Tuesday, July 28, 2026

Review – 7 Advisories Published – 7-28-26

Today CISA’s NCCIC-ICS published seven control system security advisories for products from ABB, igloohome, MikroTik, and Siemens (4). 

Advisories  

ABB Advisory - This advisory describes a missing support for integrity check vulnerability in the ABB KNX Update Tool. The ABB advisory reports that: “As classic KNX technology did not include built-in encryption, this vulnerability is not specific to ABB products and cannot be addressed through a software update.” 

Igloohome Advisory - This advisory describes an inclusion of sensitive information in source code vulnerability in the igloohome Smart Lock Mobile Application (Android). 

MikroTik Advisory - This advisory describes an improper restriction of excessive authentication attempts vulnerability in the MikroTik RouterOS and MikroTik Cloud Hosted Router. 

Siemens Advisory #1 - This advisory discusses more than 353 GNU/Linux vulnerabilities in the Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP. 

Siemens Advisory #2 - This advisory describes an allocation of resources without limit or throttling vulnerability in the Siemens SIMATIC S7-PLCSIM Advanced. 

Siemens Advisory #3 - This advisory describes an insecure inherited permissions vulnerability in the Siemens Mendix Runtime product. 

Siemens Advisory #4 - This advisory discusses an out-of-bounds write vulnerability in the Siemens Desigo CC products. 


For more information on these advisories, including DTRH looks at the Mendix vulnerability and Desigo CC exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-published-7-28-26 - subscription required. 

No comments:

 
/* Use this with templates/template-twocol.html */