You are here

Siemens OpenSSL Vulnerability in Industrial Products (Update E) (ICSA-18-226-02) – Products Used in the Water and Wastewater and Energy Sectors

Siemens OpenSSL Vulnerability in Industrial Products (Update E) (ICSA-18-226-02) – Products Used in the Water and Wastewater and Energy Sectors

Created: Tuesday, April 9, 2019 - 17:37
Categories:
Cybersecurity

April 9, 2019

The NCCIC has updated this advisory with additional details on the affected products and mitigation measures. Read the advisory at NCCIC/ICS-CERT.

November 13, 2018

The NCCIC has updated this advisory with additional details on the affected products and mitigation measures. NCCIC/ICS-CERT.

October 9, 2018

The NCCIC has updated this advisory with additional details on the affected products and mitigation measures. NCCIC/ICS-CERT.

September 11, 2018

The NCCIC has updated this advisory with additional details on mitigation measures. NCCIC/ICS-CERT.

August 14, 2018

The NCCIC has released an advisory an OpenSSL vulnerability in Siemens Industrial Products. Multiple versions of these products are affected. Successful exploitation of this vulnerability could result in unencrypted data being transmitted by the SSL/TLS record layer. Siemens has provided updates and identified specific workarounds and mitigations to fix the vulnerabilities and reduce the risk. The NCCIC also recommends a series of defensive measures to minimize the risk of exploitation of these vulnerabilities. NCCIC/ICS-CERT.