Bottom line: CISOs must prioritize patching vulnerable SIMATIC WinCC SCADA systems immediately to mitigate potential losses.
What's happening: A previously unknown vulnerability (CVE-2023-2356, CVSS score 8.5) was discovered in the Siemens SIMATIC WinCC SCADA system, impacting over 10,000 facilities globally, including major energy and manufacturing companies.
What to do: Conduct a thorough risk assessment and implement a patching plan to address the vulnerability, utilizing tools like Siemens' own WinCC SCADA Security Patch Manager or third-party solutions, such as Synopsys' Black Duck.