Close Menu
World Forbes – Business, Tech, AI & Global Insights
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
What's Hot

Berliners swim in the Spree River to protest 100-year ban

June 17, 2025

Juneteenth highlights tribal slavery descendants’ citizenship struggle

June 17, 2025

Weeds can give us clues about the lawn

June 17, 2025
Facebook X (Twitter) Instagram
Trending
  • Berliners swim in the Spree River to protest 100-year ban
  • Juneteenth highlights tribal slavery descendants’ citizenship struggle
  • Weeds can give us clues about the lawn
  • Trump Just Disclosed Earning $57.4 Million From World Liberty Financial—Here’s What We Know
  • How the humble water gun became the symbol of Barcelona’s anti-tourism movement
  • Recipe for Nigerian-inspired fried rice is easy for a weeknight
  • Amusement parks face tariffs and economic uncertainty
  • Appalachian Trail thru-hikers take on half-gallon ice cream eating challenge
World Forbes – Business, Tech, AI & Global InsightsWorld Forbes – Business, Tech, AI & Global Insights
Tuesday, June 17
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
World Forbes – Business, Tech, AI & Global Insights
Home » ICS Patch Tuesday: Advisories Published by CISA, Schneider Electric, Siemens 
Cybersecurity

ICS Patch Tuesday: Advisories Published by CISA, Schneider Electric, Siemens 

adminBy adminMarch 12, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email
Post Views: 48


Industrial giants Siemens and Schneider Electric have released their March 2025 Patch Tuesday ICS security advisories. The cybersecurity agency CISA has also published two advisories. 

Schneider Electric has published three new advisories to inform customers about three vulnerabilities affecting EcoStruxure products.

The most serious is a critical issue in Power Automation System User Interface and Microgrid Operation Large that can be exploited by an attacker to execute commands when the default password has not been changed. 

The other vulnerabilities are a high-severity authentication bypass that can allow an attacker to take control of the EcoStruxure Power Automation System User Interface, and a medium-severity sensitive information disclosure issue in EcoStruxure Panel Server. 

Siemens has published 11 new advisories, including several that describe critical vulnerabilities. 

One of them is CVE-2024-56336, which is related to an unlocked bootloader in the Sinamics S200 servo drive system. It allows an attacker to inject malicious code or install untrusted firmware on a device. 

A critical vulnerability has also been patched in the SiPass controller, which can be exploited to escalate privileges and execute arbitrary commands with root permissions. A high-severity privilege escalation flaw has also been patched in this product.

Critical and high-severity vulnerabilities that can allow authentication bypass have been fixed in Simatic, Industrial Edge for Machine Tools, Simit, and other products that use OPC UA.

Advertisement. Scroll to continue reading.

Several OpenVPN issues, including critical flaws that allow arbitrary code execution, have been addressed in Sinema Remote Connect Client. A less serious OpenVPN issue has been addressed in Scalance devices. 

Siemens has also informed customers about high-severity BIOS vulnerabilities in Simatic devices, and multiple potentially serious issues in Scalance LPE9403 products. Several high-severity vulnerabilities related to file parsing have been patched in Teamcenter Visualization and Tecnomatix Plant Simulation. 

CISA published two new ICS advisories on Tuesday. One of them describes three vulnerabilities in two Optigo Networks capture tools. They include a critical authentication bypass flaw, and two high-severity issues that can allow an attacker to generate JWT sessions and impersonate the web application service and mislead victim clients. 

The second advisory describes a Schneider Electric Uni-Telway Driver vulnerability that the vendor patched in February. 

Related: ICS Patch Tuesday: Vulnerabilities Addressed by Schneider Electric, Siemens

Related: ICS Patch Tuesday: Security Advisories Published by Schneider, Siemens, Phoenix Contact, CISA



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

O2 Service Vulnerability Exposed User Location

May 20, 2025

Madhu Gottumukkala Officially Announced as CISA Deputy Director

May 20, 2025

BreachRx Lands $15 Million as Investors Bet on Breach-Workflow Software

May 19, 2025

Printer Company Procolored Served Infected Software for Months

May 19, 2025

UK Legal Aid Agency Finds Data Breach Following Cyberattack

May 19, 2025

480,000 Catholic Health Patients Impacted by Serviceaide Data Leak

May 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Don't Miss
Billionaires

Trump Just Disclosed Earning $57.4 Million From World Liberty Financial—Here’s What We Know

June 16, 2025

Topline President Donald Trump earned $57.4 million from World Liberty Financial, a crypto company he…

Private Equity’s First Woman Billionaire Owns San Diego Soccer Team

June 11, 2025

Billionaire Walmart Heiress Urges People To ‘Mobilize’ At June 14 Anti-Trump Protests

June 11, 2025

Anduril Cofounder Trae Stephens Is Now A Billionaire

June 10, 2025
Our Picks

Berliners swim in the Spree River to protest 100-year ban

June 17, 2025

Juneteenth highlights tribal slavery descendants’ citizenship struggle

June 17, 2025

Weeds can give us clues about the lawn

June 17, 2025

Trump Just Disclosed Earning $57.4 Million From World Liberty Financial—Here’s What We Know

June 16, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to World-Forbes.com
At World-Forbes.com, we bring you the latest insights, trends, and analysis across various industries, empowering our readers with valuable knowledge. Our platform is dedicated to covering a wide range of topics, including sports, small business, business, technology, AI, cybersecurity, and lifestyle.

Our Picks

After Klarna, Zoom’s CEO also uses an AI avatar on quarterly call

May 23, 2025

Anthropic CEO claims AI models hallucinate less than humans

May 22, 2025

Anthropic’s latest flagship AI sure seems to love using the ‘cyclone’ emoji

May 22, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 world-forbes. Designed by world-forbes.

Type above and press Enter to search. Press Esc to cancel.