Showing posts with label End-of-Train. Show all posts
Showing posts with label End-of-Train. Show all posts

Thursday, September 18, 2025

Review – 7 Advisories and 2 Updates Published – 9-18-25

Today CISA’s NCCIC-ICS published control system security advisories for products from Dover Fueling, Cognex, Hitachi Energy (2), Schneider Electric, and Westermo (2). They also published an update for products from Mitsubishi and End-of-Train.

Advisories

Dover Advisory - This advisory describes three vulnerabilities in the Dover ProGauge MagLink LX4 products.

Cognex Advisory - This advisory describes nine vulnerabilities in the Cognex In-Sight Explorer and In-Sight Camera products.

Hitachi Energy Advisory #1 - This advisory discusses a deserialization of untrusted data vulnerability (with publicly available exploit) in the Hitachi Energy Service Suite.

NOTE: I briefly discussed this vulnerability on August 30th, 2025.

Hitachi Energy Advisory #2 - This advisory discusses six vulnerabilities (two with publicly available exploits) in the Hitachi Energy Asset Suite product.

NOTE: I briefly discussed this vulnerability on August 30th, 2025.

Schneider Advisory - This advisory describes two OS command injection vulnerabilities in the Schneider Saitel DR & Saitel DP remote terminal units.

Westermo Advisory #1 - This advisory describes an improper validation of syntactic correctness of input vulnerability in the Westermo WeOS 5 products.

NOTE: I briefly discussed this vulnerability on March 29th, 2025.

Westermo Advisory #2 - This advisory describes an OS command injection vulnerability in the Westermo WeOS 5 product.

NOTE: I briefly discussed this vulnerability on July 6th, 2025.

Updates

Mitsubishi Update - This update provides additional information on the FA Engineering Software advisory that was originally published on January 30th, 2024, and most recently updated on February 13th, 2025.

End-of-Train Update - This update provides additional information on the Remote Linking Protocol advisory that was originally published on July 10th, 2025, and most recently updated on September 4th, 2025.

 

For more information on these advisories, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-2-updates-published-13d - subscription required.

Thursday, September 4, 2025

Review – 1 Advisory and 4 Updates Published – 9-4-25

Today CISA’s NCCIC-ICS published one control system security advisory for products from Honeywell. They also updated advisories for products from End-of-Train, Honeywell, Delta Electronics, and Mitsubishi Electric Iconics Digital Solutions.

Advisories

Honeywell Advisory - This advisory describes four vulnerabilities in the Honeywell OneWireless wireless device manager (WDM).

Updates

End-of-Train Update - This update provides additional information on the End-of-Train advisory that was originally published on July 10th, 2025, and most recently updated on August 12th, 2025.

Honeywell Update - This update provides additional information on the Experion PKS advisory that was originally published on July 24th, 2025.

Delta Update - This update provides additional information on the COMMGR advisory that was originally published on April 15th, 2025.

Mitsubishi Update - This update provides additional information on the ICONICS Product Suite advisory that was originally published on August 5th, 2025.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-and-4-updates-published - subscription required.

Tuesday, August 12, 2025

Review – 5 Advisories and 2 Updates Published – 8-12-25

Today CISA’s NCCIC-ICS published four control system security advisories for products from Aveva, Schneider Electric, Johnson Controls, and Ashlar-Vellum. The also published a medical device security advisory for products from Santesoft. Finally, they updated two control system advisories for products from End-of-Train and Megasys.

Schneider published four additional advisories and five updates today. Unless covered by CISA on Thursday, I will address them in my Public ICS Disclosure posts this weekend.

Advisories

AVEVA Advisory - This advisory describes two vulnerabilities in the AVEVA PI Integrator.

Schneider Advisory - This advisory describes five vulnerabilities in the Schneider EcoStruxure Power Monitoring Expert.

Johnson Controls Advisory - This advisory describes six vulnerabilities in multiple iStar products from Johnson Controls.

Ashlar-Vellum Advisory - This advisory describes four vulnerabilities in multiple products from Ashlar-Vellum.

Santesoft Advisory - This advisory describes five vulnerabilities in the Santesoft Sante PACS Server.

Updates

End-of-Train Update - This update provides additional information on the remote linking protocol advisory that was originally published on July 10th 2025.

MegaSys Update - This update provides additional information on the Telenium Online Web Application advisory that was originally published on September 19th, 2024.

 

For more information on these advisories, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-2-updates-published-2b9 - subscription required.
 
/* Use this with templates/template-twocol.html */