A handful of vulnerabilities in Siemens SiPass integrated server have been patched. One allows an attacker to bypass authentication on the box. SiPass is the company s integrated access control server managing physical access in a number of industries and use cases. Users should update the server immediately to V2.70 as all prior versions are affected, ICS-CERT said. The company also patched two vulnerabilities in its SIMATIC SmartClient Android apps that enable remote operating and management of SIMATic Human Machine Interface systems.
Source: https://threatpost.com/siemens-patches-authentication-bypass-flaw-in-sipass-server/126848/

