Showing posts with label Daikin. Show all posts
Showing posts with label Daikin. Show all posts

Thursday, September 11, 2025

Review – 10 Advisories and 1 Update Published – 9-11-25

Today CISA’s NCCIC-ICS published ten control system security advisories for products from Daikin, Schneider (2), and Siemens (7). They also updated an advisory for products from Schneider.

Siemens also published eight updates for earlier advisories, but CISA is no longer updating their advisories for Siemens updates. I will cover them in this weekend’s Public ICS Disclosure.

Advisories

Daikin Advisory - This advisory describes a weak password recovery process for forgotten password vulnerability in the Daikin Security Gateway.

Schneider Advisory #1 - This advisory describes a files or directories accessible to external parties vulnerability in multiple Schneider Modicon M340 products.

Schneider Advisory #2 - This advisory describes two vulnerabilities in the Schneider EcoStruxure products.

Siemens Advisory #1 - This advisory describes four vulnerabilities in the Siemens User Management Component (UMC).

Siemens Advisory #2 - This advisory discusses an allocation of resources without limits or throttling vulnerability in the Siemens Industrial Edge Management OS (IEM-OS).

Siemens Advisory #3 - This advisory describes an exposure of sensitive information to an unauthorized actor vulnerability in the Siemens Apogee PXC and Talon TC Devices.

Siemens Advisory #4 - This advisory describes two vulnerabilities in the Siemens SINEC OS.

Siemens Advisory #5 - This advisory describes an improper privilege management vulnerability in the Siemens SINAMICS Drives.

Siemens Advisory #6 - This advisory describes an incorrect permissions assignment for critical function vulnerability in the Siemens SIMATIC Virtualization as a Service (SIVaaS) product.

Siemens Advisory #7 - This advisory discusses an improper check for unusual or exceptional conditions vulnerability in the Siemens SIMOTION Tools.

Updates  

Schneider Update - This update provides additional information on the Modicon M340 advisory that was originally published on February 4th, 2025.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/10-advisories-and-1-update-published - subscription required.

Sunday, May 4, 2025

Review – Public ICS Disclosures – Week of 4-26-25 – Part 2

For Part 2 this week we have three additional vendor disclosures from Splunk, Western Digital, and Wiesemann and Theis. There are also two vendor updates from Hitachi Energy and Palo Alto Networks. We also have nine researcher reports about vulnerabilities in products from Daikin, HP Wolf, Tesla (6), and SonicWall.

Advisories

Splunk Advisory - Splunk published an advisory that discusses 13+ vulnerabilities (six with publicly available exploits) in their User Behavior Analytics product.

Western Digital Advisory - Western Digital published an advisory that discusses 12 vulnerabilities (six with publicly available exploits) in their My Cloud devices.

Wiesemann Advisory - CERT-VDE published an advisory that describes the use of a broken or risky cryptographic algorithm vulnerability in the Wiesemann and Theis Com-Server products.

Updates

Hitachi Energy Update - Hitachi Energy published an update that provides additional information on their RTU500 series advisory that was originally published on March 25th, 2025.

Palo Alto Networks Update - Palo Alto Networks published an update for their GlobalProtect App advisory that was originally published on April 9th, 2025, and most recently updated on April 21st, 2025.

Researcher Reports

Daikin Report - Zero Science published a report that describes an insecure direct object reference vulnerability in the Daikin Security Gateway.

HP Wolf Report - SEC Consult published a report that describes a CSRF vulnerability in the HP Wolf Security Controller, as well as multiple misconfiguration issues.

Tesla Reports - ZDI published six reports about individual vulnerabilities in the Tesla Model S.

SonicWall Report - BishopFox published a report that describes a denial of service vulnerability in the SonicWall Sonic OS product.

 

For more information on these disclosures, including links to exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-d05 - subscription required.

Tuesday, October 11, 2022

Review – 3 Advisories Published – 10-11-22

Today, CISA’s NCCIC-ICS published three controls system security advisories for products from Johnson Controls, Daikin Holdings and Altair.

Johnson Control Advisory - This advisory describes an observable response discrepancy vulnerability in the Johnson Controls C-CURE 9000 security management system.

Daikin Advisory - This advisory describes two vulnerabilities in the Daikin SVMPC1 and SVMPC2 remote controllers.

Altair Advisory - This advisory describes four vulnerabilities in the Altair HyperView Player.

 

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-published-10-11-22 - subscription required.


 
/* Use this with templates/template-twocol.html */