Historical snapshot · Cybersecurity

CISA Advisories

Cybersecurity advisories and mitigation guidance for networks and critical infrastructure.

This page is an archived snapshot of the CISA Advisories feed collected on Feb 8, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
30 recordsOfficial source · JSON
· CISA Cybersecurity Advisory

Schneider Electric Zigbee Products

View CSAF Summary Schneider Electric is aware of multiple vulnerabilities with EmberZNet disclosed by Silicon Labs. Many vendors, including Schneider Electric, use Silicon Labs’ Zigbee processors in their offers. The following have denial of service vulnerabilities: Wiser iTRV, Wiser RTR, Wiser UFH, Wiser Heat Switch, Wiser Boiler Relay, cFMT (Exaact, Elko, Odace, Merten), Wiser Micromodule, Iconic Wiser Connected…
Read full source summary
View CSAF Summary Schneider Electric is aware of multiple vulnerabilities with EmberZNet disclosed by Silicon Labs. Many vendors, including Schneider Electric, use Silicon Labs’ Zigbee processors in their offers. The following have denial of service vulnerabilities: Wiser iTRV, Wiser RTR, Wiser UFH, Wiser Heat Switch, Wiser Boiler Relay, cFMT (Exaact, Elko, Odace, Merten), Wiser Micromodule, Iconic Wiser Connected Smart Dimmer, Iconic Zigbee devices, Wiser Application Modules, Wiser Connected Pushbutton Switch/Dimmer/Shutter controller, Rotary Dimmer, Motion Sensor Dimmer/Switch, Smart socket outlets, and EV socket outlet. See the following table. Failure to apply the mitigations provided below may risk denial of service, which could result in products being unavailable. The following versions of Schneider Electric Zigbee Products are affected: Wiser iTRV2 (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser iTRV3 (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser RTR2 (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser UFH (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser 16A Electrical Heat Switch (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser Boiler Relay (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Exxact cFMT 16a (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Elko cFMT 16a (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Odace cFMT 2a (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Merten cFMT 16a (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Merten cFMT 2a (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser Power Micromodule (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser FIP Micromodule (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Iconic, Wiser Connected Smart Dimmer (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Iconic, Wiser Connected Smart Switch, 2AX (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Iconic, Wiser Connected Smart Switch, 10AX (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Iconic, Connected AC Fan Controller (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Iconic, Connected Smart Socket (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser Connected Application Module 1-Gang (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser Connected Application Module 2-Gang (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser Connected Push Button Dimmer (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser Connected Push Button Switch (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser Connected Push Button Shutter (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser Connected Motion Dimmer (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser Connected Motion Switch (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Wiser Connected Rotary Dimmer (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Connected Wireless Switch (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Micromodule Switch (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Micromodule Dimmer (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Micromodule Shutter (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Connected Single Socket Outlet (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Connected Double Socket Outlet (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Fuga Connected Socket Outlet (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) Mureva EV Link (CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322) CVSS Vendor Equipment Vulnerabilities v3 6.5 Schneider Electric Schneider Electric Zigbee Products Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Uncontrolled Resource Consumption Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy, Information Technology, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: France Vulnerabilities Expand All + CVE-2024-6350 A CWE-120: A buffer overflow vulnerability exists that could cause a denial of service when a malicious device joins the network. View CVE Details Affected Products Schneider Electric Zigbee Products Vendor: Schneider Electric Product Version: Wiser iTRV2 All Versions, Wiser iTRV3 All Versions, Wiser RTR2 All Versions, Wiser UFH All Versions, Wiser 16A Electrical Heat Switch All Versions, Wiser Boiler Relay All Versions, Exxact cFMT 16a All Versions, Elko cFMT 16a All Versions, Odace cFMT 2a All Versions, Merten cFMT 16a All Versions, Merten cFMT 2a All Versions, Wiser Power Micromodule All Versions, Wiser FIP Micromodule All Versions, Iconic, Wiser Connected Smart Dimmer All Versions, Iconic, Wiser Connected Smart Switch, 2AX All Versions, Iconic, Wiser Connected Smart Switch, 10AX All Versions, Iconic, Connected AC Fan Controller All Versions, Iconic, Connected Smart Socket All Versions, Wiser Connected Application Module 1-Gang All Versions, Wiser Connected Application Module 2-Gang All Versions, Wiser Connected Push Button Dimmer All Versions, Wiser Connected Push Button Switch All Versions, Wiser Connected Push Button Shutter All Versions, Wiser Connected Motion Dimmer All Versions, Wiser Connected Motion Switch All Versions, Wiser Connected Rotary Dimmer All Versions, Connected Wireless Switch All Versions, Micromodule Switch All Versions, Micromodule Dimmer All Versions, Micromodule Shutter All Versions, Connected Single Socket Outlet All Versions, Connected Double Socket Outlet All Versions, Fuga Connected Socket Outlet All Versions, Mureva EV Link All Versions Product Status: known_affected Remediations Mitigation Customers should immediately apply the following mitigations to reduce the risk of exploit: To keep your Zigbee network safe and prevent unauthorized access: • Restrict device access: Do not allow unknown devices to join your network. • Review hub settings: Check how your Zigbee hub manages device pairing. • Control network availability: Only open the network when adding new devices and close it immediately after. • Use install codes and avoid the well-known key: Whenever possible, use unique install codes for added security. Replace default keys with secure, unique keys. Relevant CWE: CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2024-6351 A CWE-120: A buffer overflow vulnerability exists that could cause a denial of service when a malicious device joins the network. View CVE Details Affected Products Schneider Electric Zigbee Products Vendor: Schneider Electric Product Version: Wiser iTRV2 All Versions, Wiser iTRV3 All Versions, Wiser RTR2 All Versions, Wiser UFH All Versions, Wiser 16A Electrical Heat Switch All Versions, Wiser Boiler Relay All Versions, Exxact cFMT 16a All Versions, Elko cFMT 16a All Versions, Odace cFMT 2a All Versions, Merten cFMT 16a All Versions, Merten cFMT 2a All Versions, Wiser Power Micromodule All Versions, Wiser FIP Micromodule All Versions, Iconic, Wiser Connected Smart Dimmer All Versions, Iconic, Wiser Connected Smart Switch, 2AX All Versions, Iconic, Wiser Connected Smart Switch, 10AX All Versions, Iconic, Connected AC Fan Controller All Versions, Iconic, Connected Smart Socket All Versions, Wiser Connected Application Module 1-Gang All Versions, Wiser Connected Application Module 2-Gang All Versions, Wiser Connected Push Button Dimmer All Versions, Wiser Connected Push Button Switch All Versions, Wiser Connected Push Button Shutter All Versions, Wiser Connected Motion Dimmer All Versions, Wiser Connected Motion Switch All Versions, Wiser Connected Rotary Dimmer All Versions, Connected Wireless Switch All Versions, Micromodule Switch All Versions, Micromodule Dimmer All Versions, Micromodule Shutter All Versions, Connected Single Socket Outlet All Versions, Connected Double Socket Outlet All Versions, Fuga Connected Socket Outlet All Versions, Mureva EV Link All Versions Product Status: known_affected Remediations Mitigation Customers should immediately apply the following mitigations to reduce the risk of exploit: To keep your Zigbee network safe and prevent unauthorized access: • Restrict device access: Do not allow unknown devices to join your network. • Review hub settings: Check how your Zigbee hub manages device pairing. • Control network availability: Only open the network when adding new devices and close it immediately after. • Use install codes and avoid the well-known key: Whenever possible, use unique install codes for added security. Replace default keys with secure, unique keys. Relevant CWE: CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Metrics CVSS Version Base Score Base Severity Vector String 3.1 4.3 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2024-6352 A CWE-120: A buffer overflow vulnerability exists that could cause a denial of service when a malicious device joins the network. View CVE Details Affected Products Schneider Electric Zigbee Products Vendor: Schneider Electric Product Version: Wiser iTRV2 All Versions, Wiser iTRV3 All Versions, Wiser RTR2 All Versions, Wiser UFH All Versions, Wiser 16A Electrical Heat Switch All Versions, Wiser Boiler Relay All Versions, Exxact cFMT 16a All Versions, Elko cFMT 16a All Versions, Odace cFMT 2a All Versions, Merten cFMT 16a All Versions, Merten cFMT 2a All Versions, Wiser Power Micromodule All Versions, Wiser FIP Micromodule All Versions, Iconic, Wiser Connected Smart Dimmer All Versions, Iconic, Wiser Connected Smart Switch, 2AX All Versions, Iconic, Wiser Connected Smart Switch, 10AX All Versions, Iconic, Connected AC Fan Controller All Versions, Iconic, Connected Smart Socket All Versions, Wiser Connected Application Module 1-Gang All Versions, Wiser Connected Application Module 2-Gang All Versions, Wiser Connected Push Button Dimmer All Versions, Wiser Connected Push Button Switch All Versions, Wiser Connected Push Button Shutter All Versions, Wiser Connected Motion Dimmer All Versions, Wiser Connected Motion Switch All Versions, Wiser Connected Rotary Dimmer All Versions, Connected Wireless Switch All Versions, Micromodule Switch All Versions, Micromodule Dimmer All Versions, Micromodule Shutter All Versions, Connected Single Socket Outlet All Versions, Connected Double Socket Outlet All Versions, Fuga Connected Socket Outlet All Versions, Mureva EV Link All Versions Product Status: known_affected Remediations Mitigation Customers should immediately apply the following mitigations to reduce the risk of exploit: To keep your Zigbee network safe and prevent unauthorized access: • Restrict device access: Do not allow unknown devices to join your network. • Review hub settings: Check how your Zigbee hub manages device pairing. • Control network availability: Only open the network when adding new devices and close it immediately after. • Use install codes and avoid the well-known key: Whenever possible, use unique install codes for added security. Replace default keys with secure, unique keys. Relevant CWE: CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Metrics CVSS Version Base Score Base Severity Vector String 3.1 4.3 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2024-10106 A CWE-120: A buffer overflow vulnerability exists that could cause a denial of service when a malicious device joins the network. View CVE Details Affected Products Schneider Electric Zigbee Products Vendor: Schneider Electric Product Version: Wiser iTRV2 All Versions, Wiser iTRV3 All Versions, Wiser RTR2 All Versions, Wiser UFH All Versions, Wiser 16A Electrical Heat Switch All Versions, Wiser Boiler Relay All Versions, Exxact cFMT 16a All Versions, Elko cFMT 16a All Versions, Odace cFMT 2a All Versions, Merten cFMT 16a All Versions, Merten cFMT 2a All Versions, Wiser Power Micromodule All Versions, Wiser FIP Micromodule All Versions, Iconic, Wiser Connected Smart Dimmer All Versions, Iconic, Wiser Connected Smart Switch, 2AX All Versions, Iconic, Wiser Connected Smart Switch, 10AX All Versions, Iconic, Connected AC Fan Controller All Versions, Iconic, Connected Smart Socket All Versions, Wiser Connected Application Module 1-Gang All Versions, Wiser Connected Application Module 2-Gang All Versions, Wiser Connected Push Button Dimmer All Versions, Wiser Connected Push Button Switch All Versions, Wiser Connected Push Button Shutter All Versions, Wiser Connected Motion Dimmer All Versions, Wiser Connected Motion Switch All Versions, Wiser Connected Rotary Dimmer All Versions, Connected Wireless Switch All Versions, Micromodule Switch All Versions, Micromodule Dimmer All Versions, Micromodule Shutter All Versions, Connected Single Socket Outlet All Versions, Connected Double Socket Outlet All Versions, Fuga Connected Socket Outlet All Versions, Mureva EV Link All Versions Product Status: known_affected Remediations Mitigation Customers should immediately apply the following mitigations to reduce the risk of exploit: To keep your Zigbee network safe and prevent unauthorized access: • Restrict device access: Do not allow unknown devices to join your network. • Review hub settings: Check how your Zigbee hub manages device pairing. • Control network availability: Only open the network when adding new devices and close it immediately after. • Use install codes and avoid the well-known key: Whenever possible, use unique install codes for added security. Replace default keys with secure, unique keys. Relevant CWE: CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Metrics CVSS Version Base Score Base Severity Vector String 3.1 3.7 LOW CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2024-7322 A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service when a malicious device joins the network. View CVE Details Affected Products Schneider Electric Zigbee Products Vendor: Schneider Electric Product Version: Wiser iTRV2 All Versions, Wiser iTRV3 All Versions, Wiser RTR2 All Versions, Wiser UFH All Versions, Wiser 16A Electrical Heat Switch All Versions, Wiser Boiler Relay All Versions, Exxact cFMT 16a All Versions, Elko cFMT 16a All Versions, Odace cFMT 2a All Versions, Merten cFMT 16a All Versions, Merten cFMT 2a All Versions, Wiser Power Micromodule All Versions, Wiser FIP Micromodule All Versions, Iconic, Wiser Connected Smart Dimmer All Versions, Iconic, Wiser Connected Smart Switch, 2AX All Versions, Iconic, Wiser Connected Smart Switch, 10AX All Versions, Iconic, Connected AC Fan Controller All Versions, Iconic, Connected Smart Socket All Versions, Wiser Connected Application Module 1-Gang All Versions, Wiser Connected Application Module 2-Gang All Versions, Wiser Connected Push Button Dimmer All Versions, Wiser Connected Push Button Switch All Versions, Wiser Connected Push Button Shutter All Versions, Wiser Connected Motion Dimmer All Versions, Wiser Connected Motion Switch All Versions, Wiser Connected Rotary Dimmer All Versions, Connected Wireless Switch All Versions, Micromodule Switch All Versions, Micromodule Dimmer All Versions, Micromodule Shutter All Versions, Connected Single Socket Outlet All Versions, Connected Double Socket Outlet All Versions, Fuga Connected Socket Outlet All Versions, Mureva EV Link All Versions Product Status: known_affected Remediations Mitigation Customers should immediately apply the following mitigations to reduce the risk of exploit: To keep your Zigbee network safe and prevent unauthorized access: • Restrict device access: Do not allow unknown devices to join your network. • Review hub settings: Check how your Zigbee hub manages device pairing. • Control network availability: Only open the network when adding new devices and close it immediately after. • Use install codes and avoid the well-known key: Whenever possible, use unique install codes for added security. Replace default keys with secure, unique keys. Relevant CWE: CWE-400 Uncontrolled Resource Consumption Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.8 MEDIUM CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H Acknowledgments Schneider Electric CPCERT reported these vulnerabilities to CISA. Silicon Labs reported these vulnerabilities to Schneider Electric General Security Recommendations We strongly recommend the following industry cybersecurity best practices. https://www.se.com/us/en/download/document/7EN52-0390/ * Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network. * Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks. * Place all controllers in locked cabinets and never leave them in the “Program” mode. * Never connect programming software to any network other than the network intended for that device. * Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks. * Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation. * Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet. * When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices. For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document. For More Information This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process. For further information related to cybersecurity in Schneider Electric’s products, visit the company’s cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp LEGAL DISCLAIMER THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION About Schneider Electric At Schneider, we believe access to energy and digital is a basic human right. We empower all to do more with less, ensuring Life Is On everywhere, for everyone, at every moment. We provide energy and automation digital solutions for efficiency and sustainability. We combine world-leading energy technologies, real-time automation, software and services into integrated solutions for Homes, Buildings, Data Centers, Infrastructure and Industries. We are committed to unleash the infinite possibilities of an open, global, innovative community that is passionate with our Meaningful Purpose, Inclusive and Empowered values. www.se.com Vulnerability Details These vulnerabilities disclosed by Silicon Labs affect their Zigbee processors, which are used in multiple Schneider Electric's products. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2026-013-03 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-01-13 Date Revision Summary 2026-01-13 1 Original Release 2026-01-27 2 Initial Republication of Schneider Electric CPCERT SEVD-2026-013-03 advisory Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

iba Systems ibaPDA

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized actions on the file system. The following versions of iba Systems ibaPDA are affected: ibaPDA (CVE-2025-14988) CVSS Vendor Equipment Vulnerabilities v3 9.8 iba Systems iba Systems ibaPDA Incorrect Permission Assignment for Critical Resource Background Critical Infrastructure Sectors: Critical Manufacturing…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized actions on the file system. The following versions of iba Systems ibaPDA are affected: ibaPDA (CVE-2025-14988) CVSS Vendor Equipment Vulnerabilities v3 9.8 iba Systems iba Systems ibaPDA Incorrect Permission Assignment for Critical Resource Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2025-14988 A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain conditions. This may impact the confidentiality, integrity, or availability of the system. View CVE Details Affected Products iba Systems ibaPDA Vendor: iba Systems Product Version: iba Systems ibaPDA: 8.12.0 Product Status: known_affected Remediations Vendor fix iba Systems recommends users update to ibaPDA v8.12.1 or a later version. Mitigation If Installing the update is not possible, iba Systems recommends users: Mitigation Enable User Management:To activate user management, navigate to User Management settings under the Configure option. Set a password for the admin user to enable user management. Vendor fix Configure Server Access:To configure, open Server Access Manager (found under Configure in the ibaPDA Client). Set the configuration to restrict access. For example, only 127.0.0.1 (localhost) or specific system IP addresses to communicate with ibaPDA can connect to the ibaPDA Server. (In this example, only connections from localhost are permitted to access ibaPDA.) Vendor fix Restrict Connections to Localhost (if ibaPDA is only accessed from the system where it runs): Vendor fix Go to I/O Manager, then General, and deactivate the option "Automatically open necessary ports in Windows Firewall." (If this option remains active, after a restart of ibaPDA or a restart for data acquisition, the firewall will be reconfigured automatically.) Vendor fix Then, go to Advanced Windows Firewall settings and delete or deactivate all incoming rules for the ibaPDA Client and Server. Vendor fix Manually create firewall rules for the connection used for ibaPDA and verify that the correct ports are configured. For assistance with identifying the ports used by the ibaPDA service can be found in the iba Help Center. Vendor fix Note: After making the changes, verify that all ibaPDA services are operating as expected and that the data acquisition is functioning correctly. Relevant CWE: CWE-732 Incorrect Permission Assignment for Critical Resource Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Acknowledgments Siemens reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-01-27 Date Revision Summary 2026-01-27 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

CISA Adds Five Known Exploited Vulnerabilities to Catalog

CISA has added five new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2018-14634 Linux Kernel Integer Overflow Vulnerability CVE-2025-52691 SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-21509 Microsoft Office Security Feature Bypass Vulnerability CVE-2026-23760 SmarterTools SmarterMail…
Read full source summary
CISA has added five new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2018-14634 Linux Kernel Integer Overflow Vulnerability CVE-2025-52691 SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-21509 Microsoft Office Security Feature Bypass Vulnerability CVE-2026-23760 SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-24061 GNU InetUtils Argument Injection Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
· CISA Cybersecurity Advisory

Product Categories for Technologies That Use Post-Quantum Cryptography Standards

Executive Summary In response to the June 6, 2025, Executive Order (EO) 14306, “Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity and Amending Executive Order 13694 and Executive Order 14144,” the Cybersecurity and Infrastructure Security Agency (CISA) is providing and regularly updating the below lists to aid in post-quantum cryptography (PQC) adoption. The lists include hardware and software…
Read full source summary
Executive Summary In response to the June 6, 2025, Executive Order (EO) 14306, “Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity and Amending Executive Order 13694 and Executive Order 14144,” the Cybersecurity and Infrastructure Security Agency (CISA) is providing and regularly updating the below lists to aid in post-quantum cryptography (PQC) adoption. The lists include hardware and software categories with example types of widely available products that use PQC standards to protect sensitive information.1 The lists focus on categories of available products, typically acquired by the federal government, that utilize cryptographic algorithms. Because PQC-capable products are widely available in the listed categories, organizations should acquire only PQC-capable products when planning acquisitions and procuring products in these categories. Introduction Purpose The lists below are CISA’s response to Executive Order (EO) 14306, which instructed: By December 1, 2025, the Secretary of Homeland Security, acting through the Director of the Cybersecurity and Infrastructure Security Agency (CISA), and in consultation with the Director of the National Security Agency, shall release and thereafter regularly update a list of product categories in which products that support post-quantum cryptography (PQC) are widely available. When a particular category offers widely available PQC-capable products, organizations should plan acquisitions to procure only PQC-capable products from that category. Scope and Definitions The scope of the lists below includes categories of hardware and software products that are—or are anticipated to be—widely available and use PQC standards. Note: “Widely available” describes products that are generally available in the marketplace, and agencies can acquire them in accordance with their typical procurement policies and procedures. The categories cover hardware and software products that apply PQC standards for encryption and authentication through the following cryptographic functions: Key establishment:2 A function in the lifecycle of keying material; the process by which cryptographic keys are securely established among cryptographic modules using manual transport methods (e.g., key loaders), automated methods (e.g., key-transport and/or key-agreement protocols), or a combination of automated and manual methods (consisting of key transport plus key agreement). Digital signatures:3 The result of a cryptographic transformation of data that, when properly implemented, provides the services of 1. origin authentication, 2. data integrity, and 3. signer non-repudiation. Key establishment is often essential for establishing confidential communication using encryption among two or more parties. Digital signatures are often essential for authenticating the parties participating in a communication and for establishing the authenticity of data, products, and services. Automated cryptographic discovery and inventory products are out of scope of these lists. Considerations for Products That Use PQC Standards PQC Transition of Information Technology (IT) Infrastructure Recognizing the global need to support PQC algorithms, product manufacturers are developing new products and updating existing products to incorporate post-quantum cryptographic standards. National Institute of Standards and Technology In 2016, the National Institute of Standards and Technology (NIST) initiated a process to solicit, evaluate, and standardize one or more quantum-resistant public-key cryptographic algorithms. The ongoing PQC standardization process has produced PQC standards and will likely standardize additional algorithms in the coming years. The NIST Internal Report (IR) 8547, Transition to Post-Quantum Cryptography Standards, describes NIST’s expected approach to transitioning from quantum-vulnerable cryptographic algorithms to post-quantum digital signature algorithms and key-establishment schemes. The report identifies existing quantum-vulnerable cryptographic standards and the current quantum-resistant standards that organizations will use in the transition. The report informs the efforts and timelines of federal agencies, industry, and standards organizations for transitioning products, services, and infrastructure to PQC. NIST will revise this report and feed into other algorithms- and application-specific guidance for the transition to PQC as necessary to support transition timelines. Table 1 shows three NIST PQC standards along with a recommendation for stateful hash-based signature algorithms that support quantum-resistant standards. Table 1: NIST Standard PQC Algorithms Cryptographic Function Algorithm Standard Standard Key Establishment Module-Lattice-Based Key- Encapsulation Mechanism (ML-KEM) Federal Information Processing Standards (FIPS) 203 Digital Signature Module-Lattice-Based Digital Signature Algorithm (ML-DSA) Federal Information Processing Standards (FIPS) 204 Digital Signature Stateless Hash-Based Digital Signature Algorithm (SLH-DSA) Federal Information Processing Standards (FIPS) 205 Digital Signature Stateful Hash-Based Digital Signature Algorithms: Leighton-Micali Signature Scheme (LMS), Hierarchical Merkle Signature Scheme (HMS), eXtended Merkle Signature Scheme (XMSS), eXtended Merkle Signature Scheme with Multi-Tree (XMSSMT) NISTSP 800-208 Product Lists Table 2 details widely available categories with respective types of hardware and software products that use PQC standards to protect sensitive information well into the foreseeable future, including after the advent of a cryptographically relevant quantum computer (CRQC). Organizations building PQC migration plans can use these categories as a guide to assess future technological needs. Once a category is listed as having PQC-capable products widely available, organizations should plan acquisitions to procure only PQC-capable products in that category.4 Table 3 does not list categories of PQC-capable products that are currently widely available; instead, it lists product categories where manufacturer implementation and testing of PQC capabilities are encouraged. It is important that the products listed in Table 3 implement PQC for core features and for all secondary functionality, such as for software updates. As the Table 3 product categories mature their capabilities and transition to PQC, CISA will move them from Table 3 to the list in Table 2. Tables 2 and 3 consider efforts within the General Services Administration (GSA),5,6 CISA,7 NIST,8 and the National Security Agency (NSA)9. Note: Tables 2 and 3 are not exhaustive lists; CISA will periodically update these tables as needed to cover new examples of widely available products that use PQC standards. Table 2: Widely Available Hardware and Software Product Categories That Use PQC Standards Product Category* Example Product Type Cloud Services Platform-as-a-service (PaaS), infrastructure-as-a-service (IaaS) Collaboration Software Chat/messaging Web Software Web browsers, web servers Endpoint Security10 Data at rest (DAR) security, full disk encryption * Most of these categories have implemented PQC for key encapsulation and key agreement but have not yet widely implemented PQC for digital signatures and authentication. As a result, these categories are not considered to be fully quantum resistant; CISA includes them on this list because one of their main security services is quantum resistant and Federal Civilian Executive Branch (FCEB) departments and agencies should procure them appropriately. Table 3: Hardware and Software Product Categories Transitioning to Use PQC Standards Product Category Example Product Type Networking Hardware Proxy servers, routers, firewalls, switches, appliances Networking Software Software-defined network (SDN), domain name service (DNS), network operating systems Cloud Services Software-as-a-service (SaaS) Telecommunications Hardware Desk phones, fax machine, voice over IP (VoIP), radio Computers (Physical and Virtual) Operating systems, hypervisors, containers Computer Peripherals Wireless keyboards, wireless headsets Storage Area Network Appliances, operating systems, applications Identity, Credential, and Access Management (ICAM) Software Identity management systems, identity provider and federation services, certificate authorities, access brokers, access management software, public key infrastructure (PKI) management software Identity, Credential, and Access Management (ICAM) Hardware Hardware security modules (HSM), authentication tokens, badges/cards, badge/card readers Collaboration Software Email clients, email servers, conferencing, file sharing Data Database, Structured Query Language (SQL) server Endpoint Security Password managers, antivirus/anti-malware software, asset management Enterprise Security Continuous diagnostics and mitigation (CDM) tools, intrusion detection/monitoring, inspection systems, security information, and event monitoring (SIEM) Note: The above lists exclude categories of hardware and software products, such as operational technology (OT) and internet of things (IoT) devices, that are not considered traditional IT products. These also should be transitioning to PQC standards as well but are out of scope for these lists. Notes Per EO 14306, “the Secretary of Homeland Security, acting through the Director of the Cybersecurity and Infrastructure Security Agency (CISA), and in consultation with the Director of the National Security Agency, shall release and thereafter regularly update a list of product categories in which products that support post-quantum cryptography (PQC) are widely available.” https://csrc.nist.rip/glossary/term/key_establishment https://csrc.nist.rip/glossary/term/digital_signature Even once a product that supports PQC standards is procured, it may need to use non-PQC algorithms for a time for interoperability reasons. https://buy.gsa.gov/api/system/files/documents/final-508c-pqc_buyer-s_guide_2025.pdf https://www.gsa.gov/technology/it-contract-vehicles-and-purchasing-programs/multiple-award-schedule-it https://www.cisa.gov/sites/default/files/cdm_files/HWAMInitializationGuide.pdf https://www.nist.gov/itl/executive-order-improving-nations-cybersecurity/critical-software-definition-explanatory https://www.niap-ccevs.org/products The principal security service of the Endpoint Security category is not naturally quantum vulnerable. When procuring, one needs to ensure that other relevant features of the product, such as firmware updates, are utilizing post-quantum cryptography (PQC). Please share your thoughts! We welcome your feedback. CISA Product Survey
· CISA Cybersecurity Advisory

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2024-37079 Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant…
Read full source summary
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2024-37079 Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
· CISA Cybersecurity Advisory

Delta Electronics DIAView

View CSAF Summary Successful exploitation of this vulnerability could enable an attacker to execute arbitrary code. The following versions of Delta Electronics DIAView are affected: DIAView (CVE-2026-0975) CVSS Vendor Equipment Vulnerabilities v3 7.8 Delta Electronics Delta Electronics DIAView Improper Neutralization of Special Elements used in a Command ('Command Injection') Background Critical Infrastructure…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could enable an attacker to execute arbitrary code. The following versions of Delta Electronics DIAView are affected: DIAView (CVE-2026-0975) CVSS Vendor Equipment Vulnerabilities v3 7.8 Delta Electronics Delta Electronics DIAView Improper Neutralization of Special Elements used in a Command ('Command Injection') Background Critical Infrastructure Sectors: Chemical, Commercial Facilities, Critical Manufacturing, Energy, Transportation Systems, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Taiwan Vulnerabilities Expand All + CVE-2026-0975 DIAView functions can execute shell commands within a project script. If an attacker tricks the victim into running a project containing a malicious script, then arbitrary code can be executed when the malicious project starts. View CVE Details Affected Products Delta Electronics DIAView Vendor: Delta Electronics Product Version: Delta Electronics DIAView: 4.2.0 Product Status: known_affected Remediations Vendor fix Delta Electronics recommends users update to DIAView v4.4 or later. Mitigation For more information, see Delta Electronics advisory Delta-PCSA-2026-00002. Mitigation Delta Electronics offers users the following general recommendations: Mitigation Do not click on untrusted Internet links or open unsolicited attachments in emails. Mitigation Avoid exposing control systems and equipment to the Internet. Mitigation Place control system networks and remote devices behind firewalls, and isolate them from the business network. Mitigation When remote access is required, use a secure access method, such as a virtual private network (VPN). Mitigation If you have any product-related support concerns, contact Delta via the portal page for any information or materials you may require. Relevant CWE: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Acknowledgments An anonymous researcher at Trend Zero Day Initiative reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely. Revision History Initial Release Date: 2026-01-22 Date Revision Summary 2026-01-22 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Hubitat Elevation Hubs

View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to escalate their privileges and control devices outside of their authorized scope. The following versions of Hubitat Elevation Hubs are affected: Elevation C3 (CVE-2026-1201) Elevation C4 (CVE-2026-1201) Elevation C5 (CVE-2026-1201) Elevation C7 (CVE-2026-1201) Elevation C8 (CVE-2026-1201) Elevation C8 pro…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to escalate their privileges and control devices outside of their authorized scope. The following versions of Hubitat Elevation Hubs are affected: Elevation C3 (CVE-2026-1201) Elevation C4 (CVE-2026-1201) Elevation C5 (CVE-2026-1201) Elevation C7 (CVE-2026-1201) Elevation C8 (CVE-2026-1201) Elevation C8 pro (CVE-2026-1201) CVSS Vendor Equipment Vulnerabilities v3 9.1 Hubitat Hubitat Elevation Hubs Authorization Bypass Through User-Controlled Key Background Critical Infrastructure Sectors: Energy, Communications Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-1201 An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior to version 2.4.2.157 could allow a remote authenticated user to control connected devices outside of their authorized scope via client-side request manipulation. View CVE Details Affected Products Hubitat Elevation Hubs Vendor: Hubitat Product Version: Hubitat Elevation C3: <firmware_2.4.2.157, Hubitat Elevation C4: <firmware_2.4.2.157, Hubitat Elevation C5: <firmware_2.4.2.157, Hubitat Elevation C7: <firmware_2.4.2.157, Hubitat Elevation C8: <firmware_2.4.2.157, Hubitat Elevation C8 pro: <firmware_2.4.2.157 Product Status: known_affected Remediations Mitigation Hubitat has released the following for users to implement: Mitigation Firmware version 2.4.2.157 Relevant CWE: CWE-639 Authorization Bypass Through User-Controlled Key Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.1 CRITICAL CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H Acknowledgments Aaron 'theHastyOne' Hasty of Ostrich Lab reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-01-22 Date Revision Summary 2026-01-22 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-31125 Vite Vitejs Improper Access Control Vulnerability CVE-2025-34026 Versa Concerto Improper Authentication Vulnerability CVE-2025-54313 Prettier eslint-config-prettier Embedded Malicious Code Vulnerability CVE-2025-68645 Synacor Zimbra Collaboration Suite (ZCS) PHP…
Read full source summary
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-31125 Vite Vitejs Improper Access Control Vulnerability CVE-2025-34026 Versa Concerto Improper Authentication Vulnerability CVE-2025-54313 Prettier eslint-config-prettier Embedded Malicious Code Vulnerability CVE-2025-68645 Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
· CISA Cybersecurity Advisory

EVMAPA

View CSAF Summary Successful exploitation of these vulnerabilities could lead to degraded service, a denial-of-service, or unauthorized remote command execution, which could lead to spoofing or a manipulation of charging station statuses. The following versions of EVMAPA are affected: EVMAPA (CVE-2025-54816, CVE-2025-53968, CVE-2025-55705) CVSS Vendor Equipment Vulnerabilities v3 9.4 EVMAPA EVMAPA Missing…
Read full source summary
View CSAF Summary Successful exploitation of these vulnerabilities could lead to degraded service, a denial-of-service, or unauthorized remote command execution, which could lead to spoofing or a manipulation of charging station statuses. The following versions of EVMAPA are affected: EVMAPA (CVE-2025-54816, CVE-2025-53968, CVE-2025-55705) CVSS Vendor Equipment Vulnerabilities v3 9.4 EVMAPA EVMAPA Missing Authentication for Critical Function, Improper Restriction of Excessive Authentication Attempts, Insufficient Session Expiration Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Czechia, Slovakia Company Headquarters Location: Czechia Vulnerabilities Expand All + CVE-2025-54816 This vulnerability occurs when a WebSocket endpoint does not enforce proper authentication mechanisms, allowing unauthorized users to establish connections. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system. View CVE Details Affected Products EVMAPA Vendor: EVMAPA Product Version: EVMAPA EVMAPA: vers:all/* Product Status: known_affected Remediations Vendor fix CVE-2025-54816: EVMAPA informed CISA some of their charging stations do not allow changes to the authorization key using the Open Charge Point Protocol (OCPP). Currently, charge point operators have the option to connect stations using WebSocket Secure (WSS), and EVMAPA connects stations they supply via their own VPN. For OCPP 2.x and newer stations, EVMAPA plans to implement BASIC authorization control. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.4 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L CVE-2025-53968 This vulnerability arises because there are no limitations on the number of authentication attempts a user can make. An attacker can exploit this weakness by continuously sending authentication requests, leading to a denial-of-service (DoS) condition. This can overwhelm the authentication system, rendering it unavailable to legitimate users and potentially causing service disruption. This can also allow attackers to conduct brute-force attacks to gain unauthorized access. View CVE Details Affected Products EVMAPA Vendor: EVMAPA Product Version: EVMAPA EVMAPA: vers:all/* Product Status: known_affected Remediations Vendor fix CVE-2025-53968: EVMAPA did not release a statement regarding this vulnerability. Contact EVMAPA directly for more information. Relevant CWE: CWE-307 Improper Restriction of Excessive Authentication Attempts Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2025-55705 This vulnerability occurs when the system permits multiple simultaneous connections to the backend using the same charging station ID. This can result in unauthorized access, data inconsistency, or potential manipulation of charging sessions. The lack of proper session management and expiration control allows attackers to exploit this weakness by reusing valid charging station IDs to establish multiple sessions concurrently. View CVE Details Affected Products EVMAPA Vendor: EVMAPA Product Version: EVMAPA EVMAPA: vers:all/* Product Status: known_affected Remediations Vendor fix CVE-2025-55705: EVMAPA informed CISA they have resolved this issue and do not allow simultaneous connection of charging stations with the same CBID. Relevant CWE: CWE-613 Insufficient Session Expiration Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.3 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Acknowledgments Khaled Sarieddine reported these vulnerabilities to CISA Mohammad Ali Sayed reported these vulnerabilities to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-01-22 Date Revision Summary 2026-01-22 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Johnson Controls Inc. iSTAR Configuration Utility (ICU) tool

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a failure within the operating system of the machine hosting the ICU tool. The following versions of Johnson Controls Inc. iSTAR Configuration Utility (ICU) tool are affected: iSTAR Configuration Utility (ICU) tool (CVE-2025-26386) CVSS Vendor Equipment Vulnerabilities v3 7.1 Johnson Controls Inc. Johnson Controls Inc.…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a failure within the operating system of the machine hosting the ICU tool. The following versions of Johnson Controls Inc. iSTAR Configuration Utility (ICU) tool are affected: iSTAR Configuration Utility (ICU) tool (CVE-2025-26386) CVSS Vendor Equipment Vulnerabilities v3 7.1 Johnson Controls Inc. Johnson Controls Inc. iSTAR Configuration Utility (ICU) tool Stack-based Buffer Overflow Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy, Government Services and Facilities, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2025-26386 Under certain circumstances, a successful exploitation of this vulnerability could result in failure within the operating system of the machine hosting the ICU tool. View CVE Details Affected Products Johnson Controls Inc. iSTAR Configuration Utility (ICU) tool Vendor: Johnson Controls Inc. Product Version: Johnson Controls Inc. iSTAR Configuration Utility (ICU) tool: <=6.9.7 Product Status: known_affected Remediations Mitigation Johnson Controls Inc. recommends the following: Vendor fix Update the iSTAR Configuration Utility (ICU) tool to version 6.9.8 Mitigation For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2025-08 v1 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories Relevant CWE: CWE-121 Stack-based Buffer Overflow Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.1 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H Acknowledgments Tenable reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-01-22 Date Revision Summary 2026-01-22 1 Initial Publication Legal Notice and Terms of Use
Browse saved snapshots