{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[{"description":"SIMATIC WinCC OA UI pour Android versions ant\u00e9rieures \u00e0 V3.15.10","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"Desigo Automation Controllers for Integration PXC001-E.D versions ant\u00e9rieures \u00e0 V6.00.204","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIMATIC S7-1500 incl. F versions ant\u00e9rieures \u00e0 V1.8.5","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"Desigo Automation Controllers Compact PXC12/22/36-E.D versions ant\u00e9rieures \u00e0 V6.00.204","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"Desigo Automation Controllers PXC00/64/128-U avec module Web versions ant\u00e9rieures \u00e0 V6.00.204","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIMATIC S7-1500 Software Controller incl. F versions ant\u00e9rieures \u00e0 V1.8.5","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"Desigo Automation Controllers Modular PXC00/50/100/200-E.D versions ant\u00e9rieures \u00e0 V6.00.204","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIMATIC WinCC OA UI pour iOS versions ant\u00e9rieures \u00e0 V3.15.10","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIMATIC S7-410 versions ant\u00e9rieures \u00e0 V8.1","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"Desigo Operator Unit PXM20-E versions ant\u00e9rieures \u00e0 V6.00.204","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIMATIC S7-400 PN/DP V6 Incl. F versions ant\u00e9rieures \u00e0 V6.0.7","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}}],"affected_systems_content":null,"content":"## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des\ncorrectifs (cf. section Documentation).\n","cves":[{"name":"CVE-2018-4834","url":"https://www.cve.org/CVERecord?id=CVE-2018-4834"},{"name":"CVE-2018-4844","url":"https://www.cve.org/CVERecord?id=CVE-2018-4844"},{"name":"CVE-2018-4843","url":"https://www.cve.org/CVERecord?id=CVE-2018-4843"}],"links":[],"reference":"CERTFR-2018-AVI-140","revisions":[{"description":"Version initiale","revision_date":"2018-03-21T00:00:00.000000"}],"risks":[{"description":"D\u00e9ni de service \u00e0 distance"},{"description":"Atteinte \u00e0 l'int\u00e9grit\u00e9 des donn\u00e9es"},{"description":"Contournement de la politique de s\u00e9curit\u00e9"},{"description":"Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"}],"summary":"De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans SCADA les produits\nSiemens . Certaines d'entre elles permettent \u00e0 un attaquant de provoquer\nun d\u00e9ni de service \u00e0 distance, un contournement de la politique de\ns\u00e9curit\u00e9 et une atteinte \u00e0 l'int\u00e9grit\u00e9 des donn\u00e9es.\n","title":"Multiples vuln\u00e9rabilit\u00e9s dans SCADA les produits Siemens","vendor_advisories":[{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 SCADA Siemens ssa-824231 du 20 mars 2018","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-824231.pdf"},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 SCADA Siemens ssa-592007 du 20 mars 2018","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-592007.pdf"},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 SCADA Siemens ssa-822928 du 20 mars 2018","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-822928.pdf"}]}
