October 2020
Title
Capsule Technologies SmartLinx Neuron 2 (Update A)
Published
Oct. 20, 2020, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSMA-20-196-01 Capsule Technologies SmartLinx Neuron 2 that was published July 14, 2020, to the ICS webpage on us-cert.cisa.gov. This advisory contains mitigations for a Protection Mechanism Failure vulnerability in Capsule Technologies' SmartLinx Neuron 2, a bedside mobile clinical monitoring ...
Title
Advantech R-SeeNet
Published
Oct. 15, 2020, 4:05 p.m.
Summary
This advisory contains mitigations for an SQL Injection vulnerability in Advantech;s R-SeeNet monitoring application software.
Title
Wibu-Systems CodeMeter (Update C)
Published
Oct. 15, 2020, 4 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-20-203-01 Wibu-Systems CodeMeter (Update B) that was published October 1, 2020, to the ICS webpage on us-cert.gov. This advisory contains mitigations for Buffer Access with Incorrect Length Value, Inadequate Encryption Strength, Origin Validation Error, Improper Input Validation, Improper Verification ...
Title
MOXA NPort IAW5000A-I/O Series
Published
Oct. 13, 2020, 4:45 p.m.
Summary
This advisory contains mitigations for Session Fixation, Improper Privilege Management, Weak Password Requirements, Cleartext Transmission of Sensitive Information, Improper Restriction of Excessive Authentication Attempts, and Exposure of Sensitive Information to an Unauthorized Actor vulnerabilities in the MOXA NPort IAW5000A-I/O Series integrated serial device server.
Title
Wibu-Systems CodeMeter (Update B)
Published
Oct. 1, 2020, 4 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-20-203-01 Wibu-Systems CodeMeter (Update A) that was published September 17, 2020, to the ICS webpage on us-cert.gov. This advisory contains mitigations for Buffer Access with Incorrect Length Value, Inadequate Encryption Strength, Origin Validation Error, Improper Input Validation, Improper Verification ...
September 2020
Title
MB Connect line mbCONNECT24, mymbCONNECT24
Published
Sept. 29, 2020, 4:10 p.m.
Summary
This advisory contains mitigations for SQL Injection, Cross-site Request Forgery, and Command Injection vulnerabilities in the MB connect line mymbCONNECT24 and mbCONNECT24 software.
Title
Yokogawa WideField3
Published
Sept. 29, 2020, 4:05 p.m.
Summary
This advisory contains mitigations for a Buffer Copy Without Checking Size of Input vulnerability in the Yokogawa WideField3 PLC programming tool.
Title
B&R Automation SiteManager and GateManager
Published
Sept. 29, 2020, 4 p.m.
Summary
This advisory contains mitigations for Path Traversal, Uncontrolled Resource Consumption, Information Exposure, Improper Authentication, and Information Disclosure vulnerabilities in B&R Automation SiteManager and GateManager products.
Title
3S CoDeSys (Update A)
Published
Sept. 24, 2020, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-13-011-01 3S CoDeSys that was published January 10, 2013, to the ICS webpage on us-cert.gov. This advisory contains mitigations for Improper Access Control, and Relative Path Traversal vulnerabilities in 3S-Smart Software Solutions software.
Title
GE Digital APM Classic
Published
Sept. 22, 2020, 4:05 p.m.
Summary
This advisory contains mitigations for Authorization Bypass Through User-controlled Key, and Use of a One-Way Hash Without a Salt vulnerabilities in GE's APM Classic module, a data analysis and processing tool.
Title
GE Reason S20 Ethernet Switch
Published
Sept. 22, 2020, 4 p.m.
Summary
This advisory contains mitigations for Cross-site Scripting vulnerabilities in GE's Reason S20 Ethernet Switch.
Title
Philips Clinical Collaboration Platform
Published
Sept. 17, 2020, 4:10 p.m.
Summary
This advisory contains mitigations for Cross-site Request Forgery, Improper Neutralization of Script in Attributes in a Web Page, Protection Mechanism Failure, Algorithm Downgrade, and Configuration vulnerabilities in Philips Clinical Collaboration Platform HMI data management software.
Title
ENTTEC Lighting Controllers (Update A)
Published
Sept. 15, 2020, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-20-177-01 ENTTEC Lighting Controllers that was published June 25, 2020, to the ICS webpage on us-cert.gov. This advisory contains mitigations for Use of Hard-coded Cryptographic Key, Cross-site Scripting, Improper Access Control, and Incorrect Permission Assignment for Critical Resource vulnerabilities ...
August 2020
Title
Robot Motion Servers
Published
Aug. 4, 2020, 4:10 p.m.
Summary
This Alert contains a public report of a Remote Code Execution vulnerability affecting robot motion servers written in OEM exclusive programming languages running on the robot controller.
Title
Treck TCP/IP Stack (Update F)
Published
Aug. 4, 2020, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-20-168-01 Treck TCP/IP Stack (Update E) that was published July 21, 2020, to the ICS webpage on us-cert.gov. This advisory contains mitigations for Improper Handling of Length Parameter Inconsistency, Improper Input Validation, Double Free, Out-of-bounds Read, Integer Overflow or ...
July 2020
Title
Philips DreamMapper
Published
July 30, 2020, 4:20 p.m.
Summary
This advisory contains mitigations for an Insertion of Sensitive Information into Log File vulnerability in Philips DreamMapper mobile app.
Title
Inductive Automation Ignition 8
Published
July 30, 2020, 4:15 p.m.
Summary
This advisory contains mitigations for a Missing Authorization vulnerability in #Inductive Automation Ignition 8 software.
Title
Mitsubishi Electric Multiple Factory Automation Engineering Software Products
Published
July 30, 2020, 4:10 p.m.
Summary
This advisory contains mitigations for a Permission Issues vulnerability in Mitsubishi Electric Factory Automation Engineering software products.
Title
Mitsubishi Electric Factory Automation Products Path Traversal
Published
July 30, 2020, 4:05 p.m.
Summary
This advisory contains mitigations for a Path Traversal vulnerability in Mitsubishi Electric Factory Automation products.
Title
Mitsubishi Electric Factory Automation Engineering Products
Published
July 30, 2020, 4 p.m.
Summary
This advisory contains mitigations for an Unquoted Search Path or Element vulnerability in Mitsubishi Electric Factory Automation Engineering products.
Title
Secomea GateManager
Published
July 28, 2020, 4:15 p.m.
Summary
This advisory contains mitigations for Improper Neutralization of Null Byte or NUL Character, Off-by-one Error, Use of Hard-coded Credentials, Use of Password Hash with Insufficient Computational Effort vulnerabilities in Secomea GateManager, a VPN server.
Title
Softing Industrial Automation OPC
Published
July 28, 2020, 4:10 p.m.
Summary
This advisory contains mitigations for a Heap-based Buffer Overflow, and Uncontrolled Resource Consumption vulnerabilities in Softing Industrial Automation's OPC products.
Title
HMS Industrial Networks eCatcher
Published
July 28, 2020, 4:05 p.m.
Summary
This advisory contains mitigations for a Stack-based Buffer Overflow vulnerability in HMS Industrial Networks eCatcher VPN client.
Title
Delta Industrial Automation DOPSoft (Update A)
Published
July 28, 2020, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-20-182-01 Delta Industrial Automation DOPSoft that was published June 30, 2020, on the ICS webpage on us-cert.gov. This advisory contains mitigations for out-of-bounds read and heap-based buffer overflow vulnerabilities in Delta Industrial Automation DOPSoft products.
Title
Schneider Electric Triconex TriStation and Tricon Communication Module
Published
July 23, 2020, 4 p.m.
Summary
This advisory contains mitigations for Cleartext Transmission of Sensitive Information, Uncontrolled Resource Consumption, Hidden Functionality, and Improper Access Control vulnerabilities in Schneider Electric's Triconex TriStation and Tricon Communication Module products.

Last Updates

BOSCH PSIRT
21.08.2024
SIEMENS CERT
12.09.2024
US CERT
19.09.2024
US CERT (ICS)
19.09.2024

By Source

Archive

2024
2023
2022
2021
2020
2019
2018
2017

Feeds