ICS/OT

ICS Patch Tuesday: Advisories Published by Siemens, Schneider Electric, Aveva, CISA

Several ICS vendors released advisories on Tuesday to inform customers about vulnerabilities found in their industrial and OT products. 

ICS Patch Tuesday

The June 2024 Patch Tuesday brings advisories from several ICS vendors, including Siemens, Schneider Electric and Aveva, as well as the US cybersecurity agency CISA.

Siemens

Siemens has published 14 new advisories that cover more than 120 vulnerabilities. The company has made available patches and/or mitigations for these security holes. 

A majority of the flaws impact third-party components and their existence has been known since at least last year. 

The list of noteworthy vulnerabilities includes a critical authentication bypass flaw in the PowerSys service program for PowerLink 50/100 and SWT 3000 devices. This weakness allows a local attacker to gain admin privileges for the managed remote devices.

Siemens has also addressed high-severity code execution vulnerabilities in Tecnomatix Plant Simulation, Teamcenter Visualization, JT2Go, and SICAM AK3/TM/BC devices. 

Advertisement. Scroll to continue reading.

High-severity issues have also been resolved in Simatic S7-200 devices and Sinec Traffic Analyzer. 

Aveva

Industrial software maker Aveva published two new security advisories on Tuesday. One of them informs customers about a high-severity local code execution vulnerability in the PI Asset Framework (AF) Client.

The second advisory covers a high-severity remote code execution vulnerability impacting the PI Web API. Both flaws are related to the deserialization of untrusted data. 

Schneider Electric

Schneider Electric has published five new advisories describing a total of 11 vulnerabilities.

Six flaws have been patched by the industrial giant in SAGE RTUs, including a critical authentication bypass vulnerability, two high-severity issues that can be exploited to cause disruption and for unauthorized file or firmware uploads, and three medium-severity DoS flaws.

The remaining advisories published by Schneider on Tuesday address medium-severity flaws found in Modicon M340 programmable automation controllers, PowerLogic P5 protection relays, EVlink Home Smart EV charging stations, and SpaceLogic controllers.

Exploitation of these vulnerabilities can lead to unauthorized firmware updates, device hijacking, DoS attacks, exposure of the local network, privilege escalation, and the exposure of sensitive information.

CISA

CISA on Tuesday published several ICS advisories, including for a high-severity DoS vulnerability in Rockwell Automation ControlLogix, GuardLogix, and CompactLogix controllers, a critical code execution and data exposure issue in Intrado 911 Emergency Gateway, and two high-severity information disclosure and code execution flaws in MicroDicom medical software. 

Related: Cisco Finds 15 Vulnerabilities in AutomationDirect PLCs

Related: ICS Patch Tuesday: Advisories Published by Siemens, Rockwell, Mitsubishi Electric

Related Content

Artificial Intelligence

A cybersecurity advisory with technical details and recommendations has been written by the NSA, CISA and other agencies.

ICS/OT

CISA has also published several advisories describing vulnerabilities in ICS and other OT products.

ICS/OT

Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states.

ICS/OT

CERT.PL said this appears to be the first instance of a private APN being used as an attack vector.

ICS/OT

NMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities.

ICS/OT

Georgia has been confirmed as one of the attacked states after Clayton County reported a pump station disruption.

ICS/OT

The grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure.

ICS/OT

Michigan, South Dakota, and Georgia are reportedly on the list of states whose water systems have been targeted by Iran-linked hackers.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version