Showing posts with label ABB. Show all posts
Showing posts with label ABB. Show all posts

Thursday, September 17, 2026

7 Advisories and 1 Update Published – 9-17-26

Today CISA’s NCCIC-ICS published seven control system security advisories for products from Schneider Electric (3), ABB, Hitachi Energy, Mitsubishi Electric, and Bransys. They also updated an advisory for products from Mitsubishi. 

Advisories  

Schneider Advisory #1 - This advisory describes an improper restriction of excessive authentication attempts vulnerability in the Schneider Electric PowerChute Serial Shutdown. The vulnerability was self-reported. 

Schneider Advisory #2 - This advisory describes two vulnerabilities in the Schneider Electric NetBotz 5 750/755. The vulnerabilities were self-reported. 

Schneider Advisory #3 - This advisory describes an improper input validation vulnerability in the Schneider Electric Modicon M340 Controller and Communication Modules. The Schneider advisory notes that the vulnerability was reported by CyManII. 

ABB Advisory - This advisory discusses the Copy-Fail vulnerability in the ABB Ability Edgenius. The vulnerabilities were self-reported. 

Hitachi Energy Advisory - This advisory describes five vulnerabilities in the Hitachi Energy MicroSCADA Pro/X SYS600 product. The vulnerabilities were self-reported. 

Mitsubishi Advisory - This advisory describes an incorrect implementation of authentication algorithm vulnerability in the Mitsubishi Electric GX Works3 and Motion Control Settings products. The vulnerability was reported by Mayeul Fargier, Erwan Cordier, and NoĆ© Flatreaud. 

Bransys Advisory - This advisory describes three vulnerabilities in the Bransys Electronic Logbook (ELB). The vulnerabilities were reported to CISA by Jaime Lightfoot.  

Updates  

Mitsubishi Update - This update provides additional information on the CC-Link IE TSN Communication Protocol advisory that was originally published on July 30th, 2026. The new information includes updating the list of affected products. 

Thursday, August 6, 2026

Review – 3 Advisories Published – 8-6-26

Today CISA’s NCCIC-ICS published two control system security advisories for products from Johnson Controls and ABB; and one medical device security advisory for products from Medixant. 

Advisories  

Johnson Controls Advisory - This advisory describes a use of broken or risky cryptographic algorithm in the Johnson Controls (Tyco/DSC) TL280 internet security alarm communicator.  

ABB Advisory - This advisory discusses 13 vulnerabilities in the ABB Ability Zenon operations data management tool. 

Medixant Advisory - This advisory describes an out-of-bounds write vulnerability in the Medixant RadiAnt DICOM viewer. 


For more information on these advisories, including DTRH looks at researcher reports and an ABB exploit, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-published-8-6-26 - subscription required. 

Tuesday, July 28, 2026

Review – 7 Advisories Published – 7-28-26

Today CISA’s NCCIC-ICS published seven control system security advisories for products from ABB, igloohome, MikroTik, and Siemens (4). 

Advisories  

ABB Advisory - This advisory describes a missing support for integrity check vulnerability in the ABB KNX Update Tool. The ABB advisory reports that: “As classic KNX technology did not include built-in encryption, this vulnerability is not specific to ABB products and cannot be addressed through a software update.” 

Igloohome Advisory - This advisory describes an inclusion of sensitive information in source code vulnerability in the igloohome Smart Lock Mobile Application (Android). 

MikroTik Advisory - This advisory describes an improper restriction of excessive authentication attempts vulnerability in the MikroTik RouterOS and MikroTik Cloud Hosted Router. 

Siemens Advisory #1 - This advisory discusses more than 353 GNU/Linux vulnerabilities in the Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP. 

Siemens Advisory #2 - This advisory describes an allocation of resources without limit or throttling vulnerability in the Siemens SIMATIC S7-PLCSIM Advanced. 

Siemens Advisory #3 - This advisory describes an insecure inherited permissions vulnerability in the Siemens Mendix Runtime product. 

Siemens Advisory #4 - This advisory discusses an out-of-bounds write vulnerability in the Siemens Desigo CC products. 


For more information on these advisories, including DTRH looks at the Mendix vulnerability and Desigo CC exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-published-7-28-26 - subscription required. 

Tuesday, July 14, 2026

Review – 4 Advisories and 1 Update Published – 7-14-26

Today CISA’s NCCIC-ICS published four control systems security advisories for products from Rockwell Automation and ABB (3). 

Advisories  

Rockwell Advisory - This advisory describes a missing authentication for critical function vulnerability in the Rockwell 1715-AENTR EtherNet/IP Adapter. 

ABB Advisory #1 – This advisory describes four vulnerabilities in the ABB T-MAC Plus product.  

ABB Advisory #2 – This advisory discusses an incorrect resource transfer between spheres vulnerability in the ABB Ability Edgenius. This vulnerability is listed in the CISA KEV catalog. 

ABB Advisory #3 – This advisory describes an uncontrolled search path element (for loading DLLs) vulnerability in the ABB Advant Master Online Builder. 

Updates  

Inductive Automation Update #1 - This update provides additional information on the Ignition advisory that was originally published on December 18th, 2026. 


For more information on these advisories, and a list of 11 other Rockwell advisories published today, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-and-1-update-published-714 - subscription required. 

 
/* Use this with templates/template-twocol.html */