Tuesday, March 25, 2025

Review – 4 Advisories Published – 3-25-25

Today CISA’s NCCIC-ICS published four control system security advisories for products from Inaba Denki Sangyo, Rockwell Automation, and ABB.

Advisories

IDS Advisory - This advisory describes four vulnerabilities in the Inaba Denki Sangyo Co CHOCO TEI WATCHER mini camera.

Rockwell Advisory #1 - This advisory discusses an injection vulnerability in the Rockwell 440G TLS-Z safety guard locking switches.

Rockwell Advisory #2 - This advisory describes an improper validation of specified type of input vulnerability in the Rockwell Verve Asset Manager.

ABB Advisory - This advisory discusses a prototype pollution vulnerability (with publicly available exploit) in the Rockwell RMC-100 with REST interface.

 

For more information on these advisories, including links to 3rd party vulnerabilities, researcher reports, and exploits see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-published-3-25-25 - subscription required.

No comments:

 
/* Use this with templates/template-twocol.html */