Skip to content

2019

SIPLUS products - Advisories

SIPLUS products are rebranded standard products offering improved resistance to mechanical loads, chemical and biological substances, condensation, and temperature fluctuations. They are also designed to cope with temperatures between -40° and +70° Celsius. These devices share the same firmware than the products they are based on.

Cyber Security topics @ Siemens Healthineers

Starting by October 15 all topics related to the Siemens Healthineers Cyber Security (including security advisories) will be published at the Siemens Healthineers Cyber Security webpage. Should you have further questions regarding this announcement, please use the contact form at the Siemens Healthineers Cyber Security webpage.

URGENT/11 - Siemens Healthineers Products

Siemens Healthineers is aware of the vulnerabilities in a number of Real Time Operating Systems (RTOSs) collectively known as URGENT/11, discovered by Armis. We also understand the topic in terms of how such vulnerabilities can possibly affect medical devices, as communicated in the recent Safety Communication from the US Food & Drug Administration (FDA).

Siemens ProductCERT was awarded by Kaspersky

Siemens ProductCERT is proud to be awarded by Kaspersky for our quality, transparent vulnerability management process. We thank Kaspersky for the recognition and are happy that our efforts are perceived that way.

DejaBlue Vulnerabilities - Siemens Healthineers Products

Siemens Healthineers is aware of the reports about the vulnerabilities reported by Microsoft on August 13th, known as DejaBlue or CVE-2019-1181/1182. Microsoft released updates for Windows 7 SP1, Windows Server 2008 R2 SP1, Windows Server 2012, Windows 8.1, Windows Server 2012 R2, and all supported versions of Windows 10, including server versions on 2019-08-13, which fix a vulnerability in the Remote Desktop Service. The vulnerability could allow an unauthenticated remote attacker to execute arbitrary code on the target system if the system exposes the service to the network.

Microsoft DejaBlue Vulnerability in Siemens Industrial Products

Siemens is aware of the reports about the vulnerabilities reported by Microsoft on August 13th, known as DejaBlue or CVE-2019-1181/1182. Microsoft released updates for several supported Windows operating systems on 2019-08-13, which fix a vulnerability in the Remote Desktop Service. The vulnerability could allow an unauthenticated remote attacker to execute arbitrary code on the target system if the system exposes the service to the network.

BlackHat Talk "Rogue 7"

Siemens is aware of the research from Technion Haifa and Tel-Aviv University presented at BlackHat USA 2019 as "Rogue7: Rogue Engineering-Station attacks on S7 Simatic PLCs". Siemens recommends to enable the feature "access protection" to prohibit unauthorized modifications of the devices.