You are here

Siemens Desigo PX Devices (ICSA-19-318-03) – Products Used in the Water and Wastewater and Energy Sectors

Siemens Desigo PX Devices (ICSA-19-318-03) – Products Used in the Water and Wastewater and Energy Sectors

Created: Monday, November 18, 2019 - 17:35
Categories:
Cybersecurity

CISA has published an advisory on an external control of assumed-immutable web parameter vulnerability in Siemens Desigo PX Devices. Numerous products and versions of the products are affected. Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition on the device’s web server, requiring a reboot to recover the web interface. Siemens has an update available for some of the affected products and has identified specific workarounds and mitigations that users can apply to reduce risk for the others. CISA also recommends a series of measures to mitigate the vulnerability. Read the advisory at WaterISAC.