Today, CISA’s NCCIC-ICS published six control system security advisories for products from Meari, Johnson Controls (2), ABB, Monta, and Armatura. They also updated an advisory for products from CISA.
Advisories
Meari Advisory - This advisory describes two vulnerabilities in the Meari IoT Cloud Platform OpenAPI. The vulnerabilities were reported to CISA by Gabriel Adams. CISA notes that: “Meari did not respond to CISA's coordination attempts.”
Johnson Controls Advisory #1 - This advisory describes a cleartext transmission of sensitive information vulnerability in the Johnson Controls EasyIO Neo Series EC and CW Controllers. The vulnerability was reported by Gabriele Gardois.
Johnson Controls Advisory #2 - This advisory describes an exposure of sensitive information to an unauthorized actor vulnerability in the Johnson Controls EasyIO Neo Series EC and CW Controllers. The vulnerability was reported by Gabriele Gardois.
ABB Advisory - This advisory describes two vulnerabilities in the ABB Protection and Control IED Manager PCM600. The vulnerabilities were reported by Abhinav Agarwal.
Monta Advisory - This advisory describes four vulnerabilities in the Monta monta.app EV charging application. The vulnerabilities were reported to CISA by an anonymous researcher.
Armatura Advisory - This advisory describes five vulnerabilities in the Armatura LLC Armatura One web-based security platform. The vulnerabilities were reported to CISA by Andrew Capobianco of RewCon.co. One of the vulnerabilities is included in CISA’s Known Exploited Vulnerabilities (KEV) Catalog.
Updates
CISA Update
This update provides additional information on the Malcolm advisory that was originally published on September 11th, 2026. The new information includes adding self-reference to Web version.
For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-1-update-published-fd7 - subscription required.
No comments:
Post a Comment