Rewterz
Rewterz Threat advisory – ICS: Siemens LOGO!8 Devices Multiple Vulnerabilities
June 13, 2019
Rewterz
Rewterz Threat Advisory – Microsoft SharePoint Foundation 2013 Multiple Script Insertion Vulnerabilities
June 13, 2019

Rewterz Threat Advisory -CVE-2019-6567 – ICS: Siemens SCALANCE X Password Protection Vulnerability

Severity

Medium

Analysis Summary

The affected devices store passwords in a recoverable format. An attacker may extract and recover device passwords from the device configuration. Successful exploitation requires access to a device configuration backup and impacts confidentiality of the stored passwords.

Impact

Storing Passwords in a Recoverable Format

Affected Vendors

Siemens

Affected Products

SCALANCE X Switches

Remediation

Vendor has identified the following specific workarounds/mitigations to reduce the risk from this vulnerability:

https://support.industry.siemens.com/cs/ww/en/view/109767965