Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This is a historical alert from November 8, 2022, not a current patch notice. SecurityWeek reported that Siemens issued nine new industrial-security advisories covering 30 vulnerabilities. Three critical advisories involved Sicam Q100 power meters, Scalance W1750D access points and Sinumerik products. Before changing a live system, check the current, version-specific Siemens ProductCERT advisory and Siemens support documentation; the patch status described below reflects the situation reported in 2022.

What Siemens disclosed in November 2022

SecurityWeek’s November 8, 2022 report described Siemens’ November Patch Tuesday release as nine advisories covering 30 vulnerabilities. That total is SecurityWeek’s account of the release, rather than an independently checked vendor-wide statistic.

The report grouped the most urgent disclosures by product family and described additional high- and medium-severity issues. Because the underlying Siemens advisories were not available in the source material, the details and historical remediation status below should be read as SecurityWeek-reported findings. Product owners should verify affected versions, fixed firmware or software and compensating controls in the current Siemens ProductCERT portal.

Critical product families and reported impacts

Product family SecurityWeek’s November 2022 description Status reported on November 8, 2022
Sicam Q100 Four vulnerabilities: one high-severity and three critical. Reported consequences included user-session hijacking, device crashes and arbitrary code execution. Verify the affected meter versions and current fixes in Siemens’ product-specific advisory.
Scalance W1750D More than a dozen vulnerabilities, including many rated critical, with potential for arbitrary code execution or denial of service. SecurityWeek identified the access point as a Siemens-branded device made by Aruba Networks. No patches were available when the article was published; Siemens had supplied mitigations. That historical statement does not establish present-day patch availability.
Sinumerik A critical issue involving weak key protection in Sinumerik products. Use the current Siemens advisory to determine whether a firmware or configuration change is required for the exact Sinumerik version.

Sicam Q100

SecurityWeek reported four Sicam Q100 flaws. The impact descriptions—session hijacking, crashes and arbitrary code execution—cover materially different risks: an attacker might impersonate a user, disrupt meter operation or run code on the device. Do not infer exploitability or affected model numbers from the news report alone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Industrial Cybersecurity: Efficiently monitor the cybersecurity posture of your ICS environment
  • Industrial Cybersecurity: Efficiently monitor the cybersecurity posture of your ICS environment, 2nd Edition
  • ABIS BOOK
  • Packt Publishing

Scalance W1750D

The article described more than a dozen Scalance W1750D vulnerabilities and said many were critical. Potential outcomes included arbitrary code execution and denial of service. At publication, Siemens had provided mitigations but no patches were available. Treat that as a dated snapshot; consult ProductCERT for the current firmware path and any withdrawal or replacement guidance.

Sinumerik

The third critical disclosure concerned weak protection of cryptographic keys in Sinumerik products. The report does not provide the affected version range or a complete remediation procedure, so machine builders and operators should obtain those details from the matching Siemens advisory before making changes.

Other vulnerabilities in the same release

High-severity software issues

  • Teamcenter Visualization and JT2Go: SecurityWeek reported denial-of-service and remote-code-execution vulnerabilities.
  • Parasolid: The report described a remote-code-execution flaw.
  • QMS Automotive: The reported risk was credential exposure.

Medium-severity issues

SecurityWeek also listed medium-severity vulnerabilities affecting Ruggedcom ROS devices, industrial controllers and the Sinec network-management system. The article does not supply enough version or fix information to prescribe a single remediation action for these products.

Separate Siveillance Video advisory

SecurityWeek additionally reported that Siemens published a separate advisory between this Patch Tuesday and the preceding release for a critical authentication bypass in Siveillance Video mobile servers. The available report does not include a CVE identifier or specific remediation details. Handle it as a separate disclosure and locate the corresponding Siemens advisory before assessing exposure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What operators should do now

  1. Identify exact assets. Inventory Sicam Q100 meters, Scalance W1750D access points, Sinumerik equipment, Siveillance Video mobile servers and the other named software or devices, recording model, firmware/software version and site.
  2. Check Siemens ProductCERT. Search the current advisory database for each product and version. Confirm whether a fixed release exists, whether a mitigation remains recommended and whether an end-of-support notice changes the upgrade path.
  3. Apply the vendor’s tested remediation. Schedule firmware or software updates through the site’s change-control process. Validate backups, rollback capability, safety dependencies and maintenance windows before touching operational technology.
  4. Use compensating controls when a fix is unavailable. Follow Siemens’ current instructions; typical controls may include isolating management interfaces, restricting remote access, filtering unnecessary services and monitoring authentication or crash activity. Do not substitute generic controls for the vendor’s product guidance.
  5. Verify recovery. After remediation, confirm the reported version, restore required communications and review logs for session abuse, unexpected restarts, denial-of-service symptoms or unauthorized code execution.

Do not use the Siemens ProductCERT advisory SSA-686975 as confirmation of these November 2022 findings. That page concerns Intel CPU vulnerabilities in Siemens industrial products, was published February 14, 2023 and updated August 11, 2026; it is a separate matter from the Sicam, Scalance, Sinumerik and related disclosures summarized here.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to interpret the 2022 patch status

The article’s “no patches available” statement applies only to Scalance W1750D at the time of publication. It is not evidence that patches remain unavailable, nor does it establish that every product in the nine-advisory release shared the same status. Current decisions require the affected version, the latest Siemens advisory and the site’s safety and availability constraints.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.