Showing posts with label Automated Logic. Show all posts
Showing posts with label Automated Logic. Show all posts

Thursday, March 19, 2026

Review – 8 Advisories Published – 3-19-26

Today CISA’s NCCIC-ICS published control system security advisories for products from Automated Logic, IGL-Technologies, CTEK, Mitsubishi, and Schneider (4).

Advisories

Automated Logic Advisory - This advisory describes three vulnerabilities in the Automated Logic WebCTRL Premium Server.

IGL-Technologies Advisory - This advisory describes four vulnerabilities in the IGL-Technologies eParking.fi.

CTEK Advisory - This advisory describes four vulnerabilities in the CTEK Chargeportal.

NOTE: I briefly discussed Sarieddine/Sayed’s research into vehicle charging systems back on February 26th, 2026. It is interesting that continuing reports into new systems all show the same four vulnerabilities. Does this mean that all of these systems are using the same core technology?

Mitsubishi Advisory - This advisory describes an improper validation of specified index, position, or offset vulnerability in the Mitsubishi CNC Series products.

Schneider Advisory #1 - This advisory describes a deserialization of untrusted data vulnerability in the Schneider EcoStruxure PME and EPO products.

NOTE: I briefly mentioned this vulnerability on March 16th, 2026.

Schneider Advisory #2 - This advisory describes code injection vulnerability in the Schneider EcoStruxure Automation Expert.

NOTE: I briefly mentioned this vulnerability on March 16th, 2026.

Schneider Advisory #3 - This advisory describes a cross-site scripting vulnerability in the Schneider Modicon Controllers.

NOTE: I briefly mentioned this vulnerability on March 16th, 2026.

 

For more information on these advisories, including another ‘missing advisories’ discussion, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-published-3-19-26-552  - subscription required.

Thursday, November 20, 2025

Review – 6 Advisories Published – 11-20-25

Today CISA’s NCCIC-ICS published six control system security advisories for products from Emerson, Festo (2), Opto 22, ICAM365 and Automated Logic.

Advisories

Emerson Advisory - This advisory discusses a stack-based buffer overflow vulnerability in the Emerson Appleton UPSMON-PRO.

Festo Advisory #1 - This advisory discusses an improper input validation vulnerability in the Festo Didactic products.

Festo Advisory #2 - This advisory describes a hidden functionality vulnerability in the Festo MSE6-C2M-5000 product line.

NOTE: I briefly discussed this vulnerability on September 9th, 2023. CERT-VDE updated the Festo advisory (administrative and format changes) on October 1st, 2025.

Opto 22 Advisory - This advisory describes an OS command injection vulnerability in the Opto 22 GRV Programmable Logic Controllers.

ICAM365 Advisory - This advisory describes two missing authentication for critical function vulnerabilities in the ICAM365 ROBOT PT Camera P201 and Night Vision Camera QC021.

Automated Logic Advisory - This advisory describes two vulnerabilities in multiple Automated Logic (and Carrier) products.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published-11-20-25 - subscription required.
 
/* Use this with templates/template-twocol.html */