Topic
Defensive Guidance.
39 stories of advisories, analysis, and defensive guidance in this topic.
Brute force attacks bypass connection delays to target MikroTik RouterOS API credentials
High-volume brute force attacks can bypass existing connection delays in MikroTik RouterOS. Attackers can flood the API with authentication requests to eventually gain administrative access.
Multicast traffic spikes cause memory exhaustion and application crashes in Siemens SIMATIC S7-PLCSIM Advanced
High volumes of multicast network traffic can exhaust memory in Siemens SIMATIC S7-PLCSIM Advanced, causing the application to crash.
Attackers can harvest cleartext passwords via Panduit IntraVUE API vulnerabilities
🚨 Cleartext passwords stored within the Pronetiqs Panduit IntraVUE API could allow an attacker to harvest credentials easily.
Authenticated attackers can write arbitrary files through path traversal in Rockwell ThinManager
An authenticated attacker can write arbitrary files to restricted system directories via a path traversal vulnerability in Rockwell Automation's FactoryTalk ThinManager.
Malicious Read Requests Trigger Stack Buffer Overflow in MZ Automation libIEC61850 Library
A stack-based buffer overflow in the `libIEC61850` library can be triggered by a malicious Read Request. This vulnerability carries a CVSS score of 7.5 and could lead to memory corruption.
Parsing errors in lib60870 library trigger denial of service on Weintek cMT3092X hardware
A high-severity vulnerability in the `lib60870` library can be used to crash parsing processes, leading to a denial of service. This affects Weintek cMT3092X hardware.
Unauthorized action execution possible via deserialization flaw in Johnson Controls Victor software
A high-severity deserialization flaw has been identified in Johnson Controls' victor software running on Windows.
Local users could gain root privileges on Ubuntu desktop systems via snap-confine flaw
A flaw discovered in `snap-confine`, a core component used by Canonical's `snapd`, enables local attackers to bypass security sandboxes.
Malicious websites can steal sensitive session data via Adobe Acrobat Chrome extension flaw
A high-severity vulnerability in the Adobe Acrobat PDF extension for Chrome allows attackers to access sensitive session data.
Arbitrary code execution vulnerabilities found in Rockwell Automation Studio 5000 Logix Designer
Three vulnerabilities in Rockwell Automation's Studio 5000 Logix Designer could allow an attacker to execute arbitrary code on a workstation.
Malicious CIP messages can trigger denial of service in Rockwell Automation POINT I/O modules
Crafted CIP messages can force Rockwell Automation 1734 POINT I/O modules into a faulted state, requiring a manual restart. This vulnerability carries a CVSS score of 8.7.
UDP unicast network storms trigger denial-of-service in Rockwell Automation 1719-AENTR adapters
A high-severity denial-of-service vulnerability in Rockwell Automation's 1719-AENTR adapter can cause a complete loss of communication.
Malicious firmware installation possible via critical vulnerabilities in Siemens CPCI85 processing units
Critical vulnerabilities in Siemens CPCI85 central processing units could allow attackers to install malicious firmware or bypass security controls.
Vulnerability in Schneider Electric PowerChute Serial Shutdown threatens industrial power management systems
A vulnerability has been identified in Schneider Electric's PowerChute Serial Shutdown software. This advisory addresses potential risks to power management systems within industrial environments.
Hitachi Energy PROMOD V
A high-severity vulnerability has been identified in Hitachi Energy's PROMOD V software. The flaw stems from the use of insecure HTTP communication instead of the encrypted HTTPS protocol.
Unauthenticated malicious firmware uploads possible via physical access to CubeSpace CW0057 reaction wheels
Physical access to a CubeSpace CW0057 Reaction Wheel allows an attacker to upload unauthenticated, malicious firmware.
Critical Patches Released for 7-Zip: Prevent Denial of Service and Remote Code Execution Vulnerabilities
7-Zip has patched multiple vulnerabilities that could lead to denial of service.
High-Severity Vulnerability in Schneider Electric's EcoStruxure Exposes Server Files to Attackers
Schneider Electric has disclosed a vulnerability in its EcoStruxure IT Data Center Expert product. The flaw allows attackers to disclose server-side file contents via crafted XML payloads.
Unauthenticated API Bypass Exposes Audiobookshelf Servers to Unauthorized Access
Audiobookshelf, a self-hosted audiobook server, has been found vulnerable to an unauthenticated API authentication bypass (CVE-2025-25205), affecting versions 2.17.0 through 2.19.0.
Arbitrary File Write Vulnerability in `pynetdicom` Library Compromises Data Integrity
The `pynetdicom` library from pydicom is vulnerable to arbitrary file writes due to improper sanitization in its C-STORE handler.
Critical Denial-of-Service Vulnerability Disclosed in Schneider Electric PowerLogic P7 Devices
A critical vulnerability (CVE-2026-9716) in Schneider Electric's PowerLogic™ P7 devices has been disclosed.
Critical Out-of-Bounds Read Flaw in Horner Automation's Cscape Exposes Industrial Systems to Arbitrary Code Execution
Horner Automation's Cscape software is vulnerable to an Out-of-Bounds Read vulnerability (CVE-2026-12897) that could allow attackers to execute arbitrary code.
Healthcare Systems at Risk: OHIF Viewer Flaw Exposes User Tokens to Theft
A vulnerability in the OHIF DICOM Web Viewer Framework allows attackers to steal authenticated user tokens through crafted links.
OpenSSL Stack Buffer Overflows Threaten Siemens Products with DoS and Code Execution Risks
OpenSSL vulnerabilities have surfaced in versions 3.0 through 3.6, introducing stack buffer overflows that could lead to Denial of Service or remote code execution.
Remote Command Execution Vulnerability Discovered in Siemens SINEC INS Affecting Multiple Versions
Siemens' SINEC INS application has a high-severity vulnerability (CVE-2026-46746) allowing remote attackers to execute arbitrary commands due to improper input sanitization in the `/api/sftp/uploadFil
Siemens WinCC Vulnerability Exposes Sensitive Key Material; Urgent Patch Recommended
A significant vulnerability in Siemens' SIMATIC WinCC Unified PC Runtime has been identified, allowing attackers to extract sensitive key material. This flaw affects versions up to V21 Update 1.
Critical Vulnerability in Schneider Electric's EasyLogic T150 Exposes Industrial Control Systems
A critical vulnerability has been identified in Schneider Electric's EasyLogic T150 Remote Terminal Unit & Controller.
Healthcare Systems at Risk: Urgent Patching Needed for Frontier X Mobile App Vulnerabilities
The CISA advisory highlights vulnerabilities in the Frontier X Mobile Application and its successor, Frontier X2.
High-Severity DoS Vulnerability Discovered in Mitsubishi Electric's MELSEC Modules
Mitsubishi Electric's MELSEC iQ-F Series FX5-ENET/IP Ethernet Module is vulnerable to a denial-of-service (DoS) attack due to an Expected Behavior Violation.
High-Severity Vulnerability Exposes Schneider Electric's Industrial Control Systems to Unauthorized Access
Schneider Electric's Easergy MiCOM C264 has been identified with a high-severity vulnerability (CVE-2026-4827) that could lead to unauthorized access due to insufficient entropy in session-management
MELSEC iQ-F Series Vulnerability Exposes Systems to Denial-of-Service Attacks
Mitsubishi Electric's MELSEC iQ-F Series FX5-EIP EtherNet/IP Module has been found vulnerable to an integer overflow issue that can lead to denial-of-service (DoS) conditions.
Critical Denial of Service Vulnerability Threatens Rockwell Automation Controllers; Urgent Mitigation Needed
A critical vulnerability in Rockwell Automation's CompactLogix and ControlLogix controllers could lead to denial of service attacks.
Service Disruption Vulnerability in Rockwell Automation's RSLinx Classic Ethernet/IP Server Unveiled
A denial-of-service vulnerability in Rockwell Automation's RSLinx Classic Ethernet/IP server (CVE-2020-13573) can be triggered by sending malicious network packets.
Unauthorized Admin Actions Threaten Rockwell Automation's FactoryTalk Analytics PavilionX
Rockwell Automation's FactoryTalk Analytics PavilionX is vulnerable to unauthorized administrative actions due to improper API authorization enforcement.
Unauthorized Access Threat to Industrial Control Systems via Brickcom Camera Vulnerability
A recent advisory from CISA highlights a vulnerability in Brickcom Cameras that could allow unauthorized access to industrial control systems.
Unpatched Vulnerability Exposes Brickcom Cameras to Unauthorized Live Video Access
A significant vulnerability (CVE-2026-50245) has been identified in Brickcom's Cube cameras, allowing unauthenticated access to live video feeds via the `/ONVIF` endpoint.
Critical Vulnerability in B&R PPT30 OS Threatens Industrial Control Systems with Denial of Service Attacks
A critical vulnerability (CVE-2025-11482) in B&R Industrial Automation GmbH's PPT30 Operating System poses a significant threat to industrial control systems.
Hitachi Energy RTU500
A series of vulnerabilities in OpenSSL and libexpat have been disclosed, affecting multiple versions.
Securly Chrome Extension Flaws Expose Student Filtering and Monitoring Controls
CERT/CC disclosed multiple Securly Chrome extension flaws that can expose filtering logic and disrupt browsing.