ICS/OT

ICS Patch Tuesday: Siemens Fixes 7 Vulnerabilities in Ruggedcom Products

ICS Patch Tuesday: Siemens releases a dozen advisories covering over 30 vulnerabilities, but Schneider Electric has only published one advisory.

ICS Patch Tuesday

Siemens released a dozen advisories covering more than 30 vulnerabilities this Patch Tuesday, but Schneider Electric has only published one advisory to inform customers about one flaw.

Siemens has published three advisories describing serious vulnerabilities patched in its Ruggedcom products. 

One advisory covers five vulnerabilities, including four rated ‘critical’ and ‘high severity’, in the Ruggedcom Crossbow server application. The weaknesses can be exploited to cause a DoS condition, escalate privileges, execute arbitrary SQL queries on the database, and write arbitrary files to the targeted system. The issues were discovered by the UK’s National Cyber Security Centre (NCSC).

Siemens also informed customers about a critical mirror port isolation vulnerability in Ruggedcom ROS devices. 

“The affected products insufficiently block data from being forwarded over the mirror port into the mirrored network,” the vendor explained. “An attacker could use this behavior to transmit malicious packets to systems in the mirrored network, possibly influencing their configuration and runtime behavior.”

ROS devices are also impacted by a high-severity DoS vulnerability, which has been covered by Siemens in a separate advisory.

Advertisement. Scroll to continue reading.

The industrial giant informed customers about several high-severity vulnerabilities that can be exploited using specially crafted files. Impacted products include Sicam Toolbox II, Parasolid, Teamcenter Visualization, JT2Go, JT Open, JT Utilities, Solid Edge, and Siemens Software Center (SSC).

Two of Siemens’ advisories describe the impact of two medium and high-severity OpenSSL vulnerabilities on its Simatic products. 

Schneider Electric has only released one new advisory this Patch Tuesday, to inform customers about a medium-severity memory corruption issue affecting the Pro-face GP-Pro EX HMI screen editor and logic programming software.

Learn More at SecurityWeek’s ICS Cyber Security Conference
The leading global conference series for Operations, Control Systems and OT/IT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

October 23-26, 2023 | Atlanta
www.icscybersecurityconference.com

Related: ICS Patch Tuesday: Siemens, Schneider Electric Fix 50 Vulnerabilities

Related: ICS Patch Tuesday: Siemens Addresses Over 180 Third-Party Component Vulnerabilities

Related Content

ICS/OT

Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states.

ICS/OT

CERT.PL said this appears to be the first instance of a private APN being used as an attack vector.

ICS/OT

NMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities.

ICS/OT

Georgia has been confirmed as one of the attacked states after Clayton County reported a pump station disruption.

ICS/OT

The grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure.

ICS/OT

Michigan, South Dakota, and Georgia are reportedly on the list of states whose water systems have been targeted by Iran-linked hackers.

ICS/OT

CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems.

ICS/OT

The guidance details steps organizations can take to isolate vital OT and supporting systems, and operate in isolation for an extended period.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version