Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Rockwell, Schneider

Posted on December 10, 2025December 11, 2025 By CWS

Industrial giants Siemens, Rockwell Automation, Schneider Electrical, and Phoenix Contact have revealed Patch Tuesday advisories informing prospects about vulnerabilities discovered of their ICS/OT merchandise.

Siemens has revealed 14 new advisories. An total severity ranking of ‘important’ has been assigned to a few advisories protecting dozens of third-party element vulnerabilities affecting Comos, Sicam T, and Ruggedcom ROX merchandise. 

A ‘excessive severity’ ranking has been assigned to vulnerabilities present in Siemens Superior Licensing (SALT) Toolkit, IAM Consumer (a number of merchandise), Simatic CN 4100, Ruggedcom ROX, Interniche IP-Stack (a number of merchandise), and Sinec Safety Monitor.

Medium-severity points have been addressed in Vitality Companies, Constructing X-Safety Supervisor Edge Controller, Gridscale X Prepay, Ruggedcom ROS, and Sinema Distant Join Server merchandise.

The vulnerabilities might be exploited for arbitrary code execution, denial of service (DoS), unauthorized entry, man-in-the-middle (MitM) assaults, and acquiring delicate data. 

Schneider Electrical has revealed two new advisories. One among them describes the impression of an exploited Home windows Server Replace Companies (WSUS) vulnerability on the economic big’s EcoStruxure Foxboro DCS product. The second advisory covers the impression of the previous ZombieLoad vulnerability on the identical EcoStruxure product.

Rockwell Automation has additionally revealed two new advisories. One among them covers a high-severity DoS difficulty affecting the 432ES-IG3 Collection A GuardLink EtherNet/IP interface. The second advisory describes a high-severity SQL injection in FactoryTalk DataMosaix Personal Cloud.

Phoenix Contact has revealed one advisory, describing a number of XSS, DoS, authentication, and knowledge publicity vulnerabilities present in its FL SWITCH 2xxx collection switches. Commercial. Scroll to proceed studying.

The Phoenix Contact advisory has additionally been picked up by Germany’s VDE CERT. 

CISA revealed three new advisories. Every of them describes one vulnerability affecting CCTV cameras in India (lacking authentication), Festo LX Equipment (XSS), and U-Boot (code execution). 

Associated: ICS Patch Tuesday: Fixes Introduced by Siemens, Schneider, Rockwell, ABB, Phoenix Contact

Associated: International Cyber Businesses Problem AI Safety Steering for Essential Infrastructure OT

Associated: ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Rockwell, Aveva, Schneider

Security Week News Tags:Fixed, ICS, Patch, Rockwell, Schneider, Siemens, Tuesday, Vulnerabilities

Post navigation

Previous Post: Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two Zero-Days
Next Post: SAP Patches Critical Vulnerabilities With December 2025 Security Updates

Related Posts

‘ZombieAgent’ Attack Let Researchers Take Over ChatGPT Security Week News
SIM Farm Dismantled in Europe, Seven Arrested Security Week News
MITRE Launches New Security Framework for Embedded Systems  Security Week News
Chinese Cyberspies Deploy ‘BadAudio’ Malware via Supply Chain Attacks Security Week News
Nikkei Says 17,000 Impacted by Data Breach Stemming From Slack Account Hack Security Week News
Saporo Raises $8 Million for Identity Security Platform Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Johnson Controls Products Vulnerabilities Enables Remote SQL Injection Attacks
  • Moltbook AI Vulnerability Exposes Email Addresses, Login Tokens, and API Keys
  • eScan Antivirus Delivers Malware in Supply Chain Attack
  • Iran-Linked RedKitten Cyber Campaign Targets Human Rights NGOs and Activists
  • Automated Penetration Testing Toolkit Designed for Linux systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Johnson Controls Products Vulnerabilities Enables Remote SQL Injection Attacks
  • Moltbook AI Vulnerability Exposes Email Addresses, Login Tokens, and API Keys
  • eScan Antivirus Delivers Malware in Supply Chain Attack
  • Iran-Linked RedKitten Cyber Campaign Targets Human Rights NGOs and Activists
  • Automated Penetration Testing Toolkit Designed for Linux systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark