Siemens SIDIS Secured SmartPlug
Summary
Siemens SIDIS Secured SmartPlug versions prior to V7.26.0310 are affected by multiple vulnerabilities, including issues in OpenSSL, OpenSSH, and other packages. These vulnerabilities encompass improper message integrity enforcement, nonce reuse, out-of-bounds writes/reads, and more, leading to a critical CVSS score. Siemens has released an updated version V7.26.0310 to address these flaws.
IFF Assessment
The article details critical vulnerabilities in Siemens industrial equipment, posing a significant risk to defenders in critical infrastructure sectors.
Severity
Defender Context
This alert highlights critical vulnerabilities in Siemens industrial control systems (ICS) that affect the Critical Manufacturing sector worldwide. Defenders should prioritize patching or updating affected Siemens SIDIS Secured SmartPlug devices to the latest version to mitigate risks of unauthorized access and data manipulation.