Tag
#industrial control systems
18 published stories tagged with industrial control systems.
Hard-coded credentials and unauthenticated flaws expose ANDRITZ HIPASE-250 process data and workstations
Critical vulnerabilities in the ANDRITZ HIPASE-250 system allow unauthenticated attackers to steal passwords, view live process data, and suppress audit logs.
Vulnerability in ABB Ability Zenon software requires immediate review by industrial control operators
ABB has released information regarding a vulnerability in its Ability Zenon software.
Schneider Electric IGSS software vulnerability threatens industrial control station environments
A new vulnerability has been identified in Schneider Electric's Industrial Graphics Station Software (IGSS). This flaw could impact industrial control environments.
Improper message integrity in Mitsubishi Electric MELSEC MX controllers enables control data manipulation
An improper message integrity flaw in several Mitsubishi Electric MELSEC MX controllers allows attackers on a CC-Link IE TSN network to manipulate control data.
Multicast traffic spikes cause memory exhaustion and application crashes in Siemens SIMATIC S7-PLCSIM Advanced
High volumes of multicast network traffic can exhaust memory in Siemens SIMATIC S7-PLCSIM Advanced, causing the application to crash.
Attackers can harvest cleartext passwords via Panduit IntraVUE API vulnerabilities
🚨 Cleartext passwords stored within the Pronetiqs Panduit IntraVUE API could allow an attacker to harvest credentials easily.
Authenticated attackers can write arbitrary files through path traversal in Rockwell ThinManager
An authenticated attacker can write arbitrary files to restricted system directories via a path traversal vulnerability in Rockwell Automation's FactoryTalk ThinManager.
Malicious Read Requests Trigger Stack Buffer Overflow in MZ Automation libIEC61850 Library
A stack-based buffer overflow in the `libIEC61850` library can be triggered by a malicious Read Request. This vulnerability carries a CVSS score of 7.5 and could lead to memory corruption.
Parsing errors in lib60870 library trigger denial of service on Weintek cMT3092X hardware
A high-severity vulnerability in the `lib60870` library can be used to crash parsing processes, leading to a denial of service. This affects Weintek cMT3092X hardware.
Russian state-sponsored actors target Zimbra Collaboration Suite users through phishing campaigns
New intelligence indicates that Iranian-affiliated cyber actors have been targeting Programmable Logic Controllers (PLCs) used throughout US critical infrastructure.
Arbitrary code execution vulnerabilities found in Rockwell Automation Studio 5000 Logix Designer
Three vulnerabilities in Rockwell Automation's Studio 5000 Logix Designer could allow an attacker to execute arbitrary code on a workstation.
Malicious CIP messages can trigger denial of service in Rockwell Automation POINT I/O modules
Crafted CIP messages can force Rockwell Automation 1734 POINT I/O modules into a faulted state, requiring a manual restart. This vulnerability carries a CVSS score of 8.7.
UDP unicast network storms trigger denial-of-service in Rockwell Automation 1719-AENTR adapters
A high-severity denial-of-service vulnerability in Rockwell Automation's 1719-AENTR adapter can cause a complete loss of communication.
Zero-day vulnerability chain enables root access and persistence on Siemens ROX II switches
A chain of three zero-day vulnerabilities in Siemens ROX II industrial switches allows attackers to escalate privileges and gain persistent root access.
Malicious firmware installation possible via critical vulnerabilities in Siemens CPCI85 processing units
Critical vulnerabilities in Siemens CPCI85 central processing units could allow attackers to install malicious firmware or bypass security controls.
Critical flaws in ABB T-MAC Plus enable unauthorized file access and authorization bypass
ABB's T-MAC Plus software contains several critical flaws that could allow attackers to access sensitive files or bypass authorization entirely. These vulnerabilities affect versions 4.0 through 24.
Vulnerability in Schneider Electric PowerChute Serial Shutdown threatens industrial power management systems
A vulnerability has been identified in Schneider Electric's PowerChute Serial Shutdown software. This advisory addresses potential risks to power management systems within industrial environments.
Hitachi Energy PROMOD V
A high-severity vulnerability has been identified in Hitachi Energy's PROMOD V software. The flaw stems from the use of insecure HTTP communication instead of the encrypted HTTPS protocol.