Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Rockwell, Schneider

Dozens of vulnerabilities have been patched by the industrial giants across their products.

ICS Patch Tuesday

Industrial giants Siemens, Rockwell Automation, Schneider Electric, and Phoenix Contact have published Patch Tuesday advisories informing customers about vulnerabilities found in their ICS/OT products.

Siemens has published 14 new advisories. An overall severity rating of ‘critical’ has been assigned to three advisories covering dozens of third-party component vulnerabilities affecting Comos, Sicam T, and Ruggedcom ROX products. 

A ‘high severity’ rating has been assigned to vulnerabilities found in Siemens Advanced Licensing (SALT) Toolkit, IAM Client (multiple products), Simatic CN 4100, Ruggedcom ROX, Interniche IP-Stack (multiple products), and Sinec Security Monitor.

Medium-severity issues have been addressed in Energy Services, Building X-Security Manager Edge Controller, Gridscale X Prepay, Ruggedcom ROS, and Sinema Remote Connect Server products.

The vulnerabilities can be exploited for arbitrary code execution, denial of service (DoS), unauthorized access, man-in-the-middle (MitM) attacks, and obtaining sensitive information. 

Schneider Electric has published two new advisories. One of them describes the impact of an exploited Windows Server Update Services (WSUS) vulnerability on the industrial giant’s EcoStruxure Foxboro DCS product. The second advisory covers the impact of the old ZombieLoad vulnerability on the same EcoStruxure product.

Advertisement. Scroll to continue reading.

Rockwell Automation has also published two new advisories. One of them covers a high-severity DoS issue affecting the 432ES-IG3 Series A GuardLink EtherNet/IP interface. The second advisory describes a high-severity SQL injection in FactoryTalk DataMosaix Private Cloud.

Phoenix Contact has published one advisory, describing multiple XSS, DoS, authentication, and information exposure vulnerabilities found in its FL SWITCH 2xxx series switches. 

The Phoenix Contact advisory has also been picked up by Germany’s VDE CERT

CISA published three new advisories. Each of them describes one vulnerability affecting CCTV cameras in India (missing authentication), Festo LX Appliance (XSS), and U-Boot (code execution). 

Related: ICS Patch Tuesday: Fixes Announced by Siemens, Schneider, Rockwell, ABB, Phoenix Contact

Related: Global Cyber Agencies Issue AI Security Guidance for Critical Infrastructure OT

Related: ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Rockwell, Aveva, Schneider

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

With "Shadow AI" usage becoming prevalent in organizations, learn how to balance the need for rapid experimentation with the rigorous controls required for enterprise-grade deployment.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

Neill Feather has been named Chief Executive Officer at Point Wild.

Oasis Security has appointed Michael DeCesare as President.

Sterling Wilson has joined IGEL as Global Field CTO, Business Continuity and Disaster Recovery.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.