May 2022
Title
Mitsubishi Electric Multiple Products (Update D)
Published
May 31, 2022, 4:05 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-20-245-01 Mitsubishi Electric Multiple Products (Update C) that was published September 9, 2021, to the ICS webpage on cisa.gov/ics. This advisory contains mitigations for a Predictable Exact Value from Previous Values vulnerability in several Mitsubishi Electric devices.
Title
Mitsubishi Electric Factory Automation Engineering Software (Update B)
Published
May 31, 2022, 4 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-20-212-02 Mitsubishi Electric Factory Automation Engineering Software (Update A) that was published January 5, 2021, to the ICS webpage on ucisa.gov/ics. This advisory contains mitigations for a Permission Issues vulnerability in Mitsubishi Electric Factory Automation Engineering software products.
Title
Keysight N6854A Geolocation server and N6841A RF Sensor software
Published
May 26, 2022, 4:05 p.m.
Summary
This advisory contains mitigations for Relative Path Traversal, and Deserialization of Untrusted Data vulnerabilities in Keysight N6854A Geolocation and server and N6841A Sensor software, a spectrum monitoring platform.
Title
Horner Automation Cscape Csfont
Published
May 26, 2022, 4 p.m.
Summary
This advisory contains mitigations for Out-of-bounds Write, Out-of-bounds Read, and Heap-based Buffer Overflow vulnerabilities in Horner Automation Cscape PLC management software.
Title
Matrikon OPC Server
Published
May 24, 2022, 4:10 p.m.
Summary
This advisory contains mitigations for an Improper Access Control vulnerability in Makitron OPC software.
Title
Mitsubishi Electric FA Engineering Software Products (Update E)
Published
May 24, 2022, 4:05 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-21-049-02 Mitsubishi Electric FA Engineering Software Products (Update D) that was published February 8, 2022, to the ICS webpage on cisa.gov/ics. This advisory contains mitigations for Heap-based Buffer Overflow, and Improper Handling of Length Parameter Inconsistency vulnerabilities in Mitsubishi ...
Title
Mitsubishi Electric Factory Automation Engineering Products (Update G)
Published
May 24, 2022, 4 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-20-212-04 Mitsubishi Electric Factory Automation Engineering Products (Update F) that was published February 8, 2022, to the ICS webpage on cisa.gov/ics. This advisory contains mitigations for an Unquoted Search Path or Element vulnerability in Mitsubishi Electric Factory Automation Engineering ...
Title
Mitsubishi Electric MELSEC iQ-F Series
Published
May 19, 2022, 4 p.m.
Summary
This advisory contains mitigations for Improper Input Validation vulnerabilities in Mitsubishi Electric MELSEC iQ-F Series CPU modules.
Title
Circutor COMPACT DC-S BASIC
Published
May 17, 2022, 4 p.m.
Summary
This advisory contains mitigations for a Stack-based Buffer Overflow vulnerability in the Circutor COMPACT DC-S BASIC smart metering concentrator.
Title
Mitsubishi Electric MELSOFT iQ AppPortal
Published
May 12, 2022, 4:50 p.m.
Summary
This advisory contains mitigations for Missing Authorization, Out-of-bounds Write, NULL Pointer Dereference, Classic Buffer Overflow, HTTP Request Smuggling, and Infinite Loop vulnerabilities in Mitsubishi Electric MELSOFT iQ AppPortal products.
Title
Inkscape in Industrial Products
Published
May 12, 2022, 4:48 p.m.
Summary
This advisory contains mitigations for Out-of-bounds Read, Access of Uninitialized Pointer, and Out-of-bounds Write vulnerabilities in the Inkscape open-source graphics editor.
Title
Cambium Networks cnMaestro
Published
May 12, 2022, 4:46 p.m.
Summary
This advisory contains mitigations for OS Command Injection, SQL Injection, Path Traversal, and Use of Potentially Dangerous Function vulnerabilities in the Cambium Networks cnMaestro network management system.
Title
Siemens Industrial PCs and CNC devices
Published
May 12, 2022, 4:44 p.m.
Summary
This advisory contains mitigations for Improper Input Validation, Improper Authentication, Improper Isolation of Shared Resources on System-on-a-Chip, and Improper Privilege Management vulnerabilities in Siemens Industrial PCs and CNC devices.
Title
Siemens SIMATIC WinCC
Published
May 12, 2022, 4:42 p.m.
Summary
This advisory contains mitigations for a, Insecure Default Initialization of Resource vulnerability in SIMATIC PCS and WinCC industrial products.
Title
Siemens SICAM P850 and SICAM P855
Published
May 12, 2022, 4:40 p.m.
Summary
This advisory contains mitigations for Improper Neutralization of Parameter/Argument Delimiters, Cleartext Transmission of Sensitive Information, Cross-site Scripting, Missing Authentication for Critical Function, Authentication Bypass by Capture-replay, and Improper Authentication vulnerabilities in Siemens SICAM P850 and SICAM P855.
Title
Siemens JT2GO and Teamcenter Visualization
Published
May 12, 2022, 4:36 p.m.
Summary
This advisory contains mitigations for Infinite Loop, Null Pointer Dereference, Integer Overflow to Buffer Overflow, Double Free, and Access of Uninitialized Pointer vulnerabilities in Siemens JT2GO, Teamcenter Visualization products.
Title
Siemens Desigo PXC and DXR Devices
Published
May 12, 2022, 4:34 p.m.
Summary
This advisory contains mitigations for an Uncaught Exception vulnerability in the Siemens Desigo DXR and PXC controllers.
Title
Adminer in Industrial Products
Published
May 10, 2022, 4:25 p.m.
Summary
This advisory contains mitigations for a Files or Directories Accessible to External Parties vulnerability in the Adminer database tool.
Title
Eaton Intelligent Power Protector
Published
May 10, 2022, 4:20 p.m.
Summary
This advisory contains mitigations for a Cross-site Scripting vulnerability in the Eaton Intelligent Power Protector (IPP) power protection platform.
Title
Eaton Intelligent Power Manager Infrastructure
Published
May 10, 2022, 4:15 p.m.
Summary
This advisory contains mitigations for Cross-site Scripting, Reflected Cross-site Scripting, and Improper Neutralization of Formula in a CSV File vulnerabilities in Eaton Intelligent Power Manager Infrastructure power monitoring products.
Title
AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere
Published
May 10, 2022, 4:05 p.m.
Summary
This advisory contains mitigations for an Exposure of Resource to Wrong Sphere vulnerability in AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere HMI products.
Title
Mitsubishi Electric MELSOFT GT OPC UA
Published
May 10, 2022, 4 p.m.
Summary
This advisory contains mitigations for Out-of-bounds Read, and Integer Overflow or Wraparound vulnerabilities in Mitsubishi Electric MELSOFT GT OPC UA client connection products.
Title
Yokogawa CENTUM and ProSafe-RS
Published
May 3, 2022, 4 p.m.
Summary
This advisory contains mitigations for a OS Command Injection, Improper Authentication, NULL Pointer Dereference, Improper Input Validation, Resource Management Errors vulnerabilities in Yokogawa CENTUM and ProSafe-RS Distributed Control System and Safety Instrumented System products.
April 2022
Title
Hitachi Energy System Data Manager
Published
April 26, 2022, 4:05 p.m.
Summary
This advisory contains mitigations for a Integer Overflow or Wraparound, Reachable Assertion, Type Confusion, Uncontrolled Recursion, and Observable Discrepancy vulnerabilities in Hitachi Energy System Data Manager products.
Title
Mitsubishi Electric MELSEC and MELIPC Series (Update B)
Published
April 26, 2022, 4 p.m.
Summary
This updated advisory is a follow up to the advisory update titled ICSA-21-334-02 Mitsubishi Electric MELSEC and MELIPC Series (Update A) that was published January 27, 2022, to the ICS webpage on www.cisa.gov/uscert. This advisory contains mitigations for Uncontrolled Resource Consumption, Improper Handling of Length Parameter Inconsistency, and Improper Input ...

Last Updates

BOSCH PSIRT
31.10.2024
SIEMENS CERT
22.11.2024
US CERT
08.11.2024
US CERT (ICS)
21.11.2024

By Source

Archive

2024
2023
2022
2021
2020
2019
2018
2017

Feeds