Latest Siemens vulnerabilities #
Siemens has released security advisories for a variety of products and devices, including the SENTRON, SCALANCE, and RUGGEDCOM product lines.
Several of the vulnerabilities have CVSS scores in the 7.0 to 8.9 range (high) and several more in the 9.0 to 10.0 range (critical).
For a full list of vulnerabilities, please consult Siemens ProductCERT.
What is the impact? #
Several of these vulnerabilities allow for unauthenticated remote code execution, allowing for compromise of the vulnerable systems. Other vulnerabilities may lead to privilege escalation, information disclosure, or denial of service. Users are urged to upgrade as quickly as possible.
Are updates or workarounds available? #
Siemens has released updates via a variety of channels. See Siemens ProductCERT for details.
How do I find potentially vulnerable systems with runZero? #
From the Asset Inventory, use the following query to locate Siemens assets that may be vulnerable:
hardware:Siemens OR hardware:RuggedCom