SIEMENS CERT
        09/10/2019
      
          The latest update for SIMATIC WinCC fixes multiple vulnerabilities. The most severe could allow an attacker to execute arbitrary commands on an affected system under certain conditions. Siemens has released updates for several affected products, and recommends that customers update to the new version. Siemens is preparing further updates and …
        
      
    SIEMENS CERT
        09/10/2019
      
          The latest update for SINEMA Remote Connect Server fixes four vulnearbilities in the web interface. Two of the vulnerabilities are missing protection mechanisms for password guessing and for Cross Site Request Forgery attacks, the third one is a missing authentication check, and the fourth one could allow an attacker with …
        
      
    SIEMENS CERT
        09/10/2019
      
          A vulnerability has been identified in SINETPLAN that could allow local users to execute arbitrary application commands without proper authentication. Siemens provides a solution that fixes the vulnerability and recommends that users apply the update.
        
      
    SIEMENS CERT
        09/10/2019
      
          The latest update for SIMATIC WinCC fixes a vulnerability in the SIMATIC WinCC DataMonitor web application of the affected products that allows to upload arbitrary ASPX code. An attacker has to be authenticated with a valid user account. The vulnerability is only relevant for scenarios where access via the web …
        
      
    SIEMENS CERT
        09/10/2019
      
          Microsoft has released updates for several versions of Microsoft Windows, which fix vulnerabilities in the Remote Desktop Service that are discussed under the name DejaBlue. The vulnerabilities could allow an unauthenticated remote attacker to execute arbitrary code on the target system if the system exposes the service to the network. …
        
      
    SIEMENS CERT
        09/10/2019
      
          RUGGEDCOM Win is affected by multiple security vulnerabilities. These vulnerabilities could allow an attacker to leverage various attacks, e.g. to execute arbitrary code over the network. The vulnerabilities affect the underlying Wind River VxWorks network stack and were recently patched by Wind River. Siemens is working on updates for the …
        
      
    SIEMENS CERT
        09/10/2019
      
          The Siemens IE/WSN-PA Link WirelessHART Gateway is affected by a Cross-Site Scripting vulnerability. Siemens recommends specific countermeasures.
        
      
    SIEMENS CERT
        09/10/2019
      
          A vulnerability could allow an attacker to cause a Denial-of-Service condition on the UDP communication by sending a specially crafted UDP packet to the SIMATIC TDC CP51M1 module. Siemens has released an update for SIMATIC TDC CP51M1 module and recommends that customers update to the new version.