Cybersecurity is the discipline, processes, and technologies that protect enterprise networks, information systems, and data from unauthorized access, disruption, or misuse, enabling organizations to maintain confidentiality, integrity, availability, and regulatory compliance across on-premises, cloud, and hybrid digital environments.
CISA will no longer update advisories for Siemens vulnerabilities. Two critical vulnerabilities in COMOS were identified, allowing for potential code execution and data infiltration. Siemens recommends updating to version 10.4.5 or later and provides mitigations to reduce risks of exploitation.
Siemens has identified a vulnerability in Solid Edge SE2025 that allows man-in-the-middle attacks due to improper certificate validation. Users are advised to update to V225.0 Update 11 or later versions and implement protective measures to minimize exploitation risks.
General Industrial Controls' Lynx+ Gateway faces multiple vulnerabilities, including weak password requirements and missing authentication. These issues could lead to unauthorized access and denial of service. Users are advised to enhance security measures and follow CISA's recommendations to mitigate risks.
Uptycs has introduced Juno AI, a verifiable AI Security Analyst, aimed at assisting cybersecurity teams. Juno AI enhances threat detection by providing clear insights and reducing investigation times, while maintaining data privacy and control for organizations.
Festo identified a critical vulnerability in its MSE6 product line affecting remote access. The vulnerability, CVE-2023-3634, poses risks to confidentiality, integrity, and availability. Mitigation measures include updated documentation and network security recommendations.
Automated Logic's WebCTRL Premium Server has vulnerabilities including Open Redirect and Cross-Site Scripting (XSS). Users are advised to upgrade to version 9.0 as previous versions are affected. CISA recommends security practices to mitigate potential exploitation.
Festo has reported a vulnerability in its Didactic products related to Siemens TIA-Portal, affecting versions prior to updates V17 Update 6 and V18 Update 1. The vulnerability could allow arbitrary file creation or overwriting. Users are advised to update their systems accordingly.
Emerson's Appleton UPSMON-PRO is vulnerable to a stack-based buffer overflow that can allow remote code execution. The product is end-of-life, and users are advised to replace or implement specific mitigations to protect their systems. Recommended actions include blocking UDP port 2601 and isolating monitoring networks.