Skip to content
Beveiligingsnieuws

ICS Patch Tuesday: Siemens, Schneider & Phoenix Updates

ICS Patch Tuesday

Industrial operators relying on connected control environments received fresh guidance this Patch Tuesday. Siemens, Schneider Electric, and Phoenix Contact published new advisories to help customers address newly identified vulnerabilities in their industrial control systems (ICS) and related products. Below is a clear overview of what was fixed, where to look, and why these updates matter for operational security.

Note: Always verify the advisory for your specific product model and firmware version before applying changes. In ICS environments, patching can affect availability, so plan updates using your organization’s maintenance windows and validation procedures.

Siemens: multiple advisories across ICS platforms

Siemens released ten new advisories covering a range of severity levels and product families. Some issues are straightforward application stability concerns, while others involve remote exploitation paths that could lead to code execution, privilege escalation, or sensitive data exposure.

High impact: missing authentication in Simatic IoT2050 Advanced

One of Siemens’ updates addresses a maximum-severity problem affecting Simatic IoT2050 Advanced devices. The core issue is a missing-authentication weakness. According to the advisory information, a remote attacker without authentication could exploit the flaw to execute arbitrary code on the underlying server with elevated privileges.

If you use Simatic IoT2050 Advanced in networked industrial segments, prioritize this advisory during patch planning. Missing authentication vulnerabilities are typically considered urgent because they remove common barriers attackers face, such as valid credentials.

Critical flaw fixed in Siveillance Video Management Servers

Siemens also fixed a critical code execution vulnerability in Siveillance Video Management Servers. Code execution issues can be particularly risky in environments where video systems are integrated into monitoring workflows and may share network access with broader operational infrastructure.

Organizations should confirm whether the affected Siveillance components are deployed and whether they connect to systems that can be reached from untrusted networks.

High-severity issues across engineering and licensing-related components

Beyond these critical items, Siemens addressed high-severity vulnerabilities in several products, including Solid Edge, Simcenter Nastran, Siemens License Server, Simcenter Femap, Parasolid, and Logo! Soft Comfort.

Depending on the specific advisory, these flaws can enable outcomes such as application crashes, arbitrary code execution, privilege escalation, reading arbitrary files, or obtaining sensitive information. Even when an issue does not target core runtime systems, exploitation paths involving engineering tools and license services can still carry significant operational risk.

Medium-severity patches for Ruggedcom devices and Desigo controllers

Siemens also resolved medium-severity vulnerabilities affecting Ruggedcom devices and Desigo controllers. While medium severity is not always an immediate crisis, it can still create exploitable conditions—especially when combined with other weaknesses or exposed network services.

Schneider Electric: advisories for NetBotz and PowerChute Serial Shutdown

Schneider Electric published two new advisories focused on vulnerabilities in NetBotz 5 and PowerChute Serial Shutdown products. These types of devices are often used for environmental monitoring and system power management, which means they can be tightly integrated into datacenter or site infrastructure.

NetBotz 5: code/command execution fixes

For NetBotz 5, Schneider Electric addressed two code or command execution issues. The impact category indicates that attackers may be able to influence how commands are processed or how the system behaves, potentially leading to unauthorized control.

If NetBotz appliances connect to management networks or interfaces accessible to more than just authorized administrators, patching should be scheduled promptly.

PowerChute Serial Shutdown: excessive authentication attempts

Schneider Electric’s second advisory relates to PowerChute Serial Shutdown. The patched vulnerability involves excessive authentication attempts. In the advisory information provided, this condition could result in disruption or may allow access to system data.

Organizations should review whether PowerChute systems are exposed to networks where authentication attempts could be repeated at scale, and ensure the recommended update and any compensating controls are put in place.

Phoenix Contact: PLCnext firmware vulnerabilities

Phoenix Contact published one advisory that covers multiple vulnerabilities in PLCnext firmware. The advisory describes scenarios where unauthenticated attackers could exploit weaknesses to cause denial of service, trigger unexpected behavior, or execute malicious SQL queries.

PLCnext deployments are often central to automation workflows. Even when a vulnerability primarily results in unexpected behavior or SQL manipulation, it can still undermine system integrity, disrupt operations, or create an entry point for further compromise.

As part of your ICS Patch Tuesday updates process, check the firmware versions in use across PLCnext devices and align them with the guidance in Phoenix Contact’s advisory.

How to prioritize the ICS Patch Tuesday updates

With multiple vendors releasing changes at once, teams can face patch backlog and limited downtime. A sensible prioritization approach helps reduce risk without disrupting production.

  • Start with remote, unauthenticated issues: Siemens’ missing-authentication vulnerability in Simatic IoT2050 Advanced is an example of why exposure matters. If exploitation does not require credentials, treat it as high urgency.
  • Look for code execution and privilege escalation paths: Code execution bugs and privilege escalation can be used to move from initial access to deeper control.
  • Assess operational exposure: Consider whether affected systems are reachable from corporate networks or from segments that include monitoring, maintenance, or remote access.
  • Inventory engineering and support services: Products like license servers and engineering tools may not be “plant-floor controllers,” but they often sit on networks with high trust and can impact availability and access.
  • Plan validation and rollback: For PLCs, controllers, monitoring platforms, and related systems, test patches in a staging environment and prepare a rollback strategy where possible.

What to check in your environment

To use these advisories effectively, confirm three things for each affected product: whether it is present, which version is installed, and whether your connectivity assumptions match the threat described in the advisory.

For example, the Siemens items include both device-side and software-side components. That means asset owners should not only check runtime deployments but also verify if engineering workstations, video management servers, and license infrastructure are included in the scope.

Similarly, Schneider Electric’s NetBotz and PowerChute products can be found in facilities where environmental monitoring and controlled shutdown behaviors are essential. Make sure your asset register includes these support systems, not just primary industrial controllers.

And for Phoenix Contact, validate the firmware levels on PLCnext devices and the contexts in which they operate, since unauthenticated exploitation combined with PLC workflows can create immediate disruption risk.

Related guidance from the wider ecosystem

Patch Tuesday coverage in ICS security often expands beyond the initial set of vendor advisories. Alongside this Siemens, Schneider, and Phoenix Contact update, the broader reporting also notes additional advisories from other vendors earlier or concurrently, including work involving cybersecurity guidance from agencies and other industrial suppliers.

Even if your organization focuses on a particular platform set, it can help to monitor aggregations of patch information and to subscribe to vendor-specific security notifications so you don’t miss dependencies or adjacent components.

Conclusion

These ICS Patch Tuesday updates bring meaningful security fixes across industrial platforms used for monitoring, automation, and operational support. Siemens addressed issues ranging from missing authentication in Simatic IoT2050 Advanced to critical code execution in Siveillance Video Management Servers, along with patches for engineering and licensing-related products. Schneider Electric covered NetBotz 5 and PowerChute Serial Shutdown, and Phoenix Contact published firmware advisories affecting PLCnext devices, including denial of service and malicious SQL query scenarios.

To reduce risk, inventory your deployed versions, prioritize remote and unauthenticated vulnerabilities first, and schedule testing and deployment within your operational constraints. Staying current with vendor advisories is one of the most practical steps you can take to protect ICS environments against evolving threats.

Source: https://www.securityweek.com/ics-patch-tuesday-vulnerabilities-fixed-by-siemens-schneider-phoenix-contact-2/