Showing posts with label Siemens. Show all posts
Showing posts with label Siemens. Show all posts

Tuesday, July 28, 2026

Review – 7 Advisories Published – 7-28-26

Today CISA’s NCCIC-ICS published seven control system security advisories for products from ABB, igloohome, MikroTik, and Siemens (4). 

Advisories  

ABB Advisory - This advisory describes a missing support for integrity check vulnerability in the ABB KNX Update Tool. The ABB advisory reports that: “As classic KNX technology did not include built-in encryption, this vulnerability is not specific to ABB products and cannot be addressed through a software update.” 

Igloohome Advisory - This advisory describes an inclusion of sensitive information in source code vulnerability in the igloohome Smart Lock Mobile Application (Android). 

MikroTik Advisory - This advisory describes an improper restriction of excessive authentication attempts vulnerability in the MikroTik RouterOS and MikroTik Cloud Hosted Router. 

Siemens Advisory #1 - This advisory discusses more than 353 GNU/Linux vulnerabilities in the Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP. 

Siemens Advisory #2 - This advisory describes an allocation of resources without limit or throttling vulnerability in the Siemens SIMATIC S7-PLCSIM Advanced. 

Siemens Advisory #3 - This advisory describes an insecure inherited permissions vulnerability in the Siemens Mendix Runtime product. 

Siemens Advisory #4 - This advisory discusses an out-of-bounds write vulnerability in the Siemens Desigo CC products. 


For more information on these advisories, including DTRH looks at the Mendix vulnerability and Desigo CC exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-published-7-28-26 - subscription required. 

Thursday, July 23, 2026

CISA Updates Iranian PLC Attacks Advisory – 7-22-26

Yesterday, CISA announced that they had updated their Joint Cybersecurity Advisory on “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure that had originally been published on April 7th, 2026. The new information included expanding the list of affected products to include systems from Schneider Electric and Siemens and includes updated indicators of compromise information (XML and JSON). 

I do not typically cover these Joint Cybersecurity Advisories, but the Technical Details section of the report included the following comment: 

“After the actors extracted device project files, the FBI and CISA identified the modification and deletion of project file logic, to include Add-On Instructions (AOIs) and data manipulation on HMI and SCADA displays (T1565). Additionally, the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies.” 

As a former process chemist, that claim certainly caught my attention and raised the stakes considerably. 

The Joint Advisory references two supporting vendor advisories for products from Rockwell Automation and Siemens. Siemens updated that advisory today, adding S7-1200 PLC as targeted device based on the CISA advisory update as well as references to S7-1200 G1, S7-1200 G2, S7-1500 user manuals. They did not, however, remove the following comment: 

“At this point in time, we have not observed any exploitation of vulnerabilities (emphasis added) in Siemens industrial control system (ICS) products.” 

Neither CISA nor the vendors have identified a specific, correctable vulnerability involved in these attacks. 

Tuesday, July 21, 2026

Review – 10 Advisories Published – 7-21-26

Today CISA’s NCCIC-ICS published ten control system security advisories for products from Rockwell Automation (4), Siemens (5), and Tycon Systems. I also take a down-the-rabbit-hole look at exploits for the Siemens CADRA and SIDIS vulnerabilities. 

Advisories  

Rockwell Advisory # 1 - This advisory describes three vulnerabilities in the Rockwell Studio 5000 Logix Designer products. Rockwell published their advisory on July 14th, 2026. 

Rockwell Advisory #2 - This advisory describes an allocation of resources without limit or throttling vulnerability in the Rockwell 1734 POINT I/O. Rockwell published their advisory on July 14th, 2026. 

Rockwell Advisory #3 - This advisory - This advisory describes an allocation of resources without limit or throttling vulnerability in the Rockwell 1718-AENTR/1719-AENTR. Rockwell published their advisory on July 14th, 2026. 

Rockwell Advisory #4 - This advisory describes a weak authentication vulnerability in the Rockwell FactoryTalk Services Platform. Rockwell published their advisory on July 14th, 2026. 

Siemens Advisory #1 - This advisory discusses 11 vulnerabilities in the Siemens CADRA design drafting software. Siemens published their advisory on July 14th, 2026. 

NOTE: See DTRH below for exploitable vulnerabilities. 

Siemens Advisory #2 - This advisory describes an untrusted search path vulnerability in the Siemens IAM Client products. Siemens published their advisory on July 14th, 2026. 

Siemens Advisory #3 - This advisory discusses 12 vulnerabilities in the Siemens SIDIS Secured SmartPlug. Siemens published their advisory on July 14th, 2026. 

NOTE: See DTRH below for exploitable vulnerabilities. 

Siemens Advisory #4 - This advisory describes an improper verification of cryptographic signature vulnerability in the Siemens Opcenter X. Siemens published their advisory on July 14th, 2026. 

Siemens Advisory #5 - This advisory discusses three vulnerabilities in the Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW. Siemens published their advisory on July 14th, 2026. 

Tycon Advisory - This advisory describes two vulnerabilities in the Tycon TPDIN-Monitor-WEB2. 


For more information on these advisories, as well as links for exploits for the Siemens CADRA and SIDIS vulnerabilities, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/10-advisories-published-7-21-26 - subscription required. 

 
/* Use this with templates/template-twocol.html */