Showing posts with label Intrado. Show all posts
Showing posts with label Intrado. Show all posts

Thursday, May 7, 2026

Review – 1 Advisory and 4 Updates Published – 5-7-26

 Today CISA’s NCCIC-ICS published one control system security advisory for products from Maxhub. CISA also updated two control system security advisories for products from Schneider and Intrado. They also updated two medical device security advisories for products from Medtronic. 

Advisories  

MAXHUB Advisory - This advisory describes a use of broken or risky cryptographic algorithm vulnerability in the MAXHUB Pivot client application. 

Updates  

Intrado Update - This update provides additional information on the 911 Emergency Gateway advisory that was originally published on April 23rd, 2026. 

Schneider Update - This update provides additional information on the EcoStruxure Control Expert advisory that was originally published on November 26th, 2024.  

NOTE: I briefly mentioned the Schneider update upon which this update was based on April 19th, 2026. 

Medtronic Update #1 - This update provides additional information on the MyCareLink advisory that was originally published on July 24th, 2025. 

Medtronic Update #2 - This update provides additional information on the MyCareLink 24950 advisory that was originally published on August 7th, 2018. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-and-4-updates-published-37a - subscription required. 

Thursday, April 23, 2026

Review – 6 Advisories and 1 Update Published – 4-23-26

 Today CISA’s NCCIC-ICS published six control system security advisories for products from Intrado, Hangzhou Xiongmai Technology Co, SpiceJet, Milesight, Carlson Software, and YADEA. There is also an update for an advisory for products from Schneider Electric. I also take a down-the-rabbit-hole look at a second Hangzhou vulnerability. 

Advisories  

Intrado Advisory This advisory describes a path traversal vulnerability in the Intrado 911 Emergency Gateway. 

Hangzhou Advisory This advisory describes a missing authentication for critical function vulnerability in the Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera. 

SpiceJet Advisory - This advisory describes two vulnerabilities in the SpiceJet Online Booking System. 

Milesight Advisory - This advisory describes five vulnerabilities in multiple Milesight Cameras. 

Carlson Advisory This advisory describes a missing authentication for critical function vulnerability in the Carlson Software VASCO-B GNSS Receiver. 

Yadea Advisory This advisory describes a weak authentication vulnerability in the Yadea T5 Electric Bicycle. 

Updates  

Schneider Update - This update provides additional information on the Modicon Controllers advisory that was originally published on April 23rd, 2026. 


For more information on these advisories, including a down-the-rabbit-hole look at an additional Hangzhou vulnerabilitysee my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-1-update-published-6ff - subscription required. 

Tuesday, June 11, 2024

Review – 5 Advisories and 1 Update Published – 6-11-24

Today, CISA’s NCCIC-ICS published four control system security advisories for products from Intrado, AVEVA (2), and Rockwell Automation. They published a medical device security advisory for products from MicroDicom. They also updated an advisory for products from Schneider.

Advisories

Intrado Advisory - This advisory describes an SQL injection vulnerability in the Intrado 911 Emergency Gateway (EGW).

AVEVA Advisory #1 - This advisory describes a deserialization of untrusted data vulnerability in the AVEVA PI Asset Framework Client.

AVEVA Advisory #2 - This advisory describes a deserialization of untrusted data vulnerability in the AVEVA PI Web API.

Rockwell Advisory - This advisory describes an always-incorrect control flow implementation vulnerability in the Rockwell ControlLogix, GuardLogix, and CompactLogix controllers.

MicroDicom Advisory - This advisory describes two vulnerabilities in the MicroDicom DICOM Viewer medical image viewer.

Updates

Schneider Update - This update provides additional information on the APC Easy UPS advisory that was originally published on April 18th, 2023.

 

For more information on these advisories, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-1-update-published-43c - subscription required
 
/* Use this with templates/template-twocol.html */