Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Phoenix Contact

Posted on July 9, 2025July 9, 2025 By CWS

July 2025 Patch Tuesday ICS safety advisories have been revealed by Siemens, Schneider Electrical and Phoenix Contact.

Siemens has launched 9 new advisories, in addition to a safety bulletin urging clients to take steps to safe their industrial management programs (ICS) amid an rising menace to the operational expertise (OT) panorama. The alert cites the present geopolitical scenario and references a latest US authorities alert warning organizations a couple of potential surge in assaults by Iran.

The economic big additionally knowledgeable clients that its Sentron Powermanager and Desigo CC units aren’t affected by a not too long ago disclosed distant code execution vulnerability in Apache Tomcat.

Two critical- and one high-severity flaw have been addressed by Siemens in its Sinec NMS product. The safety holes may enable privilege escalation and code execution.

Siemens has additionally knowledgeable clients about high-severity vulnerabilities within the TIA Administrator framework (privilege escalation and code execution), Sicam Toolbox II (MitM assault), Strong Edge (DoS or code execution), Ruggedcom ROS (MitM and unauthorized entry), and Simatic CN 4100 (DoS). 

Medium-severity points have been addressed in Siprotect 5, and TIA Undertaking Server and TIA Portal merchandise. They’ll result in the publicity of delicate info and DoS assaults, respectively. 

Schneider Electrical has revealed 4 new advisories. Considered one of them describes a number of critical- and high-severity vulnerabilities affecting the EcoStruxure IT Information Heart Professional product. The failings may be exploited for unauthenticated distant code execution, root password discovery, distant command execution, and privilege escalation. 

A distinct advisory describes one knowledge publicity situation in EcoStruxure Energy Monitor Professional and Energy Operation merchandise. Two different advisories describe the influence of third-party part flaws on EcoStruxure Energy Operation and legacy industrial PCs.Commercial. Scroll to proceed studying.

Phoenix Contact additionally launched 4 new advisories on Tuesday. Two of them describe essential vulnerabilities in PLCnext firmware, enabling attackers to reboot PLCs, achieve entry to and execute recordsdata, trigger a DoS situation, and carry out different actions. A majority of the problems influence third-party elements. 

Two different Phoenix Contact advisories cowl vulnerabilities in Charx EV charging controllers, together with essential flaws. They are often exploited by hackers to realize learn/write entry, trigger a DoS situation, and escalate privileges. 

The Phoenix Contact advisories had been additionally revealed by Germany’s VDE CERT. 

Within the US, CISA revealed one new advisory informing organizations about a number of vulnerabilities, together with ones rated ‘essential’ and ‘excessive’, affecting Emerson ValveLink valve monitoring merchandise. The vulnerabilities may be exploited to acquire delicate info, tamper with parameters, and run unauthorized code.

A number of days previous to Patch Tuesday, advisories had been revealed by ABB (RMC-100 authentication bypass, info publicity vulnerabilities), and Mitsubishi Electrical (DoS in Melsec and code execution in Melsoft). 

Associated: ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Aveva, CISA

Associated: Siemens Notifies Clients of Microsoft Defender Antivirus Situation

Security Week News Tags:Addressed, Contact, ICS, Patch, Phoenix, Schneider, Siemens, Tuesday, Vulnerabilities

Post navigation

Previous Post: How To Automate Ticket Creation, Device Identification and Threat Triage With Tines
Next Post: U.S. Sanctions North Korean Andariel Hacker Behind Fraudulent IT Worker Scheme

Related Posts

Unbound Raises $4 Million to Secure Gen-AI Adoption Security Week News
Pharmaceutical Company Inotiv Confirms Ransomware Attack Security Week News
750,000 Impacted by Data Breach at The Alcohol & Drug Testing Service Security Week News
CrowdStrike to Acquire Onum to Fuel Falcon Next-Gen SIEM With Real-Time Telemetry Security Week News
Dropzone AI Raises $37 Million for Autonomous SOC Analyst Security Week News
Four Arrested in UK Over M&S, Co-op Cyberattacks Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Warns Salesloft OAuth Breach Extends Beyond Salesforce, Impacting All Integrations
  • Hackers Exploit Microsoft Teams, Posing as IT Help Desk for Screen Sharing and Remote Access
  • TamperedChef Malware Disguised as Fake PDF Editors Steals Credentials and Cookies
  • Threat actors Breach High Value targets like Google in Salesforce Attacks
  • Weaponized ScreenConnect RMM Tool Tricks Users into Downloading Xworm RAT

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Warns Salesloft OAuth Breach Extends Beyond Salesforce, Impacting All Integrations
  • Hackers Exploit Microsoft Teams, Posing as IT Help Desk for Screen Sharing and Remote Access
  • TamperedChef Malware Disguised as Fake PDF Editors Steals Credentials and Cookies
  • Threat actors Breach High Value targets like Google in Salesforce Attacks
  • Weaponized ScreenConnect RMM Tool Tricks Users into Downloading Xworm RAT

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News