Topic

Defensive Guidance.

51 stories of advisories, analysis, and defensive guidance in this topic.

highDefensive GuidanceAug 13, 2026·2 min read

Remote file reading and root privilege escalation vulnerabilities found in Siemens License Server

Critical flaws in the Siemens License Server (SLS) could allow attackers to read arbitrary files remotely or gain full root access via local privilege escalation.

highDefensive GuidanceAug 13, 2026·2 min read

Specially crafted X_T files trigger arbitrary code execution in Siemens Parasolid software

A high-severity out of bounds read vulnerability in Siemens Parasolid could allow an attacker to execute arbitrary code or crash the application.

highDefensive GuidanceAug 11, 2026·2 min read

Unauthenticated attackers can remotely control Pulsetto Vagus Nerve Stimulators via Bluetooth BLE vulnerabilities

⚠️ High severity. An unauthenticated attacker can send undisclosed commands to the Pulsetto Vagus Nerve Stimulator via Bluetooth Low Energy (BLE).

highDefensive GuidanceAug 7, 2026·2 min read

Remote message injection and session termination vulnerabilities threaten ATN-B1 CPDLC aviation systems

High-severity vulnerabilities in the ATN-B1 CPDLC system allow remote attackers to inject false messages or terminate active sessions via radio frequency.

mediumDefensive GuidanceAug 6, 2026·2 min read

Vulnerability in ABB Ability Zenon software requires immediate review by industrial control operators

ABB has released information regarding a vulnerability in its Ability Zenon software.

mediumDefensive GuidanceAug 4, 2026·2 min read

Schneider Electric IGSS software vulnerability threatens industrial control station environments

A new vulnerability has been identified in Schneider Electric's Industrial Graphics Station Software (IGSS). This flaw could impact industrial control environments.

mediumDefensive GuidanceAug 4, 2026·2 min read

Vulnerabilities in Thermo Fisher Applied Biosystems genetic analyzers allow remote code execution

The OFFIS DCMTK (DCMTK Toolkit) contains a vulnerability tracked as CVE-2026-17583.

highDefensive GuidanceJul 30, 2026·2 min read

Attacker requests can trigger processor resets or crashes in NASA Core Flight System

Two vulnerabilities in the NASA Core Flight System (cFS) Health and Safety application can trigger a processor reset or application crash.

highDefensive GuidanceJul 30, 2026·3 min read

Improper message integrity in Mitsubishi Electric MELSEC MX controllers enables control data manipulation

An improper message integrity flaw in several Mitsubishi Electric MELSEC MX controllers allows attackers on a CC-Link IE TSN network to manipulate control data.

highDefensive GuidanceJul 30, 2026·2 min read

Malicious configuration files could trigger arbitrary code execution in Schneider Electric IGSS software

A high-severity out-of-bounds write vulnerability in Schneider Electric's IGSS Definition software could allow an attacker to execute arbitrary code or cause data loss.

highDefensive GuidanceJul 30, 2026·3 min read

Memory corruption vulnerabilities in open62541 library enable remote code execution and service disruption

Multiple vulnerabilities in the open62541 library allow remote attackers to trigger memory corruption or service disruptions.

highDefensive GuidanceJul 30, 2026·2 min read

Unauthenticated attackers gain full root control over Toptech Systems RCU II+ devices

An unauthenticated service on Toptech RCU II+ devices allows full root-level control over the underlying Linux environment.

highDefensive GuidanceJul 28, 2026·2 min read

Brute force attacks bypass connection delays to target MikroTik RouterOS API credentials

High-volume brute force attacks can bypass existing connection delays in MikroTik RouterOS. Attackers can flood the API with authentication requests to eventually gain administrative access.

highDefensive GuidanceJul 28, 2026·2 min read

Multicast traffic spikes cause memory exhaustion and application crashes in Siemens SIMATIC S7-PLCSIM Advanced

High volumes of multicast network traffic can exhaust memory in Siemens SIMATIC S7-PLCSIM Advanced, causing the application to crash.

highDefensive GuidanceJul 23, 2026·2 min read

Attackers can harvest cleartext passwords via Panduit IntraVUE API vulnerabilities

🚨 Cleartext passwords stored within the Pronetiqs Panduit IntraVUE API could allow an attacker to harvest credentials easily.

highDefensive GuidanceJul 23, 2026·2 min read

Authenticated attackers can write arbitrary files through path traversal in Rockwell ThinManager

An authenticated attacker can write arbitrary files to restricted system directories via a path traversal vulnerability in Rockwell Automation's FactoryTalk ThinManager.

highDefensive GuidanceJul 23, 2026·2 min read

Malicious Read Requests Trigger Stack Buffer Overflow in MZ Automation libIEC61850 Library

A stack-based buffer overflow in the `libIEC61850` library can be triggered by a malicious Read Request. This vulnerability carries a CVSS score of 7.5 and could lead to memory corruption.

highDefensive GuidanceJul 23, 2026·3 min read

Parsing errors in lib60870 library trigger denial of service on Weintek cMT3092X hardware

A high-severity vulnerability in the `lib60870` library can be used to crash parsing processes, leading to a denial of service. This affects Weintek cMT3092X hardware.

highDefensive GuidanceJul 23, 2026·3 min read

Unauthorized action execution possible via deserialization flaw in Johnson Controls Victor software

A high-severity deserialization flaw has been identified in Johnson Controls' victor software running on Windows.

highDefensive GuidanceJul 22, 2026·2 min read

Local users could gain root privileges on Ubuntu desktop systems via snap-confine flaw

A flaw discovered in `snap-confine`, a core component used by Canonical's `snapd`, enables local attackers to bypass security sandboxes.

highDefensive GuidanceJul 22, 2026·2 min read

Malicious websites can steal sensitive session data via Adobe Acrobat Chrome extension flaw

A high-severity vulnerability in the Adobe Acrobat PDF extension for Chrome allows attackers to access sensitive session data.

highDefensive GuidanceJul 21, 2026·3 min read

Arbitrary code execution vulnerabilities found in Rockwell Automation Studio 5000 Logix Designer

Three vulnerabilities in Rockwell Automation's Studio 5000 Logix Designer could allow an attacker to execute arbitrary code on a workstation.

highDefensive GuidanceJul 21, 2026·2 min read

Malicious CIP messages can trigger denial of service in Rockwell Automation POINT I/O modules

Crafted CIP messages can force Rockwell Automation 1734 POINT I/O modules into a faulted state, requiring a manual restart. This vulnerability carries a CVSS score of 8.7.

highDefensive GuidanceJul 21, 2026·2 min read

UDP unicast network storms trigger denial-of-service in Rockwell Automation 1719-AENTR adapters

A high-severity denial-of-service vulnerability in Rockwell Automation's 1719-AENTR adapter can cause a complete loss of communication.

highDefensive GuidanceJul 16, 2026·2 min read

Malicious firmware installation possible via critical vulnerabilities in Siemens CPCI85 processing units

Critical vulnerabilities in Siemens CPCI85 central processing units could allow attackers to install malicious firmware or bypass security controls.

mediumDefensive GuidanceJul 9, 2026·2 min read

Vulnerability in Schneider Electric PowerChute Serial Shutdown threatens industrial power management systems

A vulnerability has been identified in Schneider Electric's PowerChute Serial Shutdown software. This advisory addresses potential risks to power management systems within industrial environments.

highDefensive GuidanceJul 7, 2026·2 min read

Hitachi Energy PROMOD V

A high-severity vulnerability has been identified in Hitachi Energy's PROMOD V software. The flaw stems from the use of insecure HTTP communication instead of the encrypted HTTPS protocol.

lowDefensive GuidanceJul 2, 2026·2 min read

Unauthenticated malicious firmware uploads possible via physical access to CubeSpace CW0057 reaction wheels

Physical access to a CubeSpace CW0057 Reaction Wheel allows an attacker to upload unauthenticated, malicious firmware.

highDefensive GuidanceJun 30, 2026·4 min read

Critical Patches Released for 7-Zip: Prevent Denial of Service and Remote Code Execution Vulnerabilities

7-Zip has patched multiple vulnerabilities that could lead to denial of service.

highDefensive GuidanceJun 30, 2026·3 min read

High-Severity Vulnerability in Schneider Electric's EcoStruxure Exposes Server Files to Attackers

Schneider Electric has disclosed a vulnerability in its EcoStruxure IT Data Center Expert product. The flaw allows attackers to disclose server-side file contents via crafted XML payloads.

highDefensive GuidanceJun 26, 2026·3 min read

Unauthenticated API Bypass Exposes Audiobookshelf Servers to Unauthorized Access

Audiobookshelf, a self-hosted audiobook server, has been found vulnerable to an unauthenticated API authentication bypass (CVE-2025-25205), affecting versions 2.17.0 through 2.19.0.

highDefensive GuidanceJun 25, 2026·2 min read

Arbitrary File Write Vulnerability in `pynetdicom` Library Compromises Data Integrity

The `pynetdicom` library from pydicom is vulnerable to arbitrary file writes due to improper sanitization in its C-STORE handler.

highDefensive GuidanceJun 25, 2026·3 min read

Critical Denial-of-Service Vulnerability Disclosed in Schneider Electric PowerLogic P7 Devices

A critical vulnerability (CVE-2026-9716) in Schneider Electric's PowerLogic™ P7 devices has been disclosed.

highDefensive GuidanceJun 25, 2026·2 min read

Critical Out-of-Bounds Read Flaw in Horner Automation's Cscape Exposes Industrial Systems to Arbitrary Code Execution

Horner Automation's Cscape software is vulnerable to an Out-of-Bounds Read vulnerability (CVE-2026-12897) that could allow attackers to execute arbitrary code.

highDefensive GuidanceJun 25, 2026·3 min read

Healthcare Systems at Risk: OHIF Viewer Flaw Exposes User Tokens to Theft

A vulnerability in the OHIF DICOM Web Viewer Framework allows attackers to steal authenticated user tokens through crafted links.

highDefensive GuidanceJun 23, 2026·4 min read

OpenSSL Stack Buffer Overflows Threaten Siemens Products with DoS and Code Execution Risks

OpenSSL vulnerabilities have surfaced in versions 3.0 through 3.6, introducing stack buffer overflows that could lead to Denial of Service or remote code execution.

highDefensive GuidanceJun 23, 2026·3 min read

Remote Command Execution Vulnerability Discovered in Siemens SINEC INS Affecting Multiple Versions

Siemens' SINEC INS application has a high-severity vulnerability (CVE-2026-46746) allowing remote attackers to execute arbitrary commands due to improper input sanitization in the `/api/sftp/uploadFil

highDefensive GuidanceJun 23, 2026·3 min read

Siemens WinCC Vulnerability Exposes Sensitive Key Material; Urgent Patch Recommended

A significant vulnerability in Siemens' SIMATIC WinCC Unified PC Runtime has been identified, allowing attackers to extract sensitive key material. This flaw affects versions up to V21 Update 1.

highDefensive GuidanceJun 18, 2026·3 min read

Critical Vulnerability in Schneider Electric's EasyLogic T150 Exposes Industrial Control Systems

A critical vulnerability has been identified in Schneider Electric's EasyLogic T150 Remote Terminal Unit & Controller.

mediumDefensive GuidanceJun 18, 2026·2 min read

Healthcare Systems at Risk: Urgent Patching Needed for Frontier X Mobile App Vulnerabilities

The CISA advisory highlights vulnerabilities in the Frontier X Mobile Application and its successor, Frontier X2.

highDefensive GuidanceJun 18, 2026·3 min read

High-Severity DoS Vulnerability Discovered in Mitsubishi Electric's MELSEC Modules

Mitsubishi Electric's MELSEC iQ-F Series FX5-ENET/IP Ethernet Module is vulnerable to a denial-of-service (DoS) attack due to an Expected Behavior Violation.

highDefensive GuidanceJun 18, 2026·3 min read

High-Severity Vulnerability Exposes Schneider Electric's Industrial Control Systems to Unauthorized Access

Schneider Electric's Easergy MiCOM C264 has been identified with a high-severity vulnerability (CVE-2026-4827) that could lead to unauthorized access due to insufficient entropy in session-management

highDefensive GuidanceJun 18, 2026·4 min read

MELSEC iQ-F Series Vulnerability Exposes Systems to Denial-of-Service Attacks

Mitsubishi Electric's MELSEC iQ-F Series FX5-EIP EtherNet/IP Module has been found vulnerable to an integer overflow issue that can lead to denial-of-service (DoS) conditions.

highDefensive GuidanceJun 16, 2026·3 min read

Critical Denial of Service Vulnerability Threatens Rockwell Automation Controllers; Urgent Mitigation Needed

A critical vulnerability in Rockwell Automation's CompactLogix and ControlLogix controllers could lead to denial of service attacks.

highDefensive GuidanceJun 16, 2026·3 min read

Service Disruption Vulnerability in Rockwell Automation's RSLinx Classic Ethernet/IP Server Unveiled

A denial-of-service vulnerability in Rockwell Automation's RSLinx Classic Ethernet/IP server (CVE-2020-13573) can be triggered by sending malicious network packets.

highDefensive GuidanceJun 16, 2026·3 min read

Unauthorized Admin Actions Threaten Rockwell Automation's FactoryTalk Analytics PavilionX

Rockwell Automation's FactoryTalk Analytics PavilionX is vulnerable to unauthorized administrative actions due to improper API authorization enforcement.

mediumDefensive GuidanceJun 11, 2026·2 min read

Unauthorized Access Threat to Industrial Control Systems via Brickcom Camera Vulnerability

A recent advisory from CISA highlights a vulnerability in Brickcom Cameras that could allow unauthorized access to industrial control systems.

highDefensive GuidanceJun 11, 2026·3 min read

Unpatched Vulnerability Exposes Brickcom Cameras to Unauthorized Live Video Access

A significant vulnerability (CVE-2026-50245) has been identified in Brickcom's Cube cameras, allowing unauthenticated access to live video feeds via the `/ONVIF` endpoint.

highDefensive GuidanceJun 4, 2026·3 min read

Critical Vulnerability in B&R PPT30 OS Threatens Industrial Control Systems with Denial of Service Attacks

A critical vulnerability (CVE-2025-11482) in B&R Industrial Automation GmbH's PPT30 Operating System poses a significant threat to industrial control systems.

highDefensive GuidanceJun 4, 2026·4 min read

Hitachi Energy RTU500

A series of vulnerabilities in OpenSSL and libexpat have been disclosed, affecting multiple versions.

highDefensive GuidanceJun 4, 2026·5 min read

Securly Chrome Extension Flaws Expose Student Filtering and Monitoring Controls

CERT/CC disclosed multiple Securly Chrome extension flaws that can expose filtering logic and disrupt browsing.