Tuesday, 30.08.2022
Title
Hitachi Energy FACTS Control Platform (FCP) Product
Published
Aug. 30, 2022, 4:55 p.m.
Summary
This advisory contains mitigations for Inconsistent Interpretation of HTTP Requests, Use After Free, Classic Buffer Overflow, Integer Underflow, Improper Certificate Validation, Observable Discrepancy vulnerabilities in Hitachi Energy FACTS Control Platform (FCP).
Title
Hitachi Energy Gateway Station (GWS) Product
Published
Aug. 30, 2022, 4:50 p.m.
Summary
This advisory contains mitigations for a Hitachi Energy Gateway Station (GWS) Product vulnerability in Inconsistent Interpretation of HTTP Requests, Use After Free, Classic Buffer Overflow, Integer Underflow, Improper Certificate Validation, Observable Discrepancy.
Title
Hitachi Energy MSM Product
Published
Aug. 30, 2022, 4:40 p.m.
Summary
This advisory contains mitigations for a Hitachi Energy MSM Product vulnerability in Reliance on Uncontrolled Component.
Title
Fuji Electric D300win
Published
Aug. 30, 2022, 4:30 p.m.
Summary
This advisory contains mitigations for a Fuji Electric D300win vulnerability Out-of-bounds Read, Write-what-where Condition
Title
Honeywell ControlEdge
Published
Aug. 30, 2022, 4:30 p.m.
Summary
This advisory contains mitigations for a Honeywell ControlEdge vulnerability Missing Authentication for Critical Function.
Title
Honeywell Experion LX
Published
Aug. 30, 2022, 4:25 p.m.
Summary
This advisory contains mitigations for a Missing Authentication for Critical Function vulnerability in versions of the Honeywell equipment, Experion LX, distributed control system (DCS).
Title
Honeywell Trend Controls Inter-Controller Protocol
Published
Aug. 30, 2022, 4:20 p.m.
Summary
This advisory contains mitigations for a Cleartext Transmission of Sensitive Information vulnerability in versions of the Honeywell products, Trend Controls IQ Series IC, an industrial communication controller.
Title
PTC Kepware KEPServerEX
Published
Aug. 30, 2022, 4:10 p.m.
Summary
This advisory contains mitigations for Heap-Based Buffer Overflow and Stack-Based Buffer Overflow vulnerabilities in versions of the PTC product, Kepware KEPServerEX, a connectivity platform.
Tuesday, 23.08.2022
Title
Measuresoft ScadaPro Server and Client
Published
Aug. 23, 2022, 5:06 p.m.
Summary
This advisory contains mitigations for Untrusted Pointer Dereference, Stack-based Buffer Overflow, Use After Free, and Link Following vulnerabilities in Measuresoft ScadaPro Server and Client, a supervisory control and data acquisition (SCADA) system.
Title
Measuresoft ScadaPro Server
Published
Aug. 23, 2022, 5:04 p.m.
Summary
This advisory contains mitigations for an Out-of-bounds Write vulnerability in Measuresoft ScadaPro Server, a supervisory control and data acquisition (SCADA) system.
Title
Hitachi Energy RTU500
Published
Aug. 23, 2022, 5:02 p.m.
Summary
This advisory contains mitigations for a Stack-based Buffer Overflow vulnerability in versions of Hitatchi Energy RTU500 firmware.
Title
Illumina Local Run Manager (Update A)
Published
Aug. 23, 2022, 5 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-22-153-02 Illumina Local Run Manager that was published June 22, 2022, on the ICS webpage on cisa.gov/ics. This advisory contains mitigations for Path Traversal, Unrestricted Upload of File with Dangerous Type, Improper Access Control, and Cleartext Transmission of Sensitive ...
Title
Delta Industrial Automation DIALink
Published
Aug. 23, 2022, 4 p.m.
Summary
This advisory contains mitigations for an Use of Hard-coded Cryptographic Key vulnerability in various versions of the DIALink Industrial Automation server.
Friday, 19.08.2022
Title
Mitsubishi Electric MELSEC iQ-R, Q, L Series and MELIPC Series (Update A)
Published
Aug. 19, 2022, 4:20 a.m.
Summary
This updated advisory is a follow-up to the advisory titled ICSA-22-221-01 Mitsubishi Electric MELSEC Q and L Series that was published June 21, 2022, to the ICS webpage on cisa.gov/ics. This advisory contains mitigations for an Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC iQ-R, Q, and L series CPU ...
Thursday, 18.08.2022
Title
Mitsubishi Electric Multiple Factory Automation Products (Update A)
Published
Aug. 18, 2022, 4:25 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-22-221-01 Mitsubishi Electric GT SoftGOT2000 that was published August 9, 2022, to the ICS webpage on cisa.gov/ics.. This advisory contains mitigations for Infinite Loop and OS Command Injection vulnerabilities in versions of Mitsubishi Electric GOT2000 compatible HMI software, CC-Link ...
Title
Siemens OpenSSL Affected Industrial Products (Update B)
Published
Aug. 18, 2022, 4:10 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-22-167-14 Siemens OpenSSL Affected Industrial Products (Update A) that was published July 14, 2022, on the ICS webpage on cisa.gov/ics. This advisory contains mitigations for an Infinite Loop vulnerability in the Siemens OpenSSL Affected Industrial Products.
Title
Siemens Industrial Products LLDP (Update D)
Published
Aug. 18, 2022, 4:05 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-21-194-07 Siemens Industrial Products LLDP (Update C) that was published August 11, 2022, on the ICS webpage on cisa.gov/ics. This advisory contains mitigations for Classic Buffer Overflow and Uncontrolled Resource Consumption vulnerabilities in versions of Siemens Industrial Products (LLDP).
Title
Siemens Linux-based Products (Update J)
Published
Aug. 18, 2022, 4 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-21-131-03 Siemens Linux-based Products (Update I) that was published August 11, 2022, to the ICS webpage at www.cisa.gov/ics. This advisory contains mitigations for a Use of Insufficiently Random Values vulnerability in versions of Siemens Linux-based products.
Tuesday, 16.08.2022
Title
AA22-228A: Threat Actors Exploiting Multiple CVEs Against Zimbra Collaboration Suite
Published
Aug. 16, 2022, 5:38 p.m.
Summary
Original release date: August 16, 2022SummaryActions for ZCS administrators to take today to mitigate malicious cyber activity: • Patch all systems and prioritize patching known exploited vulnerabilities. • Deploy detection signatures and hunt for indicators of compromise (IOCs). • If ZCS was compromised, remediate malicious activity. The Cybersecurity and Infrastructure ...
Title
Yokogawa CENTUM Controller FCS
Published
Aug. 16, 2022, 4:35 p.m.
Summary
This advisory contains mitigations for a Denial of Service vulnerability in CENTUM Controller FCS products.
Title
LS ELECTRIC PLC and XG5000
Published
Aug. 16, 2022, 4:30 p.m.
Summary
This advisory contains mitigations for an Inadequate Encryption Strength vulnerability in LS ELECTRIC PLC and XG5000, a PLC programming software.
Title
Softing Secure Integration Server
Published
Aug. 16, 2022, 4:25 p.m.
Summary
This advisory contains mitigations for Out-of-bounds Read, Uncontrolled Search Path Element, Improper Authentication, Relative Path Traversal, Cleartext Transmission of Sensitive Information, NULL Pointer Dereference, and Integer Underflow vulnerabilities in various Softing products.
Title
Delta Industrial Automation DRAS
Published
Aug. 16, 2022, 4:25 p.m.
Summary
This advisory contains mitigations for an Improper Restriction of XML External Entity Reference vulnerability in Delta Industrial Automation DRAS, a controller software suite.
Title
B&R Industrial Automation Automation Studio 4
Published
Aug. 16, 2022, 4:15 p.m.
Summary
This advisory contains mitigations for an Unrestricted Upload of File with Dangerous Type vulnerability in Industrial Automation Automation Studio 4, a PLC automation programming software.
Title
Emerson Proficy Machine Edition
Published
Aug. 16, 2022, 4:10 p.m.
Summary
This advisory contains mitigations for Missing Support for Integrity Check, Improper Access Control, Unrestricted Upload of File with Dangerous Type, Improper Verification of Cryptographic Signature, Insufficient Verification of Data Authenticity, and Path Traversal: ‘\..\filename’ vulnerabilities in Emerson Proficy Machine Edition, an engineering workstation.

Last Updates

BOSCH PSIRT
19.10.2022
CODESYS
03.11.2022
SIEMENS CERT
08.11.2022
US CERT
01.12.2022
US CERT (ICS)
01.12.2022

By Source

Archive

2022
2021
2020
2019
2018
2017

Feeds