[
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/05/01/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/05/01/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\" data-entity-type=\"node\" data-entity-uuid=\"79453b83-86b9-4e2f-b1ec-abf73c6eb291\" data-entity-substitution=\"canonical\" title=\"Known Exploited Vulnerabilities Catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-31431\" target=\"_blank\">CVE-2026-31431</a> Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/binding-operational-directive-22-01\">Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities</a> established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the <a href=\"https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf\">BOD 22-01 Fact Sheet</a> for more information.</p>\n<p>Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\" data-entity-type=\"node\" data-entity-uuid=\"79453b83-86b9-4e2f-b1ec-abf73c6eb291\" data-entity-substitution=\"canonical\" title=\"Known Exploited Vulnerabilities Catalog\">KEV Catalog vulnerabilities</a> as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities\" data-entity-type=\"node\" data-entity-uuid=\"f2adba9a-0404-494c-a90c-4363a4a5c934\" data-entity-substitution=\"canonical\" title=\"Reducing the Significant Risk of Known Exploited Vulnerabilities\">specified criteria</a>.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Fri, 01 May 26 12:00:00 +0000",
        "last_updated": "Fri, 01 May 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services",
        "title": "Careful Adoption of Agentic AI Services",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services",
        "summary": "<p>CISA, in collaboration with the Australian Signals Directorate\u2019s Australian Cyber Security Centre (ASD\u2019s ACSC) and other international and U.S. partners, released guidance for organizations on adopting agentic artificial intelligence (AI) systems.</p>\n<p>This guide outlines key security challenges and risks associated with agentic AI, and provides actionable steps for designing, deploying, and operating these systems safely. It helps organizations align AI risk management with existing cybersecurity frameworks and strengthen oversight as agentic AI adoption grows.</p>\n<p>&nbsp;</p>\n<div class=\"c-text-cta\">\n<div class=\"l-constrain c-text-cta__inner\">\n<div class=\"c-text-cta__content\">\n<h2>Please share your thoughts!</h2>\n<div class=\"c-text-cta__summary\">\n<div class=\"c-text-cta__summary\">\n<p>We welcome your feedback.</p>\n</div>\n</div>\n<p><a class=\"c-button c-button--on-dark\" href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_9n4TtB8uttUPaM6?product=https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services\">CISA Product Survey</a></p>\n</div>\n</div>\n</div>",
        "summary_is_html": true,
        "first_seen": "Fri, 01 May 26 12:00:00 +0000",
        "last_updated": "Fri, 01 May 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-05",
        "title": "ABB AWIN Gateways",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-05",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-120-05_modified_for_Drupal%201.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to remotely reboot the device or complete an unauthenticated query to reveal system configuration, including sensitive details.</strong></p>\n<p>The following versions of ABB AWIN Gateways are affected:</p>\n<ul>\n<li>ABB AWIN Firmware (2.0-0) installed on ABB AWIN GW100 rev.2 2.0-0&nbsp;</li>\n<li>ABB AWIN Firmware (2.0-1) installed on ABB AWIN GW100 rev.2 2.0-1&nbsp;</li>\n<li>ABB AWIN Firmware (1.2-0) installed on ABB AWIN GW120 1.2-0&nbsp;</li>\n<li>ABB AWIN Firmware (1.2-1) installed on ABB AWIN GW120 1.2-1&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.3</td>\n<td>ABB</td>\n<td>ABB AWIN Gateways</td>\n<td>Authentication Bypass by Capture-replay, Missing Authentication for Critical Function</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Switzerland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-13777</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An unauthenticated query reveals data. Authentication Bypass due to Improper Session Validation.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-13777\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB AWIN Gateways</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB ABB AWIN Firmware (2.0-0) installed on ABB AWIN GW100 rev.2: 2.0-0, ABB ABB AWIN Firmware (2.0-1) installed on ABB AWIN GW100 rev.2: 2.0-1, ABB ABB AWIN Firmware (1.2-0) installed on ABB AWIN GW120: 1.2-0, ABB ABB AWIN Firmware (1.2-1) installed on ABB AWIN GW120: 1.2-1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>ABB AWIN Firmware 2.1-0 installed on ABB AWIN GW100 rev. 2 (Product ID: 3BNP102988R1) are fixed versions for CVE-2025-13777<br>ABB AWIN Firmware2.0-0 installed on ABB AWIN GW120 (Product ID 3BNP103003R1) are fixed versions for CVE-2025-13777</p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 4JNO000329 ABB CYBERSECURITY ADVISORY - PDF Version https://search.abb.com/library/Download.aspx?DocumentID=4JNO000329&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch, ABB CYBERSECURITY ADVISORY - CSAF Version https://psirt.abb.com/csaf/2026/4jno000329.json.<br><a href=\"https://search.abb.com/library/Download.aspx?DocumentID=4JNO000329&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https://search.abb.com/library/Download.aspx?DocumentID=4JNO000329&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 4JNO000329 ABB CYBERSECURITY ADVISORY - PDF Version https://search.abb.com/library/Download.aspx?DocumentID=4JNO000329&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch, ABB CYBERSECURITY ADVISORY - CSAF Version https://psirt.abb.com/csaf/2026/4jno000329.json.<br><a href=\"https://psirt.abb.com/csaf/2026/4jno000329.json\">https://psirt.abb.com/csaf/2026/4jno000329.json</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/294.html\">CWE-294 Authentication Bypass by Capture-replay</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-13778</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An unauthenticated query allows an attacker to remotely reboot the device, potentially causing a denial of service.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-13778\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB AWIN Gateways</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB ABB AWIN Firmware (2.0-0) installed on ABB AWIN GW100 rev.2: 2.0-0, ABB ABB AWIN Firmware (2.0-1) installed on ABB AWIN GW100 rev.2: 2.0-1, ABB ABB AWIN Firmware (1.2-0) installed on ABB AWIN GW120: 1.2-0, ABB ABB AWIN Firmware (1.2-1) installed on ABB AWIN GW120: 1.2-1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>ABB AWIN Firmware 2.1-0 installed on ABB AWIN GW100 rev. 2 (Product ID: 3BNP102988R1) are fixed versions for CVE-2025-13778<br>ABB AWIN Firmware2.0-0 installed on ABB AWIN GW120 (Product ID 3BNP103003R1) are fixed versions for CVE-2025-13778</p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 4JNO000329 ABB CYBERSECURITY ADVISORY - PDF Version https://search.abb.com/library/Download.aspx?DocumentID=4JNO000329&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch, ABB CYBERSECURITY ADVISORY - CSAF Version https://psirt.abb.com/csaf/2026/4jno000329.json.<br><a href=\"https://search.abb.com/library/Download.aspx?DocumentID=4JNO000329&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https://search.abb.com/library/Download.aspx?DocumentID=4JNO000329&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 4JNO000329 ABB CYBERSECURITY ADVISORY - PDF Version https://search.abb.com/library/Download.aspx?DocumentID=4JNO000329&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch, ABB CYBERSECURITY ADVISORY - CSAF Version https://psirt.abb.com/csaf/2026/4jno000329.json.<br><a href=\"https://psirt.abb.com/csaf/2026/4jno000329.json\">https://psirt.abb.com/csaf/2026/4jno000329.json</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-13779</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An unauthenticated query reveals the system configuration, including sensitive details.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-13779\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB AWIN Gateways</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB ABB AWIN Firmware (2.0-0) installed on ABB AWIN GW100 rev.2: 2.0-0, ABB ABB AWIN Firmware (2.0-1) installed on ABB AWIN GW100 rev.2: 2.0-1, ABB ABB AWIN Firmware (1.2-0) installed on ABB AWIN GW120: 1.2-0, ABB ABB AWIN Firmware (1.2-1) installed on ABB AWIN GW120: 1.2-1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>ABB AWIN Firmware 2.1-0 installed on ABB AWIN GW100 rev. 2 (Product ID: 3BNP102988R1) are fixed versions for CVE-2025-13779<br>ABB AWIN Firmware2.0-0 installed on ABB AWIN GW120 (Product ID 3BNP103003R1) are fixed versions for CVE-2025-13779</p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 4JNO000329 ABB CYBERSECURITY ADVISORY - PDF Version https://search.abb.com/library/Download.aspx?DocumentID=4JNO000329&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch, ABB CYBERSECURITY ADVISORY - CSAF Version https://psirt.abb.com/csaf/2026/4jno000329.json.<br><a href=\"https://search.abb.com/library/Download.aspx?DocumentID=4JNO000329&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https://search.abb.com/library/Download.aspx?DocumentID=4JNO000329&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 4JNO000329 ABB CYBERSECURITY ADVISORY - PDF Version https://search.abb.com/library/Download.aspx?DocumentID=4JNO000329&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch, ABB CYBERSECURITY ADVISORY - CSAF Version https://psirt.abb.com/csaf/2026/4jno000329.json.<br><a href=\"https://psirt.abb.com/csaf/2026/4jno000329.json\">https://psirt.abb.com/csaf/2026/4jno000329.json</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Fred Alvarez reported these vulnerabilities to ABB</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-04-30</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-04-30</td>\n<td>1</td>\n<td>Initial Republication of ABB 4JNO000329</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 30 Apr 26 12:00:00 +0000",
        "last_updated": "Thu, 30 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-04",
        "title": "ABB Ability OPTIMAX",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-04",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-120-04.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to bypass user authentication on OPTIMAX installations that make use of the Azure Active Directory Single-Sign On integration.</strong></p>\n<p>The following versions of ABB Ability OPTIMAX are affected:</p>\n<ul>\n<li>ABB Ability OPTIMAX 6.1 vers:all/*&nbsp;</li>\n<li>ABB Ability OPTIMAX 6.2 vers:all/*&nbsp;</li>\n<li>ABB Ability OPTIMAX 6.3 &lt;6.3.1-251120&nbsp;</li>\n<li>ABB Ability OPTIMAX 6.4 &lt;6.4.1-251120&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.1</td>\n<td>ABB</td>\n<td>ABB Ability OPTIMAX</td>\n<td>Incorrect Implementation of Authentication Algorithm</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Energy, Water and Wastewater</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Switzerland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-14510</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The vulnerability allows an attacker to bypass user authentication on OPTIMAX installations that make use of the Azure Active Directory Single-Sign On integration.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-14510\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB Ability OPTIMAX</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB ABB Ability OPTIMAX 6.1: vers:all/*, ABB ABB Ability OPTIMAX 6.2: vers:all/*, ABB ABB Ability OPTIMAX 6.3: &lt;6.3.1-251120, ABB ABB Ability OPTIMAX 6.4: &lt;6.4.1-251120</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>The following product versions have been fixed:&nbsp;</p>\n<p>Ability OPTIMAX 6.3 6.3.1-251120 is a fixed version for CVE-2025-14510</p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A1331 ABB CYBERSECURITY ADVISORY - PDF Version (https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A1331&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch), ABB CYBERSECURITY ADVISORY - CSAF Version (https://psirt.abb.com/csaf/2026/9akk108472a1331.json).<br><a href=\"https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A1331&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A1331&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A1331 ABB CYBERSECURITY ADVISORY - PDF Version (https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A1331&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch), ABB CYBERSECURITY ADVISORY - CSAF Version (https://psirt.abb.com/csaf/2026/9akk108472a1331.json).<br><a href=\"https://psirt.abb.com/csaf/2026/9akk108472a1331.json\">https://psirt.abb.com/csaf/2026/9akk108472a1331.json</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/303.html\">CWE-303 Incorrect Implementation of Authentication Algorithm</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>ABB PSIRT reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability has a high attack complexity.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-04-30</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-04-30</td>\n<td>1</td>\n<td>Initial Republication of ABB PSIRT 9AKK108472A1331</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 30 Apr 26 12:00:00 +0000",
        "last_updated": "Thu, 30 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-02",
        "title": "ABB PCM600",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-120-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to send specially crafted messages to the system node resulting in execution of arbitrary code.</strong></p>\n<p>The following versions of ABB PCM600 are affected:</p>\n<ul>\n<li>PCM600 &gt;=1.5|&lt;=2.13&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 4.4</td>\n<td>ABB</td>\n<td>ABB PCM600</td>\n<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Switzerland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2018-1002208</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability exists in the SharpZip.dll included in the product versions listed above. An attacker could exploit vulnerability by providing a specially crafted message to the system node, causing insertion, and running of arbitrary code.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2018-1002208\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB PCM600</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB PCM600: &gt;=1.5|&lt;=2.13</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>The problem is corrected in the following product version: ABB Protection and control IED manager PCM600 version 2.14. ABB recommends that customers apply the update at earliest convenience.</p>\n<p><strong>Vendor fix</strong><br>Note: RE_630 protection relays are not compatible with PCM600 version 2.14. When using earlier PCM600 versions with RE_630, the known vulnerability must be mitigated through system-level defenses. For mitigation guidance, refer to the General Security Recommendations.</p>\n<p><strong>Vendor fix</strong><br>The following product versions have been fixed: Protection and Control IED manager PCM600 2.14 is a fixed version for CVE-2018-1002208</p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 2NGA002813 ABB CYBERSECURITY ADVISORY - PDF version (https://search.abb.com/library/Download.aspx?DocumentID=2NGA002813&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch), ABB CYBERSECURITY ADVISORY - CSAF version (https://psirt.abb.com/csaf/2025/2nga002813.json).<br><a href=\"https://search.abb.com/library/Download.aspx?DocumentID=2NGA002813&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">https://search.abb.com/library/Download.aspx?DocumentID=2NGA002813&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 2NGA002813 ABB CYBERSECURITY ADVISORY - PDF version (https://search.abb.com/library/Download.aspx?DocumentID=2NGA002813&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch), ABB CYBERSECURITY ADVISORY - CSAF version (https://psirt.abb.com/csaf/2025/2nga002813.json).<br><a href=\"https://psirt.abb.com/csaf/2025/2nga002813.json\">https://psirt.abb.com/csaf/2025/2nga002813.json</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/22.html\">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>4.4</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N\">CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>ABB PSIRT reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely. This vulnerability has a high attack complexity.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-04-30</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-04-30</td>\n<td>1</td>\n<td>Initial Republication of ABB PSIRT 2NGA002813</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 30 Apr 26 12:00:00 +0000",
        "last_updated": "Thu, 30 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-03",
        "title": "ABB Edgenius Management Portal",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-03",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-120-03.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to send a specially crafted message to the system node allowing the attacker to install and run arbitrary code, uninstall applications, and modify the configuration of installed applications.</strong></p>\n<p>The following versions of ABB Edgenius Management Portal are affected:</p>\n<ul>\n<li>Edgenius Management Portal 3.2.0.0|3.2.1.1</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.6</td>\n<td>ABB</td>\n<td>ABB Edgenius Management Portal</td>\n<td>Authentication Bypass Using an Alternate Path or Channel</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Switzerland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-10571</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Edgenius Management Portal in the affected product versions contains a vulnerability that allows authentication to be bypassed. An attacker could exploit the vulnerability by sending a specially crafted message to the system node allowing the attacker to install and run arbitrary code, uninstall in-stalled applications and modify the configuration of installed applications.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-10571\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB Edgenius Management Portal</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB Edgenius Management Portal: 3.2.0.0|3.2.1.1</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>ABB has prepared an update to fix this vulnerability included in the latest Roll-Up, ABB Ability Edgenius version 3.2.2.0. ABB advises customers to upgrade as soon as possible. Until the upgrade is applied, ABB advises customers to disable the Edgenius Management Portal to mitigate the vulnerability.</p>\n<p><strong>Vendor fix</strong><br>All affected products: Exploitation requires an attacker to have gained access to the network where Edgenius has been deployed, and while the Edgenius Management Portal is running. Refer to section \"General security recommendations\" for further advise on how to keep your system secure.</p>\n<p><strong>Mitigation</strong><br>All affected products: Workarounds are specific measures that a user can take to help block an attack, for example, temporarily disabling the vulnerable feature may remove the exposure with well-known impact on functionality. ABB has tested the following workaround.</p>\n<p><strong>Mitigation</strong><br>The following product versions have been fixed:<br>Ability Edgenius 3.2.2.0 is a fixed version for CVE-2025-10571</p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 7PAA022088 ABB CYBERSECURITY ADVISORY - PDF version (https://search.abb.com/library/Download.aspx?DocumentID=7PAA022088&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch), ABB CYBERSECURITY ADVISORY - CSAF version (https://psirt.abb.com/csaf/2025/7paa022088.json).<br><a href=\"https://search.abb.com/library/Download.aspx?DocumentID=7PAA022088&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https://search.abb.com/library/Download.aspx?DocumentID=7PAA022088&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch</a></p>\n<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 7PAA022088 ABB CYBERSECURITY ADVISORY - PDF version (https://search.abb.com/library/Download.aspx?DocumentID=7PAA022088&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch), ABB CYBERSECURITY ADVISORY - CSAF version (https://psirt.abb.com/csaf/2025/7paa022088.json).<br><a href=\"https://psirt.abb.com/csaf/2025/7paa022088.json\">https://psirt.abb.com/csaf/2025/7paa022088.json</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/288.html\">CWE-288 Authentication Bypass Using an Alternate Path or Channel</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.6</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>ABB PSIRT reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-04-30</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-04-30</td>\n<td>1</td>\n<td>Initial Republication of ABB PSIRT 7PAA022088</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 30 Apr 26 12:00:00 +0000",
        "last_updated": "Thu, 30 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/04/30/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/04/30/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added&nbsp;one&nbsp;new&nbsp;vulnerability&nbsp;to its&nbsp;<a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.&nbsp;</p>\n<ul type=\"disc\">\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-41940\" target=\"_blank\">CVE-2026-41940</a>&nbsp;WebPros cPanel &amp; WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability</li>\n</ul>\n<p>This&nbsp;type of vulnerability&nbsp;is a&nbsp;frequent attack vector for malicious cyber actors and poses&nbsp;significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/binding-operational-directive-22-01\">Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities</a> established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the <a href=\"https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf\">BOD 22-01 Fact Sheet</a> for more information.&nbsp;</p>\n<p>Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a> as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities\">specified criteria</a>.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Thu, 30 Apr 26 12:00:00 +0000",
        "last_updated": "Thu, 30 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-06",
        "title": "ABB Ability Symphony Plus Engineering",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-06",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-120-06.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>ABB became aware of vulnerability in the products versions listed as affected in the advisory. The ABB S+ Engineering product versions are affected by vulnerabilities in PostgreSQL version 13.11 and earlier versions. If an attacker gains access to a site\u2019s S+ Client Server network, they could exploit such vulnerabilities by executing arbitrary code and potentially compromising the entire system.</strong></p>\n<p>The following versions of ABB Ability Symphony Plus Engineering are affected:</p>\n<ul>\n<li>Ability Symphony Plus 2.2, 2.3, 2.3_RU1, 2.3_RU2, 2.3_RU3, 2.4, 2.4_SP1, 2.4_SP2, 2.4_SP2_RU1&nbsp;</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 8.8</td>\n<td>ABB</td>\n<td>ABB Ability Symphony Plus Engineering</td>\n<td>Integer Overflow or Wraparound, Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), Time-of-check Time-of-use (TOCTOU) Race Condition, Privilege Dropping / Lowering Errors</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Critical Manufacturing, Energy, Water and Wastewater</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Switzerland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2023-5869</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An attacker running as an authenticated PostgreSQL user can provide crafted data and trigger the integer overflow due to such missing overflow check. This can enable the execution of arbitrary code in the system.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2023-5869\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB Ability Symphony Plus Engineering</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB Ability Symphony Plus S+ Engineering 2.2, ABB Ability Symphony Plus S+ Engineering 2.3, ABB Ability Symphony Plus S+ Engineering 2.3 RU1, ABB Ability Symphony Plus S+ Engineering 2.3 RU2, ABB Ability Symphony Plus S+ Engineering 2.3 RU3, ABB Ability Symphony Plus S+ Engineering 2.4, ABB Ability Symphony Plus S+ Engineering 2.4 SP1, ABB Ability Symphony Plus S+ Engineering 2.4 SP2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>fixed, known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>ABB advises all customers to review their installations to determine if they are using an impacted product as listed above, no further analysis or tools are needed to make this determination. The recommended immediate actions per product are listed below: - Systems using S+ Engineering 2.2 through 2.4 SP2 should upgrade to S+ Engineering 2.4 SP2 RU1 (re-leased in December 2024) or later. - End users who are unable to install one of these updates should immediately look to implement the Mitigation and Workarounds listed below as this will restrict or prevent an attacker\u2019s ability to com-promise the system. ABB recommends that customers apply the update at the earliest convenience.</p>\n<p><strong>Mitigation</strong><br>Any exploit of these vulnerabilities would require that the attacker has access to the site\u2019s S+ client/server network. Following ABB\u2019s recommended security practices, including network architecture and perimeter firewall, are mitigating factors in preventing external access to the S+ client/server net-work. Refer to section \u201cGeneral security recommendations\u201d for further advise on how to keep your system secure.</p>\n<p><strong>Workaround</strong><br>No workarounds are available. Assess the installation specific risk based on this advisory. Use the recommendations described under \u201cMitigating factors\u201d or \u201cRecommended immediate actions\u201d.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/190.html\">CWE-190 Integer Overflow or Wraparound</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2023-39417</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>If an administrator has installed Extension scripts and specific data is used inside a quoting con-struct, an attacker having proper PostgreSQL privileges can execute arbitrary code in the system as the administrator.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2023-39417\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB Ability Symphony Plus Engineering</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB Ability Symphony Plus S+ Engineering 2.2, ABB Ability Symphony Plus S+ Engineering 2.3, ABB Ability Symphony Plus S+ Engineering 2.3 RU1, ABB Ability Symphony Plus S+ Engineering 2.3 RU2, ABB Ability Symphony Plus S+ Engineering 2.3 RU3, ABB Ability Symphony Plus S+ Engineering 2.4, ABB Ability Symphony Plus S+ Engineering 2.4 SP1, ABB Ability Symphony Plus S+ Engineering 2.4 SP2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>fixed, known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>ABB advises all customers to review their installations to determine if they are using an impacted product as listed above, no further analysis or tools are needed to make this determination. The recommended immediate actions per product are listed below: - Systems using S+ Engineering 2.2 through 2.4 SP2 should upgrade to S+ Engineering 2.4 SP2 RU1 (re-leased in December 2024) or later. - End users who are unable to install one of these updates should immediately look to implement the Mitigation and Workarounds listed below as this will restrict or prevent an attacker\u2019s ability to com-promise the system. ABB recommends that customers apply the update at the earliest convenience.</p>\n<p><strong>Mitigation</strong><br>Any exploit of these vulnerabilities would require that the attacker has access to the site\u2019s S+ client/server network. Following ABB\u2019s recommended security practices, including network architecture and perimeter firewall, are mitigating factors in preventing external access to the S+ client/server net-work. Refer to section \u201cGeneral security recommendations\u201d for further advise on how to keep your system secure.</p>\n<p><strong>Workaround</strong><br>No workarounds are available. Assess the installation specific risk based on this advisory. Use the recommendations described under \u201cMitigating factors\u201d or \u201cRecommended immediate actions\u201d.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/89.html\">CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C\">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2024-7348</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A \u2018time-of-check time-of-use\u2019 (TOCTOU) race condition in a PostgreSQL can allow an attacker to easily execute arbitrary SQL functions by leveraging a PostgreSQL utility often executed with high privileges.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2024-7348\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB Ability Symphony Plus Engineering</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB Ability Symphony Plus S+ Engineering 2.2, ABB Ability Symphony Plus S+ Engineering 2.3, ABB Ability Symphony Plus S+ Engineering 2.3 RU1, ABB Ability Symphony Plus S+ Engineering 2.3 RU2, ABB Ability Symphony Plus S+ Engineering 2.3 RU3, ABB Ability Symphony Plus S+ Engineering 2.4, ABB Ability Symphony Plus S+ Engineering 2.4 SP1, ABB Ability Symphony Plus S+ Engineering 2.4 SP2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>fixed, known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>ABB advises all customers to review their installations to determine if they are using an impacted product as listed above, no further analysis or tools are needed to make this determination. The recommended immediate actions per product are listed below: - Systems using S+ Engineering 2.2 through 2.4 SP2 should upgrade to S+ Engineering 2.4 SP2 RU1 (re-leased in December 2024) or later. - End users who are unable to install one of these updates should immediately look to implement the Mitigation and Workarounds listed below as this will restrict or prevent an attacker\u2019s ability to com-promise the system. ABB recommends that customers apply the update at the earliest convenience.</p>\n<p><strong>Mitigation</strong><br>Any exploit of these vulnerabilities would require that the attacker has access to the site\u2019s S+ client/server network. Following ABB\u2019s recommended security practices, including network architecture and perimeter firewall, are mitigating factors in preventing external access to the S+ client/server net-work. Refer to section \u201cGeneral security recommendations\u201d for further advise on how to keep your system secure.</p>\n<p><strong>Workaround</strong><br>No workarounds are available. Assess the installation specific risk based on this advisory. Use the recommendations described under \u201cMitigating factors\u201d or \u201cRecommended immediate actions\u201d.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/367.html\">CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2024-0985</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An attacker can provide untrusted materialized views and lure a high privileged authorized user to inadvertently execute arbitrary SQL functions by refreshing the attacker's materialized view.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2024-0985\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB Ability Symphony Plus Engineering</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>ABB Ability Symphony Plus S+ Engineering 2.2, ABB Ability Symphony Plus S+ Engineering 2.3, ABB Ability Symphony Plus S+ Engineering 2.3 RU1, ABB Ability Symphony Plus S+ Engineering 2.3 RU2, ABB Ability Symphony Plus S+ Engineering 2.3 RU3, ABB Ability Symphony Plus S+ Engineering 2.4, ABB Ability Symphony Plus S+ Engineering 2.4 SP1, ABB Ability Symphony Plus S+ Engineering 2.4 SP2</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>fixed, known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>ABB advises all customers to review their installations to determine if they are using an impacted product as listed above, no further analysis or tools are needed to make this determination. The recommended immediate actions per product are listed below: - Systems using S+ Engineering 2.2 through 2.4 SP2 should upgrade to S+ Engineering 2.4 SP2 RU1 (re-leased in December 2024) or later. - End users who are unable to install one of these updates should immediately look to implement the Mitigation and Workarounds listed below as this will restrict or prevent an attacker\u2019s ability to com-promise the system. ABB recommends that customers apply the update at the earliest convenience.</p>\n<p><strong>Mitigation</strong><br>Any exploit of these vulnerabilities would require that the attacker has access to the site\u2019s S+ client/server network. Following ABB\u2019s recommended security practices, including network architecture and perimeter firewall, are mitigating factors in preventing external access to the S+ client/server net-work. Refer to section \u201cGeneral security recommendations\u201d for further advise on how to keep your system secure.</p>\n<p><strong>Workaround</strong><br>No workarounds are available. Assess the installation specific risk based on this advisory. Use the recommendations described under \u201cMitigating factors\u201d or \u201cRecommended immediate actions\u201d.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/271.html\">CWE-271 Privilege Dropping / Lowering Errors</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C\">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>ABB Global reported these vulnerabilities to CISA.&nbsp;</li>\n</ul>\n<hr>\n<h2>Notice</h2>\n<p>The information in this document is subject to change without notice, and should not be construed as a commitment by ABB. ABB provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall ABB or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if ABB or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from ABB, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners.</p>\n<hr>\n<h2>Frequently Asked Questions</h2>\n<p>What is the scope of the vulnerability? - An attacker who successfully exploited these vulnerabilities could insert and run arbitrary code in the S+ system. What causes the vulnerability? - It is caused by several vulnerabilities in the PostgreSQL version 13.11 and earlier versions component used by the S+ Engineering product (see Affected products). What might an attacker use the vulnerability to do? - An attacker who successfully accessed the site\u2019s S+ client/server network could cause a denial-of-service situation, corruptions of data or unauthorized disclosure of information. How could an attacker exploit the vulnerability? - To exploit the PostgreSQL vulnerabilities (see Vulnerability severity and details), an attacker should successfully access to the site\u2019s S+ client/server network, remotely (through a wrongly configured or penetrated firewall) or even compromising a local machine and then accessing to PostgreSQL. Recommended practices help mitigate such attacks, see section Mitigating Factors above. Could the vulnerability be exploited remotely? - Yes, see the above How could an attacker exploit the vulnerability? Recommended practices include that process control systems are physically protected, have no direct connections to the Internet, and are separated from other networks by means of a firewall system that has a minimal number of ports exposed. Can functional safety be affected by an exploit of this vulnerability? - Functional safety systems are not affected by these vulnerabilities What does the update do? - The S+ Engineering update removes the vulnerability by installing a secure updated PostgreSQL version. When this security advisory was issued, had this vulnerability been publicly disclosed? - Yes, PostgreSQL 13.11 vulnerabilities have been publicly disclosed. When this security advisory was issued, had ABB received any reports that this vulnerability was being exploited? - No, ABB had not received any information indicating that S+ Engineering had been exploited when this security advisory was originally issued.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of ABB PSIRT 7PAA017341 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-04-13</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-04-13</td>\n<td>1</td>\n<td>Initial version.</td>\n</tr>\n<tr>\n<td>2026-04-30</td>\n<td>2</td>\n<td>Initial CISA Republication of ABB PSIRT 7PAA017341 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 30 Apr 26 12:00:00 +0000",
        "last_updated": "Thu, 30 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-01",
        "title": "ABB System 800xA, Symphony Plus IEC 61850",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-120-01%201.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>This vulnerability was privately reported relating to ABB\u2019s implementation of the IEC 61850 communication stack for MMS client applications used in some Automation control system products. Note: IEC 61850 communication typically supports MMS and GOOSE protocols. Some ABB products support both, others only MMS (e.g. S+ Operations and PM 877). In any case, GOOSE communication is not impacted by this reported vulnerability. If an attacker gains access to a site\u2019s IEC 61850 network, then exploiting this vulnerability will result in a device fault (PM 877, CI850 and CI868 modules) and will require a manual restart. If this attack is directed at a S+ Operations node running IEC 61850 connectivity, this will result in a crash in the IEC 61850 communication driver which, if continued a repeating basis, will also result in a denial-of-service situation. Note that this does not have an impact on the overall availability and functionality of the S+ Operations node, only the IEC 61850 communication function. The System 800xA IEC61850 Connect is not affected.</strong></p>\n<p>The following versions of ABB System 800xA, Symphony Plus IEC 61850 are affected:</p>\n<ul>\n<li>AC800M Product line (System 800xA) CI868</li>\n<li>Symphony Plus SD Series CI850</li>\n<li>Symphony Plus MR (Melody Rack) PM 877</li>\n<li>S+ Operations</li>\n<li>Firmware &lt;=6.0.0303.0, &lt;=6.1.0031.0 , &lt;=6.1.1004.0 , &lt;=6.1.1202.0 , &lt;=6.2.0006.0 , 6.1.1-3, 7.0, A_0, A_1, A_2.003, A_3.005, A_4.001, B_0.005, C_0, &gt;=3.10|&lt;=3.52, 3.53, 3.3, 2.3, 2.2, 2.1, 3.4 ()</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 6.5</td>\n<td>ABB</td>\n<td>ABB System 800xA, Symphony Plus IEC 61850</td>\n<td>Improper Validation of Specified Quantity in Input</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Critical Manufacturing, Energy, Water and Wastewater</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Switzerland</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-3756</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions listed above. An attacker with access to IEC 61850 networks could exploit the vulnerability by using a specially crafted 61850 packet, forcing the communication interfaces of the PM 877, CI850 and CI868 modules into fault mode or causing unavailability of the S+ Operations 61850 connectivity, resulting in a denial-of-service situation. The System 800xA IEC61850 Connect is not affected. Note: This vulnerability does not impact on the overall availability and functionality of the S+ Operations node, only the 61850 communication function.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-3756\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>ABB System 800xA, Symphony Plus IEC 61850</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>ABB</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>&nbsp;</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>fixed, known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>ABB advises all customers to review their installations to determine if they are using an impacted product as listed above, no further analysis or tools are needed to make this determination. The recommended immediate actions per product are listed below: - CI868 (for AC 800M) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in 6.1.1 and 7.0 tracks for 800xA. AC 800M 6.1.1-3 is planned for Q2 2027, AC 800M 7.0 has been released in December 2025. - CI850 (for Symphony Plus SD Series) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in version C_0 or later (planned Q2 2026). - PM 877 (Symphony Plus MR) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected with firmware version 3.53 or later (planned Q1 2026). - S+ Operations Versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in version 3.4 or later (released in January 2026). ABB recommends customers apply updates, as they become available, at their earliest convenience. It is also advisable to review the Mitigating Factors, Workarounds and General security recommendations sections for additional actions which may help reduce overall risk.</p>\n<p><strong>Mitigation</strong><br>The vulnerabilities announced in this Advisory for ABB Process Automation products require that an attacker has access to the system network and hosts which are generally expected to be protected. Process Control and IEC 61850 networks are NOT recommended to be exposed directly to Internet connections. If these networks are not properly isolated, then connected components may be remotely exploitable as described in this advisory. To exploit the vulnerability, an attacker with remote network access can send a specially crafted packet to the PM 877, CI850 and CI868 modules which causes the fault of these devices. S+ Operations only implements 61850 client services and therefore are not intended to listen to in-coming connection requests. However, if a specially crafted message is sent anyway, it can still cause the 61850-communication driver to crash. The usage of a perimeter firewall to allow legitimate client communications is an effective mitigation. Refer to section \u201cGeneral security recommendations\u201d for further advise on how to keep your system secure.</p>\n<p><strong>Workaround</strong><br>No workarounds are available. Assess the installation specific risk based on this advisory. Use the recommendations described under \u201cMitigating factors\u201d or \u201cRecommended immediate actions\u201d.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/1284.html\">CWE-1284 Improper Validation of Specified Quantity in Input</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Hitachi Energy reported this vulnerability to ABB Global.</li>\n<li>ABB Global reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>Notice</h2>\n<p>The information in this document is subject to change without notice, and should not be construed as a commitment by ABB. ABB provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall ABB or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if ABB or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from ABB, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners.</p>\n<hr>\n<h2>Frequently Asked Questions</h2>\n<p>What is the scope of the vulnerability? - An attacker having access to the IEC 61850 network can force the ABB hardware devices to go to \u2018fault\u2019 state by sending a specially crafted 61850 packet. This will result in a denial-of-service situation affecting the primary functionality of the listed devices and requiring a manual reset. In the same way this vulnerability can cause the unavailability of the S+ Operations 61850 connectivity, if continued on a repeating basis (but not the whole S+ Operations node). The System 800xA IEC61850 Connect is not affected. What causes the vulnerability? - The vulnerability is caused by a weakness in the message processing in the IEC 61850 communication stack. What is CI868? - CI868 is a module used in AC800M product line (System 800xA) for IEC 61850 communication. What is CI850? - CI868 is a module used in Symphony Plus SD Series product line for IEC 61850 communication. What is PM 877? - PM 877 is a controller used in Symphony Plus MR (Melody Rack) product line for IEC 61850 communication. What is S+ Operations? - S+ Operations is the Human Machine Interface for supervision and control of Symphony based control or SCADA systems. It is a module used in AC800M product line (System 800xA) for IEC 61850 communication. What might an attacker use the vulnerability to do? - An attacker with access to IEC 61850 networks could exploit the vulnerability by sending a specially crafted 61850 packet to the S+ products, forcing the Communication Interfaces to fault modes or causing unavailability of the S+ Operations 61850 connectivity, resulting in a denial-of-service situation. How could an attacker exploit the vulnerability? - An attacker could try to exploit the vulnerability by creating a specially crafted message and sending the message to an affected system node. This would require that the attacker has access to the system network, by connecting to the network either directly or through a wrongly configured or penetrated firewall, or that he installs malicious software on a system node or otherwise infects the net-work with malicious software. Recommended practices help mitigate such attacks, see section Mitigating Factors. Could the vulnerability be exploited remotely? - Yes, an attacker who has network access to an affected system node could exploit this vulnerability. Recommended practices include that process control systems are physically protected, have no direct connections to the Internet, and are separated from other networks by means of a firewall system that has a minimal number of ports exposed. Can functional safety be affected by an exploit of this vulnerability? - Functional safety systems are not affected by these vulnerabilities. What does the update do? - The update removes the vulnerability by modifying the way that the IEC 61850 stack, used by the ABB Process Automation Products described above, manages 61850 incoming messages. When this security advisory was issued, had this vulnerability been publicly disclosed? - No, ABB received information about this vulnerability through responsible disclosure. When this security advisory was issued, had ABB received any reports that this vulnerability was being exploited? - No, ABB had not received any information indicating that this vulnerability had been exploited when this security advisory was originally issued.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of ABB PSIRT 7PAA020125 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-04-13</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-04-13</td>\n<td>1</td>\n<td>Initial version.</td>\n</tr>\n<tr>\n<td>2026-04-30</td>\n<td>2</td>\n<td>Initial CISA Republication of ABB PSIRT 7PAA020125 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 30 Apr 26 12:00:00 +0000",
        "last_updated": "Thu, 30 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/resources-tools/resources/adapting-zero-trust-principles-operational-technology",
        "title": "Adapting Zero Trust Principles to Operational Technology",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/resources-tools/resources/adapting-zero-trust-principles-operational-technology",
        "summary": "<p><a class=\"c-button\" href=\"https://www.cisa.gov/sites/default/files/2026-04/joint-guide-adapting-zero-trust-principles-to-operational-technology_508c.pdf\">Adapting Zero Trust Principles to Operational Technology</a></p>\n<p>CISA, in coordination with the Department of War, Department of Energy, Federal Bureau of Investigation, and Department of State, released <a href=\"https://www.cisa.gov/sites/default/files/2026-04/joint-guide-adapting-zero-trust-principles-to-operational-technology_508c.pdf\">Adapting Zero Trust Principles to Operational Technology</a>, joint guidance for organizations applying zero trust (ZT) principles to operational technology (OT). Zero trust is a modern, adaptive approach to cybersecurity that eliminates implicit trust and requires continuously validating access based on identity, context, and risk.</p>\n<p>With advancements in technology, OT systems that were traditionally isolated or manually operated are now increasingly interconnected, digitally monitored, and remotely controlled. This IT-OT convergence introduces new cybersecurity risks that make perimeter-based defenses and implicit trust models inadequate for safeguarding OT systems and the critical physical processes they control.</p>\n<p>This guidance supports OT owners and operators in addressing the unique challenges of transitioning to a ZT architecture, considering technology gaps from legacy infrastructure, operational constraints, and safety requirements. It focuses on establishing comprehensive asset visibility, proactively addressing supply chain risks, and implementing robust identity and access management while stressing the importance of layered security measures\u2014including network segmentation, secure communication protocols, and vulnerability management.</p>\n<p>To learn more about ZT principles, visit<a href=\"https://www.cisa.gov/topics/cybersecurity-best-practices/zero-trust\"> Zero Trust</a> &nbsp;<br>&nbsp;</p>\n<div class=\"c-text-cta\">\n<div class=\"l-constrain c-text-cta__inner\">\n<div class=\"c-text-cta__content\">\n<h2>CISA Product Survey</h2>\n<div class=\"c-text-cta__summary\">\n<p>We welcome your feedback.</p>\n</div>\n<p><a class=\"c-button c-button--on-dark\" href=\"https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_9n4TtB8uttUPaM6?product=https://www.cisa.gov/resources-tools/resources/adapting-zero-trust-principles-operational-technology\">CISA Product Survey</a></p>\n</div>\n</div>\n</div>\n<p>&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Wed, 29 Apr 26 12:00:00 +0000",
        "last_updated": "Wed, 29 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-118-01",
        "title": "NSA GRASSMARLIN",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-118-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-118-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to disclose sensitive information.</strong></p>\n<p>The following versions of NSA GRASSMARLIN are affected:</p>\n<ul>\n<li>GRASSMARLIN vers:all/*</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 5.5</td>\n<td>NSA</td>\n<td>NSA GRASSMARLIN</td>\n<td>Improper Restriction of XML External Entity Reference</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-6807</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability in GRASSMARLIN v3.2.1 allows crafted session data to trigger improper handling of XML input, which may result in unintended exposure of sensitive information. The flaw stems from insufficient hardening of the XML parsing process.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-6807\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>NSA GRASSMARLIN</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>NSA</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>NSA GRASSMARLIN: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>NSA has indicated that the GRASSMARLIN project has reached end-of-life status as of 2017 and is no longer supported. The project is archived, and no patches or further updates are planned or expected.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/611.html\">CWE-611 Improper Restriction of XML External Entity Reference</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Grady DeRosa reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-04-28</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-04-28</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 28 Apr 26 12:00:00 +0000",
        "last_updated": "Tue, 28 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/04/28/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Two Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/04/28/cisa-adds-two-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added&nbsp;two&nbsp;new&nbsp;vulnerabilities&nbsp;to its&nbsp;<a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2024-1708\" target=\"_blank\">CVE-2024-1708</a>&nbsp;ConnectWise&nbsp;ScreenConnect&nbsp;Path Traversal Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-32202\" target=\"_blank\">CVE-2026-32202</a>&nbsp;Microsoft Windows Protection Mechanism Failure Vulnerability</li>\n</ul>\n<p>These&nbsp;types&nbsp;of vulnerabilities&nbsp;are&nbsp;frequent attack vectors&nbsp;for malicious cyber actors and pose significant risks to the federal enterprise.&nbsp;</p>\n<p><a href=\"https://www.cisa.gov/binding-operational-directive-22-01\">Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities</a>&nbsp;established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the&nbsp;<a href=\"https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf\">BOD 22-01 Fact Sheet</a>&nbsp;for more information.&nbsp;</p>\n<p>Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing&nbsp;timely&nbsp;remediation of&nbsp;<a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>&nbsp;as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the&nbsp;<a href=\"https://www.cisa.gov/known-exploited-vulnerabilities\">specified criteria</a>.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Tue, 28 Apr 26 12:00:00 +0000",
        "last_updated": "Tue, 28 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/04/24/cisa-adds-four-known-exploited-vulnerabilities-catalog",
        "title": "CISA Adds Four Known Exploited Vulnerabilities to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/04/24/cisa-adds-four-known-exploited-vulnerabilities-catalog",
        "summary": "<p>CISA has added four new vulnerabilities to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2024-7399\" target=\"_blank\">CVE-2024-7399</a>&nbsp;Samsung&nbsp;MagicINFO&nbsp;9 Server Path Traversal Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2024-57726\" target=\"_blank\">CVE-2024-57726</a>&nbsp;SimpleHelp&nbsp;Missing Authorization Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2024-57728\" target=\"_blank\">CVE-2024-57728</a>&nbsp;SimpleHelp&nbsp;Path Traversal Vulnerability</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-29635\" target=\"_blank\">CVE-2025-29635</a>&nbsp;D-Link DIR-823X Command Injection Vulnerability&nbsp;</li>\n</ul>\n<p>These&nbsp;types&nbsp;of vulnerabilities&nbsp;are&nbsp;frequent attack vectors&nbsp;for malicious cyber actors and pose significant risks to the federal enterprise.&nbsp;</p>\n<p><a href=\"https://www.cisa.gov/binding-operational-directive-22-01\">Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities</a>&nbsp;established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the&nbsp;<a href=\"https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf\">BOD 22-01 Fact Sheet</a>&nbsp;for more information.&nbsp;</p>\n<p>Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing&nbsp;timely&nbsp;remediation of&nbsp;<a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">KEV Catalog vulnerabilities</a>&nbsp;as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the&nbsp;<a href=\"https://www.cisa.gov/known-exploited-vulnerabilities\">specified criteria</a>.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Fri, 24 Apr 26 12:00:00 +0000",
        "last_updated": "Fri, 24 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-04",
        "title": "SpiceJet Online Booking System",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-04",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-113-04.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information.</strong></p>\n<p>The following versions of SpiceJet Online Booking System are affected:</p>\n<ul>\n<li>Online Booking System vers:all/* (CVE-2026-6375, CVE-2026-6376)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.5</td>\n<td>SpiceJet</td>\n<td>SpiceJet Online Booking System</td>\n<td>Authorization Bypass Through User-Controlled Key, Missing Authentication for Critical Function</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>India</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-6375</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability in SpiceJet's booking API allows unauthenticated users to query passenger name records (PNRs) without any access controls. Because PNR identifiers follow a predictable pattern, an attacker could systematically enumerate valid records and obtain associated passenger names. This flaw stems from missing authorization checks on an endpoint intended for authenticated profile access.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-6375\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>SpiceJet Online Booking System</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>SpiceJet</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SpiceJet Online Booking System: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>SpiceJet did not respond to CISA's requests to coordinate. Users are encouraged to reach out to SpiceJet for more information: https://corporate.spicejet.com/contactus.aspx<br><a href=\"https://corporate.spicejet.com/contactus.aspx\">https://corporate.spicejet.com/contactus.aspx</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/639.html\">CWE-639 Authorization Bypass Through User-Controlled Key</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-6376</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A weakness in SpiceJet's public booking retrieval page permits full passenger booking details to be accessed using only a PNR and last name, with no authentication or verification mechanisms. This results in exposure of extensive personal, travel, and booking metadata to any unauthenticated user who can obtain or guess those basic inputs. The issue arises from improper access control on a sensitive data retrieval function.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-6376\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>SpiceJet Online Booking System</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>SpiceJet</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SpiceJet Online Booking System: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>SpiceJet did not respond to CISA's requests to coordinate. Users are encouraged to reach out to SpiceJet for more information: https://corporate.spicejet.com/contactus.aspx<br><a href=\"https://corporate.spicejet.com/contactus.aspx\">https://corporate.spicejet.com/contactus.aspx</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Owais Shaikh reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-04-23</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-04-23</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 23 Apr 26 12:00:00 +0000",
        "last_updated": "Thu, 23 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-02",
        "title": "Carlson Software VASCO-B GNSS Receiver",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-02",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-113-02.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could enable a remote attacker to alter critical system functions or disrupt device operation.</strong></p>\n<p>The following versions of Carlson Software VASCO-B GNSS Receiver are affected:</p>\n<ul>\n<li>VASCO-B GNSS Receiver &lt;1.4.0 (CVE-2026-3893)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.4</td>\n<td>Carlson Software</td>\n<td>Carlson Software VASCO-B GNSS Receiver</td>\n<td>Missing Authentication for Critical Function</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-3893</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to directly access and modify its configuration and operational functions without needing credentials.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-3893\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Carlson Software VASCO-B GNSS Receiver</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Carlson Software</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Carlson Software VASCO-B GNSS Receiver: &lt;1.4.0</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Carlson Software recommends users update to Version 1.4.0 or greater. For more information contact Carlson Software https://www.carlsonsw.com/support-and-training/<br><a href=\"https://www.carlsonsw.com/support-and-training/\">https://www.carlsonsw.com/support-and-training/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.4</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Souvik Kandar reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-04-23</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-04-23</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 23 Apr 26 12:00:00 +0000",
        "last_updated": "Thu, 23 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-05",
        "title": "Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-05",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-113-05.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to bypass authentication and have remote access to sensitive information on the device.</strong></p>\n<p>The following versions of Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera are affected:</p>\n<ul>\n<li>IP Camera XM530V200_X6-WEQ_8M firmware V5.00.R02.000807D8.10010.346624.S.ONVIF_21.06 (CVE-2025-65856)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>Hangzhou Xiongmai Technology Co., Ltd</td>\n<td>Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera</td>\n<td>Missing Authentication for Critical Function</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>China</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-65856</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF implementation fails to enforce authentication on 31 critical endpoints, enabling direct unauthorized video stream access.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-65856\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Hangzhou Xiongmai Technology Co., Ltd</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Hangzhou Xiongmai Technology Co., Ltd IP Camera XM530V200_X6-WEQ_8M firmware: V5.00.R02.000807D8.10010.346624.S.ONVIF_21.06</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Hangzhou Xiongmai Technology Co., Ltd has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of XM530 IP cameras are invited to contact Xiongmai Technology customer support for additional information (https://www.xiongmaitech.com/en/index.php/about/contact/42).<br><a href=\"https://www.xiongmaitech.com/en/index.php/about/contact/42\">https://www.xiongmaitech.com/en/index.php/about/contact/42</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>CISA discovered a public Proof of Concept (PoC) as authored by Luis Miranda Acebedo and reported it to MITRE</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-04-23</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-04-23</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 23 Apr 26 12:00:00 +0000",
        "last_updated": "Thu, 23 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-03",
        "title": "Milesight Cameras",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-03",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-113-03.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could crash the device being accessed or allow remote code execution.</strong></p>\n<p>The following versions of Milesight Cameras are affected:</p>\n<ul>\n<li>MS-Cxx63-PD &lt;=51.7.0.77-r12 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx64-xPD &lt;=51.7.0.77-r12 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx73-xPD &lt;=51.7.0.77-r12 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx75-xxPD &lt;=51.7.0.77-r12 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx83-xPD &lt;=51.7.0.77-r12 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx74-PA &lt;=3x.8.0.3-r11 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-C8477-HPG1 &lt;=63.8.0.4-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-C8477-PC &lt;=48.8.0.4-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-C5321-FPE &lt;=62.8.0.4-r5 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx72-xxxPE &lt;=61.8.0.5-r2 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx62-xxxPE &lt;=61.8.0.5-r2 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx52-xxxPE &lt;=61.8.0.5-r2 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx66-xxxPE &lt;=61.8.0.5-r2 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx66-xxxGPE &lt;=61.8.0.5-r2 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx61-xxxPE &lt;=61.8.0.5-r2 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx67-xxxPE &lt;=61.8.0.5-r2 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx71-xxxPE &lt;=61.8.0.5-r2 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx41-xxxPE &lt;=61.8.0.5-r2 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx76-PE &lt;=61.8.0.5-r2 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx65-PE &lt;=61.8.0.5-r2 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx66-xxxG1 &lt;=63.8.0.5-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx62-xxxG1 &lt;=63.8.0.5-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx72-xxxG1 &lt;=63.8.0.5-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-CQxx31-xxxG1 &lt;=CQ_63.8.0.5-r1 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-CQxx68-xxxG1 &lt;=CQ_63.8.0.5-r1 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-CQxx72-xxxG1 &lt;=CQ_63.8.0.5-r1 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Nxxxx-NxE &lt;=7x.9.0.19-r5 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Nxxxx-xxC &lt;=7x.9.0.19-r5 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Nxxxx-xxE &lt;=7x.9.0.19-r5 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Nxxxx-xxG &lt;=7x.9.0.19-r5 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Nxxxx-xxH &lt;=7x.9.0.19-r5 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Nxxxx-xxT &lt;=7x.9.0.19-r5 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>PMC8266-FPE &lt;=PO_61.8.0.4_LPR (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>PMC8266-FGPE &lt;=PO_61.8.0.4_LPR (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>PM3322-E &lt;=PI_61.8.0.3_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS4466-X4RIPG1 &lt;=T_63.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS5366-X12RIPG1 &lt;=T_63.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS8266-X4RIPG1 &lt;=T_63.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS4466-X4RIVPG1 &lt;=T_63.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS4466-RFIVPG1 &lt;=T_63.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS8266-X4RIVPG1 &lt;=T_63.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS8266-RFIVPG1 &lt;=T_63.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS4466-X4RIWG1 &lt;=T_63.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS8266-X4RIWG1 &lt;=T_63.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS5510-GVH &lt;=T_47.8.0.4_LPR-r7 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS5510-GH &lt;=T_47.8.0.4_LPR-r6 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS5511-GVH &lt;=T_47.8.0.4_LPR-r6 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS2966-X12TPE &lt;=T_61.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS4466-X4RPE &lt;=T_61.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS5366-X12PE &lt;=T_61.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS8266-X4PE &lt;=T_61.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS2966-X12TVPE &lt;=T_61.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS4466-X4RVPE &lt;=T_61.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS5366-X12VPE &lt;=T_61.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS8266-X4VPE &lt;=T_61.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS4441-X36RPE &lt;=T_61.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS4441-X36RE &lt;=T_61.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS4466-X4RWE &lt;=T_61.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS8266-X4WE &lt;=T_61.8.0.4_LPR-r3 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-C2964-RFLPC &lt;=T_45.8.0.3-r9 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-C2972-RFLPC &lt;=T_45.8.0.3-r9 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-C2966-RFLWPC &lt;=T_45.8.0.3-r9 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS2866-X4TPC &lt;=T_45.8.0.3-r9 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS2866-X4TVPC &lt;=T_45.8.0.3-r9 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS2866-X4TGPC &lt;=T_45.8.0.3-r9 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS2841-X36TPC &lt;=T_45.8.0.3-r9 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS2841-X36TPC/W &lt;=T_45.8.0.3-r9 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS2867-X5TPC &lt;=T_45.8.0.3-r9 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS2961-X12TPC &lt;=T_45.8.0.3-r9 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>TS8266-FPC/P &lt;=T_45.8.0.3-r9 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-C2966-X12RLPC &lt;=T_45.8.0.3-r9 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-C2966-X12RLVPC &lt;=T_45.8.0.3-r9 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-C5366-X12LPC &lt;=T_45.8.0.3-r9 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-C5366-X12LVPC &lt;=T_45.8.0.3-r9 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-C5361-X12LPC &lt;=T_45.8.0.3-r9 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx66-xxxxGOPC &lt;=45.8.0.2-AIoT-r4 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>SC211 &lt;=C_21.1.0.8-r4 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>SP111 &lt;=52.8.0.4-r5 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx66-RFIPKG1 &lt;=63.8.0.4-r1-NX (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx72-RFIPKG1 &lt;=63.8.0.4-r1-NX (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx66-FIPKG1 &lt;=63.8.0.4-r1-NX (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n<li>MS-Cxx72-FIPKG1 &lt;=63.8.0.4-r1-NX (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>Milesight</td>\n<td>Milesight Cameras</td>\n<td>Authorization Bypass Through User-Controlled Key, Use of Hard-coded Credentials, Use of Hard-coded Cryptographic Key, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Heap-based Buffer Overflow</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>China</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-28747</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-28747\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Milesight Cameras</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Milesight</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Milesight MS-Cxx63-PD: &lt;=51.7.0.77-r12, Milesight MS-Cxx64-xPD: &lt;=51.7.0.77-r12, Milesight MS-Cxx73-xPD: &lt;=51.7.0.77-r12, Milesight MS-Cxx75-xxPD: &lt;=51.7.0.77-r12, Milesight MS-Cxx83-xPD: &lt;=51.7.0.77-r12, Milesight MS-Cxx74-PA: &lt;=3x.8.0.3-r11, Milesight MS-C8477-HPG1: &lt;=63.8.0.4-r3, Milesight MS-C8477-PC: &lt;=48.8.0.4-r3, Milesight MS-C5321-FPE: &lt;=62.8.0.4-r5, Milesight MS-Cxx72-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx62-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx52-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx66-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx66-xxxGPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx61-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx67-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx71-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx41-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx76-PE: &lt;=61.8.0.5-r2, Milesight MS-Cxx65-PE: &lt;=61.8.0.5-r2, Milesight MS-Cxx66-xxxG1: &lt;=63.8.0.5-r3, Milesight MS-Cxx62-xxxG1: &lt;=63.8.0.5-r3, Milesight MS-Cxx72-xxxG1: &lt;=63.8.0.5-r3, Milesight MS-CQxx31-xxxG1: &lt;=CQ_63.8.0.5-r1, Milesight MS-CQxx68-xxxG1: &lt;=CQ_63.8.0.5-r1, Milesight MS-CQxx72-xxxG1: &lt;=CQ_63.8.0.5-r1, Milesight MS-Nxxxx-NxE: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxC: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxE: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxG: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxH: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxT: &lt;=7x.9.0.19-r5, Milesight PMC8266-FPE: &lt;=PO_61.8.0.4_LPR, Milesight PMC8266-FGPE: &lt;=PO_61.8.0.4_LPR, Milesight PM3322-E: &lt;=PI_61.8.0.3_LPR-r3, Milesight TS4466-X4RIPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS5366-X12RIPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS8266-X4RIPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS4466-X4RIVPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS4466-RFIVPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS8266-X4RIVPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS8266-RFIVPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS4466-X4RIWG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS8266-X4RIWG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS5510-GVH: &lt;=T_47.8.0.4_LPR-r7, Milesight TS5510-GH: &lt;=T_47.8.0.4_LPR-r6, Milesight TS5511-GVH: &lt;=T_47.8.0.4_LPR-r6, Milesight TS2966-X12TPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4466-X4RPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS5366-X12PE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS8266-X4PE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS2966-X12TVPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4466-X4RVPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS5366-X12VPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS8266-X4VPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4441-X36RPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4441-X36RE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4466-X4RWE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS8266-X4WE: &lt;=T_61.8.0.4_LPR-r3, Milesight MS-C2964-RFLPC: &lt;=T_45.8.0.3-r9, Milesight MS-C2972-RFLPC: &lt;=T_45.8.0.3-r9, Milesight MS-C2966-RFLWPC: &lt;=T_45.8.0.3-r9, Milesight TS2866-X4TPC: &lt;=T_45.8.0.3-r9, Milesight TS2866-X4TVPC: &lt;=T_45.8.0.3-r9, Milesight TS2866-X4TGPC: &lt;=T_45.8.0.3-r9, Milesight TS2841-X36TPC: &lt;=T_45.8.0.3-r9, Milesight TS2841-X36TPC/W: &lt;=T_45.8.0.3-r9, Milesight TS2867-X5TPC: &lt;=T_45.8.0.3-r9, Milesight TS2961-X12TPC: &lt;=T_45.8.0.3-r9, Milesight TS8266-FPC/P: &lt;=T_45.8.0.3-r9, Milesight MS-C2966-X12RLPC: &lt;=T_45.8.0.3-r9, Milesight MS-C2966-X12RLVPC: &lt;=T_45.8.0.3-r9, Milesight MS-C5366-X12LPC: &lt;=T_45.8.0.3-r9, Milesight MS-C5366-X12LVPC: &lt;=T_45.8.0.3-r9, Milesight MS-C5361-X12LPC: &lt;=T_45.8.0.3-r9, Milesight MS-Cxx66-xxxxGOPC: &lt;=45.8.0.2-AIoT-r4, Milesight SC211: &lt;=C_21.1.0.8-r4, Milesight SP111: &lt;=52.8.0.4-r5, Milesight MS-Cxx66-RFIPKG1: &lt;=63.8.0.4-r1-NX, Milesight MS-Cxx72-RFIPKG1: &lt;=63.8.0.4-r1-NX, Milesight MS-Cxx66-FIPKG1: &lt;=63.8.0.4-r1-NX, Milesight MS-Cxx72-FIPKG1: &lt;=63.8.0.4-r1-NX</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Milesight advises all users to update their device to the latest firmware versions of PE/PC/PA found at https://www.milesight.com/support/download/firmware.&nbsp;<br><a href=\"https://www.milesight.com/support/download/firmware\">https://www.milesight.com/support/download/firmware</a></p>\n<p><strong>Vendor fix</strong><br>MS-Cxx63-PD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx64-xPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx73-xPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx75-xxPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx83-xPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx74-PA: 3x.8.0.3-r11 and prior versions: Update to 3x.8.0.3-r13</p>\n<p><strong>Vendor fix</strong><br>MS-C8477-HPG1: 63.8.0.4-r3 and prior versions: Update to 63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>MS-C8477-PC: 48.8.0.4-r3 and prior versions: Update to 48.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>MS-C5321-FPE: 62.8.0.4-r5 and prior versions: Update to 62.8.0.4-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx72-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx62-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx52-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-xxxGPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx61-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx67-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx71-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx41-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx76-PE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx65-PE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-xxxG1: 63.8.0.5-r3 and prior versions: Update to 63.8.0.5-r4</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx62-xxxG1: 63.8.0.5-r3 and prior versions: Update to 63.8.0.5-r4</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx72-xxxG1: 63.8.0.5-r3 and prior versions: Update to 63.8.0.5-r4</p>\n<p><strong>Vendor fix</strong><br>MS-CQxx31-xxxG1: CQ_63.8.0.5-r1 and prior versions: Update to CQ_63.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-CQxx68-xxxG1: CQ_63.8.0.5-r1 and prior versions: Update to CQ_63.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-CQxx72-xxxG1: CQ_63.8.0.5-r1 and prior versions: Update to CQ_63.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-NxE: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxC: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxE: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxG: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxH: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxT: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>PMC8266-FPE: PO_61.8.0.4_LPR and prior versions: Update to PO_61.8.0.4-r1</p>\n<p><strong>Vendor fix</strong><br>PMC8266-FGPE: PO_61.8.0.4_LPR and prior versions: Update to PO_61.8.0.4-r1</p>\n<p><strong>Vendor fix</strong><br>PM3322-E: PI_61.8.0.3_LPR-r3 and prior versions: Update to PI_61.8.0.3-r5</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RIPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS5366-X12RIPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4RIPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RIVPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-RFIVPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4RIVPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-RFIVPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RIWG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4RIWG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS5510-GVH: T_47.8.0.4_LPR-r7 and prior versions: Update to T_47.8.0.4-r8</p>\n<p><strong>Vendor fix</strong><br>TS5510-GH: T_47.8.0.4_LPR-r6 and prior versions : Update to T_47.8.0.4-r8</p>\n<p><strong>Vendor fix</strong><br>TS5511-GVH: T_47.8.0.4_LPR-r6 and prior versions: Update to T_47.8.0.4-r8</p>\n<p><strong>Vendor fix</strong><br>TS2966-X12TPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS5366-X12PE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4PE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS2966-X12TVPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RVPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS5366-X12VPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4VPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4441-X36RPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4441-X36RE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RWE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4WE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>MS-C2964-RFLPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C2972-RFLPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C2966-RFLWPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2866-X4TPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2866-X4TVPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2866-X4TGPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2841-X36TPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2841-X36TPC/W: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2867-X5TPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2961-X12TPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS8266-FPC/P: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C2966-X12RLPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C2966-X12RLVPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C5366-X12LPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C5366-X12LVPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C5361-X12LPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-xxxxGOPC : 45.8.0.2-AIoT-r4 and prior versions: Update to 45.8.0.2-AIoT-r5</p>\n<p><strong>Vendor fix</strong><br>SC211: C_21.1.0.8-r4 and prior versions: Update to C_21.1.0.8-r5</p>\n<p><strong>Vendor fix</strong><br>SP111: 52.8.0.4-r5 and prior versions: Update to 52.8.0.4-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-RFIPKG1: 63.8.0.4-r1-NX and prior versions: Update to 63.8.0.5-r2-NX</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx72-RFIPKG1: 63.8.0.4-r1-NX and prior versions: Update to 63.8.0.5-r2-NX</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-FIPKG1: 63.8.0.4-r1-NX and prior versions: Update to 63.8.0.5-r2-NX</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx72-FIPKG1: 63.8.0.4-r1-NX and prior versions: Update to 63.8.0.5-r2-NX</p>\n<p><strong>Mitigation</strong><br>Milesight asks all users to report potential security vulnerabilities to security@milesight.com.<br><a href=\"mailto:security@milesight.com\">mailto:security@milesight.com</a></p>\n<p><strong>Mitigation</strong><br>Learn more: Milesight Vulnerability Reporting Policy<br><a href=\"https://www.milesight.com/legal/vulnerability-report\">https://www.milesight.com/legal/vulnerability-report</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/639.html\">CWE-639 Authorization Bypass Through User-Controlled Key</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-27785</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-27785\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Milesight Cameras</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Milesight</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Milesight MS-Cxx63-PD: &lt;=51.7.0.77-r12, Milesight MS-Cxx64-xPD: &lt;=51.7.0.77-r12, Milesight MS-Cxx73-xPD: &lt;=51.7.0.77-r12, Milesight MS-Cxx75-xxPD: &lt;=51.7.0.77-r12, Milesight MS-Cxx83-xPD: &lt;=51.7.0.77-r12, Milesight MS-Cxx74-PA: &lt;=3x.8.0.3-r11, Milesight MS-C8477-HPG1: &lt;=63.8.0.4-r3, Milesight MS-C8477-PC: &lt;=48.8.0.4-r3, Milesight MS-C5321-FPE: &lt;=62.8.0.4-r5, Milesight MS-Cxx72-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx62-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx52-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx66-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx66-xxxGPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx61-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx67-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx71-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx41-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx76-PE: &lt;=61.8.0.5-r2, Milesight MS-Cxx65-PE: &lt;=61.8.0.5-r2, Milesight MS-Cxx66-xxxG1: &lt;=63.8.0.5-r3, Milesight MS-Cxx62-xxxG1: &lt;=63.8.0.5-r3, Milesight MS-Cxx72-xxxG1: &lt;=63.8.0.5-r3, Milesight MS-CQxx31-xxxG1: &lt;=CQ_63.8.0.5-r1, Milesight MS-CQxx68-xxxG1: &lt;=CQ_63.8.0.5-r1, Milesight MS-CQxx72-xxxG1: &lt;=CQ_63.8.0.5-r1, Milesight MS-Nxxxx-NxE: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxC: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxE: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxG: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxH: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxT: &lt;=7x.9.0.19-r5, Milesight PMC8266-FPE: &lt;=PO_61.8.0.4_LPR, Milesight PMC8266-FGPE: &lt;=PO_61.8.0.4_LPR, Milesight PM3322-E: &lt;=PI_61.8.0.3_LPR-r3, Milesight TS4466-X4RIPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS5366-X12RIPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS8266-X4RIPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS4466-X4RIVPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS4466-RFIVPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS8266-X4RIVPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS8266-RFIVPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS4466-X4RIWG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS8266-X4RIWG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS5510-GVH: &lt;=T_47.8.0.4_LPR-r7, Milesight TS5510-GH: &lt;=T_47.8.0.4_LPR-r6, Milesight TS5511-GVH: &lt;=T_47.8.0.4_LPR-r6, Milesight TS2966-X12TPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4466-X4RPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS5366-X12PE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS8266-X4PE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS2966-X12TVPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4466-X4RVPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS5366-X12VPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS8266-X4VPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4441-X36RPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4441-X36RE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4466-X4RWE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS8266-X4WE: &lt;=T_61.8.0.4_LPR-r3, Milesight MS-C2964-RFLPC: &lt;=T_45.8.0.3-r9, Milesight MS-C2972-RFLPC: &lt;=T_45.8.0.3-r9, Milesight MS-C2966-RFLWPC: &lt;=T_45.8.0.3-r9, Milesight TS2866-X4TPC: &lt;=T_45.8.0.3-r9, Milesight TS2866-X4TVPC: &lt;=T_45.8.0.3-r9, Milesight TS2866-X4TGPC: &lt;=T_45.8.0.3-r9, Milesight TS2841-X36TPC: &lt;=T_45.8.0.3-r9, Milesight TS2841-X36TPC/W: &lt;=T_45.8.0.3-r9, Milesight TS2867-X5TPC: &lt;=T_45.8.0.3-r9, Milesight TS2961-X12TPC: &lt;=T_45.8.0.3-r9, Milesight TS8266-FPC/P: &lt;=T_45.8.0.3-r9, Milesight MS-C2966-X12RLPC: &lt;=T_45.8.0.3-r9, Milesight MS-C2966-X12RLVPC: &lt;=T_45.8.0.3-r9, Milesight MS-C5366-X12LPC: &lt;=T_45.8.0.3-r9, Milesight MS-C5366-X12LVPC: &lt;=T_45.8.0.3-r9, Milesight MS-C5361-X12LPC: &lt;=T_45.8.0.3-r9, Milesight MS-Cxx66-xxxxGOPC: &lt;=45.8.0.2-AIoT-r4, Milesight SC211: &lt;=C_21.1.0.8-r4, Milesight SP111: &lt;=52.8.0.4-r5, Milesight MS-Cxx66-RFIPKG1: &lt;=63.8.0.4-r1-NX, Milesight MS-Cxx72-RFIPKG1: &lt;=63.8.0.4-r1-NX, Milesight MS-Cxx66-FIPKG1: &lt;=63.8.0.4-r1-NX, Milesight MS-Cxx72-FIPKG1: &lt;=63.8.0.4-r1-NX</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Milesight advises all users to update their device to the latest firmware versions of PE/PC/PA found at https://www.milesight.com/support/download/firmware.&nbsp;<br><a href=\"https://www.milesight.com/support/download/firmware\">https://www.milesight.com/support/download/firmware</a></p>\n<p><strong>Vendor fix</strong><br>MS-Cxx63-PD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx64-xPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx73-xPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx75-xxPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx83-xPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx74-PA: 3x.8.0.3-r11 and prior versions: Update to 3x.8.0.3-r13</p>\n<p><strong>Vendor fix</strong><br>MS-C8477-HPG1: 63.8.0.4-r3 and prior versions: Update to 63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>MS-C8477-PC: 48.8.0.4-r3 and prior versions: Update to 48.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>MS-C5321-FPE: 62.8.0.4-r5 and prior versions: Update to 62.8.0.4-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx72-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx62-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx52-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-xxxGPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx61-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx67-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx71-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx41-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx76-PE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx65-PE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-xxxG1: 63.8.0.5-r3 and prior versions: Update to 63.8.0.5-r4</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx62-xxxG1: 63.8.0.5-r3 and prior versions: Update to 63.8.0.5-r4</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx72-xxxG1: 63.8.0.5-r3 and prior versions: Update to 63.8.0.5-r4</p>\n<p><strong>Vendor fix</strong><br>MS-CQxx31-xxxG1: CQ_63.8.0.5-r1 and prior versions: Update to CQ_63.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-CQxx68-xxxG1: CQ_63.8.0.5-r1 and prior versions: Update to CQ_63.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-CQxx72-xxxG1: CQ_63.8.0.5-r1 and prior versions: Update to CQ_63.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-NxE: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxC: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxE: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxG: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxH: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxT: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>PMC8266-FPE: PO_61.8.0.4_LPR and prior versions: Update to PO_61.8.0.4-r1</p>\n<p><strong>Vendor fix</strong><br>PMC8266-FGPE: PO_61.8.0.4_LPR and prior versions: Update to PO_61.8.0.4-r1</p>\n<p><strong>Vendor fix</strong><br>PM3322-E: PI_61.8.0.3_LPR-r3 and prior versions: Update to PI_61.8.0.3-r5</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RIPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS5366-X12RIPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4RIPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RIVPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-RFIVPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4RIVPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-RFIVPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RIWG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4RIWG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS5510-GVH: T_47.8.0.4_LPR-r7 and prior versions: Update to T_47.8.0.4-r8</p>\n<p><strong>Vendor fix</strong><br>TS5510-GH: T_47.8.0.4_LPR-r6 and prior versions : Update to T_47.8.0.4-r8</p>\n<p><strong>Vendor fix</strong><br>TS5511-GVH: T_47.8.0.4_LPR-r6 and prior versions: Update to T_47.8.0.4-r8</p>\n<p><strong>Vendor fix</strong><br>TS2966-X12TPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS5366-X12PE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4PE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS2966-X12TVPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RVPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS5366-X12VPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4VPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4441-X36RPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4441-X36RE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RWE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4WE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>MS-C2964-RFLPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C2972-RFLPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C2966-RFLWPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2866-X4TPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2866-X4TVPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2866-X4TGPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2841-X36TPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2841-X36TPC/W: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2867-X5TPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2961-X12TPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS8266-FPC/P: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C2966-X12RLPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C2966-X12RLVPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C5366-X12LPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C5366-X12LVPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C5361-X12LPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-xxxxGOPC : 45.8.0.2-AIoT-r4 and prior versions: Update to 45.8.0.2-AIoT-r5</p>\n<p><strong>Vendor fix</strong><br>SC211: C_21.1.0.8-r4 and prior versions: Update to C_21.1.0.8-r5</p>\n<p><strong>Vendor fix</strong><br>SP111: 52.8.0.4-r5 and prior versions: Update to 52.8.0.4-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-RFIPKG1: 63.8.0.4-r1-NX and prior versions: Update to 63.8.0.5-r2-NX</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx72-RFIPKG1: 63.8.0.4-r1-NX and prior versions: Update to 63.8.0.5-r2-NX</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-FIPKG1: 63.8.0.4-r1-NX and prior versions: Update to 63.8.0.5-r2-NX</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx72-FIPKG1: 63.8.0.4-r1-NX and prior versions: Update to 63.8.0.5-r2-NX</p>\n<p><strong>Mitigation</strong><br>Milesight asks all users to report potential security vulnerabilities to security@milesight.com.<br><a href=\"mailto:security@milesight.com\">mailto:security@milesight.com</a></p>\n<p><strong>Mitigation</strong><br>Learn more: Milesight Vulnerability Reporting Policy<br><a href=\"https://www.milesight.com/legal/vulnerability-report\">https://www.milesight.com/legal/vulnerability-report</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/798.html\">CWE-798 Use of Hard-coded Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-32644</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-32644\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Milesight Cameras</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Milesight</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Milesight MS-Cxx63-PD: &lt;=51.7.0.77-r12, Milesight MS-Cxx64-xPD: &lt;=51.7.0.77-r12, Milesight MS-Cxx73-xPD: &lt;=51.7.0.77-r12, Milesight MS-Cxx75-xxPD: &lt;=51.7.0.77-r12, Milesight MS-Cxx83-xPD: &lt;=51.7.0.77-r12, Milesight MS-Cxx74-PA: &lt;=3x.8.0.3-r11, Milesight MS-C8477-HPG1: &lt;=63.8.0.4-r3, Milesight MS-C8477-PC: &lt;=48.8.0.4-r3, Milesight MS-C5321-FPE: &lt;=62.8.0.4-r5, Milesight MS-Cxx72-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx62-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx52-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx66-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx66-xxxGPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx61-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx67-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx71-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx41-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx76-PE: &lt;=61.8.0.5-r2, Milesight MS-Cxx65-PE: &lt;=61.8.0.5-r2, Milesight MS-Cxx66-xxxG1: &lt;=63.8.0.5-r3, Milesight MS-Cxx62-xxxG1: &lt;=63.8.0.5-r3, Milesight MS-Cxx72-xxxG1: &lt;=63.8.0.5-r3, Milesight MS-CQxx31-xxxG1: &lt;=CQ_63.8.0.5-r1, Milesight MS-CQxx68-xxxG1: &lt;=CQ_63.8.0.5-r1, Milesight MS-CQxx72-xxxG1: &lt;=CQ_63.8.0.5-r1, Milesight MS-Nxxxx-NxE: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxC: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxE: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxG: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxH: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxT: &lt;=7x.9.0.19-r5, Milesight PMC8266-FPE: &lt;=PO_61.8.0.4_LPR, Milesight PMC8266-FGPE: &lt;=PO_61.8.0.4_LPR, Milesight PM3322-E: &lt;=PI_61.8.0.3_LPR-r3, Milesight TS4466-X4RIPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS5366-X12RIPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS8266-X4RIPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS4466-X4RIVPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS4466-RFIVPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS8266-X4RIVPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS8266-RFIVPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS4466-X4RIWG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS8266-X4RIWG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS5510-GVH: &lt;=T_47.8.0.4_LPR-r7, Milesight TS5510-GH: &lt;=T_47.8.0.4_LPR-r6, Milesight TS5511-GVH: &lt;=T_47.8.0.4_LPR-r6, Milesight TS2966-X12TPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4466-X4RPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS5366-X12PE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS8266-X4PE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS2966-X12TVPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4466-X4RVPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS5366-X12VPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS8266-X4VPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4441-X36RPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4441-X36RE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4466-X4RWE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS8266-X4WE: &lt;=T_61.8.0.4_LPR-r3, Milesight MS-C2964-RFLPC: &lt;=T_45.8.0.3-r9, Milesight MS-C2972-RFLPC: &lt;=T_45.8.0.3-r9, Milesight MS-C2966-RFLWPC: &lt;=T_45.8.0.3-r9, Milesight TS2866-X4TPC: &lt;=T_45.8.0.3-r9, Milesight TS2866-X4TVPC: &lt;=T_45.8.0.3-r9, Milesight TS2866-X4TGPC: &lt;=T_45.8.0.3-r9, Milesight TS2841-X36TPC: &lt;=T_45.8.0.3-r9, Milesight TS2841-X36TPC/W: &lt;=T_45.8.0.3-r9, Milesight TS2867-X5TPC: &lt;=T_45.8.0.3-r9, Milesight TS2961-X12TPC: &lt;=T_45.8.0.3-r9, Milesight TS8266-FPC/P: &lt;=T_45.8.0.3-r9, Milesight MS-C2966-X12RLPC: &lt;=T_45.8.0.3-r9, Milesight MS-C2966-X12RLVPC: &lt;=T_45.8.0.3-r9, Milesight MS-C5366-X12LPC: &lt;=T_45.8.0.3-r9, Milesight MS-C5366-X12LVPC: &lt;=T_45.8.0.3-r9, Milesight MS-C5361-X12LPC: &lt;=T_45.8.0.3-r9, Milesight MS-Cxx66-xxxxGOPC: &lt;=45.8.0.2-AIoT-r4, Milesight SC211: &lt;=C_21.1.0.8-r4, Milesight SP111: &lt;=52.8.0.4-r5, Milesight MS-Cxx66-RFIPKG1: &lt;=63.8.0.4-r1-NX, Milesight MS-Cxx72-RFIPKG1: &lt;=63.8.0.4-r1-NX, Milesight MS-Cxx66-FIPKG1: &lt;=63.8.0.4-r1-NX, Milesight MS-Cxx72-FIPKG1: &lt;=63.8.0.4-r1-NX</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Milesight advises all users to update their device to the latest firmware versions of PE/PC/PA found at https://www.milesight.com/support/download/firmware.&nbsp;<br><a href=\"https://www.milesight.com/support/download/firmware\">https://www.milesight.com/support/download/firmware</a></p>\n<p><strong>Vendor fix</strong><br>MS-Cxx63-PD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx64-xPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx73-xPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx75-xxPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx83-xPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx74-PA: 3x.8.0.3-r11 and prior versions: Update to 3x.8.0.3-r13</p>\n<p><strong>Vendor fix</strong><br>MS-C8477-HPG1: 63.8.0.4-r3 and prior versions: Update to 63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>MS-C8477-PC: 48.8.0.4-r3 and prior versions: Update to 48.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>MS-C5321-FPE: 62.8.0.4-r5 and prior versions: Update to 62.8.0.4-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx72-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx62-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx52-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-xxxGPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx61-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx67-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx71-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx41-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx76-PE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx65-PE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-xxxG1: 63.8.0.5-r3 and prior versions: Update to 63.8.0.5-r4</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx62-xxxG1: 63.8.0.5-r3 and prior versions: Update to 63.8.0.5-r4</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx72-xxxG1: 63.8.0.5-r3 and prior versions: Update to 63.8.0.5-r4</p>\n<p><strong>Vendor fix</strong><br>MS-CQxx31-xxxG1: CQ_63.8.0.5-r1 and prior versions: Update to CQ_63.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-CQxx68-xxxG1: CQ_63.8.0.5-r1 and prior versions: Update to CQ_63.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-CQxx72-xxxG1: CQ_63.8.0.5-r1 and prior versions: Update to CQ_63.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-NxE: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxC: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxE: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxG: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxH: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxT: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>PMC8266-FPE: PO_61.8.0.4_LPR and prior versions: Update to PO_61.8.0.4-r1</p>\n<p><strong>Vendor fix</strong><br>PMC8266-FGPE: PO_61.8.0.4_LPR and prior versions: Update to PO_61.8.0.4-r1</p>\n<p><strong>Vendor fix</strong><br>PM3322-E: PI_61.8.0.3_LPR-r3 and prior versions: Update to PI_61.8.0.3-r5</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RIPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS5366-X12RIPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4RIPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RIVPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-RFIVPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4RIVPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-RFIVPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RIWG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4RIWG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS5510-GVH: T_47.8.0.4_LPR-r7 and prior versions: Update to T_47.8.0.4-r8</p>\n<p><strong>Vendor fix</strong><br>TS5510-GH: T_47.8.0.4_LPR-r6 and prior versions : Update to T_47.8.0.4-r8</p>\n<p><strong>Vendor fix</strong><br>TS5511-GVH: T_47.8.0.4_LPR-r6 and prior versions: Update to T_47.8.0.4-r8</p>\n<p><strong>Vendor fix</strong><br>TS2966-X12TPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS5366-X12PE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4PE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS2966-X12TVPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RVPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS5366-X12VPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4VPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4441-X36RPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4441-X36RE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RWE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4WE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>MS-C2964-RFLPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C2972-RFLPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C2966-RFLWPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2866-X4TPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2866-X4TVPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2866-X4TGPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2841-X36TPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2841-X36TPC/W: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2867-X5TPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2961-X12TPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS8266-FPC/P: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C2966-X12RLPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C2966-X12RLVPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C5366-X12LPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C5366-X12LVPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C5361-X12LPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-xxxxGOPC : 45.8.0.2-AIoT-r4 and prior versions: Update to 45.8.0.2-AIoT-r5</p>\n<p><strong>Vendor fix</strong><br>SC211: C_21.1.0.8-r4 and prior versions: Update to C_21.1.0.8-r5</p>\n<p><strong>Vendor fix</strong><br>SP111: 52.8.0.4-r5 and prior versions: Update to 52.8.0.4-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-RFIPKG1: 63.8.0.4-r1-NX and prior versions: Update to 63.8.0.5-r2-NX</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx72-RFIPKG1: 63.8.0.4-r1-NX and prior versions: Update to 63.8.0.5-r2-NX</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-FIPKG1: 63.8.0.4-r1-NX and prior versions: Update to 63.8.0.5-r2-NX</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx72-FIPKG1: 63.8.0.4-r1-NX and prior versions: Update to 63.8.0.5-r2-NX</p>\n<p><strong>Mitigation</strong><br>Milesight asks all users to report potential security vulnerabilities to security@milesight.com.<br><a href=\"mailto:security@milesight.com\">mailto:security@milesight.com</a></p>\n<p><strong>Mitigation</strong><br>Learn more: Milesight Vulnerability Reporting Policy<br><a href=\"https://www.milesight.com/legal/vulnerability-report\">https://www.milesight.com/legal/vulnerability-report</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/321.html\">CWE-321 Use of Hard-coded Cryptographic Key</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-32649</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-32649\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Milesight Cameras</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Milesight</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Milesight MS-Cxx63-PD: &lt;=51.7.0.77-r12, Milesight MS-Cxx64-xPD: &lt;=51.7.0.77-r12, Milesight MS-Cxx73-xPD: &lt;=51.7.0.77-r12, Milesight MS-Cxx75-xxPD: &lt;=51.7.0.77-r12, Milesight MS-Cxx83-xPD: &lt;=51.7.0.77-r12, Milesight MS-Cxx74-PA: &lt;=3x.8.0.3-r11, Milesight MS-C8477-HPG1: &lt;=63.8.0.4-r3, Milesight MS-C8477-PC: &lt;=48.8.0.4-r3, Milesight MS-C5321-FPE: &lt;=62.8.0.4-r5, Milesight MS-Cxx72-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx62-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx52-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx66-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx66-xxxGPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx61-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx67-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx71-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx41-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx76-PE: &lt;=61.8.0.5-r2, Milesight MS-Cxx65-PE: &lt;=61.8.0.5-r2, Milesight MS-Cxx66-xxxG1: &lt;=63.8.0.5-r3, Milesight MS-Cxx62-xxxG1: &lt;=63.8.0.5-r3, Milesight MS-Cxx72-xxxG1: &lt;=63.8.0.5-r3, Milesight MS-CQxx31-xxxG1: &lt;=CQ_63.8.0.5-r1, Milesight MS-CQxx68-xxxG1: &lt;=CQ_63.8.0.5-r1, Milesight MS-CQxx72-xxxG1: &lt;=CQ_63.8.0.5-r1, Milesight MS-Nxxxx-NxE: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxC: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxE: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxG: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxH: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxT: &lt;=7x.9.0.19-r5, Milesight PMC8266-FPE: &lt;=PO_61.8.0.4_LPR, Milesight PMC8266-FGPE: &lt;=PO_61.8.0.4_LPR, Milesight PM3322-E: &lt;=PI_61.8.0.3_LPR-r3, Milesight TS4466-X4RIPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS5366-X12RIPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS8266-X4RIPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS4466-X4RIVPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS4466-RFIVPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS8266-X4RIVPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS8266-RFIVPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS4466-X4RIWG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS8266-X4RIWG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS5510-GVH: &lt;=T_47.8.0.4_LPR-r7, Milesight TS5510-GH: &lt;=T_47.8.0.4_LPR-r6, Milesight TS5511-GVH: &lt;=T_47.8.0.4_LPR-r6, Milesight TS2966-X12TPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4466-X4RPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS5366-X12PE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS8266-X4PE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS2966-X12TVPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4466-X4RVPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS5366-X12VPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS8266-X4VPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4441-X36RPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4441-X36RE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4466-X4RWE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS8266-X4WE: &lt;=T_61.8.0.4_LPR-r3, Milesight MS-C2964-RFLPC: &lt;=T_45.8.0.3-r9, Milesight MS-C2972-RFLPC: &lt;=T_45.8.0.3-r9, Milesight MS-C2966-RFLWPC: &lt;=T_45.8.0.3-r9, Milesight TS2866-X4TPC: &lt;=T_45.8.0.3-r9, Milesight TS2866-X4TVPC: &lt;=T_45.8.0.3-r9, Milesight TS2866-X4TGPC: &lt;=T_45.8.0.3-r9, Milesight TS2841-X36TPC: &lt;=T_45.8.0.3-r9, Milesight TS2841-X36TPC/W: &lt;=T_45.8.0.3-r9, Milesight TS2867-X5TPC: &lt;=T_45.8.0.3-r9, Milesight TS2961-X12TPC: &lt;=T_45.8.0.3-r9, Milesight TS8266-FPC/P: &lt;=T_45.8.0.3-r9, Milesight MS-C2966-X12RLPC: &lt;=T_45.8.0.3-r9, Milesight MS-C2966-X12RLVPC: &lt;=T_45.8.0.3-r9, Milesight MS-C5366-X12LPC: &lt;=T_45.8.0.3-r9, Milesight MS-C5366-X12LVPC: &lt;=T_45.8.0.3-r9, Milesight MS-C5361-X12LPC: &lt;=T_45.8.0.3-r9, Milesight MS-Cxx66-xxxxGOPC: &lt;=45.8.0.2-AIoT-r4, Milesight SC211: &lt;=C_21.1.0.8-r4, Milesight SP111: &lt;=52.8.0.4-r5, Milesight MS-Cxx66-RFIPKG1: &lt;=63.8.0.4-r1-NX, Milesight MS-Cxx72-RFIPKG1: &lt;=63.8.0.4-r1-NX, Milesight MS-Cxx66-FIPKG1: &lt;=63.8.0.4-r1-NX, Milesight MS-Cxx72-FIPKG1: &lt;=63.8.0.4-r1-NX</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Milesight advises all users to update their device to the latest firmware versions of PE/PC/PA found at https://www.milesight.com/support/download/firmware.&nbsp;<br><a href=\"https://www.milesight.com/support/download/firmware\">https://www.milesight.com/support/download/firmware</a></p>\n<p><strong>Vendor fix</strong><br>MS-Cxx63-PD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx64-xPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx73-xPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx75-xxPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx83-xPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx74-PA: 3x.8.0.3-r11 and prior versions: Update to 3x.8.0.3-r13</p>\n<p><strong>Vendor fix</strong><br>MS-C8477-HPG1: 63.8.0.4-r3 and prior versions: Update to 63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>MS-C8477-PC: 48.8.0.4-r3 and prior versions: Update to 48.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>MS-C5321-FPE: 62.8.0.4-r5 and prior versions: Update to 62.8.0.4-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx72-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx62-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx52-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-xxxGPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx61-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx67-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx71-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx41-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx76-PE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx65-PE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-xxxG1: 63.8.0.5-r3 and prior versions: Update to 63.8.0.5-r4</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx62-xxxG1: 63.8.0.5-r3 and prior versions: Update to 63.8.0.5-r4</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx72-xxxG1: 63.8.0.5-r3 and prior versions: Update to 63.8.0.5-r4</p>\n<p><strong>Vendor fix</strong><br>MS-CQxx31-xxxG1: CQ_63.8.0.5-r1 and prior versions: Update to CQ_63.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-CQxx68-xxxG1: CQ_63.8.0.5-r1 and prior versions: Update to CQ_63.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-CQxx72-xxxG1: CQ_63.8.0.5-r1 and prior versions: Update to CQ_63.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-NxE: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxC: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxE: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxG: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxH: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxT: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>PMC8266-FPE: PO_61.8.0.4_LPR and prior versions: Update to PO_61.8.0.4-r1</p>\n<p><strong>Vendor fix</strong><br>PMC8266-FGPE: PO_61.8.0.4_LPR and prior versions: Update to PO_61.8.0.4-r1</p>\n<p><strong>Vendor fix</strong><br>PM3322-E: PI_61.8.0.3_LPR-r3 and prior versions: Update to PI_61.8.0.3-r5</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RIPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS5366-X12RIPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4RIPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RIVPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-RFIVPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4RIVPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-RFIVPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RIWG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4RIWG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS5510-GVH: T_47.8.0.4_LPR-r7 and prior versions: Update to T_47.8.0.4-r8</p>\n<p><strong>Vendor fix</strong><br>TS5510-GH: T_47.8.0.4_LPR-r6 and prior versions : Update to T_47.8.0.4-r8</p>\n<p><strong>Vendor fix</strong><br>TS5511-GVH: T_47.8.0.4_LPR-r6 and prior versions: Update to T_47.8.0.4-r8</p>\n<p><strong>Vendor fix</strong><br>TS2966-X12TPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS5366-X12PE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4PE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS2966-X12TVPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RVPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS5366-X12VPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4VPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4441-X36RPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4441-X36RE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RWE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4WE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>MS-C2964-RFLPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C2972-RFLPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C2966-RFLWPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2866-X4TPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2866-X4TVPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2866-X4TGPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2841-X36TPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2841-X36TPC/W: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2867-X5TPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2961-X12TPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS8266-FPC/P: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C2966-X12RLPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C2966-X12RLVPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C5366-X12LPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C5366-X12LVPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C5361-X12LPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-xxxxGOPC : 45.8.0.2-AIoT-r4 and prior versions: Update to 45.8.0.2-AIoT-r5</p>\n<p><strong>Vendor fix</strong><br>SC211: C_21.1.0.8-r4 and prior versions: Update to C_21.1.0.8-r5</p>\n<p><strong>Vendor fix</strong><br>SP111: 52.8.0.4-r5 and prior versions: Update to 52.8.0.4-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-RFIPKG1: 63.8.0.4-r1-NX and prior versions: Update to 63.8.0.5-r2-NX</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx72-RFIPKG1: 63.8.0.4-r1-NX and prior versions: Update to 63.8.0.5-r2-NX</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-FIPKG1: 63.8.0.4-r1-NX and prior versions: Update to 63.8.0.5-r2-NX</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx72-FIPKG1: 63.8.0.4-r1-NX and prior versions: Update to 63.8.0.5-r2-NX</p>\n<p><strong>Mitigation</strong><br>Milesight asks all users to report potential security vulnerabilities to security@milesight.com.<br><a href=\"mailto:security@milesight.com\">mailto:security@milesight.com</a></p>\n<p><strong>Mitigation</strong><br>Learn more: Milesight Vulnerability Reporting Policy<br><a href=\"https://www.milesight.com/legal/vulnerability-report\">https://www.milesight.com/legal/vulnerability-report</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/78.html\">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-20766</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-20766\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Milesight Cameras</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Milesight</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Milesight MS-Cxx63-PD: &lt;=51.7.0.77-r12, Milesight MS-Cxx64-xPD: &lt;=51.7.0.77-r12, Milesight MS-Cxx73-xPD: &lt;=51.7.0.77-r12, Milesight MS-Cxx75-xxPD: &lt;=51.7.0.77-r12, Milesight MS-Cxx83-xPD: &lt;=51.7.0.77-r12, Milesight MS-Cxx74-PA: &lt;=3x.8.0.3-r11, Milesight MS-C8477-HPG1: &lt;=63.8.0.4-r3, Milesight MS-C8477-PC: &lt;=48.8.0.4-r3, Milesight MS-C5321-FPE: &lt;=62.8.0.4-r5, Milesight MS-Cxx72-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx62-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx52-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx66-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx66-xxxGPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx61-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx67-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx71-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx41-xxxPE: &lt;=61.8.0.5-r2, Milesight MS-Cxx76-PE: &lt;=61.8.0.5-r2, Milesight MS-Cxx65-PE: &lt;=61.8.0.5-r2, Milesight MS-Cxx66-xxxG1: &lt;=63.8.0.5-r3, Milesight MS-Cxx62-xxxG1: &lt;=63.8.0.5-r3, Milesight MS-Cxx72-xxxG1: &lt;=63.8.0.5-r3, Milesight MS-CQxx31-xxxG1: &lt;=CQ_63.8.0.5-r1, Milesight MS-CQxx68-xxxG1: &lt;=CQ_63.8.0.5-r1, Milesight MS-CQxx72-xxxG1: &lt;=CQ_63.8.0.5-r1, Milesight MS-Nxxxx-NxE: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxC: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxE: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxG: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxH: &lt;=7x.9.0.19-r5, Milesight MS-Nxxxx-xxT: &lt;=7x.9.0.19-r5, Milesight PMC8266-FPE: &lt;=PO_61.8.0.4_LPR, Milesight PMC8266-FGPE: &lt;=PO_61.8.0.4_LPR, Milesight PM3322-E: &lt;=PI_61.8.0.3_LPR-r3, Milesight TS4466-X4RIPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS5366-X12RIPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS8266-X4RIPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS4466-X4RIVPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS4466-RFIVPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS8266-X4RIVPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS8266-RFIVPG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS4466-X4RIWG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS8266-X4RIWG1: &lt;=T_63.8.0.4_LPR-r3, Milesight TS5510-GVH: &lt;=T_47.8.0.4_LPR-r7, Milesight TS5510-GH: &lt;=T_47.8.0.4_LPR-r6, Milesight TS5511-GVH: &lt;=T_47.8.0.4_LPR-r6, Milesight TS2966-X12TPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4466-X4RPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS5366-X12PE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS8266-X4PE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS2966-X12TVPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4466-X4RVPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS5366-X12VPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS8266-X4VPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4441-X36RPE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4441-X36RE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS4466-X4RWE: &lt;=T_61.8.0.4_LPR-r3, Milesight TS8266-X4WE: &lt;=T_61.8.0.4_LPR-r3, Milesight MS-C2964-RFLPC: &lt;=T_45.8.0.3-r9, Milesight MS-C2972-RFLPC: &lt;=T_45.8.0.3-r9, Milesight MS-C2966-RFLWPC: &lt;=T_45.8.0.3-r9, Milesight TS2866-X4TPC: &lt;=T_45.8.0.3-r9, Milesight TS2866-X4TVPC: &lt;=T_45.8.0.3-r9, Milesight TS2866-X4TGPC: &lt;=T_45.8.0.3-r9, Milesight TS2841-X36TPC: &lt;=T_45.8.0.3-r9, Milesight TS2841-X36TPC/W: &lt;=T_45.8.0.3-r9, Milesight TS2867-X5TPC: &lt;=T_45.8.0.3-r9, Milesight TS2961-X12TPC: &lt;=T_45.8.0.3-r9, Milesight TS8266-FPC/P: &lt;=T_45.8.0.3-r9, Milesight MS-C2966-X12RLPC: &lt;=T_45.8.0.3-r9, Milesight MS-C2966-X12RLVPC: &lt;=T_45.8.0.3-r9, Milesight MS-C5366-X12LPC: &lt;=T_45.8.0.3-r9, Milesight MS-C5366-X12LVPC: &lt;=T_45.8.0.3-r9, Milesight MS-C5361-X12LPC: &lt;=T_45.8.0.3-r9, Milesight MS-Cxx66-xxxxGOPC: &lt;=45.8.0.2-AIoT-r4, Milesight SC211: &lt;=C_21.1.0.8-r4, Milesight SP111: &lt;=52.8.0.4-r5, Milesight MS-Cxx66-RFIPKG1: &lt;=63.8.0.4-r1-NX, Milesight MS-Cxx72-RFIPKG1: &lt;=63.8.0.4-r1-NX, Milesight MS-Cxx66-FIPKG1: &lt;=63.8.0.4-r1-NX, Milesight MS-Cxx72-FIPKG1: &lt;=63.8.0.4-r1-NX</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Milesight advises all users to update their device to the latest firmware versions of PE/PC/PA found at https://www.milesight.com/support/download/firmware.&nbsp;<br><a href=\"https://www.milesight.com/support/download/firmware\">https://www.milesight.com/support/download/firmware</a></p>\n<p><strong>Vendor fix</strong><br>MS-Cxx63-PD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx64-xPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx73-xPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx75-xxPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx83-xPD: 51.7.0.77-r12 and prior versions: Update to 51.7.0.77-r13</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx74-PA: 3x.8.0.3-r11 and prior versions: Update to 3x.8.0.3-r13</p>\n<p><strong>Vendor fix</strong><br>MS-C8477-HPG1: 63.8.0.4-r3 and prior versions: Update to 63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>MS-C8477-PC: 48.8.0.4-r3 and prior versions: Update to 48.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>MS-C5321-FPE: 62.8.0.4-r5 and prior versions: Update to 62.8.0.4-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx72-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx62-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx52-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-xxxGPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx61-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx67-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx71-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx41-xxxPE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx76-PE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx65-PE: 61.8.0.5-r2 and prior versions: Update to 61.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-xxxG1: 63.8.0.5-r3 and prior versions: Update to 63.8.0.5-r4</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx62-xxxG1: 63.8.0.5-r3 and prior versions: Update to 63.8.0.5-r4</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx72-xxxG1: 63.8.0.5-r3 and prior versions: Update to 63.8.0.5-r4</p>\n<p><strong>Vendor fix</strong><br>MS-CQxx31-xxxG1: CQ_63.8.0.5-r1 and prior versions: Update to CQ_63.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-CQxx68-xxxG1: CQ_63.8.0.5-r1 and prior versions: Update to CQ_63.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-CQxx72-xxxG1: CQ_63.8.0.5-r1 and prior versions: Update to CQ_63.8.0.5-r2</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-NxE: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxC: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxE: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxG: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxH: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Nxxxx-xxT: 7x.9.0.19-r5 and prior versions: Update to 7x.9.0.19-r6</p>\n<p><strong>Vendor fix</strong><br>PMC8266-FPE: PO_61.8.0.4_LPR and prior versions: Update to PO_61.8.0.4-r1</p>\n<p><strong>Vendor fix</strong><br>PMC8266-FGPE: PO_61.8.0.4_LPR and prior versions: Update to PO_61.8.0.4-r1</p>\n<p><strong>Vendor fix</strong><br>PM3322-E: PI_61.8.0.3_LPR-r3 and prior versions: Update to PI_61.8.0.3-r5</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RIPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS5366-X12RIPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4RIPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RIVPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-RFIVPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4RIVPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-RFIVPG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RIWG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4RIWG1: T_63.8.0.4_LPR-r3 and prior versions: Update to T_63.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS5510-GVH: T_47.8.0.4_LPR-r7 and prior versions: Update to T_47.8.0.4-r8</p>\n<p><strong>Vendor fix</strong><br>TS5510-GH: T_47.8.0.4_LPR-r6 and prior versions: Update to T_47.8.0.4-r8</p>\n<p><strong>Vendor fix</strong><br>TS5511-GVH: T_47.8.0.4_LPR-r6 and prior versions: Update to T_47.8.0.4-r8</p>\n<p><strong>Vendor fix</strong><br>TS2966-X12TPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS5366-X12PE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4PE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS2966-X12TVPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RVPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS5366-X12VPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4VPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4441-X36RPE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4441-X36RE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS4466-X4RWE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>TS8266-X4WE: T_61.8.0.4_LPR-r3 and prior versions: Update to T_61.8.0.4-r4</p>\n<p><strong>Vendor fix</strong><br>MS-C2964-RFLPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C2972-RFLPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C2966-RFLWPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2866-X4TPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2866-X4TVPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2866-X4TGPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2841-X36TPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2841-X36TPC/W: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2867-X5TPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS2961-X12TPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>TS8266-FPC/P: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C2966-X12RLPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C2966-X12RLVPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C5366-X12LPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C5366-X12LVPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-C5361-X12LPC: T_45.8.0.3-r9 and prior versions: Update to T_45.8.0.3-r10</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-xxxxGOPC: 45.8.0.2-AIoT-r4 and prior versions: Update to 45.8.0.2-AIoT-r5</p>\n<p><strong>Vendor fix</strong><br>SC211: C_21.1.0.8-r4 and prior versions: Update to C_21.1.0.8-r5</p>\n<p><strong>Vendor fix</strong><br>SP111: 52.8.0.4-r5 and prior versions: Update to 52.8.0.4-r6</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-RFIPKG1: 63.8.0.4-r1-NX and prior versions: Update to 63.8.0.5-r2-NX</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx72-RFIPKG1: 63.8.0.4-r1-NX and prior versions: Update to 63.8.0.5-r2-NX</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx66-FIPKG1: 63.8.0.4-r1-NX and prior versions: Update to 63.8.0.5-r2-NX</p>\n<p><strong>Vendor fix</strong><br>MS-Cxx72-FIPKG1: 63.8.0.4-r1-NX and prior versions: Update to 63.8.0.5-r2-NX</p>\n<p><strong>Mitigation</strong><br>Milesight asks all users to report potential security vulnerabilities to security@milesight.com.<br><a href=\"mailto:security@milesight.com\">mailto:security@milesight.com</a></p>\n<p><strong>Mitigation</strong><br>Learn more: Milesight Vulnerability Reporting Policy<br><a href=\"https://www.milesight.com/legal/vulnerability-report\">https://www.milesight.com/legal/vulnerability-report</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/122.html\">CWE-122 Heap-based Buffer Overflow</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Souvik Kandar reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-04-23</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-04-23</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 23 Apr 26 12:00:00 +0000",
        "last_updated": "Thu, 23 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-113a",
        "title": "Defending Against China-Nexus Covert Networks of Compromised Devices",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-113a",
        "summary": "<div class=\"SCXW131754345 BCX8\">\n<div class=\"OutlineElement Ltr SCXW131754345 BCX8\">\n<h2><a class=\"c-button c-button--on-dark\" href=\"https://urldefense.us/v3/__https://www.ncsc.gov.uk/news/defending-against-china-nexus-covert-networks-of-compromised-devices__;!!BClRuOV5cvtbuNI!Cvg8stIR3jHWVZgHhCVvEwbwDXxXIRSprOQ9JtY2YKwxUIGVovuDAu7QrFsfw3sfAVd8-gxEMIpgldwlY-jTD7G0%24\">Defending against china-nexus covert networks of compromised devices</a></h2>\n<h2><a class=\"c-button c-button--on-dark\" href=\"https://urldefense.us/v3/__https://www.ncsc.gov.uk/news/executive-summary-defending-against-china-nexus-covert-networks-of-compromised-devices__;!!BClRuOV5cvtbuNI!Cvg8stIR3jHWVZgHhCVvEwbwDXxXIRSprOQ9JtY2YKwxUIGVovuDAu7QrFsfw3sfAVd8-gxEMIpgldwlYzP90Ign%24\">executive summary</a></h2>\n<h2><strong>Defending against China-nexus covert networks of compromised devices&nbsp;</strong></h2>\n<p>Explaining the widespread shift in tactics, techniques and procedures (TTPs) towards networks of compromised infrastructure, and how to defend against it&nbsp;</p>\n<h3><strong>Summary</strong></h3>\n<p>With support from the UK <a href=\"https://www.ncsc.gov.uk/information/cyber-league\" target=\"_blank\"><u>Cyber League</u></a>, this advisory has been jointly released by the National Cyber Security Centre (NCSC-UK) and international partners:&nbsp;</p>\n<ul>\n<li>Australian Signals Directorate\u2019s (ASD\u2019s) Australian Cyber Security Centre (ACSC)</li>\n<li>Communications Security Establishment Canada\u2019s (CSE\u2019s) Canadian Centre for Cyber Security (Cyber Centre)</li>\n<li>Germany Federal Office for the Protection of the Constitution -&nbsp;&nbsp; Bundesamt f\u00fcr Verfassungsschutz (BfV)</li>\n<li>Germany Federal Intelligence Service \u2013 Bundesnachrichtendienst (BND)</li>\n<li>Germany Federal Office for Information Security - Bundesamt f\u00fcr Sicherheit in der Informationstechnik (BSI)</li>\n<li>Japan National Cybersecurity Office (NCO) - \u56fd\u5bb6\u30b5\u30a4\u30d0\u30fc\u7d71\u62ec\u5ba4</li>\n<li>Netherlands General Intelligence and Security Service - Algemene Inlichtingen- en Veiligheidsdienst (AIVD)</li>\n<li>Netherlands Defence Intelligence and Security Service - Militaire Inlichtingen- en Veiligheidsdienst (MIVD)</li>\n<li>New Zealand National Cyber Security Centre (NCSC-NZ)</li>\n<li>Spain National Cryptologic Centre \u2013 Centro Criptol\u00f3gico Nacional (CCN)</li>\n<li>Sweden National Cyber Security Centre - Nationellt cybers\u00e4kerhetscenter (NCSC-SE)</li>\n<li>United States Cybersecurity and Infrastructure Security Agency (CISA)</li>\n<li>United States Department of Defense Cyber Crime Center (DC3)</li>\n<li>United States Federal Bureau of Investigation (FBI)</li>\n<li>United States National Security Agency (NSA)&nbsp;</li>\n</ul>\n<p>Its purpose is to provide network defenders with the tools needed to defend against China-nexus cyber actors and their tactic of using large scale networks of compromised devices (covert networks) to route their cyber activity.&nbsp;</p>\n<h3><strong>Introduction&nbsp;&nbsp;</strong></h3>\n<p>Over the past few years there has been a major shift in the tactics, techniques and procedures (TTPs) used by China-nexus cyber actors, moving away from the use of individually procured infrastructure, and towards the use of externally provisioned, large-scale networks of compromised devices.&nbsp;</p>\n<div class=\"OutlineElement Ltr SCXW149482171 BCX8\">\n<p>The NCSC believes that the majority of China-nexus threat actors are using these networks (hereafter \u201ccovert networks\u201d), that multiple covert networks have been created and are being constantly updated, and that a single covert network could be being used by multiple actors. These networks are mainly made up of compromised Small Office Home Office (SOHO) routers, as well as Internet of Things (IoT) and smart devices.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW149482171 BCX8\">\n<p>Anyone who is a target of China-nexus cyber actors may be impacted by the use of covert networks. They have been <a href=\"https://www.ncsc.gov.uk/news/ncsc-and-partners-issue-warning-about-state-sponsored-cyber-attackers-hiding-on-critical-infrastructure-networks\" target=\"_blank\"><u>used by Chinese state-sponsored actors Volt Typhoon</u></a> to pre-position offensive cyber capabilities on critical national infrastructure. The group <a href=\"https://www.ncsc.gov.uk/news/ncsc-and-partners-issue-advice-to-counter-china-linked-campaign-targeting-thousands-of-devices\" target=\"_blank\"><u>Flax Typhoon used a different covert network</u></a> of compromised infrastructure to conduct cyber espionage.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW149482171 BCX8\">\n<p>The use of covert networks of compromised devices - also known as botnets - to facilitate malicious cyber activity is not new, but China-nexus cyber actors are now using them strategically, and at scale.&nbsp;&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW149482171 BCX8\">\n<p>This advisory describes the typical makeup of a covert network and what they are being used for. It also includes protective advice for organizations being targeted by cyber activity using a covert network as an access vector.</p>\n<h3><strong>Covert Networks&nbsp;</strong></h3>\n<p>Covert networks are used to connect across the internet in a low-cost, low-risk, deniable way, disguising the origin and attribution of malicious activity. Actors have been observed using them for each phase of their Cyber Kill Chains, from performing scans as part of reconnaissance, to the delivery of malware, communicating with said malware, and exfiltrating stolen data from a victim. They can also be used for general deniable internet browsing, allowing threat actors to research exploitation techniques, new TTPs, and their victims without attribution. Some covert networks are also used by legitimate customers to browse the internet, making it challenging to attribute malicious activity.&nbsp;</p>\n<div class=\"OutlineElement Ltr SCXW53561783 BCX8\">\n<p>There is evidence that covert networks used by China-nexus actors are created and maintained by Chinese information security companies. A network known to network defenders as Raptor Train, which in 2024 infected more than 200,000 devices worldwide, was controlled and managed by the Chinese company, Integrity Technology Group. This company was also <a href=\"https://www.justice.gov/archives/opa/pr/court-authorized-operation-disrupts-worldwide-botnet-used-peoples-republic-china-state\" target=\"_blank\"><u>assessed by the FBI</u></a> to be responsible for the computer intrusion activities attributed to China-based hackers known as Flax Typhoon.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW53561783 BCX8\">\n<blockquote>\n<p><strong>Botnet operations represent a significant threat to the UK by exploiting vulnerabilities in everyday internet-connected devices with the potential to carry out large-scale cyber attacks \u2013 NCSC Director of Operations, Paul Chichester&nbsp;</strong></p>\n</blockquote>\n</div>\n<div class=\"OutlineElement Ltr SCXW53561783 BCX8\">\n<p>Covert networks mostly consist of compromised SOHO routers, but they also pull in any vulnerable device they can exploit at scale. Raptor Train was made up of thousands of SOHO routers and IoT devices, such as web cameras and video recorders, as well as firewalls and Network Attached Storage (NAS) devices.\u202fThe KV Botnet used by Volt Typhoon <a href=\"https://www.justice.gov/archives/opa/pr/us-government-disrupts-botnet-peoples-republic-china-used-conceal-hacking-critical\" target=\"_blank\"><u>was mainly made up of vulnerable Cisco and NetGear routers</u></a>. The edge devices were vulnerable because they were \u201cend of life\u201d \u2013 out of date and no longer receiving updates or security patches by their manufacturers.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW53561783 BCX8\">\n<p>The cyber security industry has been aware of examples of these networks for some time and has publicly reported on the widespread scale of the threat and its implications. Mandiant Intelligence produced a <a href=\"https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-orb-networks\" target=\"_blank\"><u>public blog in May 2024</u></a> talking about covert networks in which they highlighted a key issue for defenders \u2013 indicator of compromise (IOC) Extinction. If a particular threat group could now come from one of many covert networks, each with potentially hundreds of thousands of endpoints, and each used by multiple threat actors, old network defense paradigms of static malicious IP block lists will be less effective. This is compounded by the dynamic nature of these networks where new nodes will be added as old devices are patched or removed from use.&nbsp;</p>\n<h3><strong>Typical Network Topology</strong></h3>\n<p>The number of covert networks used by China-nexus cyber actors is large, with new networks regularly developed and deployed. The existing covert networks change too, either because of defensive or legal action, or simply as a result of software updates and new exploits being used to target different technologies for incorporation into the network.&nbsp;</p>\n<div class=\"OutlineElement Ltr SCXW21942648 BCX8\">\n<p>Because of this, a description of all known covert networks in detail, including how they are constructed and how they communicate, would immediately be out of date \u2013 and for most network defenders would not be practically useful.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW21942648 BCX8\">\n<p>However, most covert networks of compromised devices use the same basic set up. Understanding this generalized structure can aid researchers and defenders by helping them to understand which part of a network they may have found, and how to defend against it.&nbsp;</p>\n\n\n\n<figure class=\"c-figure c-figure--image\" role=\"group\">\n  \n  <div class=\"c-figure__media\">    <img loading=\"lazy\" src=\"https://www.cisa.gov/sites/default/files/styles/large/public/2026-04/A%20diagram%20illustrating%20the%20basic%20setup%20of%20a%20covert%20network..png?itok=3Bfm4nKj\" width=\"1024\" height=\"877\" alt=\"A diagram illustrating the basic setup of a covert network.\">\n\n\n\n</div>\n      <figcaption class=\"c-figure__caption\">A diagram illustrating the basic setup of a covert network.</figcaption>\n  </figure>\n<div class=\"OutlineElement Ltr SCXW75515976 BCX8\">\n<p>The diagram above illustrates the basic setup of a covert network, where typically an actor will connect to the network via an on-ramp or entry node. Their traffic will be forwarded through multiple compromised devices, used as traversal nodes, before exiting the network from an exit node, usually in the same geographic region as the target.&nbsp;</p>\n<h3><strong>Protective Advice&nbsp;</strong></h3>\n<p>Defending from attackers using covert networks is not straightforward, and defensive tactics will be different based on the levels of resource and the nature of the target organization. General advice for good cyber security practice should be followed, and some key messages can be found in the appendix of this advisory.&nbsp;&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW75515976 BCX8\">\n<p>The following advice is specifically tailored to steps which can be taken to combat the risk of attacks coming from large, dynamic networks of compromised devices.&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW75515976 BCX8\">\n<p>Further guidance for all organizations facing cyber security threats is available on the NCSC website.&nbsp;</p>\n<p><em>This guidance should be considered alongside all applicable laws and regulations of the UK and co-sealing countries relating to the security of networks and data. It will be each organization\u2019s responsibility to ensure compliance with any such laws and regulations. Organizations should note that following the recommended actions set out below will not remove all risks.</em></p>\n<h4><strong>All organizations</strong></h4>\n<div class=\"OutlineElement Ltr SCXW75515976 BCX8\">\n<p>The NCSC recommends the following steps for all affected organizations to either take themselves, or ask their managed service and/or security providers to investigate for them:&nbsp;</p>\n<ul>\n<li>Map and understand network edge devices, developing a clear understanding of organizational assets and what should be connecting to them.</li>\n<li>Baseline normal connections, especially to corporate virtual private networks (VPNs) or other similar services.\n<ul>\n<li>Would you expect connections from consumer broadband ranges?</li>\n</ul>\n</li>\n<li>Leverage available dynamic threat feeds which include covert network infrastructure.</li>\n<li>Implement multifactor authentication for remote connections.</li>\n</ul>\n<p>Smaller organizations should consider creating and actioning a <a href=\"https://cybertoolkit.service.ncsc.gov.uk/\" target=\"_blank\"><u>free NCSC Cyber Action Toolkit</u></a>.&nbsp;</p>\n<h4><strong>Larger or more at-risk organizations</strong></h4>\n<div class=\"SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p>Some more comprehensive measures may be appropriate if the risk to an organization is high enough, to be conducted either in-house or through a security provider:&nbsp;&nbsp;</p>\n<ul>\n<li>Apply IP address allow lists rather than deny lists for connections to corporate VPNs for remote workers.</li>\n<li>Use geographic allow lists or profile incoming connections based on operating system, time zones, and/or organization specific system configuration settings.</li>\n<li>Implement zero trust policies for connections.</li>\n<li>Enforce machine certificates for Secure Sockets Layer (SSL) connections.</li>\n<li>Reduce the internet-facing presence of the IT estate.</li>\n<li>Investigate machine learning techniques to profile normal network edge activity to detect and block anomalies.&nbsp;</li>\n</ul>\n<p><a href=\"https://www.ncsc.gov.uk/cyberessentials/overview\" target=\"_blank\"><u>The NCSC's Cyber Essentials</u></a> can help protect organizations of all sizes.&nbsp;</p>\n<h4><strong>Largest or most at-risk organizations</strong>&nbsp;</h4>\n<p>If Advanced Persistent Threat (APT) tracking is part of an organization\u2019s in-house capability, or if it is part of the service provided by a security vendor, consider tracking China-nexus covert networks as APTs in their own right.</p>\n<ul>\n<li>Active hunting \u2013 look for connections from IP addresses likely to be part of a covert network of compromised devices, for instance those hosting SOHO routers or IoT devices.</li>\n<li>Track and map covert networks reported by industry or government by looking at banners and certificates.</li>\n<li>Use threat reporting and threat feeds to create and implement dynamic blocklists and create alert rules to detect incoming threats.</li>\n<li>Consider using NetFlow feeds to look upstream and map covert networks to find new nodes.&nbsp;</li>\n</ul>\n<p>The <a href=\"https://www.ncsc.gov.uk/collection/cyber-assessment-framework\" target=\"_blank\"><u>NCSC Cyber Assessment Framework</u></a> provides guidance for organizations under the highest levels of threat, including those operating essential services, in sectors such as energy, healthcare, transport, digital infrastructure and government.\u202f&nbsp;</p>\n<h3><strong>MITRE ATT&amp;CK\u00ae&nbsp;</strong></h3>\n<p>This advisory has been compiled with respect to the MITRE ATT&amp;CK\u00ae framework, a globally accessible knowledge base of adversary tactics and techniques based on real-world observations.&nbsp;</p>\n<table dir=\"ltr\" class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">\n<div class=\"TableCellContent SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p class=\"text-align-justify\"><strong>Tactic&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p class=\"text-align-justify\"><strong>ID&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p class=\"text-align-justify\"><strong>Technique&nbsp;</strong></p>\n</div>\n</div>\n</th>\n<th role=\"columnheader\">\n<div class=\"TableCellContent SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p class=\"text-align-justify\"><strong>Procedure&nbsp;</strong></p>\n</div>\n</div>\n</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p><strong>Resource Development&nbsp;</strong></p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v18/techniques/T1584/005/\" target=\"_blank\"><u>T1584.005</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p>Compromise Infrastructure: Botnet&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p>Botnets are used as core components of covert networks&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p><strong>Resource Development&nbsp;</strong></p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v18/techniques/T1584/008/\" target=\"_blank\"><u>T1584.008</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p>Compromise Infrastructure:\u202fNetwork Devices&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p>Devices are compromised and added to botnets&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p><strong>Resource Development&nbsp;</strong></p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v18/techniques/T1583/003/\" target=\"_blank\"><u>T1583.003</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p>Acquire Infrastructure:\u202fVirtual Private Server&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p>Virtual private servers (VPS) are used in covert networks, typically as on-ramps&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n<tr>\n<td>\n<div class=\"TableCellContent SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p><strong>Command and Control&nbsp;</strong></p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p><a href=\"https://attack.mitre.org/versions/v18/techniques/T1090/003/\" target=\"_blank\"><u>T1090.003</u></a>&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p>Proxy:\u202fMulti-hop Proxy&nbsp;</p>\n</div>\n</div>\n</td>\n<td>\n<div class=\"TableCellContent SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p>Used by China-nexus cyber actors to route traffic&nbsp;</p>\n</div>\n</div>\n</td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n<div class=\"SCXW242856196 BCX8\">\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<h3>&nbsp;<strong>Appendix: Cyber Security Best Practices&nbsp;</strong></h3>\n<p>In addition to the protective advice outlined in this advisory, a number of cyber security best practices will also be useful in defending against the activity described in this advisory.&nbsp;</p>\n<ul>\n<li><strong>Protect your devices and networks by keeping them up to date</strong>: use the latest supported versions, apply security updates promptly, use antivirus and scan regularly to guard against known malware threats. See NCSC Guidance: <a href=\"https://www.ncsc.gov.uk/collection/device-security-guidance/policies-and-settings/antivirus-and-other-security-software\" target=\"_blank\"><u>https://www.ncsc.gov.uk/collection/device-security-guidance/policies-and-settings/antivirus-and-other-security-software</u></a></li>\n<li><strong>Prevent and detect lateral movement in your organization\u2019s networks</strong>. See NCSC Guidance: <a href=\"https://www.ncsc.gov.uk/guidance/preventing-lateral-movement\" target=\"_blank\"><u>https://www.ncsc.gov.uk/guidance/preventing-lateral-movement</u></a></li>\n<li><strong>Implement architectural controls for network segregation</strong>. See NCSC Guidance: <a href=\"https://www.ncsc.gov.uk/guidance/10-steps-network-security\" target=\"_blank\"><u>https://www.ncsc.gov.uk/guidance/10-steps-network-security</u></a></li>\n<li><strong>Set up a security monitoring</strong> <strong>capability</strong> so you are collecting the data that will be needed to analyze network intrusions. See NCSC Guidance: <a href=\"https://www.ncsc.gov.uk/guidance/introduction-logging-security-purposes\" target=\"_blank\"><u>https://www.ncsc.gov.uk/guidance/introduction-logging-security-purposes</u></a> and <a href=\"https://www.ncsc.gov.uk/information/logging-made-easy\" target=\"_blank\"><u>https://www.ncsc.gov.uk/information/logging-made-easy</u></a></li>\n<li><strong>Use modern systems and software.</strong> These have better security built-in. If you cannot move off out-of-date platforms and applications straight away, there are short term steps you can take to improve your position. See NCSC Guidance:&nbsp; <a href=\"https://www.ncsc.gov.uk/collection/mobile-device-guidance/managing-the-risks-from-obsolete-products\" target=\"_blank\"><u>https://www.ncsc.gov.uk/collection/mobile-device-guidance/managing-the-risks-from-obsolete-products</u></a></li>\n<li><strong>Restrict intruders' ability to move freely around your systems and networks</strong>. Pay particular attention to potentially vulnerable entry points such as third-party systems with onward access to your core network. During an incident, disable remote access from third-party systems until you are sure they are clean. See NCSC Guidance: <a href=\"https://www.ncsc.gov.uk/guidance/preventing-lateral-movement\" target=\"_blank\"><u>https://www.ncsc.gov.uk/guidance/preventing-lateral-movement</u></a> and <a href=\"https://www.ncsc.gov.uk/guidance/assessing-supply-chain-security\" target=\"_blank\"><u>https://www.ncsc.gov.uk/guidance/assessing-supply-chain-security</u></a><u>.</u></li>\n<li><strong>Deploy a host-based intrusion detection system</strong>. A variety of products are available, free and paid-for, to suit different needs and budgets.</li>\n<li><strong>Further information</strong>: Invest in preventing malware-based attacks across various scenarios.&nbsp; See NCSC Guidance: <a href=\"https://www.ncsc.gov.uk/guidance/mitigating-malware-and-ransomware-attacks\" target=\"_blank\"><u>https://www.ncsc.gov.uk/guidance/mitigating-malware-and-ransomware-attacks</u></a>&nbsp;</li>\n</ul>\n<h4><strong>Disclaimer&nbsp;</strong>&nbsp;</h4>\n<p>This report draws on information derived from NCSC and industry sources. Any NCSC findings and recommendations made have not been provided with the intention of avoiding all risks and following the recommendations will not remove all such risk. Ownership of information risks remains with the relevant system owner at all times. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by co-sealers. UK readers should refer to the NCSC website for information about <a href=\"https://www.ncsc.gov.uk/section/products-services/assured-services\" target=\"_blank\"><u>NCSC assured services</u></a>.&nbsp;</p>\n</div>\n</div>\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p>This information is exempt under the Freedom of Information Act 2000 (FOIA) and may be exempt under other UK information legislation.&nbsp;&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p>Refer any FOIA queries to <a href=\"mailto:ncscinfoleg@ncsc.gov.uk\" target=\"_blank\"><u>ncscinfoleg@ncsc.gov.uk</u></a>.&nbsp;&nbsp;</p>\n</div>\n<div class=\"OutlineElement Ltr SCXW242856196 BCX8\">\n<p>All material is UK Crown Copyright \u00a9&nbsp;</p>\n</div>\n</div>\n</div>\n</div>\n</div>\n</div>\n</div>\n</div>",
        "summary_is_html": true,
        "first_seen": "Thu, 23 Apr 26 12:00:00 +0000",
        "last_updated": "Thu, 23 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-01",
        "title": "Yadea T5 Electric Bicycle",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-113-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could result in an attacker being able to unlock and start the bicycle, leading to vehicle theft.</strong></p>\n<p>The following versions of Yadea T5 Electric Bicycle are affected:</p>\n<ul>\n<li>T5 Electric Bicycle vers:all/* (CVE-2025-70994)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.3</td>\n<td>Yadea</td>\n<td>Yadea T5 Electric Bicycle</td>\n<td>Weak Authentication</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>China</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-70994</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Yadea T5 Electric Bicycles have a weak authentication mechanism which is vulnerable to signal forgery after a local attacker intercepts any legitimate key fob transmissions.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-70994\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Yadea T5 Electric Bicycle</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Yadea</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Yadea T5 Electric Bicycle: vers:all/*</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Yadea did not respond to CISA's attempts at coordination. Users of Yadea T5 Electric Bicycles are encouraged to keep their systems up to date and lock their property securely with external mechanisms. Users can contact Yadea at https://yadea.com/contact-us.<br><a href=\"https://yadea.com/contact-us\">https://yadea.com/contact-us</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/1390.html\">CWE-1390 Weak Authentication</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H\">CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Ashen Chathuranga reported this vulnerability to MITRE and CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-04-23</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-04-23</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 23 Apr 26 12:00:00 +0000",
        "last_updated": "Thu, 23 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-06",
        "title": "Intrado 911 Emergency Gateway (EGW)",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-06",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-113-06.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to read, modify, or delete files.</strong></p>\n<p>The following versions of Intrado 911 Emergency Gateway (EGW) are affected:</p>\n<ul>\n<li>Emergency Gateway 7.x (CVE-2026-6074)</li>\n<li>Emergency Gateway 6.x (CVE-2026-6074)</li>\n<li>Emergency Gateway 5.x (CVE-2026-6074)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>Intrado</td>\n<td>Intrado 911 Emergency Gateway (EGW)</td>\n<td>Path Traversal: '.../...//'</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Emergency Services</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-6074</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A path traversal condition in Intrado 911 Emergency Gateway could allow an attacker with existing network access the ability to access the EGW management interface without authentication. Successful exploitation of this vulnerability could allow a user to read, modify, or delete files.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-6074\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Intrado 911 Emergency Gateway (EGW)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Intrado</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Intrado Emergency Gateway: 7.x, Intrado Emergency Gateway: 6.x, Intrado Emergency Gateway: 5.x</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Intrado developed and released a software update on March 2nd, 2026, that addresses this issue and has contacted customers to coordinate applying the patch.</p>\n<p><strong>Mitigation</strong><br>If you have questions, contact Intrado E911 Support: E911Support@intrado.com<br><a href=\"mailto:E911Support@intrado.com\">mailto:E911Support@intrado.com</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/35.html\">CWE-35 Path Traversal: '.../...//'</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>An anonymous source reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-04-23</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-04-23</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Thu, 23 Apr 26 12:00:00 +0000",
        "last_updated": "Thu, 23 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/analysis-reports/ar26-113a",
        "title": "FIRESTARTER Backdoor",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/analysis-reports/ar26-113a",
        "summary": "<h2><strong>Malware Analysis Report at a Glance</strong></h2>\n<table>\n<tbody>\n<tr>\n<th>Malware Name</th>\n<td>FIRESTARTER</td>\n</tr>\n<tr>\n<th>Original Publication</th>\n<td>April 23, 2026</td>\n</tr>\n<tr>\n<th>Executive Summary</th>\n<td>\n<p>The Cybersecurity and Infrastructure Security Agency (CISA) analyzed a sample of FIRESTARTER malware obtained from a forensic investigation. CISA and the United Kingdom National Cyber Security Centre (NCSC) assess advanced persistent threat (APT) actors are using FIRESTARTER malware for persistence, specifically targeting publicly accessible Cisco Firepower and Secure Firewall devices running Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software. CISA and the NCSC are releasing this Malware Analysis Report to share analysis of one FIRESTARTER malware sample operating as a backdoor and urge organizations to take key response actions.</p>\n<p><strong>Note:</strong> The release of this Malware Analysis Report aligns with CISA\u2019s update to <a href=\"https://www.cisa.gov/news-events/directives/v1-ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices\">V1: Emergency Directive (ED) 25-03: Identify and Mitigate Potential Compromise of Cisco Devices</a> and <a href=\"https://www.cisa.gov/news-events/directives/supplemental-direction-ed-25-03-core-dump-and-hunt-instructions\">Supplemental Direction ED 25-03: Core Dump and Hunt Instructions</a>. The malware outlined in this report is relevant for both Cisco Firepower and Secure Firewall devices; however, CISA has only observed a successful implant of the malware in the wild on a Cisco Firepower device running ASA software.</p>\n</td>\n</tr>\n<tr>\n<th>Key Actions for U.S. FCEB Agencies</th>\n<td>\n<ul>\n<li><strong>Collect and submit core dumps</strong> to CISA\u2019s Malware Next Generation platform.</li>\n<li><strong>Immediately report the submission</strong> via CISA\u2019s 24/7 Operations Center; CISA will reach out with next steps.</li>\n<li><strong>Take no additional action until CISA provides further guidance.</strong></li>\n</ul>\n</td>\n</tr>\n<tr>\n<th>Key Actions for All Other Organizations</th>\n<td>\n<ul>\n<li><strong>Use the YARA rules</strong> to detect FIRESTARTER malware against either a disk image or core dump of a device.</li>\n<li><strong>Report any findings to CISA or the NCSC.</strong></li>\n<li><strong>If compromise is confirmed</strong>, conduct incident response actions.</li>\n</ul>\n</td>\n</tr>\n<tr>\n<th>Intended Audience</th>\n<td>\n<p><strong>Organizations:</strong> Government and critical infrastructure organizations (<strong>Note:</strong> While this publication supplements CISA ED 25-03, the guidance is applicable to all organizations, including U.K. organizations.)</p>\n<p><strong>Sector</strong>: Government Services and Facilities Sector</p>\n<p><strong>Roles:</strong> <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/digital-forensics\" target=\"_blank\" title=\"Digital forensics analysts\">Digital forensics analysts</a>, <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/incident-response\" target=\"_blank\" title=\"incident responders\">incident responders</a>, <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/vulnerability-analysis\" target=\"_blank\" title=\"vulnerability analysts\">vulnerability analysts</a>, <a href=\"https://niccs.cisa.gov/tools/nice-framework/work-role/systems-administration\" target=\"_blank\">system administrators</a></p>\n</td>\n</tr>\n</tbody>\n</table>\n<h2><strong>Introduction</strong></h2>\n<p>The Cybersecurity and Infrastructure Security Agency (CISA) analyzed a sample of FIRESTARTER malware obtained from a forensic investigation. CISA and the United Kingdom National Cyber Security Centre (NCSC) assess that FIRESTARTER\u2014a backdoor that allows remote access and control\u2014is part of a widespread campaign that afforded an advanced persistent threat (APT) actor initial access to Cisco Adaptive Security Appliance (ASA) firmware by exploiting <a href=\"https://www.cve.org/CVERecord?id=CVE-2025-20333\" target=\"_blank\" title=\"CVE-2025-20333\">CVE-2025-20333</a> [<a href=\"https://cwe.mitre.org/data/definitions/862.html\" target=\"_blank\" title=\"CWE-862: Missing Authorization\">CWE-862: Missing Authorization</a>] and/or <a href=\"https://www.cve.org/CVERecord?id=CVE-2025-20362\" target=\"_blank\" title=\"CVE-2025-20362\">CVE-2025-20362</a> [<a href=\"https://cwe.mitre.org/data/definitions/120.html\" target=\"_blank\" title=\"CWE-120: Classic Buffer Overflow\">CWE-120: Classic Buffer Overflow</a>]. For more information on this campaign, see CISA\u2019s original version of <a href=\"https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices\" title=\"Emergency Directive (ED) 25-03: Identify and Mitigate Potential Compromise of Cisco Devices\">Emergency Directive (ED) 25-03: Identify and Mitigate Potential Compromise of Cisco Devices</a> (released Sept. 25, 2025).</p>\n<p>CISA and the NCSC assess that FIRESTARTER can persist as an active threat on Cisco devices running ASA or Firepower Threat Defense (FTD) software, maintaining post-patching persistence and enabling threat actors to re-access compromised devices without re-exploiting vulnerabilities. U.S. Federal Civilian Executive Branch (FCEB) agencies are required to implement the new required actions in CISA\u2019s updated Emergency Directive (<a href=\"https://www.cisa.gov/news-events/directives/v1-ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices\" title=\"V1: ED 25-03\">V1: ED 25-03</a>). CISA and the NCSC urge other U.S. and U.K. organizations to use the YARA rules to detect FIRESTARTER malware against either a disk image or core dump of a device and report any findings to CISA or the NCSC.</p>\n<p>Organizations can also refer to Cisco\u2019s <a href=\"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-CISAED25-03\" target=\"_blank\">Security Advisory</a> and <a href=\"https://blog.talosintelligence.com/uat-4356-firestarter/\" target=\"_blank\">Talos Blog</a>.</p>\n<p>Download the PDF version of this report:</p>\n\n\n\n\n\n<div class=\"c-file\">\n    <div class=\"c-file__download\">\n    <a href=\"https://www.cisa.gov/sites/default/files/2026-04/AR26-113A_MAR_FIRESTARTER_backdoor.pdf\" class=\"c-file__link\" target=\"_blank\">AR26-113A_MAR_FIRESTARTER_backdoor_</a>\n    <span class=\"c-file__size\">(PDF,       604.62 KB\n  )</span>\n  </div>\n</div>\n<p>For a downloadable copy of the YARA rules associated with this malware, see:</p>\n\n\n\n\n\n<div class=\"c-file\">\n    <div class=\"c-file__download\">\n    <a href=\"https://www.cisa.gov/sites/default/files/2026-04/stix-FIRESTARTER.json\" class=\"c-file__link\" target=\"_blank\">FIRESTARTER_STIX</a>\n    <span class=\"c-file__size\">(JSON,       24.27 KB\n  )</span>\n  </div>\n</div>\n<h3><strong>FIRESTARTER Collection</strong></h3>\n<p>CISA is authorized to monitor for, analyze, and notify U.S. FCEB agencies of anomalous or suspected malicious activity detected on federal networks. Through continuous monitoring, CISA identified suspicious connections on one U.S. FCEB agency\u2019s Cisco Firepower device running ASA software. CISA notified and validated the true positive finding with agency personnel and initiated a forensic engagement. During the engagement, CISA discovered one malware sample\u2014named FIRESTARTER\u2014on the Firepower device.</p>\n<p>In this incident, APT actors initially deployed <a href=\"https://www.ncsc.gov.uk/sites/default/files/documents/ncsc-mar-rayinitiator-line-viper.pdf\" target=\"_blank\" title=\"LINE VIPER\">LINE VIPER</a> as a post-exploitation implant and subsequently used FIRESTARTER as a persistence mechanism to maintain continued access to the compromised device. Although Cisco\u2019s patches addressed CVE-2025-20333 and CVE-2025-20362, devices compromised prior to patching may remain vulnerable because FIRESTARTER is not removed by firmware updates.</p>\n<h3><strong>Threat Actor Activity&nbsp;</strong></h3>\n<p><strong>Note:</strong> This advisory uses the <a href=\"https://attack.mitre.org/versions/v18/matrices/enterprise/\" target=\"_blank\">MITRE ATT&amp;CK<sup>\u00ae</sup> Matrix for Enterprise</a> framework, version 18. See <a href=\"#appendixa\"><strong>Appendix A: MITRE ATT&amp;CK</strong></a><strong> Techniques&nbsp;</strong>for tables mapping the cyber actors\u2019 activity to MITRE ATT&amp;CK tactics and techniques.</p>\n<p>CISA\u2019s analysis identified the following:</p>\n<ul>\n<li><strong>Initial Access:</strong> CISA assesses, but has not confirmed, that APT actors obtained initial access by exploiting CVE-2025-20333 and/or CVE-2025-20362 [<a href=\"https://attack.mitre.org/versions/v18/techniques/T1190/\" target=\"_blank\" title=\"T1190\">T1190</a>]. CISA has not confirmed the exact date of initial exploitation but assesses the compromise occurred in early September 2025, and before the agency implemented patches in accordance with ED 25-03.</li>\n<li><strong>Privilege Escalation and Defense Evasion:</strong> CISA identified that APT actors first deployed LINE VIPER to establish illegitimate virtual private network (VPN) sessions [<a href=\"https://attack.mitre.org/versions/v18/techniques/T1133/\" target=\"_blank\">T1133</a>] that bypassed all VPN authentication policies. This activity was associated with user accounts that existed but were no longer active within the agency [<a href=\"https://attack.mitre.org/versions/v18/techniques/T1078/\" target=\"_blank\">T1078</a>]. Although this behavior was observed in this incident, threat actors may use other (including fabricated) accounts.\n<ul>\n<li>LINE VIPER enabled APT actors access to all configuration elements of the victim Firepower device, including administrative credentials, certificates, and private keys [<a href=\"https://attack.mitre.org/versions/v18/techniques/T1082/\" target=\"_blank\" title=\"T1082\">T1082</a>].</li>\n</ul>\n</li>\n<li><strong>Persistence:</strong> APT actors deployed FIRESTARTER on the Firepower device before Sept. 25, 2025 (exact date is unknown). Because it was present before patching, FIRESTARTER persisted through remediation and established command and control (C2) channels on the victim Firepower device [<a href=\"https://attack.mitre.org/versions/v18/techniques/T1219/\" target=\"_blank\" title=\"T1219\">T1219</a>].\n<ul>\n<li>APT actors leveraged FIRESTARTER to regain access without re-exploiting the original vulnerabilities and deployed LINE VIPER in March 2026.</li>\n</ul>\n</li>\n</ul>\n<h2><strong>Malware Summary</strong></h2>\n<p>FIRESTARTER is a Linux Executable and Linkable File (ELF) designed to execute on Cisco Firepower and Secure Firewall devices, serving as a C2 channel for remote access and control. The malware achieves persistence by detecting termination signals and relaunching itself, and it can survive firmware updates and device reboots unless a hard power cycle occurs.</p>\n<p>FIRESTARTER attempts to install a hook\u2014a way to intercept and modify normal operations\u2014within LINA, the device\u2019s core engine for network processing and security functions. This hook enables the execution of arbitrary shell code provided by the APT actors, including the deployment of LINE VIPER.</p>\n<p><strong>Note:</strong> The file CISA obtained for analysis was named <code>lina_cs</code>; filenames may vary, as threat actors can easily modify the name of the malicious file.</p>\n<h2><strong>Malware Functionality</strong></h2>\n<h3><strong>Initialization</strong></h3>\n<p>Upon execution, FIRESTARTER accesses its own binary located at <code>/usr/bin/lina_cs</code> on the device [<a href=\"https://attack.mitre.org/versions/v18/techniques/T1036/005/\" target=\"_blank\">T1036.005</a>] and copies its contents into memory. It then registers a callback function that triggers when the program receives any of the following termination-related signals [<a href=\"https://attack.mitre.org/versions/v18/techniques/T1546/004/\" target=\"_blank\">T1546.004</a>]:</p>\n<ul>\n<li><code>SIGTERM</code></li>\n<li><code>SIGINT</code></li>\n<li><code>SIGQUIT</code></li>\n<li><code>SIGABRT</code></li>\n<li><code>SIGHUP</code></li>\n<li><code>SIGTSTP</code></li>\n</ul>\n<p>After copying itself into heap, and updating the signal handlers, the shell executor initiates the following sequential commands:</p>\n<ul>\n<li><code>rm /opt/cisco/config/platform/rmdb/CSP_MOUNT_LIST 2&gt;/dev/null</code></li>\n<li><code>cp /opt/cisco/config/platform/rmdb/CSP_MOUNT_LIST.tmp</code><br><code>/opt/cisco/config/platform/rmdb/CSP_MOUNT_LIST 2&gt;/dev/null</code></li>\n<li><code>chmod 755 /opt/cisco/config/platform/rmdb/CSP_MOUNT_LIST 2&gt;/dev/null</code></li>\n<li><code>chown\u2011reference=/opt/cisco/config/platform/rmdb/CSP_MOUNT_LIST.tmp</code><br><code>/opt/cisco/config/platform/rmdb/CSP_MOUNT_LIST 2&gt;/dev/null</code></li>\n<li><code>touch\u2011r&nbsp;/opt/cisco/config/platform/rmdb/CSP_MOUNT_LIST.tmp</code><br><code>/opt/cisco/config/platform/rmdb/CSP_MOUNT_LIST 2&gt;/dev/null</code></li>\n<li><code>rm /opt/cisco/config/platform/rmdb/CSP_MOUNT_LIST.tmp 2&gt;/dev/null</code></li>\n<li><code>rm /usr/bin/lina_cs 2&gt;/dev/null</code></li>\n</ul>\n<p>These commands delete the modified <code>CSP_MOUNT_LIST</code> file [<a href=\"https://attack.mitre.org/versions/v18/techniques/T1070/004/\" target=\"_blank\">T1070.004</a>] restoring the original <code>CSP_MOUNT_LIST</code>. Execute permissions are granted to any user, the owner and timestamp are set to match the original [<a href=\"https://attack.mitre.org/versions/v18/techniques/T1070/006/\" target=\"_blank\">T1070.006</a>], and the temporary file is then deleted. Finally, <code>/usr/bin/lina_cs</code> is deleted.</p>\n<h3>Persistence and Shutdown Task</h3>\n<p>When any of these signals are received or runlevel (6) is reached, the callback function is triggered and first checks whether the&nbsp;<code>/opt/cisco/platform/logs/var/log/</code> directory exists. If absent, it creates the directory with full read/write/execute permissions [<a href=\"https://attack.mitre.org/versions/v18/techniques/T1222/\" target=\"_blank\">T1222</a>]. The callback then opens <code>/opt/cisco/platform/logs/var/log/svc_samcore.log</code> and writes a copy of itself to this file, which is in a reboot-persistent directory.</p>\n<p>Next, the callback verifies whether&nbsp;<code>/opt/cisco/config/platform/rmdb/CSP_MOUNT_LIST</code> is present on the device. If the file is missing, FIRESTARTER creates it using a special function that can run shell commands [<a href=\"https://attack.mitre.org/versions/v18/techniques/T1059/\" target=\"_blank\">T1059</a>]. After creating the file, the malware runs a series of callback commands (in sequential order) to establish persistence and manage its files:</p>\n<ul>\n<li><code>cp&nbsp;/opt/cisco/config/platform/rmdb/CSP_MOUNT_LIST/opt/cisco/config/platform/rmdb/CSP_MOUNT_LIST.tmp 2&gt;/dev/null</code></li>\n<li><code>chown&nbsp;\u2011reference=/opt/cisco/config/platform/rmdb/CSP_MOUNT_LIST</code><br><code>/opt/cisco/config/platform/rmdb/CSP_MOUNT_LIST.tmp 2&gt;/dev/null</code></li>\n<li>\n<p><code>touch\u2011r&nbsp;/opt/cisco/config/platform/rmdb/CSP_MOUNT_LIST</code></p>\n<p><code>/opt/cisco/config/platform/rmdb/CSP_MOUNT_LIST.tmp 2&gt;/dev/null</code></p>\n</li>\n<li>Append the contents below to&nbsp;<code>/opt/cisco/config/platform/rmdb/CSP_MOUNT_LIST</code>\n<ul>\n<li><code>mv /opt/cisco/platform/logs/var/log/svc_samcore.log /usr/bin/lina_cs</code></li>\n<li><code>chmod 755 /usr/bin/lina_cs</code></li>\n<li><code>lina_cs &amp;</code></li>\n</ul>\n</li>\n</ul>\n<p>These commands first create a temporary copy of <code>CSP_MOUNT_LIST</code> with the same ownership information and timestamps. A script is appended to <code>CSP_MOUNT_LIST</code>. This script is the persistence mechanism, which moves FIRESTARTER from its staging location, <code>svc_samcore.log</code>, to <code>/usr/bin/lina_cs</code>. It then makes it executable and runs it in the background [<a href=\"https://attack.mitre.org/versions/v18/techniques/T1547/\" target=\"_blank\">T1547</a>]. This sequence ensures persistent execution of the file, even when termination signals are received. All commands redirect any standard error (<code>stderr</code>) messages to <code>/dev/null</code> and hides them from the console [<a href=\"https://attack.mitre.org/versions/v18/techniques/T1564/\" target=\"_blank\">T1564</a>].</p>\n<h3>Memory Scanning and Hook Installation</h3>\n<p>The process enumerates LINA\u2019s virtual memory map to locate the private read-write (rw-p) segment associated with <code>lina</code> [<a href=\"https://attack.mitre.org/versions/v18/techniques/T1057/\" target=\"_blank\">T1057</a>], which represents the main process\u2019s writable data region. Once identified, this memory segment is parsed using a custom algorithm to locate the XML Handler element table. The algorithm inspects each 0x260-byte region for element IDs. After identifying five element IDs in the correct offset sequence (each separated by 0x260 bytes), it calculates and stores the handler pointer address for the seventeenth element.</p>\n<h3>Shellcode Injection</h3>\n<p>FIRESTARTER scans LINA\u2019s memory to locate the executable (r-xp) segment of <code>libstdc++.so</code>, which corresponds to the C++ standard library\u2019s code section. The malware injects a block of shellcode 0x200 bytes before the end of the library\u2019s text segment, installing the detour for the XML element handler [<a href=\"https://attack.mitre.org/versions/v18/techniques/T1055/\" target=\"_blank\">T1055</a>]. The process then resumes its main loop and continues operating until it detects a reboot runlevel or the termination-related signals.</p>\n<h3>Victim Identification and Stage Loading</h3>\n<p>The FIRESTARTER malware closely mirrors the RayInitiator Cisco ASA bootkit stage 3 <code>deploy</code> path. The injected shellcode is triggered when LINA processes a WebVPN request containing the XML tag with the detoured handler. Within the <code>&lt;group-select&gt;</code> element, the malware searches for a hard-coded 8-byte ASCII string unique to the installation, verifying it against a predefined value embedded in the shellcode. Additionally, a victim-specific ID\u2014another hard-coded 8-byte sequence\u2014is compared against WebVPN request elements until a match is found. Upon successful verification of identification, the next stage of the malware is loaded by copying it into LINA\u2019s memory and invoking <code>mprotect</code> to enable execution of the newly injected code [<a href=\"https://attack.mitre.org/versions/v18/techniques/T1543/\" target=\"_blank\">T1543</a>].</p>\n<h2><strong>Detection</strong></h2>\n<h3>U.S. FCEB Agency Instructions</h3>\n<p>The primary detection method for FIRESTARTER is memory analysis. In accordance with <a href=\"https://www.cisa.gov/news-events/directives/v1-ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices\">V1: ED 25-03</a>, all U.S. FCEB agencies are required to collect device core dumps and submit them to CISA\u2019s Malware Next Generation (MNG) platform (see <a href=\"#incidentresponse\"><strong>Incident Response</strong></a> section), which analyzes core dumps for the presence and behavior of the <code>lina_cs</code> binary.</p>\n<p><strong>U.S. FCEB agencies should not take further action without first consulting CISA</strong>. To preserve evidence, avoid any hard power cycles and other changes (e.g., reboots, patching, configuration changes) before collection and coordination, as these can affect volatile artifacts.</p>\n<h3>Other U.S. and U.K. Recommendations</h3>\n<p>CISA and the NCSC recommend using the following CISA-created YARA rules to detect FIRESTARTER when applied to a disk image or a core dump from a device:</p>\n<ul>\n<li>To obtain a disk image, open a <a href=\"https://www.cisco.com/c/en/us/support/docs/instructions-guides/220312-open-a-tac-support-case-for-fast-dedica.html\" target=\"_blank\">Cisco Technical Assistance Center (TAC) case</a>.</li>\n<li>For instructions on obtaining a core dump, see CISA\u2019s <a href=\"https://www.cisa.gov/news-events/directives/supplemental-direction-ed-25-03-core-dump-and-hunt-instructions\">Supplemental Direction for ED 25-03</a>. <strong>Note:</strong> CISA recommends following this Supplemental Direction rather than other open source resources, as APT actors commonly employ anti-forensic techniques.</li>\n</ul>\n<h3>YARA Rules</h3>\n<p>See <a href=\"#table1\"><strong>Table 1</strong></a> for a list of FIRESTARTER YARA rules.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"table1\">Table 1. YARA Rules</a></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">FIRESTARTER Rule 1</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>rule CISA_261290_01 : FIRESTARTER backdoor captures_system_state_data cleans_traces_of_infection fingerprints_host persists_after_system_reboot<br>{<br>&nbsp; meta:<br>&nbsp; &nbsp; &nbsp; author = \"CISA Code &amp; Media Analysis\"<br>&nbsp; &nbsp; &nbsp; incident = \"261290\"<br>&nbsp; &nbsp; &nbsp; date = \"2026-4-3\"<br>&nbsp; &nbsp; &nbsp; last_modified = \"20260406_732\"<br>&nbsp; &nbsp; &nbsp; actor = \"n/a\"<br>&nbsp; &nbsp; &nbsp; family = \"n/a\"<br>&nbsp; &nbsp; &nbsp; capabilities = \"captures-system-state-data cleans-traces-of-infection fingerprints-host persists-after-system-reboot\"<br>&nbsp; &nbsp; &nbsp; malware_type = \"backdoor\"<br>&nbsp; &nbsp; &nbsp; tool_type = \"unknown\"<br>&nbsp; &nbsp; &nbsp; description = \"Detects CISCO Firepower FIRESTARTER injector samples\"<br>&nbsp; strings:<br>&nbsp; &nbsp; &nbsp; &nbsp;$s1 = { 57 48 C1 EF 0C 48 C1 E7 0C BA 07 00 00 00 48 C7 C6 00 20 00 00 }<br>&nbsp; &nbsp; &nbsp; &nbsp;$s2 = { 2f 6f 70 74 2f 63 69 73 63 6f 2f 70 6c 61 74 66 6f 72 6d 2f 6c 6f 67 73 2f 76 61 72 2f 6c 6f 67 2f }<br>&nbsp; &nbsp; &nbsp; &nbsp;$s3 = { 2f 6f 70 74 2f 63 69 73 63 6f 2f 63 6f 6e 66 69 67 2f 70 6c 61 74 66 6f 72 6d 2f 72 6d 64 62 2f }<br>&nbsp; &nbsp; &nbsp; &nbsp;$s4 = { 2f 76 61 72 2f 72 75 6e 2f 72 75 6e 6c 65 76 65 6c}<br>&nbsp; &nbsp; &nbsp; &nbsp;$s5 = { 2f 70 72 6f 63 2f 25 73 2f 63 6f 6d 6d }<br>&nbsp; &nbsp; &nbsp; &nbsp;$s6 = { 2f 70 72 6f 63 2f 25 64 2f 6d 61 70 73 }<br>&nbsp; &nbsp; &nbsp; &nbsp;$s7 = { 2f 61 73 61 2f 62 69 6e 2f 6c 69 6e 61 }<br>&nbsp; condition:<br>&nbsp; &nbsp; &nbsp; &nbsp;5 of them<br>}</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">FIRESTARTER Rule 2</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>rule CISA_261290_02 : FIRESTARTER_shellcode backdoor captures_system_state_data cleans_traces_of_infection fingerprints_host persists_after_system_reboot<br>{<br>&nbsp; &nbsp;meta:<br>&nbsp; &nbsp; &nbsp; author = \"CISA Code &amp; Media Analysis\"<br>&nbsp; &nbsp; &nbsp; incident = \"261290\"<br>&nbsp; &nbsp; &nbsp; date = \"2026-4-3\"<br>&nbsp; &nbsp; &nbsp; last_modified = \"20260406_732\"<br>&nbsp; &nbsp; &nbsp; actor = \"n/a\"<br>&nbsp; &nbsp; &nbsp; family = \"n/a\"<br>&nbsp; &nbsp; &nbsp; capabilities = \"captures-system-state-data cleans-traces-of-infection fingerprints-host persists-after-system-reboot\"<br>&nbsp; &nbsp; &nbsp; malware_type = \"backdoor\"<br>&nbsp; &nbsp; &nbsp; tool_type = \"unknownk\"<br>&nbsp; &nbsp; &nbsp; description = \"Detects CISCO Firepower FIRESTARTER_shellcode samples\"<br>&nbsp; &nbsp;strings:<br>&nbsp; &nbsp; &nbsp; &nbsp;$1 = { 57 4C 8B 47 18 4D 85 C0 0F 84 C7 01 00 00 49 8B 38 48 85 FF }<br>&nbsp; &nbsp; &nbsp; &nbsp;$2 = { 48 83 C6 08 4C 39 C6 0F 87 7A 01 00 00 4C 8B 0E }<br>&nbsp; &nbsp; &nbsp; &nbsp;$3 = { 48 89 D7 4C 89 CE B9 D0 01 00 F3 A4 48 89 D7 57 48 C1 EF 0C 48 C1 E7 0C }<br>&nbsp; &nbsp; &nbsp; &nbsp;$4 = { 0F 05 58 5F FF E0 90 90 }<br>&nbsp; &nbsp;condition:<br>&nbsp; &nbsp; &nbsp; &nbsp;3 of them<br>}</td>\n</tr>\n</tbody>\n</table>\n<h3>Sigma Rules</h3>\n<p>Given the nature of this malware, Sigma rules do not offer effective detection because it does not generate observable log events or behavioral anomalies in standard monitoring platforms.</p>\n<h2><a class=\"ck-anchor\" id=\"incidentresponse\"><strong>Incident Response</strong></a></h2>\n<h3>U.S. FCEB Agencies</h3>\n<p>CISA requires U.S. FCEB agencies to:</p>\n<ol>\n<li>Refer to the <a href=\"https://www.cisa.gov/news-events/directives/supplemental-direction-ed-25-03-core-dump-and-hunt-instructions\">Supplemental Direction for ED 25-03</a> for guidance on running the \u201cshow checkheaps\u201d and \u201cshow tech-support detail\u201d commands. Ensure to save the full output off the device&nbsp;(preferably to an isolated system).</li>\n<li>Generate a core dump from the affected Cisco device(s) and submit it through CISA\u2019s <a href=\"https://www.cisa.gov/resources-tools/services/malware-next-generation-analysis\">Malware Next Generation platform</a>.</li>\n<li>Report the submission immediately via CISA\u2019s 24/7 Operations Center (<a href=\"https://ociocisa.sharepoint.com/teams/JCDC-ProductionOffice/Shared%20Documents/Product%20Development/2.%20IN%20PROGRESS%20Products/%5b02%5d%20-%20Desktop%20Publishing%20Edits/Inbox/FIRESTARTER%20MAR/contact@cisa.dhs.gov\" target=\"_blank\" title=\"contact@cisa.dhs.gov\">contact@cisa.dhs.gov</a>, 1-844-Say-CISA [1-844-729-2472], or CISA\u2019s <a href=\"https://myservices.cisa.gov/irf\" target=\"_blank\" title=\"Incident Reporting System\">Incident Reporting System</a>). Identify the activity is related to FIRESTARTER.</li>\n</ol>\n<p>After incident intake, CISA will provide guidance on next steps. If compromise is confirmed, this may include instructions to physically unplug the device from power to remove FIRESTARTER\u2019s persistence. <strong>Organizations should not unplug the device unless directed to do so by CISA.</strong></p>\n<h3>Other U.S. Organizations</h3>\n<p>CISA recommends<strong>&nbsp;</strong>organizations take the following actions:</p>\n<ol>\n<li>Although applicable to U.S. FCEB agencies, refer to the <a href=\"https://www.cisa.gov/news-events/directives/supplemental-direction-ed-25-03-core-dump-and-hunt-instructions\">Supplemental Direction for ED 25-03</a> for guidance on running the \u201cshow checkheaps\u201d and \u201cshow tech-support detail\u201d commands. Ensure to save the full output off the device&nbsp;(preferably to an isolated system).</li>\n<li>Generate a core dump from the affected Cisco device(s) and deploy the provided YARA rules.\n<ol>\n<li>U.S. organizations can submit core dumps through CISA\u2019s <a href=\"https://www.cisa.gov/resources-tools/services/malware-next-generation-analysis\">Malware Next Generation platform</a>.</li>\n</ol>\n</li>\n</ol>\n<p><strong>If the core dump indicates the presence of FIRESTARTER malware, proceed with steps 3 and 4 below;</strong> additionally, activate internal incident response plans to assess potential lateral movement and impact:</p>\n<ol start=\"3\">\n<li>Unplug the device from all power sources\u2014CISA assesses this is the only method to remove FIRESTARTER\u2019s persistence from a device\u2014then conduct the following steps:\n<ol>\n<li>Locate the physical device.\n<ol>\n<li>Unplug the physical device from its power source while the device is still powered on.<br><strong>Note:</strong> It is not sufficient to power the device off or reboot it. The device must be entirely removed from all power sources, including duplicate power sources created for redundancy.</li>\n</ol>\n</li>\n<li>Leave the device fully disconnected from any power source for one minute.</li>\n<li>Reconnect the device to its power source and allow it to reboot.</li>\n</ol>\n</li>\n<li>Promptly report any detection of FIRESTARTER malware to CISA.\n<ol>\n<li><strong>U.S. organizations</strong> can report to CISA\u2019s 24/7 Operations Center (<a href=\"https://ociocisa.sharepoint.com/teams/JCDC-ProductionOffice/Shared%20Documents/Product%20Development/2.%20IN%20PROGRESS%20Products/%5b02%5d%20-%20Desktop%20Publishing%20Edits/Inbox/FIRESTARTER%20MAR/contact@cisa.dhs.gov\" target=\"_blank\" title=\"contact@cisa.dhs.gov\">contact@cisa.dhs.gov</a>, 1-844-Say-CISA [1-844-729-2472], or <a href=\"https://myservices.cisa.gov/irf\" target=\"_blank\">CISA\u2019s Incident Reporting System</a>). Requests for assistance can also be submitted to CISA via this reporting channel.</li>\n</ol>\n</li>\n</ol>\n<h3>U.K. Organizations</h3>\n<p>The NCSC recommends U.K. organizations take the following actions:</p>\n<ol>\n<li>Refer to the <a href=\"https://www.cisa.gov/news-events/directives/supplemental-direction-ed-25-03-core-dump-and-hunt-instructions\">Supplemental Direction for ED 25-03</a> for guidance on running the \u201cshow checkheaps\u201d and \u201cshow tech-support detail\u201d commands. Ensure to save the full output off the device (preferably to an isolated system).</li>\n<li>Generate a core dump from the affected Cisco device(s) and deploy the provided YARA rules.</li>\n<li>If FIRESTARTER is detected, report an incident to the NCSC via <a href=\"https://report.ncsc.gov.uk/\" target=\"_blank\">https://report.ncsc.gov.uk</a>.\n<ol>\n<li>After reporting an incident, the NCSC will provide guidance on next steps. If compromise is confirmed, this may include instructions to physically unplug the device from power to remove FIRESTARTER\u2019s persistence. <strong>Organizations should not unplug the device unless directed to do so by the NCSC.</strong></li>\n</ol>\n</li>\n</ol>\n<h2><strong>Mitigations</strong></h2>\n<p>CISA and the NCSC recommend all organizations implement the mitigations below to improve cybersecurity posture on the basis of the threat actors\u2019 activity. These mitigations align with the Cross-Sector Cybersecurity Performance Goals 2.0 (CPG 2.0) developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections recommended for all organizations. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats, tactics, techniques, and procedures. Visit CISA\u2019s <a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0\">CPG 2.0</a> webpage for more information on the CPGs, including additional recommended baseline protections.</p>\n<ul>\n<li>Maintain all systems and software with the latest security patches, prioritizing expedited remediation of vulnerabilities listed in CISA\u2019s <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities (KEV) Catalog [CPG 2.B]</a>. At the time of ED 25-03\u2019s release (Sept. 25, 2025), available patches did not specifically remediate FIRESTARTER; although patching mitigated initial access, it did not eliminate this persistence mechanism. For additional information on software updates that prevent FIRESTARTER\u2019s persistence and for remediation guidance, refer to Cisco\u2019s <a href=\"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-CISAED25-03\" target=\"_blank\">Security Advisory</a>.</li>\n<li>Inventory all network edge devices [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ManageOrganizationalAssets2A\">CPG 2.A</a>], with a specific focus on Cisco devices. Monitor these devices for any suspicious network connections that correlate with the activity described in this report.</li>\n<li>Monitor and audit activity for all accounts with elevated privileges, including network administrators and service accounts, to detect unauthorized use or anomalous behavior. For example, track and review commands executed by these accounts, and promptly investigate any suspicious activity identified.</li>\n<li>Apply the principle of least privilege and restrict service accounts to needed permissions only [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementthePrinciplesofLeastPrivilege3H\">CPG 3.H</a>].</li>\n<li>Regularly rotate passwords for privileged accounts (such as network administrators) and service accounts. Routine password changes invalidate credentials that threat actors may have compromised, forcing them to reestablish access and increasing the likelihood of detection or disruption.</li>\n<li>While not specific to FIRESTARTER, modernize administrative access controls by implementing TACACS+ over TLS 1.3. This approach encrypts device administration Authentication, Authorization, and Accounting traffic, safeguards administrator and service account credentials, and reduces the risk of interception [<a href=\"https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#UtilizeStrongEncryption3K\" title=\"CPG 3.K\">CPG 3.K</a>]. See Cisco\u2019s blog, <a href=\"https://blogs.cisco.com/security/modernizing-tacacs-why-full-session-encryption-matters\" target=\"_blank\">Modernizing TACACS+: Why Full-Session Encryption Matters More Than Ever</a>.</li>\n</ul>\n<h2><strong>Disclaimer</strong></h2>\n<p>CISA and the NCSC do not endorse any commercial entity, product, company, or service, including any entities, products, companies, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favor by CISA or the NCSC.</p>\n<h2><strong>Acknowledgements</strong></h2>\n<p>Cisco contributed to this Malware Analysis Report.</p>\n<h2><strong>Version History</strong></h2>\n<p><strong>April 23, 2026:</strong> Initial version.</p>\n<h2><a class=\"ck-anchor\" id=\"appendixa\"><strong>Appendix A: MITRE ATT&amp;CK Techniques</strong></a></h2>\n<p>See <a href=\"#table2\"><strong>Table 2</strong></a> through <a href=\"#table7\"><strong>Table 7</strong></a> all referenced threat actor tactics and techniques in this advisory. For assistance with mapping malicious cyber activity to the MITRE ATT&amp;CK framework, see CISA and MITRE ATT&amp;CK\u2019s <a href=\"https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping\">Best Practices for MITRE ATT&amp;CK Mapping</a> and CISA\u2019s <a href=\"https://github.com/cisagov/Decider/\" target=\"_blank\" title=\"Decider Tool\">Decider Tool</a>.</p>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"table2\">Table 2. Initial Access</a></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Exploit Public-Facing Application</td>\n<td><a href=\"https://attack.mitre.org/versions/v18/techniques/T1190/\" target=\"_blank\">T1190</a></td>\n<td>The APT actors gained access to the victim\u2019s Cisco Firepower device, likely by exploiting CVE-2025-20333 and/or CVE-2025-20362.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 3. Execution</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Command and Scripting Interpreter</td>\n<td><a href=\"https://attack.mitre.org/versions/v18/techniques/T1059/\" target=\"_blank\">T1059</a></td>\n<td>\n<p>FIRESTARTER uses a special function to run shell commands that <code>create /opt/cisco/config/platform/rmdb/CSP_MOUNT_LIST</code>&nbsp;if it is missing.</p>\n<p>FIRESTARTER runs callback commands to manage its files.</p>\n</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 4. Persistence</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Create or Modify System Process</td>\n<td><a href=\"https://attack.mitre.org/versions/v18/techniques/T1543/\" target=\"_blank\">T1543</a></td>\n<td>FIRESTARTER invokes <code>mprotect</code> to enable execution of newly injected code.</td>\n</tr>\n<tr>\n<td>Event Triggered Execution: Unix Shell Configuration Modification</td>\n<td><a href=\"https://attack.mitre.org/versions/v18/techniques/T1546/004/\" target=\"_blank\">T1546.004</a></td>\n<td>FIRESTARTER registers a callback function that is automatically triggered when the program receives any of the following termination-related signals: <code>SIGTERM</code>, <code>SIGINT</code>, <code>SIGQUIT</code>, <code>SIGABRT</code>, <code>SIGHUP</code>, or <code>SIGTSTP</code>.</td>\n</tr>\n<tr>\n<td>Boot or Logon Autostart Execution</td>\n<td><a href=\"https://attack.mitre.org/versions/v18/techniques/T1547/\" target=\"_blank\">T1547</a></td>\n<td>Persistence is maintained by modifying a boot-time configuration/mount script so FIRESTARTER runs on startup.</td>\n</tr>\n<tr>\n<td>External Remote Services</td>\n<td><a href=\"https://attack.mitre.org/versions/v18/techniques/T1133/\" target=\"_blank\">T1133</a></td>\n<td>The APT actors used LINE VIPER to establish illegitimate VPN sessions.</td>\n</tr>\n<tr>\n<td>Valid Accounts</td>\n<td><a href=\"https://attack.mitre.org/versions/v18/techniques/T1078/\" target=\"_blank\">T1078</a></td>\n<td>The APT actors used valid user accounts for their illegitimate VPN sessions (the user accounts belonged to former employees).</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 5. Defense Evasion</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>File and Directory Permissions Modification</td>\n<td><a href=\"https://attack.mitre.org/versions/v18/techniques/T1222/\" target=\"_blank\">T1222</a></td>\n<td>\n<p>FIRESTARTER creates the <code>/opt/cisco/platform/logs/var/log/</code> directory with full read/write/execute permissions.&nbsp;</p>\n<p>FIRESTARTER uses <code>chown</code> and <code>chmod</code> to modify file permissions.</p>\n</td>\n</tr>\n<tr>\n<td>Hide Artifacts: Hidden Users</td>\n<td><a href=\"https://attack.mitre.org/versions/v18/techniques/T1564/\" target=\"_blank\">T1564</a></td>\n<td>FIRESTARTER redirects standard error (<code>stderr</code>) messages to <code>/dev/null</code> and hides them from the console.</td>\n</tr>\n<tr>\n<td>Indicator Removal on Host: File Deletion</td>\n<td><a href=\"https://attack.mitre.org/versions/v18/techniques/T1070/004/\" target=\"_blank\">T1070.004</a></td>\n<td>FIRESTARTER deletes the following files: <code>CSP_MOUNT_LIST</code>, <code>CSP_MOUNT_LIST.tmp</code>, and <code>/usr/bin/lina_cs</code>.</td>\n</tr>\n<tr>\n<td>Indicator Removal on Host: Timestomp</td>\n<td><a href=\"https://attack.mitre.org/versions/v18/techniques/T1070/006/\" target=\"_blank\">T1070.006</a></td>\n<td>FIRESTARTER uses <code>touch -r</code> to copy timestamps from original files to modified and temporary ones, explicitly to match the original.</td>\n</tr>\n<tr>\n<td>Masquerading: Match Legitimate Resource Name or Location</td>\n<td><a href=\"https://attack.mitre.org/versions/v18/techniques/T1036/005/\" target=\"_blank\">T1036.005</a></td>\n<td>FIRESTARTER accesses its own binary located at <code>/usr/bin/lina_cs</code> on the victim device.</td>\n</tr>\n<tr>\n<td>Process Injection</td>\n<td><a href=\"https://attack.mitre.org/versions/v18/techniques/T1055/\" target=\"_blank\" title=\"T1055\">T1055</a></td>\n<td>FIRESTARTER injects shellcode into a library\u2019s code section before the start of the text segment.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption>Table 6. Discovery</caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Process Discovery</td>\n<td><a href=\"https://attack.mitre.org/versions/v18/techniques/T1057/\" target=\"_blank\">T1057</a></td>\n<td>FIRESTARTER enumerates LINA\u2019s virtual memory map to locate the private read-write (<code>rw-p</code>) segment associated with <code>lina</code>.</td>\n</tr>\n<tr>\n<td>System Information Discovery</td>\n<td><a href=\"https://attack.mitre.org/versions/v18/techniques/T1082/\" target=\"_blank\">T1082</a></td>\n<td>The APT actors used LINE VIPER to access Cisco Firepower device configuration elements, including administrative credentials, certificates, and private keys.</td>\n</tr>\n</tbody>\n</table>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<caption><a class=\"ck-anchor\" id=\"table7\">Table 7. Command and Control</a></caption>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Technique Title</th>\n<th role=\"columnheader\">ID</th>\n<th role=\"columnheader\">Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Remote Access Tools</td>\n<td><a href=\"https://attack.mitre.org/versions/v18/techniques/T1219/\" target=\"_blank\">T1219</a></td>\n<td>FIRESTARTER is a Linux ELF designed to execute on Cisco Firepower and Secure Firewall devices, serving as a C2 channel for remote access and control.</td>\n</tr>\n</tbody>\n</table>",
        "summary_is_html": true,
        "first_seen": "Thu, 23 Apr 26 12:00:00 +0000",
        "last_updated": "Thu, 23 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/04/23/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/04/23/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\" data-entity-type=\"node\" data-entity-uuid=\"79453b83-86b9-4e2f-b1ec-abf73c6eb291\" data-entity-substitution=\"canonical\" title=\"Known Exploited Vulnerabilities Catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-39987\">CVE-2026-39987</a> Marimo Remote Code Execution Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/binding-operational-directive-22-01\">Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities</a> established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the <a href=\"https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf\">BOD 22-01 Fact Sheet</a> for more information.</p>\n<p>Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\" data-entity-type=\"node\" data-entity-uuid=\"79453b83-86b9-4e2f-b1ec-abf73c6eb291\" data-entity-substitution=\"canonical\" title=\"Known Exploited Vulnerabilities Catalog\">KEV Catalog vulnerabilities</a> as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities\" data-entity-type=\"node\" data-entity-uuid=\"f2adba9a-0404-494c-a90c-4363a4a5c934\" data-entity-substitution=\"canonical\" title=\"Reducing the Significant Risk of Known Exploited Vulnerabilities\">specified criteria</a>.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Thu, 23 Apr 26 12:00:00 +0000",
        "last_updated": "Thu, 23 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/alerts/2026/04/22/cisa-adds-one-known-exploited-vulnerability-catalog",
        "title": "CISA Adds One Known Exploited Vulnerability to Catalog",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/alerts/2026/04/22/cisa-adds-one-known-exploited-vulnerability-catalog",
        "summary": "<p>CISA has added one new vulnerability to its <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\" data-entity-type=\"node\" data-entity-uuid=\"79453b83-86b9-4e2f-b1ec-abf73c6eb291\" data-entity-substitution=\"canonical\" title=\"Known Exploited Vulnerabilities Catalog\">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>\n<ul>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-33825\" target=\"_blank\">CVE-2026-33825</a> Microsoft Defender Insufficient Granularity of Access Control Vulnerability</li>\n</ul>\n<p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p>\n<p><a href=\"https://www.cisa.gov/binding-operational-directive-22-01\">Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities</a> established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the <a href=\"https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf\">BOD 22-01 Fact Sheet</a> for more information.</p>\n<p>Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\" data-entity-type=\"node\" data-entity-uuid=\"79453b83-86b9-4e2f-b1ec-abf73c6eb291\" data-entity-substitution=\"canonical\" title=\"Known Exploited Vulnerabilities Catalog\">KEV Catalog vulnerabilities</a> as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the <a href=\"https://www.cisa.gov/known-exploited-vulnerabilities\" data-entity-type=\"node\" data-entity-uuid=\"f2adba9a-0404-494c-a90c-4363a4a5c934\" data-entity-substitution=\"canonical\" title=\"Reducing the Significant Risk of Known Exploited Vulnerabilities\">specified criteria</a>.&nbsp;</p>",
        "summary_is_html": true,
        "first_seen": "Wed, 22 Apr 26 12:00:00 +0000",
        "last_updated": "Wed, 22 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-12",
        "title": "SenseLive X3050",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-12",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-111-12.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to take complete control of the device.</strong></p>\n<p>The following versions of SenseLive X3050 are affected:</p>\n<ul>\n<li>X3050 V1.523 (CVE-2026-40630, CVE-2026-25720, CVE-2026-35503, CVE-2026-39462, CVE-2026-27843, CVE-2026-40431, CVE-2026-40623, CVE-2026-27841, CVE-2026-40620, CVE-2026-35064, CVE-2026-25775)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.8</td>\n<td>SenseLive</td>\n<td>SenseLive X3050</td>\n<td>Authentication Bypass Using an Alternate Path or Channel, Insufficient Session Expiration, Use of Hard-coded Credentials, Insufficiently Protected Credentials, Missing Authentication for Critical Function, Cleartext Transmission of Sensitive Information, Missing Authorization, Cross-Site Request Forgery (CSRF)</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Water and Wastewater, Energy, Information Technology</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>India</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-40630</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability in the X3050's web management interface allows unauthorized access to certain configuration endpoints due to improper access control enforcement. An attacker with network access to the device may be able to bypass the intended authentication mechanism and directly interact with sensitive configuration functions.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-40630\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>SenseLive X3050</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>SenseLive</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SenseLive X3050: V1.523</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contact<br><a href=\"https://senselive.io/contact\">https://senselive.io/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/288.html\">CWE-288 Authentication Bypass Using an Alternate Path or Channel</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-25720</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability exists in the X3050's web management interface due to improper session lifetime enforcement, allowing authenticated sessions to remain active for extended periods without requiring re-authentication. An attacker with access to a previously authenticated session could continue interacting with administrative functions long after legitimate user activity has ceased.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-25720\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>SenseLive X3050</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>SenseLive</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SenseLive X3050: V1.523</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contact<br><a href=\"https://senselive.io/contact\">https://senselive.io/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/613.html\">CWE-613 Insufficient Session Expiration</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.4</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-35503</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability in the X3050's web management interface allows authentication logic to be performed entirely on the client side, relying on hardcoded values within browser-executed scripts rather than server-side verification. An attacker with access to the login page could retrieve these exposed parameters and gain unauthorized access to administrative functionality.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-35503\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>SenseLive X3050</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>SenseLive</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SenseLive X3050: V1.523</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contact<br><a href=\"https://senselive.io/contact\">https://senselive.io/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/798.html\">CWE-798 Use of Hard-coded Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-39462</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability exists in the X3050's web management interface in which password updates are not reliably applied due to improper handling of credential changes on the backend. After the device undergoes a factory restore using the SenseLive Config 2.0 tool, the interface may indicate that the password update was successful; however, the system may continue to accept the previous or default credentials, demonstrating that the password-change process is not consistently enforced. Even after a factory reset, attempted password changes may fail to propagate correctly.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-39462\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>SenseLive X3050</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>SenseLive</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SenseLive X3050: V1.523</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contact<br><a href=\"https://senselive.io/contact\">https://senselive.io/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/522.html\">CWE-522 Insufficiently Protected Credentials</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-27843</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability exists in the X3050's web management interface that allows critical configuration parameters to be modified without sufficient authentication or server-side validation. By applying unsupported or disruptive values to recovery mechanisms and network settings, an attacker can induce a persistent lockout state. Because the device lacks a physical reset button, recovery requires specialized technical access via the console to perform a factory reset, resulting in a total denial-of-service for the gateway and its connected RS-485 downstream systems.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-27843\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>SenseLive X3050</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>SenseLive</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SenseLive X3050: V1.523</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contact<br><a href=\"https://senselive.io/contact\">https://senselive.io/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.1</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-40431</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability exists in the X3050's web management interface due to its reliance on unencrypted HTTP for all administrative communication. Because management traffic, including authentication attempts and configuration data, is transmitted in cleartext, an attacker with access to the same network segment could intercept or observe sensitive operational information.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-40431\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>SenseLive X3050</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>SenseLive</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SenseLive X3050: V1.523</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contact<br><a href=\"https://senselive.io/contact\">https://senselive.io/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/319.html\">CWE-319 Cleartext Transmission of Sensitive Information</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-40623</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability in the X3050's web management interface allows critical system and network configuration parameters to be modified without sufficient validation and safety controls. Due to inadequate enforcement of constraints on sensitive functions, parameters such as IP addressing, watchdog timers, reconnect intervals, and service ports can be set to unsupported or unsafe values. These configuration changes directly affect core device behaviour and recovery mechanisms. The lack of proper validation and safeguards allows critical system functions to be altered in a manner that can destabilize device operation or render the device persistently unavailable.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-40623\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>SenseLive X3050</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>SenseLive</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SenseLive X3050: V1.523</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contact<br><a href=\"https://senselive.io/contact\">https://senselive.io/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/862.html\">CWE-862 Missing Authorization</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-27841</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability in the X3050's web management interface allows state-changing operations to be triggered without proper Cross-Site Request Forgery (CSRF) protections. Because the application does not enforce server-side validation of request origin or implement CSRF tokens, a malicious external webpage could cause a user's browser to submit unauthorized configuration requests to the device.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-27841\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>SenseLive X3050</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>SenseLive</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SenseLive X3050: V1.523</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contact<br><a href=\"https://senselive.io/contact\">https://senselive.io/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/352.html\">CWE-352 Cross-Site Request Forgery (CSRF)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.1</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-40620</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability in the X3050's embedded management service allows full administrative control to be established without any form of authentication or authorization on the SenseLive config application. The service accepts management connections from any reachable host, enabling unrestricted modification of critical configuration parameters, operational modes, and device state through a vendor-supplied or compatible client.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-40620\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>SenseLive X3050</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>SenseLive</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SenseLive X3050: V1.523</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contact<br><a href=\"https://senselive.io/contact\">https://senselive.io/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-35064</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability in the X3050's management ecosystem allows unauthenticated discovery of deployed units through the vendor's management protocol, enabling identification of device presence, identifiers, and management interfaces without requiring credentials. Because discovery functions are exposed by the underlying service rather than gated by authentication, an attacker on the same network segment can rapidly enumerate targeted devices.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-35064\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>SenseLive X3050</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>SenseLive</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SenseLive X3050: V1.523</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contact<br><a href=\"https://senselive.io/contact\">https://senselive.io/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-25775</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability in X3050's remote management service allows firmware retrieval and update operations to be performed without authentication or authorization. The service accepts firmware-related requests from any reachable host and does not verify user privileges, integrity of uploaded images, or the authenticity of provided firmware.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-25775\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>SenseLive X3050</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>SenseLive</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SenseLive X3050: V1.523</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contact<br><a href=\"https://senselive.io/contact\">https://senselive.io/contact</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.8</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Jithin Nambiar J reported these vulnerabilities to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>\n<p>Do not click web links or open attachments in unsolicited email messages.</p>\n<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>\n<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-04-21</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-04-21</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 21 Apr 26 12:00:00 +0000",
        "last_updated": "Tue, 21 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-01",
        "title": "Siemens TPM 2.0",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-01",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-111-01.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>The products listed below contain a vulnerability that could allow an attacker to perform an out-of-bound read, potentially leading to information disclosure or denial of service of the TPM. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.</strong></p>\n<p>The following versions of Siemens TPM 2.0 are affected:</p>\n<ul>\n<li>SIMATIC CN 4100 vers:all/* (CVE-2025-2884)</li>\n<li>SIMATIC Field PG M5 vers:all/* (CVE-2025-2884)</li>\n<li>SIMATIC Field PG M6 vers:all/* (CVE-2025-2884)</li>\n<li>SIMATIC IPC BX-32A vers:intdot/&lt;29.01.09 (CVE-2025-2884)</li>\n<li>SIMATIC IPC BX-39A vers:intdot/&lt;29.01.09 (CVE-2025-2884)</li>\n<li>SIMATIC IPC BX-56A vers:intdot/&lt;32.01.09 (CVE-2025-2884)</li>\n<li>SIMATIC IPC BX-59A vers:intdot/&lt;32.01.09 (CVE-2025-2884)</li>\n<li>SIMATIC IPC MD-57A vers:intdot/&lt;30.01.10 (CVE-2025-2884)</li>\n<li>SIMATIC IPC PX-32A vers:intdot/&lt;29.01.09 (CVE-2025-2884)</li>\n<li>SIMATIC IPC PX-39A vers:intdot/&lt;29.01.09 (CVE-2025-2884)</li>\n<li>SIMATIC IPC PX-39A PRO vers:intdot/&lt;29.01.09 (CVE-2025-2884)</li>\n<li>SIMATIC IPC RW-528A vers:intdot/&lt;34.01.02 (CVE-2025-2884)</li>\n<li>SIMATIC IPC RW-548A vers:intdot/&lt;34.01.02 (CVE-2025-2884)</li>\n<li>SIMATIC IPC227E vers:all/* (CVE-2025-2884)</li>\n<li>SIMATIC IPC277E vers:all/* (CVE-2025-2884)</li>\n<li>SIMATIC IPC427E vers:intdot/&lt;21.01.20 (CVE-2025-2884)</li>\n<li>SIMATIC IPC477E vers:intdot/&lt;21.01.20 (CVE-2025-2884)</li>\n<li>SIMATIC IPC477E PRO vers:intdot/&lt;21.01.20 (CVE-2025-2884)</li>\n<li>SIMATIC IPC627E vers:all/* (CVE-2025-2884)</li>\n<li>SIMATIC IPC647E vers:all/* (CVE-2025-2884)</li>\n<li>SIMATIC IPC677E vers:all/* (CVE-2025-2884)</li>\n<li>SIMATIC IPC847E vers:all/* (CVE-2025-2884)</li>\n<li>SIMATIC ITP1000 vers:all/* (CVE-2025-2884)</li>\n<li>SIPLUS IPC427E vers:intdot/&lt;21.01.20 (CVE-2025-2884)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 6.6</td>\n<td>Siemens</td>\n<td>Siemens TPM 2.0</td>\n<td>Out-of-bounds Read</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-2884</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata Revision 1.83 and advisory TCGVRT0009 for TCG standard TPM2.0</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-2884\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens TPM 2.0</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SIMATIC CN 4100, SIMATIC Field PG M5, SIMATIC Field PG M6, SIMATIC IPC BX-32A, SIMATIC IPC BX-39A, SIMATIC IPC BX-56A, SIMATIC IPC BX-59A, SIMATIC IPC MD-57A, SIMATIC IPC PX-32A, SIMATIC IPC PX-39A, SIMATIC IPC PX-39A PRO, SIMATIC IPC RW-528A, SIMATIC IPC RW-548A, SIMATIC IPC227E, SIMATIC IPC277E, SIMATIC IPC427E, SIMATIC IPC477E, SIMATIC IPC477E PRO, SIMATIC IPC627E, SIMATIC IPC647E, SIMATIC IPC677E, SIMATIC IPC847E, SIMATIC ITP1000, SIPLUS IPC427E</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>No fix planned</strong><br>Currently no fix is planned</p>\n<p><strong>None available</strong><br>Currently no fix is available</p>\n<p><strong>Vendor fix</strong><br>Update to V21.01.20 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109763408/\">https://support.industry.siemens.com/cs/ww/en/view/109763408/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V29.01.09 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109763408/\">https://support.industry.siemens.com/cs/ww/en/view/109763408/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V30.01.10 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109763408/\">https://support.industry.siemens.com/cs/ww/en/view/109763408/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V32.01.09 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109763408/\">https://support.industry.siemens.com/cs/ww/en/view/109763408/</a></p>\n<p><strong>Vendor fix</strong><br>Update to V34.01.02 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109763408/\">https://support.industry.siemens.com/cs/ww/en/view/109763408/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.6</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H\">CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-628843 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-04-14</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-04-14</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-04-21</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-628843 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 21 Apr 26 12:00:00 +0000",
        "last_updated": "Tue, 21 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-07",
        "title": "Siemens SCALANCE",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-07",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-111-07.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>SCALANCE W-700 IEEE 802.11n family before V6.6.0 are affected by multiple vulnerabilities. Siemens has released a new version for SCALANCE W-700 IEEE 802.11n family and recommends to update to the latest version.</strong></p>\n<p>The following versions of Siemens SCALANCE are affected:</p>\n<ul>\n<li>SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n<li>SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0) vers:intdot/&lt;6.6.0 (CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 9.1</td>\n<td>Siemens</td>\n<td>Siemens SCALANCE</td>\n<td>Missing Authentication for Critical Function, Improper Authentication, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Validation of Integrity Check Value, Improper Input Validation, Out-of-bounds Read, Loop with Unreachable Exit Condition ('Infinite Loop'), Missing Authorization, Allocation of Resources Without Limits or Throttling, Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Communications, Information Technology, Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2020-24588</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary can abuse this to inject arbitrary network packets.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2020-24588\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SCALANCE</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0)</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>As these vulnerabilities can only be exploited within Wi-Fi range, when possible reduce Wi-Fi transmission power or make sure to have the devices in private areas with physical access controls</p>\n<p><strong>Mitigation</strong><br>Disable A-MSDU, if possible</p>\n<p><strong>Vendor fix</strong><br>Update to V6.6.0 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109996102/\">https://support.industry.siemens.com/cs/ww/en/view/109996102/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/306.html\">CWE-306 Missing Authentication for Critical Function</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>3.5</td>\n<td>LOW</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N\">CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2020-26139</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2020-26139\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SCALANCE</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0)</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>As these vulnerabilities can only be exploited within Wi-Fi range, when possible reduce Wi-Fi transmission power or make sure to have the devices in private areas with physical access controls</p>\n<p><strong>Vendor fix</strong><br>Update to V6.6.0 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109996102/\">https://support.industry.siemens.com/cs/ww/en/view/109996102/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/287.html\">CWE-287 Improper Authentication</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2020-26140</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2020-26140\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SCALANCE</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0)</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>As these vulnerabilities can only be exploited within Wi-Fi range, when possible reduce Wi-Fi transmission power or make sure to have the devices in private areas with physical access controls</p>\n<p><strong>Vendor fix</strong><br>Update to V6.6.0 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109996102/\">https://support.industry.siemens.com/cs/ww/en/view/109996102/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/74.html\">CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2020-26141</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An adversary can abuse this to inject and possibly decrypt packets in WPA or WPA2 networks that support the TKIP data-confidentiality protocol.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2020-26141\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SCALANCE</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0)</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>As these vulnerabilities can only be exploited within Wi-Fi range, when possible reduce Wi-Fi transmission power or make sure to have the devices in private areas with physical access controls</p>\n<p><strong>Vendor fix</strong><br>Update to V6.6.0 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109996102/\">https://support.industry.siemens.com/cs/ww/en/view/109996102/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/354.html\">CWE-354 Improper Validation of Integrity Check Value</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2020-26143</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH. The WEP, WPA, WPA2, and WPA3 implementations accept fragmented plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2020-26143\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SCALANCE</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0)</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>As these vulnerabilities can only be exploited within Wi-Fi range, when possible reduce Wi-Fi transmission power or make sure to have the devices in private areas with physical access controls</p>\n<p><strong>Vendor fix</strong><br>Update to V6.6.0 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109996102/\">https://support.industry.siemens.com/cs/ww/en/view/109996102/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/20.html\">CWE-20 Improper Input Validation</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2020-26144</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2020-26144\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SCALANCE</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0)</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>As these vulnerabilities can only be exploited within Wi-Fi range, when possible reduce Wi-Fi transmission power or make sure to have the devices in private areas with physical access controls</p>\n<p><strong>Vendor fix</strong><br>Update to V6.6.0 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109996102/\">https://support.industry.siemens.com/cs/ww/en/view/109996102/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/20.html\">CWE-20 Improper Input Validation</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.5</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N\">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2020-26146</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2020-26146\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SCALANCE</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0)</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>As these vulnerabilities can only be exploited within Wi-Fi range, when possible reduce Wi-Fi transmission power or make sure to have the devices in private areas with physical access controls</p>\n<p><strong>Vendor fix</strong><br>Update to V6.6.0 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109996102/\">https://support.industry.siemens.com/cs/ww/en/view/109996102/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/20.html\">CWE-20 Improper Input Validation</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N\">CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2020-26147</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and/or exfiltrate selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2020-26147\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SCALANCE</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0)</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>As these vulnerabilities can only be exploited within Wi-Fi range, when possible reduce Wi-Fi transmission power or make sure to have the devices in private areas with physical access controls</p>\n<p><strong>Vendor fix</strong><br>Update to V6.6.0 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109996102/\">https://support.industry.siemens.com/cs/ww/en/view/109996102/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/20.html\">CWE-20 Improper Input Validation</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>5.4</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N\">CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2021-3712</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a strict requirement, ASN.1 strings that are parsed using OpenSSL's own \"d2i\" functions (and other similar parsing functions) as well as any string whose value has been set with the ASN1_STRING_set() function will additionally NUL terminate the byte array in the ASN1_STRING structure. However, it is possible for applications to directly construct valid ASN1_STRING structures which do not NUL terminate the byte array by directly setting the \"data\" and \"length\" fields in the ASN1_STRING array. This can also happen by using the ASN1_STRING_set0() function. Numerous OpenSSL functions that print ASN.1 data have been found to assume that the ASN1_STRING byte array will be NUL terminated, even though this is not guaranteed for strings that have been directly constructed. Where an application requests an ASN.1 structure to be printed, and where that ASN.1 structure contains ASN1_STRINGs that have been directly constructed by the application without NUL terminating the \"data\" field, then a read buffer overrun can occur. The same thing can also occur during name constraints processing of certificates (for example if a certificate has been directly constructed by the application instead of loading it via the OpenSSL parsing functions, and the certificate contains non NUL terminated ASN1_STRING structures). It can also occur in the X509_get1_email(), X509_REQ_get1_email() and X509_get1_ocsp() functions. If a malicious actor can cause an application to directly construct an ASN1_STRING and then process it through one of the affected OpenSSL functions then this issue could be hit. This might result in a crash (causing a Denial of Service attack). It could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext). Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k). Fixed in OpenSSL 1.0.2za (Affected 1.0.2-1.0.2y).</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2021-3712\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SCALANCE</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0)</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V6.6.0 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109996102/\">https://support.industry.siemens.com/cs/ww/en/view/109996102/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/125.html\">CWE-125 Out-of-bounds Read</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.4</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H\">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2022-0778</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The BN_mod_sqrt() function in openSSL, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2022-0778\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SCALANCE</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0)</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V6.6.0 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109996102/\">https://support.industry.siemens.com/cs/ww/en/view/109996102/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/835.html\">CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2022-31765</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate their privileges.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2022-31765\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SCALANCE</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0)</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V6.6.0 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109996102/\">https://support.industry.siemens.com/cs/ww/en/view/109996102/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/862.html\">CWE-862 Missing Authorization</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>8.8</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2022-36323</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2022-36323\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SCALANCE</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0)</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V6.6.0 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109996102/\">https://support.industry.siemens.com/cs/ww/en/view/109996102/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/74.html\">CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.1</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C\">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2022-36324</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TCP brute force prevention and lead to a denial of service condition for the duration of the attack.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2022-36324\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SCALANCE</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0)</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V6.6.0 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109996102/\">https://support.industry.siemens.com/cs/ww/en/view/109996102/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/770.html\">CWE-770 Allocation of Resources Without Limits or Throttling</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.5</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2022-36325</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code and lead to a DOM-based XSS.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2022-36325\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SCALANCE</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0)</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V6.6.0 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109996102/\">https://support.industry.siemens.com/cs/ww/en/view/109996102/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/80.html\">CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.8</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C\">CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2023-44373</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell. Follow-up of CVE-2022-36323.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2023-44373\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SCALANCE</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0)</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V6.6.0 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/109996102/\">https://support.industry.siemens.com/cs/ww/en/view/109996102/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/74.html\">CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>9.1</td>\n<td>CRITICAL</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C\">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported these vulnerabilities to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-019200 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-04-14</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-04-14</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-04-21</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-019200 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 21 Apr 26 12:00:00 +0000",
        "last_updated": "Tue, 21 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-03",
        "title": "Siemens SINEC NMS",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-03",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-111-03.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Siemens SINEC NMS when used with User Management Component (UMC) contains an authentication bypass vulnerability due to insufficient validation of user identity. This could allow an unauthenticated remote attacker to bypass authentication and gain unauthorized access to the application. Siemens has released a new version for SINEC NMS and recommends to update to the latest version.</strong></p>\n<p>The following versions of Siemens SINEC NMS are affected:</p>\n<ul>\n<li>SINEC NMS</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.3</td>\n<td>Siemens</td>\n<td>Siemens SINEC NMS</td>\n<td>Improper Verification of Cryptographic Signature</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-24032</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>The affected application contains an authentication weakness due to insufficient validation of user identity in the UMC component. This could allow an unauthenticated remote attacker to bypass authentication and gain unauthorized access to the application. (ZDI-CAN-27564)</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-24032\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens SINEC NMS</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>SINEC NMS</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V4.0 SP3 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/110000760/\">https://support.industry.siemens.com/cs/ww/en/view/110000760/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/347.html\">CWE-347 Improper Verification of Cryptographic Signature</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-801704 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-04-14</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-04-14</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-04-21</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-801704 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 21 Apr 26 12:00:00 +0000",
        "last_updated": "Tue, 21 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-06",
        "title": "Zero Motorcycles Firmware",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-06",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-111-06.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of this vulnerability could allow an attacker to pair via Bluetooth with a motorcycle, gaining unauthorized access to all Bluetooth functions, including changing the firmware.</strong></p>\n<p>The following versions of Zero Motorcycles Firmware are affected:</p>\n<ul>\n<li>Zero Motorcycles firmware &lt;=44 (CVE-2026-1354)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 6.4</td>\n<td>Zero Motorcycles</td>\n<td>Zero Motorcycles Firmware</td>\n<td>Key Exchange without Entity Authentication</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>United States</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2026-1354</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>Zero Motorcycles firmware versions 44 and prior enable an attacker to forcibly pair a device with the motorcycle via Bluetooth. Once paired, an attacker can utilize over-the-air firmware updating functionality to potentially upload malicious firmware to the motorcycle. The motorcycle must first be in Bluetooth pairing mode, and the attacker must be in proximity of the vehicle and understand the full pairing process, to be able to pair their device with the vehicle. The attacker's device must remain paired with and in proximity of the motorcycle for the entire duration of the firmware update.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-1354\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Zero Motorcycles Firmware</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Zero Motorcycles</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Zero Motorcycles Zero Motorcycles firmware: &lt;=44</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Zero Motorcycles has investigated this report and cautions users to pair their mobile device to their vehicle in a safe location where they can be sure no one else will try to pair at the same time. Once initiated, complete the full pairing process and confirm it is successful. Store physical keys in a secure location and do not leave the bike unattended with the key in the \"ON\" position. Zero Motorcycles plans to address this issue in a firmware update scheduled for release in May 2026. Update the firmware to the latest available version.</p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/322.html\">CWE-322 Key Exchange without Entity Authentication</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.4</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H\">CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Persephone Karnstein of Bureau Veritas Cybersecurity North America reported this vulnerability to CISA</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability has a high attack complexity.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-04-21</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-04-21</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 21 Apr 26 12:00:00 +0000",
        "last_updated": "Tue, 21 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-08",
        "title": "Siemens RUGGEDCOM CROSSBOW Station Access Controller (SAC)",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-08",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-111-08.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>RUGGEDCOM CROSSBOW Station Access Controller (SAC) contains a vulnerability that could allow an attacker to achieve arbitrary code execution and to create a denial of service condition. Siemens has released a new version for RUGGEDCOM CROSSBOW Station Access Controller (SAC) and recommends to update to the latest version.</strong></p>\n<p>The following versions of Siemens RUGGEDCOM CROSSBOW Station Access Controller (SAC) are affected:</p>\n<ul>\n<li>RUGGEDCOM CROSSBOW Station Access Controller (SAC) vers:intdot/&lt;5.8 (CVE-2025-6965)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.7</td>\n<td>Siemens</td>\n<td>Siemens RUGGEDCOM CROSSBOW Station Access Controller (SAC)</td>\n<td>Numeric Truncation Error</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-6965</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-6965\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Siemens RUGGEDCOM CROSSBOW Station Access Controller (SAC)</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Siemens</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>RUGGEDCOM CROSSBOW Station Access Controller (SAC)</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Vendor fix</strong><br>Update to V5.8 or later version<br><a href=\"https://support.industry.siemens.com/cs/ww/en/view/110000841/\">https://support.industry.siemens.com/cs/ww/en/view/110000841/</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/197.html\">CWE-197 Numeric Truncation Error</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.7</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L\">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>Siemens ProductCERT reported this vulnerability to CISA.</li>\n</ul>\n<hr>\n<h2>General Recommendations</h2>\n<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>\n<hr>\n<h2>Additional Resources</h2>\n<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>\n<hr>\n<h2>Terms of Use</h2>\n<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<hr>\n<h2>Advisory Conversion Disclaimer</h2>\n<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-225816 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-04-14</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-04-14</td>\n<td>1</td>\n<td>Publication Date</td>\n</tr>\n<tr>\n<td>2026-04-21</td>\n<td>2</td>\n<td>Initial CISA Republication of Siemens ProductCERT SSA-225816 advisory</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 21 Apr 26 12:00:00 +0000",
        "last_updated": "Tue, 21 Apr 26 12:00:00 +0000"
    },
    {
        "id": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-05",
        "title": "Hardy Barth Salia EV Charge Controller",
        "source": "CISA Cybersecurity Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-05",
        "summary": "<p><a href=\"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-111-05.json\"><strong>View CSAF</strong></a></p>\n<h2>Summary</h2>\n<p><strong>Successful exploitation of these vulnerabilities could crash the device being accessed; a buffer overflow condition may allow remote code execution.</strong></p>\n<p>The following versions of Hardy Barth Salia EV Charge Controller are affected:</p>\n<ul>\n<li>Salia Board Firmware &lt;=2.3.81 (CVE-2025-5873, CVE-2025-10371)</li>\n</ul>\n<div class=\"csaf-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS</th>\n<th role=\"columnheader\">Vendor</th>\n<th role=\"columnheader\">Equipment</th>\n<th role=\"columnheader\">Vulnerabilities</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>v3 7.3</td>\n<td>Hardy Barth</td>\n<td>Hardy Barth Salia EV Charge Controller</td>\n<td>Unrestricted Upload of File with Dangerous Type</td>\n</tr>\n</tbody>\n</table>\n</div>\n<h3>Background</h3>\n<ul>\n<li><strong>Critical Infrastructure Sectors: </strong>Energy, Transportation Systems</li>\n<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>\n<li><strong>Company Headquarters Location: </strong>Germany</li>\n</ul>\n<hr>\n<h2>Vulnerabilities</h2>\n<div class=\"csaf-accordion\">\n<p><a class=\"csaf-accordion-toggle-all\" href=\"#\">Expand All +</a></p>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-5873</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A vulnerability was found in eCharge Hardy Barth Salia PLCC 2.3.81. It has been declared as critical. This vulnerability affects unknown code of the file /firmware.php of the component Web UI. The manipulation of the argument media leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-5873\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Hardy Barth Salia EV Charge Controller</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Hardy Barth</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Hardy Barth Salia Board Firmware: &lt;=2.3.81</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Hardy Barth did not respond to CISA's request for coordination.</p>\n<p><strong>Mitigation</strong><br>Contact Hardy Barth using their contact page here: https://www.hardy-barth.de/de/kontakt for more information.<br><a href=\"https://www.hardy-barth.de/de/kontakt\">https://www.hardy-barth.de/de/kontakt</a></p>\n<p><strong>Mitigation</strong><br>Alternatively, Hardy Barth can also be contacted through their eCharge brand here: https://www.echarge.de/en/contact_company<br><a href=\"https://www.echarge.de/en/contact_company\">https://www.echarge.de/en/contact_company</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/434.html\">CWE-434 Unrestricted Upload of File with Dangerous Type</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>6.3</td>\n<td>MEDIUM</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L\">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n<div class=\"csaf-accordion-item\">\n<h3><a class=\"csaf-accordion-toggle\" href=\"#\">CVE-2025-10371</a></h3>\n<div class=\"csaf-accordion-content\">\n<p>A security flaw has been discovered in eCharge Hardy Barth Salia PLCC 2.3.81. This issue affects some unknown processing of the file /api.php. The manipulation of the argument setrfidlist results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.</p>\n<p><a href=\"https://www.cve.org/CVERecord?id=CVE-2025-10371\">View CVE Details</a></p>\n<hr>\n<h4>Affected Products</h4>\n<h5>Hardy Barth Salia EV Charge Controller</h5>\n<div class=\"ics-vendor-version-status\">\n<div class=\"ics-vendor\"><strong>Vendor:</strong><br>Hardy Barth</div>\n<div class=\"ics-version\"><strong>Product Version:</strong><br>Hardy Barth Salia Board Firmware: &lt;=2.3.81</div>\n<div class=\"ics-status\"><strong>Product Status:</strong><br>known_affected</div>\n</div>\n<div class=\"ics-remediations\">\n<h6>Remediations</h6>\n<p><strong>Mitigation</strong><br>Hardy Barth did not respond to CISA's request for coordination.</p>\n<p><strong>Mitigation</strong><br>Contact Hardy Barth using their contact page here: https://www.hardy-barth.de/de/kontakt for more information.<br><a href=\"https://www.hardy-barth.de/de/kontakt\">https://www.hardy-barth.de/de/kontakt</a></p>\n<p><strong>Mitigation</strong><br>Alternatively, Hardy Barth can also be contacted through their eCharge brand here: https://www.echarge.de/en/contact_company<br><a href=\"https://www.echarge.de/en/contact_company\">https://www.echarge.de/en/contact_company</a></p>\n</div>\n<p><strong>Relevant CWE:</strong> <a href=\"https://cwe.mitre.org/data/definitions/434.html\">CWE-434 Unrestricted Upload of File with Dangerous Type</a></p>\n<hr>\n<h4>Metrics</h4>\n<div class=\"csaf-table csaf-metrics-table\">\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">CVSS Version</th>\n<th role=\"columnheader\">Base Score</th>\n<th role=\"columnheader\">Base Severity</th>\n<th role=\"columnheader\">Vector String</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>3.1</td>\n<td>7.3</td>\n<td>HIGH</td>\n<td><a href=\"https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L\">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a></td>\n</tr>\n</tbody>\n</table>\n</div>\n</div>\n</div>\n</div>\n<hr>\n<h2>Acknowledgments</h2>\n<ul>\n<li>CISA discovered a public Proof of Concept (PoC) as authored by YZS17 and reported it to Hardy Barth</li>\n</ul>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>\n<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>\n<hr>\n<h2>Recommended Practices</h2>\n<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>\n<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.</p>\n<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>\n<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>\n<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>\n<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>\n<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>\n<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>\n<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>\n<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>\n<hr>\n<h2>Revision History</h2>\n<ul>\n<li><strong>Initial Release Date: </strong>2026-04-21</li>\n</ul>\n<table class=\"tablesaw tablesaw-stack\" data-tablesaw-mode=\"stack\" data-tablesaw-minimap>\n<thead>\n<tr>\n<th role=\"columnheader\" data-tablesaw-priority=\"persist\">Date</th>\n<th role=\"columnheader\">Revision</th>\n<th role=\"columnheader\">Summary</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2026-04-21</td>\n<td>1</td>\n<td>Initial Publication</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Legal Notice and Terms of Use</h2>",
        "summary_is_html": true,
        "first_seen": "Tue, 21 Apr 26 12:00:00 +0000",
        "last_updated": "Tue, 21 Apr 26 12:00:00 +0000"
    }
]