Showing posts with label B&R. Show all posts
Showing posts with label B&R. Show all posts

Tuesday, June 30, 2026

Review – 8 Advisories Published – 6-30-26

Today CISA’s NCCIC-ICS published 7 control system security advisories for products from Delta Electronics, Stonefly, B&R Automation, Schneider (2) Frangoteam, and Mitsubishi. They also published a medical device security advisory for products from OFFIS. 

Advisories  

Delta Advisory - This advisory describes two vulnerabilities in the Delta Electronics DVP12SE PLC. 

StoneFly Advisory - This advisory This advisory describes five vulnerabilities in the StoneFly Storage Concentrator. 

B&R Advisory - This advisory discusses a race condition within a thread vulnerability in multiple B&R products.  

Schneider Advisory #1 - This advisory describes two vulnerabilities in the Schneider Electric EasyLogic T150 and Saitel DP RTU. 

Schneider Advisory #2 - This advisory describes an improper restriction of XML external entity reference vulnerability in the Schneider Electric EcoStruxure IT Data Center Expert. 

Frangoteam Advisory - This advisory describes an authentication bypass by spoofing vulnerability in the Frangoteam FUXA SCADA/HMI. 

Mitsubishi Advisory - This advisory discusses four vulnerabilities in the Mitsubishi MELSOFT Update Manager SW1DND-UDM-M.  

OFFIS Advisory - This advisory describes five vulnerabilities in the OFFIS DCMTK Toolkit. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-published-6-30-26 - subscription required. 

Tuesday, June 23, 2026

Review – 7 Advisories and 3 Updates Published – 6-23-26

Today, CISA’s NCCIC-ICS published seven control system security advisories for products from Hubbell, B&R Industrial Automation, ABB, and Siemens (4). They also updated three vulnerabilities from Zero Motorcycles, Rockwell Automation, and Brightpick AI. 

Advisories  

Hubbell Advisory - This advisory describes a missing authentication for critical function vulnerability in the Hubbell Aclara Metrum Cellular Web Interface. 

B&R Advisory - This advisory discusses five vulnerabilities (three with publicly available exploits) in multiple Linux based B&R products. 

ABB Advisory - This advisory describes an authentication bypass by primary weakness vulnerability in the ABB Freelance Security Lock. 

Siemens Advisory #1 - This advisory discusses four vulnerabilities in the Siemens SINEC INS. 

Siemens Advisory #2 - This advisory discusses an out-of-bounds write vulnerability in the Siemens Products using OpenSSL. 

Siemens Advisory #3 - This advisory discusses an unrestricted upload of file with dangerous type vulnerability in the Siemens SIPROTEC 5 Using DIGSI5 Protocol. 

Siemens Advisory #4 - This advisory describes a cleartext storage in a file or on disk vulnerability in the Siemens WinCC Certificate Manager. 

Updates  

Zero Motorcycles Update - This update provides additional information on the firmware advisory that was originally published on March 21st, 2026. 

Rockwell Update - This update provides additional information on the Arena advisory that was originally published on December 10th, 2024, and most recently updated on February 3rd, 2026. 

Brightpick Update - This update provides additional information on the Internal Logic Control advisory that was originally published on November 13th, 2025. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-3-updates-published-d4b - subscription required. 

Saturday, June 13, 2026

Review – Public ICS Disclosures – 6-6-26 – Part 1

This has been a relatively busy disclosure week. For Part 1 we have 14 vendor disclosures from B&R (2), FortiGuard (2), Hitachi (2), HP (3), HPE (4), and Mitsubishi. 

Advisories  

B&R Advisory #1 - B&R published an advisory that discusses five vulnerabilities (four with publicly available exploits) in multiple Linux based B&R products. 

B&R Advisory #2 - B&R published an advisory that discusses a race condition within a thread vulnerability in multiple B&R products. 

FortiGuard Advisory #1 - FortiGuard published an advisory that describes an internal asset exposed to unsafe debug access level or state vulnerability in their FortiOS and FortiProxy products. 

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an OS command injection vulnerability in their FortiSandbox product. 

Hitachi Advisory #1 - Hitachi published an advisory that describes an iSCSI port vulnerability in multiple Hitachi products. 

Hitachi Advisory #2 - Hitachi published an advisory that discusses an improper neutralization of escape, meta or control sequences vulnerability in their Cosminexus HTTP Server and Hitachi Web Server. 

HP Advisory #1 - HP published an advisory that discusses nine vulnerabilities in multiple HP product lines. 

HP Advisory #2 - HP published an advisory that discusses an improper isolation of shared resources on system-on-a-chip vulnerability in multiple HP product lines. 

HP Advisory #3 - HP published an advisory that discusses an improper handling of insufficient entropy in TRNG vulnerability in multiple HP product lines. 

HPE Advisory #1 - HPE published an advisory that discusses an improper access control for register interface vulnerability in their ProLiant AMD Servers. 

HPE Advisory #2 - HPE published an advisory that discusses a race condition vulnerability in their RL300 Server. 

HPE Advisory #3 - HPE published an advisory that discusses the FunkyChunks vulnerability. HPE provides a list of affected products. 

HPE Advisory #4 - HPE published an advisory that discusses a heap-based buffer overflow vulnerability in their Aruba Networking Products. 

Mitsubishi Advisory - Mitsubishi published an advisory that describes a use of hard-coded credentials vulnerability in multiple home appliance products. 


For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis https://patrickcoyle.substack.com/p/public-ics-disclosures-6-6-26-part - subscription required. 

 
/* Use this with templates/template-twocol.html */