Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list.
Today a blog post from October 10th, 2024, Review – 21 Advisories Published 10-10-24, made the list; actually, it has made the list for the last four days. This was a post about the CISA NCCIC-ICS control system security advisories for the Thursday after Cyber Tuesday. That is the reason for the 21 advisories being covered; including six for products from Rockwell and 13 for products from Siemens. Nothing unusual here, at least until I looked at the companion post over on CFSN Detailed Analysis. That post included the following comment about the Siemens SIMATIC S7-1500 CPUs advisory:
“NOTE: This advisory is a good example of the reason that CISA no longer covers Siemens updates. Of the products listed as being affected by this vulnerability, 88 of them are currently listed on the Siemens Advisory as “Currently no fix is available”. I suspect that fixes for those products will be completed in batches with multiple updates needed to keep customers advised. There is no telling how long that will take, or how many updates will be required.”
Looking back at the latest version of the Siemens Advisory, they published seven updates through October 14th, 2025. That left them with one product, SIMATIC S7-1500 Software Controller Linux V2, with no fix planned. That product is apparently no longer supported. I listed that update in the Bulk Updates – Siemens section of my Public ICS Disclosures – Week of 10-11-25 – Part 2 post.
No comments:
Post a Comment