You are here

Cybersecurity

Siemens SIPROTEC 4 and SIPROTEC Compact (ICSA-20-042-12)

CISA has published an advisory on an improper input validation vulnerability in SIPROTEC 4 and SIPROTEC Compact. All versions of both products are affected. This vulnerability could allow an attacker to conduct a denial-of-service attack over the network. Siemens has identified specific workarounds and mitigations users can apply to reduce the risk. CISA also recommends a series of measures to mitigate the vulnerability. Read the advisory at CISA.

Siemens SIMATIC S7-1500 (ICSA-20-042-11)

CISA has published an advisory on a resource exhaustion vulnerability in Siemens SIMATIC S7-1500 CPU family. Multiple products and versions of these products are affected. This vulnerability could allow a remote attacker to conduct denial-of-service attacks. Siemens has released updates for several affected products, is working on updates for the remaining affected products, and recommends specific countermeasures until fixes are available. CISA also recommends a series of measures to mitigate the vulnerabilities.

Siemens OZW Web Server (ICSA-20-042-09)

CISA has published an advisory on an information disclosure vulnerability in Siemens OZW web server. All versions prior to 10.0 are affected. Successful exploitation of this vulnerability could allow unauthenticated users to access project files. Siemens recommends users update OZW672 and OZW77 to version 10.0 and has identified specific workarounds and mitigations users can apply to reduce the risk. CISA also recommends a series of measures to mitigate the vulnerability.

Siemens SIPORT MP (ICSA-20-042-08)

CISA has published an advisory on an insufficient logging vulnerability in Siemens SIPORT MP. All versions prior to 3.1.4 are affected. Successful exploitation of this vulnerability could allow the attacker to create special accounts with administrative privileges. Siemens recommends users update to Version 3.1.4 and has identified specific workarounds and mitigations users can apply to reduce the risk. CISA also recommends a series of measures to mitigate the vulnerability.

Siemens SCALANCE X Switches (ICSA-20-042-07)

CISA has published an advisory on a protection mechanism failure vulnerability in Siemens SCALANCE X switches. Multiple products and versions of these products are affected. Successful exploitation of this vulnerability could allow an attacker to perform administrative actions. Siemens has released updates, which are recommended to be applied when possible. CISA also recommends a series of measures to mitigate the vulnerability. Read the advisory at CISA.

Siemens SIMATIC CP 1543-1 (ICSA-20-042-03) – Products Used in the Water and Wastewater and Energy Sectors

CISA has published an advisory on improper access control and loop with unreachable exit condition vulnerabilities in Siemens SIMATIC CP-1543-1. All versions starting at 2.0 and prior to 2.2. are affected. Successful exploitation of these vulnerabilities could allow remote attackers to conduct a denial-of-service attack by sending specially crafted packets to Port 161/UDP (SNMP). The latest update for SIMATIC CP 1543-1 contains fixes for the vulnerabilities within its embedded ProFTPD FPT server. Siemens recommends updating SIMATIC CP 1543-1 modules to Version 2.2.

Microsoft Releases February 2020 Security Updates

Microsoft has released its monthly update to address vulnerabilities in its software. For this month, Microsoft has released security updates for Microsoft Windows, Microsoft Edge (EdgeHTML and Chromium-based), ChakraCore, Internet Explorer, Microsoft Exchange Server, Microsoft SQL Server, Microsoft Office and Microsoft Office Services and Web Apps, Windows Malicious Software Removal Tool, and Windows Surface Hub. Read the update at Microsoft.

Safer Internet Day – Everyone Has a Responsibility to Make a Positive Difference

Today is Safer Internet Day, a worldwide event aimed at promoting the safe and positive use of digital technology for all users. This year’s theme is “Together for a better internet,” which encourages everyone to play a part in creating a safer, more secure internet. While much of the focus of this year’s theme is on children and caregivers, its promoters make clear that is intended for everyone, including for people in industry and decision makers.

Pages

Subscribe to Cybersecurity