Showing posts with label Copeland. Show all posts
Showing posts with label Copeland. Show all posts

Thursday, February 26, 2026

10 Advisories and 3 Updates Published – 2-26-26

Today CISA’s NCCIC-ICS published 10 control system security advisories for products from Copeland, Yokogawa, Mobility46, EV Energy, SWITCH EV, Chargemap, EV2GO, CloudCharge, Pelco, and Johnson Controls. They also published updates for advisories from Honeywell, Schneider Electric, and Hitachi Energy.

Advisories

Copeland Advisory - This advisory describes 23 vulnerabilities in the Copeland XWEB and XWEP Pro plant management software.

Yokogawa Advisory - This advisory describes six vulnerabilities in the Yokogaw Vnet/IP Interface Package used in their CENTUM VP R6 and R7 products.

Mobility46 Advisory - This advisory describes four vulnerabilities in the Mobility46 mobility46.se digital parking management and EV charging solution.

EV Energy Advisory - This advisory describes four vulnerabilities in the EV Energy ev.energy EV charging management solution.

SWITCH EV Advisory - This advisory describes four vulnerabilities in the SWITCH EV SwitchEnergy.com multiple EV charging systems management.

Chargemap Advisory - This advisory describes four vulnerabilities in the Chargemap Chargemap.com EV fleet charging management.

EV2GO Advisory - This advisory describes four vulnerabilities in the EV2GO ev2go.io charging infrastructure management.

CloudCharge Advisory - This advisory describes four vulnerabilities in the CloudCharge cloudcharge.se charging facility management.

Pelco Advisory - This advisory describes an authentication bypass using an alternate path or channel vulnerability in the Pelco Sarix Pro 3 Series IP Cameras.

Johnson Controls Advisory - This advisory describes six vulnerabilities in the Johnson Controls Frick Controls Quantum HD compressor control panel.

Updates

Honeywell Update - This update provides additional information on the HIB2PI and HDZ Series CCTV Cameras advisory that was originally published on February 17th, 2026.

Schneider Update - This update provides additional information on the EcoStruxure Power Operation advisory that was originally published on July 22nd, 2025.

NOTE: I briefly discussed this new information on February 15th, 2026.

Hitachi Energy Update - This update provides additional information on the Relion 670/650/SAM600-IO Series advisory that was originally published on May 13th, 2025, and most recently updated on June 5th, 2025.

NOTE: I briefly mentioned the Hitachi Energy update on February 1st, 2026.

 

For more information on these advisories, including a DTRH look at EV charger cybersecurity research, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/10-advisories-and-3-updates-published-7f5 - subscription required.

Saturday, September 6, 2025

Review – Public ICS Disclosures – Week of 8-30-25

This week we have eight vendor disclosures from Copeland, Dell, Delta Electronics, Endress+Hauser, Hitachi, HPE, Meinberg, and NI. There are also four vendor updates for products from ABB, CODESYS (2), and Mitsubishi. Finally, we have two researcher reports for products from Ilevia and Sunway.

Advisories

Copeland Advisory - Copeland published an advisory that describes 10 vulnerabilities in the E2 and E3 supervisory control products.

Dell Advisory - Dell published an advisory that discusses 147 vulnerabilities in their ThinOS product.

Delta Advisory - Delta published an advisory that describes a missing authentication for critical function vulnerability in their DIAView product.

Endress+Hauser Advisory - CERT-VDE published an advisory that describes an insertion of sensitive information into a log file vulnerability in the Endress+Hauser Promag 10 and Promass 10 products.

Hitachi Advisory - Hitachi published an advisory that discusses 73 vulnerabilities in their Disk Array products.

HPE Advisory - HPE published an advisory that discusses an inclusion of functionality from an untrusted control sphere vulnerability (with publicly available exploits) in their M-Series Switches.

Meinberg Advisory - Meinberg published an advisory that discusses 11 vulnerabilities (four with publicly available exploits) in their Lantime product.

NI Advisory - NI published an advisory that describes seven vulnerabilities in their Digilent DASYLab product.

Updates

ABB Update - ABB published an update for their ELSB/BLBA ASPECT advisory that was originally published on August 8th, 2025, and most recently updated on August 27th, 2025.

CODESYS Update #1 - CODEYSYS published an update for their Exposed PKI folder advisory that was originally published on August 4th, 2025.

CODESYS Update #2 - CODEYSYS published an update for their NULL Pointer Dereference advisory that was originally published on August 4th, 2025.

Mitsubishi Update - Mitsubishi published an update for their GENESIS64 advisory that was originally published on October 22nd, 2024.

Researcher Reports

Ilevia Report - Zero Science Lab published a report about an authorization bypass via alternate path vulnerability in the Ilevia EVE X1/X5 Server.

Sunway Report - VulnCheck published a report describing a stack-based buffer overflow vulnerability in the Sunway Forcecontrol product.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-8a1 - subscription required.
 
/* Use this with templates/template-twocol.html */