Patch Tuesday: Siemens, Schneider, Rockwell patch ICS flaws
Siemens, Schneider Electric and Rockwell Automation issued July Patch Tuesday advisories fixing multiple critical and high-severity vulnerabilities in industrial control system products.
On Tuesday, Siemens, Schneider Electric and Rockwell Automation published July Patch Tuesday advisories addressing multiple vulnerabilities in industrial control system software and controllers, including several rated critical.
Siemens posted nine advisories, six of them rated critical. One of the most severe is a token invalidation vulnerability in Opencenter X with a CVSS score of 10 that can be used to bypass authentication and grant full access to the application. Siemens also provided fixes for Mendix, Sidis Secured SmartPlug, Simatic S7-1500, Cadra and Desigo CC, and reported high-severity updates for Simatic S7-PLCSIM, Ruggedcom APE1808, Comos, Designcenter, Simcenter, Solid Edge and Tecnomatrix.
Schneider Electric released two advisories. One describes a high-severity flaw in the IGSS interactive graphical SCADA system where specially crafted files can lead to arbitrary code execution. The other details a high-severity authentication bypass in EcoStruxure Cybersecurity Admin Expert that can be exploited locally to affect managed devices.
Rockwell Automation published 12 advisories, including two classified as critical. A critical vulnerability in the 1715 Redundant IO product can allow an unauthenticated attacker to access intrusive command-line interface functions, enabling actions such as reading or deleting files, stopping tasks, changing IO states and modifying memory. Rockwell also patched three critical denial-of-service vulnerabilities that could trigger major non-recoverable faults in CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix controllers. Additional Rockwell updates address high-severity issues in Flex 5000 Adapter, FactoryTalk DataMosaix, FactoryTalk Services Platform, Arena, ThinManager, Studio 5000 Logix Designer, 1756-EN, 1734 POINT I/O and 1719-AENTR.
Vendors reported that many of the flaws stem from third-party components embedded in their products. Depending on the specific vulnerability and product, the issues can be exploited to cause service outages, execute code, bypass authentication, access sensitive data or escalate privileges.
ABB and Mitsubishi Electric did not publish new advisories on Tuesday. Both companies have notified customers in the past month about other critical and high-severity issues.
The U.S. Cybersecurity and Infrastructure Security Agency distributed three ABB advisories and one Rockwell advisory on Tuesday. Germany’s VDE CERT posted five advisories covering products from Murrelektronik, Mettler Toledo, Codesys and Wago.
Where available, the advisories include patches, recommended configurations and mitigation steps. They list affected version numbers, update procedures and temporary workarounds for environments that cannot apply immediate patches.
Operators running affected ICS software and controllers are being urged to review the advisories, verify firmware and software versions on equipment, stage updates and test changes in controlled environments before wider deployment.
Vendors continue to publish monthly security advisories to notify customers and provide fixes for newly discovered vulnerabilities.








