Showing posts with label Inductive. Show all posts
Showing posts with label Inductive. Show all posts

Thursday, September 3, 2026

Review – 8 Advisories and 2 Updates Published – 9-3-26

Today CISA’s NCCIC-ICS published eight control system security advisories for products from Tycon Systems, Pyramid Solutions, Inductive Automation, Rockwell Automation (3), IOXN, OPC Foundation. They also updated advisories for products from Tycon Systems and Schneider Electric. 

Advisories  

Tycon Advisory - This advisory describes three vulnerabilities in the Tycon TPDIN-Monitor-WEB3. The vulnerabilities were reported to CISA by Abdiwelli Guled. 

Pyramid Advisory - This advisory discusses a stack-based buffer overflow vulnerability in the Pyramid NetStaX EtherNet/IP Stack. The vulnerability is self-reported. Excellent blog post about the vulnerability on the Pyramid Solutions web site. 

Inductive Advisory - This advisory describes an incorrect default permissions vulnerability in the Inductive Automation Ignition product. The vulnerability was independently reported by Christopher Lusk and Elhussain Fathy. 

Rockwell Advisory #1 - This advisory describes an improper check for unusual or exceptional conditions vulnerability in the Rockwell 1756-ENBT Module. The vulnerability is self-reported. The associated Rockwell advisory has not yet been published. 

Rockwell Advisory #2 - This advisory describes two vulnerabilities in the Rockwell ArmorStart LT. The vulnerabilities are self-reported. 

Rockwell Advisory #3  This advisory describes a missing authentication for critical function vulnerability in the Rockwell ControlFLASH. The vulnerabilities are self-reported. 

IXON Advisory - This advisory describes a CRLF sequence injection vulnerability in the IXON VPN. The vulnerabilities are self-reported. 

OPC Foundation Advisory  This advisory describes an execution with unnecessary privileges vulnerability in the OPC Foundation OPC UA LocalDiscoveryServer (LDS). The vulnerability was reported by Lukas Schumaker of Rockwell Automation. 

Update Summaries  

Tycon Update - This update provides additional information on the TPDIN-Monitor-WEB2 advisory that was originally published on July 21st, 2026. The new information includes updating the affected version range and vulnerability details based on vendor input. 

Schneider Update - This update provides additional information on the Easergy advisory that was originally published on June 18th, 2026. The new information includes revising the summary to reflect the affected products 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-and-2-updates-published-435 - subscription required. 

Thursday, December 18, 2025

Review – 8 Advisories and 1 Update Published – 12-18-25

Today CISA’s NCCIC-ICS published eight control system security advisories for products from Axis Communications, Rockwell Automation, Advantech, Siemens, Mitsubishi Electric, National Instruments, Schneider Electric, and Inductive Automation. They also updated an advisory for products from Mitsubishi.

Advisories

Axis Advisory - This advisory describes four vulnerabilities in multiple Axis surveillance products.

Rockwell Advisory - This advisory describes two vulnerabilities in the Rockwell Micro8xx PLCs.

Advantech Advisory - This advisory describes five vulnerabilities in the Advantech WebAccess/SCADA product.

Siemens Advisory - This advisory describes an improper verification of source of a communications channel vulnerability in the Siemens Interniche IP-Stack used in a wide range of Siemens products.

NOTE: I briefly mentioned this vulnerability on December 14th, 2025.

Mitsubishi Advisory - This advisory describes an OS command injection vulnerability in multiple Mitsubishi Electric Iconics Digital Solutions products.

NI Advisory - This advisory describes nine vulnerabilities in the NI LabView product.

Schneider Advisory - This advisory discusses a deserialization of untrusted data vulnerability in the Schneider EcoStruxure Foxboro DCS Advisor.

NOTE: I briefly discussed this vulnerability on December 14th, 2025.

Inductive Advisory - This advisory describes an execution with unnecessary privileges vulnerability in the Inductive Ignition product.

Updates

Mitsubishi Update - This update provides additional information on the CNC Series advisory that was originally published on October 17th, 2024, and most recently updated on March 18th, 2025

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-and-1-update-published-f72 - subscription required.
 
/* Use this with templates/template-twocol.html */