Today CISA’s NCCIC-ICS published six control system security advisories for products from ABB. They also published a medical device security advisory for products from Eppendorf. Finally, they updated an advisory for products from Schneider Electric.
Advisories
ABB Advisory #1 - This advisory describes a clear-text storage of sensitive information in memory vulnerability in the ABB LVS MConfig product.
NOTE: I briefly discussed this vulnerability on October 11th, 2025.
ABB Advisory #2 - This advisory discusses 22 vulnerabilities in the ABB Ability Camera Connect product.
NOTE: I briefly discussed these vulnerabilities on March 28th, 2026.
ABB Advisory #3 - This advisory describes an improper resource locking vulnerability in the ABB B&R Automation Runtime product.
NOTE: I briefly discussed this vulnerability on October 11th, 2025.
ABB Advisory #4 - This advisory describes a missing authentication for critical function vulnerability in the ABB Ability Zenon Remote Transport Service.
NOTE: I briefly discussed this vulnerability on August 8th, 2025.
ABB Advisory #5 - This advisory describes a buffer over-read vulnerability in the ABB AC500 V2.
NOTE: I briefly discussed this vulnerability on July 26th, 2025.
ABB Advisory #6 - This advisory describes a heap-based buffer overflow vulnerability in the ABB Terra AC.
NOTE: I briefly discussed the vulnerability on October 25th, 2025.
Eppendorf Advisory - This advisory describes a use of hard-coded password vulnerability in the Eppendorf BioFlo 320 product.
Updates
Schneider Update - This update provides additional information on the Altivar Products advisory that was originally published on September 16th, 2025, and most recently updated on October 23rd, 2025.
For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-1-update-published-a86 - subscription required.