Showing posts with label Güralp. Show all posts
Showing posts with label Güralp. Show all posts

Tuesday, January 13, 2026

Review – 3 Advisories and 1 Update Published – 1-13-26

Today CISA’s NCCIC-ICS published three control system security advisories for products from YoSmart and Rockwell Automation (2). They also updated an advisory for products from Güralp.

Advisories

YoSmart Advisory - This advisory describes four vulnerabilities (with publicly available exploit code) in the YoSmart YoLink Smart Hub.

Rockwell Advisory #1 - This advisory describes an SQL injection vulnerability in the Rockwell FactoryTalk DataMosaix Private Cloud.

Rockwell Advisory #2 - This advisory describes an allocation of resources without limit or throttling vulnerability in the Rockwell 432ES-IG3 Series A GuardLink EtherNet/IP Interface.

Update

Güralp Update - This update provides additional information on the FMUS and MIN series devices advisory that was originally published on July 31st, 2025, and most recently updated on August 14th, 2025.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-and-1-update-published-b62 - subscription required.

Tuesday, December 16, 2025

Review – 4 Advisories and 3 Updates Published – 12-16-25

Today CISA’s NCCIC-ICS published four control system security advisories for products from Mitsubishi Electric, Hitachi Energy, Johnson Controls, and Güralp Systems. They also updated advisories for products from Fuji Electric, Johnson Controls, and Mitsubishi Electric.

Advisories

Mitsubishi Advisory - This advisory describes a cleartext storage of sensitive information vulnerability in the Mitsubishi GT Designer3 products.

Hitachi Energy Advisory - This advisory discusses the BlastRadius-Fail vulnerability.

NOTE: I briefly discussed this vulnerability on November 1st, 2025.

Johnson Controls Advisory - This advisory describes four vulnerabilities in the Johnson Controls PowerG, IQPanel and IQHub products.

Güralp Advisory - This advisory describes an allocation of resources without limit or throttling vulnerability in the Güralp Fortimus, Minimus, and Certimus product series.

Updates

Fuji Update - This update provides additional information on the Fuji Monitouch V-SFT-6 advisory that was originally published on November 4th, 2025.

Johnson Controls Update - This update provides additional information on the Johnson Controls iSTAR Ultra advisory that was originally published on August 12th, 2025.

Mitsubishi Update - This update provides additional information on the Mitsubishi GENESIS advisory that was originally published on May 20th, 2025, and most recently updated on August 28th, 2025.

I briefly discussed this update on August 9th, 2025.


For more information on these advisories, including a brief description of the CISA advisory format change, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-and-3-updates-published - subscription required.

Thursday, July 31, 2025

Review – 2 Advisories Published – 7-31-25

Today CISA’s NCCIC-ICS published two control system security advisories for products from Rockwell Automation, and Güralp. I also include a look at the availability of advisories from Rockwell.

Advisories

Rockwell Advisory - This advisory discusses four vulnerabilities in the Rockwell Lifecycle Services with VMware. These are third-party (VMware) vulnerabilities.

Güralp Advisory - This advisory describes a missing authentication for critical function vulnerability in the Güralp FMUS Series Seismic Monitoring Devices.

 

For more information on these advisories, including a down-the-rabbit-hole look at the availability of Rockwell advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-published-7-31-25 - subscription required.

 
/* Use this with templates/template-twocol.html */