logo

Siemens Patches Holes In Industrial Control Switch

ID: c1400ee2-1c0b-5a36-9ca5-ccd3194b2121

STIX ID: report--c1400ee2-1c0b-5a36-9ca5-ccd3194b2121

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2014-01-09

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

A security researcher found two serious flaws in Siemens SCALANCE X-200 ICS switches: predictable session IDs that could permit session hijacking, and a more severe issue allowing unauthenticated posting of firmware update URLs which the switch will accept, install, and reboot — enabling potential full compromise. The affected devices are widely used in critical sectors (energy, transportation) but are typically on protected networks; Siemens issued patches within months and the researcher intends to demonstrate exploit code at a conference.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.