Start your day with intelligence. Get The OODA Daily Pulse.

Siemens Sicam Vulnerabilities Could Facilitate Attacks on Energy Sector

In May Siemens informed customers that new updates containing patches for vulnerabilities, one medium-security, and two high-severity flaws.

According to Siemens, the vulnerabilities have the potential to be exploited in attacks targeting the energy sector. One of the security holes known as CVE-2024-31484 could be exploited to read memory, accessing sensitive data for users. This could lead to arbitrary code execution, and evolve into a denial-of-service (DoS) condition. The second vulnerability, known as CVE-2024-31485, enables threat actors to intercept password information of users and execute arbitrary code. The third vulnerability, CVE-2024-31486 also takes advantage of compromised password and user information, allowing threat actors to use remote shell access to gain credentialed access. 

Read more:

https://www.securityweek.com/siemens-sicam-vulnerabilities-could-facilitate-attacks-on-energy-sector/

Tagged: vulnerabilities