ICS/OT

ICS Patch Tuesday: Advisories Published by Siemens, Schneider Electric, Aveva, CISA

Several ICS vendors released advisories on Tuesday to inform customers about vulnerabilities found in their industrial and OT products. 

ICS Patch Tuesday

The June 2024 Patch Tuesday brings advisories from several ICS vendors, including Siemens, Schneider Electric and Aveva, as well as the US cybersecurity agency CISA.

Siemens

Siemens has published 14 new advisories that cover more than 120 vulnerabilities. The company has made available patches and/or mitigations for these security holes. 

A majority of the flaws impact third-party components and their existence has been known since at least last year. 

The list of noteworthy vulnerabilities includes a critical authentication bypass flaw in the PowerSys service program for PowerLink 50/100 and SWT 3000 devices. This weakness allows a local attacker to gain admin privileges for the managed remote devices.

Siemens has also addressed high-severity code execution vulnerabilities in Tecnomatix Plant Simulation, Teamcenter Visualization, JT2Go, and SICAM AK3/TM/BC devices. 

Advertisement. Scroll to continue reading.

High-severity issues have also been resolved in Simatic S7-200 devices and Sinec Traffic Analyzer. 

Aveva

Industrial software maker Aveva published two new security advisories on Tuesday. One of them informs customers about a high-severity local code execution vulnerability in the PI Asset Framework (AF) Client.

The second advisory covers a high-severity remote code execution vulnerability impacting the PI Web API. Both flaws are related to the deserialization of untrusted data. 

Schneider Electric

Schneider Electric has published five new advisories describing a total of 11 vulnerabilities.

Six flaws have been patched by the industrial giant in SAGE RTUs, including a critical authentication bypass vulnerability, two high-severity issues that can be exploited to cause disruption and for unauthorized file or firmware uploads, and three medium-severity DoS flaws.

The remaining advisories published by Schneider on Tuesday address medium-severity flaws found in Modicon M340 programmable automation controllers, PowerLogic P5 protection relays, EVlink Home Smart EV charging stations, and SpaceLogic controllers.

Exploitation of these vulnerabilities can lead to unauthorized firmware updates, device hijacking, DoS attacks, exposure of the local network, privilege escalation, and the exposure of sensitive information.

CISA

CISA on Tuesday published several ICS advisories, including for a high-severity DoS vulnerability in Rockwell Automation ControlLogix, GuardLogix, and CompactLogix controllers, a critical code execution and data exposure issue in Intrado 911 Emergency Gateway, and two high-severity information disclosure and code execution flaws in MicroDicom medical software. 

Related: Cisco Finds 15 Vulnerabilities in AutomationDirect PLCs

Related: ICS Patch Tuesday: Advisories Published by Siemens, Rockwell, Mitsubishi Electric

Related Content

Application Security

OSS Scanner sends unreviewed, model-generated vulnerability reports to open source maintainers that opt in.

ICS/OT

Revision 4 of NIST’s operational technology security guide is open for public comments until November 30.

ICS/OT

Only 21% of industrial security leaders report a complete OT asset inventory, even as 88% call their programs mature.

ICS/OT

The hackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles, officials said. 

ICS/OT

AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products.

ICS/OT

The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.

Artificial Intelligence

Forescout researchers used Claude AI to port a remote code execution exploit between WAGO PLC models.

Government

The White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version