Tuesday, July 21, 2026

Review – 10 Advisories Published – 7-21-26

Today CISA’s NCCIC-ICS published ten control system security advisories for products from Rockwell Automation (4), Siemens (5), and Tycon Systems. I also take a down-the-rabbit-hole look at exploits for the Siemens CADRA and SIDIS vulnerabilities. 

Advisories  

Rockwell Advisory # 1 - This advisory describes three vulnerabilities in the Rockwell Studio 5000 Logix Designer products. Rockwell published their advisory on July 14th, 2026. 

Rockwell Advisory #2 - This advisory describes an allocation of resources without limit or throttling vulnerability in the Rockwell 1734 POINT I/O. Rockwell published their advisory on July 14th, 2026. 

Rockwell Advisory #3 - This advisory - This advisory describes an allocation of resources without limit or throttling vulnerability in the Rockwell 1718-AENTR/1719-AENTR. Rockwell published their advisory on July 14th, 2026. 

Rockwell Advisory #4 - This advisory describes a weak authentication vulnerability in the Rockwell FactoryTalk Services Platform. Rockwell published their advisory on July 14th, 2026. 

Siemens Advisory #1 - This advisory discusses 11 vulnerabilities in the Siemens CADRA design drafting software. Siemens published their advisory on July 14th, 2026. 

NOTE: See DTRH below for exploitable vulnerabilities. 

Siemens Advisory #2 - This advisory describes an untrusted search path vulnerability in the Siemens IAM Client products. Siemens published their advisory on July 14th, 2026. 

Siemens Advisory #3 - This advisory discusses 12 vulnerabilities in the Siemens SIDIS Secured SmartPlug. Siemens published their advisory on July 14th, 2026. 

NOTE: See DTRH below for exploitable vulnerabilities. 

Siemens Advisory #4 - This advisory describes an improper verification of cryptographic signature vulnerability in the Siemens Opcenter X. Siemens published their advisory on July 14th, 2026. 

Siemens Advisory #5 - This advisory discusses three vulnerabilities in the Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW. Siemens published their advisory on July 14th, 2026. 

Tycon Advisory - This advisory describes two vulnerabilities in the Tycon TPDIN-Monitor-WEB2. 


For more information on these advisories, as well as links for exploits for the Siemens CADRA and SIDIS vulnerabilities, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/10-advisories-published-7-21-26 - subscription required. 

No comments:

 
/* Use this with templates/template-twocol.html */