Historical intelligence backfill. This assessment covers reporting originally published on 2025-09-11 and was added to the RWP archive on 2026-09-07.

Daily Top · OT / ICS

CISA's 11 September ICS drop was an identity and gateway problem, not a drive firmware problem

Eleven ICS advisories on one day, with Siemens user-management, Schneider Modicon Ethernet modules, and a Daikin security gateway sitting above the usual drive and motion patches.

RWP Ventures · 2026-09-07 · event 2025-09-11 · 5 min read · priority 7.4

Bottom line up front

CONFIRMED On 11 September 2025 CISA published eleven ICS advisories in a single alert. The list is not eleven equally urgent patches. The items that change plant risk first are identity and remote-access surfaces: Siemens User Management Component, Siemens Industrial Edge Management OS, Schneider Electric EcoStruxure and Modicon M340 Ethernet/FactoryCast modules, Siemens Apogee PXC / Talon building controllers, and the Daikin Security Gateway. Drive, motion, and virtualization tools in the same batch still matter, but they are usually reached after someone already has engineering-network access.

This is a historical intelligence backfill. The CISA alert was published on 11 September 2025. RWP added this assessment to the archive on 7 September 2026. We are not claiming RWP published it in 2025.

What happened

CISA's 11 September 2025 alert named:

WaterISAC republished the same list for water-sector operators the following week and flagged IEM-OS, EcoStruxure, Modicon modules, and the Daikin gateway as energy-relevant. Canada's CCCS, covering 8–14 September, independently warned operators about overlapping Schneider Modicon Ethernet modules and Daikin Security Gateway App 100 / Frm 214, plus a separate Rockwell/ABB set that is not this CISA-11 list.

RWP treats the Rockwell/ABB advisories from that same calendar week as a different batch. Do not collapse them into this one.

Why it mattered

ICS "patch Tuesday" alerts train operators to skim vendor names and wait for a maintenance window. That is the wrong read when the same day includes:

  1. A user-management component (UMC) that, if weak, becomes a plant-wide identity problem rather than a single PLC bug.
  2. An industrial edge management OS that sits above many devices.
  3. Ethernet modules on Modicon M340 that historically have been the internet-facing mistake, not the CPU itself.
  4. A product literally named Security Gateway.

Those four classes change blast radius. A SINAMICS drive flaw on an isolated drive network is a maintenance item. A reachable gateway or identity service is an access path.

No public reporting reviewed for this backfill showed CONFIRMED in-the-wild exploitation of this specific 11 September set on the day of publication. Absence of a KEV listing is not a pass. Internet-exposed building controllers and HVAC/refrigeration gateways are a recurring opportunistic target class.

Who / what was affected

Product classSector relevanceRWP priority
Siemens UMCAny Siemens site using centralized user managementImmediate identity review
Siemens IEM-OSEnergy and manufacturing edgeHigh if reachable from IT or vendor jump hosts
Schneider EcoStruxureEnergy, buildings, processHigh if servers/workstations are dual-homed
Modicon M340 Ethernet / FactoryCastEnergy, water, manufacturingHigh if Modbus/TCP modules are WAN-adjacent
Apogee PXC / Talon TCCommercial buildingsHigh if BMS is internet-reachable
Daikin Security GatewayFacilities / energyHigh — "security" products with default or stale firmware are a known pattern
SINEC OS, SINAMICS, SIMOTION, SIVaaSManufacturingScheduled, after exposure check

OT/ICS compromise: UNKNOWN for this batch as a set. These are vulnerability disclosures, not incident reports. Do not treat a CISA ICS alert as evidence that a plant was hit.

Technical context

The useful model is Purdue, not CVSS. Engineering workstations, edge managers, and Ethernet communications modules are the trust bridges. Building controllers (Apogee/Talon) and OEM "security gateways" are often installed by facilities contractors, not OT security, and then left with vendor remote access.

Schneider's Update A on the M340/BMXNOE family is a signal that a prior advisory was incomplete or that operators had not moved. Repeat advisories on the same communications modules are how internet-exposed PLCs stay exposed.

Exploitation / threat status at the time

CONFIRMED vendor/CISA disclosure on 11 September 2025.

REPORTED sector ISACs and national CERTs amplified the list within a week.

UNKNOWN exploitation of these specific ICSA-25-254 items on or before publication.

ASSESSED (moderate confidence): opportunistic scanning of internet-facing Modicon Ethernet modules, BMS controllers, and OEM gateways would have started as soon as the product names were public.

No ATT&CK technique is implied beyond typical ICS exposure: internet-facing services, default or shared credentials, and engineering-protocol access (T0819/T0883 class activity in later ATT&CK for ICS language). We are not assigning a named actor to this batch.

What defenders should have done

  1. Inventory first. Map which of the eleven product families exist, whether they terminate on a process network, a building network, or a vendor VPN, and whether they answer on the internet. Shodan/Censys self-search is a one-hour control; guessing from a CMMS is not.
  2. Treat UMC, IEM-OS, EcoStruxure servers, Modicon Ethernet modules, Apogee/Talon, and Daikin gateways as emergency-change candidates if they are reachable from IT or WAN. Drive and motion tools can follow in the next planned outage if they are truly isolated.
  3. For Modicon BMXNOE/FactoryCast: if the module is used as a poor-man's remote access path, replace that path with a brokered jump host. Patching an exposed Ethernet module while leaving it on the internet is not remediation.
  4. For Daikin and Apogee/Talon: confirm who owns the asset (facilities vs OT), rotate credentials, disable unused remote services, and put the management interface behind allow-listed access.
  5. Do not skip compensating controls waiting for a shutdown window: disconnect unused WAN, restrict engineering ports, and log failed authentications on gateways.

What we know now

As of this 2026 backfill, RWP has not seen a later CISA KEV entry that maps cleanly to this entire 11 September list as a single exploited event. Later 2025–2026 water-sector PLC incidents (separate registry items) involved internet-exposed controllers and credential change, which is the same class of failure, not proof that these Siemens/Schneider/Daikin CVEs were the tool.

RWP assessment

Confidence: High that the alert and product list are accurate. Moderate that identity, edge-management, Ethernet modules, BMS, and the Daikin gateway were the correct first-hour priorities. Low on exploitation of this specific batch.

The recurring lesson is architectural: CISA can keep shipping eleven-packs. Plants that still hang Ethernet modules and OEM gateways on reachable networks will keep appearing in the next one.

Defensive actions

  1. Pull the eleven ICSA pages and vendor bulletins; record affected versions against live firmware, not purchase records.
  2. Internet-exposure check the six high-priority classes above within 24 hours of any similar batch.
  3. If a "security gateway" or BMS controller has no named owner, assign one before the patch debate.
  4. Require vendor remote access to be time-bounded and logged; standing OEM VPNs are how these batches become incidents.

Sources

  1. CISA — CISA Releases Eleven Industrial Control Systems Advisories
  2. WaterISAC — CISA ICS Advisories, Additional Alerts, Updates, and Bulletins – September 18, 2025
  3. Canadian Centre for Cyber Security — CISA ICS security advisories (AV25–591)