Siemens Alert
3019Warning Date
Severity Level
Warning Number
Target Sector
13 December, 2022
● Critical
2022-5389
All
Siemens has released security updates to address multiple vulnerabilities in the following products:
- SCALANCE
- JT2Go
- Teamcenter Visualization
- SIMATIC
- SIPLUS
- TIM 1531 IRC
- Calibre ICE
- Mcenter
- SICAM
- RUGGEDCOM
- Parasolid
- Simcenter
- APOGEE
- TALON TC Series
- Mendix Workflow Commons
- Mendix Email Connector
- SIPROTEC
An attacker could exploit these vulnerabilities and achieve the following:
- Denial of Service (DoS)
- Memory Corruption
- Execute arbitrary code remotely
- Sensitive Information Disclosure
- Session Hijack
- Buffer Overflow
- Privilege Escalation
The CERT team encourages users to update affected products and review Siemens security advisory:
- https://cert-portal.siemens.com/productcert/html/ssa-333517.html
- https://cert-portal.siemens.com/productcert/html/ssa-360681.html
- https://cert-portal.siemens.com/productcert/html/ssa-363821.html
- https://cert-portal.siemens.com/productcert/html/ssa-382653.html
- https://cert-portal.siemens.com/productcert/html/ssa-408105.html
- https://cert-portal.siemens.com/productcert/html/ssa-412672.html
- https://cert-portal.siemens.com/productcert/html/ssa-413565.html
- https://cert-portal.siemens.com/productcert/html/ssa-588101.html
- https://cert-portal.siemens.com/productcert/html/ssa-700053.html
- https://cert-portal.siemens.com/productcert/html/ssa-849072.html
- https://cert-portal.siemens.com/productcert/html/ssa-930100.html
- https://cert-portal.siemens.com/productcert/html/ssa-180579.html
- https://cert-portal.siemens.com/productcert/html/ssa-210822.html
- https://cert-portal.siemens.com/productcert/html/ssa-223771.html
- https://cert-portal.siemens.com/productcert/html/ssa-224632.html