SIEMENS CERT
10/08/2019
A vulnerability in SIMATIC WinAC RTX (F) 2010 controller software could allow an attacker to perform a denial-of-service attack if a large HTTP request is sent to the network port of the host where WinAC RTX is running. Siemens recommends specific countermeasures to mitigate this issue.
SIEMENS CERT
10/08/2019
A vulnerability has been identified in the SIMATIC IT Unified Architecture Discrete Manufacturing product that caused a password to be encrypted with a predicable encryption key. An authenticated attacker could potentially recover the password and gain access to the TeamCenter station connected to the instance. Siemens provides updates to address …
SIEMENS CERT
09/10/2019
Multiple industrial products are affected by a vulnerability in the kernel known as TCP SACK PANIC. The vulnerability could allow a remote attacker to cause a denial of service condition. Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing …
SIEMENS CERT
09/10/2019
A vulnerability could allow an attacker to cause a Denial-of-Service condition on the UDP communication by sending a specially crafted UDP packet to the SIMATIC TDC CP51M1 module. Siemens has released an update for SIMATIC TDC CP51M1 module and recommends that customers update to the new version.
SIEMENS CERT
09/10/2019
The latest update for SINEMA Remote Connect Server fixes four vulnearbilities in the web interface. Two of the vulnerabilities are missing protection mechanisms for password guessing and for Cross Site Request Forgery attacks, the third one is a missing authentication check, and the fourth one could allow an attacker with …
SIEMENS CERT
09/10/2019
A vulnerability has been identified in SINETPLAN that could allow local users to execute arbitrary application commands without proper authentication. Siemens provides a solution that fixes the vulnerability and recommends that users apply the update.
SIEMENS CERT
09/10/2019
The latest update for SIMATIC WinCC fixes multiple vulnerabilities. The most severe could allow an attacker to execute arbitrary commands on an affected system under certain conditions. Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates and …