Showing posts with label Trane. Show all posts
Showing posts with label Trane. Show all posts

Monday, June 15, 2026

Review - Public ICS Disclosures – Week of 6-6-26 – Part 3

For Part 3 we have three additional vendor disclosures from Genetec (2) and VMware. There are bulk vendor updates from HP (5) and Siemens (10). There are four additional vendor updates from ABB, FortiGuard, Mitsubishi, and Moxa. We also have three researcher reports for vulnerabilities in products from Trane, Vertiv, and Splunk. Finally, we have four exploits for products from Palo Alto Networks (2), FortiGuard, and WatchGuard. 

Advisories  

Genetec Advisory #1 - Genetec published an advisory that describes an incorrect permission assignment for critical resource vulnerability in Genetec product installations deploying RabbitMQ. 

Genetec Advisory #2 - Genetec published an advisory that describes an insertion of sensitive information into a log file vulnerability in their Security Center main server installations. 

VMware Advisory - Broadcom published an advisory that describes three cross-site scripting vulnerabilities in the VMware Cloud Foundation Operations product. 

Bulk Vendor Updates  

HP (5) 

Siemens (10) 

Updates  

ABB Update - ABB published an update for their Freelance Security Lock advisory that was originally published on November 9th, 2025. 

FortiGuard Update FortiGuard published an update for their Sensitive 2FA Information advisory that was originally published on October 14th, 2025. 

Mitsubishi Update - Mitsubishi published an update for their Realtek Chips advisory that was originally published on March 24th, 2026. 

Moxa Update - Moxa published an update for their Diffie-Hellman Key Exchange Protocol advisory that was originally published on June 2nd, 2025. 

Researcher Reports  

Trane Report - Claroty published a report that describes five vulnerabilities in the Trane Tracer SC+ HVAC controller. 

Vertiv Report Claroty published a report that describes two vulnerabilities in the Vertiv’s Liebert IS-UNITY-DP network cards. 

Splunk Report WatchTowr published a report that describes a missing authentication for critical function vulnerability in the PostgreSQL Sidecar Service Endpoint in Splunk Enterprise. 

Exploits  

Palo Alto Networks Exploit #1 - Indoushka published a Metasploit module for a reliance on cookies without validation and integrity checking vulnerability in the PAN GlobalProtect product. 

Palo Alto Networks Exploit #2 - Gray Xploit published an exploit for a reliance on cookies without validation and integrity checking vulnerability in the PAN GlobalProtect product. 

FortiGuard Exploit Indoushka published a Metasploit module for an OS command injection vulnerability in the FortiGuard FortiSandbox product. 

WatchGuard Exploit - Cody Sixteen published an exploit for a logic error vulnerability in the WatchGuard Firebox product. 


For additional information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-81a - subscription required. 

Thursday, March 12, 2026

Review – 6 Advisories and 1 Update Published – 3-12-26

Today CISA’s NCCIC-ICS published six control systems security advisories for products from Inductive Automation, Siemens (4) and Trane. They also updated an advisory for products from Honeywell. Tuesday’s problem of advisories missing from the CISA advisory email continued today with two advisories not being listed.

There were two additional advisories, and 11 updates published by Siemens this week that have not yet been addressed by CISA. I will discuss those this weekend.

Advisories

Inductive Advisory - This advisory describes a deserialization of untrusted data vulnerability in the Inductive Ignition Software.

HELIOX Advisory - This advisory describes an improper restriction of communication channel to intended endpoints vulnerability in the Siemens Heliox EV Chargers.

SIMATIC Advisory - This advisory describes a cross-site scripting vulnerability in the Siemens SIMATIC S7-1500 products.

SIDIS Advisory - This advisory discusses 23 vulnerabilities in the Siemens SIDIS Prime product.

RUGGEDCOM Advisory - This advisory discusses four vulnerabilities in the Siemens RUGGEDCOM APE1808 devices.

Trane Advisory - This advisory describes five vulnerabilities in the Trane Tracer products.

Updates

Honeywell Update - This update provides additional information for the HIB2PI and HDZ Series CCTV Cameras advisory that was originally published on February 17th, 2026, and most recently updated on February 26th, 2026.

 

For more information on these advisories, including a discussion about two more ‘missing advisories’, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-1-update-published-e8f  - subscription required.

Tuesday, August 22, 2023

Review – 3 Advisories and 1 Update Published – 8-22-23

Today, CISA’s NCCIC-ICS published three control system security advisories for products from Rockwell Automation, Trane, and Hitachi Energy. They also updated an advisory for products from Mitsubishi.

Advisories

Rockwell Advisory - This advisory describes three improper input validation vulnerabilities in the Rockwell ThinManager ThinServer.

Trane Advisory - This advisory describes a command injection vulnerability in the Trane and Pivot thermostats.

Hitachi Energy Advisory - This advisory discusses six vulnerabilities in the Hitachi Energy AFF66x Products.

Updates

Mitsubishi Update - This update provides additional information on an advisory that was originally published on May 18th, 2023.

 

For more details about these advisories, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-and-1-update-published-cce - subscription required.

Thursday, January 13, 2022

Review - 7 Advisories and 3 Updates Published 1-13-22

Today, CISA’s NCCIC-ICS published seven control system security advisories for products from Siemens (4), Siemens Electric, and Mitsubishi (2). They also published three updates for products from Mistusbishi, Siemens, and Trane.

SICAM Advisory #1 - This advisory describes an unquoted search path or element vulnerability in their SICAM PQ Analyzer.

SICAM Advisory #2 - This advisory describes two vulnerabilities in the Siemens SICAM A8000.

COMOS Advisory - This advisory describes four vulnerabilities in the Siemens COMOS Web unified data platform.

SIPROTEC Advisory - This advisory describes an improper input validation vulnerability in the SIPROTEC 5 products.

Siemens Energy Advisory - This advisory discusses six of the NUCLEUS:13 vulnerabilities in the Siemens Electric PLUSCONTROL gen 1 products.

MELSEC-F Advisory #1 - This advisory describes an improper initialization vulnerability in the Mitsubishi MELSEC-F Series with FX3U-ENET Ethernet-Internet block.

MELSEC-F Advisory #2 - This advisory describes a lack of administrative control over security vulnerability in the Mitsubishi MELSEC-F Series with FX3U-ENET Ethernet-Internet block.

Mitsubishi Update - This update provides additional information on an advisory that was originally published on October 29th, 2020 and most recently updated on May 18th, 2021.

Siemens Update - This update provides additional information on an advisory that was originally published on April 14th, 2021.

NOTE: Siemens published an update for their version of this advisory on November 9th, 2021.

Trane Update - This update provides additional information on an advisory that was originally published on September 23rd, 2021.

Other Siemens Updates - Siemens published six other updates yesterday that have not been covered by NCCIC-ICS. I will be covering them this weekend.

For more details on these advisories see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-3-updates-published - subscription required.

Thursday, November 18, 2021

Review - 2 Advisories and 4 Updates Published

Today, CISA’s NCCIC-ICS published two medical device security advisories for products from Philips. They also published four updates for products from VISAM, Mitsubishi, Philips and Trane.

Patient Information Center Advisory - This advisory describes three vulnerabilities in the Philips Patient Information Center iX.

IntelliBridge Advisory - This advisory describes two vulnerabilities in the Philips IntelliBridge EC 40 and EC 80 Hub.

VISAM Update - This update provides additional information on an advisory that was originally published on March 24th, 2021 and most recently updated on July 8th, 2021.

Mitsubishi Update - This update provides additional information on an advisory that was originally published on July 30th, 2020 and most recently updated on July 27th, 2021.

Philips Update - This update provides additional information on an advisory that was originally published on September 10th, 2020 and most recently updated on August 31st, 2021.

Trane Update - This update provides additional information on an advisory that was originally published on September 23rd, 2021.

For additional details on these advisories and updates, see my article on CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-4-updates-published - subscription required –

Tuesday, October 19, 2021

Review - 2 Advisories Published – 10-19-21

Today CISA’s NCCIC-ICS published two control system security advisories from products from Trane and AUVESY.

Trane Advisory - This advisory describes a cross-site scripting vulnerability in the Trane Tracer SC Building Automation Controllers.

AUVESY Advisory - This advisory describes 17 vulnerabilities in the AUVESY versiondog data management software.

For more details about the two advisories, including to link to researcher report, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-published-10-19-21 - subscription required.

Thursday, September 23, 2021

Review – 2 Advisories and 1 Update Published – 9-23-21

Today CISA’s NCCIC-ICS published two control system security advisories for products from Trane. They also updated an advisory for products from Ovarro.

Tracer Advisory - This advisory describes a code injection vulnerability in the Trane Tracer building automation controllers.

Symbio Advisory - This advisory describes a code injection vulnerability in the Trane Symbio 700 and Symbio 800 controllers.

Ovarro Update - This update provides additional information on an advisory that was originally published on March 23, 2021.

For more details on these advisories and the update, including some interesting oddities about the update, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-1-update-published-650 - subscription required.

Friday, September 16, 2016

ICS-CERT Publishes 4 Advisories

Yesterday the DHS ICS-CERT published four new control system security advisories for products from Rockwell, Trane, ABB and Yokogawa. The Rockwell advisory had previously been published on the US CERT Secure Portal back on August 11th.

Rockwell Advisory  


This advisory describes a parser buffer overflow vulnerability in the Rockwell RSLogix 500 and RSLogix Micro products. The vulnerability was reported by Ariele Caltabiano (kimiya) via the Zero Day Initiative (ZDI). Rockwell has produced an update that mitigates the vulnerability but there is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that it would be relatively easy to create an exploit that would allow malicious code to execute on the target computer at the same privilege level as the logged-in user. They also report that a social engineering attack would be required to cause an operator to load and execute the malformed RSS file.

Trane Advisory  


This advisory describes an information exposure vulnerability in the Trane Tracer SC field panel. The vulnerability was reported by Maxim Rupp. Trane has produced an update to mitigate this vulnerability and ICS-CERT reports that Maxim Rupp has verified the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to obtain sensitive information from the contents of configuration files not protected by the web server.

ABB Advisory  


This advisory describes a credential management vulnerability in the ABB DataManagerPro application. The vulnerability was reported by Andrea Micalizzi via ZDI. ABB has produced a new version to mitigate the vulnerability, but there is no indication that Micalizzi has been afforded an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker with local system access could exploit the vulnerability to insert and run arbitrary code on a computer where the affected product is used. The ABB Security Advisory reports that an “attacker that manages to get malicious code to a specific directory in the file system of a computer where DataManagerPro is used, could get this code executed by an authenticated and legitimate user of DataManagerPro”.

Yokogawa Advisory


This advisory describes an authentication bypass vulnerability in the Yokogawa STARDOM controller. This vulnerability is apparently being self-reported. Yokogawa has produced a new version that mitigates the vulnerability. The Yokogawa Security Advisory reports that the STARDOM controller does not require authentication to connect to the device.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to execute commands such as stop application program, change values, and modify application.

Cybersecurity for Building Control Systems



ICS-CERT reported that the National Institute of Building Sciences will be holding a series of workshops in Arlington, VA on cybersecurity for building control systems. The ICS-CERT announcement does not provide much in the way of support details (Date, location, cost, etc) but the provided web link to the NIBS workshop site does provide all of the necessary details.
 
/* Use this with templates/template-twocol.html */