Thursday, July 24, 2025

Review – 5 Advisories and an Update Published – 7-24-25

Today CISA’s NCCIC-ICS published four control system security advisories for products from LG Innotek, Honeywell, Network Thermostat, and Mitsubishi Electric, as well as a medical device security advisory for products from Medtronic. They also updated an advisory for products from ICONICS/Mitsubishi.

Advisories

LG Advisory - This advisory describes an authentication bypass using an alternate path or channel vulnerability in the LG Innotek camera model LNV510R.

Honeywell Advisory - This advisory describes six vulnerabilities in the Honeywell Experion PKS. The vulnerabilities were reported by Positive Technologies.

Network Thermostat Advisory - This advisory describes a missing authentication for critical function vulnerability in the Network Thermostat X-Series WiFi thermostats.

Mitsubishi Advisory - This advisory discusses an uncontrolled search path element vulnerability in the Mitsubishi CNC Series products.

Medtronic Advisory - This advisory describes three vulnerabilities in the Medtronic MyCareLink Patient Monitors.

Updates

Mitsubishi Update - This update provides additional information on the MC Works64 advisory that was originally published on July 26th, 2022.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-an-update-published - subscription required.

No comments:

 
/* Use this with templates/template-twocol.html */