Showing posts with label Medixant. Show all posts
Showing posts with label Medixant. Show all posts

Thursday, August 6, 2026

Review – 3 Advisories Published – 8-6-26

Today CISA’s NCCIC-ICS published two control system security advisories for products from Johnson Controls and ABB; and one medical device security advisory for products from Medixant. 

Advisories  

Johnson Controls Advisory - This advisory describes a use of broken or risky cryptographic algorithm in the Johnson Controls (Tyco/DSC) TL280 internet security alarm communicator.  

ABB Advisory - This advisory discusses 13 vulnerabilities in the ABB Ability Zenon operations data management tool. 

Medixant Advisory - This advisory describes an out-of-bounds write vulnerability in the Medixant RadiAnt DICOM viewer. 


For more information on these advisories, including DTRH looks at researcher reports and an ABB exploit, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-published-8-6-26 - subscription required. 

Thursday, February 20, 2025

Review – 7 Advisories and an Update Published – 2-20-25

Today CISA’s NCCIC-ICS published six control system security advisories for products from Elesta, Rapid Response Monitoring, Siemens, Carrier, and ABB (2), as well as a medical device security advisory for products from Medixant. They also updated a control system advisory for products from Mitsubishi.

Advisories

Elseta Advisory - This advisory describes an OS command injection vulnerability in the Elseta Vinci Protocol Analyzer.

Rapid Response Advisory - This advisory describes an authorization bypass through user controlled key vulnerability in the Rapid Response Monitoring My Security Account App.

Siemens Advisory - This advisory discusses a path traversal vulnerability in the Siemens SiPass integrated product.

Carrier Advisory - This advisory describes an uncontrolled search path element vulnerability in the Carrier Block Load HVAC load calculation program.

ABB Advisory #1 - This advisory describes three vulnerabilities with publicly available exploit in the ABB FLXeon Controllers.

Medixant Advisory - This advisory that describes an improper certificate validation vulnerability.

Updates

Mitsubishi Update - This update provides additional information on the CNC Series advisory that was originally published on October 17th, 2024.

 

For more information on these advisories, including links to exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-an-update-published - subscription required.

 
/* Use this with templates/template-twocol.html */