Tuesday, October 6, 2026

Review – 6 Advisories Published – 10-6-26

Today, CISA’s NCCIC-ICS published six control system security advisories for products from Hitachi Energy (4), Savannah, and Johnson Controls. 

NOTE: There has been a minor change in the format of the ‘Vulnerabilities’ section of the CISA advisories; more information is available by default on each CVE. 

Advisories  

Hitachi Energy Advisory #1 - This advisory describes six vulnerabilities in the Hitachi Energy RTU500. The vulnerabilities were reported to CISA by Dragos. 

Hitachi Energy Advisory #2 - This advisory discusses two vulnerabilities in the Hitachi Energy REB500. These are third-party vulnerabilities. 

Hitachi Energy Advisory #3 - This advisory discusses an improper input validation vulnerability in the Hitachi Energy SOI. This is a third-party (Apache) vulnerability that is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. 

Hitachi Energy Advisory #4 - This advisory describes two vulnerabilities in the Hitachi Energy Asset Suite. The vulnerabilities were reported to CISA by EDF. 

Savannah Advisory - This advisory describes a classic buffer overflow vulnerability in the Savannah lwIP SMTP client. The vulnerability was reported by Xchg Labs 

Johnson Control Advisory - This advisory describes two vulnerabilities in the Johnson Controls EasyIO FG. The vulnerabilities were reported by Gabriele Gardois, Zachary Bushell and Lorenzo De Carli of the University of Calgary. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published-10-6-26 - subscription required. 

No comments:

 
/* Use this with templates/template-twocol.html */