Thursday, October 28, 2021

Review - 1 Advisory and 2 Updates Published – 10-28-21

Today, CISA’s NCCIC-ICS published a control system security advisory for products from Johnson Controls. They also updated two advisories for products from Delta Electronics and Mitsubishi Electric.

Johnson Controls Advisory - This advisory discusses a use of hard-coded credentials vulnerability in the Johnson Controls (American Dynamics) victor Video Management System.

Delta Update - This update provides additional information on an advisory that was originally published on August 26th, 2021.

Mitsubishi Update - This update provides additional information on an advisory that was originally published on October 7th, 2021.

For more details on the advisory and updates, including a link to an exploit and a discussion about the naming of Johnson Control advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-and-2-updates-published - subscription required.

No comments:

 
/* Use this with templates/template-twocol.html */