Vulnerabilities are weaknesses or flaws in systems, software, hardware, configurations, or processes that adversaries can exploit to compromise confidentiality, integrity, or availability. The concept underpins vulnerability management, regulatory compliance, risk assessment, and security investment decisions across enterprise IT, cloud, and operational technology environments.
CISA will no longer update advisories for Siemens vulnerabilities. Two critical vulnerabilities in COMOS were identified, allowing for potential code execution and data infiltration. Siemens recommends updating to version 10.4.5 or later and provides mitigations to reduce risks of exploitation.
Siemens has identified a vulnerability in Solid Edge SE2025 that allows man-in-the-middle attacks due to improper certificate validation. Users are advised to update to V225.0 Update 11 or later versions and implement protective measures to minimize exploitation risks.
General Industrial Controls' Lynx+ Gateway faces multiple vulnerabilities, including weak password requirements and missing authentication. These issues could lead to unauthorized access and denial of service. Users are advised to enhance security measures and follow CISA's recommendations to mitigate risks.
Festo identified a critical vulnerability in its MSE6 product line affecting remote access. The vulnerability, CVE-2023-3634, poses risks to confidentiality, integrity, and availability. Mitigation measures include updated documentation and network security recommendations.
Automated Logic's WebCTRL Premium Server has vulnerabilities including Open Redirect and Cross-Site Scripting (XSS). Users are advised to upgrade to version 9.0 as previous versions are affected. CISA recommends security practices to mitigate potential exploitation.
Festo has reported a vulnerability in its Didactic products related to Siemens TIA-Portal, affecting versions prior to updates V17 Update 6 and V18 Update 1. The vulnerability could allow arbitrary file creation or overwriting. Users are advised to update their systems accordingly.
CISA issued six advisories addressing vulnerabilities in various Industrial Control Systems (ICS), including products from Automated Logic, ICAM365, Opto 22, Festo, and Emerson. The advisories provide information on security issues and encourage users to review the mitigations.
Emerson's Appleton UPSMON-PRO is vulnerable to a stack-based buffer overflow that can allow remote code execution. The product is end-of-life, and users are advised to replace or implement specific mitigations to protect their systems. Recommended actions include blocking UDP port 2601 and isolating monitoring networks.
Opto 22 has addressed a critical vulnerability in its GRV-EPIC and groov RIO products that could allow remote code execution with root privileges. Users are advised to update to firmware version 4.0.3. Recommended cybersecurity measures for organizations have been outlined by CISA.