VORANT. Threat Intelligence Research Sign in Create a free account

Multiple vulnerabilities in Siemens industrial products

high vulnerability manufacturinginfrastructure

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CERT-FR advises of multiple vulnerabilities in Siemens CloudConnect, SCALANCE, SIMATIC, SINEMA, and SINETPLAN products allowing remote code execution, denial of service, and security policy bypass.

CERT-FR has published an advisory detailing multiple vulnerabilities affecting several Siemens industrial automation and connectivity products. The affected products include CloudConnect 712 (before V1.1.5), SCALANCE SC-600 (before V2.0.1), SIMATIC TDC CP51M1 (before V1.1.7), SINEMA Remote Connect Server (before V2.0 SP1), and SINETPLAN V2.0. The vulnerabilities carry a range of impacts including remote code execution, denial of service, security policy bypass, data confidentiality violations, and cross-site scripting (XSS) and cross-site request forgery (CSRF) flaws. The advisory references seven Siemens security bulletins published on 10 September 2019, indicating this was a coordinated disclosure event covering multiple product lines. Defenders operating these Siemens products in industrial control, connectivity, and network infrastructure contexts should prioritize patching to the specified fixed versions.

Mentioned in this report

Vulnerabilities CVE-2019-10915CVE-2019-10937CVE-2019-11477CVE-2019-11478CVE-2019-11479CVE-2019-1181CVE-2019-1182CVE-2019-1222CVE-2019-12255pocCVE-2019-12256CVE-2019-12257CVE-2019-12258weaponizedCVE-2019-12259CVE-2019-1226CVE-2019-12260CVE-2019-12261CVE-2019-12262CVE-2019-12263CVE-2019-12264CVE-2019-12265CVE-2019-13918CVE-2019-13919CVE-2019-13920CVE-2019-13922CVE-2019-13923

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2019-AVI-429

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,162 reports from 155 sources, 1,790 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs