Today CISA’s NCCIC-ICS published eight control system security advisories for products from Tycon Systems, Pyramid Solutions, Inductive Automation, Rockwell Automation (3), IOXN, OPC Foundation. They also updated advisories for products from Tycon Systems and Schneider Electric.
Advisories
Tycon Advisory - This advisory describes three vulnerabilities in the Tycon TPDIN-Monitor-WEB3. The vulnerabilities were reported to CISA by Abdiwelli Guled.
Pyramid Advisory - This advisory discusses a stack-based buffer overflow vulnerability in the Pyramid NetStaX EtherNet/IP Stack. The vulnerability is self-reported. Excellent blog post about the vulnerability on the Pyramid Solutions web site.
Inductive Advisory - This advisory describes an incorrect default permissions vulnerability in the Inductive Automation Ignition product. The vulnerability was independently reported by Christopher Lusk and Elhussain Fathy.
Rockwell Advisory #1 - This advisory describes an improper check for unusual or exceptional conditions vulnerability in the Rockwell 1756-ENBT Module. The vulnerability is self-reported. The associated Rockwell advisory has not yet been published.
Rockwell Advisory #2 - This advisory describes two vulnerabilities in the Rockwell ArmorStart LT. The vulnerabilities are self-reported.
Rockwell Advisory #3 This advisory describes a missing authentication for critical function vulnerability in the Rockwell ControlFLASH. The vulnerabilities are self-reported.
IXON Advisory - This advisory describes a CRLF sequence injection vulnerability in the IXON VPN. The vulnerabilities are self-reported.
OPC Foundation Advisory This advisory describes an execution with unnecessary privileges vulnerability in the OPC Foundation OPC UA LocalDiscoveryServer (LDS). The vulnerability was reported by Lukas Schumaker of Rockwell Automation.
Update Summaries
Tycon Update - This update provides additional information on the TPDIN-Monitor-WEB2 advisory that was originally published on July 21st, 2026. The new information includes updating the affected version range and vulnerability details based on vendor input.
Schneider Update - This update provides additional information on the Easergy advisory that was originally published on June 18th, 2026. The new information includes revising the summary to reflect the affected products
For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-and-2-updates-published-435 - subscription required.
No comments:
Post a Comment