Showing posts with label Pelco. Show all posts
Showing posts with label Pelco. Show all posts

Thursday, February 26, 2026

10 Advisories and 3 Updates Published – 2-26-26

Today CISA’s NCCIC-ICS published 10 control system security advisories for products from Copeland, Yokogawa, Mobility46, EV Energy, SWITCH EV, Chargemap, EV2GO, CloudCharge, Pelco, and Johnson Controls. They also published updates for advisories from Honeywell, Schneider Electric, and Hitachi Energy.

Advisories

Copeland Advisory - This advisory describes 23 vulnerabilities in the Copeland XWEB and XWEP Pro plant management software.

Yokogawa Advisory - This advisory describes six vulnerabilities in the Yokogaw Vnet/IP Interface Package used in their CENTUM VP R6 and R7 products.

Mobility46 Advisory - This advisory describes four vulnerabilities in the Mobility46 mobility46.se digital parking management and EV charging solution.

EV Energy Advisory - This advisory describes four vulnerabilities in the EV Energy ev.energy EV charging management solution.

SWITCH EV Advisory - This advisory describes four vulnerabilities in the SWITCH EV SwitchEnergy.com multiple EV charging systems management.

Chargemap Advisory - This advisory describes four vulnerabilities in the Chargemap Chargemap.com EV fleet charging management.

EV2GO Advisory - This advisory describes four vulnerabilities in the EV2GO ev2go.io charging infrastructure management.

CloudCharge Advisory - This advisory describes four vulnerabilities in the CloudCharge cloudcharge.se charging facility management.

Pelco Advisory - This advisory describes an authentication bypass using an alternate path or channel vulnerability in the Pelco Sarix Pro 3 Series IP Cameras.

Johnson Controls Advisory - This advisory describes six vulnerabilities in the Johnson Controls Frick Controls Quantum HD compressor control panel.

Updates

Honeywell Update - This update provides additional information on the HIB2PI and HDZ Series CCTV Cameras advisory that was originally published on February 17th, 2026.

Schneider Update - This update provides additional information on the EcoStruxure Power Operation advisory that was originally published on July 22nd, 2025.

NOTE: I briefly discussed this new information on February 15th, 2026.

Hitachi Energy Update - This update provides additional information on the Relion 670/650/SAM600-IO Series advisory that was originally published on May 13th, 2025, and most recently updated on June 5th, 2025.

NOTE: I briefly mentioned the Hitachi Energy update on February 1st, 2026.

 

For more information on these advisories, including a DTRH look at EV charger cybersecurity research, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/10-advisories-and-3-updates-published-7f5 - subscription required.

Tuesday, June 21, 2016

ICS-CERT Publishes Two Advisories

This afternoon the DHS ICS-CERT published two control system advisories for products from Schneider and Advantech.

Schneider Advisory


This advisory describes a cross-site scripting vulnerability in the Schneider Electric PowerLogic PM8ECC communications add-on module for the Series 800 PowerMeter. The vulnerability is apparently self-reported. Schneider has produced a firmware update for the module.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to inject arbitrary JavaScript in a specially crafted URL request where the response containing user data is returned to the web browser without being made safe to display.

Schneider published their Security Notice on this vulnerability on May 11th, 2016.

Advantech Advisory


This advisory describes multiple vulnerabilities in the Advantech WebAccess product. The vulnerabilities were reported by Zhou Yu of Acorn Network Security. Advantech has produced a new version that mitigates the vulnerabilities. ICS-CERT reports that Zhou has had a chance verify the efficacy of the fix.

The vulnerabilities include:

• Unsafe ActiveX controls marked as safe for scripting - CVE-2016-4525; and
• Classic buffer overflow - CVE-2016-4528.

ICS-CERT reports that a social engineering attack is required to exploit these vulnerabilities, but a successful exploit could allow an attacker to insert and run arbitrary code on an affected system.

The Advantech version notes for the new version (8.1_20160519) produced to correct these vulnerabilities mentions ‘buffer-overrun’ vulnerabilities in BwAspObj.dll and cellvision.ocx, but it does not mention any ActiveX vulnerabilities. It does, however, mention a vulnerability to reveal password in Project User web page that was not mentioned in the ICS-CERT advisory.

Another Schneider Product Vulnerability



When looking for the Schneider Security Note mentioned above I also found another Schneider product vulnerability reported on the Schneider web site. This Security Note was for an elevation of privilege vulnerability in the – Pelco Digital Sentry Video Management System.

Thursday, March 12, 2015

ICS-CERT Publishes Schneider Advisory

Today the DHS ICS-CERT published an advisory for a buffer overflow vulnerability in the Schenider Pelco DS-NVs software package (video management software). The vulnerability was reported by Ariele Caltabiano (kimiya) and Andrea Micalizzi (rgod) via the HP Zero Day Initiative. Schneider has produced a patch which mitigates the vulnerability but there is no indication that the researchers have been given the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to execute arbitrary code.


Neither this advisory nor the Schneider notification identify the vulnerable DLL involved in this vulnerability so it is not possible to tell if the vulnerability would be unique to this application or if it might be found in multiple Schneider products.
 
/* Use this with templates/template-twocol.html */