Showing posts with label MAXHUB. Show all posts
Showing posts with label MAXHUB. Show all posts

Thursday, May 7, 2026

Review – 1 Advisory and 4 Updates Published – 5-7-26

 Today CISA’s NCCIC-ICS published one control system security advisory for products from Maxhub. CISA also updated two control system security advisories for products from Schneider and Intrado. They also updated two medical device security advisories for products from Medtronic. 

Advisories  

MAXHUB Advisory - This advisory describes a use of broken or risky cryptographic algorithm vulnerability in the MAXHUB Pivot client application. 

Updates  

Intrado Update - This update provides additional information on the 911 Emergency Gateway advisory that was originally published on April 23rd, 2026. 

Schneider Update - This update provides additional information on the EcoStruxure Control Expert advisory that was originally published on November 26th, 2024.  

NOTE: I briefly mentioned the Schneider update upon which this update was based on April 19th, 2026. 

Medtronic Update #1 - This update provides additional information on the MyCareLink advisory that was originally published on July 24th, 2025. 

Medtronic Update #2 - This update provides additional information on the MyCareLink 24950 advisory that was originally published on August 7th, 2018. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-and-4-updates-published-37a - subscription required. 

Thursday, December 4, 2025

Review – 7 Advisories and 2 Updates Published – 12-4-25

Today CISA’s NCCIC-ICS published seven control system security advisories for products from Advantech, Solis Cloud, Sunbird, Johnson Controls (2), MAXHIB, and Mitsubishi. They also updated advisories for products from Johnson Controls and Consilium.

Advisories

Advantech Advisory - This advisory describes an SQL injection vulnerability in the Advantech iView product.

SolisCloud Advisory - This advisory describes an authorization bypass through a user controlled key vulnerability in the SolisCloud Monitoring Platform.

Sunbird Advisory - This advisory describes two vulnerabilities in the Sunbird DCIM dcTrack and Power IQ products.

Johnson Controls Advisory #1 - This advisory describes an improper validation of certificate expiration vulnerability in the Johnson Controls iStar products.

Johnson Controls Advisory #2 - This advisory describes a forced browsing vulnerability in the Johnson Controls OpenBlue Mobile Web Application for OpenBlue Workplace.

MAXHUB Advisory - This advisory describes a weak password recovery mechanism for forgotten password vulnerability in the MAXHUB Pivot client.

Mitsubishi Advisory - This advisory describes a cleartext storage of sensitive information vulnerability in the Mitsubishi GX Works2 product.

NOTE: I briefly discussed this vulnerability on November 29th, 2025.

Updates

Johnson Control Update - This update provides additional information on the FX80 and FX90 advisory that was originally published on August 7th, 2025.

Consilium Update - This update provides additional information on the CS5000 Fire Panel advisory that was originally published on May 29th, 2025.

NOTE: The original CISA advisory noted that no fix was planned for these vulnerabilities. See my May 29th, 2025, post for more information.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-2-updates-published-67d - subscription required.

 
/* Use this with templates/template-twocol.html */