Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Siemens heeft kwetsbaarheden verholpen in diverse producten als SIMATIC, SINEC, SIMAC, RUGGEDCOM, SIMOTION, SINAMICS, SIPROTEC en SINUMERIK.
- Interpretaties
De kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Cross-Site Scripting
- Manipulatie van gegevens
- Omzeilen van een beveiligingsmaatregel
- (Remote) code execution (SYSTEM rechten)
- (Remote) code execution (Gebruikersrechten)
- Toegang tot gevoelige gegevens
- Verhogen van rechten
De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.
- Oplossingen
Siemens heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-295
Improper Certificate Validation
- CWE-400
Uncontrolled Resource Consumption
- CWE-770
Allocation of Resources Without Limits or Throttling
- CWE-502
Deserialization of Untrusted Data
- CWE-611
Improper Restriction of XML External Entity Reference
- CWE-787
Out-of-bounds Write
- CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
- CWE-122
Heap-based Buffer Overflow
- CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
- CWE-20
Improper Input Validation
- CWE-1341
Multiple Releases of Same Resource or Handle
- CWE-1164
Irrelevant Code
- CWE-272
Least Privilege Violation
- CWE-131
Incorrect Calculation of Buffer Size
- CWE-522
Insufficiently Protected Credentials
- CWE-667
Improper Locking
- CWE-440
Expected Behavior Violation
- CWE-415
Double Free
- CWE-617
Reachable Assertion
- CWE-427
Uncontrolled Search Path Element
- CWE-680
Integer Overflow to Buffer Overflow
- CWE-288
Authentication Bypass Using an Alternate Path or Channel
- CWE-300
Channel Accessible by Non-Endpoint
- CWE-312
Cleartext Storage of Sensitive Information
- CWE-190
Integer Overflow or Wraparound
- CWE-250
Execution with Unnecessary Privileges
- CWE-434
Unrestricted Upload of File with Dangerous Type
- CWE-125
Out-of-bounds Read
- CWE-404
Improper Resource Shutdown or Release
- CWE-284
Improper Access Control
- CWE-476
NULL Pointer Dereference
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard