Showing posts with label MegaSys. Show all posts
Showing posts with label MegaSys. Show all posts

Tuesday, September 30, 2025

Review – 7 Advisories and 3 Updates Published – 9-30-25

Today CISA’s NCCIC-ICS published seven control system security advisories for products from LG Innotek, National Instruments, OpenPLC, Festo (3) and MegaSys Enterprises. The also published updates for advisories for products from Rockwell Automation, HEIDENHHAIN, and Keysight.

Advisories

LG Advisory - This advisory describes an authentication bypass by alternate path or channel vulnerability in the LG Innotek LND7210 and LNV7210R cameras.

National Instruments Advisory - This advisory describes two vulnerabilities in the NI Circuit Design Suite.

OpenPLC Advisory - This advisory describe a reliance on undefined, unspecified, or implementation defined behavior vulnerability in the OpenPLC_V3 product.

Festo Advisory #1 - This advisory discusses 29 vulnerabilities in the Festo Controller CECC-S,-LK,-D Family Firmware.

Festo Advisory #2 - This advisory describes an improper privilege management vulnerability in the Festo CPX-CEC-C1 and CPX-CMXX hardware control blocks.

Festo Advisory #3 - This advisory discusses four vulnerabilities in the Festo SBRD-Q/SBOC-Q/SBOI-Q series products.

NOTE: I briefly discussed these vulnerabilities on October 2nd, 2021.

MegaSys Advisory - This advisory describes an OS command injection vulnerability in the MegaSys Telenium Online Web Application.

Updates

Rockwell Update - This update provides additional information on the FLEX 5000 I/O advisory that was originally published on August 14th, 2025.

NOTE: I described the problem with the incorrect CVE numbers on August 14th, 2025.

HEIDENHAIN Update - This update provides additional information on the Controller TNC advisory that was originally published on October 25th, 2022.

Keysight Update - This update provides additional information on the Ixia Vision advisory that was originally published on March 4th, 2025.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-3-updates-published-e07 - subscription required.

Tuesday, August 12, 2025

Review – 5 Advisories and 2 Updates Published – 8-12-25

Today CISA’s NCCIC-ICS published four control system security advisories for products from Aveva, Schneider Electric, Johnson Controls, and Ashlar-Vellum. The also published a medical device security advisory for products from Santesoft. Finally, they updated two control system advisories for products from End-of-Train and Megasys.

Schneider published four additional advisories and five updates today. Unless covered by CISA on Thursday, I will address them in my Public ICS Disclosure posts this weekend.

Advisories

AVEVA Advisory - This advisory describes two vulnerabilities in the AVEVA PI Integrator.

Schneider Advisory - This advisory describes five vulnerabilities in the Schneider EcoStruxure Power Monitoring Expert.

Johnson Controls Advisory - This advisory describes six vulnerabilities in multiple iStar products from Johnson Controls.

Ashlar-Vellum Advisory - This advisory describes four vulnerabilities in multiple products from Ashlar-Vellum.

Santesoft Advisory - This advisory describes five vulnerabilities in the Santesoft Sante PACS Server.

Updates

End-of-Train Update - This update provides additional information on the remote linking protocol advisory that was originally published on July 10th 2025.

MegaSys Update - This update provides additional information on the Telenium Online Web Application advisory that was originally published on September 19th, 2024.

 

For more information on these advisories, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-2-updates-published-2b9 - subscription required.

Thursday, September 19, 2024

Review – 5 Advisories and 1 Update Published

Today, CISA’s NCCIC-ICS published five control system security advisories for products for Kastle Systems, MegaSys Computer Technologies, IDEC Corp, and Rockwell Automation. They also updated an advisory for products from Treck.

Advisories

Kastle Advisory - This advisory describes two vulnerabilities in the Kastle Access Control System.

MegaSys Advisory - This advisory describes an improper input validation vulnerability in the MegaSys Telenium Online Web Application.

IDEC Advisory #1 - This advisory describes a cleartext storage of sensitive information vulnerability in the IDEC WindLDR PLC and WindO/I-NV4 HMI.

IDEC Advisory #2 - This advisory describes two vulnerabilities in multiple PLCs from IDEC. The vulnerabilities are self-reported.

Rockwell Advisory - This advisory describes an insufficient verification of data authenticity vulnerability in their RSLogix 5 and RSLogix 500 programming software.

Updates

Treck Update - This update provides additional information on the Treck Ripple20 advisory that was originally published on June 16th, 202 and most recently updated on March 17th, 2022.

 

For more information on these advisories and a down-the-rabbit-hole look at CISA guidance for cloud applications, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-1-update-published-c52 - subscription required.

 
/* Use this with templates/template-twocol.html */