Tuesday, April 25, 2023

Review – 2 Advisories Published – 4-25-23

Today, CISA’s NCCIC-ICS published two control system security advisories for products from SCADA-LTS and Keysight.

Advisories

SCADAS-LTS Advisory - This advisory discusses a cross-site scripting vulnerability in the SCADA-LTS open-source HMI.

Keysight Advisory - This advisory describes a deserialization of untrusted data vulnerabilities in the Keysight N8844A Data Analytics Web Service.

 

For more details about these advisories, including links to exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-published-4-25-23 - subscription required.

No comments:

 
/* Use this with templates/template-twocol.html */