Showing posts with label Mitsubishi. Show all posts
Showing posts with label Mitsubishi. Show all posts

Thursday, September 17, 2026

7 Advisories and 1 Update Published – 9-17-26

Today CISA’s NCCIC-ICS published seven control system security advisories for products from Schneider Electric (3), ABB, Hitachi Energy, Mitsubishi Electric, and Bransys. They also updated an advisory for products from Mitsubishi. 

Advisories  

Schneider Advisory #1 - This advisory describes an improper restriction of excessive authentication attempts vulnerability in the Schneider Electric PowerChute Serial Shutdown. The vulnerability was self-reported. 

Schneider Advisory #2 - This advisory describes two vulnerabilities in the Schneider Electric NetBotz 5 750/755. The vulnerabilities were self-reported. 

Schneider Advisory #3 - This advisory describes an improper input validation vulnerability in the Schneider Electric Modicon M340 Controller and Communication Modules. The Schneider advisory notes that the vulnerability was reported by CyManII. 

ABB Advisory - This advisory discusses the Copy-Fail vulnerability in the ABB Ability Edgenius. The vulnerabilities were self-reported. 

Hitachi Energy Advisory - This advisory describes five vulnerabilities in the Hitachi Energy MicroSCADA Pro/X SYS600 product. The vulnerabilities were self-reported. 

Mitsubishi Advisory - This advisory describes an incorrect implementation of authentication algorithm vulnerability in the Mitsubishi Electric GX Works3 and Motion Control Settings products. The vulnerability was reported by Mayeul Fargier, Erwan Cordier, and NoĆ© Flatreaud. 

Bransys Advisory - This advisory describes three vulnerabilities in the Bransys Electronic Logbook (ELB). The vulnerabilities were reported to CISA by Jaime Lightfoot.  

Updates  

Mitsubishi Update - This update provides additional information on the CC-Link IE TSN Communication Protocol advisory that was originally published on July 30th, 2026. The new information includes updating the list of affected products. 

Tuesday, September 1, 2026

Review – 6 Advisories and 2 Updates Published – 9-1-26

Today CISA’s NCCIC-ICS published six control system security advisories for products from Rockwell Automation. They also updated two advisories for products from Rockwell and Mitsubishi. 

Advisories  

Rockwell Advisory #1 - This advisory describes two vulnerabilities in the Rockwell Historian ME. The vulnerabilities were self-reported. 

Rockwell Advisory #2 - This advisory discusses an infinite loop vulnerability in the Rockwell ControlLogix, CompactLogix, and GuardLogix product lines. This is a third-party vulnerability. 

Rockwell Advisory #3 - This advisory describes an improper restriction of excessive authentication attempts vulnerability in the Rockwell FactoryTalk Activation Manager. The vulnerability was reported to Rockwell by an anonymous researcher. 

Rockwell Advisory #4 - This advisory describes an improper restriction of operations within the bounds of a memory buffer vulnerability in the Rockwell Logix Platform. The vulnerability was self-reported. 

Rockwell Advisory #5 - This advisory describes two incorrect default conditions vulnerabilities in the Rockwell Redundancy Module Configuration Tool. The vulnerability was self-reported. 

Rockwell Advisory #6 - This advisory describes four vulnerabilities in the Rockwell RSLinx Classic. The vulnerabilities were self-reported. 

Updates 

Rockwell Update - This update provides additional information on the 1734 POINT I/O advisory that was originally published on July 21st, 2026. The new information includes updating impact statement and CVSS scores. 

Mitsubishi Update - This update provides additional information on the Multiple FA Engineering Software Products advisory that was originally published on May 14th, 2024, and most recently updated on June 9th, 2026. The new information includes updating GENESIS64 and ICONICS Suite affected and fixed versions. 


For more information on these advisories, as well as a DTRH look at a Rockwell exploit and 3 other Rockwell advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-2-updates-published-24b - subscription required. 

Thursday, August 27, 2026

Review – 5 Advisories and 2 Updates Published – 8-27-26

 Today CISA’s NCCIC-ICS published five control system security advisories for products from Ebyte, Applied Systems Engineering, Rockwell Automation, All-Line Equipment, and Xiiaozet. They also updated two advisories for products from Mitsubishi. 

Advisories  

Ebyte Advisory - This advisory describes 13 vulnerabilities in the Ebyte NA111-M serial port server. The vulnerabilities were reported to CISA by Jithin Nambiar. 

Applied Systems Advisory - This advisory describes two vulnerabilities in the Applied Systems Engineering ASE2000 V2 Communications Test Set. The vulnerabilities were reported to CISA by Enoch Wang. 

Rockwell Advisory - This advisory describes a use of password hash with insufficient computational effort vulnerability in the Rockwell OTTO Fleet Manager. The vulnerability was self-reported. 

All-Line Equipment Advisory - This advisory discusses two vulnerabilities (both with public exploits) in the All-Line Fuel-Boss. These vulnerabilities were reported to CISA anonymously. 

Xiiaozet Advisory - This advisory describes three vulnerabilities in the Xiiaozet LK100W wireless print server. The vulnerabilities were reported to CISA by Byron Guernsey of Okachobi, LLC. 

Updates  

Mitsubishi Update #1 - This update provides additional information on the CNC Series advisory that was originally published on March 19th, 2026. 

Mitsubishi Update #2 - This update provides additional information on the Multiple FA Products advisory that was originally published on April 25th, 2025, and most recently updated on April 30th, 2026. 


For more information on these advisories, including a DTRH look at 3rd party exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-2-updates-published-b0d - subscription required. 

 
/* Use this with templates/template-twocol.html */