This content is restricted.
Brief
Summary:
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. The document provides information on two vulnerabilities in Siemens' POWER METER SICAM Q100 devices, including a Cross-Site Request Forgery (CSRF) and Incorrect Permission Assignment for Critical Resource. These vulnerabilities could allow an attacker to perform arbitrary actions on the device on behalf of a legitimate user or impersonate that user. The document includes mitigations, recommendations, and guidance on reducing risk, including updating software and configuring network access. No public exploitation of these vulnerabilities has been reported at this time.
Highlights content goes here...
This content is restricted.
