December 2021
Title
Siemens Capital VSTAR
Published
Dec. 16, 2021, 4:42 p.m.
Summary
This advisory contains mitigations for a several vulnerabilities in Siemens Capital VSTAR software platform products using Nucleus NET, the networking stack of Nucleus RTOS (real-time operating system).
Title
Siemens POWER METER SICAM Q100
Published
Dec. 16, 2021, 4:40 p.m.
Summary
This advisory contains mitigations for a Stack-based Buffer Overflow vulnerability in the Siemens POWER METER SICAM Q100 power monitoring device.
Title
Siemens JTTK and JT Utilities
Published
Dec. 16, 2021, 4:38 p.m.
Summary
This advisory contains mitigations for Out-of-bounds Write, Use after Free, Out-of-bounds Read vulnerability in in the Siemens JTTK programming interface, and JT Utilities series of command line utilities.
Title
Schneider Electric Rack PDU
Published
Dec. 14, 2021, 4:05 p.m.
Summary
This advisory contains mitigations for a Cross-site Scripting vulnerability in Schneider Electric Rack Power Distribution Unit (PDU).
Title
Hillrom Medical Device Management (Update A)
Published
Dec. 14, 2021, 4 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-21-152-01 Hillrom Medical Device Management that was published June 1, 2021, to the ICS webpage at www.cisa.gov/uscert. This advisory contains mitigations for a Out-of-Bounds Write, an d Out-of-Bounds Read vulnerabilities in Hillrom Welch Allyn medical device management tools.
Title
Hillrom Welch Allyn Cardio Products
Published
Dec. 9, 2021, 4:10 p.m.
Summary
This advisory contains mitigations for an Authentication Bypass Using an Alternate Path or Channel vulnerability in Hillrom Welch Allyn cardiology devices.
Title
Hitachi Energy GMS600, PWC600, and Relion
Published
Dec. 9, 2021, 4:05 p.m.
Summary
This advisory contains mitigations for an Improper Access Controls vulnerability in Hitachi Energy GMS600, PWC600, and Relion circuit breaker monitoring systems.
Title
Hitachi Energy RTU500 OpenLDAP
Published
Dec. 7, 2021, 4:10 p.m.
Summary
This advisory contains mitigations for Type Confusion, and Reachable Assertion vulnerabilities in Hitachi Energy RTU500 OpenLDAP firmware.
Title
Hitachi Energy XMC20 and FOX61x
Published
Dec. 7, 2021, 4:05 p.m.
Summary
This advisory contains mitigations for Weak Password Requirements, and Missing Handler vulnerabilities in Hitachi Energy XMC20 and FOX61x multi-service network elements.
Title
FANUC Robot Controllers
Published
Dec. 7, 2021, 4 p.m.
Summary
This advisory is a follow-up to the original advisory titled ICSA-21-243-02P FANUC Robot Controllers that was posted to the HSIN ICS library on August 31, 2021. This advisory contains mitigations for Integer Coercion Error, and Out-of-bounds Write vulnerabilities in FANUC Robot Controllers.
Title
Schneider Electric SESU
Published
Dec. 2, 2021, 4:35 p.m.
Summary
This advisory contains mitigations for an Insufficient Entropy vulnerability in the Schneider Electric Software Update.
Title
Johnson Controls Entrapass
Published
Dec. 2, 2021, 4:30 p.m.
Summary
This advisory contains mitigations for a Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Johnson Controls Entrapass security management software.
Title
Distributed Data Systems WebHMI
Published
Dec. 2, 2021, 4:25 p.m.
Summary
This advisory contains mitigations for Authentication Bypass by Primary Weakness, and Unrestricted Upload of File with Dangerous Type vulnerabilities in Distributed Data Systems WebHMI SCADA systems.
Title
Hitachi Energy RTU500 series BCI
Published
Dec. 2, 2021, 4:20 p.m.
Summary
This advisory contains mitigations for an Improper Input Validation vulnerability in Hitachi Energy RTU500 series BCI remote terminal units.
Title
Hitachi Energy Relion 670/650/SAM600-IO
Published
Dec. 2, 2021, 4:15 p.m.
Summary
This advisory contains mitigations for an Insecure Default Initialization of Resource vulnerability in Hitachi Energy Relion 670/650/SAM600-IO Intelligent Electronic Devices (IEDs).
Title
Hitachi Energy APM Edge
Published
Dec. 2, 2021, 4:10 p.m.
Summary
This advisory contains mitigations for a Using Components with Known Vulnerabilities vulnerability in Hitachi Energy Transformer Asset Performance Management (APM) Edge software.
Title
Hitachi Energy PCM600 Update Manager
Published
Dec. 2, 2021, 4:05 p.m.
Summary
This advisory contains mitigations for a Improper Certificate Validation vulnerability in Hitachi Energy PCM600 Update Manager protection and control IED software.
Title
Hitachi Energy RTU500 series
Published
Dec. 2, 2021, 4 p.m.
Summary
This advisory contains mitigations for Observable Discrepancy, Buffer Over-read, and Out-of-bounds Read vulnerabilities in Hitachi Energy RTU500 remote terminal units.
November 2021
Title
Xylem Aanderaa GeoView
Published
Nov. 30, 2021, 4:30 p.m.
Summary
This advisory contains mitigations for a SQL Injection vulnerability in the Xylem Aanderaa GeoView web-based data display.
Title
Mitsubishi Electric MELSEC and MELIPC Series
Published
Nov. 30, 2021, 4:25 p.m.
Summary
This advisory contains mitigations for Uncontrolled Resource Consumption, Improper Handling of Length Parameter Inconsistency, and Improper Input Validation vulnerabilities in Mitsubishi Electric MELSEC and MELIPC Series software management platforms.
Title
Delta Electronics CNCSoft
Published
Nov. 30, 2021, 4:20 p.m.
Summary
This advisory contains mitigations for a Stack-based Buffer Overflow vulnerability in the Delta Electronics CNCSoft sofware management platform.
Title
Johnson Controls CEM Systems AC2000
Published
Nov. 30, 2021, 4:15 p.m.
Summary
This advisory contains mitigations for an Off-by-one Error vulnerability in the Johnson Controls CEM Systems AC2000 access control system.
Title
Hitachi Energy Retail Operations and CSB Software
Published
Nov. 30, 2021, 4:10 p.m.
Summary
This advisory contains mitigations for an Improper Access Control vulnerability in Hitachi Energy Retail Operations and CSB Software systems.
Title
InHand Networks IR615 Router (Update A)
Published
Nov. 30, 2021, 4:05 p.m.
Summary
This updated advisory is a follow-up to the original advisory titled ICSA-21-280-05 InHand Networks IR615 Router that was published October 7, 2021, to the ICS webpage on us-cert.cisa.gov. This advisory contains mitigations for numerous vulnerabilities in the InHand Networks IR615 Router.
Title
Multiple RTOS (Update D)
Published
Nov. 30, 2021, 4 p.m.
Summary
This updated advisory is a follow-up to the advisory update titled ICSA-21-119-04 Multiple RTOS (Update C) that was published August 17, 2021, to the ICS webpage on us-cert.cisa.gov. CISA is aware of a public report, known as “BadAlloc” that details vulnerabilities found in multiple real-time operating systems (RTOS) and supporting ...

Last Updates

BOSCH PSIRT
15.01.2025
SIEMENS CERT
17.04.2025
US CERT
01.04.2025
US CERT (ICS)
17.04.2025

By Source

Archive

2025
2024
2023
2022
2021
2020
2019
2018
2017

Feeds