Showing posts with label Schneider. Show all posts
Showing posts with label Schneider. Show all posts

Thursday, September 17, 2026

7 Advisories and 1 Update Published – 9-17-26

Today CISA’s NCCIC-ICS published seven control system security advisories for products from Schneider Electric (3), ABB, Hitachi Energy, Mitsubishi Electric, and Bransys. They also updated an advisory for products from Mitsubishi. 

Advisories  

Schneider Advisory #1 - This advisory describes an improper restriction of excessive authentication attempts vulnerability in the Schneider Electric PowerChute Serial Shutdown. The vulnerability was self-reported. 

Schneider Advisory #2 - This advisory describes two vulnerabilities in the Schneider Electric NetBotz 5 750/755. The vulnerabilities were self-reported. 

Schneider Advisory #3 - This advisory describes an improper input validation vulnerability in the Schneider Electric Modicon M340 Controller and Communication Modules. The Schneider advisory notes that the vulnerability was reported by CyManII. 

ABB Advisory - This advisory discusses the Copy-Fail vulnerability in the ABB Ability Edgenius. The vulnerabilities were self-reported. 

Hitachi Energy Advisory - This advisory describes five vulnerabilities in the Hitachi Energy MicroSCADA Pro/X SYS600 product. The vulnerabilities were self-reported. 

Mitsubishi Advisory - This advisory describes an incorrect implementation of authentication algorithm vulnerability in the Mitsubishi Electric GX Works3 and Motion Control Settings products. The vulnerability was reported by Mayeul Fargier, Erwan Cordier, and Noé Flatreaud. 

Bransys Advisory - This advisory describes three vulnerabilities in the Bransys Electronic Logbook (ELB). The vulnerabilities were reported to CISA by Jaime Lightfoot.  

Updates  

Mitsubishi Update - This update provides additional information on the CC-Link IE TSN Communication Protocol advisory that was originally published on July 30th, 2026. The new information includes updating the list of affected products. 

Tuesday, September 15, 2026

Review – 8 Advisories Published – 9-15-26

Today CISA’s NCCIC-ICS published eight control systems security advisories for products from CareCam, Siemens (3), Schneider Electric, myScada, Wärtsilä, and Digital Watchdog. 

Advisories  

CareCam Advisory - This advisory describes eight vulnerabilities in the CareCam CM2507. The vulnerabilities were reported to CISA by Ben Law. CISA notes that: “CareCam has not responded to CISA's attempts to coordinate.” 

Siemens Advisory #1 - This advisory describes a cross-site scripting vulnerability in the Siemens Teamcenter. The vulnerability was reported by Enzo Alvarez from Bishop Fox. 

Siemens Advisory #2 - This advisory describes an improper verification of cryptographic signature vulnerability in the Siemens Mendix SAML. The vulnerability was self-reported. 

Siemens Advisory #3 - This advisory discusses 14 vulnerabilities in the Siemens Reyrolle 7SR5 motor protection relay. Five of these are third-party (Cesanta Mongoose Web Server) vulnerabilities. 

Schneider Advisory - This advisory describes an insufficiently protected credentials vulnerability in the Schneider Electric SCADAPack x70 Products. The vulnerability was reported to CISA by Abhinav Agarwal. 

MyScada Advisory - This advisory describes two missing authorization vulnerabilities in the mySCADA myPRO Manager. These vulnerabilities were reported to CISA by Shirshak of Secnora OÜ. 

Wärtsilä Advisory - This advisory describes two use of hard-coded cryptographic key vulnerabilities in the Wärtsilä FOS-Onboard fleet optimization software. The vulnerabilities were reported by Cydome Security Ltd. 

Digital Watchdog - This advisory describes six vulnerabilities in the Digital Watchdog VMAX DVR and NVR Product Lineups. The vulnerabilities were reported to CISA by Scot Berner of TrustedSec. 


For more information on these advisories, as well as a DTRH looks at a POC and missing Siemens and Schneider advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-published-9-15-26  - subscription required. 

Thursday, September 3, 2026

Review – 8 Advisories and 2 Updates Published – 9-3-26

Today CISA’s NCCIC-ICS published eight control system security advisories for products from Tycon Systems, Pyramid Solutions, Inductive Automation, Rockwell Automation (3), IOXN, OPC Foundation. They also updated advisories for products from Tycon Systems and Schneider Electric. 

Advisories  

Tycon Advisory - This advisory describes three vulnerabilities in the Tycon TPDIN-Monitor-WEB3. The vulnerabilities were reported to CISA by Abdiwelli Guled. 

Pyramid Advisory - This advisory discusses a stack-based buffer overflow vulnerability in the Pyramid NetStaX EtherNet/IP Stack. The vulnerability is self-reported. Excellent blog post about the vulnerability on the Pyramid Solutions web site. 

Inductive Advisory - This advisory describes an incorrect default permissions vulnerability in the Inductive Automation Ignition product. The vulnerability was independently reported by Christopher Lusk and Elhussain Fathy. 

Rockwell Advisory #1 - This advisory describes an improper check for unusual or exceptional conditions vulnerability in the Rockwell 1756-ENBT Module. The vulnerability is self-reported. The associated Rockwell advisory has not yet been published. 

Rockwell Advisory #2 - This advisory describes two vulnerabilities in the Rockwell ArmorStart LT. The vulnerabilities are self-reported. 

Rockwell Advisory #3  This advisory describes a missing authentication for critical function vulnerability in the Rockwell ControlFLASH. The vulnerabilities are self-reported. 

IXON Advisory - This advisory describes a CRLF sequence injection vulnerability in the IXON VPN. The vulnerabilities are self-reported. 

OPC Foundation Advisory  This advisory describes an execution with unnecessary privileges vulnerability in the OPC Foundation OPC UA LocalDiscoveryServer (LDS). The vulnerability was reported by Lukas Schumaker of Rockwell Automation. 

Update Summaries  

Tycon Update - This update provides additional information on the TPDIN-Monitor-WEB2 advisory that was originally published on July 21st, 2026. The new information includes updating the affected version range and vulnerability details based on vendor input. 

Schneider Update - This update provides additional information on the Easergy advisory that was originally published on June 18th, 2026. The new information includes revising the summary to reflect the affected products 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-and-2-updates-published-435 - subscription required. 

 
/* Use this with templates/template-twocol.html */