Thursday, February 8, 2024

Review - 1 Advisory and 1 Update Published – 2-8-24

Today, CISA’s NCCIC-ICS published a control system security advisory for products from Qolsys and updated an advisory from ProPump and Controls.


Qolsys Advisory - This advisory describes an exposure of sensitive information to an unauthorized actor vulnerability in the Qolsys (Johnson Controls subsidiary) IQ Panel 4 and IQ4 Hub.


ProPump Update - This update provides additional information on an advisory that was originally published on March 23, 2023.


For more information on these two advisories, including a look at Johnson Controls advisories links and comments on vendor responses to CISA, see my article at CFSN Detailed Analysis - - subscription required.

No comments:

/* Use this with templates/template-twocol.html */