Showing posts with label HEIDENHAIN. Show all posts
Showing posts with label HEIDENHAIN. Show all posts

Tuesday, September 30, 2025

Review – 7 Advisories and 3 Updates Published – 9-30-25

Today CISA’s NCCIC-ICS published seven control system security advisories for products from LG Innotek, National Instruments, OpenPLC, Festo (3) and MegaSys Enterprises. The also published updates for advisories for products from Rockwell Automation, HEIDENHHAIN, and Keysight.

Advisories

LG Advisory - This advisory describes an authentication bypass by alternate path or channel vulnerability in the LG Innotek LND7210 and LNV7210R cameras.

National Instruments Advisory - This advisory describes two vulnerabilities in the NI Circuit Design Suite.

OpenPLC Advisory - This advisory describe a reliance on undefined, unspecified, or implementation defined behavior vulnerability in the OpenPLC_V3 product.

Festo Advisory #1 - This advisory discusses 29 vulnerabilities in the Festo Controller CECC-S,-LK,-D Family Firmware.

Festo Advisory #2 - This advisory describes an improper privilege management vulnerability in the Festo CPX-CEC-C1 and CPX-CMXX hardware control blocks.

Festo Advisory #3 - This advisory discusses four vulnerabilities in the Festo SBRD-Q/SBOC-Q/SBOI-Q series products.

NOTE: I briefly discussed these vulnerabilities on October 2nd, 2021.

MegaSys Advisory - This advisory describes an OS command injection vulnerability in the MegaSys Telenium Online Web Application.

Updates

Rockwell Update - This update provides additional information on the FLEX 5000 I/O advisory that was originally published on August 14th, 2025.

NOTE: I described the problem with the incorrect CVE numbers on August 14th, 2025.

HEIDENHAIN Update - This update provides additional information on the Controller TNC advisory that was originally published on October 25th, 2022.

Keysight Update - This update provides additional information on the Ixia Vision advisory that was originally published on March 4th, 2025.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-3-updates-published-e07 - subscription required.

Tuesday, October 25, 2022

Review – 8 Advisories Published – 10-25-22

Today, CISA’s NCCIC-ICS published seven control system security advisories for products from Delta Electronics (2), Johnson Controls, Hitachi Energy, Siemens, HEIDENHAIN, and Haas Automation. They also published a medical device security advisory for products from AliveCor.

Delta Advisory #1 - This advisory describes ten vulnerabilities in the Delta InfraSuite Device Master.

Delta Advisory #2 - This advisory describes eight vulnerabilities in the Delta DIAEnergie.

Johnson Controls Advisory - This advisory describes a cross-site scripting vulnerability in the Johnson Controls (CKS subsidiary) CEVAS deployment management and billing system.

Hitachi Energy Advisory - This advisory describes two reliance on uncontrolled component vulnerabilities in the Hitachi Energy DMS600 integrated with MicroSCADA X.

NOTE: I briefly reported on these vulnerabilities on October 15th, 2022.

Siemens Advisory - This advisory describes a weak authentication vulnerability in the Siemens Siveillance Video Mobile Server.

NOTE: I briefly reported on this vulnerability this last weekend.

HEIDENHAIN Advisory - This advisory describes an improper authentication vulnerability in the HEIDENHAIN TNC 640 controlling a HARTFORD 5A-65E CNC machine.

Haas Advisory - This advisory describes three vulnerabilities in the Haas Controller.

AliveCor Advisory - This advisory describes two vulnerabilities in the AliveCor KardiaMobile smartphone-based personal electrocardiogram (EKG) device.

 

For more details about these advisories, including links to third-party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-published-10-25-22 - subscription required.


 
/* Use this with templates/template-twocol.html */