Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

ICS Patch Tuesday: Siemens Fixes 7 Vulnerabilities in Ruggedcom Products

ICS Patch Tuesday: Siemens releases a dozen advisories covering over 30 vulnerabilities, but Schneider Electric has only published one advisory.

ICS Patch Tuesday

Siemens released a dozen advisories covering more than 30 vulnerabilities this Patch Tuesday, but Schneider Electric has only published one advisory to inform customers about one flaw.

Siemens has published three advisories describing serious vulnerabilities patched in its Ruggedcom products. 

One advisory covers five vulnerabilities, including four rated ‘critical’ and ‘high severity’, in the Ruggedcom Crossbow server application. The weaknesses can be exploited to cause a DoS condition, escalate privileges, execute arbitrary SQL queries on the database, and write arbitrary files to the targeted system. The issues were discovered by the UK’s National Cyber Security Centre (NCSC).

Siemens also informed customers about a critical mirror port isolation vulnerability in Ruggedcom ROS devices. 

“The affected products insufficiently block data from being forwarded over the mirror port into the mirrored network,” the vendor explained. “An attacker could use this behavior to transmit malicious packets to systems in the mirrored network, possibly influencing their configuration and runtime behavior.”

ROS devices are also impacted by a high-severity DoS vulnerability, which has been covered by Siemens in a separate advisory.

Advertisement. Scroll to continue reading.

The industrial giant informed customers about several high-severity vulnerabilities that can be exploited using specially crafted files. Impacted products include Sicam Toolbox II, Parasolid, Teamcenter Visualization, JT2Go, JT Open, JT Utilities, Solid Edge, and Siemens Software Center (SSC).

Two of Siemens’ advisories describe the impact of two medium and high-severity OpenSSL vulnerabilities on its Simatic products. 

Schneider Electric has only released one new advisory this Patch Tuesday, to inform customers about a medium-severity memory corruption issue affecting the Pro-face GP-Pro EX HMI screen editor and logic programming software.

Learn More at SecurityWeek’s ICS Cyber Security Conference
The leading global conference series for Operations, Control Systems and OT/IT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.
ICS Cybersecurity Conference
October 23-26, 2023 | Atlanta
www.icscybersecurityconference.com

Related: ICS Patch Tuesday: Siemens, Schneider Electric Fix 50 Vulnerabilities

Related: ICS Patch Tuesday: Siemens Addresses Over 180 Third-Party Component Vulnerabilities

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In cyber-physical systems (CPS), just one hour of downtime can outweigh an entire annual security budget. Learn how to master the Return on Security Investment (ROSI) to align security goals with the bottom-line priorities.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

Malwarebytes has named Chung Ip as Chief Financial Officer.

Semperis has appointed John Podboy as Chief Information Security Officer.

Randy Menon has become Chief Product and Marketing Officer at One Identity.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.