Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

Siemens Wants to Release Security Advisories on Patch Tuesday

Siemens wants to release security advisories on the second Tuesday of every month, similar to Microsoft, Adobe and SAP.

Siemens wants to release security advisories on the second Tuesday of every month, similar to Microsoft, Adobe and SAP.

The company carried out a pilot test last month, when it published a total of 16 advisories – including new advisories and updates to previously posted announcements – on November 13. It’s now hoping to get some feedback and comments from customers on the decision to release advisories on Patch Tuesday, which the company has dubbed “Siemens Advisory Day.”Siemens Patch Tuesday advisories

“We constantly improve our service quality and are eager to give you the best options we can to run your Siemens systems as secure as possible. Our approach with vulnerabilities in our products is to communicate them transparently and responsibly,” Martin Ruf of Siemens ProductCERT told customers via email.

“We want to give you the chance to better plan resources and maintenance windows. Therefore, we decided to publish vulnerabilities once a month. We decided to take the second Tuesday as you might already have service windows aligned to that date in place,” Ruf added. “In case we have reasons to publish advisories out of band (e.g. due to criticality), we will still do so.”

Learn More About ICS Vendor Strategies at SecurityWeek’s ICS Cyber Security Conference

Siemens’ advisories typically inform customers of vulnerabilities, but they don’t always announce the availability of patches. The German industrial giant also uses advisories to tell customers that it’s investigating the impact of specific flaws on its products, that mitigations and workarounds are available for a security hole, or that fixes are in the process of being developed.

One out-of-band advisory was published on November 27, when Siemens revealed that some of the Linux and GNU components of a multifunctional platform for its SIMATIC S7-1500 industrial automation controllers are affected by over 20 vulnerabilities.

It’s not uncommon for Siemens products to be exposed to attacks due to vulnerabilities in third-party components. The list includes several variants of the Meltdown and Spectre vulnerabilities, and the Foreshadow/L1TF flaws.

Related: Flaws in Siemens Tool Put ICS Environments at Risk

Advertisement. Scroll to continue reading.

Related: Flaws Expose Siemens Protection Relays to DoS Attacks

Related: Flaws Expose Siemens Central Plant Clocks to Attacks

Related: Electrical Substations Exposed to Attacks by Flaws in Siemens Devices

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

CISO Strategy

SecurityWeek spoke with more than 300 cybersecurity experts to see what is bubbling beneath the surface, and examine how those evolving threats will present...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

CISO Conversations

Joanna Burkey, CISO at HP, and Kevin Cross, CISO at Dell, discuss how the role of a CISO is different for a multinational corporation...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...