Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

Siemens, Schneider Electric Release First ICS Patch Tuesday Advisories of 2024

Industrial giants Siemens and Schneider Electric publish a total of 7 new security advisories addressing 22 vulnerabilities. 

ICS Patch Tuesday

On the first Patch Tuesday of 2024, industrial giants Siemens and Schneider Electric have released a total of only seven new security advisories, announcing fixes for 22 vulnerabilities. 

Siemens has published six new advisories covering 21 vulnerabilities. The most serious, based on its CVSS score of 10, is a vulnerability in Simatic IPCs, specifically the Redfish server component of MaxView Storage Manager. Microchip has released a patch for its MaxView product and users have been advised to install it.

Siemens has also informed customers about critical and high-severity Simatic CN 4100 vulnerabilities that can be exploited to remotely take control of a device. 

The company also patched a dozen vulnerabilities in Solid Edge 2023. These appear to be related to variations of an attack method involving PAR files — attackers could execute arbitrary code by getting the victim to open specially crafted files. 

Security holes related to the processing of specially crafted files — this time CGM files — were also addressed in the Teamcenter Visualization and JT2Go products.

In addition, Siemens has patched a vulnerability in Spectrum Power 7 that could allow arbitrary code injection and root access to the system, but exploitation requires local access with admin privileges. 

Advertisement. Scroll to continue reading.

A medium-severity issue in Sicam A8000 devices has been patched to prevent authenticated attackers from injecting commands that would get executed on the device with root privileges during startup.

Schneider Electric has only published one new advisory, to inform customers about a high-severity Easergy Studio vulnerability that could “allow an attacker logged in with a user level account to gain higher privileges by providing a harmful serialized object”.

Related: ICS Patch Tuesday: 90 Vulnerabilities Addressed by Siemens and Schneider Electric

Related: ICS Patch Tuesday: Electromagnetic Fault Injection, Critical Redis Vulnerability

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Opal Security has appointed CPO, CTO, VP of Field Engineering, VP of Marketing, and Head of Product and Solutions Marketing.

The Department of the Air Force has appointed Ashley Devoto as Chief Information Officer.

Bartley Richardson has been named Chief AI and Autonomous Systems Officer at CrowdStrike.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.