12.04.2022 12:54 | |
Beigetreten: 18.12.2014 Letzter Bes: 15.11.2024 Beiträge: 34226 Bewertung: (4262) |
Siemens ProductCERT hat elf veröffentlicht und 33 Advisories/Bulletins aktualisiert. Ladies and Gentlemen, for your information: The following new advisories/bulletins have just been published on the Siemens ProductCERT web site [1]: SSA-316850: Unauthenticated File Access in SICAM A8000 Devices SSA-350757: Improper Access Control Vulnerability in TIA Portal Affecting S7-1200 and S7-1500 CPUs Web Server (Incl. Related ET200 CPUs and SIPLUS variants) SSA-392912: Multiple Denial Of Service Vulnerabilities in SCALANCE W1700 Devices SSA-414513: Information Disclosure Vulnerability in Mendix SSA-446448: Denial of Service Vulnerability in PROFINET Stack Integrated on Interniche Stack SSA-557541: Denial-of-Service Vulnerability in SIMATIC S7-400 CPUs SSA-655554: Multiple Vulnerabilities in SIMATIC Energy Manager before V7.3 Update 1 SSA-711829: Denial of Service Vulnerability in TIA Administrator SSA-836527: Multiple Vulnerabilities in SCALANCE X-300 Switch Family Devices SSA-870917: Improper Access Control Vulnerability in Mendix SSA-998762: File Parsing Vulnerabilities in Simcenter Femap before V2022.1.2 Additionally, the following advisories / bulletins have just been updated on the Siemens ProductCERT web site [1]: SSA-102233: SegmentSmack in VxWorks-based Industrial Devices SSA-114589: Multiple Vulnerabilities in Nucleus RTOS based APOGEE, TALON and Desigo PXC/PXM Products SSA-148641: XPath Constraint Vulnerability in Mendix Runtime SSA-162506: DHCP Client Vulnerability in SIMOTICS CONNECT 400, Desigo PXC/PXM, APOGEE MEC/MBC/PXC, APOGEE PXC Series, and TALON TC Series SSA-244969: OpenSSL Vulnerability in Industrial Products SSA-256353: Third-Party Component Vulnerabilities in RUGGEDCOM ROS SSA-270778: Denial-of-Service Vulnerability in SIMATIC PCS 7, SIMATIC WinCC and SIMATIC NET PC Software SSA-273799: Message Integrity Protection Bypass Vulnerability in SIMATIC Products SSA-301589: Multiple File Parsing Vulnerabilities in Solid Edge, JT2Go and Teamcenter Visualization SSA-307392: Denial of Service in OPC UA in Industrial Products SSA-309571: IPU 2021.1 Vulnerabilities in Siemens Industrial Products using Intel CPUs (June 2021) SSA-312271: Unquoted Search Path Vulnerabilities in Windows-based Industrial Software Applications SSA-348629: Denial-of-Service Vulnerability in SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional and SIMATIC NET PC Software SSB-439005: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP SSA-462066: Vulnerability known as TCP SACK PANIC in Industrial Products SSA-535640: Vulnerability in Industrial Products SSA-539476: Siemens SIMATIC NET CP, SINEMA and SCALANCE Products Affected by Vulnerabilities in Third-Party Component strongSwan SSA-560465: DHCP Client Vulnerability in VxWorks-based Industrial Products SSA-562051: Cross-Site Scripting Vulnerability in Polarion ALM SSA-593272: SegmentSmack in Interniche IP-Stack based Industrial Devices SSA-599968: Denial-of-Service Vulnerability in Profinet Devices * Added solution for SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) and SCALANCE W-1700 (11ac) family SSA-661247: Apache Log4j Vulnerabilities (Log4Shell, CVE-2021-44228, CVE-2021-45046) - Impact to Siemens Products SSA-672373: Vulnerabilities in CP 1543-1 before V2.0.28 SSA-676336: OpenSSH Vulnerabilities in SCALANCE X-200 and X-300/X408 Switches SSA-764417: Multiple Vulnerabilities in RUGGEDCOM Devices SSA-772220: OpenSSL Vulnerabilities in Industrial Products SSA-780073: Denial of Service Vulnerability in PROFINET Devices via DCE-RPC Packets SSA-787292: Denial-of-Service Vulnerability in SIMATIC RFID Readers SSA-840188: Multiple Vulnerabilities in SIMATIC WinCC Affecting Other SIMATIC Software Products SSA-913875: Frame Aggregation and Fragmentation Vulnerabilities in 802.11 SSA-914168: Multiple Vulnerabilities in SIMATIC WinCC Affecting Other SIMATIC Software Products SSA-978220: Denial of Service Vulnerability over SNMP in Multiple Industrial Products SSA-995338: Multiple Vulnerabilities in COMOS Web |
Für diesen Beitrag bedanken sich1 Benutzer |
Folgen Sie uns auf