Wednesday, July 22, 2026

Review – Bills Introduced – 7-22-26

Yesterday, with both the House and Senate in session there were 66 bills introduced. One of those bills will receive additional coverage in this blog: 

HR 9797 - To establish a pilot program for State, local, Tribal, and territorial government officials to be trained by the Cybersecurity and Infrastructure Security Agency regarding carrying out security vulnerability or terrorism risk assessments of critical infrastructure facilities, and for other purposes. Rep. Underwood, Lauren [D-IL-14] 


For more information on these bills, including legislative history for similar bills in the 118th Congress, as well as a mention in passing of a bill dealing with staged accidents with commercial trucks, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-7-22-26 - subscription required. 

Looking Back – 10-10-24 – 21 Advisories

Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today a blog post from October 10th, 2024, Review – 21 Advisories Published 10-10-24, made the list; actually, it has made the list for the last four days. This was a post about the CISA NCCIC-ICS control system security advisories for the Thursday after Cyber Tuesday. That is the reason for the 21 advisories being covered; including six for products from Rockwell and 13 for products from Siemens. Nothing unusual here, at least until I looked at the companion post over on CFSN Detailed Analysis. That post included the following comment about the Siemens SIMATIC S7-1500 CPUs advisory: 

“NOTE: This advisory is a good example of the reason that CISA no longer covers Siemens updates. Of the products listed as being affected by this vulnerability, 88 of them are currently listed on the Siemens Advisory as “Currently no fix is available”. I suspect that fixes for those products will be completed in batches with multiple updates needed to keep customers advised. There is no telling how long that will take, or how many updates will be required.” 

Looking back at the latest version of the Siemens Advisory, they published seven updates through October 14th, 2025. That left them with one product, SIMATIC S7-1500 Software Controller Linux V2, with no fix planned. That product is apparently no longer supported. I listed that update in the Bulk Updates – Siemens section of my Public ICS Disclosures – Week of 10-11-25 – Part 2 post. 

Tuesday, July 21, 2026

Review – 10 Advisories Published – 7-21-26

Today CISA’s NCCIC-ICS published ten control system security advisories for products from Rockwell Automation (4), Siemens (5), and Tycon Systems. I also take a down-the-rabbit-hole look at exploits for the Siemens CADRA and SIDIS vulnerabilities. 

Advisories  

Rockwell Advisory # 1 - This advisory describes three vulnerabilities in the Rockwell Studio 5000 Logix Designer products. Rockwell published their advisory on July 14th, 2026. 

Rockwell Advisory #2 - This advisory describes an allocation of resources without limit or throttling vulnerability in the Rockwell 1734 POINT I/O. Rockwell published their advisory on July 14th, 2026. 

Rockwell Advisory #3 - This advisory - This advisory describes an allocation of resources without limit or throttling vulnerability in the Rockwell 1718-AENTR/1719-AENTR. Rockwell published their advisory on July 14th, 2026. 

Rockwell Advisory #4 - This advisory describes a weak authentication vulnerability in the Rockwell FactoryTalk Services Platform. Rockwell published their advisory on July 14th, 2026. 

Siemens Advisory #1 - This advisory discusses 11 vulnerabilities in the Siemens CADRA design drafting software. Siemens published their advisory on July 14th, 2026. 

NOTE: See DTRH below for exploitable vulnerabilities. 

Siemens Advisory #2 - This advisory describes an untrusted search path vulnerability in the Siemens IAM Client products. Siemens published their advisory on July 14th, 2026. 

Siemens Advisory #3 - This advisory discusses 12 vulnerabilities in the Siemens SIDIS Secured SmartPlug. Siemens published their advisory on July 14th, 2026. 

NOTE: See DTRH below for exploitable vulnerabilities. 

Siemens Advisory #4 - This advisory describes an improper verification of cryptographic signature vulnerability in the Siemens Opcenter X. Siemens published their advisory on July 14th, 2026. 

Siemens Advisory #5 - This advisory discusses three vulnerabilities in the Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW. Siemens published their advisory on July 14th, 2026. 

Tycon Advisory - This advisory describes two vulnerabilities in the Tycon TPDIN-Monitor-WEB2. 


For more information on these advisories, as well as links for exploits for the Siemens CADRA and SIDIS vulnerabilities, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/10-advisories-published-7-21-26 - subscription required. 

 
/* Use this with templates/template-twocol.html */