Siemens released a dozen advisories covering more than 30 vulnerabilities this Patch Tuesday, but Schneider Electric has only published one advisory to inform customers about one flaw.
Siemens has published three advisories describing serious vulnerabilities patched in its Ruggedcom products.
One advisory covers five vulnerabilities, including four rated ‘critical’ and ‘high severity’, in the Ruggedcom Crossbow server application. The weaknesses can be exploited to cause a DoS condition, escalate privileges, execute arbitrary SQL queries on the database, and write arbitrary files to the targeted system. The issues were discovered by the UK’s National Cyber Security Centre (NCSC).
Siemens also informed customers about a critical mirror port isolation vulnerability in Ruggedcom ROS devices.
“The affected products insufficiently block data from being forwarded over the mirror port into the mirrored network,” the vendor explained. “An attacker could use this behavior to transmit malicious packets to systems in the mirrored network, possibly influencing their configuration and runtime behavior.”
ROS devices are also impacted by a high-severity DoS vulnerability, which has been covered by Siemens in a separate advisory.
The industrial giant informed customers about several high-severity vulnerabilities that can be exploited using specially crafted files. Impacted products include Sicam Toolbox II, Parasolid, Teamcenter Visualization, JT2Go, JT Open, JT Utilities, Solid Edge, and Siemens Software Center (SSC).
Two of Siemens’ advisories describe the impact of two medium and high-severity OpenSSL vulnerabilities on its Simatic products.
Schneider Electric has only released one new advisory this Patch Tuesday, to inform customers about a medium-severity memory corruption issue affecting the Pro-face GP-Pro EX HMI screen editor and logic programming software.
Related: ICS Patch Tuesday: Siemens, Schneider Electric Fix 50 Vulnerabilities
Related: ICS Patch Tuesday: Siemens Addresses Over 180 Third-Party Component Vulnerabilities
https://www.securityweek.com/ics-patch-tuesday-siemens-fixes-7-vulnerabilities-in-ruggedcom-products/