Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Phoenix Contact

Posted on July 9, 2025July 9, 2025 By CWS

July 2025 Patch Tuesday ICS safety advisories have been revealed by Siemens, Schneider Electrical and Phoenix Contact.

Siemens has launched 9 new advisories, in addition to a safety bulletin urging clients to take steps to safe their industrial management programs (ICS) amid an rising menace to the operational expertise (OT) panorama. The alert cites the present geopolitical scenario and references a latest US authorities alert warning organizations a couple of potential surge in assaults by Iran.

The economic big additionally knowledgeable clients that its Sentron Powermanager and Desigo CC units aren’t affected by a not too long ago disclosed distant code execution vulnerability in Apache Tomcat.

Two critical- and one high-severity flaw have been addressed by Siemens in its Sinec NMS product. The safety holes may enable privilege escalation and code execution.

Siemens has additionally knowledgeable clients about high-severity vulnerabilities within the TIA Administrator framework (privilege escalation and code execution), Sicam Toolbox II (MitM assault), Strong Edge (DoS or code execution), Ruggedcom ROS (MitM and unauthorized entry), and Simatic CN 4100 (DoS). 

Medium-severity points have been addressed in Siprotect 5, and TIA Undertaking Server and TIA Portal merchandise. They’ll result in the publicity of delicate info and DoS assaults, respectively. 

Schneider Electrical has revealed 4 new advisories. Considered one of them describes a number of critical- and high-severity vulnerabilities affecting the EcoStruxure IT Information Heart Professional product. The failings may be exploited for unauthenticated distant code execution, root password discovery, distant command execution, and privilege escalation. 

A distinct advisory describes one knowledge publicity situation in EcoStruxure Energy Monitor Professional and Energy Operation merchandise. Two different advisories describe the influence of third-party part flaws on EcoStruxure Energy Operation and legacy industrial PCs.Commercial. Scroll to proceed studying.

Phoenix Contact additionally launched 4 new advisories on Tuesday. Two of them describe essential vulnerabilities in PLCnext firmware, enabling attackers to reboot PLCs, achieve entry to and execute recordsdata, trigger a DoS situation, and carry out different actions. A majority of the problems influence third-party elements. 

Two different Phoenix Contact advisories cowl vulnerabilities in Charx EV charging controllers, together with essential flaws. They are often exploited by hackers to realize learn/write entry, trigger a DoS situation, and escalate privileges. 

The Phoenix Contact advisories had been additionally revealed by Germany’s VDE CERT. 

Within the US, CISA revealed one new advisory informing organizations about a number of vulnerabilities, together with ones rated ‘essential’ and ‘excessive’, affecting Emerson ValveLink valve monitoring merchandise. The vulnerabilities may be exploited to acquire delicate info, tamper with parameters, and run unauthorized code.

A number of days previous to Patch Tuesday, advisories had been revealed by ABB (RMC-100 authentication bypass, info publicity vulnerabilities), and Mitsubishi Electrical (DoS in Melsec and code execution in Melsoft). 

Associated: ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Aveva, CISA

Associated: Siemens Notifies Clients of Microsoft Defender Antivirus Situation

Security Week News Tags:Addressed, Contact, ICS, Patch, Phoenix, Schneider, Siemens, Tuesday, Vulnerabilities

Post navigation

Previous Post: How To Automate Ticket Creation, Device Identification and Threat Triage With Tines
Next Post: U.S. Sanctions North Korean Andariel Hacker Behind Fraudulent IT Worker Scheme

Related Posts

CISA Warns AMI BMC Vulnerability Exploited in the Wild Security Week News
Nova Scotia Power Confirms Ransomware Attack, 280k Notified of Data Breach Security Week News
Infostealers: The Silent Smash-and-Grab Driving Modern Cybercrime Security Week News
Anatsa Android Banking Trojan Now Targeting 830 Financial Apps Security Week News
Counter Antivirus Service AVCheck Shut Down by Law Enforcement Security Week News
Cyberstarts Launches $300M Liquidity Fund to Help Startups Retain Top Talent Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Malicious Code on Unity Website Skims Information From Hundreds of Customers
  • Microsoft Intune MDM and Entra ID Leveraged to Elevate your Trust in Device Identity
  • WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More
  • SonicWall SSL VPN Accounts in Attacker Crosshairs
  • Astaroth Banking Malware Leveraging GitHub to Host Malware Configurations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Malicious Code on Unity Website Skims Information From Hundreds of Customers
  • Microsoft Intune MDM and Entra ID Leveraged to Elevate your Trust in Device Identity
  • WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More
  • SonicWall SSL VPN Accounts in Attacker Crosshairs
  • Astaroth Banking Malware Leveraging GitHub to Host Malware Configurations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News