Skip to content

2021

Vulnerabilities in the Apache Log4j ("Log4Shell")

Siemens is aware of the security vulnerabilities in Apache Log4j (CVE-2021-44228 and CVE-2021-45046), also named "Log4Shell". For Siemens products, a security advisory (SSA-661247) was issued on 2021-12-13 and will be updated in the following days as more information becomes available.

Vulnerabilities in the Nucleus TCP/IP Stack ("NUCLEUS:13")

Today, in coordination with Forescout, CISA and other contributors, Siemens has disclosed the security vulnerabilities CVE-2021-31344 through CVE-2021-31346 and CVE-2021-31881 through CVE-2021-31890, also named "NUCLEUS:13". The impact and remediations of these vulnerabilities in Nucleus RTOS (a real-time operating system provided by Siemens EDA, formerly Mentor Graphics) is described in SSA-044112: Multiple Vulnerabilities (NUCLEUS:13) in the TCP/IP Stack of Nucleus RTOS.