<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_siemens</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:50:51 +0000</lastBuildDate>
    <item>
      <title>SSA-625789 — SSA-625789: Multiple Vulnerabilities in SIMATIC S7-1200 CPU V1/V2 Devices</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-625789</link>
      <description>&lt;p&gt;The web server interface of affected devices improperly processes incoming malformed HTTP traffic at high rate. This could allow an unauthenticated remote attacker to force the device entering the stop/defect state, thus creating a denial of service condition. Affected controllers are vulnerable to capture-replay in the communication with the engineering software. This could allow an on-path attacker between the engineering software and the controller to execute any previously recorded commands at a later time (e.g. set the controller to STOP), regardless whether or not the controller had a password configured.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The web server interface of affected devices improperly processes incoming malformed HTTP traffic at high rate. This could allow an unauthenticated remote attacker to force the device entering the stop/defect state, thus creating a denial of service condition. Affected controllers are vulnerable to capture-replay in the communication with the engineering software. This could allow an on-path attacker between the engineering software and the controller to execute any previously recorded commands at a later time (e.g. set the controller to STOP), regardless whether or not the controller had a password configured.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-625789</guid>
      <pubDate>Fri, 10 Jun 2011 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-130874 — SSA-130874: Buffer Overflow Vulnerability in SCALANCE X Switches</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-130874</link>
      <description>&lt;p&gt;The embedded web server on affected devices contains a buffer overflow vulnerability. This could allow remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a malformed URL.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The embedded web server on affected devices contains a buffer overflow vulnerability. This could allow remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a malformed URL.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-130874</guid>
      <pubDate>Thu, 05 Apr 2012 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-240718 — SSA-240718: Insecure Storage of HTTPS CA Certificate in SIMATIC S7-1200 CPU V2</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-240718</link>
      <description>&lt;p&gt;Affected devices do not properly protect the private key of the integrated Certification Authority (CA) certificate. Possession of this key could allow remote attackers to spoof the device&amp;#39;s web server by creating a forged web server certificate.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Affected devices do not properly protect the private key of the integrated Certification Authority (CA) certificate. Possession of this key could allow remote attackers to spoof the device&amp;#39;s web server by creating a forged web server certificate.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-240718</guid>
      <pubDate>Thu, 13 Sep 2012 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-279823 — SSA-279823: Cross-Site Scripting Vulnerability in SIMATIC S7-1200 CPU V2/V3 Before V3.0.2</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-279823</link>
      <description>&lt;p&gt;The web server on affected devices contains a cross-site scripting (XSS) vulnerability that could allow remote attackers to inject arbitrary web script or HTML via a crafted URI.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The web server on affected devices contains a cross-site scripting (XSS) vulnerability that could allow remote attackers to inject arbitrary web script or HTML via a crafted URI.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-279823</guid>
      <pubDate>Mon, 08 Oct 2012 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-783261 — SSA-783261: Denial of Service Vulnerability in Automation License Manager (ALM) Before V5.2</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-783261</link>
      <description>&lt;p&gt;Specially crafted packets sent to port 4410/tcp cause memory leaks within the application. This could allow a remote unauthenticated attacker to crash the application due to insufficient resources. This denial of service condition could prevent legitimate users from using subsequent products that rely on the affected application for license verification.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Specially crafted packets sent to port 4410/tcp cause memory leaks within the application. This could allow a remote unauthenticated attacker to crash the application due to insufficient resources. This denial of service condition could prevent legitimate users from using subsequent products that rely on the affected application for license verification.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-783261</guid>
      <pubDate>Wed, 12 Dec 2012 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-373591 — SSA-373591: Buffer Overflow Vulnerability in RUGGEDCOM ROS Devices</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-373591</link>
      <description>&lt;p&gt;The DHCP client in affected devices fails to properly sanitize incoming DHCP packets. This could allow an unauthenticated remote attacker to cause memory to be overwritten, potentially allowing remote code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The DHCP client in affected devices fails to properly sanitize incoming DHCP packets. This could allow an unauthenticated remote attacker to cause memory to be overwritten, potentially allowing remote code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-373591</guid>
      <pubDate>Tue, 13 Jul 2021 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-599968 — SSA-599968: Denial of Service Vulnerability in Profinet Devices</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-599968</link>
      <description>&lt;p&gt;Affected devices contain a vulnerability that allows an unauthenticated attacker to trigger a denial of service condition. The vulnerability can be triggered if a large amount of DCP reset packets are sent to the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Affected devices contain a vulnerability that allows an unauthenticated attacker to trigger a denial of service condition. The vulnerability can be triggered if a large amount of DCP reset packets are sent to the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-599968</guid>
      <pubDate>Tue, 13 Jul 2021 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-913875 — SSA-913875: Frame Aggregation and Fragmentation Vulnerabilities in 802.11</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-913875</link>
      <description>&lt;p&gt;The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn&amp;#39;t require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary can abuse this to inject arbitrary network packets. An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients. An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration. An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An adversary can abuse this to inject and possibly decrypt packets in WPA or WPA2 networks that support the TKIP data-confidentiality protocol. An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH. The WEP, WPA, WPA2, and WPA3 implementations accept fragme…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn&amp;#39;t require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary can abuse this to inject arbitrary network packets. An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients. An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration. An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An adversary can abuse this to inject and possibly decrypt packets in WPA or WPA2 networks that support the TKIP data-confidentiality protocol. An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH. The WEP, WPA, WPA2, and WPA3 implementations accept fragme…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-913875</guid>
      <pubDate>Tue, 13 Jul 2021 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-244969 — SSA-244969: OpenSSL Vulnerability in Industrial Products</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-244969</link>
      <description>&lt;p&gt;ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a strict requirement, ASN.1 strings that are parsed using OpenSSL&amp;#39;s own &amp;#34;d2i&amp;#34; functions (and other similar parsing functions) as well as any string whose value has been set with the ASN1_STRING_set() function will additionally NUL terminate the byte array in the ASN1_STRING structure. However, it is possible for applications to directly construct valid ASN1_STRING structures which do not NUL terminate the byte array by directly setting the &amp;#34;data&amp;#34; and &amp;#34;length&amp;#34; fields in the ASN1_STRING array. This can also happen by using the ASN1_STRING_set0() function. Numerous OpenSSL functions that print ASN.1 data have been found to assume that the ASN1_STRING byte array will be NUL terminated, even though this is not guaranteed for strings that have been directly constructed. Where an application requests an ASN.1 structure to be printed, and where that ASN.1 structure contains ASN1_STRINGs that have been directly constructed by the application without NUL terminating the &amp;#34;data&amp;#34; field, then a read buffer overrun can occur. The same thing can also occur during name constraints processing of certificates (for example if a certificate has been directly constructed by the applicati…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a strict requirement, ASN.1 strings that are parsed using OpenSSL&amp;#39;s own &amp;#34;d2i&amp;#34; functions (and other similar parsing functions) as well as any string whose value has been set with the ASN1_STRING_set() function will additionally NUL terminate the byte array in the ASN1_STRING structure. However, it is possible for applications to directly construct valid ASN1_STRING structures which do not NUL terminate the byte array by directly setting the &amp;#34;data&amp;#34; and &amp;#34;length&amp;#34; fields in the ASN1_STRING array. This can also happen by using the ASN1_STRING_set0() function. Numerous OpenSSL functions that print ASN.1 data have been found to assume that the ASN1_STRING byte array will be NUL terminated, even though this is not guaranteed for strings that have been directly constructed. Where an application requests an ASN.1 structure to be printed, and where that ASN.1 structure contains ASN1_STRINGs that have been directly constructed by the application without NUL terminating the &amp;#34;data&amp;#34; field, then a read buffer overrun can occur. The same thing can also occur during name constraints processing of certificates (for example if a certificate has been directly constructed by the applicati…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-244969</guid>
      <pubDate>Tue, 08 Feb 2022 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-306654 — SSA-306654: Insyde BIOS Vulnerabilities in Siemens Industrial Products</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-306654</link>
      <description>&lt;p&gt;Insyde has published information on vulnerabilities in Insyde BIOS in February 2022. This advisory lists the Siemens Industrial products affected by these vulnerabilities.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Insyde has published information on vulnerabilities in Insyde BIOS in February 2022. This advisory lists the Siemens Industrial products affected by these vulnerabilities.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-306654</guid>
      <pubDate>Tue, 22 Feb 2022 00:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
