Cybersecurity and Infrastructure Security Agency (CISA) issued six new advisories concerning Industrial Control Systems (ICS).

Cybersecurity and Infrastructure Security Agency (CISA) issued six new advisories concerning Industrial Control Systems (ICS). These advisories address critical vulnerabilities and offer mitigation guidance for affected vendors and systems. Below is an overview of the advisories and their key points:

List of Advisories

Advisory CodeVendorProduct(s)Focus / Issue
ICSA-25-196-01Hitachi EnergyAsset SuiteCross-Site Scripting & Mobile App Flaws
ICSA-25-196-02ABBRMC-100ICS Vulnerability
ICSA-25-196-03LITEONIC48A & IC80A EV ChargersFirmware Vulnerabilities
ICSA-25-037-02 (Update B)Schneider ElectricEcoStruxureUpdate B on prior vulnerability
ICSA-25-140-08 (Update A)Schneider ElectricModicon ControllersUpdate A on prior vulnerability
ICSA-25-070-01 (Update A)Schneider ElectricUni-Telway DriverUpdate A on prior vulnerability

Key Highlights

  • Hitachi Energy Asset Suite: The advisory addresses cross-site scripting vulnerabilities and mobile application security concerns. CISA recommends defensive measures and performing risk assessments before deploying any patches or mitigation strategies.
  • ABB RMC-100: This advisory focuses on vulnerabilities in ABB’s RMC-100 product. Users are urged to apply proper defensive measures and follow cyber defense best practices.
  • LITEON IC48A & IC80A EV Chargers: Newly released firmware mitigates identified vulnerabilities in these EV charging products. Minimal network exposure and regular updates are strongly advised.
  • Schneider Electric EcoStruxure, Modicon Controllers, Uni-Telway Driver (Updates): These updates address evolving vulnerabilities within Schneider Electric’s portfolio. The advisories provide new details and mitigation steps for these products.

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply