Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Rockwell, Aveva, Schneider

An Aveva vulnerability also impacts Schneider Electric products and both vendors have published advisories.

ICS Patch Tuesday

Industrial giants Siemens, Schneider Electric, Rockwell Automation, and Aveva have released Patch Tuesday advisories informing customers about vulnerabilities in their ICS/OT products.

Siemens published six new advisories. One of them covers two vulnerabilities in the Comos plant engineering software, including a critical code execution flaw, and a high-severity security bypass issue.

Vulnerabilities have also been addressed in Siemens Solid Edge (remote MitM, code execution), Altair Grid Engine (code execution), Logo! 8 BM (code execution, DoS, settings tampering), and Sicam P850 (CSRF) products.

Rockwell Automation published five new advisories on November 11, each covering high-severity vulnerabilities found in various products. 

The company informed customers of its Verve Asset Manager OT security platform that the product is affected by a high-severity access control issue that allows unauthorized read-only users to tamper with other user accounts via an API.

In the Studio 5000 integrated design environment for Logix 5000 controllers, Rockwell fixed an SSRF flaw exposing NTLM hashes, as well as a local code execution bug.

Advertisement. Scroll to continue reading.

MFA bypass and persistent XSS vulnerabilities have been patched in FactoryTalk DataMosaix Private Cloud. In addition, flaws introduced by the use of third-party components have been fixed in SIS Workstation (code execution) and FactoryTalk Policy Manager (DoS).

Aveva published two new advisories on Tuesday. One of them describes a high-severity persistent XSS flaw that can be exploited for privilege escalation. 

The second advisory covers an Aveva Edge vulnerability that allows an attacker with read access to project and cache files to obtain user passwords by brute-forcing weak hashes.

This vulnerability also impacts Schneider Electric’s EcoStruxure Machine SCADA Expert & Pro-face BLUE Open Studio products. Schneider published two new advisories this Patch Tuesday and one of them covers the impact of this flaw. 

Schneider’s second advisory describes high-severity path traversal, authentication brute-forcing, and privilege escalation issues in the PowerChute Serial Shutdown UPS management software.

Moxa, ABB, Honeywell, and Mitsubishi Electric did not publish any advisories on Patch Tuesday, but they all informed customers about fixed vulnerabilities in the preceding days. Germany’s VDE@CERT also published two advisories in recent days. 

Related: ICS Patch Tuesday: Fixes Announced by Siemens, Schneider, Rockwell, ABB, Phoenix Contact

Related: ICS Patch Tuesday: Rockwell Automation Leads With 8 Security Advisories

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

Tim Byrd has been appointed Chief Information Security Officer at First Citizens Bank.

IRONSCALES has named Steve McKenzie as Chief Operating Officer.

Silvio Pappalardo has joined AuthMind as Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.