Showing posts with label Orthanc. Show all posts
Showing posts with label Orthanc. Show all posts

Thursday, September 10, 2026

Review – 3 Advisories and 1 Update Published – 9-10-26

Today CISA’s NCCIC-ICS published one control system security advisory for products from AVEVA, and two medical device security advisories for products from Orthanc and NextGen. They also updated a control system advisory for products from ST Engineering. 

Advisories  

Aveva Advisory - This advisory describes four vulnerabilities in the AVEVA Pipeline Integrity Monitor. Two of the vulnerabilities were reported by Adham Khairy Ramadan via HackerOne. 

Orthanc Advisory - This advisory describes an integer overflow or wraparound vulnerability in the Orthanc DICOM Server. The vulnerability was reported to CISA by Andrej Tomci 

NextGen Advisory - This advisory describes three vulnerabilities in the NextGen Healthcare Mirth Connect. The vulnerabilities were reported to CISA by Abhinav Agarwal  

Updates  

ST Engineering Update - This update provides additional information on the iDirect iQ-Series Terminals advisory that was originally on July 2nd, 2026. The new information includes adding two vulnerabilities. 


For more information on these advisories, including DTRH looks at exploits in the wild and POC, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-and-1-update-published-091 - subscription required. 

Thursday, February 6, 2025

Review – 6 Advisories Published – 2-6-25

Today CISA’s NCCIC-ICS published four control system security advisories for products from Trimble, ABB, and Schneider (2). They also published two medical device security advisories for products from Orthanc and MicroDicom.

Advisories

Trimble Advisory - This advisory describes a deserialization of untrusted data vulnerability in the Trimble Cityworks asset and work management system.

ABB Advisory - This advisory discusses a path traversal advisory in their Drive Composer products.

Schneider Advisory #1 - This advisory discusses an uncontrolled search path element vulnerability in their EcoStruxure products using FlexNet Publisher.

Schneider Advisory #2 - This advisory describes a deserialization of untrusted data vulnerability in the Schneider EcoStruxure Power Monitoring Expert.

Orthanc Advisory - This advisory describes a missing authentication for critical function vulnerability in the Orthanc Server.

MicroDicom Advisory - This advisory describes an improper certificate validation vulnerability in the MicroDicom DICOM Viewer.

 

For more information on these advisories, including links to 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published-2-6-25 - subscription required.

 
/* Use this with templates/template-twocol.html */