This content is restricted.
Brief
Summary:
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. The advisory announces two NULL Pointer Dereference vulnerabilities in Siemens products, which could allow an attacker to cause a persistent denial-of-service condition in the RPC Server. The affected products include OpenPCS 7 V9.1, SIMATIC BATCH V9.1, and other versions. Siemens has released updates and workarounds for some of the affected products, and recommends implementing defensive measures such as minimizing network exposure and using firewalls to reduce the risk of exploitation. No known public exploitation has been reported at this time.
Highlights content goes here...
This content is restricted.
