Siemens and Schneider Electric address over 50 flaws
Siemens has published 13 security advisories describing 36 vulnerabilities. Two of the advisories focus on the impact of the newly disclosed NUCLEUS:13 vulnerabilities on the company’s products. The flaws, many of which have been assigned critical and high severity ratings, can be exploited by remote attackers for remote code execution, DoS attacks, and to obtain information.
Siemens’ advisories address high-severity flaws in Siveillance Video DLNA Server (path traversal), SENTRON powermanager V3 (local code execution and privilege escalation), NX (code execution), and PSS, SICAM and SIMATIC products (DoS). Medium-severity issues have been addressed in Climatix POL909 (information disclosure), SIMATIC RTLS Locating Manager (DoS and information disclosure), Mendix (information disclosure and content manipulation), and NX (code execution).
Source: securityweek.com
12 November 2021