Public ICS Disclosures – Week of 10-11-25 – Part 2
For Part 2 we have 11 additional vendor disclosures from Phoenix Contact (2), Rockwell Automation (2), Schneider, Sick (2), Supermicro, and Westermo (3). We have 20 bulk updates from Schneider (5), and Siemens (15). We have three additional vendor updates from B&R Automation, CODESYS, and HP. Finally, we have four researcher reports describing vulnerabilities in products from Red Lion and Ilevia (3).
Phoenix Contact Advisories
Phoenix Contact published an advisory that describes four vulnerabilities in their QUINT4-UPS EIP uninterruptible power supplies. The vulnerabilities were reported by D. Blagojevic, S. Dietz, F. Koroknai, T. Weber of CyberDanube Security Research. Phoenix Contact has a new version that mitigates the vulnerabilities.
The four reported vulnerabilities are:
Allocation of resources without limits or throttling - CVE-2025-41704,
Unprotected transport of credentials - CVE-2025-41705, and
Classic buffer overflow (2) - CVE-2025-41706 and CVE-2025-41707.
Phoenix Contact published an advisory that describes a code injection vulnerability in their CHARX SEC-3xxx charging controllers. The vulnerability was reported by X of JPCERT. Phoenix Contact has a new version that mitigates the vulnerability.
Rockwell Advisories
Rockwell published an advisory that describes an uncaught exception vulnerability in their Compact GuardLogix 5370 product. Rockwell has a new version that mitigates the vulnerability.
Rockwell published an advisory that describes two vulnerabilities in their 1715 EtherNet/IP Comms Module. Rockwell has a new version that mitigates the vulnerability.
The two reported vulnerabilities are:
Allocation of resources without limits or throttling - CVE-2025-9177, and
Out-of-bounds write - CVE-2025-9178
Schneider Advisory
Schneider published an advisory that describes an allocation of resources without limits or throttling vulnerability in their EcoStruxure OPC UA Server Expert and EcoStruxure Modicon Communication Server products. The vulnerability was reported by Jin Huang of ADLab of Venustech. Schneider has new versions that mitigate the vulnerability.
Sick Advisories
Sick published an advisory that describes 18 vulnerabilities in their Enterprise Analytics and Logistic Analytics products. For all but one vulnerability, Sick provides generic mitigation measures. For the remaining vulnerability, Sick recommends applying a ‘Vendor fix’, but does not identify the vendor (and Sick is identified as the CAN on the CVE - CVE-2025-58590).
Sick published an advisory that discusses 28 vulnerabilities in their Endress+Hauser SSG-E210GC. These are third-party vulnerabilities. Sick provides generic mitigation measures.
Supermicro Advisory
Supermicro published an advisory that discusses an improper access control vulnerability. This is a third-party (AMD) vulnerability. Supermicro has new BIOS versions that mitigate the vulnerability.
Westermo Advisories
Westermo published an advisory that describes a cleartext transmission of sensitive information vulnerability in their RADIUS Server Groups. Westermo has a new version that mitigates the vulnerability.
Westermo published an advisory that describes a cleartext transmission of sensitive information in their WeOS 5. Westermo has a new version that mitigates the vulnerability.
Westermo published an advisory that describes an improper restriction of communications channel to expected endpoints vulnerability in their WeOS 5. Westermo has a new version that mitigates the vulnerability.
Bulk Updates – Schneider
Bulk Updates – Siemens
Vulnerability in Nozomi Guardian/CMC on RUGGEDCOM APE1808 Devices,
Open Redirect Vulnerability in SIMATIC S7-1500 and S7-1200 CPUs,
Multiple Vulnerabilities in User Management Component (UMC),
Deserialization Vulnerability in Siemens Engineering Platforms,
Denial of Service Vulnerabilities in User Management Component (UMC),
Multiple Vulnerabilities in Palo Alto Networks Virtual NGFW on RUGGEDCOM APE1808 Devices,
Deserialization Vulnerability in Siemens Engineering Platforms,
Improper Integrity Check of Firmware Updates in SiPass integrated AC5102 / ACC-G2 and ACC-AP,
DLL Hijacking Vulnerability in Siemens Web Installer used by the Online Software Delivery,
Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP V1.1,
XML External Entity (XXE) Injection Vulnerability in SIMOTION SCOUT,
Unauthenticated Information Disclosure in Web Server of SIMATIC S7-1500 CPUs, and
Heap-based Buffer Overflow Vulnerability in User Management Component (UMC).
B&R Update
B&R published an update for their System Diagnostic Manager advisory that was originally published on October 7th, 2025. The new information includes adding information about CVE-2025-11498, improper neutralization of formula elements in a CSV file.
CODESYS Update
CODESYS published an update for their Control V3 advisory that was originally published on August 4th, 2025, and most recently updated on September 1st, 2025. The new information includes correcting list of affected and fixed products regarding CODESYS HMI (SL) and CODESYS Runtime Toolkit.
HP Update
HP published an update for their Intel 2024.3 IPU advisory that was originally published on October 24th, 2024, and most recently updated on March 31st, 2025. The new information includes updating information for Business Notebooks, Business Desktops, and Point-of-Sales Systems.
Red Lion Report
Claroty published a report describing two vulnerabilities in the Red Lion Sixnet RTU’s. The report includes proof-of-concept code. CISA and HMS (Red Lion is apparently a part of HMS now) previously disclosed these two vulnerabilities.
The two reported vulnerabilities are:
Exposed dangerous method or function - CVE-2023-40151, and
Authentication bypass using alternate path or channel - CVE-2023-42770
Ilevia Reports
Zero Science published four reports describing vulnerabilities in the Ilevia EVE X1 Server. The reports include links to exploits. Zero Science has notified the vendor but has not received a response describing mitigation actions. These may be 0-day vulnerabilities.
The four reported vulnerabilities are:
OS Command injection - CVE-2025-34513 (exploit),
Cross-site scripting - CVE-2025-34512 (exploit), and
Path traversal - CVE-2025-34517 (exploit) and CVE-2025-34518