April 11, 2023, midnight |

Siemens ProductCERT Security Advisories cert-portal.siemens.com

The Adaptec Maxview application shipped with affected SIMATIC IPCs contains a hard coded, non-unique certificate to secure HTTPS connections between the browser and the local Maxview configuration application. A local attacker may use this key to decrypt intercepted local traffic between the browser and the application and could perform a man-in-the-middle attack in order to modify data in transit.


Adaptec has released updates for the affected products and recommends to update to the latest versions. Siemens recommends countermeasures for products …

application attack browser certificate configuration connections countermeasures data decrypt hard hard coded https key keys latest local man-in-the-middle may non order private private keys products siemens simatic ssa tls traffic update updates

More from cert-portal.siemens.com / Siemens ProductCERT Security Advisories

Azure DevSecOps Cloud Engineer II

@ Prudent Technology | McLean, VA, USA

Security Engineer III - Python, AWS

@ JPMorgan Chase & Co. | Bengaluru, Karnataka, India

SOC Analyst (Threat Hunter)

@ NCS | Singapore, Singapore

Managed Services Information Security Manager

@ NTT DATA | Sydney, Australia

Senior Security Engineer (Remote)

@ Mattermost | United Kingdom

Penetration Tester (Part Time & Remote)

@ TestPros | United States - Remote