ABB FLXeon Controllers Identified with Multiple Vulnerabilities
ABB's FLXeon Controllers are identified with multiple vulnerabilities, including hard-coded credentials and improper input validation, allowing potential remote exploitation.
Records are individual enterprise-technology developments, captured as they happen: product launches, funding, partnerships, executive moves, vulnerabilities, and announcements across cloud infrastructure, networking, security, and AI. Looking for the synthesis? See Briefs
Decision Insights Threat Desk • November 13, 2025
ABB's FLXeon Controllers are identified with multiple vulnerabilities, including hard-coded credentials and improper input validation, allowing potential remote exploitation.
Decision Insights Threat Desk • November 13, 2025
CISA has issued four Advisories on Industrial Control Systems, detailing security issues and urging users to review for mitigations.
November 13, 2025
Itential discusses the integration of AI into automation processes, emphasizing a hybrid model that maintains control and compliance.
Decision Insights Threat Desk • November 13, 2025
AVEVA disclosed a vulnerability in its Application Server IDE, affecting versions up to 2023 R2 SP1 P02. The issue involves improper HTML tag neutralization, allowing potential XSS code exploitation.
Decision Insights Threat Desk • November 13, 2025
Rockwell Automation's Studio 5000 Simulation Interface has multiple vulnerabilities, including path traversal and SSRF, impacting versions 2.02 and prior.
Decision Insights Threat Desk • November 13, 2025
CISA has issued 18 advisories focused on vulnerabilities and security issues within various Industrial Control Systems (ICS).
Decision Insights Threat Desk • November 13, 2025
Rockwell Automation disclosed a vulnerability in FactoryTalk Policy Manager that could lead to denial of service. The affected versions are 6.51.00 and prior, with a CVSS v4 score of 8.7.
Decision Insights Threat Desk • November 13, 2025
Rockwell Automation has reported a vulnerability in its Verve Asset Manager affecting multiple versions, allowing unauthorized access via the API.
Decision Insights Threat Desk • November 13, 2025
Brightpick AI's warehouse automation platform is vulnerable to multiple security issues, allowing unauthorized access to critical functions and sensitive data.
Decision Insights Threat Desk • November 13, 2025
CISA will cease updating ICS security advisories for Siemens vulnerabilities as of January 10, 2023. Siemens advises updating Spectrum Power 4 to V4.70 SP12 Update 2.
Decision Insights Threat Desk • November 13, 2025
As of January 10, 2023, CISA stopped updating ICS advisories for Siemens vulnerabilities. A risk in Solid Edge allows remote attacks.
Decision Insights Threat Desk • November 13, 2025
CISA, in collaboration with federal and international partners, has issued an updated Cybersecurity Advisory on Akira ransomware, detailing latest attack methods and prevention strategies.
Decision Insights Threat Desk • November 13, 2025
Rockwell Automation has identified multiple vulnerabilities in the FactoryTalk DataMosaix Private Cloud, urging users to update to secure versions.
Decision Insights Threat Desk • November 13, 2025
Mitsubishi Electric has reported a vulnerability in its MELSEC iQ-F Series that may allow a Denial of Service condition when exploited.
Decision Insights Threat Desk • November 13, 2025
General Industrial Controls has reported vulnerabilities in Lynx+ Gateway, including weak password requirements and missing authentication, which could lead to unauthorized access.
Decision Insights Threat Desk • November 13, 2025
AVEVA has reported a vulnerability in its Edge software that may allow attackers to reverse engineer passwords via weak cryptographic algorithms.
Decision Insights Threat Desk • November 13, 2025
Siemens has addressed vulnerabilities in Altair Grid Engine versions prior to V2026.0.0, which can allow attackers to escalate privileges.
Decision Insights Threat Desk • November 13, 2025
CISA will discontinue updates on Siemens product vulnerabilities, urging users to update software and adopt cybersecurity measures.
Decision Insights Threat Desk • November 13, 2025
CISA will cease updates for Siemens ICS security advisories after January 10, 2023. Siemens reports vulnerabilities in COMOS software versions prior to 10.4.5, with risk of code execution and data…
Decision Insights Threat Desk • November 13, 2025
CISA will cease updates on Siemens ICS security advisories for product vulnerabilities. The SICAM P850 and P855 families face vulnerabilities allowing unauthorized actions via CSRF and session…
A synthesis of what changed across the vendors, projects and technologies tracked here. Published every two weeks. Subscribing creates a free Decision Insights account.