Rewterz

Rewterz Threat Advisory – Siemens Industrial Products Multiple Vulnerabilities

September 11, 2019
Rewterz

Rewterz Threat Advisory – CVE-2019-10937 – Siemens SIMATIC TDC CP51M1 Denial of Service Vulnerability

September 11, 2019

Rewterz Threat Advisory – CVE-2019-13923 – Siemens IE-WSN-PA Link WirelessHART Gateway Multiple Vulnerabilities

Severity

Medium

Analysis summary

An attacker sending a malicious link to an unsuspecting user may be able to execute a cross-site scripting attack, which may allow information disclosure, code execution, or denial-of-service.

Impact

  • Information disclosure
  • Denial of service

Affected Vendors

Siemens

Affected Products

IE/WSN-PA Link WirelessHART Gateway all versions

Remediation

Siemens has identified the following specific workarounds and mitigations that users can apply to reduce the risk:

  • Only access links from trusted sources in the browser used to configure IE/WSN-PA Link.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.