SecureWorld News

Siemens Patches Endpoint and DDoS Vulnerabilities 

Written by SecureWorld News Team | Fri | Mar 23, 2018 | 4:47 PM Z

Industrial control system (ICS) related security patches are coming out at a greater speed than the muscle cars in "The Fast and the Furious" movies. 

Or at least, that's how it seems.

This week, Siemens issued several noteworthy patches. One secures your endpoints, because there were vulnerabilities in a Siemens app for both iOS and Android.

"SIMATIC WinCC OA UI fix a security vulnerability which could allow read and write access from one HMI project cache folder to other HMI project cache folders within the app’s sandbox on the same mobile device," the company says. The advisory is here.

And there is another patch for a communications and software controller that has DDoS vulnerabilities for an incredible number of industries.

"They are used worldwide, e.g. in the automotive industry, mechanical equipment manufacture, warehousing systems, building engineering, steel industry, power generation and distribution, pharmaceuticals, food and beverages industry, or chemical industry."

You can see that advisory here.