Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Rockwell, Aveva, Schneider

An Aveva vulnerability also impacts Schneider Electric products and both vendors have published advisories.

ICS Patch Tuesday

Industrial giants Siemens, Schneider Electric, Rockwell Automation, and Aveva have released Patch Tuesday advisories informing customers about vulnerabilities in their ICS/OT products.

Siemens published six new advisories. One of them covers two vulnerabilities in the Comos plant engineering software, including a critical code execution flaw, and a high-severity security bypass issue.

Vulnerabilities have also been addressed in Siemens Solid Edge (remote MitM, code execution), Altair Grid Engine (code execution), Logo! 8 BM (code execution, DoS, settings tampering), and Sicam P850 (CSRF) products.

Rockwell Automation published five new advisories on November 11, each covering high-severity vulnerabilities found in various products. 

The company informed customers of its Verve Asset Manager OT security platform that the product is affected by a high-severity access control issue that allows unauthorized read-only users to tamper with other user accounts via an API.

In the Studio 5000 integrated design environment for Logix 5000 controllers, Rockwell fixed an SSRF flaw exposing NTLM hashes, as well as a local code execution bug.

Advertisement. Scroll to continue reading.

MFA bypass and persistent XSS vulnerabilities have been patched in FactoryTalk DataMosaix Private Cloud. In addition, flaws introduced by the use of third-party components have been fixed in SIS Workstation (code execution) and FactoryTalk Policy Manager (DoS).

Aveva published two new advisories on Tuesday. One of them describes a high-severity persistent XSS flaw that can be exploited for privilege escalation. 

The second advisory covers an Aveva Edge vulnerability that allows an attacker with read access to project and cache files to obtain user passwords by brute-forcing weak hashes.

This vulnerability also impacts Schneider Electric’s EcoStruxure Machine SCADA Expert & Pro-face BLUE Open Studio products. Schneider published two new advisories this Patch Tuesday and one of them covers the impact of this flaw. 

Schneider’s second advisory describes high-severity path traversal, authentication brute-forcing, and privilege escalation issues in the PowerChute Serial Shutdown UPS management software.

Moxa, ABB, Honeywell, and Mitsubishi Electric did not publish any advisories on Patch Tuesday, but they all informed customers about fixed vulnerabilities in the preceding days. Germany’s VDE@CERT also published two advisories in recent days. 

Related: ICS Patch Tuesday: Fixes Announced by Siemens, Schneider, Rockwell, ABB, Phoenix Contact

Related: ICS Patch Tuesday: Rockwell Automation Leads With 8 Security Advisories

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Fable Security has appointed Jacob Berry as Chief Information Security Officer.

iCOUNTER has named Ali Waezzadah as Chief Information Security Officer.

Roger Hale has joined 1Kosmos as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.