13 maja 2025 r. firma Siemens opublikowała ostrzeżenia mające na celu usunięcie luk w zabezpieczeniach wielu produktów. Zawarto aktualizacje dla następujących produktów:

  • Desigo CC – wszystkie wersje
  • INTRALOG WMS – wersje wcześniejsze niż V5
  • OZW672 – wiele modeli i wersji
  • RUGGEDCOM ROX II family – wiele modeli i wersji
  • SCALANCE LPE9403 (6GK5998-3GS00-2AC2) – wszystkie wersje
  • SIMATIC IPC RS-828A – wszystkie wersje
  • SIMATIC PCS neo – wersje V4.1 i V5.0
  • SINEC NMS – wersje wcześniejsze niż V2.15.1.1
  • SINEMA Remote Connect – wersje wcześniejsze niż UMC V2.15.1.1
  • SIRIUS 3RK3 Modular Safety System (MSS) – wszystkie wersje
  • SIRIUS Safety Relays 3SK2 – wszystkie wersje
  • Teamcenter Visualization – wiele modeli i wersji
  • Totally Integrated Automation Portal (TIA Portal) – wersje wcześniejsze niż UMCV2.15.1.1
  • User Management Component (UMC) – wersje wcześniejsze niż do UMC V2.15.1.1
  • Seria VersiCharge AC – wiele modeli i wersji
IDCVSSLink/Descriptions
SSA-9355007.5Denial of Service Vulnerability in FTP Server of Nucleus RTOS based APOGEE, TALON and Desigo PXC/PXM Products AKTUALIZACJA
SSA-9289849.8Heap-based Buffer Overflow Vulnerability in User Management Component (UMC) AKTUALIZACJA
SSA-9015088.7Multiple Vulnerabilities in INTRALOG WMS Before V5
SSA-8767874.7Open Redirect Vulnerability in SIMATIC S7-1500 and S7-1200 CPUs AKTUALIZACJA
SSA-8649003.7Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices
SSA-8322739.8Multiple Vulnerabilities in Fortigate NGFW Before V7.4.3 on RUGGEDCOM APE1808 Devices AKTUALIZACJA
SSA-8281166.5Denial of Service Vulnerability in BACnet ATEC Devices
SSA-8196299.8Weak Authentication Vulnerability in Industrial Edge Device Kit AKTUALIZACJA
SSA-7941859.0RADIUS Protocol Susceptible to Forgery Attacks (CVE-2024-3596) – Impact to SIPROTEC, SICAM and Related Products
SSA-7707709.8Multiple Vulnerabilities in Fortigate NGFW Before V7.4.7 on RUGGEDCOM APE1808 Devices AKTUALIZACJA
SSA-7676157.5Information Disclosure Vulnerability in SIPROTEC 5 Devices AKTUALIZACJA
SSA-7266172.2Incorrect Privilege Assignment Vulnerability in Mendix OIDC SSO Module
SSA-7183934.7Partial Denial of Service Vulnerability in APOGEE PXC and TALON TC Series (BACnet) Devices
SSA-6739968.2Buffer Overflow Vulnerability in Third-Party Component in SICAM and SITIPE Products AKTUALIZACJA
SSA-6681546.5Denial of Service Vulnerability in MS/TP Point Pickup Module
SSA-6147237.5Denial of Service Vulnerabilities in User Management Component (UMC)
SSA-5569378.8Multiple Vulnerabilities in VersiCharge AC Series EV Chargers
SSA-5425407.8Out of Bounds Read Vulnerability in Teamcenter Visualization
SSA-5234187.5Information Disclosure Vulnerability in Desigo CC
SSA-4552509.8Multiple Vulnerabilities in Palo Alto Networks Virtual NGFW on RUGGEDCOM APE1808 Devices Before V11.1.2-h3 AKTUALIZACJA
SSA-44630710Authentication Bypass Vulnerability in BMC (CVE-2024-54085) affects SIMATIC IPC RS-828A
SSA-3735918.1Buffer Overflow Vulnerability in RUGGEDCOM ROS Devices AKTUALIZACJA
SSA-3660679.8Multiple Vulnerabilities in Fortigate NGFW Before V7.4.1 on RUGGEDCOM APE1808 Devices AKTUALIZACJA
SSA-35456910Multiple Vulnerabilities in Palo Alto Networks PAN-OS on RUGGEDCOM APE1808 Devices AKTUALIZACJA
SSA-3390868.8Insufficient Session Expiration Vulnerability in SIMATIC PCS neo
SSA-3274387.8Multiple Vulnerabilities in SCALANCE LPE9403
SSA-3012299.9Client-Side Enforcement of Server-Side Security Vulnerabilities in RUGGEDCOM ROX II
SSA-2227687.5Multiple Vulnerabilities in SIRIUS 3SK2 Safety Relays and 3RK3 Modular Safety Systems
SSA-1622556.5Multiple Vulnerabilities in Polarion Before V2410
SSA-1036538.6Denial-of-Service Vulnerability in Automation License Manager
SSA-0540465.3Unauthenticated Information Disclosure in Web Server of SIMATIC S7-1500 CPUs AKTUALIZACJA
SSA-04742410Code Execution and SQL Injection Vulnerabilities in OZW Web Servers
SSA-0390079.8Heap-based Buffer Overflow Vulnerability in User Management Component (UMC) AKTUALIZACJA