Firma Siemens informuje o nowych podatnościach w swoich produktach oraz aktualizuje starsze biuletyny (P25-273)

cert.pse-online.pl 1 tydzień temu

14 sierpnia 2025 r. firma Siemens opublikowała ostrzeżenia dotyczące luk w zabezpieczeniach wielu produktów. Aktualizacje dotyczyły następujących produktów:

  • Mendix SAML (zgodny z Mendix 9.24) – wersje starsze niż V3.6.21
  • Mendix SAML (zgodny z Mendix 10.12) – wersje starsze niż V4.0.3
  • Mendix SAML (zgodny z Mendix 10.21) – wersje starsze niż V4.1.2
  • Rodzina Desigo CC – wszystkie wersje
  • SENTRON Powermanager – wszystkie wersje
IDCVSSTytuł
SSA-2015958.2Privilege Escalation Vulnerability in WIBU CodeMeter Runtime Affecting the Desigo CC Product Family and SENTRON Powermanager AKTUALIZACJA
SSA-7113097.5Denial of Service Vulnerability in the OPC UA Implementations of SIMATIC Products AKTUALIZACJA
SSA-3954588.7Account Hijacking Vulnerability in Mendix SAML Module
SSA-0287239.8Multiple OpenSSL Vulnerabilities in BFCClient Before V2.17 AKTUALIZACJA
SSA-9940878.3Multiple SQLite Vulnerabilities in RUGGEDCOM CROSSBOW Station Access Controller Before V5.7
SSA-9781777.2Vulnerability in Nozomi Guardian/CMC on RUGGEDCOM APE1808 Devices
SSA-9148925.3Race Condition Vulnerability in Basic Authentication Implementation of Mendix Runtime AKTUALIZACJA
SSA-9081859.1Mirror Port Isolation Vulnerability in RUGGEDCOM ROS Devices AKTUALIZACJA
SSA-8940582.4Improper Bandwidth Limitation of Network Packets Over Local USB Port Vulnerability in SIPROTEC 5
SSA-8649006.7Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices AKTUALIZACJA
SSA-8567218.8Vulnerability in RUGGEDCOM Discovery Protocol (RCDP) of Industrial Communication Devices AKTUALIZACJA
SSA-8408008.0Code Injection Vulnerability in RUGGEDCOM ROS AKTUALIZACJA
SSA-8001267.8Deserialization Vulnerability in Siemens Engineering Platforms before V20 AKTUALIZACJA
SSA-7941859.0RADIUS Protocol Susceptible to Forgery Attacks (CVE-2024-3596) – Impact to SIPROTEC, SICAM and Related Products AKTUALIZACJA
SSA-7879415.3Denial of Service Vulnerability in RUGGEDCOM ROS devices AKTUALIZACJA
SSA-7709027.5Denial of Service Vulnerability in the Web Server of RUGGEDCOM ROS Devices AKTUALIZACJA
SSA-7707709.8Multiple Vulnerabilities in Fortigate NGFW Before V7.4.7 on RUGGEDCOM APE1808 Devices AKTUALIZACJA
SSA-7697918.2Local Arbitrary Code Execution Vulnerability in COMOS Before V10.6
SSA-7676157.5Information Disclosure Vulnerability in SIPROTEC 5 Devices AKTUALIZACJA
SSA-7644176.7Weak Encryption Vulnerability in RUGGEDCOM ROS Devices AKTUALIZACJA
SSA-7076306.3Multiple Vulnerabilities in SIMATIC RTLS Locating Manager Before V3.3
SSA-6938088.2Deserialization Vulnerability in Siemens Engineering Platforms
SSA-6879556.8Accessible Development Shell via Physical Interface in SIPROTEC 5 AKTUALIZACJA
SSA-6740847.8File Parsing Vulnerabilities in Simcenter Femap Before V2506
SSA-6651084.1Arbitrary File Upload Vulnerability in RUGGEDCOM ROX II
SSA-6131169.1Multiple Vulnerabilities in Third-Party Components in SINEC OS before V3.1
SSA-5292916.2Information Disclosure Vulnerabilities in SICAM Q100/Q200
SSA-5173387.8Multiple Vulnerabilities in SINEC Traffic Analyzer Before V3.0
SSA-4937879.1Arbitrary Code Execution Vulnerability in SIMATIC RTLS Locating Manager Before V3.2
SSA-4933967.8Deserialization Vulnerability in Siemens Engineering Platforms
SSA-4604664.3Denial of Service Vulnerability in TIA Project-Server and TIA Portal AKTUALIZACJA
SSA-44630710Authentication Bypass Vulnerability in BMC (CVE-2024-54085) affects SIMATIC IPC RS-828A AKTUALIZACJA
SSA-4000897.5Denial of Service Vulnerability in SIPROTEC 4 and SIPROTEC 4 Compact
SSA-3983309.8Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP >= V3.1.0 and < V3.1.5 AKTUALIZACJA
SSA-3928597.3Local Arbitrary Code Execution Vulnerability in Siemens Engineering Platforms before V20 AKTUALIZACJA
SSA-3829997.1Multiple Vulnerabilities in Opcenter Quality Before V2506
SSA-3555579.1Multiple Vulnerabilities in Third-Party Components in SINEC OS before V3.2
SSA-3530024.9Multiple Vulnerabilities in SCALANCE XB-200 / XC-200 / XP-200 / XF-200BA / XR-300WG Family AKTUALIZACJA
SSA-3317398.2Privilege Escalation Vulnerability in WIBU CodeMeter Runtime Affecting Siemens Products
SSA-2820447.8DLL Hijacking Vulnerability in Siemens Web Installer used by the Online Software Delivery
SSA-2656889.1Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP V1.1 AKTUALIZACJA
SSA-2563539.6Third-Party Component Vulnerabilities in RUGGEDCOM ROS AKTUALIZACJA
SSA-1862935.5XML External Entity (XXE) Injection Vulnerability in SIMOTION SCOUT, SIMOTION SCOUT TIA and SINAMICS STARTER
SSA-1778478.3Improper VNC Password Check Vulnerability in SINUMERIK Controllers
SSA-1703758.8Multiple Vulnerabilities in RUGGEDCOM ROS Before V5.9 AKTUALIZACJA
SSA-0974355.3Usernames Disclosure Vulnerability in Mendix Runtime AKTUALIZACJA
SSA-0949547.6Authentication Bypass Vulnerability in BIST mode of RUGGEDCOM ROX II
SSA-0825569.8Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5 AKTUALIZACJA
Idź do oryginalnego materiału