Credentials, Insufficiently Protected Credentials, Use of Insufficiently Random Values, Use of Client-side Authentication, Client-side Enforcement of Server-side Security, Authentication Bypass by Capture-Replay, Unprotected Transport of Credentials, Key Exchange Without Entity Authentication, and Authentication Bypass by Spoofing vulnerabilities in SOOIL Dana Diabecare ...
Title
Schneider Electric EcoStruxure Power Build-Rapsody
Published
Jan. 12, 2021, 4:55 p.m.
Summary
This advisory contains mitigations for an Unrestricted Upload of File with Dangerous Type vulnerability in the Schneider Electric EcoStruxure Power Build-Rapsody software.
Title
Siemens JT2Go and Teamcenter Visualization
Published
Jan. 12, 2021, 4:45 p.m.
Summary
This advisory contains mitigations for a Type Confusion, Improper Restriction of XML External Entity Reference, Out-of-bounds Write, Heap-based Buffer Overflow, Stack-based Buffer Overflow, Untrusted Pointer Dereference, and Out-of-bounds Read vulnerabilities in Siemens JT2Go and Teamcenter Visualization software products.
Title
Siemens Solid Edge
Published
Jan. 12, 2021, 4:40 p.m.
Summary
This advisory contains mitigations for Out-of-bounds Write, and Stack-based Buffer Overflow vulnerabilities in Siemens Solid Edge software tools.
Title
Siemens SCALANCE X Products
Published
Jan. 12, 2021, 4:35 p.m.
Summary
This advisory contains mitigations for Missing Authentication for Critical Function, and Heap-based Buffer Overflow vulnerabilities in Siemens SCALANCE X switches.
Title
Siemens Opcenter Execution Core (Update B)
Published
Jan. 12, 2021, 4:30 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-20-196-07 Siemens Opcenter Execution Core (Update A) that was published August 11, 2020, to the ICS webpage on us-cert.cisa.gov. This advisory contains mitigations for Cross-site Scripting, SQL Injection, and Improper Access Control vulnerabilities in Siemens Opcenter Execution Core software.
Title
Siemens SIMATIC, SINAMICS, SINEC, SINEMA, SINUMERIK (Update E)
Published
Jan. 12, 2021, 4:25 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-20-161-04 Siemens SIMATIC, SINAMICS, SINEC, SINEMA, SINUMERIK (Update D) that was published December 8, 2020, to the ICS webpage on us-cert.cisa.gov. This advisory contains mitigations for an Unquoted Search Path or Element vulnerability in Siemens SIMATIC, SINAMICS, SINEC, SINEMA, ...
Title
Siemens SIMOTICS, Desigo, APOGEE, and TALON (Update A)
Published
Jan. 12, 2021, 4:20 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-20-105-06 Siemens SIMOTICS, Desigo, APOGEE, and TALON that was published April 14, 2020, to the ICS webpage on us-cert.cisa.gov. This advisory contains mitigations for a business logic errors vulnerability in Siemens SIMOTICS, Desigo, APOGEE, and TALON products.
Title
Siemens SCALANCE & SIMATIC (Update C)
Published
Jan. 12, 2021, 4:15 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-20-105-07 Siemens SCALANCE & SIMATIC (Update B) that was published September 8, 2020, to the ICS webpage on us-cert.cisa.gov. This advisory contains mitigations for a resource exhaustion vulnerability in Siemens SCALANCE and SIMATIC products.
December 2020
Title
Schneider Electric EcoStruxure Operator Terminal Expert runtime (Vijeo XD)
Published
Dec. 1, 2020, 4 p.m.
Summary
This advisory contains mitigations for an Improper Privilege Management vulnerability in Schneider Electric EcoStruxure Operator Terminal Expert products.
November 2020
Title
Rockwell Automation FactoryTalk Linx
Published
Nov. 24, 2020, 4:05 p.m.
Summary
This advisory contains mitigations for Improper Input Validation, and Heap-based Buffer Overflow vulnerabilities in Rockwell Automation FactoryTalk Linx software.

Last Updates

BOSCH PSIRT
15.01.2025
SIEMENS CERT
17.04.2025
US CERT
01.04.2025
US CERT (ICS)
17.04.2025

By Source

Archive

2025
2024
2023
2022
2021
2020
2019
2018
2017

Feeds