You are here

siemens

Siemens devices using the PROFINET Discovery and Configuration Protocol (Update K) (ICSA-17-129-01I) – Product Used in Energy and Water and Wastewater Systems Sectors

February 14, 2019

The NCCIC has updated this advisory with additional information on affected products and mitigation measures. Read the advisory at NCCIC/ICS-CERT.

February 27, 2018

ICS-CERT has updated this advisory with additional details on affected products and mitigation details. ICS-CERT.

January 23, 2018

Siemens Siveillance VMS Video Mobile App (ICSA-18-128-03)

The NCCIC has released an advisory about a vulnerability in Siemens Siveillance VMS Video Mobile App. For both Siveillance VMS for Android and iOS, all versions prior to V12.1a (2018 R1) are affected. Successful exploitation of this vulnerability may allow an attacker in a privileged network position to read data from and write data to the encrypted communication channel between the app and a server.

Siemens SIMATIC WinCC OA UI Mobile App (ICSA-18-081-01) – Product Used in the Water and Wastewater and Energy Sectors

The NCCIC has released an advisory on a vulnerability in Siemens SIMATIC WinCC OA UI Mobile App. For both Android and Apple users, all versions prior to V3.15.10 are affected. This vulnerability could be exploited by an attacker who tricks an app user to connect to a malicious WinCC OA server. Successful exploitation of this vulnerability could allow an attacker to read and write data from and to the app’s project cache folder. Siemens has provided updates to mitigate this vulnerability.

Pages

Subscribe to siemens