Tuesday, August 18, 2026

Review – 2 Advisories Published – 8-18-26

Today CISA’s NCCIC-ICS published two control system security advisories for products from Siemens and CISA. I also take a down-the-rabbit-hole look at the Github advisories for the CISA Malcom vulnerabilities. 

Advisories  

  • Siemens Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Siemens Simcenter Nastran FEM modeling tool. The vulnerability was reported to Siemens by Michael Heinzl. 
  • CISA Advisory - This advisory describes six vulnerabilities in the CISA Malcom network traffic analysis tool. The vulnerabilities were reported to CISA separately by pavanchow, kah-ja, DeathRipper21, and tinb0y. 


For more information on these advisories, as well as a DTRH look at CISA vulnerability reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-published-8-18-26 - subscription required. 

No comments:

 
/* Use this with templates/template-twocol.html */