Friday, January 10, 2025

Review – Three Advisories and An Update Published – 1-10-25

Today, CISA’s NCCIC-ICS published three control system security advisories for products from Delta Electronics and Schneider (2). They also updated an advisory for products from Rockwell Automation.

Advisories

Delta Advisory - This advisory describes three vulnerabilities in the Delta DRASimuCAD, a robotic simulation platform.

Schneider Advisory #1 - This advisory describes a use of unmaintained third-party components vulnerability in the Schneider Harmony HMI and Pro-face HMI Products.

Schneider Advisory #2 - This advisory describes an improper authentication vulnerability in the Schneider PowerChute Serial Shutdown.

Updates

Rockwell Update - This update provides additional information on the Arena advisory that was originally published on December 10th, 2024.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/three-advisories-and-an-update-published - subscription required.

No comments:

 
/* Use this with templates/template-twocol.html */