Showing posts with label Weintek. Show all posts
Showing posts with label Weintek. Show all posts

Thursday, July 23, 2026

Review – 7 Advisories Published – 7-23-26

 Today, CISA’s NCCIC-ICS published seven control system security advisories for products from MZ Automation (2), Rockwell, Panduit, Weintek, and Johnson Controls (2). 

Advisories  

MZ Automation Advisory #1 - This advisory describes an out-of-bound read vulnerability in the MZ Automation lib60870. 

MZ Automation Advisory #2 - This advisory describes four vulnerabilities in the MZ Automation libIEC61850. 

Rockwell Advisory - This advisory describes a path traversal vulnerability in the Rockwell Automation ThinManager, 

Panduit Advisory - This advisory describes five vulnerabilities in the Panduit IntraVUE. 

Weintek Advisory - This advisory describes four vulnerabilities in the Weintek cMT3092X HMI. 

Johnson Controls Advisory #1 - This advisory describes a clear text storage of sensitive information vulnerability in the Johnson Controls XAAP Android system inspection application. 

Johnson Controls Advisory #2 - This advisory describes three vulnerabilities in the Johnson Controls C-CURE 9000 and Victor application server. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-published-7-23-26 - subscription required. 

Thursday, January 22, 2026

Review – 8 Advisories and 2 Updates Published – 1-22-26

Today CISA’s NCCIC-ICS published eight control system security advisories for products from EVMAPA, Delta Electronics, Hubitat, Weintek, Johnson Controls, Rockwell Automation, and Schneider Electric. They also updated two advisories for products from Hitachi Energy, and Axis Communications.

Advisories

EVMAPA Advisory - This advisory describes three vulnerabilities in the EVMAPA vehicle charging software.

Delta Advisory - This advisory describes a command injection vulnerability in the Delta DIAView product.

NOTE: I briefly discussed this vulnerability on January 17th, 2026.

Hubitat Advisory - This advisory describes an authorization bypass through user controlled key vulnerability Hubitat Elevation Hubs (home automation hubs).

Weintek Advisory - This advisory describes two vulnerabilities in the Weintek cMT X Series HMI EasyWeb Service.

Johnson Controls Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Johnson Control iSTAR Configuration Utility (ICU) tool.

Rockwell Advisory - This advisory describes an improper validation of specified quantity in input vulnerability in the Rockwell CompactLogix 5370 PLCs.

AutomationDirect Advisory - This advisory describes two vulnerabilities in the AutomationDirect CLICK Programmable Logic Controller.

Schneider Advisory - This advisory that describes an incorrect default permissions vulnerability in their EcoStruxure Process Expert products

NOTE: I briefly discussed this vulnerability on January 17th, 2026.

Updates

Hitachi Energy Update - This update provides additional information on the Relion 670/650 advisory that was originally published on July 3rd, 2025, and most recently updated on August 28th, 2025.

NOTE: I briefly discussed this updated information on December 14th, 2025.

Axis Update - This update provides additional information on the Camera Station Pro advisory that was originally published on December 18th, 2025, and most recently updated on January 15th, 2026.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-and-2-updates-published-68c - subscription required.

Thursday, November 2, 2023

Review – 6 Advisories Published – 11-2-23

Today, CISA’s NCCIC-ICS published six control system security advisories for products from Schneider Electric, Weintek, Franklin Fueling Systems, Mitsubishi Electric (2), and Red Lion.

Advisories

Schneider Advisory - This advisory describes two vulnerabilities in the Schnieder SpaceLogic C-Bus Toolkit.

Weintek Advisory - This advisory describes a use of hard-coded credentials vulnerability in the Weintek EasyBuilder Pro products.

Franklin Advisory - This advisory describes a use of password hash with insufficient computational effort vulnerability in the Franklin Fueling Systems TS-550 product.

Mitsubishi Advisory #1 - This advisory describes an insufficient verification of data authenticity vulnerability in the Mitsubishi MELSEC Series products.

Mitsubishi Advisory #2 - This advisory describes an improper restriction of excessive authentication attempts vulnerability in the Mitsubishi MELSEC iQ-F Series products.

Red Lion Advisory - This advisory describes an improper neutralization of null byte or null character vulnerability in the Red Lion Crimson 3.2 Windows-based configuration tool.

 

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published-11-2-23 - subscription required.

Thursday, October 12, 2023

Review – 18 Advisories and 1 Updates Published

Today, CISA’s NCCIC-ICS published 16 control system security advisories for products from Schneider, Advantech, Hikvision, Mitsubishi, Weintek, and Siemens (11) and two medical device security advisories for products from Santesoft. They also updated an advisory for products from PTC.

Siemens published one additional advisory (and 11 updates) on Tuesday that were not covered here. CISA no longer updates their Siemens advisories. I will discuss all them this weekend in my Public ICS Disclosure blog post.

Advisories

Schneider Advisory - This advisory describes a missing authentication for critical function vulnerability in the Schneider Interactive Graphical SCADA System (IGSS).

Advantech Advisory - This advisory describes an exposure of sensitive information to an unauthorized actor vulnerability in the Advantech WebAccess product.

Hikvision Advisory - This advisory describes two vulnerabilities in the Hikvision Access Control and Intercom Products.

Mitsubishi Advisory - This advisory describes an improper authentication vulnerability in the Mitsubishi MELSEC-F Series main modules.

Weintek Advisory - This advisory describes three vulnerabilities in the Weintek cMT3000 CMI Web CGI.

Mendix Advisory - This advisory describes an observable discrepancy vulnerability in the Siemens Mendix Forgot Password Module.

Tecnomatix Advisory - This advisory describes seven vulnerabilities in the Siemens Tecnomatix Plant Simulation product.

SICAM Advisory #1 - This advisory describes a use of hard-coded credentials vulnerability in the Siemens CP-8050 and CP-8031 master modules.

SICAM Advisory #2 - This advisory describes an incorrect permission assignment for a critical resource vulnerability in the Siemens SICAM PAS/PQS.

SICAM Advisory #3 - This advisory describes a path traversal advisory vulnerability in the Siemens SICAM A8000 CP-8031 and CP-8050 master modules.

SINEC Advisory - This advisory describes two vulnerabilities in the Siemens SINEC NMS.

RUGGEDCOM Advisory - This advisory discusses seven vulnerabilities in the Siemens RUGGEDCOM APE1808.

Simcenter Advisory - This advisory describes a code injection vulnerability in the Siemens Simcenter Amesim product.

Xpedition Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Siemens Xpedition Layout Browser.

SCALANCE Advisory - This advisory discusses thirteen vulnerabilities in the Siemens SCALANCE W1750D.

SIMATIC Advisory - This advisory describes two vulnerabilities in the Siemens SIMATIC CP products.

Santesoft Advisory #1 - This advisory describes an out-of-bounds read vulnerability in the Santesoft Sante FFT Imaging.

Santesoft Advisory #2 - This advisory describes two vulnerabilities in the Santesoft Sante DICOM Viewer Pro.

Updates

PTC Update - This update provides additional information on an advisory that was originally published on August 31st, 2023.

 

For more information on these advisories, including lists of missing vulnerabilities, links to 3rd party advisories and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/18-advisories-and-1-updates-published - subscription required.

Tuesday, February 14, 2023

Review - 1 Advisory Published – 2-14-23

Today, CISA’s NCCIC-ICS published a control system security advisory for products from Weintek.

Weintek Advisory - This advisory describes a path traversal vulnerability in the Weintek EasyBuilder Pro project management software.

 

For more details on this advisory, and a down-the-rabbit-hole look at the 2019 bug that allowed researchers to develop proof-of-concept code for the Weintek vulnerability, see my article at CFSN Detailed Analysis - - subscription required.

Tuesday, March 23, 2021

4 Advisories and 2 Updates Published – 3-23-21

Today the CISA NCCIC-ICS published four control system security advisories for products from Ovarro, GE Grid Solutions (2), and Weintek. They also published two updates for products from Rockwell Automation.

Ovarro Advisory

This advisory describes five vulnerabilities in the Ovarro TBox remote terminal units. The vulnerabilities were reported by Uri Katz of Claroty. Ovarro has new versions that mitigate the vulenrabilities. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Code injection - CVE-2021-22646,

• Incorrect permission assignment for critical resource - CVE-2021-22648,

• Uncontrolled resource consumption - CVE-2021-22642,

• Insufficiently protected credentials - CVE-2021-22640, and

• Use of hard-coded cryptographic key - CVE-2021-22644

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to result in remote code execution, which may cause a denial-of-service condition.

NOTE: This advisory was originally published on February 23rd, 2021 on the restricted HSIN ICS library. This limited disclosure allows critical infrastructure additional time to implement mitigation measures before the vulnerability becomes public. NCCIC-ICS does not use this limited distribution very often, the last time was on July 21st, 2020 and the time before that was on November 6th, 2018.

Reason DR60 Advisory

This advisory describes three vulnerabilities in the GE Reason DR60 digital fault recorder products. The vulnerabilities were reported by Thales OT Security Team. GE has a firmware update that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Use of hard-coded password - CVE-2021-27440,

• Code injection - CVE-2021-27438, and

• Execution with unnecessary privileges - CVE-2021-27454

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to  allow an attacker to take full control of the digital fault recorder (DFR), remotely execute code, or escalate privileges.

MU320E Advisory

This advisory describes three vulnerabilities in the GE MU320E product. The vulnerabilities were reported by Tom Westenberg of Thales UK. GE has a new firmware version that mitigates the vulnerabilities. There is no indication that Westenberg has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Use of hard-coded password - CVE-2021-27452,

• Execution with unnecessary privileges - CVE-2021-27448, and

• Inadequate encryption strength - CVE-2021-27450

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to escalate unnecessary privileges and use hard-coded credentials to take control of the device.

NOTE: Neither of these advisories appear to address any of the 17 advisories published by GE on March 17th, 2021 that I briefly mentioned Saturday.

Weintek Advisory

This advisory describes three vulnerabilities in the Weintek cMT product. The vulnerabilities were reported by Marcin Dudek from CERT.PL. Weintek has upgrades that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Code injection - CVE-2021-27446,

• Improper access control - CVE-2021-27444, and

• Cross-site scripting - CVE-2021-27442

NCCIC-ICS reports

MicroLogix 1400 Update

This update provides additional information for an advisory that was originally published on February 2nd, 2021. The new information includes:

• Adding the names of the researchers from the Veermata Jijabai Technological Institute that reported the vulnerability, and

• Adding a link to the Rockwell advisory.

CompactLogix 5370 Update

This update provides additional information for an advisory that was originally published on March 2nd, 2021. The new information includes adding a link to the Rockwell Advisory.

 
/* Use this with templates/template-twocol.html */