Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2025-0051

Published Feb 11, 2025·Last modified Feb 11, 2025
Description
Feiten

Siemens heeft kwetsbaarheden verholpen in diverse producten als APOGEE, Opcenter, RUGGEDCOM, SCALANCE, SIMATIC, SIPROTEC en Teamcenter.

Interpretaties

De kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:

  • Denial-of-Service (DoS)
  • Cross-Site-Scripting (XSS)
  • Cross-Site Request Forgery (CSRF)
  • Manipulatie van gegevens
  • Omzeilen van een beveiligingsmaatregel
  • Omzeilen van authenticatie
  • (Remote) code execution (root/admin rechten)
  • (Remote) code execution (Gebruikersrechten)
  • Toegang tot systeemgegevens
  • Toegang tot gevoelige gegevens

De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.

Oplossingen

Siemens heeft beveiligingsupdates uitgebracht om de kwetsbaarheden te verhelpen. Voor de kwetsbaarheden waar nog geen updates voor zijn, heeft Siemens mitigerende maatregelen gepubliceerd om de risico's zoveel als mogelijk te beperken. Zie de bijgevoegde referenties voor meer informatie.

Kans

medium

Schade

high

CWE-489

Active Debug Code

CWE-1240

Use of a Cryptographic Primitive with a Risky Implementation

CWE-606

Unchecked Input for Loop Condition

CWE-170

Improper Null Termination

CWE-1395

Dependency on Vulnerable Third-Party Component

CWE-183

Permissive List of Allowed Inputs

CWE-1325

Improperly Controlled Sequential Memory Allocation

CWE-385

Covert Timing Channel

CWE-1392

Use of Default Credentials

CWE-222

Truncation of Security-relevant Information

CWE-310

CWE-310

CWE-328

Use of Weak Hash

CWE-304

Missing Critical Step in Authentication

CWE-684

Incorrect Provision of Specified Functionality

CWE-208

Observable Timing Discrepancy

CWE-326

Inadequate Encryption Strength

CWE-923

Improper Restriction of Communication Channel to Intended Endpoints

CWE-201

Insertion of Sensitive Information Into Sent Data

CWE-347

Improper Verification of Cryptographic Signature

CWE-834

Excessive Iteration

CWE-732

Incorrect Permission Assignment for Critical Resource

CWE-425

Direct Request ('Forced Browsing')

CWE-440

Expected Behavior Violation

CWE-704

Incorrect Type Conversion or Cast

CWE-415

Double Free

CWE-1286

Improper Validation of Syntactic Correctness of Input

CWE-754

Improper Check for Unusual or Exceptional Conditions

CWE-427

Uncontrolled Search Path Element

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

CWE-610

Externally Controlled Reference to a Resource in Another Sphere

CWE-613

Insufficient Session Expiration

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

CWE-312

Cleartext Storage of Sensitive Information

CWE-369

Divide By Zero

CWE-252

Unchecked Return Value

CWE-203

Observable Discrepancy

CWE-354

Improper Validation of Integrity Check Value

CWE-325

Missing Cryptographic Step

CWE-190

Integer Overflow or Wraparound

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CWE-125

Out-of-bounds Read

CWE-404

Improper Resource Shutdown or Release

CWE-284

Improper Access Control

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-1333

Inefficient Regular Expression Complexity

CWE-416

Use After Free

CWE-113

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

CWE-401

Missing Release of Memory after Effective Lifetime

CWE-476

NULL Pointer Dereference

CWE-295

Improper Certificate Validation

CWE-757

Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')

CWE-327

Use of a Broken or Risky Cryptographic Algorithm

CWE-436

Interpretation Conflict

CWE-400

Uncontrolled Resource Consumption

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard