Tuesday, July 13, 2021

Review - 17 Advisories Published – 7-13-21

SINUMERIK Advisory - This advisory describes an improper restriction of operations within the bounds of a memory buffer vulnerability in the Siemens SINUMERIK ONE and SINUMERIK MC CNC products.

Mendix Advisory - This advisory describes an incorrect authorization vulnerability in the Siemens Mendix Application.

JT2Go Advisory - This advisory describes 43 vulnerabilities in the Siemens JT2Go and Teamcenter Visualization.

RWG Advisory - This advisory describes an allocation of resources without limit or throttling vulnerability in the Siemens RWG Universal Controllers.

SINAMICS Advisory - This advisory describes an improper restriction of operation within the bounds of a memory buffer vulnerability in the Siemens SINAMICS PERFECT HARMONY GH180 product.

Industrial Products Advisory #1 - This advisory describes a heap-based buffer overflow vulnerability in the Wind River VxWorks-based Industrial Products.

Industrial Products Advisory #1 - This advisory describes a heap-based buffer overflow vulnerability in the Wind River VxWorks-based Industrial Products.

Teamcenter Advisory - This advisory describes three vulnerabilities in the Siemens Teamcenter Active Workspace product.

RUGGEDCOM Advisory - This advisory describes a classic buffer overflow vulnerability in the Siemens RUGGEDCOM ROS.

Solid Edge Advisory - This advisory describes four heap-based buffer overflow vulnerabilities in the Siemens Solid Edge, portfolio of software tools.

Industrial Products Advisory #2 - This advisory describes two vulnerabilities in the Siemens Industrial Products.

SIMATIC Advisory #1 - This advisory describes an incorrect permission assignment vulnerability to the Siemens SIMATIC Software Products.

SIMATIC Advisory #2 - This advisory describes a classic buffer overflow vulnerability in the Siemens SIMATIC Software Products.

SINUMERIK Advisory - This advisory describes an improper certificate validation vulnerability in the SINUMERIK Integrate Operate Client.

PROFINET Advisory - This advisory describes an allocation of resources without limit or throttling in the Siemens PROFINET Devices.

SCADApack Advisory -This advisory describes six vulnerabilities in the Schneider EcoStruxure Control Expert, EcoStruxure Process Expert, SCADAPack RemoteConnect x70, SCADAPack x70 RTUs, and Modicon M580 and M340 control products.

For a more detailed look at these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/17-advisories-published - subscription required.

No comments:

 
/* Use this with templates/template-twocol.html */