Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2025-0077

Published Mar 11, 2025·Last modified Mar 11, 2025
Description
Feiten

Siemens heeft kwetsbaarheden verholpen in diverse producten als SCALANCE, SIMATIC, SINAMICS, SINEMA, SiPass, Teamcenter en Tecnomatix.

Interpretaties

De kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:

  • Denial-of-Service (DoS)
  • Manipulatie van gegevens
  • Omzeilen van een beveiligingsmaatregel
  • Omzeilen van authenticatie
  • (Remote) code execution (root/admin rechten)
  • (Remote) code execution (Gebruikersrechten)
  • Toegang tot systeemgegevens
  • Toegang tot gevoelige gegevens
  • Spoofing

De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.

Oplossingen

Siemens heeft beveiligingsupdates uitgebracht om de kwetsbaarheden te verhelpen. Voor de kwetsbaarheden waar nog geen updates voor zijn, heeft Siemens mitigerende maatregelen gepubliceerd om de risico's zoveel als mogelijk te beperken. Zie de bijgevoegde referenties voor meer informatie.

Dreigingsinformatie:

Kans

medium

Schade

high

CWE-187

Partial String Comparison

CWE-283

Unverified Ownership

CWE-273

Improper Check for Dropped Privileges

CWE-1287

Improper Validation of Specified Type of Input

CWE-130

Improper Handling of Length Parameter Inconsistency

CWE-772

Missing Release of Resource after Effective Lifetime

CWE-208

Observable Timing Discrepancy

CWE-923

Improper Restriction of Communication Channel to Intended Endpoints

CWE-824

Access of Uninitialized Pointer

CWE-305

Authentication Bypass by Primary Weakness

CWE-117

Improper Output Neutralization for Logs

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-190

Integer Overflow or Wraparound

CWE-693

Protection Mechanism Failure

CWE-552

Files or Directories Accessible to External Parties

CWE-290

Authentication Bypass by Spoofing

CWE-639

Authorization Bypass Through User-Controlled Key

CWE-125

Out-of-bounds Read

CWE-306

Missing Authentication for Critical Function

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-416

Use After Free

CWE-476

NULL Pointer Dereference

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-787

Out-of-bounds Write

CWE-121

Stack-based Buffer Overflow

CWE-20

Improper Input Validation

CWE-287

Improper Authentication

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard