Siemens WTV676 and WTV776
View CSAF Summary The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens WTV676 and WTV776…
Excerpt from the primary source: CISA Cybersecurity Advisories
Who is affected
Critical infrastructure
What you should do · Be aware
No immediate action is indicated. Share this with the relevant teams and watch for updates.
Automated guidance based on this story's classification. Check the linked advisories for specifics.
Sources
We link to original and authoritative sources. Headlines and excerpts belong to their publishers.
Government advisory
Related
Fortra Patches Critical Vulnerabilities in BoKS
The bugs could lead to authentication bypass, shell command execution, and memory corruption.
Apply the vendor's security update for the affected products.
Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response
One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to releasing a patch for its product.
There are signs this may already be exploited, which usually shortens the time available to patch.
Apply the vendor's security update for the affected products.
SWIFT Banking & Government Middleware Enables RCE
Patch middleware vulnerabilities now to avoid hardware-based MFA exploits in ultra-sensitive environments.
GitLab warns of critical RCE vulnerability in AI Gateway service
GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances.
Apply the vendor's security update for the affected products.
