Brief

Summary:

CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. The vendor, Siemens, recommends protecting network access to devices and configuring the environment according to their operational guidelines for industrial security.

The advisory reports 11 vulnerabilities in Solid Edge, a Siemens product, with CVEs ranging from 2023-49121 to 2023-49132. The vulnerabilities are primarily heap-based buffer overflows, out-of-bounds reads and writes, stack-based buffer overflows, and access of uninitialized pointers.

Successful exploitation of these vulnerabilities could allow an attacker to execute code in the context of the current process. Siemens recommends updating to V223.0 Update 10 or later version, avoiding opening untrusted files from unknown sources, and protecting network access to devices.

CISA recommends minimizing network exposure, isolating control system networks, and using secure remote access methods, such as Virtual Private Networks (VPNs).

As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens’ ProductCERT Security Advisories (CERT Services | Services | Siemens Global).  View CSAF 1. EXECUTIVE SUMMARY CVSS v3 7.8 ATTENTION: Low attack complexity

This content is restricted.

Highlights content goes here...

As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens’ ProductCERT Security Advisories (CERT Services | Services | Siemens Global).  View CSAF 1. EXECUTIVE SUMMARY CVSS v3 7.8 ATTENTION: Low attack complexity

This content is restricted.

Cybersecurity and Infrastructure Security Agency

Quick Insight
RADA.AI
RADA.AI
Hello! I'm RADA.AI - Regulatory Analysis and Decision Assistance. Your Intelligent guide for compliance and decision-making. How can i assist you today?
Suggested

Form successfully submitted. One of our GRI rep will contact you shortly

Thanking You!

Enter your Email

Enter your registered username/email id.

Enter your Email

Enter your email id below to signup.
Individual Plan
$125 / month OR $1250 / year
Features
Best for: Researchers, Legal professionals, Academics
Enterprise Plan
Contact for Pricing
Features
Best for: Law Firms, Corporations, Government Bodies