Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2025-0106

Published Apr 8, 2025·Last modified Apr 8, 2025
Description
Feiten

Siemens heeft kwetsbaarheden verholpen in diverse producten als Industrial Edge Devices, Mendix, SENTRON, SIDIS, SIMATIC, SIPLUS,Insights Hub Private Cloud, Siemens License Server en Solid Edge.

Interpretaties

De kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:

  • Denial-of-Service (DoS)
  • Manipulatie van gegevens
  • Omzeilen van een beveiligingsmaatregel
  • Omzeilen van authenticatie
  • (Remote) code execution (root/admin rechten)
  • (Remote) code execution (Gebruikersrechten)
  • Toegang tot systeemgegevens
  • Toegang tot gevoelige gegevens
  • Spoofing

De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.

Oplossingen

Siemens heeft beveiligingsupdates uitgebracht om de kwetsbaarheden te verhelpen. Voor de kwetsbaarheden waar nog geen updates voor zijn, heeft Siemens mitigerende maatregelen gepubliceerd om de risico's zoveel als mogelijk te beperken. Zie de bijgevoegde referenties voor meer informatie.

Dreigingsinformatie:

Kans

medium

Schade

high

CWE-287

Improper Authentication

CWE-1240

Use of a Cryptographic Primitive with a Risky Implementation

CWE-606

Unchecked Input for Loop Condition

CWE-1395

Dependency on Vulnerable Third-Party Component

CWE-363

Race Condition Enabling Link Following

CWE-420

Unprotected Alternate Channel

CWE-684

Incorrect Provision of Specified Functionality

CWE-834

Excessive Iteration

CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

CWE-440

Expected Behavior Violation

CWE-754

Improper Check for Unusual or Exceptional Conditions

CWE-319

Cleartext Transmission of Sensitive Information

CWE-354

Improper Validation of Integrity Check Value

CWE-325

Missing Cryptographic Step

CWE-404

Improper Resource Shutdown or Release

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-1333

Inefficient Regular Expression Complexity

CWE-416

Use After Free

CWE-476

NULL Pointer Dereference

CWE-327

Use of a Broken or Risky Cryptographic Algorithm

CWE-400

Uncontrolled Resource Consumption

CWE-787

Out-of-bounds Write

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-122

Heap-based Buffer Overflow

CWE-20

Improper Input Validation

CWE-1390

Weak Authentication

CWE-204

Observable Response Discrepancy

CWE-15

External Control of System or Configuration Setting

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-653

Improper Isolation or Compartmentalization

CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-620

Unverified Password Change

CWE-798

Use of Hard-coded Credentials

CWE-269

Improper Privilege Management

CWE-295

Improper Certificate Validation

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard