The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS security advisories, along with additional alerts, updates, and bulletins:
ICS Advisories:
On August 14, 2025, CISA Released Thirty Two Industrial Control Systems Advisories for products used across multiple sectors, please check these latest advisories for specific equipment used across your ICS/SCADA environments and address accordingly:
- Siemens SIMATIC RTLS Locating Manager
- Siemens COMOS
- Siemens Engineering Platforms
- Siemens Simcenter Femap
- Siemens Wibu CodeMeter Runtime
- Siemens Opcenter Quality
- Siemens Third-Party Components in SINEC OS
- Siemens RUGGEDCOM CROSSBOW Station Access Controller
- Siemens RUGGEDCOM APE1808
- Siemens SIPROTEC 5
- Siemens SIMATIC S7-PLCSIM
- Siemens SIPROTEC 4 and SIPROTEC 4 Compact
- Siemens SIMATIC RTLS Locating Manager
- Siemens RUGGEDCOM ROX II
- Siemens SINEC OS
- Siemens SICAM Q100/Q200
- Siemens SINEC Traffic Analyzer
- Siemens SIMOTION SCOUT, SIMOTION SCOUT TIA, and SINAMICS STARTER
- Siemens SINUMERIK
- Siemens RUGGEDCOM ROX II
- Siemens BFCClient
- Siemens Web Installer
- Rockwell Automation FactoryTalk Viewpoint
- Rockwell FactoryTalk Linx
- Rockwell Automation Micro800
- Rockwell Automation FLEX 5000 I/O
- Rockwell Automation ArmorBlock 5000 I/O – Webserver
- Rockwell Automation ControlLogix Ethernet Modules
- Rockwell Automation Studio 5000 Logix Designer
- Rockwell Automation FactoryTalk Action Manager
- Rockwell Automation 1756-ENT2R, 1756-EN4TR, 1756-EN4T
- Güralp Systems FMUS Series and MIN Series Devices (Update A)
On August 12, 2025, CISA Released Seven Industrial Control Systems Advisories for products used across multiple sectors, please check these latest advisories for specific equipment used across your ICS/SCADA environments and address accordingly:
- Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share
- Johnson Controls iSTAR Ultra, iSTAR Ultra SE, iSTAR Ultra G2, iSTAR Ultra G2 SE, iSTAR Edge G2
- Schneider Electric EcoStruxure Power Monitoring Expert
- AVEVA PI Integrator
- MegaSys Computer Technologies Telenium Online Web Application (Update A)
- End-of-Train and Head-of-Train Remote Linking Protocol (Update A)
- Santesoft Sante PACS Server
On August 7, 2025, CISA Released Ten Industrial Control Systems Advisories for products used across multiple sectors, please check these latest advisories for specific equipment used across your ICS/SCADA environments and address accordingly:
- Delta Electronics DIAView
- Johnson Controls FX80 and FX90
- Burk Technology ARC Solo
- Rockwell Automation Arena
- Packet Power EMX and EG
- Dreame Technology iOS and Android Mobile Applications
- EG4 Electronics EG4 Inverters
- Yealink IP Phones and RPS (Redirect and Provisioning Service)
- Instantel Micromate (Update A)
- Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric Products (Update A)
Additional Alerts, Updates, and Bulletins:
- August 13 - CISA Adds Two Known Exploited Vulnerabilities to Catalog
- August 12 - CISA Adds Three Known Exploited Vulnerabilities to Catalog
- CISA Issues ED 25-02: Mitigate Microsoft Exchange Vulnerability
- CISA and Partners Release Asset Inventory Guidance for Operational Technology Owners and Operators