Showing posts with label MZ Automation. Show all posts
Showing posts with label MZ Automation. Show all posts

Thursday, July 30, 2026

Review – 11 Advisories and 1 Update Published – 7-30-26

Today CISA’s NCCIC-ICS published 11 control system security advisories for products from MZ Automation (2), Watchfire, 06 Automation, Mitsubishi Electric, NASA, Rockwell Automation, Schneider Electric, Toptech, Johnson Controls, and MikroTik. They also updated an advisory for products from Hardy Barth. 

Advisories  

MZ Automation Advisory #1 - This advisory describes two vulnerabilities in the MZ Automation lib60870. 

MZ Automation Advisory #2 - This advisory describes eight vulnerabilities in the MZ Automation GmbH libiec61850. 

Watchfire Advisory - This advisory describes a hard-coded cryptographic key vulnerability in the Watchfire Controller Software. 

06 Automation Advisory - This advisory describes four vulnerabilities in the o6 Automation open62541 OPC UA stack. 

Mitsubishi Advisory - This advisory describes an improper enforcement of message integrity during transmission in a communication channel vulnerability in the Mitsubishi CC-Link IE TSN Communication Protocol. 

NASA Advisory - This advisory describes a NULL pointer dereference vulnerability in the NASA Core Flight System (cFS) Health & Safety (HS) Application. 

NOTE: This vulnerability is related to an incomplete fix for CVE 2026-15352. 

Rockwell Advisory - This advisory describes an improper check for certificate revocation vulnerability in the Rockwell CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module. 

Schneider Advisory - This advisory describes an out-of-bounds write vulnerability in the Schneider IGSS. 

Toptech Advisory - This advisory describes a missing authentication for critical function vulnerability in the Toptech Systems RCU II+ and Multiload II+. 

Johnson Controls Advisory - This advisory describes three vulnerabilities in the Johnson Controls OpenBlue Employee smart building ecosystem. 

MikroTik Advisory - This advisory describes an insufficient session expiration vulnerability in the MikroTik RouterOS. 

Updates  

Hardy Barth Update -  This update provides additional information on the Salia EV Charge Controller advisory that was originally published on April 21st, 2026. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/11-advisories-and-1-update-published-68f  - subscription required. 

Thursday, July 23, 2026

Review – 7 Advisories Published – 7-23-26

 Today, CISA’s NCCIC-ICS published seven control system security advisories for products from MZ Automation (2), Rockwell, Panduit, Weintek, and Johnson Controls (2). 

Advisories  

MZ Automation Advisory #1 - This advisory describes an out-of-bound read vulnerability in the MZ Automation lib60870. 

MZ Automation Advisory #2 - This advisory describes four vulnerabilities in the MZ Automation libIEC61850. 

Rockwell Advisory - This advisory describes a path traversal vulnerability in the Rockwell Automation ThinManager, 

Panduit Advisory - This advisory describes five vulnerabilities in the Panduit IntraVUE. 

Weintek Advisory - This advisory describes four vulnerabilities in the Weintek cMT3092X HMI. 

Johnson Controls Advisory #1 - This advisory describes a clear text storage of sensitive information vulnerability in the Johnson Controls XAAP Android system inspection application. 

Johnson Controls Advisory #2 - This advisory describes three vulnerabilities in the Johnson Controls C-CURE 9000 and Victor application server. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-published-7-23-26 - subscription required. 

 
/* Use this with templates/template-twocol.html */