Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

Siemens Patches DoS Flaws in Industrial Products

Siemens has released software updates for some of its industrial products, including SIMATIC and SCALANCE, to patch several medium severity denial-of-service (DoS) vulnerabilities.

Siemens has released software updates for some of its industrial products, including SIMATIC and SCALANCE, to patch several medium severity denial-of-service (DoS) vulnerabilities.

Siemens and ICS-CERT have each published three advisories covering a total of four security holes. Two of the advisories describe vulnerabilities affecting products that use the PROFINET Discovery and Configuration Protocol (DCP).

The flaws, caused by improper input validation, can be exploited by attackers with network access to cause a DoS condition on devices by sending specially crafted PROFINET DCP broadcast packets. Manual intervention is required to restore the system after an attack.

The list of affected products includes SIMATIC communication processors, modules, PLCs, identification systems, HMI panels, and remote servicing products; SCALANCE routers, switches and firewalls; SITOP power supply units; and SIRIUS relays. Some SIMOCODE, SINAMICS, SIMOTION, SINEMA, SINAUT, and SINUMERIK products are also impacted.

Duan JinTong, Ma ShaoShuai and Cheng Lei from the NSFOCUS Security Team reported these flaws to Siemens. The vendor has released patches for some of the affected products, and provided mitigation recommendations for products that have yet to receive fixes.

Siemens’ recommendations include using VPNs to protect network communications, and applying cell protection and defense-in-depth concepts as described in the company’s operational guidelines for industrial security.

The third advisory published by Siemens and ICS-CERT describes a DoS vulnerability affecting SIMATIC WinCC SCADA systems, the WinCC Runtime Professional visualization platform, and the WinCC (TIA Portal) Professional engineering software.

The weakness, reported by researchers at Kaspersky Lab, allows an attacker to crash services by sending specially crafted messages to the DCOM interface. This flaw is less severe as the attack requires not only network access, but also administrative credentials.

Advertisement. Scroll to continue reading.

Related Reading: Siemens Patches Flaws in SIMATIC, License Manager Products

Related Reading: Vulnerabilities Found in Siemens Desigo PX, SIMATIC Products

Related Reading: Siemens Releases Firmware Updates to Patch SIMATIC Flaws

Related Reading: Siemens SIMATIC Controllers Vulnerable to DoS Attacks

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

Vulnerabilities

The latest Chrome update brings patches for eight vulnerabilities, including seven reported by external researchers.