Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2025-0160

Published May 14, 2025·Last modified May 14, 2025
Description
Feiten

Siemens heeft kwetsbaarheden verholpen in diverse producten als Apogee, BacNet ATEC, Desigo CC, Intralog, OZW, Polarion, RUGGEDCOM, SICAM, SIMATIC, SIPROTEC, SIRIUS, Teamcenter en Versicharge

Interpretaties

De kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:

  • Denial-of-Service (DoS)
  • Manipulatie van gegevens
  • Omzeilen van een beveiligingsmaatregel
  • Omzeilen van authenticatie
  • (Remote) code execution (root/admin rechten)
  • (Remote) code execution (Gebruikersrechten)
  • Toegang tot systeemgegevens
  • Toegang tot gevoelige gegevens
  • Spoofing

De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.

Oplossingen

Siemens heeft beveiligingsupdates uitgebracht om de kwetsbaarheden te verhelpen. Voor de kwetsbaarheden waar nog geen updates voor zijn, heeft Siemens mitigerende maatregelen gepubliceerd om de risico's zoveel als mogelijk te beperken. Zie de bijgevoegde referenties voor meer informatie.

Kans

medium

Schade

high

CWE-1326

Missing Immutable Root of Trust in Hardware

CWE-420

Unprotected Alternate Channel

CWE-59

Improper Link Resolution Before File Access ('Link Following')

CWE-328

Use of Weak Hash

CWE-257

Storing Passwords in a Recoverable Format

CWE-1188

Initialization of a Resource with an Insecure Default

CWE-407

Inefficient Algorithmic Complexity

CWE-732

Incorrect Permission Assignment for Critical Resource

CWE-440

Expected Behavior Violation

CWE-311

Missing Encryption of Sensitive Data

CWE-924

Improper Enforcement of Message Integrity During Transmission in a Communication Channel

CWE-836

Use of Password Hash Instead of Password for Authentication

CWE-319

Cleartext Transmission of Sensitive Information

CWE-613

Insufficient Session Expiration

CWE-354

Improper Validation of Integrity Check Value

CWE-204

Observable Response Discrepancy

CWE-451

User Interface (UI) Misrepresentation of Critical Information

CWE-290

Authentication Bypass by Spoofing

CWE-125

Out-of-bounds Read

CWE-306

Missing Authentication for Critical Function

CWE-416

Use After Free

CWE-327

Use of a Broken or Risky Cryptographic Algorithm

CWE-400

Uncontrolled Resource Consumption

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-611

Improper Restriction of XML External Entity Reference

CWE-787

Out-of-bounds Write

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CWE-20

Improper Input Validation

CWE-294

Authentication Bypass by Capture-replay

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard