Historical intelligence backfill. This assessment covers reporting originally published on 2025-09-11 and was added to the RWP archive on 2026-09-07.
CISA's 11 September ICS drop was an identity and gateway problem, not a drive firmware problem
Eleven ICS advisories on one day, with Siemens user-management, Schneider Modicon Ethernet modules, and a Daikin security gateway sitting above the usual drive and motion patches.
Bottom line up front
CONFIRMED On 11 September 2025 CISA published eleven ICS advisories in a single alert. The list is not eleven equally urgent patches. The items that change plant risk first are identity and remote-access surfaces: Siemens User Management Component, Siemens Industrial Edge Management OS, Schneider Electric EcoStruxure and Modicon M340 Ethernet/FactoryCast modules, Siemens Apogee PXC / Talon building controllers, and the Daikin Security Gateway. Drive, motion, and virtualization tools in the same batch still matter, but they are usually reached after someone already has engineering-network access.
This is a historical intelligence backfill. The CISA alert was published on 11 September 2025. RWP added this assessment to the archive on 7 September 2026. We are not claiming RWP published it in 2025.
What happened
CISA's 11 September 2025 alert named:
- ICSA-25-254-01 Siemens SIMOTION Tools
- ICSA-25-254-02 Siemens SIMATIC Virtualization as a Service (SIVaaS)
- ICSA-25-254-03 Siemens SINAMICS Drives
- ICSA-25-254-04 Siemens SINEC OS
- ICSA-25-254-05 Siemens Apogee PXC and Talon TC Devices
- ICSA-25-254-06 Siemens Industrial Edge Management OS (IEM-OS)
- ICSA-25-254-07 Siemens User Management Component (UMC)
- ICSA-25-254-08 Schneider Electric EcoStruxure
- ICSA-25-254-09 Schneider Electric Modicon M340, BMXNOE0100, and BMXNOE0110
- ICSA-25-254-10 Daikin Security Gateway
- ICSA-25-035-06 Schneider Electric Modicon M340 and BMXNOE0100/0110, BMXNOR0200H (Update A)
WaterISAC republished the same list for water-sector operators the following week and flagged IEM-OS, EcoStruxure, Modicon modules, and the Daikin gateway as energy-relevant. Canada's CCCS, covering 8–14 September, independently warned operators about overlapping Schneider Modicon Ethernet modules and Daikin Security Gateway App 100 / Frm 214, plus a separate Rockwell/ABB set that is not this CISA-11 list.
RWP treats the Rockwell/ABB advisories from that same calendar week as a different batch. Do not collapse them into this one.
Why it mattered
ICS "patch Tuesday" alerts train operators to skim vendor names and wait for a maintenance window. That is the wrong read when the same day includes:
- A user-management component (UMC) that, if weak, becomes a plant-wide identity problem rather than a single PLC bug.
- An industrial edge management OS that sits above many devices.
- Ethernet modules on Modicon M340 that historically have been the internet-facing mistake, not the CPU itself.
- A product literally named Security Gateway.
Those four classes change blast radius. A SINAMICS drive flaw on an isolated drive network is a maintenance item. A reachable gateway or identity service is an access path.
No public reporting reviewed for this backfill showed CONFIRMED in-the-wild exploitation of this specific 11 September set on the day of publication. Absence of a KEV listing is not a pass. Internet-exposed building controllers and HVAC/refrigeration gateways are a recurring opportunistic target class.
Who / what was affected
| Product class | Sector relevance | RWP priority |
|---|---|---|
| Siemens UMC | Any Siemens site using centralized user management | Immediate identity review |
| Siemens IEM-OS | Energy and manufacturing edge | High if reachable from IT or vendor jump hosts |
| Schneider EcoStruxure | Energy, buildings, process | High if servers/workstations are dual-homed |
| Modicon M340 Ethernet / FactoryCast | Energy, water, manufacturing | High if Modbus/TCP modules are WAN-adjacent |
| Apogee PXC / Talon TC | Commercial buildings | High if BMS is internet-reachable |
| Daikin Security Gateway | Facilities / energy | High — "security" products with default or stale firmware are a known pattern |
| SINEC OS, SINAMICS, SIMOTION, SIVaaS | Manufacturing | Scheduled, after exposure check |
OT/ICS compromise: UNKNOWN for this batch as a set. These are vulnerability disclosures, not incident reports. Do not treat a CISA ICS alert as evidence that a plant was hit.
Technical context
The useful model is Purdue, not CVSS. Engineering workstations, edge managers, and Ethernet communications modules are the trust bridges. Building controllers (Apogee/Talon) and OEM "security gateways" are often installed by facilities contractors, not OT security, and then left with vendor remote access.
Schneider's Update A on the M340/BMXNOE family is a signal that a prior advisory was incomplete or that operators had not moved. Repeat advisories on the same communications modules are how internet-exposed PLCs stay exposed.
Exploitation / threat status at the time
CONFIRMED vendor/CISA disclosure on 11 September 2025.
REPORTED sector ISACs and national CERTs amplified the list within a week.
UNKNOWN exploitation of these specific ICSA-25-254 items on or before publication.
ASSESSED (moderate confidence): opportunistic scanning of internet-facing Modicon Ethernet modules, BMS controllers, and OEM gateways would have started as soon as the product names were public.
No ATT&CK technique is implied beyond typical ICS exposure: internet-facing services, default or shared credentials, and engineering-protocol access (T0819/T0883 class activity in later ATT&CK for ICS language). We are not assigning a named actor to this batch.
What defenders should have done
- Inventory first. Map which of the eleven product families exist, whether they terminate on a process network, a building network, or a vendor VPN, and whether they answer on the internet. Shodan/Censys self-search is a one-hour control; guessing from a CMMS is not.
- Treat UMC, IEM-OS, EcoStruxure servers, Modicon Ethernet modules, Apogee/Talon, and Daikin gateways as emergency-change candidates if they are reachable from IT or WAN. Drive and motion tools can follow in the next planned outage if they are truly isolated.
- For Modicon BMXNOE/FactoryCast: if the module is used as a poor-man's remote access path, replace that path with a brokered jump host. Patching an exposed Ethernet module while leaving it on the internet is not remediation.
- For Daikin and Apogee/Talon: confirm who owns the asset (facilities vs OT), rotate credentials, disable unused remote services, and put the management interface behind allow-listed access.
- Do not skip compensating controls waiting for a shutdown window: disconnect unused WAN, restrict engineering ports, and log failed authentications on gateways.
What we know now
As of this 2026 backfill, RWP has not seen a later CISA KEV entry that maps cleanly to this entire 11 September list as a single exploited event. Later 2025–2026 water-sector PLC incidents (separate registry items) involved internet-exposed controllers and credential change, which is the same class of failure, not proof that these Siemens/Schneider/Daikin CVEs were the tool.
RWP assessment
Confidence: High that the alert and product list are accurate. Moderate that identity, edge-management, Ethernet modules, BMS, and the Daikin gateway were the correct first-hour priorities. Low on exploitation of this specific batch.
The recurring lesson is architectural: CISA can keep shipping eleven-packs. Plants that still hang Ethernet modules and OEM gateways on reachable networks will keep appearing in the next one.
Defensive actions
- Pull the eleven ICSA pages and vendor bulletins; record affected versions against live firmware, not purchase records.
- Internet-exposure check the six high-priority classes above within 24 hours of any similar batch.
- If a "security gateway" or BMS controller has no named owner, assign one before the patch debate.
- Require vendor remote access to be time-bounded and logged; standing OEM VPNs are how these batches become incidents.
Sources
- CISA — CISA Releases Eleven Industrial Control Systems Advisories
- WaterISAC — CISA ICS Advisories, Additional Alerts, Updates, and Bulletins – September 18, 2025
- Canadian Centre for Cyber Security — CISA ICS security advisories (AV25–591)