<feed xmlns="http://www.w3.org/2005/Atom">
  <id>https://cert-portal.siemens.com/productcert/rss/alerts.atom</id>
  <title>Siemens ProductCERT Security Alerts and News</title>
  <updated>2021-11-14T23:00:00+00:00</updated>
  <author>
    <name>Siemens ProductCERT</name>
    <email>productcert@siemens.com</email>
  </author>
  <link href="https://cert-portal.siemens.com/productcert/rss/alerts.atom" rel="self"/>
  <generator>Siemens ProductCERT</generator>
  <subtitle>Siemens Security Alerts and News</subtitle>
  <entry>
  <id>https://www.siemens.com/cert#Newsroom-11</id>
  <title>Vulnerabilities in the Apache Log4j (\"Log4Shell\")</title>
  <updated>2021-12-14T23:00:00+00:00</updated>
  <link href="https://www.siemens.com/cert#Newsroom" rel="alternate"/>
  <summary type="html">Siemens is aware of the security vulnerabilities in Apache Log4j (CVE-2021-44228 and CVE-2021-45046), also named \"Log4Shell\".&lt;br/&gt;For Siemens products, a security advisory (SSA-661247) was issued on 2021-12-13 and will be updated in the following days as more information becomes available.</summary>
  </entry>
  <entry>
    <id>https://www.siemens.com/cert#Newsroom-10</id>
    <title>Vulnerabilities in the Nucleus TCP/IP Stack (\"NUCLEUS:13\")</title>
    <updated>2021-11-09T12:00:00+00:00</updated>
    <link href="https://www.siemens.com/cert#Newsroom" rel="alternate"/>
    <summary type="html">Today, in coordination with Forescout, CISA and other contributors, Siemens has disclosed the security vulnerabilities CVE-2021-31344 through CVE-2021-31346 and CVE-2021-31881 through CVE-2021-31890, also named \"NUCLEUS:13\".&lt;br/&gt;The impact and remediations of these vulnerabilities in Nucleus RTOS (a real-time operating system provided by Siemens EDA, formerly Mentor Graphics) is described in the following Security Advisory:&lt;br/&gt; - &lt;a href=&apos;https://cert-portal.siemens.com/productcert/pdf/ssa-044112.pdf&apos; target=&apos;_blank&apos;&gt;SSA-044112: Multiple Vulnerabilities (NUCLEUS:13) in the TCP/IP Stack of Nucleus RTOS&lt;/a&gt;"</summary>
  </entry>
  <entry>
    <id>https://www.siemens.com/cert#Newsroom-9</id>
    <title>Vulnerabilities in Interniche TCP/IP Stack (\"INFRA:HALT\")</title>
    <updated>2021-08-04T18:00:00+00:00</updated>
    <link href="https://www.siemens.com/cert#Newsroom" rel="alternate"/>
    <summary type="html">Siemens is aware of the security vulnerabilities named INFRA:HALT. The impact to Siemens products is described in the following Security Advisory:&lt;br/&gt; - &lt;a href=&apos;https://cert-portal.siemens.com/productcert/pdf/ssa-789208.pdf&apos; target=&apos;_blank&apos;&gt;SSA-789208: Multiple Vulnerabilities (INFRA:HALT) in Interniche IP-Stack based Low Voltage Devices&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Please note that SIMATIC S7 PLCs are not affected by these vulnerabilities.</summary>
  </entry>
  <entry>
    <id>https://www.siemens.com/cert#Newsroom-8</id>
    <title>New Vulnerabilities in Treck TCP/IP Stack</title>
    <updated>2020-12-23T15:00:00+00:00</updated>
    <link href="https://www.siemens.com/cert#Newsroom" rel="alternate"/>
    <summary type="html">Siemens is aware of the new security vulnerabilities in the Treck TCP/IP stack, disclosed on 2020-12-08 on &lt;a href=&apos;https://treck.com/vulnerability-response-information/&apos; target=&apos;_blank&apos;&gt;Treck, Inc.&apos;s advisory page&lt;/a&gt;.&lt;br/&gt;No Siemens product is known to use Treck Inc.&apos;s TCP/IP stack, or otherwise be affected by the reported vulnerabilities.&lt;br/&gt;Note that Siemens products and systems might interact with products from other manufacturers which are affected by the reported vulnerabilities. In such cases Siemens recommends that owners of operational infrastructures verify if these products are affected and evaluate the potential impact of the Ripple20 vulnerabilities. Siemens ProductCERT may release additional information via specific Security Advisories.</summary>
  </entry>
  <entry>
    <id>https://www.siemens.com/cert#Newsroom-7</id>
    <title>AMNESIA:33 Vulnerabilities</title>
    <updated>2020-12-09T11:30:00+00:00</updated>
    <link href="https://www.siemens.com/cert#Newsroom" rel="alternate"/>
    <summary type="html">Siemens is aware of the security vulnerabilities in several TCP/IP stacks, also named and &lt;a href=&apos;https://www.forescout.com/research-labs/amnesia33/&apos; target=&apos;_blank&apos;&gt;disclosed on &lt;/a&gt;. The impact to Siemens products is described in the &lt;a href=&apos;https://cert-portal.siemens.com/productcert/pdf/ssa-541017.pdf&apos; target=&apos;_blank&apos;&gt;Security Advisory SSA541017&lt;/a&gt;, published on on the same day.&lt;br/&gt;Note that Siemens products and systems might interact with products from other manufacturers which are affected by the reported vulnerabilities. In such cases Siemens recommends that owners of operational infrastructures verify if these products are affected and evaluate the potential impact of the vulnerabilities.</summary>
  </entry>
  <entry>
    <id>https://www.siemens.com/cert#Newsroom-6</id>
    <title>Ripple20 Vulnerabilities</title>
    <updated>2020-07-09T18:30:00+00:00</updated>
    <link href="https://www.siemens.com/cert#Newsroom" rel="alternate"/>
    <summary type="html">Siemens is aware of the recently disclosed &lt;a href=&apos;https://www.jsof-tech.com/ripple20/&apos; target=&apos;_blank&apos;&gt;set of security vulnerabilities in Treck, Inc.&apos;s TCP/IP stack&lt;/a&gt;, known as Ripple20, disclosed by the JSOF research lab. Siemens experts had conducted an internal investigation to assess impact on Siemens products. No Siemens product is known to use Treck Inc.&apos;s TCP/IP stack, or otherwise be affected by the reported vulnerabilities.&lt;br/&gt;Note that Siemens products and systems might interact with products from other manufacturers which are affected by the reported vulnerabilities. In such cases Siemens recommends that owners of operational infrastructures verify if these products are affected and evaluate the potential impact of the Ripple20 vulnerabilities.</summary>
  </entry>
  <entry>
    <id>https://www.siemens.com/cert#Newsroom-5</id>
    <title>Operational Guidelines for Industrial Security</title>
    <updated>2020-03-18T00:00:00+00:00</updated>
    <link href="https://www.siemens.com/cert#Newsroom" rel="alternate"/>
    <summary type="html">Siemens has released an updated version 2.1 of the &lt;a href=&apos;https://www.siemens.com/cert/operational-guidelines-industrial-security&apos; target=&apos;_blank&apos;&gt;Operational Guidelines for Industrial Security&lt;/a&gt;.&lt;br/&gt;The guidelines provide recommendations for the secure operation of plant and machinery in industrial environments, including a &apos;Defense-in-Depth&apos; security concept.&lt;br/&gt;Version 2.1 replaces all former versions of the guidelines and is referenced in Siemens Security Advisories related with Siemens Industrial Products.</summary>
  </entry>
  <entry>
    <id>https://www.siemens.com/cert#Newsroom-4</id>
    <title>SIPLUS products - Advisories</title>
    <updated>2019-12-16T00:00:00+00:00</updated>
    <link href="https://www.siemens.com/cert#Newsroom" rel="alternate"/>
    <summary type="html">SIPLUS products are rebranded standard products offering improved resistance to mechanical loads, chemical and biological substances, condensation, and temperature fluctuations. They are also designed to cope with temperatures between -40° and +70° Celsius. These devices share the same firmware than the &lt;a href=&apos;https://new.siemens.com/global/en/products/automation/products-for-specific-requirements/siplus-extreme/conversion-tool.html&apos; target=&apos;_blank&apos;&gt;products they are based on&lt;/a&gt;.&lt;br/&gt;Although these devices were already implicitly mentioned in our existing advisories we were made aware that if not explicitly mentioned it could leave these devices out-of-scope. Therefore, starting with Advisory Day December 2019, Siemens will explicitly mention this product family and in the future also update old Siemens advisories.</summary>
  </entry>
  <entry>
    <id>https://www.siemens.com/cert#Newsroom-3</id>
    <title>Cyber Security topics @ Siemens Healthineers</title>
    <updated>2019-10-15T00:00:00+00:00</updated>
    <link href="https://www.siemens.com/cert#Newsroom" rel="alternate"/>
    <summary type="html">Starting by October 15 all topics related to the Siemens Healthineers Cyber Security (including security advisories) will be published at the Siemens Healthineers Cyber Security &lt;a href=&apos;https://www.siemens-healthineers.com/support-documentation/cybersecurity/index.html#Security_publications&apos; target=&apos;_blank&apos;&gt;webpage&lt;/a&gt;.&lt;br/&gt;&lt;br/&gt;Should you have further questions regarding this announcement, please use the contact form at the Siemens Healthineers Cyber Security &lt;a href=&apos;https://www.siemens-healthineers.com/how-can-we-help-you/index.html&apos; target=&apos;_blank&apos;&gt;webpage&lt;/a&gt;.</summary>
  </entry>
  <entry>
    <id>https://www.siemens.com/cert#Newsroom-2</id>
    <title>Microsoft DejaBlue Vulnerability in Siemens Industrial Products</title>
    <updated>2019-08-21T00:00:00+00:00</updated>
    <link href="https://www.siemens.com/cert#Newsroom" rel="alternate"/>
    <summary type="html">Siemens is aware of the reports about the vulnerabilities reported by Microsoft on August 13th, known as DejaBlue or CVE-2019-1181/1182. Microsoft released updates for several supported Windows operating systems on 2019-08-13, which fix a vulnerability in the Remote Desktop Service. The vulnerability could allow an unauthenticated remote attacker to execute arbitrary code on the target system if the system exposes the service to the network.&lt;br/&gt;&lt;br/&gt;A number of Siemens Industrial products can be installed on Microsoft Windows. Siemens recommends that customers of these products test the compatibility of the patches in their environment and apply the patches if found to be compatible. Information on patch compatibility for Microsoft Windows patches for SIMATIC PCS 7 is published in &lt;a href=&quot;https://support.industry.siemens.com/cs/ww/en/view/18490004&quot;&gt;this FAQ entry&lt;/a&gt;.&lt;br/&gt;&lt;br/&gt;Further information on this vulnerability can be found at:&lt;br/&gt;&lt;br/&gt;&lt;a href=&quot;https://msrc-blog.microsoft.com/2019/08/13/patch-new-wormable-vulnerabilities-in-remote-desktop-services-cve-2019-1181-1182/&quot;&gt;https://msrc-blog.microsoft.com/2019/08/13/patch-new-wormable-vulnerabilities-in-remote-desktop-services-cve-2019-1181-1182/&lt;/a&gt;</summary>
  </entry>
  <entry>
    <id>https://www.siemens.com/cert#Newsroom-1</id>
    <title>DejaBlue Vulnerabilities - Siemens Healthineers Products</title>
    <updated>2019-09-10T00:00:00+00:00</updated>
    <link href="https://www.siemens.com/cert#Newsroom" rel="alternate"/>
    <summary type="html">Siemens Healthineers is aware of the reports about the vulnerabilities reported by Microsoft on August 13th, known as DejaBlue or CVE-2019-1181/1182. Microsoft released updates for Windows 7 SP1, Windows Server 2008 R2 SP1, Windows Server 2012, Windows 8.1, Windows Server 2012 R2, and all supported versions of Windows 10, including server versions on 2019-08-13, which fix a vulnerability in the Remote Desktop Service. The vulnerability could allow an unauthenticated remote attacker to execute arbitrary code on the target system if the system exposes the service to the network.&lt;br/&gt;&lt;br/&gt;All Siemens Healthineers products from all business lines have been evaluated. Most Siemens Healthineers products are not affected by the vulnerabilities because they do not provide the option to activate the Remote Desktop Service, implement other controls that mitigate the vulnerabilities, use a version of Microsoft Windows that is not affected, or are not based on Microsoft Windows. This advisory (&lt;a href=&apos;https://cert-portal.siemens.com/productcert/pdf/ssa-187667.pdf&apos;&gt;https://cert-portal.siemens.com/productcert/pdf/ssa-187667.pdf&lt;/a&gt;) provides a full list of affected products from Siemens Healthineers and provides recommendations to mitigate the vulnerabilities.</summary>
  </entry>
 </feed>
