Showing posts with label INVT. Show all posts
Showing posts with label INVT. Show all posts

Tuesday, August 26, 2025

Review – 2 Advisories and 1 Update Published

Today CISA’s NCCIC-ICS published two control system security advisories for products from Schneider Electric and INVT. They also updated an advisory for products from Danfoss.

Advisories

Schneider Advisory - This advisory describes an improper input validation vulnerability in the Schneider Modicon M340 and Communication Modules.

INVT Advisory - This advisory describes nine vulnerabilities in the INVT VT-Designer and HMITool products.

Updates

Danfoss Update - This update provides additional information on the AK-SM 8xxA Series advisory that was originally published on May 20th, 2025.


For more information on these advisories, including links to researcher reports, and a DTRH look at a ‘missing advisory’, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-1-update-published-edb - subscription required.

Thursday, November 29, 2018

One Advisory Published – 11-29-18


Today the DHS NCCIC-ICS published a control system security advisory for products from INVT Electric.

The advisory describes two vulnerabilities in the INVT VT-Designer. The vulnerabilities were reported by Ariele Caltabiano (kimiya) via the Zero Day Initiative. No mitigation measures are currently available for these vulnerabilities.

The two reported vulnerabilities are:

• Deserialization of untrusted data - CVE-2018-18987; and
Heap-based buffer overflow - CVE-2018-18983

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities cause the program to crash and may allow remote code execution.

NOTE: It looks like another Chinese ICS company is not quite responsive to NCCIC-ICS vulnerability coordination efforts.

 
/* Use this with templates/template-twocol.html */