Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Siemens heeft kwetsbaarheden verholpen in diverse producten als Industrial Edge Devices, Mendix, SENTRON, SIDIS, SIMATIC, SIPLUS,Insights Hub Private Cloud, Siemens License Server en Solid Edge.
- Interpretaties
De kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Manipulatie van gegevens
- Omzeilen van een beveiligingsmaatregel
- Omzeilen van authenticatie
- (Remote) code execution (root/admin rechten)
- (Remote) code execution (Gebruikersrechten)
- Toegang tot systeemgegevens
- Toegang tot gevoelige gegevens
- Spoofing
De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.
- Oplossingen
Siemens heeft beveiligingsupdates uitgebracht om de kwetsbaarheden te verhelpen. Voor de kwetsbaarheden waar nog geen updates voor zijn, heeft Siemens mitigerende maatregelen gepubliceerd om de risico's zoveel als mogelijk te beperken. Zie de bijgevoegde referenties voor meer informatie.
Dreigingsinformatie:
- Kans
medium
- Schade
high
- CWE-287
Improper Authentication
- CWE-1240
Use of a Cryptographic Primitive with a Risky Implementation
- CWE-606
Unchecked Input for Loop Condition
- CWE-1395
Dependency on Vulnerable Third-Party Component
- CWE-363
Race Condition Enabling Link Following
- CWE-420
Unprotected Alternate Channel
- CWE-684
Incorrect Provision of Specified Functionality
- CWE-834
Excessive Iteration
- CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
- CWE-440
Expected Behavior Violation
- CWE-754
Improper Check for Unusual or Exceptional Conditions
- CWE-319
Cleartext Transmission of Sensitive Information
- CWE-354
Improper Validation of Integrity Check Value
- CWE-325
Missing Cryptographic Step
- CWE-404
Improper Resource Shutdown or Release
- CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-1333
Inefficient Regular Expression Complexity
- CWE-416
Use After Free
- CWE-476
NULL Pointer Dereference
- CWE-327
Use of a Broken or Risky Cryptographic Algorithm
- CWE-400
Uncontrolled Resource Consumption
- CWE-787
Out-of-bounds Write
- CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
- CWE-122
Heap-based Buffer Overflow
- CWE-20
Improper Input Validation
- CWE-1390
Weak Authentication
- CWE-204
Observable Response Discrepancy
- CWE-15
External Control of System or Configuration Setting
- CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-653
Improper Isolation or Compartmentalization
- CWE-94
Improper Control of Generation of Code ('Code Injection')
- CWE-620
Unverified Password Change
- CWE-798
Use of Hard-coded Credentials
- CWE-269
Improper Privilege Management
- CWE-295
Improper Certificate Validation
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard