Showing posts with label Instantel. Show all posts
Showing posts with label Instantel. Show all posts

Thursday, August 7, 2025

Review – 8 Advisories and 2 Updates Published – 8-7-25

Today CISA’s NCCIC-ICS published eight control system security advisories for products from Yealink, EG4 Electronics, Dreame Technology, Packet Power, Rockwell Automation, Burk Technology, Johnson Controls, and Delta Electronics. They also updated advisories from Mitsubishi and Instantel.

Advisories

Yealink Advisory - This advisory describes four vulnerabilities in the Yealink IP Phones.

EG4 Advisory - This advisory describes four vulnerabilities in the EGR4 Inverters.

Dreame Advisory - This advisory describes an improper certificate validation vulnerability in the Dreame Dreamehome and MOVAhome mobile applications.

Packet Power Advisory - This advisory describes a missing authentication for critical function vulnerability in the Packet Power EMX and EG products.

Rockwell Advisory - This advisory describes three vulnerabilities in the Rockwell Arena product.

Burk Advisory - This advisory describes a missing authentication for critical function vulnerability in the Burk ARC Solo monitoring and control device.

Johnson Controls Advisory - This advisory describes a dependency on vulnerable third party component vulnerability in the Johnson Controls FX80 and FX90 controllers.

Delta Advisory - This advisory describes a path traversal vulnerability in the Delta DIAView industrial automation management system.

Updates

Mitsubishi Update - This update provides additional information on the Iconics Digital Solutions advisory that was originally published on May 20th, 2025.

Instantel Update - This update provides additional information on the Micromate advisory that was originally published on May 29th, 2025.

 

For more information on these advisories, including links to researcher reports and vendor advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-and-2-updates-published - subscription required.

Thursday, May 29, 2025

Review – 5 Advisories Published – 5-29-25

Today CISA’s NCCIC-ICS published four control system security advisories for products from Instantel, Consilium Safety, and Siemens (2). They also published a medical device security advisory for products from Santsoft.

Advisories

Instantel Advisory - This advisory describes a missing authentication for critical function vulnerability in the Instantel Micromate monitoring device.

Consilium Advisory - This advisory describes two vulnerabilities in the Consilium S5000 Fire Panel.

Siemens Advisory #1 - This advisory describes an out-of-bounds read vulnerability in the Siemens SiPass integrated products.

Siemens Advisory #2 - This advisory describes an improper verification of cryptographic signature vulnerability in the Siemens SiPass integrated products.

Santesoft Advisory - This advisory describes an out-of-bounds read vulnerability in the Santesoft Sante DICOM Viewer Pro.

 

For more information on these advisories, including links to researcher reports, as well as a down-the-rabbit-hole look at the Consilium vulnerability, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-published-5-29-25 - subscription required.
 
/* Use this with templates/template-twocol.html */