Showing posts with label Ashlar-Vellum. Show all posts
Showing posts with label Ashlar-Vellum. Show all posts

Tuesday, May 12, 2026

Review – 6 Advisories and 1 Update Published – 5-12-26

 Today CISA’s NCCIC-ICS published six control system security advisories for products from ABB (4), Subnet Solutions, and Fuji Electric. They also updated an advisory for products from Ashlar-Vellum. 

Advisories  

ABB Advisory #1 - This advisory describes three vulnerabilities in the ABB WebPro SNMP Card PowerValue product. ABB has a new version that mitigates the vulnerabilities. 

ABB Advisory #2 - This advisory discusses an out-of-bounds write vulnerability in the ABB AC500 V3 product. 

ABB Advisory #3 - This advisory discusses an insecure default initialization of resource vulnerability in the ABB Automation Builder product.  

ABB Advisory #4 - This advisory discusses three vulnerabilities in their AC500 V3 products. 

Subnet Advisory - This advisory describes four vulnerabilities in the Subnet Solutions PowerSYSTEM Center. 

Fuji Advisory - This advisory describes an exposed dangerous method or function vulnerability in the Fuji Tellus product. 

Update  

Ashlar-Vellum Update - This update provides additional information on the Cobalt advisory that was originally published on November 25, 2025. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-1-update-published-890 - subscription required. 

Tuesday, November 25, 2025

Review – 6 Advisories and 1 Update Published – 11-25-25

Today CISA’s NCCIC-ICS published five control system security advisories for products from SiRcom, Festo, Opto 22, Zenitel, Rockwell, and Ashlar-Vellum. They also updated an advisory for products from Mitsubishi.

Advisories

SiRcom Advisory - This advisory describes a missing authentication for critical function vulnerability in the SiRcom SMART Alert (SiSA) central control system.

Festo Advisory - This advisory discusses two vulnerabilities in the multiple Festo product lines.

NOTE: I briefly discussed these vulnerabilities on December 3rd, 2022.

Opto 22 Advisory - This advisory describes an exposure of sensitive data through meta data vulnerability in the Opto 22 groov View product line.

Zenitel Advisory - This advisory describes five vulnerabilities in the Zenitel TCIV-3+ IP video intercom.

Rockwell Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Rockwell Arena Simulation product.

NOTE: I briefly discussed this vulnerability on November 16th, 2025.

Ashlar-Vellum Advisory - This advisory describes two vulnerabilities in multiple Ashlar-Vellum products.

Updates

Mitsubishi Update - This update provides additional information on the FA Engineering Software advisory that was originally published on December 5th, 2022, and most recently updated on June 29th, 2023.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-1-update-published-b5e - subscription required.

Tuesday, August 12, 2025

Review – 5 Advisories and 2 Updates Published – 8-12-25

Today CISA’s NCCIC-ICS published four control system security advisories for products from Aveva, Schneider Electric, Johnson Controls, and Ashlar-Vellum. The also published a medical device security advisory for products from Santesoft. Finally, they updated two control system advisories for products from End-of-Train and Megasys.

Schneider published four additional advisories and five updates today. Unless covered by CISA on Thursday, I will address them in my Public ICS Disclosure posts this weekend.

Advisories

AVEVA Advisory - This advisory describes two vulnerabilities in the AVEVA PI Integrator.

Schneider Advisory - This advisory describes five vulnerabilities in the Schneider EcoStruxure Power Monitoring Expert.

Johnson Controls Advisory - This advisory describes six vulnerabilities in multiple iStar products from Johnson Controls.

Ashlar-Vellum Advisory - This advisory describes four vulnerabilities in multiple products from Ashlar-Vellum.

Santesoft Advisory - This advisory describes five vulnerabilities in the Santesoft Sante PACS Server.

Updates

End-of-Train Update - This update provides additional information on the remote linking protocol advisory that was originally published on July 10th 2025.

MegaSys Update - This update provides additional information on the Telenium Online Web Application advisory that was originally published on September 19th, 2024.

 

For more information on these advisories, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-2-updates-published-2b9 - subscription required.

Tuesday, February 4, 2025

Review – 8 Advisories and 1 Update Published – 2-4-25

Today CISA’s NCCIC-ICS published eight control system security advisories for products from AutomationDirect, Schneider (4), Elber, Rockwell Automation, and Western Telematics. They also updated an advisory for products from Ashlar-Vellum.

Advisories

AutomationDirect Advisory - This advisory describes a classic buffer overflow vulnerability in the AutomationDirect C-more EA9 HMI.

Schneider Advisory #1 - This advisory describes an improper enforcement of message integrity during transmission in a communications channel vulnerability in the Schneider Pro-face GP-Pro EX and Remote HMI.

Schneider Advisory #2 - This advisory describes an exposure of sensitive information to unauthorized actor vulnerability in the Schneider Modicon M340 and BMXNOE0100/0110, BMXNOR0200H products.

Schneider Advisory #3 - This advisory describes an improper restriction of XML entity external reference vulnerability in the Schneider Web Designer for Modicon.

Schneider Advisory #4 - This advisory describes an incorrect calculation of buffer size vulnerability in the Schneider M580 PLCs, BMENOR2200H and EVLink Pro AC products.

NOTE: I briefly discussed all four of these Schneider vulnerabilities on January 20th, 2025.

Elber Advisory - This advisory describes two vulnerabilities with publicly available exploits in multiple communication products from Elber.

Rockwell Advisory - This advisory describes an improper handling of exceptional conditions vulnerability in the Rockwell GuardLogix 5380 and 5580 controllers.

Western Telematic Advisory - This advisory describes an external control of file name or path in the Western Telematic NPS Series, DSM Series, CPM Series products.

Updates

Ashlar-Vellum Update - This update provides additional information on the Ashlar-Vellum modeling tools advisory that was originally published on October 24th, 2023.

 

For more information on these advisories, including links to researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-and-1-update-published-4e3 - subscription required.

Saturday, November 18, 2023

Review – Public ICS Disclosures – Week of 11-11-23 – Part 2

For Part 2 we have eight additional vendor disclosures from Schneider (3), Siemens (2), VMware, and Wireshark (2). There are 21 updates from Broadcom, Cisco, Mitsubishi, and Siemens (18). There are four researcher reports for products from Ashlar-Vellum.

Advisories

Schneider Advisory #1 - Schneider published an advisory that describes two vulnerabilities in their s PowerLogic ION8650 and ION8800 products.

Schneider Advisory #2 - Schneider published an advisory that describes two vulnerabilities in their s EcoStruxure™ Power products.

Schneider Advisory #3 - Schneider published an advisory that describes a path traversal vulnerability in their Galaxy VS and VL.

Siemens Advisory #1 - Siemens published an advisory that describes two vulnerabilities in their Simcenter Femap product.

Siemens Advisory #2 - Siemens published an advisory that describes seven vulnerabilities in their Tecnomatix Plant Simulation product.

VMware Advisory - VMware published an advisory that describes an authentication bypass vulnerability in their Cloud Director Appliance.

Wireshark Advisory #1 - Wireshark published an advisory that describes an SSH dissector crash vulnerability.

Wireshark Advisory #2 - Wireshark published an advisory that describes an SSH dissector crash vulnerability.

Updates

Broadcom Update - Broadcom published an update for their GNU Coreutils advisory that was originally published on November 14th, 2023 and most recently updated on November 10th, 2023.

Cisco Update - Cisco published an update for their HTTP/2 Rapid Reset Attack advisory that was originally published on October 16th, 2023 and most recently updated on November 9th, 2023.

Mitsubishi Update - Mitsubishi published an update for their GENESIS64 advisory that was originally published on December 13th, 2022 and most recently updated on August 3rd, 2023.

Siemens Update #1 - Siemens published an update for their SIMATIC IPCs advisory that was originally published on September 12th, 2023.

Siemens Update #2 - Siemens published an update for their Open Design Alliance Drawings SDK advisory that was originally published on June 13th, 2023.

Siemens Update #3 - Siemens published an update for their RUGGEDCOM ROS devices advisory that was originally published on August 8th, 2023.

Siemens Update #4 - Siemens published an update for their RUGGEDCOM ROS advisory that was originally published on July 12th, 2022 and most recently updated on April 11th, 2023.

Siemens Update #5 - Siemens published an update for their SIMATIC S7-1500 TM MFP V1.0 advisory that was originally published on June 13th, 2023 and most recently updated on September 12th, 2023.

Siemens Update #6 - Siemens published an update for their SIMATIC S7-1500 TM MFP V1.0 advisory that was originally published on June 13th, 2203 and most recently update on September 12th, 2023.

Siemens Update #7 - Siemens published an update for their RUGGEDCOM ROS devices advisory that was originally published on November 8th, 2022 and most recently updated on September 12th, 2023.

Siemens Update #8 - Siemens published an update for their RUGGEDCOM ROS Devices advisory that was originally published on August 8th, 2023.

Siemens Update #9 - Siemens published an update for their RUGGEDCOM ROS Devices advisory that was originally published on March 8th, 2022 and most recently updated on March 14th, 2023.

Siemens Update #10 - Siemens published an update for their OPC UA Implementations of SIMATIC Products advisory that was originally published on September 12th, 2023 and most recently updated on October 10th, 2023.

Siemens Update #11 - Siemens published an update for their OPC Foundation advisory that was originally published on April 11th, 2023 and most recently updated on August 8th, 2023.

Siemens Update #12 - Siemens published an update for their RUGGEDCOM APE1808 devices advisory that was originally published on October 10th, 2023.

Siemens Update #13 - Siemens published an update for their SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP advisory that was originally published on November 27th, 2018 and most recently updated on October 10th, 2023.

Siemens Update #14 - Siemens published an update for their Parasolid and Teamcenter Visualization advisory that was originally published on August 8th, 2023.

Siemens Update #15 - Siemens published an update for their SIMATIC WinCC Kiosk Mode advisory that was originally published on May 10th, 2022 and most recently updated on October 10th, 2023.

Siemens Update #16 - Siemens published an update for their Industrial Products using Intel CPUs advisory that was originally published on August 10th, 2021 and most recently updated on May 9th, 2023.

Siemens Update #17 - Siemens published an update for their Insyde BIOS Vulnerabilities advisory that was originally published on February 22nd, 2022 and most recently updated on August 8th, 2023.

Research Reports

Ashlar-Vellum Reports - The Zero Day Initiative published four reports about vulnerabilities in the Ashlar-Vellum Lithium products.

 

For more details about these disclosures, including summaries of changes made in updates and links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-66a - subscription required.

Thursday, October 26, 2023

Review – 8 Advisories and 1 Update Published – 10-26-23

Today, CISA’s NCCIC-ICS published eight control system security advisories for products from Sielco, Rockwell Automation, Ashlar-Vellum, Centralite, and Dingtian. They also updated a medical device security advisory for products from BD Alaris.

Advisories

Sielco Advisory #1 - This advisory describes four vulnerabilities in the Sielco Analog FM Transmitters and Radio Link.

Sielco Advisory #2 - This advisory describes seven vulnerabilities in the Sielco PolyEco FM transmitters.

Rockwell Advisory #1 - This advisory describes an improper authentication vulnerability in the Rockwell FactoryTalk Services Platform web service.

Rockwell Advisory #2 - This advisory describes an improper input validation vulnerability in the Rockwell FactoryTalk View Site Edition.

Rockwell Advisory #3 - This advisory describes two vulnerabilities in the Rockwell Arena simulation software.

Ashlar-Vellum Advisory - This advisory describes two vulnerabilities in the Ashlar-Vellum Cobalt, Graphite, Xenon, Argon, Lithium, and Cobalt Share modeling programs.

Centralite Advisory - This advisory describes an allocation of resources without limits or throttling vulnerability in the Centralite Pearl Thermostat.

Dingtian Advisory - This advisory describes an authentication bypass by capture relay vulnerability in the Dingtian DT-R002 relay.

Updates

BD Alaris Update - This update provides additional information on an advisory that was originally published on July 13th, 2023.

 

For more information on these advisories, including links to researcher advisories, and a down-the-rabbit-hole look at one of the Rockwell advisories - https://patrickcoyle.substack.com/p/8-advisories-and-1-update-published - subscription required.

 

 
/* Use this with templates/template-twocol.html */