Kaspersky Lab

Günter Herkommer,

Vulnerability discovered in Siemens protection technology

Kaspersky Lab has identified a vulnerability in Siemens protection technology products as part of a security audit of critical infrastructure. Once it became known, Siemens immediately closed the gap.

Potential vulnerabilities in IT or industrial systems can be detected using penetration tests or security assessments.

© Kaspersky

The vulnerability was specifically discovered within a 'Siprotec 4' network module from Siemens. This device is widely used in the energy sector to protect power grids from short circuits or critical overloads. According to Kaspersky, attackers could gain limited access to memory information via the CVE-2016-4785 vulnerability.

"Detecting such vulnerabilities is not our main job. However, in the past, we have repeatedly shown that we almost always find something during security assessments," says Sergey Gordeychik, Deputy CTO at Kaspersky Lab. Siemens has confirmed the vulnerability and published a document containing useful instructions on prevention measures and updates.

Advertisement
  • Xing Icon
  • LinkedIn Icon
Advertisement
Advertisement

You might also be interested in

Advertisement
Advertisement
Advertisement

Risk analysis

Safety starts with the design

A generally established 'state of the art' has developed for the design, development and operation of safety control systems. The situation is different when it comes to IT security, where appropriate measures are often defined and implemented on an...

read more...
Advertisement
Advertisement
Advertisement
Advertisement
Subscribe to our newsletter
Advertisement
Back to home