Thursday, August 13, 2026

15 Advisories Published – 8-13-26

Today, CISA’s NCCIC-ICS published 14 control systems security advisories for products from Johnson Controls (2), Siemens (8), ANDRITZ, Hitachi Energy, Haiwell, and AVEVA. They also published a medical device security advisory for products from Flow Neuroscience. 

Advisories  

Johnson Control Advisory #1 - This advisory describes a cross-site scripting vulnerability in the Johnson Controls Metasys UI. 

Johnson Control Advisory #2 - This advisory describes two vulnerabilities in the Johnson Controls Airwall product. 

Siemens Advisory #1 - This advisory describes two vulnerabilities in the Siemens LOGO! Soft Comfort product. The vulnerability was reported to Siemens by Jeroen Slobbe. 

Siemens Advisory #2 - This advisory describes 7 vulnerabilities in the Siemens Solid Edge products. The vulnerabilities were reported to Siemens by Yutao Wang from YunShangHuaAn and Yu Zhou from Southeast University. 

Siemens Advisory #3 - This advisory describes two vulnerabilities in the Siemens Simcenter Femap product. The vulnerabilities were reported to Siemens by Michael Heinzl. 

Siemens Advisory #4 - This advisory describes an out-of-bounds read vulnerability in the Siemens Parasolid product. The vulnerability was reported to Siemens by Michael Heinzl. 

Siemens Advisory #5 - This advisory discusses an OS command injection vulnerability in the  Siemens Siveillance Video products. This is a third-party (Milestone) vulnerability. 

Siemens Advisory #6 - This advisory describes an improper check for unusual or exceptional conditions vulnerability in the Siemens Desigo DXR and PXC Controllers. The vulnerability was reported to Siemens by Thomas EBI from Sauter.  

Siemens Advisory #7 - This advisory describes two vulnerabilities in the Siemens License Server. The vulnerabilities were reported to Siemens by Intel PSIRT. 

Siemens Advisory #8 - This advisory discusses two vulnerabilities in the Siemens RUGGEDCOM APE1808 products. These are third-party (FortiGuard) vulnerabilities. 

ANDRITZ Advisory - This advisory describes four vulnerabilities in the ANDRITZ HIPASE-250 and 250 SCALA products. The vulnerabilities were reported to CISA by Duc Anh Nguyen and Ta Duc Thien of NTCS OT Penetration Testing Team. 

Hitachi Energy Advisory - This advisory discusses the Dirty Frag vulnerabilities in the Hitachi Energy APM Edge Product. 

Haiwell Advisory - This advisory describes an OS command injection vulnerability in the Haiwell Haiwell IoT Cloud HMI Gateway. The vulnerability was reported to CISA by Fiqram Akmal. 

AVEVA Advisory - This advisory describes a deserialization of untrusted data vulnerability in the AVEVA Enterprise SCADA.  

Flow Advisory - This advisory describes a use of hard-coded credentials vulnerability in the Flow Neuroscience FL-100 neuromodulation device. The vulnerability was reported to CISA by A.C. Buglione. 

No comments:

 
/* Use this with templates/template-twocol.html */