Výsledky hledání

téma: průmyslové systémy× typ: zranitelnost× v celém archivu zrušit filtry

108 karet z 118 položek · strana 1 z 2 CZ · EN/orig

1

SPOJENO PŘES CVE Moxa TN-4500B Series — Out-of-Bounds Write Vulnerability

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 8.8, CVEs: CVE-2026-15579, Summary: Moxa has disclosed an out-of-bounds write vulnerability in the Web login functionality of TN-4500B Series Ethernet switches. The vulnerability can be exploited remotely without authentication by supplying an overly long username, potentially causing a buffer overflow and denial of service. Moxa has released firmware 2.1, which addresses the vulnerability. Affected…

EPSS 0.01 CVSS 8.8 CVE-2026-15579 Moxa FI CA FR

tg: zranitelnost tg: novinka v produktu tp: průmyslové systémy

· NCSC-FI · Moxa TN-4500B Series — Out-of-Bounds Write Vulnerability · Cyber Centre Kanada · [Control Systems] Moxa security advisory (AV26-938) · CERT-FR – avis · Vulnérabilité dans les produits Moxa (18 septembre 2026)

3

[Control systems] ABB security advisory (AV26-942)

Serial number: AV26-942Date: September 18, 2026 As of September 18, 2026, ABB published a security advisory to address vulnerabilities in the following product: Freelance Controller Multiple versions and models The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Freelance SECURITY - Missing Length Check CVE ID: CVE-2023-5778 ABB Cyber security alerts and notifications

CVE-2023-5778 ABB CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control systems] ABB security advisory (AV26-942)

[Control systems] Advantech security advisory (AV26-937)

Serial number: AV26-937Date: September 18, 2026 As of September 4, 2026, Advantech is affected by vulnerabilities in the following products: EKI-1242EIMS Prior to or equal to V2.00.01 EKI-1242IEIMS Prior to or equal to V2.00.01 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Vulnerabilities Identified in EKI-1242EIMS/EKI-1242IEIMS (PDF) Advantech Security Advisories

Advantech CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control systems] Advantech security advisory (AV26-937)

CISA Releases Eight Industrial Control Systems Advisories

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.0: 9.9, CVEs: CVE-2026-13348, CVE-2026-31431, CVE-2026-13336, CVE-2026-13337, CVE-2025-6625, CVE-2024-4872, CVE-2024-3980, CVE-2024-3982, CVE-2024-7940, CVE-2024-7941, CVE-2026-15688, CVE-2026-86520, CVE-2026-86689, CVE-2026-77960, CVE-2026-13584, Summary: CISA released eight Industrial Control Systems (ICS) Advisories. These advisories provide timely information about current security issues,…

KEV ✓ EPSS 1.00 CVSS 9.9 CVE-2024-3980 CVE-2024-3982 CVE-2024-4872 CVE-2024-7940 CVE-2024-7941 CVE-2025-6625 CVE-2026-13336 CVE-2026-13337 CVE-2026-13348 CVE-2026-13584 CVE-2026-15688 CVE-2026-31431 CVE-2026-77960 CVE-2026-86520 CVE-2026-86689 Bransys Mitsubishi Electric Hitachi Energy Schneider Electric FI

tg: zranitelnost tp: průmyslové systémy

· NCSC-FI · CISA Releases Eight Industrial Control Systems Advisories

9

SPOJENO PŘES CVE ABB Ability Edgenius

View CSAF Summary ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete…

KEV ✓ EPSS 1.00 CVSS 7.8 CVE-2026-31431 ABB Linux výroba a průmysl energetika vodárenství US EU AT HU

tg: zneužíváno tg: zranitelnost tg: rozbor tp: průmyslové systémy

· CISA Advisories · ABB Ability Edgenius · Fortinet PSIRT · Linux Kernel Vulnerability copy.fail - CVE-2026-31431 · Elastic Security · Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild · CERT-EU · 2026-005: High Vulnerability in the Linux Kernel ("Copy Fail") · CERT.at · Copy Fail Update #1: Kritische Linux-Kernel-Schwachstelle ermöglicht lokale Root-Rechte · NKI Maďarsko · Riasztás a Linux rendszereket érintő Copy Fail sérülékenységről

Schneider Electric PowerChute Serial Shutdown

View CSAF Summary Schneider Electric is aware of vulnerabilities in its PowerChute Serial Shutdown product. The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. Failure to apply the remediation provided below may risk improper authentication validation which could result in disruption of operations and access to system data. The following versions of Schneider Electric…

EPSS 0.00 CVSS 5.3 CVE-2026-13348 Schneider Electric energetika výroba a průmysl US

tg: zranitelnost tp: identita tp: průmyslové systémy

· CISA Advisories · Schneider Electric PowerChute Serial Shutdown

Schneider Electric Modicon M340 Controller and Communication Modules

View CSAF Summary Schneider Electric is aware of a vulnerability in its Modicon M340 https://www.se.com/ww/en/product-range/1468-modicon-m340-pac/, BMXNOR0200H https://www.se.com/us/en/product/BMXNOR0200H/communication-module-modicon-m340-iec-608705101-104-dnp3-for-severe-environments/: Modicon M340 X80 Ethernet Communication Modules, BMXNGD0100 https://www.se.com/us/en/product/BMXNGD0100/communication-module-modicon-m580-global-data-service/: M580 Global Data module, BMXNOC0401 https://www.se…

EPSS 0.00 CVSS 7.5 CVE-2025-6625 Schneider Electric energetika vodárenství výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Schneider Electric Modicon M340 Controller and Communication Modules

Schneider Electric NetBotz 5 750/755

View CSAF Summary Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities. Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access. The following versions…

EPSS 0.01 CVSS 6.4 CVE-2026-13336 CVE-2026-13337 Schneider Electric výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Schneider Electric NetBotz 5 750/755

Bransys ELD

View CSAF Summary Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware. The following versions of Bransys ELD are affected: Android <11.00.00 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960) iOS <1.1.54 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960) CVSS Vendor Equipment Vulnerabilities v3 7.5 Bransys Bransys ELD Use of Hard-coded Credentials, Cleartext Transmission of Sensitive Information Background Critical Infrastructure Sectors:…

CVSS 7.5 CVE-2026-77960 CVE-2026-86520 CVE-2026-86689 Bransys doprava US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Bransys ELD

Hitachi Energy FACTS Control Platform (FCP)

View CSAF Summary Hitachi Energy is aware of vulnerabilities that affect the FACTS Control systems with GWS component listed in this document. An attacker exploiting these vulnerabilities can cause impact on confidentiality, integrity and availability of the product. Following FACTS Control systems with GWS component deployed from year 2020 onwards are likely affected by the above vulnerabilities. Product deployments without GWS component are not affected. • SVC Light (STATCOM) • Fixed Series…

EPSS 0.01 CVSS 9.9 CVE-2024-3980 CVE-2024-3982 CVE-2024-4872 CVE-2024-7940 CVE-2024-7941 Hitachi Energy energetika US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Hitachi Energy FACTS Control Platform (FCP)

Mitsubishi Electric GX Works3 and Motion Control Settings

View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs. The following versions of Mitsubishi Electric GX Works3 and Motion Control Settings are affected: Mitsubishi Electric GX Works3 vers:all/* (CVE-2026-15688)…

EPSS 0.00 CVSS 8.8 CVE-2026-15688 Mitsubishi Electric výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Mitsubishi Electric GX Works3 and Motion Control Settings

Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly. The following versions of Mitsubishi Electric CC-Link IE TSN…

EPSS 0.00 CVE-2026-13584 Mitsubishi Electric výroba a průmysl US

tg: zranitelnost tp: DDoS tp: průmyslové systémy

· CISA Advisories · Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)

6

[Control Systems] Phoenix Contact security advisory (AV26-927)

Serial number: AV26-927Date: September 16, 2026 As of September 16, 2026, Phoenix Contact is affected by vulnerabilities in the following products: ICE2-8IOL-G65L-V1D Prior to 1.7.4 ICE2-8IOL-K45P-RJ45 Prior to 1.7.4 ICE2-8IOL-K45S-RJ45 Prior to 1.7.4 ICE2-8IOL1-G65L-V1D Prior to 1.7.4 ICE3-8IOL-G65L-V1D Prior to 1.7.4 ICE3-8IOL-G65L-V1D-Y Prior to 1.7.4 ICE3-8IOL-K45P-RJ45 Prior to 1.7.4 ICE3-8IOL-K45S-RJ45 Prior to 1.7.4 ICE3-8IOL1-G65L-V1D Prior to 1.7.4 IOL MA8 EIP DI8 Prior to 1.7.4 IOL…

Phoenix Contact Pepperl+Fuchs Carlo Gavazzi Automation CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control Systems] Phoenix Contact security advisory (AV26-927)

Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities

[VDE-2026-028] The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be executed on the devices through command injection and local file inclusion. Path traversal and modified schemata can be used to read sensitive information such as password hashes or private keys from the devices.

Carlo Gavazzi DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities

Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities

[VDE-2026-014] The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be executed on the devices through command injection and local file inclusion. Path traversal and modified schemata can be used to read sensitive information such as password hashes or private keys from the devices.

Pepperl+Fuchs DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities

Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices

[VDE-2026-027] The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerabilities that can be used to bypass authentication. Code can be executed on the devices through command injection and local file inclusion. Path traversal and modified schemata can be used to read sensitive information such as password hashes or private keys from the devices.

Phoenix Contact DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices

SPOJENO PŘES CVE TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 8.6, CVEs: CVE-2026-81573, CVE-2026-81574, CVE-2026-81572, CVE-2026-81576, CVE-2026-81575, Summary: The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowing privilege escalation.

EPSS 0.00 CVSS 8.6 CVE-2026-81572 CVE-2026-81573 CVE-2026-81574 CVE-2026-81575 CVE-2026-81576 TRUMPF WIBU-SYSTEMS Wibu-Systems výroba a průmysl FI DE

tg: zranitelnost tp: dodavatelský řetězec tp: průmyslové systémy

· NCSC-FI · TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities · CERT@VDE · TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities

CISA Releases Eight Industrial Control Systems Advisories

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.0: 9.8, CVEs: CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372, CVE-2026-88259, CVE-2026-84398, CVE-2026-84400, CVE-2026-81305, CVE-2026-85478, CVE-2026-85497, CVE-2026-81321, CVE-2026-58113, CVE-2026-80465, CVE-2024-42384, CVE-2024-42385, CVE-2024-42386, CVE-2024-42391, CVE-2024-42392 (+14 other associated CVEs), Summary: CISA released eight Industrial Control…

CVSS 9.8 Digital Watchdog Wärtsilä mySCADA Schneider Electric FI

tg: zranitelnost tp: průmyslové systémy

· NCSC-FI · CISA Releases Eight Industrial Control Systems Advisories

5

Siemens Reyrolle 7SR5

View CSAF Summary Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version. The following versions of Siemens Reyrolle 7SR5 are affected: Reyrolle 7SR5 vers:intdot/<2.70 (CVE-2024-42384, CVE-2024-42385, CVE-2024-42386, CVE-2024-42391, CVE-2024-42392, CVE-2026-62645, CVE-2026-62646, CVE-2026-62647, CVE-2026-62648, CVE-2026-62649, CVE-2026-62650, CVE-2026-62652, CVE-2026-62653,…

EPSS 0.00 CVSS 9.8 CVE-2024-42384 CVE-2024-42385 CVE-2024-42386 CVE-2024-42391 CVE-2024-42392 CVE-2026-62645 CVE-2026-62646 CVE-2026-62647 CVE-2026-62648 CVE-2026-62649 CVE-2026-62650 CVE-2026-62652 CVE-2026-62653 CVE-2026-62654 Siemens energetika US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Siemens Reyrolle 7SR5

Wärtsilä FOS-Onboard

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to allow the attacker to impersonate a privileged client. The following versions of Wärtsilä FOS-Onboard are affected: FOS-Onboard 5.07.0923.01 (CVE-2026-78225, CVE-2026-81855) CVSS Vendor Equipment Vulnerabilities v3 9.1 Wärtsilä Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key Background Critical Infrastructure Sectors:…

EPSS 0.00 CVSS 9.1 CVE-2026-78225 CVE-2026-81855 Wärtsilä doprava US

tg: zranitelnost tp: identita tp: průmyslové systémy

· CISA Advisories · Wärtsilä FOS-Onboard

Siemens Teamcenter

View CSAF Summary A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim's Teamcenter session. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following…

EPSS 0.00 CVSS 6.1 CVE-2026-58113 Siemens výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Siemens Teamcenter

Schneider Electric SCADAPack x70 Products

View CSAF Summary Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities for remote monitoring and control. Failure to apply the mitigations provided below may increase the risk of unauthorized access to RTU configuration through the Secure Lock functionality, potentially resulting in a loss of confidentiality. The…

EPSS 0.00 CVSS 6.5 CVE-2026-81861 Schneider Electric výroba a průmysl energetika US

tg: zranitelnost tp: identita tp: průmyslové systémy

· CISA Advisories · Schneider Electric SCADAPack x70 Products

mySCADA myPRO Manager

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem. The following versions of mySCADA myPRO Manager are affected: mySCADA myPRO Manager <=2.1 (CVE-2026-73807, CVE-2026-82567) CVSS Vendor Equipment Vulnerabilities v3 9.8 mySCADA Technologies mySCADA myPRO Manager Missing Authorization, Missing Authentication for Critical Function Background Critical…

EPSS 0.01 CVSS 9.8 CVE-2026-73807 CVE-2026-82567 mySCADA Technologies výroba a průmysl energetika doprava vodárenství US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · mySCADA myPRO Manager

3

[Control Systems] National Instruments security advisory (AV26-914)

Serial number: AV26-914Date: September 11, 2026 As of September 10, 2026, National Instruments is affected by vulnerabilities in the following products: SystemLink Prior to or equal to 2026 Q3 Patch 1 SystemLink Server Prior to or equal to 2026 Q3 Patch 1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available./p> Improper Access Controls in NI SystemLink Storage of Sensitive Information in Cleartext in NI…

National Instruments CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control Systems] National Instruments security advisory (AV26-914)

[Control systems] GeoVision security advisory (AV26-913)

Serial number: AV26-913Date: Septembre 11, 2026 As of September 10, 2026, GeoVision is affected by vulnerabilities in the following product:: GV-LPC2011/LPC2211 Firmware version 1.13 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. GeoVision Security Advisory - GV-LPC-2026-09-01 Cyber Security - GeoVision

GeoVision CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control systems] GeoVision security advisory (AV26-913)

[Control systems] Schneider Electric security advisory (AV26-912)

Serial number: AV26-912Date: September 11, 2026 As of September 9, 2026, Schneider Electric is affected by vulnerabilities in the following products: EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert) Versions 9.1.2 and prior PowerLogic T300 Versions 2.9.8-5620 and prior The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates. Multiple Vulnerabilities on…

Schneider Electric CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control systems] Schneider Electric security advisory (AV26-912)

2

[Control systems] Advantech security advisory (AV26-907)

Serial number: AV26-907Date: September 10, 2026 As of September 10, 2026, Advantech is affected by vulnerabilities in the following product: Advantech WISE-6610 industrial gateway Multiple versions and models The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Vulnerabilities Identified in WISE-6610 Security Advisories - Advantech

Advantech CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control systems] Advantech security advisory (AV26-907)

AVEVA Pipeline Integrity Monitor

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session. The following versions of AVEVA Pipeline Integrity Monitor are affected: AVEVA Pipeline Integrity Monitor <=2025_SP1_P1_build_7.1.9580.8513 (CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, CVE-2026-81824) CVSS Vendor Equipment Vulnerabilities v3 8.4 AVEVA AVEVA Pipeline Integrity Monitor Use of Hard-coded…

EPSS 0.00 CVSS 8.4 CVE-2026-81821 CVE-2026-81822 CVE-2026-81823 CVE-2026-81824 AVEVA výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · AVEVA Pipeline Integrity Monitor

5

[Control Systems] Inductive Automation security advisory (AV26-892)

Serial Number: AV26-892Date: September 8, 2026 As of September 4, 2026, Inductive Automation is affected by a vulnerability in the following product: Ignition Prior to or equal to 8.1.53 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CSAF/csaf_files/OT/white/2026/icsa-26-246-06.json at develop · cisagov/CSAF · GitHub Inductive Automation Ignition | CISA

Inductive Automation CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control Systems] Inductive Automation security advisory (AV26-892)

[Control Systems] Siemens security advisory (AV26-890)

Serial Number: AV26-890Date: September 8, 2026 As of September 8, 2026, Siemens is affected by vulnerabilities in the following products: Reyrolle 7SR5 Versions prior to V2.70 Teamcenter Multiple versions and models Siveillance Control Multiple versions and models SIMATIC AX Runtime Multiple versions and models Desigo CC Product Family Multiple versions and models Industrial Edge Management Multiple versions and models SIMOVE Fleetmanager and SIPLANT Multiple versions and models The Cyber…

Siemens CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control Systems] Siemens security advisory (AV26-890)

NCSC-2026-0346 [1.01] [M/H] Kwetsbaarheden verholpen in Siemens producten

Siemens heeft kwetsbaarheden verholpen in diverse producten als Desigo, Reyrolle, SIMATIC, SCALANCE, SINAMICS en Siveillance. De kwetsbaarheden stellen een kwaadwillende in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: * Denial-of-Service (DoS) * Manipulatie van gegevens * Omzeilen van een beveiligingsmaatregel * (Remote) code execution (root/admin rechten) * (Remote) code execution (gebruikersrechten) * Toegang tot gevoelige gegevens * Verhogen van rechten…

Siemens NL

tg: zranitelnost tp: průmyslové systémy

· NCSC-NL · NCSC-2026-0346 [1.01] [M/H] Kwetsbaarheden verholpen in Siemens producten

Multiples vulnérabilités dans Schneider Electric EcoStruxure (08 septembre 2026)

De multiples vulnérabilités ont été découvertes dans Schneider Electric EcoStruxure. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et une falsification de requêtes côté serveur (SSRF).

EPSS 0.01 CVE-2026-19233 CVE-2026-8044 Schneider Electric FR

tg: zranitelnost tp: průmyslové systémy

· CERT-FR – avis · Multiples vulnérabilités dans Schneider Electric EcoStruxure (08 septembre 2026)

1

11

Pyramid Solutions NetStaX EtherNet/IP Stack

View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed. The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack are affected: EtherNet/IP Adapter DLL Kit (EIPA) EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE) EtherNet/IP Adapter Development Kit (EADK) EtherNet/IP Adapter…

EPSS 0.00 CVSS 9.8 CVE-2026-78012 Pyramid Solutions výroba a průmysl energetika vodárenství US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Pyramid Solutions NetStaX EtherNet/IP Stack

IXON VPN Client

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges. The following versions of IXON VPN Client are affected: VPN Client <1.4.7 (CVE-2026-75925) CVSS Vendor Equipment Vulnerabilities v3 9.6 IXON IXON VPN Client Improper Neutralization of CRLF Sequences ('CRLF Injection') Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy,…

EPSS 0.01 CVSS 9.6 CVE-2026-75925 IXON energetika výroba a průmysl vodárenství US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · IXON VPN Client

Rockwell Automation ArmorStart LT

View CSAF Summary Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page. The following versions of Rockwell Automation ArmorStart LT are affected: ArmorStart LT <=v2.001 (CVE-2026-19471, CVE-2026-19472) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation ArmorStart LT Improper Neutralization of Input During…

EPSS 0.00 CVSS 7.5 CVE-2026-19471 CVE-2026-19472 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation ArmorStart LT

Rockwell Automation ControlFLASH

View CSAF Summary Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. The following versions of Rockwell Automation ControlFLASH are affected: ControlFLASH <=V15.07 (CVE-2026-12663) CVSS Vendor Equipment Vulnerabilities v3 7.3 Rockwell Automation Rockwell Automation ControlFLASH Missing Authentication for Critical Function Background Critical…

EPSS 0.00 CVSS 7.3 CVE-2026-12663 Rockwell Automation výroba a průmysl energetika vodárenství US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation ControlFLASH

Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)

View CSAF Summary Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM P30 is a family of multifunction protection and control relays designed for medium, high and extra high voltage electrical networks. The Easergy MiCOM P40 is a protection relay series for Medium Voltage, High Voltage and Extra…

EPSS 0.00 CVSS 8.3 CVE-2026-4827 Schneider Electric energetika vodárenství výroba a průmysl US

tg: zranitelnost tp: identita tp: průmyslové systémy

· CISA Advisories · Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)

Tycon Systems TPDIN-Monitor-WEB3

View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected: TPDIN-Monitor-WEB3 <=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684) CVSS Vendor Equipment Vulnerabilities v3 8.8 Tycon Systems Tycon Systems TPDIN-Monitor-WEB3 Use of Hard-coded Credentials, Cross-Site…

EPSS 0.00 CVSS 8.8 CVE-2026-77847 CVE-2026-82684 CVE-2026-82712 Tycon Systems výroba a průmysl energetika US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Tycon Systems TPDIN-Monitor-WEB3

OPCFoundation OPC UA LocalDiscoveryServer (LDS)

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected: UA-LDS-Installers <1.04.420 (CVE-2026-77477) CVSS Vendor Equipment Vulnerabilities v3 4.6 OPCFoundation OPCFoundation OPC UA LocalDiscoveryServer (LDS) Execution with Unnecessary Privileges Background Critical Infrastructure…

CVSS 4.6 CVE-2026-77477 OPC Foundation energetika vodárenství výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · OPCFoundation OPC UA LocalDiscoveryServer (LDS)

Inductive Automation Ignition

View CSAF Summary Successful exploitation of this vulnerability could allow any authenticated user to create projects. The following versions of Inductive Automation Ignition are affected: Ignition <=8.1.53 (CVE-2026-77393) CVSS Vendor Equipment Vulnerabilities v3 8.8 Inductive Automation Inductive Automation Ignition Incorrect Default Permissions Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Information Technology Countries/Areas Deployed: Worldwide Company…

EPSS 0.01 CVSS 8.8 CVE-2026-77393 Inductive Automation výroba a průmysl energetika US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Inductive Automation Ignition

Tycon Systems TPDIN-Monitor-WEB2 (Update A)

View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected: TPDIN-Monitor-WEB2 <2.4.5 (CVE-2026-61884, CVE-2026-55985) CVSS Vendor Equipment Vulnerabilities v3 9.8 Tycon Systems Tycon Systems TPDIN-Monitor-WEB2 Missing…

EPSS 0.00 CVSS 9.8 CVE-2026-55985 CVE-2026-61884 Tycon Systems výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Tycon Systems TPDIN-Monitor-WEB2 (Update A)

Rockwell Automation 1756-ENBT Module

View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1756-ENBT Module Improper Check for Unusual or Exceptional Conditions Background Critical Infrastructure Sectors: Critical Manufacturing, Food and Agriculture,…

CVSS 7.5 CVE-2025-10478 Rockwell Automation výroba a průmysl doprava vodárenství US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation 1756-ENBT Module

Haavoittuvuuksia Rockwell Automation -tuotteissa

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.0: 8.6, CVEs: CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625, CVE-2026-9633, CVE-2026-9634, CVE-2026-9637, CVE-2026-16675, Summary: Rockwell Automation FactoryTalk Activation Manager Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation RSLinx Classic are affected: RSLinx…

EPSS 0.00 CVSS 8.6 CVE-2026-16675 CVE-2026-9621 CVE-2026-9622 CVE-2026-9624 CVE-2026-9625 CVE-2026-9633 CVE-2026-9634 CVE-2026-9637 Rockwell Automation FI

tg: zranitelnost tp: průmyslové systémy

· NCSC-FI · Haavoittuvuuksia Rockwell Automation -tuotteissa

2

[Control systems] Schneider Electric security advisory (AV26-871)

Serial Number: AV26-871Date: September 2, 2026 As of September 1, 2026, Schneider Electric is affected by vulnerabilities in the following products: NetBotz 5 - 750/755 Versions prior to or equal to 5.5.2 PowerChute Serial Shutdown Versions prior to or equal to 1.5 The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates. Multiple Vulnerabilities on NetBotz 5 - 750/755 Products Improper Restriction…

Schneider Electric CA

tg: zranitelnost tp: identita tp: průmyslové systémy

· Cyber Centre Kanada · [Control systems] Schneider Electric security advisory (AV26-871)

8

Rockwell Automation security advisory (AV26-869)

Serial number: AV26-869Date: September 1, 2026 As of September 1, 2026, Rockwell Automation is affected by vulnerabilities in the following products: 1756-ENBT Module All versions ArmorStart LT Prior to or equal to v2.001 CompactLogix 5380 / ControlLogix 5580 Prior to or equal to V33 V34.011 to V34.014 V35.011 to V35.013 V36.011 to V36.012 RSLinx Classic Prior to or equal to V4.50 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary…

Rockwell Automation CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · Rockwell Automation security advisory (AV26-869)

Rockwell Automation FactoryTalk Activation Manager

View CSAF Summary The following versions of Rockwell Automation FactoryTalk Activation Manager are affected: FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation FactoryTalk Activation Manager Improper Restriction of Excessive Authentication Attempts Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States…

EPSS 0.00 CVSS 7.8 CVE-2026-16675 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation FactoryTalk Activation Manager

Rockwell Automation Redundancy Module Configuration Tool

View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges. The following versions of Rockwell Automation Redundancy Module Configuration Tool are affected: Redundancy Module Configuration Tool 10.00.00 (CVE-2026-9633) Redundancy Module Configuration Tool >=9.00.00|<=10.00.00 (CVE-2026-9634) CVSS Vendor Equipment Vulnerabilities v3 7.3 Rockwell Automation Rockwell Automation Redundancy Module…

EPSS 0.00 CVSS 7.3 CVE-2026-9633 CVE-2026-9634 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation Redundancy Module Configuration Tool

Rockwell Automation Logix Platform

View CSAF Summary The following versions of Rockwell Automation Logix Platform are affected: ControlLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) CompactLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) GuardLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)…

EPSS 0.00 CVSS 7.5 CVE-2026-9637 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation Logix Platform

Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix

View CSAF Summary The following versions of Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix are affected: ControlLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) GuardLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) CompactLogix 5380 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE…

EPSS 0.03 CVSS 7.5 CVE-2021-42260 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix

Rockwell Automation Historian ME

View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution. The following versions of Rockwell Automation Historian ME are affected: Series B 5.202 (CVE-2025-12768, CVE-2026-12661) Series C 7.101 (CVE-2025-12768, CVE-2026-12661) CVSS Vendor Equipment Vulnerabilities v3 8 Rockwell Automation Rockwell Automation Historian ME Out-of-bounds Write, Stack-based Buffer Overflow Background…

EPSS 0.00 CVSS 8.0 CVE-2025-12768 CVE-2026-12661 Rockwell Automation výroba a průmysl zdravotnictví vodárenství US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation Historian ME

Rockwell Automation RSLinx Classic

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation RSLinx Classic are affected: RSLinx Classic <=4.50 (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) CVSS Vendor Equipment Vulnerabilities v3 8.6 Rockwell Automation Rockwell Automation RSLinx Classic Integer Overflow or Wraparound, Integer Underflow (Wrap or Wraparound), Buffer Copy…

EPSS 0.00 CVSS 8.6 CVE-2026-9621 CVE-2026-9622 CVE-2026-9624 CVE-2026-9625 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: DDoS tp: průmyslové systémy

· CISA Advisories · Rockwell Automation RSLinx Classic

SAUTER: modulo 6 and EY-modulo 5 Vulnerability in Firmware update mechanism allowing remote code execution

[VDE-2026-093] A vulnerability has been found in the firmware update process of SAUTER Building Controllers. The identified vulnerability could allow unauthorized code execution on affected controllers.

EPSS 0.00 CVE-2026-78319 SAUTER DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · SAUTER: modulo 6 and EY-modulo 5 Vulnerability in Firmware update mechanism allowing remote code execution

1

[Control Systems] Siemens security advisory (AV26-864)

Serial Number: AV26-864Date: August 31, 2026 As of August 27, 2026, Siemens is affected by a vulnerability in the following products: Element maps-ng V47 Prior to V47.12.3 Element maps-ng V48 Prior to V48.11.3 Element maps-ng V49 Prior to V49.16.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SSA-682041 CERT Services | Siemens

Siemens CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control Systems] Siemens security advisory (AV26-864)

1

[Control Systems] National Instruments security advisory (AV26-856)

Serial Number: AV26-856Date: August 28, 2026 As of August 25, 2026, National Instruments is affected by vulnerabilities in the following product: LabVIEW Prior to 23.0.0 Prior to 23.3.10 Prior to 24.3.7 Prior to 25.3.5 Prior to 26.3.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Memory Corruption Vulnerabilities in NI LabVIEW - NI Integer Conversion Vulnerability Resulting in an Out of Bounds Read…

National Instruments výroba a průmysl energetika vodárenství telekomunikace CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control Systems] National Instruments security advisory (AV26-856)

2

Murrelektronik: Vulnerability in 'Copy learned MAC Addresses' function enables MAC Spoofing on Xelity Switches

[VDE-2026-061] An information disclosure vulnerability in the web GUI of Murrelektronik Xelity switches causes MAC addresses from the device's MAC address table to be written into a server-side log that is exposed via the device's web interface to unauthenticated users. The leak is triggered when an authenticated administrator invokes the 'Copy learned MAC Addresses' function, which causes a syslog error that inserts the affected MAC addresses into the log output. Once the error has been…

EPSS 0.00 CVE-2026-8173 Murrelektronik výroba a průmysl DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Murrelektronik: Vulnerability in 'Copy learned MAC Addresses' function enables MAC Spoofing on Xelity Switches

Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities

[VDE-2026-083] Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execution vulnerability. IE-SR-2TX-WL-4G routers are also affected by a SMS password authorization bypass vulnerability. Weidmueller has released new firmware versions of the affected products to fix the vulnerabilities.

EPSS 0.01 CVE-2026-63586 CVE-2026-63587 Weidmüller DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities