Siemens Alert
2835Warning Date
Severity Level
Warning Number
Target Sector
10 January, 2023
● High
2023-5415
All
Siemens has released security updates to address multiple vulnerabilities in the following products:
- SIMATIC
- Mendix Workflow Commons
- Mendix SAML
- SINEC INS
- Automation License Manager V5
- Automation License Manager V6
- RUGGEDCOM
- SCALANCE
An attacker could exploit these vulnerabilities and achieve the following:
- Denial of Service (DoS)
- Memory Corruption
- Remote code execution
- Sensitive Information Disclosure
- Buffer Overflow
- Privilege Escalation
- Session Hijack
The CERT team encourages users to update affected products and review Siemens security advisory:
- https://cert-portal.siemens.com/productcert/html/ssa-113131.html
- https://cert-portal.siemens.com/productcert/html/ssa-210822.html
- https://cert-portal.siemens.com/productcert/html/ssa-332410.html
- https://cert-portal.siemens.com/productcert/html/ssa-476715.html
- https://cert-portal.siemens.com/productcert/html/ssa-496604.html
- https://cert-portal.siemens.com/productcert/html/ssa-697140.html
- https://cert-portal.siemens.com/productcert/html/ssa-710008.html