Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Siemens heeft kwetsbaarheden verholpen in diverse producten zoals Analytics Toolkit, Ruggedcom, Industrial Edge Management Pro, SIDIS en TPM.
- Interpretaties
De kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Manipulatie van gegevens
- Omzeilen van een beveiligingsmaatregel
- (Remote) code execution (root/admin rechten)
- Toegang tot systeemgegevens
- Verhogen van rechten
Voor succesvol misbruik van de genoemde kwetsbaarheden moet de kwaadwillende toegang hebben tot de productie-omgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.
- Oplossingen
Siemens heeft beveiligingsupdates uitgebracht om de kwetsbaarheden te verhelpen. Voor de kwetsbaarheden waar nog geen updates voor zijn, heeft Siemens mitigerende maatregelen gepubliceerd om de risico's zoveel als mogelijk te beperken. Zie de bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-20
Improper Input Validation
- CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-80
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
- CWE-99
Improper Control of Resource Identifiers ('Resource Injection')
- CWE-125
Out-of-bounds Read
- CWE-197
Numeric Truncation Error
- CWE-266
Incorrect Privilege Assignment
- CWE-284
Improper Access Control
- CWE-287
Improper Authentication
- CWE-290
Authentication Bypass by Spoofing
- CWE-295
Improper Certificate Validation
- CWE-305
Authentication Bypass by Primary Weakness
- CWE-306
Missing Authentication for Critical Function
- CWE-307
Improper Restriction of Excessive Authentication Attempts
- CWE-327
Use of a Broken or Risky Cryptographic Algorithm
- CWE-345
Insufficient Verification of Data Authenticity
- CWE-346
Origin Validation Error
- CWE-347
Improper Verification of Cryptographic Signature
- CWE-354
Improper Validation of Integrity Check Value
- CWE-400
Uncontrolled Resource Consumption
- CWE-639
Authorization Bypass Through User-Controlled Key
- CWE-770
Allocation of Resources Without Limits or Throttling
- CWE-829
Inclusion of Functionality from Untrusted Control Sphere
- CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
- CWE-862
Missing Authorization
- CWE-863
Incorrect Authorization
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard