DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Tech News

Critical bugs trouble Siemens automation systems

DigitalCIO Bureau by DigitalCIO Bureau
February 13, 2019
in Tech News
0
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Source: Cyware | By Ryan Stewart

• The flaws exist in SICAM 230, an industrial control system (ICS) by Siemens used in energy-related applications.
• Siemens has recommended users to apply updates for the DRM used in SICAM 230 to patch the issue.

A string of vulnerabilities present in one of Siemens’ automation systems has been identified. SICAM 230, an ICS meant for smart-grid applications is the affected product.

In a security advisory, Siemens has mentioned that the flaws could allow a serious remote code execution (RCE) attack in the automation system. Specifically, SICAM 230’s digital rights management (DRM) solution, known as WibuKey DRM, contained three critical vulnerabilities.

These flaws are marked using the CVSS 3.0 scoring system with the following scores:

• CVE-2018-3989 – 4.3
• CVE-2018-3990 – 9.3
• CVE-2018-3991 – 10.0

Among them, the first vulnerability CVE-2018-3989 — allows custom I/O request packet to return uninitialized memory thus revealing kernel memory. Similarly, the second one CVE-2018-3990 allows custom I/O request packet to cause a buffer overflow resulting in privilege escalation. The third vulnerability CVE-2018-3991 allowed TCP packets to port 22347/tcp causing a heap overflow. This would ultimately give way for an RCE attack.

Advisories with mitigations released
However, Siemens has urged its customers to update the WibuKey DRM to the latest version provided through WibuKey’s website. Apart from that, the German company has patched flaws found in their other products.

A total of 16 security advisories were published covering various products in their portfolio. Industrial systems such as SIMATIC, SIMOTION, and SINAMIC were found to have vulnerabilities that could permit denial of service attacks.

While some of these were patched through updates, Siemens is currently working on the others and has suggested workaround mitigations to prevent any security incident.

* Lead image used for representational purposes only.

Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

TrendAI Becomes Part of Anthropic’s Project Glasswing

by DigitalCIO Bureau
June 5, 2026
0
TrendAI Becomes Part of Anthropic’s Project Glasswing

The collaboration will enhance efforts to detect and address software vulnerabilities through advanced AI capabilities. TrendAI, the enterprise AI security leader of Trend Micro, has announced its participation...

Read moreDetails

Tata Technologies Announces Fourth Edition of InnoVent Hackathon with Emerson and AWS, Spotlighting ‘AI at the Edge’

by DigitalCIO Bureau
June 5, 2026
0
Tata Technologies Announces Fourth Edition of InnoVent Hackathon with Emerson and AWS, Spotlighting ‘AI at the Edge’

Tata Technologies announced the launch of the 4th edition of its flagship engineering innovation hackathon, InnoVent-27. Building on its continued success, this year the initiative has been further...

Read moreDetails

Nokian Tyres accelerates its IT transformation through AI-driven modernization, partnering with TCS

by DigitalCIO Bureau
June 4, 2026
0
Nokian Tyres accelerates its IT transformation through AI-driven modernization, partnering with TCS

Combining advanced AI capabilities with deep manufacturing domain expertise, TCS will support Nokian Tyres in driving innovation and sustainable business outcomes Tata Consultancy Services (TCS) has entered into...

Read moreDetails

TCS broadens its collaboration with Euroclear to upgrade Sweden’s central securities depository system

by DigitalCIO Bureau
June 3, 2026
0
TCS broadens its collaboration with Euroclear to upgrade Sweden’s central securities depository system

TCS BaNCS and Quartz will support Euroclear Sweden’s move toward a unified Nordic securities ecosystem across the Finnish and Swedish financial markets. Tata Consultancy Services (TCS) today announced...

Read moreDetails

Hexaware Enables Enterprises to Confidently Scale AI with New Agentverse Enhancements

by DigitalCIO Bureau
June 3, 2026
0
Hexaware Enables Enterprises to Confidently Scale AI with New Agentverse Enhancements

A next-generation platform for building, deploying, and scaling AI across three core layers Hexaware Technologies has introduced new enhancements to Agentverse, its enterprise AI agent platform, focusing on...

Read moreDetails
Next Post

IBM makes Watson available for competing Cloud services

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Suspension order revoked as Ola agrees to pay Rs 15 lakh penalty

March 25, 2019
SentinelOne Streamlines Vulnerability Management

SentinelOne Streamlines Vulnerability Management

August 20, 2023
ManageEngine adds next-generation antivirus capability in its UEM solution

ManageEngine adds next-generation antivirus capability in its UEM solution

October 17, 2023

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Accenture Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Digital Transformation E-books Fortinet Gartner Generative AI Google Cloud IBM India Infographics Infosys Internet of Things (IoT) Kaspersky Microsoft NTT DATA NVIDIA Palo Alto Networks Panel Discussion Salesforce Sophos Strategic Partnership Tata Consultancy Services TCS Tenable Trend Micro Veeam Veeam Software Vertiv Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?