Skip to content

News

Siemens ProductCERT and Siemens CERT continously monitor the cyber threat landscape as well as dedicated cyber-attack campaigns against Siemens products, solutions, services, or infrastructure. In order to provide timely support to Siemens customers and operators on imminent cyber threats, Siemens issues Security Alerts and News.

Increasing Vulnerability Transparency with Supplier-ADP

Since 2024, the Cybersecurity and Infrastructure Security Agency (CISA) has implemented the “Vulnrichment” program to enrich CVE data with additional information. The goal is to give additional context and help defenders in assessing the specific risk of these vulnerabilities. Each CVE from cve.org or github has an Authorized Data Publisher (ADP) container where this data is stored.

As a next level, Siemens PSIRT was advocating a further extension of this: The Supplier-ADP (SADP), which was piloted in the last months and finally introduced in April 2026. The SADP comes handy if a supplier like Siemens wants to add information to a vulnerability, which originates in an upstream dependency.

On the Malicious NuGet Packages Containing Logic Bombs

Siemens is aware of the following nine malicious NuGet packages reported recently by Socket researchers. 

  • MyDbRepository (Last updated on May 13, 2023), 
  • MCDbRepository (Last updated on June 5, 2024), 
  • Sharp7Extend (Last updated on August 14, 2024), 
  • SqlDbRepository (Last updated on October 24, 2024), 
  • SqlRepository (Last updated on October 25, 2024), 
  • SqlUnicornCoreTest (Last updated on October 26, 2024), 
  • SqlUnicornCore (Last updated on October 26, 2024), 
  • SqlUnicorn.Core (Last updated on October 27, 2024), and 
  • SqlLiteRepository (Last updated on October 28, 2024)

Introduction of "Known Not Affected Products" in Siemens Security Advisories

Last year's improvements in Siemens Security Advisories, where we introduced the ability to describe a product-specific impact to a vulnerability, raised the next logical and expected question: "...but what if a product is not impacted at all by that vulnerability?"

Starting with Advisory Day in June 2025 we're excited to introduce the support of "Known not affected products" in both human-readable HTML advisories, and machine-readable CSAF documents.

Black Hat Europe 2023 - Details of the Legacy PG/PC and HMI Communication in SIMATIC S7-1500 SW Controller

Siemens is aware of the talk at the Black Hat Conference Europe (December 6, 2023, London), titled “A Decade After Stuxnet: How Siemens S7 is Still an Attacker’s Heaven”. The talk and the related research paper describe the details of the legacy PG/PC and HMI communication protocol as used between TIA Portal / HMIs and SIMATIC S7-1500 SW Controller in versions before V17. No previously unknown security vulnerabilities were disclosed in this talk. Siemens was in close coordination with the presenting company.