Showing posts with label Pyramid. Show all posts
Showing posts with label Pyramid. Show all posts

Thursday, September 3, 2026

Review – 8 Advisories and 2 Updates Published – 9-3-26

Today CISA’s NCCIC-ICS published eight control system security advisories for products from Tycon Systems, Pyramid Solutions, Inductive Automation, Rockwell Automation (3), IOXN, OPC Foundation. They also updated advisories for products from Tycon Systems and Schneider Electric. 

Advisories  

Tycon Advisory - This advisory describes three vulnerabilities in the Tycon TPDIN-Monitor-WEB3. The vulnerabilities were reported to CISA by Abdiwelli Guled. 

Pyramid Advisory - This advisory discusses a stack-based buffer overflow vulnerability in the Pyramid NetStaX EtherNet/IP Stack. The vulnerability is self-reported. Excellent blog post about the vulnerability on the Pyramid Solutions web site. 

Inductive Advisory - This advisory describes an incorrect default permissions vulnerability in the Inductive Automation Ignition product. The vulnerability was independently reported by Christopher Lusk and Elhussain Fathy. 

Rockwell Advisory #1 - This advisory describes an improper check for unusual or exceptional conditions vulnerability in the Rockwell 1756-ENBT Module. The vulnerability is self-reported. The associated Rockwell advisory has not yet been published. 

Rockwell Advisory #2 - This advisory describes two vulnerabilities in the Rockwell ArmorStart LT. The vulnerabilities are self-reported. 

Rockwell Advisory #3  This advisory describes a missing authentication for critical function vulnerability in the Rockwell ControlFLASH. The vulnerabilities are self-reported. 

IXON Advisory - This advisory describes a CRLF sequence injection vulnerability in the IXON VPN. The vulnerabilities are self-reported. 

OPC Foundation Advisory  This advisory describes an execution with unnecessary privileges vulnerability in the OPC Foundation OPC UA LocalDiscoveryServer (LDS). The vulnerability was reported by Lukas Schumaker of Rockwell Automation. 

Update Summaries  

Tycon Update - This update provides additional information on the TPDIN-Monitor-WEB2 advisory that was originally published on July 21st, 2026. The new information includes updating the affected version range and vulnerability details based on vendor input. 

Schneider Update - This update provides additional information on the Easergy advisory that was originally published on June 18th, 2026. The new information includes revising the summary to reflect the affected products 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-and-2-updates-published-435 - subscription required. 

Thursday, June 23, 2022

Review – 6 Advisories Published – 6-23-22

Today, CISA’s NCCIC-ICS published five control system security advisories for products from Elcomplus, Pyramid Solutions, Secheron, and Yokogawa (2). They also published a medical device control system security advisory for products from OFFIS.

NCCIC-ICS has now reported advisories for four of the ten vendors covered in the OT:ICEFALL report.

Elcomplus Advisory - This advisory describes three vulnerabilities in the Elcomplus SmartICS web-based HMI.

Pyramid Solutions Advisory - This advisory describes an out-of-bounds write vulnerability in the Pyramid Solutions EtherNet/IP Adapter Development Kit.

NOTE: Weidmueller is almost certainly not the only vendor that uses the affected development or DLL kits. This is sure to show up (eventually) as a third-party vulnerability in a number of products.

Secheron Advisory - This advisory describes seven vulnerabilities in the Secheron SEPCOS Control and Protection Relay.

NOTE: There is a vendor level of control over PLC’s? From the description in the advisory, it sounds like admin level access. Could someone try to explain the difference?

Yokogawa Advisory #1 - This advisory describes a violation of secure design principles vulnerability in the Yokogawa Consolidation Alarm Management Software for Human Interface Station (CAMS for HIS) software.

NOTE: I briefly reported on this vulnerability on May 28th, 2022.

Yokogawa Advisory #2 - This advisory discusses OT:ICEFALL vulnerabilities in the Yokogawa STARDOM network control system.

NOTE: NCCIC-ICS still is not providing links to the OT:ICEFALL report or naming Forescout as the authoring agency.

OFFIS Advisory - This advisory describes three vulnerabilities in the OFFIS DCMTK libraries and software that process DICOM image files.

 

For more information on these advisories, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published-6-23-22 - subscription required.

 
/* Use this with templates/template-twocol.html */