Industrial giants Siemens, Rockwell Automation, Schneider Electric, and Phoenix Contact have published Patch Tuesday advisories informing customers about vulnerabilities found in their ICS/OT products.
Siemens has published 14 new advisories. An overall severity rating of ‘critical’ has been assigned to three advisories covering dozens of third-party component vulnerabilities affecting Comos, Sicam T, and Ruggedcom ROX products.
A ‘high severity’ rating has been assigned to vulnerabilities found in Siemens Advanced Licensing (SALT) Toolkit, IAM Client (multiple products), Simatic CN 4100, Ruggedcom ROX, Interniche IP-Stack (multiple products), and Sinec Security Monitor.
Medium-severity issues have been addressed in Energy Services, Building X-Security Manager Edge Controller, Gridscale X Prepay, Ruggedcom ROS, and Sinema Remote Connect Server products.
The vulnerabilities can be exploited for arbitrary code execution, denial of service (DoS), unauthorized access, man-in-the-middle (MitM) attacks, and obtaining sensitive information.
Schneider Electric has published two new advisories. One of them describes the impact of an exploited Windows Server Update Services (WSUS) vulnerability on the industrial giant’s EcoStruxure Foxboro DCS product. The second advisory covers the impact of the old ZombieLoad vulnerability on the same EcoStruxure product.
Rockwell Automation has also published two new advisories. One of them covers a high-severity DoS issue affecting the 432ES-IG3 Series A GuardLink EtherNet/IP interface. The second advisory describes a high-severity SQL injection in FactoryTalk DataMosaix Private Cloud.
Phoenix Contact has published one advisory, describing multiple XSS, DoS, authentication, and information exposure vulnerabilities found in its FL SWITCH 2xxx series switches.
The Phoenix Contact advisory has also been picked up by Germany’s VDE CERT.
CISA published three new advisories. Each of them describes one vulnerability affecting CCTV cameras in India (missing authentication), Festo LX Appliance (XSS), and U-Boot (code execution).
Related: ICS Patch Tuesday: Fixes Announced by Siemens, Schneider, Rockwell, ABB, Phoenix Contact
Related: Global Cyber Agencies Issue AI Security Guidance for Critical Infrastructure OT
Related: ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Rockwell, Aveva, Schneider

