Rewterz

Rewterz Threat Advisory – Siemens SCALANCE W1750D Multiple Command Injection and Cross-Site Scripting Vulnerabilities

May 16, 2019
Rewterz

Rewterz Threat Advisory – CVE-2019-11634 – Citrix Workspace / Receiver for Windows Remote Code Execution Vulnerability

May 16, 2019

Rewterz Threat Advisory – Siemens SIMATIC Panels and WinCC (TIA Portal) Multiple Vulnerabilities

Severity

Medium

Analysis Summary


CVE-2019-6572

The affected devices offer SNMP read/write capabilities with a hardcoded community string, which may allow an attacker to read/write variables over SNMP. This could compromise the confidentiality and integrity of the affected system.

CVE-2019-6576

An attacker with network access could potentially obtain a TLS session key and use it to decrypt TLS traffic. This could impact the confidentiality of communications between the device and a legitimate user.

CVE-2019-6577

The integrated web server could allow a cross-site scripting (XSS) attack if an attacker is able to modify certain device configuration settings via SNMP. This could impact confidentiality and integrity of the affected system.

Impact

  • Use of Hard-coded Credentials
  • Insufficient Protection of Credentials
  • Cross-site Scripting

Affected Vendors

Siemens

Affected Products

  • SIMATIC WinCC Runtime Advanced
  • WinCC Runtime Professional
  • WinCC (TIA Portal)
  • HMI Panels

Remediation

Siemens has updates at for the following products:

https://support.industry.siemens.com/cs/ww/en/view/109763890/

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.