Thursday, August 27, 2026

Review – 5 Advisories and 2 Updates Published – 8-27-26

 Today CISA’s NCCIC-ICS published five control system security advisories for products from Ebyte, Applied Systems Engineering, Rockwell Automation, All-Line Equipment, and Xiiaozet. They also updated two advisories for products from Mitsubishi. 

Advisories  

Ebyte Advisory - This advisory describes 13 vulnerabilities in the Ebyte NA111-M serial port server. The vulnerabilities were reported to CISA by Jithin Nambiar. 

Applied Systems Advisory - This advisory describes two vulnerabilities in the Applied Systems Engineering ASE2000 V2 Communications Test Set. The vulnerabilities were reported to CISA by Enoch Wang. 

Rockwell Advisory - This advisory describes a use of password hash with insufficient computational effort vulnerability in the Rockwell OTTO Fleet Manager. The vulnerability was self-reported. 

All-Line Equipment Advisory - This advisory discusses two vulnerabilities (both with public exploits) in the All-Line Fuel-Boss. These vulnerabilities were reported to CISA anonymously. 

Xiiaozet Advisory - This advisory describes three vulnerabilities in the Xiiaozet LK100W wireless print server. The vulnerabilities were reported to CISA by Byron Guernsey of Okachobi, LLC. 

Updates  

Mitsubishi Update #1 - This update provides additional information on the CNC Series advisory that was originally published on March 19th, 2026. 

Mitsubishi Update #2 - This update provides additional information on the Multiple FA Products advisory that was originally published on April 25th, 2025, and most recently updated on April 30th, 2026. 


For more information on these advisories, including a DTRH look at 3rd party exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-2-updates-published-b0d - subscription required. 

No comments:

 
/* Use this with templates/template-twocol.html */