Siemens Patches Holes In Industrial Control Switch
ID: c1400ee2-1c0b-5a36-9ca5-ccd3194b2121
STIX ID: report--c1400ee2-1c0b-5a36-9ca5-ccd3194b2121
Feed Name: Security Ledger
A security researcher found two serious flaws in Siemens SCALANCE X-200 ICS switches: predictable session IDs that could permit session hijacking, and a more severe issue allowing unauthenticated posting of firmware update URLs which the switch will accept, install, and reboot — enabling potential full compromise. The affected devices are widely used in critical sectors (energy, transportation) but are typically on protected networks; Siemens issued patches within months and the researcher intends to demonstrate exploit code at a conference.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
