Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

ICS Patch Tuesday: Siemens Fixes 7 Vulnerabilities in Ruggedcom Products

ICS Patch Tuesday: Siemens releases a dozen advisories covering over 30 vulnerabilities, but Schneider Electric has only published one advisory.

ICS Patch Tuesday

Siemens released a dozen advisories covering more than 30 vulnerabilities this Patch Tuesday, but Schneider Electric has only published one advisory to inform customers about one flaw.

Siemens has published three advisories describing serious vulnerabilities patched in its Ruggedcom products. 

One advisory covers five vulnerabilities, including four rated ‘critical’ and ‘high severity’, in the Ruggedcom Crossbow server application. The weaknesses can be exploited to cause a DoS condition, escalate privileges, execute arbitrary SQL queries on the database, and write arbitrary files to the targeted system. The issues were discovered by the UK’s National Cyber Security Centre (NCSC).

Siemens also informed customers about a critical mirror port isolation vulnerability in Ruggedcom ROS devices. 

“The affected products insufficiently block data from being forwarded over the mirror port into the mirrored network,” the vendor explained. “An attacker could use this behavior to transmit malicious packets to systems in the mirrored network, possibly influencing their configuration and runtime behavior.”

ROS devices are also impacted by a high-severity DoS vulnerability, which has been covered by Siemens in a separate advisory.

Advertisement. Scroll to continue reading.

The industrial giant informed customers about several high-severity vulnerabilities that can be exploited using specially crafted files. Impacted products include Sicam Toolbox II, Parasolid, Teamcenter Visualization, JT2Go, JT Open, JT Utilities, Solid Edge, and Siemens Software Center (SSC).

Two of Siemens’ advisories describe the impact of two medium and high-severity OpenSSL vulnerabilities on its Simatic products. 

Schneider Electric has only released one new advisory this Patch Tuesday, to inform customers about a medium-severity memory corruption issue affecting the Pro-face GP-Pro EX HMI screen editor and logic programming software.

Learn More at SecurityWeek’s ICS Cyber Security Conference
The leading global conference series for Operations, Control Systems and OT/IT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.
ICS Cybersecurity Conference
October 23-26, 2023 | Atlanta
www.icscybersecurityconference.com

Related: ICS Patch Tuesday: Siemens, Schneider Electric Fix 50 Vulnerabilities

Related: ICS Patch Tuesday: Siemens Addresses Over 180 Third-Party Component Vulnerabilities

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

SolarWinds has appointed Justin Henkel as Chief Information Security Officer.

J. Paul Haynes has joined Cinchy as Chief Executive Officer.

Hatem Naguib has become Chief Executive Officer at Sysdig.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.