Saturday, March 28, 2026

Review – Public ICS Disclosures – Week of 3-21-26 – Part 1

This week was a relatively light disclosure week. We have eleven vendor disclosures from ABB, CODESYS (2), Helmholz, Hitachi (2), HP, HPE, MB Connect, Mitsubishi, and Philips.

 

Advisories

 

ABB Advisory - ABB published an advisory that discusses 25 vulnerabilities in their Ability Camera Connect product.

CODESYS Advisory #1 - CODESYS published an advisory that describes the use of an externally-controlled format string vulnerability in their Control and Runtime Toolkit products.

CODESYS Advisory #2 - CODESYS published an advisory that describes an incorrect resource transfer between spheres vulnerability in their Control runtime system.

Helmholz Advisory - CERT-VDE published an advisory that describes two vulnerabilities in the Helmholz myREX24V2 products.

Hitachi Advisory #1 - Hitachi published an advisory that describes a cross-site scripting vulnerability in their Infrastructure Analytics Advisor and Ops Center Analyzer products.4

Hitachi Advisory #2 - Hitachi published an advisory that describes an open redirect vulnerability in their Ops Center Administrator product.

HP Advisory - HP published an advisory that discusses an out-of-bounds write vulnerability in their consumer notebook PCs.

HPE Advisory - HPE published an advisory that discusses three vulnerabilities (two with publicly available exploits) in their Telco Service Orchestrator product.

MB Connect Advisory - MB Connect published an advisory that describes two vulnerabilities in their mbCONNECT24 products.

Mitsubishi Advisory - Mitsubishi published an advisory that discusses a heap-based buffer overflow vulnerability in multiple Mitsubishi HVAC products.

Philips Advisory - Philips published an advisory that discusses a known Oracle missing authentication for critical function vulnerability.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-4d6 - subscription required

No comments:

 
/* Use this with templates/template-twocol.html */