Translucid Security

Inteligência de Ameaças

  • Painel
  • Notícias
  • CVEs
  • Exploits
  • Ransomware
  • OT / ICS
Translucid Security
ENPT-BR

CISA

Avisos de OT / ICS

Avisos da CISA para sistemas de controle industrial — os CLPs, as IHMs e os sistemas prediais por trás do chão de fábrica, não o ambiente de TI.

Atualizando resultados…

Últimos 90 dias

Período
Classificação
Fabricante
Setor
Buscar avisos
Ordenação
ICSA-26-254-01AltaCVSS v3 8.815 CVEs

CISA Malcolm

The following versions of CISA Malcolm are affected:

EnergyInformation TechnologyWater and Wastewater
há 1 diaCISA
ICSA-26-274-01CríticaCVSS v3 9.85 CVEs

Armatura LLC Armatura One

Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system.

CommunicationsCritical ManufacturingEnergyTransportation Systems
há 1 diaArmatura LLC
ICSA-26-274-02CríticaCVSS v3 9.44 CVEs

Monta monta.app

Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.

EnergyTransportation Systems
há 1 diaMonta
ICSA-26-274-03MédiaCVSS v3 6.42 CVEs

ABB Protection and Control IED Manager PCM600

Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files.

Energy
há 1 diaABB
ICSA-26-274-04BaixaCVSS v3 3.51 CVE

Johnson Controls EasyIO Neo Series EC and CW Controllers

Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system.

Critical ManufacturingCommercial FacilitiesGovernment Services and FacilitiesTransportation SystemsEnergy
há 1 diaJohnson Controls
ICSA-26-274-05MédiaCVSS v3 5.41 CVE

Johnson Controls EasyIO Neo Series EC and CW Controllers

Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data.

Critical ManufacturingCommercial FacilitiesGovernment Services and FacilitiesTransportation SystemsEnergy
há 1 diaJohnson Controls
ICSA-26-274-06AltaCVSS v3 7.72 CVEs

Meari IoT Cloud Platform OpenAPI Service

Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization.

Commercial FacilitiesInformation Technology
há 1 diaMeari
ICSA-26-272-01AltaCVSS v3 7.52 CVEs

Lantronix G520 Series Cellular Gateway

Successful exploitation of these vulnerabilities could allow an attacker to replace software and execute arbitrary code with root privileges.

Transportation SystemsEnergyWater and Wastewater Systems
há 3 diasLantronix
ICSA-26-272-02CríticaCVSS v3 10.010 CVEs

Toptech TMS7 and TopHAT

Successful exploitation of these vulnerabilities could allow an attacker to access critical data or execute arbitrary code.

EnergyChemicalTransportation Systems
há 3 diasToptech Systems
ICSA-26-272-03CríticaCVSS v3 10.01 CVE

VIVOTEK Camera Firmware

Successful exploitation of this vulnerability may allow attackers to achieve remote command execution on affected devices, potentially with root privileges, leading to full compromise of the camera system.

Government Services and FacilitiesTransportation SystemsCommercial FacilitiesEnergyCritical ManufacturingFinancial Services
há 3 diasVIVOTEK
ICSA-26-272-04AltaCVSS v3 7.41 CVE

Baicells Nova 430H

Successful exploitation of this vulnerability could allow an attacker to inject malformed messages which may lead to a denial-of-service condition.

CommunicationsInformation Technology
há 3 diasBaicells Technologies
ICSA-26-272-05CríticaCVSS v3 9.89 CVEs

Anjvision YSSD-RTMP-H5

Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, access user accounts, execute OS-level commands, or take full control over the device.

Commercial Facilities
há 3 diasAnjvision
ICSA-26-272-06CríticaCVSS v3 9.81 CVE

MikroTik RouterOS

Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service.

CommunicationsInformation Technology
há 3 diasMikroTik
ICSA-26-272-07CríticaCVSS v3 10.02 CVEs

Viidure Dashcam Android Application

Successful exploitation of these vulnerabilities could allow attackers to access, modify, or delete sensitive user data and critical system files, potentially compromising the operation of the entire platform.

Transportation Systems
há 3 diasViidure
ICSA-26-209-02CríticaCVSS v3 9.11 CVE

Siemens Mendix Runtime (Update A)

This advisory is revoked. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute.

Critical Manufacturing
há 8 diasSiemens
ICSA-26-267-01AltaCVSS v3 8.814 CVEs

Botslab G980H Dashcams

Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication controls, gain unauthorized access to sensitive data and privileged device functionality, modify device configuration, disrupt device operation.

Transportation Systems
há 8 diasBotslab
ICSA-26-267-02CríticaCVSS v3 9.43 CVEs

Eufy Omni C20, Omni X10 Pro

Successful exploitation of these vulnerabilities could allow an attacker to run system level commands or execute arbitrary code.

Information Technology
há 8 diasEufy
ICSA-26-265-01CríticaCVSS v3 9.81 CVE

lwIP TCP/IP Stack MQTT Client Application

Successful exploitation of this vulnerability could allow an attacker to gain full code execution on the device.

ChemicalCommunicationsCritical ManufacturingEnergyFinancial ServicesHealthcare and Public Health
há 10 diaslwIP
ICSA-26-265-02AltaCVSS v3 8.81 CVE

lwIP (Lightweight IP)

Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system.

ChemicalCommunicationsCritical ManufacturingEnergyFinancial ServicesHealthcare and Public Health
há 10 diaslwIP
ICSA-26-265-03CríticaCVSS v3 9.01 CVE

Siemens Siveillance Control

A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server. Siemens has released patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions.

Critical ManufacturingCommunicationsCommercial Facilities
há 10 diasSiemens
ICSA-26-265-04AltaCVSS v3 7.81 CVE

Siemens SIPLUS and SIMATIC Products

Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

Critical ManufacturingEnergyWater and Wastewater SystemsChemicalFood and AgricultureCommercial Facilities
há 10 diasSiemens
ICSA-26-265-05AltaCVSS v3 8.21 CVE

Siemens Desigo CC family

A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization.

Critical ManufacturingCommercial Facilities
há 10 diasSiemens
ICSA-26-265-06CríticaCVSS v3 9.11 CVE

Siemens Industrial Edge Management

Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Critical Manufacturing
há 10 diasSiemens
ICSA-26-265-07AltaCVSS v3 8.61 CVE

Siemens SIMOVE Fleetmanager and SIPLANT

SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Critical Manufacturing
há 10 diasSiemens
ICSA-26-265-08MédiaCVSS v3 6.51 CVE

Siemens WTV676 and WTV776

The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Energy
há 10 diasSiemens
ICSA-26-265-09MédiaCVSS v3 6.11 CVE

OpenPLC Runtime v3

Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives.

Critical ManufacturingEnergyTransportation SystemsWater and Wastewater Systems
há 10 diasAutonomy Logic
ICSA-26-211-07AltaCVSS v3 7.11 CVE

Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)

Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.

Critical Manufacturing
há 15 diasMitsubishi Electric
ICSA-26-260-01AltaCVSS v3 7.53 CVEs

Bransys ELD

Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware.

Transportation Systems
há 15 diasBransys
ICSA-26-260-02AltaCVSS v3 8.81 CVE

Mitsubishi Electric GX Works3 and Motion Control Setting

Successful exploitation of this vulnerability could allow a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs.

Critical Manufacturing
há 15 diasMitsubishi Electric
ICSA-26-260-03CríticaCVSS v3 9.95 CVEs

Hitachi Energy FACTS Control Platform (FCP)

Hitachi Energy is aware of vulnerabilities that affect the FACTS Control systems with GWS component listed in this document. An attacker exploiting these vulnerabilities can cause impact on confidentiality, integrity and availability of the product. Following FACTS Control systems with GWS component deployed from year 2020 onwards are likely affected by the above vulnerabilities. Product deployments without GWS component are not affected. • SVC Light (STATCOM) • Fixed Series Capacitor • Thyristor Controlled Series Capacitor • Static Var Compensator • Static Watt Compensator • Hybrid Synchronou

Energy
há 15 diasHitachi Energy
ICSA-26-260-04AltaCVSS v3 7.51 CVE

Schneider Electric Modicon M340 Controller and Communication Modules

Schneider Electric is aware of a vulnerability in its Modicon M340 https://www.se.com/ww/en/product-range/1468-modicon-m340-pac/ , BMXNOR0200H https://www.se.com/us/en/product/BMXNOR0200H/communication-module-modicon-m340-iec-608705101-104-dnp3-for-severe-environments/ : Modicon M340 X80 Ethernet Communication Modules, BMXNGD0100 https://www.se.com/us/en/product/BMXNGD0100/communication-module-modicon-m580-global-data-service/ : M580 Global Data module, BMXNOC0401 https://www.se.com/us/en/product/BMXNOC0401/network-module-modicon-m340-ethernet-ip-and-modbus-tcp-4-x-rj45/?pageType=product&sourc

ChemicalCommercial FacilitiesCritical ManufacturingEnergyWater and Wastewater
há 15 diasSchneider Electric
ICSA-26-260-05MédiaCVSS v3 6.42 CVEs

Schneider Electric NetBotz 5 750/755

Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities. Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access.

Commercial FacilitiesCritical ManufacturingInformation Technology
há 15 diasSchneider Electric
ICSA-26-260-06AltaCVSS v3 7.81 CVE

ABB Ability Edgenius

ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete control of the system

Critical ManufacturingEnergyWater and WastewaterChemical
há 15 diasABB
ICSA-26-260-07MédiaCVSS v3 5.31 CVE

Schneider Electric PowerChute Serial Shutdown

Schneider Electric is aware of vulnerabilities in its PowerChute Serial Shutdown product. The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. Failure to apply the remediation provided below may risk improper authentication validation which could result in disruption of operations and access to system data.

Commercial FacilitiesCritical ManufacturingEnergyInformation Technology
há 15 diasSchneider Electric
ICSA-26-258-01CríticaCVSS v3 9.66 CVEs

Digital Watchdog VMAX DVR and NVR Product Lineups

Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point.

Commercial FacilitiesGovernment Services and FacilitiesHealthcare and Public HealthTransportation Systems
há 17 diasDigital Watchdog
ICSA-26-258-02AltaCVSS v3 8.32 CVEs

Wärtsilä FOS-Onboard (Update A)

Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to allow the attacker to impersonate a privileged client.

Transportation Systems
há 17 diasWärtsilä
ICSA-26-258-03CríticaCVSS v3 9.82 CVEs

mySCADA myPRO Manager

Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem.

Critical ManufacturingEnergyFood and AgricultureTransportation SystemsWater and Wastewater
há 17 diasmySCADA Technologies
ICSA-26-258-04MédiaCVSS v3 6.51 CVE

Schneider Electric SCADAPack x70 Products

Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities for remote monitoring and control. Failure to apply the mitigations provided below may increase the risk of unauthorized access to RTU configuration through the Secure Lock functionality, potentially resulting in a loss of confidentiality.

Critical ManufacturingEnergy
há 17 diasSchneider Electric
ICSA-26-258-05CríticaCVSS v3 9.814 CVEs

Siemens Reyrolle 7SR5

Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version.

Energy
há 17 diasSiemens
ICSA-26-258-06AltaCVSS v3 8.71 CVE

Siemens Mendix SAML

Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version.

Critical ManufacturingInformation Technology
há 17 diasSiemens
ICSA-26-258-07MédiaCVSS v3 6.11 CVE

Siemens Teamcenter

A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim's Teamcenter session. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Critical ManufacturingInformation Technology
há 17 diasSiemens
ICSA-26-258-08AltaCVSS v3 7.57 CVEs

CareCam CM2507

Successful exploitation of these vulnerabilities could allow an attacker to access live video and sensitive device information, enable unauthorized services, execute arbitrary code, modify device operation, and recover stored credentials.

Commercial Facilities
há 17 diasCareCam
ICSA-26-183-01AltaCVSS v3 8.84 CVEs

ST Engineering iDirect iQ-Series Terminals (Update A)

Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition.

CommunicationsDefense Industrial BaseEnergyGovernment Services and FacilitiesTransportation Systems
há 22 diasST Engineering iDirect
ICSA-26-253-01AltaCVSS v3 8.44 CVEs

AVEVA Pipeline Integrity Monitor

Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session.

Critical Manufacturing
há 22 diasAVEVA
ICSA-26-251-01MédiaCVSS v3 6.81 CVE

CareCam Pro IP Cameras

Successful exploitation of this vulnerability could allow an attacker to take full control of the device.

Commercial Facilities
há 24 diasCareCam
ICSA-26-169-07AltaCVSS v3 8.31 CVE

Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)

Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM P30 is a family of multifunction protection and control relays designed for medium, high and extra high voltage electrical networks. The Easergy MiCOM P40 is a protection relay series for Medium Voltage, High Voltage and Extra High Voltage protection. The Easergy MiCOM C264 is a modular and compact substation or bay controller, smart RTU and MV

ChemicalCritical ManufacturingEnergyWater and Wastewater
há 29 diasSchneider Electric
ICSA-26-202-01CríticaCVSS v3 9.82 CVEs

Tycon Systems TPDIN-Monitor-WEB2 (Update A)

Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.

Critical Manufacturing
há 29 diasTycon Systems
ICSA-26-246-01MédiaCVSS v3 4.61 CVE

OPCFoundation OPC UA LocalDiscoveryServer (LDS)

Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands.

ChemicalEnergyFood and AgricultureWater and WastewaterCritical Manufacturing
há 29 diasOPCFoundation
ICSA-26-246-02CríticaCVSS v3 9.61 CVE

IXON VPN Client

Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges.

Commercial FacilitiesCritical ManufacturingEnergyInformation TechnologyWater and Wastewater
há 29 diasIXON
ICSA-26-246-03AltaCVSS v3 7.31 CVE

Rockwell Automation ControlFLASH

Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.

Critical ManufacturingEnergyWater and Wastewater
há 29 diasRockwell Automation

Mostrando 1–50 de 120 avisos

Página 1 de 3