Thursday, September 23, 2021

Review – 2 Advisories and 1 Update Published – 9-23-21

Today CISA’s NCCIC-ICS published two control system security advisories for products from Trane. They also updated an advisory for products from Ovarro.

Tracer Advisory - This advisory describes a code injection vulnerability in the Trane Tracer building automation controllers.

Symbio Advisory - This advisory describes a code injection vulnerability in the Trane Symbio 700 and Symbio 800 controllers.

Ovarro Update - This update provides additional information on an advisory that was originally published on March 23, 2021.

For more details on these advisories and the update, including some interesting oddities about the update, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-1-update-published-650 - subscription required.

No comments:

 
/* Use this with templates/template-twocol.html */