news.mlab.sh
Back to the feed
threat-intel

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell

High
Summary

This Patch Tuesday saw significant security updates released by Siemens, Schneider Electric, Rockwell Automation, ABB, and Mitsubishi Electric to address a range of vulnerabilities in their industrial control systems (ICS) products. The updates include critical flaws that could lead to unauthorized access, DoS attacks, and data breaches, highlighting the ongoing need for proactive security measures within industrial environments.

This Patch Tuesday saw a flurry of security updates released by several major industrial automation vendors. Siemens published nine advisories, including six with critical vulnerabilities, based on CVSS scores. A particularly serious issue involved a token invalidation vulnerability in Opencenter X, allowing an attacker to bypass authentication and gain full access to the application. Siemens also addressed critical vulnerabilities in Mendix, Sidis Secured SmartPlug, Simatic S7-1500, Cadra, and Desigo CC, many of which stemmed from third-party components.

Schneider Electric released two advisories, including a high-severity vulnerability in their IGSS (Interactive Graphical SCADA System) product, where specially crafted files could be used to execute arbitrary code. The second advisory detailed a high-severity authentication bypass flaw in EcoStruxure Cybersecurity Admin Expert, exploitable by a local attacker to compromise managed devices.

Rockwell Automation published 12 new advisories, including two covering critical vulnerabilities. A critical vulnerability in the 1715 Redundant IO product could allow an unauthenticated attacker to access intrusive CLI commands, enabling them to read or delete files, stop tasks, change IO states, and modify memory. Rockwell also patched three critical DoS security holes in its CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controllers.

ABB and Mitsubishi Electric released information about new flaws over the past month, but did not publish new advisories this Patch Tuesday. CISA distributed three ABB advisories and one Rockwell advisory. Germany’s VDE CERT published five new advisories covering vulnerabilities in Murrelektronik, Mettler Toledo, Codesys, and Wago products.

Read the full article at SecurityWeek