Showing posts with label Control System Security. Show all posts
Showing posts with label Control System Security. Show all posts

Thursday, September 17, 2026

7 Advisories and 1 Update Published – 9-17-26

Today CISA’s NCCIC-ICS published seven control system security advisories for products from Schneider Electric (3), ABB, Hitachi Energy, Mitsubishi Electric, and Bransys. They also updated an advisory for products from Mitsubishi. 

Advisories  

Schneider Advisory #1 - This advisory describes an improper restriction of excessive authentication attempts vulnerability in the Schneider Electric PowerChute Serial Shutdown. The vulnerability was self-reported. 

Schneider Advisory #2 - This advisory describes two vulnerabilities in the Schneider Electric NetBotz 5 750/755. The vulnerabilities were self-reported. 

Schneider Advisory #3 - This advisory describes an improper input validation vulnerability in the Schneider Electric Modicon M340 Controller and Communication Modules. The Schneider advisory notes that the vulnerability was reported by CyManII. 

ABB Advisory - This advisory discusses the Copy-Fail vulnerability in the ABB Ability Edgenius. The vulnerabilities were self-reported. 

Hitachi Energy Advisory - This advisory describes five vulnerabilities in the Hitachi Energy MicroSCADA Pro/X SYS600 product. The vulnerabilities were self-reported. 

Mitsubishi Advisory - This advisory describes an incorrect implementation of authentication algorithm vulnerability in the Mitsubishi Electric GX Works3 and Motion Control Settings products. The vulnerability was reported by Mayeul Fargier, Erwan Cordier, and Noé Flatreaud. 

Bransys Advisory - This advisory describes three vulnerabilities in the Bransys Electronic Logbook (ELB). The vulnerabilities were reported to CISA by Jaime Lightfoot.  

Updates  

Mitsubishi Update - This update provides additional information on the CC-Link IE TSN Communication Protocol advisory that was originally published on July 30th, 2026. The new information includes updating the list of affected products. 

Tuesday, September 15, 2026

Review – 8 Advisories Published – 9-15-26

Today CISA’s NCCIC-ICS published eight control systems security advisories for products from CareCam, Siemens (3), Schneider Electric, myScada, Wärtsilä, and Digital Watchdog. 

Advisories  

CareCam Advisory - This advisory describes eight vulnerabilities in the CareCam CM2507. The vulnerabilities were reported to CISA by Ben Law. CISA notes that: “CareCam has not responded to CISA's attempts to coordinate.” 

Siemens Advisory #1 - This advisory describes a cross-site scripting vulnerability in the Siemens Teamcenter. The vulnerability was reported by Enzo Alvarez from Bishop Fox. 

Siemens Advisory #2 - This advisory describes an improper verification of cryptographic signature vulnerability in the Siemens Mendix SAML. The vulnerability was self-reported. 

Siemens Advisory #3 - This advisory discusses 14 vulnerabilities in the Siemens Reyrolle 7SR5 motor protection relay. Five of these are third-party (Cesanta Mongoose Web Server) vulnerabilities. 

Schneider Advisory - This advisory describes an insufficiently protected credentials vulnerability in the Schneider Electric SCADAPack x70 Products. The vulnerability was reported to CISA by Abhinav Agarwal. 

MyScada Advisory - This advisory describes two missing authorization vulnerabilities in the mySCADA myPRO Manager. These vulnerabilities were reported to CISA by Shirshak of Secnora OÜ. 

Wärtsilä Advisory - This advisory describes two use of hard-coded cryptographic key vulnerabilities in the Wärtsilä FOS-Onboard fleet optimization software. The vulnerabilities were reported by Cydome Security Ltd. 

Digital Watchdog - This advisory describes six vulnerabilities in the Digital Watchdog VMAX DVR and NVR Product Lineups. The vulnerabilities were reported to CISA by Scot Berner of TrustedSec. 


For more information on these advisories, as well as a DTRH looks at a POC and missing Siemens and Schneider advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-published-9-15-26  - subscription required. 

Thursday, September 10, 2026

Review – 3 Advisories and 1 Update Published – 9-10-26

Today CISA’s NCCIC-ICS published one control system security advisory for products from AVEVA, and two medical device security advisories for products from Orthanc and NextGen. They also updated a control system advisory for products from ST Engineering. 

Advisories  

Aveva Advisory - This advisory describes four vulnerabilities in the AVEVA Pipeline Integrity Monitor. Two of the vulnerabilities were reported by Adham Khairy Ramadan via HackerOne. 

Orthanc Advisory - This advisory describes an integer overflow or wraparound vulnerability in the Orthanc DICOM Server. The vulnerability was reported to CISA by Andrej Tomci 

NextGen Advisory - This advisory describes three vulnerabilities in the NextGen Healthcare Mirth Connect. The vulnerabilities were reported to CISA by Abhinav Agarwal  

Updates  

ST Engineering Update - This update provides additional information on the iDirect iQ-Series Terminals advisory that was originally on July 2nd, 2026. The new information includes adding two vulnerabilities. 


For more information on these advisories, including DTRH looks at exploits in the wild and POC, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-and-1-update-published-091 - subscription required. 

 
/* Use this with templates/template-twocol.html */