Showing posts with label Control System Security. Show all posts
Showing posts with label Control System Security. Show all posts

Thursday, September 3, 2026

Review – 8 Advisories and 2 Updates Published – 9-3-26

Today CISA’s NCCIC-ICS published eight control system security advisories for products from Tycon Systems, Pyramid Solutions, Inductive Automation, Rockwell Automation (3), IOXN, OPC Foundation. They also updated advisories for products from Tycon Systems and Schneider Electric. 

Advisories  

Tycon Advisory - This advisory describes three vulnerabilities in the Tycon TPDIN-Monitor-WEB3. The vulnerabilities were reported to CISA by Abdiwelli Guled. 

Pyramid Advisory - This advisory discusses a stack-based buffer overflow vulnerability in the Pyramid NetStaX EtherNet/IP Stack. The vulnerability is self-reported. Excellent blog post about the vulnerability on the Pyramid Solutions web site. 

Inductive Advisory - This advisory describes an incorrect default permissions vulnerability in the Inductive Automation Ignition product. The vulnerability was independently reported by Christopher Lusk and Elhussain Fathy. 

Rockwell Advisory #1 - This advisory describes an improper check for unusual or exceptional conditions vulnerability in the Rockwell 1756-ENBT Module. The vulnerability is self-reported. The associated Rockwell advisory has not yet been published. 

Rockwell Advisory #2 - This advisory describes two vulnerabilities in the Rockwell ArmorStart LT. The vulnerabilities are self-reported. 

Rockwell Advisory #3  This advisory describes a missing authentication for critical function vulnerability in the Rockwell ControlFLASH. The vulnerabilities are self-reported. 

IXON Advisory - This advisory describes a CRLF sequence injection vulnerability in the IXON VPN. The vulnerabilities are self-reported. 

OPC Foundation Advisory  This advisory describes an execution with unnecessary privileges vulnerability in the OPC Foundation OPC UA LocalDiscoveryServer (LDS). The vulnerability was reported by Lukas Schumaker of Rockwell Automation. 

Update Summaries  

Tycon Update - This update provides additional information on the TPDIN-Monitor-WEB2 advisory that was originally published on July 21st, 2026. The new information includes updating the affected version range and vulnerability details based on vendor input. 

Schneider Update - This update provides additional information on the Easergy advisory that was originally published on June 18th, 2026. The new information includes revising the summary to reflect the affected products 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-and-2-updates-published-435 - subscription required. 

Tuesday, September 1, 2026

Review – 6 Advisories and 2 Updates Published – 9-1-26

Today CISA’s NCCIC-ICS published six control system security advisories for products from Rockwell Automation. They also updated two advisories for products from Rockwell and Mitsubishi. 

Advisories  

Rockwell Advisory #1 - This advisory describes two vulnerabilities in the Rockwell Historian ME. The vulnerabilities were self-reported. 

Rockwell Advisory #2 - This advisory discusses an infinite loop vulnerability in the Rockwell ControlLogix, CompactLogix, and GuardLogix product lines. This is a third-party vulnerability. 

Rockwell Advisory #3 - This advisory describes an improper restriction of excessive authentication attempts vulnerability in the Rockwell FactoryTalk Activation Manager. The vulnerability was reported to Rockwell by an anonymous researcher. 

Rockwell Advisory #4 - This advisory describes an improper restriction of operations within the bounds of a memory buffer vulnerability in the Rockwell Logix Platform. The vulnerability was self-reported. 

Rockwell Advisory #5 - This advisory describes two incorrect default conditions vulnerabilities in the Rockwell Redundancy Module Configuration Tool. The vulnerability was self-reported. 

Rockwell Advisory #6 - This advisory describes four vulnerabilities in the Rockwell RSLinx Classic. The vulnerabilities were self-reported. 

Updates 

Rockwell Update - This update provides additional information on the 1734 POINT I/O advisory that was originally published on July 21st, 2026. The new information includes updating impact statement and CVSS scores. 

Mitsubishi Update - This update provides additional information on the Multiple FA Engineering Software Products advisory that was originally published on May 14th, 2024, and most recently updated on June 9th, 2026. The new information includes updating GENESIS64 and ICONICS Suite affected and fixed versions. 


For more information on these advisories, as well as a DTRH look at a Rockwell exploit and 3 other Rockwell advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-2-updates-published-24b - subscription required. 

 
/* Use this with templates/template-twocol.html */