Thursday, July 23, 2026

Review – 7 Advisories Published – 7-23-26

 Today, CISA’s NCCIC-ICS published seven control system security advisories for products from MZ Automation (2), Rockwell, Panduit, Weintek, and Johnson Controls (2). 

Advisories  

MZ Automation Advisory #1 - This advisory describes an out-of-bound read vulnerability in the MZ Automation lib60870. 

MZ Automation Advisory #2 - This advisory describes four vulnerabilities in the MZ Automation libIEC61850. 

Rockwell Advisory - This advisory describes a path traversal vulnerability in the Rockwell Automation ThinManager, 

Panduit Advisory - This advisory describes five vulnerabilities in the Panduit IntraVUE. 

Weintek Advisory - This advisory describes four vulnerabilities in the Weintek cMT3092X HMI. 

Johnson Controls Advisory #1 - This advisory describes a clear text storage of sensitive information vulnerability in the Johnson Controls XAAP Android system inspection application. 

Johnson Controls Advisory #2 - This advisory describes three vulnerabilities in the Johnson Controls C-CURE 9000 and Victor application server. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-published-7-23-26 - subscription required. 

No comments:

 
/* Use this with templates/template-twocol.html */