Industry 4.0 connects machines – and widens the attack surface. This radar counts new security advisories (ICS-CERT) for the automation vendors that run German factories: Siemens, Phoenix Contact, WAGO, Beckhoff, SICK, Schneider, Rockwell, ABB and more.
Distribution of all tracked advisories by CVSS severity.
New advisories per month for the tracked vendors (last 24 months).
Which automation vendors account for the most advisories. “DE” = headquartered in Germany.
More advisories doesn't mean “less secure” – large, widely deployed portfolios (e.g. Siemens) simply generate more reports.
The latest ICS-CERT advisories for the tracked vendors.
Rockwell Automation FactoryTalk Historian Site Edition
Schneider Electric EasyLogic T150 and Saitel DP
Mitsubishi Electric MELSEC iQ-F Series
Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module
Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products
Rockwell Automation FactoryTalk, Analytics, PavilionX
Rockwell Automation RSLinx
Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP
Rockwell Automation CompactLogix
Rockwell Automation FLEX I/O EtherNet/IP Adapters
Schneider Electric EcoStruxure Panel Server
Siemens KACO Blueplanet Inverters
Schneider Electric Modicon Network Managed Switches
Hitachi Energy ITT600 Explorer
Hitachi Energy RTU500
Hitachi Energy MACH HiDraw
ABB EIBPORT
ABB Busch-Welcome 2 Wire Door Opener Actuator
Schnieider Electric EcoStruxure Machine Expert HVAC
ABB Terra AC
ABB AC500 V2
ABB Ability Zenon Remote Transport Vulnerability (Update A)
ABB Ability Camera Connect
ABB LVS MConfig
Hitachi Energy GMS600
ABB Terra AC Wallbox
ABB CoreSense HM and CoreSense M10
Siemens RUGGEDCOM APE1808 Devices
Siemens gWAP
Siemens Ruggedcom Rox
We read the ICS Advisory Project database – an open, structured mirror of every CISA ICS-CERT advisory – and keep the vendors that matter to DACH industry.
Source: the ICS Advisory Project (github.com/icsadvprj, CC-licensed), which structures the advisories of the US agency CISA. CISA tracks globally; the advisories concern products used worldwide, including in Germany. No AI model, no keys.
All figures without guarantee. Data source: ICS Advisory Project (mirror of CISA ICS-CERT advisories, CC). The vendor selection is curated (industrial automation relevant to DACH) and not exhaustive. An advisory doesn't mean your plant is affected – check the respective original advisory. i6eal is not a security authority.
How many new security advisories (ICS-CERT) exist for the automation vendors common in German factories – with severity, a vendor ranking, a monthly trend and the latest reports.
From the ICS Advisory Project, an open structured database of all advisories from the US cybersecurity agency CISA (ICS-CERT). We filter to vendors relevant to DACH industry and refresh several times a day.
Not necessarily. An advisory describes a reported flaw in a product. Whether your specific plant is affected depends on version, configuration and patch level – the original vendor/CISA advisory clarifies that.
Large vendors with very broad, globally deployed portfolios (like Siemens) publish correspondingly more advisories. The absolute number is not a measure of “insecurity”.
Whether AI in production or connected OT: we bring new technology into operation securely.