icsad_ID,Original_Release_Date,Last_Updated,Year,ICS-CERT_Number,ICS-CERT_Advisory_Title,Vendor,Product,Products_Affected,CVE_Number,Cumulative_CVSS,CVSS_Severity,CWE_Number,Critical_Infrastructure_Sector,Product_Distribution,Company_Headquarters,License 4016,9/8/2026,9/8/2026,2026,ICSA-26-251-01,CareCam Pro IP Cameras,CareCam,CareCam Pro IP Cameras,ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26,CVE-2026-85083,6.8,Medium,CWE-798,Commercial Facilities,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 4015,9/3/2026,9/3/2026,2026,ICSA-26-246-01,OPC Foundation OPC UA LocalDiscoveryServer (LDS),OPC Foundation,OPC Foundation OPC UA LocalDiscoveryServer (LDS),UA-LDS-Installers <1.04.420,CVE-2026-77477,4.6,Medium,CWE-250,Chemical; Energy; Food and Agriculture; Water and Wastewater Systems; Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 4014,9/3/2026,9/3/2026,2026,ICSA-26-246-02,IXON VPN Client,IXON,IXON VPN Client,VPN Client <1.4.7,CVE-2026-75925,9.6,Critical,CWE-93,Commercial Facilities; Critical Manufacturing; Energy; Information Technology; Water and Wastewater Systems,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 4013,9/3/2026,9/3/2026,2026,ICSA-26-246-03,Rockwell Automation ControlFLASH,Rockwell Automation,Rockwell Automation ControlFLASH,ControlFLASH <=V15.07,CVE-2026-12663,7.3,High,CWE-306,Critical Manufacturing; Energy; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 4012,9/3/2026,9/3/2026,2026,ICSA-26-246-04,Rockwell Automation ArmorStart LT,Rockwell Automation,Rockwell Automation ArmorStart LT,ArmorStart LT <=v2.001,"CVE-2026-19471, CVE-2026-19472",7.5,High,"CWE-770, CWE-79",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 4011,9/3/2026,9/3/2026,2026,ICSA-26-246-05,Rockwell Automation 1756-ENBT Module,Rockwell Automation,Rockwell Automation 1756-ENBT Module,1756-ENBT module,CVE-2025-10478,7.5,High,CWE-754,Critical Manufacturing; Food and Agriculture; Transportation Systems; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 4010,9/3/2026,9/3/2026,2026,ICSA-26-246-06,Inductive Automation Ignition,Inductive Automation,Inductive Automation Ignition,Ignition <=8.1.53,CVE-2026-77393,8.8,High,CWE-276,Critical Manufacturing; Energy; Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 4009,9/3/2026,9/3/2026,2026,ICSA-26-246-07,Pyramid Solutions NetStaX EtherNet/IP Stack,Pyramid Solutions,Pyramid Solutions NetStaX EtherNet/IP Stack,EtherNet/IP Adapter DLL Kit (EIPA) | EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE) | EtherNet/IP Adapter Development Kit (EADK) | EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE) | EtherNet/IP Scanner DLL Kit (EIPS) | EtherNet/IP Scanner DLL Kit with CIP Security (EIPS-SECURE) | EtherNet/IP Scanner Development Kit (ESDK) | EtherNet/IP Scanner Development Kit with CIP Security (ESDK-SECURE),CVE-2026-78012,9.8,Critical,CWE-121,Critical Manufacturing; Energy; Water and Wastewater Systems; Chemical,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 4008,9/3/2026,9/3/2026,2026,ICSA-26-246-08,Tycon Systems TPDIN-Monitor-WEB3,Tycon Systems,Tycon Systems TPDIN-Monitor-WEB3,TPDIN-Monitor-WEB3 <=2.2.9,"CVE-2026-77847, CVE-2026-82712, CVE-2026-82684",8.8,High,"CWE-352, CWE-798, CWE-862",Critical Manufacturing; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 4007,9/1/2026,9/1/2026,2026,ICSA-26-244-01,Rockwell Automation RSLinx Classic,Rockwell Automation,Rockwell Automation RSLinx Classic,RSLinx Classic <=4.50,"CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625",8.6,High,"CWE-120, CWE-190, CWE-191",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 4006,9/1/2026,9/1/2026,2026,ICSA-26-244-02,Rockwell Automation Redundancy Module Configuration Tool,Rockwell Automation,Rockwell Automation Redundancy Module Configuration Tool,Redundancy Module Configuration Tool 10.00.00 | Redundancy Module Configuration Tool >=9.00.00|<=10.00.00,"CVE-2026-9633, CVE-2026-9634",7.3,High,CWE-276,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 4005,9/1/2026,9/1/2026,2026,ICSA-26-244-03,Rockwell Automation Logix Platform,Rockwell Automation,Rockwell Automation Logix Platform,"ControlLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 | CompactLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 | GuardLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 | Compact GuardLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012",CVE-2026-9637,7.5,High,CWE-119,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 4004,9/1/2026,9/1/2026,2026,ICSA-26-244-04,Rockwell Automation FactoryTalk Activation Manager,Rockwell Automation,Rockwell Automation FactoryTalk Activation Manager,FactoryTalk Activation Manager V5.02_and_below,CVE-2026-16675,7.8,High,CWE-307,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 4003,9/1/2026,9/1/2026,2026,ICSA-26-244-05,"Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix",Rockwell Automation,"Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix","ControlLogix 5580 <34.015, <35.014, <36.013, <37.011 | GuardLogix 5580 <34.015, <35.014, <36.013, <37.011 | CompactLogix 5380 <34.015, <35.014, <36.013, <37.011 | Compact GuardLogix 5380 <34.015, <35.014, <36.013, <37.011 | CompactLogix 5480 <34.015, <35.014, <36.013, <37.011",CVE-2021-42260,7.5,High,CWE-835,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 4002,9/1/2026,9/1/2026,2026,ICSA-26-244-06,Rockwell Automation Historian ME,Rockwell Automation,Rockwell Automation Historian ME,Series B 5.202 | Series C 7.101,"CVE-2025-12768, CVE-2026-12661",8.0,High,"CWE-121, CWE-787",Chemical; Critical Manufacturing; Food and Agriculture; Healthcare and Public Health; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 4001,8/27/2026,8/27/2026,2026,ICSA-26-239-01,Xiiaozet LK100W,Xiiaozet,Xiiaozet LK100W,LK100W <2.1.240,"CVE-2026-78037, CVE-2026-78239, CVE-2026-76943",9.8,Critical,"CWE-288, CWE-306, CWE-78",Information Technology,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 4000,8/27/2026,8/27/2026,2026,ICSA-26-239-02,All-Line Equipment Company Fuel-Boss,All-Line Equipment Company,All-Line Equipment Company Fuel-Boss,Fuel-Boss V1 Standard >=|<=PHP_7.1.5_7.1.5 | Fuel-Boss V1 Portal >=|<=PHP_7.1.5_7.1.5 | Fuel-Boss V1 Master/Slave >=|<=PHP_7.1.5_7.1.5 | Fuel-Boss V1 Backflush Systems >=|<=PHP_7.1.5_7.1.5,"CVE-2018-19518, CVE-2019-11043",8.7,High,"CWE-120, CWE-88",Critical Manufacturing; Defense Industrial Base; Emergency Services; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3999,8/27/2026,8/27/2026,2026,ICSA-26-239-03,Rockwell Automation OTTO Fleet Manager,Rockwell Automation,Rockwell Automation OTTO Fleet Manager,OTTO Fleet Manager <=V2.36.2,CVE-2026-75112,6.8,Medium,CWE-916,Critical Manufacturing; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3998,8/27/2026,8/27/2026,2026,ICSA-26-239-04,Applied Systems Engineering ASE2000 V2 Communications Test Set,Applied Systems Engineering,Applied Systems Engineering ASE2000 V2 Communications Test Set,ASE2000 >=2.25|<=2.37,"CVE-2018-1285, CVE-2026-18717",9.8,Critical,"CWE-295, CWE-611",Chemical; Critical Manufacturing; Energy; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3997,8/27/2026,8/27/2026,2026,ICSA-26-239-05,Ebyte NA111-M,Ebyte,Ebyte NA111-M,NA111-M Firmware 9013-2-17,"CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, CVE-2026-77977",9.8,Critical,"CWE-1021, CWE-1390, CWE-306, CWE-307, CWE-312, CWE-319, CWE-327, CWE-352, CWE-598, CWE-603, CWE-862",Information Technology,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3996,8/25/2026,8/25/2026,2026,ICSA-26-237-01,Rently Smart Home,Rently,Rently Smart Home,Rently Smart Home: <=20.1.0,CVE-2026-75960,8.1,High,CWE-522,Commercial Facilities; Communications; Information Technology,"United States, India",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3995,8/25/2026,8/25/2026,2026,ICSA-26-237-02,Zoneminder,Zoneminder,Zoneminder,Zoneminder Zoneminder: 1.37.48|1.38.3,CVE-2026-76060,8.8,High,CWE-78,Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3994,8/25/2026,8/25/2026,2026,ICSA-26-237-03,Siemens SIMATIC IoT2050 Advanced,Siemens,Siemens SIMATIC IoT2050 Advanced,SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) < V4.3.4.1 running Industrial OS with Node-RED installed,CVE-2026-58115,10.0,Critical,CWE-306,Chemical; Critical Manufacturing; Energy; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3993,8/25/2026,8/25/2026,2026,ICSA-26-237-04,PayRange API,PayRange,PayRange API,PayRange API: vers:all/*,CVE-2026-18965,8.8,High,CWE-862,Commercial Facilities,"United States, Canada",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3992,8/25/2026,8/25/2026,2026,ICSA-26-237-05,Bendix EC80 Brake ECU,Bendix,Bendix EC80 Brake ECU,"Bendix EC80ESP+ J1708: Z228999, Bendix EC80ESP+ 6S/6M: Z228999, Bendix EC80ESP+ PLC: Z228999, Bendix EC80ESP+ 2nd CAN: Z228999, Bendix EC80ESP+ Integrated TPMS: Z228999, Bendix EC80ESP 6S/6M: Z266494, Bendix EC80ESP PLC: Z266494, Bendix EC80ESP 2nd CAN: Z266494, Bendix EC80ESP CAN Gateway: Z266494, Bendix EC80ESP 4S/4M: Z286098, Bendix EC80ESP PLC: Z286098","CVE-2026-67560, CVE-2026-68967, CVE-2026-71396",7.5,High,"CWE-121, CWE-787, CWE-798",Transportation Systems,"United States, Canada",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3991,8/25/2026,8/25/2026,2026,ICSA-26-237-06,Ebyte NE2-D11,Ebyte,Ebyte NE2-D11,Ebyte NE2-D11 Firmware: FW-9167-0-11,"CVE-2026-73125, CVE-2026-73809, CVE-2026-73839, CVE-2026-71187, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-75548, CVE-2026-75813, CVE-2026-76945, CVE-2026-69658",9.8,Critical,"CWE-1021, CWE-306, CWE-307, CWE-319, CWE-352, CWE-522, CWE-598, CWE-603, CWE-862",Critical Manufacturing; Energy,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3990,8/25/2026,8/25/2026,2026,ICSA-26-237-07,FURUNO FA-50 Class B AIS Transponder,"FURUNO ELECTRIC CO.,LTD.",FURUNO FA-50 Class B AIS Transponder,FURUNO FA-50 Class B AIS Transponder: vers:all/*,"CVE-2026-59769, CVE-2026-67578",9.1,Critical,"CWE-306, CWE-798",Transportation Systems,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3989,8/20/2026,8/20/2026,2026,ICSA-26-232-01,Johnson Controls Simplex Incident Manager,Johnson Controls Inc.,Johnson Controls Simplex Incident Manager,Johnson Controls Simplex Incident Manager: <=V2.01,CVE-2026-27875,5.8,Medium,CWE-316,Critical Manufacturing; Commercial Facilities; Government Facilities; Transportation Systems; Energy,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3988,8/18/2026,8/18/2026,2026,ICSA-26-230-01,CISA Malcolm,CISA,CISA Malcolm,Malcolm <26.06.1 | Malcolm <26.07.0 | Malcolm <=26.07.1,"CVE-2026-63133, CVE-2026-63134, CVE-2026-55676, CVE-2026-63177, CVE-2026-19670, CVE-2026-19671",8.8,High,"CWE-22, CWE-409, CWE-434, CWE-770, CWE-863",Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3987,8/18/2026,8/18/2026,2026,ICSA-26-230-02,Siemens Simcenter Nastran,Siemens,Siemens Simcenter Nastran,"Simcenter Femap < V2606, Simcenter Nastran < V2606",CVE-2026-59086,7.8,High,CWE-121,Critical Manufacturing; Defense Industrial Base; Energy; Healthcare and Public Health; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3986,8/13/2026,8/13/2026,2026,ICSA-26-225-01,AVEVA Enterprise SCADA,AVEVA,AVEVA Enterprise SCADA,"AVEVA Enterprise SCADA: 2025, AVEVA Enterprise SCADA: >=2024|<=2024_SP1_P01, AVEVA Enterprise SCADA: >=2023|<=2023_SP1, AVEVA Enterprise SCADA: >=2022|<=2022_SP2_P2, AVEVA Enterprise SCADA: <=2021_SP2_P5, AVEVA Enterprise SCADA HMI: 2024|2024_R2, AVEVA Enterprise SCADA HMI: <=2023_P1",CVE-2025-7639,7.1,High,CWE-502,Critical Manufacturing,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3985,8/13/2026,8/13/2026,2026,ICSA-26-225-02,Haiwell IoT Cloud HMI Gateway,Haiwell,Haiwell IoT Cloud HMI Gateway,Haiwell Haiwell IoT Cloud HMI Gateway: 3.40.1.12,CVE-2026-19188,10.0,Critical,CWE-78,Energy; Critical Manufacturing; Water and Wastewater Systems,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3984,8/13/2026,8/13/2026,2026,ICSA-26-225-03,Johnson Controls Inc. Airwall,Johnson Controls Inc.,Johnson Controls Inc. Airwall,Johnson Controls Inc. Airwall: <=4.0.4,"CVE-2026-64887, CVE-2026-34492",6.8,Medium,"CWE-321, CWE-73",Critical Manufacturing; Commercial Facilities; Government Facilities; Transportation Systems; Energy,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3983,8/13/2026,8/13/2026,2026,ICSA-26-225-04,Hitachi Energy APM Edge Product,Hitachi Energy,Hitachi Energy APM Edge Product,APM Edge versions 6.10 and prior,"CVE-2026-43284, CVE-2026-43500",8.8,High,"CWE-123, CWE-787",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3982,8/13/2026,8/13/2026,2026,ICSA-26-225-05,ANDRITZ HIPASE-250 and 250 SCALA,ANDRITZ,ANDRITZ HIPASE-250 and 250 SCALA,"ANDRITZ HIPASE-250: <=7.20, ANDRITZ 250 SCALA: <=7.20","CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313",8.1,High,"CWE-257, CWE-306, CWE-798",Energy,Worldwide,Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3981,8/12/2026,8/12/2026,2026,ICSA-26-225-06,Siemens RUGGEDCOM APE1808,Siemens,Siemens RUGGEDCOM APE1808,RUGGEDCOM APE1808 with Fortinet NGFW,"CVE-2026-23573, CVE-2026-59839",6.1,Medium,"CWE-22, CWE-79",Critical Manufacturing; Energy; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3980,8/13/2026,8/13/2026,2026,ICSA-26-225-07,Siemens License Server (SLS),Siemens,Siemens License Server (SLS),Siemens License Server (SLS) < V5.1,"CVE-2026-69108, CVE-2026-69109",7.5,High,"CWE-35, CWE-732",Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3979,8/13/2026,8/13/2026,2026,ICSA-26-225-08,Siemens Desigo DXR and PXC Controllers,Siemens,Siemens Desigo DXR and PXC Controllers,"Desigo DXR2 < V01.21.233.16-7862, Desigo PXC3 < V01.21.233.16-7862, Desigo PXC4 < V02.21.194.36-2715, Desigo PXC5.E003 < V02.21.194.36-2715, Desigo PXC5.E24 < V02.21.194.36-2715, Desigo PXC7 < V02.21.194.36-2715",CVE-2026-59693,4.3,Medium,CWE-754,Commercial Facilities; Critical Manufacturing; Energy; Healthcare and Public Health; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3978,8/13/2026,8/13/2026,2026,ICSA-26-225-09,Siemens Siveillance Video,Siemens,Siemens Siveillance Video,"Siveillance Video V2023 R3 < V23.3.27, Siveillance Video V2024 R1 < V24.1.16, Siveillance Video V2025 < V25.1.15",CVE-2026-3014,9.1,Critical,CWE-78,Critical Manufacturing; Communications; Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3977,8/13/2026,8/13/2026,2026,ICSA-26-225-10,Siemens Parasolid,Siemens,Siemens Parasolid,"Parasolid V38.0 < V38.0.235, Parasolid V38.1 < V38.1.230",CVE-2026-64629,7.8,High,CWE-125,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3976,8/13/2026,8/13/2026,2026,ICSA-26-225-11,Siemens Simcenter Femap,Siemens,Siemens Simcenter Femap,Simcenter Femap < V2606.0001,"CVE-2026-59700, CVE-2026-59701",7.8,High,CWE-125,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3975,8/13/2026,8/13/2026,2026,ICSA-26-225-12,Siemens Solid Edge,Siemens,Siemens Solid Edge,"Solid Edge SE2025 < V225.0.15, Solid Edge SE2026 < V226.0.7","CVE-2026-50058, CVE-2026-50059, CVE-2026-50060, CVE-2026-50061, CVE-2026-50062, CVE-2026-50063, CVE-2026-50064",7.8,High,"CWE-125, CWE-416, CWE-787",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3974,8/13/2026,8/13/2026,2026,ICSA-26-225-13,Siemens LOGO! Soft Comfort,Siemens,Siemens LOGO! Soft Comfort,LOGO! Soft Comfort < V9,"CVE-2026-57262, CVE-2026-57263",6.8,Medium,"CWE-321, CWE-759",Commercial Facilities; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3973,8/13/2026,8/13/2026,2026,ICSA-26-225-14,Johnson Controls Metasys,Johnson Controls Inc.,Johnson Controls Metasys,"Johnson Controls Inc Metasys 12: vers:all/*, Johnson Controls Inc Metasys 13: vers:all/*, Johnson Controls Inc Metasys 14: =V36|<=V37 | CompactLogix 5380 >=V36|<=V37 | GuardLogix 5580 >=V36|<=V37 | Compact GuardLogix 5380 >=V36|<=V37 | 1756-EN4TR V6.001 | 1756-EN4TR V7.001,CVE-2026-9636,5.9,Medium,CWE-299,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3958,7/30/2026,7/30/2026,2026,ICSA-26-211-06,NASA Core Flight System (cFS) Health & Safety (HS) Application,NASA,NASA Core Flight System (cFS) Health & Safety (HS) Application,Core Flight System (cFS) Health & Safety (HS) Application <=v7.0.1,CVE-2026-18064,7.5,High,CWE-476,Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3957,7/30/2026,7/30/2026,2026,ICSA-26-211-07,Mitsubishi Electric CC-Link IE TSN Communication Protocol,Mitsubishi Electric,Mitsubishi Electric CC-Link IE TSN Communication Protocol,Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-16 | Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-32 | Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-64 | Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-128 | Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-256 | Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-N32 | Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-P32 | Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-N32 | Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-P32 | Mitsubishi Electric Master/local module RJ71GN11-T2 | Mitsubishi Electric Master/local module RJ71GN11-SX | Mitsubishi Electric Master/local module RJ71GN11-EIP | Mitsubishi Electric Master/local module FX5-CCLGN-MS | Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-SX | Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-T2 | Mitsubishi Electric Motion module RD78G4 | Mitsubishi Electric Motion module RD78G8 | Mitsubishi Electric Motion module RD78G16 | Mitsubishi Electric Motion module RD78G64 | Mitsubishi Electric Motion module RD78GHV | Mitsubishi Electric Motion module RD78GHW | Mitsubishi Electric Motion module FX5-40SSC-G | Mitsubishi Electric Motion module FX5-80SSC-G | Mitsubishi Electric Motion Control Board MR-EM441G | Mitsubishi Electric Block-type remote module NZ2GN2S1-32D | Mitsubishi Electric Block-type remote module NZ2GN2S1-32T | Mitsubishi Electric Block-type remote module NZ2GN2S1-32TE | Mitsubishi Electric Block-type remote module NZ2GN2S1-32DT | Mitsubishi Electric Block-type remote module NZ2GN2S1-32DTE | Mitsubishi Electric Block-type remote module NZ2GN2B1-32D | Mitsubishi Electric Block-type remote module NZ2GN2B1-32T | Mitsubishi Electric Block-type remote module NZ2GN2B1-32TE | Mitsubishi Electric Block-type remote module NZ2GN2B1-32DT | Mitsubishi Electric Block-type remote module NZ2GN2B1-32DTE | Mitsubishi Electric Block-type remote module NZ2GNCF1-32D | Mitsubishi Electric Block-type remote module NZ2GNCF1-32T | Mitsubishi Electric Block-type remote module NZ2GNCE3-32D | Mitsubishi Electric Block-type remote module NZ2GNCE3-32DT | Mitsubishi Electric Block-type remote module NZ2GN12A4-16D | Mitsubishi Electric Block-type remote module NZ2GN12A4-16DE | Mitsubishi Electric Block-type remote module NZ2GN12A2-16T | Mitsubishi Electric Block-type remote module NZ2GN12A2-16TE | Mitsubishi Electric Block-type remote module NZ2GN12A42-16DT | Mitsubishi Electric Block-type remote module NZ2GN12A42-16DTE | Mitsubishi Electric Block-type remote module NZ2GN2S1-16D | Mitsubishi Electric Block-type remote module NZ2GN2S1-16T | Mitsubishi Electric Block-type remote module NZ2GN2S1-16TE | Mitsubishi Electric Block-type remote module NZ2GN2B1-16D | Mitsubishi Electric Block-type remote module NZ2GN2B1-16T | Mitsubishi Electric Block-type remote module NZ2GN2B1-16TE | Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8D | Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8D-K | Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8TE | Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-8TE-K | Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-16DTE | Mitsubishi Electric Block-type remote module with safety functions NZ2GNSS2-16DTE-K | Mitsubishi Electric Block-type remote module with safety functions NZ2GNS12A2-14DT | Mitsubishi Electric Block-type remote module with safety functions NZ2GNS12A2-16DTE | Mitsubishi Electric Analog-Digital converter module NZ2GN2S-60AD4 | Mitsubishi Electric Analog-Digital converter module NZ2GN2B-60AD4 | Mitsubishi Electric Digital-Analog converter module NZ2GN2S-60DA4 | Mitsubishi Electric Digital-Analog converter module NZ2GN2B-60DA4 | Mitsubishi Electric CC-Link IE TSN compatible coupler NZ2FT-GN | Mitsubishi Electric FPGA module NZ2GN2S-D41P01 | Mitsubishi Electric FPGA module NZ2GN2S-D41D01 | Mitsubishi Electric FPGA module NZ2GN2S-D41PD02 | Mitsubishi Electric Tension meter LM7-1LG | Mitsubishi Electric Tension meter LM7-2LG | Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G | Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5W-G | Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-HS | Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-RJ | Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5-G-LL | Mitsubishi Electric AC Servo MELSERVO-J5 MR-J5D-G4 | Mitsubishi Electric AC Servo MELSERVO-J5 MR-MD333G | Mitsubishi Electric AC Servo MELSERVO-JET MR-JET-G | Mitsubishi Electric AC Servo MELSERVO-JET MR-JET-G4-HS | Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A8NCG | Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A8NCG-S | Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-A800-GN | Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-E800-E | Mitsubishi Electric Inverter FR-A800/F800/E800 Series FR-E800-SCE | Mitsubishi Electric Industrial Robot CR800-D series controller Network Base Card 2F-DQ535-TSN | Mitsubishi Electric CC-Link IE TSN expansion unit FCU8-EX569 | Mitsubishi Electric CC-Link IE TSN-CC-Link IE Field Network bridge module NZ2GN-GFB | Mitsubishi Electric CC-Link IE TSN-AnyWireASLINK bridge module NZ2AW1GNAL | Mitsubishi Electric Energy Measuring Unit CC-Link IE TSN Communication Unit EMU4-CM-TSN | Mitsubishi Electric Industrial Computer MELIPC series MI2532-W | Mitsubishi Electric Industrial Computer MELIPC series MI2332-W | Mitsubishi Electric GOT3000 Series GT3715-FHCBD | Mitsubishi Electric GOT3000 Series GT3712-WXCBD | Mitsubishi Electric GOT3000 Series GT3715-XRBA | Mitsubishi Electric GOT3000 Series GT3715-XRBD | Mitsubishi Electric GOT3000 Series GT3712-XRBA | Mitsubishi Electric GOT3000 Series GT3712-XRBD | Mitsubishi Electric GOT3000 Series GT3710-XRBA | Mitsubishi Electric GOT3000 Series GT3710-XRBD | Mitsubishi Electric GOT3000 Series GT3708-XRBA | Mitsubishi Electric GOT3000 Series GT3708-XRBD | Mitsubishi Electric CC-Link IE TSN Communication Unit GT25-J71GN13-T2 | Mitsubishi Electric Motion Control Software SWM-G | Mitsubishi Electric Motion Control Software SWM-G-N1 | Mitsubishi Electric CC-Link IE TSN Communication Software for Windows SW1DND-CCIETCT-M | Mitsubishi Electric Master/Local module Designated communication LSI DeviceKit NZ2KT-NPETNG51 | Mitsubishi Electric Master/Local module Designated communication LSI NZ2GACP610-60 | Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP620-60 | Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP620-300 | Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP621-90 | Mitsubishi Electric Remote Station Communication LSI with GbE-PHY NZ2GACP621-720 | Mitsubishi Electric CC-Link IE TSN Master/Local module Designated communication LSI SDK SW1DNN-GN610SRC-M | Mitsubishi Electric Remote station software development kit SW1DNC-GNSDK1S-M | Mitsubishi Electric Remote station software development kit SW1DNC-GNSDK2S-M | Mitsubishi Electric Liner Track System MTR-S series Linear track control module MTR-SCU00-4G | Mitsubishi Electric Liner Track System MTR-S series Linear track control module MTR-SCU00-PG | Mitsubishi Electric Analysis Support Software MELSOFT VIMA SW1DNN-VIMA-M,CVE-2026-13584,7.1,High,CWE-924,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3956,7/30/2026,7/30/2026,2026,ICSA-26-211-08,o6 Automation open62541,o6 Automation GmbH,o6 Automation open62541,open62541 on Windows and Linux >=from_1.3.0|<=1.3.17 | open62541 on Windows and Linux >=from_1.4.0|<=1.4.16 | open62541 on Windows and Linux >=from_1.5.0|<=1.5.4 | open62541 on Windows and Linux master,"CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559",8.8,High,"CWE-190, CWE-191, CWE-416",Critical Manufacturing; Energy; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3955,7/30/2026,7/30/2026,2026,ICSA-26-211-09,Watchfire Controller Software,Watchfire,Watchfire Controller Software,BC550 12.30 | BC750 11.33|12.35 | BC760 12.38|13.00 | BC760DC 12.39,CVE-2026-5846,5.7,Medium,CWE-321,Commercial Facilities; Critical Manufacturing; Healthcare and Public Health; Financial Services,"United States, Dominican Republic, Canada, Peru, El Salvador",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3954,7/30/2026,7/30/2026,2026,ICSA-26-211-10,MZ Automation GmbH libiec61850,MZ Automation GmbH,MZ Automation GmbH libiec61850,libiec61850 <1.6.2,"CVE-2026-66720, CVE-2026-66369, CVE-2026-63550, CVE-2026-65421, CVE-2026-66364, CVE-2026-66349, CVE-2026-56758, CVE-2026-66360",7.5,High,CWE-125,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3953,7/30/2026,7/30/2026,2026,ICSA-26-211-11,MZ Automation lib60870,MZ Automation GmbH,MZ Automation lib60870,lib60870 2.4.0,"CVE-2026-61893, CVE-2026-63033",6.5,Medium,CWE-125,Energy; Water and Wastewater Systems; Critical Manufacturing; Chemical,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3952,7/28/2026,7/28/2026,2026,ICSA-26-209-01,Siemens Desigo CC,Siemens,Siemens Desigo CC,"Desigo CC family V7, Desigo CC family V8, Desigo CC family V9 < V9.0.1",CVE-2025-15467,9.8,Critical,CWE-787,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3951,7/28/2026,7/28/2026,2026,ICSA-26-209-02,Siemens Mendix Runtime,Siemens,Siemens Mendix Runtime,Mendix Runtime,CVE-2026-7891,9.1,Critical,CWE-277,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3950,7/28/2026,7/28/2026,2026,ICSA-26-209-03,Siemens SIMATIC S7-PLCSIM Advanced,Siemens,Siemens SIMATIC S7-PLCSIM Advanced,SIMATIC S7-PLCSIM Advanced,CVE-2026-54429,7.4,High,CWE-770,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3949,7/28/2026,7/28/2026,2026,ICSA-26-209-04,Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP,Siemens,Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP,"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) >= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) >= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) >= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) >= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) >= V3.1.6","CVE-2021-41617, CVE-2023-28531, CVE-2023-51384, CVE-2023-52927, CVE-2024-26783, CVE-2024-27056, CVE-2024-28956, CVE-2024-36903, CVE-2024-36927, CVE-2024-42079, CVE-2024-46786, CVE-2024-47736, CVE-2024-47809, CVE-2024-49968, CVE-2024-49994, CVE-2024-49998, CVE-2024-50014, CVE-2024-50063, CVE-2024-50164, CVE-2024-50298, CVE-2024-53124, CVE-2024-53170, CVE-2024-54458, CVE-2024-56631, CVE-2024-56703, CVE-2024-56719, CVE-2024-57917, CVE-2024-57924, CVE-2024-57973, CVE-2024-57977, CVE-2024-57979, CVE-2024-58011, CVE-2024-58016, CVE-2024-58020, CVE-2024-58056, CVE-2024-58058, CVE-2024-58061, CVE-2024-58086, CVE-2025-21645, CVE-2025-21648, CVE-2025-21655, CVE-2025-21676, CVE-2025-21682, CVE-2025-21702, CVE-2025-21705, CVE-2025-21706, CVE-2025-21707, CVE-2025-21718, CVE-2025-21731, CVE-2025-21745, CVE-2025-21758, CVE-2025-21760, CVE-2025-21764, CVE-2025-21765, CVE-2025-21780, CVE-2025-21795, CVE-2025-21796, CVE-2025-21802, CVE-2025-21814, CVE-2025-21846, CVE-2025-21853, CVE-2025-21861, CVE-2025-21864, CVE-2025-21867, CVE-2025-21875, CVE-2025-21887, CVE-2025-21913, CVE-2025-21919, CVE-2025-21925, CVE-2025-21926, CVE-2025-21938, CVE-2025-21959, CVE-2025-21999, CVE-2025-22005, CVE-2025-22015, CVE-2025-22055, CVE-2025-22056, CVE-2025-22060, CVE-2025-22083, CVE-2025-22090, CVE-2025-22095, CVE-2025-22107, CVE-2025-22111, CVE-2025-22121, CVE-2025-23136, CVE-2025-23143, CVE-2025-37785, CVE-2025-37909, CVE-2025-37917, CVE-2025-37945, CVE-2025-37959, CVE-2025-37964, CVE-2025-37972, CVE-2025-37980, CVE-2025-38125, CVE-2025-38162, CVE-2025-38192, CVE-2025-38201, CVE-2025-38232, CVE-2025-38322, CVE-2025-38591, CVE-2025-38614, CVE-2025-38681, CVE-2025-38704, CVE-2025-38721, CVE-2025-38725, CVE-2025-38727, CVE-2025-38732, CVE-2025-38736, CVE-2025-39681, CVE-2025-39691, CVE-2025-39721, CVE-2025-39748, CVE-2025-39756, CVE-2025-39764, CVE-2025-39770, CVE-2025-39773, CVE-2025-39782, CVE-2025-39795, CVE-2025-39826, CVE-2025-39827, CVE-2025-39845, CVE-2025-39866, CVE-2025-39871, CVE-2025-39931, CVE-2025-39953, CVE-2025-39955, CVE-2025-39964, CVE-2025-39977, CVE-2025-39978, CVE-2025-39980, CVE-2025-40022, CVE-2025-40070, CVE-2025-40078, CVE-2025-40080, CVE-2025-40105, CVE-2025-40135, CVE-2025-40149, CVE-2025-40219, CVE-2025-40261, CVE-2025-40300, CVE-2025-61984, CVE-2025-61985, CVE-2025-68206, CVE-2025-68261, CVE-2025-68264, CVE-2025-68265, CVE-2025-68266, CVE-2025-68291, CVE-2025-68337, CVE-2025-68349, CVE-2025-68363, CVE-2025-68371, CVE-2025-68724, CVE-2025-68725, CVE-2025-68742, CVE-2025-68764, CVE-2025-68773, CVE-2025-68776, CVE-2025-68782, CVE-2025-68787, CVE-2025-68788, CVE-2025-68798, CVE-2025-68803, CVE-2025-68814, CVE-2025-68816, CVE-2025-68818, CVE-2025-68820, CVE-2025-71064, CVE-2025-71075, CVE-2025-71079, CVE-2025-71085, CVE-2025-71086, CVE-2025-71088, CVE-2025-71095, CVE-2025-71097, CVE-2025-71098, CVE-2025-71104, CVE-2025-71112, CVE-2025-71113, CVE-2025-71114, CVE-2025-71120, CVE-2025-71123, CVE-2025-71131, CVE-2025-71161, CVE-2025-71162, CVE-2025-71163, CVE-2025-71185, CVE-2025-71186, CVE-2025-71189, CVE-2025-71190, CVE-2025-71191, CVE-2025-71197, CVE-2025-71221, CVE-2025-71265, CVE-2025-71266, CVE-2025-71267, CVE-2026-3497, CVE-2026-22977, CVE-2026-22979, CVE-2026-22980, CVE-2026-22982, CVE-2026-22992, CVE-2026-22994, CVE-2026-23003, CVE-2026-23005, CVE-2026-23010, CVE-2026-23011, CVE-2026-23019, CVE-2026-23026, CVE-2026-23038, CVE-2026-23054, CVE-2026-23060, CVE-2026-23083, CVE-2026-23084, CVE-2026-23086, CVE-2026-23087, CVE-2026-23095, CVE-2026-23100, CVE-2026-23103, CVE-2026-23110, CVE-2026-23111, CVE-2026-23113, CVE-2026-23154, CVE-2026-23204, CVE-2026-23231, CVE-2026-23242, CVE-2026-23243, CVE-2026-23245, CVE-2026-23270, CVE-2026-23271, CVE-2026-23273, CVE-2026-23274, CVE-2026-23277, CVE-2026-23284, CVE-2026-23287, CVE-2026-23290, CVE-2026-23293, CVE-2026-23300, CVE-2026-23304, CVE-2026-23319, CVE-2026-23321, CVE-2026-23335, CVE-2026-23340, CVE-2026-23343, CVE-2026-23351, CVE-2026-23359, CVE-2026-23365, CVE-2026-23368, CVE-2026-23370, CVE-2026-23378, CVE-2026-23379, CVE-2026-23381, CVE-2026-23391, CVE-2026-23392, CVE-2026-23397, CVE-2026-23398, CVE-2026-23414, CVE-2026-23422, CVE-2026-23434, CVE-2026-23438, CVE-2026-23439, CVE-2026-23446, CVE-2026-23449, CVE-2026-23450, CVE-2026-23452, CVE-2026-23454, CVE-2026-23455, CVE-2026-23456, CVE-2026-23457, CVE-2026-23458, CVE-2026-23463, CVE-2026-23474, CVE-2026-23475, CVE-2026-27135, CVE-2026-31389, CVE-2026-31391, CVE-2026-31396, CVE-2026-31402, CVE-2026-31403, CVE-2026-31411, CVE-2026-31414, CVE-2026-31415, CVE-2026-31416, CVE-2026-31417, CVE-2026-31418, CVE-2026-31421, CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31427, CVE-2026-31428, CVE-2026-31431, CVE-2026-31441, CVE-2026-31446, CVE-2026-31447, CVE-2026-31448, CVE-2026-31450, CVE-2026-31452, CVE-2026-31466, CVE-2026-31469, CVE-2026-31485, CVE-2026-31494, CVE-2026-31495, CVE-2026-31496, CVE-2026-31503, CVE-2026-31504, CVE-2026-31507, CVE-2026-31508, CVE-2026-31515, CVE-2026-31518, CVE-2026-31521, CVE-2026-31533, CVE-2026-31546, CVE-2026-31555, CVE-2026-31563, CVE-2026-31565, CVE-2026-31628, CVE-2026-31634, CVE-2026-31649, CVE-2026-31651, CVE-2026-31658, CVE-2026-31664, CVE-2026-31665, CVE-2026-31669, CVE-2026-31670, CVE-2026-31671, CVE-2026-31674, CVE-2026-31680, CVE-2026-31682, CVE-2026-31737, CVE-2026-31752, CVE-2026-31761, CVE-2026-31768, CVE-2026-40355, CVE-2026-41989, CVE-2026-43011, CVE-2026-43024, CVE-2026-43025, CVE-2026-43026, CVE-2026-43027, CVE-2026-43028, CVE-2026-43030, CVE-2026-43033, CVE-2026-43035, CVE-2026-43038, CVE-2026-43040, CVE-2026-43057, CVE-2026-43284, CVE-2026-46174, CVE-2026-46300, CVE-2026-46333",9.8,Critical,"CWE-115, CWE-120, CWE-123, CWE-124, CWE-125, CWE-1285, CWE-1287, CWE-130, CWE-131, CWE-134, CWE-1341, CWE-1421, CWE-158, CWE-159, CWE-166, CWE-170, CWE-190, CWE-20, CWE-213, CWE-237, CWE-252, CWE-256, CWE-266, CWE-269, CWE-304, CWE-311, CWE-358, CWE-360, CWE-362, CWE-364, CWE-366, CWE-367, CWE-369, CWE-372, CWE-392, CWE-401, CWE-402, CWE-404, CWE-413, CWE-416, CWE-457, CWE-459, CWE-476, CWE-478, CWE-489, CWE-573, CWE-617, CWE-667, CWE-669, CWE-672, CWE-674, CWE-681, CWE-704, CWE-763, CWE-772, CWE-787, CWE-789, CWE-805, CWE-820, CWE-821, CWE-822, CWE-824, CWE-825, CWE-833, CWE-835, CWE-841, CWE-843, CWE-908, CWE-909, CWE-911",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3948,7/28/2026,7/28/2026,2026,ICSA-26-209-05,MikroTik RouterOS and Cloud Hosted Router,MikroTik,MikroTik RouterOS and Cloud Hosted Router,"MikroTik RouterOS: vers:all/*, MikroTik Cloud Hosted Router: vers:all/*",CVE-2026-16347,8.8,High,CWE-307,Information Technology; Commercial Facilities,Worldwide,Latvia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3947,7/28/2026,7/28/2026,2026,ICSA-26-209-06,igloohome Smart Lock Mobile Application,igloohome,igloohome Smart Lock Mobile Application,igloohome Smart Lock Mobile Application (Android): 3.2.3,CVE-2026-16581,5.3,Medium,CWE-540,Commercial Facilities,Worldwide,Singapore,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3946,7/28/2026,7/28/2026,2026,ICSA-26-209-07,ABB KNX Update Tool,ABB,ABB KNX Update Tool,"KNX Update Tool (ABB) <=2.0.175, KNX Update Tool (BJE) <=2.0.175",CVE-2026-12705,6.4,Medium,CWE-353,Critical Manufacturing,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3945,7/23/2026,8/11/2026,2026,ICSA-26-204-01,Johnson Controls C-CURE 9000 and Victor application server (Update A),Johnson Controls Inc.,Johnson Controls C-CURE 9000 and Victor application server,C-CURE 9000 <=v3.10.1 | victor Application Server <=v4.10 | victor <=v7.0 | victor Web | victor Web <=v7.1,"CVE-2026-21655, CVE-2026-21653, CVE-2026-34496",9.6,Critical,"CWE-250, CWE-918",Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3944,7/23/2026,7/23/2026,2026,ICSA-26-204-02,Johnson Controls XAAP Android,Johnson Controls Inc.,Johnson Controls XAAP Android,XAAP Android <1.53,CVE-2026-34490,3.3,Low,CWE-312,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3943,7/23/2026,7/23/2026,2026,ICSA-26-204-03,Weintek cMT3092X,Weintek,Weintek cMT3092X,cMT3092X firmware <20210218 | EasyWeb =13.0.0|<13.0.7, >=13.1.0|<13.1.5, >=13.2.0|<13.2.4, >=14.0.0|<14.0.2",CVE-2026-11917,8.1,High,CWE-22,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3940,7/23/2026,7/23/2026,2026,ICSA-26-204-06,MZ Automation libIEC61850,MZ Automation GmbH,MZ Automation libIEC61850,libIEC61850 >=v1.0.0|<=v1.6.1,"CVE-2026-50039, CVE-2026-49035, CVE-2026-50103, CVE-2026-50032",8.1,High,"CWE-121, CWE-122, CWE-228, CWE-476",Critical Manufacturing; Energy; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3939,7/23/2026,7/23/2026,2026,ICSA-26-204-07,MZ Automation lib60870,MZ Automation GmbH,MZ Automation lib60870,lib60870 <=2.4.0,CVE-2026-16002,8.2,High,CWE-125,Chemical; Energy; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3938,7/21/2026,9/3/2026,2026,ICSA-26-202-01,Tycon Systems TPDIN-Monitor-WEB2 (Update A),Tycon Systems,Tycon Systems TPDIN-Monitor-WEB2 (Update A),TPDIN-Monitor-WEB2 <2.4.5,"CVE-2026-61884, CVE-2026-55985",9.8,Critical,"CWE-306, CWE-312",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3937,7/21/2026,7/21/2026,2026,ICSA-26-202-02,Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW,Siemens,Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW,RUGGEDCOM APE1808,"CVE-2026-0266, CVE-2026-0272, CVE-2026-0273",7.2,High,"CWE-78, CWE-79, CWE-862",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3936,7/21/2026,7/21/2026,2026,ICSA-26-202-03,Siemens Opcenter X,Siemens,Siemens Opcenter X,Opcenter X,CVE-2026-56451,10.0,Critical,CWE-347,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3935,7/21/2026,7/21/2026,2026,ICSA-26-202-04,Siemens SIDIS Secured SmartPlug,Siemens,Siemens SIDIS Secured SmartPlug,SIDIS Secured SmartPlug,"CVE-2022-23303, CVE-2022-23304, CVE-2022-37660, CVE-2022-48174, CVE-2025-5222, CVE-2025-5914, CVE-2025-9230, CVE-2025-9231, CVE-2025-9232, CVE-2025-26465, CVE-2025-32462, CVE-2026-5121",9.8,Critical,"CWE-120, CWE-125, CWE-190, CWE-323, CWE-385, CWE-390, CWE-787, CWE-863, CWE-924",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3934,7/21/2026,7/21/2026,2026,ICSA-26-202-05,Siemens IAM Client,Siemens,Siemens IAM Client,COMOS V10.4.5 | COMOS V10.6 | Designcenter NX | Simcenter 3D | Simcenter Femap V2506 | Simcenter Femap V2512 | Simcenter Nastran | Simcenter STAR-CCM+ | Solid Edge SE2025 | Solid Edge SE2026 | Teamcenter Visualization V2412 | Teamcenter Visualization V2506 | Teamcenter Visualization V2512 | Tecnomatix Plant Simulation V2404 | Tecnomatix Plant Simulation V2504 | Tecnomatix Process Simulate,CVE-2025-40945,6.7,Medium,CWE-426,Chemical; Critical Manufacturing; Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3933,7/21/2026,7/21/2026,2026,ICSA-26-202-06,Siemens CADRA,Siemens,Siemens CADRA,CADRA,"CVE-2005-2096, CVE-2016-9840, CVE-2016-9841, CVE-2016-9842, CVE-2017-14919, CVE-2018-25032, CVE-2022-37434, CVE-2023-45853, CVE-2025-10585, CVE-2025-13223, CVE-2026-22184",9.8,Critical,"CWE-120, CWE-1335, CWE-190, CWE-20, CWE-787, CWE-843",Chemical; Commercial Facilities; Communications; Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3932,7/21/2026,7/21/2026,2026,ICSA-26-202-07,Rockwell Automation FactoryTalk Services Platform,Rockwell Automation,Rockwell Automation FactoryTalk Services Platform,FactoryTalk Directory (FTSP) 6.60,CVE-2026-10714,7.8,High,CWE-1390,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3931,7/21/2026,7/21/2026,2026,ICSA-26-202-08,Rockwell Automation 1718-AENTR/1719-AENTR,Rockwell Automation,Rockwell Automation 1718-AENTR/1719-AENTR,1718/ 1719 Ex I/O 3.011,CVE-2026-9140,7.5,High,CWE-770,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3930,7/21/2026,9/1/2026,2026,ICSA-26-202-09,Rockwell Automation 1734 POINT I/O (Update A),Rockwell Automation,Rockwell Automation 1734 POINT I/O (Update A),1734 POINT I/O 3.023,CVE-2026-10573,3.7,Low,CWE-770,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3929,7/21/2026,7/21/2026,2026,ICSA-26-202-10,Rockwell Automation Studio 5000 Logix Designer,Rockwell Automation,Rockwell Automation Studio 5000 Logix Designer,Studio 5000 Logix Designer V36.00 | Studio 5000 Logix Designer V35.00 | Studio 5000 Logix Designer V35.01 | Studio 5000 Logix Designer >=V34.00|<=V34.03 | Studio 5000 Logix Designer >=V33.00|<=V33.03 | Studio 5000 Logix Designer >=V32.00|<=V32.04 | Studio 5000 Logix Designer V34.00 | Studio 5000 Logix Designer V34.01 | Studio 5000 Logix Designer V33.00 | Studio 5000 Logix Designer V33.02 | Studio 5000 Logix Designer >=V34.00|<=V34.02 | Studio 5000 Logix Designer >=V33.00|<=V33.02,"CVE-2026-9108, CVE-2026-9127, CVE-2026-9128",7.5,High,"CWE-22, CWE-428, CWE-863",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3928,7/16/2026,7/16/2026,2026,ICSA-26-197-01,Rockwell Automation Arena,Rockwell Automation,Rockwell Automation Arena,Arena <=V17.00.00,"CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314",7.8,High,CWE-787,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3927,7/16/2026,7/16/2026,2026,ICSA-26-197-02,"Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT",Rockwell Automation,"Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT",1756-EN3 <=V12.001 | 1756-EN2 <=V12.001 | 1756-ENBT V6.006,CVE-2026-9653,7.5,High,CWE-354,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3926,7/16/2026,7/16/2026,2026,ICSA-26-197-03,NASA Core Flight System (cFS) Health & Safety (HS) Application,NASA,NASA Core Flight System (cFS) Health & Safety (HS) Application,Core Flight System (cFS) Health & Safety (HS) Application,CVE-2026-15352,7.5,High,CWE-476,Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3925,7/16/2026,7/16/2026,2026,ICSA-26-197-04,AutomationDirect Productivity Suite,AutomationDirect,AutomationDirect Productivity Suite,Productivity Suite <=v4.6.2.2,"CVE-2026-60063, CVE-2026-61389, CVE-2026-60140, CVE-2026-57896, CVE-2026-60073, CVE-2026-61378",7.0,High,"CWE-125, CWE-369, CWE-787",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3924,7/16/2026,7/16/2026,2026,ICSA-26-197-05,Siemens SICAM 8,Siemens,Siemens SICAM 8,CPCI85 Central Processing/Communication | SICORE Base system,"CVE-2026-54798, CVE-2026-54799, CVE-2026-54800, CVE-2026-54801",7.2,High,"CWE-1188, CWE-489, CWE-620",Critical Manufacturing; Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3923,7/16/2026,7/16/2026,2026,ICSA-26-197-06,"Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix",Rockwell Automation,"Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix",CompactLogix 5370 <=V35.015 | Compact GuardLogix 5370 <=V35.015 | ControlLogix 5570 <=V35.015 | GuardLogix 5570 <=V35.015 | CompactLogix 5380 <=V34.012 | CompactLogix 5380 <=V35.011 | Compact GuardLogix 5380 <=V34.012 | Compact GuardLogix 5380 <=V35.011 | CompactLogix 5480 <=V34.012 | CompactLogix 5480 <=V35.011 | ControlLogix 5580 <=V34.012 | ControlLogix 5580 <=V35.011 | GuardLogix 5580 <=V34.012 | GuardLogix 5580 <=V35.011 | CompactLogix 5380 Recovery Image <=1.072 | Compact GuardLogix 5380 Recovery Image <=1.072 | CompactLogix 5480 Recovery Image <=1.072 | ControlLogix 5580 Recovery Image <=1.072 | GuardLogix 5580 Recovery Image <=1.072,"CVE-2025-12011, CVE-2025-12012, CVE-2025-11698",8.6,High,CWE-120,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3922,7/16/2026,7/16/2026,2026,ICSA-26-197-07,SALTO ProAccess Space,SALTO,SALTO ProAccess Space,ProAccess Space <6.13,CVE-2026-11889,6.5,Medium,CWE-639,Commercial Facilities; Critical Manufacturing,Worldwide,Spain,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3921,7/16/2026,7/16/2026,2026,ICSA-26-197-08,Rockwell Automation Flex 5000 Adapter,Rockwell Automation,Rockwell Automation Flex 5000 Adapter,Flex 5000 Adapter 6.011,CVE-2026-12659,7.5,High,CWE-415,Critical Manufacturing; Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3920,7/16/2026,7/16/2026,2026,ICSA-26-197-09,Rockwell Automation FactoryTalk DataMosaix,Rockwell Automation,Rockwell Automation FactoryTalk DataMosaix,DataMosaix Private Cloud <=8.02,CVE-2026-9292,6.1,Medium,CWE-79,Critical Manufacturing; Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3919,7/14/2026,7/14/2026,2026,ICSA-26-195-01,ABB Advant Master Online Builder,ABB,ABB Advant Master Online Builder,"Control Builder A <=1.4/4 | 800xA for Advant Master <=6.0.3-1, <=6.1.1-1, 6.1.1-3, 6.2.0-1",CVE-2025-13162,4.4,Medium,CWE-427,Critical Manufacturing,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3918,7/14/2026,7/14/2026,2026,ICSA-26-195-02,ABB Ability Edgenius,ABB,ABB Ability Edgenius,"Ability Edgenius >=3.2.0.0|<3.2.4.1 installed on ABB Ability Edgenius Gateway - bE100, >=3.2.0.0|<3.2.4.1 installed on ABB Ability Edgenius Gateway - E3100C, >=3.2.0.0|<3.2.4.1 installed on ABB Ability Edgenius Server - vE1000",CVE-2026-31431,7.8,High,CWE-669,Critical Manufacturing,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3917,7/14/2026,7/14/2026,2026,ICSA-26-195-03,ABB T-MAC Plus,ABB,ABB T-MAC Plus,T-MAC Plus 4.0-24,"CVE-2025-14771, CVE-2025-14772, CVE-2025-14773, CVE-2025-14774",9.9,Critical,"CWE-552, CWE-639, CWE-79, CWE-863",Critical Manufacturing,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3916,7/14/2026,7/14/2026,2026,ICSA-26-195-04,Rockwell Automation 1715-AENTR EtherNet/IP Adapter,Rockwell Automation,Rockwell Automation 1715-AENTR EtherNet/IP Adapter,1715-AENTR EtherNet/IP Adapter <=3.003,CVE-2026-10577,10.0,Critical,CWE-306,Energy; Water and Wastewater Systems; Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3915,7/9/2026,7/9/2026,2026,ICSA-26-190-01,OpenPLC v3,OpenPLC,OpenPLC v3,OpenPLC v3,CVE-2026-14480,9.9,Critical,CWE-73,Critical Manufacturing; Energy; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3914,7/9/2026,7/9/2026,2026,ICSA-26-190-02,Schneider Electric PowerChute Serial Shutdown,"SuSE, Schneider Electric, Red Hat, Microsoft",Schneider Electric PowerChute Serial Shutdown,PowerChute Serial Shutdown <=1.4,"CVE-2026-2399, CVE-2026-2404, CVE-2026-2402, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, CVE-2026-2401",6.1,Medium,"CWE-116, CWE-1284, CWE-22, CWE-307, CWE-400, CWE-532, CWE-93",Communications; Critical Manufacturing; Energy; Healthcare and Public Health; Information Technology; Transportation Systems,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3913,7/9/2026,7/9/2026,2026,ICSA-26-190-03,Schneider Electric Easergy MiCOM Px40 Series,Schneider Electric,Schneider Electric Easergy MiCOM Px40 Series,"Easergy MiCOM P14x All versions prior to B4A | Easergy MiCOM P24x All versions prior to D3A | Easergy MiCOM P341 All versions prior to E3F | Easergy MiCOM P342, P343, P344, P345 All versions prior to B3F | Easergy MiCOM P442, P444 All versions prior to E3A | Easergy MiCOM P443, P445, P446, P543, P544, P545, P546 All versions prior to H6A | Easergy MiCOM P841 All versions prior to G6A | Easergy MiCOM P643 All versions prior to B3F | Easergy MiCOM P642, P645 All versions prior to B4A | Easergy MiCOM P741, P742, P743 All versions prior to B2A | Easergy MiCOM P746 All versions prior to B4E | Easergy MiCOM P746 All versions prior to C4E | Easergy MiCOM P849 All versions prior to B4A",CVE-2026-4832,5.3,Medium,CWE-798,Critical Manufacturing; Energy; Transportation Systems,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3912,7/7/2026,7/7/2026,2026,ICSA-26-188-01,Hydro-Quebec Le Circuit Electrique charging station backend,Hydro-Quebec,Hydro-Quebec Le Circuit Electrique charging station backend,Le Circuit Electrique charging station backend,"CVE-2026-20744, CVE-2026-42952, CVE-2026-44383",9.8,Critical,"CWE-284, CWE-307, CWE-613",Transportation Systems,Canada,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3911,7/7/2026,7/7/2026,2026,ICSA-26-188-02,Hitachi Energy PROMOD V,Hitachi Energy,Hitachi Energy PROMOD V,PROMOD V vers:PROMOD_V/<=1.0.10,CVE-2026-10763,7.1,High,CWE-1428,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3910,7/7/2026,7/7/2026,2026,ICSA-26-188-03,Hitachi Energy e-mesh EMS,Hitachi Energy,Hitachi Energy e-mesh EMS,"Hitachi Energy e-mesh EMS 4.1.6, 4.4.2, 4.7.0",CVE-2026-42945,8.1,High,CWE-122,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3909,7/7/2026,7/7/2026,2026,ICSA-26-188-04,Siemens Mendix Studio Pro,Siemens,Siemens Mendix Studio Pro,Mendix Studio Pro 10.11 | Mendix Studio Pro 10.12 | Mendix Studio Pro 10.13 | Mendix Studio Pro 10.14 | Mendix Studio Pro 10.15 | Mendix Studio Pro 10.16 | Mendix Studio Pro 10.17 | Mendix Studio Pro 10.18 | Mendix Studio Pro 10.19 | Mendix Studio Pro 10.20 | Mendix Studio Pro 10.21 | Mendix Studio Pro 10.22 | Mendix Studio Pro 10.23 | Mendix Studio Pro 10.24 | Mendix Studio Pro 11.0 | Mendix Studio Pro 11.1 | Mendix Studio Pro 11.10 | Mendix Studio Pro 11.11 | Mendix Studio Pro 11.2 | Mendix Studio Pro 11.3 | Mendix Studio Pro 11.4 | Mendix Studio Pro 11.5 | Mendix Studio Pro 11.6 | Mendix Studio Pro 11.7 | Mendix Studio Pro 11.8 | Mendix Studio Pro 11.9,CVE-2026-48192,5.4,Medium,CWE-94,Critical Manufacturing; Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3908,7/7/2026,7/7/2026,2026,ICSA-26-188-05,Siemens SINEC OS,Siemens,Siemens SINEC OS,RUGGEDCOM RST2428P (6GK6242-6PA00),"CVE-2025-1352, CVE-2025-1376, CVE-2025-6052, CVE-2025-6141, CVE-2025-6170, CVE-2025-7039, CVE-2025-8732, CVE-2025-9086, CVE-2025-9230, CVE-2025-9231, CVE-2025-9232, CVE-2025-10966, CVE-2025-13465, CVE-2025-13601, CVE-2025-39913, CVE-2025-40214, CVE-2025-40248, CVE-2025-40250, CVE-2025-40251, CVE-2025-40252, CVE-2025-40254, CVE-2025-40257, CVE-2025-40258, CVE-2025-40261, CVE-2025-40262, CVE-2025-40263, CVE-2025-40264, CVE-2025-40271, CVE-2025-40278, CVE-2025-40280, CVE-2025-40281, CVE-2025-40345, CVE-2025-46394, CVE-2025-49794, CVE-2025-49795, CVE-2025-49796, CVE-2025-60876, CVE-2025-66035, CVE-2025-66382, CVE-2025-66412, CVE-2025-69720, CVE-2025-71185, CVE-2025-71186, CVE-2025-71188, CVE-2025-71189, CVE-2025-71190, CVE-2025-71191, CVE-2026-1484, CVE-2026-1489, CVE-2026-3784, CVE-2026-22610, CVE-2026-22976, CVE-2026-22977, CVE-2026-23025, CVE-2026-23026, CVE-2026-23030, CVE-2026-23031, CVE-2026-23032, CVE-2026-23033, CVE-2026-23037, CVE-2026-23038, CVE-2026-23111, CVE-2026-23112, CVE-2026-23220, CVE-2026-23222, CVE-2026-23228, CVE-2026-23229, CVE-2026-23230, CVE-2026-23231, CVE-2026-23236, CVE-2026-23238, CVE-2026-24515, CVE-2026-25210, CVE-2026-26157, CVE-2026-26158, CVE-2026-35535, CVE-2026-41918",9.8,Critical,"CWE-119, CWE-121, CWE-125, CWE-1321, CWE-1335, CWE-1341, CWE-190, CWE-20, CWE-201, CWE-22, CWE-271, CWE-284, CWE-305, CWE-362, CWE-385, CWE-404, CWE-407, CWE-451, CWE-476, CWE-489, CWE-525, CWE-625, CWE-674, CWE-73, CWE-787, CWE-79, CWE-820, CWE-825, CWE-835, CWE-911",Critical Manufacturing; Transportation Systems; Energy; Healthcare and Public Health; Financial Services; Government Services and Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3907,7/7/2026,7/7/2026,2026,ICSA-26-188-06,Labcenter Proteus 9,Labcenter Electronics,Labcenter Proteus 9,Proteus 9.1_SP4_Build_42914,"CVE-2026-42953, CVE-2026-49033, CVE-2026-42958",7.8,High,"CWE-121, CWE-416, CWE-787",Communications; Critical Manufacturing; Defense Industrial Base; Energy; Healthcare and Public Health; Transportation Systems; Water and Wastewater Systems,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3906,7/7/2026,7/7/2026,2026,ICSA-26-188-07,"Digi International PortServer TS, Digi One SP IA",Digi International,"Digi International PortServer TS, Digi One SP IA",PortServer TS | Digi One SP | Digi One SP IA | Digi One IA,"CVE-2026-12352, CVE-2026-12948",5.9,Medium,"CWE-79, CWE-863",Critical Manufacturing; Communications; Information Technology; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3905,7/2/2026,7/2/2026,2026,ICSA-26-183-01,ST Engineering iDirect iQ-Series Terminals,ST Engineering iDirect,ST Engineering iDirect iQ-Series Terminals,Evolution iQ‑Series terminals <=4.5.2.1 | 3315‑Series terminals <=4.5.2.1 | 9‑Series terminals <=4.5.2.1,"CVE-2026-38059, CVE-2026-38057",8.1,High,"CWE-306, CWE-352",Communications; Defense Industrial Base; Energy; Government Facilities; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3904,7/2/2026,7/2/2026,2026,ICSA-26-183-02,CubeSpace CW0057 Reaction Wheel,CubeSpace,CubeSpace CW0057 Reaction Wheel,CW0057 Reaction Wheel,CVE-2026-13743,6.1,Medium,CWE-347,Communications,Worldwide,South Africa,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3903,7/2/2026,7/2/2026,2026,ICSA-26-183-03,Gardyn IoT Hub,Gardyn,Gardyn IoT Hub,Home Firmware | Studio Firmware | Cloud API <2.12.2026,"CVE-2026-13768, CVE-2026-55726, CVE-2026-54477",10.0,Critical,"CWE-497, CWE-644, CWE-798",Food and Agriculture,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3902,6/30/2026,6/30/2026,2026,ICSMA-26-181-01,OFFIS DCMTK Toolkit,OFFIS,OFFIS DCMTK Toolkit,DCMTK <=3.7.0,"CVE-2026-50003, CVE-2026-50254, CVE-2026-35505, CVE-2026-52868, CVE-2026-44628",9.8,Critical,"CWE-22, CWE-401, CWE-843",Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3901,6/30/2026,6/30/2026,2026,ICSA-26-181-01,Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M,Mitsubishi Electric,Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M,MELSOFT Update Manager SW1DND-UDM-M >=1.000A|<=1.014Q,"CVE-2025-53816, CVE-2025-53817, CVE-2025-55188, CVE-2025-11001",8.8,High,"CWE-122, CWE-22, CWE-476, CWE-59",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3900,6/30/2026,6/30/2026,2026,ICSA-26-181-02,Frangoteam FUXA SCADA/HMI,Frangoteam,Frangoteam FUXA SCADA/HMI,FUXA SCADA/HMI <=1.3.1,CVE-2026-13207,7.5,High,CWE-290,Critical Manufacturing; Energy; Water and Wastewater Systems,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3899,6/30/2026,6/30/2026,2026,ICSA-26-181-03,Schneider Electric EcoStruxure IT Data Center Expert,Schneider Electric,Schneider Electric EcoStruxure IT Data Center Expert,EcoStruxure IT Data Center Expert 9.1.2,CVE-2026-8045,6.5,Medium,CWE-611,Information Technology; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3898,6/30/2026,6/30/2026,2026,ICSA-26-181-04,Schneider Electric EasyLogic T150 and Saitel DP RTU,Schneider Electric,Schneider Electric EasyLogic T150 and Saitel DP RTU,EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller <=11.06.30 | EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller <=11.06.31 | Saitel DP Remote Terminal Unit & Controller <=11.06.35 | Saitel DP Remote Terminal Unit & Controller <=11.06.37,"CVE-2026-9650, CVE-2026-9651",7.5,High,"CWE-522, CWE-732",Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3897,6/30/2026,6/30/2026,2026,ICSA-26-181-05,XZ Utils vulnerability impacting B&R Products,B&R Industrial Automation GmbH,XZ Utils vulnerability impacting B&R Products,"PPC3100 <1.8.1, 1.8.1 | C50 <1.8.0, 1.8.0 | C80 <1.8.0, 1.8.0 | FT50 <1.8.1, 1.8.1 | MT50 <1.8.1, 1.8.1 | T30 <1.8.0, 1.8.0 | T80 <1.8.0, 1.8.0 | T50 <1.8.1, 1.8.1",CVE-2025-31115,7.5,High,CWE-366,Critical Manufacturing,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3896,6/30/2026,6/30/2026,2026,ICSA-26-181-06,StoneFly Storage Concentrator,StoneFly,StoneFly Storage Concentrator,Storage Concentrator <8.0.4.22 | Storage Concentrator Virtual Machine <8.0.4.22 | Storage Concentrator <8.0.4.26 | Storage Concentrator Virtual Machine <8.0.4.26 | Storage Concentrator <8.0.4.29 | Storage Concentrator Virtual Machine <8.0.4.29,"CVE-2026-50110, CVE-2026-56413, CVE-2026-56415, CVE-2026-55721, CVE-2026-50040",10.0,Critical,"CWE-78, CWE-79, CWE-798, CWE-89",Defense Industrial Base; Energy; Financial Services; Healthcare and Public Health; Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3895,6/30/2026,6/30/2026,2026,ICSA-26-181-07,Delta Electronics DVP12SE PLC,Delta Electronics,Delta Electronics DVP12SE PLC,DVP12SE PLC,"CVE-2026-12819, CVE-2026-12818",9.8,Critical,"CWE-306, CWE-770",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3894,6/25/2026,6/25/2026,2026,ICSMA-26-176-01,pydicom pynetdicom Library,pydicom,pydicom pynetdicom Library,pynetdicom >=v1.0.0|=R9.01|<=R10.04 | Collaborative Information Server (CI Server) >=R1.01|<=R1.04,CVE-2026-11833,7.5,High,CWE-319,Critical Manufacturing; Energy; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3891,6/25/2026,6/25/2026,2026,ICSA-26-176-02,EVoke Systems Charging Station Management System,EVoke Systems,EVoke Systems Charging Station Management System,EVoke CSMS,"CVE-2026-40702, CVE-2026-50176, CVE-2026-54479, CVE-2026-44622",9.4,Critical,"CWE-306, CWE-307, CWE-522, CWE-613",Energy; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3890,6/25/2026,6/25/2026,2026,ICSA-26-176-03,Horner Automation Cscape,Horner Automation,Horner Automation Cscape,Cscape <10.2_SP3,CVE-2026-12897,7.8,High,CWE-125,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3889,6/25/2026,6/25/2026,2026,ICSA-26-176-04,Daktronics Controller Firmware,Daktronics,Daktronics Controller Firmware,VFC-DMP-5000 =12.7.1|<=12.7.7, vers: RTU500_series_CMU_Firmware/>=13.5.1|<=13.5.4, vers: RTU500_series_CMU_Firmware/>=13.6.1|<=13.6.3, vers: RTU500_series_CMU_Firmware/>=13.7.1|<=13.7.8, 13.8.1, vers: RTU500_series_CMU_Firmware/>=13.7.1|<=13.7.7","CVE-2025-69421, CVE-2026-24515, CVE-2026-25210, CVE-2026-32776, CVE-2026-32777, CVE-2026-32778, CVE-2026-8479",7.8,High,"CWE-190, CWE-476, CWE-835",Dams; Energy; Water and Wastewater Systems,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3854,6/4/2026,6/4/2026,2026,ICSA-26-155-05,Hitachi Energy MACH HiDraw,Hitachi Energy,Hitachi Energy MACH HiDraw,MACH HiDraw vers:MACH_HiDraw/<=9.22,CVE-2026-7310,5.5,Medium,CWE-122,Dams; Energy; Transportation Systems,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3853,5/28/2026,5/28/2026,2026,ICSA-26-148-01,MacGregor Voyage Data Recorder (VDR) G4e,Danelec,MacGregor Voyage Data Recorder (VDR) G4e,MacGregor Voyage Data Recorder (VDR) G4e =7.50|<=14,CVE-2025-8754,7.5,High,CWE-306,Chemical; Communications; Critical Manufacturing; Dams; Energy; Healthcare and Public Health; Information Technology; Water and Wastewater Systems,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3841,5/26/2026,5/26/2026,2026,ICSA-26-146-04,ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager,B&R Industrial Automation GmbH,B&R Automation Runtime System Diagnostics Manager (SDM),"Automation Runtime <6.3, Automation Runtime =7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 6MD86 (CP200) vers:all/* () | SIPROTEC 5 6MD86 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 6MD89 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 6MU85 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 7KE85 (CP200) vers:all/* () | SIPROTEC 5 7KE85 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 7SA82 (CP100) vers:intdot/>=7.80 (CVE-2024-54017) | SIPROTEC 5 7SA82 (CP150) vers:intdot/<11.0 (CVE-2024-54017) | SIPROTEC 5 7SA84 (CP200) vers:all/* () | SIPROTEC 5 7SA86 (CP200) vers:all/* () | SIPROTEC 5 7SA86 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 7SA87 (CP200) vers:all/* () | SIPROTEC 5 7SA87 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 7SD82 (CP100) vers:intdot/>=7.80 (CVE-2024-54017) | SIPROTEC 5 7SD82 (CP150) vers:intdot/<11.0 (CVE-2024-54017) | SIPROTEC 5 7SD84 (CP200) vers:all/* () | SIPROTEC 5 7SD86 (CP200) vers:all/* () | SIPROTEC 5 7SD86 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 7SD87 (CP200) vers:all/* () | SIPROTEC 5 7SD87 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 7SJ81 (CP100) vers:intdot/>=7.80 (CVE-2024-54017) | SIPROTEC 5 7SJ81 (CP150) vers:intdot/<11.0 (CVE-2024-54017) | SIPROTEC 5 7SJ82 (CP100) vers:intdot/>=7.80 (CVE-2024-54017) | SIPROTEC 5 7SJ82 (CP150) vers:intdot/<11.0 (CVE-2024-54017) | SIPROTEC 5 7SJ85 (CP200) vers:all/* () | SIPROTEC 5 7SJ85 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 7SJ86 (CP200) vers:all/* () | SIPROTEC 5 7SJ86 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 7SK82 (CP100) vers:intdot/>=7.80 (CVE-2024-54017) | SIPROTEC 5 7SK82 (CP150) vers:intdot/<11.0 (CVE-2024-54017) | SIPROTEC 5 7SK85 (CP200) vers:all/* () | SIPROTEC 5 7SK85 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 7SL82 (CP100) vers:intdot/>=7.80 (CVE-2024-54017) | SIPROTEC 5 7SL82 (CP150) vers:intdot/<11.0 (CVE-2024-54017) | SIPROTEC 5 7SL86 (CP200) vers:all/* () | SIPROTEC 5 7SL86 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 7SL87 (CP200) vers:all/* () | SIPROTEC 5 7SL87 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 7SS85 (CP200) vers:all/* () | SIPROTEC 5 7SS85 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 7ST85 (CP200) vers:all/* () | SIPROTEC 5 7ST85 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 7ST86 (CP300) vers:intdot/<11.0 (CVE-2024-54017) | SIPROTEC 5 7SX82 (CP150) vers:intdot/<11.0 (CVE-2024-54017) | SIPROTEC 5 7SX85 (CP300) vers:intdot/<11.0 (CVE-2024-54017) | SIPROTEC 5 7SY82 (CP150) vers:intdot/<11.0 (CVE-2024-54017) | SIPROTEC 5 7UM85 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 7UT82 (CP100) vers:intdot/>=7.80 (CVE-2024-54017) | SIPROTEC 5 7UT82 (CP150) vers:intdot/<11.0 (CVE-2024-54017) | SIPROTEC 5 7UT85 (CP200) vers:all/* () | SIPROTEC 5 7UT85 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 7UT86 (CP200) vers:all/* () | SIPROTEC 5 7UT86 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 7UT87 (CP200) vers:all/* () | SIPROTEC 5 7UT87 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 7VE85 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 7VK87 (CP200) vers:all/* () | SIPROTEC 5 7VK87 (CP300) vers:intdot/>=7.80|<11.0 (CVE-2024-54017) | SIPROTEC 5 7VU85 (CP300) vers:intdot/<11.0 (CVE-2024-54017) | SIPROTEC 5 Compact 7SX800 (CP050) vers:intdot/<11.0 (CVE-2024-54017),CVE-2024-54017,5.3,Medium,CWE-334,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3814,5/14/2026,5/14/2026,2026,ICSA-26-134-14,Siemens SENTRON 7KT PAC1261 Data Manager,Siemens,Siemens SENTRON 7KT PAC1261 Data Manager,SENTRON 7KT PAC1261 Data Manager vers:intdot/<2.1.0,CVE-2025-22871,9.1,Critical,CWE-444,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3813,5/14/2026,5/14/2026,2026,ICSA-26-134-15,Siemens SIMATIC S7 PLC Web Server,Siemens,Siemens SIMATIC S7 PLC Web Server,"SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC Drive Controller CPU 1507D TF (6ES7615-7DF10-0AB0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SJ00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SJ01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SK03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DJ00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DJ01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DK03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SK00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SK01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SM03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC ET 200SP CPU 1512SP-1 PN (6ES7512-1DK00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC ET 200SP CPU 1512SP-1 PN (6ES7512-1DK01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC ET 200SP CPU 1512SP-1 PN (6ES7512-1DM03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC ET 200SP CPU 1514SP F-2 PN (6ES7514-2SN03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC ET 200SP CPU 1514SP-2 PN (6ES7514-2DN03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC ET 200SP CPU 1514SPT F-2 PN (6ES7514-2WN03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC ET 200SP CPU 1514SPT-2 PN (6ES7514-2VN03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V2 CPUs vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V3 CPUs vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC ET 200SP Open Controller CPU 1515SP PC3 V4 CPUs vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK02-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AL03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK00-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CL03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK02-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FL03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1511T-1 PN (6ES7511-1TK01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1511T-1 PN (6ES7511-1TL03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1511TF-1 PN (6ES7511-1UK01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1511TF-1 PN (6ES7511-1UL03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK00-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CM03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL02-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AM03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL02-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FM03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1513pro F-2 PN (6ES7513-2GM03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1513pro-2 PN (6ES7513-2PM03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM02-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AN03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM02-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FN03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1515T-2 PN (6ES7515-2TM01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1515T-2 PN (6ES7515-2TN03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1515TF-2 PN (6ES7515-2UM01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1515TF-2 PN (6ES7515-2UN03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN02-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AP03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN00-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN01-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN02-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FP03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1516pro F-2 PN (6ES7516-2GP03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1516pro-2 PN (6ES7516-2PP03-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1516T-3 PN (6ES7516-3TP10-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1516T-3 PN/DP (6ES7516-3TN00-0AB0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1516TF-3 PN (6ES7516-3UP10-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1516TF-3 PN/DP (6ES7516-3UN00-0AB0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1517-3 PN (6ES7517-3AQ10-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1517-3 PN/DP (6ES7517-3AP00-0AB0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1517F-3 PN (6ES7517-3FQ10-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1517F-3 PN/DP (6ES7517-3FP00-0AB0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1517F-3 PN/DP (6ES7517-3FP01-0AB0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1517T-3 PN (6ES7517-3TQ10-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1517T-3 PN/DP (6ES7517-3TP00-0AB0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1517TF-3 PN (6ES7517-3UQ10-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1517TF-3 PN/DP (6ES7517-3UP00-0AB0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1518-3 PN (6ES7518-3AT10-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1518-4 PN/DP (6ES7518-4AP00-0AB0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1518F-3 PN (6ES7518-3FT10-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1518F-4 PN/DP (6ES7518-4FP00-0AB0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1518T-3 PN (6ES7518-3TT10-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1518T-4 PN/DP (6ES7518-4TP00-0AB0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1518TF-3 PN (6ES7518-3UT10-0AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU 1518TF-4 PN/DP (6ES7518-4UP00-0AB0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU S7-1518-4 PN/DP ODK (6ES7518-4AP00-3AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 CPU S7-1518F-4 PN/DP ODK (6ES7518-4FP00-3AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 ET 200pro: CPU 1513PRO F-2 PN (6ES7513-2GL00-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 ET 200pro: CPU 1513PRO-2 PN (6ES7513-2PL00-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 ET 200pro: CPU 1516PRO F-2 PN (6ES7516-2GN00-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 ET 200pro: CPU 1516PRO-2 PN (6ES7516-2PN00-0AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 Software Controller CPU 1507S F V2 vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 Software Controller CPU 1507S F V3 vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 Software Controller CPU 1507S F V4 vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 Software Controller CPU 1507S V2 vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 Software Controller CPU 1507S V3 vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 Software Controller CPU 1507S V4 vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 Software Controller CPU 1508S F V2 vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 Software Controller CPU 1508S F V3 vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 Software Controller CPU 1508S F V4 vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 Software Controller CPU 1508S T V3 vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 Software Controller CPU 1508S TF V3 vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 Software Controller CPU 1508S V2 vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 Software Controller CPU 1508S V3 vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 Software Controller CPU 1508S V4 vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 Software Controller Linux V2 vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-1500 Software Controller Linux V3 vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIMATIC S7-PLCSIM Advanced vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS ET 200SP CPU 1510SP F-1 PN (6AG1510-1SJ01-2AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS ET 200SP CPU 1510SP F-1 PN RAIL (6AG2510-1SJ01-1AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS ET 200SP CPU 1510SP-1 PN (6AG1510-1DJ01-2AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS ET 200SP CPU 1510SP-1 PN (6AG1510-1DJ01-7AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS ET 200SP CPU 1510SP-1 PN RAIL (6AG2510-1DJ01-1AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS ET 200SP CPU 1510SP-1 PN RAIL (6AG2510-1DJ01-4AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK00-2AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK01-2AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK01-7AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL (6AG2512-1SK01-1AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL (6AG2512-1SK01-4AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS ET 200SP CPU 1512SP-1 PN (6AG1512-1DK01-2AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS ET 200SP CPU 1512SP-1 PN (6AG1512-1DK01-7AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS ET 200SP CPU 1512SP-1 PN RAIL (6AG2512-1DK01-1AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS ET 200SP CPU 1512SP-1 PN RAIL (6AG2512-1DK01-4AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK00-2AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK01-2AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK01-7AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK02-2AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK02-7AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL (6AG2511-1AK01-1AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL (6AG2511-1AK02-1AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1511-1 PN TX RAIL (6AG2511-1AK01-4AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1511-1 PN TX RAIL (6AG2511-1AK02-4AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK00-2AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK01-2AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK02-2AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL00-2AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL01-2AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL01-7AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL02-2AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL02-7AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL00-2AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL01-2AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL02-2AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1515F-2 PN (6AG1515-2FM01-2AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1515F-2 PN (6AG1515-2FM02-2AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1515F-2 PN RAIL (6AG2515-2FM02-4AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1515F-2 PN T2 RAIL (6AG2515-2FM01-2AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN00-2AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN00-7AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN01-2AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN01-7AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN02-2AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN02-7AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1516-3 PN/DP RAIL (6AG2516-3AN02-4AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1516-3 PN/DP TX RAIL (6AG2516-3AN01-4AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN00-2AB0) vers:all/* (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN01-2AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN02-2AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL (6AG2516-3FN02-2AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL (6AG2516-3FN02-4AB0) vers:intdot/<2.9.9 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1518-4 PN/DP (6AG1518-4AP00-4AB0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789) | SIPLUS S7-1500 CPU 1518F-4 PN/DP (6AG1518-4FP00-4AB0) vers:intdot/<3.1.6 (CVE-2026-25786, CVE-2026-25787, CVE-2026-25789)","CVE-2026-25786, CVE-2026-25787, CVE-2026-25789",9.1,Critical,CWE-79,Chemical; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3812,5/14/2026,5/14/2026,2026,ICSA-26-134-16,Siemens Ruggedcom Rox,Siemens,Siemens Ruggedcom Rox,"RUGGEDCOM ROX MX5000 vers:intdot/<2.17.1 (CVE-2019-13103, CVE-2019-13104, CVE-2019-13106, CVE-2019-14192, CVE-2019-14193, CVE-2019-14194, CVE-2019-14195, CVE-2019-14196, CVE-2019-14197, CVE-2019-14198, CVE-2019-14199, CVE-2019-14200, CVE-2019-14201, CVE-2019-14202, CVE-2019-14203, CVE-2019-14204, CVE-2020-10648, CVE-2022-2347, CVE-2022-30552, CVE-2022-30790, CVE-2022-34835, CVE-2023-3019, CVE-2023-27043, CVE-2024-3447, CVE-2024-22365, CVE-2024-57256, CVE-2024-57258, CVE-2025-0395, CVE-2025-3576, CVE-2025-6020, CVE-2025-7425, CVE-2025-9714, CVE-2025-46836, CVE-2025-49794, CVE-2025-49796) | RUGGEDCOM ROX MX5000RE vers:intdot/<2.17.1 (CVE-2019-13103, CVE-2019-13104, CVE-2019-13106, CVE-2019-14192, CVE-2019-14193, CVE-2019-14194, CVE-2019-14195, CVE-2019-14196, CVE-2019-14197, CVE-2019-14198, CVE-2019-14199, CVE-2019-14200, CVE-2019-14201, CVE-2019-14202, CVE-2019-14203, CVE-2019-14204, CVE-2020-10648, CVE-2022-2347, CVE-2022-30552, CVE-2022-30790, CVE-2022-34835, CVE-2023-3019, CVE-2023-27043, CVE-2024-3447, CVE-2024-22365, CVE-2024-57256, CVE-2024-57258, CVE-2025-0395, CVE-2025-3576, CVE-2025-6020, CVE-2025-7425, CVE-2025-9714, CVE-2025-46836, CVE-2025-49794, CVE-2025-49796) | RUGGEDCOM ROX RX1400 vers:intdot/<2.17.1 (CVE-2019-13103, CVE-2019-13104, CVE-2019-13106, CVE-2019-14192, CVE-2019-14193, CVE-2019-14194, CVE-2019-14195, CVE-2019-14196, CVE-2019-14197, CVE-2019-14198, CVE-2019-14199, CVE-2019-14200, CVE-2019-14201, CVE-2019-14202, CVE-2019-14203, CVE-2019-14204, CVE-2020-10648, CVE-2022-2347, CVE-2022-30552, CVE-2022-30790, CVE-2022-34835, CVE-2023-3019, CVE-2023-27043, CVE-2024-3447, CVE-2024-22365, CVE-2024-57256, CVE-2024-57258, CVE-2025-0395, CVE-2025-3576, CVE-2025-6020, CVE-2025-7425, CVE-2025-9714, CVE-2025-46836, CVE-2025-49794, CVE-2025-49796) | RUGGEDCOM ROX RX1500 vers:intdot/<2.17.1 (CVE-2019-13103, CVE-2019-13104, CVE-2019-13106, CVE-2019-14192, CVE-2019-14193, CVE-2019-14194, CVE-2019-14195, CVE-2019-14196, CVE-2019-14197, CVE-2019-14198, CVE-2019-14199, CVE-2019-14200, CVE-2019-14201, CVE-2019-14202, CVE-2019-14203, CVE-2019-14204, CVE-2020-10648, CVE-2022-2347, CVE-2022-30552, CVE-2022-30790, CVE-2022-34835, CVE-2023-3019, CVE-2023-27043, CVE-2024-3447, CVE-2024-22365, CVE-2024-57256, CVE-2024-57258, CVE-2025-0395, CVE-2025-3576, CVE-2025-6020, CVE-2025-7425, CVE-2025-9714, CVE-2025-46836, CVE-2025-49794, CVE-2025-49796) | RUGGEDCOM ROX RX1501 vers:intdot/<2.17.1 (CVE-2019-13103, CVE-2019-13104, CVE-2019-13106, CVE-2019-14192, CVE-2019-14193, CVE-2019-14194, CVE-2019-14195, CVE-2019-14196, CVE-2019-14197, CVE-2019-14198, CVE-2019-14199, CVE-2019-14200, CVE-2019-14201, CVE-2019-14202, CVE-2019-14203, CVE-2019-14204, CVE-2020-10648, CVE-2022-2347, CVE-2022-30552, CVE-2022-30790, CVE-2022-34835, CVE-2023-3019, CVE-2023-27043, CVE-2024-3447, CVE-2024-22365, CVE-2024-57256, CVE-2024-57258, CVE-2025-0395, CVE-2025-3576, CVE-2025-6020, CVE-2025-7425, CVE-2025-9714, CVE-2025-46836, CVE-2025-49794, CVE-2025-49796) | RUGGEDCOM ROX RX1510 vers:intdot/<2.17.1 (CVE-2019-13103, CVE-2019-13104, CVE-2019-13106, CVE-2019-14192, CVE-2019-14193, CVE-2019-14194, CVE-2019-14195, CVE-2019-14196, CVE-2019-14197, CVE-2019-14198, CVE-2019-14199, CVE-2019-14200, CVE-2019-14201, CVE-2019-14202, CVE-2019-14203, CVE-2019-14204, CVE-2020-10648, CVE-2022-2347, CVE-2022-30552, CVE-2022-30790, CVE-2022-34835, CVE-2023-3019, CVE-2023-27043, CVE-2024-3447, CVE-2024-22365, CVE-2024-57256, CVE-2024-57258, CVE-2025-0395, CVE-2025-3576, CVE-2025-6020, CVE-2025-7425, CVE-2025-9714, CVE-2025-46836, CVE-2025-49794, CVE-2025-49796) | RUGGEDCOM ROX RX1511 vers:intdot/<2.17.1 (CVE-2019-13103, CVE-2019-13104, CVE-2019-13106, CVE-2019-14192, CVE-2019-14193, CVE-2019-14194, CVE-2019-14195, CVE-2019-14196, CVE-2019-14197, CVE-2019-14198, CVE-2019-14199, CVE-2019-14200, CVE-2019-14201, CVE-2019-14202, CVE-2019-14203, CVE-2019-14204, CVE-2020-10648, CVE-2022-2347, CVE-2022-30552, CVE-2022-30790, CVE-2022-34835, CVE-2023-3019, CVE-2023-27043, CVE-2024-3447, CVE-2024-22365, CVE-2024-57256, CVE-2024-57258, CVE-2025-0395, CVE-2025-3576, CVE-2025-6020, CVE-2025-7425, CVE-2025-9714, CVE-2025-46836, CVE-2025-49794, CVE-2025-49796) | RUGGEDCOM ROX RX1512 vers:intdot/<2.17.1 (CVE-2019-13103, CVE-2019-13104, CVE-2019-13106, CVE-2019-14192, CVE-2019-14193, CVE-2019-14194, CVE-2019-14195, CVE-2019-14196, CVE-2019-14197, CVE-2019-14198, CVE-2019-14199, CVE-2019-14200, CVE-2019-14201, CVE-2019-14202, CVE-2019-14203, CVE-2019-14204, CVE-2020-10648, CVE-2022-2347, CVE-2022-30552, CVE-2022-30790, CVE-2022-34835, CVE-2023-3019, CVE-2023-27043, CVE-2024-3447, CVE-2024-22365, CVE-2024-57256, CVE-2024-57258, CVE-2025-0395, CVE-2025-3576, CVE-2025-6020, CVE-2025-7425, CVE-2025-9714, CVE-2025-46836, CVE-2025-49794, CVE-2025-49796) | RUGGEDCOM ROX RX1524 vers:intdot/<2.17.1 (CVE-2019-13103, CVE-2019-13104, CVE-2019-13106, CVE-2019-14192, CVE-2019-14193, CVE-2019-14194, CVE-2019-14195, CVE-2019-14196, CVE-2019-14197, CVE-2019-14198, CVE-2019-14199, CVE-2019-14200, CVE-2019-14201, CVE-2019-14202, CVE-2019-14203, CVE-2019-14204, CVE-2020-10648, CVE-2022-2347, CVE-2022-30552, CVE-2022-30790, CVE-2022-34835, CVE-2023-3019, CVE-2023-27043, CVE-2024-3447, CVE-2024-22365, CVE-2024-57256, CVE-2024-57258, CVE-2025-0395, CVE-2025-3576, CVE-2025-6020, CVE-2025-7425, CVE-2025-9714, CVE-2025-46836, CVE-2025-49794, CVE-2025-49796) | RUGGEDCOM ROX RX1536 vers:intdot/<2.17.1 (CVE-2019-13103, CVE-2019-13104, CVE-2019-13106, CVE-2019-14192, CVE-2019-14193, CVE-2019-14194, CVE-2019-14195, CVE-2019-14196, CVE-2019-14197, CVE-2019-14198, CVE-2019-14199, CVE-2019-14200, CVE-2019-14201, CVE-2019-14202, CVE-2019-14203, CVE-2019-14204, CVE-2020-10648, CVE-2022-2347, CVE-2022-30552, CVE-2022-30790, CVE-2022-34835, CVE-2023-3019, CVE-2023-27043, CVE-2024-3447, CVE-2024-22365, CVE-2024-57256, CVE-2024-57258, CVE-2025-0395, CVE-2025-3576, CVE-2025-6020, CVE-2025-7425, CVE-2025-9714, CVE-2025-46836, CVE-2025-49794, CVE-2025-49796) | RUGGEDCOM ROX RX5000 vers:intdot/<2.17.1 (CVE-2019-13103, CVE-2019-13104, CVE-2019-13106, CVE-2019-14192, CVE-2019-14193, CVE-2019-14194, CVE-2019-14195, CVE-2019-14196, CVE-2019-14197, CVE-2019-14198, CVE-2019-14199, CVE-2019-14200, CVE-2019-14201, CVE-2019-14202, CVE-2019-14203, CVE-2019-14204, CVE-2020-10648, CVE-2022-2347, CVE-2022-30552, CVE-2022-30790, CVE-2022-34835, CVE-2023-3019, CVE-2023-27043, CVE-2024-3447, CVE-2024-22365, CVE-2024-57256, CVE-2024-57258, CVE-2025-0395, CVE-2025-3576, CVE-2025-6020, CVE-2025-7425, CVE-2025-9714, CVE-2025-46836, CVE-2025-49794, CVE-2025-49796)","CVE-2019-13103, CVE-2019-13104, CVE-2019-13106, CVE-2019-14192, CVE-2019-14193, CVE-2019-14194, CVE-2019-14195, CVE-2019-14196, CVE-2019-14197, CVE-2019-14198, CVE-2019-14199, CVE-2019-14200, CVE-2019-14201, CVE-2019-14202, CVE-2019-14203, CVE-2019-14204, CVE-2020-10648, CVE-2022-2347, CVE-2022-30552, CVE-2022-30790, CVE-2022-34835, CVE-2023-3019, CVE-2023-27043, CVE-2024-3447, CVE-2024-22365, CVE-2024-57256, CVE-2024-57258, CVE-2025-0395, CVE-2025-3576, CVE-2025-6020, CVE-2025-7425, CVE-2025-9714, CVE-2025-46836, CVE-2025-49794, CVE-2025-49796",9.8,Critical,"CWE-674, CWE-191, CWE-787, CWE-125, CWE-20, CWE-122, CWE-120, CWE-416, CWE-1286, CWE-664, CWE-190, CWE-131, CWE-328, CWE-22, CWE-121, CWE-825",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3811,5/14/2026,5/14/2026,2026,ICSA-26-134-17,Universal Robots Polyscope 5,Universal Robots,Universal Robots Polyscope 5,Polyscope 5 <5.25.1,CVE-2026-8153,9.8,Critical,CWE-78,Critical Manufacturing,Worldwide,Denmark,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3810,5/12/2026,5/12/2026,2026,ICSA-26-132-01,Fuji Electric Tellus,Fuji Electric,Fuji Electric Tellus,Fuji Electric Tellus: 5.0.2,CVE-2026-8108,7.8,High,CWE-749,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3809,5/12/2026,5/12/2026,2026,ICSA-26-132-02,Subnet Solutions PowerSYSTEM Center,Subnet Solutions Inc.,Subnet Solutions PowerSYSTEM Center,"Subnet Solutions Inc. PowerSYSTEM Center 2020: >=5.8.x|<=5.28.x, Subnet Solutions Inc. PowerSYSTEM Center 2024: >=6.0.x|<=6.1.x, Subnet Solutions Inc. PowerSYSTEM Center 2026: 7.0.x","CVE-2026-26289, CVE-2026-33570, CVE-2026-35555, CVE-2026-35504",8.2,High,"CWE-863, CWE-93",Critical Manufacturing; Energy,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3808,5/12/2026,5/12/2026,2026,ICSA-26-132-03,ABB AC500 V3 Multiple Vulnerabilities,ABB,ABB AC500 V3 Multiple Vulnerabilities,ABB AC500 V3 <3.9.0,"CVE-2025-2595, CVE-2025-41659, CVE-2025-41691",8.3,High,"CWE-425, CWE-476, CWE-732",Chemical; Critical Manufacturing; Energy; Water and Wastewater Systems,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3807,5/12/2026,5/12/2026,2026,ICSA-26-132-04,ABB Automation Builder Gateway for Windows,ABB,ABB Automation Builder Gateway for Windows,ABB Automation Builder <2.9.0,CVE-2024-41975,5.3,Medium,CWE-1188,Chemical; Critical Manufacturing; Energy; Water and Wastewater Systems,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3806,5/12/2026,5/12/2026,2026,ICSA-26-132-05,ABB AC500 V3 Stack buffer overflow in Cryptographic Message Syntax,ABB,ABB AC500 V3 Stack Buffer Overflow in Cryptographic Message Syntax,ABB AC500 V3 PM5xxx Firmware Version 3.9.0,CVE-2025-15467,9.8,Critical,CWE-787,Chemical; Critical Manufacturing; Energy; Water and Wastewater Systems,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3805,5/12/2026,5/12/2026,2026,ICSA-26-132-06,ABB WebPro SNMP Card PowerValue,ABB,ABB WebPro SNMP Card PowerValue Multiple Vulnerabilities,ABB WebPro SNMP Card PowerValue <=1.1.8.k,"CVE-2025-4675, CVE-2025-4676, CVE-2025-4677",8.8,High,"CWE-303, CWE-613, CWE-754",Chemical; Communications; Critical Manufacturing; Dams; Energy; Healthcare and Public Health; Information Technology; Water and Wastewater Systems,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3804,5/7/2026,5/7/2026,2026,ICSA-26-127-01,Maxhub Pivot,MAXHUB,MAXHUB Pivot Client Application,MAXHUB MAXHUB Pivot client application: =3.10|<=3.52, 3.53, 3.3, 2.3, 2.2, 2.1, 3.4 ()",CVE-2025-3756,6.5,Medium,CWE-1284,Chemical; Critical Manufacturing; Energy; Water and Wastewater Systems,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3797,4/30/2026,4/30/2026,2026,ICSA-26-120-02,ABB PCM600,ABB,ABB PCM600,ABB PCM600: >=1.5|<=2.13,CVE-2018-1002208,4.4,Medium,CWE-22,Critical Manufacturing,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3796,4/30/2026,4/30/2026,2026,ICSA-26-120-03,ABB Edgenius Management Portal,ABB,ABB Edgenius Management Portal,ABB Edgenius Management Portal: 3.2.0.0|3.2.1.1,CVE-2025-10571,9.6,Critical,CWE-288,Critical Manufacturing; Information Technology,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3795,4/30/2026,4/30/2026,2026,ICSA-26-120-04,ABB Ability OPTIMAX,ABB,ABB Ability OPTIMAX,"ABB ABB Ability OPTIMAX 6.1: vers:all/*, ABB ABB Ability OPTIMAX 6.2: vers:all/*, ABB ABB Ability OPTIMAX 6.3: <6.3.1-251120, ABB ABB Ability OPTIMAX 6.4: <6.4.1-251120",CVE-2025-14510,8.1,High,CWE-303,Energy; Water and Wastewater,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3794,4/30/2026,4/30/2026,2026,ICSA-26-120-05,ABB AWIN Gateways,ABB,ABB AWIN Gateways,"ABB ABB AWIN Firmware (2.0-0) installed on ABB AWIN GW100 rev.2: 2.0-0, ABB ABB AWIN Firmware (2.0-1) installed on ABB AWIN GW100 rev.2: 2.0-1, ABB ABB AWIN Firmware (1.2-0) installed on ABB AWIN GW120: 1.2-0, ABB ABB AWIN Firmware (1.2-1) installed on ABB AWIN GW120: 1.2-1","CVE-2025-13777, CVE-2025-13778, CVE-2025-13779",8.3,High,"CWE-294, CWE-306",Critical Manufacturing,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3793,4/30/2026,4/30/2026,2026,ICSA-26-120-06,ABB Ability Symphony Plus Engineering,ABB,ABB Ability Symphony Plus Engineering,"ABB Ability Symphony Plus S+ Engineering 2.2, ABB Ability Symphony Plus S+ Engineering 2.3, ABB Ability Symphony Plus S+ Engineering 2.3 RU1, ABB Ability Symphony Plus S+ Engineering 2.3 RU2, ABB Ability Symphony Plus S+ Engineering 2.3 RU3, ABB Ability Symphony Plus S+ Engineering 2.4, ABB Ability Symphony Plus S+ Engineering 2.4 SP1, ABB Ability Symphony Plus S+ Engineering 2.4 SP2","CVE-2023-5869, CVE-2023-39417, CVE-2024-7348, CVE-2024-0985",8.8,High,"CWE-190, CWE-89, CWE-367, CWE-271",Chemical; Critical Manufacturing; Energy; Water and Wastewater Systems,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3792,4/28/2026,4/28/2026,2026,ICSA-26-118-01,NSA GrassMarlin,NSA,NSA GRASSMARLIN,NSA GRASSMARLIN: vers:all/*,CVE-2026-6807,5.5,Medium,CWE-611,Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3791,4/23/2026,4/23/2026,2026,ICSA-26-113-01,YADEA T5 Electric Bike,Yadea,Yadea T5 Electric Bicycle,Yadea T5 Electric Bicycle: vers:all/*,CVE-2025-70994,7.3,High,CWE-1390,Transportation Systems,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3790,4/23/2026,4/23/2026,2026,ICSA-26-113-02,Carlson Software VASCO-B GNSS Receiver,Carlson Software,Carlson Software VASCO-B GNSS Receiver,Carlson Software VASCO-B GNSS Receiver: <1.4.0,CVE-2026-3893,9.4,Critical,CWE-306,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3789,4/23/2026,4/23/2026,2026,ICSA-26-113-03,Milesight Cameras,Milesight,Milesight Cameras,"Milesight MS-Cxx63-PD: <=51.7.0.77-r12, Milesight MS-Cxx64-xPD: <=51.7.0.77-r12, Milesight MS-Cxx73-xPD: <=51.7.0.77-r12, Milesight MS-Cxx75-xxPD: <=51.7.0.77-r12, Milesight MS-Cxx83-xPD: <=51.7.0.77-r12, Milesight MS-Cxx74-PA: <=3x.8.0.3-r11, Milesight MS-C8477-HPG1: <=63.8.0.4-r3, Milesight MS-C8477-PC: <=48.8.0.4-r3, Milesight MS-C5321-FPE: <=62.8.0.4-r5, Milesight MS-Cxx72-xxxPE: <=61.8.0.5-r2, Milesight MS-Cxx62-xxxPE: <=61.8.0.5-r2, Milesight MS-Cxx52-xxxPE: <=61.8.0.5-r2, Milesight MS-Cxx66-xxxPE: <=61.8.0.5-r2, Milesight MS-Cxx66-xxxGPE: <=61.8.0.5-r2, Milesight MS-Cxx61-xxxPE: <=61.8.0.5-r2, Milesight MS-Cxx67-xxxPE: <=61.8.0.5-r2, Milesight MS-Cxx71-xxxPE: <=61.8.0.5-r2, Milesight MS-Cxx41-xxxPE: <=61.8.0.5-r2, Milesight MS-Cxx76-PE: <=61.8.0.5-r2, Milesight MS-Cxx65-PE: <=61.8.0.5-r2, Milesight MS-Cxx66-xxxG1: <=63.8.0.5-r3, Milesight MS-Cxx62-xxxG1: <=63.8.0.5-r3, Milesight MS-Cxx72-xxxG1: <=63.8.0.5-r3, Milesight MS-CQxx31-xxxG1: <=CQ_63.8.0.5-r1, Milesight MS-CQxx68-xxxG1: <=CQ_63.8.0.5-r1, Milesight MS-CQxx72-xxxG1: <=CQ_63.8.0.5-r1, Milesight MS-Nxxxx-NxE: <=7x.9.0.19-r5, Milesight MS-Nxxxx-xxC: <=7x.9.0.19-r5, Milesight MS-Nxxxx-xxE: <=7x.9.0.19-r5, Milesight MS-Nxxxx-xxG: <=7x.9.0.19-r5, Milesight MS-Nxxxx-xxH: <=7x.9.0.19-r5, Milesight MS-Nxxxx-xxT: <=7x.9.0.19-r5, Milesight PMC8266-FPE: <=PO_61.8.0.4_LPR, Milesight PMC8266-FGPE: <=PO_61.8.0.4_LPR, Milesight PM3322-E: <=PI_61.8.0.3_LPR-r3, Milesight TS4466-X4RIPG1: <=T_63.8.0.4_LPR-r3, Milesight TS5366-X12RIPG1: <=T_63.8.0.4_LPR-r3, Milesight TS8266-X4RIPG1: <=T_63.8.0.4_LPR-r3, Milesight TS4466-X4RIVPG1: <=T_63.8.0.4_LPR-r3, Milesight TS4466-RFIVPG1: <=T_63.8.0.4_LPR-r3, Milesight TS8266-X4RIVPG1: <=T_63.8.0.4_LPR-r3, Milesight TS8266-RFIVPG1: <=T_63.8.0.4_LPR-r3, Milesight TS4466-X4RIWG1: <=T_63.8.0.4_LPR-r3, Milesight TS8266-X4RIWG1: <=T_63.8.0.4_LPR-r3, Milesight TS5510-GVH: <=T_47.8.0.4_LPR-r7, Milesight TS5510-GH: <=T_47.8.0.4_LPR-r6, Milesight TS5511-GVH: <=T_47.8.0.4_LPR-r6, Milesight TS2966-X12TPE: <=T_61.8.0.4_LPR-r3, Milesight TS4466-X4RPE: <=T_61.8.0.4_LPR-r3, Milesight TS5366-X12PE: <=T_61.8.0.4_LPR-r3, Milesight TS8266-X4PE: <=T_61.8.0.4_LPR-r3, Milesight TS2966-X12TVPE: <=T_61.8.0.4_LPR-r3, Milesight TS4466-X4RVPE: <=T_61.8.0.4_LPR-r3, Milesight TS5366-X12VPE: <=T_61.8.0.4_LPR-r3, Milesight TS8266-X4VPE: <=T_61.8.0.4_LPR-r3, Milesight TS4441-X36RPE: <=T_61.8.0.4_LPR-r3, Milesight TS4441-X36RE: <=T_61.8.0.4_LPR-r3, Milesight TS4466-X4RWE: <=T_61.8.0.4_LPR-r3, Milesight TS8266-X4WE: <=T_61.8.0.4_LPR-r3, Milesight MS-C2964-RFLPC: <=T_45.8.0.3-r9, Milesight MS-C2972-RFLPC: <=T_45.8.0.3-r9, Milesight MS-C2966-RFLWPC: <=T_45.8.0.3-r9, Milesight TS2866-X4TPC: <=T_45.8.0.3-r9, Milesight TS2866-X4TVPC: <=T_45.8.0.3-r9, Milesight TS2866-X4TGPC: <=T_45.8.0.3-r9, Milesight TS2841-X36TPC: <=T_45.8.0.3-r9, Milesight TS2841-X36TPC/W: <=T_45.8.0.3-r9, Milesight TS2867-X5TPC: <=T_45.8.0.3-r9, Milesight TS2961-X12TPC: <=T_45.8.0.3-r9, Milesight TS8266-FPC/P: <=T_45.8.0.3-r9, Milesight MS-C2966-X12RLPC: <=T_45.8.0.3-r9, Milesight MS-C2966-X12RLVPC: <=T_45.8.0.3-r9, Milesight MS-C5366-X12LPC: <=T_45.8.0.3-r9, Milesight MS-C5366-X12LVPC: <=T_45.8.0.3-r9, Milesight MS-C5361-X12LPC: <=T_45.8.0.3-r9, Milesight MS-Cxx66-xxxxGOPC: <=45.8.0.2-AIoT-r4, Milesight SC211: <=C_21.1.0.8-r4, Milesight SP111: <=52.8.0.4-r5, Milesight MS-Cxx66-RFIPKG1: <=63.8.0.4-r1-NX, Milesight MS-Cxx72-RFIPKG1: <=63.8.0.4-r1-NX, Milesight MS-Cxx66-FIPKG1: <=63.8.0.4-r1-NX, Milesight MS-Cxx72-FIPKG1: <=63.8.0.4-r1-NX","CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766",9.8,Critical,"CWE-122, CWE-321, CWE-639, CWE-78, CWE-798",Commercial Facilities,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3788,4/23/2026,4/23/2026,2026,ICSA-26-113-04,SpiceJet Online Booking System,SpiceJet,SpiceJet Online Booking System,SpiceJet Online Booking System: vers:all/*,"CVE-2026-6375, CVE-2026-6376",7.5,High,"CWE-306, CWE-639",Transportation Systems,Worldwide,India,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3787,4/23/2026,4/23/2026,2026,ICSA-26-113-05,"Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera","Hangzhou Xiongmai Technology Co., Ltd","Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera","Hangzhou Xiongmai Technology Co., Ltd IP Camera XM530V200_X6-WEQ_8M firmware: V5.00.R02.000807D8.10010.346624.S.ONVIF_21.06",CVE-2025-65856,9.8,Critical,CWE-306,Commercial Facilities,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3786,4/23/2026,5/7/2026,2026,ICSA-26-113-06,Intrado 911 Emergency Gateway (EGW) (Update A),Intrado,Intrado 911 Emergency Gateway (EGW) (Update A),"Intrado Emergency Gateway: 7.x, Intrado Emergency Gateway: 6.x, Intrado Emergency Gateway: 5.x",CVE-2026-6074,9.8,Critical,CWE-35,Emergency Services,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3785,4/21/2026,4/21/2026,2026,ICSA-26-111-01,Siemens TPM 2.0,Siemens,Siemens TPM 2.0,"SIMATIC CN 4100, SIMATIC Field PG M5, SIMATIC Field PG M6, SIMATIC IPC BX-32A, SIMATIC IPC BX-39A, SIMATIC IPC BX-56A, SIMATIC IPC BX-59A, SIMATIC IPC MD-57A, SIMATIC IPC PX-32A, SIMATIC IPC PX-39A, SIMATIC IPC PX-39A PRO, SIMATIC IPC RW-528A, SIMATIC IPC RW-548A, SIMATIC IPC227E, SIMATIC IPC277E, SIMATIC IPC427E, SIMATIC IPC477E, SIMATIC IPC477E PRO, SIMATIC IPC627E, SIMATIC IPC647E, SIMATIC IPC677E, SIMATIC IPC847E, SIMATIC ITP1000, SIPLUS IPC427E",CVE-2025-2884,6.6,Medium,CWE-125,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3784,4/21/2026,4/21/2026,2026,ICSA-26-111-02,Siemens RUGGEDCOM CROSSBOW Secure Access Manager Primary,Siemens,Siemens RUGGEDCOM CROSSBOW Secure Access Manager Primary,RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P),CVE-2026-27668,8.8,High,CWE-266,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3783,4/21/2026,4/21/2026,2026,ICSA-26-111-03,Siemens SINEC NMS,Siemens,Siemens SINEC NMS,SINEC NMS,CVE-2026-24032,7.3,High,CWE-347,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3782,4/21/2026,4/21/2026,2026,ICSA-26-111-04,Siemens Analytics Toolkit,Siemens,Siemens Analytics Toolkit,"Siemens Software Center, Simcenter 3D, Simcenter Femap, Simcenter STAR-CCM+, Solid Edge SE2025, Solid Edge SE2026, Tecnomatix Plant Simulation",CVE-2025-40745,3.7,Low,CWE-295,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3781,4/21/2026,7/30/2026,2026,ICSA-26-111-05,Hardy Barth Salia EV Charge Controller (Update A),Hardy Barth,Hardy Barth Salia EV Charge Controller,Hardy Barth Salia Board Firmware: <=2.3.81,"CVE-2025-5873, CVE-2025-10371",7.3,High,CWE-434,Energy; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3780,4/21/2026,6/23/2026,2026,ICSA-26-111-06,Zero Motorcycles Firmware (Update A),Zero Motorcycles,Zero Motorcycles Firmware (Update A),Zero Motorcycles firmware <=44,CVE-2026-1354,6.4,Medium,CWE-322,Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3779,4/21/2026,4/21/2026,2026,ICSA-26-111-07,Siemens SCALANCE,Siemens,Siemens SCALANCE,"SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0)","CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146, CVE-2020-26147, CVE-2021-3712, CVE-2022-0778, CVE-2022-31765, CVE-2022-36323, CVE-2022-36324, CVE-2022-36325, CVE-2023-44373",9.1,Critical,"CWE-125, CWE-20, CWE-287, CWE-306, CWE-354, CWE-74, CWE-770, CWE-80, CWE-835, CWE-862",Communications; Information Technology; Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3778,4/21/2026,4/21/2026,2026,ICSA-26-111-08,Siemens RUGGEDCOM CROSSBOW Station Access Controller (SAC),Siemens,Siemens RUGGEDCOM CROSSBOW Station Access Controller (SAC),RUGGEDCOM CROSSBOW Station Access Controller (SAC),CVE-2025-6965,7.7,High,CWE-197,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3777,4/21/2026,4/21/2026,2026,ICSA-26-111-09,Siemens SINEC NMS,Siemens,Siemens SINEC NMS,SINEC NMS,CVE-2026-25654,8.8,High,CWE-639,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3776,4/21/2026,4/21/2026,2026,ICSA-26-111-10,Silex Technology SD-330AC and AMC Manager,Silex Technology,Silex Technology SD-330AC and AMC Manager,"Silex Technology SD-330AC: <=1.42, Silex Technology AMC Manager: <=5.0.2","CVE-2026-32955, CVE-2026-32956, CVE-2026-32957, CVE-2026-32958, CVE-2015-5621, CVE-2026-32959, CVE-2026-32960, CVE-2026-32961, CVE-2026-32962, CVE-2024-24487, CVE-2026-32963, CVE-2026-32964, CVE-2026-32965",9.8,Critical,"CWE-1188, CWE-121, CWE-122, CWE-1395, CWE-226, CWE-266, CWE-306, CWE-321, CWE-327, CWE-79, CWE-93",Information Technology,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3775,4/21/2026,4/21/2026,2026,ICSA-26-111-11,Siemens Industrial Edge Management,Siemens,Siemens Industrial Edge Management,"Industrial Edge Management Pro V1, Industrial Edge Management Pro V2, Industrial Edge Management Virtual",CVE-2026-33892,7.1,High,CWE-305,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3774,4/21/2026,4/21/2026,2026,ICSA-26-111-12,SenseLive X3050,SenseLive,SenseLive X3050,SenseLive X3050: V1.523,"CVE-2026-40630, CVE-2026-25720, CVE-2026-35503, CVE-2026-39462, CVE-2026-27843, CVE-2026-40431, CVE-2026-40623, CVE-2026-27841, CVE-2026-40620, CVE-2026-35064, CVE-2026-25775",9.8,Critical,"CWE-288, CWE-306, CWE-319, CWE-352, CWE-522, CWE-613, CWE-798, CWE-862",Critical Manufacturing; Water and Wastewater Systems; Energy; Information Technology,Worldwide,India,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3773,4/16/2026,4/16/2026,2026,ICSA-26-106-01,Delta Electronics ASDA-Soft,Delta Electronics,Delta Electronics ASDA-Soft,Delta Electronics ASDA-Soft: <=V7.2.2.0,CVE-2026-5726,7.8,High,CWE-121,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3772,4/16/2026,4/16/2026,2026,ICSA-26-106-02,"Horner Automation Cscape and XL4, XL7 PLC",Horner Automation,"Horner Automation Cscape and XL4, XL7 PLC","Horner Automation Cscape: v10.0, Horner Automation XL7 PLC: v15.60, Horner Automation XL4 PLC: v16.32.0",CVE-2026-6284,9.1,Critical,CWE-521,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3771,4/16/2026,4/16/2026,2026,ICSA-26-106-03,Anviz Multiple Products,Anviz,Anviz Multiple Products,Anviz CX7 Firmware: vers:all/*,"CVE-2026-33093, CVE-2026-35061, CVE-2026-32648, CVE-2026-40461, CVE-2026-35682, CVE-2026-35546, CVE-2026-40066, CVE-2026-32324, CVE-2026-31927, CVE-2026-33569, CVE-2026-40434, CVE-2026-32650",9.8,Critical,"CWE-23, CWE-306, CWE-319, CWE-321, CWE-494, CWE-757, CWE-77, CWE-862, CWE-940",Commercial Facilities; Critical Manufacturing; Defense Industrial Base; Energy; Financial Services; Food and Agriculture; Government Facilities; Healthcare and Public Health; Information Technology; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3770,4/16/2026,4/16/2026,2026,ICSA-26-106-04,AVEVA Pipeline Simulation,AVEVA,AVEVA Pipeline Simulation,AVEVA Pipeline Simulation: <=2025_SP1_build_7.1.9497.6351,CVE-2026-5387,9.1,Critical,CWE-862,Critical Manufacturing,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3769,4/9/2026,4/9/2026,2026,ICSA-26-099-01,Contemporary Controls BASC 20T,Contemporary Controls Sedona Alliance,Contemporary Controls BASC 20T,Contemporary Controls Sedona Alliance BASControl20: 3.1,CVE-2025-13926,9.8,Critical,CWE-807,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3768,4/9/2026,4/9/2026,2026,ICSA-26-099-02,GPL Odorizers GPL750,GPL Odorizers,GPL Odorizers GPL750,"GPL Odorizers GPL750 (XL4): >=v1.0|=v4.0|=v13.0|=v18.4|=R5.01.00|=R6.01.00|=R9.01|<=R10.04,"CVE-2025-66594, CVE-2025-66595, CVE-2025-66597, CVE-2025-66598, CVE-2025-66599, CVE-2025-66600, CVE-2025-66601, CVE-2025-66602, CVE-2025-66603, CVE-2025-66604, CVE-2025-66605, CVE-2025-66606, CVE-2025-66607, CVE-2025-66608",8.2,High,"CWE-209, CWE-29, CWE-291, CWE-319, CWE-327, CWE-352, CWE-358, CWE-359, CWE-497, CWE-86",Critical Manufacturing; Energy; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3693,2/10/2026,2/10/2026,2026,ICSA-26-041-02,ZLAN Information Technology Co. ZLAN5143D,ZLAN Information Technology Co.,ZLAN Information Technology Co. ZLAN5143D,ZLAN Information Technology Co. ZLAN5143D: v1.600,"CVE-2026-25084, CVE-2026-24789",9.8,Critical,CWE-306,Critical Manufacturing,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3692,2/10/2026,2/10/2026,2026,ICSA-26-041-03,AVEVA PI Data Archive,AVEVA,AVEVA PI Data Archive,"AVEVA PI Data Archive PI Server: <=2018_SP3_Patch_7, AVEVA PI Data Archive PI Server: 2023, AVEVA PI Data Archive PI Server: 2023_Patch_1, AVEVA PI Data Archive PI Server: 2024",CVE-2026-1507,7.5,High,CWE-248,Critical Manufacturing,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3691,2/10/2026,2/10/2026,2026,ICSA-26-041-04,AVEVA PI to CONNECT Agent,AVEVA,AVEVA PI to CONNECT Agent,AVEVA PI to CONNECT Agent: <=v2.4.2520,CVE-2026-1495,6.5,Medium,CWE-532,Critical Manufacturing,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3690,2/10/2026,2/10/2026,2026,ICSMA-26-041-01,ZOLL ePCR IOS Mobile Application,ZOLL,ZOLL ePCR IOS Mobile Application,ZOLL ePCR IOS Mobile Application: 2.6.7,CVE-2025-12699,5.5,Medium,CWE-538,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3689,2/5/2026,2/5/2026,2026,ICSA-26-036-01,TP-Link Systems Inc. VIGI C330I IP Camera,TP-Link Systems Inc.,TP-Link Systems Inc. VIGI Series IP Camera,"TP-Link Systems Inc. VIGI Cx45 Series Models C345, C445: <=3.1.0_Build_250820_Rel.57668n, TP-Link Systems Inc. VIGI Cx55 Series Models C355, C455: <=3.1.0_Build_250820_Rel.58873n, TP-Link Systems Inc. VIGI Cx85 Series Models C385, C485: <=3.0.2_Build_250630_Rel.71279n, TP-Link Systems Inc. VIGI C340S Series: <=3.1.0_Build_250625_Rel.65381n, TP-Link Systems Inc. VIGI C540S Series Models C540S, EasyCam C540S: <=3.1.0_Build_250625_Rel.66601n, TP-Link Systems Inc. VIGI C540V Series: <=2.1.0_Build_250702_Rel.54300n, TP-Link Systems Inc. VIGI C250 Series: <=2.1.0_Build_250702_Rel.54301n, TP-Link Systems Inc. VIGI Cx50 Series Models C350, C450: <=2.1.0_Build_250702_Rel.54294n, TP-Link Systems Inc. VIGI Cx20I (1.0) Series Models C220I 1.0, C320I 1.0, C420I 1.0: <=2.1.0_Build_251014_Rel.58331n, TP-Link Systems Inc. VIGI Cx20I (1.20) Series Models C220I 1.20, C320I 1.20, C420I 1.20: <=2.1.0_Build_250701_Rel.44071n, TP-Link Systems Inc. VIGI Cx30I (1.0) Series Models C230I 1.0, C330I 1.0, C430I 1.0: <=2.1.0_Build_250701_Rel.45506n, TP-Link Systems Inc. VIGI Cx30I (1.20) Series Models C230I 1.20, C330I 1.20, C430I 1.20: <=2.1.0_Build_250701_Rel.44555n, TP-Link Systems Inc. VIGI Cx30 (1.0) Series Models C230 1.0, C330 1.0, C430 1.0: <=2.1.0_Build_250701_Rel.46796n, TP-Link Systems Inc. VIGI Cx30 (1.20) Series Models C230 1.20, C330 1.20, C430 1.20: <=2.1.0_Build_250701_Rel.46796n, TP-Link Systems Inc. VIGI Cx40I (1.0) Series Models C240I 1.0, C340I 1.0, C440I 1.0: <=2.1.0_Build_250701_Rel.46003n, TP-Link Systems Inc. VIGI Cx40I (1.20) Series Models C240I 1.20, C340I 1.20, C440I 1.20: <=2.1.0_Build_250701_Rel.45041n, TP-Link Systems Inc. VIGI C230I Mini Series: <=2.1.0_Build_250701_Rel.47570n, TP-Link Systems Inc. VIGI C240 1.0 Series: <=2.1.0_Build_250701_Rel.48425n, TP-Link Systems Inc. VIGI C340 2.0 Series: <=2.1.0_Build_250701_Rel.49304n, TP-Link Systems Inc. VIGI C440 2.0 Series: <=2.1.0_Build_250701_Rel.49778n, TP-Link Systems Inc. VIGI C540 2.0 Series: <=2.1.0_Build_250701_Rel.50397n, TP-Link Systems Inc. VIGI C540‑4G Series: <=2.2.0_Build_250826_Rel.56808n, TP-Link Systems Inc. VIGI Cx40‑W Series Models C340‑W 2.0/2.20, C440‑W 2.0, C540‑W 2.0: <=2.1.1_Build_250717, TP-Link Systems Inc. VIGI Cx20 Series Models C320, C420: <=2.1.0_Build_250701_Rel.39597n, TP-Link Systems Inc. VIGI InSight Sx45 Series Models S245, S345, S445: <=3.1.0_Build_250820_Rel.57668n, TP-Link Systems Inc. VIGI InSight Sx55 Series Models S355, S455: <=3.1.0_Build_250820_Rel.58873n, TP-Link Systems Inc. VIGI InSight Sx85 Series Models S285, S385: <=3.0.2_Build_250630_Rel.71279n, TP-Link Systems Inc. VIGI InSight Sx45ZI Series Models S245ZI, S345ZI, S445ZI: <=1.2.0_Build_250820_Rel.60930n, TP-Link Systems Inc. VIGI InSight Sx85PI Series Models S385PI, S485PI: <=1.2.0_Build_250827_Rel.66817n, TP-Link Systems Inc. VIGI InSight S655I Series: <=1.1.1_Build_250625_Rel.64224n, TP-Link Systems Inc. VIGI InSight S345‑4G Series: <=2.1.0_Build_250725_Rel.36867n, TP-Link Systems Inc. VIGI InSight Sx25 Series Models S225, S325, S425: <=1.1.0_Build_250630_Rel.39597n",CVE-2026-0629,8.8,High,CWE-287,Commercial Facilities,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3688,2/5/2026,2/5/2026,2026,ICSA-26-036-02,Mitsubishi Electric MELSEC iQ-R Series,Mitsubishi Electric,Mitsubishi Electric MELSEC iQ-R Series,Mitsubishi Electric MELSEC iQ-R Series R08/16/32/120PCPU firmware: <=48,CVE-2025-15080,9.4,Critical,CWE-1284,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3687,2/5/2026,2/5/2026,2026,ICSA-26-036-03,o6 Automation GmbH Open62541,o6 Automation GmbH,o6 Automation GmbH Open62541,o6 Automation GmbH Open62541: >=1.5-rc1|<1.5-rc2,CVE-2026-1301,5.7,Medium,CWE-787,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3686,2/5/2026,2/5/2026,2026,ICSA-26-036-04,Ilevia EVE X1 Server,Ilevia,Ilevia EVE X1 Server,Ilevia EVE X1: <=4.7.18.0,"CVE-2025-34185, CVE-2025-34184, CVE-2025-34183, CVE-2025-34186, CVE-2025-34187, CVE-2025-34517, CVE-2025-34518, CVE-2025-34512, CVE-2025-34513",9.8,Critical,"CWE-22, CWE-532, CWE-78, CWE-79",Critical Manufacturing,Worldwide,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3685,2/5/2026,2/5/2026,2026,ICSA-26-036-05,Hitachi Energy XMC20,Hitachi Energy,Hitachi Energy XMC20,"XMC20 version R18, XMC20 version R17A and earlier",CVE-2024-3596,9.0,Critical,CWE-924,"Energy, Transportation Systems",Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3684,2/5/2026,2/5/2026,2026,ICSA-26-036-06,Hitachi Energy FOX61x,Hitachi Energy,Hitachi Energy FOX61x,"FOX61x version R18, FOX61x version R17A and earlier",CVE-2024-3596,9.0,Critical,CWE-924,"Energy, Transportation Systems",Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3683,2/3/2026,2/3/2026,2026,ICSA-26-034-01,Mitsubishi Electric FREQSHIP-mini,Mitsubishi Electric,Mitsubishi Electric FREQSHIP-mini for Windows,Mitsubishi Electric FREQSHIP-mini for Windows: >=8.0.0|<=8.0.2,CVE-2025-10314,8.8,High,CWE-276,Critical Manufacturing; Energy; Information Technology; Healthcare and Public Health; Government Facilities,Japan,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3682,2/3/2026,2/3/2026,2026,ICSA-26-034-02,Avation Light Engine Pro,Avation,Avation Light Engine Pro,Avation Light Engine Pro: vers:all/*,CVE-2026-1341,9.8,Critical,CWE-306,Commercial Facilities,Worldwide,Australia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3681,2/3/2026,2/3/2026,2026,ICSA-26-034-03,RISS SRL MOMA Seismic Station,RISS SRL,RISS SRL MOMA Seismic Station,RISS SRL MOMA Seismic Station: <=v2.4.2520,CVE-2026-1632,9.1,Critical,CWE-306,Critical Manufacturing; Dams; Energy; Water and Wastewater Systems; Transportation Systems,Worldwide,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3680,2/3/2026,2/3/2026,2026,ICSA-26-034-04,Synectix LAN 232 TRIO,Synectix,Synectix LAN 232 TRIO,Synectix LAN 232 TRIO: vers:all/*,CVE-2026-1633,10.0,Critical,CWE-306,Critical Manufacturing; Emergency Services; Energy; Information Technology; Transportation Systems; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3679,1/29/2026,2/5/2026,2026,ICSA-26-029-01,KiloView Encoder Series (Update A),KiloView,KiloView Encoder Series,"KiloView Encoder Series E1 hardware Version 1.4: 4.7.2516, KiloView Encoder Series E1 hardware Version 1.6.20: 4.7.2511|4.8.2523|4.8.2611|4.6.2400|4.7.2512|4.8.2561|4.8.2554|4.3.2029|4.8.2555|4.6.2408, KiloView Encoder Series E1-s hardware Version 1.4: 4.7.2516|4.8.2519|4.8.2525|4.8.2611|4.8.2561|4.8.2554|4.8.2523, KiloView Encoder Series E2 hardware Version 1.7.20: 4.8.2611|4.8.2561, KiloView Encoder Series E2 hardware Version 1.8.20: 4.8.2523|4.8.2611|4.8.2554, KiloView Encoder Series G1 hardware Version 1.6.20: 4.8.2561, KiloView Encoder Series P1 hardware Version 1.3.20: 4.8.2633|4.8.2608, KiloView Encoder Series P2 hardware Version 1.8.20: 4.8.2633, KiloView Encoder Series RE1 hardware Version 2.0.00: 4.7.2513, KiloView Encoder Series RE1 hardware Version 3.0.00: 4.8.2519|4.8.2561|4.8.2611|4.8.2525",CVE-2026-1453,9.8,Critical,CWE-306,Communications; Information Technology,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3678,1/29/2026,1/29/2026,2026,ICSA-26-029-02,Rockwell Automation ArmorStart LT,Rockwell Automation,Rockwell Automation ArmorStart LT,"Rockwell Automation ArmorStart LT 290D: <=V2.002, Rockwell Automation ArmorStart LT 291D: <=V2.002, Rockwell Automation ArmorStart LT 294D: <=V2.002","CVE-2025-9464, CVE-2025-9465, CVE-2025-9466, CVE-2025-9278, CVE-2025-9279, CVE-2025-9280, CVE-2025-9281, CVE-2025-9282, CVE-2025-9283",7.5,High,CWE-400,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3677,1/29/2026,1/29/2026,2026,ICSA-26-029-03,Rockwell Automation ControlLogix,Rockwell Automation,Rockwell Automation ControlLogix,"Rockwell Automation ControlLogix Redundancy Enhanced Module Catalog 1756-RM2 Firmware: vers:all/*, Rockwell Automation ControlLogix Redundancy Enhanced Module Catalog 1756-RM2XT Firmware: vers:all/*",CVE-2025-14027,7.5,High,CWE-401,Chemical; Energy; Critical Manufacturing; Food and Agriculture; Transportation Systems; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3676,1/27/2026,1/27/2026,2026,ICSA-26-027-01,iba Systems ibaPDA,iba Systems,iba Systems ibaPDA,iba Systems ibaPDA: 8.12.0,CVE-2025-14988,9.8,Critical,CWE-732,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3675,1/27/2026,1/27/2026,2026,ICSA-26-027-02,Festo Didactic SE MES PC,Festo Didactic SE,Festo Didactic SE MES PC,Festo Didactic SE MES PC shipped with Windows 10,"CVE-2019-11036, CVE-2023-25727, CVE-2021-2011, CVE-2022-32083, CVE-2021-46668, CVE-2018-19518, CVE-2021-2194, CVE-2019-11049, CVE-2022-31626, CVE-2022-32084, CVE-2022-32088, CVE-2022-27377, CVE-2020-2922, CVE-2019-9638, CVE-2019-11044, CVE-2020-7068, CVE-2020-7069, CVE-2015-2301, CVE-2023-0568, CVE-2022-27458, CVE-2021-21706, CVE-2022-27452, CVE-2020-7071, CVE-2022-27387, CVE-2022-27376, CVE-2019-11043, CVE-2021-2032, CVE-2021-2007, CVE-2019-11045, CVE-2022-27445, CVE-2022-27457, CVE-2022-27384, CVE-2022-23808, CVE-2023-0567, CVE-2019-9025, CVE-2022-27379, CVE-2019-9637, CVE-2021-27928, CVE-2021-21703, CVE-2020-2760, CVE-2021-2166, CVE-2015-2787, CVE-2022-23807, CVE-2020-2752, CVE-2021-46666, CVE-2020-2814, CVE-2020-7065, CVE-2021-21705, CVE-2020-7062, CVE-2019-11039, CVE-2019-11035, CVE-2022-27447, CVE-2019-11046, CVE-2022-27446, CVE-2022-27386, CVE-2019-9639, CVE-2019-11042, CVE-2022-27385, CVE-2020-7059, CVE-2020-7070, CVE-2022-32091, CVE-2015-2348, CVE-2019-9020, CVE-2021-35604, CVE-2022-27444, CVE-2018-14883, CVE-2014-9705, CVE-2020-7064, CVE-2022-27382, CVE-2020-7063, CVE-2021-2372, CVE-2019-9021, CVE-2018-14851, CVE-2022-27448, CVE-2021-46663, CVE-2021-2180, CVE-2014-9709, CVE-2023-25690, CVE-2022-32082, CVE-2022-31629, CVE-2019-9022, CVE-2016-3078, CVE-2023-0662, CVE-2021-2022, CVE-2022-32089, CVE-2019-11048, CVE-2021-46669, CVE-2019-11047, CVE-2022-27383, CVE-2021-46667, CVE-2022-32087, CVE-2022-36760, CVE-2020-7060, CVE-2018-17082, CVE-2019-9640, CVE-2021-46661, CVE-2019-11034, CVE-2022-27456, CVE-2020-7061, CVE-2022-27455, CVE-2021-2144, CVE-2021-2154, CVE-2022-21595, CVE-2019-11040, CVE-2021-2389, CVE-2023-27522, CVE-2020-2812, CVE-2021-46665, CVE-2022-32086, CVE-2022-32085, CVE-2021-21704, CVE-2020-7066, CVE-2022-31628, CVE-2021-46662, CVE-2016-5385, CVE-2022-37436, CVE-2013-6501, CVE-2021-21702, CVE-2019-9024, CVE-2019-9023, CVE-2022-27449, CVE-2021-46664, CVE-2019-11050, CVE-2021-21708, CVE-2022-31625, CVE-2022-32081, CVE-2022-27378, CVE-2006-20001, CVE-2018-19935, CVE-2022-4900, CVE-2018-12882, CVE-2019-9641, CVE-2022-27380, CVE-2022-27381, CVE-2021-21707, CVE-2022-27451, CVE-2020-2780, CVE-2019-11041, CVE-2021-2174",9.8,Critical,"CWE-732, CWE-126, CWE-79, CWE-20, CWE-229, CWE-400, CWE-88, CWE-415, CWE-120, CWE-416, CWE-200, CWE-125, CWE-170, CWE-131, CWE-24, CWE-617, CWE-89, CWE-916, CWE-787, CWE-266, CWE-94, CWE-287, CWE-121, CWE-476, CWE-909, CWE-626, CWE-119, CWE-281, CWE-444, CWE-190, CWE-674, CWE-601, CWE-113, CWE-74, CWE-590, CWE-908, CWE-159, CWE-1173, CWE-77",Commercial Facilities; Communications; Critical Manufacturing; Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3674,1/27/2026,1/27/2026,2026,ICSA-26-027-03,Schneider Electric Zigbee Products,Schneider Electric,Schneider Electric Zigbee Products,"Wiser iTRV2 All Versions, Wiser iTRV3 All Versions, Wiser RTR2 All Versions, Wiser UFH All Versions, Wiser 16A Electrical Heat Switch All Versions, Wiser Boiler Relay All Versions, Exxact cFMT 16a All Versions, Elko cFMT 16a All Versions, Odace cFMT 2a All Versions, Merten cFMT 16a All Versions, Merten cFMT 2a All Versions, Wiser Power Micromodule All Versions, Wiser FIP Micromodule All Versions, Iconic, Wiser Connected Smart Dimmer All Versions, Iconic, Wiser Connected Smart Switch, 2AX All Versions, Iconic, Wiser Connected Smart Switch, 10AX All Versions, Iconic, Connected AC Fan Controller All Versions, Iconic, Connected Smart Socket All Versions, Wiser Connected Application Module 1-Gang All Versions, Wiser Connected Application Module 2-Gang All Versions, Wiser Connected Push Button Dimmer All Versions, Wiser Connected Push Button Switch All Versions, Wiser Connected Push Button Shutter All Versions, Wiser Connected Motion Dimmer All Versions, Wiser Connected Motion Switch All Versions, Wiser Connected Rotary Dimmer All Versions, Connected Wireless Switch All Versions, Micromodule Switch All Versions, Micromodule Dimmer All Versions, Micromodule Shutter All Versions, Connected Single Socket Outlet All Versions, Connected Double Socket Outlet All Versions, Fuga Connected Socket Outlet All Versions, Mureva EV Link All Versions","CVE-2024-6350, CVE-2024-6351, CVE-2024-6352, CVE-2024-10106, CVE-2024-7322",6.5,Medium,"CWE-120, CWE-400",Commercial Facilities; Critical Manufacturing; Energy; Information Technology; Transportation Systems,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3673,1/27/2026,1/27/2026,2026,ICSA-26-027-04,Johnson Controls Products,Johnson Controls Inc.,Johnson Controls Products,"Johnson Controls Application and Data Server (ADS): <=Metasys_14.1, Johnson Controls Extended Application and Data Server (ADX): Metasys_14.1, Johnson Controls LCS8500: >=Metasys_installation__12.0|<=14.1, Johnson Controls NAE8500: >=Metasys_installation__12.0|<=14.1, Johnson Controls System Configuration Tool (SCT): <=17.1, Johnson Controls Controller Configuration Tool (CCT): <=17.0",CVE-2025-26385,10.0,Critical,CWE-77,Commercial Facilities; Critical Manufacturing; Energy; Government Facilities; Transportation Systems,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3672,1/13/2026,5/21/2026,2026,ICSA-26-022-01,Schneider Electric EcoStruxure Process Expert (Update A),Schneider Electric,Schneider Electric EcoStruxure Process Expert (Update A),"EcoStruxure Process Expert versions prior to 2025, EcoStruxure Process Expert for AVEVA System Platform versions prior to 2025",CVE-2025-13905,7.3,High,CWE-276,Critical Manufacturing; Energy; Commercial Facilities,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3671,1/22/2026,1/22/2026,2026,ICSA-26-022-02,AutomationDirect CLICK Programmable Logic Controller,AutomationDirect,AutomationDirect CLICK Programmable Logic Controller,"AutomationDirect CLICK Programmable Logic Controller: C0-0x, AutomationDirect CLICK Programmable Logic Controller: C0-1x, AutomationDirect CLICK Programmable Logic Controller: C2-x","CVE-2025-67652, CVE-2025-25051",6.1,Medium,"CWE-256, CWE-261",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3670,1/22/2026,1/22/2026,2026,ICSA-26-022-03,Rockwell Automation CompactLogix 5370,Rockwell Automation, Rockwell Automation CompactLogix 5370,"Rockwell Automation CompactLogix 5370: <=34.013, Rockwell Automation CompactLogix 5370: <=35.012, Rockwell Automation CompactLogix 5370: 36.011",CVE-2025-11743,6.5,Medium,CWE-1284,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3669,1/22/2026,1/22/2026,2026,ICSA-26-022-04,Johnson Controls Inc. iSTAR Configuration Utility (ICU) tool,Johnson Controls Inc.,Johnson Controls Inc. iSTAR Configuration Utility (ICU) tool,Johnson Controls Inc. iSTAR Configuration Utility (ICU) tool: <=6.9.7,CVE-2025-26386,7.1,High,CWE-121,Commercial Facilities; Critical Manufacturing; Energy; Government Facilities; Transportation Systems,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3668,1/22/2026,1/22/2026,2026,ICSA-26-022-05,Weintek cMT X Series HMI EasyWeb Service,Weintek,Weintek cMT X Series HMI EasyWeb Service,"Weintek cMT3072XH: >=20200630|<20241112, Weintek cMT3072XH(T): >=20200630|<20241112, Weintek cMT-SVRX-820: >=20220413|<20240919, Weintek cMT-CTRL01: >=20230308|<20250827","CVE-2025-14750, CVE-2025-14751",8.3,High,"CWE-472, CWE-620",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3667,1/22/2026,1/22/2026,2026,ICSA-26-022-06,Hubitat Elevation Hubs,Hubitat,Hubitat Elevation Hubs,"Hubitat Elevation C3: =10.97|<=10.97.1, Mitsubishi Electric ICONICS Suite: >=10.97|<=10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64: >=10.97|<=10.97.1, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: >=10.97|<=10.97.1","CVE-2022-29834, CVE-2022-33315, CVE-2022-33316, CVE-2022-33317, CVE-2022-33318, CVE-2022-33319, CVE-2022-33320",9.8,Critical,"CWE-125, CWE-22, CWE-502, CWE-829",Critical Manufacturing,Worldwide,"United States, Japan",Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3413,7/22/2025,7/22/2025,2025,ICSA-25-203-01,DuraComm DP-10iN-100-MU,DuraComm Corporation,SPM-500 DP-10iN-100-MU,"The following versions of DuraComm SPM-500 DP-10iN-100-MU, a power distribution panel, are affected: SPM-500 DP-10iN-100-MU: Version 4.10 and prior.","CVE-2025-41425, CVE-2025-48733, CVE-2025-53703",8.7,High,"CWE-79, CWE-306, CWE-319",Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3412,7/22/2025,7/22/2025,2025,ICSA-25-203-02,Lantronix Provisioning Manager,Lantronix,Provisioning Manager,The following Lantronix products are affected: Provisioning Manager: Versions 7.10.2 and prior.,CVE-2025-7766,8.6,High,CWE-611,Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3411,7/22/2025,7/22/2025,2025,ICSA-25-203-03,Schneider Electric EcoStruxure,Schneider Electric,EcoStruxure Power Monitoring Expert (PME) and EcoStruxure Power Operation (EPO),Schneider Electric reports the following products are affected: EcoStruxure Power Monitoring Expert (PME): 2023 EcoStruxure Power Monitoring Expert (PME): 2023 R2 EcoStruxure Power Monitoring Expert (PME): 2024 EcoStruxure Power Monitoring Expert (PME): 2024 R2 EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module: 2022 EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module: 2024.,CVE-2025-6788,5.3,Medium,CWE-668,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3410,7/22/2025,2/26/2026,2025,ICSA-25-203-04,Schneider Electric EcoStruxure Power Operation (Update A),Schneider Electric,Schneider Electric EcoStruxure Power Operation (Update A),"Schneider Electric EcoStruxure Power Operation (EPO) 2022: <=CU6, Schneider Electric EcoStruxure Power Operation (EPO) 2024: <=CU1","CVE-2023-50447, CVE-2024-28219, CVE-2022-45198, CVE-2023-5217, CVE-2023-35945, CVE-2023-44487",8.8,High,"CWE-400, CWE-409, CWE-680, CWE-787, CWE-95",Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3409,7/22/2025,7/22/2025,2025,ICSA-25-203-05,Schneider Electric System Monitor Application,Schneider Electric,System Monitor Application,Schneider Electric reports the following products are affected: System Monitor application in Harmony Industrial PC series: All versions System Monitor application in Pro-face Industrial PC series: All versions.,CVE-2020-11023,6.9,Medium,CWE-79,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3408,7/22/2025,7/22/2025,2025,ICSA-25-203-06,Schneider Electric EcoStruxture IT Data Center Expert,Schneider Electric,EcoStruxure IT Data Center Expert,Schneider Electric reports the following product is affected: EcoStruxure IT Data Center Expert: Versions v8.3 and prior.,"CVE-2025-50121, CVE-2025-50122, CVE-2025-50123, CVE-2025-50124, CVE-2025-50125, CVE-2025-6438",9.5,Critical,"CWE-78, CWE-331, CWE-94, CWE-918, CWE-269, CWE-611",Critical Manufacturing,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3407,7/17/2025,7/17/2025,2025,ICSA-25-198-01,Leviton AcquiSuite and Energy Monitoring Hub,Leviton,"AcquiSuite, Energy Monitoring Hub",The following versions of Leviton AcquiSuite and Leviton Energy Monitoring Hub are affected: AcquiSuite: Version A8810 Energy Monitoring Hub: Version A8812.,CVE-2025-6185,8.7,High,CWE-79,Critical Manufacturing; Commercial Facilities; Government Facilities; Energy; Food and Agriculture; Healthcare and Public Health; Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3406,7/17/2025,7/17/2025,2025,ICSMA-25-198-01,Panoramic Corporation Digital Imaging Software,Panoramic Corporation,Digital Imaging Software,The following Panoramic Corporation products are affected: Digital Imaging Software: Version 9.1.2.7600.,CVE-2024-22774,8.5,High,CWE-427,Healthcare and Public Health,North America,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3405,7/15/2025,7/15/2025,2025,ICSA-25-196-01,Hitachi Energy Asset Suite,Hitachi Energy,Energy Asset Suite,"Hitachi Energy reports that the following products are affected: Asset Suite AnyWhere for Inventory (AWI) Android mobile app: Versions 11.5 and prior (CVE-2019-9262, CVE-2019-9429, CVE-2019-9256, CVE-2019-9290) Asset Suite 9 series: Version 9.6.4.4 (CVE-2025-1484, CVE-2025-2500) Asset Suite 9 series: Version 9.7 (CVE-2025-2500).","CVE-2019-9256, CVE-2019-9262, CVE-2019-9290, CVE-2019-9429, CVE-2025-1484, CVE-2025-2500",9.1,Critical,"CWE-184, CWE-256, CWE-787, CWE-763",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3404,7/3/2025,5/19/2026,2025,ICSA-25-196-02,ABB RMC-100 (Update A),ABB,ABB RMC-100 (Update A),"RMC-100 Version (>=2105457-043|<=2105457-045) , RMC-100 LITE Version (>=2106229-015|<=2106229-016)","CVE-2025-6074, CVE-2025-6073, CVE-2025-6072, CVE-2025-6071",7.5,High,"CWE-121, CWE-321",Critical Manufacturing,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3403,7/15/2025,7/15/2025,2025,ICSA-25-196-03,LITEON IC48A and IC80A EV Chargers,LITEON,IC48A and IC80A,The following versions of LITEON EV chargers are affected: LITEON IC48A: Firmware versions prior to 01.00.19r LITEON IC80A: Firmware versions prior to 01.01.12e.,CVE-2025-7357,8.7,High,CWE-256,Commercial Facilities; Energy; Transportation Systems,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3402,7/10/2025,7/10/2025,2025,ICSA-25-191-01,Siemens SINEC NMS,Siemens,SINEC NMS,Siemens reports the following products are affected: Siemens SINEC NMS: All versions prior to V4.0.,"CVE-2025-40735, CVE-2025-40736, CVE-2025-40737, CVE-2025-40738",9.3,Critical,"CWE-89, CWE-306, CWE-22",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3401,7/10/2025,7/10/2025,2025,ICSA-25-191-02,Siemens Solid Edge,Siemens,Solid Edge SE2025,Siemens reports the following products are affected: Solid Edge SE2025: All versions prior to V225.0 Update 5.,"CVE-2025-40739, CVE-2025-40740, CVE-2025-40741",7.3,High,"CWE-125, CWE-121",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3400,7/10/2025,7/10/2025,2025,ICSA-25-191-03,Siemens TIA Administrator,Siemens,TIA Administrator,Siemens reports that the following products are affected: TIA Administrator: All versions prior to V3.0.6.,"CVE-2025-23364, CVE-2025-23365",8.5,High,"CWE-347, CWE-284",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3399,7/10/2025,7/10/2025,2025,ICSA-25-191-04,Siemens SIMATIC CN 4100,Siemens,SIMATIC CN 4100,Siemens reports that the following products are affected: SIMATIC CN 4100: All versions prior to V4.0.,CVE-2025-40593,7.1,High,CWE-20,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3398,7/10/2025,7/10/2025,2025,ICSA-25-191-05,Siemens TIA Project-Server and TIA Portal,Siemens,Project-Server and TIA Portal,Siemens reports that the following products are affected: TIA Project-Server: Versions prior to V2.1.1 TIA Project-Server V17: All versions Totally Integrated Automation Portal (TIA Portal) V17: All versions Totally Integrated Automation Portal (TIA Portal) V18: All versions Totally Integrated Automation Portal (TIA Portal) V19: All versions Totally Integrated Automation Portal (TIA Portal) V20: Versions prior to V20 Update 3.,CVE-2025-27127,5.3,Medium,CWE-434,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3397,7/10/2025,7/10/2025,2025,ICSA-25-191-06,Siemens SIPROTEC 5,Siemens,SIPROTEC 5,Siemens reports that the following products are affected: SIPROTEC 5 6MD84 (CP300): All versions SIPROTEC 5 7SA86 (CP300): All versions SIPROTEC 5 7SA87 (CP300): All versions SIPROTEC 5 7SD82 (CP100): All versions SIPROTEC 5 7SD82 (CP150): All versions SIPROTEC 5 7SD86 (CP300): All versions SIPROTEC 5 7SD87 (CP300): All versions SIPROTEC 5 7SJ81 (CP100): All versions SIPROTEC 5 7SJ81 (CP150): All versions SIPROTEC 5 7SJ82 (CP100): All versions SIPROTEC 5 7SJ82 (CP150): All versions SIPROTEC 5 6MD85 (CP300): All versions SIPROTEC 5 7SJ85 (CP300): All versions SIPROTEC 5 7SJ86 (CP300): All versions SIPROTEC 5 7SK82 (CP100): All versions SIPROTEC 5 7SK82 (CP150): All versions SIPROTEC 5 7SK85 (CP300): All versions SIPROTEC 5 7SL82 (CP100): All versions SIPROTEC 5 7SL82 (CP150): All versions SIPROTEC 5 7SL86 (CP300): All versions SIPROTEC 5 7SL87 (CP300): All versions SIPROTEC 5 7SS85 (CP300): All versions SIPROTEC 5 6MD86 (CP300): All versions SIPROTEC 5 7ST85 (CP300): All versions SIPROTEC 5 7ST86 (CP300): All versions SIPROTEC 5 7SX82 (CP150): All versions SIPROTEC 5 7SX85 (CP300): All versions SIPROTEC 5 7SY82 (CP150): All versions SIPROTEC 5 7UM85 (CP300): All versions SIPROTEC 5 7UT82 (CP100): All versions SIPROTEC 5 7UT82 (CP150): All versions SIPROTEC 5 7UT85 (CP300): All versions SIPROTEC 5 7UT86 (CP300): All versions SIPROTEC 5 6MD89 (CP300): All versions SIPROTEC 5 7UT87 (CP300): All versions SIPROTEC 5 7VE85 (CP300): All versions SIPROTEC 5 7VK87 (CP300): All versions SIPROTEC 5 7VU85 (CP300): All versions SIPROTEC 5 Compact 7SX800 (CP050): All versions SIPROTEC 5 6MD89 (CP300) V9.6: All versions SIPROTEC 5 6MU85 (CP300): All versions SIPROTEC 5 7KE85 (CP300): All versions SIPROTEC 5 7SA82 (CP100): All versions SIPROTEC 5 7SA82 (CP150): All versions.,CVE-2025-40742,6.0,Medium,CWE-598,Energy; Critical Manufacturing,Worldwide,Siemens,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3396,7/10/2025,7/10/2025,2025,ICSA-25-191-07,Delta Electronics DTM Soft,Delta Electronics,DTM Soft,The following Delta Electronics products are affected: DTM Soft: Versions 1.6.0.0 and prior.,CVE-2025-53415,8.4,High,CWE-502,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3395,7/10/2025,7/10/2025,2025,ICSA-25-191-08,Advantech iView,Advantech,iView,The following Advantech products are affected: iView: Versions prior to 5.7.05 build 7057.,"CVE-2025-41442, CVE-2025-46704, CVE-2025-48891, CVE-2025-52459, CVE-2025-52577, CVE-2025-53397, CVE-2025-53475, CVE-2025-53509, CVE-2025-53515, CVE-2025-53519",8.7,High,"CWE-79, CWE-89, CWE-22, CWE-88",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3394,7/10/2025,7/10/2025,2025,ICSA-25-191-09,KUNBUS RevPi Webstatus,KUNBUS,RevPi Webstatus,KUNBUS reports the following products are affected: Revolution Pi Webstatus: Version 2.4.5 and prior Revolution Pi OS Bullseye: 04/2024 Revolution Pi OS Bullseye: 09/2023 Revolution Pi OS Bullseye: 07/2023 Revolution Pi OS Bullseye: 06/2023 Revolution Pi OS Bullseye: 02/2024.,CVE-2025-41646,9.3,Critical,CWE-303,Critical Manufacturing; Energy; Transportation Systems; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3393,7/10/2025,9/18/2025,2025,ICSA-25-191-10,End-of-Train and Head-of-Train Remote Linking Protocol (Update C),End-of-Train and Head-of-Train remote linking protocol,End-of-Train and Head-of-Train devices,The following version of End-of-Train and Head-of-Train remote linking protocol is affected: End-of-Train and Head-of-Train remote linking protocol: All versions The following specific devices have been confirmed to be affected by their respective manufacturers: Wabtec TrainLink NG End of Train (NGEOT) Wabtec TrainLink NG3 ATX End of Train (NG3 EOT) Wabtec TrainLink NG4 ATX End of Train (NG4 EOT) Wabtec TrainLink NG5 ATX End of Train (NG5 EOT) Siemens Trainguard EOT Siemens Trainguard HOT DPS Electronics DPS 2020-He-LD: ETD External 2dB Antenna DPS Electronics DPS 2020-He: ETD Internal Antenna DPS Electronics DPS 3030-CM-MAG: HTD Console Mount DPS Electronics DPS 3030-I-MAG HTD: HTD Integrated.,CVE-2025-1727,7.2,High,CWE-1390,Transportation Systems,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3392,7/8/2025,7/8/2025,2025,ICSA-25-189-01,Emerson ValveLink Products,Emerson,ValveLink Products,The following ValveLink products are affected: ValveLink SOLO: All versions prior to ValveLink 14.0 ValveLink DTM: All versions prior to ValveLink 14.0 ValveLink PRM: All versions prior to ValveLink 14.0 ValveLink SNAP-ON: All versions prior to ValveLink 14.0.,"CVE-2025-46358, CVE-2025-48496, CVE-2025-50109, CVE-2025-52579, CVE-2025-53471",9.3,Critical,"CWE-316, CWE-693, CWE-427, CWE-20",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3391,7/3/2025,2/5/2026,2025,ICSA-25-184-01,Hitachi Energy Relion 670/650 and SAM600-IO Series (Update C),Hitachi Energy,Hitachi Energy Relion 670/650 and SAM600-IO Series,"Relion 670/650 series version 2.2.6 up to revision 2.2.6.3, Relion 670/650 and SAM600-IO series version 2.2.5 up to revision 2.2.5.7, Relion 670/650 series version 2.2.4 up to revision 2.2.4.5, Relion 670 series version 2.2.3 up to revision 2.2.3.7, Relion 670 series version 2.2.2 up to revision 2.2.2.6, Relion 670/650 series version 2.2.1 up to revision 2.2.1.8, Relion 670/650 series version 2.2.0 up to revision 2.2.0.13, Relion 670/650 series version 2.1 all revisions, Relion 670 series version 2.0 all revisions, Relion 670/650 series version 1 all subversions and revisions",CVE-2025-1718,6.5,Medium,CWE-754,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3390,7/3/2025,7/3/2025,2025,ICSA-25-184-02,Hitachi Energy MicroSCADA X SYS600,Hitachi Energy,MicroSCADA X SYS600,"Hitachi Energy reports that the following products are affected: Hitachi Energy MicroSCADA Pro/X SYS600: version 10.0 up to 10.6 (CVE-2025-39201, CVE-2025-39202, CVE-2025-39204, CVE-2025-39205), Hitachi Energy MicroSCADA Pro/X SYS600: version 10.5 up to 10.6 (CVE-2025-39203), Hitachi Energy MicroSCADA Pro/X SYS600: version 10.3 up to 10.6 (CVE-2025-39205).","CVE-2025-39201, CVE-2025-39202, CVE-2025-39203, CVE-2025-39204, CVE-2025-39205",7.1,High,"CWE-276, CWE-73, CWE-354, CWE-202, CWE-295",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3389,7/3/2025,2/5/2026,2025,ICSA-25-184-03,Mitsubishi Electric MELSOFT Update Manager (Update B),Mitsubishi Electric,Mitsubishi Electric MELSOFT Update Manager,Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M: >=1.000A|<1.012N,"CVE-2024-11477, CVE-2025-0411",8.2,High,"CWE-191, CWE-693",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3388,7/3/2025,7/3/2025,2025,ICSA-25-184-04,Mitsubishi Electric MELSEC iQ-F Series,Mitsubishi Electric,MELSEC iQ-F Series,"The following version of MELSEC iQ-F Series is affected: FX5U-32MT/ES: All versions, FX5U-32MT/DS: All versions, FX5U-32MT/ESS: All versions, FX5U-32MT/DSS: All versions, FX5U-32MR/ES: All versions, FX5U-32MR/DS: All versions, FX5U-64MT/ES: All versions, FX5U-64MT/DS: All versions, FX5U-64MT/ESS: All versions, FX5U-64MT/DSS: All versions, FX5U-64MR/ES: All versions, FX5U-64MR/DS: All versions, FX5U-80MT/ES: All versions, FX5U-80MT/DS: All versions, FX5U-80MT/ESS: All versions, FX5U-80MT/DSS: All versions, FX5U-80MR/ES: All versions, FX5U-80MR/DS: All versions, FX5UC-32MT/D: All versions, FX5UC-32MT/DSS: All versions, FX5UC-64MT/D: All versions, FX5UC-64MT/DSS: All versions, FX5UC-96MT/D: All versions, FX5UC-96MT/DSS: All versions, FX5UC-32MT/DS-TS: All versions, FX5UC-32MT/DSS-TS: All versions, FX5UC-32MR/DS-TS: All versions, FX5UJ-24MT/ES: All versions, FX5UJ-24MT/DS: All versions, FX5UJ-24MT/ESS: All versions, FX5UJ-24MT/DSS: All versions, FX5UJ-24MR/ES: All versions, FX5UJ-24MR/DS: All versions, FX5UJ-40MT/ES: All versions, FX5UJ-40MT/DS: All versions, FX5UJ-40MT/ESS: All versions, FX5UJ-40MT/DSS: All versions, FX5UJ-40MR/ES: All versions, FX5UJ-40MR/DS: All versions, FX5UJ-60MT/ES: All versions, FX5UJ-60MT/DS: All versions, FX5UJ-60MT/ESS: All versions, FX5UJ-60MT/DSS: All versions, FX5UJ-60MR/ES: All versions, FX5UJ-60MR/DS: All versions, FX5UJ-24MT/ES-A: All versions, FX5UJ-24MR/ES-A: All versions, FX5UJ-40MT/ES-A: All versions, FX5UJ-40MR/ES-A: All versions, FX5UJ-60MT/ES-A: All versions, FX5UJ-60MR/ES-A: All versions, FX5S-30MT/ES: All versions, FX5S-30MT/DS: All versions, FX5S-30MT/ESS: All versions, FX5S-30MT/DSS: All versions, FX5S-30MR/ES: All versions, FX5S-30MR/DS: All versions, FX5S-40MT/ES: All versions, FX5S-40MT/DS: All versions, FX5S-40MT/ESS: All versions, FX5S-40MT/DSS: All versions, FX5S-40MR/ES: All versions, FX5S-40MR/DS: All versions, FX5S-60MT/ES: All versions, FX5S-60MT/DS: All versions, FX5S-60MT/ESS: All versions, FX5S-60MT/DSS: All versions, FX5S-60MR/ES: All versions, FX5S-60MR/DS: All versions, FX5S-80MT/ES: All versions, FX5S-80MT/ESS: All versions, FX5S-80MR/ES: All versions, FX5-CCLGN-MS: All versions.",CVE-2025-5241,6.9,Medium,CWE-645,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3387,7/1/2025,7/1/2025,2025,ICSA-25-182-01,"FESTO Didactic CP, MPS 200, and MPS 400 Firmware",Festo Didactic SE,"CP, MPS 200, MPS 400",FESTO Didactic reports that the following products are affected: FESTO Didactic Firmware Siemens Simatic S7-1500 / ET200SP (< V2.9.2) installed on FESTO Didactic CP including S7 PLC(All versions): All versions FESTO Didactic Firmware Siemens Simatic S7-1500 / ET200SP (< V2.9.2) installed on FESTO Didactic MPS 200 Systems(All versions): All versions FESTO Didactic Firmware Siemens Simatic S7-1500 / ET200SP (< V2.9.2) installed on FESTO Didactic MPS 400 Systems(All versions): All versions.,CVE-2020-15782,9.8,Critical,CWE-119,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3386,7/1/2025,7/1/2025,2025,ICSA-25-182-02,"FESTO Automation Suite, FluidDraw, and Festo Didactic Products","Festo, Festo Didactic SE","CIROS Studio / Education, Automation Suite, FluidDraw, FluidSIM, MES-PC","FESTO, FESTO Didactic reports that the following products are affected: FESTO Didactic CIROS Studio / Education: 6.0.0 - 6.4.6 FESTO Didactic CIROS Studio / Education: 7.0.0 - 7.1.7 FESTO Festo Automation Suite: <= 2.6.0.481 FESTO FluidDraw: P6 <= 6.2k FESTO FluidDraw: 365 <= 7.0a FESTO Didactic FluidSIM: 5 all versions FESTO Didactic FluidSIM: 6 <= 6.1c FESTO Didactic MES-PC: shipped before December 2023.",CVE-2023-3935,9.8,Critical,CWE-787,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3385,7/1/2025,7/1/2025,2025,ICSA-25-182-03,FESTO CODESYS,Festo,CODESYS,FESTO reports that the following products are affected: FESTO CODESYS Gateway Server V2: All versions FESTO CODESYS Gateway Server V2: prior to V2.3.9.38.,"CVE-2022-31802, CVE-2022-31803, CVE-2022-31804",9.8,Critical,"CWE-187, CWE-400, CWE-789",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3384,7/1/2025,7/1/2025,2025,ICSA-25-182-04,"FESTO Hardware Controller, Hardware Servo Press Kit",Festo,"Hardware Controller, Hardware Servo Press Kit",FESTO reports the following products are affected: Festo Firmware installed on Festo Hardware Controller CECC-X-M1: Version 4.0.14 Festo Firmware installed on Festo Hardware Controller CECC-X-M1: Versions 3.8.14 and prior Festo Firmware installed on Festo Hardware Controller CECC-X-M1-MV: Versions 3.8.14 and prior Festo Firmware installed on Festo Hardware Controller CECC-X-M1-MV: Version 4.0.14 Festo Firmware installed on Festo Hardware Controller CECC-X-M1-MV-S1: Version 4.0.14 Festo Firmware installed on Festo Hardware Controller CECC-X-M1-MV-S1: Versions 3.8.14 and prior Festo Firmware installed on Festo Hardware Controller CECC-X-M1-YS-L1: Versions 3.8.14 and prior Festo Firmware installed on Festo Hardware Controller CECC-X-M1-YS-L2: Versions 3.8.14 and prior Festo Firmware installed on Festo Hardware Controller CECC-X-M1-Y-YJKP: Versions 3.8.14 and prior Festo Firmware installed on Festo Hardware Servo Press Kit YJKP: Versions 3.8.14 and prior Festo Firmware installed on Festo Hardware Servo Press Kit YJKP-: Versions 3.8.14 and prior.,"CVE-2022-30308, CVE-2022-30309, CVE-2022-30310, CVE-2022-30311",9.8,Critical,CWE-78,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3383,7/1/2025,7/1/2025,2025,ICSA-25-182-05,Voltronic Power and PowerShield UPS Monitoring Software,"Voltronic Power, PowerShield","Viewpower, NetGuard","The following Voltronic Power and PowerShield UPS monitoring software is affected, as well as other derivative products: Voltronic Power Viewpower: Version 1.04-24215 and prior Voltronic Power ViewPower Pro: Version 2.2165 and prior Powershield NetGuard: Version 1.04-22119 and prior.","CVE-2022-31491, CVE-2022-43110",10.0,Critical,"CWE-749, CWE-425",Commercial Facilities; Critical Manufacturing; Energy,Worldwide,"Taiwan, Australia",Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3382,7/1/2025,9/2/2025,2025,ICSA-25-182-06,Hitachi Energy Relion 670/650 and SAM600-IO Series (Update A),Hitachi Energy,Relion 670/650 and SAM600-IO,Hitachi Energy reports that the following products are affected: Hitachi Energy Relion 650: Version 2.2.4.4 Hitachi Energy Relion 650: Version 2.2.5.6 Hitachi Energy Relion 650: All versions from 2.2.6.0 to 2.2.6.2 Hitachi Energy Relion 670: Version 2.2.2.6 Hitachi Energy Relion 670: Version 2.2.3.7 Hitachi Energy Relion 670: Version 2.2.4.4 Hitachi Energy Relion 670: Version 2.2.5.6 Hitachi Energy Relion 670: All versions from 2.2.6.0 to 2.2.6.2 Hitachi Energy SAM600-IO: Version 2.2.5.6.,CVE-2025-2403,8.7,High,CWE-770,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3381,7/1/2025,7/1/2025,2025,ICSA-25-182-07,Hitachi Energy MSM,Hitachi Energy,Modular Switchgear Monitoring (MSM),Hitachi Energy reports the following products are affected: Hitachi Energy MSM: Version 2.2.9 and prior.,CVE-2020-11022,5.3,Medium,CWE-79,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3380,6/26/2025,12/23/2025,2025,ICSA-25-177-01,Mitsubishi Electric Air Conditioning Systems (Update B),Mitsubishi Electric,Mitsubishi Electric Air Conditioning Systems,"Mitsubishi Electric G-50: vers:all/*, Mitsubishi Electric G-50-W: vers:all/*, Mitsubishi Electric G-50A: vers:all/*, Mitsubishi Electric GB-50: vers:all/*, Mitsubishi Electric GB-50A: vers:all/*, Mitsubishi Electric GB-24A: vers:all/*, Mitsubishi Electric G-150AD: vers:all/*, Mitsubishi Electric AG-150A-A: vers:all/*, Mitsubishi Electric AG-150A-J: vers:all/*, Mitsubishi Electric GB-50AD: vers:all/*, Mitsubishi Electric GB-50ADA-A: vers:all/*, Mitsubishi Electric GB-50ADA-J: vers:all/*, Mitsubishi Electric EB-50GU-A: vers:all/*, Mitsubishi Electric EB-50GU-J: vers:all/*, Mitsubishi Electric AE-200J: vers:all/*, Mitsubishi Electric AE-200A: vers:all/*, Mitsubishi Electric AE-200E: vers:all/*, Mitsubishi Electric AE-50J: vers:all/*, Mitsubishi Electric AE-50A: vers:all/*, Mitsubishi Electric AE-50E: vers:all/*, Mitsubishi Electric EW-50J: vers:all/*, Mitsubishi Electric EW-50A: vers:all/*, Mitsubishi Electric EW-50E: vers:all/*, Mitsubishi Electric TE-200A: vers:all/*, Mitsubishi Electric TE-50A: vers:all/*, Mitsubishi Electric TW-50A: vers:all/*, Mitsubishi Electric CMS-RMD-J: vers:all/*.",CVE-2025-3699,9.8,Critical,CWE-306,Commercial Facilities,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3379,6/26/2025,6/26/2025,2025,ICSA-25-177-02,TrendMakers Sight Bulb Pro,TrendMakers,Sight Bulb Pro,The following versions of the Sight Bulb Pro Firmware are affected: Sight Bulb Pro Firmware ZJ_CG32-2201: Version 8.57.83 and prior.,"CVE-2025-6521, CVE-2025-6522",5.3,Medium,"CWE-327, CWE-77",Commercial Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3378,6/24/2025,6/24/2025,2025,ICSA-25-175-01,Kaleris Navis N4 Terminal Operating System,Kaleris,Navis N4,"The following versions of Kaleris Navis N4, a terminal operating system, are affected: Navis N4: Versions prior to 4.0.","CVE-2025-2566, CVE-2025-5087",9.3,Critical,"CWE-502, CWE-319",Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3377,6/24/2025,6/24/2025,2025,ICSA-25-175-02,Delta Electronics CNCSoft,Delta Electronics,CNCSoft,"Delta Electronics reports the following versions of CNCSoft, a human-machine interface, are affected: CNCSoft: v1.01.34 and prior.","CVE-2025-47724, CVE-2025-47725, CVE-2025-47726, CVE-2025-47727",7.3,High,CWE-787,Critical Manufacturing; Energy,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3376,6/24/2025,7/22/2025,2025,ICSA-25-175-03,Schneider Electric Modicon Controllers (Update A),Schneider Electric,Modicon Controllers,"Schneider Electric reports that the following products are affected: Modicon Controllers M241: Versions prior to 5.3.12.51 Modicon Controllers M251: Versions prior to 5.3.12.51 Modicon Controllers M262: Versions prior to 5.3.9.18 (CVE-2025-3898, CVE-2025-3117) Modicon Controllers M258: All versions (CVE-2025-3905, CVE-2025-3116, CVE-2025-3117) Modicon Controllers LMC058: All versions (CVE-2025-3905, CVE-2025-3116, CVE-2025-3117).","CVE-2025-3112, CVE-2025-3116, CVE-2025-3117, CVE-2025-3898, CVE-2025-3899, CVE-2025-3905",7.1,High,"CWE-20, CWE-79, CWE-400",Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3375,6/24/2025,7/22/2025,2025,ICSA-25-175-04,Schneider Electric EVLink WallBox (Update A),Schneider Electric,EVLink WallBox,Schneider Electric reports that the following products are affected: EVLink WallBox: All versions.,"CVE-2025-5740, CVE-2025-5741, CVE-2025-5742, CVE-2025-5743",8.6,High,"CWE-22, CWE-79, CWE-78",Transportation Systems,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3374,6/24/2025,6/24/2025,2025,ICSA-25-175-05,ControlID iDSecure On-Premises,ControlID,iDSecure On-premises,"The following versions of ControlID iDSecure On-premises, a vehicle control software, are affected: iDSecure On-premises: Versions 4.7.48.0 and prior.","CVE-2025-49851, CVE-2025-49852, CVE-2025-49853",9.3,Critical,"CWE-287, CWE-918, CWE-89",Commercial Facilities,Worldwide,Brazil,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3373,6/24/2025,6/24/2025,2025,ICSA-25-175-06,Parsons AccuWeather Widget,Parsons,AccuWeather and Custom RSS widget,The following version of AccuWeather and Custom RSS widget are affected: Parsons Utility Enterprise Data Management: Version 5.18 Parsons Utility Enterprise Data Management: Version 5.03 Parsons Utility Enterprise Data Management: Versions 4.02 through 4.26 Parsons Utility Enterprise Data Management: Version 3.30 AclaraONE Utility Portal: versions prior to 1.22.,CVE-2025-5015,8.7,High,CWE-79,Communications,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3372,6/24/2025,6/24/2025,2025,ICSA-25-175-07,MICROSENS NMP Web+,MICROSENS,NMP Web+,The following versions of NMP Web+ are affected: NMP Web+: Version 3.2.5 and prior.,"CVE-2025-49151, CVE-2025-49152, CVE-2025-49153",9.3,Critical,"CWE-547, CWE-613, CWE-22",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3371,6/17/2025,6/17/2025,2025,ICSA-25-168-01,Siemens Mendix Studio Pro,Siemens,Mendix Studio Pro,Siemens reports the following versions of Mendix Studio Pro integrated development environment are affected: Siemens Mendix Studio Pro 8: Versions prior to V8.18.35 Siemens Mendix Studio Pro 9: Versions prior to V9.24.35 Siemens Mendix Studio Pro 10: Versions prior to V10.23.0 Siemens Mendix Studio Pro 10.6: Versions prior to V10.6.24 Siemens Mendix Studio Pro 10.12: Versions prior to V10.12.17 Siemens Mendix Studio Pro 10.18: Versions prior to V10.18.7 Siemens Mendix Studio Pro 11: All versions.,CVE-2025-40592,4.6,Medium,CWE-22,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3370,6/17/2025,6/17/2025,2025,ICSA-25-168-02,LS Electric GMWin 4,LS Electric,GMWin 4,"The following versions of LS Electric GMWin 4, a programming software tool, are affected: GMWin 4: Version 4.18.","CVE-2025-49848, CVE-2025-49849, CVE-2025-49850",8.4,High,"CWE-122, CWE-125, CWE-787",Critical Manufacturing,Worldwide,South Korea,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3369,6/17/2025,6/17/2025,2025,ICSA-25-168-04,Fuji Electric Smart Editor,Fuji Electric,Smart Editor,The following Fuji Electric products are affected: Smart Editor: Versions 1.0.1.0 and prior.,"CVE-2025-32412, CVE-2025-41388, CVE-2025-41413",8.4,High,"CWE-125, CWE-787, CWE-121",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3368,6/17/2025,6/17/2025,2025,ICSA-25-168-05,Dover Fueling Solutions ProGauge MagLink LX Consoles,Dover Fueling Solutions (DFS),ProGauge MagLink LX consoles,"The following versions of ProGauge MagLink LX, a fuel and water tank monitor, are affected: ProGauge MagLink LX 4: Versions prior to 4.20.3 ProGauge MagLink LX Plus: Versions prior to 4.20.3 ProGauge MagLink LX Ultimate: Versions prior to 5.20.3.",CVE-2025-5310,9.2,Critical,CWE-306,Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3367,6/12/2025,6/12/2025,2025,ICSA-25-162-01,Siemens Tecnomatix Plant Simulation,Siemens,Tecnomatix Plant Simulation,Siemens reports that the following products are affected: Tecnomatix Plant Simulation V2404: All versions prior to V2404.0013.,CVE-2025-32454,7.3,High,CWE-125,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3366,6/12/2025,6/12/2025,2025,ICSA-25-162-02,Siemens RUGGEDCOM APE1808,Siemens,RUGGEDCOM APE1808,Siemens reports that the following products are affected: Siemens RUGGEDCOM APE1808: All versions with Palo Alto Networks Virtual NGFW with an enabled GlobalProtect gateway or portal.,CVE-2025-0133,5.1,Medium,CWE-79,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3365,6/12/2025,6/12/2025,2025,ICSA-25-162-03,Siemens SCALANCE and RUGGEDCOM,Siemens,SCALANCE and RUGGEDCOM,"Siemens reports that the following products are affected: Siemens RUGGEDCOM RST2428P (6GK6242-6PA00): All versions prior to V3.1 Siemens SCALANCE XCM324 (6GK5324-8TS01-2AC2): All versions prior to V3.1 Siemens SCALANCE XCM328 (6GK5328-4TS01-2AC2): All versions prior to V3.1 Siemens SCALANCE XCM332 (6GK5332-0GA01-2AC2): All versions prior to V3.1 Siemens SCALANCE XR302-32 (6GK5334-5TS00-2AR3): All versions prior to V3.1 Siemens SCALANCE XR302-32 (6GK5334-5TS00-3AR3): All versions prior to V3.1 Siemens SCALANCE XR302-32 (6GK5334-5TS00-4AR3): All versions prior to V3.1 Siemens SCALANCE XR322-12 (6GK5334-3TS00-2AR3): All versions prior to V3.1 Siemens SCALANCE XR322-12 (6GK5334-3TS00-3AR3): All versions prior to V3.1 Siemens SCALANCE XR322-12 (6GK5334-3TS00-4AR3): All versions prior to V3.1 Siemens SCALANCE XR326-8 (6GK5334-2TS00-2AR3): All versions prior to V3.1 Siemens SCALANCE XC316-8 (6GK5324-8TS00-2AC2): All versions prior to V3.1 Siemens SCALANCE XR326-8 (6GK5334-2TS00-3AR3): All versions prior to V3.1 Siemens SCALANCE XR326-8 (6GK5334-2TS00-4AR3): All versions prior to V3.1 Siemens SCALANCE XR326-8 EEC (6GK5334-2TS00-2ER3): All versions prior to V3.1 Siemens SCALANCE XR502-32 (6GK5534-5TR00-2AR3): All versions prior to V3.1 Siemens SCALANCE XR502-32 (6GK5534-5TR00-3AR3): All versions prior to V3.1 Siemens SCALANCE XR502-32 (6GK5534-5TR00-4AR3): All versions prior to V3.1 Siemens SCALANCE XR522-12 (6GK5534-3TR00-2AR3): All versions prior to V3.1 Siemens SCALANCE XR522-12 (6GK5534-3TR00-3AR3): All versions prior to V3.1 Siemens SCALANCE XR522-12 (6GK5534-3TR00-4AR3): All versions prior to V3.1 Siemens SCALANCE XR526-8 (6GK5534-2TR00-2AR3): All versions prior to V3.1 Siemens SCALANCE XC324-4 (6GK5328-4TS00-2AC2): All versions prior to V3.1 Siemens SCALANCE XR526-8 (6GK5534-2TR00-3AR3): All versions prior to V3.1 Siemens SCALANCE XR526-8 (6GK5534-2TR00-4AR3): All versions prior to V3.1 Siemens SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3): All versions prior to V3.1 Siemens SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3): All versions prior to V3.1 Siemens SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3): All versions prior to V3.1 Siemens SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3): All versions prior to V3.1 Siemens SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3): All versions prior to V3.1 Siemens SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3): All versions prior to V3.1 Siemens SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3): All versions prior to V3.1 Siemens SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3): All versions prior to V3.1 Siemens SCALANCE XC324-4 EEC (6GK5328-4TS00-2EC2): All versions prior to V3.1 Siemens SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3): All versions prior to V3.1 Siemens SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3): All versions prior to V3.1 Siemens SCALANCE XC332 (6GK5332-0GA00-2AC2): All versions prior to V3.1 Siemens SCALANCE XC416-8 (6GK5424-8TR00-2AC2): All versions prior to V3.1 Siemens SCALANCE XC424-4 (6GK5428-4TR00-2AC2): All versions prior to V3.1 Siemens SCALANCE XC432 (6GK5432-0GR00-2AC2): All versions prior to V3.1 Siemens SCALANCE XCH328 (6GK5328-4TS01-2EC2): All versions prior to V3.1.",CVE-2024-41797,5.3,Medium,CWE-269,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3364,6/12/2025,6/12/2025,2025,ICSA-25-162-04,Siemens SCALANCE and RUGGEDCOM,Siemens,SCALANCE and RUGGEDCOM,"Siemens reports that the following products are affected: Siemens RUGGEDCOM RST2428P (6GK6242-6PA00): All versions prior to V3.2 Siemens SCALANCE XCM324 (6GK5324-8TS01-2AC2): All versions prior to V3.2 Siemens SCALANCE XCM328 (6GK5328-4TS01-2AC2): All versions prior to V3.2 Siemens SCALANCE XCM332 (6GK5332-0GA01-2AC2): All versions prior to V3.2 Siemens SCALANCE XR302-32 (6GK5334-5TS00-2AR3): All versions prior to V3.2 Siemens SCALANCE XR302-32 (6GK5334-5TS00-3AR3): All versions prior to V3.2 Siemens SCALANCE XR302-32 (6GK5334-5TS00-4AR3): All versions prior to V3.2 Siemens SCALANCE XR322-12 (6GK5334-3TS00-2AR3): All versions prior to V3.2 Siemens SCALANCE XR322-12 (6GK5334-3TS00-3AR3): All versions prior to V3.2 Siemens SCALANCE XR322-12 (6GK5334-3TS00-4AR3): All versions prior to V3.2 Siemens SCALANCE XR326-8 (6GK5334-2TS00-2AR3): All versions prior to V3.2 Siemens SCALANCE XC316-8 (6GK5324-8TS00-2AC2): All versions prior to V3.2 Siemens SCALANCE XR326-8 (6GK5334-2TS00-3AR3): All versions prior to V3.2 Siemens SCALANCE XR326-8 (6GK5334-2TS00-4AR3): All versions prior to V3.2 Siemens SCALANCE XR326-8 EEC (6GK5334-2TS00-2ER3): All versions prior to V3.2 Siemens SCALANCE XR502-32 (6GK5534-5TR00-2AR3): All versions prior to V3.2 Siemens SCALANCE XR502-32 (6GK5534-5TR00-3AR3): All versions prior to V3.2 Siemens SCALANCE XR502-32 (6GK5534-5TR00-4AR3): All versions prior to V3.2 Siemens SCALANCE XR522-12 (6GK5534-3TR00-2AR3): All versions prior to V3.2 Siemens SCALANCE XR522-12 (6GK5534-3TR00-3AR3): All versions prior to V3.2 Siemens SCALANCE XR522-12 (6GK5534-3TR00-4AR3): All versions prior to V3.2 Siemens SCALANCE XR526-8 (6GK5534-2TR00-2AR3): All versions prior to V3.2 Siemens SCALANCE XC324-4 (6GK5328-4TS00-2AC2): All versions prior to V3.2 Siemens SCALANCE XR526-8 (6GK5534-2TR00-3AR3): All versions prior to V3.2 Siemens SCALANCE XR526-8 (6GK5534-2TR00-4AR3): All versions prior to V3.2 Siemens SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3): All versions prior to V3.2 Siemens SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3): All versions prior to V3.2 Siemens SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3): All versions prior to V3.2 Siemens SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3): All versions prior to V3.2 Siemens SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3): All versions prior to V3.2 Siemens SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3): All versions prior to V3.2 Siemens SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3): All versions prior to V3.2 Siemens SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3): All versions prior to V3.2 Siemens SCALANCE XC324-4 EEC (6GK5328-4TS00-2EC2): All versions prior to V3.2 Siemens SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3): All versions prior to V3.2 Siemens SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3): All versions prior to V3.2 Siemens SCALANCE XC332 (6GK5332-0GA00-2AC2): All versions prior to V3.2 Siemens SCALANCE XC416-8 (6GK5424-8TR00-2AC2): All versions prior to V3.2 Siemens SCALANCE XC424-4 (6GK5428-4TR00-2AC2): All versions prior to V3.2 Siemens SCALANCE XC432 (6GK5432-0GR00-2AC2): All versions prior to V3.2 Siemens SCALANCE XCH328 (6GK5328-4TS01-2EC2): All versions prior to V3.2.","CVE-2025-40567, CVE-2025-40568, CVE-2025-40569",7.1,High,"CWE-863, CWE-362",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3363,6/12/2025,6/12/2025,2025,ICSA-25-162-05,Siemens SIMATIC S7-1500 CPU Family,Siemens,SIMATIC S7-1500 CPU family,Siemens reports that the following products are affected: SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0): V3.1.5 and prior SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0): V3.1.5 and prior SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0): V3.1.5 and prior SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0): V3.1.5 and prior SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0): V3.1.5 and prior.,"CVE-2021-41617, CVE-2023-4527, CVE-2023-4806, CVE-2023-4911, CVE-2023-5363, CVE-2023-6246, CVE-2023-6779, CVE-2023-6780, CVE-2023-28531, CVE-2023-38545, CVE-2023-38546, CVE-2023-44487, CVE-2023-46218, CVE-2023-46219, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2023-52927, CVE-2024-2961, CVE-2024-6119, CVE-2024-6387, CVE-2024-12133, CVE-2024-12243, CVE-2024-24855, CVE-2024-26596, CVE-2024-28085, CVE-2024-33599, CVE-2024-33600, CVE-2024-33601, CVE-2024-33602, CVE-2024-34397, CVE-2024-37370, CVE-2024-37371, CVE-2024-45490, CVE-2024-45491, CVE-2024-45492, CVE-2024-50246, CVE-2024-53166, CVE-2024-57977, CVE-2024-57996, CVE-2024-58005, CVE-2025-4373, CVE-2025-4598, CVE-2025-21701, CVE-2025-21702, CVE-2025-21712, CVE-2025-21724, CVE-2025-21728, CVE-2025-21745, CVE-2025-21756, CVE-2025-21758, CVE-2025-21765, CVE-2025-21766, CVE-2025-21767, CVE-2025-21795, CVE-2025-21796, CVE-2025-21848, CVE-2025-21862, CVE-2025-21864, CVE-2025-21865, CVE-2025-26465, CVE-2025-31115, CVE-2025-46836",8.7,High,"CWE-311, CWE-125, CWE-121, CWE-684, CWE-787, CWE-131, CWE-122, CWE-73, CWE-400, CWE-20, CWE-222, CWE-304, CWE-78, CWE-843, CWE-364 , CWE-407, CWE-362, CWE-476, CWE-617, CWE-466, CWE-130, CWE-190, CWE-416, CWE-667, CWE-129, CWE-124, CWE-364, CWE-908, CWE-390, CWE-826",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3362,6/12/2025,6/12/2025,2025,ICSA-25-162-06,Siemens Energy Services,Siemens,Energy Services,Siemens reports that the following products are affected: Energy Services: All versions.,CVE-2025-40585,9.5,Critical,CWE-276,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3361,6/12/2025,6/12/2025,2025,ICSA-25-162-07,AVEVA PI Data Archive,AVEVA,PI Data Archive,"The following versions of PI Data Archive, as delivered by PI Server are affected: PI Data Archive: Versions 2018 SP3 Patch 4 and prior (CVE-2025-44019) PI Data Archive: Version 2023 (CVE-2025-44019, CVE-2025-36539) PI Data Archive: Version 2023 Patch 1 (CVE-2025-44019, CVE-2025-36539) PI Server: Versions 2018 SP3 Patch 6 and prior (CVE-2025-44019) PI Server: Version 2023 (CVE-2025-44019, CVE-2025-36539) PI Server: Version 2023 Patch 1 (CVE-2025-44019, CVE-2025-36539).","CVE-2025-36539, CVE-2025-44019",7.1,High,CWE-248,Critical Manufacturing,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3360,6/12/2025,6/12/2025,2025,ICSA-25-162-08,AVEVA PI Web API,AVEVA,PI Web API,The following versions of AVEVA PI Web API are affected: PI Web API: Versions 2023 SP1 and prior.,CVE-2025-2745,4.5,Medium,CWE-79,Critical Manufacturing,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3359,6/12/2025,6/12/2025,2025,ICSA-25-162-09,AVEVA PI Connector for CygNet,AVEVA,PI Connector for CygNet,The following versions of PI Connector for CygNet are affected: PI Connector for CygNet: Version 1.6.14 and prior.,"CVE-2025-4417, CVE-2025-4418",6.9,Medium,"CWE-79, CWE-354",Critical Manufacturing,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3358,6/12/2025,6/12/2025,2025,ICSA-25-162-10,PTZOptics and Other Pan-Tilt-Zoom Cameras,"ValueHD, PTZOptics, multiCAM Systems, SMTAV",Various pan-tilt-zoom cameras,"The following ValueHD, PTZOptics, multiCAM Systems, and SMTAV products are affected: PTZOptics PT12X-SDI-xx-G2: Versions 6.3.34 and prior (CVE-2025-35451) PTZOptics PT12X-NDI-xx: Versions 6.3.34 and prior (CVE-2025-35451) PTZOptics PT12X-USB-xx-G2: Versions 6.2.81 and prior (CVE-2025-35451) PTZOptics PT20X-SDI-xx-G2: Versions 6.3.20 and prior (CVE-2025-35451) PTZOptics PT20X-NDI-xx: Versions 6.3.20 and prior (CVE-2025-35451) PTZOptics PT20X-USB-xx-G2: Versions 6.2.73 and prior (CVE-2025-35451) PTZOptics PT30X-SDI-xx-G2: Versions 6.3.30 and prior (CVE-2025-35451) PTZOptics PT30X-NDI-xx: Versions 6.3.30 and prior (CVE-2025-35451) PTZOptics PT12X-ZCAM: Versions 7.2.76 and prior (CVE-2025-35451) PTZOptics PT20X-ZCAM: Versions 7.2.82 and prior (CVE-2025-35451) PTZOptics PTVL-ZCAM: Versions 7.2.79 and prior (CVE-2025-35451) PTZOptics PTEPTZ-ZCAM-G2: Versions 8.1.81 and prior (CVE-2025-35451) PTZOptics PTEPTZ-NDI-ZCAM-G2: Versions 8.1.81 and prior (CVE-2025-35451) PTZOptics PT12X-SDI-xx-G2: All versions (CVE-2025-35452) PTZOptics PT12X-NDI-xx: All versions (CVE-2025-35452) PTZOptics PT12X-USB-xx-G2: All versions (CVE-2025-35452) PTZOptics PT20X-SDI-xx-G2: All versions (CVE-2025-35452) PTZOpticsPT20X-NDI-xx: All versions (CVE-2025-35452) PTZOptics PT20X-USB-xx-G2: All versions (CVE-2025-35452) PTZOptics PT30X-SDI-xx-G2: All versions (CVE-2025-35452) PTZOptics PT30X-NDI-xx: All versions (CVE-2025-35452) PTZOptics PT12X-ZCAM: All versions (CVE-2025-35452) PTZOptics PT20X-ZCAM: All versions (CVE-2025-35452) PTZOptics PTVL-ZCAM: All versions (CVE-2025-35452) PTZOptics PTEPTZ-ZCAM-G2: All versions (CVE-2025-35452) PTZOptics PTEPTZ-NDI-ZCAM-G2 All versions (CVE-2025-35452) PTZOptics PT12X-4K-xx-G3: Versions 0.0.58 and prior (CVE-2025-35452) PTZOptics PT20X-4K-xx-G3: Versions 0.0.85 and prior (CVE-2025-35452) PTZOptics PT30X-4K-xx-G3: Versions 2.0.64 and prior (CVE-2025-35452) PTZOptics PT12X-LINK-4K-xx: Versions 0.0.63 and prior (CVE-2025-35452) PTZOptics PT20X-LINK-4K-xx: Versions 0.0.89 and prior (CVE-2025-35452) PTZOptics PT30X-LINK-4K-xx: Versions 2.0.71 and prior (CVE-2025-35452) PTZOptics PT12X-SE-xx-G3: Versions 9.1.43 and prior (CVE-2025-35452) PTZOptics PT20X-SE-xx-G3: Versions 9.1.32 and prior (CVE-2025-35452) PTZOptics PT30X-SE-xx-G3: Versions 9.1.33 and prior (CVE-2025-35452) PTZOptics PT-STUDIOPRO: Versions 9.0.41 and prior (CVE-2025-35452) PTZOptics PTZOptics VL Fixed Camera/NDI Fixed Camera: Versions 7.2.94 and prior SMTAV Pan-Tilt-Zoom Cameras: All versions multiCAM Systems Pan-Tilt-Zoom Cameras: All versions ValueHD Pan-Tilt-Zoom Cameras: All versions.","CVE-2024-8956, CVE-2024-8957, CVE-2025-35451, CVE-2025-35452",9.3,Critical,"CWE-287, CWE-78, CWE-798",Commercial Facilities; Critical Manufacturing; Government Facilities; Healthcare and Public Health,Worldwide,"United States, China",Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3357,6/10/2025,6/10/2025,2025,ICSA-25-160-01,SinoTrack GPS Receiver,SinoTrack,All Known SinoTrack Devices,The following SinoTrack products are affected: SinoTrack IOT PC Platform: All versions.,"CVE-2025-5484, CVE-2025-5485",8.8,High,"CWE-1390, CWE-204",Communications,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3356,6/27/2023,3/17/2026,2025,ICSA-25-160-02,"Hitachi Energy’s Relion 670, 650, SAM600-IO series (Update A)",Hitachi Energy,"Hitachi Energy Relion 670, 650, SAM600-IO Series","Relion 670/650 series version 2.2.0 all revisions, Relion 670/650/SAM600-IO series version 2.2.1 revisions up to 2.2.1.8, Relion 670 series version 2.2.2 revisions up to 2.2.2.5, Relion 670 series version 2.2.3 revisions up to 2.2.3.6, Relion 670/650 series version 2.2.4 revisions up to 2.2.4.3, Relion 670/650/SAM600-IO series version 2.2.5 revisions up to 2.2.5.5",CVE-2022-4304,5.9,Medium,CWE-203,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3355,6/10/2025,6/10/2025,2025,ICSMA-25-160-01,MicroDicom DICOM Viewer,MicroDicom,DICOM Viewer,The following MicroDicom products are affected: DICOM Viewer: Versions 2025.2 (Build 8154) and prior.,CVE-2025-5943,8.6,High,CWE-787,Healthcare and Public Health,Worldwide,Bulgaria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3354,6/5/2025,6/5/2025,2025,ICSA-25-155-01,CyberData 011209 SIP Emergency Intercom,CyberData,011209 SIP Emergency Intercom,The following CyberData products are affected: 011209 SIP Emergency Intercom: Versions prior to 22.0.1.,"CVE-2025-26468, CVE-2025-30183, CVE-2025-30184, CVE-2025-30507, CVE-2025-30515",9.3,Critical,"CWE-288, CWE-306, CWE-89, CWE-522, CWE-35",Communications; Emergency Services; Commercial Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3353,6/5/2025,6/5/2025,2025,ICSA-25-155-02,"Hitachi Energy Relion 670, 650 series and SAM600-IO Product",Hitachi Energy,"Relion 670, Relion 650, SAM600-IO",Hitachi Energy reports that the following products are affected: Relion 670/650/SAM600-IO series: Version 2.2.5 revisions up to 2.2.5.1 Relion 670/650 series: Version 2.2.4 revisions up to 2.2.4.2 Relion 670 series: Version 2.2.3 revisions up to 2.2.3.4 Relion 670 series: Version 2.2.2 revisions up to 2.2.2.4 Relion 670/650/SAM600-IO series: Version 2.2.1 revisions up to 2.2.1.7 Relion 670/650 series version 2.2.0: All revisions Relion 670/650 series version 2.1: All revisions Relion 670 series version 2.0: All revisions Relion 670 series version 1.2: All revisions Relion 670 series version 1.1: All revisions Relion 650 series version 1.3: All revisions Relion 650 series version 1.2: All revisions Relion 650 series version 1.1: All revisions Relion 650 series version 1.0: All revisions.,"CVE-2020-28895, CVE-2020-35198",9.8,Critical,CWE-190,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3352,6/3/2025,6/3/2025,2025,ICSA-25-153-01,Schneider Electric Wiser Home Automation,Schneider Electric,"Wiser AvatarOn 6K Freelocate, Wiser Cuadro H 5P Socket",The following Schneider Electric products are affected: Wiser AvatarOn 6K Freelocate: All versions Wiser Cuadro H 5P Socket: All versions.,CVE-2023-4041,9.3,Critical,CWE-120,Commercial Facilities; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3351,6/3/2025,6/3/2025,2025,ICSA-25-153-02,Schneider Electric EcoStruxure Power Build Rapsody,Schneider Electric,EcoStruxure Power Build Rapsody,The following Schneider Electric product is affected: EcoStruxure Power Build Rapsody: v2.7.12 FR and prior.,CVE-2025-3916,4.6,Medium,CWE-121,Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3350,6/3/2025,6/3/2025,2025,ICSA-25-153-03,Mitsubishi Electric MELSEC iQ-F Series,Mitsubishi Electric,MELSEC iQ-F Series,"The following versions of Mitsubishi Electric MELSEC iQ-F Series are affected. Products with [Note *1] are sold in limited regions: FX5U-xMy/z x=32, 64, 80, y=T, R, z=ES,DS, ESS, DSS: All versions FX5UC-xMy/z x=32, 64, 96, y=T, z=D, DSS: All versions FX5UC-32MT/DS-TS, FX5UC-32MT/DSS-TS, FX5UC-32MR/DS-TS: All versions FX5UJ-xMy/z x=24, 40, 60, y=T, R, z=ES,DS,ESS,DSS: All versions FX5UJ-xMy/ES-A[Note *1] x=24, 40, 60, y=T, R: All versions FX5S-xMy/z x=30, 40, 60, 80[Note *1], y=T, R, z= ES,DS,ESS,DSS: All versions.",CVE-2025-3755,9.1,Critical,CWE-1285,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3349,5/29/2025,5/29/2025,2025,ICSA-25-148-01,Siemens SiPass,Siemens,SiPass,Siemens reports that the following products are affected: Siemens SiPass integrated AC5102 (ACC-G2): All versions Siemens SiPass integrated ACC-AP: All versions.,CVE-2022-31807,8.2,High,CWE-347,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3348,5/29/2025,5/29/2025,2025,ICSA-25-148-02,Siemens SiPass Integrated,Siemens,SiPass integrated,Siemens reports that the following products are affected: SiPass integrated: Versions prior to V2.95.3.18.,CVE-2022-31812,8.7,High,CWE-125,Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3347,5/29/2025,12/4/2025,2025,ICSA-25-148-03,Consilium Safety CS5000 Fire Panel (Update A),Consilium Safety,CS5000 Fire Panel,The following Consilium Safety product is affected: CS5000 Fire Panel: All versions prior to R1.17.1.,"CVE-2025-41438, CVE-2025-46352",8.6,High,"CWE-1188, CWE-798",Commercial Facilities; Energy; Government Facilities; Healthcare and Public Health; Transportation Systems,Worldwide,Sweden,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3346,5/29/2025,8/7/2025,2025,ICSA-25-148-04,Instantel Micromate (Update A),Instantel,Micromate,The following versions of Micromate are affected: Micromate: All versions prior to 11.0BD and 11.0CB.,CVE-2025-1907,9.3,Critical,CWE-306,Critical Manufacturing,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3345,5/29/2025,5/29/2025,2025,ICSMA-25-148-01,Santesoft Sante DICOM Viewer Pro,Santesoft,Sante DICOM Viewer Pro,The following Santesoft products are affected: Sante DICOM Viewer Pro: Versions 14.2.1 and prior.,CVE-2025-5307,8.4,High,CWE-125,Healthcare and Public Health,Worldwide,Cyprus,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3344,5/27/2025,5/27/2025,2025,ICSA-25-146-01,Johnson Controls iSTAR Configuration Utility (ICU) Tool,Johnson Controls Inc.,iSTAR Configuration Utility (ICU) tool,Johnson Controls reports the following versions of ICU are affected: ICU: All versions prior to 6.9.5.,CVE-2025-26383,6.3,Medium,CWE-457,Commercial Facilities; Critical Manufacturing; Energy; Government Facilities; Transportation Systems,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3343,5/22/2025,5/22/2025,2025,ICSA-25-142-01,Lantronix Device Installer,Lantronix,Device Installer,The following Lantronix products are affected: Device Installer: Versions 4.4.0.7 and prior.,CVE-2025-4338,6.9,Medium,CWE-611,Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3342,5/22/2025,5/22/2025,2025,ICSA-25-142-02,Rockwell Automation FactoryTalk Historian ThingWorx,Rockwell Automation,95057C-FTHTWXCT11,The following versions of Rockwell Automation FactoryTalk Historian ThingWorx are affected: 95057C-FTHTWXCT11: Versions v4.02.00 and prior.,CVE-2018-1285,9.3,Critical,CWE-611,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3341,5/20/2025,5/20/2025,2025,ICSA-25-140-01,ABUP IoT Cloud Platform,ABUP,ABUP Internet of Things (IoT) Cloud Platform,The following ABUP products are affected: ABUP IoT Cloud Platform: All Versions.,CVE-2025-4692,5.9,Medium,CWE-266,Communications,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3340,5/20/2025,5/20/2025,2025,ICSA-25-140-02,National Instruments Circuit Design Suite,National Instruments Corp (NI),Circuit Design Suite,The following National Instruments products are affected: Circuit Design Suite: Versions 14.3.0 and prior.,"CVE-2025-30417, CVE-2025-30418, CVE-2025-30419, CVE-2025-30420, CVE-2025-30421",8.4,High,"CWE-787, CWE-125, CWE-121",Communications; Defense Industrial Base; Government Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3339,5/20/2025,8/26/2025,2025,ICSA-25-140-03,Danfoss AK-SM 8xxA Series (Update A),Danfoss,AK-SM 8xxA Series,"The following versions of AK-SM 8xxA series are affected: AK-SM 8xxA Series: Versions prior to R4.2 (CVE-2025-41450) AK-SM 8xxA Series: Versions prior to 4.3.1 (CVE-2025-41451, CVE-2025-41452).","CVE-2025-41450, CVE-2025-41451, CVE-2025-41452",8.7,High,"CWE-287, CWE-77, CWE-15",Commercial Facilities,Worldwide,Denmark,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3338,5/20/2025,2/12/2026,2025,ICSA-25-140-04,Mitsubishi Electric Iconics Digital Solutions / Mitsubishi Electric GENESIS64 (Update E),Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric,Mitsubishi Electric Iconics Digital Solutions / Mitsubishi Electric GENESIS64 (Update E),"Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric BizViz: vers:all/*, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric GENESIS32: vers:all/*, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric GENESIS64: vers:all/*, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric GENESIS: 11.00, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric ICONICS Suite: vers:all/*, Mitsubishi Electric MC Works64 vers:all/*",CVE-2025-0921,6.5,Medium,CWE-250,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3337,5/20/2025,5/20/2025,2025,ICSA-25-140-05,Siemens Siveillance Video,Siemens,Siveillance Video,Siemens reports that the following products are affected: Siemens Siveillance Video: Versions V24.1 and later.,CVE-2025-1688,5.5,Medium,CWE-311,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3336,5/20/2025,5/20/2025,2025,ICSA-25-140-06,Schneider Electric PrismaSeT Active - Wireless Panel Server,Schneider Electric,PrismaSeT Active - Wireless Panel Server,The following versions of Schneider Electric products are affected: PrismaSeT Active - Wireless Panel Server: All versions.,CVE-2023-4041,9.8,Critical,CWE-120,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3335,5/20/2025,9/16/2025,2025,ICSA-25-140-07,"Schneider Electric Galaxy VS, Galaxy VL, Galaxy VXL (Update A)",Schneider Electric,"Galaxy VS, Galaxy VL, Galaxy VXL",The following versions of Schneider Electric products are affected: Galaxy VS: Versions prior to v6.118.0 and prior Galaxy VL: Versions prior to v18.5.0 and prior Galaxy VXL: Versions prior to v15.21.0 and prior.,CVE-2025-32433,10.0,Critical,CWE-306,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3334,5/20/2025,10/21/2025,2025,ICSA-25-140-08,Schneider Electric Modicon Controllers (Update B),Schneider Electric,Modicon Controllers M241/M251/M258/LMC058,Schneider Electric reports that the following products are affected: Schneider Electric Modicon Controllers M241: Versions prior to 5.3.12.48 Schneider Electric Modicon Controllers M251: Versions prior to 5.3.12.48 Schneider Electric Modicon Controllers M258: Versions prior to 5.0.4.19 Schneider Electric Modicon Controllers LMC058: Versions prior to 5.0.4.19.,CVE-2025-2875,8.7,High,CWE-610,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3333,5/20/2025,5/20/2025,2025,ICSA-25-140-09,AutomationDirect MB-Gateway,AutomationDirect,MB-Gateway,The following AutomationDirect product is affected: MB-Gateway: All Versions.,CVE-2025-36535,10.0,Critical,CWE-306,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3332,5/20/2025,5/20/2025,2025,ICSA-25-140-10,Vertiv Liebert RDU101 and UNITY,Vertiv,Liebert RDU101 and Liebert UNITY,The following Vertiv products are affected: Liebert RDU101: Versions 1.9.0.0 and prior Liebert IS-UNITY: Versions 8.4.1.0 and prior.,"CVE-2025-41426, CVE-2025-46412",9.3,Critical,"CWE-288, CWE-121",Communications; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3331,5/20/2025,6/10/2025,2025,ICSA-25-140-11,Assured Telematics Inc (ATI) Fleet Management System (Update A),Assured Telematics Inc.,Fleet Management System,"The following product is affected: Fleet Management System: Versions prior to February 6th, 2025.",CVE-2025-4364,8.7,High,CWE-497,Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3330,5/15/2025,5/15/2025,2025,ICSA-25-135-01,Siemens RUGGEDCOM APE1808 Devices,Siemens,RUGGEDCOM APE1808 Devices,Siemens reports that the following products are affected: RUGGEDCOM APE1808: All versions.,"CVE-2024-32122, CVE-2024-52963",6.3,Medium,"CWE-522, CWE-787",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3329,5/15/2025,5/15/2025,2025,ICSA-25-135-02,Siemens INTRALOG WMS,Siemens,INTRALOG WMS,Siemens reports that the following products are affected: Siemens INTRALOG WMS: All versions prior to v5.,"CVE-2024-0056, CVE-2024-20672, CVE-2024-30105, CVE-2024-35264, CVE-2024-38081, CVE-2024-38095, CVE-2024-43483, CVE-2024-43485",8.7,High,"CWE-319, CWE-400, CWE-416, CWE-59, CWE-20, CWE-407",Chemical; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3328,5/15/2025,5/15/2025,2025,ICSA-25-135-03,Siemens BACnet ATEC Devices,Siemens,BACnet ATEC Devices,Siemens reports the following BACnet ATEC products are affected: Siemens BACnet ATEC 550-440: All versions Siemens BACnet ATEC 550-441: All versions Siemens BACnet ATEC 550-445: All versions Siemens BACnet ATEC 550-446: All versions.,CVE-2025-40556,7.1,High,CWE-20,Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3327,5/15/2025,5/15/2025,2025,ICSA-25-135-04,Siemens Desigo,Siemens,Desigo,Siemens reports that the following products are affected: Siemens Desigo CC: All versions.,CVE-2024-23815,8.7,High,CWE-306,Commercial Facilities; Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3326,5/15/2025,5/15/2025,2025,ICSA-25-135-05,Siemens SIPROTEC and SICAM,Siemens,SIPROTEC and SICAM,Siemens reports the following products using the RADIUS protocol are affected: CPC80 Central Processing/Communication: All versions CPCI85 Central Processing/Communication: All versions POWER METER SICAM Q100 family: All versions prior to V2.70 POWER METER SICAM Q200 family: All versions Powerlink IP: All versions SICAM GridPass: All versions prior to V2.50 SICORE Base system: All versions SIPROTEC 5 Compact 7SX800 (CP050): All versions SIPROTEC 5 7SA82 (CP100): Versions V7.80 and after SIPROTEC 5 7SD82 (CP100): Versions V7.80 and after SIPROTEC 5 7SJ81 (CP100): Versions V7.80 and after SIPROTEC 5 7SJ82 (CP100): Versions V7.80 and after SIPROTEC 5 7SK82 (CP100): Versions V7.80 and after SIPROTEC 5 7SL82 (CP100): Versions V7.80 and after SIPROTEC 5 7UT82 (CP100): Versions V7.80 and after SIPROTEC 5 7SA82 (CP150): All versions SIPROTEC 5 7SD82 (CP150): All versions SIPROTEC 5 7SJ81 (CP150): All versions SIPROTEC 5 7SJ82 (CP150): All versions SIPROTEC 5 7SK82 (CP150): All versions SIPROTEC 5 7SL82 (CP150): All versions SIPROTEC 5 7SX82 (CP150): All versions SIPROTEC 5 7SY82 (CP150): All versions SIPROTEC 5 7UT82 (CP150): All versions SIPROTEC 5 6MD84 (CP300): All versions SIPROTEC 5 6MD85 (CP300): Versions V7.80 and after SIPROTEC 5 6MD86 (CP300): Versions V7.80 and after SIPROTEC 5 6MD89 (CP300): Versions V7.80 and after SIPROTEC 5 6MD89 (CP300) V9.6: Versions prior to V9.68 SIPROTEC 5 6MU85 (CP300): All versions SIPROTEC 5 7KE85 (CP300): Versions V7.80 and after SIPROTEC 5 7SA86 (CP300): Versions V7.80 and after SIPROTEC 5 7SA87 (CP300): Versions V7.80 and after SIPROTEC 5 7SD86 (CP300): Versions V7.80 and after SIPROTEC 5 7SD87 (CP300): Versions V7.80 and after SIPROTEC 5 7SJ85 (CP300): Versions V7.80 and after SIPROTEC 5 7SJ86 (CP300): Versions V7.80 and after SIPROTEC 5 7SK85 (CP300): Versions V7.80 and after SIPROTEC 5 7SL86 (CP300): Versions V7.80 and after SIPROTEC 5 7SL87 (CP300): Versions V7.80 and after SIPROTEC 5 7SS85 (CP300): Versions V7.80 and after SIPROTEC 5 7ST85 (CP300): Versions prior to V9.68 SIPROTEC 5 7ST86 (CP300): Versions prior to V9.83 SIPROTEC 5 7SX85 (CP300): All versions SIPROTEC 5 7UM85 (CP300): Versions V7.80 and after SIPROTEC 5 7UT85 (CP300): Versions V7.80 and after SIPROTEC 5 7UT86 (CP300): Versions V7.80 and after SIPROTEC 5 7UT87 (CP300): Versions V7.80 and after SIPROTEC 5 7VE85 (CP300): Versions V7.80 and after SIPROTEC 5 7VK87 (CP300): Versions V7.80 and after SIPROTEC 5 7VU85 (CP300): All versions.,CVE-2024-3596,9.1,Critical,CWE-924,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3325,5/15/2025,5/15/2025,2025,ICSA-25-135-06,Siemens Teamcenter Visualization,Siemens,Teamcenter Visualization,Siemens reports that the following products are affected: Siemens Teamcenter Visualization V14.3: All versions prior to V14.3.0.14 Siemens Teamcenter Visualization V2312: All versions prior to V2312.0010 Siemens Teamcenter Visualization V2406: All versions prior to V2406.0008 Siemens Teamcenter Visualization V2412: All versions prior to V2412.0004.,CVE-2025-32454,8.2,High,CWE-125,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3324,5/15/2025,5/15/2025,2025,ICSA-25-135-07,Siemens IPC RS-828A,Siemens,IPC RS-828A,Siemens reports the following rugged industrial PCs are affected: SIMATIC IPC RS-828A: All versions.,CVE-2024-54085,10.0,Critical,CWE-290,Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3323,5/15/2025,5/15/2025,2025,ICSA-25-135-08,Siemens VersiCharge AC Series EV Chargers,Siemens,VersiCharge AC Series EV Chargers,"Siemens reports that the following products are affected: Siemens IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0): All versions (CVE-2025-31929) Siemens IEC 1Ph 7.4kW Parent socket (8EM1310-2EH04-3GA1): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC 1Ph 7.4kW Parent socket incl. SIM (8EM1310-2EH04-3GA2): All versions (CVE-2025-31929) Siemens IEC 1Ph 7.4kW Parent socket incl. SIM (8EM1310-2EH04-3GA2): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC 1Ph 7.4kW Parent socket/ shutter (8EM1310-2EN04-3GA1): All versions (CVE-2025-31929) Siemens IEC 1Ph 7.4kW Parent socket/ shutter (8EM1310-2EN04-3GA1): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC 1Ph 7.4kW Parent socket/ shutter SIM (8EM1310-2EN04-3GA2): All versions (CVE-2025-31929) Siemens IEC 1Ph 7.4kW Parent socket/ shutter SIM (8EM1310-2EN04-3GA2): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC 3Ph 22kW Child cable 7m (8EM1310-3EJ04-0GA0): All versions (CVE-2025-31929) Siemens IEC 3Ph 22kW Child cable 7m (8EM1310-3EJ04-0GA0): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC 3Ph 22kW Child socket (8EM1310-3EH04-0GA0): All versions (CVE-2025-31929) Siemens IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC 3Ph 22kW Child socket (8EM1310-3EH04-0GA0): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC 3Ph 22kW Child socket/ shutter (8EM1310-3EN04-0GA0): All versions (CVE-2025-31929) Siemens IEC 3Ph 22kW Child socket/ shutter (8EM1310-3EN04-0GA0): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC 3Ph 22kW Parent cable 7m (8EM1310-3EJ04-3GA1): All versions (CVE-2025-31929) Siemens IEC 3Ph 22kW Parent cable 7m (8EM1310-3EJ04-3GA1): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC 3Ph 22kW Parent cable 7m incl. SIM (8EM1310-3EJ04-3GA2): All versions (CVE-2025-31929) Siemens IEC 3Ph 22kW Parent cable 7m incl. SIM (8EM1310-3EJ04-3GA2): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC 3Ph 22kW Parent socket (8EM1310-3EH04-3GA1): All versions (CVE-2025-31929) Siemens IEC 3Ph 22kW Parent socket (8EM1310-3EH04-3GA1): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC 3Ph 22kW Parent socket incl. SIM (8EM1310-3EH04-3GA2): All versions (CVE-2025-31929) Siemens IEC 1Ph 7.4kW Child socket/ shutter (8EM1310-2EN04-0GA0): All versions (CVE-2025-31929) Siemens IEC 3Ph 22kW Parent socket incl. SIM (8EM1310-3EH04-3GA2): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC 3Ph 22kW Parent socket/ shutter (8EM1310-3EN04-3GA1): All versions (CVE-2025-31929) Siemens IEC 3Ph 22kW Parent socket/ shutter (8EM1310-3EN04-3GA1): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC 3Ph 22kW Parent socket/ shutter SIM (8EM1310-3EN04-3GA2): All versions (CVE-2025-31929) Siemens IEC 3Ph 22kW Parent socket/ shutter SIM (8EM1310-3EN04-3GA2): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC ERK 3Ph 22 kW Child cable 7m (8EM1310-3FJ04-0GA0): All versions (CVE-2025-31929) Siemens IEC ERK 3Ph 22 kW Child cable 7m (8EM1310-3FJ04-0GA0): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC ERK 3Ph 22 kW Child cable 7m (8EM1310-3FJ04-0GA1): All versions (CVE-2025-31929) Siemens IEC ERK 3Ph 22 kW Child cable 7m (8EM1310-3FJ04-0GA1): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC ERK 3Ph 22 kW Child cable 7m (8EM1310-3FJ04-0GA2): All versions (CVE-2025-31929) Siemens IEC 1Ph 7.4kW Child socket/ shutter (8EM1310-2EN04-0GA0): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC ERK 3Ph 22 kW Child cable 7m (8EM1310-3FJ04-0GA2): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC ERK 3Ph 22 kW Child socket (8EM1310-3FH04-0GA0): All versions (CVE-2025-31929) Siemens IEC ERK 3Ph 22 kW Child socket (8EM1310-3FH04-0GA0): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC ERK 3Ph 22 kW Parent socket (8EM1310-3FH04-3GA1): All versions (CVE-2025-31929) Siemens IEC ERK 3Ph 22 kW Parent socket (8EM1310-3FH04-3GA1): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC ERK 3Ph 22 kW Parent socket incl. SI (8EM1310-3FH04-3GA2): All versions (CVE-2025-31929) Siemens IEC ERK 3Ph 22 kW Parent socket incl. SI (8EM1310-3FH04-3GA2): All versions prior to V2.135 (CVE-2025-31930) Siemens UL Commercial Cellular 48A NTEP (8EM1310-5HF14-1GA2): All versions (CVE-2025-31929) Siemens UL Commercial Cellular 48A NTEP (8EM1310-5HF14-1GA2): All versions prior to V2.135 (CVE-2025-31930) Siemens UL Commercial Child 40A w/ 15118 HW (8EM1310-4CF14-0GA0): All versions (CVE-2025-31929) Siemens IEC 1Ph 7.4kW Parent cable 7m (8EM1310-2EJ04-3GA1): All versions (CVE-2025-31929) Siemens UL Commercial Child 40A w/ 15118 HW (8EM1310-4CF14-0GA0): All versions prior to V2.135 (CVE-2025-31930) Siemens UL Commercial Child 48A BA Compliant (8EM1315-5CG14-0GA0): All versions (CVE-2025-31929) Siemens UL Commercial Child 48A BA Compliant (8EM1315-5CG14-0GA0): All versions prior to V2.135 (CVE-2025-31930) Siemens UL Commercial Child 48A w/ 15118 HW (8EM1310-5CF14-0GA0): All versions (CVE-2025-31929) Siemens UL Commercial Child 48A w/ 15118 HW (8EM1310-5CF14-0GA0): All versions prior to V2.135 (CVE-2025-31930) Siemens UL Commercial Parent 40A with Simcard (8EM1310-4CF14-1GA2): All versions (CVE-2025-31929) Siemens UL Commercial Parent 40A with Simcard (8EM1310-4CF14-1GA2): All versions prior to V2.135 (CVE-2025-31930) Siemens UL Commercial Parent 48A (USPS) (8EM1317-5CG14-1GA2): All versions (CVE-2025-31929) Siemens UL Commercial Parent 48A (USPS) (8EM1317-5CG14-1GA2): All versions prior to V2.135 (CVE-2025-31930) Siemens UL Commercial Parent 48A BA Compliant (8EM1315-5CG14-1GA2): All versions (CVE-2025-31929) Siemens IEC 1Ph 7.4kW Parent cable 7m (8EM1310-2EJ04-3GA1): All versions prior to V2.135 (CVE-2025-31930) Siemens UL Commercial Parent 48A BA Compliant (8EM1315-5CG14-1GA2): All versions prior to V2.135 (CVE-2025-31930) Siemens UL Commercial Parent 48A with Simcard BA (8EM1310-5CF14-1GA2): All versions (CVE-2025-31929) Siemens UL Commercial Parent 48A with Simcard BA (8EM1310-5CF14-1GA2): All versions prior to V2.135 (CVE-2025-31930) Siemens UL Commercial Parent 48A,15118 25ft Sim (8EM1310-5CG14-1GA2): All versions (CVE-2025-31929) Siemens UL Commercial Parent 48A,15118 25ft Sim (8EM1310-5CG14-1GA2): All versions prior to V2.135 (CVE-2025-31930) Siemens UL Commercial Parent 48A, 15118, 25ft (8EM1310-5CG14-1GA1): All versions (CVE-2025-31929) Siemens UL Commercial Parent 48A, 15118, 25ft (8EM1310-5CG14-1GA1): All versions prior to V2.135 (CVE-2025-31930) Siemens UL Commercial Parent 48A, 15118, 25ft (8EM1314-5CG14-2FA2): All versions (CVE-2025-31929) Siemens UL Commercial Parent 48A, 15118, 25ft (8EM1314-5CG14-2FA2): All versions prior to V2.135 (CVE-2025-31930) Siemens UL Commercial Parent 48A, 15118, 25ft (8EM1315-5HG14-1GA2): All versions (CVE-2025-31929) Siemens IEC 1Ph 7.4kW Parent cable 7m incl. SIM (8EM1310-2EJ04-3GA2): All versions (CVE-2025-31929) Siemens UL Commercial Parent 48A, 15118, 25ft (8EM1315-5HG14-1GA2): All versions prior to V2.135 (CVE-2025-31930) Siemens UL Resi High End 40A w/15118 Hw (8EM1312-4CF18-0FA3): All versions (CVE-2025-31929) Siemens UL Resi High End 48A w/15118 Hw (8EM1312-5CF18-0FA3): All versions (CVE-2025-31929) Siemens VersiCharge Blue 80A AC Cellular (8EM1315-7BG16-1FH2): All versions (CVE-2025-31929) Siemens VersiCharge Blue 80A AC Cellular (8EM1315-7BG16-1FH2): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC 1Ph 7.4kW Parent cable 7m incl. SIM (8EM1310-2EJ04-3GA2): All versions prior to V2.135 (CVE-2025-31930) Siemens IEC 1Ph 7.4kW Parent socket (8EM1310-2EH04-3GA1): All versions (CVE-2025-31929).","CVE-2025-31929, CVE-2025-31930",8.7,High,"CWE-1326, CWE-1188",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3322,5/15/2025,5/15/2025,2025,ICSA-25-135-09,Siemens User Management Component (UMC),Siemens,User Management Component (UMC),Siemens reports that the following products are affected: Siemens SIMATIC PCS neo V4.1: All versions Siemens SIMATIC PCS neo V5.0: All versions Siemens SINEC NMS: All versions Siemens SINEMA Remote Connect: All versions Siemens Totally Integrated Automation Portal (TIA Portal) V17: All versions Siemens Totally Integrated Automation Portal (TIA Portal) V18: All versions Siemens Totally Integrated Automation Portal (TIA Portal) V19: All versions Siemens Totally Integrated Automation Portal (TIA Portal) V20: All versions Siemens User Management Component (UMC): All versions prior to V2.15.1.1.,"CVE-2025-30174, CVE-2025-30175, CVE-2025-30176",8.7,High,"CWE-125, CWE-787, CWE-125",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3321,5/15/2025,5/15/2025,2025,ICSA-25-135-10,Siemens OZW Web Servers,Siemens,OZW Web Servers,Siemens reports that the following products are affected: OZW672: Versions prior to V8.0 (CVE-2025-26389) OZW672: Versions prior to V6.0 (CVE-2025-26390) OZW772: Versions prior to V8.0 (CVE-2025-26389) OZW772: Versions prior to V6.0 (CVE-2025-26390).,"CVE-2025-26389, CVE-2025-26390",10.0,Critical,"CWE-78, CWE-89",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3320,5/15/2025,5/15/2025,2025,ICSA-25-135-11,Siemens Polarion,Siemens,Polarion,"Siemens reports that the following products are affected: Polarion V2310: All versions Polarion V2404: Versions prior to V2404.4 (CVE-2024-51444, CVE-2024-51445, CVE-2024-51446) Polarion V2404: Versions prior to V2404.2 (CVE-2024-51447).","CVE-2024-51444, CVE-2024-51445, CVE-2024-51446, CVE-2024-51447",7.1,High,"CWE-89, CWE-611, CWE-79, CWE-204",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3319,5/15/2025,5/15/2025,2025,ICSA-25-135-12,Siemens SIMATIC PCS neo,Siemens,SIMATIC PCS neo,Siemens reports that the following products are affected: SIMATIC PCS neo V4.1: All versions prior to V4.1 Update 3 SIMATIC PCS neo V5.0: All versions prior to V5.0 Update 1.,CVE-2025-40566,8.7,High,CWE-613,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3318,5/15/2025,5/15/2025,2025,ICSA-25-135-13,Siemens SIRIUS 3SK2 Safety Relays and 3RK3 Modular Safety Systems,Siemens,"SIRIUS 3RK3 Modular Safety System (MSS), SIRIUS Safety Relays 3SK2",Siemens reports that the following products are affected: SIRIUS 3RK3 Modular Safety System (MSS): All versions SIRIUS Safety Relays 3SK2: All versions.,"CVE-2025-24007, CVE-2025-24008, CVE-2025-24009",8.7,High,"CWE-327, CWE-311, CWE-732",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3317,5/15/2025,5/15/2025,2025,ICSA-25-135-14,Siemens APOGEE PXC and TALON TC Series,Siemens,APOGEE PXC and TALON TC Series,Siemens reports the following products are affected: Siemens APOGEE PXC+TALON TC Series: All versions.,CVE-2025-40555,5.3,Medium,CWE-440,Commercial Facilities; Energy; Government Facilities; Healthcare and Public Health; Information Technology; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3316,5/15/2025,5/15/2025,2025,ICSA-25-135-15,Siemens Mendix OIDC SSOICSA-25-135-16 Siemens MS/TP Point Pickup Module,Siemens,Mendix OIDC SSO,Siemens reports the following products are affected: Siemens Mendix OIDC SSO (Mendix 9 compatible): All versions Siemens Mendix OIDC SSO (Mendix 10 compatible): All versions before V4.0.0.,CVE-2025-40571,2.1,Low,CWE-266,Critical Manufacturing; Energy; Financial Services; Healthcare and Public Health; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3315,5/15/2025,5/15/2025,2025,ICSA-25-135-16,Siemens MS/TP Point Pickup Module,Siemens,MS/TP Point Pickup Module,Siemens reports the following products are affected: Siemens MS/TP Point Pickup Module: All versions.,CVE-2025-24510,7.1,High,CWE-20,Commercial Facilities; Energy; Government Facilities; Healthcare and Public Health; Information Technology; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3314,5/15/2025,5/15/2025,2025,ICSA-25-135-17,Siemens RUGGEDCOM ROX II,Siemens,RUGGEDCOM ROX II,. 3. TECHNICAL DETAILS 3.1 AFFECTED PRODUCTS Siemens reports that the following products are affected: RUGGEDCOM ROX MX5000: Versions prior to V2.16.5 RUGGEDCOM ROX RX1536: Versions prior to V2.16.5 RUGGEDCOM ROX RX5000: Versions prior to V2.16.5 RUGGEDCOM ROX MX5000RE: Versions prior to V2.16.5 RUGGEDCOM ROX RX1400: Versions prior to V2.16.5 RUGGEDCOM ROX RX1500: Versions prior to V2.16.5 RUGGEDCOM ROX RX1501: Versions prior to V2.16.5 RUGGEDCOM ROX RX1510: Versions prior to V2.16.5 RUGGEDCOM ROX RX1511: Versions prior to V2.16.5 RUGGEDCOM ROX RX1512: Versions prior to V2.16.5 RUGGEDCOM ROX RX1524: Versions prior to V2.16.5.,"CVE-2025-32469, CVE-2025-33024, CVE-2025-33025",9.4,Critical,CWE-602,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3313,5/15/2025,5/15/2025,2025,ICSA-25-135-18,Siemens SCALANCE LPE9403,Siemens,SCALANCE LPE9403,"Siemens reports that the following products are affected: SCALANCE LPE9403 (6GK5998-3GS00-2AC2): All versions (CVE-2025-40572, CVE-2025-40573, CVE-2025-40574, CVE-2025-40575, CVE-2025-40576, CVE-2025-40577, CVE-2025-40578, CVE-2025-40579, CVE-2025-40580) SCALANCE LPE9403 (6GK5998-3GS00-2AC2): All versions (CVE-2025-40581, CVE-2025-40582, CVE-2025-40583).","CVE-2025-40572, CVE-2025-40573, CVE-2025-40574, CVE-2025-40575, CVE-2025-40576, CVE-2025-40577, CVE-2025-40578, CVE-2025-40579, CVE-2025-40580, CVE-2025-40581, CVE-2025-40582, CVE-2025-40583",8.5,High,"CWE-732, CWE-35, CWE-457, CWE-476, CWE-125, CWE-121, CWE-288, CWE-78, CWE-319",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3312,5/15/2025,7/10/2025,2025,ICSA-25-135-19,ECOVACS DEEBOT Vacuum and Base Station (Update A),ECOVACS,DEEBOT Vacuum and Base Station,ECOVACS reports the following DEEBOT vacuum and base station devices are affected: X1S PRO: Versions prior to 2.5.38 X1 PRO OMNI: Versions prior to 2.5.38 X1 OMNI: Versions prior to 2.4.45 X1 TURBO: Versions prior to 2.4.45 T10 Series: Versions prior to 1.11.0 T20 Series: Versions prior to 1.25.0 T30 Series: Versions prior to 1.100.0.,"CVE-2025-30198, CVE-2025-30199, CVE-2025-30200",8.6,High,"CWE-321, CWE-494",Commercial Facilities,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3311,5/15/2025,5/15/2025,2025,ICSA-25-135-20,Schneider Electric EcoStruxure Power Build Rapsody,Schneider Electric,EcoStruxure Power Build Rapsody,The following versions of Schneider Electric EcoStruxure Power Build Rapsody is affected: EcoStruxure Power Build Rapsody: Version v2.7.12 FR and prior.,CVE-2025-3916,4.6,Medium,CWE-121,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3310,5/13/2025,5/13/2025,2025,ICSA-25-133-01,Hitachi Energy Service Suite,Hitachi Energy,Service Suite,Hitachi Energy reports the following products are affected: Service Suite: Versions 9.8.1.3 and prior.,"CVE-2006-20001, CVE-2022-26377, CVE-2022-28330, CVE-2022-28614, CVE-2022-28615, CVE-2022-29404, CVE-2022-30522, CVE-2022-30556, CVE-2022-31813, CVE-2022-36760, CVE-2022-37436, CVE-2023-25690, CVE-2023-27522, CVE-2023-31122, CVE-2023-43622, CVE-2023-45802",9.3,Critical,"CWE-348, CWE-444, CWE-190, CWE-787, CWE-770, CWE-200, CWE-789, CWE-125, CWE-400, CWE-404, CWE-113",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3309,11/28/2023,2/26/2026,2025,ICSA-25-133-02,Hitachi Energy Relion 670/650/SAM600-IO Series (Update B),Hitachi Energy,Hitachi Energy Relion 670/650/SAM600-IO Series (Update C),"Relion 670 series version 2.0 revisions up to 2.0.0.13, Relion 670/650 series version 2.1 revisions up to 2.1.0.5, Relion 670 series version 2.2.0 all revisions, Relion 670/650/SAM600-IO series version 2.2.1 revisions up to 2.2.1.8, Relion 670 series version 2.2.2.x below 2.2.2.6, Relion 670 series version 2.2.3.x below 2.2.3.7, Relion 670/650 series version 2.2.4.x below 2.2.4.4, Relion 670/650/SAM600-IO series version 2.2.5.x below 2.2.5.6",CVE-2023-4518,6.5,Medium,CWE-1284,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3308,5/13/2025,5/13/2025,2025,ICSA-25-133-03,Hitachi Energy MACH GWS Products,Hitachi Energy,MACH GWS products,"The following versions of Hitachi Energy products are affected: MACH GWS: Version 2.1.0.0 (CVE-2024-4872, CVE-2024-3980) MACH GWS: Versions 2.2.0.0 to 2.4.0.0 (CVE-2024-4872, CVE-2024-3980) MACH GWS: Versions 3.0.0.0 to 3.3.0.0 (CVE-2024-4872, CVE-2024-3980, CVE-2024-3982) MACH GWS: Versions 3.1.0.0 to 3.3.0.0 (CVE-2024-7940).","CVE-2024-3980, CVE-2024-3982, CVE-2024-4872, CVE-2024-7940",9.4,Critical,"CWE-943, CWE-22, CWE-294, CWE-306",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3307,4/30/2025,5/21/2026,2025,ICSA-25-133-04,ABB Automation Builder (Update A),ABB,ABB Automation Builder (Update A),All ABB Automation Builder <= 2.8.0,"CVE-2025-3394, CVE-2025-3395",7.8,High,CWE-732,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3306,5/8/2025,5/8/2025,2025,ICSA-25-128-01,Horner Automation Cscape,Horner Automation,Cscape,"The following versions of Horner Automation Cscape, a control system application programming software, are affected: Cscape: Version 10.0 (10.0.415.2) SP1.",CVE-2025-4098,8.4,High,CWE-125,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3305,5/8/2025,5/8/2025,2025,ICSA-25-128-02,Hitachi Energy RTU500 series,Hitachi Energy,RTU500 series,Hitachi Energy reports the following products are affected: RTU500 series: Versions 12.0.1 to 12.0.14 RTU500 series: Versions 12.2.1 to 12.2.11 RTU500 series: Versions 12.4.1 to 12.4.11 RTU500 series: Versions 12.6.1 to 12.6.9 RTU500 series: Versions 12.7.1 to 12.7.6 RTU500 series: Versions 13.2.1 to 13.2.6 RTU500 series: Versions 13.4.1 to 13.4.3.,"CVE-2023-5767, CVE-2023-5768, CVE-2023-5769",8.2,High,"CWE-79, CWE-1285",Critical Manufacturing,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3304,4/25/2025,8/27/2026,2025,ICSA-25-128-03,Mitsubishi Electric Multiple FA Products (Update D),Mitsubishi Electric,Mitsubishi Electric Multiple FA Products (Update D),Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32D <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32T <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32TE <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32DT <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-32DTE <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32D <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32T <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32TE <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32DT <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-32DTE <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCF1-32D <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCF1-32T <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCE3-32D <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GNCE3-32DT <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A4-16D <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A4-16DE <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A2-16T <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A2-16TE <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A42-16DT <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN12A42-16DTE <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-16D <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-16T <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2S1-16TE <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-16D <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-16T <=09 | Mitsubishi Electric CC-Link IE TSN Remote I/O module NZ2GN2B1-16TE <=09 | Mitsubishi Electric CC-Link IE TSN Analog-Digital Converter module NZ2GN2S-60AD4 <=07 | Mitsubishi Electric CC-Link IE TSN Analog-Digital Converter module NZ2GN2B-60AD4 <=07 | Mitsubishi Electric CC-Link IE TSN Digital-Analog Converter module NZ2GN2S-60DA4 <=07 | Mitsubishi Electric CC-Link IE TSN Digital-Analog Converter module NZ2GN2B-60DA4 <=07 | Mitsubishi Electric CC-Link IE TSN FPGA module NZ2GN2S-D41P01 01 | Mitsubishi Electric CC-Link IE TSN FPGA module NZ2GN2S-D41D01 01 | Mitsubishi Electric CC-Link IE TSN FPGA module NZ2GN2S-D41PD02 01 | Mitsubishi Electric CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY NZ2GACP620-300 <=1.08J | Mitsubishi Electric CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY NZ2GACP620-60 <=1.08J | Mitsubishi Electric MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-T2 <=26 | Mitsubishi Electric MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-EIP <=10 | Mitsubishi Electric MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-SX <=05 | Mitsubishi Electric MELSEC iQ-R Series Ethernet Interface Module RJ71EN71 <=85 | Mitsubishi Electric CC-Link IE TSN master/local Station Communication LSI CP610 NZ2GACP610-60 <=05 | Mitsubishi Electric CC-Link IE TSN master/local Station Communication LSI CP610 NZ2KT-NPETNG51 <=05 | Mitsubishi Electric MELSEC iQ-F Series FX5 CC-Link IE TSN Master/Local Module FX5-CCLGN-MS <=1.020 | Mitsubishi Electric MELSEC iQ-F Series FX5 Ethernet Module FX5-ENET <=1.200 | Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP <=1.106 | Mitsubishi Electric MELSEC iQ-R Series CPU module R04ENCPU (Network Part) <=85 | Mitsubishi Electric MELSEC iQ-R Series CPU module R08ENCPU (Network Part) <=85 | Mitsubishi Electric MELSEC iQ-R Series CPU module R16ENCPU (Network Part) <=85 | Mitsubishi Electric MELSEC iQ-R Series CPU module R32ENCPU (Network Part) <=85 | Mitsubishi Electric MELSEC iQ-R Series CPU module R120ENCPU (Network Part) <=85,CVE-2025-3511,7.5,High,CWE-1284,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3303,5/8/2025,5/8/2025,2025,ICSMA-25-128-01,Pixmeo OsiriX MD,Pixmeo,OsiriX MD,The following Pixmeo products are affected: OsiriX MD: Versions 14.0.1 (Build 2024-02-28) and prior.,"CVE-2025-27578, CVE-2025-27720, CVE-2025-31946",9.3,Critical,"CWE-416, CWE-319",Healthcare and Public Health,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3302,5/6/2025,5/6/2025,2025,ICSA-25-126-01,Optigo Networks ONS NC600,Optigo Networks,ONS NC600,The following versions of Optigo Networks ONS NC600 are affected: ONS NC600: Versions 4.2.1-084 through 4.7.2-330.,CVE-2025-4041,9.3,Critical,CWE-798,Critical Manufacturing,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3301,5/6/2025,5/6/2025,2025,ICSA-25-126-02,Milesight UG65-868M-EA,Milesight,UG65-868M-EA,"The following versions of UG65-868M-EA, an industrial gateway, are affected: UG65-868M-EA: Firmware versions prior to 60.0.0.46.",CVE-2025-4043,6.1,Medium,CWE-1274,Energy,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3300,5/6/2025,1/29/2026,2025,ICSA-25-126-03,BrightSign Players (Update A),BrightSign,BrightSign Players (Update A),"BrightSign BrightSign OS series 4 players: =V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V30.1.0 Siemens SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AL03-0AB0): vers:all/>=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V6.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V3.1.0|=V30.1.0.,CVE-2023-37482,6.9,Medium,CWE-203,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3205,2/13/2025,2/13/2025,2025,ICSA-25-044-03,Siemens SIPROTEC 5,Siemens,SIPROTEC 5,Siemens reports the following products are affected: Siemens SIPROTEC 5 7SK85 (CP300): vers:all/* Siemens SIPROTEC 5 7SJ81 (CP100): vers:all/* Siemens SIPROTEC 5 7SL86 (CP300): vers:all/* Siemens SIPROTEC 5 7SL86 (CP200): vers:all/* Siemens SIPROTEC 5 7SJ86 (CP300): vers:all/* Siemens SIPROTEC 5 7SK82 (CP100): vers:all/* Siemens SIPROTEC 5 6MD84 (CP300): vers:all/* Siemens SIPROTEC 5 7SA87 (CP200): vers:all/* Siemens SIPROTEC 5 7ST85 (CP300): vers:all/* Siemens SIPROTEC 5 7SD87 (CP200): vers:all/* Siemens SIPROTEC 5 7UT87 (CP300): vers:all/* Siemens SIPROTEC 5 6MD89 (CP300): vers:all/* Siemens SIPROTEC 5 7SD82 (CP100): vers:all/* Siemens SIPROTEC 5 6MD85 (CP300): vers:all/* Siemens SIPROTEC 5 7ST86 (CP300): vers:all/* Siemens SIPROTEC 5 7SJ82 (CP150): vers:all/* Siemens SIPROTEC 5 7UT86 (CP200): vers:all/* Siemens SIPROTEC 5 7SX85 (CP300): vers:all/* Siemens SIPROTEC 5 7SD87 (CP300): vers:all/* Siemens SIPROTEC 5 7VU85 (CP300): vers:all/* Siemens SIPROTEC 5 6MU85 (CP300): vers:all/* Siemens SIPROTEC 5 7SD86 (CP300): vers:all/* Siemens SIPROTEC 5 7UT86 (CP300): vers:all/* Siemens SIPROTEC 5 7VK87 (CP200): vers:all/* Siemens SIPROTEC 5 7UT85 (CP300): vers:all/* Siemens SIPROTEC 5 7UT82 (CP150): vers:all/* Siemens SIPROTEC 5 7SA87 (CP300): vers:all/* Siemens SIPROTEC 5 7SJ81 (CP150): vers:all/* Siemens SIPROTEC 5 7SJ82 (CP100): vers:all/* Siemens SIPROTEC 5 7SA82 (CP100): vers:all/* Siemens SIPROTEC 5 7UT87 (CP200): vers:all/* Siemens SIPROTEC 5 7SX82 (CP150): vers:all/* Siemens SIPROTEC 5 7SD86 (CP200): vers:all/* Siemens SIPROTEC 5 7SL87 (CP300): vers:all/* Siemens SIPROTEC 5 6MD85 (CP200): vers:all/* Siemens SIPROTEC 5 7ST85 (CP200): vers:all/* Siemens SIPROTEC 5 Compact 7SX800 (CP050): vers:all/* Siemens SIPROTEC 5 6MD86 (CP300): vers:all/* Siemens SIPROTEC 5 7SD82 (CP150): vers:all/* Siemens SIPROTEC 5 7KE85 (CP300): vers:all/* Siemens SIPROTEC 5 7SL82 (CP100): vers:all/* Siemens SIPROTEC 5 7SL82 (CP150): vers:all/* Siemens SIPROTEC 5 7VE85 (CP300): vers:all/* Siemens SIPROTEC 5 7KE85 (CP200): vers:all/* Siemens SIPROTEC 5 7SA86 (CP200): vers:all/* Siemens SIPROTEC 5 7SL87 (CP200): vers:all/* Siemens SIPROTEC 5 7SY82 (CP150): vers:all/* Siemens SIPROTEC 5 6MD86 (CP200): vers:all/* Siemens SIPROTEC 5 7SJ86 (CP200): vers:all/* Siemens SIPROTEC 5 7SA86 (CP300): vers:all/* Siemens SIPROTEC 5 7UM85 (CP300): vers:all/* Siemens SIPROTEC 5 7SS85 (CP300): vers:all/* Siemens SIPROTEC 5 7SK82 (CP150): vers:all/* Siemens SIPROTEC 5 7UT82 (CP100): vers:all/* Siemens SIPROTEC 5 7SS85 (CP200): vers:all/* Siemens SIPROTEC 5 7SJ85 (CP200): vers:all/* Siemens SIPROTEC 5 7UT85 (CP200): vers:all/* Siemens SIPROTEC 5 7SK85 (CP200): vers:all/* Siemens SIPROTEC 5 7VK87 (CP300): vers:all/* Siemens SIPROTEC 5 7SJ85 (CP300): vers:all/* Siemens SIPROTEC 5 7SA82 (CP150): vers:all/*.,CVE-2024-53651,5.1,Medium,CWE-312,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3204,2/13/2025,2/13/2025,2025,ICSA-25-044-04,Siemens SIPROTEC 5,Siemens,SIPROTEC 5,Siemens reports that the following products are affected: Siemens SIPROTEC 5 7SK85 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7SJ81 (CP100): All versions Siemens SIPROTEC 5 7SL86 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7SL86 (CP200): All versions Siemens SIPROTEC 5 7SJ86 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7SK82 (CP100): All versions Siemens SIPROTEC 5 6MD84 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7SA87 (CP200): All versions Siemens SIPROTEC 5 7ST85 (CP300): All versions Siemens SIPROTEC 5 7SD87 (CP200): All versions Siemens SIPROTEC 5 7UT87 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 6MD89 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7SD82 (CP100): All versions Siemens SIPROTEC 5 6MD85 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7ST86 (CP300): All versions Siemens SIPROTEC 5 7SJ82 (CP150): All versions prior to V9.90 Siemens SIPROTEC 5 7UT86 (CP200): All versions Siemens SIPROTEC 5 7SX85 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7SD87 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7VU85 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 6MU85 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7SD86 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7UT86 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7VK87 (CP200): All versions Siemens SIPROTEC 5 7UT85 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7UT82 (CP150): All versions prior to V9.90 Siemens SIPROTEC 5 7SA87 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7SJ81 (CP150): All versions prior to V9.90 Siemens SIPROTEC 5 7SJ82 (CP100): All versions Siemens SIPROTEC 5 7SA82 (CP100): All versions Siemens SIPROTEC 5 7UT87 (CP200): All versions Siemens SIPROTEC 5 7SX82 (CP150): All versions prior to V9.90 Siemens SIPROTEC 5 7SD86 (CP200): All versions Siemens SIPROTEC 5 7SL87 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 6MD85 (CP200): All versions Siemens SIPROTEC 5 7ST85 (CP200): All versions Siemens SIPROTEC 5 Compact 7SX800 (CP050): All versions prior to V9.90 Siemens SIPROTEC 5 6MD86 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7SD82 (CP150): All versions prior to V9.90 Siemens SIPROTEC 5 7KE85 (CP300): All versions Siemens SIPROTEC 5 7SL82 (CP100): All versions Siemens SIPROTEC 5 7SL82 (CP150): All versions prior to V9.90 Siemens SIPROTEC 5 7VE85 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7KE85 (CP200): All versions Siemens SIPROTEC 5 7SA86 (CP200): All versions Siemens SIPROTEC 5 7SL87 (CP200): All versions Siemens SIPROTEC 5 7SY82 (CP150): All versions prior to V9.90 Siemens SIPROTEC 5 6MD86 (CP200): All versions Siemens SIPROTEC 5 7SJ86 (CP200): All versions Siemens SIPROTEC 5 7SA86 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7UM85 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7SS85 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7SK82 (CP150): All versions prior to V9.90 Siemens SIPROTEC 5 7UT82 (CP100): All versions Siemens SIPROTEC 5 7SS85 (CP200): All versions Siemens SIPROTEC 5 7SJ85 (CP200): All versions Siemens SIPROTEC 5 7UT85 (CP200): All versions Siemens SIPROTEC 5 7SK85 (CP200): All versions Siemens SIPROTEC 5 7VK87 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7SJ85 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7SA82 (CP150): All versions prior to V9.90.,CVE-2024-53648,7.0,High,CWE-489,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3203,2/13/2025,2/13/2025,2025,ICSA-25-044-05,Siemens SIPROTEC 5 Devices,Siemens,SIPROTEC 5 Devices,Siemens reports that the following products are affected: Siemens SIPROTEC 5 7VE85 (CP300): Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 7SS85 (CP300): Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 2): All versions prior to V9.90 Siemens SIPROTEC 5 Communication Module ETH-BA-2EL (Rev.2): All versions prior to V9.90 Siemens SIPROTEC 5 7UT82 (CP150): All versions prior to V9.90 Siemens SIPROTEC 5 7UT85 (CP300): Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 6MD84 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7SJ82 (CP150): All versions prior to V9.90 Siemens SIPROTEC 5 7SL86 (CP300): Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 7KE85 (CP300): Versions later than and including V8.80 Siemens SIPROTEC 5 7SJ86 (CP300): Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 6MD86 (CP300): Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 7SX82 (CP150): All versions prior to V9.90 Siemens SIPROTEC 5 7SL87 (CP300): Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 7SA82 (CP150): All versions prior to V9.90 Siemens SIPROTEC 5 7SL82 (CP150): All versions prior to V9.90 Siemens SIPROTEC 5 7SJ85 (CP300): Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 7ST85 (CP300): Versions later than and including V8.80 Siemens SIPROTEC 5 7ST86 (CP300): All versions Siemens SIPROTEC 5 7SD82 (CP150): All versions prior to V9.90 Siemens SIPROTEC 5 7SK85 (CP300): Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 Compact 7SX800 (CP050): Version V9.50 up to but not including V9.90 Siemens SIPROTEC 5 6MD85 (CP300): Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 6MU85 (CP300): Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 7SK82 (CP150): All versions prior to V9.90 Siemens SIPROTEC 5 7SA87 (CP300): Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 7VK87 (CP300): Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 7VU85 (CP300): All versions prior to V9.90 Siemens SIPROTEC 5 7SA86 (CP300): Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 7SD87 (CP300): Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 Communication Module ETH-BD-2FO: Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 6MD89 (CP300): Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 7UM85 (CP300): Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 7SJ81 (CP150): All versions prior to V9.90 Siemens SIPROTEC 5 7UT86 (CP300): Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 7SX85 (CP300): Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 7UT87 (CP300): Version V8.80 up to but not including V9.90 Siemens SIPROTEC 5 7SY82 (CP150): All versions prior to V9.90 Siemens SIPROTEC 5 7SD86 (CP300): Version V8.80 up to but not including V9.90.,CVE-2024-54015,8.7,High,CWE-1392,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3202,2/13/2025,2/13/2025,2025,ICSA-25-044-06,Siemens RUGGEDCOM APE1808 Devices,Siemens,RUGGEDCOM APE1808 Devices,Siemens reports that the following products are affected: Siemens RUGGEDCOM APE1808: All versions.,"CVE-2024-36504, CVE-2024-46665, CVE-2024-46666, CVE-2024-46668, CVE-2024-46669, CVE-2024-46670, CVE-2024-48884, CVE-2024-48885, CVE-2024-52963, CVE-2024-54021",7.5,High,"CWE-125, CWE-201, CWE-770, CWE-190, CWE-22, CWE-787, CWE-113",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3201,2/13/2025,2/13/2025,2025,ICSA-25-044-07,Siemens Teamcenter,Siemens,Teamcenter,Siemens reports that the following products are affected: Siemens Teamcenter: All versions prior to V14.3.0.0.,CVE-2025-23363,7.4,High,CWE-601,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3200,2/13/2025,2/13/2025,2025,ICSA-25-044-08,Siemens OpenV2G,Siemens,OpenV2G,Siemens reports that the following products are affected: Siemens OpenV2G: All versions prior to V0.9.6.,CVE-2025-24956,6.2,Medium,CWE-120,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3199,2/13/2025,2/13/2025,2025,ICSA-25-044-09,Siemens SCALANCE W700,Siemens,SCALANCE W700,Siemens reports that the following products are affected: Siemens SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0): All versions prior to v3.0.0 Siemens SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0): All versions prior to v3.0.0 Siemens SCALANCE WUM763-1 (US) (6GK5763-1AL00-3DB0):All versions prior to v3.0.0 Siemens SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0): All versions prior to v3.0.0 Siemens SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0): All versions prior to v3.0.0 Siemens SCALANCE WUM766-1 (USA) (6GK5766-1GE00-3DB0): All versions prior to v3.0.0 Siemens SCALANCE WUM763-1 (US) (6GK5763-1AL00-3AB0):All versions prior to v3.0.0 Siemens SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0): All versions prior to v3.0.0 Siemens SCALANCE WUM766-1 (ME) (6GK5766-1GE00-3DC0): All versions prior to v3.0.0 Siemens SCALANCE WAM763-1 (6GK5763-1AL00-7DA0): All versions prior to v3.0.0 Siemens SCALANCE WAM766-1 (6GK5766-1GE00-7DA0): All versions prior to v3.0.0 Siemens SCALANCE WUM766-1 (6GK5766-1GE00-3DA0): All versions prior to v3.0.0 Siemens SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0): All versions prior to v3.0.0 Siemens SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0): All versions prior to v3.0.0 Siemens SCALANCE WUB762-1 iFeatures (6GK5762-1AJ00-2AA0): All versions prior to v3.0.0 Siemens SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0): All versions prior to v3.0.0 Siemens SCALANCE WUM763-1 (6GK5763-1AL00-3AA0): All versions prior to v3.0.0 Siemens SCALANCE WUB762-1 (6GK5762-1AJ00-1AA0): All versions prior to v3.0.0.,"CVE-2022-2588, CVE-2022-2663, CVE-2022-3524, CVE-2022-4304, CVE-2022-4450, CVE-2022-39188, CVE-2022-39842, CVE-2022-40303, CVE-2022-40304, CVE-2022-43750, CVE-2022-47069, CVE-2022-47929, CVE-2023-0045, CVE-2023-0215, CVE-2023-0286, CVE-2023-0464, CVE-2023-0465, CVE-2023-0466, CVE-2023-0590, CVE-2023-1073, CVE-2023-1074, CVE-2023-1118, CVE-2023-1206, CVE-2023-1380, CVE-2023-1670, CVE-2023-2194, CVE-2023-3446, CVE-2023-3611, CVE-2023-4623, CVE-2023-4921, CVE-2023-5363, CVE-2023-5678, CVE-2023-5717, CVE-2023-6129, CVE-2023-6237, CVE-2023-7250, CVE-2023-23454, CVE-2023-23455, CVE-2023-23559, CVE-2023-26545, CVE-2023-28484, CVE-2023-28578, CVE-2023-29469, CVE-2023-31085, CVE-2023-31315, CVE-2023-35001, CVE-2023-39192, CVE-2023-39193, CVE-2023-42754, CVE-2023-43522, CVE-2023-44320, CVE-2023-44322, CVE-2023-45853, CVE-2023-45863, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-0727, CVE-2024-2511, CVE-2024-4603, CVE-2024-4741, CVE-2024-5535, CVE-2024-6119, CVE-2024-9143, CVE-2024-23814, CVE-2024-26306, CVE-2024-33016, CVE-2024-50560, CVE-2024-50561, CVE-2024-50572, CVE-2025-24499, CVE-2025-24532",9.8,Critical,"CWE-415, CWE-923, CWE-404, CWE-326, CWE-362, CWE-190, CWE-787, CWE-476, CWE-610, CWE-416, CWE-843, CWE-295, CWE-401, CWE-400, CWE-125, CWE-1333, CWE-684, CWE-754, CWE-183, CWE-20, CWE-369, CWE-425, CWE-252, CWE-222, CWE-304, CWE-78, CWE-834, CWE-200, CWE-203, CWE-119, CWE-79, CWE-74, CWE-284",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3198,2/13/2025,2/13/2025,2025,ICSA-25-044-10,Siemens Questa and ModelSim,Siemens,"Questa, ModelSim",Siemens reports that the following products are affected: Siemens Questa: All versions prior to V2025.1 Siemens ModelSim: All versions prior to V2025.1.,CVE-2024-53977,6.7,Medium,CWE-427,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3197,2/13/2025,2/13/2025,2025,ICSA-25-044-11,Siemens APOGEE PXC and TALON TC Series,Siemens,APOGEE PXC and TALON TC Series,Siemens reports that the following products are affected: APOGEE PXC Series (P2 Ethernet): All versions APOGEE PXC Series (BACnet): All versions TALON TC Series (BACnet): All versions.,"CVE-2024-54089, CVE-2024-54090",8.7,High,"CWE-326, CWE-125",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3196,2/13/2025,2/13/2025,2025,ICSA-25-044-12,Siemens SIMATIC IPC DiagBase and SIMATIC IPC DiagMonitor,Siemens,SIMATIC IPC DiagBase and SIMATIC IPC DiagMonitor,Siemens reports that the following products are affected: SMATIC IPC DiagMonitor: All versions SIMATIC IPC DiagBase: All versions.,CVE-2025-23403,7.3,High,CWE-732,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3195,2/13/2025,2/13/2025,2025,ICSA-25-044-13,Siemens SIMATIC PCS neo and TIA Administrator,Siemens,SIMATIC PCS neo and TIA Administrator,Siemens reports that the following products are affected: SIMOCODE ES V19: Versions prior to V19 Update 1 TIA Administrator: Versions 3.0.4 and prior SIMATIC PCS neo V4.1: Versions prior to V4.1 Update 2 SIMATIC PCS neo V4.0: All versions SIRIUS Safety ES V19 (TIA Portal): Versions prior to V19 Update 1 SIRIUS Soft Starter ES V19 (TIA Portal): Versions prior to V19 Update 1 SIMATIC PCS neo V5.0: Versions prior to V5.0 Update 1.,CVE-2024-45386,8.7,High,CWE-613,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3194,2/13/2025,2/13/2025,2025,ICSA-25-044-14,Siemens Opcenter Intelligence,Siemens,Opcenter Intelligence,Siemens reports that the following products are affected: Siemens Opcenter Intelligence: All versions prior to V2501.,"CVE-2022-22127, CVE-2022-22128, CVE-2023-46604, CVE-2025-26490, CVE-2025-26491",9.4,Critical,"CWE-287, CWE-22, CWE-502, CWE-532, CWE-918",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3193,2/13/2025,2/13/2025,2025,ICSA-25-044-15,ORing IAP-420,ORing,IAP-420,The following ORing products are affected: IAP-420: Versions 2.01e and prior.,"CVE-2024-5410, CVE-2024-5411",8.6,High,"CWE-79, CWE-77",Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3192,2/13/2025,2/13/2025,2025,ICSA-25-044-16,mySCADA myPRO Manager,mySCADA Technologies,myPRO Manager,The following mySCADA products are affected: myPRO Manager: Versions prior to 1.4.,"CVE-2025-22896, CVE-2025-23411, CVE-2025-24865, CVE-2025-25067",10.0,Critical,"CWE-78, CWE-306, CWE-312, CWE-352",Critical Manufacturing,Worldwide,Czech Republic,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3191,2/13/2025,2/13/2025,2025,ICSA-25-044-17,Outback Power Mojave Inverter,Outback Power,Mojave Inverter,"The following versions of Outback Power Mojave Inverter, a system for managing power in a residential grid-connected battery backup system, are affected: Outback Power Mojave Inverter: All versions.","CVE-2025-26473, CVE-2025-25281, CVE-2025-24861",8.7,High,"CWE-598, CWE-200, CWE-77",Energy,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3190,2/13/2025,2/13/2025,2025,ICSA-25-044-18,Dingtian DT-R0 Series,Dingtian,DT-R0 Series,The following versions of Dingtian DT-R0 Series are affected: DT-R002: Version V3.1.3044A DT-R008: Version V3.1.1759A DT-R016: Version V3.1.2776A DT-R032: Version V3.1.3826A.,CVE-2025-1283,9.3,Critical,CWE-288,Critical Manufacturing,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3189,2/13/2025,2/13/2025,2025,ICSMA-25-044-01,Qardio Heart Health IOS and Android Application and QardioARM A100,Qardio,"Heart Health IOS application, Heart Health Android Application, QardioARM A100",The following Qardio products are affected: Qardio Heart Health IOS Mobile Application: Version 2.7.4 Qardio Heart Health Android Mobile Application: Version 2.5.1 QardioARM A100: All versions.,"CVE-2025-20615, CVE-2025-24836, CVE-2025-23421 ",7.2,High,"CWE-359, CWE-248, CWE-552",Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3188,2/6/2025,5/20/2025,2025,ICSA-25-037-01,Schneider Electric EcoStruxure Power Monitoring Expert (PME) (Update B),Schneider Electric,EcoStruxure Power Monitoring Expert (PME),Schneider Electric reports the following products are affected: Schneider Electric EcoStruxure Power Monitoring Expert (PME): 2022 Schneider Electric EcoStruxure Power Monitoring Expert (PME): Versions 2021 and prior.,CVE-2024-9005,7.3,High,CWE-502,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3187,1/14/2025,4/2/2026,2025,ICSA-25-037-02,Schneider Electric EcoStruxure (Update D),Schneider Electric,Schneider Electric EcoStruxure,"EcoStruxure Control Expert Versions prior to V16.2, EcoStruxure Process Expert Versions prior to 2023 (v4.8.0.5715), EcoStruxure OPC UA Server Expert Versions prior to SV2.01SP3, EcoStruxure Control Expert Asset Link Versions prior to V4.0 SP1, EcoStruxure Machine SCADA Expert Asset Link All versions, EcoStruxure Architecture Builder Versions prior to V7.0.18, EcoStruxure Operator Terminal Expert Versions prior to V4.0, Vijeo Designer Version prior to V6.3SP1 HF1, EcoStruxure Machine Expert versions prior to v2.5.0.1, EcoStruxure Machine Expert Twin versions prior to v2.3, Zelio Soft 2 Versions prior to v5.4.3, EcoStruxure Process Expert for AVEVA System Platform All versions, Pro-face BLUE Versions prior to V4.0, EcoStruxure Process Expert Versions prior to 2023, EcoStruxure Machine Expert Safety All versions",CVE-2024-2658,7.8,High,CWE-427,Commercial Facilities; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater Systems,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3186,2/6/2025,2/6/2025,2025,ICSA-25-037-03,ABB Drive Composer,ABB,Drive Composer,ABB reports that the following Drive Composer products are affected: Drive Composer entry: Version 2.9.0.1 and prior Drive Composer pro: Version 2.9.0.1 and prior.,CVE-2024-48510,9.3,Critical,CWE-22,Critical Manufacturing,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3185,2/6/2025,2/11/2025,2025,ICSA-25-037-04,Trimble Cityworks (Update A),Trimble,Cityworks,"The following versions of Trimble Cityworks, an asset and work management system, are affected: Cityworks: All versions prior to 15.8.9 Cityworks with office companion: All versions prior to 23.10.",CVE-2025-0994,8.6,High,CWE-502,Water and Wastewater Systems; Energy; Transportation Systems; Government Facilities; Communications,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3184,2/6/2025,2/6/2025,2025,ICSMA-25-037-01,MicroDicom DICOM Viewer,MicroDicom,DICOM Viewer,The following MicroDicom DICOM Viewer are affected: MicroDicom DICOM Viewer: Version 2024.03.,CVE-2025-1002,5.7,Medium,CWE-295,Healthcare and Public Health,Worldwide,Bulgaria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3183,2/6/2025,2/6/2025,2025,ICSMA-25-037-02,Orthanc Server,Orthanc,Orthanc Server,The following Orthanc products are affected: Orthanc server: Versions prior to 1.5.8.,CVE-2025-0896,9.2,Critical,CWE-306,Healthcare and Public Health,Worldwide,Belgium,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3182,2/4/2025,2/4/2025,2025,ICSA-25-035-01,"Western Telematic Inc NPS Series, DSM Series, CPM Series",Western Telematic Inc,"NPS Series, DSM Series, CPM Series",The following Western Telematic Inc products are affected: Network Power Switch (NPS Series): Firmware Version 6.62 and prior Console Server (DSM Series): Firmware Version 6.62 and prior Console Server + PDU Combo Unit (CPM Series): Firmware Version 6.62 and prior.,CVE-2025-0630,6.0,Medium,CWE-73,Communications,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3181,2/4/2025,2/18/2025,2025,ICSA-25-035-02,Rockwell Automation GuardLogix 5380 and 5580 (Update A),Rockwell Automation,GuardLogix 5380 and 5580,"The following Rockwell Automation products are affected: GuardLogix 5580 (SIL 3 with the safety partner 3): Versions prior to V33.017, V34.014, V35.013, V36.011 Compact GuardLogix 5380 SIL 3: Versions prior to V33.017, V34.014, V35.013, V36.011.",CVE-2025-24478,7.1,High,CWE-755,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3180,2/4/2025,2/4/2025,2025,ICSA-25-035-03,Elber Communications Equipment,Elber,Communications Equipment,The following versions of Elber Communications Equipment are affected: Signum DVB-S/S2 IRD: Versions 1.999 and prior Cleber/3 Broadcast Multi-Purpose Platform: Version 1.0 Reble610 M/ODU XPIC IP-ASI-SDH: Version 0.01 ESE DVB-S/S2 Satellite Receiver: Versions 1.5.179 and prior Wayber Analog/Digital Audio STL: Version 4.,"CVE-2025-0674, CVE-2025-0675",9.3,Critical,"CWE-288, CWE-912",Communications,Worldwide,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3179,2/4/2025,4/22/2025,2025,ICSA-25-035-04,"Schneider Electric Modicon M580 PLCs, BMENOR2200H and EVLink Pro AC (Update A)",Schneider Electric,"Modicon M580 PLCs, BMENOR2200H and EVLink Pro AC","The following versions of Modicon M580 PLCs, BMENOR2200H and EVLink Pro AC are affected: Modicon M580 CPU (part numbers BMEP* and BMEH*, excluding M580 CPU Safety): Versions prior to SV4.30 Modicon M580 CPU Safety (part numbers BMEP58-S and BMEH58-S): Versions prior to SV4.21 BMENOR2200H: Versions prior to SV4.02.01 EVLink Pro AC: Versions prior to v1.3.10.",CVE-2024-11425,8.7,High,CWE-131,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3178,2/4/2025,2/4/2025,2025,ICSA-25-035-05,Schneider Electric Web Designer for Modicon,Schneider Electric,Web Designer for Modicon,The following versions of Web Designer for Modicon are affected: Web Designer for BMXNOR0200H: All versions Web Designer for BMXNOE0110(H): All versions Web Designer for BMENOC0311(C): All versions Web Designer for BMENOC0321(C): All versions.,CVE-2024-12476,7.8,High,CWE-611,Commercial Facilities; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater Systems,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3177,2/4/2025,6/9/2026,2025,ICSA-25-035-06,"Schneider Electric Modicon M340 and BMXNOE0100/0110, BMXNOR0200H (Update B)",Schneider Electric,"Schneider Electric Modicon M340 and BMXNOE0100/0110, BMXNOR0200H","Schneider Electric Modicon M340 processors (part numbers BMXP34*): =1.100|<=1.200, Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP: >=1.100|<=1.104",CVE-2024-8403,7.5,High,CWE-1287,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3086,11/14/2024,11/14/2024,2024,ICSA-24-319-01,Siemens RUGGEDCOM CROSSBOW,Siemens,RUGGEDCOM CROSSBOW,The following Siemens products are affected: RUGGEDCOM CROSSBOW Station Access Controller (SAC): Versions prior to 5.6.,"CVE-2023-7104, CVE-2024-0232",5.5,Medium,"CWE-122, CWE-416",Critical Manufacturing; Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3085,11/14/2024,11/14/2024,2024,ICSA-24-319-02,Siemens SIPORT,Siemens,SIPORT,The following Siemens products are affected: Siemens SIPORT: Versions prior to V3.4.0.,CVE-2024-47783,8.5,High,CWE-732,Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3084,11/14/2024,11/14/2024,2024,ICSA-24-319-03,Siemens OZW672 and OZW772 Web Server,Siemens,OZW672 and OZW772 Web Server,The following Siemens products are affected: OZW672: versions prior to V5.2 OZW772: versions prior to V5.2.,CVE-2024-36140,8.2,High,CWE-79,Critical manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3083,11/14/2024,11/14/2024,2024,ICSA-24-319-04,Siemens SINEC NMS,Siemens,SINEC NMS,The following Siemens products are affected: Siemens SINEC NMS: versions prior to V3.0 SP1.,"CVE-2023-38709, CVE-2023-46218, CVE-2023-46219, CVE-2023-46280, CVE-2023-4807, CVE-2023-5363, CVE-2023-5678, CVE-2023-6129, CVE-2023-6237, CVE-2024-0727, CVE-2024-2004, CVE-2024-2379, CVE-2024-2398, CVE-2024-2466, CVE-2024-24795, CVE-2024-27316, CVE-2024-47808",8.3,High,"CWE-20, CWE-754, CWE-787, CWE-400, CWE-113, CWE-311, CWE-125, CWE-295, CWE-772, CWE-297, CWE-770, CWE-732",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3082,11/14/2024,11/14/2024,2024,ICSA-24-319-05,Siemens Solid Edge,Siemens,Solid Edge,The following Siemens products are affected: Solid Edge SE2024: versions prior to V224.0 Update 9.,"CVE-2024-47940, CVE-2024-47941, CVE-2024-47942",7.3,High,"CWE-125, CWE-125, CWE-427",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3081,11/14/2024,11/14/2024,2024,ICSA-24-319-06,Siemens SCALANCE M-800 Family,Siemens,SCALANCE M-800 Family,The following Siemens products are affected: RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2): versions prior to V8.2 RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2): versions prior to V8.2 SCALANCE M804PB (6GK5804-0AP00-2AA2): versions prior to V8.2 SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2): versions prior to V8.2 SCALANCE M812-1 ADSL-Router (6GK5812-1BA00-2AA2): versions prior to V8.2 SCALANCE M816-1 ADSL-Router (6GK5816-1AA00-2AA2): versions prior to V8.2 SCALANCE M816-1 ADSL-Router (6GK5816-1BA00-2AA2): versions prior to V8.2 SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2): versions prior to V8.2 SCALANCE M874-2 (6GK5874-2AA00-2AA2): versions prior to V8.2 SCALANCE M874-3 3G-Router (CN) (6GK5874-3AA00-2FA2): versions prior to V8.2 SCALANCE M874-3 (6GK5874-3AA00-2AA2): versions prior to V8.2 SCALANCE M876-3 (6GK5876-3AA02-2BA2): versions prior to V8.2 SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2): versions prior to V8.2 SCALANCE M876-4 (6GK5876-4AA10-2BA2): versions prior to V8.2 SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2): versions prior to V8.2 SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2): versions prior to V8.2 SCALANCE MUM853-1 (A1) (6GK5853-2EA10-2AA1): versions prior to V8.2 SCALANCE MUM853-1 (B1) (6GK5853-2EA10-2BA1): versions prior to V8.2 SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1): versions prior to V8.2 SCALANCE MUM856-1 (A1) (6GK5856-2EA10-3AA1): versions prior to V8.2 SCALANCE MUM856-1 (B1) (6GK5856-2EA10-3BA1): versions prior to V8.2 SCALANCE MUM856-1 (CN) (6GK5856-2EA00-3FA1): versions prior to V8.2 SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1): versions prior to V8.2 SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1): versions prior to V8.2 SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2): versions prior to V8.2 SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2): versions prior to V8.2.,"CVE-2021-3506, CVE-2023-28450, CVE-2023-49441, CVE-2024-2511, CVE-2024-26306, CVE-2024-26925, CVE-2024-28882, CVE-2024-4603, CVE-2024-4741, CVE-2024-50557, CVE-2024-50558, CVE-2024-50559, CVE-2024-50560, CVE-2024-50561, CVE-2024-50572, CVE-2024-5594",8.6,High,"CWE-125, CWE-311, CWE-190, CWE-400, CWE-834, CWE-416, CWE-117, CWE-203, CWE-667, CWE-772, CWE-20, CWE-284, CWE-22, CWE-79, CWE-74",Critical Manufacturing; Communications,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3080,11/14/2024,11/14/2024,2024,ICSA-24-319-07,Siemens Engineering Platforms,Siemens,Siemens Engineering Platforms,Siemens reports that the following products are affected: SIMATIC S7-PLCSIM V16: all versions SIMATIC S7-PLCSIM V17: all versions SIMATIC STEP 7 Safety V16: all versions SIMATIC STEP 7 Safety V17: versions prior to V17 Update 8 SIMATIC STEP 7 Safety V18: versions prior to V18 Update 5 SIMATIC STEP 7 V16: all versions SIMATIC STEP 7 V17: versions prior to V17 Update 8 SIMATIC STEP 7 V18: versions prior to V18 Update 5 SIMATIC WinCC Unified V16: all versions SIMATIC WinCC Unified V17: versions prior to V17 Update 8 SIMATIC WinCC Unified V18: versions prior to V18 Update 5 SIMATIC WinCC V16: all versions SIMATIC WinCC V17: versions prior to V17 Update 8 SIMATIC WinCC V18: versions prior to V18 Update 5 SIMOCODE ES V16: all versions SIMOCODE ES V17: versions prior to V17 Update 8 SIMOCODE ES V18: all versions SIMOTION SCOUT TIA V5.4 SP1: all versions SIMOTION SCOUT TIA V5.4 SP3: all versions SIMOTION SCOUT TIA V5.5 SP1: all versions SINAMICS Startdrive V16: all versions SINAMICS Startdrive V17: all versions SINAMICS Startdrive V18: all versions SIRIUS Safety ES V17: versions prior to V17 Update 8 SIRIUS Safety ES V18: all versions SIRIUS Soft Starter ES V17: versions prior to V17 Update 8 SIRIUS Soft Starter ES V18: all versions TIA Portal Cloud V16: all versions TIA Portal Cloud V17: versions prior to V4.6.0.1 TIA Portal Cloud V18: versions prior to V4.6.1.0.,CVE-2023-32736,7.0,High,CWE-502,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3079,11/14/2024,11/14/2024,2024,ICSA-24-319-08,Siemens SINEC INS,Siemens,SINEC INS,The following Siemens products are affected: SINEC INS: versions prior to V1.0 SP2 Update 3.,"CVE-2023-2975, CVE-2023-3341, CVE-2023-3446, CVE-2023-3817, CVE-2023-4236, CVE-2023-4408, CVE-2023-4807, CVE-2023-5517, CVE-2023-5678, CVE-2023-5679, CVE-2023-5680, CVE-2023-6129, CVE-2023-6237, CVE-2023-6516, CVE-2023-7104, CVE-2023-32002, CVE-2023-32003, CVE-2023-32004, CVE-2023-32005, CVE-2023-32006, CVE-2023-32558, CVE-2023-32559, CVE-2023-38552, CVE-2023-39331, CVE-2023-39332, CVE-2023-39333, CVE-2023-44487, CVE-2023-45143, CVE-2023-46809, CVE-2023-47038, CVE-2023-47039, CVE-2023-47100, CVE-2023-48795, CVE-2023-50387, CVE-2023-50868, CVE-2023-52389, CVE-2024-0232, CVE-2024-0727, CVE-2024-2511, CVE-2024-4741, CVE-2024-5535, CVE-2024-21890, CVE-2024-21891, CVE-2024-21892, CVE-2024-21896, CVE-2024-22017, CVE-2024-22019, CVE-2024-22025, CVE-2024-24758, CVE-2024-24806, CVE-2024-27980, CVE-2024-27982, CVE-2024-27983, CVE-2024-46888, CVE-2024-46889, CVE-2024-46890, CVE-2024-46891, CVE-2024-46892, CVE-2024-46894",9.9,Critical,"CWE-287, CWE-787, CWE-1333, CWE-834, CWE-617, CWE-400, CWE-20, CWE-617, CWE-754, CWE-789, CWE-122, CWE-311, CWE-22, CWE-732, CWE-311, CWE-200, CWE-385, CWE-122, CWE-222, CWE-190, CWE-416, CWE-94, CWE-27, CWE-250, CWE-918, CWE-78, CWE-444, CWE-321, CWE-613",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3078,11/14/2024,11/14/2024,2024,ICSA-24-319-09,Siemens Spectrum Power 7,Siemens,Spectrum Power 7,The following versions of Spectrum Power 7 are affected: Spectrum Power 7: All versions prior to V24Q3.,CVE-2024-29119,8.5,High,CWE-266,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3077,11/14/2024,11/14/2024,2024,ICSA-24-319-10,Siemens TeleControl Server,Siemens,TeleControl Server,The following versions of TeleControl Server are affected: PP TeleControl Server Basic 8 to 32 V3.1 (6NH9910-0AA31-0AB1): versions prior to V3.1.2.1 PP TeleControl Server Basic 32 to 64 V3.1 (6NH9910-0AA31-0AF1): versions prior to V3.1.2.1 PP TeleControl Server Basic 64 to 256 V3.1 (6NH9910-0AA31-0AC1): versions prior to V3.1.2.1 PP TeleControl Server Basic 256 to 1000 V3.1 (6NH9910-0AA31-0AD1): versions prior to V3.1.2.1 PP TeleControl Server Basic 1000 to 5000 V3.1 (6NH9910-0AA31-0AE1): versions prior to V3.1.2.1 TeleControl Server Basic 8 V3.1 (6NH9910-0AA31-0AA0): versions prior to V3.1.2.1 TeleControl Server Basic 32 V3.1 (6NH9910-0AA31-0AF0): versions prior to V3.1.2.1 TeleControl Server Basic 64 V3.1 (6NH9910-0AA31-0AB0): versions prior to V3.1.2.1 TeleControl Server Basic 256 V3.1 (6NH9910-0AA31-0AC0): versions prior to V3.1.2.1 TeleControl Server Basic 1000 V3.1 (6NH9910-0AA31-0AD0): versions prior to V3.1.2.1 TeleControl Server Basic 5000 V3.1 (6NH9910-0AA31-0AE0): versions prior to V3.1.2.1 TeleControl Server Basic Serv Upgr (6NH9910-0AA31-0GA1): versions prior to V3.1.2.1 TeleControl Server Basic Upgr V3.1 (6NH9910-0AA31-0GA0): versions prior to V3.1.2.1.,CVE-2024-44102,10.0,Critical,CWE-502,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3076,11/14/2024,11/14/2024,2024,ICSA-24-319-11,Siemens SIMATIC CP,Siemens,SIMATIC CP,The following version of SIMATIC CP is affected: SIMATIC CP1543-1: V4.0 (6GK7543-1AX10-0XE0).,CVE-2024-50310,8.7,High,CWE-863,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3075,11/14/2024,11/14/2024,2024,ICSA-24-319-12,Siemens Mendix Runtime,Siemens,Mendix Runtime,The following versions of Mendix Runtime are affected: Mendix Runtime: V8 Mendix Runtime: V9 Mendix Runtime: V10 Mendix Runtime: V10.6 Mendix Runtime: V10.12.,CVE-2024-50313,6.9,Medium,CWE-362,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3074,11/14/2024,11/14/2024,2024,ICSA-24-319-13,Rockwell Automation Verve Asset Manager,Rockwell Automation,Verve Asset Manager,The following versions of Verve Asset Manager are affected: Verve Asset Manager: Versions 1.39 and prior.,CVE-2024-37287,8.6,High,CWE-1395,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3073,11/14/2024,11/14/2024,2024,ICSA-24-319-14,Rockwell Automation FactoryTalk Updater,Rockwell Automation,FactoryTalk Updater,The following versions of FactoryTalk are affected: FactoryTalk Updater - Web Client: Version 4.00.00 FactoryTalk Updater - Client: All versions FactoryTalk Updater - Agent: All versions.,"CVE-2024-10943, CVE-2024-10944, CVE-2024-10945",9.1,Critical,"CWE-922, CWE-20, CWE-358",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3072,11/14/2024,11/14/2024,2024,ICSA-24-319-15,Rockwell Automation Arena Input Analyzer,Rockwell Automation,Arena Input Analyzer,"The following versions of Rockwell Automation Input Analyzer (Arena), an event simulation and automation software, are affected: Arena Input Analyzer: v16.20.03 and prior.",CVE-2024-6068,7.0,High,CWE-1284,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3071,10/29/2024,5/5/2026,2024,ICSA-24-319-16,Hitachi Energy MSM (Update A),Hitachi Energy,Hitachi Energy MSM,Affected Products: None,"CVE-2024-2398, CVE-2019-5097",8.6,High,"CWE-772, CWE-835",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3070,11/14/2024,2/11/2025,2024,ICSA-24-319-17,2N Access Commander (Update A),2N,Access Commander,"The following versions of 2N Access Commander, an IP access control system, are affected: Access Commander: Versions 3.1.1.2 and prior Access Commander: Versions 1.14 and prior (CVE-2024-47256).","CVE-2024-47253, CVE-2024-47254, CVE-2024-47255, CVE-2024-47256",8.6,High,"CWE-22, CWE-345, CWE-321",Government Facilities; Commercial Facilities; Communications; Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3069,11/14/2024,11/14/2024,2024,ICSMA-24-319-01,Baxter Life2000 Ventilation System,Baxter,Life2000 Ventilation System,The following Baxter (formerly Hillrom) products are affected: Life2000 Ventilation System: Version 06.08.00.00 and prior.,"CVE-2020-8004, CVE-2024-48966, CVE-2024-48967, CVE-2024-48970, CVE-2024-48971, CVE-2024-48973, CVE-2024-48974, CVE-2024-9832, CVE-2024-9834",10.0,Critical,"CWE-319, CWE-307, CWE-798, CWE-1263, CWE-494, CWE-1191, CWE-1318, CWE-306, CWE-778",Healthcare and Public Health,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3068,11/12/2024,11/12/2024,2024,ICSA-24-317-01,Subnet Solutions PowerSYSTEM Center,SUBNET Solutions Inc.,PowerSYSTEM Center,"The following versions of SUBNET PowerSYSTEM Center, an OT device management platform, are affected: PowerSYSTEM Center PSC 2020: v5.22.x and prior.","CVE-2024-45490, CVE-2024-45491, CVE-2024-45492",9.8,Critical,"CWE-611, CWE-190",Critical Manufacturing; Energy,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3067,11/12/2024,11/12/2024,2024,ICSA-24-317-02,Hitachi Energy TRO600,Hitachi Energy,TRO600 Series,The following products of Hitachi Energy are affected: Hitachi Energy TRO600 series firmware versions: 9.0.1.0 - 9.2.0.0 (CVE-2024-41156) Hitachi Energy TRO600 series firmware versions: 9.1.0.0 - 9.2.0.0 (CVE-2024-41153).,"CVE-2024-41153, CVE-2024-41156",7.2,High,"CWE-77, CWE-212",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3066,11/12/2024,11/12/2024,2024,ICSA-24-317-03,Rockwell Automation FactoryTalk View ME,Rockwell Automation,FactoryTalk View ME,"Rockwell Automation reports that the following versions of FactoryTalk Software are affected: FactoryTalk View ME, when using default folder privileges: v14.0 and prior.",CVE-2024-37365,7.0,High,CWE-20,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3065,11/7/2024,11/7/2024,2024,ICSA-24-312-01,Beckhoff Automation TwinCAT Package Manager,Beckhoff Automation,TwinCAT Package Manager,The following Beckhoff Automation products are affected: TwinCAT Package Manager: Versions prior to 1.0.603.0.,CVE-2024-8934,7.0,High,CWE-78,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3064,11/7/2024,11/7/2024,2024,ICSA-24-312-02,Delta Electronics DIAScreen,Delta Electronics,DIAScreen,"The following versions of DIAScreen, which is a component of Delta's DIAStudio Smart Machine Suite integrated engineering software package, are affected: DIAScreen: versions prior to v1.5.0.","CVE-2024-39354, CVE-2024-39605, CVE-2024-47131",8.4,High,CWE-121,Energy,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3063,11/7/2024,11/7/2024,2024,ICSA-24-312-03,Bosch Rexroth IndraDrive,Bosch Rexroth,IndraDrive,"Bosch Rexroth reports that the following versions of IndraDrive, servo drive system, are affected: Bosch Rexroth AG IndraDrive FWA-INDRV* - MP*: 17VRS < 20V36.",CVE-2024-48989,8.7,High,CWE-400,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3062,10/31/2024,10/31/2024,2024,ICSA-24-305-01,Rockwell Automation FactoryTalk ThinManager,Rockwell Automation,FactoryTalk ThinManager,The following Rockwell Automation FactoryTalk product versions are affected: ThinManager: Versions 11.2.0 to 11.2.9 ThinManager: Versions 12.0.0 to 12.0.7 ThinManager: Versions 12.1.0 to 12.1.8 ThinManager: Versions 13.0.0 to 13.0.5 ThinManager: Versions 13.1.0 to 13.1.3 ThinManager: Versions 13.2.0 to 13.2.2 ThinManager: Version 14.0.0.,"CVE-2024-10386, CVE-2024-10387",9.3,Critical,"CWE-306, CWE-125",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3061,10/29/2024,10/29/2024,2024,ICSA-24-303-01,Siemens InterMesh Subscriber Devices,Siemens,InterMesh,"The following versions of Siemens InterMesh Subscriber Devices, a wireless alarm reporting system, are affected: InterMesh 7177 Hybrid 2.0 Subscriber: All versions prior to V8.2.12 InterMesh 7707 Fire Subscriber: All versions prior to V7.2.12.","CVE-2024-47901, CVE-2024-47902, CVE-2024-47903, CVE-2024-47904",10.0,Critical,"CWE-78, CWE-306, CWE-250, CWE-266",Critical Manufacturing; Commercial Facilities; Government Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3060,10/29/2024,10/29/2024,2024,ICSA-24-303-02,Solar-Log Base 15,Solar-Log,Base 15,The following versions of Solar-Log Base 15 are affected: Base 15: Firmware 6.0.1 Build 161.,CVE-2023-46344,5.1,Medium,CWE-79,Energy,Multiple,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3059,10/29/2024,10/29/2024,2024,ICSA-24-303-03,Delta Electronics InfraSuite Device Master,Delta Electronics,InfraSuite Device Master,"The following versions of InfraSuite Device Master, a real-time device monitoring software, are affected: InfraSuite Device Master: Versions 1.0.12 and prior.",CVE-2024-10456,9.3,Critical,CWE-502,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3058,10/24/2024,10/24/2024,2024,ICSA-24-298-01,VIMESA VHF/FM Transmitter Blue Plus,VIMESA,VHF/FM Transmitter Blue Plus,"The following version of VIMESA VHF/FM Transmitter Blue Plus, a VHF/FM Transmitter, is affected: VHF/FM Transmitter Blue Plus: Version v9.7.1.",CVE-2024-9692,6.9,Medium,CWE-284,Communications,Worldwide,Spain,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3057,10/24/2024,10/24/2024,2024,ICSA-24-298-02,iniNet Solutions SpiderControl SCADA PC HMI Editor,iniNet Solutions GmbH,SpiderControl SCADA PC HMI Editor,"The following versions of iniNet Solutions SpiderControl SCADA PC HMI Editor, a software management platform, are affected: SpiderControl SCADA PC HMI Editor: Version 8.10.00.00.",CVE-2024-10313,8.6,High,CWE-22,Critical Manufacturing,Europe,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3056,10/24/2024,10/24/2024,2024,ICSA-24-298-03,Deep Sea Electronics DSE855,Deep Sea Electronics,DSE855,"The following versions of Deep Sea Electronics DSE855, an ethernet communications device, are affected: DSE855: Version 1.0.26.",CVE-2024-5947,7.1,High,CWE-306,Energy,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3055,10/22/2024,2/24/2026,2024,ICSA-24-296-01,Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric Products (Update C),Mitsubishi Electric Iconics Digital Solutions,Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric Products (Update C),"Mitsubishi Electric Iconics Digital Solutions GENESIS64: <=10.97.3, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: <=10.97.3, Mitsubishi Electric Iconics Digital Solutions Hyper Historian: <=10.97.3, Mitsubishi Electric Iconics Digital Solutions AnalytiX: <=10.97.3, Mitsubishi Electric Iconics Digital Solutions MobileHMI: <=10.97.3, Mitsubishi Electric Iconics Digital Solutions GENESIS32: <=9.70.300.23, Mitsubishi Electric GENESIS64: <=10.97.3, Mitsubishi Electric ICONICS Suite: <=10.97.3, Mitsubishi Electric Hyper Historian: <=10.97.3, Mitsubishi Electric AnalytiX: <=10.97.3, Mitsubishi Electric MobileHMI: <=10.97.3, Mitsubishi Electric GENESIS32: <=9.70.300.23, Mitsubishi Electric MC Works64: vers:all/*",CVE-2024-7587,7.8,High,CWE-276,Critical Manufacturing,Worldwide,"United States, Japan",Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3054,10/17/2024,11/14/2024,2024,ICSA-24-291-01,Elvaco M-Bus Metering Gateway CMe3100 (Update A),Elvaco,M-Bus Metering Gateway CMe3100,"The following versions of Elvaco CMe3100, a metering gateway are affected: CMe3100: Version 1.12. 1.","CVE-2024-49396, CVE-2024-49397, CVE-2024-49398, CVE-2024-49399",9.2,Critical,"CWE-522, CWE-79, CWE-434, CWE-306",Critical Manufacturing; Energy,Multiple,Sweden,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3053,10/17/2024,10/17/2024,2024,ICSA-24-291-02,LCDS LAquis SCADA,LCDS - Leao Consultoria e Desenvolvimento de Sistemas Ltda ME,LAquis SCADA,"The following versions of LAquis SCADA, an HMI program, are affected: LAquis SCADA: Version 4.7.1.511.",CVE-2024-9414,7.0,High,CWE-79,Chemical; Commercial Facilities; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater Systems,South America,Brazil,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3052,10/17/2024,7/2/2026,2024,ICSA-24-291-03,Mitsubishi Electric CNC Series (Update D),Mitsubishi Electric,Mitsubishi Electric CNC Series (Update D),Mitsubishi Electric CNC M800V/M80V Series M800VW (BND-2051W000-**) <=B1 | Mitsubishi Electric CNC M800V/M80V Series M800VS (BND-2052W000-**) <=B1 | Mitsubishi Electric CNC M800V/M80V Series M80V (BND-2053W000-**) <=B1 | Mitsubishi Electric CNC M800V/M80V Series M80VW (BND-2054W000-**) <=B1 | Mitsubishi Electric CNC M800/M80/E80 Series M800W (BND-2005W000-**) <=FH | Mitsubishi Electric CNC M800/M80/E80 Series M800S (BND-2006W000-**) <=FH | Mitsubishi Electric CNC M800/M80/E80 Series M80 (BND-2007W000-**) <=FH | Mitsubishi Electric CNC M800/M80/E80 Series M80W (BND-2008W000-**) <=FH | Mitsubishi Electric CNC M800/M80/E80 Series E80 (BND-2009W000-**) <=FH | Mitsubishi Electric CNC C80 Series C80 (BND-2036W000-**) <=BJ | Mitsubishi Electric CNC M700V/M70V/E70 Series M750VW (BND-1015W002-**) <=LG | Mitsubishi Electric CNC M700V/M70V/E70 Series M730VW (BND-1015W000-**) <=LG | Mitsubishi Electric CNC M700V/M70V/E70 Series M720VW (BND-1015W000-**) <=LG | Mitsubishi Electric CNC M700V/M70V/E70 Series M750VS (BND-1012W002-**) <=LG | Mitsubishi Electric CNC M700V/M70V/E70 Series M730VS (BND-1012W000-**) <=LG | Mitsubishi Electric CNC M700V/M70V/E70 Series M720VS (BND-1012W000-**) <=LG | Mitsubishi Electric CNC M700V/M70V/E70 Series M70V (BND-1018W000-**) <=LG | Mitsubishi Electric CNC M700V/M70V/E70 Series E70 (BND-1022W000-**) <=LG,CVE-2024-7316,5.9,Medium,CWE-1284,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3051,10/17/2024,10/17/2024,2024,ICSA-24-291-04,HMS Networks EWON FLEXY 202,HMS Networks,EWON FLEXY 202,"The following versions of EWON FLEXY 202, an industrial modular gateway, are affected: EWON FLEXY 202: Firmware Version 14.2s0.",CVE-2024-7755,7.1,High,CWE-522,Water and Wastewater Systems; Energy; Food and Agriculture,Worldwide,Sweden,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3050,10/17/2024,10/17/2024,2024,ICSA-24-291-05,Kieback&Peter DDC4000 Series,Kieback&Peter,DDC4000 Series,The following Kieback&Peter DDC4000 series products are affected: DDC4002 : Versions 1.12.14 and prior DDC4100 : Versions 1.7.4 and prior DDC4200 : Versions 1.12.14 and prior DDC4200-L : Versions 1.12.14 and prior DDC4400 : Versions 1.12.14 and prior DDC4002e : Versions 1.17.6 and prior DDC4200e : Versions 1.17.6 and prior DDC4400e : Versions 1.17.6 and prior DDC4020e : Versions 1.17.6 and prior DDC4040e : Versions 1.17.6 and prior.,"CVE-2024-41717, CVE-2024-43698, CVE-2024-43812",9.3,Critical,"CWE-22, CWE-522, CWE-1391",Critical Manufacturing; Commercial Facilities; Communications; Financial Services; Food and Agriculture; Government Facilities; Healthcare and Public Health; Information Technology,"Europe, the Middle East and Asia.",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3049,10/15/2024,10/15/2024,2024,ICSA-24-289-01,Siemens Siveillance Video Camera,Siemens,Siveillance Video Camera,The following versions of Siemens Siveillance Video Camera are affected: Siveillance Video Camera: All versions prior to V13.2.,CVE-2024-3506,7.3,High,CWE-120,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3048,10/15/2024,10/15/2024,2024,ICSA-24-289-02,Schneider Electric Data Center Expert,Schneider Electric,Data Center Expert,"Schneider Electric reports that the following versions of Data Center Expert, a monitoring software, are affected: Data Center Expert: Versions 8.1.1.3 and prior.","CVE-2024-8531, CVE-2024-8530",8.6,High,"CWE-347, CWE-306",Commercial Facilities; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater Systems,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3047,10/10/2024,10/10/2024,2024,ICSA-24-284-01,Siemens SIMATIC S7-1500 and S7-1200 CPUs,Siemens,SIMATIC S7-1500 and S7-1200 CPUs,Siemens reports that the following SIMATIC S7-1500 and S7-1200 CPUs are affected: SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0): versions prior to V3.1.4 SIMATIC Drive Controller CPU 1507D TF (6ES7615-7DF10-0AB0): versions prior to V3.1.4 SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): all versions SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0): all versions SIMATIC S7-1200 CPU 1211C DC/DC/DC (6ES7211-1AE40-0XB0): all versions SIMATIC S7-1200 CPU 1211C DC/DC/Rly (6ES7211-1HE40-0XB0): all versions SIMATIC S7-1200 CPU 1212C AC/DC/Rly (6ES7212-1BE40-0XB0): all versions SIMATIC S7-1200 CPU 1212C DC/DC/DC (6ES7212-1AE40-0XB0): all versions SIMATIC S7-1200 CPU 1212C DC/DC/Rly (6ES7212-1HE40-0XB0): all versions SIMATIC S7-1200 CPU 1212FC DC/DC/DC (6ES7212-1AF40-0XB0): all versions SIMATIC S7-1200 CPU 1212FC DC/DC/Rly (6ES7212-1HF40-0XB0): all versions SIMATIC S7-1200 CPU 1214C AC/DC/Rly (6ES7214-1BG40-0XB0): all versions SIMATIC S7-1200 CPU 1214C DC/DC/DC (6ES7214-1AG40-0XB0): all versions SIMATIC S7-1200 CPU 1214C DC/DC/Rly (6ES7214-1HG40-0XB0): all versions SIMATIC S7-1200 CPU 1214FC DC/DC/DC (6ES7214-1AF40-0XB0): all versions SIMATIC S7-1200 CPU 1214FC DC/DC/Rly (6ES7214-1HF40-0XB0): all versions SIMATIC S7-1200 CPU 1215C AC/DC/Rly (6ES7215-1BG40-0XB0): all versions SIMATIC S7-1200 CPU 1215C DC/DC/DC (6ES7215-1AG40-0XB0): all versions SIMATIC S7-1200 CPU 1215C DC/DC/Rly (6ES7215-1HG40-0XB0): all versions SIMATIC S7-1200 CPU 1215FC DC/DC/DC (6ES7215-1AF40-0XB0): all versions SIMATIC S7-1200 CPU 1215FC DC/DC/Rly (6ES7215-1HF40-0XB0): all versions SIMATIC S7-1200 CPU 1217C DC/DC/DC (6ES7217-1AG40-0XB0): all versions SIMATIC S7-1500 CPU 1510SP F-1 PN (6ES7510-1SJ01-0AB0): all versions SIMATIC S7-1500 CPU 1510SP F-1 PN (6ES7510-1SK03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1510SP-1 PN (6ES7510-1DJ01-0AB0): all versions SIMATIC S7-1500 CPU 1510SP-1 PN (6ES7510-1DK03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK01-0AB0): all versions SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK02-0AB0): all versions SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AL03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK00-0AB0): all versions SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK01-0AB0): all versions SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CL03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK01-0AB0): all versions SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK02-0AB0): all versions SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FL03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1511T-1 PN (6ES7511-1TK01-0AB0): all versions SIMATIC S7-1500 CPU 1511T-1 PN (6ES7511-1TL03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1511TF-1 PN (6ES7511-1UK01-0AB0): all versions SIMATIC S7-1500 CPU 1511TF-1 PN (6ES7511-1UL03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK00-0AB0): all versions SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK01-0AB0): all versions SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CM03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1512SP F-1 PN (6ES7512-1SK01-0AB0): all versions SIMATIC S7-1500 CPU 1512SP F-1 PN (6ES7512-1SM03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1512SP-1 PN (6ES7512-1DK01-0AB0): all versions SIMATIC S7-1500 CPU 1512SP-1 PN (6ES7512-1DM03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL01-0AB0): all versions SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL02-0AB0): all versions SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AM03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL01-0AB0): all versions SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL02-0AB0): all versions SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FM03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1513pro F-2 PN (6ES7513-2GM03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1513pro-2 PN (6ES7513-2PM03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1514SP F-2 PN (6ES7514-2SN03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1514SP-2 PN (6ES7514-2DN03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1514SPT F-2 PN (6ES7514-2WN03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1514SPT-2 PN (6ES7514-2VN03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM01-0AB0): all versions SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM02-0AB0): all versions SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AN03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM01-0AB0): all versions SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM02-0AB0): all versions SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FN03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1515T-2 PN (6ES7515-2TM01-0AB0): all versions SIMATIC S7-1500 CPU 1515T-2 PN (6ES7515-2TN03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1515TF-2 PN (6ES7515-2UM01-0AB0): all versions SIMATIC S7-1500 CPU 1515TF-2 PN (6ES7515-2UN03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN01-0AB0): all versions SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN02-0AB0): all versions SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AP03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN01-0AB0): all versions SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN02-0AB0): all versions SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FP03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1516pro F-2 PN (6ES7516-2GP03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1516pro-2 PN (6ES7516-2PP03-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1516T-3 PN/DP (6ES7516-3TN00-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1516TF-3 PN/DP (6ES7516-3UN00-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1517-3 PN/DP (6ES7517-3AP00-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1517F-3 PN/DP (6ES7517-3FP00-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1517F-3 PN/DP (6ES7517-3FP01-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1517T-3 PN/DP (6ES7517-3TP00-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1517TF-3 PN/DP (6ES7517-3UP00-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1518-4 PN/DP (6ES7518-4AP00-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0): all versions SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0): all versions SIMATIC S7-1500 CPU 1518F-4 PN/DP (6ES7518-4FP00-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0): all versions SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0): all versions SIMATIC S7-1500 CPU 1518T-4 PN/DP (6ES7518-4TP00-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU 1518TF-4 PN/DP (6ES7518-4UP00-0AB0): versions prior to V3.1.4 SIMATIC S7-1500 CPU S7-1518-4 PN/DP ODK (6ES7518-4AP00-3AB0): all versions SIMATIC S7-1500 CPU S7-1518F-4 PN/DP ODK (6ES7518-4FP00-3AB0): all versions SIMATIC S7-1500 ET 200pro: CPU 1513PRO F-2 PN (6ES7513-2GL00-0AB0): all versions SIMATIC S7-1500 ET 200pro: CPU 1513PRO-2 PN (6ES7513-2PL00-0AB0): all versions SIMATIC S7-1500 ET 200pro: CPU 1516PRO F-2 PN (6ES7516-2GN00-0AB0): all versions SIMATIC S7-1500 ET 200pro: CPU 1516PRO-2 PN (6ES7516-2PN00-0AB0): all versions SIMATIC S7-1500 Software Controller CPU 1507S F V2: all versions SIMATIC S7-1500 Software Controller CPU 1507S F V3: all versions SIMATIC S7-1500 Software Controller CPU 1507S V2: all versions SIMATIC S7-1500 Software Controller CPU 1507S V3: all versions SIMATIC S7-1500 Software Controller CPU 1508S F V2: all versions SIMATIC S7-1500 Software Controller CPU 1508S F V3: all versions SIMATIC S7-1500 Software Controller CPU 1508S T V3: all versions SIMATIC S7-1500 Software Controller CPU 1508S TF V3: all versions SIMATIC S7-1500 Software Controller CPU 1508S V2: all versions SIMATIC S7-1500 Software Controller CPU 1508S V3: all versions SIMATIC S7-1500 Software Controller Linux V2: all versions SIMATIC S7-1500 Software Controller Linux V3: all versions SIMATIC S7-PLCSIM Advanced: all versions SIPLUS ET 200SP CPU 1510SP F-1 PN (6AG1510-1SJ01-2AB0): all versions SIPLUS ET 200SP CPU 1510SP F-1 PN RAIL (6AG2510-1SJ01-1AB0): all versions SIPLUS ET 200SP CPU 1510SP-1 PN (6AG1510-1DJ01-2AB0): all versions SIPLUS ET 200SP CPU 1510SP-1 PN (6AG1510-1DJ01-7AB0): all versions SIPLUS ET 200SP CPU 1510SP-1 PN RAIL (6AG2510-1DJ01-1AB0): all versions SIPLUS ET 200SP CPU 1510SP-1 PN RAIL (6AG2510-1DJ01-4AB0): all versions SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK01-2AB0): all versions SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK01-7AB0): all versions SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL (6AG2512-1SK01-1AB0): all versions SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL (6AG2512-1SK01-4AB0): all versions SIPLUS ET 200SP CPU 1512SP-1 PN (6AG1512-1DK01-2AB0): all versions SIPLUS ET 200SP CPU 1512SP-1 PN (6AG1512-1DK01-7AB0): all versions SIPLUS ET 200SP CPU 1512SP-1 PN RAIL (6AG2512-1DK01-1AB0): all versions SIPLUS ET 200SP CPU 1512SP-1 PN RAIL (6AG2512-1DK01-4AB0): all versions SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK01-2AB0): all versions SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK01-7AB0): all versions SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK02-2AB0): all versions SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK02-7AB0): all versions SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL (6AG2511-1AK01-1AB0): all versions SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL (6AG2511-1AK02-1AB0): all versions SIPLUS S7-1500 CPU 1511-1 PN TX RAIL (6AG2511-1AK01-4AB0): all versions SIPLUS S7-1500 CPU 1511-1 PN TX RAIL (6AG2511-1AK02-4AB0): all versions SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK01-2AB0): all versions SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK02-2AB0): all versions SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL01-2AB0): all versions SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL01-7AB0): all versions SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL02-2AB0): all versions SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL02-7AB0): all versions SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL01-2AB0): all versions SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL02-2AB0): all versions SIPLUS S7-1500 CPU 1515F-2 PN (6AG1515-2FM01-2AB0): all versions SIPLUS S7-1500 CPU 1515F-2 PN (6AG1515-2FM02-2AB0): all versions SIPLUS S7-1500 CPU 1515F-2 PN RAIL (6AG2515-2FM02-4AB0): all versions SIPLUS S7-1500 CPU 1515F-2 PN T2 RAIL (6AG2515-2FM01-2AB0): all versions SIPLUS S7-1500 CPU 1515R-2 PN TX RAIL (6AG2515-2RM00-4AB0): all versions SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN01-2AB0): all versions SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN01-7AB0): all versions SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN02-2AB0): all versions SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN02-7AB0): all versions SIPLUS S7-1500 CPU 1516-3 PN/DP RAIL (6AG2516-3AN02-4AB0): all versions SIPLUS S7-1500 CPU 1516-3 PN/DP TX RAIL (6AG2516-3AN01-4AB0): all versions SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN01-2AB0): all versions SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN02-2AB0): all versions SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL (6AG2516-3FN02-2AB0): all versions SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL (6AG2516-3FN02-4AB0): all versions SIPLUS S7-1500 CPU 1518-4 PN/DP (6AG1518-4AP00-4AB0): versions prior to V3.1.4 SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0): all versions SIPLUS S7-1500 CPU 1518F-4 PN/DP (6AG1518-4FP00-4AB0): versions prior to V3.1.4.,CVE-2024-46886,5.1,Medium,CWE-601,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3046,10/10/2024,10/10/2024,2024,ICSA-24-284-02,Siemens Simcenter Nastran,Siemens,Simcenter Nastran,Siemens reports that the following versions of Simcenter Nastran finite element method (FEM) solver are affected: Simcenter Nastran 2306: All versions Simcenter Nastran 2312: All versions Simcenter Nastran 2406: Versions prior to V2406.5000.,"CVE-2024-41981, CVE-2024-47046",7.3,High,"CWE-122, CWE-119",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3045,10/10/2024,10/10/2024,2024,ICSA-24-284-03,Siemens Teamcenter Visualization and JT2Go,Siemens,Teamcenter Visualization and JT2Go,The following versions of Siemens Teamcenter Visualization and JT2Go are affected: JT2Go: All versions prior to V2406.0003 Teamcenter Visualization V14.2: All versions prior to V14.2.0.13 Teamcenter Visualization V14.3: All versions prior to V14.3.0.11 Teamcenter Visualization V2312: All versions prior to V2312.0008 Teamcenter Visualization V2406: All versions prior to V2406.0003.,"CVE-2024-37996, CVE-2024-37997",7.3,High,"CWE-476, CWE-121",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3044,10/10/2024,10/10/2024,2024,ICSA-24-284-04,Siemens SENTRON PAC3200 Devices,Siemens,SENTRON 7KM PAC3200,The following versions of Siemens SENTRON PAC3200 devices are affected: SENTRON 7KM PAC3200: All versions.,CVE-2024-41798,9.3,Critical,CWE-287,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3043,10/10/2024,10/10/2024,2024,ICSA-24-284-05,Siemens Questa and ModelSim,Siemens,Questa and ModelSim,The following versions of Siemens Questa and ModelSim are affected: ModelSim: All versions prior to V2024.3 Questa: All versions prior to V2024.3.,"CVE-2024-47194, CVE-2024-47195, CVE-2024-47196",5.4,Medium,CWE-427,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3042,10/10/2024,10/10/2024,2024,ICSA-24-284-06,Siemens SINEC Security Monitor,Siemens,SINEC Security Monitor,"The following versions of Siemens SINEC Security Monitor, a modular cyber security software, are affected: SINEC Security Monitor: All versions prior to V4.9.0.","CVE-2024-47553, CVE-2024-47562, CVE-2024-47563, CVE-2024-47565",9.4,Critical,"CWE-88, CWE-77, CWE-22, CWE-183",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3041,10/10/2024,10/10/2024,2024,ICSA-24-284-07,Siemens JT2Go,Siemens,JT2Go,"The following versions of Siemens JT2Go, a 3D viewing tool, are affected: JT2Go: All versions prior to V2406.0003.",CVE-2024-41902,7.3,High,CWE-121,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3040,10/10/2024,10/10/2024,2024,ICSA-24-284-08,Siemens HiMed Cockpit,Siemens,HiMed Cockpit,"The following versions of Siemens HiMed Cockpit, a multimedia terminal, are affected: HiMed Cockpit 12 pro (J31032-K2017-H259): Versions V11.5.1 up to but not including V11.6.2 HiMed Cockpit 14 pro+ (J31032-K2017-H435): Versions V11.5.1 up to but not including V11.6.2 HiMed Cockpit 18 pro (J31032-K2017-H260): Versions V11.5.1 up to but not including V11.6.2 HiMed Cockpit 18 pro+ (J31032-K2017-H436): Versions V11.5.1 up to but not including V11.6.2.",CVE-2023-52952,9.3,Critical,CWE-424,Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3039,10/10/2024,10/10/2024,2024,ICSA-24-284-09,Siemens PSS SINCAL,Siemens,PSS SINCAL,The following Siemens products are affected if WibuKey dongles are used: PSS SINCAL: All versions.,"CVE-2024-45181, CVE-2024-45182",9.3,Critical,CWE-119,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3038,10/10/2024,10/10/2024,2024,ICSA-24-284-10,Siemens SIMATIC S7-1500 CPUs,Siemens,SIMATIC S7-1500 CPUs,The following Siemens products are affected: SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0): Versions prior to V3.1.4 SIMATIC Drive Controller CPU 1507D TF (6ES7615-7DF10-0AB0): Versions prior to V3.1.4 SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions SIMATIC S7-1500 CPU 1510SP F-1 PN (6ES7510-1SJ01-0AB0): All versions SIMATIC S7-1500 CPU 1510SP F-1 PN (6ES7510-1SK03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1510SP-1 PN (6ES7510-1DJ01-0AB0): All versions SIMATIC S7-1500 CPU 1510SP-1 PN (6ES7510-1DK03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK01-0AB0): All versions SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK02-0AB0): All versions SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AL03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK00-0AB0): All versions SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK01-0AB0): All versions SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CL03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK01-0AB0): All versions SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK02-0AB0): All versions SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FL03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1511T-1 PN (6ES7511-1TK01-0AB0): All versions SIMATIC S7-1500 CPU 1511T-1 PN (6ES7511-1TL03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1511TF-1 PN (6ES7511-1UK01-0AB0): All versions SIMATIC S7-1500 CPU 1511TF-1 PN (6ES7511-1UL03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK00-0AB0): All versions SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK01-0AB0): All versions SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CM03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1512SP F-1 PN (6ES7512-1SK01-0AB0): All versions SIMATIC S7-1500 CPU 1512SP F-1 PN (6ES7512-1SM03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1512SP-1 PN (6ES7512-1DK01-0AB0): All versions SIMATIC S7-1500 CPU 1512SP-1 PN (6ES7512-1DM03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL01-0AB0): All versions SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL02-0AB0): All versions SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AM03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL01-0AB0): All versions SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL02-0AB0): All versions SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FM03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1513pro F-2 PN (6ES7513-2GM03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1513pro-2 PN (6ES7513-2PM03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1514SP F-2 PN (6ES7514-2SN03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1514SP-2 PN (6ES7514-2DN03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1514SPT F-2 PN (6ES7514-2WN03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1514SPT-2 PN (6ES7514-2VN03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM01-0AB0): All versions SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM02-0AB0): All versions SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AN03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM01-0AB0): All versions SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM02-0AB0): All versions SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FN03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1515T-2 PN (6ES7515-2TM01-0AB0): All versions SIMATIC S7-1500 CPU 1515T-2 PN (6ES7515-2TN03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1515TF-2 PN (6ES7515-2UM01-0AB0): All versions SIMATIC S7-1500 CPU 1515TF-2 PN (6ES7515-2UN03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN01-0AB0): All versions SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN02-0AB0): All versions SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AP03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN01-0AB0): All versions SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN02-0AB0): All versions SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FP03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1516pro F-2 PN (6ES7516-2GP03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1516pro-2 PN (6ES7516-2PP03-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1516T-3 PN/DP (6ES7516-3TN00-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1516TF-3 PN/DP (6ES7516-3UN00-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1517-3 PN/DP (6ES7517-3AP00-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1517F-3 PN/DP (6ES7517-3FP00-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1517F-3 PN/DP (6ES7517-3FP01-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1517T-3 PN/DP (6ES7517-3TP00-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1517TF-3 PN/DP (6ES7517-3UP00-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1518-4 PN/DP (6ES7518-4AP00-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0): All versions SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0): All versions SIMATIC S7-1500 CPU 1518F-4 PN/DP (6ES7518-4FP00-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0): All versions SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0): All versions SIMATIC S7-1500 CPU 1518T-4 PN/DP (6ES7518-4TP00-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU 1518TF-4 PN/DP (6ES7518-4UP00-0AB0): Versions prior to V3.1.4 SIMATIC S7-1500 CPU S7-1518-4 PN/DP ODK (6ES7518-4AP00-3AB0): All versions SIMATIC S7-1500 CPU S7-1518F-4 PN/DP ODK (6ES7518-4FP00-3AB0): All versions SIMATIC S7-1500 ET 200pro: CPU 1513PRO F-2 PN (6ES7513-2GL00-0AB0): All versions SIMATIC S7-1500 ET 200pro: CPU 1513PRO-2 PN (6ES7513-2PL00-0AB0): All versions SIMATIC S7-1500 ET 200pro: CPU 1516PRO F-2 PN (6ES7516-2GN00-0AB0): All versions SIMATIC S7-1500 ET 200pro: CPU 1516PRO-2 PN (6ES7516-2PN00-0AB0): All versions SIMATIC S7-1500 Software Controller V2: All versions SIMATIC S7-1500 Software Controller V3: All versions SIMATIC S7-PLCSIM Advanced: All versions SIPLUS ET 200SP CPU 1510SP F-1 PN (6AG1510-1SJ01-2AB0): All versions SIPLUS ET 200SP CPU 1510SP F-1 PN RAIL (6AG2510-1SJ01-1AB0): All versions SIPLUS ET 200SP CPU 1510SP-1 PN (6AG1510-1DJ01-2AB0): All versions SIPLUS ET 200SP CPU 1510SP-1 PN (6AG1510-1DJ01-7AB0): All versions SIPLUS ET 200SP CPU 1510SP-1 PN RAIL (6AG2510-1DJ01-1AB0): All versions SIPLUS ET 200SP CPU 1510SP-1 PN RAIL (6AG2510-1DJ01-4AB0): All versions SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK01-2AB0): All versions SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK01-7AB0): All versions SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL (6AG2512-1SK01-1AB0): All versions SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL (6AG2512-1SK01-4AB0): All versions SIPLUS ET 200SP CPU 1512SP-1 PN (6AG1512-1DK01-2AB0): All versions SIPLUS ET 200SP CPU 1512SP-1 PN (6AG1512-1DK01-7AB0): All versions SIPLUS ET 200SP CPU 1512SP-1 PN RAIL (6AG2512-1DK01-1AB0): All versions SIPLUS ET 200SP CPU 1512SP-1 PN RAIL (6AG2512-1DK01-4AB0): All versions SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK01-2AB0): All versions SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK01-7AB0): All versions SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK02-2AB0): All versions SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK02-7AB0): All versions SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL (6AG2511-1AK01-1AB0): All versions SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL (6AG2511-1AK02-1AB0): All versions SIPLUS S7-1500 CPU 1511-1 PN TX RAIL (6AG2511-1AK01-4AB0): All versions SIPLUS S7-1500 CPU 1511-1 PN TX RAIL (6AG2511-1AK02-4AB0): All versions SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK01-2AB0): All versions SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK02-2AB0): All versions SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL01-2AB0): All versions SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL01-7AB0): All versions SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL02-2AB0): All versions SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL02-7AB0): All versions SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL01-2AB0): All versions SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL02-2AB0): All versions SIPLUS S7-1500 CPU 1515F-2 PN (6AG1515-2FM01-2AB0): All versions SIPLUS S7-1500 CPU 1515F-2 PN (6AG1515-2FM02-2AB0): All versions SIPLUS S7-1500 CPU 1515F-2 PN RAIL (6AG2515-2FM02-4AB0): All versions SIPLUS S7-1500 CPU 1515F-2 PN T2 RAIL (6AG2515-2FM01-2AB0): All versions SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN01-2AB0): All versions SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN01-7AB0): All versions SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN02-2AB0): All versions SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN02-7AB0): All versions SIPLUS S7-1500 CPU 1516-3 PN/DP RAIL (6AG2516-3AN02-4AB0): All versions SIPLUS S7-1500 CPU 1516-3 PN/DP TX RAIL (6AG2516-3AN01-4AB0): All versions SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN01-2AB0): All versions SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN02-2AB0): All versions SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL (6AG2516-3FN02-2AB0): All versions SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL (6AG2516-3FN02-4AB0): All versions SIPLUS S7-1500 CPU 1518-4 PN/DP (6AG1518-4AP00-4AB0): Versions prior to V3.1.4 SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0): All versions SIPLUS S7-1500 CPU 1518F-4 PN/DP (6AG1518-4FP00-4AB0): Versions prior to V3.1.4.,CVE-2024-46887,6.9,Medium,CWE-288,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3037,10/10/2024,10/10/2024,2024,ICSA-24-284-11,Siemens RUGGEDCOM APE1808,Siemens,RUGGEDCOM APE1808,The following Siemens products with Nozomi Guardian / CMC before 24.3.1 are affected: RUGGEDCOM APE1808LNX (6GK6015-0AL20-0GH0): All versions RUGGEDCOM APE1808LNX CC (6GK6015-0AL20-0GH1): All versions.,CVE-2024-4465,6.0,Medium,CWE-863,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3036,10/10/2024,10/10/2024,2024,ICSA-24-284-12,Siemens Sentron Powercenter 1000,Siemens,Sentron Powercenter 1000,The following Siemens products are affected: SENTRON Powercenter 1000 (7KN1110-0MC00): All versions.,CVE-2023-6874,9.2,Critical,CWE-754,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3035,10/10/2024,10/10/2024,2024,ICSA-24-284-13,Siemens Tecnomatix Plant Simulation,Siemens,Tecnomatix Plant Simulation,Siemens reports that the following versions of Tecnomatix Plant Simulation are affected: Tecnomatix Plant Simulation V2302: Versions prior to V2302.0016 Tecnomatix Plant Simulation V2404: Versions prior to V2404.0005.,"CVE-2024-45463, CVE-2024-45464, CVE-2024-45465, CVE-2024-45466, CVE-2024-45467, CVE-2024-45468, CVE-2024-45469, CVE-2024-45470, CVE-2024-45471, CVE-2024-45472, CVE-2024-45473, CVE-2024-45474, CVE-2024-45475, CVE-2024-45476",7.3,High,"CWE-125, CWE-119, CWE-787, CWE-476",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3034,10/10/2024,10/10/2024,2024,ICSA-24-284-14,Schneider Electric Zelio Soft 2,Schneider Electric,Zelio Soft 2,The following versions of Schneider Electric Zelio Soft 2 are affected: Zelio Soft 2: Versions prior to 5.4.2.2.,"CVE-2024-8422, CVE-2024-8518",7.8,High,"CWE-416, CWE-20",Energy; Critical Manufacturing,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3033,10/10/2024,10/10/2024,2024,ICSA-24-284-15,Rockwell Automation DataMosaix Private Cloud,Rockwell Automation,DataMosaix Private Cloud,Rockwell Automation reports that the following versions of DataMosaix Private Cloud are affected: DataMosaix Private Cloud: Versions 7.07 and prior.,"CVE-2024-7952, CVE-2024-7953, CVE-2024-7956",8.7,High,"CWE-200, CWE-862, CWE-863",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3032,10/10/2024,10/10/2024,2024,ICSA-24-284-16,Rockwell Automation DataMosaix Private Cloud,Rockwell Automation,DataMosaix Private Cloud,Rockwell Automation reports that the following versions of DataMosaix Private Cloud are affected: DataMosaix Private Cloud: Versions 7.07 and prior.,"CVE-2019-14855, CVE-2019-17543, CVE-2019-18276, CVE-2019-19244, CVE-2019-9893, CVE-2019-9923",9.3,Critical,"CWE-326, CWE-787, CWE-273, CWE-1357, CWE-476",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3031,10/10/2024,10/10/2024,2024,ICSA-24-284-17,Rockwell Automation Verve Asset Manager,Rockwell Automation,Verve Asset Manager,Rockwell Automation reports that the following versions of Verve Asset Manager are affected: Verve Asset Manager: Versions 1.38 and prior.,CVE-2024-9412,8.4,High,CWE-842,Chemical; Critical Manufacturing; Water and Wastewater Systems; Healthcare and Public Health; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3030,10/10/2024,10/10/2024,2024,ICSA-24-284-18,Rockwell Automation Logix Controllers,Rockwell Automation,"Compact GuardLogix, CompactLogix, ControlLogix, GuardLogix, 1756-EN4TR","The following versions of Rockwell Automation Logix Controllers, are affected: CompactLogix 5380: All versions later than v33.011 up to v33.015 Compact GuardLogix 5380: All versions later than v33.011 up to v33.015 CompactLogix 5480: All versions later than v33.011 up to v33.015 ControlLogix 5580: All versions later than v33.011 up to v33.015 GuardLogix 5580: All versions later than v33.011 up to v33.015 1756-EN4TR: Version v3.002.",CVE-2024-8626,8.7,High,CWE-400,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3029,10/10/2024,10/10/2024,2024,ICSA-24-284-19,Rockwell Automation PowerFlex 6000T,Rockwell Automation,PowerFlex 6000T,"The following versions of Rockwell Automation PowerFlex 6000T are affected: PowerFlex 6000T: Versions 8.001, 8.002, 9.001.",CVE-2024-9124,8.2,High,CWE-754,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3028,10/10/2024,10/10/2024,2024,ICSA-24-284-20,Rockwell Automation ControlLogix,Rockwell Automation,ControlLogix,"The following Rockwell Automation products are affected: ControlLogix 5580: Versions prior to V33.017, V34.014, V35.013, V36.011 ControlLogix 5580 Process: Versions prior to V33.017, V34.014, V35.013, V36.011 GuardLogix 5580: Versions prior to V33.017, V34.014, V35.013, V36.011 CompactLogix 5380: Versions prior to V33.017, V34.014, V35.013, V36.011 Compact GuardLogix 5380 SIL 2: Versions prior to V33.017, V34.014, V35.013, V36.011 Compact GuardLogix 5380 SIL 3: Versions prior to V33.017, V34.014, V35.013, V36.011 CompactLogix 5480: Versions prior to V33.017, V34.014, V35.013, V36.011 FactoryTalk Logix Echo: Versions prior to V33.017, V34.014, V35.013, V36.011.",CVE-2024-6207,8.7,High,CWE-20,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3027,10/10/2024,10/10/2024,2024,ICSA-24-284-21,Delta Electronics CNCSoft-G2,Delta Electronics,CNCSoft-G2,"The following versions of Delta Electronics CNCSoft-G2, a Human-Machine Interface (HMI) software, are affected: CNCSoft-G2: Version 2.1.0.10.","CVE-2024-47962, CVE-2024-47963, CVE-2024-47964, CVE-2024-47965, CVE-2024-47966",8.4,High,"CWE-121, CWE-787, CWE-122, CWE-125, CWE-457",Energy; Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3026,10/3/2024,10/3/2024,2024,ICSA-24-277-01,TEM Opera Plus FM Family Transmitter,TEM,Opera Plus FM Family Transmitter,"The following versions of TEM Opera Plus FM Family Transmitter, a FM Transmitter, are affected: Opera Plus FM Family Transmitter: Version 35.45.","CVE-2024-41987, CVE-2024-41988",9.3,Critical,"CWE-306, CWE-352",Communications,Worldwide,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3025,10/3/2024,10/3/2024,2024,ICSA-24-277-02,Subnet Solutions Inc. PowerSYSTEM Center,SUBNET Solutions Inc.,PowerSYSTEM Center,The following versions of PowerSYSTEM Center are affected: PowerSYSTEM Center: PSC 2020 v5.21.x and prior.,"CVE-2020-28168, CVE-2021-3749, CVE-2023-45857",7.5,High,"CWE-918, CWE-1333, CWE-352",Critical Manufacturing; Energy,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3024,10/3/2024,10/3/2024,2024,ICSA-24-277-03,Delta Electronics DIAEnergie,Delta Electronics,DIAEnergie,"The following versions of Delta Electronics DIAEnergie, an industrial energy management system, are affected: DIAEnergie: Versions v1.10.01.008 and prior.","CVE-2024-42417, CVE-2024-43699",9.3,Critical,CWE-89,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3023,10/1/2024,10/1/2024,2024,ICSA-24-275-01,Optigo Networks ONS-S8 Spectra Aggregation Switch,Optigo Networks,ONS-S8 - Spectra Aggregation Switch,"The following versions of ONS-S8 - Spectra Aggregation Switch, an OT network management device, are affected: ONS-S8 - Spectra Aggregation Switch: 1.3.7 and prior.","CVE-2024-41925, CVE-2024-45367",9.3,Critical,"CWE-98, CWE-1390",Critical Manufacturing; Commercial Facilities,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3022,10/1/2024,10/1/2024,2024,ICSA-24-275-02,Mitsubishi Electric MELSEC iQ-F FX5-OPC,Mitsubishi Electric,MELSEC iQ-F FX5-OPC,The following Mitsubishi Electric products are affected: MELSEC iQ-F FX5-OPC: All versions.,CVE-2024-0727,7.5,High,CWE-476,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3021,9/26/2024,9/26/2024,2024,ICSA-24-270-01,Advantech ADAM-5550,Advantech,ADAM-5550,"The following versions of Advantech's ADAM, are affected: Advantech ADAM 5550: All versions.","CVE-2024-37187, CVE-2024-38308",8.7,High,"CWE-261, CWE-79",Energy; Water and Wastewater Systems,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3020,9/26/2024,9/26/2024,2024,ICSA-24-270-02,Advantech ADAM-5630,Advantech,ADAM-5630,The following versions of Advantech's ADAM are affected: Advantech ADAM-5630: versions prior to v2.5.2.,"CVE-2024-28948, CVE-2024-34542, CVE-2024-39275, CVE-2024-39364",8.5,High,"CWE-539, CWE-352, CWE-261, CWE-306",Energy; Water and Wastewater Systems,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3019,9/26/2024,9/26/2024,2024,ICSA-24-270-03,Atelmo Atemio AM 520 HD Full HD Satellite Receiver,Atelmo,Atemio AM 520 HD Full HD Satellite Receiver,"The following versions of Atelmo Atemio AM 520 HD, a satellite receiver, are affected: Atemio AM 520 HD: TitanNit 2.01 and prior.",CVE-2024-9166,9.3,Critical,CWE-78,Communications; Commercial Facilities,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3018,9/26/2024,10/17/2024,2024,ICSA-24-270-04,goTenna Pro X and Pro X2 (Update A),goTenna,Pro series,"The following versions of goTenna Pro series, mesh networking device, are affected: goTenna Pro App: versions 1.6.1 and prior.","CVE-2024-47121, CVE-2024-47122, CVE-2024-47123, CVE-2024-47124, CVE-2024-47125, CVE-2024-47126, CVE-2024-47127, CVE-2024-47128, CVE-2024-47129, CVE-2024-47130",8.7,High,"CWE-521, CWE-922, CWE-353, CWE-319, CWE-923, CWE-338, CWE-1390, CWE-201, CWE-204, CWE-306",Communications; Government Facilities,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3017,9/26/2024,10/17/2024,2024,ICSA-24-270-05,goTenna Pro ATAK Plugin (Update A),goTenna,Pro ATAK Plugin,"The following versions of goTenna Pro ATAK Plugin, a mesh networking device, are affected: goTenna Pro ATAK Plugin: Versions 1.9.12 and prior.","CVE-2024-45374, CVE-2024-43694, CVE-2024-43108, CVE-2024-45838, CVE-2024-45723, CVE-2024-41722, CVE-2024-41931, CVE-2024-41715, CVE-2024-43814",7.1,High,"CWE-521, CWE-922, CWE-353, CWE-319, CWE-338, CWE-1390, CWE-201, CWE-204",Communications; Government Facilities,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3016,9/24/2024,9/24/2024,2024,ICSA-24-268-01,OPW Fuel Management Systems SiteSentinel,OPW Fuel Management Systems,SiteSentinel,The following OPW Fuel Management Systems products are affected: SiteSentinel: Versions prior to 17Q2.1.,CVE-2024-8310,9.3,Critical,CWE-306,Energy; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3015,9/24/2024,9/24/2024,2024,ICSA-24-268-02,Alisonic Sibylla,Alisonic,Sibylla,"The following versions of Sibylla, an automated tank gauge, are affected: Sibylla: All Versions.",CVE-2024-8630,9.3,Critical,CWE-89,Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3014,9/24/2024,9/24/2024,2024,ICSA-24-268-03,Franklin Fueling Systems TS-550 EVO,Franklin Fueling System,TS-550 EVO Automatic Tank Gauge,The following Franklin Fueling Systems products are affected: TS-550 EVO: Versions prior to 2.26.4.8967.,CVE-2024-8497,8.7,High,CWE-36,Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3013,9/24/2024,9/24/2024,2024,ICSA-24-268-04,Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE,Dover Fueling Solutions (DFS),ProGauge MAGLINK LX CONSOLE,"The following versions of Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE, tank gauge consoles, are affected: ProGauge MAGLINK LX CONSOLE: Versions 3.4.2.2.6 and prior ProGauge MAGLINK LX4 CONSOLE: Versions 4.17.9e and prior.","CVE-2024-41725, CVE-2024-43423, CVE-2024-43692, CVE-2024-43693, CVE-2024-45066, CVE-2024-45373",10.0,Critical,"CWE-77, CWE-269, CWE-259, CWE-288, CWE-79",Energy; Transportation Systems,North America,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3012,9/24/2024,9/24/2024,2024,ICSA-24-268-05,Moxa MXview One,Moxa,"MXview One, MXview One Central Manager Series",The following Moxa products are affected: MXview One Series: Versions 1.4.0 and prior MXview One Central Manager Series: Version 1.0.0.,"CVE-2024-6785, CVE-2024-6786, CVE-2024-6787",6.8,Medium,"CWE-313, CWE-24, CWE-367",Critical Manufacturing; Energy; Transportation Systems,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3011,9/24/2024,10/24/2024,2024,ICSA-24-268-06,OMNTEC Proteus Tank Monitoring (Update A),"OMNTEC Mfg., Inc.",Proteus Tank Monitoring,The following version of Proteus Tank Monitoring is affected: OMNTEC Proteus Tank Monitoring: OEL8000III K/X ATG Generation 3.0.,CVE-2024-6981,9.3,Critical,CWE-306,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3010,9/19/2024,9/19/2024,2024,ICSA-24-263-01,Rockwell Automation RSLogix 5 and RSLogix 500,Rockwell Automation,RSLogix 5 and RSLogix 500,"The following versions of Rockwell Automation RSLogix 5 and RSLogix 500, a programming software, are affected: RSLogix 500: All versions RSLogix Micro Developer and Starter: All versions RSLogix 5: All versions.",CVE-2024-7847,8.8,High,CWE-345,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3009,9/19/2024,7/10/2025,2024,ICSA-24-263-02,IDEC Products (Update A),IDEC Corporation,IDEC Products,The following versions of IDEC products are affected: FC6A Series MICROSmart All-in-One CPU module: Ver.2.60 and prior FC6B Series MICROSmart All-in-One CPU module: Ver.2.60 and prior FC6A Series MICROSmart Plus CPU module: Ver.2.40 and prior FC6B Series MICROSmart Plus CPU module: Ver.2.60 and prior FT1A Series SmartAXIS Pro/Lite: Ver.2.41 and prior (affected only by CVE-2024-41927) SX8R Bus Coupler Module: Ver.2.1.0 and prior (affected only by CVE-2024-28957).,"CVE-2024-28957, CVE-2024-41927",5.3,Medium,"CWE-319, CWE-340",Critical Manufacturing; Energy; Food and Agriculture; Transportation Systems,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3008,9/19/2024,9/19/2024,2024,ICSA-24-263-03,IDEC CORPORATION WindLDR and WindO/I-NV4,IDEC Corporation,"WindLDR, WindO/I-NV4",The following versions of WindLDR and WindO/I-NV4 are affected: WindLDR: Ver.9.1.0 and prior WindO/I-NV4: Ver.3.0.1 and prior.,CVE-2024-41716,5.9,Medium,CWE-312,Food and Agriculture; Critical Manufacturing; Energy; Transportation Systems,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3007,9/19/2024,8/12/2025,2024,ICSA-24-263-04,MegaSys Computer Technologies Telenium Online Web Application (Update A),MegaSys Computer Technologies,Telenium Online Web Application,The following MegaSys Computer Technologies products are affected: Telenium Online Web Application: versions 8.3 and prior.,CVE-2025-8769,9.3,Critical,CWE-20,Information Technology; Communications,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3006,9/19/2024,9/19/2024,2024,ICSA-24-263-05,Kastle Systems Access Control System,Kastle Systems,Access Control System,"The following versions of Kastle Systems Access Control System are affected: Access Control System: Firmware before May 1, 2024.","CVE-2024-45861, CVE-2024-45862",9.2,Critical,"CWE-798, CWE-312",Commercial Facilities; Government Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3005,9/17/2024,9/17/2024,2024,ICSA-24-261-01,Siemens SIMATIC S7-200 SMART Devices,Siemens,SIMATIC S7-200 SMART Devices,The following versions of Siemens SIMATIC S7-200 SMART Devices are affected: SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0): All versions SIMATIC S7-200 SMART CPU CR60 (6ES7288-1CR60-0AA0): All Versions SIMATIC S7-200 SMART CPU SR20 (6ES7288-1SR20-0AA0): All Versions SIMATIC S7-200 SMART CPU SR20 (6ES7288-1SR20-0AA1): All Versions SIMATIC S7-200 SMART CPU SR30 (6ES7288-1SR30-0AA0): All Versions SIMATIC S7-200 SMART CPU SR30 (6ES7288-1SR30-0AA1): All Versions SIMATIC S7-200 SMART CPU SR40 (6ES7288-1SR40-0AA0): All Versions SIMATIC S7-200 SMART CPU SR40 (6ES7288-1SR40-0AA1): All Versions SIMATIC S7-200 SMART CPU SR60 (6ES7288-1SR60-0AA0): All Versions SIMATIC S7-200 SMART CPU SR60 (6ES7288-1SR60-0AA1): All Versions SIMATIC S7-200 SMART CPU ST20 (6ES7288-1ST20-0AA0): All Versions SIMATIC S7-200 SMART CPU ST20 (6ES7288-1ST20-0AA1): All Versions SIMATIC S7-200 SMART CPU ST30 (6ES7288-1ST30-0AA0): All Versions SIMATIC S7-200 SMART CPU ST30 (6ES7288-1ST30-0AA1): All Versions SIMATIC S7-200 SMART CPU ST40 (6ES7288-1ST40-0AA0): All Versions SIMATIC S7-200 SMART CPU ST40 (6ES7288-1ST40-0AA1): All Versions SIMATIC S7-200 SMART CPU ST60 (6ES7288-1ST60-0AA0): All Versions SIMATIC S7-200 SMART CPU ST60 (6ES7288-1ST60-0AA1): All Versions.,CVE-2024-43647,8.7,High,CWE-400,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3004,9/17/2024,9/17/2024,2024,ICSA-24-261-02,Millbeck Communications Proroute H685t-w,Millbeck Communications,Proroute H685t-w,"The following versions of Millbeck Communications Proroute H685t-w, a 4G router, are affected: Proroute H685t-w: Version 3.2.334.","CVE-2024-45682, CVE-2024-38380",8.8,High,"CWE-77, CWE-79",Commercial Facilities; Energy,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3003,9/17/2024,9/17/2024,2024,ICSA-24-261-03,Yokogawa Dual-redundant Platform for Computer (PC2CKM),Yokogawa,Dual-redundant Platform for Computer (PC2CKM),"The following versions of Yokogawa PC2CKM, a dual-redundant platform computer, are affected: Dual-redundant Platform for Computer (PC2CKM): R1.01.00 to R2.03.00.",CVE-2024-8110,7.5,High,CWE-252,Critical Manufacturing; Energy; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3002,9/12/2024,9/12/2024,2024,ICSA-24-256-01,Siemens SINEMA Remote Connect Server,Siemens,SINEMA Remote Connect Server,"Siemens reports that the following versions of SINEMA Remote Connect Server, a remote network management platform, are affected: SINEMA Remote Connect Server: versions prior to V3.2 SP2.",CVE-2024-42345,5.3,Medium,CWE-384,Critical Manufacturing; Commercial Facilities; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3001,9/12/2024,9/12/2024,2024,ICSA-24-256-02,"Siemens SINUMERIK ONE, SINUMERIK 840D and SINUMERIK 828D",Siemens,"SINUMERIK ONE, SINUMERIK 840D, SINUMERIK 828D","The following versions of Siemens SINUMERIK products, an automation system, are affected: SINUMERIK 828D V4: All versions SINUMERIK 828D V5: All versions prior to V5.24 SINUMERIK 840D sl V4: All versions SINUMERIK ONE: All versions prior to V6.24.",CVE-2024-41171,9.3,Critical,CWE-732,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3000,9/12/2024,9/12/2024,2024,ICSA-24-256-03,Siemens User Management Component (UMC),Siemens,"SIMATIC Information Server, SIMATIC PCS neo, SINEC NMS, Totally Integrated Automation Portal (TIA Portal)",The following Siemens User Managements Components are affected: SIMATIC Information Server 2022: All versions SIMATIC Information Server 2024: All versions SIMATIC PCS neo V4.0: All versions SIMATIC PCS neo V4.1: All versions prior to V4.1 Update 2 SIMATIC PCS neo V5.0: All versions SINEC NMS: All versions Totally Integrated Automation Portal (TIA Portal) V16: All versions Totally Integrated Automation Portal (TIA Portal) V17: All versions prior to V17 Update 8 Totally Integrated Automation Portal (TIA Portal) V18: All versions Totally Integrated Automation Portal (TIA Portal) V19: All versions.,CVE-2024-33698,9.3,Critical,CWE-122,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2999,9/12/2024,9/12/2024,2024,ICSA-24-256-04,Siemens SINUMERIK Systems,Siemens,SINUMERIK systems,The following versions of Siemens SINUMERIK systems are affected: SINUMERIK 828D V4: All versions prior to V4.95 SP3 SINUMERIK 840D sl V4: All versions prior to V4.95 SP3 in connection with using Create MyConfig (CMC) V4.8 SP1 HF6 and prior SINUMERIK ONE prior to V6.23: All versions prior to V6.23 in connection with using Create MyConfig (CMC) V6.6 and prior SINUMERIK ONE prior to V6.15 SP4: All versions prior to V6.15 SP4 in connection with using Create MyConfig (CMC) V6.6 and prior.,CVE-2024-43781,6.8,Medium,CWE-532,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2998,9/12/2024,9/12/2024,2024,ICSA-24-256-05,Siemens Mendix Runtime,Siemens,Mendix Runtime,"The following versions of Siemens Mendix Runtime, are affected: Mendix Runtime V8: All versions only if the basic authentication mechanism is used by the application Mendix Runtime V9: All versions prior to V9.24.26 only if the basic authentication mechanism is used by the application Mendix Runtime V10: All versions prior to V10.14.0 only if the basic authentication mechanism is used by the application Mendix Runtime V10.6: All versions prior to V10.6.12 only if the basic authentication mechanism is used by the application Mendix Runtime V10.12: All versions prior to V10.12.2 only if the basic authentication mechanism is used by the application.",CVE-2023-49069,6.9,Medium,CWE-204,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2997,9/12/2024,9/12/2024,2024,ICSA-24-256-06,Siemens Automation License Manager,Siemens,Automation License Manager,"The following versions of Siemens Automation License Manager, are affected: Automation License Manager V5: All versions Automation License Manager V6.0: All versions Automation License Manager V6.2: All versions prior to V6.2 Upd3.",CVE-2024-44087,9.2,Critical,CWE-190,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2996,9/12/2024,9/12/2024,2024,ICSA-24-256-07,Siemens SIMATIC RFID Readers,Siemens,SIMATIC RFID Readers,Siemens reports that the following SIMATIC RFID Readers are affected: SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0): versions prior to V4.2 SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0): versions prior to V4.2 SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0): versions prior to V4.2 SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0): versions prior to V4.2 SIMATIC Reader RF615R ETSI (6GT2811-6CC10-0AA0): versions prior to V4.2 SIMATIC Reader RF615R FCC (6GT2811-6CC10-1AA0): versions prior to V4.2 SIMATIC Reader RF650R ARIB (6GT2811-6AB20-4AA0): versions prior to V4.2 SIMATIC Reader RF650R CMIIT (6GT2811-6AB20-2AA0): versions prior to V4.2 SIMATIC Reader RF650R ETSI (6GT2811-6AB20-0AA0): versions prior to V4.2 SIMATIC Reader RF650R FCC (6GT2811-6AB20-1AA0): versions prior to V4.2 SIMATIC Reader RF680R ARIB (6GT2811-6AA10-4AA0): versions prior to V4.2 SIMATIC Reader RF680R CMIIT (6GT2811-6AA10-2AA0): versions prior to V4.2 SIMATIC Reader RF680R ETSI (6GT2811-6AA10-0AA0): versions prior to V4.2 SIMATIC Reader RF680R FCC (6GT2811-6AA10-1AA0): versions prior to V4.2 Siemens SIMATIC Reader RF685R ARIB (6GT2811-6CA10-4AA0): versions prior to V4.2 SIMATIC Reader RF685R CMIIT (6GT2811-6CA10-2AA0): versions prior to V4.2 SIMATIC Reader RF685R ETSI (6GT2811-6CA10-0AA0): versions prior to V4.2 SIMATIC Reader RF685R FCC (6GT2811-6CA10-1AA0): versions prior to V4.2 SIMATIC RF166C (6GT2002-0EE20): versions prior to V2.2 SIMATIC RF185C (6GT2002-0JE10): versions prior to V2.2 SIMATIC RF186C (6GT2002-0JE20): versions prior to V2.2 SIMATIC RF186CI (6GT2002-0JE50): versions prior to V2.2 SIMATIC RF188C (6GT2002-0JE40): versions prior to V2.2 SIMATIC RF188CI (6GT2002-0JE60): versions prior to V2.2 SIMATIC RF360R (6GT2801-5BA30): versions prior to V2.2 SIMATIC RF1140R (6GT2831-6CB00): versions prior to V1.1 SIMATIC RF1170R (6GT2831-6BB00): versions prior to V1.1.,"CVE-2024-37990, CVE-2024-37991, CVE-2024-37992, CVE-2024-37993, CVE-2024-37994, CVE-2024-37995",7.0,High,"CWE-912, CWE-200, CWE-703, CWE-284",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2995,9/12/2024,9/12/2024,2024,ICSA-24-256-08,Siemens Industrial Products,Siemens,Industrial Products,Siemens reports that the following industrial products are affected: AI Model Deployer: versions prior to V1.1 Data Flow Monitoring Industrial Edge Device User Interface (DFM IED UI): versions prior to V0.0.6 LiveTwin Industrial Edge app (6AV2170-0BL00-0AA0): versions prior to V2.4 SIMATIC PCS neo V4.1: versions prior to V4.1 Update 2 SIMATIC PCS neo V5.0: all versions SIMATIC WinCC Runtime Professional V17: all versions SIMATIC WinCC Runtime Professional V18: all versions SIMATIC WinCC Runtime Professional V19: all versions SIMATIC WinCC Runtime Professional V20: all versions SIMATIC WinCC V7.4 with installed WebRH: All versions SIMATIC WinCC V7.5: all versions SIMATIC WinCC V8.0: all versions TIA Administrator: versions prior to V3.0 SP3.,CVE-2024-38355,6.9,Medium,CWE-20,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2994,9/12/2024,9/12/2024,2024,ICSA-24-256-09,"Siemens SIMATIC, SIPLUS, and TIM",Siemens,"SIMATIC, SIPLUS, and TIM",The following products of Siemens are affected: SIMATIC CP 1242-7 V2 (incl. SIPLUS variants): Versions prior to V3.5.20 SIMATIC CP 1243-1 (incl. SIPLUS variants): Versions prior to V3.5.20 SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants): Versions prior to V3.5.20 SIMATIC CP 1243-1 IEC (incl. SIPLUS variants): Versions prior to V3.5.20 SIMATIC CP 1243-7 LTE: Versions prior to V3.5.20 SIMATIC CP 1243-8 IRC (6GK7243-8RX30-0XE0): Versions prior to V3.5.20 SIMATIC HMI Comfort Panels (incl. SIPLUS variants): All versions SIMATIC IPC DiagBase: All versions SIMATIC IPC DiagMonitor: All versions SIMATIC WinCC Runtime Advanced: All versions SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0): Versions prior to V2.4.8 TIM 1531 IRC (6GK7543-1MX00-0XE0): Versions prior to V2.4.8.,"CVE-2023-28827, CVE-2023-30755, CVE-2023-30756",8.2,High,CWE-476,Energy; Critical Manufacturing;,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2993,9/12/2024,9/12/2024,2024,ICSA-24-256-10,Siemens SINEMA,Siemens,SINEMA,The following products of Siemens are affected: SINEMA Remote Connect Client: Versions prior to V3.2 SP2.,"CVE-2023-46850, CVE-2024-2004, CVE-2024-2379, CVE-2024-2398, CVE-2024-2466, CVE-2024-32006, CVE-2024-42344",5.3,Medium,"CWE-416, CWE-20, CWE-295, CWE-772, CWE-297, CWE-613, CWE-532",Energy; Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2992,9/12/2024,9/12/2024,2024,ICSA-24-256-11,Siemens Industrial Edge Management,Siemens,Industrial Edge Management,The following Siemens products are affected: Industrial Edge Management Pro: Versions prior to V1.9.5 Industrial Edge Management Virtual: Versions prior to V2.3.1-1.,CVE-2024-45032,10.0,Critical,CWE-639,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2991,9/12/2024,9/12/2024,2024,ICSA-24-256-12,Siemens Tecnomatix Plant Simulation,Siemens,Tecnomatix Plant Simulation,The following Siemens products are affected: Plant Simulation V2302: versions prior to V2302.0015 Plant Simulation V2404: versions prior to V2404.0004.,CVE-2024-41170,7.3,High,CWE-121,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2990,9/12/2024,9/12/2024,2024,ICSA-24-256-13,Siemens SCALANCE W700,Siemens,SCALANCE W700,Siemens reports that the following SCALANCE W700 802.11 AX Family products are affected: SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0): All versions prior to V2.4.0 SCALANCE WAM763-1 (6GK5763-1AL00-7DA0): All versions prior to V2.4.0 SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0): All versions prior to V2.4.0 SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0): All versions prior to V2.4.0 SCALANCE WAM766-1 (EU) (6GK5766-1GE00-7DA0): All versions prior to V2.4.0 SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0): All versions prior to V2.4.0 SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0): All versions prior to V2.4.0 SCALANCE WAM766-1 EEC (EU) (6GK5766-1GE00-7TA0): All versions prior to V2.4.0 SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0): All versions prior to V2.4.0 SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0): All versions prior to V2.4.0 SCALANCE WUB762-1 (6GK5762-1AJ00-1AA0): All versions prior to V2.4.0 SCALANCE WUB762-1 (6GK5762-1AJ00-2AA0): All versions prior to V2.4.0 SCALANCE WUM763-1 (6GK5763-1AL00-3AA0): All versions prior to V2.4.0 SCALANCE WUM763-1 (6GK5763-1AL00-3DA0): All versions prior to V2.4.0 SCALANCE WUM763-1 (US) (6GK5763-1AL00-3AB0): All versions prior to V2.4.0 SCALANCE WUM763-1 (US) (6GK5763-1AL00-3DB0): All versions prior to V2.4.0 SCALANCE WUM766-1 (EU) (6GK5766-1GE00-3DA0): All versions prior to V2.4.0 SCALANCE WUM766-1 (ME) (6GK5766-1GE00-3DC0): All versions prior to V2.4.0 SCALANCE WUM766-1 (US) (6GK5766-1GE00-3DB0): All versions prior to V2.4.0.,CVE-2023-44373,9.4,Critical,CWE-74,"Chemical Sector; Critical Manufacturing; Energy Sector; Nuclear Reactors, Materials, and Waste",Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2989,9/12/2024,9/12/2024,2024,ICSA-24-256-14,Siemens SIMATIC SCADA and PCS 7 Systems,Siemens,SIMATIC SCADA and PCS 7 Systems,The following Siemens products are affected: SIMATIC BATCH V9.1: All versions SIMATIC Information Server 2020: All versions SIMATIC Information Server 2022: All versions SIMATIC PCS 7 V9.1: All versions SIMATIC Process Historian 2020: All versions SIMATIC Process Historian 2022: All versions SIMATIC WinCC Runtime Professional V18: All versions SIMATIC WinCC Runtime Professional V19: All versions SIMATIC WinCC V7.4: All versions SIMATIC WinCC V7.5: All versions prior to V7.5 SP2 Update 18 SIMATIC WinCC V8.0: All versions prior to V8.0 Update 5.,CVE-2024-35783,9.4,Critical,CWE-250,Chemical; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2988,9/12/2024,9/12/2024,2024,ICSA-24-256-15,Siemens Industrial Products,Siemens,"Industrial Edge Management OS (IEM-OS), SINEMA Remote Connect Server, SINUMERIK ONE",The following Siemens products are affected: Industrial Edge Management OS (IEM-OS): All versions SINEMA Remote Connect Server: All versions prior to V3.2 SP2 SINUMERIK ONE: All versions prior to V6.24.,CVE-2024-6387,8.1,High,CWE-364,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2987,9/12/2024,9/12/2024,2024,ICSA-24-256-16,Siemens Third Party Component in SICAM and SITIPE Products,Siemens,IEC 61850 Client libraries from Triangle MicroWorks affecting SICAM and SITIPE products,The following Siemens products are affected: SICAM A8000 Device Firmware ETI5 Ethernet Int. 1x100TX IEC61850: All versions prior to V05.30 SICAM EGS Device Firmware ETI5: All versions prior to V05.30 SICAM 8 Software Solution: ETI5 All versions prior to V05.30 SICAM SCC: All versions prior to V10.0 SITIPE AT: All versions.,CVE-2024-34057,8.8,High,CWE-120,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2986,9/12/2024,9/12/2024,2024,ICSA-24-256-17,AutomationDirect DirectLogic H2-DM1E,AutomationDirect,DirectLogic H2-DM1E,"The following versions of DirectLogic H2-DM1E, a programmable logic controller, are affected: DirectLogic H2-DM1E: Versions 2.8.0 and prior.","CVE-2024-43099, CVE-2024-45368",8.7,High,"CWE-294, CWE-384",Critical Manufacturing; Dams; Food and Agriculture,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2985,9/12/2024,9/12/2024,2024,ICSA-24-256-18,Rockwell Automation ControlLogix/GuardLogix 5580 and CompactLogix/Compact GuardLogix 5380,Rockwell Automation,"ControlLogix/GuardLogix 5580 and CompactLogix/Compact GuardLogix 5380, CompactLogix 5480, 1756-EN4",Rockwell Automation reports that the following controllers are affected: CompactLogix 5380: v.32 .011 CompactLogix 5380 Process: v.33.011 Compact GuardLogix 5380 SIL 2: v.32.013 Compact GuardLogix 5380 SIL 3: v.32.011 CompactLogix 5480: v.32.011 ControlLogix 5580: v.32.011 ControlLogix 5580 Process: v.33.011 GuardLogix 5580: v.32.011 1756-EN4: v2.001.,CVE-2024-6077,8.7,High,CWE-20,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2984,9/12/2024,9/12/2024,2024,ICSA-24-256-19,Rockwell Automation OptixPanel,Rockwell Automation,OptixPanel,Rockwell Automation reports that the following operator panels are affected: 2800C OptixPanel Compact: version 4.0.0.325 2800S OptixPanel Standard: version 4.0.0.350 Embedded Edge Compute Module: version 4.0.0.347.,CVE-2024-8533,7.7,High,CWE-269,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2983,9/12/2024,9/12/2024,2024,ICSA-24-256-20,Rockwell Automation AADvance Trusted SIS Workstation,Rockwell Automation,AADvance Trusted SIS Workstation,"The following versions of AADvance Trusted SIS Workstation, a manufacturing controller management suite, are affected: AADvance Trusted SIS Workstation: 2.00.01 and prior.","CVE-2023-31102, CVE-2023-40481",7.8,High,"CWE-20, CWE-787",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2982,9/12/2024,9/12/2024,2024,ICSA-24-256-21,Rockwell Automation 5015-U8IHFT,Rockwell Automation,5015-U8IHFT,"The following versions of 5015-U8IHFT, an I/O module, are affected: 5015-U8IHFT: Versions 1.012 and prior.",CVE-2024-45825,8.7,High,CWE-20,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2981,9/12/2024,9/12/2024,2024,ICSA-24-256-22,Rockwell Automation FactoryTalk Batch View,Rockwell Automation,FactoryTalk Batch View,"The following versions of Rockwell Automation FactoryTalk Batch View, a manufacturing process batch solution, are affected: FactoryTalk Batch View: 2.01.00 and prior.",CVE-2024-45823,9.2,Critical,CWE-287,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2980,9/12/2024,9/12/2024,2024,ICSA-24-256-23,Rockwell Automation FactoryTalk View Site,Rockwell Automation,FactoryTalk,"The following versions of Rockwell Automation FactoryTalk View Site, are affected: FactoryTalk View Site Edition: Versions V12.0, V13.0, V14.0.",CVE-2024-45824,9.2,Critical,CWE-77,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2979,9/12/2024,9/12/2024,2024,ICSA-24-256-24,Rockwell Automation Pavilion8,Rockwell Automation,Pavilion8,"The following versions of Rockwell Automation Pavilion8, a model predictive control software, are affected: Pavilion8: All versions prior to V5.20.","CVE-2024-7960, CVE-2024-7961",8.8,High,"CWE-269, CWE-22",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2978,9/12/2024,9/12/2024,2024,ICSA-24-256-25,Rockwell Automation ThinManager,Rockwell Automation,ThinManager,"The following versions of Rockwell Automation ThinManager, a visualization resource manager, are affected: ThinManager: Versions V13.1.0 to 13.1.2 ThinManager: Versions V13.2.0 to 13.2.1.",CVE-2024-45826,8.5,High,CWE-610,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2977,9/10/2024,9/10/2024,2024,ICSA-24-254-01,Viessmann Climate Solutions SE Vitogate 300,Viessmann Climate Solutions SE,Vitogate 300,"The following versions of Viessmann Climate Solutions SE Vitogate 300, a solution to connecting boilers and heat pumps to a building management system, are affected: Viessmann Vitogate 300: Versions 2.1.3.0 and prior.","CVE-2023-5222, CVE-2023-5702, CVE-2023-45852",9.3,Critical,"CWE-798, CWE-425, CWE-77",Commercial Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2976,9/10/2024,9/10/2024,2024,ICSA-24-254-02,iniNet Solutions SpiderControl SCADA Web Server,iniNet Solutions GmbH,SpiderControl SCADA Web Server,"The following versions of SpiderControl, an HMI program, are affected: SpiderControl SCADA Web Server: Versions v2.09 and prior.",CVE-2024-8232,8.7,High,CWE-434,Critical Manufacturing,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2975,9/10/2024,9/10/2024,2024,ICSA-24-254-03,Rockwell Automation SequenceManager,Rockwell Automation,SequenceManager,"The following versions of SequenceManager, a logix controller-based batch and sequencing solution, are affected: SequenceManager: Versions prior to 2.0.",CVE-2024-4609,8.7,High,CWE-428,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2974,9/10/2024,9/10/2024,2024,ICSMA-24-254-01,BPL Medical Technologies PWS-01-BT and BPL Be Well Android Application,BPL Medical Technologies,"PWS-01-BT, Be Well Android App",The following BPL Medical Technologies products are affected: Be Well Android Application: Versions 3.64 and prior PWS-01-BT: All versions.,CVE-2024-34463,5.1,Medium,CWE-319,Healthcare and Public Health,Worldwide,India,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2973,9/5/2024,9/5/2024,2024,ICSA-24-249-01,Hughes Network Systems WL3000 Fusion Software,Hughes Network Systems,WL3000 Fusion Software,The following Hughes Network Systems work streams are affected: WL3000 Fusion Software: Versions prior to 2.7.0.10.,"CVE-2024-39278, CVE-2024-42495",7.1,High,"CWE-522, CWE-311",Information Technology,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2972,9/5/2024,9/5/2024,2024,ICSMA-24-249-01,Baxter Connex Health Portal,Baxter,Connex Health Portal,The following Baxter (formerly Hillrom and Welch Allyn) products are affected: Baxter Connex Health Portal: all versions prior to 8/30/2024.,"CVE-2024-6795, CVE-2024-6796",10.0,Critical,"CWE-89, CWE-284",Healthcare and Public Health,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2971,9/3/2024,9/3/2024,2024,ICSA-24-247-01,LOYTEC Electronics LINX Series,LOYTEC electronics GmbH,LINX series,The following Loytec products are affected: LINX-151: All versions LINX-212: All versions LVIS-3ME12-A1: All versions LIOB-586: All versions LIOB-580 V2: All versions LIOB-588: All versions L-INX Configurator: All versions.,"CVE-2023-46380, CVE-2023-46381, CVE-2023-46382, CVE-2023-46383, CVE-2023-46384, CVE-2023-46385, CVE-2023-46386, CVE-2023-46387, CVE-2023-46388, CVE-2023-46389",9.3,Critical,"CWE-319, CWE-306, CWE-312, CWE-284",Critical Manufacturing,Worldwide,Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2970,8/29/2024,8/29/2024,2024,ICSA-24-242-01,Rockwell Automation ThinManager ThinServer,Rockwell Automation,ThinManager ThinServer,"The following versions of Rockwell Automation ThinManager ThinServer, a client management software, are affected: ThinManager ThinServer: Versions 11.1.0 to 11.1.7 ThinManager ThinServer: Versions 11.2.0 to 11.2.8 ThinManager ThinServer: Versions 12.0.0 to 12.0.6 ThinManager ThinServer: Versions 12.1.0 to 12.1.7 ThinManager ThinServer: Versions 13.0.0 to 13.0.4 ThinManager ThinServer: Versions 13.1.0 to 13.1.2 ThinManager ThinServer: Versions 13.2.0 to 13.2.1.","CVE-2024-7986, CVE-2024-7987, CVE-2024-7988",9.3,Critical,"CWE-269, CWE-732, CWE-20",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2969,8/29/2024,8/29/2024,2024,ICSA-24-242-02,Delta Electronics DTN Soft,Delta Electronics,DTN Soft,"The following versions of Delta Electronics DTN Soft, a temperature control, are affected: DTN Soft: Version 2.0.1 and prior.",CVE-2024-8255,8.4,High,CWE-502,Energy; Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2968,8/22/2024,8/22/2024,2024,ICSA-24-235-01,Rockwell Automation Emulate3D,Rockwell Automation,Emulate3D,"The following version of Rockwell Automation Emulate3D, a Digital Twin technology, is affected: Emulate3D: Versions 17.00.00.13276.",CVE-2024-6079,5.4,Medium,CWE-610,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2967,8/22/2024,8/22/2024,2024,ICSA-24-235-02,Rockwell Automation 5015 – AENFTXT,Rockwell Automation,5015 - AENFTXT,"The following versions of Rockwell Automation 5015 - AENFTXT, a part of the FLEXHA 5000 I/O Modules, are affected: 5015 - AENFTXT: Version 2.011.",CVE-2024-6089,8.7,High,CWE-20,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2966,8/22/2024,8/22/2024,2024,ICSA-24-235-03,MOBOTIX P3 and Mx6 Cameras,MOBOTIX,"P3 Cameras, Mx6 Cameras","The following products of MOBOTIX are affected: P3 D24M: MX-V4.1.4.11, MX-V4.1.4.70, MX-V4.1.6.25, MX-V4.1.6.27, MX-V4.1.9.29, MX-V4.1.10.28, MX-V4.1.10.35, MX-V4.2.1.43, MX-V4.2.1.61, MX-V4.3.0.15, MX-V4.3.2.45, MX-V4.3.2.53, MX-V4.3.2.68, MX-V4.3.2.72, MX-V4.3.2.77, MX-V4.3.4.50, MX-V4.3.4.66, MX-V4.3.4.83, MX-V4.4.0.31, MX-V4.4.0.31.r1, MX-V4.4.1.55, MX-V4.4.1.56, MX-V4.4.2.34, MX-V4.4.2.51.r1, MX-V4.4.2.69, MX-V4.4.2.73 P3 M24M: MX-V4.1.4.11, MX-V4.1.4.70, MX-V4.1.6.25, MX-V4.1.6.27, MX-V4.1.9.29, MX-V4.1.10.28, MX-V4.1.10.35, MX-V4.2.1.43, MX-V4.2.1.61, MX-V4.3.0.15, MX-V4.3.2.45, MX-V4.3.2.53, MX-V4.3.2.68, MX-V4.3.2.72, MX-V4.3.2.77, MX-V4.3.4.50, MX-V4.3.4.66, MX-V4.3.4.83, MX-V4.4.0.31, MX-V4.4.0.31.r1, MX-V4.4.1.55, MX-V4.4.1.56, MX-V4.4.2.34, MX-V4.4.2.51.r1, MX-V4.4.2.69, MX-V4.4.2.73 P3 Q24M: MX-V4.1.4.11, MX-V4.1.4.70, MX-V4.1.6.25, MX-V4.1.6.27, MX-V4.1.9.29, MX-V4.1.10.28, MX-V4.1.10.35, MX-V4.2.1.43, MX-V4.2.1.61, MX-V4.3.0.15, MX-V4.3.2.45, MX-V4.3.2.53, MX-V4.3.2.68, MX-V4.3.2.72, MX-V4.3.2.77, MX-V4.3.4.50, MX-V4.3.4.66, MX-V4.3.4.83, MX-V4.4.0.31, MX-V4.4.0.31.r1, MX-V4.4.1.55, MX-V4.4.1.56, MX-V4.4.2.34, MX-V4.4.2.51.r1, MX-V4.4.2.69, MX-V4.4.2.73 P3 T24M: MX-V4.1.4.11, MX-V4.1.4.70, MX-V4.1.6.25, MX-V4.1.6.27, MX-V4.1.9.29, MX-V4.1.10.28, MX-V4.1.10.35, MX-V4.2.1.43, MX-V4.2.1.61, MX-V4.3.0.15, MX-V4.3.2.45, MX-V4.3.2.53, MX-V4.3.2.68, MX-V4.3.2.72, MX-V4.3.2.77, MX-V4.3.4.50, MX-V4.3.4.66, MX-V4.3.4.83, MX-V4.4.0.31, MX-V4.4.0.31.r1, MX-V4.4.1.55, MX-V4.4.1.56, MX-V4.4.2.34, MX-V4.4.2.51.r1, MX-V4.4.2.69, MX-V4.4.2.73 P3 D14Di: MX-V4.1.4.11, MX-V4.1.4.70, MX-V4.1.6.25, MX-V4.1.6.27, MX-V4.1.9.29, MX-V4.1.10.28, MX-V4.1.10.35, MX-V4.2.1.43, MX-V4.2.1.61, MX-V4.3.0.15, MX-V4.3.2.45, MX-V4.3.2.53, MX-V4.3.2.68, MX-V4.3.2.72, MX-V4.3.2.77, MX-V4.3.4.50, MX-V4.3.4.66, MX-V4.3.4.83, MX-V4.4.0.31, MX-V4.4.0.31.r1, MX-V4.4.1.55, MX-V4.4.1.56, MX-V4.4.2.34, MX-V4.4.2.51.r1, MX-V4.4.2.69, MX-V4.4.2.73 P3 S14: MX-V4.1.4.11, MX-V4.1.4.70, MX-V4.1.6.25, MX-V4.1.6.27, MX-V4.1.9.29, MX-V4.1.10.28, MX-V4.1.10.35, MX-V4.2.1.43, MX-V4.2.1.61, MX-V4.3.0.15, MX-V4.3.2.45, MX-V4.3.2.53, MX-V4.3.2.68, MX-V4.3.2.72, MX-V4.3.2.77, MX-V4.3.4.50, MX-V4.3.4.66, MX-V4.3.4.83, MX-V4.4.0.31, MX-V4.4.0.31.r1, MX-V4.4.1.55, MX-V4.4.1.56, MX-V4.4.2.34, MX-V4.4.2.51.r1, MX-V4.4.2.69, MX-V4.4.2.73 P3 V14D: MX-V4.1.4.11, MX-V4.1.4.70, MX-V4.1.6.25, MX-V4.1.6.27, MX-V4.1.9.29, MX-V4.1.10.28, MX-V4.1.10.35, MX-V4.2.1.43, MX-V4.2.1.61, MX-V4.3.0.15, MX-V4.3.2.45, MX-V4.3.2.53, MX-V4.3.2.68, MX-V4.3.2.72, MX-V4.3.2.77, MX-V4.3.4.50, MX-V4.3.4.66, MX-V4.3.4.83, MX-V4.4.0.31, MX-V4.4.0.31.r1, MX-V4.4.1.55, MX-V4.4.1.56, MX-V4.4.2.34, MX-V4.4.2.51.r1, MX-V4.4.2.69, MX-V4.4.2.73 P3 i25: MX-V4.1.4.11, MX-V4.1.4.70, MX-V4.1.6.25, MX-V4.1.6.27, MX-V4.1.9.29, MX-V4.1.10.28, MX-V4.1.10.35, MX-V4.2.1.43, MX-V4.2.1.61, MX-V4.3.0.15, MX-V4.3.2.45, MX-V4.3.2.53, MX-V4.3.2.68, MX-V4.3.2.72, MX-V4.3.2.77, MX-V4.3.4.50, MX-V4.3.4.66, MX-V4.3.4.83, MX-V4.4.0.31, MX-V4.4.0.31.r1, MX-V4.4.1.55, MX-V4.4.1.56, MX-V4.4.2.34, MX-V4.4.2.51.r1, MX-V4.4.2.69, MX-V4.4.2.73 P3 c25: MX-V4.1.4.11, MX-V4.1.4.70, MX-V4.1.6.25, MX-V4.1.6.27, MX-V4.1.9.29, MX-V4.1.10.28, MX-V4.1.10.35, MX-V4.2.1.43, MX-V4.2.1.61, MX-V4.3.0.15, MX-V4.3.2.45, MX-V4.3.2.53, MX-V4.3.2.68, MX-V4.3.2.72, MX-V4.3.2.77, MX-V4.3.4.50, MX-V4.3.4.66, MX-V4.3.4.83, MX-V4.4.0.31, MX-V4.4.0.31.r1, MX-V4.4.1.55, MX-V4.4.1.56, MX-V4.4.2.34, MX-V4.4.2.51.r1, MX-V4.4.2.69, MX-V4.4.2.73 P3 p25: MX-V4.1.4.11, MX-V4.1.4.70, MX-V4.1.6.25, MX-V4.1.6.27, MX-V4.1.9.29, MX-V4.1.10.28, MX-V4.1.10.35, MX-V4.2.1.43, MX-V4.2.1.61, MX-V4.3.0.15, MX-V4.3.2.45, MX-V4.3.2.53, MX-V4.3.2.68, MX-V4.3.2.72, MX-V4.3.2.77, MX-V4.3.4.50, MX-V4.3.4.66, MX-V4.3.4.83, MX-V4.4.0.31, MX-V4.4.0.31.r1, MX-V4.4.1.55, MX-V4.4.1.56, MX-V4.4.2.34, MX-V4.4.2.51.r1, MX-V4.4.2.69, MX-V4.4.2.73 P3 v25: MX-V4.1.4.11, MX-V4.1.4.70, MX-V4.1.6.25, MX-V4.1.6.27, MX-V4.1.9.29, MX-V4.1.10.28, MX-V4.1.10.35, MX-V4.2.1.43, MX-V4.2.1.61, MX-V4.3.0.15, MX-V4.3.2.45, MX-V4.3.2.53, MX-V4.3.2.68, MX-V4.3.2.72, MX-V4.3.2.77, MX-V4.3.4.50, MX-V4.3.4.66, MX-V4.3.4.83, MX-V4.4.0.31, MX-V4.4.0.31.r1, MX-V4.4.1.55, MX-V4.4.1.56, MX-V4.4.2.34, MX-V4.4.2.51.r1, MX-V4.4.2.69, MX-V4.4.2.73 P3 D25M: MX-V4.1.4.11, MX-V4.1.4.70, MX-V4.1.6.25, MX-V4.1.6.27, MX-V4.1.9.29, MX-V4.1.10.28, MX-V4.1.10.35, MX-V4.2.1.43, MX-V4.2.1.61, MX-V4.3.0.15, MX-V4.3.2.45, MX-V4.3.2.53, MX-V4.3.2.68, MX-V4.3.2.72, MX-V4.3.2.77, MX-V4.3.4.50, MX-V4.3.4.66, MX-V4.3.4.83, MX-V4.4.0.31, MX-V4.4.0.31.r1, MX-V4.4.1.55, MX-V4.4.1.56, MX-V4.4.2.34, MX-V4.4.2.51.r1, MX-V4.4.2.69, MX-V4.4.2.73 P3 M25M: MX-V4.1.4.11, MX-V4.1.4.70, MX-V4.1.6.25, MX-V4.1.6.27, MX-V4.1.9.29, MX-V4.1.10.28, MX-V4.1.10.35, MX-V4.2.1.43, MX-V4.2.1.61, MX-V4.3.0.15, MX-V4.3.2.45, MX-V4.3.2.53, MX-V4.3.2.68, MX-V4.3.2.72, MX-V4.3.2.77, MX-V4.3.4.50, MX-V4.3.4.66, MX-V4.3.4.83, MX-V4.4.0.31, MX-V4.4.0.31.r1, MX-V4.4.1.55, MX-V4.4.1.56, MX-V4.4.2.34, MX-V4.4.2.51.r1, MX-V4.4.2.69, MX-V4.4.2.73 P3 Q25M: MX-V4.1.4.11, MX-V4.1.4.70, MX-V4.1.6.25, MX-V4.1.6.27, MX-V4.1.9.29, MX-V4.1.10.28, MX-V4.1.10.35, MX-V4.2.1.43, MX-V4.2.1.61, MX-V4.3.0.15, MX-V4.3.2.45, MX-V4.3.2.53, MX-V4.3.2.68, MX-V4.3.2.72, MX-V4.3.2.77, MX-V4.3.4.50, MX-V4.3.4.66, MX-V4.3.4.83, MX-V4.4.0.31, MX-V4.4.0.31.r1, MX-V4.4.1.55, MX-V4.4.1.56, MX-V4.4.2.34, MX-V4.4.2.51.r1, MX-V4.4.2.69, MX-V4.4.2.73 P3 T25M: MX-V4.1.4.11, MX-V4.1.4.70, MX-V4.1.6.25, MX-V4.1.6.27, MX-V4.1.9.29, MX-V4.1.10.28, MX-V4.1.10.35, MX-V4.2.1.43, MX-V4.2.1.61, MX-V4.3.0.15, MX-V4.3.2.45, MX-V4.3.2.53, MX-V4.3.2.68, MX-V4.3.2.72, MX-V4.3.2.77, MX-V4.3.4.50, MX-V4.3.4.66, MX-V4.3.4.83, MX-V4.4.0.31, MX-V4.4.0.31.r1, MX-V4.4.1.55, MX-V4.4.1.56, MX-V4.4.2.34, MX-V4.4.2.51.r1, MX-V4.4.2.69, MX-V4.4.2.73 P3 D15Di: MX-V4.1.4.11, MX-V4.1.4.70, MX-V4.1.6.25, MX-V4.1.6.27, MX-V4.1.9.29, MX-V4.1.10.28, MX-V4.1.10.35, MX-V4.2.1.43, MX-V4.2.1.61, MX-V4.3.0.15, MX-V4.3.2.45, MX-V4.3.2.53, MX-V4.3.2.68, MX-V4.3.2.72, MX-V4.3.2.77, MX-V4.3.4.50, MX-V4.3.4.66, MX-V4.3.4.83, MX-V4.4.0.31, MX-V4.4.0.31.r1, MX-V4.4.1.55, MX-V4.4.1.56, MX-V4.4.2.34, MX-V4.4.2.51.r1, MX-V4.4.2.69, MX-V4.4.2.73 P3 M15: MX-V4.1.4.11, MX-V4.1.4.70, MX-V4.1.6.25, MX-V4.1.6.27, MX-V4.1.9.29, MX-V4.1.10.28, MX-V4.1.10.35, MX-V4.2.1.43, MX-V4.2.1.61, MX-V4.3.0.15, MX-V4.3.2.45, MX-V4.3.2.53, MX-V4.3.2.68, MX-V4.3.2.72, MX-V4.3.2.77, MX-V4.3.4.50, MX-V4.3.4.66, MX-V4.3.4.83, MX-V4.4.0.31, MX-V4.4.0.31.r1, MX-V4.4.1.55, MX-V4.4.1.56, MX-V4.4.2.34, MX-V4.4.2.51.r1, MX-V4.4.2.69, MX-V4.4.2.73 P3 M15-Thermal: MX-V4.1.4.11, MX-V4.1.4.70, MX-V4.1.6.25, MX-V4.1.6.27, MX-V4.1.9.29, MX-V4.1.10.28, MX-V4.1.10.35, MX-V4.2.1.43, MX-V4.2.1.61, MX-V4.3.0.15, MX-V4.3.2.45, MX-V4.3.2.53, MX-V4.3.2.68, MX-V4.3.2.72, MX-V4.3.2.77, MX-V4.3.4.50, MX-V4.3.4.66, MX-V4.3.4.83, MX-V4.4.0.31, MX-V4.4.0.31.r1, MX-V4.4.1.55, MX-V4.4.1.56, MX-V4.4.2.34, MX-V4.4.2.51.r1, MX-V4.4.2.69, MX-V4.4.2.73 P3 S15: MX-V4.1.4.11, MX-V4.1.4.70, MX-V4.1.6.25, MX-V4.1.6.27, MX-V4.1.9.29, MX-V4.1.10.28, MX-V4.1.10.35, MX-V4.2.1.43, MX-V4.2.1.61, MX-V4.3.0.15, MX-V4.3.2.45, MX-V4.3.2.53, MX-V4.3.2.68, MX-V4.3.2.72, MX-V4.3.2.77, MX-V4.3.4.50, MX-V4.3.4.66, MX-V4.3.4.83, MX-V4.4.0.31, MX-V4.4.0.31.r1, MX-V4.4.1.55, MX-V4.4.1.56, MX-V4.4.2.34, MX-V4.4.2.51.r1, MX-V4.4.2.69, MX-V4.4.2.73 P3 V15D: MX-V4.1.4.11, MX-V4.1.4.70, MX-V4.1.6.25, MX-V4.1.6.27, MX-V4.1.9.29, MX-V4.1.10.28, MX-V4.1.10.35, MX-V4.2.1.43, MX-V4.2.1.61, MX-V4.3.0.15, MX-V4.3.2.45, MX-V4.3.2.53, MX-V4.3.2.68, MX-V4.3.2.72, MX-V4.3.2.77, MX-V4.3.4.50, MX-V4.3.4.66, MX-V4.3.4.83, MX-V4.4.0.31, MX-V4.4.0.31.r1, MX-V4.4.1.55, MX-V4.4.1.56, MX-V4.4.2.34, MX-V4.4.2.51.r1, MX-V4.4.2.69, MX-V4.4.2.73 Mx6 D16: MX-V5.0.0.127, MX-V5.0.0.130, MX-V5.0.0.133, MX-V5.0.1.53, MX-V5.0.2.14, MX-V5.1.0.99, MX-V5.1.0.99-r3, MX-V5.1.0.99-r4 Mx6 M16: MX-V5.0.0.127, MX-V5.0.0.130, MX-V5.0.0.133, MX-V5.0.1.53, MX-V5.0.2.14, MX-V5.1.0.99, MX-V5.1.0.99-r3, MX-V5.1.0.99-r4 Mx6 S16: MX-V5.0.0.127, MX-V5.0.0.130, MX-V5.0.0.133, MX-V5.0.1.53, MX-V5.0.2.14, MX-V5.1.0.99, MX-V5.1.0.99-r3, MX-V5.1.0.99-r4 Mx6 V16: MX-V5.0.0.127, MX-V5.0.0.130, MX-V5.0.0.133, MX-V5.0.1.53, MX-V5.0.2.14, MX-V5.1.0.99, MX-V5.1.0.99-r3, MX-V5.1.0.99-r4 Mx6 D26: MX-V5.0.0.127, MX-V5.0.0.130, MX-V5.0.0.133, MX-V5.0.1.53, MX-V5.0.2.14, MX-V5.1.0.99, MX-V5.1.0.99-r3, MX-V5.1.0.99-r4 Mx6 M26: MX-V5.0.0.127, MX-V5.0.0.130, MX-V5.0.0.133, MX-V5.0.1.53, MX-V5.0.2.14, MX-V5.1.0.99, MX-V5.1.0.99-r3, MX-V5.1.0.99-r4 Mx6 Q26: MX-V5.0.0.127, MX-V5.0.0.130, MX-V5.0.0.133, MX-V5.0.1.53, MX-V5.0.2.14, MX-V5.1.0.99, MX-V5.1.0.99-r3, MX-V5.1.0.99-r4 Mx6 S26: MX-V5.0.0.127, MX-V5.0.0.130, MX-V5.0.0.133, MX-V5.0.1.53, MX-V5.0.2.14, MX-V5.1.0.99, MX-V5.1.0.99-r3, MX-V5.1.0.99-r4 Mx6 T26: MX-V5.0.0.127, MX-V5.0.0.130, MX-V5.0.0.133, MX-V5.0.1.53, MX-V5.0.2.14, MX-V5.1.0.99, MX-V5.1.0.99-r3, MX-V5.1.0.99-r4 Mx6 c26: MX-V5.0.0.127, MX-V5.0.0.130, MX-V5.0.0.133, MX-V5.0.1.53, MX-V5.0.2.14, MX-V5.1.0.99, MX-V5.1.0.99-r3, MX-V5.1.0.99-r4 Mx6 i26: MX-V5.0.0.127, MX-V5.0.0.130, MX-V5.0.0.133, MX-V5.0.1.53, MX-V5.0.2.14, MX-V5.1.0.99, MX-V5.1.0.99-r3, MX-V5.1.0.99-r4 Mx6 p26: MX-V5.0.0.127, MX-V5.0.0.130, MX-V5.0.0.133, MX-V5.0.1.53, MX-V5.0.2.14, MX-V5.1.0.99, MX-V5.1.0.99-r3, MX-V5.1.0.99-r4 Mx6 v26: MX-V5.0.0.127, MX-V5.0.0.130, MX-V5.0.0.133, MX-V5.0.1.53, MX-V5.0.2.14, MX-V5.1.0.99, MX-V5.1.0.99-r3, MX-V5.1.0.99-r4.",CVE-2023-34873,8.7,High,CWE-146,Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2965,8/22/2024,8/22/2024,2024,ICSA-24-235-04,Avtec Outpost 0810,Avtec,"Outpost 0810, Outpost Uploader Utility",The following Avtec products are affected: Outpost 0810: Versions prior to v5.0.0 Outpost Uploader Utility: Versions prior to v5.0.0.,"CVE-2024-39776, CVE-2024-42418",8.7,High,"CWE-219, CWE-321",Communications,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2964,8/15/2024,8/15/2024,2024,ICSA-24-228-01,"Siemens SCALANCE M-800, RUGGEDCOM RM1224",Siemens,"RUGGEDCOM RM1224, SCALANCE M-800 Family","The following products of Siemens, are affected: Siemens RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2): Versions prior to V8.1 Siemens RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2): Versions prior to V8.1 Siemens SCALANCE M804PB (6GK5804-0AP00-2AA2): Versions prior to V8.1 Siemens SCALANCE M812-1 ADSL-Router family: Versions prior to V8.1 Siemens SCALANCE M816-1 ADSL-Router family: Versions prior to V8.1 Siemens SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2): Versions prior to V8.1 Siemens SCALANCE M874-2 (6GK5874-2AA00-2AA2): Versions prior to V8.1 Siemens SCALANCE M874-3 3G-Router (CN) (6GK5874-3AA00-2FA2): Versions prior to V8.1 Siemens SCALANCE M874-3 (6GK5874-3AA00-2AA2): Versions prior to V8.1 Siemens SCALANCE M876-3 (6GK5876-3AA02-2BA2): Versions prior to V8.1 Siemens SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2): Versions prior to V8.1 Siemens SCALANCE M876-4 (6GK5876-4AA10-2BA2): Versions prior to V8.1 Siemens SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2): Versions prior to V8.1 Siemens SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2): Versions prior to V8.1 Siemens SCALANCE MUM853-1 (A1) (6GK5853-2EA10-2AA1): Versions prior to V8.1 Siemens SCALANCE MUM853-1 (B1) (6GK5853-2EA10-2BA1): Versions prior to V8.1 Siemens SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1): Versions prior to V8.1 Siemens SCALANCE MUM856-1 (A1) (6GK5856-2EA10-3AA1): Versions prior to V8.1 Siemens SCALANCE MUM856-1 (B1) (6GK5856-2EA10-3BA1): Versions prior to V8.1 Siemens SCALANCE MUM856-1 (CN) (6GK5856-2EA00-3FA1): Versions prior to V8.1 Siemens SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1): Versions prior to V8.1 Siemens SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1): Versions prior to V8.1 Siemens SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2): Versions prior to V8.1 Siemens SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2): Versions prior to V8.1.","CVE-2023-44321, CVE-2024-41976, CVE-2024-41977, CVE-2024-41978",8.6,High,"CWE-400, CWE-20, CWE-488, CWE-532",Chemical; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2963,8/15/2024,8/15/2024,2024,ICSA-24-228-02,Siemens INTRALOG WMS,Siemens,INTRALOG WMS,"The following version of Siemens INTRALOG WMS, are affected: Siemens INTRALOG WMS: Versions prior to V4.","CVE-2024-0056, CVE-2024-30045",8.8,High,"CWE-319, CWE-122",Chemical; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2962,8/15/2024,8/15/2024,2024,ICSA-24-228-03,Siemens Teamcenter Visualization and JT2Go,Siemens,Teamcenter Visualization and JT2Go,"The following versions of Siemens Teamcenter Visualization and JT2Go, are affected: Siemens JT2Go: Versions prior to V2312.0005 Siemens Teamcenter Visualization V14.2: Versions prior to V14.2.0.12 Siemens Teamcenter Visualization V14.3: Versions prior to V14.3.0.10 Siemens Teamcenter Visualization V2312: Versions prior to V2312.0005.","CVE-2024-32635, CVE-2024-32636, CVE-2024-32637",7.3,High,"CWE-125, CWE-476",Chemical; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2961,8/15/2024,8/15/2024,2024,ICSA-24-228-04,Siemens SINEC Traffic Analyzer,Siemens,SINEC Traffic Analyzer,"The following products of Siemens, are affected: Siemens SINEC Traffic Analyzer (6GK8822-1BG01-0BA0): versions prior to V2.0.","CVE-2024-41903, CVE-2024-41904, CVE-2024-41905, CVE-2024-41906, CVE-2024-41907",8.7,High,"CWE-269, CWE-307, CWE-284, CWE-524, CWE-358",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2960,8/15/2024,8/15/2024,2024,ICSA-24-228-05,Siemens LOGO! V8.3 BM Devices,Siemens,LOGO! V8.3 BM Devices,"The following products of Siemens, are affected: Siemens LOGO! 12/24RCE (6ED1052-1MD08-0BA1): All versions Siemens LOGO! 12/24RCEo (6ED1052-2MD08-0BA1): All versions Siemens LOGO! 24CE (6ED1052-1CC08-0BA1): All versions Siemens LOGO! 24CEo (6ED1052-2CC08-0BA1): All versions Siemens LOGO! 24RCE (6ED1052-1HB08-0BA1): All versions Siemens LOGO! 24RCEo (6ED1052-2HB08-0BA1): All versions Siemens LOGO! 230RCE (6ED1052-1FB08-0BA1): All versions Siemens LOGO! 230RCEo (6ED1052-2FB08-0BA1): All versions Siemens SIPLUS LOGO! 12/24RCE (6AG1052-1MD08-7BA1): All versions Siemens SIPLUS LOGO! 12/24RCEo (6AG1052-2MD08-7BA1): All versions Siemens SIPLUS LOGO! 24CE (6AG1052-1CC08-7BA1): All versions Siemens SIPLUS LOGO! 24CEo (6AG1052-2CC08-7BA1): All versions Siemens SIPLUS LOGO! 24RCE (6AG1052-1HB08-7BA1): All versions Siemens SIPLUS LOGO! 24RCEo (6AG1052-2HB08-7BA1): All versions Siemens SIPLUS LOGO! 230RCE (6AG1052-1FB08-7BA1): All versions Siemens SIPLUS LOGO! 230RCEo (6AG1052-2FB08-7BA1): All versions.",CVE-2024-39922,5.1,Medium,CWE-256,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2959,8/15/2024,8/15/2024,2024,ICSA-24-228-06,Siemens SINEC NMS,Siemens,SINEC NMS,"The following products of Siemens, are affected: SINEC NMS: versions prior to V3.0.","CVE-2023-31122, CVE-2023-34050, CVE-2023-39615, CVE-2023-42794, CVE-2023-42795, CVE-2023-43622, CVE-2023-44487, CVE-2023-45648, CVE-2023-45802, CVE-2023-4611, CVE-2023-46120, CVE-2023-46280, CVE-2023-46589, CVE-2023-52425, CVE-2023-52426, CVE-2023-5868, CVE-2023-5869, CVE-2023-5870, CVE-2023-6378, CVE-2023-6481, CVE-2024-0985, CVE-2024-25062, CVE-2024-28182, CVE-2024-28757, CVE-2024-36398, CVE-2024-41938, CVE-2024-41939, CVE-2024-41940, CVE-2024-41941",9.4,Critical,"CWE-416, CWE-20, CWE-502, CWE-119, CWE-400, CWE-125, CWE-776, CWE-271, CWE-770, CWE-250, CWE-22, CWE-863",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2958,8/15/2024,8/15/2024,2024,ICSA-24-228-07,Siemens Location Intelligence,Siemens,Location Intelligence,"The following versions of Siemens Location Intelligence, a web-based application software, are affected: Location Intelligence: All versions prior to V4.4.","CVE-2024-41681, CVE-2024-41682, CVE-2024-41683",6.9,Medium,"CWE-326, CWE-307, CWE-521",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2957,8/15/2024,8/15/2024,2024,ICSA-24-228-08,Siemens COMOS,Siemens,COMOS,"The following versions of Siemens COMOS, a unified data platform, are affected: COMOS: All versions prior to V10.5.","CVE-2023-26495, CVE-2023-5180",7.8,High,"CWE-787, CWE-416",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2956,8/15/2024,8/15/2024,2024,ICSA-24-228-09,Siemens NX,Siemens,NX,"The following versions of Siemens NX, an integrated toolset, are affected: NX: All versions prior to V2406.3000.",CVE-2024-41908,7.3,High,CWE-125,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2955,8/15/2024,8/15/2024,2024,ICSA-24-228-10,AVEVA Historian Web Server,AVEVA,Historian Server,"The following versions of AVEVA Historian Server, a Process database, are affected: Historian Server: Version 2023 R2 Historian Server: Versions 2023 to 2023 P03 Historian Server: Versions 2020 to 2020 R2 SP1 P01.",CVE-2024-6456,8.5,High,CWE-89,Critical Manufacturing,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2954,8/15/2024,8/15/2024,2024,ICSA-24-228-11,PTC Kepware ThingWorx Kepware Server,PTC,Kepware ThingWorx Kepware Server,PTC reports that the following products and versions are affected: PTC Kepware ThingWorx Kepware Server: V6 PTC Kepware KEPServerEX: V6 Software Toolbox TOP Server: V6 GE IGS: V7.6x.,CVE-2024-6098,5.9,Medium,CWE-770,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2953,8/13/2024,8/13/2024,2024,ICSA-24-226-01,AVEVA SuiteLink Server,AVEVA,SuiteLink Server,"The following AVEVA products with AVEVA SuiteLink Server installed, are affected: SuiteLink: Versions 3.7.0 and prior Historian: Versions 2023 R2 P01 and prior InTouch: Versions 2023 R2 P01 and prior Application Server: Versions 2023 R2 P01 and prior Communication Drivers Pack: Versions 2023 R2 and prior Batch Management: Versions 2023 and prior.",CVE-2024-7113,8.7,High,CWE-770,Critical Manufacturing,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2952,8/13/2024,8/13/2024,2024,ICSA-24-226-02,Rockwell Automation AADvance Standalone OPC-DA Server,Rockwell Automation,AADvance Standalone OPC-DA Server,The following versions of Rockwell Automation AADvance Standalone OPC-DA Server are affected: AADvance Standalone OPC-DA Server: Versions v2.01.510 and later.,"CVE-2006-0743, CVE-2018-1285",9.8,Critical,"CWE-20, CWE-134",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2951,8/13/2024,8/13/2024,2024,ICSA-24-226-03,Rockwell Automation GuardLogix/ControlLogix 5580 Controller,Rockwell Automation,"ControlLogix 5580, GuardLogix 5580","The following versions of Rockwell Automation GuardLogix/ControlLogix 5580, programmable logic controllers, are affected: ControlLogix 5580: Versions v34.011 and later GuardLogix 5580: Versions v34.011 and later.",CVE-2024-40619,8.7,High,CWE-754,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2950,8/13/2024,8/13/2024,2024,ICSA-24-226-04,Rockwell Automation Pavilion8,Rockwell Automation,Pavilion8,"The following versions Rockwell Automation Pavilion8, a model predictive control software, are affected: Pavilion8: Versions v5.20 and later.",CVE-2024-40620,5.3,Medium,CWE-311,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2949,8/13/2024,8/13/2024,2024,ICSA-24-226-05,Rockwell Automation DataMosaix Private Cloud,Rockwell Automation,DataMosaix Private Cloud,The following versions of Rockwell Automation's DataMosaix Private Cloud are affected: DataMosaix Private Cloud: Versions prior to 7.07.,CVE-2024-6078,8.6,High,CWE-287,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2948,8/13/2024,8/29/2024,2024,ICSA-24-226-06,Rockwell Automation FactoryTalk View Site Edition (Update A),Rockwell Automation,FactoryTalk View Site Edition,"Rockwell Automation reports that the following versions of FactoryTalk, an HMI application, are affected: FactoryTalk View SE: version 13.0.",CVE-2024-7513,8.5,High,CWE-732,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Government Facilities; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2947,8/13/2024,8/13/2024,2024,ICSA-24-226-07,Rockwell Automation Micro850/870,Rockwell Automation,Micro850/870,Rockwell Automation reports that the following versions of Micro850/870 programmable controllers are affected: PLC - Micro850/870 (2080 -L50E/2080 -L70E): versions prior to v22.011.,CVE-2024-7567,6.9,Medium,CWE-400,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2946,8/13/2024,8/13/2024,2024,ICSA-24-226-08,Ocean Data Systems Dream Report,Ocean Data Systems,Dream Report 2023,"The following components of Ocean Data Systems Dream Report, a report generating and delivery software, are affected: Dream Report 2023: Version 23.0.17795.1010 and prior AVEVA Reports for Operations 2023: Version 23.0.17795.1010.","CVE-2024-6618, CVE-2024-6619",8.5,High,"CWE-22, CWE-732",Critical Manufacturing; Chemical; Energy; Water and Wastewater Systems,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2945,8/13/2024,8/13/2024,2024,ICSA-24-226-09,"Rockwell Automation ControlLogix, GuardLogix 5580, CompactLogix, Compact GuardLogix 5380",Rockwell Automation,"ControlLogix, GuardLogix 5580, CompactLogix, Compact GuardLogix 5380","The following Rockwell Automation products are affected: CompactLogix 5380 (5069 - L3z): Versions prior to v36.011, v35.013, v34.014 CompactLogix 5480 (5069 - L4): Versions prior to v36.011, v35.013, v34.014 ControlLogix 5580 (1756 - L8z): Versions prior to v36.011, v35.013, v34.014 GuardLogix 5580 (1756 - L8z): Versions prior to v36.011, v35.013, v34.014 Compact GuardLogix 5380 (5069 - L3zS2): Versions prior to v36.011, v35.013, v34.014.",CVE-2024-7507,8.7,High,CWE-20,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2944,8/13/2024,8/13/2024,2024,ICSA-24-226-10,"Rockwell Automation ControlLogix, GuardLogix 5580, CompactLogix, and Compact GuardLogix 5380",Rockwell Automation,"CompactLogix 5380, ControlLogix 5580, GuardLogix 5580, Compact GuardLogix 5380, CompactLogix 5480","The following Rockwell Automation products are affected: CompactLogix 5380 (5069 - L3z): Versions prior to v36.011, v35.013, v34.014 CompactLogix 5480 (5069 - L4): Versions prior to v36.011, v35.013, v34.014 ControlLogix 5580 (1756 - L8z): Versions prior to v36.011, v35.013, v34.014 GuardLogix 5580 (1756 - L8z): Versions prior to v36.011, v35.013, v34.014 Compact GuardLogix 5380 (5069 - L3zS2): Versions prior to v36.011, v35.013, v34.014.",CVE-2024-7515,8.7,High,CWE-20,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2943,8/8/2024,8/8/2024,2024,ICSA-24-221-01,Dorsett Controls InfoScan,Dorsett Controls,InfoScan,"The following Dorsett Controls products are affected: InfoScan: v1.32, v1.33, and v1.35.","CVE-2024-42493, CVE-2024-42408, CVE-2024-39287",6.9,Medium,"CWE-200, CWE-22",Water and Wastewater Systems,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2942,8/6/2024,8/6/2024,2024,ICSA-24-219-01,Delta Electronics DIAScreen,Delta Electronics,DIAScreen,The following versions of Delta Electronics DIAScreen visualization software are affected: DIAScreen: Versions prior to 1.4.2.,CVE-2024-7502,8.5,High,CWE-121,Energy,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2941,8/1/2024,8/1/2024,2024,ICSA-24-214-01,Johnson Controls exacqVision Client and exacqVision Server,Johnson Controls Inc.,"exacqVision Client, exacqVision Server key",Johnson Controls reports that the following versions of exacqVision client and exacqVision server are affected: exacqVision client: All versions exacqVision server: All versions.,CVE-2024-32758,9.0,Critical,CWE-326,Critical Manufacturing; Commercial Facilities; Government Facilities; Transportation Systems; Energy,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2940,8/1/2024,8/1/2024,2024,ICSA-24-214-02,Johnson Controls exacqVision Server Web Service,Johnson Controls Inc.,exacqVision Web Service,Johnson Controls reports that the following versions of exacqVision Web Service are affected: exacqVision Web Service: 22.12.1.0.,CVE-2024-32862,7.6,High,CWE-942,Critical Manufacturing; Commercial Facilities; Government Facilities; Transportation Systems; Energy,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2939,8/1/2024,8/1/2024,2024,ICSA-24-214-03,Johnson Controls exacqVision Web Service,Johnson Controls Inc.,exacqVision Web Service,The following versions of Johnson Controls exacqVision Web Service are affected: exacqVision Web Service: Versions 24.03 and prior.,CVE-2024-32863,6.8,Medium,CWE-352,Critical Manufacturing; Commercial Facilities; Government Facilities; Transportation Systems; Energy,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2938,8/1/2024,8/1/2024,2024,ICSA-24-214-04,Johnson Controls exacqVision Web Service,Johnson Controls Inc.,exacqVision Web Service,The following versions of Johnson Controls exacqVision Web Service are affected: exacqVision Web Service: Versions 24.03 and prior.,CVE-2024-32864,6.4,Medium,CWE-319,Critical Manufacturing; Commercial Facilities; Government Facilities; Transportation Systems; Energy,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2937,8/1/2024,8/1/2024,2024,ICSA-24-214-05,Johnson Controls exacqVision Web Service,Johnson Controls Inc.,exacqVision Server,The following versions of Johnson Controls exacqVision Server are affected: exacqVision Server: Versions 24.03 and prior.,CVE-2024-32865,6.4,Medium,CWE-295,Critical Manufacturing; Commercial Facilities; Government Facilities; Transportation Systems; Energy,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2936,8/1/2024,8/1/2024,2024,ICSA-24-214-06,Johnson Controls exacqVision Web Service,Johnson Controls Inc.,Web Service,The following versions of Johnson Controls exacqVision Web Service are affected: exacqVision Web Service: Versions 24.03 and prior.,CVE-2024-32931,5.7,Medium,CWE-598,Critical Manufacturing; Commercial Facilities; Government Facilities; Transportation Systems; Energy,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2935,8/1/2024,8/1/2024,2024,ICSA-24-214-07,AVTECH IP Camera,AVTECH SECURITY Corporation,IP camera,The following AVTECH IP camera was identified as being affected; it is suspected that prior versions of other IP cameras and NVR (network video recorder) products are also affected: AVM1203: firmware version FullImg-1023-1007-1011-1009 and prior.,CVE-2024-7029,9.3,Critical,CWE-77,Commercial Facilities; Financial Services; Healthcare and Public Health; Transportation Systems,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2934,8/1/2024,8/1/2024,2024,ICSA-24-214-08,Vonets WiFi Bridges,Vonets,"VAR1200-H, VAR1200-L, VAR600-H, VAP11AC, VAP11G-500S, VBG1200, VAP11S-5G, VAP11S, VAR11N-300, VAP11G-300, VAP11N-300, VAP11G, VAP11G-500, VBG1200, VAP11AC, VGA-1000",At least the following Vonets products are affected: VAR1200-H: Versions 3.3.23.6.9 and prior VAR1200-L: Versions 3.3.23.6.9 and prior VAR600-H: Versions 3.3.23.6.9 and prior VAP11AC: Versions 3.3.23.6.9 and prior VAP11G-500S: Versions 3.3.23.6.9 and prior VBG1200: Versions 3.3.23.6.9 and prior VAP11S-5G: Versions 3.3.23.6.9 and prior VAP11S: Versions 3.3.23.6.9 and prior VAR11N-300: Versions 3.3.23.6.9 and prior VAP11G-300: Versions 3.3.23.6.9 and prior VAP11N-300: Versions 3.3.23.6.9 and prior VAP11G: Versions 3.3.23.6.9 and prior VAP11G-500: Versions 3.3.23.6.9 and prior VBG1200: Versions 3.3.23.6.9 and prior VAP11AC: Versions 3.3.23.6.9 and prior VGA-1000: Versions 3.3.23.6.9 and prior.,"CVE-2024-29082, CVE-2024-37023, CVE-2024-39791, CVE-2024-39815, CVE-2024-41161, CVE-2024-41936, CVE-2024-42001",10.0,Critical,"CWE-798, CWE-284, CWE-22, CWE-77, CWE-703, CWE-121, CWE-425",Communications,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2933,8/1/2024,8/1/2024,2024,ICSA-24-214-09,Rockwell Automation Logix Controllers,Rockwell Automation,"ControlLogix, GuardLogix, and 1756 ControlLogix I/O Modules","The following versions of ControlLogix, GuardLogix, and 1756 ControlLogix I/O Modules are affected: ControlLogix: Version V28 GuardLogix: Version V31 1756-EN4TR: Version V2 1756-EN2T, Series A/B/C (unsigned version): Version v5.007 1756-EN2F, Series A/B (unsigned version): Version v5.007 1756-EN2TR, Series A/B (unsigned version): Version v5.007 1756-EN3TR, Series B (unsigned version): Version v5.007 1756-EN2T, Series A/B/C (signed version): Version v5.027 1756-EN2F, Series A/B (signed version): Version v5.027 1756-EN2TR, Series A/B (signed version): Version v5.027 1756-EN3TR, Series B (signed version): Version v5.027 1756-EN2T, Series D: Version V10.006 1756-EN2F, Series C: Version V10.009 1756-EN2TR, Series C: Version V10.007 1756-EN3TR, Series B: Version V10.007 1756-EN2TP, Series A: Version V10.020.",CVE-2024-6242,7.3,High,CWE-420,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2932,7/25/2024,7/25/2024,2024,ICSA-24-207-01,Siemens SICAM Products,Siemens,"CPCI85 for CP-8031/CP-8050, CPCI85, SICORE",The following Siemens SICAM product versions are affected: CPCI85 Central Processing/Communication: All versions prior to V5.40 SICORE Base system: All versions prior to V1.4.0.,"CVE-2024-37998, CVE-2024-39601",9.3,Critical,"CWE-620, CWE-306",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2931,7/25/2024,7/25/2024,2024,ICSA-24-207-02,Positron Broadcast Signal Processor,Positron S.R.L,Broadcast Signal Processor TRA7005,The following versions of Positron Broadcast Signal Processor are affected: Broadcast Signal Processor TRA7005: v1.20.,CVE-2024-7007,8.7,High,CWE-288,Communications,Italy,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2930,7/23/2024,7/23/2024,2024,ICSA-24-205-01,National Instruments IO Trace,National Instruments Corp (NI),IO Trace,The following National Instruments I/O TRACE bundled products are affected: I/O TRACE: All versions.,CVE-2024-5602,8.4,High,CWE-121,Critical Manufacturing; Defense Industrial Base; Information Technology; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2929,7/23/2024,7/23/2024,2024,ICSA-24-205-02,Hitachi Energy AFS/AFR Series Products,Hitachi Energy,"AFS650, AFS660, AFS665, AFS670, AFS675, AFS677, AFR677",The following versions of Hitachi Energy AFS/AFR are affected: AFS650: Version 9.1.08 and prior AFS660-C: Version 7.1.05 and prior AFS665-B: Version 7.1.05 and prior AFS670-V2: Version 7.1.05 and prior AFS670: Version 9.1.08 and prior AFS675: Version 9.1.08 and prior AFS677: Version 9.1.08 and prior AFR677: Version 9.1.08 and prior.,"CVE-2023-0286, CVE-2023-0215, CVE-2022-4450, CVE-2022-4304",7.5,High,"CWE-843, CWE-416, CWE-415, CWE-203",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2928,7/23/2024,7/23/2024,2024,ICSA-24-205-03,National Instruments LabVIEW,National Instruments Corp (NI),LabVIEW,The following National Instruments LabVIEW products are affected: LabVIEW: Versions 24.1f0 and prior.,"CVE-2024-4079, CVE-2024-4080, CVE-2024-4081",8.4,High,"CWE-125, CWE-119",Critical Manufacturing; Defense Industrial Base; Information Technology; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2927,7/18/2024,5/15/2025,2024,ICSA-24-200-01,Mitsubishi Electric MELSOFT MaiLab and MELSOFT VIXIO (Update A),Mitsubishi Electric,"MELSOFT MaiLab, MELSOFT VIXIO",Mitsubishi Electric reports the following versions of MELSOFT MaiLab and MELSOFT VIXIO are affected: MELSOFT MaiLab SW1DND-MAILAB-M: Versions 1.00A to 1.05F MELSOFT MaiLab SW1DND-MAILABPR-M: Versions 1.00A to 1.05F MELSOFT VIXIO SW1DND-AIVILE-M: Versions 1.00A to 1.03D MELSOFT VIXIO SW1DND-AIVIIN-M: Versions 1.00A to 1.03D.,CVE-2023-4807,8.2,High,CWE-347,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2926,7/18/2024,7/18/2024,2024,ICSA-24-200-02,Subnet Solutions PowerSYSTEM Center,SUBNET Solutions Inc.,Subnet PowerSYSTEM Center,The following versions of Subnet PowerSYSTEM Center are affected: PowerSYSTEM Center 2020: Update 20 and prior.,CVE-2023-26136,6.9,Medium,CWE-1321,Critical Manufacturing; Energy,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2925,7/18/2024,11/26/2024,2024,ICSMA-24-200-01,Philips Vue PACS (Update A),Philips,Vue PACS,The following Philips products are affected: Vue PACS: Versions prior to 12.2.8.410.,"CVE-2021-28165, CVE-2023-40704",6.0,Medium,"CWE-770, CWE-1392",Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2924,7/16/2024,7/16/2024,2024,ICSA-24-198-01,Rockwell Automation Pavilion8,Rockwell Automation,Pavilion8,"The following versions of Rockwell Automation Pavilion 8, a Model Predictive Control (MPC) solution, are affected: Pavilion 8: Versions 5.15.00 to 5.20.00.",CVE-2024-6435,8.7,High,CWE-732,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2923,7/11/2024,7/11/2024,2024,ICSA-24-193-01,Siemens Remote Connect Server,Siemens,Remote Connect Server,"The following products of Siemens, are affected: Siemens SINEMA Remote Connect Server: All versions prior to V3.2 SP1.","CVE-2022-32260, CVE-2024-39865, CVE-2024-39866, CVE-2024-39867, CVE-2024-39868, CVE-2024-39869, CVE-2024-39870, CVE-2024-39871, CVE-2024-39872, CVE-2024-39873, CVE-2024-39874, CVE-2024-39875, CVE-2024-39876",9.6,Critical,"CWE-286, CWE-434, CWE-267, CWE-425, CWE-754, CWE-602, CWE-863, CWE-378, CWE-307, CWE-732, CWE-770","Critical Manufacturing; Energy; Nuclear Reactors, Materials, and Waste",Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2922,7/11/2024,7/11/2024,2024,ICSA-24-193-02,Siemens RUGGEDCOM APE 1808,Siemens,RUGGEDCOM APE 1808,"The following products of Siemens, are affected: Siemens RUGGEDCOM APE1808: All versions with Fortinet NGFW.","CVE-2023-46720, CVE-2024-21754, CVE-2024-23111, CVE-2024-26010",7.5,High,"CWE-121, CWE-916, CWE-79",Communications; Critical Manufacturing; Energy; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2921,7/11/2024,7/11/2024,2024,ICSA-24-193-03,Siemens Teamcenter Visualization and JT2Go,Siemens,"Teamcenter Visualization, JT2Go","The following products of Siemens, are affected: Siemens JT2Go: Versions prior to v14.3.0.8 Siemens Teamcenter Visualization V14.1: Versions prior to v14.1.0.14 Siemens Teamcenter Visualization V14.2: Versions prior to v14.2.0.10 Siemens Teamcenter Visualization V14.3: Versions prior to v14.3.0.8 Siemens Teamcenter Visualization V2312: Versions prior to v2312.0002.",CVE-2023-7066,7.8,High,CWE-125,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2920,7/11/2024,7/11/2024,2024,ICSA-24-193-04,Siemens Simcenter Femap,Siemens,Simcenter Femap,The following Siemens products are affected: Simcenter Femap: Versions prior to V2406.,"CVE-2024-32055, CVE-2024-32056, CVE-2024-32057, CVE-2024-32058, CVE-2024-32059, CVE-2024-32060, CVE-2024-32061, CVE-2024-32062, CVE-2024-32063, CVE-2024-32064, CVE-2024-32065, CVE-2024-32066, CVE-2024-33577, CVE-2024-33653, CVE-2024-33654",7.3,High,"CWE-125, CWE-787, CWE-843, CWE-119, CWE-843, CWE-121",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2919,7/11/2024,7/11/2024,2024,ICSA-24-193-05,"Siemens SCALANCE, RUGGEDCOM, SIPLUS, and SINEC",Siemens,"SCALANCE, RUGGEDCOM, SIPLUS, and SINEC","The following products of Siemens, are affected: RUGGEDCOM CROSSBOW: All versions RUGGEDCOM i800: All versions RUGGEDCOM i800NC: All versions RUGGEDCOM i801: All versions RUGGEDCOM i801NC: All versions RUGGEDCOM i802: All versions RUGGEDCOM i802NC: All versions RUGGEDCOM i803: All versions RUGGEDCOM i803NC: All versions RUGGEDCOM M969: All versions RUGGEDCOM M969NC: All versions RUGGEDCOM M2100: All versions RUGGEDCOM M2100NC: All versions RUGGEDCOM M2200: All versions RUGGEDCOM M2200NC: All versions RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2): All versions RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2): All versions RUGGEDCOM RMC30: All versions RUGGEDCOM RMC30NC: All versions RUGGEDCOM RMC8388 V4.X: All versions RUGGEDCOM RMC8388 V5.X: All versions RUGGEDCOM RMC8388NC V4.X: All versions RUGGEDCOM RMC8388NC V5.X: All versions RUGGEDCOM ROX MX5000: All versions RUGGEDCOM ROX MX5000RE: All versions RUGGEDCOM ROX RX1400: All versions RUGGEDCOM ROX RX1500: All versions RUGGEDCOM ROX RX1501: All versions RUGGEDCOM ROX RX1510: All versions RUGGEDCOM ROX RX1511: All versions RUGGEDCOM ROX RX1512: All versions RUGGEDCOM ROX RX1524: All versions RUGGEDCOM ROX RX1536: All versions RUGGEDCOM ROX RX5000: All versions RUGGEDCOM RP110: All versions* RUGGEDCOM RP110NC: All versions RUGGEDCOM RS400: All versions RUGGEDCOM RS400NC: All versions RUGGEDCOM RS401: All versions RUGGEDCOM RS401NC: All versions RUGGEDCOM RS416: All versions RUGGEDCOM RS416NC: All versions RUGGEDCOM RS416NCv2 V4.X: All versions RUGGEDCOM RS416NCv2 V5.X: All versions RUGGEDCOM RS416P: All versions RUGGEDCOM RS416PNC: All versions RUGGEDCOM RS416PNCv2 V4.X: All versions RUGGEDCOM RS416PNCv2 V5.X: All versions RUGGEDCOM RS416Pv2 V4.X: All versions RUGGEDCOM RS416Pv2 V5.X: All versions RUGGEDCOM RS416v2 V4.X: All versions RUGGEDCOM RS416v2 V5.X: All versions RUGGEDCOM RS900: All versions RUGGEDCOM RS900 (32M) V4.X: All versions RUGGEDCOM RS900 (32M) V5.X: All versions RUGGEDCOM RS900G: All versions RUGGEDCOM RS900G (32M) V4.X: All versions RUGGEDCOM RS900G (32M) V5.X: All versions RUGGEDCOM RS900GNC: All versions RUGGEDCOM RS900GNC(32M) V4.X: All versions RUGGEDCOM RS900GNC(32M) V5.X: All versions RUGGEDCOM RS900GP: All versions RUGGEDCOM RS900GPNC: All versions RUGGEDCOM RS900M-GETS-C01: All versions RUGGEDCOM RS900M-GETS-XX: All versions RUGGEDCOM RS900M-STND-C01: All versions RUGGEDCOM RS900M-STND-XX: All versions RUGGEDCOM RS900MNC-GETS-C01: All versions RUGGEDCOM RS900MNC-GETS-XX: All versions RUGGEDCOM RS900MNC-STND-XX: All versions RUGGEDCOM RS900MNC-STND-XX-C01: All versions RUGGEDCOM RS900NC: All versions RUGGEDCOM RS900NC(32M) V4.X: All versions RUGGEDCOM RS900NC(32M) V5.X: All versions RUGGEDCOM RS900W: All versions RUGGEDCOM RS910: All versions RUGGEDCOM RS910NC: All versions RUGGEDCOM RS910W: All versions RUGGEDCOM RS940G: All versions RUGGEDCOM RS940GNC: All versions RUGGEDCOM RS1600: All versions RUGGEDCOM RS1600F: All versions RUGGEDCOM RS1600FNC: All versions RUGGEDCOM RS1600NC: All versions RUGGEDCOM RS1600T: All versions RUGGEDCOM RS1600TNC: All versions RUGGEDCOM RS8000: All versions RUGGEDCOM RS8000A: All versions RUGGEDCOM RS8000ANC: All versions RUGGEDCOM RS8000H: All versions RUGGEDCOM RS8000HNC: All versions RUGGEDCOM RS8000NC: All versions RUGGEDCOM RS8000T: All versions RUGGEDCOM RS8000TNC: All versions RUGGEDCOM RSG907R: All versions RUGGEDCOM RSG908C: All versions RUGGEDCOM RSG909R: All versions RUGGEDCOM RSG910C: All versions RUGGEDCOM RSG920P V4.X: All versions RUGGEDCOM RSG920P V5.X: All versions RUGGEDCOM RSG920PNC V4.X: All versions RUGGEDCOM RSG920PNC V5.X: All versions RUGGEDCOM RSG2100: All versions RUGGEDCOM RSG2100 (32M) V4.X: All versions RUGGEDCOM RSG2100 (32M) V5.X: All versions RUGGEDCOM RSG2100NC: All versions RUGGEDCOM RSG2100NC(32M) V4.X: All versions RUGGEDCOM RSG2100NC(32M) V5.X: All versions RUGGEDCOM RSG2100P: All versions RUGGEDCOM RSG2100PNC: All versions RUGGEDCOM RSG2200: All versions RUGGEDCOM RSG2200NC: All versions RUGGEDCOM RSG2288 V4.X: All versions RUGGEDCOM RSG2288 V5.X: All versions RUGGEDCOM RSG2288NC V4.X: All versions RUGGEDCOM RSG2288NC V5.X: All versions RUGGEDCOM RSG2300 V4.X: All versions RUGGEDCOM RSG2300 V5.X: All versions RUGGEDCOM RSG2300NC V4.X: All versions RUGGEDCOM RSG2300NC V5.X: All versions RUGGEDCOM RSG2300P V4.X: All versions RUGGEDCOM RSG2300P V5.X: All versions RUGGEDCOM RSG2300PNC V4.X: All versions RUGGEDCOM RSG2300PNC V5.X: All versions RUGGEDCOM RSG2488 V4.X: All versions RUGGEDCOM RSG2488 V5.X: All versions RUGGEDCOM RSG2488NC V4.X: All versions RUGGEDCOM RSG2488NC V5.X: All versions RUGGEDCOM RSL910: All versions RUGGEDCOM RSL910NC: All versions RUGGEDCOM RST916C: All versions RUGGEDCOM RST916P: All versions RUGGEDCOM RST2228: All versions RUGGEDCOM RST2228P: All versions SCALANCE M804PB (6GK5804-0AP00-2AA2): All versions SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2): All versions SCALANCE M812-1 ADSL-Router (6GK5812-1BA00-2AA2): All versions SCALANCE M816-1 ADSL-Router (6GK5816-1AA00-2AA2): All versions SCALANCE M816-1 ADSL-Router (6GK5816-1BA00-2AA2): All versions SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2): All versions SCALANCE M874-2 (6GK5874-2AA00-2AA2): All versions SCALANCE M874-3 3G-Router (CN) (6GK5874-3AA00-2FA2): All versions SCALANCE M874-3 (6GK5874-3AA00-2AA2): All versions SCALANCE M876-3 (6GK5876-3AA02-2BA2): All versions SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2): All versions SCALANCE M876-4 (6GK5876-4AA10-2BA2): All versions SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2): All versions SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2): All versions SCALANCE MUM853-1 (A1) (6GK5853-2EA10-2AA1): All versions SCALANCE MUM853-1 (B1) (6GK5853-2EA10-2BA1): All versions SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1): All versions SCALANCE MUM856-1 (A1) (6GK5856-2EA10-3AA1): All versions SCALANCE MUM856-1 (B1) (6GK5856-2EA10-3BA1): All versions SCALANCE MUM856-1 (CN) (6GK5856-2EA00-3FA1): All versions SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1): All versions SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1): All versions SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2): All versions SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2): All versions SCALANCE SC622-2C (6GK5622-2GS00-2AC2): All versions SCALANCE SC626-2C (6GK5626-2GS00-2AC2): All versions SCALANCE SC632-2C (6GK5632-2GS00-2AC2): All versions SCALANCE SC636-2C (6GK5636-2GS00-2AC2): All versions SCALANCE SC642-2C (6GK5642-2GS00-2AC2): All versions SCALANCE SC646-2C (6GK5646-2GS00-2AC2): All versions SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0): All versions SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0): All versions SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0): All versions SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0): All versions SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0): All versions SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0): All versions SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6): All versions SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0): All versions SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6): All versions SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0): All versions SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0): All versions SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0): All versions SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0): All versions SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0): All versions SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0): All versions SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0): All versions SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0): All versions SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0): All versions SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0): All versions SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0): All versions SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6): All versions SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0): All versions SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0): All versions SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6): All versions SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0): All versions SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0): All versions SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0): All versions SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0): All versions SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0): All versions SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0): All versions SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0): All versions SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0): All versions SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0): All versions SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0): All versions SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0): All versions SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0): All versions SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0): All versions SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0): All versions SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0): All versions SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0): All versions SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0): All versions SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0): All versions SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0): All versions SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0): All versions SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0): All versions SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0): All versions SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0): All versions SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0): All versions SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0): All versions SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0): All versions SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0): All versions SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0): All versions SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0): All versions SCALANCE W1788-2 M12 (6GK5788-2GY01-0AA0): All versions SCALANCE W1788-2IA M12 (6GK5788-2HY01-0AA0): All versions SCALANCE WAM763-1 (6GK5763-1AL00-7DA0): All versions SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0): All versions SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0): All versions SCALANCE WAM766-1 (EU) (6GK5766-1GE00-7DA0): All versions SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0): All versions SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0): All versions SCALANCE WAM766-1 EEC (EU) (6GK5766-1GE00-7TA0): All versions SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0): All versions SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0): All versions SCALANCE WUM763-1 (6GK5763-1AL00-3AA0): All versions SCALANCE WUM763-1 (6GK5763-1AL00-3DA0): All versions SCALANCE WUM763-1 (US) (6GK5763-1AL00-3AB0): All versions SCALANCE WUM763-1 (US) (6GK5763-1AL00-3DB0): All versions SCALANCE WUM766-1 (EU) (6GK5766-1GE00-3DA0): All versions SCALANCE WUM766-1 (ME) (6GK5766-1GE00-3DC0): All versions SCALANCE WUM766-1 (US) (6GK5766-1GE00-3DB0): All versions SCALANCE X302-7 EEC (2x 24V) (6GK5302-7GD00-2EA3): Versions prior to V4.1.8 SCALANCE X302-7 EEC (2x 24V, coated) (6GK5302-7GD00-2GA3): Versions prior to V4.1.8 SCALANCE X302-7 EEC (2x 230V) (6GK5302-7GD00-4EA3): Versions prior to V4.1.8 SCALANCE X302-7 EEC (2x 230V, coated) (6GK5302-7GD00-4GA3): Versions prior to V4.1.8 SCALANCE X302-7 EEC (24V) (6GK5302-7GD00-1EA3): Versions prior to V4.1.8 SCALANCE X302-7 EEC (24V, coated) (6GK5302-7GD00-1GA3): Versions prior to V4.1.8 SCALANCE X302-7 EEC (230V) (6GK5302-7GD00-3EA3): Versions prior to V4.1.8 SCALANCE X302-7 EEC (230V, coated) (6GK5302-7GD00-3GA3): Versions prior to V4.1.8 SCALANCE X304-2FE (6GK5304-2BD00-2AA3): Versions prior to V4.1.8 SCALANCE X306-1LD FE (6GK5306-1BF00-2AA3): Versions prior to V4.1.8 SCALANCE X307-2 EEC (2x 24V) (6GK5307-2FD00-2EA3): Versions prior to V4.1.8 SCALANCE X307-2 EEC (2x 24V, coated) (6GK5307-2FD00-2GA3): Versions prior to V4.1.8 SCALANCE X307-2 EEC (2x 230V) (6GK5307-2FD00-4EA3): Versions prior to V4.1.8 SCALANCE X307-2 EEC (2x 230V, coated) (6GK5307-2FD00-4GA3): Versions prior to V4.1.8 SCALANCE X307-2 EEC (24V) (6GK5307-2FD00-1EA3): Versions prior to V4.1.8 SCALANCE X307-2 EEC (24V, coated) (6GK5307-2FD00-1GA3): Versions prior to V4.1.8 SCALANCE X307-2 EEC (230V) (6GK5307-2FD00-3EA3): Versions prior to V4.1.8 SCALANCE X307-2 EEC (230V, coated) (6GK5307-2FD00-3GA3): Versions prior to V4.1.8 SCALANCE X307-3 (6GK5307-3BL00-2AA3): Versions prior to V4.1.8 SCALANCE X307-3 (6GK5307-3BL10-2AA3): Versions prior to V4.1.8 SCALANCE X307-3LD (6GK5307-3BM00-2AA3): Versions prior to V4.1.8 SCALANCE X307-3LD (6GK5307-3BM10-2AA3): Versions prior to V4.1.8 SCALANCE X308-2 (6GK5308-2FL00-2AA3): Versions prior to V4.1.8 SCALANCE X308-2 (6GK5308-2FL10-2AA3): Versions prior to V4.1.8 SCALANCE X308-2LD (6GK5308-2FM00-2AA3): Versions prior to V4.1.8 SCALANCE X308-2LD (6GK5308-2FM10-2AA3): Versions prior to V4.1.8 SCALANCE X308-2LH (6GK5308-2FN00-2AA3): Versions prior to V4.1.8 SCALANCE X308-2LH (6GK5308-2FN10-2AA3): Versions prior to V4.1.8 SCALANCE X308-2LH+ (6GK5308-2FP00-2AA3): Versions prior to V4.1.8 SCALANCE X308-2LH+ (6GK5308-2FP10-2AA3): Versions prior to V4.1.8 SCALANCE X308-2M (6GK5308-2GG00-2AA2): Versions prior to V4.1.8 SCALANCE X308-2M (6GK5308-2GG10-2AA2): Versions prior to V4.1.8 SCALANCE X308-2M PoE (6GK5308-2QG00-2AA2): Versions prior to V4.1.8 SCALANCE X308-2M PoE (6GK5308-2QG10-2AA2): Versions prior to V4.1.8 SCALANCE X308-2M TS (6GK5308-2GG00-2CA2): Versions prior to V4.1.8 SCALANCE X308-2M TS (6GK5308-2GG10-2CA2): Versions prior to V4.1.8 SCALANCE X310 (6GK5310-0FA00-2AA3): Versions prior to V4.1.8 SCALANCE X310 (6GK5310-0FA10-2AA3): Versions prior to V4.1.8 SCALANCE X310FE (6GK5310-0BA00-2AA3): Versions prior to V4.1.8 SCALANCE X310FE (6GK5310-0BA10-2AA3): Versions prior to V4.1.8 SCALANCE X320-1 FE (6GK5320-1BD00-2AA3): Versions prior to V4.1.8 SCALANCE X320-1-2LD FE (6GK5320-3BF00-2AA3): Versions prior to V4.1.8 SCALANCE X408-2 (6GK5408-2FD00-2AA2): Versions prior to V4.1.8 SCALANCE XB205-3 (SC, PN) (6GK5205-3BB00-2AB2): All versions SCALANCE XB205-3 (ST, E/IP) (6GK5205-3BB00-2TB2): All versions SCALANCE XB205-3 (ST, E/IP) (6GK5205-3BD00-2TB2): All versions SCALANCE XB205-3 (ST, PN) (6GK5205-3BD00-2AB2): All versions SCALANCE XB205-3LD (SC, E/IP) (6GK5205-3BF00-2TB2): All versions SCALANCE XB205-3LD (SC, PN) (6GK5205-3BF00-2AB2): All versions SCALANCE XB208 (E/IP) (6GK5208-0BA00-2TB2): All versions SCALANCE XB208 (PN) (6GK5208-0BA00-2AB2): All versions SCALANCE XB213-3 (SC, E/IP) (6GK5213-3BD00-2TB2): All versions SCALANCE XB213-3 (SC, PN) (6GK5213-3BD00-2AB2): All versions SCALANCE XB213-3 (ST, E/IP) (6GK5213-3BB00-2TB2): All versions SCALANCE XB213-3 (ST, PN) (6GK5213-3BB00-2AB2): All versions SCALANCE XB213-3LD (SC, E/IP) (6GK5213-3BF00-2TB2): All versions SCALANCE XB213-3LD (SC, PN) (6GK5213-3BF00-2AB2): All versions SCALANCE XB216 (E/IP) (6GK5216-0BA00-2TB2): All versions SCALANCE XB216 (PN) (6GK5216-0BA00-2AB2): All versions SCALANCE XC206-2 (SC) (6GK5206-2BD00-2AC2): All versions SCALANCE XC206-2 (ST/BFOC) (6GK5206-2BB00-2AC2): All versions SCALANCE XC206-2G PoE (6GK5206-2RS00-2AC2): All versions SCALANCE XC206-2G PoE (54 V DC) (6GK5206-2RS00-5AC2): All versions SCALANCE XC206-2G PoE EEC (54 V DC) (6GK5206-2RS00-5FC2): All versions SCALANCE XC206-2SFP (6GK5206-2BS00-2AC2): All versions SCALANCE XC206-2SFP EEC (6GK5206-2BS00-2FC2): All versions SCALANCE XC206-2SFP G (6GK5206-2GS00-2AC2): All versions SCALANCE XC206-2SFP G (EIP DEF.) (6GK5206-2GS00-2TC2): All versions SCALANCE XC206-2SFP G EEC (6GK5206-2GS00-2FC2): All versions SCALANCE XC208 (6GK5208-0BA00-2AC2): All versions SCALANCE XC208EEC (6GK5208-0BA00-2FC2): All versions SCALANCE XC208G (6GK5208-0GA00-2AC2): All versions SCALANCE XC208G (EIP def.) (6GK5208-0GA00-2TC2): All versions SCALANCE XC208G EEC (6GK5208-0GA00-2FC2): All versions SCALANCE XC208G PoE (6GK5208-0RA00-2AC2): All versions SCALANCE XC208G PoE (54 V DC) (6GK5208-0RA00-5AC2): All versions SCALANCE XC216 (6GK5216-0BA00-2AC2): All versions SCALANCE XC216-3G PoE (6GK5216-3RS00-2AC2): All versions SCALANCE XC216-3G PoE (54 V DC) (6GK5216-3RS00-5AC2): All versions SCALANCE XC216-4C (6GK5216-4BS00-2AC2): All versions SCALANCE XC216-4C G (6GK5216-4GS00-2AC2): All versions SCALANCE XC216-4C G (EIP Def.) (6GK5216-4GS00-2TC2): All versions SCALANCE XC216-4C G EEC (6GK5216-4GS00-2FC2): All versions SCALANCE XC216EEC (6GK5216-0BA00-2FC2): All versions SCALANCE XC224 (6GK5224-0BA00-2AC2): All versions SCALANCE XC224-4C G (6GK5224-4GS00-2AC2): All versions SCALANCE XC224-4C G (EIP Def.) (6GK5224-4GS00-2TC2): All versions SCALANCE XC224-4C G EEC (6GK5224-4GS00-2FC2): All versions SCALANCE XCH328 (6GK5328-4TS01-2EC2): All versions SCALANCE XCM324 (6GK5324-8TS01-2AC2): All versions SCALANCE XCM328 (6GK5328-4TS01-2AC2): All versions SCALANCE XCM332 (6GK5332-0GA01-2AC2): All versions SCALANCE XF204 (6GK5204-0BA00-2GF2): All versions SCALANCE XF204 DNA (6GK5204-0BA00-2YF2): All versions SCALANCE XF204-2BA (6GK5204-2AA00-2GF2): All versions SCALANCE XF204-2BA DNA (6GK5204-2AA00-2YF2): All versions SCALANCE XM408-4C (6GK5408-4GP00-2AM2): All versions SCALANCE XM408-4C (L3 int.) (6GK5408-4GQ00-2AM2): All versions SCALANCE XM408-8C (6GK5408-8GS00-2AM2): All versions SCALANCE XM408-8C (L3 int.) (6GK5408-8GR00-2AM2): All versions SCALANCE XM416-4C (6GK5416-4GS00-2AM2): All versions SCALANCE XM416-4C (L3 int.) (6GK5416-4GR00-2AM2): All versions SCALANCE XP208 (6GK5208-0HA00-2AS6): All versions SCALANCE XP208 (Ethernet/IP) (6GK5208-0HA00-2TS6): All versions SCALANCE XP208EEC (6GK5208-0HA00-2ES6): All versions SCALANCE XP208PoE EEC (6GK5208-0UA00-5ES6): All versions SCALANCE XP216 (6GK5216-0HA00-2AS6): All versions SCALANCE XP216 (Ethernet/IP) (6GK5216-0HA00-2TS6): All versions SCALANCE XP216EEC (6GK5216-0HA00-2ES6): All versions SCALANCE XP216POE EEC (6GK5216-0UA00-5ES6): All versions SCALANCE XR324-4M EEC (2x 24V, ports on front) (6GK5324-4GG00-2ER2): Versions prior to V4.1.8 SCALANCE XR324-4M EEC (2x 24V, ports on front) (6GK5324-4GG10-2ER2): Versions prior to V4.1.8 SCALANCE XR324-4M EEC (2x 24V, ports on rear) (6GK5324-4GG00-2JR2): Versions prior to V4.1.8 SCALANCE XR324-4M EEC (2x 24V, ports on rear) (6GK5324-4GG10-2JR2): Versions prior to V4.1.8 SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front) (6GK5324-4GG00-4ER2): Versions prior to V4.1.8 SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front) (6GK5324-4GG10-4ER2): Versions prior to V4.1.8 SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG00-4JR2): Versions prior to V4.1.8 SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG10-4JR2): Versions prior to V4.1.8 SCALANCE XR324-4M EEC (24V, ports on front) (6GK5324-4GG00-1ER2): Versions prior to V4.1.8 SCALANCE XR324-4M EEC (24V, ports on front) (6GK5324-4GG10-1ER2): Versions prior to V4.1.8 SCALANCE XR324-4M EEC (24V, ports on rear) (6GK5324-4GG00-1JR2): Versions prior to V4.1.8 SCALANCE XR324-4M EEC (24V, ports on rear) (6GK5324-4GG10-1JR2): Versions prior to V4.1.8 SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front) (6GK5324-4GG00-3ER2): Versions prior to V4.1.8 SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front) (6GK5324-4GG10-3ER2): Versions prior to V4.1.8 SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG00-3JR2): Versions prior to V4.1.8 SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG10-3JR2): Versions prior to V4.1.8 SCALANCE XR324-4M PoE (24V, ports on front) (6GK5324-4QG00-1AR2): Versions prior to V4.1.8 SCALANCE XR324-4M PoE (24V, ports on front) (6GK5324-4QG10-1AR2): Versions prior to V4.1.8 SCALANCE XR324-4M PoE (24V, ports on rear) (6GK5324-4QG00-1HR2): Versions prior to V4.1.8 SCALANCE XR324-4M PoE (24V, ports on rear) (6GK5324-4QG10-1HR2): Versions prior to V4.1.8 SCALANCE XR324-4M PoE (230V, ports on front) (6GK5324-4QG00-3AR2): Versions prior to V4.1.8 SCALANCE XR324-4M PoE (230V, ports on front) (6GK5324-4QG10-3AR2): Versions prior to V4.1.8 SCALANCE XR324-4M PoE (230V, ports on rear) (6GK5324-4QG00-3HR2): Versions prior to V4.1.8 SCALANCE XR324-4M PoE (230V, ports on rear) (6GK5324-4QG10-3HR2): Versions prior to V4.1.8 SCALANCE XR324-4M PoE TS (24V, ports on front) (6GK5324-4QG00-1CR2): Versions prior to V4.1.8 SCALANCE XR324-4M PoE TS (24V, ports on front) (6GK5324-4QG10-1CR2): Versions prior to V4.1.8 SCALANCE XR324-12M (24V, ports on front) (6GK5324-0GG00-1AR2): Versions prior to V4.1.8 SCALANCE XR324-12M (24V, ports on front) (6GK5324-0GG10-1AR2): Versions prior to V4.1.8 SCALANCE XR324-12M (24V, ports on rear) (6GK5324-0GG00-1HR2): Versions prior to V4.1.8 SCALANCE XR324-12M (24V, ports on rear) (6GK5324-0GG10-1HR2): Versions prior to V4.1.8 SCALANCE XR324-12M (230V, ports on front) (6GK5324-0GG00-3AR2): Versions prior to V4.1.8 SCALANCE XR324-12M (230V, ports on front) (6GK5324-0GG10-3AR2): Versions prior to V4.1.8 SCALANCE XR324-12M (230V, ports on rear) (6GK5324-0GG00-3HR2): Versions prior to V4.1.8 SCALANCE XR324-12M (230V, ports on rear) (6GK5324-0GG10-3HR2): Versions prior to V4.1.8 SCALANCE XR324-12M TS (24V) (6GK5324-0GG00-1CR2): Versions prior to V4.1.8 SCALANCE XR324-12M TS (24V) (6GK5324-0GG10-1CR2): Versions prior to V4.1.8 SCALANCE XR324WG (24 x FE, AC 230V) (6GK5324-0BA00-3AR3): All versions SCALANCE XR324WG (24 X FE, DC 24V) (6GK5324-0BA00-2AR3): All versions SCALANCE XR326-2C PoE WG (6GK5326-2QS00-3AR3): All versions SCALANCE XR326-2C PoE WG (without UL) (6GK5326-2QS00-3RR3): All versions SCALANCE XR328-4C WG (24xFE,4xGE,AC230V) (6GK5328-4FS00-3AR3): All versions SCALANCE XR328-4C WG (24xFE,4xGE,AC230V) (6GK5328-4FS00-3RR3): All versions SCALANCE XR328-4C WG (24XFE, 4XGE, 24V) (6GK5328-4FS00-2AR3): All versions SCALANCE XR328-4C WG (24xFE, 4xGE,DC24V) (6GK5328-4FS00-2RR3): All versions SCALANCE XR328-4C WG (28xGE, AC 230V) (6GK5328-4SS00-3AR3): All versions SCALANCE XR328-4C WG (28xGE, DC 24V) (6GK5328-4SS00-2AR3): All versions SCALANCE XR524-8C, 1x230V (6GK5524-8GS00-3AR2): All versions SCALANCE XR524-8C, 1x230V (L3 int.) (6GK5524-8GR00-3AR2): All versions SCALANCE XR524-8C, 2x230V (6GK5524-8GS00-4AR2): All versions SCALANCE XR524-8C, 2x230V (L3 int.) (6GK5524-8GR00-4AR2): All versions SCALANCE XR524-8C, 24V (6GK5524-8GS00-2AR2): All versions SCALANCE XR524-8C, 24V (L3 int.) (6GK5524-8GR00-2AR2): All versions SCALANCE XR526-8C, 1x230V (6GK5526-8GS00-3AR2): All versions SCALANCE XR526-8C, 1x230V (L3 int.) (6GK5526-8GR00-3AR2): All versions SCALANCE XR526-8C, 2x230V (6GK5526-8GS00-4AR2): All versions SCALANCE XR526-8C, 2x230V (L3 int.) (6GK5526-8GR00-4AR2): All versions SCALANCE XR526-8C, 24V (6GK5526-8GS00-2AR2): All versions SCALANCE XR526-8C, 24V (L3 int.) (6GK5526-8GR00-2AR2): All versions SCALANCE XR528-6M (2HR2) (6GK5528-0AA00-2HR2): All versions SCALANCE XR528-6M (2HR2, L3 int.) (6GK5528-0AR00-2HR2): All versions SCALANCE XR528-6M (6GK5528-0AA00-2AR2): All versions SCALANCE XR528-6M (L3 int.) (6GK5528-0AR00-2AR2): All versions SCALANCE XR552-12M (2HR2) (6GK5552-0AA00-2HR2): All versions SCALANCE XR552-12M (2HR2) (6GK5552-0AR00-2HR2): All versions SCALANCE XR552-12M (2HR2, L3 int.) (6GK5552-0AR00-2AR2): All versions SCALANCE XR552-12M (6GK5552-0AA00-2AR2): All versions SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3): All versions SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3): All versions SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3): All versions SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3): All versions SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3): All versions SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3): All versions SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3): All versions SINEC INS: All versions when RADIUS Server feature is enabled SIPLUS NET SCALANCE X308-2 (6AG1308-2FL10-4AA3): Versions prior to V4.1.8 SIPLUS NET SCALANCE XC206-2 (6AG1206-2BB00-7AC2): All versions SIPLUS NET SCALANCE XC206-2SFP (6AG1206-2BS00-7AC2): All versions SIPLUS NET SCALANCE XC208 (6AG1208-0BA00-7AC2): All versions SIPLUS NET SCALANCE XC216-4C (6AG1216-4BS00-7AC2): All versions.",CVE-2024-3596,9.1,Critical,CWE-924,Critical Manufacturing; Communications,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2918,7/11/2024,7/11/2024,2024,ICSA-24-193-06,Siemens RUGGEDCOM,Siemens,RUGGEDCOM,"The following products of Siemens, are affected: RUGGEDCOM i800: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM i800NC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM i801: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM i801NC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM i802: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM i802NC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM i803: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM i803NC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM M969: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM M969NC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM M2100: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM M2100NC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM M2200: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM M2200NC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RMC30: Versions prior to V4.3.10 (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RMC30NC: Versions prior to V4.3.10 (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RMC8388 V4.X: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RMC8388 V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RMC8388NC V4.X: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RMC8388NC V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RP110: Versions prior to V4.3.10 (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RP110NC: Versions prior to V4.3.10 (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS400: Versions prior to V4.3.10 (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS400NC: Versions prior to V4.3.10 (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS401: Versions prior to V4.3.10 (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS401NC: Versions prior to V4.3.10 (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS416: Versions prior to V4.3.10 (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS416NC: Versions prior to V4.3.10 (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS416NCv2 V4.X: Versions prior to V4.3.10 (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS416NCv2 V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278, CVE-2024-39675) RUGGEDCOM RS416P: Versions prior to V4.3.10 (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS416PNC: Versions prior to V4.3.10 (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS416PNCv2 V4.X: Versions prior to V4.3.10 (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS416PNCv2 V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278, CVE-2024-39675) RUGGEDCOM RS416Pv2 V4.X: Versions prior to V4.3.10 (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS416Pv2 V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278, CVE-2024-39675) RUGGEDCOM RS416v2 V4.X: Versions prior to V4.3.10 (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS416v2 V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278, CVE-2024-39675) RUGGEDCOM RS900: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS900 (32M) V4.X: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS900 (32M) V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RS900G: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS900G (32M) V4.X: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS900G (32M) V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RS900GNC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS900GNC(32M) V4.X: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS900GNC(32M) V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RS900GP: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS900GPNC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS900L: All versions (CVE-2023-52237) RUGGEDCOM RS900LNC: All versions (CVE-2023-52237) RUGGEDCOM RS900M-GETS-C01: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS900M-GETS-XX: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS900M-STND-C01: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS900M-STND-XX: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS900MNC-GETS-C01: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS900MNC-GETS-XX: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS900MNC-STND-XX: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS900MNC-STND-XX-C01: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS900NC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS900NC(32M) V4.X: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS900NC(32M) V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RS900W: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS910: Versions prior to V4.3.10 (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS910L: All versions (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS910LNC: All versions (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS910NC: Versions prior to V4.3.10 (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS910W: Versions prior to V4.3.10 (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS920L: All versions (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS920LNC: All versions (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS920W: All versions (CVE-2023-52237, CVE-2024-39675) RUGGEDCOM RS930L: All versions (CVE-2023-52237) RUGGEDCOM RS930LNC: All versions (CVE-2023-52237) RUGGEDCOM RS930W: All versions (CVE-2023-52237) RUGGEDCOM RS940G: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS940GNC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS969: All versions (CVE-2023-52237) RUGGEDCOM RS969NC: All versions (CVE-2023-52237) RUGGEDCOM RS1600: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS1600F: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS1600FNC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS1600NC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS1600T: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS1600TNC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS8000: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS8000A: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS8000ANC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS8000H: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS8000HNC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS8000NC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS8000T: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RS8000TNC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RSG907R: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RSG908C: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RSG909R: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RSG910C: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RSG920P V4.X: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RSG920P V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RSG920PNC V4.X: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RSG920PNC V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RSG2100: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RSG2100 (32M) V4.X: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RSG2100 (32M) V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RSG2100NC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RSG2100NC(32M) V4.X: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RSG2100NC(32M) V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RSG2100P: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RSG2100PNC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RSG2200: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RSG2200NC: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RSG2288 V4.X: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RSG2288 V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RSG2288NC V4.X: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RSG2288NC V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RSG2300 V4.X: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RSG2300 V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RSG2300NC V4.X: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RSG2300NC V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RSG2300P V4.X: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RSG2300P V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RSG2300PNC V4.X: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RSG2300PNC V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RSG2488 V4.X: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RSG2488 V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RSG2488NC V4.X: Versions prior to V4.3.10 (CVE-2023-52237) RUGGEDCOM RSG2488NC V5.X: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RSL910: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RSL910NC: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RST916C: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RST916P: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2024-38278) RUGGEDCOM RST2228: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2023-52238, CVE-2024-38278) RUGGEDCOM RST2228P: Versions prior to V5.9.0 (CVE-2023-52237, CVE-2023-52238, CVE-2024-38278).","CVE-2023-52237, CVE-2023-52238, CVE-2024-38278, CVE-2024-39675",8.7,High,"CWE-200, CWE-266, CWE-497",Energy; Communications,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2917,7/11/2024,7/11/2024,2024,ICSA-24-193-07,Siemens SIMATIC and SIMIT,Siemens,"SIMATIC, SIMIT","The following products of Siemens, are affected: SIMATIC Energy Manager Basic: Versions prior to V7.5 SIMATIC Energy Manager PRO: Versions prior to V7.5 SIMATIC IPC DiagBase: All versions SIMATIC IPC DiagMonitor: All versions SIMIT V10: All versions SIMIT V11: Versions prior to V11.1.",CVE-2023-52891,5.3,Medium,CWE-1325,Critical manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2916,7/11/2024,7/11/2024,2024,ICSA-24-193-08,Siemens Mendix Encryption Module,Siemens,Mendix Encryption,The following products of Siemens are affected: Mendix Encryption: Versions V10.0.0 and prior.,CVE-2024-39888,8.7,High,CWE-547,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2915,7/11/2024,7/11/2024,2024,ICSA-24-193-09,Siemens SINEMA Remote Connect Server,Siemens,SINEMA Remote Connect Server,The following products of Siemens are affected: SINEMA Remote Connect Server: All versions.,"CVE-2024-39570, CVE-2024-39571",8.7,High,CWE-77,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2914,7/11/2024,7/11/2024,2024,ICSA-24-193-10,Siemens JT Open and PLM XML SDK,Siemens,JT Open and PLM XML SDK,The following products of Siemens are affected: JT Open: All versions PLM XML SDK: All versions.,"CVE-2024-37996, CVE-2024-37997",7.3,High,"CWE-476, CWE-121",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2913,7/11/2024,7/11/2024,2024,ICSA-24-193-11,Siemens RUGGEDCOM APE 1808,Siemens,RUGGEDCOM APE1808,The following products of Siemens are affected: RUGGEDCOM APE1808: All versions.,CVE-2023-48795,8.2,High,CWE-222,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2912,7/11/2024,7/11/2024,2024,ICSA-24-193-12,Siemens TIA Portal and SIMATIC STEP 7,Siemens,TIA Portal and SIMATIC STEP 7,"The following products of Siemens, are affected: Totally Integrated Automation Portal (TIA Portal): All versions Totally Integrated Automation Portal (TIA Portal) V18: All versions SIMATIC STEP 7 Safety V18: All versions.",CVE-2023-32737,7.0,High,CWE-502,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2911,7/11/2024,7/11/2024,2024,ICSA-24-193-13,"Siemens TIA Portal, SIMATIC, and SIRIUS",Siemens,"TIA Portal, SIMATIC, and SIRIUS","The following products of Siemens, are affected: Siemens SIMATIC STEP 7 (TIA Portal) V16: All versions prior to V16 Update 7 Siemens SIMATIC STEP 7 (TIA Portal) V17: All versions prior to V17 Update 7 Siemens SIMATIC STEP 7 (TIA Portal) V18: All versions prior to V18 Update 2 Siemens SIMATIC STEP 7 Safety V16: All versions prior to V16 Update 7 Siemens SIMATIC STEP 7 Safety V17: All versions prior to V17 Update 7 Siemens SIMATIC STEP 7 Safety V18: All versions prior to V18 Update 2 Siemens SIMATIC WinCC (TIA Portal) V16: All versions prior to V16 Update 7 Siemens SIMATIC WinCC (TIA Portal) V17: All versions prior to V17 Update 7 Siemens SIMATIC WinCC (TIA Portal) V18: All versions prior to V18 Update 2 Siemens SIMATIC WinCC Unified V16: All versions prior to V16 Update 7 Siemens SIMATIC WinCC Unified V17: All versions prior to V17 Update 7 Siemens SIMATIC WinCC Unified V18: All versions prior to V18 Update 2 Siemens SIMOCODE ES V16: All versions prior to V16 Update 7 Siemens SIMOCODE ES V17: All versions prior to V17 Update 7 Siemens SIMOCODE ES V18: All versions prior to V18 Update 2 Siemens SIMOTION SCOUT TIA V5.4 SP1: All versions Siemens SIMOTION SCOUT TIA V5.4 SP3: All versions Siemens SIMOTION SCOUT TIA V5.5 SP1: All versions Siemens SINAMICS Startdrive V16: All versions Siemens SINAMICS Startdrive V17: All versions Siemens SINAMICS Startdrive V18: All versions Siemens SIRIUS Safety ES V17: All versions prior to V17 Update 7 Siemens SIRIUS Safety ES V18: All versions prior to V18 Update 2 Siemens SIRIUS Soft Starter ES V17: All versions prior to V17 Update 7 Siemens SIRIUS Soft Starter ES V18: All versions prior to V18 Update 2 Siemens Soft Starter ES V16: All versions prior to V16 Update 7 Siemens TIA Portal Cloud V3.0: All versions prior to V18 Update 2.",CVE-2023-32735,7.0,High,CWE-502,Chemical; Critical Manufacturing; Energy; Transportation Systems; Water and Wastewater Systems.,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2910,7/11/2024,7/11/2024,2024,ICSA-24-193-14,Siemens SIPROTEC,Siemens,SIPROTEC,The following Siemens products are affected: Siemens SIPROTEC 5 6MD84 (CP300): All versions prior to V9.64 Siemens SIPROTEC 5 6MD85 (CP200): All versions Siemens SIPROTEC 5 6MD85 (CP300): All versions prior to V9.64 Siemens SIPROTEC 5 6MD86 (CP200): All versions Siemens SIPROTEC 5 6MD86 (CP300): All versions prior to V9.64 Siemens SIPROTEC 5 6MD89 (CP300): All versions prior to V9.64 Siemens SIPROTEC 5 6MU85 (CP300): All versions prior to V9.64 Siemens SIPROTEC 5 7KE85 (CP200): All versions Siemens SIPROTEC 5 7KE85 (CP300): All versions prior to V9.64 Siemens SIPROTEC 5 7SA82 (CP100): All versions Siemens SIPROTEC 5 7SA82 (CP150): All versions prior to V9.65 Siemens SIPROTEC 5 7SA84 (CP200): All versions Siemens SIPROTEC 5 7SA86 (CP200): All versions Siemens SIPROTEC 5 7SA86 (CP300): All versions prior to V9.65 Siemens SIPROTEC 5 7SA87 (CP200): All versions Siemens SIPROTEC 5 7SA87 (CP300): All versions prior to V9.65 Siemens SIPROTEC 5 7SD82 (CP100): All versions Siemens SIPROTEC 5 7SD82 (CP150): All versions prior to V9.65 Siemens SIPROTEC 5 7SD84 (CP200): All versions Siemens SIPROTEC 5 7SD86 (CP200): All versions Siemens SIPROTEC 5 7SD86 (CP300): All versions prior to V9.65 Siemens SIPROTEC 5 7SD87 (CP200): All versions Siemens SIPROTEC 5 7SD87 (CP300): All versions prior to V9.65 Siemens SIPROTEC 5 7SJ81 (CP100): All versions prior to V8.89 Siemens SIPROTEC 5 7SJ81 (CP150): All versions prior to V9.65 Siemens SIPROTEC 5 7SJ82 (CP100): All versions prior to V8.89 Siemens SIPROTEC 5 7SJ82 (CP150): All versions prior to V9.65 Siemens SIPROTEC 5 7SJ85 (CP200): All versions Siemens SIPROTEC 5 7SJ85 (CP300): All versions prior to V9.65 Siemens SIPROTEC 5 7SJ86 (CP200): All versions Siemens SIPROTEC 5 7SJ86 (CP300): All versions prior to V9.65 Siemens SIPROTEC 5 7SK82 (CP100): All versions prior to V8.89 Siemens SIPROTEC 5 7SK82 (CP150): All versions prior to V9.65 Siemens SIPROTEC 5 7SK85 (CP200): All versions Siemens SIPROTEC 5 7SK85 (CP300): All versions prior to V9.65 Siemens SIPROTEC 5 7SL82 (CP100): All versions Siemens SIPROTEC 5 7SL82 (CP150): All versions prior to V9.65 Siemens SIPROTEC 5 7SL86 (CP200): All versions Siemens SIPROTEC 5 7SL86 (CP300): All versions prior to V9.65 Siemens SIPROTEC 5 7SL87 (CP200): All versions Siemens SIPROTEC 5 7SL87 (CP300): All versions prior to V9.65 Siemens SIPROTEC 5 7SS85 (CP200): All versions Siemens SIPROTEC 5 7SS85 (CP300): All versions prior to V9.64 Siemens SIPROTEC 5 7ST85 (CP200): All versions Siemens SIPROTEC 5 7ST85 (CP300): All versions prior to V9.64 Siemens SIPROTEC 5 7ST86 (CP300): All versions prior to V9.64 Siemens SIPROTEC 5 7SX82 (CP150): All versions prior to V9.65 Siemens SIPROTEC 5 7SX85 (CP300): All versions prior to V9.65 Siemens SIPROTEC 5 7UM85 (CP300): All versions prior to V9.64 Siemens SIPROTEC 5 7UT82 (CP100): All versions Siemens SIPROTEC 5 7UT82 (CP150): All versions prior to V9.65 Siemens SIPROTEC 5 7UT85 (CP200): All versions Siemens SIPROTEC 5 7UT85 (CP300): All versions prior to V9.65 Siemens SIPROTEC 5 7UT86 (CP200): All versions Siemens SIPROTEC 5 7UT86 (CP300): All versions prior to V9.65 Siemens SIPROTEC 5 7UT87 (CP200): All versions Siemens SIPROTEC 5 7UT87 (CP300): All versions prior to V9.65 Siemens SIPROTEC 5 7VE85 (CP300): All versions prior to V9.64 Siemens SIPROTEC 5 7VK87 (CP200): All versions Siemens SIPROTEC 5 7VK87 (CP300): All versions prior to V9.65 Siemens SIPROTEC 5 7VU85 (CP300): All versions prior to V9.64 Siemens SIPROTEC 5 Communication Module ETH-BA-2EL (Rev.1): All versions installed on CP200 devices Siemens SIPROTEC 5 Communication Module ETH-BA-2EL (Rev.1): All versions prior to V8.89 installed on CP100 devices Siemens SIPROTEC 5 Communication Module ETH-BA-2EL (Rev.1): All versions prior to V9.62 installed on CP150 and CP300 devices Siemens SIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 1): All versions installed on CP200 devices Siemens SIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 1): All versions prior to V8.89 installed on CP100 devices Siemens SIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 1): All versions prior to V9.62 installed on CP150 and CP300 devices Siemens SIPROTEC 5 Communication Module ETH-BD-2FO: All versions prior to V9.62 Siemens SIPROTEC 5 Compact 7SX800 (CP050): All versions prior to V9.64.,CVE-2024-38867,5.9,Medium,CWE-326,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2909,7/11/2024,7/11/2024,2024,ICSA-24-193-15,Siemens SINEMA Remote Connect Server,Siemens,SINEMA Remote Connect Server,Siemens reports that the following versions of SINEMA Remote Connect management platform are affected: SINEMA Remote Connect Client: versions prior to V3.2 HF1.,"CVE-2024-39567, CVE-2024-39568, CVE-2024-39569",8.5,High,CWE-77,Critical Manufacturing; Commercial Facilities; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2908,7/11/2024,7/11/2024,2024,ICSA-24-193-16,Siemens SIMATIC WinCC,Siemens,SIMATIC WinCC,Siemens reports that the following versions of SIMATIC WinCC are affected: Siemens SIMATIC PCS 7 V9.1: all versions Siemens SIMATIC WinCC Runtime Professional V18: all versions Siemens SIMATIC WinCC Runtime Professional V19: all versions Siemens SIMATIC WinCC V7.4: versions prior to V7.4 SP1 Update 23 Siemens SIMATIC WinCC V7.5: versions prior to V7.5 SP2 Update 17 Siemens SIMATIC WinCC V8.0: versions prior to V8.0 Update 5.,CVE-2024-30321,8.2,High,CWE-359,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2907,7/11/2024,7/11/2024,2024,ICSA-24-193-17,Siemens SIMATIC STEP 7 (TIA Portal),Siemens,SIMATIC STEP 7 (TIA Portal),Siemens reports that the following products are affected: SIMATIC PCS neo V4.0: all versions SIMATIC STEP 7 V16: all versions SIMATIC STEP 7 V17: all versions SIMATIC STEP 7 V18: versions prior to V18 Update 2.,CVE-2022-45147,8.5,High,CWE-502,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2906,7/11/2024,7/11/2024,2024,ICSA-24-193-18,Rockwell Automation ThinManager ThinServer,Rockwell Automation,ThinManager ThinServer,"The vulnerabilities exist in the following versions of ThinManger ThinServer: ThinManager ThinServer: Versions 11.1.0, 11.2.0, 12.0.0, 12.1.0, 13.0.0, 13.1.0, 13.2.0 (CVE-2024-5988, CVE-2024-5989) ThinManager ThinServer: Versions 11.1.0, 11.2.0, 12.0.0, 12.1.0, 13.0.0, 13.1.0 (CVE-2024-5990).","CVE-2024-5988, CVE-2024-5989, CVE-2024-5990",9.3,Critical,CWE-20,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2905,7/11/2024,7/11/2024,2024,ICSA-24-193-19,Rockwell Automation FactoryTalk System Services and Policy Manager,Rockwell Automation,FactoryTalk System Services and Policy Manager,The following Rockwell Automation FactoryTalk products are affected: FactoryTalk System Services: v6.40 FactoryTalk Policy Manager: v6.40.,"CVE-2024-6236, CVE-2024-6325",6.0,Medium,CWE-269,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2904,7/11/2024,7/11/2024,2024,ICSA-24-193-20,HMS Industrial Networks Anybus-CompactCom 30,HMS Industrial Networks,Anybus-CompactCom 30,"The following versions of Anybus-CompactCom 30, an industrial communication interface, are affected if they include a web server: Anybus-CompactCom 30: All versions.",CVE-2024-6558,6.3,Medium,CWE-79,Critical Manufacturing,Worldwide,Sweden,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2903,7/9/2024,2/18/2025,2024,ICSA-24-191-01,Delta Electronics CNCSoft-G2 (Update A),Delta Electronics,CNCSoft-G2,"The following versions of Delta Electronics CNCSoft-G2, a human-machine interface (HMI) software, are affected: CNCSoft-G2: Version 2.0.0.5 (CVE-2024-39880, CVE-2024-39881, CVE-2024-39882, CVE-2024-39883) CNCSoft-G2: Version 2.1.0.10 and prior (CVE-2025-22880) CNCSoft-G2: Version 2.1.0.16 and prior (CVE-2024-12858).","CVE-2024-12858, CVE-2024-39880, CVE-2024-39881, CVE-2024-39882, CVE-2024-39883, CVE-2025-22880",8.4,High,"CWE-121, CWE-787, CWE-125, CWE-122",Critical Manufacturing; Energy,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2902,7/9/2024,7/9/2024,2024,ICSA-24-191-02,Mitsubishi Electric MELIPC Series MI5122-VW,Mitsubishi Electric,MI5122-VW,"The following versions of Mitsubishi Electric MELIPC Series MI5122-VW, an industrial PC, are affected: MI5122-VW: Firmware versions ""05"" up to and including ""07"".",CVE-2024-3904,8.8,High,CWE-276,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2901,7/9/2024,7/9/2024,2024,ICSA-24-191-03,Johnson Controls Illustra Pro Gen 4,Johnson Controls Inc.,Illustra Pro Gen 4,Johnson Controls reports that the following versions of Illustra Pro Gen 4 Camera are affected: Illustra Pro Gen 4 Camera: Version SS016.05.03.01.0010 and prior.,CVE-2024-32753,7.0,High,CWE-1395,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2900,7/9/2024,7/9/2024,2024,ICSA-24-191-04,Johnson Controls Software House C-CURE 9000,Johnson Controls Inc.,Software House C-CURE 9000,The following Johnson Controls products are affected: Software House C-CURE 9000: Version 2.80 and prior.,CVE-2024-32759,7.3,High,CWE-1391,Critical Manufacturing; Commercial Facilities; Government Facilities; Transportation Systems; Energy,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2899,7/9/2024,7/17/2025,2024,ICSA-24-191-05,Johnson Controls Inc. Software House C-CURE 9000 (Update B),Johnson Controls Inc.,Software House C-CURE 9000,The following Johnson Controls Inc. products are affected when the optional C-CURE IQ Web and/or C-CURE Portal is installed: Software House C-CURE 9000 Site Server: Version 2.80 and prior.,CVE-2024-32861,8.5,High,CWE-276,Critical Manufacturing; Commercial Facilities; Government Facilities; Transportation Systems; Energy,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2898,7/2/2024,7/2/2024,2024,ICSA-24-184-01,Johnson Controls Kantech Door Controllers,Johnson Controls Inc.,"Kantech KT1, KT2, KT400 Door Controllers","The following products by Kantech, a subsidiary of Johnson Controls, are affected: Kantech KT1 Door Controller Rev01: Versions 2.09.01 and prior Kantech KT2 Door Controller Rev01: Versions 2.09.01 and prior Kantech KT400 Door Controller Rev01: Versions 3.01.16 and prior.",CVE-2024-32754,3.1,Low,CWE-200,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2897,7/2/2024,7/2/2024,2024,ICSA-24-184-02,mySCADA myPRO,mySCADA Technologies,myPRO,The following mySCADA products are affected: myPRO: Versions prior to 8.31.0.,CVE-2024-4708,9.3,Critical,CWE-259,Critical Manufacturing,Worldwide,Czech Republic,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2896,6/27/2024,6/27/2024,2024,ICSA-24-179-01,TELSAT marKoni FM Transmitter,marKoni,"Markoni-D (Compact) FM Transmitters, Markoni-DH (Exciter+Amplifiers) FM Transmitters",The following versions of TELSAT marKoni FM Transmitters are affected: Markoni-D (Compact) FM Transmitters: All versions prior to 2.0.1 Markoni-DH (Exciter+Amplifiers) FM Transmitters: All versions prior to 2.0.1.,"CVE-2024-39373, CVE-2024-39374, CVE-2024-39375, CVE-2024-39376",9.3,Critical,"CWE-77, CWE-798, CWE-603, CWE-284",Communications,Worldwide,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2895,6/27/2024,6/27/2024,2024,ICSA-24-179-02,SDG Technologies PnPSCADA,SDG Technologies,PnPSCADA,"The following versions of SDG Technologies PnPSCADA, a web-based SCADA HMI, are affected: PnPSCADA: Versions prior to 4.",CVE-2024-2882,9.3,Critical,CWE-862,Energy; Water and Wastewater Systems; Critical Manufacturing,Worldwide,South Africa,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2894,6/27/2024,6/27/2024,2024,ICSA-24-179-03,Yokogawa FAST/TOOLS and CI Server,Yokogawa,FAST/TOOLS and CI Server,"The following versions of Yokogawa FAST/TOOLS and CI Server, SCADA software environments, are affected: FAST/TOOLS RVSVRN Package: Versions R9.01 through R10.04 FAST/TOOLS UNSVRN Package: Versions R9.01 through R10.04 FAST/TOOLS HMIWEB Package: Versions R9.01 through R10.04 FAST/TOOLS FTEES Package: Versions R9.01 through R10.04 FAST/TOOLS HMIMOB Package: Versions R9.01 through R10.04 CI Server: Versions R1.01.00 through R1.03.00.","CVE-2024-4105, CVE-2024-4106",6.9,Medium,"CWE-79, CWE-258",Critical Manufacturing; Energy; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2893,6/27/2024,7/2/2024,2024,ICSA-24-179-04,Johnson Controls Illustra Essentials Gen 4 (Update A),Johnson Controls Inc.,Illustra Essentials Gen 4,Johnson Controls reports that the following versions of Illustra Essentials Gen 4 IP camera are affected: Illustra Essentials Gen 4: all versions up to Illustra.Ess4.01.02.10.5982.,CVE-2024-32755,9.1,Critical,CWE-20,Critical Manufacturing; Commercial Facilities; Government Facilities; Transportation Systems; Energy,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2892,6/27/2024,7/2/2024,2024,ICSA-24-179-05,Johnson Controls Illustra Essentials Gen 4 (Update A),Johnson Controls Inc.,Illustra Essentials Gen 4,"Johnson Controls reports that the following versions of Illustra Essential Gen 4, an IP camera, are affected: Illustra Essentials Gen 4: versions up to Illustra.Ess4.01.02.10.5982.",CVE-2024-32756,6.8,Medium,CWE-257,Critical Manufacturing; Commercial Facilities; Government Facilities; Transportation Systems; Energy,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2891,6/27/2024,7/2/2024,2024,ICSA-24-179-06,Johnson Controls Illustra Essentials Gen 4 (Update A),Johnson Controls Inc.,Illustra Essentials Gen 4,Johnson Controls reports that the following versions of Illustra Essential Gen 4 IP cameras are affected: Illustra Essential Gen 4: version Illustra.Ess4.01.02.10.5982 and prior.,CVE-2024-32757,6.8,Medium,CWE-532,Critical Manufacturing; Commercial Facilities; Government Facilities; Transportation Systems; Energy,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2890,6/27/2024,7/2/2024,2024,ICSA-24-179-07,Johnson Controls Illustra Essentials Gen 4 (Update A),Johnson Controls Inc.,Illustra Essentials Gen 4,Johnson Controls reports that the following versions of Illustra Essentials IP cameras are affected: Illustra Essential Gen 4: versions Illustra.Ess4.01.02.10.5982 and prior.,CVE-2024-32932,6.8,Medium,CWE-257,Critical Manufacturing; Commercial Facilities; Government Facilities; Transportation Systems; Energy,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2889,6/25/2024,7/9/2024,2024,ICSA-24-177-02,PTC Creo Elements/Direct License Server (Update A),PTC,Creo Elements/Direct License Server,"PTC reports that the following versions of Creo Elements/Direct License Server are affected; note that this vulnerability does not impact ""PTC Creo License Server"" (lmadmin, lmgrd): Creo Elements/Direct Drafting: versions 15.00 through 20.7 Creo Elements/Direct Model Manager / Drawing Manager: versions 15.00 through 20.7 Creo Elements/Direct Modeling: versions 15.00 through 20.7 Creo Elements/Direct WorkManager / DDM: versions 15.00 through 20.4 Creo Elements/Direct License Server (MEls): version 20.7.0.0 and prior.",CVE-2024-6071,10.0,Critical,CWE-862,Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2888,6/5/2024,5/19/2026,2024,ICSA-24-177-01,ABB 800xA Base (Update A),ABB,ABB 800xA Base (Update A),"800xA Base <=6.1.1-2 , 6.1.1-3 , 6.2.0-0, 6.0.3-10, <=6.0.3-9",CVE-2024-3036,5.7,Medium,CWE-1284,Chemical; Critical Manufacturing; Dams; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2887,6/20/2024,6/20/2024,2024,ICSA-24-172-01,Yokogawa CENTUM,Yokogawa,CENTUM,"The following versions of Yokogawa CENTUM, a distributed control system (DCS), are affected: CENTUM CS 3000 (Including CENTUM CS 3000 Entry Class): Version R3.08.10 to R3.09.50 CENTUM VP (Including CENTUM VP Entry Class): Version R4.01.00 to R4.03.00 CENTUM VP (Including CENTUM VP Entry Class): Version R5.01.00 to R5.04.20 CENTUM VP (Including CENTUM VP Entry Class): Version R6.01.00 to R6.11.10.",CVE-2024-5650,7.7,High,CWE-284,Critical Manufacturing; Energy; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2886,6/20/2024,6/20/2024,2024,ICSA-24-172-02,CAREL Boss-Mini,CAREL,Boss-Mini,"The following versions of CAREL Boss-Mini, a local supervisor solution, are affected: Boss-Mini: Version 1.4.0 (Build 6221).",CVE-2023-3643,9.3,Critical,CWE-73,Commercial Facilities,Worldwide,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2885,6/20/2024,6/20/2024,2024,ICSA-24-172-03,Westermo L210-F2G,Westermo,L210-F2G Lynx,The following versions of Westermo L210-F2G industrial ethernet switches are affected: L210-F2G Lynx: version 4.21.0.,"CVE-2024-32943, CVE-2024-35246, CVE-2024-37183",8.7,High,"CWE-799, CWE-319",Critical Manufacturing; Transportation Systems,Worldwide,Sweden,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2884,6/18/2024,6/18/2024,2024,ICSA-24-170-01,RAD Data Communications SecFlow-2,RAD Data Communications,SecFlow-2,The following RAD Data Communications products are affected: SecFlow-2: All versions.,CVE-2019-6268,8.7,High,CWE-29,Communications,Worldwide,Israel,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2883,6/13/2024,6/13/2024,2024,ICSA-24-165-01,Siemens Mendix Applications,Siemens,Mendix Applications,"The following Siemens products, are affected: Siemens Mendix Applications using Mendix 9: Versions prior to V9.24.22 and after V9.3.0 Siemens Mendix Applications using Mendix 10: Versions prior to V10.11.0 Siemens Mendix Applications using Mendix 10 (V10.6): Versions prior V10.6.9.",CVE-2024-33500,7.4,High,CWE-269,Commercial Facilities; Critical Manufacturing; Defense Industrial Base; Energy; Financial Services; Government Facilities; Healthcare and Public Health; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2882,6/13/2024,6/13/2024,2024,ICSA-24-165-02,Siemens SIMATIC S7-200 SMART Devices,Siemens,SIMATIC S7-200 SMART devices,The following Siemens programmable logic controllers are affected: Siemens SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0): All versions Siemens SIMATIC S7-200 SMART CPU CR60 (6ES7288-1CR60-0AA0): All versions Siemens SIMATIC S7-200 SMART CPU SR20 (6ES7288-1SR20-0AA0): All versions Siemens SIMATIC S7-200 SMART CPU SR20 (6ES7288-1SR20-0AA1): All versions Siemens SIMATIC S7-200 SMART CPU SR30 (6ES7288-1SR30-0AA0): All versions Siemens SIMATIC S7-200 SMART CPU SR30 (6ES7288-1SR30-0AA1): All versions Siemens SIMATIC S7-200 SMART CPU SR40 (6ES7288-1SR40-0AA0): All versions Siemens SIMATIC S7-200 SMART CPU SR40 (6ES7288-1SR40-0AA1): All versions Siemens SIMATIC S7-200 SMART CPU SR60 (6ES7288-1SR60-0AA0): All versions Siemens SIMATIC S7-200 SMART CPU SR60 (6ES7288-1SR60-0AA1): All versions Siemens SIMATIC S7-200 SMART CPU ST20 (6ES7288-1ST20-0AA0): All versions Siemens SIMATIC S7-200 SMART CPU ST20 (6ES7288-1ST20-0AA1): All versions Siemens SIMATIC S7-200 SMART CPU ST30 (6ES7288-1ST30-0AA0): All versions Siemens SIMATIC S7-200 SMART CPU ST30 (6ES7288-1ST30-0AA1): All versions Siemens SIMATIC S7-200 SMART CPU ST40 (6ES7288-1ST40-0AA0): All versions Siemens SIMATIC S7-200 SMART CPU ST40 (6ES7288-1ST40-0AA1): All versions Siemens SIMATIC S7-200 SMART CPU ST60 (6ES7288-1ST60-0AA0): All versions Siemens SIMATIC S7-200 SMART CPU ST60 (6ES7288-1ST60-0AA1): All versions.,CVE-2024-35292,8.8,High,CWE-330,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2881,6/13/2024,6/13/2024,2024,ICSA-24-165-03,Siemens TIA Administrator,Siemens,TIA Administrator,"The following versions of Siemens TIA Administrator, a web-based framework, are affected: TIA Administrator: All versions prior to V3 SP2.",CVE-2023-38533,4.8,Medium,CWE-379,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2880,6/13/2024,6/13/2024,2024,ICSA-24-165-04,Siemens ST7 ScadaConnect,Siemens,ST7 ScadaConnect,"The following Siemens products, are affected: Siemens ST7 ScadaConnect (6NH7997-5DA10-0AA0): Versions prior to 1.1.","CVE-2022-40303, CVE-2022-40304, CVE-2023-0464, CVE-2023-0465, CVE-2023-0466, CVE-2023-21808, CVE-2023-24895, CVE-2023-24897, CVE-2023-24936, CVE-2023-28260, CVE-2023-28484, CVE-2023-29331, CVE-2023-29469, CVE-2023-32032, CVE-2023-33126, CVE-2023-33127, CVE-2023-33128, CVE-2023-33135, CVE-2023-33170, CVE-2023-3446, CVE-2023-35390, CVE-2023-35391, CVE-2023-36038, CVE-2023-36049, CVE-2023-36435, CVE-2023-36558, CVE-2023-36792, CVE-2023-36793, CVE-2023-36794, CVE-2023-36796, CVE-2023-36799, CVE-2023-38171, CVE-2023-38178, CVE-2023-38180, CVE-2023-39615, CVE-2023-44487, CVE-2023-5678",8.2,High,"CWE-190, CWE-415, CWE-295, CWE-1333, CWE-754, CWE-20, CWE-476, CWE-311, CWE-119, CWE-400",Commercial Facilities; Energy; Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2879,6/13/2024,6/13/2024,2024,ICSA-24-165-05,Siemens SITOP UPS1600,Siemens,"SITOP UPS1600 10 A Ethernet/ PROFINET (6EP4134-3AB00-2AY0), SITOP UPS1600 20 A Ethernet/ PROFINET (6EP4136-3AB00-2AY0), SITOP UPS1600 40 A Ethernet/ PROFINET (6EP4137-3AB00-2AY0), SITOP UPS1600 EX 20 A Ethernet PROFINET (6EP4136-3AC00-2AY0)","The following versions of Siemens SITOP UPS1600, an uninterruptible power supply, are affected: SITOP UPS1600 10 A Ethernet/ PROFINET (6EP4134-3AB00-2AY0): All versions prior to V2.5.4 SITOP UPS1600 20 A Ethernet/ PROFINET (6EP4136-3AB00-2AY0): All versions prior to V2.5.4 SITOP UPS1600 40 A Ethernet/ PROFINET (6EP4137-3AB00-2AY0): All versions prior to V2.5.4 SITOP UPS1600 EX 20 A Ethernet PROFINET (6EP4136-3AC00-2AY0) All versions prior to V2.5.4.","CVE-2023-26552, CVE-2023-26553, CVE-2023-26554",5.6,Medium,CWE-787,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2878,6/13/2024,6/13/2024,2024,ICSA-24-165-06,Siemens TIM 1531 IRC,Siemens,SIPLUS TIM 1531 IRC,"The following versions of SIPLUS TIM 1531 IRC, are affected: SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0): All versions prior to 2.4.8 SIPLUS TIM 1531 IRC (6GK7543-1MX00-0XE0): All versions prior to 2.4.8.","CVE-2021-47178, CVE-2022-1015, CVE-2022-39189, CVE-2022-40225, CVE-2022-40303, CVE-2022-40304, CVE-2022-4304, CVE-2022-4450, CVE-2022-45886, CVE-2022-45887, CVE-2022-45919, CVE-2023-0160, CVE-2023-0215, CVE-2023-0286, CVE-2023-0464, CVE-2023-0465, CVE-2023-0466, CVE-2023-1017, CVE-2023-2124, CVE-2023-21255, CVE-2023-2269, CVE-2023-27321, CVE-2023-28319, CVE-2023-35788, CVE-2023-35823, CVE-2023-35824, CVE-2023-35828, CVE-2023-35829, CVE-2023-41910, CVE-2023-50763, CVE-2023-52474, CVE-2024-0775",6.9,Medium,"CWE-20, CWE-787, CWE-326, CWE-415, CWE-311, CWE-681, CWE-190, CWE-416, CWE-667, CWE-295, CWE-125, CWE-835",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2877,6/13/2024,6/13/2024,2024,ICSA-24-165-07,Siemens PowerSys,Siemens,PowerSys,The following products of Siemens are affected: Siemens PowerSys: versions prior to V3.11.,CVE-2024-36266,8.5,High,CWE-287,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2876,6/13/2024,6/13/2024,2024,ICSA-24-165-08,Siemens Teamcenter Visualization and JT2Go,Siemens,Teamcenter Visualization and JT2Go,"The following Siemens products, are affected: Siemens JT2Go: All versions prior to V2312.0004 Siemens Teamcenter Visualization V14.2: All Versions Siemens Teamcenter Visualization V14.3: All versions prior to V14.3.0.9 Siemens Teamcenter Visualization V2312: All versions prior to V2312.0004.","CVE-2024-26275, CVE-2024-26276, CVE-2024-26277",7.8,High,"CWE-125, CWE-770, CWE-476",Chemical; Critical Manufacturing; Defense Industrial Base; Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2875,6/13/2024,6/13/2024,2024,ICSA-24-165-09,Siemens SICAM AK3/BC/TM,Siemens,"SICAM AK3, SICAM BC and SICAM TM","The following products of Siemens, are affected: Siemens CPCX26 Central Processing/Communication: Versions prior to V06.02 Siemens ETA4 Ethernet Interface IEC60870-5-104: Versions prior to V10.46 Siemens ETA5 Ethernet Int. 1x100TX IEC61850 Ed.2: Versions prior to V03.27 Siemens PCCX26 Ax 1703 PE, Contr, Communication Element: Versions prior to V06.05.",CVE-2024-31484,7.8,High,CWE-170,Critical Manufacturing; Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2874,6/13/2024,6/13/2024,2024,ICSA-24-165-10,Siemens SIMATIC and SIPLUS,Siemens,"SIMATIC, SIPLUS","The following products of Siemens, are affected: Siemens SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0): All versions prior to V2.3 Siemens SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0): All versions prior to V2.3 Siemens SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0): All versions prior to V2.3 Siemens SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0): All versions prior to V2.3 Siemens SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0): All versions prior to V2.3 Siemens SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0): All versions prior to V2.3.","CVE-2022-2097, CVE-2022-3435, CVE-2022-3545, CVE-2022-3623, CVE-2022-3643, CVE-2022-40303, CVE-2022-40304, CVE-2022-42328, CVE-2022-42329, CVE-2022-4304, CVE-2022-4450, CVE-2022-44792, CVE-2022-44793, CVE-2023-0215, CVE-2023-0286, CVE-2023-0464, CVE-2023-0465, CVE-2023-0466, CVE-2023-28484, CVE-2023-29469, CVE-2023-38380, CVE-2023-41910, CVE-2023-50763",9.8,Critical,"CWE-326, CWE-119, CWE-362, CWE-74, CWE-415, CWE-190, CWE-667, CWE-476, CWE-416, CWE-20, CWE-295, CWE-401, CWE-125, CWE-835",Chemical; Critical Manufacturing; Energy; Transportation; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2873,6/13/2024,6/13/2024,2024,ICSA-24-165-11,"Siemens SCALANCE XM-400, XR-500",Siemens,SCALANCE XM-400/XR-500,"The following Siemens products, are affected: Siemens SCALANCE XM408-4C (6GK5408-4GP00-2AM2): All versions prior to V6.6.1 Siemens SCALANCE XM408-4C (L3 int.) (6GK5408-4GQ00-2AM2): All versions prior to V6.6.1 Siemens SCALANCE XM408-8C (6GK5408-8GS00-2AM2): All versions prior to V6.6.1 Siemens SCALANCE XM408-8C (L3 int.) (6GK5408-8GR00-2AM2): All versions prior to V6.6.1 Siemens SCALANCE XM416-4C (6GK5416-4GS00-2AM2): All versions prior to V6.6.1 Siemens SCALANCE XM416-4C (L3 int.) (6GK5416-4GR00-2AM2): All versions prior to V6.6.1 Siemens SCALANCE XR524-8C, 1x230V (6GK5524-8GS00-3AR2): All versions prior to V6.6.1 Siemens SCALANCE XR524-8C, 1x230V (L3 int.) (6GK5524-8GR00-3AR2): All versions prior to V6.6.1 Siemens SCALANCE XR524-8C, 2x230V (6GK5524-8GS00-4AR2): All versions prior to V6.6.1 Siemens SCALANCE XR524-8C, 2x230V (L3 int.) (6GK5524-8GR00-4AR2): All versions prior to V6.6.1 Siemens SCALANCE XR524-8C, 24V (6GK5524-8GS00-2AR2): All versions prior to V6.6.1 Siemens SCALANCE XR524-8C, 24V (L3 int.) (6GK5524-8GR00-2AR2): All versions prior to V6.6.1 Siemens SCALANCE XR526-8C, 1x230V (6GK5526-8GS00-3AR2): All versions prior to V6.6.1 Siemens SCALANCE XR526-8C, 1x230V (L3 int.) (6GK5526-8GR00-3AR2): All versions prior to V6.6.1 Siemens SCALANCE XR526-8C, 2x230V (6GK5526-8GS00-4AR2): All versions prior to V6.6.1 Siemens SCALANCE XR526-8C, 2x230V (L3 int.) (6GK5526-8GR00-4AR2): All versions prior to V6.6.1 Siemens SCALANCE XR526-8C, 24V (6GK5526-8GS00-2AR2): All versions prior to V6.6.1 Siemens SCALANCE XR526-8C, 24V (L3 int.) (6GK5526-8GR00-2AR2): All versions prior to V6.6.1 Siemens SCALANCE XR528-6M (2HR2) (6GK5528-0AA00-2HR2): All versions prior to V6.6.1 Siemens SCALANCE XR528-6M (2HR2, L3 int.) (6GK5528-0AR00-2HR2): All versions prior to V6.6.1 Siemens SCALANCE XR528-6M (6GK5528-0AA00-2AR2): All versions prior to V6.6.1 Siemens SCALANCE XR528-6M (L3 int.) (6GK5528-0AR00-2AR2): All versions prior to V6.6.1 Siemens SCALANCE XR552-12M (2HR2) (6GK5552-0AA00-2HR2): All versions prior to V6.6.1 Siemens SCALANCE XR552-12M (2HR2) (6GK5552-0AR00-2HR2): All versions prior to V6.6.1 Siemens SCALANCE XR552-12M (2HR2, L3 int.) (6GK5552-0AR00-2AR2): All versions prior to V6.6.1 Siemens SCALANCE XR552-12M (6GK5552-0AA00-2AR2): All versions prior to V6.6.1.","CVE-2022-2097, CVE-2022-4304, CVE-2022-4450, CVE-2023-0215, CVE-2023-0286, CVE-2023-0464, CVE-2023-0465, CVE-2023-0466",7.5,High,"CWE-326, CWE-415, CWE-416, CWE-20, CWE-295","Chemical; Critical Manufacturing; Energy; Nuclear Reactors, Materials, and Waste",Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2872,6/13/2024,6/13/2024,2024,ICSA-24-165-12,Siemens SCALANCE W700,Siemens,SCALANCE W700 devices,"The following products of Siemens, are affected: Siemens SCALANCE WAM763-1 (6GK5763-1AL00-7DA0): All Versions Siemens SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0): All Versions Siemens SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0): All Versions Siemens SCALANCE WAM766-1 (EU) (6GK5766-1GE00-7DA0): All Versions Siemens SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0): All Versions Siemens SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0): All Versions Siemens SCALANCE WAM766-1 EEC (EU) (6GK5766-1GE00-7TA0): All Versions Siemens SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0): All Versions Siemens SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0): All Versions Siemens SCALANCE WUM763-1 (6GK5763-1AL00-3AA0): All Versions Siemens SCALANCE WUM763-1 (6GK5763-1AL00-3DA0): All Versions Siemens SCALANCE WUM763-1 (US) (6GK5763-1AL00-3AB0): All Versions Siemens SCALANCE WUM763-1 (US) (6GK5763-1AL00-3DB0): All Versions Siemens SCALANCE WUM766-1 (EU) (6GK5766-1GE00-3DA0): All Versions Siemens SCALANCE WUM766-1 (ME) (6GK5766-1GE00-3DC0): All Versions Siemens SCALANCE WUM766-1 (US) (6GK5766-1GE00-3DB0): All Versions.","CVE-2022-46144, CVE-2023-44317, CVE-2023-44318, CVE-2023-44319, CVE-2023-44373, CVE-2023-44374, CVE-2023-49691",9.1,Critical,"CWE-664, CWE-349, CWE-321, CWE-328, CWE-74, CWE-567, CWE-78","Chemical; Critical Manufacturing; Energy; Nuclear Reactors, Materials, and Waste",Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2871,6/13/2024,6/13/2024,2024,ICSA-24-165-13,Siemens SINEC Traffic Analyzer,Siemens,SINEC Traffic Analyzer,"The following products of Siemens, are affected: SINEC Traffic Analyzer (6GK8822-1BG01-0BA0): Versions prior to V1.2.","CVE-2022-41742, CVE-2024-35206, CVE-2024-35207, CVE-2024-35208, CVE-2024-35209, CVE-2024-35210, CVE-2024-35211, CVE-2024-35212",8.7,High,"CWE-787, CWE-613, CWE-352, CWE-522, CWE-749, CWE-319, CWE-614, CWE-20",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2870,6/13/2024,6/13/2024,2024,ICSA-24-165-14,Fuji Electric Tellus Lite V-Simulator,Fuji Electric,Tellus Lite V-Simulator,"The following versions of Fuji Electric Tellus Lite V-Simulator, a remote monitoring and operation software, are affected: Tellus Lite V-Simulator: Versions prior to v4.0.20.0.","CVE-2024-37022, CVE-2024-37029",8.5,High,"CWE-787, CWE-121",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2869,6/13/2024,6/13/2024,2024,ICSA-24-165-16,Rockwell Automation FactoryTalk View SE,Rockwell Automation,FactoryTalk View SE,Rockwell Automation reports that the following versions of FactoryTalk Software are affected: FactoryTalk View SE: v12.0.,CVE-2024-37367,8.2,High,CWE-287,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2868,6/13/2024,6/13/2024,2024,ICSA-24-165-17,Rockwell Automation FactoryTalk View SE,Rockwell Automation,FactoryTalk View SE,Rockwell Automation reports that the following versions of FactoryTalk Software are affected: FactoryTalk View SE: v12.0.,CVE-2024-37369,8.5,High,CWE-732,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2867,6/13/2024,6/13/2024,2024,ICSA-24-165-18,Rockwell Automation FactoryTalk View SE,Rockwell Automation,FactoryTalk View SE,Rockwell Automation reports that the following versions of FactoryTalk Software are affected: FactoryTalk View SE: v11.0.,CVE-2024-37368,8.2,High,CWE-287,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2866,6/13/2024,6/13/2024,2024,ICSA-24-165-19,Motorola Solutions Vigilant License Plate Readers,Motorola Solutions,Vigilant Fixed LPR Coms Box (BCAV1F2-C600),The following versions of Motorola Vigilant License Plate Readers are affected: Vigilant Fixed LPR Coms Box (BCAV1F2-C600): Versions 3.1.171.9 and prior.,"CVE-2024-38279, CVE-2024-38280, CVE-2024-38281, CVE-2024-38282, CVE-2024-38283, CVE-2024-38284, CVE-2024-38285",8.7,High,"CWE-288, CWE-313, CWE-798, CWE-522, CWE-311, CWE-294, CWE-522",Emergency Services,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2865,6/11/2024,6/11/2024,2024,ICSA-24-163-01,"Rockwell Automation ControlLogix, GuardLogix, and CompactLogix",Rockwell Automation,"ControlLogix, GuardLogix, CompactLogix",Rockwell Automation reports that the following controllers are affected: ControlLogix 5580: V34.011 GuardLogix 5580: V34.011 1756-EN4: V4.001 CompactLogix 5380: V34.011 Compact GuardLogix 5380: V34.011 CompactLogix 5380: V34.011 ControlLogix 5580: V34.011 CompactLogix 5480: V34.011.,CVE-2024-5659,8.3,High,CWE-670,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2864,6/11/2024,6/11/2024,2024,ICSA-24-163-02,AVEVA PI Web API,AVEVA,PI Web API,"The following versions of AVEVA PI Web API, a RESTful interface to the PI system, are affected: AVEVA PI Web API: Versions 2023 and prior.",CVE-2024-3468,8.4,High,CWE-502,Critical Manufacturing,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2863,6/11/2024,6/11/2024,2024,ICSA-24-163-03,AVEVA PI Asset Framework Client,AVEVA,PI Asset Framework Client,"The following versions of AVEVA PI Asset Framework Client, a tool to model either physical or logical objects, are affected: PI Asset Framework Client: 2023 PI Asset Framework Client: 2018 SP3 P04 and prior.",CVE-2024-3467,7.0,High,CWE-502,Critical Manufacturing,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2862,6/11/2024,6/11/2024,2024,ICSA-24-163-04,Intrado 911 Emergency Gateway,Intrado,911 Emergency Gateway (EGW),The following versions of Intrado's 911 Emergency Gateway are affected: 911 Emergency Gateway (EGW): All versions.,CVE-2024-1839,10.0,Critical,CWE-89,Emergency Services,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2861,6/11/2024,6/11/2024,2024,ICSMA-24-163-01,MicroDicom DICOM Viewer,MicroDicom,DICOM Viewer,"The following versions of MicroDicom DICOM Viewer, a medical image viewer, are affected: DICOM Viewer: Versions prior to 2024.2.","CVE-2024-28877, CVE-2024-33606",8.7,High,"CWE-939, CWE-121",Healthcare and Public Health,Worldwide,Bulgaria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2860,6/6/2024,6/6/2024,2024,ICSA-24-158-01,Emerson PACSystem and Fanuc,Emerson,"PACSystem, Fanuc","The following Emerson products are affected: PAC Machine Edition: All versions (CVE-2022-30263, CVE-2022-30265) PACSystem RXi: All versions (CVE-2022-30263, CVE-2022-30268, CVE-2022-30266) PACSystem RX3i: All versions (CVE-2022-30263, CVE-2022-30268, CVE-2022-30265) PACSystem RSTi-EP: All versions (CVE-2022-30263, CVE-2022-30268, CVE-2022-30266, CVE-2022-30265) PACSystem VersaMax: All versions (CVE-2022-30263, CVE-2022-30265) Fanuc VersaMax: All versions (CVE-2022-30263, CVE-2022-30268, CVE-2022-30266).","CVE-2022-30263, CVE-2022-30265, CVE-2022-30266, CVE-2022-30268",5.6,Medium,"CWE-319, CWE-345, CWE-522, CWE-494",Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2859,6/6/2024,6/6/2024,2024,ICSA-24-158-02,Emerson Ovation,Emerson,Ovation,The following Emerson products are affected: Ovation: Version 3.8.0 Feature Pack 1 and prior.,"CVE-2022-29966, CVE-2022-30267",9.8,Critical,"CWE-306, CWE-345",Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2858,6/6/2024,6/6/2024,2024,ICSA-24-158-03,Mitsubishi Electric CC-Link IE TSN Industrial Managed Switch,Mitsubishi Electric,CC-Link IE TSN Industrial Managed Switch,The following versions of CC-Link IE TSN Industrial Managed Switch are affected: NZ2MHG-TSNT8F2: Versions 05 and prior NZ2MHG-TSNT4: Versions 05 and prior.,CVE-2023-2650,5.1,Medium,CWE-770,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2857,6/6/2024,7/29/2025,2024,ICSA-24-158-04,Johnson Controls Software House iStar Pro Door Controller (Update A),Johnson Controls Inc.,"Software House iStar Pro, Edge, eX, Ultra and Ultra LT controllers, ICU","Johnson Controls reports that the following products are affected: Software House iStar Pro, Edge and eX door controllers: all versions Software House iStar Ultra and Ultra LT door controllers: Firmware prior to 6.6.B iSTAR Configuration Utility (ICU) Tool: All versions.",CVE-2024-32752,8.8,High,CWE-306,Critical Manufacturing; Commercial Facilities; Government Facilities; Transportation Systems; Energy,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2856,6/4/2024,9/24/2024,2024,ICSA-24-156-01,Uniview NVR301-04S2-P4 (Update A),Uniview,NVR301-04S2-P4,"The following version of Uniview NVR, a network video recorder, is affected: NVR301-04S2-P4: Versions prior to NVR-B3801.20.17.240507.",CVE-2024-3850,5.1,Medium,CWE-79,Commercial Facilities,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2855,5/30/2024,5/30/2024,2024,ICSA-24-151-01,LenelS2 NetBox,LenelS2,NetBox,"The following products of LenelS2, a Carrier Brand, are affected: NetBox: All versions prior to 5.6.2.","CVE-2024-2420, CVE-2024-2421, CVE-2024-2422",9.3,Critical,"CWE-259, CWE-78, CWE-88",Commercial Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2854,5/30/2024,6/4/2024,2024,ICSA-24-151-02,Fuji Electric Monitouch V-SFT (Update A),Fuji Electric,Monitouch V-SFT,"The following versions of Fuji Electric's Monitouch V-SFT, a screen configuration software, are affected: Monitouch V-SFT: Versions prior to 6.2.3.0.","CVE-2024-5271, CVE-2024-34171, CVE-2024-5597",8.5,High,"CWE-787, CWE-121, CWE-843",Critical Manufacturing; Energy,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2853,5/30/2024,5/30/2024,2024,ICSA-24-151-03,Inosoft VisiWin,Inosoft,VisiWin,The following Inosoft products are affected: VisiWin 7: All versions prior to version 2024-1.,CVE-2023-31468,8.5,High,CWE-276,Critical manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2852,5/30/2024,5/30/2024,2024,ICSA-24-151-04,Westermo EDW-100,Westermo,EDW-100,"The following versions of Westermo EDW-100, a Serial to Ethernet converter, are affected: EDW-100: All versions.","CVE-2024-36080, CVE-2024-36081",9.8,Critical,"CWE-259, CWE-522",Energy; Water and Wastewater Systems; Transportation Systems,Worldwide,Sweden,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2851,5/30/2024,5/30/2024,2024,ICSMA-24-151-01,Baxter Welch Allyn Configuration Tool,Baxter,Welch Allyn Configuration Tool,"The following Baxter (formerly Hillrom and Welch Allyn) products, are affected: Welch Allyn Product Configuration Tool: Versions 1.9.4.1 and prior.",CVE-2024-5176,9.4,Critical,CWE-522,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2850,5/30/2024,5/30/2024,2024,ICSMA-24-151-02,Baxter Welch Allyn Connex Spot Monitor,Baxter,Welch Allyn Connex Spot Monitor (CSM),The following Baxter (formerly manufactured by Hillrom) medical devices are affected: Welch Allyn Connex Spot Monitor (CSM): Versions 1.52 and prior.,CVE-2024-1275,9.1,Critical,CWE-1394,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2849,5/28/2024,5/28/2024,2024,ICSA-24-149-01,Campbell Scientific CSI Web Server,Campbell Scientific,CSI Web Server,"The following versions of Campbell Scientific CSI Web Server and RTMC (Real-Time Monitoring and Control) Pro, which contains the CSI Web Server are affected: Campbell Scientific CSI Web Server: Versions 1.6 and prior RTMC Pro: Version 5.0 and prior.","CVE-2024-5433, CVE-2024-5434",6.9,Medium,"CWE-22, CWE-261",Energy; Food and Agriculture; Water and Wastewater Systems; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2848,5/23/2024,5/23/2024,2024,ICSA-24-144-01,AutomationDirect Productivity PLCs,AutomationDirect,Productivity PLCs,AutomationDirect reports the following versions of Productivity PLCs are affected: Productivity 3000 P3-550E CPU: FW 1.2.10.9 Productivity 3000 P3-550E CPU: SW 4.1.1.10 Productivity 3000 P3-550 CPU: FW 1.2.10.9 Productivity 3000 P3-550 CPU: SW 4.1.1.10 Productivity 3000 P3-530 CPU: FW 1.2.10.9 Productivity 3000 P3-530 CPU: SW 4.1.1.10 Productivity 2000 P2-550 CPU: FW 1.2.10.10 Productivity 2000 P2-550 CPU: SW 4.1.1.10 Productivity 1000 P1-550 CPU: FW 1.2.10.10 Productivity 1000 P1-550 CPU: SW 4.1.1.10 Productivity 1000 P1-540 CPU: FW 1.2.10.10 Productivity 1000 P1-540 CPU: SW 4.1.1.10.,"CVE-2024-21785, CVE-2024-22187, CVE-2024-23315, CVE-2024-23601, CVE-2024-24851, CVE-2024-24946, CVE-2024-24947, CVE-2024-24954, CVE-2024-24955, CVE-2024-24956, CVE-2024-24957, CVE-2024-24958, CVE-2024-24959, CVE-2024-24962, CVE-2024-24963",9.3,Critical,"CWE-805, CWE-121, CWE-284, CWE-489, CWE-345",Commercial Facilities; Critical Manufacturing; Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2847,5/21/2024,5/21/2024,2024,ICSA-24-142-01,LCDS LAquis SCADA,LCDS - Leao Consultoria e Desenvolvimento de Sistemas Ltda ME,LAquis SCADA,"The following versions of LAquis SCADA, an HMI program, are affected: LAquis SCADA: Versions 4.7.1.7 and prior.",CVE-2024-5040,8.5,High,CWE-22,Chemical; Commercial Facilities; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater Systems,South America,Brazil,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2846,5/16/2024,5/16/2024,2024,ICSA-24-137-01,Siemens Parasolid,Siemens,Parasolid,"The following versions of Siemens Parasolid, a design and simulation product, are affected: Siemens Parasolid V35.1: Versions prior to V35.1.256 Siemens Parasolid V36.0: Versions prior to V36.0.208 Siemens Parasolid V36.1: Versions prior to V36.1.173.","CVE-2024-32635, CVE-2024-32636, CVE-2024-32637",7.3,High,"CWE-125, CWE-476",Critical Manufacturing; Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2845,5/16/2024,5/16/2024,2024,ICSA-24-137-02,Siemens SICAM Products,Siemens,"CPC80 Central Processing/Communication, CPCI85 Central Processing/Communication, OPUPI0 AMQP/MQTT, SICORE Base system",The following versions of multiple Siemens SICAM products are affected: CPC80 Central Processing/Communication: All versions prior to V16.41 CPCI85 Central Processing/Communication: All versions prior to V5.30 OPUPI0 AMQP/MQTT: All versions prior to V5.30 SICORE Base system: All versions prior to V1.3.0.,"CVE-2024-31484, CVE-2024-31485, CVE-2024-31486",8.6,High,"CWE-170, CWE-77, CWE-312",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2844,5/16/2024,5/16/2024,2024,ICSA-24-137-03,Siemens Teamcenter Visualization and JT2Go,Siemens,"JT2Go, Teamcenter Visualization","The following versions of Siemens Teamcenter Visualization and JT2Go, 3d file viewers, are affected: JT2Go: All versions prior to V2312.0001 Teamcenter Visualization V14.1: All versions prior to V14.1.0.13 Teamcenter Visualization V14.2: All versions prior to V14.2.0.10 Teamcenter Visualization V14.3: All versions prior to V14.3.0.7 Teamcenter Visualization V2312: All versions prior to V2312.0001.","CVE-2024-34085, CVE-2024-34086",7.8,High,"CWE-121, CWE-787",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2843,5/16/2024,5/16/2024,2024,ICSA-24-137-04,Siemens Polarion ALM,Siemens,Polarion ALM,"The following versions of Siemens Polarion ALM, an application lifecycle management software, are affected: Polarion ALM: All versions prior to V2404.0.",CVE-2024-33647,7.1,High,CWE-284,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2842,5/16/2024,5/16/2024,2024,ICSA-24-137-05,Siemens Simcenter Nastran,Siemens,Simcenter Nastran,"The following versions of Siemens Simcenter Nastran, a finite element analysis program, are affected: Simcenter Nastran 2306: All versions Simcenter Nastran 2312: All versions Simcenter Nastran 2406: All versions prior to V2406.90.",CVE-2024-33577,7.8,High,CWE-121,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2841,5/16/2024,5/16/2024,2024,ICSA-24-137-06,Siemens SIMATIC CN 4100 Before V3.0,Siemens,SIMATIC CN 4100,"The following versions of Siemens SIMATIC CN 4100, a communication node, are affected: SIMATIC CN 4100: All versions prior to V3.0.","CVE-2024-32740, CVE-2024-32741, CVE-2024-32742",10.0,Critical,"CWE-798, CWE-259, CWE-1326",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2840,5/16/2024,5/16/2024,2024,ICSA-24-137-07,Siemens SIMATIC RTLS Locating Manager,Siemens,SIMATIC RTLS Locating Manager,"The following versions of SIMATIC RTLS Locating Manager, a configuration, operation, and maintenance tool, are affected: Siemens SIMATIC RTLS Locating Manager (6GT2780-0DA00): Versions prior to V3.0.1.1 Siemens SIMATIC RTLS Locating Manager (6GT2780-0DA10): Versions prior to V3.0.1.1 Siemens SIMATIC RTLS Locating Manager (6GT2780-0DA20): Versions prior to V3.0.1.1 Siemens SIMATIC RTLS Locating Manager (6GT2780-0DA30): Versions prior to V3.0.1.1 Siemens SIMATIC RTLS Locating Manager (6GT2780-1EA10): Versions prior to V3.0.1.1 Siemens SIMATIC RTLS Locating Manager (6GT2780-1EA20): Versions prior to V3.0.1.1 Siemens SIMATIC RTLS Locating Manager (6GT2780-1EA30): Versions prior to V3.0.1.1.","CVE-2023-29409, CVE-2023-33953, CVE-2023-38039, CVE-2023-38545, CVE-2023-38546, CVE-2023-46218, CVE-2023-46219, CVE-2023-4807, CVE-2023-5363, CVE-2023-5678, CVE-2024-30206, CVE-2024-30207, CVE-2024-30208, CVE-2024-30209, CVE-2024-33494, CVE-2024-33495, CVE-2024-33496, CVE-2024-33497, CVE-2024-33498, CVE-2024-33499, CVE-2024-33583",10.0,Critical,"CWE-20, CWE-754, CWE-400, CWE-834, CWE-770, CWE-122, CWE-73, CWE-311, CWE-494, CWE-321, CWE-732, CWE-319, CWE-345, CWE-770, CWE-522, CWE-912",Critical Manufacturing; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2839,5/16/2024,5/16/2024,2024,ICSA-24-137-08,Siemens PS/IGES Parasolid Translator Component,Siemens,PS/IGES Parasolid Translator Component,Siemens reports that the following single-format translator toolkits are affected: PS/IGES Parasolid Translator Component: versions prior to V27.1.215.,"CVE-2024-32055, CVE-2024-32057, CVE-2024-32058, CVE-2024-32059, CVE-2024-32060, CVE-2024-32061, CVE-2024-32062, CVE-2024-32063, CVE-2024-32064, CVE-2024-32065, CVE-2024-32066",7.8,High,"CWE-125, CWE-843, CWE-119",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2838,5/16/2024,5/16/2024,2024,ICSA-24-137-09,Siemens Solid Edge,Siemens,Solid Edge,"The following products of Siemens, are affected: Solid Edge: All versions prior to V224.0 Update 5 (CVE-2024-33489, CVE-2024-33490, CVE-2024-33491, CVE-2024-33492, CVE-2024-33493) Solid Edge: All versions prior to V224.0 Update 2 (CVE-2024-34771, CVE-2024-34773) Solid Edge: All versions prior to V224.0 Update 4 (CVE-2024-34772).","CVE-2024-33489, CVE-2024-33490, CVE-2024-33491, CVE-2024-33492, CVE-2024-33493, CVE-2024-34771, CVE-2024-34772, CVE-2024-34773",7.8,High,"CWE-122, CWE-125, CWE-121",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2837,5/16/2024,5/16/2024,2024,ICSA-24-137-10,Siemens RUGGEDCOM CROSSBOW,Siemens,RUGGEDCOM CROSSBOW,"The following products of Siemens, are affected: RUGGEDCOM CROSSBOW: Versions prior to V5.5.","CVE-2024-27939, CVE-2024-27940, CVE-2024-27941, CVE-2024-27942, CVE-2024-27943, CVE-2024-27944, CVE-2024-27945, CVE-2024-27946, CVE-2024-27947",9.8,Critical,"CWE-862, CWE-89, CWE-306, CWE-73, CWE-22, CWE-200",Critical Manufacturing; Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2836,5/16/2024,5/16/2024,2024,ICSA-24-137-11,Siemens RUGGEDCOM APE1808,Siemens,RUGGEDCOM APE1808,"The following Siemens products using Nozomi Guardian/CMC before 23.4.1, are affected: RUGGEDCOMAPE1808LNX (6GK6015-0AL200GH0): All versions RUGGEDCOM APE1808LNX CC (6GK60150AL20-0GH1): All versions.","CVE-2023-6916, CVE-2024-0218",7.5,High,"CWE-522, CWE-20",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2835,5/16/2024,5/16/2024,2024,ICSA-24-137-12,Siemens Desigo Fire Safety UL and Cerberus PRO UL Fire Protection Systems,Siemens,Cerberus PRO UL and Desigo Fire Safety UL,"The following products of Siemens, are affected: Siemens Cerberus PRO UL Compact Panel FC922/924: All versions prior to MP4 Siemens Cerberus PRO UL Engineering Tool: All versions prior to MP4 Siemens Cerberus PRO UL X300 Cloud Distribution: All versions prior to V4.3.0001 Siemens Desigo Fire Safety UL Compact Panel FC2025/2050: All versions prior to MP4 Siemens Desigo Fire Safety UL Engineering Tool: All versions prior to MP4 Siemens Desigo Fire Safety UL X300 Cloud Distribution: All versions prior to V4.3.0001.","CVE-2024-22039, CVE-2024-22040, CVE-2024-22041",10.0,Critical,"CWE-120, CWE-125, CWE-119",Emergency Services,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2834,5/16/2024,5/16/2024,2024,ICSA-24-137-13,Siemens Industrial Products,Siemens,"S7-PCT, SCT, SIMATIC, SINAMICS, SINUMERIK, and TIA Portal Products",The following products of Siemens are affected: Siemens S7-PCT: All versions Siemens Security Configuration Tool (SCT): All versions Siemens SIMATIC Automation Tool: All versions Siemens SIMATIC BATCH V9.1: All versions prior to V9.1.2.5 Siemens SIMATIC NET PC Software: All versions Siemens SIMATIC PCS 7 V9.1: All versions Siemens SIMATIC PDM V9.2: All versions prior to V9.2 SP2 Upd3 Siemens SIMATIC Route Control V9.1: All versions prior to V9.1.2.5 Siemens SIMATIC STEP 7 V5: All versions Siemens SIMATIC WinCC OA V3.17: All versions Siemens SIMATIC WinCC OA V3.18: All versions prior to V3.18 P025 Siemens SIMATIC WinCC OA V3.19: All versions prior to V3.19 P010 Siemens SIMATIC WinCC Runtime Advanced: All versions Siemens SIMATIC WinCC Runtime Professional V16: All versions Siemens SIMATIC WinCC Runtime Professional V17: All versions Siemens SIMATIC WinCC Runtime Professional V18: All versions Siemens SIMATIC WinCC Runtime Professional V19: All versions Siemens SIMATIC WinCC Unified PC Runtime: All versions Siemens SIMATIC WinCC V7.4: All versions Siemens SIMATIC WinCC V7.5: All versions Siemens SIMATIC WinCC V8.0: All versions Siemens SINAMICS Startdrive: All versions prior to V19 SP1 Siemens SINUMERIK ONE virtual: All versions prior to V6.23 Siemens SINUMERIK PLC Programming Tool: All versions Siemens TIA Portal Cloud Connector: All versions prior to V2.0 Siemens Totally Integrated Automation Portal (TIA Portal) V15.1: All versions Siemens Totally Integrated Automation Portal (TIA Portal) V16: All versions Siemens Totally Integrated Automation Portal (TIA Portal) V17: All versions Siemens Totally Integrated Automation Portal (TIA Portal) V18: All versions Siemens Totally Integrated Automation Portal (TIA Portal) V19: All versions prior to V19 Update 2.,CVE-2023-46280,8.2,High,CWE-125,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2833,5/16/2024,5/16/2024,2024,ICSA-24-137-14,Rockwell Automation FactoryTalk View SE,Rockwell Automation,FactoryTalk View SE,"The following versions of Rockwell Automation's FactoryTalk View SE, monitoring software, are affected: FactoryTalk View SE: Versions prior to 14.0.",CVE-2024-4609,8.8,High,CWE-20,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Government Facilities; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2832,5/14/2024,5/14/2024,2024,ICSA-24-135-01,Rockwell Automation FactoryTalk Remote Access,Rockwell Automation,FactoryTalk Remote Access,The following versions of Rockwell Automation's FactoryTalk Remote Access are affected: FactoryTalk Remote Access: v13.5.0.174 and prior.,CVE-2024-3640,7.0,High,CWE-428,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Government Facilities; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2831,5/14/2024,5/14/2024,2024,ICSA-24-135-02,SUBNET PowerSYSTEM Center and Substation Server,SUBNET Solutions Inc.,PowerSYSTEM Center,SUBNET Solutions reports that the following products use components with vulnerabilities: PowerSYSTEM Center: Update 19 and prior.,CVE-2024-28042,8.6,High,CWE-1357,Critical Manufacturing; Energy,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2830,5/14/2024,5/14/2024,2024,ICSA-24-135-03,Johnson Controls Software House C-CURE 9000,Johnson Controls Inc.,Software House C-CURE 9000,"Johnson Controls reports that the following versions of Software House C-CURE 9000, a security management system, are affected: Software House C-CURE 9000: v3.00.2.",CVE-2024-0912,7.7,High,CWE-532,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2829,5/14/2024,9/1/2026,2024,ICSA-24-135-04,Mitsubishi Electric Multiple FA Engineering Software Products (Update F),Mitsubishi Electric,Mitsubishi Electric Multiple FA Engineering Software Products (Update F),CPU Module Logging Configuration Tool <=1.154L | CSGL (GX Works2 connection configuration) <=2.5 | CW Configurator <=1.019V | Data Transfer <=3.58L | Data Transfer Classic <=1.00A | EZSocket <=5.92 | FR Configurator SW3 | FR Configurator2 <=1.32J | GENESIS64 <=10.97.3 | GT Designer3 Version1 (GOT1000) <=1.310Y | GT Designer3 Version1 (GOT2000) <=1.317F | GT SoftGOT1000 Version3 <=3.310Y | GT SoftGOT2000 Version1 <=1.315D | GX Developer | GX LogViewer <=1.154L | GX Works2 <=1.622Y | GX Works3 <=1.106L | iQ Works (MELSOFT Navigator) <=2.102G | MI Configurator | Numerical Control Device Communication Software (FCSB1224) <=A8 | MR Configurator (SETUP221) | MR Configurator2 <=1.150G | Position Board Utility2 (MRZJW3-MC2-UTL) <=3.40 | MX Component <=5.007H | MX OPC Server DA/UA (Software packaged with MC Works64) | PX Developer/Monitor Tool <=1.58L | RT ToolBox3 <=2.20W | RT VisualBox <=1.11M | Setting/monitoring tools for the C Controller module (SW4PVC-CCPU) <=4.14Q | MELSECNET/H Interface Board software package (SW0DNC-MNETH-B) <=36N | CC-Link System Master/Local Interface Board software package (SW1DNC-CCBD2-B) <=1.25B | CC-Link IE Field Network Interface Board software package (SW1DNC-CCIEF-J) <=1.18U | CC-Link IE Controller Network Interface Board software package (SW1DNC-MNETG-B) <=1.31H | C Controller Interface Module utility (SW1DNC-QSCCF-B) <=2.10 | MELSOFT EM Software Development Kit (SW1DND-EMSDK-B) <=1.020W | MT Works2 <=1.200J | ICONICS Suite <=10.97.3 | CC-Link IE Field Network Interface Board software package (SW1DNC-CCIEF-B) <=1.18U,"CVE-2023-51776, CVE-2023-51777, CVE-2023-51778, CVE-2024-22102, CVE-2024-22103, CVE-2024-22104, CVE-2024-22105, CVE-2024-22106, CVE-2024-25086, CVE-2024-25087, CVE-2024-25088, CVE-2024-26314",6.0,Medium,"CWE-269, CWE-400, CWE-787",Critical Manufacturing,Worldwide,"United States, Japan",Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2828,5/9/2024,5/9/2024,2024,ICSA-24-130-01,Rockwell Automation FactoryTalk Historian SE,Rockwell Automation,FactoryTalk Historian SE,"The following versions of Rockwell Automation FactoryTalk Historian SE, a data management application, are affected: FactoryTalk Historian SE: Versions v9.0 and prior.","CVE-2023-31274, CVE-2023-34348",7.7,High,"CWE-772, CWE-703",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2827,5/9/2024,5/9/2024,2024,ICSA-24-130-02,alpitronic Hypercharger EV Charger,alpitronic,Hypercharger EV charger,"The following versions of Hypercharger EV charger, a high power charging station, are affected: Hypercharger EV charger: all versions.",CVE-2024-4622,8.3,High,CWE-1392,Transportation Systems,Worldwide,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2826,5/9/2024,5/9/2024,2024,ICSA-24-130-03,Delta Electronics InfraSuite Device Master,Delta Electronics,InfraSuite Device Master,The following Delta Electronics products are affected: InfraSuite Device Master: Versions 1.0.10 and prior.,CVE-2023-46604,9.3,Critical,CWE-502,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2825,5/7/2024,5/7/2024,2024,ICSA-24-128-01,PTC Codebeamer,PTC,Codebeamer,"The following versions of PTC Codebeamer, an application lifecycle management platform, are affected: Codebeamer: version 22.10 SP9 and prior Codebeamer: version 2.0.0.3 and prior Codebeamer: version 2.1.0.0.",CVE-2024-3951,5.1,Medium,CWE-79,Information Technology; Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2824,5/7/2024,5/7/2024,2024,ICSA-24-128-02,SUBNET Substation Server,SUBNET Solutions Inc.,Substation Server,SUBNET Solutions reports that the following products use components with vulnerabilities: Substation Server: 2.23.10 and prior.,CVE-2024-26024,8.6,High,CWE-1357,Critical Manufacturing; Energy,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2823,5/2/2024,5/2/2024,2024,ICSA-24-123-01,CyberPower PowerPanel,CyberPower,PowerPanel,"The following versions of PowerPanel, a business management software, are affected: PowerPanel: 4.9.0 and prior.","CVE-2024-34025, CVE-2024-34025, CVE-2024-33615, CVE-2024-32053, CVE-2024-32047, CVE-2024-32042, CVE-2024-31856, CVE-2024-31410, CVE-2024-31409",9.8,Critical,"CWE-259, CWE-23, CWE-798, CWE-489, CWE-257, CWE-89, CWE-321, CWE-285",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2822,5/2/2024,5/2/2024,2024,ICSA-24-123-02,Delta Electronics DIAEnergie,Delta Electronics,DIAEnergie,"The following versions of Delta Electronics DIAEnergie, an industrial energy management system, are affected: DIAEnergie: Versions v1.10.00.005.","CVE-2024-34031, CVE-2024-34032, CVE-2024-34033",9.3,Critical,"CWE-89, CWE-22",Energy,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2821,4/30/2024,10/16/2025,2024,ICSA-24-121-01,Delta Electronics CNCSoft-G2 DOPSoft (Update A),Delta Electronics,CNCSoft-G2 DOPSoft,"The following versions of Delta Electronics CNCSoft-G2, a Human-Machine Interface (HMI) software, are affected: CNCSoft-G2: Versions 2.0.0.5 (with DOPSoft v5.0.0.93) and prior (CVE-2024-4192) CNCSoft-G2: Versions 2.1.0.27 and prior (CVE-2025-58319).","CVE-2024-4192, CVE-2025-58319",8.5,High,CWE-121,Energy; Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2820,4/25/2024,4/25/2024,2024,ICSA-24-116-01,Multiple Vulnerabilities in Hitachi Energy RTU500 Series,Hitachi Energy,RTU500 Series,The following versions of Hitachi's RTU500 series CMU Firmware are affected: RTU500 series CMU Firmware: Version 12.0.1 - 12.0.14 RTU500 series CMU Firmware: Version 12.2.1 - 12.2.11 RTU500 series CMU Firmware: Version 12.4.1 - 12.4.11 RTU500 series CMU Firmware: Version 12.6.1 - 12.6.9 RTU500 series CMU Firmware: Version 12.7.1 - 12.7.6 RTU500 series CMU Firmware: Version 13.2.1 - 13.2.6 RTU500 series CMU Firmware: Version 13.4.1 - 13.4.4 RTU500 series CMU Firmware: Version 13.5.1 - 13.5.3.,"CVE-2024-1531, CVE-2024-1532",7.0,High,CWE-434,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2819,4/25/2024,10/23/2025,2024,ICSA-24-116-02,Hitachi Energy MACH SCM (Update A),Hitachi Energy,MACH SCM,"The following versions of MACH SCM, are affected: MACH SCM: Versions 4.0 to 4.5.x MACH SCM: Versions 4.6 to 4.38 MACH SCM Tools: Versions 1.8 and prior.","CVE-2024-0400, CVE-2024-2097",7.7,High,"CWE-94, CWE-95",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2818,4/25/2024,4/25/2024,2024,ICSA-24-116-03,Siemens RUGGEDCOM APE1808 Devices Configured with Palo Alto Networks Virtual NGFW,Siemens,RUGGEDCOM APE1808,"The following versions of Siemens RUGGEDCOM APE1808, an application hosting platform, are affected: RUGGEDCOM APE1808: All versions with Palo Alto Networks Virtual NGFW configured with GlobalProtect gateway or GlobalProtect portal (or both).",CVE-2024-3400,10.0,Critical,CWE-77,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2817,4/25/2024,4/25/2024,2024,ICSA-24-116-04,"Honeywell Experion PKS, Experion LX, PlantCruise by Experion, Safety Manager, Safety Manager SC",Honeywell,"Experion PKS, Experion LX, PlantCruise by Experion, Safety Manager, Safety Manager SC","Honeywell reports these vulnerabilities affect the following versions of Experion PKS, LX, PlantCruise, Safety Manager, and Safety Manager SC: Experion PKS: All releases prior to R510.2 HF14 Experion PKS: All releases prior to R511.5 TCU4 HF4 Experion PKS: All releases prior to R520.1 TCU5 Experion PKS: All releases prior to R520.2 TCU4 HF2 Experion LX: All releases prior to R511.5 TCU4 HF4 Experion LX: All releases prior to R520.1 TCU5 Experion LX: All releases prior to R520.2 TCU4 HF2 PlantCruise by Experion: All releases prior to R511.5 TCU4 HF4 PlantCruise by Experion: All releases prior to R520.1 TCU5 PlantCruise by Experion: All releases prior to R520.2 TCU4 HF2 Safety Manager: R15x, R16x up to and including R162.10 Safety Manager SC: R210.X, R211.1, R211.2, R212.1.","CVE-2023-5389, CVE-2023-5390, CVE-2023-5392, CVE-2023-5393, CVE-2023-5394, CVE-2023-5396, CVE-2023-5397, CVE-2023-5398, CVE-2023-5405, CVE-2023-5406, CVE-2023-5407",9.1,Critical,"CWE-749, CWE-36, CWE-121, CWE-1295, CWE-787, CWE-122, CWE-1327, CWE-20, CWE-805, CWE-119, CWE-130",Chemical; Critical Manufacturing; Energy; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2816,4/18/2024,4/30/2024,2024,ICSA-24-109-01,Unitronics Vision Legacy Series (Update A),Unitronics,Vision Legacy series,The following versions of Unitronics Vision Legacy series PLCs are affected: Vision 230: All versions Vision 280: All versions Vision 290: All versions Vision 530: All versions Vision 120: All versions.,CVE-2024-1480,8.7,High,CWE-257,Water and Wastewater Systems,Worldwide,Israel,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2815,4/16/2024,4/16/2024,2024,ICSA-24-107-01,Measuresoft ScadaPro,Measuresoft,ScadaPro,"The following versions of ScadaPro, a supervisory control and data acquisition (SCADA) system, are affected: ScadaPro: version 6.9.0.0.",CVE-2024-3746,6.8,Medium,CWE-284,Energy; Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2814,4/16/2024,4/16/2024,2024,ICSA-24-107-02,Electrolink FM/DAB/TV Transmitter,Electrolink,FM/DAB/TV Transmitter,"The following Electrolink transmitters are affected: 10W, 100W, 250W, Compact DAB Transmitter 500W, 1kW, 2kW Medium DAB Transmitter 2.5kW, 3kW, 4kW, 5kW High Power DAB Transmitter 100W, 500W, 1kW, 2kW Compact FM Transmitter 3kW, 5kW, 10kW, 15kW, 20kW, 30kW Modular FM Transmitter 15W - 40kW Digital FM Transmitter BI, BIII VHF TV Transmitter 10W - 5kW UHF TV Transmitter.","CVE-2024-1491, CVE-2024-21846, CVE-2024-21872, CVE-2024-22179, CVE-2024-22186, CVE-2024-3741, CVE-2024-3742",8.8,High,"CWE-302, CWE-565, CWE-306, CWE-312",Communications,Worldwide,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2813,4/16/2024,5/9/2024,2024,ICSA-24-107-03,Rockwell Automation ControlLogix and GuardLogix (Update A),Rockwell Automation,"ControlLogix 5580, GuardLogix 5580, CompactLogix 5380, 1756-EN4TR","The following versions of Rockwell Automation ControlLogix and GuardLogix, programmable logic controllers, are affected: ControlLogix 5580: Version V35.011 GuardLogix 5580: Version V35.011 CompactLogix 5380: Version V35.011 1756-EN4TR: Version V5.001 Compact GuardLogix 5380: V35.011 ControlLogix 5580 Process: V35.011 CompactLogix 5380 Process: V35.011 CompactLogix 5480: V35.011.",CVE-2024-3493,9.2,Critical,CWE-20,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2812,4/16/2024,4/16/2024,2024,ICSA-24-107-04,RoboDK RoboDK,RoboDK,RoboDK,"The following versions of RoboDK, a robotics development software, are affected: RoboDK: RoboDK v5.5.4 (Windows 64 bit).",CVE-2024-0257,3.3,Low,CWE-122,Critical Manufacturing,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2811,4/11/2024,4/11/2024,2024,ICSA-24-102-01,Siemens SIMATIC S7-1500,Siemens,SIMATIC S7-1500,The following Siemens products are affected: Siemens SIMATIC S7-1500 TM MFP (GNU/Linux subsystem): All versions.,"CVE-2023-45898, CVE-2023-5678, CVE-2023-6121, CVE-2023-6817, CVE-2023-6931, CVE-2023-6932, CVE-2024-0727",7.8,High,"CWE-754, CWE-20, CWE-416, CWE-787",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2810,4/11/2024,4/11/2024,2024,ICSA-24-102-02,Siemens SIMATIC WinCC,Siemens,"SIMATIC PCS 7, SIMATIC WinCC","The following versions of Siemens SIMATIC PCS 7 and SIMATIC WinCC, a SCADA system, are affected: Siemens SIMATIC PCS 7 V9.1: All versions before V9.1 SP2 UC04 Siemens SIMATIC WinCC Runtime Professional V17: All versions Siemens SIMATIC WinCC Runtime Professional V18: All versions Siemens SIMATIC WinCC Runtime Professional V19: All versions before V19 Update 1 Siemens SIMATIC WinCC V7.5: All versions before V7.5 SP2 Update 16 Siemens SIMATIC WinCC V8.0: All versions.",CVE-2023-50821,6.9,Medium,CWE-120,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2809,4/11/2024,4/11/2024,2024,ICSA-24-102-03,Siemens RUGGEDCOM APE1808 before V11.0.1,Siemens,RUGGEDCOM APE1808,"The following versions of Siemens RUGGEDCOM APE1808, an application hosting platform, are affected: Siemens RUGGEDCOM APE1808: All versions with Palo Alto Networks Virtual NGFW before V11.0.1.","CVE-2022-0028, CVE-2023-0005, CVE-2023-0008, CVE-2023-38046, CVE-2023-6790, CVE-2023-6791",6.1,Medium,"CWE-406, CWE-497, CWE-73, CWE-79, CWE-522, CWE-610",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2808,4/11/2024,4/11/2024,2024,ICSA-24-102-04,Siemens RUGGEDCOM APE1808,Siemens,RUGGEDCOM APE1808,"The following versions of Siemens RUGGEDCOM APE1808, an application hosting platform, are affected: Siemens RUGGEDCOM APE1808: All versions with Palo Alto Networks Virtual NGFW configured with support for the CHACHA20-POLY1305 algorithm or any Encrypt-then-MAC algorithms (CVE-2023-48795) Siemens RUGGEDCOM APE1808: All versions with Palo Alto Networks Virtual NGFW (CVE-2023-6789, CVE-2023-6793, CVE-2024-0008) Siemens RUGGEDCOM APE1808: All versions with Palo Alto Networks Virtual NGFW that are configured with BGP routing features enabled (CVE-2023-38802).","CVE-2023-38802, CVE-2023-48795, CVE-2023-6789, CVE-2023-6793, CVE-2024-0008",8.2,High,"CWE-79, CWE-269, CWE-754, CWE-222, CWE-613",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2807,4/11/2024,4/11/2024,2024,ICSA-24-102-05,Siemens Scalance W1750D,Siemens,Scalance W1750D,"The following products of Siemens Scalance W1750D, a direct access point, are affected: Siemens SCALANCE W1750D (JP) (6GK5750-2HX01-1AD0): All versions prior to V8.10.0.9 Siemens SCALANCE W1750D (ROW) (6GK5750-2HX01-1AA0): All versions prior to V8.10.0.9 Siemens SCALANCE W1750D (USA) (6GK5750-2HX01-1AB0): All versions prior to V8.10.0.9.","CVE-2023-35980, CVE-2023-35981, CVE-2023-35982",9.8,Critical,CWE-120,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2806,4/11/2024,4/11/2024,2024,ICSA-24-102-06,Siemens Parasolid,Siemens,Parasolid,"The following products of Siemens, are affected: Siemens Parasolid V35.1: Versions prior to V35.1.254 Siemens Parasolid V36.0: Versions prior to V36.0.207 Siemens Parasolid V36.1: Versions prior to V36.1.147.","CVE-2024-26275, CVE-2024-26276, CVE-2024-26277",7.3,High,"CWE-125, CWE-770, CWE-476",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2805,4/11/2024,4/11/2024,2024,ICSA-24-102-07,Siemens SINEC NMS,Siemens,SINEC NMS,"The following products of Siemens, are affected: SINEC NMS: All versions prior to V2.0 SP2.","CVE-2023-5678, CVE-2024-31978",7.2,High,"CWE-754, CWE-22",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2804,4/11/2024,4/11/2024,2024,ICSA-24-102-08,Siemens Telecontrol Server Basic,Siemens,Telecontrol Server Basic,Siemens reports that the following products are affected: Siemens TeleControl Server Basic V3: versions prior to V3.1.2.,"CVE-2022-40303, CVE-2022-40304, CVE-2022-4304, CVE-2022-43513, CVE-2022-43514, CVE-2022-4450, CVE-2022-44725, CVE-2022-46908, CVE-2023-0215, CVE-2023-0286, CVE-2023-0464, CVE-2023-0465, CVE-2023-0466, CVE-2023-21528, CVE-2023-21568, CVE-2023-21704, CVE-2023-21705, CVE-2023-21713, CVE-2023-21718, CVE-2023-23384, CVE-2023-28484, CVE-2023-29349, CVE-2023-29356, CVE-2023-29469, CVE-2023-32025, CVE-2023-32026, CVE-2023-32027, CVE-2023-32028, CVE-2023-3446, CVE-2023-36049, CVE-2023-36417, CVE-2023-36420, CVE-2023-36560, CVE-2023-36728, CVE-2023-36730, CVE-2023-36785, CVE-2023-36788, CVE-2023-36792, CVE-2023-36793, CVE-2023-36794, CVE-2023-36796, CVE-2023-36873, CVE-2023-36899, CVE-2023-38169, CVE-2023-39615, CVE-2023-4807, CVE-2023-5678",8.8,High,"CWE-326, CWE-415, CWE-190, CWE-73, CWE-22, CWE-20, CWE-311, CWE-416, CWE-295, CWE-1333, CWE-754, CWE-476, CWE-119",Energy; Transportation Systems; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2803,4/11/2024,4/25/2024,2024,ICSA-24-102-09,Rockwell Automation 5015-AENFTXT (Update A),Rockwell Automation,5015-AENFTXT,The following Rockwell Automation ethernet/IP adapter products are affected: 5015-AENFTXT: v2.011 to v2.012.,CVE-2024-2424,8.7,High,CWE-20,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2802,4/9/2024,4/9/2024,2024,ICSA-24-100-01,SUBNET PowerSYSTEM Server and Substation Server,SUBNET Solutions Inc.,"PowerSYSTEM Server, Substation Server 2021",SUBNET Solutions reports that the following products use components with vulnerabilities: PowerSYSTEM Server: version 4.07.00 and prior Substation Server 2021: version 4.07.00 and prior.,CVE-2024-3313,8.6,High,CWE-1357,Critical Manufacturing; Energy,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2801,4/4/2024,4/4/2024,2024,ICSA-24-095-01,Hitachi Energy Asset Suite 9,Hitachi Energy,Asset Suite 9,"The following versions of Hitachi Energy's Asset Suite, an enterprise asset management tool, are affected: Asset Suite: Versions prior to 9.6.3.13 Asset Suite: Versions prior to 9.6.4.1.",CVE-2024-2244,6.9,Medium,CWE-287,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2800,4/4/2024,4/4/2024,2024,ICSA-24-095-02,Schweitzer Engineering Laboratories SEL,Schweitzer Engineering Laboratories,SEL 700 series relays,The following Schweitzer Engineering Laboratories products are affected: SEL-700BT Motor Bus Transfer Relay: R301-V0 up to but not including R301-V6 SEL-700BT Motor Bus Transfer Relay: R302-V0 up to but not including R302-V1 SEL-700G Generator Protection Relay: R100-V0 up to but not including R301-V6 SEL-700G Generator Protection Relay: R302-V0 up to but not including R302-V1 SEL-710-5 Motor Protection Relay: R100-V0 up to but not including R302-V1 SEL-751 Feeder Protection Relay: R101-V0 up to but not including R302-V3 SEL-751 Feeder Protection Relay: R400-V0 up to but not including R400-V2 SEL-787-2/-3/-4 Transformer Protection Relay: R100-V0 up to but not including R302-V1 SEL-787Z High-Impedance Differential Relay: R302-V0 up to but not including R302-V3.,CVE-2024-2103,5.9,Medium,CWE-1242,Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2799,4/2/2024,4/2/2024,2024,ICSA-24-093-01,IOSIX IO-1020 Micro ELD,IOSiX,IO-1020 Micro ELD,The following IOSiX products are affected: IO-1020 Micro ELD: Versions prior to 360.,"CVE-2024-30210, CVE-2024-31069, CVE-2024-28878",9.4,Critical,"CWE-1392, CWE-494",Transportation Systems,North America,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2798,3/26/2024,3/26/2024,2024,ICSA-24-086-01,Automation-Direct C-MORE EA9 HMI,AutomationDirect,C-MORE EA9 HMI,"The following versions of C-MORE EA9 HMI, a display system used for interfacing with controllers, are affected: C-MORE EA9 HMI EA9-T6CL: Version 6.77 and prior, C-MORE EA9 HMI EA9-T7CL: Version 6.77 and prior, C-MORE EA9 HMI EA0-T7CL-R: Version 6.77 and prior, C-MORE EA9 HMI EA9-T8CL: Version 6.77 and prior, C-MORE EA9 HMI EA9-T10CL: Version 6.77 and prior, C-MORE EA9 HMI EA9-T10WCL: Version 6.77 and prior, C-MORE EA9 HMI EA9-T12CL: Version 6.77 and prior, C-MORE EA9 HMI EA9-T15CL: Version 6.77 and prior, C-MORE EA9 HMI EA9-T15CL-R: Version 6.77 and prior, C-MORE EA9 HMI EA9-RHMI: Version 6.77 and prior, C-MORE EA9 HMI EA9-PGMSW: Version 6.77 and prior.","CVE-2024-25136, CVE-2024-25137, CVE-2024-25138",7.5,High,"CWE-22, CWE-121, CWE-256",Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2797,3/26/2024,3/26/2024,2024,ICSA-24-086-02,Rockwell Automation PowerFlex 527,Rockwell Automation,PowerFlex 527,Rockwell Automation reports that the following versions of PowerFlex 527 adjustable frequency AC drives are affected: PowerFlex 527: Versions v2.001.x and later.,"CVE-2024-2425, CVE-2024-2426, CVE-2024-2427",8.7,High,"CWE-120, CWE-400",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2796,3/26/2024,3/26/2024,2024,ICSA-24-086-03,Rockwell Automation Arena Simulation,Rockwell Automation,Arena Simulation Software,Rockwell Automation reports that the following versions of Arena Simulation Software are affected: Arena Simulation Software: version 16.00.,"CVE-2024-21912, CVE-2024-21913, CVE-2024-2929, CVE-2024-21918, CVE-2024-21919, CVE-2024-21920",7.8,High,"CWE-787, CWE-122, CWE-119, CWE-416, CWE-824, CWE-125",Food and Agriculture; Healthcare and Public Health; Critical Manufacturing; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2795,3/26/2024,3/26/2024,2024,ICSA-24-086-04,Rockwell Automation FactoryTalk View ME,Rockwell Automation,FactoryTalk View ME,"The following versions of FactoryTalk View ME, an HMI software application, are affected: FactoryTalk View ME: prior to v14.",CVE-2024-21914,6.9,Medium,CWE-79,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2794,3/21/2024,3/21/2024,2024,ICSA-24-081-01,Advantech WebAccess/SCADA,Advantech,WebAccess/SCADA,"The following versions of Advantech WebAccess/SCADA, a bowser-based SCADA software, are affected: WebAccess/SCADA: Version 9.1.5U.",CVE-2024-2453,7.1,High,CWE-89,Critical Manufacturing; Energy; Water and Wastewater Systems,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2793,3/19/2024,3/19/2024,2024,ICSA-24-079-01,Franklin Fueling System EVO 550/5000,Franklin Fueling System,"EVO 550, EVO 5000","The following versions of Franklin Fueling System EVO 550 and EVO 5000, an automatic tank gauge (ATG), are affected: EVO 550: All versions prior to 2.26.3.8963 EVO 5000: All versions prior to 2.26.3.8963.",CVE-2024-2442,8.7,High,CWE-25,Critical Manufacturing; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2792,3/14/2024,3/14/2024,2024,ICSA-24-074-01,Siemens SENTRON 7KM PAC3x20,Siemens,"SENTRON 7KM PAC3120, SENTRON 7KM PAC3220","The following versions of Siemens SENTRON 7KM PAC3120 and PAC3220, power measuring devices, are affected: SENTRON 7KM PAC3120 AC/DC (7KM3120-0BA01-1DA0): Versions V3.2.3 and after but before V3.3.0 only when manufactured between LQN231003... and LQN231215... (with LQNYYMMDD...) SENTRON 7KM PAC3120 DC (7KM3120-1BA01-1EA0): Versions V3.2.3 and after but before V3.3.0 only when manufactured between LQN231003... and LQN231215... (with LQNYYMMDD...) SENTRON 7KM PAC3220 AC/DC (7KM3220-0BA01-1DA0): Versions V3.2.3 and after but before V3.3.0 only when manufactured between LQN231003... and LQN231215... (with LQNYYMMDD...) SENTRON 7KM PAC3220 DC (7KM3220-1BA01-1EA0): Versions V3.2.3 and after but before V3.3.0 only when manufactured between LQN231003... and LQN231215... (with LQNYYMMDD...).",CVE-2024-21483,4.6,Medium,CWE-284,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2791,3/14/2024,3/14/2024,2024,ICSA-24-074-02,Siemens Solid Edge,Siemens,Solid Edge,"The following versions of Siemens Solid Edge, a product development tool, are affected: Solid Edge: Versions prior to V223.0.11.",CVE-2023-49125,7.8,High,CWE-125,Critical Manufacturing; Commercial Facilities; Energy; Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2790,3/14/2024,3/14/2024,2024,ICSA-24-074-03,Siemens SINEMA Remote Connect Server,Siemens,SINEMA Remote Connect Server,"The following versions of Siemens SINEMA Remote Connect Server, a remote management platform, are affected: SINEMA Remote Connect Server: Versions prior to V3.2, SINEMA Remote Connect Server: Versions prior to V3.1.","CVE-2020-23064, CVE-2022-32257",9.8,Critical,"CWE-79, CWE-284",Critical Manufacturing; Commercial Facilities; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2789,3/14/2024,3/14/2024,2024,ICSA-24-074-04,Siemens SINEMA Remote Connect Client,Siemens,SINEMA Remote Connect Client,"The following versions of Siemens SINEMA Remote Connect Client, a remote management platform, are affected: SINEMA Remote Connect Client: All versions prior to V3.1 SP1.",CVE-2024-22045,7.6,High,CWE-538,Critical Manufacturing; Commercial Facilities; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2788,3/14/2024,3/14/2024,2024,ICSA-24-074-05,Siemens RUGGEDCOM APE1808,Siemens,RUGGEDCOM APE1808,"The following versions of Siemens RUGGEDCOM APE1808, an application hosting platform, are affected: RUGGEDCOM APE1808: All versions with Fortinet NGFW.","CVE-2023-38545, CVE-2023-38546, CVE-2023-44250, CVE-2023-44487, CVE-2023-47537, CVE-2024-21762, CVE-2024-23113",9.8,Critical,"CWE-122, CWE-73, CWE-269, CWE-400, CWE-295, CWE-787, CWE-134",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2787,3/14/2024,3/14/2024,2024,ICSA-24-074-06,Siemens SENTRON,Siemens,SENTRON,The following Siemens SENTRON products are affected: SENTRON 3KC ATC6 Expansion Module Ethernet (3KC9000-8TL75): all versions.,CVE-2024-22044,7.5,High,CWE-912,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2786,3/14/2024,3/14/2024,2024,ICSA-24-074-07,Siemens SIMATIC,Siemens,SIMATIC,Siemens reports that the following SIMATIC mobile RFID reader products are affected: SIMATIC RF160B (6GT2003-0FA00): versions prior to V2.2.,"CVE-2017-14491, CVE-2017-18509, CVE-2020-0338, CVE-2020-0417, CVE-2020-10768, CVE-2020-11301, CVE-2020-14305, CVE-2020-14381, CVE-2020-15436, CVE-2020-24587, CVE-2020-25705, CVE-2020-26555, CVE-2020-26558, CVE-2020-29660, CVE-2020-29661, CVE-2021-0302, CVE-2021-0305, CVE-2021-0325, CVE-2021-0326, CVE-2021-0327, CVE-2021-0328, CVE-2021-0329, CVE-2021-0330, CVE-2021-0331, CVE-2021-0333, CVE-2021-0334, CVE-2021-0336, CVE-2021-0337, CVE-2021-0339, CVE-2021-0341, CVE-2021-0390, CVE-2021-0391, CVE-2021-0392, CVE-2021-0393, CVE-2021-0394, CVE-2021-0396, CVE-2021-0397, CVE-2021-0399, CVE-2021-0400, CVE-2021-0429, CVE-2021-0431, CVE-2021-0433, CVE-2021-0434, CVE-2021-0435, CVE-2021-0436, CVE-2021-0437, CVE-2021-0438, CVE-2021-0443, CVE-2021-0444, CVE-2021-0471, CVE-2021-0473, CVE-2021-0474, CVE-2021-0476, CVE-2021-0478, CVE-2021-0480, CVE-2021-0481, CVE-2021-0484, CVE-2021-0506, CVE-2021-0507, CVE-2021-0508, CVE-2021-0509, CVE-2021-0510, CVE-2021-0511, CVE-2021-0512, CVE-2021-0513, CVE-2021-0514, CVE-2021-0515, CVE-2021-0516, CVE-2021-0519, CVE-2021-0520, CVE-2021-0521, CVE-2021-0522, CVE-2021-0584, CVE-2021-0585, CVE-2021-0586, CVE-2021-0587, CVE-2021-0588, CVE-2021-0589, CVE-2021-0591, CVE-2021-0593, CVE-2021-0594, CVE-2021-0596, CVE-2021-0597, CVE-2021-0598, CVE-2021-0599, CVE-2021-0600, CVE-2021-0601, CVE-2021-0604, CVE-2021-0640, CVE-2021-0641, CVE-2021-0642, CVE-2021-0646, CVE-2021-0650, CVE-2021-0651, CVE-2021-0652, CVE-2021-0653, CVE-2021-0682, CVE-2021-0683, CVE-2021-0684, CVE-2021-0687, CVE-2021-0688, CVE-2021-0689, CVE-2021-0690, CVE-2021-0692, CVE-2021-0695, CVE-2021-0704, CVE-2021-0706, CVE-2021-0708, CVE-2021-0870, CVE-2021-0919, CVE-2021-0920, CVE-2021-0926, CVE-2021-0928, CVE-2021-0929, CVE-2021-0930, CVE-2021-0931, CVE-2021-0933, CVE-2021-0952, CVE-2021-0953, CVE-2021-0961, CVE-2021-0963, CVE-2021-0964, CVE-2021-0965, CVE-2021-0967, CVE-2021-0968, CVE-2021-0970, CVE-2021-1972, CVE-2021-1976, CVE-2021-29647, CVE-2021-33909, CVE-2021-38204, CVE-2021-39621, CVE-2021-39623, CVE-2021-39626, CVE-2021-39627, CVE-2021-39629, CVE-2021-39633, CVE-2021-39634, CVE-2022-20127, CVE-2022-20130, CVE-2022-20227, CVE-2022-20229, CVE-2022-20355, CVE-2022-20411, CVE-2022-20421, CVE-2022-20422, CVE-2022-20423, CVE-2022-20462, CVE-2022-20466, CVE-2022-20468, CVE-2022-20469, CVE-2022-20472, CVE-2022-20473, CVE-2022-20476, CVE-2022-20483, CVE-2022-20498, CVE-2022-20500",9.8,Critical,"CWE-119, CWE-20, CWE-311, CWE-732, CWE-440, CWE-287, CWE-787, CWE-416, CWE-326, CWE-330, CWE-863, CWE-667, CWE-1021, CWE-269, CWE-862, CWE-312, CWE-754, CWE-295, CWE-415, CWE-190, CWE-125, CWE-665, CWE-362, CWE-908, CWE-755, CWE-909, CWE-668, CWE-610, CWE-74, CWE-834, CWE-281, CWE-116, CWE-681, CWE-502, CWE-120, CWE-1188, CWE-835, CWE-191",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2785,3/14/2024,3/14/2024,2024,ICSA-24-074-08,Siemens SCALANCE XB-200/XC-200/XP-200/XF-200BA/XR-300WG Family,Siemens,SCALANCE XB-200/XC-200/XP-200/XF-200BA/XR-300WG Family,"The following products of Siemens, are affected: SCALANCE XB205-3 (SC, PN) (6GK5205-3BB00-2AB2): All versions SCALANCE XB205-3 (ST, E/IP) (6GK5205-3BB00-2TB2): All versions SCALANCE XB205-3 (ST, E/IP) (6GK5205-3BD00-2TB2): All versions SCALANCE XB205-3 (ST, PN) (6GK5205-3BD00-2AB2): All versions SCALANCE XB205-3LD (SC, E/IP) (6GK5205-3BF00-2TB2): All versions SCALANCE XB205-3LD (SC, PN) (6GK5205-3BF00-2AB2): All versions SCALANCE XB208 (E/IP) (6GK5208-0BA00-2TB2): All versions SCALANCE XB208 (PN) (6GK5208-0BA00-2AB2): All versions SCALANCE XB213-3 (SC, E/IP) (6GK5213-3BD00-2TB2): All versions SCALANCE XB213-3 (SC, PN) (6GK5213-3BD00-2AB2): All versions SCALANCE XB213-3 (ST, E/IP) (6GK5213-3BB00-2TB2): All versions SCALANCE XB213-3 (ST, PN) (6GK5213-3BB00-2AB2): All versions SCALANCE XB213-3LD (SC, E/IP) (6GK5213-3BF00-2TB2): All versions SCALANCE XB213-3LD (SC, PN) (6GK5213-3BF00-2AB2): All versions SCALANCE XB216 (E/IP) (6GK5216-0BA00-2TB2): All versions SCALANCE XB216 (PN) (6GK5216-0BA00-2AB2): All versions SCALANCE XC206-2 (SC) (6GK5206-2BD00-2AC2): All versions SCALANCE XC206-2 (ST/BFOC) (6GK5206-2BB00-2AC2): All versions SCALANCE XC206-2G PoE (6GK5206-2RS00-2AC2): All versions SCALANCE XC206-2G PoE (54 V DC) (6GK5206-2RS00-5AC2): All versions SCALANCE XC206-2G PoE EEC (54 V DC) (6GK5206-2RS00-5FC2): All versions SCALANCE XC206-2SFP (6GK5206-2BS00-2AC2): All versions SCALANCE XC206-2SFP EEC (6GK5206-2BS00-2FC2): All versions SCALANCE XC206-2SFP G (6GK5206-2GS00-2AC2): All versions SCALANCE XC206-2SFP G (EIP DEF.) (6GK5206-2GS00-2TC2): All versions SCALANCE XC206-2SFP G EEC (6GK5206-2GS00-2FC2): All versions SCALANCE XC208 (6GK5208-0BA00-2AC2): All versions SCALANCE XC208EEC (6GK5208-0BA00-2FC2): All versions SCALANCE XC208G (6GK5208-0GA00-2AC2): All versions SCALANCE XC208G (EIP def.) (6GK5208-0GA00-2TC2): All versions SCALANCE XC208G EEC (6GK5208-0GA00-2FC2): All versions SCALANCE XC208G PoE (6GK5208-0RA00-2AC2): All versions SCALANCE XC208G PoE (54 V DC) (6GK5208-0RA00-5AC2): All versions SCALANCE XC216 (6GK5216-0BA00-2AC2): All versions SCALANCE XC216-3G PoE (6GK5216-3RS00-2AC2): All versions SCALANCE XC216-3G PoE (54 V DC) (6GK5216-3RS00-5AC2): All versions SCALANCE XC216-4C (6GK5216-4BS00-2AC2): All versions SCALANCE XC216-4C G (6GK5216-4GS00-2AC2): All versions SCALANCE XC216-4C G (EIP Def.) (6GK5216-4GS00-2TC2): All versions SCALANCE XC216-4C G EEC (6GK5216-4GS00-2FC2): All versions SCALANCE XC216EEC (6GK5216-0BA00-2FC2): All versions SCALANCE XC224 (6GK5224-0BA00-2AC2): All versions SCALANCE XC224-4C G (6GK5224-4GS00-2AC2): All versions SCALANCE XC224-4C G (EIP Def.) (6GK5224-4GS00-2TC2): All versions SCALANCE XC224-4C G EEC (6GK5224-4GS00-2FC2): All versions SCALANCE XF204 (6GK5204-0BA00-2GF2): All versions SCALANCE XF204 DNA (6GK5204-0BA00-2YF2): All versions SCALANCE XF204-2BA (6GK5204-2AA00-2GF2): All versions SCALANCE XF204-2BA DNA (6GK5204-2AA00-2YF2): All versions SCALANCE XP208 (6GK5208-0HA00-2AS6): All versions SCALANCE XP208 (Ethernet/IP) (6GK5208-0HA00-2TS6): All versions SCALANCE XP208EEC (6GK5208-0HA00-2ES6): All versions SCALANCE XP208PoE EEC (6GK5208-0UA00-5ES6): All versions SCALANCE XP216 (6GK5216-0HA00-2AS6): All versions SCALANCE XP216 (Ethernet/IP) (6GK5216-0HA00-2TS6): All versions SCALANCE XP216EEC (6GK5216-0HA00-2ES6): All versions SCALANCE XP216POE EEC (6GK5216-0UA00-5ES6): All versions SCALANCE XR324WG (24 x FE, AC 230V) (6GK5324-0BA00-3AR3): All versions SCALANCE XR324WG (24 X FE, DC 24V) (6GK5324-0BA00-2AR3): All versions SCALANCE XR326-2C PoE WG (6GK5326-2QS00-3AR3): All versions SCALANCE XR326-2C PoE WG (without UL) (6GK5326-2QS00-3RR3): All versions SCALANCE XR328-4C WG (24xFE,4xGE,AC230V) (6GK5328-4FS00-3AR3): All versions SCALANCE XR328-4C WG (24xFE,4xGE,AC230V) (6GK5328-4FS00-3RR3): All versions SCALANCE XR328-4C WG (24XFE, 4XGE, 24V) (6GK5328-4FS00-2AR3): All versions SCALANCE XR328-4C WG (24xFE, 4xGE,DC24V) (6GK5328-4FS00-2RR3): All versions SCALANCE XR328-4C WG (28xGE, AC 230V) (6GK5328-4SS00-3AR3): All versions SCALANCE XR328-4C WG (28xGE, DC 24V) (6GK5328-4SS00-2AR3): All versions SIPLUS NET SCALANCE XC206-2 (6AG1206-2BB00-7AC2): All versions SIPLUS NET SCALANCE XC206-2SFP (6AG1206-2BS00-7AC2): All versions SIPLUS NET SCALANCE XC208 (6AG1208-0BA00-7AC2): All versions SIPLUS NET SCALANCE XC216-4C (6AG1216-4BS00-7AC2): All versions.","CVE-2023-44318, CVE-2023-44321",4.9,Medium,"CWE-321, CWE-400",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2784,3/14/2024,3/14/2024,2024,ICSA-24-074-09,Siemens Sinteso EN Cerberus PRO EN Fire Protection Systems,Siemens,"Sinteso EN, Cerberus PRO EN Fire Protection Systems","The following products of Siemens, are affected: Cerberus PRO EN Engineering Tool: Versions prior to IP8 Cerberus PRO EN Engineering Tool: All versions Cerberus PRO EN Fire Panel FC72x: Versions prior to IP8 Cerberus PRO EN Fire Panel FC72x: Versions prior to IP8 SR4 Cerberus PRO EN X200 Cloud Distribution: Versions prior to V4.0.5016 Cerberus PRO EN X200 Cloud Distribution: Versions prior to V4.3.5618 Cerberus PRO EN X300 Cloud Distribution: Versions prior to V4.2.5015 Cerberus PRO EN X300 Cloud Distribution: Versions prior to V4.3.5617 Sinteso FS20 EN Engineering Tool: Versions prior to MP8 Sinteso FS20 EN Engineering Tool: All versions Sinteso FS20 EN Fire Panel FC20: Versions prior to MP8 Sinteso FS20 EN Fire Panel FC20: Versions prior to MP8 SR4 Sinteso FS20 EN X200 Cloud Distribution: Versions prior to V4.0.5016 Sinteso FS20 EN X200 Cloud Distribution: Versions prior to V4.3.5618 Sinteso FS20 EN X300 Cloud Distribution: Versions prior to V4.2.5015 Sinteso FS20 EN X300 Cloud Distribution: Versions prior to V4.3.5617 Sinteso Mobile: Versions prior to V3.0.0 Sinteso Mobile: All versions.","CVE-2024-22039, CVE-2024-22040, CVE-2024-22041",10.0,Critical,"CWE-120, CWE-125, CWE-119",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2783,3/14/2024,3/14/2024,2024,ICSA-24-074-10,Siemens Siveillance Control,Siemens,Siveillance Control,"The following products of Siemens, are affected: Siveillance Control: Versions V2.8 and after until V3.1.1.",CVE-2023-45793,5.5,Medium,CWE-863,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2782,3/14/2024,3/14/2024,2024,ICSA-24-074-11,Siemens RUGGEDCOM APE1808 with Fortigate NGFW Devices,Siemens,RUGGEDCOM APE1808 devices,The following products of Siemens using Fortinet NGFW V7.4.1 and prior are affected: RUGGEDCOM APE1808: All versions.,"CVE-2022-39948, CVE-2022-41327, CVE-2022-41328, CVE-2022-41329, CVE-2022-41330, CVE-2022-41334, CVE-2022-42469, CVE-2022-42474, CVE-2022-42476, CVE-2022-43947, CVE-2022-43953, CVE-2022-45861, CVE-2023-22639, CVE-2023-22640, CVE-2023-22641, CVE-2023-25610, CVE-2023-26207, CVE-2023-27997, CVE-2023-28001, CVE-2023-28002, CVE-2023-29175, CVE-2023-29178, CVE-2023-29179, CVE-2023-29180, CVE-2023-29181, CVE-2023-29183, CVE-2023-33301, CVE-2023-33305, CVE-2023-33306, CVE-2023-33307, CVE-2023-33308, CVE-2023-36555, CVE-2023-36639, CVE-2023-36641, CVE-2023-37935, CVE-2023-40718, CVE-2023-41675, CVE-2023-41841",9.8,Critical,"CWE-295, CWE-319, CWE-22, CWE-200, CWE-79, CWE-183, CWE-23, CWE-307, CWE-134, CWE-824, CWE-787, CWE-601, CWE-20, CWE-532, CWE-122, CWE-613, CWE-354, CWE-295, CWE-20, CWE-476, CWE-134, CWE-284, CWE-835, CWE-476, CWE-121, CWE-124, CWE-80, CWE-598, CWE-436, CWE-416, CWE-285",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2781,3/14/2024,3/14/2024,2024,ICSA-24-074-12,Delta Electronics DIAEnergie,Delta Electronics,DIAEnergie,The following Delta Electronics products are affected: DIAEnergie: Versions prior to v1.10.00.005.,"CVE-2024-23494, CVE-2024-23975, CVE-2024-25567, CVE-2024-25574, CVE-2024-25937, CVE-2024-28029, CVE-2024-28040, CVE-2024-28045, CVE-2024-28171, CVE-2024-28891",8.8,High,"CWE-285, CWE-89, CWE-22, CWE-79",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2780,3/14/2024,3/14/2024,2024,ICSA-24-074-13,Softing edgeConnector,Softing Industrial Automation GmbH,edgeConnector,The following versions of Softing edgeConnector are affected: Softing edgeConnector: Version 3.60 Softing edgeAggregator: Version 3.60.,"CVE-2023-38126, CVE-2024-0860",7.2,High,"CWE-22, CWE-319",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2779,3/14/2024,6/13/2024,2024,ICSA-24-074-14,Mitsubishi Electric MELSEC-Q/L Series (Update B),Mitsubishi Electric,MELSEC-Q/L Series,"The following versions of Mitsubishi Electric MELSEC-Q/L Series, a controller used for factory automation, are affected: MELSEC-Q Series Q03UDECPU: The first 5 digits of serial No. ""26061"" and prior MELSEC-Q Series Q04UDEHCPU: The first 5 digits of serial No. ""26061"" and prior MELSEC-Q Series Q06UDEHCPU: The first 5 digits of serial No. ""26061"" and prior MELSEC-Q Series Q10UDEHCPU: The first 5 digits of serial No. ""26061"" and prior MELSEC-Q Series Q13UDEHCPU: The first 5 digits of serial No. ""26061"" and prior MELSEC-Q Series Q20UDEHCPU: The first 5 digits of serial No. ""26061"" and prior MELSEC-Q Series Q26UDEHCPU: The first 5 digits of serial No. ""26061"" and prior MELSEC-Q Series Q50UDEHCPU: The first 5 digits of serial No. ""26061"" and prior MELSEC-Q Series Q100UDEHCPU: The first 5 digits of serial No. ""26061"" and prior MELSEC-Q Series Q03UDVCPU: The first 5 digits of serial No. ""26061"" and prior MELSEC-Q Series Q04UDVCPU: The first 5 digits of serial No. ""26061"" and prior MELSEC-Q Series Q06UDVCPU: The first 5 digits of serial No. ""26061"" and prior MELSEC-Q Series Q13UDVCPU: The first 5 digits of serial No. ""26061"" and prior MELSEC-Q Series Q26UDVCPU: The first 5 digits of serial No. ""26061"" and prior MELSEC-Q Series Q04UDPVCPU: The first 5 digits of serial No. ""26061"" and prior MELSEC-Q Series Q06UDPVCPU: The first 5 digits of serial No. ""26061"" and prior MELSEC-Q Series Q13UDPVCPU: The first 5 digits of serial No. ""26061"" and prior MELSEC-Q Series Q26UDPVCPU: The first 5 digits of serial No. ""26061"" and prior MELSEC-L Series L02CPU(-P): The first 5 digits of serial numbers ""26041"" and prior MELSEC-L Series L06CPU(-P): The first 5 digits of serial numbers ""26041"" and prior MELSEC-L Series L26CPU(-P): The first 5 digits of serial numbers ""26041"" and prior MELSEC-L Series L26CPU-(P)BT: The first 5 digits of serial numbers ""26041"" and prior.","CVE-2024-0802, CVE-2024-0803, CVE-2024-1915, CVE-2024-1916, CVE-2024-1917",9.8,Critical,"CWE-468, CWE-190",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2778,3/12/2024,3/12/2024,2024,ICSA-24-072-01,Schneider Electric EcoStruxure Power Design,Schneider Electric,EcoStruxure Power Design,"The following versions of Schneider Electric - EcoStruxure Power Design - Ecodial, an equipment management platform, are affected: EcoStruxure Power Design - Ecodial NL: All Versions EcoStruxure Power Design - Ecodial INT: All Versions EcoStruxure Power Design - Ecodial FR: All Versions.",CVE-2024-2229,7.8,High,CWE-502,Commercial Facilities; Information Technology; Healthcare and Public Health; Critical Manufacturing; Transportation Systems; Energy; Chemical,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2777,3/7/2024,5/2/2024,2024,ICSA-24-067-01,Chirp Systems Chirp Access (Update C),Chirp Systems,Chirp Access,The following Chirp Systems products are affected when deployed in non-networked beacon configurations: Chirp Access app (Android and iOS): All Versions.,CVE-2024-2197,2.3,Low,CWE-259,Commercial Facilities,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2776,3/5/2024,3/5/2024,2024,ICSA-24-065-01,Nice Linear eMerge E3-Series,Nice,Linear eMerge E3-Series,The following versions of Nice Linear eMerge E3-Series are affected: Linear eMerge E3-Series: versions 1.00-06 and prior.,"CVE-2019-7253, CVE-2019-7254, CVE-2019-7255, CVE-2019-7256, CVE-2019-7257, CVE-2019-7258, CVE-2019-7259, CVE-2019-7260, CVE-2019-7261, CVE-2019-7262, CVE-2019-7264, CVE-2019-7265",10.0,Critical,"CWE-22, CWE-79, CWE-78, CWE-434, CWE-863, CWE-200, CWE-522, CWE-798, CWE-352, CWE-787",Commercial Facilities,Worldwide,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2775,3/5/2024,3/5/2024,2024,ICSMA-24-065-01,Santesoft Sante FFT Imaging,Santesoft,Sante FFT Imaging,The following Santesoft products are affected: Sante FFT Imaging: Versions 1.4.1 and prior.,CVE-2024-1696,7.8,High,CWE-787,Healthcare and Public Health,Worldwide,Cyprus,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2774,2/29/2024,2/29/2024,2024,ICSA-24-060-01,Delta Electronics CNCSoft-B,Delta Electronics,CNCSoft-B,The following Delta Electronics products are affected: CNCSoft-B: Versions 1.0.0.4 and prior.,CVE-2024-1941,7.8,High,CWE-121,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2773,2/29/2024,2/29/2024,2024,ICSMA-24-060-01,MicroDicom DICOM Viewer,MicroDicom,DICOM Viewer,"The following versions of MicroDicom DICOM Viewer, a medical image viewer, are affected: MicroDicom DICOM Viewer: Versions 2023.3 (Build 9342) and prior.","CVE-2024-22100, CVE-2024-25578",7.8,High,"CWE-122, CWE-787",Healthcare and Public Health,Worldwide,Bulgaria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2772,2/27/2024,1/16/2025,2024,ICSA-24-058-01,Mitsubishi Electric Multiple Factory Automation Products (Update A),Mitsubishi Electric,Multiple Factory Automation products,The following versions of Mitsubishi Electric Factory Automation products are affected: MELSEC iQ-R series CPU module R00CPU: All Versions MELSEC iQ-R series CPU module R01CPU: All Versions MELSEC iQ-R series CPU module R02CPU: All Versions MELSEC iQ-R series CPU module R04 (EN)CPU: All Versions MELSEC iQ-R series CPU module R08 (EN)CPU: All Versions MELSEC iQ-R series CPU module R16 (EN)CPU: All Versions MELSEC iQ-R series CPU module R32(EN)CPU: All Versions MELSEC iQ-R series CPU module R120(EN)CPU: All Versions MELSEC iQ-R series CPU module R08SFCPU: All Versions MELSEC iQ-R series CPU module R16SFCPU: All Versions MELSEC iQ-R series CPU module R32SFCPU: All Versions MELSEC iQ-R series CPU module R120SFCPU: All Versions MELSEC iQ-R series CPU module R08PCPU: All Versions MELSEC iQ-R series CPU module R16PCPU: All Versions MELSEC iQ-R series CPU module R32PCPU: All Versions MELSEC iQ-R series CPU module R120PCPU: All Versions MELSEC iQ-R series CPU module R08PSFCPU: All Versions MELSEC iQ-R series CPU module R16PSFCPU: All Versions MELSEC iQ-R series CPU module R32PSFCPU: All Versions MELSEC iQ-R series CPU module R120PSFCPU: All Versions MELSEC iQ-L series CPU module L04HCPU(sold in limited regions): All Versions MELSEC iQ-L series CPU module L08HCPU(sold in limited regions): All Versions MELSEC iQ-L series CPU module L16HCPU(sold in limited regions): All Versions MELSEC iQ-L series CPU module L32HCPU(sold in limited regions): All Versions MELSEC iQ-R Ethernet Interface Module RJ71EN71: All Versions MELSEC iQ-R CC-Link IE TSN Master/Local Module RJ71GN11-T2: All Versions MELSEC iQ-R CC-Link IE TSN Master/Local Module RJ71GN11-SX: All Versions MELSEC iQ-R CC-Link IE TSN Master/Local Module RJ71GN11-EIP: All Versions CC-Link IE TSN Remote I/O Module NZ2GN2B1-32D: All Versions CC-Link IE TSN Remote I/O Module NZ2GN2B1-32T: All Versions CC-Link IE TSN Remote I/O Module NZ2GN2B1-32TE: All Versions CC-Link IE TSN Remote I/O Module NZ2GN2B1-32DT: All Versions CC-Link IE TSN Remote I/O Module NZ2GN2B1-32DTE: All Versions CC-Link IE TSN Remote I/O Module NZ2GN2B1-16D: All Versions CC-Link IE TSN Remote I/O Module NZ2GN2B1-16T: All Versions CC-Link IE TSN Remote I/O Module NZ2GN2B1-16TE: All Versions CC-Link IE TSN Remote I/O Module NZ2GN2S1-32D: All Versions CC-Link IE TSN Remote I/O Module NZ2GN2S1-32T: All Versions CC-Link IE TSN Remote I/O Module NZ2GN2S1-32TE: All Versions CC-Link IE TSN Remote I/O Module NZ2GN2S1-32DT: All Versions CC-Link IE TSN Remote I/O Module NZ2GN2S1-32DTE: All Versions CC-Link IE TSN Remote I/O Module NZ2GN2S1-16D: All Versions CC-Link IE TSN Remote I/O Module NZ2GN2S1-16T: All Versions CC-Link IE TSN Remote I/O Module NZ2GN2S1-16TE: All Versions CC-Link IE TSN Remote I/O Module NZ2GNCF1-32D: All Versions CC-Link IE TSN Remote I/O Module NZ2GNCF1-32T: All Versions CC-Link IE TSN Remote I/O Module NZ2GNCE3-32D: All Versions CC-Link IE TSN Remote I/O Module NZ2GNCE3-32DT: All Versions CC-Link IE TSN Remote I/O Module NZ2GN12A4-16D: All Versions CC-Link IE TSN Remote I/O Module NZ2GN12A4-16DE: All Versions CC-Link IE TSN Remote I/O Module NZ2GN12A2-16T: All Versions CC-Link IE TSN Remote I/O Module NZ2GN12A2-16TE: All Versions CC-Link IE TSN Remote I/O Module NZ2GN12A42-16DT: All Versions CC-Link IE TSN Remote I/O Module NZ2GN12A42-16DTE: All Versions CC-Link IE TSN Analog-Digital Converter Module NZ2GN2S-60AD4: All Versions CC-Link IE TSN Analog-Digital Converter Module NZ2GN2B-60AD4: All Versions CC-Link IE TSN Digital-Analog Converter Module NZ2GN2S-60DA4: All Versions CC-Link IE TSN Digital-Analog Converter Module NZ2GN2B-60DA4: All Versions CC-Link IE TSN - CC-Link IE Field Network Bridge Module NZ2GN-GFB: All Versions CC-Link IE TSN - AnyWireASLINK Bridge Module NZ2AW1GNAL: All Versions CC-Link IE TSN FPGA Module NZ2GN2S-D41P01: All Versions CC-Link IE TSN FPGA Module NZ2GN2S-D41D01: All Versions CC-Link IE TSN FPGA Module NZ2GN2S- D41PD02: All Versions CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY NZ2GACP620-300: All Versions CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY NZ2GACP620-60: All Versions MELSEC iQ-R Motion Module RD78G4: All Versions MELSEC iQ-R Motion Module RD78G8: All Versions MELSEC iQ-R Motion Module RD78G16: All Versions MELSEC iQ-R Motion Module RD78G32: All Versions MELSEC iQ-R Motion Module RD78G64: All Versions MELSEC iQ-R Motion Module RD78GHV: All Versions MELSEC iQ-R Motion Module RD78GHW: All Versions MELSEC iQ-L Motion Module LD78G4(sold in limited regions): All Versions MELSEC iQ-L Motion Module LD78G16(sold in limited regions): All Versions MELSEC iQ-F FX5 Motion Module FX5-40SSC-G: All Versions MELSEC iQ-F FX5 Motion Module FX5-80SSC-G: All Versions MELSEC iQ-F Series CPU module FX5U-32MT/ES: All Versions MELSEC iQ-F Series CPU module FX5U-32MT/DS: All Versions MELSEC iQ-F Series CPU module FX5U-32MT/ESS: All Versions MELSEC iQ-F Series CPU module FX5U-32MT/DSS: All Versions MELSEC iQ-F Series CPU module FX5U-32MR/ES: All Versions MELSEC iQ-F Series CPU module FX5U-32MR/DS: All Versions MELSEC iQ-F Series CPU module FX5U-64MT/ES: All Versions MELSEC iQ-F Series CPU module FX5U-64MT/DS: All Versions MELSEC iQ-F Series CPU module FX5U-64MT/ESS: All Versions MELSEC iQ-F Series CPU module FX5U-64MT/DSS: All Versions MELSEC iQ-F Series CPU module FX5U-64MR/ES: All Versions MELSEC iQ-F Series CPU module FX5U-64MR/DS: All Versions MELSEC iQ-F Series CPU module FX5U-80MT/ES: All Versions MELSEC iQ-F Series CPU module FX5U-80MT/DS: All Versions MELSEC iQ-F Series CPU module FX5U-80MT/ESS: All Versions MELSEC iQ-F Series CPU module FX5U-80MT/DSS: All Versions MELSEC iQ-F Series CPU module FX5U-80MR/ES: All Versions MELSEC iQ-F Series CPU module FX5U-80MR/DS: All Versions MELSEC iQ-F Series CPU module FX5UC-32MT/D: All Versions MELSEC iQ-F Series CPU module FX5UC-32MT/DSS: All Versions MELSEC iQ-F Series CPU module FX5UC-64MT/D: All Versions MELSEC iQ-F Series CPU module FX5UC-64MT/DSS: All Versions MELSEC iQ-F Series CPU module FX5UC-96MT/D: All Versions MELSEC iQ-F Series CPU module FX5UC-96MT/DSS: All Versions MELSEC iQ-F Series CPU module FX5UC-32MT/DS-TS: All Versions MELSEC iQ-F Series CPU module FX5UC-32MT/DSS-TS: All Versions MELSEC iQ-F Series CPU module FX5UC-32MR/DS-TS: All Versions MELSEC iQ-F Series CPU module FX5UJ-24MT/ES: All Versions MELSEC iQ-F Series CPU module FX5UJ-24MT/DS: All Versions MELSEC iQ-F Series CPU module FX5UJ-24MT/ESS: All Versions MELSEC iQ-F Series CPU module FX5UJ-24MT/DSS: All Versions MELSEC iQ-F Series CPU module FX5UJ-24MR/ES: All Versions MELSEC iQ-F Series CPU module FX5UJ-24MR/DS: All Versions MELSEC iQ-F Series CPU module FX5UJ-40MT/ES: All Versions MELSEC iQ-F Series CPU module FX5UJ-40MT/DS: All Versions MELSEC iQ-F Series CPU module FX5UJ-40MT/ESS: All Versions MELSEC iQ-F Series CPU module FX5UJ-40MT/DSS: All Versions MELSEC iQ-F Series CPU module FX5UJ-40MR/ES: All Versions MELSEC iQ-F Series CPU module FX5UJ-40MR/DS: All Versions MELSEC iQ-F Series CPU module FX5UJ-60MT/ES: All Versions MELSEC iQ-F Series CPU module FX5UJ-60MT/DS: All Versions MELSEC iQ-F Series CPU module FX5UJ-60MT/ESS: All Versions MELSEC iQ-F Series CPU module FX5UJ-60MT/DSS: All Versions MELSEC iQ-F Series CPU module FX5UJ-60MR/ES: All Versions MELSEC iQ-F Series CPU module FX5UJ-60MR/DS: All Versions MELSEC iQ-F Series CPU module FX5UJ-24MT/ES-A (sold in limited regions): All Versions MELSEC iQ-F Series CPU module FX5UJ-24MR/ES-A (sold in limited regions): All Versions MELSEC iQ-F Series CPU module FX5UJ-40MT/ES-A (sold in limited regions): All Versions MELSEC iQ-F Series CPU module FX5UJ-40MR/ES-A (sold in limited regions): All Versions MELSEC iQ-F Series CPU module FX5UJ-60MT/ES-A (sold in limited regions): All Versions MELSEC iQ-F Series CPU module FX5UJ-60MR/ES-A (sold in limited regions): All Versions MELSEC iQ-F Series CPU module FX5S-30MT/ES: All Versions MELSEC iQ-F Series CPU module FX5S-30MT/ESS: All Versions MELSEC iQ-F Series CPU module FX5S-30MR/ES: All Versions MELSEC iQ-F Series CPU module FX5S-40MT/ES: All Versions MELSEC iQ-F Series CPU module FX5S-40MT/ESS: All Versions MELSEC iQ-F Series CPU module FX5S-40MR/ES: All Versions MELSEC iQ-F Series CPU module FX5S-60MT/ES: All Versions MELSEC iQ-F Series CPU module FX5S-60MT/ESS: All Versions MELSEC iQ-F Series CPU module FX5S-60MR/ES: All Versions MELSEC iQ-F Series CPU module FX5S-80MT/ES (sold in limited regions): All versions MELSEC iQ-F Series CPU module FX5S-80MT/ESS (sold in limited regions): All versions MELSEC iQ-F Series CPU module FX5S-80MR/ES (sold in limited regions): All versions MELSEC iQ-F Series Ethernet module FX5-ENET: All Versions MELSEC iQ-F Series Ethernet/IP module FX5-ENET/IP: All Versions MELSEC iQ-F Series OPC UA Module FX5-OPC: All Versions MELSEC iQ-F Series CC-Link IE TSN master/local module FX5-CCLGN-MS: All Versions GOT2000 Series CC-Link IE TSN Communication Unit GT25-J71GN13-T2: All Versions FR-A800-E series inverters FR-A800-E series: All Versions FR-F800-E series inverters FR-F800-E series: All Versions FR-E800-E series inverters FR-E800-E series: All Versions INVERTER CC-Link IE TSN Plug-in option FR-A8NCG: All Versions INVERTER CC-Link IE TSN Safety Plug-in option FR-A8NCG-S: All Versions INVERTER CC-Link IE TSN communication function built-in type FR-A800-GN: All Versions MR-J5 series AC Servos MELSERVO MR-J5-A series: All Versions MR-J5 series AC Servos MELSERVO MR-J5-G series: All Versions MR-J5 series AC Servos MELSERVO MR-J5W-G series: All Versions MR-J5 series AC Servos MELSERVO MR-J5D-G series: All Versions MR-JET series AC Servos MELSERVO MR-JET-G series (sold in limited regions): All Versions MR-MD333G series AC Servos MELSERVO MR-MD333G series: All Versions MR-JE series AC Servos MELSERVO MR-JE-C series (sold in limited regions): All Versions MELSERVO-J4 AC Servos MELSERVO MR-J4-GF series: Version A4 or later Embedded Type Servo System Controller MR-EM441G series: All Versions.,CVE-2023-7033,5.3,Medium,CWE-410,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2771,2/27/2024,2/27/2024,2024,ICSMA-24-058-01,Santesoft Sante DICOM Viewer Pro,Santesoft,Sante DICOM Viewer Pro,The following Santesoft products and versions are affected: Sante DICOM Viewer Pro: Versions 14.0.3 and prior.,CVE-2024-1453,7.8,High,CWE-125,Healthcare and Public Health,Worldwide,Cyprus,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2770,2/22/2024,2/22/2024,2024,ICSA-24-053-01,Delta Electronics CNCSoft-B DOPSoft,Delta Electronics,CNCSoft-B DOPSoft,The following Delta Electronics products are affected: CNCSoft-B v1.0.0.4 DOPSoft: versions prior to v4.0.0.82.,CVE-2024-1595,7.8,High,CWE-427,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2769,2/20/2024,2/20/2024,2024,ICSA-24-051-01,Commend WS203VICM,Commend,WS203VICM,Commend reports that the following versions of WS203VICM video door station are affected: WS203VICM: version 1.7 and prior.,"CVE-2024-21767, CVE-2024-22182, CVE-2024-23492",9.4,Critical,"CWE-88, CWE-284, CWE-261",Commercial Facilities,Worldwide,Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2768,2/20/2024,2/20/2024,2024,ICSA-24-051-02,Ethercat Zeek Plugin,CISA,Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Plugin for Zeek,"The following GitHub commits (versions) of ICSNPP - Ethercat Plugin, a plugin for Zeek, are affected: Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin: versions d78dda6 and prior.","CVE-2023-7242, CVE-2023-7243, CVE-2023-7244",9.8,Critical,"CWE-787, CWE-125",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2767,2/20/2024,4/23/2024,2024,ICSA-24-051-03,Mitsubishi Electric Electrical Discharge Machines (Update A),Mitsubishi Electric,Electrical discharge machines,"Mitsubishi Electric reports that the following electrical discharge machines are affected by this vulnerability in Microsoft Message Queuing service: Wire-cut EDM MV Series MV1200S D-CUBES Series Standard system BRD-B60W000: versions B13 and prior, without Special Modification Patch BRD-C62W003-A0 installed Wire-cut EDM MV Series MV2400S D-CUBES Series Standard system BRD-B60W000: versions B13 and prior, without Special Modification Patch BRD-C62W003-A0 installed Wire-cut EDM MV Series MV4800S D-CUBES Series Standard system BRD-B60W000: versions B13 and prior, without Special Modification Patch BRD-C62W003-A0 installed Wire-cut EDM MV Series MV1200R D-CUBES Series Standard system BRD-B60W000: versions B13 and prior, without Special Modification Patch BRD-C62W003-A0 installed Wire-cut EDM MV Series MV2400R D-CUBES Series Standard system BRD-B60W000: versions B13 and prior, without Special Modification Patch BRD-C62W003-A0 installed Wire-cut EDM MV Series MV4800R D-CUBES Series Standard system BRD-B60W000: versions B13 and prior, without Special Modification Patch BRD-C62W003-A0 installed Wire-cut EDM MV Series MV1200S D-CUBES Series Special system BRD-B63W000 to W036: all versions Wire-cut EDM MV Series MV2400S D-CUBES Series Special system BRD-B63W000 to W036: all versions Wire-cut EDM MV Series MV4800S D-CUBES Series Special system BRD-B63W000 to W036: all versions Wire-cut EDM MV Series MV1200R D-CUBES Series Special system BRD-B63W000 to W036: all versions Wire-cut EDM MV Series MV2400R D-CUBES Series Special system BRD-B63W000 to W036: all versions Wire-cut EDM MV Series MV4800R D-CUBES Series Special system BRD-B63W000 to W036: all versions Wire-cut EDM MP Series MP1200 D-CUBES Series Standard system BRD-B60W000: versions B13 and prior, without Special Modification Patch BRD-C62W003-A0 installed Wire-cut EDM MP Series MP2400 D-CUBES Series Standard system BRD-B60W000: versions B13 and prior, without Special Modification Patch BRD-C62W003-A0 installed Wire-cut EDM MP Series MP4800 D-CUBES Series Standard system BRD-B60W000: versions B13 and prior, without Special Modification Patch BRD-C62W003-A0 installed Wire-cut EDM MP Series MP1200 D-CUBES Series Special system BRD-B63W000 to W036: all versions Wire-cut EDM MP Series MP2400 D-CUBES Series Special system BRD-B63W000 to W036: all versions Wire-cut EDM MP Series MP4800 D-CUBES Series Special system BRD-B63W000 to W036: all versions Wire-cut EDM MX Series MX900 D-CUBES Series Standard system BRD-B60W000: versions B13 and prior, without Special Modification Patch BRD-C62W003-A0 installed Wire-cut EDM MX Series MX2400 D-CUBES Series Standard system BRD-B60W000: versions B13 and prior, without Special Modification Patch BRD-C62W003-A0 installed Wire-cut EDM MX Series MX900 D-CUBES Series Special system BRD-B63W000 to W036: all versions Wire-cut EDM MX Series MX2400 D-CUBES Series Special system BRD-B63W000 to W036: all versions Sinker EDM SV-P Series SV8P D-CUBES Series Standard system BRD-M60W000: versions A12 and prior, without Special Modification Patch BRD-C62W003-A0 installed Sinker EDM SV-P Series SV12P D-CUBES Series Standard system BRD-M60W000: versions A12 and prior, without Special Modification Patch BRD-C62W003-A0 installed Sinker EDM SV-P Series SV8P D-CUBES Series Special system BRD-M63W000 to W022: all versions Sinker EDM SV-P Series SV12P D-CUBES Series Special system BRD-M63W000 to W022: all versions Sinker EDM SG Series SG8 D-CUBES Series Standard system BRD-M60W000: versions A12 and prior, without Special Modification Patch BRD-C62W003-A0 installed Sinker EDM SG Series SG12 D-CUBES Series Standard system BRD-M60W000: versions A12 and prior, without Special Modification Patch BRD-C62W003-A0 installed Sinker EDM SG Series SG28 D-CUBES Series Standard system BRD-M60W000: versions A12 and prior, without Special Modification Patch BRD-C62W003-A0 installed Sinker EDM SG Series SG8 D-CUBES Series Special system BRD-BRD-M63W000 to W022: all versions Sinker EDM SG Series SG12 D-CUBES Series Special system BRD-M63W000 to W022: all versions Sinker EDM SG Series SG28 D-CUBES Series Special system BRD-M63W000 to W022: all versions.",CVE-2023-21554,9.3,Critical,CWE-20,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2766,2/15/2024,2/15/2024,2024,ICSA-24-046-01,Siemens SCALANCE W1750D,Siemens,SCALANCE W1750D,"The following products of Siemens, are affected: SCALANCE W1750D (JP) (6GK5750-2HX01-1AD0): All versions SCALANCE W1750D (ROW) (6GK5750-2HX01-1AA0): All versions SCALANCE W1750D (USA) (6GK5750-2HX01-1AB0): All versions.","CVE-2023-45614, CVE-2023-45615, CVE-2023-45616, CVE-2023-45617, CVE-2023-45618, CVE-2023-45619, CVE-2023-45620, CVE-2023-45621, CVE-2023-45622, CVE-2023-45623, CVE-2023-45624, CVE-2023-45625, CVE-2023-45626, CVE-2023-45627",9.8,Critical,"CWE-120, CWE-20, CWE-77",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2765,2/15/2024,2/15/2024,2024,ICSA-24-046-02,Siemens SIDIS Prime,Siemens,SIDIS Prime,The following Siemens products are affected: SIDIS Prime: All versions prior to V4.0.400.,"CVE-2019-19135, CVE-2020-1967, CVE-2020-1971, CVE-2022-0778, CVE-2022-29862",9.1,Critical,"CWE-330, CWE-476, CWE-835",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2764,2/15/2024,2/15/2024,2024,ICSA-24-046-03,Siemens SIMATIC RTLS Gateways,Siemens,"SIMATIC RTLS Gateway RTLS4030G, SIMATIC RTLS Gateway RTLS4430G","The following Siemens products are affected: SIMATIC RTLS Gateway RTLS4030G, CMIIT (6GT2701-5DB23): All versions SIMATIC RTLS Gateway RTLS4030G, ETSI (6GT2701-5DB03): All versions SIMATIC RTLS Gateway RTLS4030G, FCC (6GT2701-5DB13): All versions SIMATIC RTLS Gateway RTLS4030G, ISED (6GT2701-5DB33): All versions SIMATIC RTLS Gateway RTLS4430G, Chirp, ETSI, FCC, ISED, IP65 (6GT2701-5CB03): All versions.",CVE-2020-11896,7.7,High,CWE-130,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2763,2/15/2024,2/15/2024,2024,ICSA-24-046-04,Siemens CP343-1 Devices,Siemens,"SIMATIC CP 343-1, SIMATIC CP 343-1Lean, SIPLUS NET CP 343-1, SIPLUS NET CP 343-1 Lean",The following Siemens products are affected: SIMATIC CP 343-1 (6GK7343-1EX30-0XE0): All versions SIMATIC CP 343-1 Lean (6GK7343-1CX10-0XE0): All versions SIPLUS NET CP 343-1 (6AG1343-1EX30-7XE0): All versions SIPLUS NET CP 343-1 Lean (6AG1343-1CX10-2XE0): All versions.,CVE-2023-51440,8.7,High,CWE-940,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2762,2/15/2024,2/15/2024,2024,ICSA-24-046-05,Siemens Location Intelligence,Siemens,"Location Intelligence Perpetual Large, Location Intelligence Perpetual Medium, Location Intelligence Perpetual Non-Prod, Location Intelligence Perpetual Small, Location Intelligence SUS Large, Location Intelligence SUS Medium, Location Intelligence SUS Non-Prod, Location Intelligence SUS Small",The following Siemens products are affected: Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0): All versions prior to V4.3 Location Intelligence Perpetual Medium (9DE5110-8CA12-1AX0): All versions prior to V4.3 Location Intelligence Perpetual Non-Prod (9DE5110-8CA10-1AX0): All versions prior to V4.3 Location Intelligence Perpetual Small (9DE5110-8CA11-1AX0): All versions prior to V4.3 Location Intelligence SUS Large (9DE5110-8CA13-1BX0): All versions prior to V4.3 Location Intelligence SUS Medium (9DE5110-8CA12-1BX0): All versions prior to V4.3 Location Intelligence SUS Non-Prod (9DE5110-8CA10-1BX0): All versions prior to V4.3 Location Intelligence SUS Small (9DE5110-8CA11-1BX0): All versions prior to V4.3.,CVE-2024-23816,9.3,Critical,CWE-798,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2761,2/15/2024,2/15/2024,2024,ICSA-24-046-06,Siemens Unicam FX,Siemens,Unicam FX,The following Siemens products are affected: Unicam FX: All versions.,CVE-2024-22042,8.5,High,CWE-648,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2760,2/15/2024,2/15/2024,2024,ICSA-24-046-07,Siemens Tecnomatix Plant Simulation,Siemens,Tecnomatix Plant Simulation,"The following Siemens products are affected: Tecnomatix Plant Simulation V2201: Versions prior to V2201.0012 (CVE-2024-23795, CVE-2024-23796, CVE-2024-23797, CVE-2024-23798, CVE-2024- 23802, CVE-2024-23804) Tecnomatix Plant Simulation V2201: All versions (CVE-2024-23799, CVE-2024-23800, CVE-2024-23801, CVE-2024-23803) Tecnomatix Plant Simulation V2302: Versions prior to V2302.0006 (CVE-2024-23795, CVE-2024-23796, CVE-2024-23797, CVE-2024-23798, CVE-2024- 23802, CVE-2024-23804) Tecnomatix Plant Simulation V2302: Versions prior to V2302.0007 (CVE-2024-23799, CVE-2024-23800, CVE-2024-23801, CVE-2024-23803).","CVE-2024-23795, CVE-2024-23796, CVE-2024-23797, CVE-2024-23798, CVE-2024-23799, CVE-2024-23800, CVE-2024-23801, CVE-2024-23802, CVE-2024-23803, CVE-2024-23804",7.3,High,"CWE-787, CWE-122, CWE-121, CWE-476, CWE-125, CWE-787",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2759,2/15/2024,2/15/2024,2024,ICSA-24-046-08,Siemens RUGGEDCOM APE1808,Siemens,RUGGEDCOM APE1808,The following products with Nozomi Guardian/CMC are affected: RUGGEDCOM APE1808: All versions prior to 23.3.0.,CVE-2023-5253,5.3,Medium,CWE-200,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2758,2/15/2024,2/15/2024,2024,ICSA-24-046-09,Siemens SCALANCE SC-600 Family,Siemens,SCALANCE SC-600 Family,"The following Siemens products are affected: SCALANCE SC622-2C (6GK5622-2GS00-2AC2) (CVE-2023-44317, CVE-2023-44373, CVE-2023-49691, CVE-2023-49692): Versions prior to V3.0.2 SCALANCE SC622-2C (6GK5622-2GS00-2AC2) (CVE-2023-44319, CVE-2023-44320, CVE-2023-44322): Versions prior to V3.1 SCALANCE SC622-2C (6GK5622-2GS00-2AC2) (CVE-2023-44321): All versions SCALANCE SC626-2C (6GK5626-2GS00-2AC2) (CVE-2023-44317, CVE-2023-44373, CVE-2023-49691, CVE-2023-49692): Versions prior to V3.0.2 SCALANCE SC626-2C (6GK5626-2GS00-2AC2) (CVE-2023-44319, CVE-2023-44320, CVE-2023-44322): Versions prior to V3.1 SCALANCE SC626-2C (6GK5626-2GS00-2AC2) (CVE-2023-44321): All versions SCALANCE SC632-2C (6GK5632-2GS00-2AC2) (CVE-2023-44317, CVE-2023-44373, CVE-2023-49691, CVE-2023-49692): Versions prior to V3.0.2 SCALANCE SC632-2C (6GK5632-2GS00-2AC2) (CVE-2023-44319, CVE-2023-44320, CVE-2023-44322): Versions prior to V3.1 SCALANCE SC632-2C (6GK5632-2GS00-2AC2) (CVE-2023-44321): All versions SCALANCE SC636-2C (6GK5636-2GS00-2AC2) (CVE-2023-44317, CVE-2023-44373, CVE-2023-49691, CVE-2023-49692): Versions prior to V3.0.2 SCALANCE SC636-2C (6GK5636-2GS00-2AC2) (CVE-2023-44319, CVE-2023-44320, CVE-2023-44322): Versions prior to V3.1 SCALANCE SC636-2C (6GK5636-2GS00-2AC2) (CVE-2023-44321): All versions SCALANCE SC642-2C (6GK5642-2GS00-2AC2) (CVE-2023-44317, CVE-2023-44373, CVE-2023-49691, CVE-2023-49692): Versions prior to V3.0.2 SCALANCE SC642-2C (6GK5642-2GS00-2AC2) (CVE-2023-44319, CVE-2023-44320, CVE-2023-44322): Versions prior to V3.1 SCALANCE SC642-2C (6GK5642-2GS00-2AC2) (CVE-2023-44321): All versions SCALANCE SC646-2C (6GK5646-2GS00-2AC2) (CVE-2023-44317, CVE-2023-44373, CVE-2023-49691, CVE-2023-49692): Versions prior to V3.0.2 SCALANCE SC646-2C (6GK5646-2GS00-2AC2) (CVE-2023-44319, CVE-2023-44320, CVE-2023-44322): Versions prior to V3.1 SCALANCE SC646-2C (6GK5646-2GS00-2AC2)(CVE-2023-44321): All versions.","CVE-2023-44317, CVE-2023-44319, CVE-2023-44320, CVE-2023-44321, CVE-2023-44322, CVE-2023-44373, CVE-2023-49691, CVE-2023-49692",9.1,Critical,"CWE-349, CWE-328, CWE-425, CWE-400, CWE-252, CWE-74, CWE-78",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2757,2/15/2024,2/15/2024,2024,ICSA-24-046-10,Siemens Simcenter Femap,Siemens,Simcenter Femap,"The following Siemens products are affected: Simcenter Femap: Versions prior to V2401.0000 (CVE-2024-24920, CVE-2024-24921, CVE-2024-24922, CVE-2024-24923) Simcenter Femap: Versions prior to V2306.0001 (CVE-2024-24923) Simcenter Femap: Versions prior to V2306.0000 (CVE-2024-24924, CVE-2024-24925).","CVE-2024-24920, CVE-2024-24921, CVE-2024-24922, CVE-2024-24923, CVE-2024-24924, CVE-2024-24925",7.3,High,"CWE-787, CWE-119, CWE-125, CWE-824",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2756,2/15/2024,2/15/2024,2024,ICSA-24-046-11,Siemens SCALANCE XCM-/XRM-300,Siemens,SCALANCE XCM-/XRM-300,"Siemens reports that the following versions of SCALANCE XCM-/XRM-300, switches used to connect industrial components, are affected: SCALANCE XCH328 (6GK5328-4TS01-2EC2): versions prior to V2.4 SCALANCE XCM324 (6GK5324-8TS01-2AC2): versions prior to V2.4 SCALANCE XCM328 (6GK5328-4TS01-2AC2): versions prior to V2.4 SCALANCE XCM332 (6GK5332-0GA01-2AC2): versions prior to V2.4 SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3): versions prior to V2.4 SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3): versions prior to V2.4 SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3): versions prior to V2.4 SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3): versions prior to V2.4 SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3): versions prior to V2.4 SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3): versions prior to V2.4 SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3): versions prior to V2.4.","CVE-2006-20001, CVE-2020-10735, CVE-2021-3445, CVE-2021-3638, CVE-2021-4037, CVE-2021-36369, CVE-2021-43666, CVE-2021-45451, CVE-2022-1015, CVE-2022-1348, CVE-2022-2586, CVE-2022-2880, CVE-2022-3294, CVE-2022-3437, CVE-2022-3515, CVE-2022-4415, CVE-2022-4743, CVE-2022-4744, CVE-2022-4900, CVE-2022-4904, CVE-2022-23471, CVE-2022-23521, CVE-2022-24834, CVE-2022-26691, CVE-2022-28737, CVE-2022-28738, CVE-2022-28739, CVE-2022-29154, CVE-2022-29162, CVE-2022-29187, CVE-2022-29536, CVE-2022-32148, CVE-2022-34903, CVE-2022-34918, CVE-2022-36021, CVE-2022-36227, CVE-2022-36760, CVE-2022-37436, CVE-2022-37454, CVE-2022-37797, CVE-2022-38725, CVE-2022-39189, CVE-2022-39260, CVE-2022-41409, CVE-2022-41556, CVE-2022-41715, CVE-2022-41717, CVE-2022-41723, CVE-2022-41860, CVE-2022-41861, CVE-2022-41862, CVE-2022-41903, CVE-2022-42919, CVE-2022-44370, CVE-2022-45061, CVE-2022-45142, CVE-2022-45919, CVE-2022-46392, CVE-2022-46393, CVE-2022-47629, CVE-2022-48303, CVE-2022-48434, CVE-2023-0160, CVE-2023-0330, CVE-2023-0361, CVE-2023-0494, CVE-2023-0567, CVE-2023-0568, CVE-2023-0590, CVE-2023-0662, CVE-2023-1206, CVE-2023-1380, CVE-2023-1393, CVE-2023-1611, CVE-2023-1670, CVE-2023-1838, CVE-2023-1855, CVE-2023-1859, CVE-2023-1989, CVE-2023-1990, CVE-2023-2002, CVE-2023-2124, CVE-2023-2194, CVE-2023-2269, CVE-2023-2861, CVE-2023-2953, CVE-2023-3006, CVE-2023-3090, CVE-2023-3111, CVE-2023-3141, CVE-2023-3212, CVE-2023-3247, CVE-2023-3268, CVE-2023-3301, CVE-2023-3316, CVE-2023-3390, CVE-2023-3611, CVE-2023-3776, CVE-2023-3863, CVE-2023-4128, CVE-2023-4194, CVE-2023-20593, CVE-2023-21255, CVE-2023-22490, CVE-2023-22742, CVE-2023-22745, CVE-2023-23454, CVE-2023-23931, CVE-2023-23934, CVE-2023-23946, CVE-2023-24538, CVE-2023-25153, CVE-2023-25155, CVE-2023-25193, CVE-2023-25588, CVE-2023-25690, CVE-2023-25727, CVE-2023-26081, CVE-2023-26965, CVE-2023-27522, CVE-2023-27534, CVE-2023-27535, CVE-2023-27536, CVE-2023-28450, CVE-2023-28466, CVE-2023-28486, CVE-2023-28487, CVE-2023-29402, CVE-2023-29404, CVE-2023-29405, CVE-2023-29406, CVE-2023-29409, CVE-2023-30086, CVE-2023-30456, CVE-2023-30772, CVE-2023-31084, CVE-2023-31124, CVE-2023-31130, CVE-2023-31147, CVE-2023-31436, CVE-2023-31489, CVE-2023-32067, CVE-2023-32233, CVE-2023-32573, CVE-2023-33203, CVE-2023-34256, CVE-2023-34872, CVE-2023-34969, CVE-2023-35001, CVE-2023-35788, CVE-2023-35789, CVE-2023-35823, CVE-2023-35824, CVE-2023-35828, CVE-2023-36054, CVE-2023-36617, CVE-2023-36664, CVE-2023-37920, CVE-2023-38559, CVE-2023-40283",9.8,Critical,"CWE-787, CWE-704, CWE-347, CWE-284, CWE-287, CWE-311, CWE-327, CWE-732, CWE-416, CWE-444, CWE-20, CWE-122, CWE-190, CWE-401, CWE-415, CWE-1284, CWE-400, CWE-697, CWE-125, CWE-276, CWE-282, CWE-74, CWE-843, CWE-407, CWE-476, CWE-113, CWE-770, CWE-354, CWE-203, CWE-667, CWE-131, CWE-863, CWE-212, CWE-252, CWE-362, CWE-59, CWE-120, CWE-754, CWE-22, CWE-94, CWE-908, CWE-79, CWE-668, CWE-116, CWE-436, CWE-330, CWE-124, CWE-369, CWE-522, CWE-824, CWE-1333, CWE-78, CWE-345",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2755,2/15/2024,2/15/2024,2024,ICSA-24-046-12,"Siemens SIMATIC WinCC, OpenPCS",Siemens,"SIMATIC, OpenPCS","The following products of Siemens, are affected: OpenPCS 7 V9.1: All versions SIMATIC BATCH V9.1: All versions SIMATIC PCS 7 V9.1: All versions SIMATIC Route Control V9.1: All versions SIMATIC WinCC Runtime Professional V18: All versions SIMATIC WinCC Runtime Professional V19: All versions SIMATIC WinCC V7.4: All versions SIMATIC WinCC V7.5: All versions prior to V7.5 SP2 Update 15 SIMATIC WinCC V8.0: All versions prior V8.0 SP4.","CVE-2023-48363, CVE-2023-48364",7.1,High,CWE-476,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2754,2/15/2024,2/15/2024,2024,ICSA-24-046-13,Siemens Parasolid,Siemens,Parasolid,The following products of Siemens are affected: Parasolid V35.0: all versions prior to V35.0.263 Parasolid V35.0: all versions prior to V35.0.251 Parasolid V35.1: all versions prior to V35.1.252 Parasolid V35.1: all versions prior to V35.1.170 Parasolid V36.0: all versions prior to V36.0.198.,"CVE-2023-49125, CVE-2024-22043",7.8,High,"CWE-125, CWE-476",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2753,2/15/2024,2/15/2024,2024,ICSA-24-046-14,Siemens Polarion ALM,Siemens,Polarion ALM,Siemens reports that the following products are affected: Polarion ALM: all versions.,"CVE-2023-50236, CVE-2024-23813",8.5,High,"CWE-276, CWE-287",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2752,2/15/2024,2/15/2024,2024,ICSA-24-046-15,Siemens SINEC NMS,Siemens,SINEC NMS,Siemens reports that the following network management systems are affected: SINEC NMS: All versions prior to V2.0 SP1.,"CVE-2022-4203, CVE-2022-4304, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0286, CVE-2023-0401, CVE-2023-1255, CVE-2023-2454, CVE-2023-2455, CVE-2023-2650, CVE-2023-2975, CVE-2023-3446, CVE-2023-3817, CVE-2023-25690, CVE-2023-27522, CVE-2023-27533, CVE-2023-27534, CVE-2023-27535, CVE-2023-27536, CVE-2023-27537, CVE-2023-27538, CVE-2023-28319, CVE-2023-28320, CVE-2023-28321, CVE-2023-28322, CVE-2023-28709, CVE-2023-30581, CVE-2023-30582, CVE-2023-30583, CVE-2023-30584, CVE-2023-30585, CVE-2023-30586, CVE-2023-30587, CVE-2023-30588, CVE-2023-30589, CVE-2023-30590, CVE-2023-31124, CVE-2023-31130, CVE-2023-31147, CVE-2023-32002, CVE-2023-32003, CVE-2023-32004, CVE-2023-32005, CVE-2023-32006, CVE-2023-32067, CVE-2023-32558, CVE-2023-32559, CVE-2023-34035, CVE-2023-35945, CVE-2023-38039, CVE-2023-38199, CVE-2023-38545, CVE-2023-38546, CVE-2023-39417, CVE-2023-39418, CVE-2023-41080, CVE-2023-46120, CVE-2024-23810, CVE-2024-23811, CVE-2024-23812",9.8,Critical,"CWE-125, CWE-326, CWE-415, CWE-416, CWE-476, CWE-20, CWE-311, CWE-770, CWE-287, CWE-1333, CWE-834, CWE-444, CWE-74, CWE-22, CWE-362, CWE-295, CWE-193, CWE-862, CWE-330, CWE-124, CWE-732, CWE-400, CWE-863, CWE-843, CWE-122, CWE-89, CWE-601, CWE-434, CWE-78",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2751,2/15/2024,2/15/2024,2024,ICSA-24-046-16,Rockwell Automation FactoryTalk Service Platform,Rockwell Automation,FactoryTalk Service Platform,Rockwell Automation reports that the following versions of FactoryTalk Service Platform are affected: FactoryTalk Service Platform: versions prior to v2.74.,CVE-2024-21915,7.8,High,CWE-279,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2750,2/13/2024,5/16/2024,2024,ICSA-24-044-01,Mitsubishi Electric MELSEC iQ-R Series Safety CPU and SIL2 Process CPU (Update A),Mitsubishi Electric,MELSEC iQ-R Series Safety CPU and SIL2 Process CPU,Mitsubishi Electric reports that the following MELSEC iQ-R Series products are affected: MELSEC iQ-R Series Safety CPU R08SFCPU: all versions MELSEC iQ-R Series Safety CPU R16SFCPU: all versions MELSEC iQ-R Series Safety CPU R32SFCPU: all versions MELSEC iQ-R Series Safety CPU R120SFCPU: all versions MELSEC iQ-R Series SIL2 Process CPU R08PSFCPU: all versions MELSEC iQ-R Series SIL2 Process CPU R16PSFCPU: all versions MELSEC iQ-R Series SIL2 Process CPU R32PSFCPU: all versions MELSEC iQ-R Series SIL2 Process CPU R120PSFCPU: all versions.,CVE-2023-6815,6.5,Medium,CWE-266,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2749,2/8/2024,2/8/2024,2024,ICSA-24-039-01,"Qolsys IQ Panel 4, IQ4 HUB","Qolsys, Inc. (Subsidiary of Johnson Controls)","IQ Panel 4, IQ4 Hub","The following products from Qolsys, Inc, a subsidiary of Johnson Controls, are affected: Qolsys IQ Panel 4: Versions prior to 4.4.2 Qolsys IQ4 Hub: Versions prior to 4.4.2.",CVE-2024-0242,7.3,High,CWE-200,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2748,2/6/2024,2/6/2024,2024,ICSA-24-037-01,HID Global Encoders,HID Global,"iCLASS SE, OMNIKEY",The following HID products are affected when configured as an encoder: iCLASS SE CP1000 Encoder: All versions iCLASS SE Readers: All versions iCLASS SE Reader Modules: All versions iCLASS SE Processors: All versions OMNIKEY 5427CK Readers: All versions OMNIKEY 5127CK Readers: All versions OMNIKEY 5023 Readers: All versions OMNIKEY 5027 Readers: All versions.,CVE-2024-22388,5.9,Medium,CWE-285,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2747,2/6/2024,2/6/2024,2024,ICSA-24-037-02,HID Global Reader Configuration Cards,HID Global,Reader Configuration Cards,The following HID products are affected: HID iCLASS SE reader configuration cards: All versions OMNIKEY Secure Elements reader configuration cards: All versions.,CVE-2024-23806,5.3,Medium,CWE-285,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2746,2/1/2024,2/1/2024,2024,ICSA-24-032-01,Gessler GmbH WEB-MASTER,Gessler GmbH,WEB-MASTER,"The following versions of Gessler GmbH WEB-MASTER, an emergency lighting management system, are affected: WEB-MASTER: version 7.9.","CVE-2024-1039, CVE-2024-1040",9.8,Critical,"CWE-1391, CWE-328",Multiple Critical Sectors,Worlwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2745,2/1/2024,2/1/2024,2024,ICSA-24-032-03,AVEVA Edge products (formerly known as InduSoft Web Studio),AVEVA,AVEVA Edge products (formerly known as InduSoft Web Studio),The following AVEVA Edge products (formerly known as InduSoft Web Studio) are affected: AVEVA Edge: 2020 R2 SP2 and prior.,CVE-2023-6132,7.3,High,CWE-427,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2744,1/30/2024,1/30/2024,2024,ICSA-24-030-01,"Emerson Rosemount GC370XA, GC700XA, GC1500XA",Emerson,"Rosemount GC370XA, GC700XA, GC1500XA",The following Emerson Rosemount Gas Chromatographs are affected: GC370XA: Version 4.1.5 GC700XA: Version 4.1.5 GC1500XA: Version 4.1.5.,"CVE-2023-43609, CVE-2023-46687, CVE-2023-49716, CVE-2023-51761",9.8,Critical,"CWE-77, CWE-287, CWE-285",Energy; Chemical,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2743,1/30/2024,9/18/2025,2024,ICSA-24-030-02,Mitsubishi Electric FA Engineering Software Products (Update D),Mitsubishi Electric,"EZSocket, GT Designer3 Version1(GOT1000), GT Designer3 Version1(GOT2000), GX Works2, GX Works3, MELSOFT Navigator, MT Works2, MX Component, MX OPC Server DA/UA (Software packaged with MC Works64)",The following versions of Mitsubishi Electric FA Engineering Software Products are affected: EZSocket: Versions 3.0 to 5.92 GT Designer3 Version1(GOT1000): Versions 1.325P and prior GT Designer3 Version1(GOT2000): Versions 1.320J and prior GX Works2: Versions 1.11M to 1.626C GX Works3: Versions 1.106L and prior MELSOFT Navigator: Versions 1.04E to 2.102G MT Works2: Versions 1.190Y and prior MX Component: Versions 4.00A to 5.007H MX OPC Server DA/UA (Software packaged with MC Works64): All versions.,"CVE-2023-6942, CVE-2023-6943",9.8,Critical,"CWE-306, CWE-470",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2742,1/30/2024,1/30/2024,2024,ICSA-24-030-03,Mitsubishi Electric MELSEC WS Series Ethernet Interface Module,Mitsubishi Electric,MELSEC WS Series,"The following versions of Mitsubishi Electric MELSEC WS Series Ethernet Interface Modules, are affected: WS0-GETH00200: All serial numbers.",CVE-2023-6374,5.9,Medium,CWE-294,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2741,1/30/2024,1/30/2024,2024,ICSA-24-030-04,Hitron Systems Security Camera DVR,Hitron Systems,DVR,"The following versions of Hitron Systems DVR, a digital video recorder, are affected: DVR HVR-4781: Versions 1.03 through 4.02 DVR HVR-8781: Versions 1.03 through 4.02 DVR HVR-16781: Versions 1.03 through 4.02 DVR LGUVR-4H: Versions 1.02 through 4.02 DVR LGUVR-8H: Versions 1.02 through 4.02 DVR LGUVR-16H: Versions 1.02 through 4.02.","CVE-2024-22768, CVE-2024-22769, CVE-2024-22770, CVE-2024-22771, CVE-2024-22772, CVE-2024-23842",8.1,High,CWE-20,Commercial Facilities,Worldwide,South Korea,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2740,1/30/2024,1/30/2024,2024,ICSA-24-030-05,Rockwell Automation ControlLogix and GuardLogix,Rockwell Automation,"ControlLogix, GuardLogix",The following versions of Rockwell Automation ControlLogix and GuardLogix programmable logic controllers are affected: ControlLogix 5570: Firmware version 20.011 ControlLogix 5570 redundant: Firmware versions 20.054_kit1 GuardLogix 5570: Firmware version 20.011.,CVE-2024 21916,8.6,High,CWE-119,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2739,1/30/2024,1/30/2024,2024,ICSA-24-030-06,Rockwell Automation FactoryTalk Service Platform,Rockwell Automation,FactoryTalk Service Platform,The following Rockwell Automation products are affected: FactoryTalk Service Platform: Versions prior to v6.4.,CVE-2024-21917,9.8,Critical,CWE-347,Critical manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2738,1/30/2024,1/30/2024,2024,ICSA-24-030-07,Rockwell Automation LP30/40/50 and BM40 Operator Interface,Rockwell Automation,"LP30, LP40, LP50, and BM40 Operator Panels",The following Rockwell Automation products are affected: LP30 Operator Panel: Versions prior to V3.5.19.0 LP40 Operator Pane: Versions prior to V3.5.19.0 LP50 Operator Panel: Versions prior to V3.5.19.0 BM40 Operator Panel: Versions prior to V3.5.19.0.,"CVE-2022-47378, CVE-2022-47379, CVE-2022-47380, CVE-2022-47381, CVE-2022-47382, CVE-2022-47383, CVE-2022-47384, CVE-2022-47385, CVE-2022-47386, CVE-2022-47387, CVE-2022-47388, CVE-2022-47389, CVE-2022-47390, CVE-2022-47392, CVE-2022-47393",8.8,High,"CWE-1288, CWE-787, CWE-121, CWE-822",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2737,1/25/2024,1/25/2024,2024,ICSA-24-025-01,Opteev MachineSense FeverWarn,MachineSense LLC.,MachineSense FeverWarn,"The following components of the FeverWarn ecosystem, an IoT-based skin temperature scanning system, are affected: FeverWarn: ESP32 FeverWarn: RaspberryPi FeverWarn: DataHub RaspberryPi.","CVE-2023-46706, CVE-2023-47867, CVE-2023-49115, CVE-2023-49610, CVE-2023-49617, CVE-2023-6221",10.0,Critical,"CWE-306, CWE-798, CWE-284, CWE-20",Healthcare and Public Health Sector,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2736,1/25/2024,1/25/2024,2024,ICSA-24-025-02,SystemK NVR 504/508/516,SystemK,NVR 504/508/516,"The following versions of SystemK NVR, a network video recorder, are affected: NVR 504: 2.3.5SK.30084998 NVR 508: 2.3.5SK.30084998 NVR 516: 2.3.5SK.30084998.",CVE-2023-7227,9.8,Critical,CWE-77,Commercial Facilities,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2735,1/23/2024,1/23/2024,2024,ICSA-24-023-01,APsystems Energy Communication Unit (ECU-C) Power Control Software,APsystems,Energy communication Unit (ECU-C) Power Control Software,The following APsystems products are affected: Energy Communication Unit Power Control Software: C1.2.2 Energy Communication Unit Power Control Software: v3.11.4 Energy Communication Unit Power Control Software: W2.1.NA Energy Communication Unit Power Control Software: v4.1SAA Energy Communication Unit Power Control Software: v4.1NA.,CVE-2022-44037,8.8,High,CWE-284,Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2734,1/23/2024,1/23/2024,2024,ICSA-24-023-02,Crestron AM-300,Crestron,AM-300,The following Crestron AirMedia Presentation System products are affected: AM-300: Version 1.4499.00018.,CVE-2023-6926,8.4,High,CWE-78,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2733,1/23/2024,1/23/2024,2024,ICSA-24-023-03,Voltronic Power ViewPower Pro,Voltronic Power,ViewPower Pro,"The following versions of ViewPower Pro, an Uninterruptable Power Supply (UPS) management software, are affected: ViewPower Pro: 2.0-22165.","CVE-2023-51570, CVE-2023-51571, CVE-2023-51572, CVE-2023-51573",9.8,Critical,"CWE-502, CWE-306, CWE-78, CWE-749",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2732,1/23/2024,1/23/2024,2024,ICSA-23-023-04,Westermo Lynx 206-F2G,Westermo,Lynx 206-F2G,"The following versions of Lynx 206-F2G, a layer three industrial Ethernet switch, are affected: Lynx: Model Version L206-F2G1 Lynx: Firmware Version 4.24.","CVE-2023-38579, CVE-2023-40143, CVE-2023-40544, CVE-2023-45213, CVE-2023-42765, CVE-2023-45222, CVE-2023-45227, CVE-2023-45735",8.0,High,"CWE-79, CWE-94, CWE-942, CWE-319, CWE-352",Multiple Critical Sectors,Worldwide,Sweden,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2731,1/23/2024,1/23/2024,2024,ICSA-24-023-05,Lantronix XPort,Lantronix,XPort,"The following versions of XPort, a device server configuration manager, are affected: XPort Device Server Configuration Manager: Version 2.0.0.13.",CVE-2023-7237,5.7,Medium,CWE-261,Critical Manufacturing; Energy; Healthcare and Public Health; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2730,1/23/2024,1/23/2024,2024,ICSMA-24-023-01,Orthanc Osimis DICOM Web Viewer,Orthanc,Osimis Web Viewer,The following versions of Osimis Web Viewer are affected: Osimis WebViewer: Version 1.4.2.0-9d9eff4.,CVE-2023-7238,7.1,High,CWE-79,Healthcare and Public Health,Worldwide,Belgium,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2729,1/18/2024,1/18/2024,2024,ICSA-24-018-01,AVEVA PI Server,AVEVA,PI Server,"The following versions of AVEVA PI Server, are affected: PI Server: 2023 PI Server: 2018 SP3 P05 and prior.","CVE-2023-31274, CVE-2023-34348",9.8,Critical,"CWE-703, CWE-772",Critical Manufacturing,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2728,1/16/2024,4/30/2024,2024,ICSA-24-016-01,SEW-EURODRIVE MOVITOOLS MotionStudio (Update A),SEW-EURODRIVE,MOVITOOLS MotionStudio,The following versions of MOVITOOLS MotionStudio are affected: MOVITOOLS MotionStudio: Version 6.5.0.2.,CVE-2024-1167,5.6,Medium,CWE-611,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2727,1/16/2024,3/5/2024,2024,ICSA-24-016-02,Integration Objects OPC UA Server Toolkit (Update A),Integration Objects,OPC UA Server Toolkit,"The following versions of OPC UA Server Toolkit, OPC library designed to allow creation of OPC DA, DX and HDA servers software, are affected: OPC UA Server Toolkit: versions 1.0.0 and prior.",CVE-2023-7234,5.3,Medium,CWE-117,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2726,1/11/2024,1/11/2024,2024,ICSA-24-011-03,Rapid Software LLC Rapid SCADA,Rapid Software LLC,Rapid SCADA,"The following versions of Rapid SCADA, an open-source industrial automation platform, are affected: Rapid SCADA: Version 5.8.4 and prior.","CVE-2024-21764, CVE-2024-21794, CVE-2024-21852, CVE-2024-21866, CVE-2024-21869, CVE-2024-22016, CVE-2024-22096",9.6,Critical,"CWE-22, CWE-23, CWE-732, CWE-601, CWE-798, CWE-256, CWE-209",Energy; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2725,1/11/2024,1/11/2024,2024,ICSA-24-011-04,Horner Automation Cscape,Horner Automation,Cscape,The following Horner Automation products are affected: Cscape: Versions 9.90 SP10 and prior.,CVE-2023-7206,7.8,High,CWE-121,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2724,1/11/2024,1/11/2024,2024,ICSA-24-011-05,Schneider Electric Easergy Studio,Schneider Electric,Easergy Studio,"The following versions of Schneider Electric Easergy Studio, a power relay protection control software, are affected: Easergy Studio: Versions prior to v9.3.5.",CVE-2023-7032,7.8,High,CWE-502,Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2723,1/11/2024,1/11/2024,2024,ICSA-24-011-06,Siemens Teamcenter Visualization and JT2Go,Siemens,"JT2Go, Teamcenter Visualization",The following Siemens products are affected: JT2Go: All versions prior to V14.3.0.6 Teamcenter Visualization V13.3: All versions prior to V13.3.0.13 Teamcenter Visualization V14.1: All versions prior to V14.1.0.12 Teamcenter Visualization V14.2: All versions prior to V14.2.0.9 Teamcenter Visualization V14.3: All versions prior to V14.3.0.6.,"CVE-2023-51439, CVE-2023-51744, CVE-2023-51745, CVE-2023-51746",7.8,High,"CWE-125, CWE-476, CWE-121",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2722,1/11/2024,1/11/2024,2024,ICSA-24-011-07,Siemens Spectrum Power 7,Siemens,Spectrum Power 7,The following Siemens products are affected: Spectrum Power 7: All versions prior to V23Q4.,CVE-2023-44120,7.8,High,CWE-732,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2721,1/11/2024,1/11/2024,2024,ICSA-24-011-08,Siemens SICAM A8000,Siemens,SICAM A8000,"The following Siemens products, are affected: CP-8031 MASTER MODULE (6MF2803-1AA00): All versions prior to CPCI85 V05.20 CP-8050 MASTER MODULE (6MF2805-0AA00): All versions prior to CPCI85 V05.20.",CVE-2023-42797,6.6,Medium,CWE-908,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2720,1/11/2024,1/11/2024,2024,ICSA-24-011-09,Siemens SIMATIC CN 4100,Siemens,SIMATIC CN 4100,"The following products of Siemens, are affected: SIMATIC CN 4100: Versions prior to V2.7.","CVE-2023-49251, CVE-2023-49252, CVE-2023-49621",9.8,Critical,"CWE-639, CWE-20, CWE-1392",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2719,1/11/2024,1/11/2024,2024,ICSA-24-011-10,Siemens SIMATIC,Siemens,SIMATIC,"The following Siemens products with maxView Storage Manager on Windows, are affected: SIMATIC IPC647E: All versions prior to V4.14.00.26068 SIMATIC IPC847E: All versions prior to V4.14.00.26068 SIMATIC IPC1047E: All versions prior to V4.14.00.26068.",CVE-2023-51438,10.0,Critical,CWE-20,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2718,1/11/2024,1/11/2024,2024,ICSA-24-011-11,Siemens Solid Edge,Siemens,Solid Edge,"The following Siemens products, are affected: Solid Edge SE2023: All versions prior to V223.0 Update 10.","CVE-2023-49121, CVE-2023-49122, CVE-2023-49123, CVE-2023-49124, CVE-2023-49126, CVE-2023-49127, CVE-2023-49128, CVE-2023-49129, CVE-2023-49130, CVE-2023-49131, CVE-2023-49132",7.8,High,"CWE-122, CWE-125, CWE-787, CWE-121, CWE-824",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2717,1/4/2024,1/4/2024,2024,ICSA-24-004-01,Rockwell Automation FactoryTalk Activation,Rockwell Automation,FactoryTalk Activation Manager,The following versions of Factory Talk are affected: Factory Talk: V4.00 (Utilizes Wibu-Systems CodeMeter <7.60c).,"CVE-2023-38545, CVE-2023-3935",9.8,Critical,CWE-787,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2716,1/4/2024,1/4/2024,2024,ICSA-24-004-02,Mitsubishi Electric Factory Automation Products,Mitsubishi Electric,Multiple Factory Automation Products,"The following Factory Automation products are affected: GT SoftGOT2000: Versions 1.275M to 1.290C (CVE-2023-0286) OPC UA Data Collector: Versions 1.04E and prior (CVE-2023-0286) MX OPC Server UA (Software packaged with MC Works64): Versions 3.05F and later (Packaged with MC Works64 Version 4.03D and later) (CVE-2022-4304) OPC UA Server Unit: All versions (CVE-2022-4304) FX5-OPC: Versions 1.006 and prior (CVE-2022-4304, CVE-2022-4450).","CVE-2022-4304, CVE-2022-4450, CVE-2023-0286",7.5,High,"CWE-208, CWE-415, CWE-843",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2715,12/21/2023,12/21/2023,2023,ICSA-23-355-01,FXC AE1021/AE1021PE,FXC,"AE1021, AE1021PE","The following versions of FXC AE1021, a wireless LAN router, are affected: AE1021PE firmware: version 2.0.9 and earlier AE1021 firmware: version 2.0.9 and earlier.",CVE-2023-49897,8.0,High,CWE-78,Information Technology; Commercial Facilities,Japan,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2714,12/21/2023,12/21/2023,2023,ICSA-23-355-02,QNAP VioStor NVR,QNAP,VioStor NVR,"The following versions of QNAP VioStor NVR, are affected: VioStor NVR QVR firmware: All versions prior to 4.x.",CVE-2023-47565,8.0,High,CWE-78,Commercial Facilities,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2713,12/19/2023,12/19/2023,2023,ICSA-23-353-01,Subnet Solutions Inc. PowerSYSTEM Center,SUBNET Solutions Inc.,PowerSYSTEM Center,"The following versions of PowerSYSTEM Center, a multi-function management platform, are affected: PowerSYSTEM Center: 2020 v5.0.x through 5.16.x.",CVE-2023-6631,7.8,High,CWE-428,Multiple Critical Sectors,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2712,12/19/2023,12/19/2023,2023,ICSA-23-353-02,EFACEC BCU 500,EFACEC,BCU 500,"The following version of EFACEC BCU 500, an automation and control IED, is affected: BCU 500: version 4.07.","CVE-2023-50707, CVE-2023-6689",9.6,Critical,"CWE-400, CWE-352","Critical Manufacturing, Energy",Multiple,Portugal,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2711,12/19/2023,12/19/2023,2023,ICSA-23-353-03,EFACEC UC 500E,EFACEC,UC 500,"The following version of EFACEC UC 500E, a HMI, is affected: UC 500E: version 10.1.0.","CVE-2023-50703, CVE-2023-50704, CVE-2023-50705, CVE-2023-50706",6.3,Medium,"CWE-319, CWE-601, CWE-200, CWE-284","Critical Manufacturing, Energy",Multiple,Portugal,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2710,12/19/2023,12/19/2023,2023,ICSA-23-353-04,Open Design Alliance Drawing SDK,Open Design Alliance,Drawing SDK,The following versions of ODA Drawing SDK are affected: Drawing SDK: Versions prior to 2024.1.,"CVE-2023-22669, CVE-2023-22670, CVE-2023-26495",7.8,High,"CWE-416, CWE-122",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2709,12/19/2023,12/19/2023,2023,ICSA-23-353-05,EuroTel ETL3100 Radio Transmitter,EuroTel,ETL3100,The following versions EuroTel ETL3100 radio transmitter are affected: ETL3100: version v01c01 ETL3100: version v01x37.,"CVE-2023-6928, CVE-2023-6929, CVE-2023-6930",9.8,Critical,"CWE-307, CWE-639, CWE-284",Communications,Worldwide,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2708,12/14/2023,12/14/2023,2023,ICSA-23-348-16,Siemens SINEC INS,Siemens,SINEC INS,The following Siemens products are affected: SINEC INS: Versions prior to V1.0 SP2 Update 2,"CVE-2023-0464, CVE-2023-27538, CVE-2023-48427, CVE-2023-48428, CVE-2023-48429, CVE-2023-48430, CVE-2023-48431",8.1,High,"CWE-295, CWE-20, CWE-78, CWE-394, CWE-392, CWE-754",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2707,12/14/2023,1/4/2024,2023,ICSA-23-348-15,Unitronics Vision and Samba Series (Update A),Unitronics,"Vision Series, Samba Series",The following Unitronics products are affected: VisiLogic: Versions prior to 9.9.00 OS: Versions prior to 12.38.,CVE-2023-6448,9.8,Critical,CWE-1188,Water and Wastewater Systems,Worldwide,Israel,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2706,12/14/2023,12/14/2023,2023,ICSA-23-348-14,Siemens RUGGEDCOM and SCALANCE M-800/S615 Family,Siemens,SCALANCE M-800/S615 Family,"The following products of Siemens, are affected: RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2): All versions prior to V8.0 RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2): All versions RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2): All versions prior to V8.0 RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2): All versions SCALANCE M804PB (6GK5804-0AP00-2AA2): All versions prior to V8.0 SCALANCE M804PB (6GK5804-0AP00-2AA2): All versions SCALANCE M812-1 ADSL-Router (Annex A) (6GK5812-1AA00-2AA2): All versions prior to V8.0 SCALANCE M812-1 ADSL-Router (Annex A) (6GK5812-1AA00-2AA2): All versions SCALANCE M812-1 ADSL-Router (Annex B) (6GK5812-1BA00-2AA2): All versions prior to V8.0 SCALANCE M812-1 ADSL-Router (Annex B) (6GK5812-1BA00-2AA2): All versions SCALANCE M816-1 ADSL-Router (Annex A) (6GK5816-1AA00-2AA2): All versions prior to V8.0 SCALANCE M816-1 ADSL-Router (Annex A) (6GK5816-1AA00-2AA2): All versions SCALANCE M816-1 ADSL-Router (Annex B) (6GK5816-1BA00-2AA2): All versions prior to V8.0 SCALANCE M816-1 ADSL-Router (Annex B) (6GK5816-1BA00-2AA2): All versions SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2): All versions prior to V8.0 SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2): All versions SCALANCE M874-2 (6GK5874-2AA00-2AA2): All versions prior to V8.0 SCALANCE M874-2 (6GK5874-2AA00-2AA2): All versions SCALANCE M874-3 (6GK5874-3AA00-2AA2): All versions prior to V8.0 SCALANCE M874-3 (6GK5874-3AA00-2AA2): All versions SCALANCE M876-3 (EVDO) (6GK5876-3AA02-2BA2): All versions prior to V8.0 SCALANCE M876-3 (EVDO) (6GK5876-3AA02-2BA2): All versions SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2): All versions prior to V8.0 SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2): All versions SCALANCE M876-4 (6GK5876-4AA10-2BA2): All versions prior to V8.0 SCALANCE M876-4 (6GK5876-4AA10-2BA2): All versions SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2): All versions prior to V8.0 SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2): All versions SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2): All versions prior to V8.0 SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2): All versions SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1): All versions prior to V8.0 SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1): All versions SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1): All versions prior to V8.0 SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1): All versions SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1): All versions prior to V8.0 SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1): All versions SCALANCE S615 (6GK5615-0AA00-2AA2): All versions prior to V8.0 SCALANCE S615 (6GK5615-0AA00-2AA2): All versions SCALANCE S615 EEC (6GK5615-0AA01-2AA2): All versions prior to V8.0 SCALANCE S615 EEC (6GK5615-0AA01-2AA2): All versions","CVE-2022-46143, CVE-2023-44318, CVE-2023-44319, CVE-2023-44320, CVE-2023-44321, CVE-2023-44322, CVE-2023-44373, CVE-2023-44374, CVE-2023-49691",9.1,Critical,"CWE-1284, CWE-321, CWE-328, CWE-425, CWE-400, CWE-252, CWE-74, CWE-567, CWE-78",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2705,12/14/2023,12/14/2023,2023,ICSA-23-348-13,Siemens SCALANCE and RUGGEDCOM M-800/S615 Family,Siemens,SCALANCE M-800/S615 Family,"The following products of Siemens, are affected: RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2): All versions prior to V7.2.2 RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2): All versions prior to V7.2.2 SCALANCE M804PB (6GK5804-0AP00-2AA2): All versions prior to V7.2.2 SCALANCE M812-1 ADSL-Router (Annex A) (6GK5812-1AA00-2AA2): All versons prior to V7.2.2 SCALANCE M812-1 ADSL-Router (Annex B) (6GK5812-1BA00-2AA2): All versions prior to V7.2.2 SCALANCE M816-1 ADSL-Router (Annex A) (6GK5816-1AA00-2AA2): All versions prior to V7.2.2 SCALANCE M816-1 ADSL-Router (Annex B) (6GK5816-1BA00-2AA2): All versions prior to V7.2.2 SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2): All versions prior to V7.2.2 SCALANCE M874-2 (6GK5874-2AA00-2AA2): All versions prior to V7.2.2 SCALANCE M874-3 (6GK5874-3AA00-2AA2): All versions prior to V7.2.2 SCALANCE M876-3 (EVDO) (6GK5876-3AA02-2BA2): All versions prior to V7.2.2 SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2): All versions prior to V7.2.2 SCALANCE M876-4 (6GK5876-4AA10-2BA2): All versions prior to V7.2.2 SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2): All versions prior to V7.2.2 SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2): All versions prior to V7.2.2 SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1): All versions prior to V7.2.2 SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1): All versions prior to V7.2.2 SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1): All versions prior to V7.2.2 SCALANCE S615 (6GK5615-0AA00-2AA2): All versions prior to V7.2.2 SCALANCE S615 EEC (6GK5615-0AA01-2AA2): All versions prior to V7.2.2","CVE-2023-44317, CVE-2023-49692",7.2,High,"CWE-349, CWE-78",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2704,12/14/2023,12/14/2023,2023,ICSA-23-348-12,Siemens SICAM Q100 Devices,Siemens,"POWER METER SICAM Q100, POWER METER SICAM Q100","The following products of Siemens, are affected: POWER METER SICAM Q100 (7KG9501-0AA01-2AA1): All versions prior to V2.60 POWER METER SICAM Q100 (7KG9501-0AA31-2AA1): All versions prior to V2.60","CVE-2023-30901, CVE-2023-31238",5.5,Medium,"CWE-352, CWE-732",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2703,12/14/2023,12/14/2023,2023,ICSA-23-348-11,Siemens SINUMERIK,Siemens,"SINUMERIK MC, SINUMERIK ONE",The following Siemens products are affected: SINUMERIK MC: All versions SINUMERIK ONE: All versions,CVE-2023-46156,7.5,High,CWE-416,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2702,12/14/2023,12/14/2023,2023,ICSA-23-348-10,Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1,Siemens,SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1,"The following products of Siemens, are affected: SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0): All versions prior to V3.1.0, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0): All versions prior to V3.1.0, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0): All versions prior to V3.1.0, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0): All versions prior to V3.1.0, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0): All versions prior to V3.1.0.","CVE-2013-0340, CVE-2013-4235, CVE-2014-7209, CVE-2015-20107, CVE-2016-3189, CVE-2016-3709, CVE-2016-4658, CVE-2016-5131, CVE-2016-9318, CVE-2016-10228, CVE-2016-10739, CVE-2017-0663, CVE-2017-7375, CVE-2017-7376, CVE-2017-9047, CVE-2017-9048, CVE-2017-9049, CVE-2016-1839., CVE-2017-9050, CVE-2017-16931, CVE-2017-16932, CVE-2017-17512, CVE-2017-18258, CVE-2018-0495, CVE-2018-12886, CVE-2018-14404, CVE-2018-14567, CVE-2018-18928, CVE-2018-19591, CVE-2018-20482, CVE-2018-20843, CVE-2018-25032, CVE-2019-3855, CVE-2019-3856, CVE-2019-3857, CVE-2019-3858, CVE-2019-3859, CVE-2019-3860, CVE-2019-3861, CVE-2019-3862, CVE-2019-3863, CVE-2019-5018, CVE-2019-5094, CVE-2019-5188, CVE-2019-5435, CVE-2019-5436, CVE-2019-5443, CVE-2019-5481, CVE-2019-5482, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2019-6488, CVE-2019-7309, CVE-2019-8457, CVE-2019-9169, CVE-2019-9636, CVE-2019-9674, CVE-2019-9740, CVE-2019-9923, CVE-2019-9936, CVE-2019-9937, CVE-2019-9947, CVE-2019-9948, CVE-2019-10160, CVE-2019-11360, CVE-2019-12290, CVE-2019-12900, CVE-2019-12904, CVE-2019-13057, CVE-2019-13565, CVE-2019-13627, CVE-2019-15847, CVE-2019-15903,CVE-2019-16056, CVE-2019-16168, CVE-2019-16905, CVE-2019-17498, CVE-2019-17543, CVE-2019-17594, CVE-2019-17595, CVE-2019-18224, CVE-2019-18276, CVE-2019-18348, CVE-2019-19126, CVE-2019-19242, CVE-2019-19244, CVE-2019-19317, CVE-2019-19603, CVE-2019-19645, CVE-2019-19646, CVE-2019-19880, CVE-2019-19906, CVE-2019-19923, CVE-2019-19924, CVE-2019-19925, CVE-2019-19880., CVE-2019-19926, CVE-2019-19956, CVE-2019-19959, CVE-2019-20218, CVE-2019-20367, CVE-2019-20388, CVE-2019-20795, CVE-2019-20907, CVE-2019-25013, CVE-2019-1010022, CVE-2019-1010023, CVE-2019-1010024, CVE-2019-1010025, CVE-2019-1010180, CVE-2020-1712, CVE-2020-1751, CVE-2020-1752, CVE-2020-6096, CVE-2020-7595, CVE-2020-8169, CVE-2020-8177, CVE-2020-8231, CVE-2020-8284, CVE-2020-8285, CVE-2020-8286, CVE-2020-8315, CVE-2020-8492, CVE-2020-9327, CVE-2020-10029, CVE-2020-10531, CVE-2020-10543, CVE-2020-10735, CVE-2020-10878, CVE-2020-11501, CVE-2020-11655, CVE-2020-11656, CVE-2020-12062, CVE-2020-12243, CVE-2020-12723, CVE-2020-12762, CVE-2020-13434, CVE-2020-13435, CVE-2020-13529, CVE-2020-13630, CVE-2020-13631, CVE-2020-13632, CVE-2017-1000082., CVE-2020-13776, CVE-2020-13777, CVE-2020-13871, CVE-2020-14145, CVE-2020-14422, CVE-2020-15358, CVE-2020-15523, CVE-2020-15778, CVE-2020-15801, CVE-2020-19185, CVE-2020-19186, CVE-2020-19187, CVE-2020-19188, CVE-2020-19189, CVE-2020-19190, CVE-2020-19909, CVE-2020-21047, CVE-2020-21913, CVE-2020-22218, CVE-2020-24659, CVE-2020-24977, CVE-2020-25692, CVE-2020-25709, CVE-2020-25710, CVE-2020-26116, CVE-2016-10228., CVE-2020-27618, CVE-2020-28196, CVE-2020-29361, CVE-2020-29362, CVE-2020-29363, CVE-2020-29562, CVE-2020-29573, CVE-2020-35525, CVE-2020-35527, CVE-2020-36221, CVE-2020-36222, CVE-2020-36223, CVE-2020-36224, CVE-2020-36225, CVE-2020-36226, CVE-2020-36227, CVE-2020-36228, CVE-2020-36229, CVE-2020-36230, CVE-2021-3177, CVE-2021-3326, CVE-2021-3426, CVE-2021-3516, CVE-2021-3517, CVE-2021-3518, CVE-2021-3520, CVE-2021-3537, CVE-2021-3541, CVE-2021-3580, CVE-2021-3733, CVE-2021-3737, CVE-2021-3826, CVE-2021-3997, CVE-2021-3998, CVE-2021-3999, CVE-2021-4122, CVE-2021-4189, CVE-2021-4209, CVE-2021-20193, CVE-2021-20227, CVE-2021-20231, CVE-2021-20232, CVE-2021-20305, CVE-2021-22876, CVE-2021-22890, CVE-2021-22897, CVE-2021-22898, CVE-2021-22901, CVE-2021-22922, CVE-2021-22923, CVE-2021-22924, CVE-2021-22925, CVE-2021-22926, CVE-2021-22945, CVE-2021-22946, CVE-2021-22947, CVE-2021-23336, CVE-2021-27212, CVE-2021-27218, CVE-2021-27219, CVE-2021-27645, CVE-2021-28041, CVE-2021-28153, CVE-2021-28363, CVE-2021-28861, CVE-2021-31239, CVE-2021-32292, CVE-2021-33294, CVE-2021-33560, CVE-2021-33574, CVE-2021-33910, CVE-2021-35942, CVE-2021-36084, CVE-2021-36085, CVE-2021-36086, CVE-2021-36087, CVE-2021-36222, CVE-2021-36690, CVE-2021-37600, CVE-2021-37750, CVE-2021-38604, CVE-2021-41617, CVE-2021-43396, CVE-2021-43618, CVE-2021-45960, CVE-2021-46143, CVE-2021-46195, CVE-2021-46828, CVE-2021-46848, CVE-2022-0391, CVE-2022-0563, CVE-2022-0778, CVE-2022-1271, CVE-2022-1292, CVE-2022-1304, CVE-2022-1343, CVE-2022-1434, CVE-2022-1473, CVE-2022-2068, CVE-2022-2097, CVE-2022-2274, CVE-2022-2509, CVE-2022-3715, CVE-2022-3821, CVE-2022-4304, CVE-2022-4450, CVE-2022-22576, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824, CVE-2022-22825, CVE-2022-22826, CVE-2022-22827, CVE-2022-23218, CVE-2022-23219, CVE-2022-23308, CVE-2022-23852, CVE-2022-23990, CVE-2022-24407, CVE-2022-25235, CVE-2022-25236, CVE-2022-25313, CVE-2022-25314, CVE-2022-25315, CVE-2022-26488, CVE-2022-27774, CVE-2022-27775, CVE-2022-27776, CVE-2022-27778, CVE-2022-27779, CVE-2022-27780, CVE-2022-27781, CVE-2022-27782, CVE-2022-27943, CVE-2022-28321, CVE-2022-29155, CVE-2022-29824, CVE-2022-30115, CVE-2022-32205, CVE-2022-32206, CVE-2022-32207, CVE-2022-32208, CVE-2022-32221, CVE-2022-35252, CVE-2022-35260, CVE-2022-35737, CVE-2022-37434, CVE-2022-37454, CVE-2022-40303, CVE-2022-40304, CVE-2022-40674, CVE-2022-42898, CVE-2022-42915, CVE-2022-42916, CVE-2022-43551, CVE-2022-43552, CVE-2022-43680, CVE-2022-45061, CVE-2022-45873, CVE-2022-46908, CVE-2022-48303, CVE-2022-48522, CVE-2022-48560, CVE-2023-0215, CVE-2023-0286, CVE-2023-0361, CVE-2023-0464, CVE-2023-0465, CVE-2023-0466, CVE-2023-0687, CVE-2023-1077, CVE-2023-1206, CVE-2023-2650, CVE-2023-2953, CVE-2023-3212, CVE-2023-3446, CVE-2023-3609, CVE-2023-3611, CVE-2023-3772, CVE-2023-3817, CVE-2023-4016, CVE-2023-4039, CVE-2023-4527, CVE-2023-4623, CVE-2023-4806, CVE-2023-4807, CVE-2023-4813, CVE-2023-4911, CVE-2023-4921, CVE-2023-5156, CVE-2023-5678, CVE-2023-5717, CVE-2023-5981, CVE-2023-23914, CVE-2023-23915, CVE-2023-23916, CVE-2023-24329, CVE-2023-25136, CVE-2023-25139, CVE-2023-26604, CVE-2023-27371, CVE-2023-27533, CVE-2023-27534, CVE-2023-27535, CVE-2023-27536, CVE-2023-27537, CVE-2023-27538, CVE-2023-28484, CVE-2023-28531, CVE-2023-29383, CVE-2023-29469, CVE-2023-29491, CVE-2023-29499, CVE-2023-31085, CVE-2023-32611, CVE-2023-32636, CVE-2023-32643, CVE-2023-32665, CVE-2023-34319, CVE-2023-34969, CVE-2023-35001, CVE-2023-35945, CVE-2016-10009., CVE-2023-38408, CVE-2023-38545, CVE-2023-38546, CVE-2023-39128, CVE-2023-39189, CVE-2023-39192, CVE-2023-39193, CVE-2023-39194, CVE-2023-39615, CVE-2023-40283, CVE-2023-42754, CVE-2023-42755, CVE-2023-44487, CVE-2023-45322, CVE-2023-45853, CVE-2023-45871",9.8,Critical,"CWE-611, CWE-367, CWE-77, CWE-77, CWE-311, CWE-79, CWE-119, CWE-416, CWE-611, CWE-20, CWE-20, CWE-787, CWE-611, CWE-119, CWE-119, CWE-119, CWE-125, CWE-125, CWE-119, CWE-835, CWE-74, CWE-770, CWE-203, CWE-209, CWE-476, CWE-835, CWE-190, CWE-20, CWE-835, CWE-611, CWE-787, CWE-787, CWE-787, CWE-787, CWE-125, CWE-125, CWE-125, CWE-125, CWE-125, CWE-787, CWE-416, CWE-787, CWE-787, CWE-190, CWE-787, CWE-427, CWE-415, CWE-787, CWE-116, CWE-838, CWE-22, CWE-404, CWE-311, CWE-125, CWE-125, CWE-311, CWE-400, CWE-93, CWE-476, CWE-125, CWE-476, CWE-93, CWE-22, CWE-172, CWE-787, CWE-20, CWE-787, CWE-668, CWE-311, CWE-311, CWE-203, CWE-331, CWE-125, CWE-311, CWE-369, CWE-190, CWE-190, CWE-787, CWE-125, CWE-125, CWE-787, CWE-273, CWE-74, CWE-665, CWE-476, CWE-20, CWE-681, CWE-20, CWE-674, CWE-754, CWE-476, CWE-787, CWE-476, CWE-755, CWE-434, CWE-476, CWE-772, CWE-311, CWE-755, CWE-125, CWE-401, CWE-416, CWE-835, CWE-125, CWE-119, CWE-311, CWE-200, CWE-330, CWE-125, CWE-416, CWE-787, CWE-416, CWE-195, CWE-835, CWE-200, CWE-74, CWE-416, CWE-200, CWE-674, CWE-295, CWE-427, CWE-400, CWE-476, CWE-787, CWE-787, CWE-787, CWE-704, CWE-190, CWE-330, CWE-665, CWE-416, CWE-20, CWE-674, CWE-120, CWE-190, CWE-190, CWE-476, CWE-290, CWE-416, CWE-20, CWE-476, CWE-269, CWE-327, CWE-416, CWE-203, CWE-682, CWE-787, CWE-427, CWE-78, CWE-426, CWE-787, CWE-787, CWE-787, CWE-787, CWE-787, CWE-787, CWE-190, CWE-787, CWE-416, CWE-787, CWE-787, CWE-125, CWE-476, CWE-617, CWE-617, CWE-74, CWE-835, CWE-674, CWE-190, CWE-125, CWE-787, CWE-617, CWE-787, CWE-476, CWE-119, CWE-191, CWE-617, CWE-125, CWE-763, CWE-415, CWE-311, CWE-835, CWE-191, CWE-843, CWE-617, CWE-120, CWE-617, CWE-22, CWE-416, CWE-787, CWE-416, CWE-190, CWE-476, CWE-776, CWE-20, CWE-400, CWE-400, CWE-119, CWE-674, CWE-125, CWE-193, CWE-345, CWE-252, CWE-476, CWE-125, CWE-416, CWE-416, CWE-416, CWE-787, CWE-200, CWE-290, CWE-668, CWE-909, CWE-416, CWE-354, CWE-522, CWE-706, CWE-908, CWE-295, CWE-415, CWE-319, CWE-345, CWE-20, CWE-617, CWE-681, CWE-681, CWE-415, CWE-415, CWE-59, CWE-295, CWE-601, CWE-125, CWE-787, CWE-835, CWE-203, CWE-416, CWE-770, CWE-190, CWE-416, CWE-416, CWE-416, CWE-125, CWE-476, CWE-311, CWE-190, CWE-476, CWE-476, CWE-311, CWE-311, CWE-190, CWE-400, CWE-190, CWE-674, CWE-770, CWE-193, CWE-74, CWE-209, CWE-835, CWE-20, CWE-78, CWE-787, CWE-295, CWE-327, CWE-404, CWE-78, CWE-326, CWE-787, CWE-415, CWE-787, CWE-193, CWE-326, CWE-415, CWE-287, CWE-190, CWE-190, CWE-190, CWE-190, CWE-190, CWE-190, CWE-120, CWE-120, CWE-416, CWE-190, CWE-190, CWE-89, CWE-116, CWE-668, CWE-400, CWE-190, CWE-190, CWE-426, CWE-522, CWE-311, CWE-522, CWE-706, CWE-311, CWE-918, CWE-400, CWE-295, CWE-674, CWE-287, CWE-89, CWE-190, CWE-319, CWE-770, CWE-770, CWE-276, CWE-787, CWE-440, CWE-1286, CWE-121, CWE-129, CWE-787, CWE-190, CWE-190, CWE-415, CWE-416, CWE-190, CWE-415, CWE-319, CWE-319, CWE-416, CWE-416, CWE-407, CWE-400, CWE-311, CWE-125, CWE-787, CWE-416, CWE-416, CWE-20, CWE-203, CWE-295, CWE-295, CWE-295, CWE-120, CWE-843, CWE-400, CWE-770, CWE-476, CWE-476, CWE-1333, CWE-416, CWE-787, CWE-476, CWE-834, CWE-122, CWE-693, CWE-125, CWE-416, CWE-416, CWE-20, CWE-416, CWE-121, CWE-416, CWE-401, CWE-754, CWE-787, CWE-203, CWE-319, CWE-319, CWE-770, CWE-20, CWE-415, CWE-787, CWE-311, CWE-20, CWE-74, CWE-22, CWE-287, CWE-287, CWE-415, CWE-20, CWE-476, CWE-311, CWE-74, CWE-415, CWE-787, CWE-400, CWE-369, CWE-400, CWE-400, CWE-122, CWE-502, CWE-787, CWE-311, CWE-787, CWE-400, CWE-20, CWE-122, CWE-311, CWE-787, CWE-125, CWE-125, CWE-125, CWE-125, CWE-119, CWE-416, CWE-476, CWE-125, CWE-400, CWE-416, CWE-190, CWE-120",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2701,12/14/2023,12/14/2023,2023,ICSA-23-348-09,Siemens Simantic S7-1500 CPU family,Siemens,Simantic S7-1500 CPU family,The following Siemens products are affected: SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0): All versions prior to V3.1.0 SIMATIC Drive Controller CPU 1507D TF (6ES7615-7DF10-0AB0): All versions prior to V3.1.0 SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions SIMATIC S7-1500 CPU 1510SP F-1 PN (6ES7510-1SJ00-0AB0): All versions SIMATIC S7-1500 CPU 1510SP F-1 PN (6ES7510-1SJ01-0AB0): All versions SIMATIC S7-1500 CPU 1510SP F-1 PN (6ES7510-1SK03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1510SP-1 PN (6ES7510-1DJ00-0AB0): All versions SIMATIC S7-1500 CPU 1510SP-1 PN (6ES7510-1DJ01-0AB0): All versions SIMATIC S7-1500 CPU 1510SP-1 PN (6ES7510-1DK03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK00-0AB0): All versions SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK01-0AB0): All versions SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK02-0AB0): All versions SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AL03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK00-0AB0): All versions SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK01-0AB0): All versions SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CL03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK00-0AB0): All versions SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK01-0AB0): All versions SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK02-0AB0): All versions SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FL03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1511T-1 PN (6ES7511-1TK01-0AB0): All versions SIMATIC S7-1500 CPU 1511T-1 PN (6ES7511-1TL03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1511TF-1 PN (6ES7511-1UK01-0AB0): All versions SIMATIC S7-1500 CPU 1511TF-1 PN (6ES7511-1UL03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK00-0AB0): All versions SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK01-0AB0): All versions SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CM03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1512SP F-1 PN (6ES7512-1SK00-0AB0): All versions SIMATIC S7-1500 CPU 1512SP F-1 PN (6ES7512-1SK01-0AB0): All versions SIMATIC S7-1500 CPU 1512SP F-1 PN (6ES7512-1SM03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1512SP-1 PN (6ES7512-1DK00-0AB0): All versions SIMATIC S7-1500 CPU 1512SP-1 PN (6ES7512-1DK01-0AB0): All versions SIMATIC S7-1500 CPU 1512SP-1 PN (6ES7512-1DM03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL00-0AB0): All versions SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL01-0AB0): All versions SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL02-0AB0): All versions SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AM03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL00-0AB0): All versions SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL01-0AB0): All versions SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL02-0AB0): All versions SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FM03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1513R-1 PN (6ES7513-1RL00-0AB0): All versions SIMATIC S7-1500 CPU 1513R-1 PN (6ES7513-1RM03-0AB0): All versions SIMATIC S7-1500 CPU 1514SP F-2 PN (6ES7514-2SN03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1514SP-2 PN (6ES7514-2DN03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1514SPT F-2 PN (6ES7514-2WN03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1514SPT-2 PN (6ES7514-2VN03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM00-0AB0): All versions SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM01-0AB0): All versions SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM02-0AB0): All versions SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AN03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM00-0AB0): All versions SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM01-0AB0): All versions SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM02-0AB0): All versions SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FN03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1515R-2 PN (6ES7515-2RM00-0AB0): All versions SIMATIC S7-1500 CPU 1515R-2 PN (6ES7515-2RN03-0AB0): All versions SIMATIC S7-1500 CPU 1515T-2 PN (6ES7515-2TM01-0AB0): All versions SIMATIC S7-1500 CPU 1515T-2 PN (6ES7515-2TN03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1515TF-2 PN (6ES7515-2UM01-0AB0): All versions SIMATIC S7-1500 CPU 1515TF-2 PN (6ES7515-2UN03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN00-0AB0): All versions SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN01-0AB0): All versions SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN02-0AB0): All versions SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AP03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN00-0AB0): All versions SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN01-0AB0): All versions SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN02-0AB0): All versions SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FP03-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1516T-3 PN/DP (6ES7516-3TN00-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1516TF-3 PN/DP (6ES7516-3UN00-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1517-3 PN/DP (6ES7517-3AP00-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1517F-3 PN/DP (6ES7517-3FP00-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1517F-3 PN/DP (6ES7517-3FP01-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1517H-3 PN (6ES7517-3HP00-0AB0): All versions SIMATIC S7-1500 CPU 1517T-3 PN/DP (6ES7517-3TP00-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1517TF-3 PN/DP (6ES7517-3UP00-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1518-4 PN/DP (6ES7518-4AP00-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1518F-4 PN/DP (6ES7518-4FP00-0AB0):All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1518HF-4 PN (6ES7518-4JP00-0AB0): All versions SIMATIC S7-1500 CPU 1518T-4 PN/DP (6ES7518-4TP00-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU 1518TF-4 PN/DP (6ES7518-4UP00-0AB0): All versions prior to V3.1.0 SIMATIC S7-1500 CPU S7-1518-4 PN/DP ODK (6ES7518-4AP00-3AB0): All versions SIMATIC S7-1500 CPU S7-1518F-4 PN/DP ODK (6ES7518-4FP00-3AB0): All versions SIMATIC S7-1500 ET 200pro: CPU 1513PRO F-2 PN (6ES7513-2GL00-0AB0): All versions SIMATIC S7-1500 ET 200pro: CPU 1513PRO-2 PN (6ES7513-2PL00-0AB0): All versions SIMATIC S7-1500 ET 200pro: CPU 1516PRO F-2 PN (6ES7516-2GN00-0AB0): All versions SIMATIC S7-1500 ET 200pro: CPU 1516PRO-2 PN (6ES7516-2PN00-0AB0): All versions SIMATIC S7-1500 Software Controller: All versions SIMATIC S7-PLCSIM Advanced: All versions prior to V6.0 SIPLUS ET 200SP CPU 1510SP F-1 PN (6AG1510-1SJ01-2AB0): All versions SIPLUS ET 200SP CPU 1510SP F-1 PN RAIL (6AG2510-1SJ01-1AB0): All versions SIPLUS ET 200SP CPU 1510SP-1 PN (6AG1510-1DJ01-2AB0): All versions SIPLUS ET 200SP CPU 1510SP-1 PN (6AG1510-1DJ01-7AB0): All versions SIPLUS ET 200SP CPU 1510SP-1 PN RAIL (6AG2510-1DJ01-1AB0): All versions SIPLUS ET 200SP CPU 1510SP-1 PN RAIL (6AG2510-1DJ01-4AB0): All versions SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK00-2AB0): All versions SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK01-2AB0): All versions SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK01-7AB0): All versions SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL (6AG2512-1SK01-1AB0): All versions SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL (6AG2512-1SK01-4AB0): All versions SIPLUS ET 200SP CPU 1512SP-1 PN (6AG1512-1DK01-2AB0): All versions SIPLUS ET 200SP CPU 1512SP-1 PN (6AG1512-1DK01-7AB0): All versions SIPLUS ET 200SP CPU 1512SP-1 PN RAIL (6AG2512-1DK01-1AB0): All versions SIPLUS ET 200SP CPU 1512SP-1 PN RAIL (6AG2512-1DK01-4AB0): All versions SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK00-2AB0): All versio,CVE-2023-46156,7.5,High,CWE-416,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2700,12/14/2023,12/14/2023,2023,ICSA-23-348-08,Siemens Web Server of Industrial Products,Siemens,"SIMATIC CP, SINAMICS, SIPLUS NET CP","The following products of Siemens, are affected: SIMATIC CP 1242-7 V2 (incl. SIPLUS variants): All versions SIMATIC CP 1243-1 (incl. SIPLUS variants): All versions SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants): All versions SIMATIC CP 1243-1 IEC (incl. SIPLUS variants): All versions SIMATIC CP 1243-7 LTE: All versions SIMATIC CP 1243-8 IRC (6GK7243-8RX30-0XE0): All versions SIMATIC CP 1543-1 (6GK7543-1AX00-0XE0): All versions SINAMICS S210 (6SL5...): Versions V6.1 up to but not including V6.1 HF2 SIPLUS NET CP 1543-1 (6AG1543-1AX00-2XE0): All versions",CVE-2023-38380,7.5,High,CWE-401,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2699,12/14/2023,12/14/2023,2023,ICSA-23-348-07,Siemens SIMATIC STEP 7 (TIA Portal),Siemens,SIMATIC STEP 7 (TIA Portal),The following Siemens product is affected: SIMATIC STEP 7 (TIA Portal): All versions prior to V19,CVE-2022-46141,4.2,Medium,CWE-316,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2698,12/14/2023,12/14/2023,2023,ICSA-23-348-06,Siemens OPC UA Implementation in SINUMERIK ONE and SINUMERIK MC,Siemens,"SINUMERIK MC, SINUMERIK ONE","The following products of Siemens, are affected: SINUMERIK MC: All versions prior to V1.22 SINUMERIK ONE: All versions prior to V6.22",CVE-2023-28831,7.5,High,CWE-190,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2697,12/14/2023,12/14/2023,2023,ICSA-23-348-05,Siemens SIMATIC and SIPLUS Products,Siemens,SIMATIC and SIPLUS products,"The following products of Siemens, are affected: SIMATIC S7-400 CPU 412-2 PN V7 (6ES7412-2EK07-0AB0): All versions SIMATIC S7-400 CPU 414-3 PN/DP V7 (6ES7414-3EM07-0AB0): All versions SIMATIC S7-400 CPU 414F-3 PN/DP V7 (6ES7414-3FM07-0AB0): All versions SIMATIC S7-400 CPU 416-3 PN/DP V7 (6ES7416-3ES07-0AB0): All versions SIMATIC S7-400 CPU 416F-3 PN/DP V7 (6ES7416-3FS07-0AB0): All versions SIMATIC PC-Station Plus: All versions SINAMICS S120 (incl. SIPLUS variants): All versions prior to SP3 HF15 SIPLUS S7-400 CPU 414-3 PN/DP V7 (6AG1414-3EM07-7AB0): All versions SIPLUS S7-400 CPU 416-3 PN/DP V7 (6AG1416-3ES07-7AB0): All versions","CVE-2022-47374, CVE-2022-47375",7.5,High,"CWE-674, CWE-805",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2696,12/14/2023,12/14/2023,2023,ICSA-23-348-04,Siemens LOGO! and SIPLUS LOGO!,Siemens,LOGO! and SIPLUS LOGO! Products,"The following products of Siemens, are affected: LOGO! 12/24RCE (6ED1052-1MD08-0BA1): Versions v8.3 and prior LOGO! 12/24RCEo (6ED1052-2MD08-0BA1): Versions v8.3 and prior LOGO! 24CE (6ED1052-1CC08-0BA1): Versions v8.3 and prior LOGO! 24CEo (6ED1052-2CC08-0BA1): Versions v8.3 and prior LOGO! 24RCE (6ED1052-1HB08-0BA1): Versions v8.3 and prior LOGO! 24RCEo (6ED1052-2HB08-0BA1): Versions v8.3 and prior LOGO! 230RCE (6ED1052-1FB08-0BA1): Versions v8.3 and prior LOGO! 230RCEo (6ED1052-2FB08-0BA1): Versions v8.3 and prior SIPLUS LOGO! 12/24RCE (6AG1052-1MD08-7BA1): Versions v8.3 and prior SIPLUS LOGO! 12/24RCEo (6AG1052-2MD08-7BA1): Versions v8.3 and prior SIPLUS LOGO! 24CE (6AG1052-1CC08-7BA1): Versions v8.3 and prior SIPLUS LOGO! 24CEo (6AG1052-2CC08-7BA1): Versions v8.3 and prior SIPLUS LOGO! 24RCE (6AG1052-1HB08-7BA1): Versions v8.3 and prior SIPLUS LOGO! 24RCEo (6AG1052-2HB08-7BA1): Versions v8.3 and prior SIPLUS LOGO! 230RCE (6AG1052-1FB08-7BA1): Versions v8.3 and prior SIPLUS LOGO! 230RCEo (6AG1052-2FB08-7BA1): Versions v8.3 and prior",CVE-2022-42784,7.6,High,CWE-1319,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2695,12/14/2023,12/14/2023,2023,ICSA-23-348-03,Siemens User Management Component (UMC),Siemens,User Management Component (UMC),Siemens reports the following products are affected: Opcenter Quality: all versions SIMATIC PCS neo: versions prior to v4.1 SINUMERIK Integrate RunMyHMI /Automotive: all versions Totally Integrated Automation Portal (TIA Portal) v14: all versions Totally Integrated Automation Portal (TIA Portal) v15.1: all versions Totally Integrated Automation Portal (TIA Portal) v16: all versions Totally Integrated Automation Portal (TIA Portal) v17: all versions Totally Integrated Automation Portal (TIA Portal) v18: versions prior to V18 update 3,"CVE-2023-46281, CVE-2023-46282, CVE-2023-46283, CVE-2023-46284, CVE-2023-46285",7.5,High,"CWE-942, CWE-79, CWE-120, CWE-20",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2694,12/14/2023,12/14/2023,2023,ICSA-23-348-02,Johnson Controls Kantech Gen1 ioSmart,Sensormatic Electronics LLC (Subsidiary of Johnson Controls),Kantech Gen1 ioSmart card reader,The following versions of Kantech Gen1 ioSmart card reader are affected: Kantech Gen1 ioSmart card reader: firmware versions prior to 1.7.2,CVE-2023-0248,7.5,High,CWE-401,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2693,12/14/2023,1/9/2024,2023,ICSA-23-348-01,Cambium ePMP 5GHz Force 300-25 Radio (Update A),Cambium Networks,ePMP Force 300-25,The following versions of Cambium ePMP Force 300-25 radio are affected: ePMP Force 300-25: version 4.7.0.1.,CVE-2023-6691,7.8,High,CWE-94,Communications,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2692,12/12/2023,12/12/2023,2023,ICSA-23-346-01,Schneider Electric Easy UPS Online Monitoring Software,Schneider Electric,Easy UPS Online Monitoring Software,"Schneider Electric reports that the following versions of Easy UPS Online Monitoring Software are affected: Easy UPS Online Monitoring Software (Windows 10, 11, Windows Server 2016, 2019, 2022): 2.6-GA-01-23116 and prior",CVE-2023-6407,5.3,Medium,CWE-22,Multiple Critical Sectors,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2691,12/07/2023,12/7/2023,2023,ICSA-23-341-01,Mitsubishi Electric FA Engineering Software Products,Mitsubishi Electric,"MELIPC , MELSEC iQ-R, and MELSEC Q Series","Mitsubishi Electric reports the following versions of FA Engineering Software Products are affected. For the correspondence table of the affected products and each vulnerability, refer to Mitsubishi Electric's security bulletin. MELIPC MI5122-VW: All Versions MELIPC MI2012-W: All Versions MELIPC MI1002-W: All Versions MELIPC MI3321G-W: All Versions MELIPC MI3315G-W: All Versions MELSEC iQ-R R102WCPU-W: All Versions MELSEC Q Q24DHCCPU-V: All Versions MELSEC Q Q24DHCCPU-VG: All Versions MELSEC Q Q24DHCCPU-LS: All Versions MELSEC Q Q26DHCCPU-LS: All Versions","CVE-2022-21151, CVE-2021-33149",5.3,Medium,"CWE-1037, CWE-203",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2690,12/07/2023,12/7/2023,2023,ICSA-23-341-02,Schweitzer Engineering Laboratories SEL-411L,Schweitzer Engineering Laboratories,SEL-411L,The following versions of the Schweitzer Engineering Laboratories SEL-411L are affected: R118: V0 - V4 R119: V0 - V5 R120: V0 - V6 R121: V0 - V3 R122: V0 - V3 R123: V0 - V3 R124: V0 - V3 R125: V0 - V3 R126: V0 - V4 R127: V0 - V2 R128: V0 - V1 R129: V0 - V1,CVE-2023-2265,4.3,Medium,CWE-1021,Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2689,12/7/2023,12/19/2023,2023,ICSA-23-341-03,Johnson Controls Metasys and Facility Explorer (Update A),Johnson Controls Inc.,Metasys and Facility Explorer,The following versions of Johnson Controls Metasys and Facility Explorer are affected: Metasys NAE55 engines: Versions prior to 12.0.4 Metasys SNE engines: Versions prior to 12.0.4 Metasys SNC engines: Versions prior to 12.0.4 Facility Explorer F4-SNC: Versions prior to 11.0.6 Facility Explorer F4-SNC: Versions prior to 12.0.4.,CVE-2023-4486,7.5,High,CWE-400,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2688,12/07/2023,12/7/2023,2023,ICSA-23-341-05,ControlbyWeb Relay,ControlByWeb,X-332 and X-301,The following versions of ControlByWeb Relay are affected: X-332-24I: Firmware 1.06 X-301-I: Firmware 1.15 X-301-24I: Firmware 1.15,CVE-2023-6333,7.5,High,CWE-79,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2687,12/07/2023,12/7/2023,2023,ICSA-23-341-06,Sierra Wireless AirLink with ALEOS firmware,Sierra Wireless,AirLink,The following versions of Sierra Wireless AirLink router with ALEOS firmware are affected: AirLink ALEOS firmware: All versions prior to 4.9.9 AirLink ALEOS firmware: All versions prior to 4.17.0,"CVE-2023-40458, CVE-2023-40459, CVE-2023-40460, CVE-2023-40461, CVE-2023-40462, CVE-2023-40463, CVE-2023-40464",8.1,High,"CWE-835, CWE-476, CWE-79, CWE-617, CWE-798, CWE-321",Commercial Facilities; Communications; Emergency Services; Energy; Government Facilities; Transportation Systems; Water and Wastewater Systems,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2686,12/05/2023,12/5/2023,2023,ICSA-23-339-01,Zebra ZTC Industrial ZT400 and Desktop GK420d,Zebra Technologies,"ZTC Industrial ZT410, ZTC Desktop GK420d",The following versions of Zebra ZTC industrial and desktop printers are affected: ZTC Industrial ZT410: All versions ZTC Desktop GK420d: All versions,CVE-2023-4957,5.4,Medium,CWE-288,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2685,11/30/2023,11/30/2023,2023,ICSA-23-334-01,Delta Electronics DOPSoft,Delta Electronics,DOPSoft,The following versions of Delta Electronics products are affected: DOPSoft: All versions,CVE-2023-5944,7.8,High,CWE-121,Energy,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2684,11/30/2023,11/30/2023,2023,ICSA-23-334-02,Yokogawa STARDOM,Yokogawa,STARDOM FCN/FCJ,"The following versions of Yokogawa STARDOM FCN/FCJ, a network control system, are affected: STARDOM FCN/FCJ: versions R1.01 through R4.31",CVE-2023-5915,5.3,Medium,CWE-400,Multiple Critical Sectors,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2683,11/30/2023,11/30/2023,2023,ICSA-23-334-03,PTC KEPServerEx,PTC,"KEPServerEX, ThingWorx, OPC-Aggregator","The following PTC Kepware products, are affected: KEPServerEX: v6.14.263.0 and prior ThingWorx Kepware Server: v6.14.263.0 and prior ThingWorx Industrial Connectivity: All versions OPC-Aggregator: v6.14 and prior ThingWorx Kepware Edge: v1.7 and prior Rockwell Automation KEPServer Enterprise: Versions v6.14.263.0 and prior GE Digital Industrial Gateway Server: Versions v7.614 and prior Software Toolbox TOP Server: Versions v6.14.263.0 and prior","CVE-2023-5908, CVE-2023-5909",9.1,Critical,"CWE-122, CWE-297",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2682,11/30/2023,11/30/2023,2023,ICSA-23-334-04,Mitsubishi Electric FA Engineering Software Products,Mitsubishi Electric,FA Engineering Software Products,Mitsubishi Electric reports the following versions of FA Engineering Software Products are affected: GX Works3: All versions MELSOFT iQ AppPortal: All versions MELSOFT Navigator: All versions Motion Control Setting (Software packaged with GX Works3): All versions,CVE-2023-5247,7.8,High,CWE-73,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2681,11/28/2023,11/28/2023,2023,ICSA-23-331-01,Delta Electronics InfraSuite Device Master,Delta Electronics,InfraSuite Device Master,The following Delta Electronics products are affected: InfraSuite Device Master: Versions 1.0.7 and prior,"CVE-2023-46690, CVE-2023-47207, CVE-2023-39226, CVE-2023-47279",9.8,Critical,"CWE-35, CWE-502, CWE-749",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2680,11/28/2023,11/28/2023,2023,ICSA-23-331-02,Franklin Electric Fueling Systems Colibri,Franklin Electric Fueling Systems,Colibri,"The following versions of FFS Colibri, a discontinued fuel inventory monitoring system, are affected: FFS Colibri: all versions.",CVE-2023-5885,6.5,Medium,CWE-35,Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2679,11/28/2023,11/28/2023,2023,ICSA-23-331-03,Mitsubishi Electric GX Works2,Mitsubishi Electric,GX Works2,GX Works2: all versions,"CVE-2023-5274, CVE-2023-5275",2.9,Low,CWE-20,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2678,11/28/2023,11/28/2023,2023,ICSMA-23-331-01,BD FACSChorus,"Becton, Dickinson and Company (BD)",FACSChorus,"The following BD products are affected: BD FACSChorus (HP Z2 G9 workstation, shipped with FACSDiscover S8 Cell Sorter): v5.0 and v5.1 BD FACSChorus (HP Z2 G5 workstation, shipped with FACSMelody Cell Sorter): v3.0 and v3.1","CVE-2023-29060, CVE-2023-29061, CVE-2023-29062, CVE-2023-29063, CVE-2023-29064, CVE-2023-29065, CVE-2023-29066",5.4,Medium,"CWE-1299, CWE-306, CWE-287, CWE-798, CWE-277, CWE-266",Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2677,11/21/2023,11/21/2023,2023,ICSA-23-325-01,WAGO PFC200 Series,WAGO,PFC200 Series,"WAGO reports the following products are affected: Compact Controller CC100: Versions later than FW19, up to and including FW26 Edge Controller: Versions later than FW18, up to and including FW26 PFC100: Versions later than FW16, up to and including FW26 PFC200: Versions later than FW16, up to and including FW26 Touch Panel 600 Advanced Line: Versions later than FW16, up to and including FW26 Touch Panel 600 Marine Line: Versions later than FW16, up to and including FW26 Touch Panel 600 Standard Line: Versions later than FW16, up to and including FW26",CVE-2023-4089,2.7,Low,CWE-610,Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2676,11/21/2023,11/21/2023,2023,ICSA-23-325-02,Fuji Electric Tellus Lite V-Simulator,Fuji Electric,Tellus Lite V-Simulator,Fuji Electric reports that the following versions of Tellus Lite V-Simulator remote monitoring software are affected: Tellus Lite V-Simulator: versions prior to V4.0.19.0,"CVE-2023-35127, CVE-2023-40152, CVE-2023-5299",7.8,High,"CWE-121, CWE-787, CWE-284",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2675,11/16/2023,11/16/2023,2023,ICSA-23-320-01,Red Lion Sixnet RTUs,Red Lion,Sixnet RTU,The following Red Lion products are affected: ST-IPm-8460: Firmware 6.0.202 and later ST-IPm-6350: Firmware version 4.9.114 and later VT-mIPm-135-D: Firmware version 4.9.114 and later VT-mIPm-245-D: Firmware version 4.9.114 and later VT-IPm2m-213-D: Firmware version 4.9.114 and later VT-IPm2m-113-D: Firmware version 4.9.114 and later,"CVE-2023-42770, CVE-2023-40151",10.0,Critical,"CWE-288, CWE-749",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2674,11/16/2023,11/16/2023,2023,ICSA-23-320-02,Hitachi Energy MACH System Software,Hitachi Energy,MACH System Software,The following Hitachi Energy products are affected: MACH SSW: Version 5.0 to 7.17.0.0 MACH SSW: Version 7.10.0.0 to 7.18.0.0,"CVE-2023-2621, CVE-2023-2622",6.5,Medium,"CWE-29, CWE-266",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2673,11/16/2023,11/16/2023,2023,ICSA-23-320-03,Siemens Desigo CC product family,Siemens,Desigo CC product family,Siemens reports that the following products are affected by vulnerabilities in the underlying third-party component WIBU Systems CodeMeter Runtime: Desigo CC product family V5.0: All versions Desigo CC product family V5.1: All versions Desigo CC product family V6: All versions Desigo CC product family V7: All versions,"CVE-2021-20093, CVE-2021-20094, CVE-2023-3935",9.1,Critical,"CWE-126, CWE-122",Commercial Facilities; Government Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2672,11/16/2023,11/16/2023,2023,ICSA-23-320-04,Siemens Mendix Runtime,Siemens,"Mendix 7, Mendix 8, Mendix 9, Mendix 10","The following versions of Siemens Mendix Applications, are affected: Mendix Applications using Mendix 7: all versions prior to V7.23.37 Mendix Applications using Mendix 8: all versions prior to V8.18.27 Mendix Applications using Mendix 9: all versions prior to V9.24.10 Mendix Applications using Mendix 10: all versions prior to V10.4.0",CVE-2023-45794,6.8,Medium,CWE-294,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2671,11/16/2023,11/16/2023,2023,ICSA-23-320-05,Siemens SCALANCE W700,Siemens,SCALANCE W700,"The following products of Siemens, are affected: SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0): All versions SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0): All versions SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0): All versions SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0): All versions SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0): All versions SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0): All versions SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6): All versions SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0): All versions SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6): All versions SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0): All versions SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0): All versions SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0): All versions SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0): All versions SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0): All versions SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0): All versions SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0): All versions SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0): All versions SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0): All versions SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0): All versions SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0): All versions SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6): All versions SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0): All versions SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0): All versions SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6): All versions SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0): All versions SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0): All versions SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0): All versions SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0): All versions SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0): All versions SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0): All versions SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0): All versions SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0): All versions SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0): All versions SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0): All versions SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0): All versions SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0): All versions SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0): All versions SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0): All versions SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0): All versions SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0): All versions SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0): All versions SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0): All versions SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0): All versions SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0): All versions SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0): All versions SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0): All versions SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0): All versions SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0): All versions SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0): All versions SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0): All versions SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0): All versions SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0): All versions SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0): All versions SCALANCE W1788-2 M12 (6GK5788-2GY01-0AA0): All versions SCALANCE W1788-2IA M12 (6GK5788-2HY01-0AA0): All versions SCALANCE WAM763-1 (6GK5763-1AL00-7DA0): All versions SCALANCE WAM766-1 (EU) (6GK5766-1GE00-7DA0): All versions SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0): All versions SCALANCE WAM766-1 EEC (EU) (6GK5766-1GE00-7TA0): All versions SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0): All versions SCALANCE WUM763-1 (6GK5763-1AL00-3AA0): All versions SCALANCE WUM763-1 (6GK5763-1AL00-3DA0): All versions SCALANCE WUM766-1 (EU) (6GK5766-1GE00-3DA0): All versions SCALANCE WUM766-1 (US) (6GK5766-1GE00-3DB0): All versions",CVE-2022-47522,8.4,High,CWE-20,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2670,11/16/2023,11/16/2023,2023,ICSA-23-320-06,Siemens SIMATIC PCS neo,Siemens,SIMATIC PCS neo,The following Siemens products are affected: SIMATIC PCS neo: Versions prior to V4.1,"CVE-2023-46096, CVE-2023-46097, CVE-2023-46098, CVE-2023-46099",8.0,High,"CWE-306, CWE-89, CWE-942, CWE-79",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2669,11/16/2023,11/16/2023,2023,ICSA-23-320-07,Siemens OPC UA Modeling Editor (SiOME),Siemens,OPC UA Modeling Editor (SiOME),"The following versions of Siemens OPC UA Modeling Editor (SiOME), are affected: OPC UA Modelling Editor (SiOME): versions prior to V2.8",CVE-2023-46590,7.5,High,CWE-611,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2668,11/16/2023,11/16/2023,2023,ICSA-23-320-08,Siemens SCALANCE Family Products,Siemens,SCALANCE XB-200/XC-200/XP-200/XF-200BA/XR-300WG Family,"The following products of Siemens, are affected: SCALANCE XB205-3 (SC, PN) (6GK5205-3BB00-2AB2): Versions prior to V4.5 SCALANCE XB205-3 (ST, E/IP) (6GK5205-3BB00-2TB2): Versions prior to V4.5 SCALANCE XB205-3 (ST, E/IP) (6GK5205-3BD00-2TB2): Versions prior to V4.5 SCALANCE XB205-3 (ST, PN) (6GK5205-3BD00-2AB2): Versions prior to V4.5 SCALANCE XB205-3LD (SC, E/IP) (6GK5205-3BF00-2TB2): Versions prior to V4.5 SCALANCE XB205-3LD (SC, PN) (6GK5205-3BF00-2AB2): Versions prior to V4.5 SCALANCE XB208 (E/IP) (6GK5208-0BA00-2TB2): Versions prior to V4.5 SCALANCE XB208 (PN) (6GK5208-0BA00-2AB2): Versions prior to V4.5 SCALANCE XB213-3 (SC, E/IP) (6GK5213-3BD00-2TB2): Versions prior to V4.5 SCALANCE XB213-3 (SC, PN) (6GK5213-3BD00-2AB2): Versions prior to V4.5 SCALANCE XB213-3 (ST, E/IP) (6GK5213-3BB00-2TB2): Versions prior to V4.5 SCALANCE XB213-3 (ST, PN) (6GK5213-3BB00-2AB2): Versions prior to V4.5 SCALANCE XB213-3LD (SC, E/IP) (6GK5213-3BF00-2TB2): Versions prior to V4.5 SCALANCE XB213-3LD (SC, PN) (6GK5213-3BF00-2AB2): Versions prior to V4.5 SCALANCE XB216 (E/IP) (6GK5216-0BA00-2TB2): Versions prior to V4.5 SCALANCE XB216 (PN) (6GK5216-0BA00-2AB2): Versions prior to V4.5 SCALANCE XC206-2 (SC) (6GK5206-2BD00-2AC2): Versions prior to V4.5 SCALANCE XC206-2 (ST/BFOC) (6GK5206-2BB00-2AC2): Versions prior to V4.5 SCALANCE XC206-2G PoE (6GK5206-2RS00-2AC2): Versions prior to V4.5 SCALANCE XC206-2G PoE (54 V DC) (6GK5206-2RS00-5AC2): Versions prior to V4.5 SCALANCE XC206-2G PoE EEC (54 V DC) (6GK5206-2RS00-5FC2): Versions prior to V4.5 SCALANCE XC206-2SFP (6GK5206-2BS00-2AC2): Versions prior to V4.5 SCALANCE XC206-2SFP EEC (6GK5206-2BS00-2FC2): Versions prior to V4.5 SCALANCE XC206-2SFP G (6GK5206-2GS00-2AC2): Versions prior to V4.5 SCALANCE XC206-2SFP G (EIP DEF.) (6GK5206-2GS00-2TC2): Versions prior to V4.5 SCALANCE XC206-2SFP G EEC (6GK5206-2GS00-2FC2): Versions prior to V4.5 SCALANCE XC208 (6GK5208-0BA00-2AC2): Versions prior to V4.5 SCALANCE XC208EEC (6GK5208-0BA00-2FC2): Versions prior to V4.5 SCALANCE XC208G (6GK5208-0GA00-2AC2): Versions prior to V4.5 SCALANCE XC208G (EIP def.) (6GK5208-0GA00-2TC2): Versions prior to V4.5 SCALANCE XC208G EEC (6GK5208-0GA00-2FC2): Versions prior to V4.5 SCALANCE XC208G PoE (6GK5208-0RA00-2AC2): Versions prior to V4.5 SCALANCE XC208G PoE (54 V DC) (6GK5208-0RA00-5AC2): Versions prior to V4.5 SCALANCE XC216 (6GK5216-0BA00-2AC2): Versions prior to V4.5 SCALANCE XC216-3G PoE (6GK5216-3RS00-2AC2): Versions prior to V4.5 SCALANCE XC216-3G PoE (54 V DC) (6GK5216-3RS00-5AC2): Versions prior to V4.5 SCALANCE XC216-4C (6GK5216-4BS00-2AC2): Versions prior to V4.5 SCALANCE XC216-4C G (6GK5216-4GS00-2AC2): Versions prior to V4.5 SCALANCE XC216-4C G (EIP Def.) (6GK5216-4GS00-2TC2): Versions prior to V4.5 SCALANCE XC216-4C G EEC (6GK5216-4GS00-2FC2): Versions prior to V4.5 SCALANCE XC216EEC (6GK5216-0BA00-2FC2): Versions prior to V4.5 SCALANCE XC224 (6GK5224-0BA00-2AC2): Versions prior to V4.5 SCALANCE XC224-4C G (6GK5224-4GS00-2AC2): Versions prior to V4.5 SCALANCE XC224-4C G (EIP Def.) (6GK5224-4GS00-2TC2): Versions prior to V4.5 SCALANCE XC224-4C G EEC (6GK5224-4GS00-2FC2): Versions prior to V4.5 SCALANCE XF204 (6GK5204-0BA00-2GF2): Versions prior to V4.5 SCALANCE XF204 DNA (6GK5204-0BA00-2YF2): Versions prior to V4.5 SCALANCE XF204-2BA (6GK5204-2AA00-2GF2): Versions prior to V4.5 SCALANCE XF204-2BA DNA (6GK5204-2AA00-2YF2): Versions prior to V4.5 SCALANCE XP208 (6GK5208-0HA00-2AS6): Versions prior to V4.5 SCALANCE XP208 (Ethernet/IP) (6GK5208-0HA00-2TS6): Versions prior to V4.5 SCALANCE XP208EEC (6GK5208-0HA00-2ES6): Versions prior to V4.5 SCALANCE XP208PoE EEC (6GK5208-0UA00-5ES6): Versions prior to V4.5 SCALANCE XP216 (6GK5216-0HA00-2AS6): Versions prior to V4.5 SCALANCE XP216 (Ethernet/IP) (6GK5216-0HA00-2TS6): Versions prior to V4.5 SCALANCE XP216EEC (6GK5216-0HA00-2ES6): Versions prior to V4.5 SCALANCE XP216POE EEC (6GK5216-0UA00-5ES6): Versions prior to V4.5 SCALANCE XR324WG (24 x FE, AC 230V) (6GK5324-0BA00-3AR3): Versions prior to V4.5 SCALANCE XR324WG (24 X FE, DC 24V) (6GK5324-0BA00-2AR3): Versions prior to V4.5 SCALANCE XR326-2C PoE WG (6GK5326-2QS00-3AR3): Versions prior to V4.5 SCALANCE XR326-2C PoE WG (without UL) (6GK5326-2QS00-3RR3): Versions prior to V4.5 SCALANCE XR328-4C WG (24xFE, 4xGE, AC230V) (6GK5328-4FS00-3AR3): Versions prior to V4.5 SCALANCE XR328-4C WG (24xFE, 4xGE, AC230V) (6GK5328-4FS00-3RR3): Versions prior to V4.5 SCALANCE XR328-4C WG (24XFE, 4XGE, 24V) (6GK5328-4FS00-2AR3): Versions prior to V4.5 SCALANCE XR328-4C WG (24xFE, 4xGE,DC24V) (6GK5328-4FS00-2RR3): Versions prior to V4.5 SCALANCE XR328-4C WG (28xGE, AC 230V) (6GK5328-4SS00-3AR3): Versions prior to V4.5 SCALANCE XR328-4C WG (28xGE, DC 24V) (6GK5328-4SS00-2AR3): Versions prior to V4.5 SIPLUS NET SCALANCE XC206-2 (6AG1206-2BB00-7AC2): Versions prior to V4.5 SIPLUS NET SCALANCE XC206-2SFP (6AG1206-2BS00-7AC2): Versions prior to V4.5 SIPLUS NET SCALANCE XC208 (6AG1208-0BA00-7AC2): Versions prior to V4.5 SIPLUS NET SCALANCE XC216-4C (6AG1216-4BS00-7AC2): Versions prior to V4.5","CVE-2022-4203, CVE-2022-4304, CVE-2022-4450, CVE-2023-0216, CVE-2023-0217, CVE-2023-0401, CVE-2023-2650, CVE-2023-44317, CVE-2023-44318, CVE-2023-44319, CVE-2023-44320, CVE-2023-44321, CVE-2023-44322, CVE-2023-44373, CVE-2023-44374",9.1,Critical,"CWE-125, CWE-326, CWE-415, CWE-476, CWE-770, CWE-349, CWE-321, CWE-328, CWE-425, CWE-400, CWE-252, CWE-74, CWE-567",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2667,11/16/2023,11/16/2023,2023,ICSA-23-320-09,Siemens COMOS,Siemens,COMOS,The following products of Siemens are affected: COMOS: All versions,"CVE-2020-25020, CVE-2020-35460, CVE-2022-23095, CVE-2022-28807, CVE-2022-28808, CVE-2022-28809, CVE-2023-0933, CVE-2023-1530, CVE-2023-2931, CVE-2023-2932, CVE-2023-22669, CVE-2023-22670, CVE-2023-43503, CVE-2023-43504, CVE-2023-43505, CVE-2023-46601",9.8,Critical,"CWE-611, CWE-22, CWE-787, CWE-125, CWE-190, CWE-416, CWE-122, CWE-319, CWE-120, CWE-284",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2666,11/16/2023,11/16/2023,2023,ICSA-23-320-10,Siemens SIPROTEC 4 7SJ66,Siemens,SIPROTEC 4 7SJ66,Siemens reports that the following SIPROTEC products are affected due to vulnerabilities in the underlying Wind River VxWorks network stack: SIPROTEC 4 7SJ66: versions prior to V4.41,"CVE-2019-12255, CVE-2019-12256, CVE-2019-12258, CVE-2019-12259, CVE-2019-12260, CVE-2019-12261, CVE-2019-12262, CVE-2019-12263, CVE-2019-12265",9.8,Critical,"CWE-120, CWE-384, CWE-476, CWE-346, CWE-362, CWE-401",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2665,11/16/2023,11/16/2023,2023,ICSA-23-320-11,Siemens Mendix Studio Pro,Siemens,"Mendix Studio Pro 7, 8, 9, 10.","The following products of Siemens, are affected: Mendix Studio Pro 7: Versions prior to V7.23.37 Mendix Studio Pro 8: Versions prior to V8.18.27 Mendix Studio Pro 9: Versions prior to V9.24.0 Mendix Studio Pro 10: Versions prior to V10.3.1",CVE-2023-4863,7.5,High,CWE-787,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2664,11/16/2023,11/16/2023,2023,ICSA-23-320-12,Siemens PNI,Siemens,SINEC PNI,"The following products of Siemens, are affected: SINEC PNI: Versions prior to V2.0","CVE-2022-30184, CVE-2022-37434, CVE-2022-41032, CVE-2023-21808, CVE-2023-24895, CVE-2023-24897, CVE-2023-24936, CVE-2023-28260, CVE-2023-29331 , CVE-2023-32032, CVE-2023-33126, CVE-2023-33128, CVE-2023-33135",9.8,Critical,"CWE-20, CWE-787",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2663,11/16/2023,11/16/2023,2023,ICSA-23-320-13,Siemens SIMATIC MV500,Siemens,SIMATIC MV500,"The following products of Siemens, are affected: SIMATIC MV500 family: Versions prior to V3.3.5","CVE-2022-23218, CVE-2022-23219, CVE-2022-44792, CVE-2022-44793, CVE-2023-2975, CVE-2023-3446, CVE-2023-3446, CVE-2023-3817, CVE-2023-35788",9.8,Critical,"CWE-120, CWE-476, CWE-287, CWE-1333, CWE-834, CWE-787",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2662,11/16/2023,11/16/2023,2023,ICSA-23-320-14,Siemens RUGGEDCOM APE1808 Devices,Siemens,RUGGEDCOM APE1808,The following components of Siemens are affected: RUGGEDCOM APE1808 with Nozomi Guardian / CMC: All versions before V22.6.3 or 23.1.0,"CVE-2023-2567, CVE-2023-29245, CVE-2023-32649",8.1,High,"CWE-89, CWE-20",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2661,11/14/2023,11/14/2023,2023,ICSA-23-318-01,AVEVA Operations Control Logger,AVEVA,Operations Control Logger,"AVEVA has created a security update to address vulnerabilities in the AVEVA Operations Control Logger (formerly known as ArchestrA Logger), impacting the following products: AVEVA SystemPlatform: 2020 R2 SP1 P01 and prior AVEVA Historian: 2020 R2 SP1 P01 and prior AVEVA Application Server: 2020 R2 SP1 P01 and prior AVEVA InTouch: 2020 R2 SP1 P01 and prior AVEVA Enterprise Licensing (formerly known as License Manager): version 3.7.002 and prior AVEVA Manufacturing Execution System (formerly known as Wonderware MES): 2020 P01 and prior AVEVA Recipe Management: 2020 R2 Update 1 Patch 2 and prior AVEVA Batch Management: 2020 SP1 and prior AVEVA Edge (formerly known as Indusoft Web Studio): 2020 R2 SP1 P01 and prior AVEVA Worktasks (formerly known as Workflow Management): 2020 U2 and prior AVEVA Plant SCADA (formerly known as Citect): 2020 R2 Update 15 and prior AVEVA Mobile Operator (formerly known as IntelaTrac Mobile Operator Rounds): 2020 R1 and prior AVEVA Communication Drivers Pack: 2020 R2 SP1 and prior AVEVA Telemetry Server: 2020 R2 SP1 and prior.","CVE-2023-33873, CVE-2023-34982",7.8,High,"CWE-250, CWE-73",Critical Manufacturing,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2660,11/14/2023,11/14/2023,2023,ICSA-23-318-02,Rockwell Automation SIS Workstation and ISaGRAF Workbench,Rockwell Automation,SIS Workstation and ISaGRAF Workbench,Rockwell Automation reports the following versions of SIS Workstation and ISaGRAF Workbench Code are affected: Safety Instrumented System Workstation: v1.2 up to but not including v2.00 ISaGRAF Workbench: v6.6.9 up to but not including v6.06.10,CVE-2015-9268,7.8,High,CWE-20,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2659,11/09/2023,11/9/2023,2023,ICSA-23-313-01,Johnson Controls Quantum HD Unity,Johnson Controls Inc.,Quantum HD Unity,The following Johnson Controls Quantum HD Unity products are affected: Quantum HD Unity Compressor control panels (Q5): All versions prior to v11.22 Quantum HD Unity Compressor control panels (Q6): All versions prior to v12.22 Quantum HD Unity AcuAir control panels(Q5): All versions prior to v11.12 Quantum HD Unity AcuAir control panels(Q6): All versions prior to v12.12 Quantum HD Unity Condenser/Vessel control panels (Q5): All versions prior to v11.11 Quantum HD Unity Condenser/Vessel control panels (Q6): All versions prior to v12.11 Quantum HD Unity Evaporator control panels (Q5): All versions prior to v11.11 Quantum HD Unity Evaporator control panels (Q6): All versions prior to v12.11 Quantum HD Unity Engine Room control panels (Q5): All versions prior to v11.11 Quantum HD Unity Engine Room control panels (Q6): All versions prior to v12.11 Quantum HD Unity Interface control panels (Q5): All versions prior to v11.11 Quantum HD Unity Interface control panels (Q6): All versions prior to v12.11,CVE-2023-4804,10.0,Critical,CWE-489,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2658,11/09/2023,11/9/2023,2023,ICSA-23-313-02,Hitachi Energy eSOMS,Hitachi Energy,eSOMS,The following Hitachi Energy products are affected: eSOMS: v6.3.13 and prior,"CVE-2023-5514, CVE-2023-5515, CVE-2023-5516",5.3,Medium,"CWE-209, CWE-497",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2657,11/07/2023,11/7/2023,2023,ICSA-23-311-01,GE MiCOM S1 Agile,GE,MiCOM S1 Agile,The following versions of General Electric MiCOM S1 Agile is affected: MiCOM S1 Agile: All versions.,CVE-2023-0898,5.3,Medium,CWE-427,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2656,11/02/2023,11/2/2023,2023,ICSA-23-306-01,Red Lion Crimson,Red Lion,"FlexEdge Gateway, DA50A, DA70A running Crimson",The following Red Lion products are affected: Crimson: v3.2.0053.18 or prior,CVE-2023-5719,8.8,High,CWE-158,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2655,11/02/2023,2/15/2024,2023,ICSA-23-306-02,Mitsubishi Electric MELSEC iQ-F/iQ-R Series CPU Module (Update A),Mitsubishi Electric,MELSEC iQ-F/iQ-R Series,"The following Mitsubishi Electric MELSEC iQ-F/iQ-R Series products are affected (Products with * are sold in limited regions): FX5U-xMy/z x=32,64,80, y=T,R, z=ES,DS,ESS,DSS (Serial number 17X**** and later): All versions FX5U-xMy/z x=32,64,80, y=T,R, z=ES,DS,ESS,DSS (Serial number 179**** and prior): Versions 1.060 or later FX5UC-xMy/z x=32,64,96, y=T, z=D,DSS (Serial number 17X**** and later): All versions FX5UC-xMy/z x=32,64,96, y=T, z=D,DSS (Serial number 179**** and prior): Versions 1.060 or later FX5UC-32MT/DS-TS, FX5UC-32MT/DSS-TS, FX5UC-32MR/DS-TS: All versions FX5UJ-xMy/z x=24,40,60, y=T,R, z=ES,DS,ESS,DSS: All versions FX5UJ-xMy/ES-A* x=24,40,60, y=T,R: All versions FX5S-xMy/z x=30,40,60,80*, y=T,R, z=ES,ESS: All versions R00/01/02CPU: Versions 05 or later R04/08/16/32/120(EN)CPU: Versions 35 or later R08/16/32/120/PCPU: Versions 37 or later.",CVE-2023-4625,5.3,Medium,CWE-307,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2654,11/2/2023,11/12/2024,2023,ICSA-23-306-03,Mitsubishi Electric MELSEC Series (Update A),Mitsubishi Electric,FA products,"Mitsubishi Electric reports that the following FA products are affected. However, MELSEC-F series CPU modules are only affected when they are used with Ethernet communication special adapter FX3U-ENET-ADP or Ethernet communication block FX3U-ENET(-L), with the exception of ""FX3GE-xMy/z x=24,40, y=T,R, z=ES,ESS,DS,DSS"". Some of these products are sold in limited regions. See the Mitsubishi Electric advisory for details: MELSEC-F series CPU module FX3U-16MT/ES: All versions MELSEC-F series CPU module FX3U-32MT/ES: All versions MELSEC-F series CPU module FX3U-48MT/ES: All versions MELSEC-F series CPU module FX3U-64MT/ES: All versions MELSEC-F series CPU module FX3U-80MT/ES: All versions MELSEC-F series CPU module FX3U-128MT/ES: All versions MELSEC-F series CPU module FX3U-16MR/ES: All versions MELSEC-F series CPU module FX3U-32MR/ES: All versions MELSEC-F series CPU module FX3U-48MR/ES: All versions MELSEC-F series CPU module FX3U-64MR/ES: All versions MELSEC-F series CPU module FX3U-80MR/ES: All versions MELSEC-F series CPU module FX3U-128MR/ES: All versions MELSEC-F series CPU module FX3U-16MT/ESS: All versions MELSEC-F series CPU module FX3U-32MT/ESS: All versions MELSEC-F series CPU module FX3U-48MT/ESS: All versions MELSEC-F series CPU module FX3U-64MT/ESS: All versions MELSEC-F series CPU module FX3U-80MT/ESS: All versions MELSEC-F series CPU module FX3U-128MT/ESS: All versions MELSEC-F series CPU module FX3U-16MT/DS: All versions MELSEC-F series CPU module FX3U-32MT/DS: All versions MELSEC-F series CPU module FX3U-48MT/DS: All versions MELSEC-F series CPU module FX3U-64MT/DS: All versions MELSEC-F series CPU module FX3U-80MT/DS: All versions MELSEC-F series CPU module FX3U-128MT/DS: All versions MELSEC-F series CPU module FX3U-16MR/DS: All versions MELSEC-F series CPU module FX3U-32MR/DS: All versions MELSEC-F series CPU module FX3U-48MR/DS: All versions MELSEC-F series CPU module FX3U-64MR/DS: All versions MELSEC-F series CPU module FX3U-80MR/DS: All versions MELSEC-F series CPU module FX3U-128MR/DS: All versions MELSEC-F series CPU module FX3U-16MT/DSS: All versions MELSEC-F series CPU module FX3U-32MT/DSS: All versions MELSEC-F series CPU module FX3U-48MT/DSS: All versions MELSEC-F series CPU module FX3U-64MT/DSS: All versions MELSEC-F series CPU module FX3U-80MT/DSS: All versions MELSEC-F series CPU module FX3U-128MT/DSS: All versions MELSEC-F series CPU module FX3U-32MR/UA1: All versions MELSEC-F series CPU module FX3U-64MR/UA1: All versions MELSEC-F series CPU module FX3U-32MS/ES: All versions MELSEC-F series CPU module FX3U-64MS/ES: All versions MELSEC-F series CPU module FX3U-16MT/ES-A: All versions MELSEC-F series CPU module FX3U-32MT/ES-A: All versions MELSEC-F series CPU module FX3U-48MT/ES-A: All versions MELSEC-F series CPU module FX3U-64MT/ES-A: All versions MELSEC-F series CPU module FX3U-80MT/ES-A: All versions MELSEC-F series CPU module FX3U-128MT/ES-A: All versions MELSEC-F series CPU module FX3U-16MR/ES-A: All versions MELSEC-F series CPU module FX3U-32MR/ES-A: All versions MELSEC-F series CPU module FX3U-48MR/ES-A: All versions MELSEC-F series CPU module FX3U-64MR/ES-A: All versions MELSEC-F series CPU module FX3U-80MR/ES-A: All versions MELSEC-F series CPU module FX3U-128MR/ES-A: All versions MELSEC-F series CPU module FX3UC-16MT/D: All versions MELSEC-F series CPU module FX3UC-32MT/D: All versions MELSEC-F series CPU module FX3UC-64MT/D: All versions MELSEC-F series CPU module FX3UC-96MT/D: All versions MELSEC-F series CPU module FX3UC-16MT/DSS: All versions MELSEC-F series CPU module FX3UC-32MT/DSS: All versions MELSEC-F series CPU module FX3UC-64MT/DSS: All versions MELSEC-F series CPU module FX3UC-96MT/DSS: All versions MELSEC-F series CPU module FX3UC-16MR/D-T: All versions MELSEC-F series CPU module FX3UC-16MR/DS-T: All versions MELSEC-F series CPU module FX3UC-32MT-LT: All versions MELSEC-F series CPU module FX3UC-32MT-LT-2: All versions MELSEC-F series CPU module FX3UC-16MT/D-P4: All versions MELSEC-F series CPU module FX3UC-16MT/DSS-P4: All versions MELSEC-F series CPU module FX3G-14MT/ES: All versions MELSEC-F series CPU module FX3G-24MT/ES: All versions MELSEC-F series CPU module FX3G-40MT/ES: All versions MELSEC-F series CPU module FX3G-60MT/ES: All versions MELSEC-F series CPU module FX3G-14MR/ES: All versions MELSEC-F series CPU module FX3G-24MR/ES: All versions MELSEC-F series CPU module FX3G-40MR/ES: All versions MELSEC-F series CPU module FX3G-60MR/ES: All versions MELSEC-F series CPU module FX3G-14MT/ESS: All versions MELSEC-F series CPU module FX3G-24MT/ESS: All versions MELSEC-F series CPU module FX3G-40MT/ESS: All versions MELSEC-F series CPU module FX3G-60MT/ESS: All versions MELSEC-F series CPU module FX3G-14MT/DS: All versions MELSEC-F series CPU module FX3G-24MT/DS: All versions MELSEC-F series CPU module FX3G-40MT/DS: All versions MELSEC-F series CPU module FX3G-60MT/DS: All versions MELSEC-F series CPU module FX3G-14MR/DS: All versions MELSEC-F series CPU module FX3G-24MR/DS: All versions MELSEC-F series CPU module FX3G-40MR/DS: All versions MELSEC-F series CPU module FX3G-60MR/DS: All versions MELSEC-F series CPU module FX3G-14MT/DSS: All versions MELSEC-F series CPU module FX3G-24MT/DSS: All versions MELSEC-F series CPU module FX3G-40MT/DSS: All versions MELSEC-F series CPU module FX3G-60MT/DSS: All versions MELSEC-F series CPU module FX3G-14MT/ES-A: All versions MELSEC-F series CPU module FX3G-24MT/ES-A: All versions MELSEC-F series CPU module FX3G-40MT/ES-A: All versions MELSEC-F series CPU module FX3G-60MT/ES-A: All versions MELSEC-F series CPU module FX3G-14MR/ES-A: All versions MELSEC-F series CPU module FX3G-24MR/ES-A: All versions MELSEC-F series CPU module FX3G-40MR/ES-A: All versions MELSEC-F series CPU module FX3G-60MR/ES-A: All versions MELSEC-F series CPU module FX3GC-32MT/D: All versions MELSEC-F series CPU module FX3GC-32MT/DSS: All versions MELSEC-F series CPU module FX3GE-24MT/ES: All versions MELSEC-F series CPU module FX3GE-40MT/ES: All versions MELSEC-F series CPU module FX3GE-24MR/ES: All versions MELSEC-F series CPU module FX3GE-40MR/ES: All versions MELSEC-F series CPU module FX3GE-24MT/ESS: All versions MELSEC-F series CPU module FX3GE-40MT/ESS: All versions MELSEC-F series CPU module FX3GE-24MT/DS: All versions MELSEC-F series CPU module FX3GE-40MT/DS: All versions MELSEC-F series CPU module FX3GE-24MR/DS: All versions MELSEC-F series CPU module FX3GE-40MR/DS: All versions MELSEC-F series CPU module FX3GE-24MT/DSS: All versions MELSEC-F series CPU module FX3GE-40MT/DSS: All versions MELSEC-F series CPU module FX3GA-24MT-CM: All versions MELSEC-F series CPU module FX3GA-40MT-CM: All versions MELSEC-F series CPU module FX3GA-60MT-CM: All versions MELSEC-F series CPU module FX3GA-24MR-CM: All versions MELSEC-F series CPU module FX3GA-40MR-CM: All versions MELSEC-F series CPU module FX3GA-60MR-CM: All versions MELSEC-F series CPU module FX3S-10MT/ES: All versions MELSEC-F series CPU module FX3S-14MT/ES: All versions MELSEC-F series CPU module FX3S-20MT/ES: All versions MELSEC-F series CPU module FX3S-30MT/ES: All versions MELSEC-F series CPU module FX3S-10MR/ES: All versions MELSEC-F series CPU module FX3S-14MR/ES: All versions MELSEC-F series CPU module FX3S-20MR/ES: All versions MELSEC-F series CPU module FX3S-30MR/ES: All versions MELSEC-F series CPU module FX3S-10MT/ESS: All versions MELSEC-F series CPU module FX3S-14MT/ESS: All versions MELSEC-F series CPU module FX3S-20MT/ESS: All versions MELSEC-F series CPU module FX3S-30MT/ESS: All versions MELSEC-F series CPU module FX3S-10MT/DS: All versions MELSEC-F series CPU module FX3S-14MT/DS: All versions MELSEC-F series CPU module FX3S-20MT/DS: All versions MELSEC-F series CPU module FX3S-30MT/DS: All versions MELSEC-F series CPU module FX3S-10MR/DS: All versions MELSEC-F series CPU module FX3S-14MR/DS: All versions MELSEC-F series CPU module FX3S-20MR/DS: All versions MELSEC-F series CPU module FX3S-30MR/DS: All versions MELSEC-F series CPU module FX3S-10MT/DSS: All versions MELSEC-F series CPU module FX3S-14MT/DSS: All versions MELSEC-F series CPU module FX3S-20MT/DSS: All versions MELSEC-F series CPU module FX3S-30MT/DSS: All versions MELSEC-F series CPU module FX3S-30MT/ES-2AD: All versions MELSEC-F series CPU module FX3S-30MT/ESS-2AD: All versions MELSEC-F series CPU module FX3S-30MR/ES-2AD: All versions MELSEC-F series CPU module FX3SA-10MT-CM: All versions MELSEC-F series CPU module FX3SA-14MT-CM: All versions MELSEC-F series CPU module FX3SA-20MT-CM: All versions MELSEC-F series CPU module FX3SA-30MT-CM: All versions MELSEC-F series CPU module FX3SA-10MR-CM: All versions MELSEC-F series CPU module FX3SA-14MR-CM: All versions MELSEC-F series CPU module FX3SA-20MR-CM: All versions MELSEC-F series CPU module FX3SA-30MR-CM: All versions MELSEC iQ-F series FX5U-32MT/ES: All versions MELSEC iQ-F series FX5U-64MT/ES: All versions MELSEC iQ-F series FX5U-80MT/ES: All versions MELSEC iQ-F series FX5U-32MR/ES: All versions MELSEC iQ-F series FX5U-64MR/ES: All versions MELSEC iQ-F series FX5U-80MR/ES: All versions MELSEC iQ-F series FX5U-32MT/DS: All versions MELSEC iQ-F series FX5U-64MT/DS: All versions MELSEC iQ-F series FX5U-80MT/DS: All versions MELSEC iQ-F series FX5U-32MR/DS: All versions MELSEC iQ-F series FX5U-64MR/DS: All versions MELSEC iQ-F series FX5U-80MR/DS: All versions MELSEC iQ-F series FX5U-32MT/ESS: All versions MELSEC iQ-F series FX5U-64MT/ESS: All versions MELSEC iQ-F series FX5U-80MT/ESS: All versions MELSEC iQ-F series FX5U-32MT/DSS: All versions MELSEC iQ-F series FX5U-64MT/DSS: All versions MELSEC iQ-F series FX5U-80MT/DSS: All versions MELSEC iQ-F series FX5UC-32MT/D: All versions MELSEC iQ-F series FX5UC-64MT/D: All versions MELSEC iQ-F series FX5UC-96MT/D: All versions MELSEC iQ-F series FX5UC-32MT/DSS: All versions MELSEC iQ-F series FX5UC-64MT/DSS: All versions MELSEC iQ-F series FX5UC-96MT/DSS: All versions MELSEC iQ-F series FX5UC-32MT/DS-TS: All versions MELSEC iQ-F series FX5UC-32MT/DSS-TS: All versions MELSEC iQ-F series FX5UC-32MR/DS-TS: All versions MELSEC iQ-F series FX5UJ-24MT/ES: All versions MELSEC iQ-F series FX5UJ-40MT/ES: All versions MELSEC iQ-F series FX5UJ-60MT/ES: All versions MELSEC iQ-F series FX5UJ-24MR/ES: All versions MELSEC iQ-F series FX5UJ-40MR/ES: All versions MELSEC iQ-F series FX5UJ-60MR/ES: All versions MELSEC iQ-F series FX5UJ-24MT/ESS: All versions MELSEC iQ-F series FX5UJ-40MT/ESS: All versions MELSEC iQ-F series FX5UJ-60MT/ESS: All versions MELSEC iQ-F series FX5UJ-24MT/DS: All versions MELSEC iQ-F series FX5UJ-40MT/DS: All versions MELSEC iQ-F series FX5UJ-60MT/DS: All versions MELSEC iQ-F series FX5UJ-24MR/DS: All versions MELSEC iQ-F series FX5UJ-40MR/DS: All versions MELSEC iQ-F series FX5UJ-60MR/DS: All versions MELSEC iQ-F series FX5UJ-24MT/DSS: All versions MELSEC iQ-F series FX5UJ-40MT/DSS: All versions MELSEC iQ-F series FX5UJ-60MT/DSS: All versions MELSEC iQ-F series FX5UJ-24MT/ES-A: All versions MELSEC iQ-F series FX5UJ-40MT/ES-A: All versions MELSEC iQ-F series FX5UJ-60MT/ES-A: All versions MELSEC iQ-F series FX5UJ-24MR/ES-A: All versions MELSEC iQ-F series FX5UJ-40MR/ES-A: All versions MELSEC iQ-F series FX5UJ-60MR/ES-A: All versions MELSEC iQ-F series FX5S-30MT/ES: All versions MELSEC iQ-F series FX5S-40MT/ES: All versions MELSEC iQ-F series FX5S-60MT/ES: All versions MELSEC iQ-F series FX5S-80MT/ES: All versions MELSEC iQ-F series FX5S-30MR/ES: All versions MELSEC iQ-F series FX5S-40MR/ES: All versions MELSEC iQ-F series FX5S-60MR/ES: All versions MELSEC iQ-F series FX5S-80MR/ES: All versions MELSEC iQ-F series FX5S-30MT/ESS: All versions MELSEC iQ-F series FX5S-40MT/ESS: All versions MELSEC iQ-F series FX5S-60MT/ESS: All versions MELSEC iQ-F series FX5S-80MT/ESS: All versions MELSEC iQ-F series FX5-40SSC-G: All versions MELSEC iQ-F series FX5-80SSC-G: All versions MELSEC iQ-F series FX5-40SSC-S: All versions MELSEC iQ-F series FX5-80SSC-S: All versions MELSEC iQ-R series CPU module R04/08/16/32/120(EN)CPU: All versions MELSEC iQ-R series CPU module R08/16/32/120PCPU: All versions MELSEC iQ-R series CPU module R16/32/64MTCPU: All versions MELSEC iQ-R series RD78G4/8/16/32/64/HV/HW: All versions MELSEC iQ-R series RD77MS2/4/8/16: All versions MELSEC iQ-R series RD77GF4/8/16/32: All versions MELSEC iQ-L series LD78G4/16: All versions MELSEC Q series Q172/173DSCPU: All versions MELSEC Q series Q170MSCPU: All versions MELSEC Q series QD77MS2/4/16: All versions MELSEC Q series QD77GF4/8/16: All versions MELSEC L LD77MS2/4/16: All versions Mitsubishi Electric CNC M800V/M80V series M800VW BND-2051W000-**: All versions Mitsubishi Electric CNC M800V/M80V series M800VS BND-2052W000-**: All versions Mitsubishi Electric CNC M800V/M80V series M80V BND-2053W000-**: All versions Mitsubishi Electric CNC M800V/M80V series M80VW BND-2054W000-**: All versions Mitsubishi Electric CNC M800/M80/E80 series M800W BND-2005W000-**: All versions Mitsubishi Electric CNC M800/M80/E80 series M800S BND-2006W000-**: All versions Mitsubishi Electric CNC M800/M80/E80 series M80 BND-2007W000-**: All versions Mitsubishi Electric CNC M800/M80/E80 series M80W BND-2008W000-**: All versions Mitsubishi Electric CNC M800/M80/E80 series E80 BND-2009W000-**: All versions Mitsubishi Electric CNC M700V/M70V/E70 series M750VW BND-1015W002-**: All versions Mitsubishi Electric CNC M700V/M70V/E70 series M730VW/M720VW BND-1015W000-**: All versions Mitsubishi Electric CNC M700V/M70V/E70 series M750VS BND-1012W002-**: All versions Mitsubishi Electric CNC M700V/M70V/E70 series M730VS /M720VS BND-1012W000-**: All versions Mitsubishi Electric CNC M700V/M70V/E70 series M70V BND-1018W000-**: All versions Mitsubishi Electric CNC M700V/M70V/E70 series E70 BND-1022W000-**: All versions.",CVE-2023-4699,10.0,Critical,CWE-306,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2653,11/02/2023,11/2/2023,2023,ICSA-23-306-04,Franklin Fueling System TS-550,Franklin Fueling System,TS-550,"The following versions of Franklin Fueling System TS-550, are affected: TS-550: All versions prior to 1.9.23.8960",CVE-2023-5846,8.3,High,CWE-916,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2652,11/02/2023,11/2/2023,2023,ICSA-23-306-05,Weintek EasyBuilder Pro,Weintek,EasyBuilder Pro,The following Weintek products are affected: EasyBuilder Pro: Versions prior to v6.07.02 EasyBuilder Pro: Versions 6.08.01.592 and prior EasyBuilder Pro: Versions 6.08.02.470 and prior,CVE-2023-5777,9.8,Critical,CWE-798,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2651,11/02/2023,11/2/2023,2023,ICSA-23-306-06,Schneider Electric SpaceLogic C-Bus Toolkit,Schneider Electric,SpaceLogic C-Bus Toolkit,The following Schneider Electric products are affected: SpaceLogic C-Bus Toolkit: Versions 1.16.3 and prior,"CVE-2023-5402, CVE-2023-5399",9.8,Critical,"CWE-269, CWE-22",Commercial Facilities,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2650,10/31/2023,10/31/2023,2023,ICSA-23-304-02,INEA ME RTU,INEA,ME RTU,The following versions of Inea ME RTU are affected: ME RTU: versions 3.36b and prior,"CVE-2023-35762, CVE-2023-29155",9.9,Critical,"CWE-78, CWE-287",Energy; Water and Wastewater Systems; Transportation Systems,Worldwide,Slovenia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2649,10/31/2023,10/31/2023,2023,ICSA-23-304-03,Zavio IP Camera,Zavio,IP Camera,The following versions of Zavio IP Cameras are affected: CF7500: version M2.1.6.05 CF7300: version M2.1.6.05 CF7201: version M2.1.6.05 CF7501: version M2.1.6.05 CB3211: version M2.1.6.05 CB3212: version M2.1.6.05 CB5220: version M2.1.6.05 CB6231: version M2.1.6.05 B8520: version M2.1.6.05 B8220: version M2.1.6.05 CD321: version M2.1.6.05,"CVE-2023-3959, CVE-2023-45225, CVE-2023-43755, CVE-2023-39435, CVE-2023-4249",9.8,Critical,"CWE-121, CWE-78",Multiple Critical Sectors,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2648,10/26/2023,10/26/2023,2023,ICSA-23-299-01,Dingtian DT-R002,Dingtian,DT-R002,"The following versions of Dingtian DT-R002, a relay board, are affected: DT-R002: version 3.1.276A",CVE-2022-29593,5.9,Medium,CWE-294,Critical Manufacturing,Unknown,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2647,10/26/2023,10/26/2023,2023,ICSA-23-299-02,Centralite Pearl Thermostat,Centralite,Pearl Thermostat,The following versions Centralite Pearl Thermostat are affected: Pearl Thermostat: version 0x04075010,CVE-2023-24678,7.5,High,CWE-770,Commercial Facilities; Communications,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2646,10/24/2023,2/4/2025,2023,ICSA-23-299-03,"Ashlar-Vellum Cobalt, Graphite, Xenon, Argon, Lithium (Update A)",Ashlar-Vellum,"Cobalt, Graphite, Xenon, Argon, Lithium, and Cobalt Share",The following Ashlar-Vellum products are affected: Cobalt: Versions prior to v12 SP2 Build (1204.200) Cobalt Share: Versions prior to v12 SP2 Build (1204.200) Graphite: v13.0.48 and prior Xenon: Versions prior to v12 SP2 Build (1204.200) Argon: Versions prior to v12 SP2 Build (1204.200) Lithium: Versions prior to v12 SP2 Build (1204.200).,"CVE-2023-39427, CVE-2023-39936, CVE-2023-39943, CVE-2023-40222",8.4,High,"CWE-787, CWE-125, CWE-122, CWE-787",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2645,10/26/2023,10/26/2023,2023,ICSA-23-299-04,Rockwell Automation Arena,Rockwell Automation,Arena,"The following versions of Arena, a simulation software, are affected: Arena: Version 16.20.00001","CVE-2023-27854, CVE-2023-27858",7.8,High,"CWE-125, CWE-824",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2644,10/26/2023,10/26/2023,2023,ICSA-23-299-05,Rockwell Automation FactoryTalk View Site Edition,Rockwell Automation,FactoryTalk View Site Edition,Rockwell Automation reports that the following versions of FactoryTalk View Site Edition are affected: FactoryTalk View Site Edition: V11.0,CVE-2023-46289,7.5,High,CWE-20,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2643,10/26/2023,10/26/2023,2023,ICSA-23-299-06,Rockwell Automation FactoryTalk Services Platform,Rockwell Automation,FactoryTalk Services Platform,Rockwell Automation reports that the following products are affected: FactoryTalk Services Platform: v2.74,CVE-2023-46290,8.1,High,CWE-287,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2642,10/26/2023,10/26/2023,2023,ICSA-23-299-07,Sielco PolyEco FM Transmitter,Sielco,PolyEco1000,"The following versions of Sielco PolyEco1000, a FM transmitter, are affected: PolyEco1000: CPU:2.0.6 FPGA:10.19 PolyEco1000: CPU:1.9.4 FPGA:10.19 PolyEco1000: CPU:1.9.3 FPGA:10.19 PolyEco500: CPU:1.7.0 FPGA:10.16 PolyEco300: CPU:2.0.2 FPGA:10.19 PolyEco300: CPU:2.0.0 FPGA:10.19","CVE-2023-0897, CVE-2023-5754, CVE-2023-46661, CVE-2023-46662, CVE-2023-46663, CVE-2023-46664, CVE-2023-46665",9.8,Critical,"CWE-384, CWE-307, CWE-284",Communications,Worldwide,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2641,10/26/2023,10/26/2023,2023,ICSA-23-299-08,Sielco Radio Link and Analog FM Transmitters,Sielco,Analog FM Transmitters and Radio Link,The following Sielco devices are affected: Analog FM transmitter: 2.12 (EXC5000GX) Analog FM transmitter: 2.12 (EXC120GX) Analog FM transmitter: 2.11 (EXC300GX) Analog FM transmitter: 2.10 (EXC1600GX) Analog FM transmitter: 2.10 (EXC2000GX) Analog FM transmitter: 2.08 (EXC1600GX) Analog FM transmitter: 2.08 (EXC1000GX) Analog FM transmitter: 2.07 (EXC3000GX) Analog FM transmitter: 2.06 (EXC5000GX) Analog FM transmitter: 1.7.7 (EXC30GT) Analog FM transmitter: 1.7.4 (EXC300GT) Analog FM transmitter: 1.7.4 (EXC100GT) Analog FM transmitter: 1.7.4 (EXC5000GT) Analog FM transmitter: 1.6.3 (EXC1000GT) Analog FM transmitter: 1.5.4 (EXC120GT) Radio Link: 2.06 (RTX19) Radio Link: 2.05 (RTX19) Radio Link: 2.00 (EXC19) Radio Link: 1.60 (RTX19) Radio Link: 1.59 (RTX19) Radio Link: 1.55 (EXC19),"CVE-2023-42769, CVE-2023-45317, CVE-2023-45228, CVE-2023-41966",9.8,Critical,"CWE-284, CWE-352, CWE-267",Communications,Worldwide,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2640,10/24/2023,11/21/2023,2023,ICSA-23-297-01,Rockwell Automation Stratix 5800 and Stratix 5200 (Update A),Rockwell Automation,Stratix 5800 and Stratix 5200,The following versions of Stratix products and the contained Cisco IOS software are affected: Stratix 5800 (running Cisco IOS XE Software with the Web UI feature enabled): All versions Stratix 5200 (running Cisco IOS XE Software with the Web UI feature enabled): All versions,"CVE-2023-20198, CVE-2023-20273",10.0,Critical,"CWE-420, CWE-78",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2639,10/17/2023,10/17/2023,2023,ICSA-23-290-01,Schneider Electric EcoStruxure Power Monitoring Expert and Power Operation Products,Schneider Electric,"EcoStruxure Power Monitoring Expert, EcoStruxure Power Operation with Advanced Reports, EcoStruxure Power SCADA Operation with Advanced Reports",The following version of Schneider Electric EcoStruxure Power Monitoring Expert and Power Operation Products is affected: EcoStruxure Power Monitoring Expert: All versions prior to Hotfix-145271 EcoStruxure Power Operation with Advanced Reports: All versions prior to application of Hotfix-145271 EcoStruxure Power SCADA Operation with Advanced Reports: All versions prior to Hotfix-145271.,CVE-2023-5391,9.8,Critical,CWE-502,Multiple Critical Sectors,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2638,10/17/2023,10/17/2023,2023,ICSA-23-290-02,Rockwell Automation FactoryTalk Linx,Rockwell Automation,FactoryTalk Linx,The following versions of Rockwell products are affected: FactoryTalk Linx: v6.20 and prior.,CVE-2023-29464,8.2,High,CWE-20,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2637,10/12/2023,10/12/2023,2023,ICSA-23-285-01,Siemens SIMATIC CP products,Siemens,SIMATIC CP products,"The following products of Siemens, are affected: SIMATIC CP 1604 (6GK1160-4AA01): all versions SIMATIC CP 1616 (6GK1161-6AA02): all versions SIMATIC CP 1623 (6GK1162-3AA00): all versions SIMATIC CP 1626 (6GK1162-6AA01): all versions SIMATIC CP 1628 (6GK1162-8AA00): all versions","CVE-2023-37194, CVE-2023-37195",7.8,High,"CWE-284, CWE-400",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2636,10/12/2023,10/12/2023,2023,ICSA-23-285-02,Siemens SCALANCE W1750D,Siemens,SCALANCE W1750D,"The following products of Siemens, are affected: SCALANCE W1750D (JP) (6GK5750-2HX01-1AD0): versions prior to V8.10.0.6 SCALANCE W1750D (ROW) (6GK5750-2HX01-1AA0): versions prior to V8.10.0.6 SCALANCE W1750D (USA) (6GK5750-2HX01-1AB0): versions prior to V8.10.0.6","CVE-2023-22779, CVE-2023-22780, CVE-2023-22781, CVE-2023-22782, CVE-2023-22783, CVE-2023-22784, CVE-2023-22785, CVE-2023-22786, CVE-2023-22787, CVE-2023-22788, CVE-2023-22789, CVE-2023-22790, CVE-2023-22791",9.8,Critical,"CWE-120, CWE-20, CWE-77, CWE-200",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2635,10/12/2023,10/12/2023,2023,ICSA-23-285-03,Siemens SICAM A8000 Devices,Siemens,SICAM A8000,"The following versions of Siemens SICAM A8000, a remote terminal unit, are affected: CP-8031 MASTER MODULE (6MF2803-1AA00): All versions prior to CPCI85 V05.11 CP-8050 MASTER MODULE (6MF2805-0AA00): All versions prior to CPCI85 V05.11",CVE-2023-42796,7.5,High,CWE-22,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2634,10/12/2023,10/12/2023,2023,ICSA-23-285-04,Siemens Xpedition Layout Browser,Siemens,Xpedition Layout Browser,The following versions of Siemens Xpedition Layout Browser are affected: Xpedition Layout Browser: All versions prior to VX.2.14,CVE-2023-30900,7.8,High,CWE-121,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2633,10/12/2023,10/12/2023,2023,ICSA-23-285-05,Siemens Simcenter Amesim,Siemens,Simcenter Amesim,The following versions of Siemens Simcenter Amesim are affected: Simcenter Amesim: All versions prior to V2021.1,CVE-2023-43625,8.0,High,CWE-94,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2632,10/12/2023,10/12/2023,2023,ICSA-23-285-06,Siemens SICAM PAS/PQS,Siemens,SICAM PAS/PQS,The following versions of Siemens SICAM PAS/PQS are affected: SICAM PAS/PQS: Version 8.00 up to but not including 8.22.,CVE-2023-38640,6.6,Medium,CWE-732,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2631,10/12/2023,10/12/2023,2023,ICSA-23-285-07,Siemens RUGGEDCOM APE180,Siemens,RUGGEDCOM APE1808,"The following products of Siemens, are affected: RUGGEDCOM APE1808 with Nozomi Guardian / CMC: versions prior to V22.6.2","CVE-2023-22378, CVE-2023-22843, CVE-2023-23574, CVE-2023-23903, CVE-2023-24015, CVE-2023-24471, CVE-2023-24477",7.1,High,"CWE-89, CWE-79, CWE-20, CWE-863, CWE-384",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2630,10/12/2023,10/12/2023,2023,ICSA-23-285-08,Siemens SINEC NMS,Siemens,SINEC NMS,"The following products of Siemens, are affected: SINEC NMS: All versions prior to V2.0","CVE-2022-30527, CVE-2023-44315",7.8,High,"CWE-732, CWE-79",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2629,10/12/2023,10/12/2023,2023,ICSA-23-285-09,Siemens CPCI85 Firmware of SICAM A8000 Devices,Siemens,"CP-8050, CP-8031","The following products of Siemens, are affected if activated with debug support: CP-8031 MASTER MODULE (6MF2803-1AA00): All versions prior to CPCI85 V05.11 CP-8050 MASTER MODULE (6MF2805-0AA00): All versions prior to CPCI85 V05.11",CVE-2023-36380,9.8,Critical,CWE-798,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2628,10/12/2023,10/12/2023,2023,ICSA-23-285-10,Siemens Tecnomatix Plant Simulation,Siemens,Tecnomatix Plant Simulation,"The following products of Siemens, are affected: Tecnomatix Plant Simulation V2201: All versions prior to V2201.0009 Tecnomatix Plant Simulation V2302: All versions prior to V2302.0003","CVE-2023-44081, CVE-2023-44082, CVE-2023-44083, CVE-2023-44084, CVE-2023-44085, CVE-2023-44086, CVE-2023-44087",7.8,High,"CWE-787, CWE-125",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2627,10/12/2023,10/12/2023,2023,ICSA-23-285-11,Siemens Mendix Forgot Password Module,Siemens,Mendix Forgot Password Module,"The following products of Siemens, are affected: Mendix Forgot Password (Mendix 7 compatible): All versions prior to V3.7.3. Mendix Forgot Password (Mendix 8 compatible): All versions prior to V4.1.3. Mendix Forgot Password (Mendix 9 compatible): All versions prior to V5.4.0. Mendix Forgot Password (Mendix 10 compatible): All versions prior to V5.4.0.",CVE-2023-43623,5.3,Medium,CWE-203,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2626,10/12/2023,10/12/2023,2023,ICSA-23-285-12,Weintek cMT3000 HMI Web CGI,Weintek,cMT3000 CMI Web CGI,The following Weintek products are affected: cMT-FHD: OS version 20210210 or prior. cMT-HDM: OS version 20210204 or prior. cMT3071: OS version 20210218 or prior. cMT3072: OS version 20210218 or prior. cMT3103: OS version 20210218 or prior. cMT3090: OS version 20210218 or prior. cMT3151: OS version 20210218 or prior.,"CVE-2023-38584, CVE-2023-40145, CVE-2023-43492",9.8,Critical,"CWE-121, CWE-78",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2625,10/12/2023,10/12/2023,2023,ICSA-23-285-13,Mitsubishi Electric MELSEC-F Series,Mitsubishi Electric,MELSEC-F Series,"Mitsubishi Electric reports that the following versions of MELSEC-F series programmable controllers are affected if they are used with ethernet communication special adapter FX3U-ENET-ADP or ethernet communication block FX3U-ENET(-L). Some of these products are sold in limited regions, see the Mitsubishi Electric advisory for details: MELSEC-F series FX3U-xMy/z x=16,32,48,64,80,128, y=T,R, z=ES,ESS,DS,DSS: All versions. MELSEC-F series FX3U-32MR/UA1, FX3U-64MR/UA1: All versions. MELSEC-F FX3U-32MS/ES, FX3U-64MS/ES: All versions. MELSEC-F FX3U-xMy/ES-A x=16,32,48,64,80,128, y=T,R: All versions. MELSEC-F FX3UC-xMT/z x=16,32,64,96, z=D,DSS: All versions. MELSEC-F FX3UC-16MR/D-T, FX3UC-16MR/DS-T: All versions. MELSEC-F FX3UC-32MT-LT, FX3UC-32MT-LT-2: All versions. MELSEC-F FX3UC-16MT/D-P4, FX3UC-16MT/DSS-P4: All versions. MELSEC-F FX3G-xMy/z x=14,24,40,60, y=T,R, z=ES,ESS,DS,DSS: All versions. MELSEC-F FX3G-xMy/ES-A x=14,24,40,60, y=T,R: All versions. MELSEC-F FX3GC-32MT/D, FX3GC-32MT/DSS: All versions. MELSEC-F FX3GE-xMy/z x=24,40, y=T,R, z=ES,ESS,DS,DSS: All versions. MELSEC-F FX3GA-xMy-CM x=24,40,60, y=T,R: All versions. MELSEC-F FX3S-xMy/z x=10,14,20,30, y=T,R, z=ES,ESS,DS,DSS: All versions. MELSEC-F FX3S-30My/z-2AD y=T,R, z=ES,ESS: All versions. MELSEC-F FX3SA-xMy-CM x=10,14,20,30, y=T,R: All versions.",CVE-2023-4562,9.1,Critical,CWE-287,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2624,10/12/2023,10/12/2023,2023,ICSA-23-285-14,Hikvision Access Control and Intercom Products,Hikvision,Access Control and Intercom Products,The following Access Control and Intercom Products are affected: DS-K1T804AXX: V1.4.0_build221212 and prior. DS-K1T341AXX: V3.2.30_build221223 and prior. DS-K1T671XXX: V3.2.30_build221223 and prior. DS-K1T343XXX: V3.14.0_build230117 and prior. DS-K1T341C: V3.3.8_build230112 and prior. DS-K1T320XXX: V3.5.0_build220706 and prior. DS-KH63 Series: V2.2.8_build230219 and prior. DS-KH85 Series: V2.2.8_build230219 and prior. DS-KH62 Series: V1.4.62_build220414 and prior. DS-KH9310-WTE1(B): V2.1.76_build230204 and prior. DS-KH9510-WTE1(B): V2.1.76_build230204 and prior.,"CVE-2023-28809, CVE-2023-28810",7.5,High,"CWE-384, CWE-284",Commercial Facilities; Government Facilities,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2623,10/12/2023,10/12/2023,2023,ICSA-23-285-15,Advantech WebAccess,Advantech,WebAccess,"The following versions of Advantech WebAccess, are affected: Advantech WebAccess: Version 9.1.3.",CVE-2023-4215,6.5,Medium,CWE-200,Critical Manufacturing; Energy; Water and Wastewater Systems,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2622,10/12/2023,10/12/2023,2023,ICSA-23-285-16,Schneider Electric IGSS,Schneider Electric,IGSS (Interactive Graphical SCADA System),Schneider Electric reports these vulnerabilities affect the following IGSS (Interactive Graphical SCADA System) products: IGSS Update Service (IGSSupdateservice.exe): v16.0.0.23211 and prior.,CVE-2023-4516,7.8,High,CWE-306,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2621,10/12/2023,10/12/2023,2023,ICSMA-23-285-01,Santesoft Sante DICOM Viewer Pro,Santesoft,Sante DICOM Viewer Pro,The following Santesoft products are affected: Sante DICOM Viewer Pro: v12.2.4 and prior,"CVE-2023-39431, CVE-2023-35986",7.8,High,"CWE-787, CWE-121",Healthcare and Public Health,Worldwide,Cyprus,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2620,10/12/2023,10/12/2023,2023,ICSMA-23-285-02,Santesoft Sante FFT Imaging,Santesoft,Sante FFT Imaging,The following Santesof products are affected: Sante FFT Imaging: Versions v1.4.0 and prior,CVE-2023-5059,7.8,High,CWE-125,Healthcare and Public Health,Worldwide,Cyprus,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2619,10/5/2023,10/5/2023,2023,ICSA-23-278-01,"Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products",Hitachi Energy,"AFS65x, AFF66x, AFS67x, AFR67x Series",The following Hitachi Energy products and versions are affected: AFF66X FW: 03.0.02 and prior AFS66X-S: All versions AFS660-C: All versions AFS66X-B: All versions AFS670-V20: All versions AFS65X: All versions AFS67X: All versions AFR677: All versions,"CVE-2021-45960, CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824, CVE-2022-22825, CVE-2022-22826, CVE-2022-22827, CVE-2022-25314, CVE-2022-25315, CVE-2022-25235, CVE-2022-25236, CVE-2022-23852, CVE-2022-23990",9.8,Critical,"CWE-682, CWE-190, CWE-116, CWE-668",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2618,10/5/2023,10/5/2023,2023,ICSA-23-278-02,Qognify NiceVision,Qognify,NiceVision,"The following versions of Qoginfy NiceVision, an IP-video surveillance system, are affected: NiceVision: v3.1 and prior",CVE-2023-2306,10.0,Critical,CWE-798,Commercial Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2617,10/5/2023,6/4/2024,2023,ICSA-23-278-03,Mitsubishi Electric CC-Link IE TSN Industrial Managed Switch (Update A),Mitsubishi Electric,CC-Link IE TSN Industrial Managed Switch,The following Mitsubishi Electric products are affected: CC-Link IE TSN Industrial Managed Switch NZ2MHG-TSNT8F2: firmware version 05 and prior CC-Link IE TSN Industrial Managed Switch NZ2MHG-TSNT4: firmware version 05 and prior.,"CVE-2022-4304, CVE-2022-4450",6.5,Medium,"CWE-208, CWE-415",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2616,9/28/2023,9/28/2023,2023,ICSA-23-271-01,Rockwell Automation PanelView 800,Rockwell Automation,PanelView 800,"The following versions of Rockwell Automation PanelView 800, a graphics terminal, are affected: PanelView 800 2711R-T10T: V3.011 PanelView 800 2711R-T7T: V3.011 PanelView 800 2711R-T4T: V3.011",CVE-2017-12652,9.8,Critical,CWE-20,Energy; Water and Wastewater System; Telecommunications,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2615,9/28/2023,9/28/2023,2023,ICSA-23-271-02,DEXMA DexGate,DEXMA,DEXGate,The following version of DEXGate is affected: DEXGate: Version 20130114,"CVE-2023-40153, CVE-2023-42435, CVE-2023-4108, CVE-2023-41088, CVE-2023-42666",8.0,High,"CWE-79, CWE-352, CWE-287, CWE-319, CWE-200",Multiple Critical Sectors,Worldwide,Spain,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2614,9/26/2023,9/26/2023,2023,ICSA-23-269-01,Suprema BioStar 2,Suprema Inc.,BioStar 2,"The following versions of Suprema BioStar 2, an access control system, are affected: BioStar 2: version 2.8.16",CVE-2023-27167,6.5,Medium,CWE-89,Multiple Critical Sectors,Worldwide,South Korea,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2613,9/26/2023,9/26/2023,2023,ICSA-23-269-02,Hitachi Energy Asset Suite 9,Hitachi Energy,Asset Suite 9,Hitachi Energy reports these vulnerabilities affect the following products: Asset Suite: Versions 9.6.3.11.1 and prior Asset Suite: Version 9.6.4,CVE-2023-4816,6.9,Medium,CWE-287,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2612,9/26/2023,7/9/2024,2023,ICSA-23-269-03,Mitsubishi Electric FA Engineering Software (Update A),Mitsubishi Electric,FA Engineering Software Products,The following versions of Mitsubishi Electric FA Engineering Software Products are affected: AL-PCS/WIN-E: All versions CPU Module Logging Configuration Tool: All versions EZSocket: All versions FR Configurator2: All versions FX Configurator-EN: All versions FX Configurator-EN-L: All versions FX Configurator-FP: All versions GT Designer3 Version1(GOT1000): All versions GT Designer3 Version1(GOT2000): All versions GT SoftGOT1000 Version3: All versions GT SoftGOT2000 Version1: All versions GX LogViewer: All versions GX Works2: All versions GX Works3: All versions MELSOFT FieldDeviceConfigurator: All versions MELSOFT iQ AppPortal: All versions MELSOFT MaiLab: All versions MELSOFT Navigator: All versions MELSOFT Update Manager: All versions MX Component: All versions MX Sheet: All versions PX Developer: All versions RT ToolBox3: All versions RT VisualBox: All versions Data Transfer: All versions Data Transfer Classic: All versions.,CVE-2023-4088,9.3,Critical,CWE-276,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2611,9/26/2023,9/26/2023,2023,ICSA-23-269-04,Advantech EKI-1524-CE series,Advantech,"EKI-1524-CE, EKI-1522-CE, EKI-1521-CE",The following Advantech serial device servers are affected: EKI-1524-CE series: versions 1.24 and prior EKI-1522-CE series: versions 1.24 and prior EKI-1521-CE series: versions 1.24 and prior,"CVE-2023-4202, CVE-2023-4203",5.4,Medium,CWE-79,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2610,9/26/2023,9/26/2023,2023,ICSA-23-269-05,Baker Hughes Bently Nevada 3500,Baker Hughes - Bently Nevada,Bently Nevada 3500 System,"The following versions of the Bently Nevada 3500 System, a real-time monitoring solution, are affected: Bently Nevada 3500 Rack (TDI Firmware): version 5.05","CVE-2023-34437, CVE-2023-34441, CVE-2023-36857",7.5,High,"CWE-200, CWE-319, CWE-294",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2609,9/21/2023,9/21/2023,2023,ICSA-23-264-01,Real Time Automation 460 Series,Real Time Automation,460MCBS,The following Real Time Automation products are affected: 460 Series: Versions prior to v8.9.8.,CVE-2023-4523,9.4,Critical,CWE-79,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2608,9/21/2023,9/21/2023,2023,ICSA-23-264-02,Siemens Spectrum Power 7,Siemens,Spectrum Power 7,"The following products of Siemens, are affected: Spectrum Power 7: versions prior to V23Q3.",CVE-2023-38557,8.2,High,CWE-732,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2607,9/21/2023,9/21/2023,2023,ICSA-23-264-03,Delta Electronics DIAScreen,Delta Electronics,DIAScreen,"Delta Electronics reports the following versions of DIAScreen, a software configuration tool for Delta devices, are affected: DIAScreen: versions prior to v1.3.2.",CVE-2023-5068,7.8,High,CWE-787,Energy,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2606,9/21/2023,9/21/2023,2023,ICSA-23-264-04,Rockwell Automation Select Logix Communication Modules,Rockwell Automation,"1756-EN2T, 1756-EN2TK, 1756-EN2TXT, 1756-EN2TP, 1756-EN2TPK, 1756-EN2TPXT, 1756-EN2TR, 1756-EN2TRK, 1756-EN2TRXT, 1756-EN2F, 1756-EN2FK, 1756-EN3TR, 1756-EN3TRK","The following versions of Rockwell Automation Logix Communication Modules, are affected: 1756-EN2T Series A: versions 5.008 and prior 1756-EN2T Series A: version 5.028 1756-EN2T Series B: versions 5.008 and prior 1756-EN2T Series B: version 5.028 1756-EN2T Series C: versions 5.008 and prior 1756-EN2T Series C: version 5.028 1756-EN2T Series D: versions 11.002 and prior 1756-EN2TK Series A: versions 5.008 and prior 1756-EN2TK Series A: version 5.028 1756-EN2TK Series B: versions 5.008 and prior 1756-EN2TK Series B: version 5.028 1756-EN2TK Series C: versions 5.008 and prior 1756-EN2TK Series C: version 5.028 1756-EN2TK Series D: versions 11.002 and prior 1756-EN2TXT Series A: versions 5.008 and prior 1756-EN2TXT Series A: and version 5.028 1756-EN2TXT Series B: versions 5.008 and prior 1756-EN2TXT Series B: version 5.028 1756-EN2TXT Series C: versions 5.008 and prior 1756-EN2TXT Series C: version 5.028 1756-EN2TXT Series D: versions 11.002 and prior 1756-EN2TP Series A: versions 11.002 and prior 1756-EN2TPK Series A: versions 11.002 and prior 1756-EN2TPXT Series A: versions 11.002 and prior 1756-EN2TR Series A: versions 5.008 and prior 1756-EN2TR Series A: version 5.028 1756-EN2TR Series B: versions 5.008 and prior 1756-EN2TR Series B: version 5.028 1756-EN2TR Series C: versions 11.002 and prior 1756-EN2TRK Series A: versions 5.008 and prior 1756-EN2TRK Series A: version 5.028 1756-EN2TRK Series B: versions 5.008 and prior 1756-EN2TRK Series B: version 5.028 1756-EN2TRK Series C: versions 11.002 and prior 1756-EN2TRXT Series A: versions 5.008 and prior 1756-EN2TRXT Series A: version 5.028 1756-EN2TRXT Series B: versions 5.008 and prior 1756-EN2TRXT Series B: version 5.028 1756-EN2TRXT Series C: versions 11.002 and prior 1756-EN2F Series A: versions 5.008 and prior 1756-EN2F Series A: version 5.028 1756-EN2F Series B: versions 5.008 and prior 1756-EN2F Series B: version 5.028 1756-EN2F Series C: versions 11.002 and prior 1756-EN2FK Series A: versions 5.008 and prior 1756-EN2FK Series A: version 5.028 1756-EN2FK Series B: versions 5.008 and prior 1756-EN2FK Series B: version 5.028 1756-EN2FK Series C: versions 11.002 and prior 1756-EN3TR Series A: versions 5.008 and prior 1756-EN3TR Series A: version 5.028 1756-EN3TR Series B: versions 11.002 and prior 1756-EN3TRK Series A: versions 5.008 and prior 1756-EN3TRK Series A: version 5.028 1756-EN3TRK Series B: versions 11.002 and prior.",CVE-2023-2262,9.8,Critical,CWE-121,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2605,9/21/2023,9/21/2023,2023,ICSA-23-264-05,Rockwell Automation Connected Components Workbench,Rockwell Automation,Connected Components Workbench,The following versions of Rockwell Automation Connected Components Workbench Smart Security Manager are affected: Connected Components Workbench: versions prior to R21.,"CVE-2020-16017, CVE-2022-0609, CVE-2020-16009, CVE-2020-16013, CVE-2020-15999",9.6,Critical,"CWE-416, CWE-787",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2604,9/21/2023,9/21/2023,2023,ICSA-23-264-06,Rockwell Automation FactoryTalk View Machine Edition,Rockwell Automation,FactoryTalk View Machine Edition,The following Rockwell Automation products are affected: FactoryTalk View Machine Edition: v13.0 FactoryTalk View Machine Edition: v12.0 and prior.,CVE-2023-2071,9.8,Critical,CWE-20,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2603,9/19/2023,9/19/2023,2023,ICSA-23-262-01,Siemens SIMATIC PCS neo Administration Console,Siemens,SIMATIC PCS neo Administration Console,Siemens reports that the following products are affected:SIMATIC PCS neo (Administration Console): V4.0SIMATIC PCS neo (Administration Console): V4.0 Update 1.,CVE-2023-38558,5.5,Medium,CWE-538,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2602,9/19/2023,9/19/2023,2023,ICSA-23-262-03,Omron Engineering Software Zip-Slip,Omron,"Sysmac Studio, NX-IO Configurator",The following versions of Omron engineering software are affected:Sysmac Studio: version 1.54 and priorNX-IO Configurator: version 1.22 and prior.,CVE-2018-1002205,5.5,Medium,CWE-22,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2601,9/19/2023,9/19/2023,2023,ICSA-23-262-04,Omron Engineering Software,Omron,Sysmac Studio,The following versions of Omron engineering software are affected: Sysmac Studio: version 1.54 and prior.,CVE-2022-45793,5.5,Medium,CWE-285,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2600,9/19/2023,9/19/2023,2023,ICSA-23-262-05,Omron CJ/CS/CP Series,Omron,Sysmac CJ/CS/CP Series,"The following versions of Omron CJ/CS/CP series, programmable logic controllers, are affected:Smart Security Manager: Versions 1.4 and prior to 1.31Smart Security Manager: Versions 1.5 and prior CJ2H-CPU ** (-EIP): version 1.4 and prior CJ2M-CPU ** : version 2.0 and prior CS1H/G-CPU ** CJ1G-CPU ** P: version 4.0 and prior CS1D-CPU ** H / -CPU ** P: version 1.3 and prior CS1D-CPU ** S: version 2.0 and prior CP1E-E / -N: version 1.2 and prior.",CVE-2022-45790,7.5,High,CWE-799,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2599,9/14/2023,9/14/2023,2023,ICSA-23-257-01,"Siemens SIMATIC, SIPLUS Products",Siemens,"SIMATIC, SIPLUS Products",The following Siemens products are affected:SIMATIC Cloud Connect 7 CC712 (6GK1411-1AC00): All versions prior to v2.2SIMATIC Cloud Connect 7 CC716 (6GK1411-5AC00): All versions prior to v2.2SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0): All versions prior to v2.9.7SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0): All versions from v3.0.1 to v3.0.3SIMATIC Drive Controller CPU 1507D TF (6ES7615-7DF10-0AB0): All versions prior to v2.9.7SIMATIC Drive Controller CPU 1507D TF (6ES7615-7DF10-0AB0): All versions from v3.0.1 to v3.0.3SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions prior to v21.9.7SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): Versions 30.0.0 and priorSIMATIC S7-1200 CPU family (incl. SIPLUS variants): All versionsSIMATIC S7-1500 CPU 1510SP F-1 PN (6ES7510-1SJ01-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1510SP F-1 PN (6ES7510-1SK03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1510SP-1 PN (6ES7510-1DJ01-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1510SP-1 PN (6ES7510-1DK03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK01-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK02-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AL03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK00-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK01-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK01-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK02-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FL03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1511T-1 PN (6ES7511-1TK01-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1511T-1 PN (6ES7511-1TL03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1511TF-1 PN (6ES7511-1UK01-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1511TF-1 PN (6ES7511-1UL03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK00-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK01-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1512SP F-1 PN (6ES7512-1SK01-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1512SP F-1 PN (6ES7512-1SM03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1512SP-1 PN (6ES7512-1DK01-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1512SP-1 PN (6ES7512-1DM03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL01-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL02-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AM03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL01-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL02-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FM03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1513R-1 PN (6ES7513-1RL00-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1513R-1 PN (6ES7513-1RM03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1514SP F-2 PN (6ES7514-2SN03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1514SP-2 PN (6ES7514-2DN03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1514SPT F-2 PN (6ES7514-2WN03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1514SPT-2 PN (6ES7514-2VN03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM01-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM02-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AN03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM01-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM02-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FN03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1515R-2 PN (6ES7515-2RM00-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1515R-2 PN (6ES7515-2RN03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1515T-2 PN (6ES7515-2TM01-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1515T-2 PN (6ES7515-2TN03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1515TF-2 PN (6ES7515-2UM01-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1515TF-2 PN (6ES7515-2UN03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN01-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN02-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AP03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN01-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN02-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FP03-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1516T-3 PN/DP (6ES7516-3TN00-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1516TF-3 PN/DP (6ES7516-3UN00-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1517-3 PN/DP (6ES7517-3AP00-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1517F-3 PN/DP (6ES7517-3FP00-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1517H-3 PN (6ES7517-3HP00-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1517T-3 PN/DP (6ES7517-3TP00-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1517TF-3 PN/DP (6ES7517-3UP00-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1518-4 PN/DP (6ES7518-4AP00-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0):All versions prior to v3.0.3SIMATIC S7-1500 CPU 1518F-4 PN/DP (6ES7518-4FP00-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1518HF-4 PN (6ES7518-4JP00-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1518T-4 PN/DP (6ES7518-4TP00-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU 1518TF-4 PN/DP (6ES7518-4UP00-0AB0): All versions prior to v3.0.3SIMATIC S7-1500 CPU S7-1518-4 PN/DP ODK (6ES7518-4AP00-3AB0):All versions prior to v2.9.7SIMATIC S7-1500 CPU S7-1518F-4 PN/DP ODK (6ES7518-4FP00-3AB0): All versions prior to v2.9.7SIMATIC S7-1500 ET 200pro: CPU 1513PRO F-2 PN (6ES7513-2GL00-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 ET 200pro: CPU 1513PRO-2 PN (6ES7513-2PL00-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 ET 200pro: CPU 1516PRO F-2 PN (6ES7516-2GN00-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 ET 200pro: CPU 1516PRO-2 PN (6ES7516-2PN00-0AB0): All versions prior to v2.9.7SIMATIC S7-1500 Software Controller V2: All versions prior to v21.9.7SIMATIC S7-1500 Software Controller V3: All versionsSIMATIC S7-PLCSIM Advanced: All versionsSIPLUS ET 200SP CPU 1510SP F-1 PN (6AG1510-1SJ01-2AB0): All versions prior to v2.9.7SIPLUS ET 200SP CPU 1510SP F-1 PN RAIL (6AG2510-1SJ01-1AB0):All versions prior to v2.9.7SIPLUS ET 200SP CPU 1510SP-1 PN (6AG1510-1DJ01-2AB0): All versions prior to v2.9.7SIPLUS ET 200SP CPU 1510SP-1 PN (6AG1510-1DJ01-7AB0): All versions prior to v2.9.7SIPLUS ET 200SP CPU 1510SP-1 PN RAIL (6AG2510-1DJ01-4AB0): All versions prior to v2.9.7SIPLUS ET 200SP CPU 1510SP-1 PN RAIL (6AG2510-1DJ01-1AB0): All versions prior to v2.9.7SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK01-2AB0): All versions prior to v2.9.7SIPLUS ET 200SP CPU 1512SP F-1 PN (6AG1512-1SK01-7AB0): All versions prior to v2.9.7SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL (6AG2512-1SK01-1AB0): All versions prior to v2.9.7SIPLUS ET 200SP CPU 1512SP F-1 PN RAIL (6AG2512-1SK01-4AB0): All versions prior to v2.9.7SIPLUS ET 200SP CPU 1512SP-1 PN (6AG1512-1DK01-2AB0): All versions prior to v2.9.7SIPLUS ET 200SP CPU 1512SP-1 PN (6AG1512-1DK01-7AB0): All versions prior to v2.9.7SIPLUS ET 200SP CPU 1512SP-1 PN RAIL (6AG2512-1DK01-4AB0): All versions prior to v2.9.7SIPLUS ET 200SP CPU 1512SP-1 PN RAIL (6AG2512-1DK01-1AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK01-2AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK02-2AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK01-7AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1511-1 PN (6AG1511-1AK02-7AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL (6AG2511-1AK01-1AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1511-1 PN T1 RAIL (6AG2511-1AK02-1AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1511-1 PN TX RAIL (6AG2511-1AK01-4AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1511-1 PN TX RAIL (6AG2511-1AK02-4AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK01-2AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1511F-1 PN (6AG1511-1FK02-2AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL01-7AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL01-2AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL02-2AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1513-1 PN (6AG1513-1AL02-7AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL01-2AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1513F-1 PN (6AG1513-1FL02-2AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1515F-2 PN (6AG1515-2FM01-2AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1515F-2 PN (6AG1515-2FM02-2AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1515F-2 PN RAIL (6AG2515-2FM02-4AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1515F-2 PN T2 RAIL (6AG2515-2FM01-2AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1515R-2 PN (6AG1515-2RM00-7AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1515R-2 PN TX RAIL (6AG2515-2RM00-4AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN01-7AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN01-2AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN02-2AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1516-3 PN/DP (6AG1516-3AN02-7AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1516-3 PN/DP RAIL (6AG2516-3AN02-4AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1516-3 PN/DP TX RAIL (6AG2516-3AN01-4AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN02-2AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1516F-3 PN/DP (6AG1516-3FN01-2AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL (6AG2516-3FN02-2AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1516F-3 PN/DP RAIL (6AG2516-3FN02-4AB0): All versions prior to v2.9.7SIPLUS S7-1500 CPU 1517H-3 PN (6AG1517-3HP00-4AB0): All versions prior to v3.0.3SIPLUS S7-1500 CPU 1518-4 PN/DP (6AG1518-4AP00-4AB0): All versions prior to v3.0.3SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0): All versions prior to v3.0.3SIPLUS S7-1500 CPU 1518F-4 PN/DP (6AG1518-4FP00-4AB0): All versions prior to v3.0.3SIPLUS S7-1500 CPU 1518HF-4 PN (6AG1518-4JP00-4AB0): All versions prior to v3.0.3.,CVE-2023-28831,7.5,High,CWE-190,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2598,9/14/2023,9/14/2023,2023,ICSA-23-257-02,Siemens Parasolid,Siemens,Parasolid,"The following versions of Siemens Parasolid, a 3D geometric modeling tool, are affected: Parasolid V34.1: all versions prior to V34.1.258 Parasolid V35.0: all versions prior to V35.0.253 Parasolid V35.0: all versions prior to V35.0.260 Parasolid V35.1: all versions prior to V35.1.184 Parasolid V35.1: all versions prior to V35.1.246 Parasolid V36.0: all versions prior to V36.0.142 Parasolid V36.0: all versions prior to V36.0.156.","CVE-2023-41032, CVE-2023-41033",7.8,High,CWE-787,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2597,9/14/2023,9/14/2023,2023,ICSA-23-257-03,Siemens QMS Automotive,Siemens,QMS Automotive,"The following products of Siemens, are affected: QMS Automotive: All versions prior to v12.39.","CVE-2022-43958, CVE-2023-40724, CVE-2023-40725, CVE-2023-40726, CVE-2023-40727, CVE-2023-40728, CVE-2023-40729, CVE-2023-40730, CVE-2023-40731, CVE-2023-40732",8.8,High,"CWE-256, CWE-316, CWE-209, CWE-550, CWE-347, CWE-922, CWE-319, CWE-284, CWE-434, CWE-613",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2596,9/14/2023,9/14/2023,2023,ICSA-23-257-04,Siemens RUGGEDCOM APE1808 Product,Siemens,RUGGEDCOM APE1808 Product Family,Siemens reports that the following products contain affected versions of Insyde BIOS:RUGGEDCOM APE1808 ADM (6GK6015-0AL20-0GL0): BIOS versions prior to V1.0.212NRUGGEDCOM APE1808 ADM CC (6GK6015-0AL20-0GL1): BIOS versions prior to V1.0.212NRUGGEDCOM APE1808 CKP (6GK6015-0AL20-0GK0): BIOS versions prior to V1.0.212NRUGGEDCOM APE1808 CKP CC (6GK6015-0AL20-0GK1): BIOS versions prior to V1.0.212NRUGGEDCOM APE1808 CLOUDCONNECT (6GK6015-0AL20-0GM0): BIOS versions prior to V1.0.212NRUGGEDCOM APE1808 CLOUDCONNECT CC (6GK6015-0AL20-0GM1): BIOS versions < V1.0.212NRUGGEDCOM APE1808 ELAN (6GK6015-0AL20-0GP0): BIOS versions prior to V1.0.212NRUGGEDCOM APE1808 ELAN CC (6GK6015-0AL20-0GP1): BIOS versions prior to V1.0.212NRUGGEDCOM APE1808 SAM-L (6GK6015-0AL20-0GN0): BIOS versions prior to V1.0.212NRUGGEDCOM APE1808 SAM-L CC (6GK6015-0AL20-0GN1): BIOS versions prior to V1.0.212NRUGGEDCOM APE1808CLA-P (6GK6015-0AL20-1AA0): BIOS versions prior to V1.0.212NRUGGEDCOM APE1808CLA-P CC (6GK6015-0AL20-1AA1): BIOS versions prior to V1.0.212NRUGGEDCOM APE1808CLA-S1 (6GK6015-0AL20-1AB0): BIOS versions prior to V1.0.212NRUGGEDCOM APE1808CLA-S1 CC (6GK6015-0AL20-1AB1): BIOS versions prior to V1.0.212NRUGGEDCOM APE1808CLA-S3 (6GK6015-0AL20-1AD0): BIOS versions prior to V1.0.212NRUGGEDCOM APE1808CLA-S3 CC (6GK6015-0AL20-1AD1): BIOS versions prior to V1.0.212NRUGGEDCOM APE1808CLA-S5 (6GK6015-0AL20-1AF0): BIOS versions prior to V1.0.212NRUGGEDCOM APE1808CLA-S5 CC (6GK6015-0AL20-1AF1): BIOS versions prior to V1.0.212NRUGGEDCOM APE1808LNX (6GK6015-0AL20-0GH0): BIOS versions prior to V1.0.212NRUGGEDCOM APE1808LNX CC (6GK6015-0AL20-0GH1): BIOS versions prior to V1.0.212NRUGGEDCOM APE1808W10 (6GK6015-0AL20-0GJ0): BIOS versions prior to V1.0.212NRUGGEDCOM APE1808W10 CC (6GK6015-0AL20-0GJ1): BIOS versions prior to V1.0.212N.,"CVE-2017-5715, CVE-2021-38578, CVE-2022-24350, CVE-2022-24351, CVE-2022-27405, CVE-2022-29275, CVE-2022-30283, CVE-2022-30772, CVE-2022-32469, CVE-2022-32470, CVE-2022-32471, CVE-2022-32475, CVE-2022-32477, CVE-2022-32953, CVE-2022-32954, CVE-2022-35893, CVE-2022-35894, CVE-2022-35895, CVE-2022-35896, CVE-2022-36338, CVE-2023-24932, CVE-2023-27373, CVE-2023-31041",8.2,High,"CWE-200, CWE-124, CWE-120, CWE-367, CWE-125, CWE-119, CWE-787, CWE-20, CWE-401, CWE-358, CWE-256",Critical Manufacturing; Energy; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2595,9/14/2023,9/14/2023,2023,ICSA-23-257-05,Siemens SIMATIC IPCs,Siemens,SIMATIC Field PG and SIMATIC IPC,"The following products of Siemens, are affected: SIMATIC Field PG M6: All Versions SIMATIC IPC BX-39A: All Versions SIMATIC IPC PX-39A: All Versions SIMATIC IPC PX-39A PRO: All Versions SIMATIC IPC RW-543A: All Versions SIMATIC IPC627E: All Versions SIMATIC IPC647E: All Versions SIMATIC IPC677E: All Versions SIMATIC IPC847E: All Versions.",CVE-2022-40982,6.5,Medium,CWE-200,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2594,9/14/2023,9/14/2023,2023,ICSA-23-257-06,Siemens WIBU Systems CodeMeter,Siemens,WIBU Systems CodeMeter,"The following products of Siemens, are affected: PSS(R)CAPE V14: All versions prior to V14.2023-08-23 PSS(R)CAPE V15: All versions prior to V15.0.22 PSS(R)E V34: All versions prior to V34.9.6 PSS(R)E V35: All versions PSS(R)ODMS V13.0: All versions PSS(R)ODMS V13.1: All versions prior to V13.1.12.1 SIMATIC PCS neo V3: All versions SIMATIC PCS neo V4: All versions SIMATIC WinCC OA V3.17: All versions SIMATIC WinCC OA V3.18: All versions SIMATIC WinCC OA V3.19: All versions prior to V3.19 P006 SIMIT Simulation Platform: All versions SINEC INS: All versions SINEMA Remote Connect: All versions.",CVE-2023-3935,9.0,Critical,CWE-122,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2593,9/14/2023,9/14/2023,2023,ICSA-23-257-07,Rockwell Automation Pavilion8,Rockwell Automation,Pavilion8,"The following versions of Rockwell Automation Pavilion8, a model predictive control software, are affected: Pavilion8: versions v5.17.00 and v5.17.01.",CVE-2023-29463,8.8,High,CWE-287,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2592,9/12/2023,9/12/2023,2023,ICSA-23-255-01,Hitachi Energy Lumada APM Edge,Hitachi Energy,Lumada Asset Performance Management (APM) Edge,The following Hitachi products are affected: Lumada APM Edge: Versions 4.0 and prior Lumada APM Edge: Version 6.3.,"CVE-2023-0215, CVE-2022-4450, CVE-2023-0286, CVE-2022-4304",7.5,High,"CWE-416, CWE-415, CWE-843, CWE-203",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2591,9/12/2023,9/12/2023,2023,ICSA-23-255-02,Fujitsu Software Infrastructure Manager,Fujitsu Software,Infrastructure Manager,The following versions of Infrastructure Manager are affected: Infrastructure Manager: Advanced Edition V2.8.0.060 Infrastructure Manager: Advanced Edition for PRIMEFLEX V2.8.0.060 Infrastructure Manager: Essential Edition V2.8.0.060.,CVE-2023-39903,5.9,Medium,CWE-312,Multiple Critical Sectors,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2590,9/7/2023,9/7/2023,2023,ICSA-23-250-01,Dover Fueling Solutions MAGLINK LX Console,Dover Fueling Solutions (DFS),MAGLINK LX - Web Console Configuration,The following versions of MAGLINK LX Web Console Configuration are affected: MAGLINK LX Web Console Configuration: version 2.5.1 MAGLINK LX Web Console Configuration: version 2.5.2 MAGLINK LX Web Console Configuration: version 2.5.3 MAGLINK LX Web Console Configuration: version 2.6.1 MAGLINK LX Web Console Configuration: version 2.11 MAGLINK LX Web Console Configuration: version 3.0 MAGLINK LX Web Console Configuration: version 3.2 MAGLINK LX Web Console Configuration: version 3.3.,"CVE-2023-41256, CVE-2023-36497, CVE-2023-38256",9.1,Critical,"CWE-288, CWE-284, CWE-22",Multiple Critical Sectors,"Europe, United Kingdom, Worldwide",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2589,9/7/2023,9/7/2023,2023,ICSA-23-250-02,Phoenix Contact TC ROUTER and TC CLOUD CLIENT,PHOENIX CONTACT,TC ROUTER and TC CLOUD CLIENT,Phoenix contact reports that the following products are affected: TC ROUTER 3002T-4G: versions prior to 2.07.2 TC ROUTER 3002T-4G ATT: versions prior to 2.07.2 TC ROUTER 3002T-4G VZW: versions prior to 2.07.2 TC CLOUD CLIENT 1002-4G: versions prior to 2.07.2 TC CLOUD CLIENT 1002-4G ATT: versions prior to 2.07.2 TC CLOUD CLIENT 1002-4G VZW: versions prior to 2.07.2 CLOUD CLIENT 1101T-TX/TX: versions prior to 2.06.10.,"CVE-2023-3526, CVE-2023-3569",9.6,Critical,"CWE-79, CWE-776",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2588,9/7/2023,9/7/2023,2023,ICSA-23-250-03,Socomec MOD3GP-SY-120K,Socomec,MOD3GP-SY-120K,The following Socomec products are affected: MODULYS GP (MOD3GP-SY-120K): Web firmware v01.12.10.,"CVE-2023-38582, CVE-2023-39446, CVE-2023-41965, CVE-2023-41084, CVE-2023-40221, CVE-2023-39452, CVE-2023-38255",10.0,Critical,"CWE-79, CWE-352, CWE-922, CWE-565, CWE-94, CWE-256",Multiple Critical Sectors,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2587,9/5/2023,9/5/2023,2023,ICSA-23-248-01,Fujitsu Limited Real-time Video Transmission Gear IP series,Fujitsu Limited,"Real-time Video Transmission Gear ""IP series""","The following versions of Real-time Video Transmission Gear ""IP series"", a hosted web application, are affected: Real-time Video Transmission Gear ""IP series"" IP-HE950E: firmware versions V01L001 to V01L053 Real-time Video Transmission Gear ""IP series"" IP-HE950D: firmware versions V01L001 to V01L053 Real-time Video Transmission Gear ""IP series"" IP-HE900E: firmware versions V01L001 to V01L010 Real-time Video Transmission Gear ""IP series"" IP-HE900D: firmware versions V01L001 to V01L004 Real-time Video Transmission Gear ""IP series"" IP-900E / IP-920E: firmware versions V01L001 to V02L061 Real-time Video Transmission Gear ""IP series"" IP-900D / IP-900â…¡D / IP-920D: firmware versions V01L001 to V02L061 Real-time Video Transmission Gear ""IP series"" IP-90: firmware versions V01L001 to V01L013 Real-time Video Transmission Gear ""IP series"" IP-9610: firmware versions V01L001 to V02L007.",CVE-2023-38433,5.9,Medium,CWE-798,Commercial Facilities; Government Facilities,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2586,9/5/2023,9/5/2023,2023,ICSMA-23-248-01,Softneta MedDream PACS Premium,Softneta,MedDream PACS,The following Softneta products are affected: MedDream PACS: v7.2.8.810 and prior.,"CVE-2023-40150, CVE-2023-39227",9.8,Critical,"CWE-749, CWE-256",Healthcare and Public Health,Worldwide,Lithuania,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2585,8/31/2023,8/31/2023,2023,ICSA-23-243-04,Digi RealPort Protocol,"Digi International, Inc.",Digi RealPort Protocol,Digi International reports that the following products using Digi RealPort Protocol are affected: Digi RealPort for Windows: version 4.8.488.0 and earlier Digi RealPort for Linux: version 1.9-40 and earlier Digi ConnectPort TS 8/16: versions prior to 2.26.2.4 Digi Passport Console Server: all versions Digi ConnectPort LTS 8/16/32: versions prior to 1.4.9 Digi CM Console Server: all versions Digi PortServer TS: all versions Digi PortServer TS MEI: all versions Digi PortServer TS MEI Hardened: all versions Digi PortServer TS M MEI: all versions Digi PortServer TS P MEI: all versions Digi One IAP Family: all versions Digi One IA: all versions Digi One SP IA: all versions Digi One SP: all versions Digi WR31: all versions Digi WR11 XT: all versions Digi WR44 R: all versions Digi WR21: all versions Digi Connect ES: versions prior to 2.26.2.4 Digi Connect SP: all versions Digi International reports that the following products do NOT use Digi RealPort Protocol are NOT affected: Digi 6350-SR: all versions Digi ConnectCore 8X products: all versions,CVE-2023-4299,9.0,Critical,CWE-836,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2584,8/31/2023,10/12/2023,2023,ICSA-23-243-03,PTC Kepware KepServerEX (Update A),PTC,Kepware KepServerEX,"The following versions of Kepware KepServerEX, an industrial automation control platform, are affected: Kepware KepServerEX: version 6.14.263.0 and prior ThingWorx Kepware Server: version 6.14.263.0 and prior ThingWorx Industrial Connectivity: version 8.0 to 8.5","CVE-2023-29444, CVE-2023-29445, CVE-2023-29446, CVE-2023-29447",6.3,Medium,"CWE-427, CWE-20, CWE-522",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2583,8/31/2023,8/31/2023,2023,ICSA-23-243-02,GE Digital CIMPLICITY,GE Digital,CIMPLICITY,The following GE products are affected: GE Digital CIMPLICITY: v2023,CVE-2023-4487,7.8,High,CWE-114,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2582,8/31/2023,8/31/2023,2023,ICSA-23-243-01,ARDEREG Sistemas SCADA,ARDEREG,Sistemas SCADA,The following ARDEREG products are affected: Sistemas SCADA: Versions 2.203 and prior,CVE-2023-4485,9.8,Critical,CWE-89,Healthcare and Public Health,South America,Argentina,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2581,8/29/2023,8/29/2023,2023,ICSA-23-241-01,PTC CodeBeamer,PTC,Codebeamer,"The following versions of PTC Codebeamer, Application Lifecycle Management (ALM) platform for product and software development, are affected:Codebeamer: v22.10-SP6 or lowerCodebeamer: v22.04-SP2 or lowerCodebeamer: v21.09-SP13 or lower",CVE-2023-4296,8.8,High,CWE-79,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2580,8/24/2023,8/24/2023,2023,ICSA-23-236-01,KNX Protocol,KNX Association,KNX devices using KNX Connection Authorization,The following devices using KNX Protocol are affected: KNX devices using Connection Authorization Option 1 Style in which no BCU Key is currently set: All versions,CVE-2023-4346,7.5,High,CWE-645,Commercial Facilities,Europe,Belgium,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2579,8/24/2023,8/24/2023,2023,ICSA-23-236-02,Opto 22 SNAP PAC S1,Opto 22,SNAP PAC S1,"The following version of SNAP PAC S1, an industrial programmable automation controller, is affected:SNAP PAC S1 Firmware: Version R10.3b","CVE-2023-40706, CVE-2023-40707, CVE-2023-40708, CVE-2023-40709, CVE-2023-40710",7.5,High,"CWE-307, CWE-521, CWE-284, CWE-400",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2578,8/24/2023,8/24/2023,2023,ICSA-23-236-03,CODESYS Development System,CODESYS GmbH,CODESYS Development System,CODESYS reports this vulnerability affects the following versions of CODESYS Development System:CODESYS Development System: versions from 3.5.17.0 and prior to 3.5.19.20,CVE-2023-3662,7.3,High,CWE-427,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2577,8/24/2023,8/24/2023,2023,ICSA-23-236-04,CODESYS Development System,CODESYS GmbH,CODESYS Development System,CODESYS reports this vulnerability affects the following versions of CODESYS Development System: CODESYS Development System: versions prior to 3.5.19.20,CVE-2023-3669,3.3,Low,CWE-345,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2576,8/24/2023,8/24/2023,2023,ICSA-23-236-05,CODESYS Development System,CODESYS GmbH,CODESYS Development System,CODESYS reports this vulnerability affects the following versions of CODESYS Development System: CODESYS Development System: versions from 3.5.11.0 and prior to 3.5.19.20,CVE-2023-3663,9.6,Critical,CWE-345,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2575,8/24/2023,8/24/2023,2023,ICSA-23-236-06,Rockwell Automation Input/Output Modules,Rockwell Automation,"1734-AENT/1734-AENTR Series C, 1734-AENT/1734-AENTR Series B, 1738-AENT/ 1738-AENTR Series B, 1794-AENTR Series A, 1732E-16CFGM12QCWR Series A, 1732E-12X4M12QCDR Series A, 1732E-16CFGM12QCR Series A, 1732E-16CFGM12P5QCR Series A, 1732E-12X4M12P5QCDR Series A, 1732E-16CFGM12P5QCWR Series B, 1732E-IB16M12R Series B, 1732E-OB16M12R Series B, 1732E-16CFGM12R Series B, 1732E-IB16M12DR Series B, 1732E-OB16M12DR Series B, 1732E-8X8M12DR Series B, 1799ER-IQ10XOQ10 Series B",The following versions of select Input/Output Modules from Rockwell Automation are affected:1734-AENT/1734-AENTR Series C: Versions 7.011 and prior1734-AENT/1734-AENTR Series B: Versions 5.019 and prior1738-AENT/ 1738-AENTR Series B: Versions 6.011 and prior1794-AENTR Series A: Versions 2.011 and prior1732E-16CFGM12QCWR Series A: Versions 3.011 and prior1732E-12X4M12QCDR Series A: Versions 3.011 and prior1732E-16CFGM12QCR Series A: Versions 3.011 and prior1732E-16CFGM12P5QCR Series A: Versions 3.011 and prior1732E-12X4M12P5QCDR Series A: Versions 3.011 and prior1732E-16CFGM12P5QCWR Series B: Versions 3.011 and prior1732E-IB16M12R Series B: Versions 3.011 and prior1732E-OB16M12R Series B: Versions 3.011 and prior1732E-16CFGM12R Series B: Versions 3.011 and prior1732E-IB16M12DR Series B: Versions 3.011 and prior1732E-OB16M12DR Series B: Versions 3.011 and prior1732E-8X8M12DR Series B: Versions 3.011 and prior1799ER-IQ10XOQ10 Series B: Versions 3.011 and prior,CVE-2022-1737,8.6,High,CWE-787,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2574,8/22/2023,8/22/2023,2023,ICSA-23-234-01,Hitachi Energy AFF66x,Hitachi Energy,AFF66x,Hitachi Energy reports these vulnerabilities affect the following AFF660/665 products:AFF660/665: Firmware 03.0.02 and prior,"CVE-2021-43523, CVE-2020-13817, CVE-2020-11868, CVE-2019-11477, CVE-2022-3204, CVE-2018-18066",9.6,Critical,"CWE-79, CWE-330, CWE-346, CWE-190, CWE-400, CWE-476",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2573,8/22/2023,8/22/2023,2023,ICSA-23-234-02,Trane Thermostats,Trane,"XL824, XL850, XL1050, and Pivot thermostats",Trane reports this vulnerability affects the following thermostats:Trane Technologies XL824 Thermostat: Firmware versions 5.9.8 and earlierTrane Technologies XL850 Thermostat: Firmware versions 5.9.8 and earlierTrane Technologies XL1050 Thermostat: Firmware versions 5.9.8 and earlierTrane Technologies Pivot Thermostat: Firmware versions 1.8 and earlier,CVE-2023-4212,6.8,Medium,CWE-74,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2572,8/22/2023,8/22/2023,2023,ICSA-23-234-03,Rockwell Automation ThinManager ThinServer,Rockwell Automation,ThinManager ThinServer,"Rockwell Automation reports this vulnerability affects the following versions of ThinManager ThinServer, a thin client and remote desktop protocol (RDP) server management software: ThinManager ThinServer: Versions 11.0.0-11.0.6 ThinManager ThinServer: Versions 11.1.0-11.1.6 ThinManager ThinServer: Versions 11.2.0-11.2.6 ThinManager ThinServer: Versions 12.1.0-12.1.6 ThinManager ThinServer: Versions 12.0.0-12.0.5 ThinManager ThinServer: Versions 13.0.0-13.0.2 ThinManager ThinServer: Version 13.1.0","CVE-2023-2914, CVE-2023-2915, CVE-2023-2917",9.8,Critical,CWE-20,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2571,8/17/2023,8/17/2023,2023,ICSA-23-229-01,ICONICS and Mitsubishi Electric Products,ICONICS,ICONICS Product Suite,"ICONICS reports these vulnerabilities affect the following products using OpenSSL:ICONICS Suite including GENESIS64, Hyper Historian, AnalytiX, and MobileHMI: Version 10.97.2","CVE-2022-3602, CVE-2022-3786, CVE-2022-4203, CVE-2022-4304, CVE-2022-4450, CVE-2023-0401",5.9,Medium,"CWE-120, CWE-125, CWE-208, CWE-415, CWE-476",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2570,8/17/2023,8/17/2023,2023,ICSA-23-229-01,ICONICS and Mitsubishi Electric Products,Mitsubishi Electric,ICONICS Product Suite,"ICONICS reports these vulnerabilities affect the following products using OpenSSL:ICONICS Suite including GENESIS64, Hyper Historian, AnalytiX, and MobileHMI: Version 10.97.2","CVE-2022-3602, CVE-2022-3786, CVE-2022-4203, CVE-2022-4304, CVE-2022-4450, CVE-2023-0401",5.9,Medium,"CWE-120, CWE-125, CWE-208, CWE-415, CWE-476",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2569,8/17/2023,8/17/2023,2023,ICSA-23-229-03,Schnieder Electric PowerLogic ION7400 PM8000 ION9000 Power Meters,Schneider Electric,PowerLogic ION7400 / PM8000 / ION8650 / ION8800 / ION9000,"The following components of Schneider Electric PowerLogic, a power meter, are affected: PowerLogic ION9000: All versions prior to 4.0.0 PowerLogic ION7400: All versions prior to 4.0.0 PowerLogic PM8000: All versions prior to 4.0.0 PowerLogic ION8650: All versions PowerLogic ION8800: All versions Legacy ION products: All versions",CVE-2022-46680,8.8,High,CWE-319,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2568,8/17/2023,8/17/2023,2023,ICSA-23-229-04,Walchem Intuition 9,Walchem,Intuition 9,"The following versions of Intuition 9, a water treatment controller, are affected: Intuition 9: versions prior to v4.21","CVE-2023-38422, CVE-2023-32202",7.5,High,"CWE-306, CWE-287",Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2567,8/15/2023,5/5/2026,2023,ICSA-23-227-01,"Schneider Electric EcoStruxure Control Expert and Modicon M340, Momentum, MC80, M580 and M580 CPU Safety (Update A)",Schneider Electric,"Schneider Electric EcoStruxure Control Expert and Modicon M340, Momentum, MC80, M580 and M580 CPU Safety (Update A)","Schneider Electric EcoStruxure Control Expert: = V7.80 < V9.30 SIPROTEC 5 6MD86 (CP300) - >= V7.80 < V9.30 SIPROTEC 5 6MD89 (CP300) - >= V7.80 SIPROTEC 5 6MU85 (CP300) - >= V7.90 < V9.30 SIPROTEC 5 7KE85 (CP300) - >= V7.80 < V9.30 SIPROTEC 5 7SA86 (CP300) - >= V7.80 < V9.30 SIPROTEC 5 7SA87 (CP300) - >= V7.80 < V9.30 SIPROTEC 5 7SD86 (CP300) - >= V7.80 < V9.30 SIPROTEC 5 7SD87 (CP300) - >= V7.80 < V9.30 SIPROTEC 5 7SJ85 (CP300) - >= V7.80 < V9.30 SIPROTEC 5 7SJ86 (CP300) - >= V7.80 < V9.30 SIPROTEC 5 7SK85 (CP300) - >= V7.80 < V9.30 SIPROTEC 5 7SL86 (CP300) - >= V7.80 < V9.30 SIPROTEC 5 7SL87 (CP300) - >= V7.80 < V9.30 SIPROTEC 5 7SS85 (CP300) - >= V7.80 < V9.30 SIPROTEC 5 7ST85 (CP300) - >= V8.81 < V9.30 SIPROTEC 5 7ST86 (CP300) - >= V9.20 < V9.30 SIPROTEC 5 7SX85 (CP300) - >= V8.30 < V9.30 SIPROTEC 5 7UM85 (CP300) - >= V7.80 < V9.30 SIPROTEC 5 7UT85 (CP300) - >= V7.80 < V9.30 SIPROTEC 5 7UT86 (CP300) - >= V7.80 < V9.30 SIPROTEC 5 7UT87 (CP300) - >= V7.80 < V9.30 SIPROTEC 5 7VE85 (CP300) - >= V7.80 < V9.30 SIPROTEC 5 7VK87 (CP300) - >= V7.80 < V9.30 SIPROTEC 5 Communication Module ETH-BA-2EL - >= V7.80 < V9.30 SIPROTEC 5 Communication Module ETH-BB-2FO - >= V7.80 < V9.30 SIPROTEC 5 Communication Module ETH-BD-2FO - >= V7.80 < V9.30 SIPROTEC 5 Compact 7SX800 (CP050) - >= V8.70 < V9.30.,CVE-2022-38767,7.5,High,CWE-835,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2414,3/21/2023,3/21/2023,2023,ICSA-23-080-05,VISAM VBASE Automation Base,VISAM,VBASE,VISAM reports these vulnerabilities affect the following VBASE products: VBASE Automation Base: versions prior to 11.7.5.,"CVE-2022-41696, CVE-2022-43512, CVE-2022-45121, CVE-2022-45468, CVE-2022-45876, CVE-2022-46286, CVE-2022-46300",5.5,Medium,CWE-611,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2413,3/21/2023,3/21/2023,2023,ICSA-23-080-06,Rockwell Automation ThinManager,Rockwell Automation,ThinManager ThinServer,"The following versions of Rockwell Automation ThinManager ThinServer, a thin client and remote desktop protocol (RDP) server management software, are affected: ThinManager ThinServer: Versions 6.x - 10.x ThinManager ThinServer: Versions 11.0.0 - 11.0.5 ThinManager ThinServer: Versions 11.1.0 - 11.1.5 ThinManager ThinServer: Versions 11.2.0 - 11.2.6 ThinManager ThinServer: Versions 12.0.0 - 12.0.4 ThinManager ThinServer: Versions 12.1.0 - 12.1.5 ThinManager ThinServer: Versions 13.0.0 - 13.0.1.","CVE-2023-27855, CVE-2023-27856, CVE-2023-27857",9.8,Critical,"CWE-22, CWE-122",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2412,3/21/2023,3/21/2023,2023,ICSA-23-080-07,Siemens SCALANCE Third-Party,Siemens,Various third-party components used in SCALANCE W-700 devices,The following software from Siemens is affected: SCALANCE WAM763-1 (6GK5763-1AL00-7DA0): All versions prior to v2.0 SCALANCE WAM766-1 (EU) (6GK5766-1GE00-7DA0): All versions prior to v2.0 SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0): All versions prior to v2.0 SCALANCE WAM766-1 EEC (EU) (6GK5766-1GE00-7TA0): All versions prior to v2.0 SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0): All versions prior to v2.0 SCALANCE WUM763-1 (6GK5763-1AL00-3DA0): All versions prior to v2.0 SCALANCE WUM763-1 (6GK5763-1AL00-3AA0): All versions prior to v2.0 SCALANCE WUM766-1 (EU) (6GK5766-1GE00-3DA0): All versions prior to v2.0 SCALANCE WUM766-1 (US) (6GK5766-1GE00-3DB0): All versions prior to v2.0.,"CVE-2018-12886, CVE-2018-25032, CVE-2021-42373, CVE-2021-42374, CVE-2021-42375, CVE-2021-42376, CVE-2021-42377, CVE-2021-42378, CVE-2021-42379, CVE-2021-42380, CVE-2021-42381, CVE-2021-42382, CVE-2021-42383, CVE-2021-42384, CVE-2021-42385, CVE-2021-42386, CVE-2022-23395, CVE-2021-42385, CVE-2021-42386, CVE-2022-0001, CVE-2022-0002, CVE-2022-0494, CVE-2022-0547, CVE-2022-1011, CVE-2022-1016, CVE-2022-1198, CVE-2022-1199, CVE-2022-1292, CVE-2022-1304, CVE-2022-1343, CVE-2022-1353, CVE-2022-1473, CVE-2022-1516, CVE-2022-1652, CVE-2022-1729, CVE-2022-1734, CVE-2022-1974, CVE-2022-1975, CVE-2022-2380, CVE-2022-2588, CVE-2022-2639, CVE-2022-20158, CVE-2022-23036, CVE-2022-23037, CVE-2022-23038, CVE-2022-23039, CVE-2022-23040, CVE-2022-23041, CVE-2022-23042, CVE-2022-23308, CVE-2022-26490, CVE-2022-28356, CVE-2022-28390, CVE-2022-30065, CVE-2022-30594, CVE-2022-32205, CVE-2022-32206, CVE-2022-32207, CVE-2022-32208, CVE-2022-32296, CVE-2022-32981, CVE-2022-33981, CVE-2022-35252, CVE-2022-36879, CVE-2022-36946",8.1,High,"CWE-209, CWE-787, CWE-476, CWE-125, CWE-20, CWE-763, CWE-416, CWE-1321, CWE-200, CWE-287, CWE-78, CWE-295, CWE-404, CWE-362, CWE-248, CWE-191, CWE-120, CWE-415, CWE-863, CWE-770, CWE-276, CWE-203, CWE-1286",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2411,3/16/2023,3/16/2023,2023,ICSA-23-075-01,"Siemens SCALANCE, RUGGEDCOM Third-Party",Siemens,Busybox Applet affecting SCALANCE and RUGGEDCOM products,The following software from Siemens is affected: RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2): All versions prior to v7.2 RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2): All versions prior to v7.2 SCALANCE M804PB (6GK5804-0AP00-2AA2): All versions prior to v7.2 SCALANCE M812-1 ADSL-Router (Annex A) (6GK5812-1AA00-2AA2): All versions prior to v7.2 SCALANCE M812-1 ADSL-Router (Annex B) (6GK5812-1BA00-2AA2): All versions prior to v7.2 SCALANCE M816-1 ADSL-Router (Annex A) (6GK5816-1AA00-2AA2): All versions prior to v7.2 SCALANCE M816-1 ADSL-Router (Annex B) (6GK5816-1BA00-2AA2): All versions prior to v7.2 SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2): All versions prior to v7.2 SCALANCE M874-2 (6GK5874-2AA00-2AA2): All versions prior to v7.2 SCALANCE M874-3 (6GK5874-3AA00-2AA2): All versions prior to v7.2 SCALANCE M876-3 (EVDO) (6GK5876-3AA02-2BA2): All versions prior to v7.2 SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2): All versions prior to v7.2 SCALANCE M876-4 (6GK5876-4AA10-2BA2): All versions prior to v7.2 SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2): All versions prior to v7.2 SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2): All versions prior to v7.2 SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1): All versions prior to v7.2 SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1): All versions prior to v7.2 SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1): All versions prior to v7.2 SCALANCE S615 (6GK5615-0AA00-2AA2): All versions prior to v7.2 SCALANCE S615 EEC (6GK5615-0AA01-2AA2): All versions prior to v7.2.,"CVE-2018-25032, CVE-2019-1125, CVE-2021-4034, CVE-2021-4149, CVE-2021-26401, CVE-2021-42373, CVE-2021-42374, CVE-2021-42375, CVE-2021-42376, CVE-2021-42377, CVE-2021-42378, CVE-2021-42379, CVE-2021-42380, CVE-2021-42381, CVE-2021-42382, CVE-2021-42383, CVE-2021-42384, CVE-2021-42385, CVE-2021-4238, CVE-2022-0001, CVE-2022-0002, CVE-2022-0494, CVE-2022-0547, CVE-2022-1011, CVE-2022-1016, CVE-2022-1198, CVE-2022-1199, CVE-2022-1292, CVE-2022-1304, CVE-2022-1343, CVE-2022-1353, CVE-2022-1473, CVE-2022-1516, CVE-2022-1652, CVE-2022-1729, CVE-2022-1734, CVE-2022-1974, CVE-2022-1975, CVE-2022-2380, CVE-2022-2588, CVE-2022-2639, CVE-2022-20158, CVE-2022-23036, CVE-2022-23037, CVE-2022-23038, CVE-2022-23039, CVE-2022-23040, CVE-2022-23041, CVE-2022-23042, CVE-2022-23308, CVE-2022-26490, CVE-2022-28356, CVE-2022-28390, CVE-2022-30065, CVE-2022-30594, CVE-2022-32205, CVE-2022-32206, CVE-2022-32207, CVE-2022-32208, CVE-2022-32296, CVE-2022-32981, CVE-2022-33981, CVE-2022-35252, CVE-2022-36879, CVE-2022-36946",9.8,Critical,"CWE-787, CWE-200, CWE-667, CWE-20, CWE-476, CWE-125, CWE-763, CWE-416, CWE-287, CWE-78, CWE-295, CWE-404, CWE-362, CWE-248, CWE-191, CWE-120, CWE-415, CWE-863, CWE-770, CWE-276, CWE-203, CWE-1286",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2410,3/16/2023,3/16/2023,2023,ICSA-23-075-02,Siemens RUGGEDCOM CROSSBOW V5.3,Siemens,RUGGEDCOM CROSSBOW,The following software from Siemens is affected: Siemens RUGGEDCOM CROSSBOW: All versions prior to V5.3.,"CVE-2023-27462, CVE-2023-27463",8.8,High,"CWE-862, CWE-89",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2409,3/16/2023,3/16/2023,2023,ICSA-23-075-03,Siemens RUGGEDCOM CROSSBOW V5.2,Siemens,RUGGEDCOM CROSSBOW,The following software from Siemens is affected: Siemens RUGGEDCOM CROSSBOW: All versions prior to V5.2.,"CVE-2023-27309, CVE-2023-27310",6.6,Medium,CWE-862,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2408,3/16/2023,3/16/2023,2023,ICSA-23-075-04,Siemens SCALANCE W1750D Devices,Siemens,SCALANCE W1750D,The following software from Siemens is affected: SCALANCE W1750D (JP) (6GK5750-2HX01-1AD0): All versions SCALANCE W1750D (ROW) (6GK5750-2HX01-1AA0): All versions SCALANCE W1750D (USA) (6GK5750-2HX01-1AB0): All versions.,"CVE-2022-4304, CVE-2022-4450, CVE-2023-0215, CVE-2023-0286",7.4,High,"CWE-326, CWE-415, CWE-416, CWE-20",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2407,3/16/2023,3/16/2023,2023,ICSA-23-075-05,Siemens Mendix SAML Module,Siemens,Mendix SAML Module,"The following software from Siemens is affected: Mendix SAML (Mendix 7 compatible): Versions 1.16.4 to 1.17.2 Mendix SAML (Mendix 8 compatible): Versions 2.2.0 to 2.2.3 Mendix SAML (Mendix 9 compatible, New Track): Versions 3.1.9 to 3.2.5 Mendix SAML (Mendix 9 compatible, Upgrade Track): Version 3.1.9 to 3.2.5.",CVE-2023-25957,9.1,Critical,CWE-303,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2406,3/16/2023,3/16/2023,2023,ICSA-23-075-06,Honeywell OneWireless Wireless Device Manager,Honeywell,OneWireless Wireless Device Manager (WDM),Honeywell reports these vulnerabilities affect the following versions of OneWireless WDM: All versions up to R322.1.,"CVE-2022-46361, CVE-2022-43485, CVE-2022-4240",9.8,Critical,"CWE-77, CWE-330, CWE-306",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2405,3/16/2023,3/16/2023,2023,ICSA-23-075-07,Rockwell Automation Modbus TCP AOI Server,Rockwell Automation,Modbus TCP Server Add-On Instruction (AOI),"The following versions of Rockwell Automation Modbus TCP Server AOI, are affected: Modbus TCP Server AOI: Versions 2.00 and 2.03.",CVE-2023-0027,5.3,Medium,CWE-200,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2404,3/14/2023,3/14/2023,2023,ICSA-23-073-01,Omron CJ1m PLC,Omron,CJ1M PLC,"The following components of Omron CJ1M, a programmable logic controller, are affected: SYSMAC CJ-series CJ2H-CPU6 -EIP: All versions CJ2H-CPU6 : All versions CJ2M-CPU : All versions CJ1G-CPU P: All versions SYSMAC CS-series CS1H-CPU H: All versions CS1G-CPU H: All versions CS1D-CPU HA: All versions CS1D-CPU H: All versions CS1D-CPU SA: All versions CS1D-CPU S: All versions CS1D-CPU P: All versions SYSMAC CP-series CP2E-E D - : All versions CP2E-S D - All versions CP2E-N D - : All versions CP1H-X40D - : All versions CP1H-XA40D - : All versions CP1H-Y20DT-D: All versions CP1L-EL20D - : All versions CP1L-EM D - : All versions CP1L-L D - : All versions CP1L-M D - : All versions CP1E-E D - : All versions CP1E-NA D - : All versions.",CVE-2023-0811,9.1,Critical,CWE-284,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2403,3/14/2023,3/14/2023,2023,ICSA-23-073-02,Autodesk FBX SDK,Autodesk,FBX SDK,The following versions of the affected products are affected: Autodesk FBX SDK versions 2020 and prior Luxion KeyShot version 11.3 and prior.,"CVE-2022-41302, CVE-2022-41303, CVE-2022-41304",7.8,High,"CWE-125, CWE-416, CWE-787",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2402,3/14/2023,3/14/2023,2023,ICSA-23-073-03,GE iFIX,GE Digital,iFIX,"The following components of iFIX, a human machine interface (HMI) supervisory control and data acquisition (SCADA) software, are affected: GE Digital Proficy iFIX 2022 GE Digital Proficy iFIX v6.1 GE Digital Proficy iFIX v6.5.",CVE-2023-0598,7.8,High,CWE-94,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2401,3/14/2023,3/14/2023,2023,ICSA-23-073-04,AVEVA Plant SCADA and AVEVA Telemetry Server,AVEVA,AVEVA Plant SCADA and AVEVA Telemetry Server,"The following versions of AVEVA Plant SCADA and AVEVA Telemetry Server are affected: AVEVA Plant SCADA 2023, AVEVA Plant SCADA 2020R2 Update 10 and all prior versions. AVEVA Telemetry Server 2020 R2 SP1 and all prior versions.",CVE-2023-1256,9.8,Critical,CWE-285,Critical Manufacturing,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2400,3/9/2023,3/9/2023,2023,ICSA-23-068-01,Akuvox E11 Publication,Akuvox,E11,"The following versions of Akuvox E11, a doorbell camera phone, are affected: E11: All versions.","CVE-2023-0343, CVE-2023-0355, CVE-2023-0354, CVE-2023-0353, CVE-2023-0352, CVE-2023-0351, CVE-2023-0350, CVE-2023-0349, CVE-2023-0348, CVE-2023-0347, CVE-2023-0346, CVE-2023-0345, CVE-2023-0344",9.8,Critical,"CWE-329, CWE-321, CWE-306, CWE-257, CWE-640, CWE-94, CWE-646, CWE-862, CWE-284, CWE-200, CWE-287, CWE-798, CWE-912",Information Technology,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2399,3/9/2023,3/9/2023,2023,ICSA-23-068-02,B&R Systems Diagnostics Manager,B&R Industrial Automation GmbH,Systems Diagnostics Manager (SDM),"The following versions B&R System Diagnostics Manager, used to diagnose B&R controllers, are affected: System Diagnostics Manager: runtime versions 3.00 and later System Diagnostics Manager: runtime versions C4.93 and prior.",CVE-2022-4286,6.1,Medium,CWE-79,Chemical; Critical Manufacturing; Energy,Worldwide,Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2398,3/9/2023,3/9/2023,2023,ICSA-23-068-03,ABB Ability Symphony Plus,ABB,Ability Symphony Plus,ABB reports this vulnerability affects the following Ability Symphony Plus products: S+ Operations 3.3 SP2 (part of SPR1 2023.0) S+ Operations 3.3 SP1 and earlier 3.x versions S+ Operations 2.2 S+ Operations 2.1 SP2 and earlier 2.x versions.,CVE-2023-0228,8.8,High,CWE-287,Chemical; Critical Manufacturing; Dams; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2397,3/9/2023,3/9/2023,2023,ICSA-23-068-04,STEP Tools Third-Party,"Step Tools, Inc",STEPTools ifcmesh library,The following versions of STEPTools are affected: STEPTools v18SP1 ifcmesh library (v18.1).,CVE-2023-0973,2.2,Low,CWE-476,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2396,2/28/2023,2/3/2026,2023,ICSA-23-068-05,"Hitachi Energy Relion 670, 650 and SAM600-IO Series (Update B)",Hitachi Energy,"Hitachi Energy Relion 670, 650 and SAM600-IO Series","Relion 670 series version 2.2.0 all revisions, Relion 670 series version 2.2.1 revisions up to 2.2.1.8, Relion 670 series version 2.2.2 revisions up to 2.2.2.5, Relion 670 series version 2.2.3 revisions up to 2.2.3.6, Relion 670 series version 2.2.4 revisions up to 2.2.4.3, Relion 670 series version 2.2.5 revisions up to 2.2.5.5, Relion 650 series version 2.2.0 all revisions, Relion 650 series version 2.2.1 revisions up to 2.2.1.8, Relion 650 series version 2.2.4 revisions up to 2.2.4.3, Relion 650 series version 2.2.5 revisions up to 2.2.5.5, SAM600-IO series version 2.2.1 revisions up to 2.2.1.8",CVE-2022-3864,4.5,Medium,CWE-345,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2395,3/2/2023,6/22/2023,2023,ICSA-23-061-01,Mitsubishi Electric MELSEC iQ-F Series (Update A),Mitsubishi Electric,"MELSEC iQ-F, iQ-R, Q, and L series","--------- Begin Update A Part 2 of 4 --------- The following Mitsubishi Electric MELSEC products are affected: MELSEC iQ-F FX5U(C) CPU modules: All models, all versions MELSEC iQ-F FX5UJ CPU modules: All models, all versions MELSEC iQ-F FX5S CPU modules: All models, all versions MELSEC iQ-F FX5-ENET: All versions MELSEC iQ-F FX5-ENET/IP: All versions MELSEC iQ-R R00/01/02CPU: All versions MELSEC iQ-R R04/08/16/32/120(EN)CPU: All versions MELSEC iQ-R R08/16/32/120SFCPU: All versions MELSEC iQ-R R08/16/32/120PCPU: All versions MELSEC iQ-R R08/16/32/120PSFCPU: All versions MELSEC iQ-R RJ71EN71: All versions MELSEC iQ-R R12CCPU-V: All versions MELSEC-Q Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: All versions MELSEC-Q Q03/04/06/13/26UDVCPU: All versions MELSEC-Q Q04/06/13/26UDPVCPU: All versions MELSEC-Q QJ71E71-100: All versions MELSEC-L L02/06/26CPU(-P), L26CPU-(P)BT: All versions MELSEC-L LJ71E71-100: All versions --------- End Update A Part 2 of 4 ---------.",CVE-2023-0457,7.5,High,CWE-256,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2394,3/2/2023,3/2/2023,2023,ICSA-23-061-02,Baicells Nova,Baicells Technologies,"Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430",Baicells reports this vulnerability affects the following LTE TDD eNodeB devices with firmware versions through QRTB 2.12.7: Nova 436Q Nova 430E Nova 430I Neutrino 430.,CVE-2023-0776,9.8,Critical,CWE-77,Communications,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2393,3/2/2023,3/2/2023,2023,ICSA-23-061-03,Rittal CMC III Access systems,Rittal,CMC III,Rittal reports this vulnerability affects the following control cabinet locks: CMC III.,CVE-2022-40633,4.8,Medium,CWE-284,Commercial Facilities; Communications; Critical Manufacturing; Energy; Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2392,3/2/2023,3/2/2023,2023,ICSMA-23-061-01,Medtronic Micro Clinician and InterStim Apps,Medtronic,Micros Clinician (A51200) app and InterStim X Clinician (A51300) app,The following versions of Medtronic Clinician App are affected: Micro Clinician (A51200) InterStim X Clinician (A51300).,CVE-2023-25931,6.4,Medium,CWE-620,Healthcare and Public Health,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2391,2/28/2023,2/28/2023,2023,ICSA-23-059-01,Hitachi Energy Gateway Station,Hitachi Energy,Gateway Station (GWS),Hitachi Energy reports these vulnerabilities affect open-source software (OpenLDAP and OpenSSL) used by the following Gateway Station (GWS) versions: GWS 2.0.0.0 GWS 2.1.0.0 GWS 2.2.0.0 GWS 2.3.0.0 GWS 2.4.0.0 GWS 3.0.0.0 GWS 3.1.0.0 GWS 3.2.0.0 and earlier.,"CVE-2020-25692, CVE-2022-0778",7.5,High,"CWE-476, CWE-835",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2390,2/28/2023,2/28/2023,2023,ICSA-23-059-02,Hitachi Energy Gateway Station,Hitachi Energy,Gateway Station (GWS),Hitachi Energy reports these vulnerabilities affect the following Gateway Station (GWS) versions: GWS 3.0.0.0 GWS 3.1.0.0 GWS 3.2.0.0.,"CVE-2022-2277, CVE-2022-29922, CVE-2022-1778",7.5,High,"CWE-20, CWE-120",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2389,2/23/2023,2/23/2023,2023,ICSA-23-054-01,PTC ThingWorx Edge,PTC,ThingWorx Edge,The following components of PTC ThingWorx are affected: ThingWorx Edge C-SDK: v2.2.12.1052 or lower .NET-SDK: v5.8.4.971 or lower ThingWorx Edge MicroServer (EMS): v5.4.10.0 or lower Kepware KEPServerEX: v6.12 or lower ThingWorx Kepware Server (formerly ThingWorx Industrial Connectivity): v6.12 or lower ThingWorx Industrial Connectivity: All versions ThingWorx Kepware Edge: v1.5 or lower Rockwell Automation KEPServer Enterprise: v6.12 or lower GE Digital Industrial Gateway Server: v7.612 or lower.,"CVE-2023-0755, CVE-2023-0754",9.8,Critical,"CWE-129, CWE-190",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2388,2/21/2023,2/21/2023,2023,ICSA-23-052-01,Mitsubishi Electric MELSOFT iQ AppPortal,Mitsubishi Electric,MELSOFT iQ AppPortal,The following Mitsubishi Electric products and versions are affected: MELSOFT iQ AppPortal (SW1DND-IQAPL-M): v1.00A to 1.29F.,"CVE-2022-26377, CVE-2022-31813",9.8,Critical,"CWE-444, CWE-345",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2387,2/16/2023,2/16/2023,2023,ICSA-23-047-01,Siemens Solid Edge,Siemens,Solid Edge,Siemens reports these vulnerabilities affect Solid Edge products. See SSA-491245 for more information on which specific vulnerabilities affect each of the following: Solid Edge SE2022: All versions Solid Edge SE2022: All versions prior to V2210 Update12 Solid Edge SE2023: All versions prior to V2023 Update 2.,"CVE-2021-32936, CVE-2021-32938, CVE-2021-32948, CVE-2021-43336, CVE-2021-43391, CVE-2022-46345, CVE-2022-46346, CVE-2022-46347, CVE-2022-46348, CVE-2022-46349, CVE-2023-22295, CVE-2023-22321, CVE-2023-22354, CVE-2023-22669, CVE-2023-22670, CVE-2023-22846, CVE-2023-23579, CVE-2023-24549, CVE-2023-24550, CVE-2023-24551, CVE-2023-24552, CVE-2023-24553, CVE-2023-24554, CVE-2023-24555, CVE-2023-24556, CVE-2023-24557, CVE-2023-24558, CVE-2023-24559, CVE-2023-24560, CVE-2023-24561, CVE-2023-24562, CVE-2023-24563, CVE-2023-24564, CVE-2023-24565, CVE-2023-24566, CVE-2023-24581, CVE-2023-25140",7.8,High,"CWE-787, CWE-125, CWE-122, CWE-121",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2386,2/16/2023,2/16/2023,2023,ICSA-23-047-02,Siemens SCALANCE X-200 IRT,Siemens,SCALANCE X200 IRT Products,The following Siemens products are affected: SCALANCE X200-4P IRT (6GK5200-4AH00-2BA3): All versions prior to V5.5.0 SCALANCE X201-3P IRT (6GK5201-3BH00-2BA3): All versions prior to V5.5.0 SCALANCE X201-3P IRT PRO (6GK5201-3JR00-2BA6): All versions prior to V5.5.0 SCALANCE X202-2IRT (6GK5202-2BB00-2BA3): All versions prior to V5.5.0 SCALANCE X202-2P IRT (6GK5202-2BH00-2BA3): All versions prior to V5.5.0 SCALANCE X202-2P IRT PRO (6GK5202-2JR00-2BA6): All versions prior to V5.5.0 SCALANCE X204IRT (6GK5204-0BA00-2BA3): All versions prior to V5.5.0 SCALANCE X204IRT PRO (6GK5204-0JA00-2BA6): All versions prior to V5.5.0 SCALANCE XF201-3P IRT (6GK5201-3BH00-2BD2): All versions prior to V5.5.0 SCALANCE XF202-2P IRT (6GK5202-2BH00-2BD2): All versions prior to V5.5.0 SCALANCE XF204-2BA IRT (6GK5204-2AA00-2BD2): All versions prior to V5.5.0 SCALANCE XF204IRT (6GK5204-0BA00-2BF2): All versions prior to V5.5.0 SIPLUS NET SCALANCE X202-2P IRT (6AG1202-2BH00-2BA3): All versions prior to V5.5.0.,CVE-2007-5846,7.5,High,CWE-20,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2385,2/16/2023,2/16/2023,2023,ICSA-23-047-03,Siemens Brownfield Connectivity Client,Siemens,Brownfield Connectivity Client,Siemens reports these vulnerabilities affect the following Siemens Brownfield Connectivity Client products: Brownfield Connectivity Client: All versions prior to V2.15.,"CVE-2022-1292, CVE-2022-1343, CVE-2022-1434, CVE-2022-1473",9.8,Critical,"CWE-78, CWE-295, CWE-327, CWE-404",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2384,2/16/2023,2/16/2023,2023,ICSA-23-047-04,Siemens Brownfield Connectivity Gateway,Siemens,Brownfield Connectivity”Gateway,Siemens reports these vulnerabilities affect the following Brownfield Connectivity”Gateway products: Brownfield Connectivity”Gateway: all versions prior to V1.10 Brownfield Connectivity”Gateway: V1.10.1.,"CVE-2021-41771, CVE-2021-41772, CVE-2021-44716, CVE-2021-44717, CVE-2022-24675, CVE-2022-24921, CVE-2022-27536, CVE-2022-28327",7.5,High,"CWE-119, CWE-20, CWE-400, CWE-668, CWE-770, CWE-295",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2383,2/16/2023,2/16/2023,2023,ICSA-23-047-05,Siemens SiPass integrated AC5102/ACC-G2 and ACC-AP,Siemens,"SiPass integrated AC5100, AC5102, AC5200, ACC-AP, Granta-MK3","The following software from Siemens is affected: SiPass integrated AC5100 (ACC): All versions SiPass integrated AC5102 (ACC-G2): All versions prior to V2.85.44 SiPass integrated AC5200 (ACC-Lite, ACC-4, ACC-8, ACC-16, ACC-32): All versions SiPass integrated ACC-AP: All versions prior to V2.85.43 SiPass integrated Granta-MK3 (ACC-GRANTA): All versions.",CVE-2022-31808,7.8,High,CWE-20,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2382,2/16/2023,2/16/2023,2023,ICSA-23-047-06,Siemens Simcenter Femap,Siemens,Simcenter Femap,The following software from Siemens is affected: Simcenter Femap: All versions prior to V2023.1.,"CVE-2022-39157, CVE-2022-43397",7.8,High,"CWE-125, CWE-787",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2381,2/16/2023,2/16/2023,2023,ICSA-23-047-07,Siemens TIA Project Server,Siemens,TIA Project-Server,The following software from Siemens is affected: TIA Multiuser Server V14: All versions TIA Multiuser Server V15: All versions prior to V15.1 Update 8 TIA Project-Server: All versions prior to V1.1 TIA Project-Server V16: All versions TIA Project-Server V17: All versions.,CVE-2022-35868,6.7,Medium,CWE-426,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2380,2/16/2023,2/16/2023,2023,ICSA-23-047-08,Siemens RUGGEDCOM APE1808,Siemens,RUGGEDCOM APE1808 Product Family,The following software from Siemens is affected: RUGGEDCOM APE1808 ADM (6GK6015-0AL20-0GL0): All versions RUGGEDCOM APE1808 ADM CC (6GK6015-0AL20-0GL1): All versions RUGGEDCOM APE1808 CKP (6GK6015-0AL20-0GK0): All versions RUGGEDCOM APE1808 CKP CC (6GK6015-0AL20-0GK1): All versions RUGGEDCOM APE1808 CLOUDCONNECT (6GK6015-0AL20-0GM0): All versions RUGGEDCOM APE1808 CLOUDCONNECT CC (6GK6015-0AL20-0GM1): All versions RUGGEDCOM APE1808 ELAN (6GK6015-0AL20-0GP0): All versions RUGGEDCOM APE1808 ELAN CC (6GK6015-0AL20-0GP1): All versions RUGGEDCOM APE1808 SAM-L (6GK6015-0AL20-0GN0): All versions RUGGEDCOM APE1808 SAM-L CC (6GK6015-0AL20-0GN1): All versions RUGGEDCOM APE1808CLA-P (6GK6015-0AL20-1AA0): All versions RUGGEDCOM APE1808CLA-P CC (6GK6015-0AL20-1AA1): All versions RUGGEDCOM APE1808CLA-S1 (6GK6015-0AL20-1AB0): All versions RUGGEDCOM APE1808CLA-S1 CC (6GK6015-0AL20-1AB1): All versions RUGGEDCOM APE1808CLA-S3 (6GK6015-0AL20-1AD0): All versions RUGGEDCOM APE1808CLA-S3 CC (6GK6015-0AL20-1AD1): All versions RUGGEDCOM APE1808CLA-S5 (6GK6015-0AL20-1AF0): All versions RUGGEDCOM APE1808CLA-S5 CC (6GK6015-0AL20-1AF1): All versions RUGGEDCOM APE1808LNX (6GK6015-0AL20-0GH0): All versions RUGGEDCOM APE1808LNX CC (6GK6015-0AL20-0GH1): All versions RUGGEDCOM APE1808W10 (6GK6015-0AL20-0GJ0): All versions RUGGEDCOM APE1808W10 CC (6GK6015-0AL20-0GJ1): All versions.,"CVE-2022-30774, CVE-2022-31243, CVE-2022-33906, CVE-2022-33907, CVE-2022-33908, CVE-2022-33982, CVE-2022-33984",7.0,High,CWE-367,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2379,2/16/2023,2/16/2023,2023,ICSA-23-047-09,Siemens SIMATIC Industrial Products,Siemens,SIMATIC industrial products,The following software from Siemens is affected: SIMATIC Field PG M5: All versions SIMATIC Field PG M6: All versions SIMATIC IPC BX-39A: All versions SIMATIC IPC427E: All versions SIMATIC IPC477E: All versions SIMATIC IPC477E Pro: All versions SIMATIC IPC627E: All versions SIMATIC IPC647E: All versions SIMATIC IPC677E: All versions SIMATIC IPC847E: All versions SIMATIC ITP1000: All versions.,CVE-2022-21198,7.9,High,CWE-367,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2378,2/16/2023,2/16/2023,2023,ICSA-23-047-10,Siemens COMOS,Siemens,COMOS,The following Siemens software is affected: COMOS V10.2: All versions COMOS V10.3.3.1: Versions prior to V10.3.3.1.45 COMOS V10.3.3.2: Versions prior to V10.3.3.2.33 COMOS V10.3.3.3: Versions prior to V10.3.3.3.9 COMOS V10.3.3.4: Versions prior to V10.3.3.4.6 COMOS V10.4.0.0: Versions prior to V10.4.0.0.31 COMOS V10.4.1.0: Versions prior to V10.4.1.0.32 COMOS V10.4.2.0: Versions prior to V10.4.2.0.25.,CVE-2023-24482,10.0,Critical,CWE-120,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2377,2/16/2023,2/16/2023,2023,ICSA-23-047-11,Siemens Mendix,Siemens,Mendix Applications,The following Siemens software is affected: Mendix Applications using Mendix 7: All versions prior to V7.23.34 Mendix Applications using Mendix 8: All versions prior to V8.18.23 Mendix Applications using Mendix 9: All versions prior to V9.22.0 Mendix Applications using Mendix 9 (V9.12): All versions prior to V9.12.10 Mendix Applications using Mendix 9 (V9.18): All versions prior to V9.18.4 Mendix Applications using Mendix 9 (V9.6): All versions prior to V9.6.15.,CVE-2023-23835,5.9,Medium,CWE-284,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2376,2/16/2023,2/16/2023,2023,ICSA-23-047-12,"Siemens JT Open, JT Utilities, and Parasolid",Siemens,"JT Open Toolkit, JT Utilities, and Parasolid","The following Siemens software is affected: JT Open: All versions prior to V11.2.3.0 (only affected by CVE-2022-47936, CVE-2022-47977) JT Utilities: All versions prior to V13.2.3.0 (only affected by CVE-2022-47936, CVE-2022-47977) Parasolid V34.0: All versions prior to V34.0.252 (only affected by CVE-2022-47936) Parasolid V34.0: All versions prior to V34.0.254 (only affected by CVE-2022-25140) Parasolid V34.1: All versions prior to V34.1.242 (only affected by CVE-2022-47936, CVE-2023-25140) Parasolid V35.0: All versions prior to V35.0.170 (only affected by CVE-2022-47936, CVE-2023-25140) Parasolid V35.1: All versions prior to V35.1.150 (only affected by CVE-2022-47936, CVE-2023-25140).","CVE-2022-47936, CVE-2022-47977, CVE-2023-25140",7.8,High,"CWE-121, CWE-119",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2375,2/16/2023,2/16/2023,2023,ICSA-23-047-13,Sub-IoT DASH 7 Alliance Protocol,Sub-IoT project,DASH 7 Alliance Protocol stack implementation,"The following versions of the Sub-IoT implementation of the Dash7 Alliance protocol, a low power, sub-GHz Internet of Things (IoT) communication protocol, are affected: Sub-IoT DASH 7 Alliance protocol implementation: All versions prior to 0.5.0.",CVE-2023-0847,5.3,Medium,CWE-787,Multiple Critical Sectors,Worldwide,Open-source,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2374,2/16/2023,2/23/2023,2023,ICSMA-23-047-01,BD Alaris Infusion Central (Update A),"Becton, Dickinson and Company (BD)",Alaris Infusion Central,"The following BD software products are affected: Alaris Infusion Central software versions 1.1 to 1.3.2, which are not sold in the U.S. Users who use BD Alaris PCU 8015 or BD Alaris Systems Manager are not impacted by this vulnerability.",CVE-2022-47376,7.3,High,CWE-257,Healthcare and Public Health,Outside the United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2373,2/14/2023,2/14/2023,2023,ICSA-23-045-01,Weintek EasyBuilder Pro cMT Series,Weintek,EasyBuilder Pro,"The following versions of Weintek EasyBuilder Pro, a project management software, are affected: v6.07.01 and prior v6.07.02.479 and prior v6.08.01.349 and prior.",CVE-2023-0104,9.3,Critical,CWE-29,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2372,2/9/2023,2/9/2023,2023,ICSA-23-040-01,"ControlByWeb X-400, X-600M",ControlByWeb,"X-400, X-600M","The following versions of ControlByWeb X-400 and X-600M, web enabled I/O Controllers, are affected: X-400: All firmware versions prior to 2.8 X-600M: All firmware versions prior to 1.16.00.","CVE-2023-23553, CVE-2023-23551",9.1,Critical,"CWE-79, CWE-94",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2371,2/9/2023,2/9/2023,2023,ICSA-23-040-02,LS Electric XBC-DN32U,"LS ELECTRIC, LS Industrial Systems (LSIS) Co. Ltd",XBC-DN32U,"The following version of XBC-DN32U, a PLC performance module, is affected: XBC-DN32U: Operating System Version 01.80.","CVE-2023-22803, CVE-2023-22804, CVE-2023-22805, CVE-2023-22806, CVE-2023-22807, CVE-2023-0102, CVE-2023-0103",9.8,Critical,"CWE-306, CWE-284, CWE-319, CWE-788",Multiple Critical Sectors,Worldwide,South Korea,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2370,2/9/2023,2/9/2023,2023,ICSA-23-040-03,Johnson Controls System Configuration Tool (SCT),Johnson Controls Inc.,System Configuration Tool,The following versions of System Configuration Tool (SCT) are affected: System Configuration Tool (SCT) version 14: Versions prior to 14.2.3 System Configuration Tool (SCT) version 15: Versions prior to 15.0.3.,"CVE-2022-21939, CVE-2022-21940",7.5,High,"CWE-1004, CWE-614",Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2369,2/9/2023,2/9/2023,2023,ICSA-23-040-04,Horner Automation Cscape Envision RV,Horner Automation,Cscape Envision RV,"The following version of Cscape Envision RV, a control system remote access management software, is affected: Cscape Envision RV: Version 4.60.","CVE-2023-0621, CVE-2023-0622, CVE-2023-0623",7.8,High,"CWE-125, CWE-787",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2368,2/6/2023,2/6/2023,2023,ICSA-23-037-01,EnOcean SmartServer,EnOcean Edge Inc (Subsidiary of EnOcean GmbH),SmartServer with i.LON Vision,The following EnOcean Edge products are affected: EnOcean SmartServer: v2.2 SR8/SP8 (4.12.006) with i.LON Vision v2.2 SR8/SP8 (4.12.006).,CVE-2022-3089,6.3,Medium,CWE-798,Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2367,2/2/2023,2/2/2023,2023,ICSA-23-033-01,Delta Electronics DIAScreen,Delta Electronics,DIAScreen,"The following versions of DIAScreen, a software configuration tool for Delta devices, are affected: DIAScreen: versions 1.2.1.23 and prior.","CVE-2023-0250, CVE-2023-0251, CVE-2023-0249",7.8,High,"CWE-121, CWE-119, CWE-787",Energy,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2366,2/2/2023,2/2/2023,2023,ICSA-23-033-02,Mitsubishi Electric GOT2000 Series and GT SoftGOT2000,Mitsubishi Electric,GOT Mobile Function on GOT2000 Series and GT SoftGOT2000,Mitsubishi Electric reports these vulnerabilities affect the GOT Mobile Function on the following products: GOT2000 Series: GT27 model: GOT Mobile versions 01.14.000-01.47.000 GT25 model: GOT Mobile versions 01.14.000-01.47.000 GT SoftGOT2000: software versions 1.265B-1.285X.,"CVE-2022-40269, CVE-2022-40268",6.8,Medium,"CWE-290, CWE-1021",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2365,2/2/2023,2/2/2023,2023,ICSA-23-033-03,Baicells Nova,Baicells Technologies,Nova,Baicells reports this vulnerability affects the following Nova LTE TDD eNodeB devices with firmware through RTS/RTD 3.6.6: Nova 227 Nova 233 Nova 243 Nova 246.,CVE-2023-24508,9.8,Critical,CWE-77,Communications,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2364,2/2/2023,2/2/2023,2023,ICSA-23-033-04,Delta Electronics DVW-W02W2-E2,Delta Electronics,DVW-W02W2-E2,"The following versions of DVW-W02W2-E2, an industrial ethernet router, are affected: DVW-W02W2-E2: Version 2.42.",CVE-2022-42139,9.9,Critical,CWE-78,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2363,2/2/2023,2/2/2023,2023,ICSA-23-033-05,Delta Electronics DX-2100-L1-CN,Delta Electronics,DX-2100-L1-CN,"The following versions of DX-2100-L1-CN, an industrial ethernet router, are affected: DX-2100-L1-CN: Version 1.5.0.10.","CVE-2022-42140, CVE-2023-0432",9.0,Critical,"CWE-78, CWE-79",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2362,1/31/2023,1/31/2023,2023,ICSA-23-031-01,Delta Electronics DOPSoft,Delta Electronics,DOPSoft,"The following versions of DOPSoft, a human machine interface (HMI) editing software, are affected: DOPSoft: versions 4.00.16.22 and prior.","CVE-2023-0123, CVE-2023-0124",7.8,High,"CWE-121, CWE-787",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2361,1/26/2023,1/26/2023,2023,ICSA-23-026-01,Delta Electronics CNCSoft ScreenEditor,Delta Electronics,CNCSoft,"The following versions of CNCSoft, a software management platform, are affected: CNCSoft: All versions prior to v1.01.34 Running ScreenEditor: All versions 1.01.5 and prior.",CVE-2022-4634,7.8,High,CWE-121,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2360,1/26/2023,6/22/2023,2023,ICSA-23-026-02,Econolite EOS (Update A),Econolite,EOS,"The following versions of EOS, a traffic control software, are affected: --------- Begin Update A Part 1 of 4 --------- EOS: Versions prior to 3.2.23 --------- End Update A Part 1 of 4 ---------.","CVE-2023-0451, CVE-2023-0452",9.8,Critical,"CWE-284, CWE-328",Transportation Systems,"United States, Canada",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2359,1/26/2023,1/26/2023,2023,ICSA-23-026-03,SnapOne Wattbox,Snap One,Wattbox WB-300-IP -3,"The following versions of Snap One Wattbox WB-300-IP-3, a surge protector, are affected: Wattbox WB-300-IP-3: versions WB10.9a17 and prior.","CVE-2023-24020, CVE-2023-23582, CVE-2023-22389, CVE-2023-22315",7.5,High,"CWE-307, CWE-122, CWE-256, CWE-345",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2358,1/26/2023,1/26/2023,2023,ICSA-23-026-04,Sierra Wireless AirLink Router with ALEOS Software,Sierra Wireless,AirLink Router with ALEOS Software,"Sierra Wireless reports the following versions of AirLink router with ALEOS software are affected: Airlink Router (ES450, GX450) running ALEOS software: Versions 4.9.7 and prior Airlink Router (MP70, RV50, RV50x, RV55, LX 40, LX60) running ALEOS software: Versions prior to 4.16.0.","CVE-2022-46649, CVE-2022-46650",8.0,High,"CWE-88, CWE-200",Multiple Critical Sectors,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2357,1/26/2023,1/26/2023,2023,ICSA-23-026-05,Mitsubishi Electric MELFA SD SQ series and F-series Robot Controllers,Mitsubishi Electric,MELFA SD/SQ series and F-series Robot Controllers,Mitsubishi Electric reports this vulnerability affects the following Robot Controllers: MELFA SD/SQ Series: firmware version S7x and prior MELFA SD/SQ Series: firmware version R7x and prior MELFA F-Series: firmware version S7x and prior MELFA F-Series: firmware version R7x and prior Note: The affected firmware version depends on the model name; see Mitsubishi Electric's publication for the specific model names and controller types.,CVE-2022-33323,7.5,High,CWE-489,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2356,1/26/2023,1/26/2023,2023,ICSA-23-026-06,Rockwell Automation products using GoAhead Web Server,Rockwell Automation,Products using GoAhead Web Server,Rockwell Automation reports the following products use a version of GoAhead web server vulnerable to both CVE-2019-5096 and CVE-2019-5097: 1732E-8CFGM8R/A: firmware version 1.012 1732E-IF4M12R/A (discontinued): firmware version 1.012 1732E-IR4IM12R/A: firmware version 1.012 1732E-IT4IM12R/A: firmware version 1.012 1732E-OF4M12R/A: firmware version 1.012 1732E-OB8M8SR/A: firmware version 1.013 1732E-IB8M8SOER: firmware version 1.012 1732E-8IOLM12R: firmware version 2.011 1747-AENTR: firmware version 2.002 1769-AENTR: firmware version 1.001 5069-AEN2TR: firmware version 3.011 1756-EN2TR/C: firmware versions up to and including 11.001 1756-EN2T/D: firmware versions up to and including 11.001 1756-EN2TSC/B (discontinued): firmware version 10.01 1756-EN2TSC/B: firmware version 10.01 1756-HIST1G/A (discontinued): firmware versions up to and including 3.054 1756-HIST2G/A(discontinued): firmware versions up to and including 3.054 1756-HIST2G/B: firmware versions up to and including 5.103 Rockwell Automation reports the following products use a version of GoAhead web server vulnerable to CVE-2019-5097: ControlLogix 5580 controllers: firmware version V28 - V32 GuardLogix 5580 controllers: firmware version V31 - V32 CompactLogix 5380 controllers: firmware version V28 - V32 Compact GuardLogix 5380 controllers: firmware version V31 - V32 CompactLogix 5480 controllers: firmware version V32 1756- EN2T/D: firmware version 11.001 1756-EN2TR/C: firmware version 11.001 1765 - EN3TR/B: firmware version 11.001 1756-EN2F/C: firmware version 11.001 1756-EN2TP/A: firmware version 11.001.,"CVE-2019-5097, CVE-2019-5096",9.8,Critical,"CWE-835, CWE-416",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2355,1/26/2023,1/26/2023,2023,ICSA-23-026-07,Landis+Gyr E580,Landis+Gyr,E850 (ZMQ200),The following versions of E850 (ZMQ200) are affected: E850 (ZMQ200): All versions.,CVE-2022-3083,3.9,Low,CWE-784,Multiple Critical Sectors,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2354,1/24/2023,1/24/2023,2023,ICSA-23-024-01,XINJE XD,XINJE,XINJE XD Programing Tool,The following versions of XINJE XD are affected: Version 3.5.1 and prior .,"CVE-2021-34605, CVE-2021-34606",7.3,High,"CWE-23, CWE-427",Critical Manufacturing; Energy,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2353,1/24/2023,9/26/2023,2023,ICSA-23-024-02,SOCOMEC MODULYS GP (UPDATE A),Socomec,MODULYS GP,"The following versions of SOCOMEC MODULYS GP, a modular UPS, are affected: MODULYS GP: Net Vision v7.20",CVE-2023-0356,5.7,Medium,CWE-261,Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2352,1/19/2023,1/19/2023,2023,ICSA-23-019-01,Hitachi Energy PCU400,Hitachi Energy,PCU400,"The following versions of PCU400, a network manager and process communication unit, are affected: PCU400: Versions 9.3.0 and later up to but not including 9.3.8 PCULogger tool: Version 1.0.1.","CVE-2022-3602, CVE-2022-3786",7.5,High,CWE-1357,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2351,1/17/2023,1/17/2023,2023,ICSA-23-017-01,GE Proficy Historian,GE Digital,Proficy Historian,GE Digital reports these vulnerabilities affect the following Proficy Historian product: Proficy Historian v7.0 and higher versions Not Affected: Other GE software offerings including GE Digital and Proficy Products not listed above.,"CVE-2022-4673, CVE-2022-46660, CVE-2022-43494, CVE-2022-46331, CVE-2022-38469",9.8,Critical,"CWE-288, CWE-434, CWE-284, CWE-261",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2350,1/17/2023,4/18/2023,2023,ICSA-23-017-02,"Mitsubishi Electric MELSEC iQ-F, iQ-R Series (Update B)",Mitsubishi Electric,MELSEC iQ-F and iQ-R Series products,"The following Mitsubishi Electric MELSEC products are affected: MELSEC iQ-F Series with serial number 17X**** or later: FX5U-xMy/z x=32,64,80, y=T,R, z=ES,DS,ESS,DSS: Versions 1.280 and prior FX5UC-xMy/z x=32,64,96 y=T, z=D,DSS: Versions 1.280 and prior MELSEC iQ-F Series with serial number 179**** and prior: FX5U-xMy/z x=32,64,80, y=T,R, z=ES,DS,ESS,DSS: Versions 1.074 and prior FX5UC-xMy/z x=32,64,96 y=T, z=D,DSS: Versions 1.074 and prior MELSEC iQ-F Series FX5UC-32MT/DS-TS, FX5UC-32MT/DSS-TS, FX5UC-32MR/DS-TS: Versions 1.280 and prior FX5UJ-xMy/z x=24,40,60, y=T,R, z=ES,ESS: Versions 1.042 and prior FX5UJ-xMy/ES-A* x=24,40,60, y=T,R: Versions 1.043 and prior FX5S-xMy/z x=30,40,60,80, y=T,R, z=ES,ESS: Versions 1.003 and prior --------- Begin Update B Part 1 of 3 --------- MELSEC iQ-R Series R00/01/02CPU: Versions 33 and prior MELSEC iQ-R Series R04/08/16/32/120(EN)CPU: Versions 66 and prior --------- End Update B Part 1 of 3 --------- * These products are available in limited regions.",CVE-2022-40267,5.9,Medium,CWE-337,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2349,1/17/2023,1/17/2023,2023,ICSA-23-017-03,Siemens SINEC INS,Siemens,SINEC INS,Siemens reports these vulnerabilities affect the following network services application: SINEC INS: versions prior to V1.0 SP2 Update 1,"CVE-2022-1292, CVE-2022-2068, CVE-2022-32212, CVE-2022-2097, CVE-2022-2274, CVE-2022-32213, CVE-2022-32215, CVE-2022-32222, CVE-2022-35255, CVE-2022-35256, CVE-2022-45092, CVE-2022-45093, CVE-2022-45094",9.9,Critical,"CWE-78, CWE-326, CWE-787, CWE-444, CWE-330, CWE-290, CWE-22, CWE-77",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2348,1/12/2023,1/12/2023,2023,ICSA-23-012-01,Sewio RTLS Studio,Sewio,RTLS Studio,"The following version of Sewio's RTLS Studio, a Real-Time Location System (RTLS), is affected: RTLS Studio: version 2.0.0 up to and including version 2.6.2","CVE-2022-45444, CVE-2022-47911, CVE-2022-43483, CVE-2022-41989, CVE-2022-45127, CVE-2022-47395, CVE-2022-47917, CVE-2022-46733, CVE-2022-43455",10.0,Critical,"CWE-259, CWE-78, CWE-787, CWE-352, CWE-20, CWE-79",Multiple Critical Sectors,Worldwide,Czech Republic,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2347,1/12/2023,1/12/2023,2023,ICSA-23-012-02,RONDS Equipment Predictive Maintenance Solution,RONDS,Equipment Predictive Maintenance (EPM),"The following version of RONDS EPM, an equipment predictive maintenance solution, is affected: v1.19.5","CVE-2022-3091, CVE-2022-2893",8.2,High,"CWE-200, CWE-22",Critical Manufacturing,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2346,1/12/2023,1/12/2023,2023,ICSA-23-012-03,InHand Networks InRouter,InHand Networks,"InRouter302, InRouter615","The following versions of InRouters, an industrial router line, are affected: InRouter 302: All versions prior to IR302 V3.5.56 InRouter 615: All versions prior to InRouter6XX-S-V2.3.0.r5542","CVE-2022-22597, CVE-2022-22598, CVE-2022-22599, CVE-2022-22600, CVE-2022-22601",10.0,Critical,"CWE-319, CWE-78, CWE-760, CWE-284, CWE-330",Energy; Critical Manufacturing; Transportation Systems; Healthcare and Public Health,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2345,1/12/2023,1/12/2023,2023,ICSA-23-012-04,Panasonic Sanyo CCTV Network Camera,Panasonic,Sanyo CCTV Network Camera,The following versions of Panasonic Sanyo CCTV Network Camera are affected: VCC-HD5600P version 2.03-06 VDC-HD3300P version 2.03-08 VDC-HD3300P version 1.02-05 VCC-HD3300 version 2.03-02 VDC-HD3100P version 2.03-00 VCC-HD2100P version 2.03-02,CVE-2022-4621,7.5,High,CWE-352,Commercial Facilities,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2344,1/12/2023,1/12/2023,2023,ICSA-23-012-05,SAUTER Controls Nova 200 - 220 Series (PLC 6),SAUTER Controls,Nova 200-220 Series (PLC 6),"The following firmware versions of SAUTER Controls Nova, a series of programmable logic controllers (PLCs), are affected: Nova 220 (EYK220F001) DDC with BACnet connection: Firmware version 3.3-006 and prior with BACnetstac version 4.2.1 and prior Nova 230 (EYK230F001) DDC with BACnet connection: Firmware version 3.3-006 and prior with BACnetstac version 4.2.1 and prior Nova 106 (EYK300F001) BACnet communication card: Firmware version 3.3-006 and prior with BACnetstac version 4.2.1 and prior moduNet300 (EY-AM300F001, EY-AM300F002): Firmware version 3.3-006 and prior with BACnetstac version 4.2.1 and prior","CVE-2023-0052, CVE-2023-0053",9.8,Critical,"CWE-306, CWE-319","Critical Manufacturing, Energy",Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2343,1/12/2023,1/12/2023,2023,ICSA-23-012-06,Johnson Controls Metasys,Johnson Controls Inc.,Metasys ADS/ADX/OAS Servers,The following versions of Metasys ADS/ADX/OAS Servers are affected: Metasys ADS/ADX/OAS Version 10.X: All versions prior to 10.1.6 Metasys ADS/ADX/OAS Version 11.X: All versions prior to 11.0.3,CVE-2021-36204,7.8,High,CWE-522,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2342,1/12/2023,1/12/2023,2023,ICSA-23-012-07,Hitachi Energy Lumada APM,Hitachi Energy,Lumada APM,Hitachi Energy reports the following products are affected: Lumada APM - SaaS: Versions 6.0.0.0 to 6.4.220601.0 Lumada APM - On Premises: Versions 6.0.0.0.0 to 6.4.0,CVE-2022-2155,5.7,Medium,CWE-284,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2341,1/12/2023,1/12/2023,2023,ICSA-23-012-08,Siemens S7-1500 CPU devices,Siemens,S7-1500 CPU product family,Siemens reports this vulnerability affects the following CPU products: SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0): All versions SIMATIC Drive Controller CPU 1507D TF (6ES7615-7DF10-0AB0): All versions SIMATIC S7-1500 CPU 1510SP F-1 PN (6ES7510-1SJ00-0AB0): All versions SIMATIC S7-1500 CPU 1510SP F-1 PN (6ES7510-1SJ01-0AB0): All versions SIMATIC S7-1500 CPU 1510SP-1 PN (6ES7510-1DJ00-0AB0): All versions SIMATIC S7-1500 CPU 1510SP-1 PN (6ES7510-1DJ01-0AB0): All versions SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK00-0AB0): All versions SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK01-0AB0): All versions SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK02-0AB0): All versions SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK00-0AB0): All versions SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK01-0AB0): All versions SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK00-0AB0): All versions SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK01-0AB0): All versions SIMATIC S7-1500 CPU 1511F-1 PN (6ES7511-1FK02-0AB0): All versions SIMATIC S7-1500 CPU 1511T-1 PN (6ES7511-1TK01-0AB0): All versions SIMATIC S7-1500 CPU 1511TF-1 PN (6ES7511-1UK01-0AB0): All versions SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK00-0AB0): All versions SIMATIC S7-1500 CPU 1512C-1 PN (6ES7512-1CK01-0AB0): All versions SIMATIC S7-1500 CPU 1512SP F-1 PN (6ES7512-1SK00-0AB0): All versions SIMATIC S7-1500 CPU 1512SP F-1 PN (6ES7512-1SK01-0AB0): All versions SIMATIC S7-1500 CPU 1512SP-1 PN (6ES7512-1DK00-0AB0): All versions SIMATIC S7-1500 CPU 1512SP-1 PN (6ES7512-1DK01-0AB0): All versions SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL00-0AB0): All versions SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL01-0AB0): All versions SIMATIC S7-1500 CPU 1513-1 PN (6ES7513-1AL02-0AB0): All versions SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL00-0AB0): All versions SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL01-0AB0): All versions SIMATIC S7-1500 CPU 1513F-1 PN (6ES7513-1FL02-0AB0): All versions SIMATIC S7-1500 CPU 1513R-1 PN (6ES7513-1RL00-0AB0): All versions SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM00-0AB0): All versions SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM01-0AB0): All versions SIMATIC S7-1500 CPU 1515-2 PN (6ES7515-2AM02-0AB0): All versions SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM00-0AB0): All versions SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM01-0AB0): All versions SIMATIC S7-1500 CPU 1515F-2 PN (6ES7515-2FM02-0AB0): All versions SIMATIC S7-1500 CPU 1515R-2 PN (6ES7515-2RM00-0AB0): All versions SIMATIC S7-1500 CPU 1515T-2 PN (6ES7515-2TM01-0AB0): All versions SIMATIC S7-1500 CPU 1515TF-2 PN (6ES7515-2UM01-0AB0): All versions SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN00-0AB0): All versions SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN01-0AB0): All versions SIMATIC S7-1500 CPU 1516-3 PN/DP (6ES7516-3AN02-0AB0): All versions SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN00-0AB0): All versions SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN01-0AB0): All versions SIMATIC S7-1500 CPU 1516F-3 PN/DP (6ES7516-3FN02-0AB0): All versions SIMATIC S7-1500 CPU 1516T-3 PN/DP (6ES7516-3TN00-0AB0): All versions SIMATIC S7-1500 CPU 1516TF-3 PN/DP (6ES7516-3UN00-0AB0): All versions SIMATIC S7-1500 CPU 1517-3 PN/DP (6ES7517-3AP00-0AB0): All versions SIMATIC S7-1500 CPU 1517F-3 PN/DP (6ES7517-3FP00-0AB0): All versions SIMATIC S7-1500 CPU 1517H-3 PN (6ES7517-3HP00-0AB0): All versions SIMATIC S7-1500 CPU 1517T-3 PN/DP (6ES7517-3TP00-0AB0): All versions SIMATIC S7-1500 CPU 1517TF-3 PN/DP (6ES7517-3UP00-0AB0): All versions SIMATIC S7-1500 CPU 1518-4 PN/DP (6ES7518-4AP00-0AB0): All versions SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0): All versions SIMATIC S7-1500 CPU 1518-4F PN/DP (6ES7518-4FP00-0AB0): All versions SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0): All versions SIMATIC S7-1500 CPU 1518HF-4 PN (6ES7518-4JP00-0AB0): All versions SIMATIC S7-1500 CPU 1518T-4 PN/DP (6ES7518-4TP00-0AB0): All versions SIMATIC S7-1500 CPU 1518TF-4 PN/DP (6ES7518-4UP00-0AB0): All versions SIMATIC S7-1500 C,CVE-2022-38773,4.6,Medium,CWE-1326,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2340,1/12/2023,1/12/2023,2023,ICSA-23-012-09,Siemens Mendix SAML Module,Siemens,Mendix SAML,"The following components from Siemens are affected: Mendix SAML (Mendix 8 compatible): Versions V2.3.0 and after up to V2.3.4 Mendix SAML (Mendix 9 compatible, New Track): Versions V3.3.0 and after up to V3.3.9 Mendix SAML (Mendix 9 compatible, Upgrade Track): Versions V3.3.0 and after up to V3.3.8",CVE-2022-46823,9.3,Critical,CWE-79,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2339,1/12/2023,1/12/2023,2023,ICSA-23-012-10,Siemens Automation License Manager,Siemens,Automation License Manager (ALM),The following software from Siemens is affected: Automation License Manager V5: All versions Automation License Manager V6: All versions prior to V6.0 SP9 Upd4,CVE-2022-43513,8.2,High,"CWE-73, CWE-22",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2338,1/12/2023,1/12/2023,2023,ICSA-23-012-11,Siemens Solid Edge before V2023 MP1,Siemens,Solid Edge,The following versions of Siemens Solid Edge are affected: All versions prior to V2023 MP1,CVE-2022-47967,7.8,High,CWE-119,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2337,1/10/2023,1/10/2023,2023,ICSA-23-010-01,Black Box KVM,Black Box,KVM Switches and Extenders,"The following models and versions of Black Box KVMs, a Keyboard/Video/Mouse switch and extender, are affected: Black Box KVM ACR1000A-R-R2: Firmware version v3.4.31307 Black Box KVM ACR1000A-T-R2: Firmware version v3.4.31307 Black Box KVM ACR1002A-T: Firmware version v3.4.31307 Black Box KVM ACR1002A-R: Firmware version v3.4.31307 Black Box KVM ACR1020A-T: Firmware version v3.4.31307.",CVE-2022-4636,7.5,High,CWE-22,Multiple Critical Sectors,Worldwide,India,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2336,1/5/2023,1/5/2023,2023,ICSA-23-005-01,Hitachi Energy UNEM,Hitachi Energy,UNEM,Hitachi Energy reports these vulnerabilities affect the following UNEM products: UNEM R16A UNEM R15B UNEM R15A UNEM R14B UNEM R14A UNEM R11B UNEM R11A UNEM R10C UNEM R9C.,"CVE-2021-40341, CVE-2021-40342, CVE-2022-3927, CVE-2022-3928, CVE-2022-3929",8.3,High,"CWE-326, CWE-321, CWE-319",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2335,1/5/2023,1/5/2023,2023,ICSA-23-005-02,Hitachi Energy FOXMAN-UN,Hitachi Energy,FOXMAN-UN,Hitachi Energy reports these vulnerabilities affect the following FOXMAN-UN products: FOXMAN-UN R16A FOXMAN-UN R15B FOXMAN-UN R15A FOXMAN-UN R14B FOXMAN-UN R14A FOXMAN-UN R11B FOXMAN-UN R11A FOXMAN-UN R10C FOXMAN-UN R9C.,"CVE-2021-40341, CVE-2021-40342, CVE-2022-3927, CVE-2022-3928, CVE-2022-3929",8.3,High,"CWE-326, CWE-1394, CWE-321, CWE-319",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2334,1/5/2023,1/5/2023,2023,ICSA-23-005-03,Hitachi Energy Lumada Asset Performance Management,Hitachi Energy,Lumada Asset Performance Management (APM),"The following versions of Lumada Asset Performance Management (APM), a web-based asset monitoring software deployable as both a cloud service or as a local deployment, are affected: Lumada APM: Version 6.5.0.0 Lumada APM: Versions 6.1.0.0 through 6.4.0.0 (CVE-2022-37434 only).","CVE-2022-3602, CVE-2022-3786, CVE-2022-37434",9.8,Critical,"CWE-120, CWE-787",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2333,12/22/2022,12/22/2022,2022,ICSA-22-356-01,Priva TopControl Suite,Priva,TopControl Suite,The following components of Priva TopControl Suite are affected: Bacnet: All versions prior to 8.7.8.0 Blue ID: All versions prior to 8.7.8.0 Compass: All versions prior to 8.7.8.0 Connect: All versions prior to 8.7.8.0 TPC: All versions prior to 8.7.8.0.,CVE-2022-3010,7.5,High,CWE-916,Energy,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2332,12/22/2022,12/22/2022,2022,ICSA-22-356-02,Rockwell Automation Studio 5000 Logix Emulate,Rockwell Automation,Studio 5000 Logix Emulate,The following versions of Studio 5000 Logix Emulate are affected: Studio 5000 Logix Emulate v .20-33.,CVE-2022-3156,7.8,High,CWE-284,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2331,12/22/2022,9/5/2024,2022,ICSA-22-356-03,"Mitsubishi Electric MELSEC iQ-R, iQ-L Series and MELIPC Series (Update E)",Mitsubishi Electric,"MELSEC iQ-R, iQ-L Series and MELIPC Series","Mitsubishi Electric reports this vulnerability affects the following MELSEC iQ-R, iQ-L series CPU module, and MELIPC series: MELSEC iQ-R Series R00CPU: firmware versions 32 and prior MELSEC iQ-R Series R01CPU: firmware versions 32 and prior MELSEC iQ-R Series R02CPU: firmware versions 32 and prior MELSEC iQ-R Series R04(EN)CPU: firmware versions 65 and prior MELSEC iQ-R Series R08(EN)CPU: firmware versions 65 and prior MELSEC iQ-R Series R16(EN)CPU: firmware versions 65 and prior MELSEC iQ-R Series R32(EN)CPU: firmware versions 65 and prior MELSEC iQ-R Series R120(EN)CPU: firmware versions 65 and prior MELSEC iQ-R Series R08SFCPU: firmware versions 29 and prior MELSEC iQ-R Series R16SFCPU: firmware versions 29 and prior MELSEC iQ-R Series R32SFCPU: firmware versions 29 and prior MELSEC iQ-R Series R120SFCPU: firmware versions 29 and prior MELSEC iQ-R Series R08PSFCPU: firmware versions 08 and prior MELSEC iQ-R Series R16PSFCPU: firmware versions 08 and prior MELSEC iQ-R Series R32PSFCPU: firmware versions 08 and prior MELSEC iQ-R Series R120PSFCPU: firmware versions 08 and prior MELSEC iQ-R Series R12CCPU-V: firmware versions 17 and prior MELSEC iQ-L Series L04HCPU (sold in limited regions): firmware versions 05 and prior MELSEC iQ-L Series L08HCPU (sold in limited regions): firmware versions 05 and prior MELSEC iQ-L Series L16HCPU (sold in limited regions): firmware versions 05 and prior MELSEC iQ-L Series L32HCPU (sold in limited regions): firmware versions 05 and prior MELIPC Series MI5122-VW: firmware versions 07 and prior.",CVE-2022-33324,7.5,High,CWE-404,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2330,12/22/2022,12/22/2022,2022,ICSA-22-356-04,Omron CX-Programmer,Omron,CX-Programmer,"The following versions of CX-Programmer, part of a software automation suite, are affected: CX-Programmer: Versions 9.78 and prior.",CVE-2022-43509,7.8,High,CWE-787,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2329,12/20/2022,12/20/2022,2022,ICSA-22-354-01,Fuji Electric Tellus Lite V-Simulator,Fuji Electric,Tellus Lite V-Simulator,The following versions of Fuji Electric Tellus Lite V-Simulator”a remote monitoring and operation software”are affected: Versions 4.0.12.0 and prior.,"CVE-2022-3087, CVE-2022-3085",7.8,High,"CWE-787, CWE-121",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2328,12/20/2022,12/20/2022,2022,ICSA-22-354-02,Rockwell Automation GuardLogix and ControlLogix controllers,Rockwell Automation,"GuardLogix, ControlLogix, Compact Logix, and Compact GaurdLogix controllers",Rockwell Automation reports this vulnerability affects the following controllers: CompactLogix 5370 Versions 20-33 Compact GuardLogix 5370 Versions 28-33 ControlLogix 5570 Versions 20-33 ControlLogix5570 redundancy Versions 20-33 GuardLogix 5570 Versions 20-33.,CVE-2022-3157,8.6,High,CWE-20,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2327,12/20/2022,2/9/2023,2022,ICSA-22-354-03,ARC Informatique PcVue (Update A),ARC Informatique,PcVue,"The following versions of PcVue, a supervisory control and data acquisition (SCADA) monitoring and control software, are affected: PcVue Versions 15 through 15.2.2 (CVE-2022-3411 only) --------- Begin Update A part 1 of 2 --------- PcVue Versions 8.10 through 15.2.3 (CVE-2022-3412 only) PcVue 12 products are only affected until Version 12.0.28 --------- End Update A part 1 of 2 ---------.","CVE-2022-4312, CVE-2022-4311",5.5,Medium,"CWE-312, CWE-532",Commercial Facilities; Transportation Systems; Water and Wastewater Systems; Energy; Critical Manufacturing; Food and Agriculture,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2326,12/20/2022,12/20/2022,2022,ICSA-22-354-04,Rockwell Automation MicroLogix 1100 and 1400,Rockwell Automation,MicroLogix 1100 and 1400,The following versions of MicroLogix”a line of programmable logic controllers (PLCs)”are affected: MicroLogix 1100: all versions MicroLogix 1400 A: Versions 7.000 and prior MicroLogix 1400 B/C: Versions 21.007 and prior.,"CVE-2022-46670, CVE-2022-3166",7.5,High,"CWE-79, CWE-1021",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2325,12/20/2022,12/20/2022,2022,ICSA-22-354-05,Delta 4G Router DX-3021,Delta Electronics,4G Router DX-3021,Delta reports this vulnerability affects the following 4G Routers: DX-3021L9 versions prior to V1.24.,CVE-2022-4616,7.2,High,CWE-77,Energy,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2324,12/15/2022,12/20/2022,2022,ICSA-22-349-01,Prosys OPC UA Simulation Server (Update A),Prosys OPC,UA Simulation Server,The following version of Prosys OPC UA simulation servers are affected: Prosys OPC UA Simulation Server versions prior to 5.4.0 Prosys OPC UA Modbus Server 1.4.18-5 and prior.,CVE-2022-2967,6.5,Medium,CWE-522,Critical Manufacturing; Energy; Information Technology,Worldwide,Finland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2323,12/15/2022,12/15/2022,2022,ICSA-22-349-02,Siemens SCALANCE X-200RNA Switch Devices,Siemens,SCALANCE,The following Siemens software is affected: SCALANCE X204RNA (HSR) (6GK5204-0BA00-2MB2): All versions prior to V3.2.7 SCALANCE X204RNA (PRP) (6GK5204-0BA00-2KB2): All versions prior to V3.2.7 SCALANCE X204RNA EEC (HSR) (6GK5204-0BS00-2NA3): All versions prior to V3.2.7 SCALANCE X204RNA EEC (PRP) (6GK5204-0BS00-3LA3): All versions prior to V3.2.7 SCALANCE X204RNA EEC (PRP/HSR) (6GK5204-0BS00-3PA3): All versions prior to V3.2.7.,"CVE-2022-46350, CVE-2022-46351, CVE-2022-46352, CVE-2022-46353, CVE-2022-46354, CVE-2022-46355",8.8,High,"CWE-80, CWE-400, CWE-330, CWE-284, CWE-200",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2322,12/15/2022,12/15/2022,2022,ICSA-22-349-03,Siemens Multiple Denial of Service Vulnerabilities in Industrial Products,Siemens,"SIMATIC Products, TIM 1531 IRC",The following software from Siemens is affected: SIMATIC Drive Controller family: All versions prior to V3.0.1 SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions SIMATIC S7-1200 CPU family (incl. SIPLUS variants): All versions prior to V4.6.0 SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions prior to V3.0.1 SIMATIC S7-1500 Software Controller: All versions SIMATIC S7-PLCSIM Advanced: All versions prior V5.0 SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0): All versions TIM 1531 IRC (6GK7543-1MX00-0XE0): All versions.,"CVE-2021-40365, CVE-2021-44693, CVE-2021-44694, CVE-2021-44695",7.5,High,"CWE-20, CWE-1284, CWE-1287, CWE-1286",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2321,12/15/2022,12/15/2022,2022,ICSA-22-349-04,Siemens Multiple Vulnerabilities in SCALANCE Products,Siemens,RUGGEDCOM and SCALANCE devices,"RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (only affected by CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (only affected by CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE M804PB (6GK5804-0AP00-2AA2) (only affected by CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE M812-1 ADSL-Router (Annex A) (6GK5812-1AA00-2AA2) (only affected by CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE M812-1 ADSL-Router (Annex B) (6GK5812-1BA00-2AA2) (only affected by CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE M816-1 ADSL-Router (Annex A) (6GK5816-1AA00-2AA2) (only affected by CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE M816-1 ADSL-Router (Annex B) (6GK5816-1BA00-2AA2) (only affected by CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2) (only affected by CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE M874-2 (6GK5874-2AA00-2AA2) (only affected by CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE M874-3 (6GK5874-3AA00-2AA2) (only affected by CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE M876-3 (EVDO) (6GK5876-3AA02-2BA2) (only affected by CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2) (only affected by CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE M876-4 (6GK5876-4AA10-2BA2) (only affected by CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2) (only affected by CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2) (only affected by CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1) (only affected by CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1) (only affected by CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1) (only affected by CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE S615 (6GK5615-0AA00-2AA2) (only affected by CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE S615 EEC (6GK5615-0AA01-2AA2) (only affected by CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE SC622-2C (6GK5622-2GS00-2AC2): All versions prior to V2.3 SCALANCE SC622-2C (6GK5622-2GS00-2AC2) (only affected by CVE-2022-34821, CVE-2022-46142, CVE-2022-46143, CVE-2022-46144): All versions V2.3 and later, but prior to V3.0 SCALANCE SC626-2C (6GK5626-2GS00-2AC2): All versions prior to V2.3 SCALANCE SC626-2C (6GK5626-2GS00-2AC2) (only affected by CVE-2022-34821, CVE-2022-46142, CVE-2022-46143, CVE-2022-46144): All versions V2.3 and later, but prior to V3.0 SCALANCE SC632-2C (6GK5632-2GS00-2AC2): All versions prior to V2.3 SCALANCE SC632-2C (6GK5632-2GS00-2AC2) (only affected by CVE-2022-34821, CVE-2022-46142, CVE-2022-46143, CVE-2022-46144): All versions V2.3 and later, but prior to V3.0 SCALANCE SC636-2C (6GK5636-2GS00-2AC2): All versions prior to V2.3 SCALANCE SC636-2C (6GK5636-2GS00-2AC2) (only affected by CVE-2022-34821, CVE-2022-46142, CVE-2022-46143, CVE-2022-46144): All versions V2.3 and later, but prior to V3.0 SCALANCE SC642-2C (6GK5642-2GS00-2AC2): All versions prior to V2.3 SCALANCE SC642-2C (6GK5642-2GS00-2AC2) (only affected by CVE-2022-34821, CVE-2022-46142, CVE-2022-46143, CVE-2022-46144): All versions V2.3 and later, but prior to V3.0 SCALANCE SC646-2C (6GK5646-2GS00-2AC2): All versions prior to V2.3 SCALANCE SC646-2C (6GK5646-2GS00-2AC2) (only affected by CVE-2022-34821, CVE-2022-46142, CVE-2022-46143, CVE-2022-46144): All versions V2.3 and later, but prior to V3.0 SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W1788-2 M12 (6GK5788-2GY01-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W1788-2IA M12 (6GK5788-2HY01-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE WAM763-1 (6GK5763-1AL00-7DA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE WAM766-1 (6GK5766-1GE00-7DA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE WAM766-1 (6GK5766-1GE00-7DB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE WAM766-1 6GHz (6GK5766-1JE00-7DA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE WAM766-1 EEC 6GHz (6GK5766-1JE00-7TA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE WUM763-1 (6GK5763-1AL00-3DA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE WUM763-1 (6GK5763-1AL00-3AA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE WUM766-1 (6GK5766-1GE00-3DA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE WUM766-1 (6GK5766-1GE00-3DB0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE WUM766-1 6GHz (6GK5766-1JE00-3DA0) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XB205-3 (SC, PN) (6GK5205-3BB00-2AB2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XB205-3 (ST, E/IP) (6GK5205-3BD00-2TB2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XB205-3 (ST, E/IP) (6GK5205-3BB00-2TB2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XB205-3 (ST, PN) (6GK5205-3BD00-2AB2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XB205-3LD (SC, E/IP) (6GK5205-3BF00-2TB2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XB205-3LD (SC, PN) (6GK5205-3BF00-2AB2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XB208 (E/IP) (6GK5208-0BA00-2TB2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XB208 (PN) (6GK5208-0BA00-2AB2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XB213-3 (SC, E/IP) (6GK5213-3BD00-2TB2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XB213-3 (SC, PN) (6GK5213-3BD00-2AB2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XB213-3 (ST, E/IP) (6GK5213-3BB00-2TB2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XB213-3 (ST, PN) (6GK5213-3BB00-2AB2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XB213-3LD (SC, E/IP) (6GK5213-3BF00-2TB2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XB213-3LD (SC, PN) (6GK5213-3BF00-2AB2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XB216 (E/IP) (6GK5216-0BA00-2TB2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XB216 (PN) (6GK5216-0BA00-2AB2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC206-2 (SC) (6GK5206-2BD00-2AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC206-2 (ST/BFOC) (6GK5206-2BB00-2AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC206-2G PoE (6GK5206-2RS00-2AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC206-2G PoE (54 V DC) (6GK5206-2RS00-5AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC206-2G PoE EEC (54 V DC) (6GK5206-2RS00-5FC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC206-2SFP (6GK5206-2BS00-2AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC206-2SFP EEC (6GK5206-2BS00-2FC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC206-2SFP G (6GK5206-2GS00-2AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC206-2SFP G (EIP DEF.) (6GK5206-2GS00-2TC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC206-2SFP G EEC (6GK5206-2GS00-2FC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC208 (6GK5208-0BA00-2AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC208EEC (6GK5208-0BA00-2FC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC208G (6GK5208-0GA00-2AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC208G (EIP def.) (6GK5208-0GA00-2TC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC208G EEC (6GK5208-0GA00-2FC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC208G PoE (6GK5208-0RA00-2AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC208G PoE (54 V DC) (6GK5208-0RA00-5AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC216 (6GK5216-0BA00-2AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC216-3G PoE (6GK5216-3RS00-2AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC216-3G PoE (54 V DC) (6GK5216-3RS00-5AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC216-4C (6GK5216-4BS00-2AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC216-4C G (6GK5216-4GS00-2AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC216-4C G (EIP Def.) (6GK5216-4GS00-2TC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC216-4C G EEC (6GK5216-4GS00-2FC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC216EEC (6GK5216-0BA00-2FC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC224 (6GK5224-0BA00-2AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC224-4C G (6GK5224-4GS00-2AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC224-4C G (EIP Def.) (6GK5224-4GS00-2TC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XC224-4C G EEC (6GK5224-4GS00-2FC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XF204 (6GK5204-0BA00-2GF2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XF204 DNA (6GK5204-0BA00-2YF2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XF204-2BA (6GK5204-2AA00-2GF2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XF204-2BA DNA (6GK5204-2AA00-2YF2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XM408-4C (6GK5408-4GP00-2AM2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XM408-4C (L3 int.) (6GK5408-4GQ00-2AM2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XM408-8C (6GK5408-8GS00-2AM2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XM408-8C (L3 int.) (6GK5408-8GR00-2AM2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XM416-4C (6GK5416-4GS00-2AM2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XM416-4C (L3 int.) (6GK5416-4GR00-2AM2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XP208 (6GK5208-0HA00-2AS6) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XP208 (Ethernet/IP) (6GK5208-0HA00-2TS6) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XP208EEC (6GK5208-0HA00-2ES6) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XP208PoE EEC (6GK5208-0UA00-5ES6) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XP216 (6GK5216-0HA00-2AS6) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XP216 (Ethernet/IP) (6GK5216-0HA00-2TS6) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XP216EEC (6GK5216-0HA00-2ES6) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XP216POE EEC (6GK5216-0UA00-5ES6) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR324WG (24 x FE, AC 230V) (6GK5324-0BA00-3AR3) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR324WG (24 X FE, DC 24V) (6GK5324-0BA00-2AR3) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR326-2C PoE WG (6GK5326-2QS00-3AR3) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR326-2C PoE WG (without UL) (6GK5326-2QS00-3RR3) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR328-4C WG (24XFE, 4XGE, 24V) (6GK5328-4FS00-2AR3) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR328-4C WG (24xFE, 4xGE,DC24V) (6GK5328-4FS00-2RR3) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR328-4C WG (24xFE,4xGE,AC230V) (6GK5328-4FS00-3AR3) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR328-4C WG (24xFE,4xGE,AC230V) (6GK5328-4FS00-3RR3) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR328-4C WG (28xGE, AC 230V) (6GK5328-4SS00-3AR3) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR328-4C WG (28xGE, DC 24V) (6GK5328-4SS00-2AR3) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR524-8C, 1x230V (6GK5524-8GS00-3AR2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR524-8C, 1x230V (L3 int.) (6GK5524-8GR00-3AR2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR524-8C, 24V (6GK5524-8GS00-2AR2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR524-8C, 24V (L3 int.) (6GK5524-8GR00-2AR2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR524-8C, 2x230V (6GK5524-8GS00-4AR2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR524-8C, 2x230V (L3 int.) (6GK5524-8GR00-4AR2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR526-8C, 1x230V (6GK5526-8GS00-3AR2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR526-8C, 1x230V (L3 int.) (6GK5526-8GR00-3AR2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR526-8C, 24V (6GK5526-8GS00-2AR2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR526-8C, 24V (L3 int.) (6GK5526-8GR00-2AR2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR526-8C, 2x230V (6GK5526-8GS00-4AR2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR526-8C, 2x230V (L3 int.) (6GK5526-8GR00-4AR2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR528-6M (6GK5528-0AA00-2AR2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR528-6M (2HR2, L3 int.) (6GK5528-0AR00-2HR2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR528-6M (2HR2) (6GK5528-0AA00-2HR2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR528-6M (L3 int.) (6GK5528-0AR00-2AR2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR552-12M (6GK5552-0AA00-2AR2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR552-12M (2HR2, L3 int.) (6GK5552-0AR00-2AR2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR552-12M (2HR2) (6GK5552-0AA00-2HR2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SCALANCE XR552-12M (2HR2) (6GK5552-0AR00-2HR2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SIPLUS NET SCALANCE XC206-2 (6AG1206-2BB00-7AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SIPLUS NET SCALANCE XC206-2SFP (6AG1206-2BS00-7AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SIPLUS NET SCALANCE XC208 (6AG1208-0BA00-7AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions SIPLUS NET SCALANCE XC216-4C (6AG1216-4BS00-7AC2) (only affected by CVE-2022-46140, CVE-2022-46142, CVE-2022-46143): All versions.","CVE-2022-34821, CVE-2022-46140, CVE-2022-46142, CVE-2022-46143, CVE-2022-46144",7.6,High,"CWE-94, CWE-327, CWE-257, CWE-1284, CWE-664",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2320,12/12/2022,12/12/2022,2022,ICSA-22-346-05,Siemens PLM Help Server,Siemens,PLM Help Server,"The following versions of Siemens PLM Help Server, a documentation server, are affected: Version 4.2.",CVE-2022-44575,6.1,Medium,CWE-79,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2319,12/15/2022,12/15/2022,2022,ICSA-22-349-06,Siemens SIMATIC WinCC OA Ultralight Client,Siemens,SIMATIC WinCC OA Ultralight Client,"The following versions of Siemens SIMATIC WinCC OA, a human machine interface (HMI), are affected: SIMATIC WinCC OA V3.15: All versions SIMATIC WinCC OA V3.16: All versions prior to V3.16 P035 SIMATIC WinCC OA V3.17: All versions prior to V3.17 P024 SIMATIC WinCC OA V3.18: All versions prior to V3.18 P014.",CVE-2022-44731,5.4,Medium,CWE-88,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2318,12/15/2022,12/15/2022,2022,ICSA-22-349-07,Siemens Simcenter STAR-CCM+,Siemens,Simcenter STAR-CCM+,"The following versions of Siemens Simcenter STAR-CCM+, a computational fluid dynamics software, are affected: All versions.",CVE-2022-43517,7.8,High,CWE-732,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2317,12/15/2022,12/15/2022,2022,ICSA-22-349-08,Siemens Polarion ALM,Siemens,Polarion ALM,"The following versions of Siemens Polarion ALM, an application lifecycle management software, are affected: All versions.",CVE-2022-46265,5.4,Medium,CWE-74,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2316,12/15/2022,12/15/2022,2022,ICSA-22-349-09,Siemens Products affected by OpenSSL 3.0,Siemens,"Calibre ICE, Mcenter, SCALANCE X-200RNA switch family, SICAM GridPass, SIMATIC RTLS Locating Manager",The following products from Siemens are affected: Calibre ICE: Versions 2022.4 and after Mcenter: Versions 5.2.1.0 and after SCALANCE X-200RNA switch family: Versions 3.2.7 and after SICAM GridPass (6MD7711-2AA00-1EA0): Versions 1.80 and after SIMATIC RTLS Locating Manager (6GT2780-0DA00): Versions 2.13 and after.,"CVE-2022-3602, CVE-2022-3786",7.5,High,CWE-120,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2315,12/15/2022,12/15/2022,2022,ICSA-22-349-10,Siemens APOGEE/TALON Field Panels,Siemens,APOGEE PXC/TALON TC,The following products from Siemens are affected: APOGEE PXC Series (BACnet): All versions prior to 3.5.5 APOGEE PXC Series (P2 Ethernet): All versions prior to 2.8.20 TALON TC Series (BACnet): All versions prior to 3.5.5.,CVE-2020-28388,6.5,Medium,CWE-342,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2314,12/15/2022,12/15/2022,2022,ICSA-22-349-11,Siemens SIPROTEC 5 Devices,Siemens,SIPROTEC 5,The following products from Siemens are affected: SIPROTEC 5 6MD85 devices (CPU variant CP200): All versions SIPROTEC 5 6MD85 devices (CPU variant CP300): All versions SIPROTEC 5 6MD86 devices (CPU variant CP200): All versions SIPROTEC 5 6MD86 devices (CPU variant CP300): All versions SIPROTEC 5 6MD89 devices (CPU variant CP300): All versions SIPROTEC 5 6MU85 devices (CPU variant CP300): All versions SIPROTEC 5 7KE85 devices (CPU variant CP200): All versions SIPROTEC 5 7KE85 devices (CPU variant CP300): All versions SIPROTEC 5 7SA82 devices (CPU variant CP100): All versions SIPROTEC 5 7SA82 devices (CPU variant CP150): All versions SIPROTEC 5 7SA86 devices (CPU variant CP200): All versions SIPROTEC 5 7SA86 devices (CPU variant CP300): All versions SIPROTEC 5 7SA87 devices (CPU variant CP200): All versions SIPROTEC 5 7SA87 devices (CPU variant CP300): All versions SIPROTEC 5 7SD82 devices (CPU variant CP100): All versions SIPROTEC 5 7SD82 devices (CPU variant CP150): All versions SIPROTEC 5 7SD86 devices (CPU variant CP200): All versions SIPROTEC 5 7SD86 devices (CPU variant CP300): All versions SIPROTEC 5 7SD87 devices (CPU variant CP200): All versions SIPROTEC 5 7SD87 devices (CPU variant CP300): All versions SIPROTEC 5 7SJ81 devices (CPU variant CP100): All versions SIPROTEC 5 7SJ81 devices (CPU variant CP150): All versions SIPROTEC 5 7SJ82 devices (CPU variant CP100): All versions SIPROTEC 5 7SJ82 devices (CPU variant CP150): All versions SIPROTEC 5 7SJ85 devices (CPU variant CP200): All versions SIPROTEC 5 7SJ85 devices (CPU variant CP300): All versions SIPROTEC 5 7SJ86 devices (CPU variant CP200): All versions SIPROTEC 5 7SJ86 devices (CPU variant CP300): All versions SIPROTEC 5 7SK82 devices (CPU variant CP100): All versions SIPROTEC 5 7SK82 devices (CPU variant CP150): All versions SIPROTEC 5 7SK85 devices (CPU variant CP200): All versions SIPROTEC 5 7SK85 devices (CPU variant CP300): All versions SIPROTEC 5 7SL82 devices (CPU variant CP100): All versions SIPROTEC 5 7SL82 devices (CPU variant CP150): All versions SIPROTEC 5 7SL86 devices (CPU variant CP200): All versions SIPROTEC 5 7SL86 devices (CPU variant CP300): All versions SIPROTEC 5 7SL87 devices (CPU variant CP200): All versions SIPROTEC 5 7SL87 devices (CPU variant CP300): All versions SIPROTEC 5 7SS85 devices (CPU variant CP200): All versions SIPROTEC 5 7SS85 devices (CPU variant CP300): All versions SIPROTEC 5 7ST85 devices (CPU variant CP200): All versions SIPROTEC 5 7ST85 devices (CPU variant CP300): All versions SIPROTEC 5 7SX85 devices (CPU variant CP300): All versions SIPROTEC 5 7UM85 devices (CPU variant CP300): All versions SIPROTEC 5 7UT82 devices (CPU variant CP100): All versions SIPROTEC 5 7UT82 devices (CPU variant CP150): All versions SIPROTEC 5 7UT85 devices (CPU variant CP200): All versions SIPROTEC 5 7UT85 devices (CPU variant CP300): All versions SIPROTEC 5 7UT86 devices (CPU variant CP200): All versions SIPROTEC 5 7UT86 devices (CPU variant CP300): All versions SIPROTEC 5 7UT87 devices (CPU variant CP200): All versions SIPROTEC 5 7UT87 devices (CPU variant CP300): All versions SIPROTEC 5 7VE85 devices (CPU variant CP300): All versions SIPROTEC 5 7VK87 devices (CPU variant CP200): All versions SIPROTEC 5 7VK87 devices (CPU variant CP300): All versions SIPROTEC 5 Communication Module ETH-BA-2EL: All versions SIPROTEC 5 Communication Module ETH-BB-2FO: All versions SIPROTEC 5 Communication Module ETH-BD-2FO: All versions SIPROTEC 5 Compact 7SX800 devices (CPU variant CP050): All versions.,CVE-2022-45044,5.3,Medium,CWE-400,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2313,12/15/2022,12/15/2022,2022,ICSA-22-349-12,Siemens Parasolid,Siemens,Parasolid,The following products from Siemens are affected: Parasolid V33.1: All versions up to 33.1.264 Parasolid V34.0: All versions up to 34.0.252 Parasolid V34.1: All versions up to 34.1.242 Parasolid V35.0: All versions up to 35.0.170.,"CVE-2022-46345, CVE-2022-46346, CVE-2022-46347, CVE-2022-46348, CVE-2022-46349",7.8,High,"CWE-787, CWE-125",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2312,12/15/2022,12/15/2022,2022,ICSA-22-349-13,Siemens Mendix Workflow Commons,Siemens,Mendix Workflow Commons,The following Siemens products are affected: Mendix Workflow Commons: All versions prior to v2.4.0.,CVE-2022-46664,8.1,High,CWE-284,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2311,12/15/2022,12/15/2022,2022,ICSA-22-349-14,Siemens SISCO MMS-EASE Third Party Component,Siemens,SISCO MMS-EASE third party component,"The following Siemens products are affected by this third-party component vulnerability: SIPROTEC 5 6MD85 devices (CPU variants CP200, CP300): All versions prior to v7.80 SIPROTEC 5 6MD86 devices (CPU variants CP200, CP300): All versions prior to v7.80 SIPROTEC 5 6MU89 devices (CPU variant CP300): All versions prior to v7.80 SIPROTEC 5 6MU85 devices (CPU variant CP300): All versions prior to v7.80 SIPROTEC 5 7KE85 devices (CPU variants CP200, CP300): All versions prior to v7.80 SIPROTEC 5 7SA82 devices (CPU variant CP100): All versions prior to v7.80 SIPROTEC 5 7SA86 devices (CPU variants CP200, CP300): All versions prior to v7.80 SIPROTEC 5 7SA87 devices (CPU variants CP200, CP300): All versions prior to v7.80 SIPROTEC 5 7SD82 devices (CPU variant CP100): All versions prior to v7.80 SIPROTEC 5 7SD86 devices (CPU variants CP200, CP300): All versions prior to v7.80 SIPROTEC 5 7SD87 devices (CPU variants CP200, CP300): All versions prior to v7.80 SIPROTEC 5 7SJ81 devices (CPU variant CP100): All versions prior to v7.80 SIPROTEC 5 7SJ82 devices (CPU variant CP100): All versions prior to v7.80 SIPROTEC 5 7SJ85 devices (CPU variants CP200, CP300): All versions prior to v7.80 SIPROTEC 5 7SJ86 devices (CPU variants CP200, CP300): All versions prior to v7.80 SIPROTEC 5 7SK82 devices (CPU variant CP100): All versions prior to v7.80 SIPROTEC 5 7SK85 devices (CPU variants CP200, CP300): All versions prior to v7.80 SIPROTEC 5 7SL82 devices (CPU variant CP100): All versions prior to v7.80 SIPROTEC 5 7SL86 devices (CPU variants CP200, CP300): All versions prior to v7.80 SIPROTEC 5 7SL87 devices (CPU variants CP200, CP300): All versions prior to v7.80 SIPROTEC 5 7SS85 devices (CPU variants CP200, CP300): All versions prior to v7.80 SIPROTEC 5 7ST85 devices (CPU variants CP200, CP300): All versions prior to v7.80 SIPROTEC 5 7SX85 devices (CPU variant CP300): All versions prior to v7.80 SIPROTEC 5 7UM85 devices (CPU variant CP300): All versions prior to v7.80 SIPROTEC 5 7UT82 devices (CPU variant CP100): All versions prior to v7.80 SIPROTEC 5 7UT85 devices (CPU variants CP200, CP300): All versions prior to v7.80 SIPROTEC 5 7UT86 devices (CPU variants CP200, CP300): All versions prior to v7.80 SIPROTEC 5 7UT87 devices (CPU variants CP200, CP300): All versions prior to v7.80 SIPROTEC 5 7VE85 devices (CPU variant CP300): All versions prior to v7.80 SIPROTEC 5 7VK87 devices (CPU variants CP200, CP300): All versions prior to v7.80 SIPROTEC 5 Communication Module ETH-BA-2EL: All versions prior to v7.80 SIPROTEC 5 Communication Module ETH-BB-2FO: All versions prior to v7.80 SIPROTEC 5 Communication Module USART-AB-1EL: All versions prior to v7.80 SIPROTEC 5 Communication Module USART-AC-2EL: All versions prior to v7.80 SIPROTEC 5 Communication Module USART-AD-1FO: All versions prior to v7.80 SIPROTEC 5 Communication Module USART-AE-2FO: All versions prior to v7.80.",CVE-2015-6574,7.5,High,CWE-399,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2310,12/15/2022,12/15/2022,2022,ICSA-22-349-15,Siemens Teamcenter Visualization and JT2Go,Siemens,Teamcenter Visualization and JT2Go,"Siemens reports the following viewing and lifecycle management products are affected because they contain the APDFL library from Datalogics, which is affected by these vulnerabilities: JT2Go: All versions prior to V14.1.0.5 Teamcenter Visualization V13.3: All versions prior to V13.3.0.8 Teamcenter Visualization V14.0: All versions prior to V14.0.0.4 Teamcenter Visualization V14.1: All versions prior to V14.1.0.5.","CVE-2022-3159, CVE-2022-3160, CVE-2022-3161",7.8,High,"CWE-121, CWE-122, CWE-119",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2309,12/15/2022,12/15/2022,2022,ICSA-22-349-16,Siemens APOGEE and TALON,Siemens,APOGEE and TALON,"The following versions of Siemens APOGEE PXC and TALON TC Series, a building automation and control systems, are affected: APOGEE PXC Series (BACnet): Versions prior to 3.5.5 APOGEE PXC Series (P2 Ethernet): Versions prior to 2.8.20 TALON TC Series (BACnet): Versions prior to 3.5.5.",CVE-2022-45937,8.8,High,CWE-284,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2308,12/15/2022,12/15/2022,2022,ICSA-22-349-17,Siemens Mendix Email Connector,Siemens,Mendix Email Connector,"The following versions of Siemens Mendix Email Connector, a software management platform, are affected: Mendix Email Connector: Versions prior to 2.0.",CVE-2022-45936,8.1,High,CWE-284,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2307,12/15/2022,12/15/2022,2022,ICSA-22-349-18,Siemens SCALANCE SC-600 Family,Siemens,SCALANCE SC-600 Family,"The following versions of Siemens SCALANCE SC-600 Family, a software management platform, are affected: SCALANCE SC622-2C (6GK5622-2GS00-2AC2): Versions prior to 3.0 SCALANCE SC626-2C (6GK5626-2GS00-2AC2): Versions prior to 3.0 SCALANCE SC632-2C (6GK5632-2GS00-2AC2): Versions prior to 3.0 SCALANCE SC636-2C (6GK5636-2GS00-2AC2): Versions prior to 3.0 SCALANCE SC642-2C (6GK5642-2GS00-2AC2): Versions prior to 3.0 SCALANCE SC646-2C (6GK5646-2GS00-2AC2): Versions prior to 3.0.","CVE-2022-25032, CVE-2022-30065, CVE-2022-32205, CVE-2022-32206",7.8,High,"CWE-787, CWE-416, CWE-770",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2306,12/15/2022,12/15/2022,2022,ICSA-22-349-19,Siemens SICAM PAS,Siemens,SICAM PAS,Siemens reports these vulnerabilities affect the following energy automation products for operating electrical substations: SICAM PAS/PQS: all versions prior to V7.0 SICAM PAS/PQS: all versions from and including 7.0 and prior to V8.06.,"CVE-2022-43722, CVE-2022-43723, CVE-2022-43724",8.8,High,"CWE-427, CWE-1287, CWE-319",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2305,12/15/2022,12/15/2022,2022,ICSA-22-349-20,Siemens Teamcenter Visualization and JT2Go,Siemens,Teamcenter Visualization and JT2Go,Siemens reports these vulnerabilities affect the following visualization and product lifecycle management tools: JT2Go: all versions Teamcenter Visualization V13.2: versions prior to V13.2.0.12 Teamcenter Visualization V13.3: versions prior to V13.3.0.8 Teamcenter Visualization V13.3: versions since and including V13.3.0.8 (CVE-2022-45484 only) Teamcenter Visualization V14.0: versions prior to V14.0.0.4 Teamcenter Visualization V14.0: versions since and including V14.0.0.4 (CVE-2022-45484 only) Teamcenter Visualization V14.1: versions prior to V14.1.0.6.,"CVE-2022-41278, CVE-2022-41279, CVE-2022-41280, CVE-2022-41283, CVE-2022-41281, CVE-2022-41282, CVE-2022-41284, CVE-2022-41286, CVE-2022-45484, CVE-2022-41285, CVE-2022-41287, CVE-2022-41288",7.8,High,"CWE-476, CWE-787, CWE-125, CWE-416, CWE-369, CWE-770",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2304,12/15/2022,12/15/2022,2022,ICSA-22-349-21,Siemens SCALANCE X-200RNA Switch Devices,Siemens,SCALANCE X-200RNA switch devices before V3.2.7,Siemens reports the following industrial ethernet network access points are affected because they use OpenSSL and OpenSSH (which are affected by these vulnerabilities): SCALANCE X204RNA (HSR) (6GK5204-0BA00-2MB2): All versions prior to V3.2.7 SCALANCE X204RNA (PRP) (6GK5204-0BA00-2KB2): All versions prior to V3.2.7 SCALANCE X204RNA EEC (HSR) (6GK5204-0BS00-2NA3): All versions prior to V3.2.7 SCALANCE X204RNA EEC (PRP) (6GK5204-0BS00-3LA3): All versions prior to V3.2.7 SCALANCE X204RNA EEC (PRP/HSR) (6GK5204-0BS00-3PA3): All versions prior to V3.2.7.,"CVE-2003-0190, CVE-2003-1562, CVE-2015-1791, CVE-2015-3196, CVE-2018-15473, CVE-2014-8176, CVE-2015-0287, CVE-2015-0292, CVE-2015-1789, CVE-2016-0778, CVE-2016-0799, CVE-2016-1907, CVE-2016-2108, CVE-2016-2176, CVE-2016-10012, CVE-2017-3735, CVE-2015-0207, CVE-2015-0293, CVE-2015-1787, CVE-2015-6563, CVE-2016-0705, CVE-2016-0797, CVE-2016-6302, CVE-2016-6305, CVE-2016-6515, CVE-2015-0208, CVE-2015-0288, CVE-2015-0289, CVE-2015-0290, CVE-2015-0291, CVE-2015-1790, CVE-2015-3194, CVE-2015-0209, CVE-2015-0285, CVE-2015-4000, CVE-2015-0286, CVE-2015-1788, CVE-2015-1792, CVE-2016-0798, CVE-2016-2109, CVE-2016-2179, CVE-2016-6308, CVE-2016-8858, CVE-2015-1794, CVE-2016-2181, CVE-2015-3193, CVE-2015-3195, CVE-2015-3197, CVE-2016-0701, CVE-2016-0702, CVE-2016-0703, CVE-2016-0704, CVE-2016-0777, CVE-2016-2107, CVE-2016-2183, CVE-2016-6210, CVE-2015-5352, CVE-2015-5600, CVE-2015-6564, CVE-2015-6565, CVE-2015-8325, CVE-2016-10010, CVE-2016-10011, CVE-2016-0800, CVE-2016-2182, CVE-2016-6303, CVE-2016-1908, CVE-2016-2105, CVE-2016-2106, CVE-2016-2177, CVE-2019-16905, CVE-2016-2178, CVE-2016-2180, CVE-2016-6306, CVE-2016-6304, CVE-2016-6307, CVE-2016-10009, CVE-2017-15906, CVE-2018-20685, CVE-2019-1552, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111",9.8,Critical,"CWE-200, CWE-264, CWE-787, CWE-287, CWE-190, CWE-203, CWE-125, CWE-401, CWE-400, CWE-426, CWE-732, CWE-863, CWE-295, CWE-116, CWE-838, CWE-22",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2303,12/13/2022,12/13/2022,2022,ICSA-22-347-01,ICONICS and Mitsubishi Electric Products,"ICONICS, Mitsubishi Electric",ICONICS Product Suite,"This vulnerability could affect the ICONICS Suite including GENESIS64, Hyper Historian, AnalytiX, and MobileHMI: Versions v10.96 to v10.97.2 Note: ICONICS version 10.97.2 CFR1 and later versions are not vulnerable to this vulnerability.",CVE-2022-40264,6.3,Medium,CWE-22,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2302,12/13/2022,12/13/2022,2022,ICSA-22-347-01,ICONICS and Mitsubishi Electric Products,"ICONICS, Mitsubishi Electric",ICONICS Product Suite,"This vulnerability could affect the ICONICS Suite including GENESIS64, Hyper Historian, AnalytiX, and MobileHMI: Versions v10.96 to v10.97.2 Note: ICONICS version 10.97.2 CFR1 and later versions are not vulnerable to this vulnerability.",CVE-2022-40264,6.3,Medium,CWE-22,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2301,12/13/2022,12/13/2022,2022,ICSA-22-347-02,Schneider Electric APC Easy UPS Online,Schneider Electric,APC Easy UPS Online,"The following versions of APC Easy UPS Online, an uninterruptible power supply (UPS) monitoring software, are affected: APC Easy UPS Online Version 2.5-GA and prior (Windows 7, 10, 11, Windows Server 2016, 2019, 2022) APC Easy UPS Online Version 2.5-GA-01-22261 and prior (Windows 11, Windows Server 2019, 2022).","CVE-2022-42970, CVE-2022-42971, CVE-2022-42972, CVE-2022-42973",9.8,Critical,"CWE-306, CWE-434, CWE-732, CWE-798",Multiple Critical Sectors,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2300,12/13/2022,1/17/2023,2022,ICSA-22-347-03,Contec CONPROSYS HMI System (CHS) (Update A),Contec,CONPROSYS HMI System (CHS),"The following versions of CONPROSYS HMI System (CHS), are affected: --------- Begin Update A part 3 of 5 --------- CVE-2022-44456 CONPROSYS HMI System (CHS): Ver.3.4.4 and prior CVE-2023-22331, CVE-2023-22334, CVE-2023-22373, CVE-2023-22339 CONPROSYS HMI System (CHS): Ver.3.4.5 and prior --------- End Update A part 3 of 5 ---------","CVE-2022-44456, CVE-2023-22331, CVE-2023-22334, CVE-2023-22373, CVE-2023-22339",10.0,Critical,"CWE-78, CWE-1392, CWE-836, CWE-79, CWE-284",Multiple Critical Sectors,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2299,12/8/2022,12/8/2022,2022,ICSA-22-342-01,Advantech iView,Advantech,iView,The following versions of Advantech iView management software are affected: Version 5.7.04.6469 and prior.,CVE-2022-3323,7.5,High,CWE-89,Multiple Critical Sectors,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2298,12/8/2022,3/16/2023,2022,ICSA-22-342-02,AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere (Update A),AVEVA,"InTouch Access Anywhere, Plant SCADA Access Anywhere",Begin Update A Part 4 of 6 --------- The following versions of AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere”both remote human machine interface (HMI) software”are affected: InTouch Access Anywhere: 2023 and prior Plant SCADA Access Anywhere: 2020 R2 and prior --------- End Update A Part 4 of 6.,"CVE-2022-23854, CVE-2021-3711, CVE-2020-11022",9.8,Critical,"CWE-23, CWE-120, CWE-79",Critical Manufacturing,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2297,12/8/2022,12/8/2022,2022,ICSA-22-342-03,Rockwell Automation Logix controllers,Rockwell Automation,"CompactLogix, Compact GuardLogix, ControlLogix, and GuardLogix controllers",The following Rockwell Automation controllers are affected: CompactLogix 5380 controllers: firmware version 31.011 and later Compact GuardLogix 5380 controllers: firmware version 31.011 and later CompactLogix 5480 controllers: firmware version 32.011 and later ControlLogix 5580 controllers: firmware version 31.011 and later GuardLogix 5580 controllers: firmware version 31.011 and later.,CVE-2022-3752,8.6,High,CWE-20,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2296,12/1/2022,12/1/2022,2022,ICSMA-22-335-01,BD BodyGuard Pumps,"Becton, Dickinson and Company (BD)",BodyGuard Pumps,The following BD BodyGuard products are affected: BD BodyGuard CME BodyGuard 323 (2nd Edition) CME BodyGuard 323 Color Vision (2nd Edition) CME BodyGuard 323 Color Vision (3rd Edition) CME BodyGuard Twins (2nd Edition).,CVE-2022-43557,5.3,Medium,CWE-1299,Healthcare and Public Health,Deployed outside the United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2295,12/1/2022,12/1/2022,2022,ICSA-22-335-01,Mitsubishi Electric MELSEC iQ-R Series,Mitsubishi Electric,MELSEC iQ-R Series,"The following Mitsubishi Electric MELSEC iQ-R Series products are affected: RJ71EN71: Firmware version ""65"" and prior R04/08/16/32/120ENCPU: Network part firmware version ""65"" and prior.",CVE-2022-40265,8.6,High,CWE-20,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2294,12/1/2022,12/1/2022,2022,ICSA-22-335-02,Horner Automation Remote Compact Controller,Horner Automation,Remote Compact Controller (RCC) 972,"The following version of Remote Compact Controller (RCC) 972, an all-in-one I/O controller, is affected: RCC 972: Firmware Version 15.40.","CVE-2022-2640, CVE-2022-2641, CVE-2022-2642",9.8,Critical,"CWE-326, CWE-321, CWE-1108",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2293,11/29/2022,11/29/2022,2022,ICSA-22-333-01,Mitsubishi Electric GOT2000,Mitsubishi Electric,GOT2000 Series,The following Mitsubishi Electric GOT2000 Series products are affected: GT27 Model: FTP server versions 01.39.000 and prior GT25 Model: FTP server versions 01.39.000 and prior GT23 Model: FTP server versions 01.39.000 and prior.,CVE-2022-40266,5.3,Medium,CWE-20,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2292,11/29/2022,7/23/2024,2022,ICSA-22-333-02,Hitachi Energy IED Connectivity Packages and PCM600 Products (Update A),Hitachi Energy,PCM600,"The following versions of Hitachi Energy's IED Connectivity Packages and PCM600 products are affected: PCM600: v2.11 and previous versions, including hotfixes 670 Connectivity Package: versions from 3.0 to 3.4.1 650 Connectivity Package: versions from 1.3 to 2.4.1 SAM600-IO Connectivity Package: versions from 1.0 to 1.2 GMS600 Connectivity Package: versions from 1.3 to 1.3.1 PWC600 Connectivity Package: versions from 1.1 to 1.3.",CVE-2022-2513,7.1,High,CWE-312,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2291,11/29/2022,11/9/2023,2022,ICSA-22-333-03,Hitachi Energy MicroSCADA Pro/X SYS600 Products (Update A),Hitachi Energy,"MicroSCADA X SYS600, MicroSCADA Pro",The following versions of Hitachi Energy's MicroSCADA Pro/X SYS600 products are affected: SYS600: 10.4 and earlier SYS600: 9.4 FP2 Hotfix 4 and earlier,CVE-2022-3388,8.8,High,CWE-1173,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2290,11/29/2022,2/23/2023,2022,ICSA-22-333-04,Moxa UC Series (Update A),Moxa,UC Series,"The following bootloader versions of Moxa UC Series, industrial internet-of-things (IIoT) gateway devices, are affected: UC-8580 Series: V1.1 UC-8540 Series: V1.0 to V1.2 UC-8410A Series: V2.2 UC-8200 Series: V1.0 to V2.4 UC-8100A-ME-T Series: V1.0 to V1.1 --------- Begin Update A part 1 of 1 --------- UC-8100 Series: V1.2 --------- End Update A part 1 of 1 --------- UC-5100 Series: V1.2 UC-3100 Series: V1.2 to V2.0 UC-2100 Series: V1.3 to V1.5 UC-2100-W Series: V1.3 to V1.5.",CVE-2022-3086,7.6,High,CWE-1263,Multiple Critical Sectors,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2289,12/5/2022,11/25/2025,2022,ICSA-22-333-05,Mitsubishi Electric FA Engineering Software (Update C),Mitsubishi Electric,"GX Works3, MX OPC UA Module Configurator-R, GX Works2, GX Developer, GT Designer3 Version1 (GOT2000), Motion Control Setting, MT Works2","The following versions of Mitsubishi Electric FA Engineering Software are affected: GX Works3: 1.000A to 1.011M (affected by CVE-2022-25164, CVE-2022-29825, CVE-2022-29826, CVE-2022-29827, CVE-2022-29828, CVE-2022-29829, and CVE-2022-29830). GX Works3: 1.015R to 1.087R (affected by CVE-2022-25164, CVE-2022-29825, CVE-2022-29826, CVE-2022-29827, CVE-2022-29828, CVE-2022-29829, CVE-2022-29830, CVE-2022-29831, CVE-2022-29832, and CVE-2022-29833). GX Works3: 1.090U (affected by CVE-2022-25164, CVE-2022-29825, CVE-2022-29827, CVE-2022-29828, CVE-2022-29829, CVE-2022-29830, CVE-2022-29831, CVE-2022-29832, and CVE-2022-29833). GX Works3: 1.095Z (affected by CVE-2022-25164, CVE-2022-29827, CVE-2022-29828, CVE-2022-29830, CVE-2022-29831, CVE-2022-29832, CVE-2022-29833). GX Works3: 1.096A and later (affected by CVE-2022-29827, CVE-2022-29828, CVE-2022-29832, CVE-2022-29833). MX OPC UA Module Configurator-R: 1.08J and prior (affected by CVE-2022-25164). GX Works2: All versions (affected by CVE-2022-29832). GX Developer: 8.40S or later (affected by CVE-2022-29832). GT Designer3 Version1 (GOT2000): 1.122C to 1.290C (affected by CVE-2022-29825 and CVE-2022-29829). Motion Control Settings (GX Works3 related software): 1.000A to 1.033K (affected by CVE-2022-29826 and CVE-2022-29830). Motion Control Settings (GX Works3 related software): 1.035M to 1.042U (affected by CVE-2022-29826, CVE-2022-29829, and CVE-2022-29830). Motion Control Settings (GX Works3 related software): 1.045X to 1.065T (affected by CVE-2022-29830). MT Works2: 1.100E to 1.200J (affected by CVE-2022-29825 and CVE-2022-29829).","CVE-2022-25164, CVE-2022-29825, CVE-2022-29826, CVE-2022-29827, CVE-2022-29828, CVE-2022-29829, CVE-2022-29830, CVE-2022-29831, CVE-2022-29832, CVE-2022-29833",9.1,Critical,"CWE-312, CWE-259, CWE-522, CWE-321, CWE-316",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2288,11/22/2022,11/22/2022,2022,ICSA-22-326-01,AVEVA Edge,AVEVA,Edge,"The following versions of AVEVA Edge, an HMI/SCADA software, are affected: AVEVA Edge 2020 R2 SP1 AVEVA Edge 2020 R2 SP1 w/ HF 2020.2.00.40 AVEVA Edge 2020 R2 and all prior versions (formerly known as InduSoft Web Studio).","CVE-2021-42797, CVE-2021-42796, CVE-2021-42794, CVE-2016-2542",9.8,Critical,"CWE-40, CWE-284, CWE-200, CWE-427",Critical Manufacturing,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2287,11/22/2022,11/22/2022,2022,ICSA-22-326-02,Digital Alert Systems DASDEC,Digital Alert Systems,DASDEC,"The following versions of DASDEC, an emergency communication system, are affected: Versions prior to 4.1 (CVE-2019-18265 only) All versions (CVE-2022-40204 only).","CVE-2022-40204, CVE-2019-18265",4.7,Medium,CWE-79,Communications; Emergency Services,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2286,11/22/2022,11/22/2022,2022,ICSA-22-326-03,Phoenix Contact Automation Worx,PHOENIX CONTACT,Automation Worx Software Suite,The following components of Automation Worx Software Suite are affected: Config+: Versions 1.89 and prior PC Worx: Versions 1.89 and prior PC Worx Express: Versions 1.89 and prior.,"CVE-2022-3737, CVE-2022-3461",7.8,High,"CWE-125, CWE-119",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2285,11/22/2022,11/22/2022,2022,ICSA-22-326-04,GE CIMPLICITY,GE,CIMPLICITY,"The following versions of CIMPLICITY, an HMI/SCADA software, are affected: CIMPLICITY: Versions 2022 and prior.","CVE-2022-3084, CVE-2022-2952, CVE-2022-2948, CVE-2022-2002, CVE-2022-3092",7.8,High,"CWE-824, CWE-122, CWE-822, CWE-787",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2284,11/22/2022,11/22/2022,2022,ICSA-22-326-05,Moxa Multiple ARM-Based Computers,Moxa,ARM-Based Computers,Moxa reports this vulnerability affects the following products and versions: UC-8100A-ME-T System Image: Versions v1.0 to v1.6 UC-2100 System Image: Versions v1.0 to v1.12 UC-2100-W System Image: Versions v1.0 to v 1.12 UC-3100 System Image: Versions v1.0 to v1.6 UC-5100 System Image: Versions v1.0 to v1.4 UC-8100 System Image: Versions v3.0 to v3.5 UC-8100-ME-T System Image: Versions v3.0 and v3.1 UC-8100A-ME-T System Image: Versions v1.0 to v1.6 UC-8200 System Image: v1.0 to v1.5 AIG-300 System Image: v1.0 to v1.4 UC-8410A with Debian 9 System Image: Versions v4.0.2 and v4.1.2 UC-8580 with Debian 9 System Image: Versions v2.0 and v2.1 UC-8540 with Debian 9 System Image: Versions v2.0 and v2.1 DA-662C-16-LX (GLB) System Image: Versions v1.0.2 to v1.1.2.,CVE-2022-3088,7.8,High,CWE-250,Critical Manufacturing; Energy; Transportation Systems,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2283,11/17/2022,11/17/2022,2022,ICSA-22-321-01,Red Lion Crimson,Red Lion Controls,Crimson,"The following versions of Crimson, a programming software for various controllers, HMIs, and modules are affected: Crimson 3.0: Version 707.000 and prior Crimson 3.1: Version 3126.001 and prior Crimson 3.2: Version 3.2.0044.0 and prior.",CVE-2022-3090,7.5,High,CWE-22,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2282,11/17/2022,11/17/2022,2022,ICSA-22-321-02,Cradlepoint IBR600,Cradlepoint,IBR600,The following versions of Cradlepoint IBR600 are affected: NetCloud OS (NCOS) Version: 6.5.0.160bc2e and prior.,CVE-2022-3086,7.1,High,CWE-77,Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2281,11/15/2022,11/15/2022,2022,ICSA-22-319-01,Mitsubishi Electric GT SoftGOT2000,Mitsubishi Electric,GT SoftGOT2000,Mitsubishi Electric reports this vulnerability affects OpenSSL in the following products: GT SoftGOT2000 1.275M”1.280S.,CVE-2022-2068,9.8,Critical,CWE-78,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2280,11/10/2022,11/10/2022,2022,ICSA-22-314-01,Siemens Parasolid,Siemens,Parasolid,Siemens reports these vulnerabilities affect the following Parasolid 3D geometric modeling tools: Parasolid V34.0: versions prior to V34.0.252 Parasolid V34.0: versions prior to V34.0.254 Parasolid V34.1: versions prior to V34.1.242 Parasolid V34.1: versions prior to V34.1.244 Parasolid V35.0: versions prior to V35.0.184 Parasolid V35.0: versions prior to V35.0.170.,"CVE-2022-39157, CVE-2022-43397",7.8,High,"CWE-125, CWE-787",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2279,11/10/2022,11/10/2022,2022,ICSA-22-314-03,Siemens SINEC Network Management System Logback Component,Siemens,SINEC NMS,"The following versions of Siemens SINEC NMS, a network management system, are affected: All versions prior to v1.0.3.",CVE-2021-42550,6.6,Medium,CWE-502,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2278,11/10/2022,12/15/2022,2022,ICSA-22-314-02,Siemens Web Server Login Page of Industrial Controllers (Update A),Siemens,SIMATIC Industrial Controllers and Software,The web server login pages of the following Siemens devices are affected: --------- Begin Update A Part 1 of 5 --------- SIMATIC Drive Controller family: All versions prior to V3.0.1. --------- End Update A Part 1 of 5 --------- SIMATIC ET 200pro IM154-8 PN/DP CPU (6ES7154-8AB01-0AB0): All versions prior to V3.2.19. SIMATIC ET 200pro IM154-8F PN/DP CPU (6ES7154-8FB01-0AB0): All versions prior to V3.2.19. SIMATIC ET 200pro IM154-8FX PN/DP CPU (6ES7154-8FX00-0AB0): All versions prior to V3.2.19. SIMATIC ET 200S IM151-8 PN/DP CPU (6ES7151-8AB01-0AB0): All versions prior to V3.2.19. SIMATIC ET 200S IM151-8F PN/DP CPU (6ES7151-8FB01-0AB0): All versions prior to V3.2.19. SIMATIC PC Station: All versions V2.1 and later. SIMATIC S7-300 CPU 314C-2 PN/DP (6ES7314-6EH04-0AB0): All versions prior to V3.3.19. SIMATIC S7-300 CPU 315-2 PN/DP (6ES7315-2EH14-0AB0): All versions prior to V3.2.19. SIMATIC S7-300 CPU 315F-2 PN/DP (6ES7315-2FJ14-0AB0): All versions prior to V3.2.19. SIMATIC S7-300 CPU 315T-3 PN/DP (6ES7315-7TJ10-0AB0): All versions prior to V3.2.19. SIMATIC S7-300 CPU 317-2 PN/DP (6ES7317-2EK14-0AB0): All versions prior to V3.2.19. SIMATIC S7-300 CPU 317F-2 PN/DP (6ES7317-2FK14-0AB0): All versions prior to V3.2.19. SIMATIC S7-300 CPU 317T-3 PN/DP (6ES7317-7TK10-0AB0): All versions prior to V3.2.19. SIMATIC S7-300 CPU 317TF-3 PN/DP (6ES7317-7UL10-0AB0): All versions prior to V3.2.19. SIMATIC S7-300 CPU 319-3 PN/DP (6ES7318-3EL01-0AB0): All versions prior to V3.2.19. SIMATIC S7-300 CPU 319F-3 PN/DP (6ES7318-3FL01-0AB0): All versions prior to V3.2.19. SIMATIC S7-400 PN/DP V6 CPU family (incl. SIPLUS variants): All versions. SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants): All versions. SIMATIC S7-1200 CPU family (incl. SIPLUS variants): All versions. --------- Begin Update A Part 2 of 5 --------- SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions prior to V3.0.1. --------- End Update A Part 2 of 5 --------- SIMATIC S7-1500 Software Controller: All versions. --------- Begin Update A Part 3 of 5 --------- SIMATIC S7-PLCSIM Advanced: All versions prior to V5.0 --------- End Update A Part 3 of 5 --------- SIMATIC S7-PLCSIM Advanced: All versions. SIMATIC WinCC Runtime Advanced: All versions. SINUMERIK ONE: All versions. SIPLUS ET 200S IM151-8 PN/DP CPU (6AG1151-8AB01-7AB0): All versions prior to V3.2.19. SIPLUS ET 200S IM151-8F PN/DP CPU (6AG1151-8FB01-2AB0): All versions prior to V3.2.19. SIPLUS S7-300 CPU 314C-2 PN/DP (6AG1314-6EH04-7AB0): All versions prior to V3.3.19. SIPLUS S7-300 CPU 315-2 PN/DP (6AG1315-2EH14-7AB0): All versions prior to V3.2.19. SIPLUS S7-300 CPU 315F-2 PN/DP (6AG1315-2FJ14-2AB0): All versions prior to V3.2.19. SIPLUS S7-300 CPU 317-2 PN/DP (6AG1317-2EK14-7AB0): All versions prior to V3.2.19. SIPLUS S7-300 CPU 317F-2 PN/DP (6AG1317-2FK14-2AB0): All versions prior to V3.2.19.,CVE-2022-30694,6.5,Medium,CWE-352,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2277,11/10/2022,11/10/2022,2022,ICSA-22-314-04,Siemens SINUMERIK ONE and SINUMERIK MC,Siemens,SINUMERIK ONE and SINUMERIK MC,The following versions of SINUMERIK CNC systems are affected: SINUMERIK ONE All Versions SINUMERIK MC All Versions.,CVE-2022-38465,9.3,Critical,CWE-522,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2276,11/10/2022,11/10/2022,2022,ICSA-22-314-05,Siemens RUGGEDCOM ROS,Siemens,RUGGEDCOM ROS,Siemens reports this vulnerability affects the following RUGGEDCOM ROS switches and serial-to-Ethernet devices: RUGGEDCOM ROS i800 V4.X: All versions RUGGEDCOM ROS i801 V4.X: All versions RUGGEDCOM ROS i802 V4.X: All versions RUGGEDCOM ROS i803 V4.X: All versions RUGGEDCOM ROS RMC30 V4.X: All versions RUGGEDCOM ROS RMC8388 V4.X: All versions RUGGEDCOM ROS RP110 V4.X: All versions RUGGEDCOM ROS RS1600 V4.X: All versions RUGGEDCOM ROS RS1600F V4.X: All versions RUGGEDCOM ROS RS1600T V4.X: All versions RUGGEDCOM ROS RS400 V4.X: All versions RUGGEDCOM ROS RS401 V4.X: All versions RUGGEDCOM ROS RS416Pv2 V4.X: All versions RUGGEDCOM ROS RS416v2 V4.X: All versions RUGGEDCOM ROS RS8000 V4.X: All versions RUGGEDCOM ROS RS8000A V4.X: All versions RUGGEDCOM ROS RS8000H V4.X: All versions RUGGEDCOM ROS RS8000T V4.X: All versions RUGGEDCOM ROS RS900 (32M) V4.X: All versions RUGGEDCOM ROS RS900 V4.X: All versions RUGGEDCOM ROS RS900G (32M) V4.X: All versions RUGGEDCOM ROS RS900G V4.X: All versions RUGGEDCOM ROS RS900GP V4.X: All versions RUGGEDCOM ROS RS900L V4.X: All versions RUGGEDCOM ROS RS900M V4.X: All versions RUGGEDCOM ROS RS900W V4.X: All versions RUGGEDCOM ROS RS910 V4.X: All versions RUGGEDCOM ROS RS910L V4.X: All versions RUGGEDCOM ROS RS910W V4.X: All versions RUGGEDCOM ROS RS920L V4.X: All versions RUGGEDCOM ROS RS920W V4.X: All versions RUGGEDCOM ROS RS930L V4.X: All versions RUGGEDCOM ROS RS930W V4.X: All versions RUGGEDCOM ROS RS940G V4.X: All versions RUGGEDCOM ROS RSG2100 (32M) V4.X: All versions RUGGEDCOM ROS RSG2100 V4.X: All versions RUGGEDCOM ROS RSG2100P V4.X: All versions RUGGEDCOM ROS RSG2200 V4.X: All versions RUGGEDCOM ROS RSG2288 V4.X: All versions RUGGEDCOM ROS RSG2300 V4.X: All versions RUGGEDCOM ROS RSG2300P V4.X: All versions RUGGEDCOM ROS RSG2488 V4.X: All versions RUGGEDCOM ROS RSG920P V4.X: All versions.,CVE-2022-39158,5.3,Medium,CWE-400,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2275,11/10/2022,11/10/2022,2022,ICSA-22-314-06,Siemens QMS Automotive,Siemens,QMS Automotive,"The following versions of Siemens QMS Automotive, a quality management system, are affected: All versions.",CVE-2022-43958,7.6,High,CWE-316,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2274,11/10/2022,11/10/2022,2022,ICSA-22-314-07,Omron NJ/NX-series Machine Automation Controllers,Omron,NJ/NX-series Machine Automation Controllers,The following products of the NJ/NX-series Machine Automation Controllers are affected: NX7-series Machine Automation Controller (All Models): Versions 1.28 and prior NX1-series Machine Automation Controller (All Models): Versions 1.48 and prior NJ-series Machine Automation Controller (All Models): Versions 1.48 and prior.,CVE-2022-33971,8.3,High,CWE-489,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2273,11/10/2022,11/10/2022,2022,ICSA-22-314-08,Omron NJNX-series,Omron,NJ/NX-series Controllers and Software,"The following versions of NJ/NX-series, a machine automation controller, are affected: NX7-series Machine Automation Controller (All Models): Versions 1.28 and prior NX1-series Machine Automation Controller (All Models): Versions 1.48 and prior NJ-series Machine Automation Controller (All Models): Versions 1.48 and prior Automation Software Sysmac Studio (All Models): Versions 1.49 and prior NA-series Programable Terminal (NA5-15W, NA5-12W, NA5-9W, NA5-7W): Runtime versions 1.15 and prior.","CVE-2022-34151, CVE-2022-33208",9.4,Critical,"CWE-798, CWE-294",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2272,11/10/2022,12/15/2022,2022,ICSA-22-314-09,Siemens Teamcenter Visualization and JT2Go (Update A),Siemens,Teamcenter Visualization and JT2Go,"The following software from Siemens is affected: JT2Go: All versions prior to V14.1.0.4 --------- Begin Update A Part 1 of 2 --------- Teamcenter Visualization V13.3: All versions V13.3.0.7 and later, prior to V13.3.0.8 (only affected by CVE-2022-39136) --------- End Update A Part 1 of 2 --------- Teamcenter Visualization V13.3: All versions prior to V13.3.0.7 Teamcenter Visualization V14.0: All versions prior to V14.0.0.3 Teamcenter Visualization V14.1: All versions prior to V14.1.0.4.","CVE-2022-39136, CVE-2022-41660, CVE-2022-41661, CVE-2022-41662, CVE-2022-41663, CVE-2022-41664",7.8,High,"CWE-122, CWE-787, CWE-125, CWE-416, CWE-121",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2271,11/10/2022,11/10/2022,2022,ICSA-22-314-10,Siemens SCALANCE W1750D,Siemens,SCALANCE W1750D,"Siemens reports these vulnerabilities affect the following versions of SCALANCE W1750D, which is a brand-labeled access point device from Aruba: SCALANCE W1750D (JP) (6GK5750-2HX01-1AD0): All versions SCALANCE W1750D (ROW) (6GK5750-2HX01-1AA0): All versions SCALANCE W1750D (USA) (6GK5750-2HX01-1AB0): All versions.","CVE-2002-20001, CVE-2022-37885, CVE-2022-37886, CVE-2022-37887, CVE-2022-37888, CVE-2022-37889, CVE-2022-37890, CVE-2022-37891, CVE-2022-37892, CVE-2022-37896, CVE-2022-37893, CVE-2022-37894, CVE-2022-37895",9.8,Critical,"CWE-400, CWE-120, CWE-79, CWE-77, CWE-20",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2270,11/10/2022,11/10/2022,2022,ICSA-22-314-11,Siemens SICAM Q100,Siemens,SICAM Q100,Siemens reports these vulnerabilities affect the following SICAM Q100 products: POWER METER SICAM Q100 (7KG9501-0AA31-2AA1): prior to V2.50 POWER METER SICAM Q100 (7KG9501-0AA01-2AA1): prior to V2.50.,"CVE-2022-43398, CVE-2022-43439, CVE-2022-43545, CVE-2022-43546",9.9,Critical,"CWE-384, CWE-20",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2269,11/3/2022,12/3/2024,2022,ICSA-22-307-01,ETIC Telecom Remote Access Server (RAS) (Update B),ETIC Telecom,Remote Access Server (RAS),"ETIC Telecom Remote Access Server (RAS) is used to manage connections between the machine network of the industrial site and the operator who has to perform remote maintenance from his PC or smartphone. The following versions of ETIC Telecom Remote Access Server (RAS), are affected: ETIC Telecom RAS: All versions prior to 4.5.0 (CVE-2022-3703, CVE-2022-41607, CVE-2022-40981, CVE-2024-26155, CVE-2024-26154, CVE-2024-26157, CVE-2024-26156), ETIC Telecom RAS: All versions prior to 4.11.0 (CVE-2024-26153).","CVE-2022-3703, CVE-2022-41607, CVE-2022-40981, CVE-2024-26156, CVE-2024-26157, CVE-2024-26154, CVE-2024-26155, CVE-2024-26153",6.3,Medium,"CWE-345, CWE-22, CWE-434, CWE-79, CWE-319, CWE-352",Communications; Information Technology; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2268,11/3/2022,11/3/2022,2022,ICSA-22-307-02,Nokia ASIK AirScale System Module,Nokia,ASIK AirScale 5G Common System Module,"The following versions of Nokia ASIK AirScale, a baseband unit, are affected: ASIK 474021A.101 ASIK 474021A.102 (not affected by CVE-2022-2484).","CVE-2022-2482, CVE-2022-2484, CVE-2022-2483",8.4,High,"CWE-1274, CWE-1282",Communications,Worldwide,Finland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2267,11/3/2022,11/3/2022,2022,ICSA-22-307-03,Delta Industrial Automation DIALink,Delta Electronics,DIALink,Delta Electronics Industrial Automation reports this vulnerability affects the following DIALink products: DIALink versions prior to v1.5.0.0 Beta 4.,CVE-2022-2969,8.1,High,CWE-22,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2266,10/27/2022,10/27/2022,2022,ICSA-22-300-01,Rockwell Automation FactoryTalk Alarm and Events Server,Rockwell Automation,FactoryTalk Alarm and Events Server,Rockwell Automation reports this vulnerability affects the following FactoryTalk Alarm and Events Server: FactoryTalk Alarm and Events Server: All versions.,CVE-2022-38744,7.5,High,CWE-284,Chemical; Critical Manufacturing; Food and Agriculture; Water and Wastewater System,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2265,10/27/2022,10/27/2022,2022,ICSA-22-300-02,SAUTER Controls moduWeb,SAUTER Controls,moduWeb,"The following version of SAUTER moduWeb firmware, web services used to monitor Building and Control networks and devices, are affected: SAUTER moduWeb firmware Version 2.7.1.",CVE-2022-40190,8.8,High,CWE-79,Critical Manufacturing; Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2264,10/27/2022,10/27/2022,2022,ICSA-22-300-03,Rockwell Automation Stratix Devices Containing Cisco IOS,Rockwell Automation,Stratix Devices,"The following versions of Stratix Devices, industrial ethernet switches, and the contained Cisco software are affected: Cisco IOS XE and Cisco IOS software contained in: Stratix 5800 switches: All versions prior to v16.12.01 Stratix 5400/5410 switches: All versions prior to v15.2(7)E2 (CVE-2020-3200 only)","CVE-2020-3229, CVE-2020-3219, CVE-2021-1446, CVE-2020-3200, CVE-2020-3211, CVE-2020-3218, CVE-2020-3209, CVE-2021-1385, CVE-2020-3516",8.8,High,"CWE-863, CWE-20, CWE-754, CWE-436, CWE-78, CWE-347, CWE-22",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2263,10/27/2022,10/27/2022,2022,ICSA-22-300-04,Trihedral VTScada,Trihedral,VTScada,The following versions of VTScada software are affected: VTScada Versions 12.0.38 and prior configured to accept incoming HTTP(S) connections.,CVE-2022-3181,7.5,High,CWE-20,Energy; Water and Wastewater,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2262,10/25/2022,10/25/2022,2022,ICSMA-22-298-01,AliveCor KardiaMobile,AliveCor,KardiaMobile,"The following versions of KardiaMobile, a smartphone-based personal electrocardiogram (EKG) device, are affected: Kardia App Android application Version 5.17.1-754993421 and prior (affected only by CVE-[CWE-302]) KardiaMobile IoT device, all versions (affected only by CVE-[CWE-311]).","CVE-2022-40703, CVE-2022-41627",5.2,Medium,"CWE-302, CWE-311",Healthcare and Public Health,"North America, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2261,10/25/2022,10/25/2022,2022,ICSA-22-298-01,Haas Controller,"Haas Automation, Inc",Haas Controller,"The following versions of the Haas Controller, a Computer Numerical Control (CNC), are affected: Haas Controller: Version 100.20.000.1110.","CVE-2022-2474, CVE-2022-2475, CVE-2022-41636",9.8,Critical,"CWE-306, CWE-1220, CWE-319",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2260,10/25/2022,9/30/2025,2022,ICSA-22-298-02,HEIDENHAIN Controller TNC (Update A),HEIDENHAIN,HEIDENHAIN TNC 640,HEIDENHAIN reports the following products are affected: HEIDENHAIN Controller TNC 640 NC Software: Version 340590 07 SP5.,CVE-2022-41648,9.2,Critical,CWE-1188,Critical Manufacturing; Communications; Energy; Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2259,10/25/2022,10/25/2022,2022,ICSA-22-298-03,Siemens Siveillance Video Mobile Server,Siemens,Siveillance Video 2022 R2,"The following versions of Siemens Siveillance Video, a mobile server, are affected: All versions prior to V22.2a(80).",CVE-2022-43400,9.4,Critical,CWE-1390,Communications; Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2258,10/25/2022,10/25/2022,2022,ICSA-22-298-04,Hitachi Energy MicroSCADA X DMS600,Hitachi Energy,DMS600,"The following Hitachi Energy product, integrated with MicroSCADA X, is affected: DMS600: Version 4.5.","CVE-2021-32027, CVE-2021-32028",8.8,High,CWE-1357,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2257,10/25/2022,10/25/2022,2022,ICSA-22-298-05,Johnson Controls CKS CEVAS,CKS (Subsidiary of Johnson Controls),CEVAS,"The following versions of CKS CEVAS, a deployment management and billing system, are affected: All CEVAS versions prior to 1.01.46.",CVE-2021-36206,10.0,Critical,CWE-79,Emergency Services,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2256,10/25/2022,2/16/2023,2022,ICSA-22-298-06,Delta Electronic DIAEnergie (Update B),Delta Electronics,DIAEnergie,"Delta Electronics reports the following versions of DIAEnergie, an industrial energy management system, are affected: DIAEnergie versions prior to v1.9.01.002 DIAEnergie versions prior to v1.9.02.001 --------- Begin Update B part 3 of 5 --------- DIAEnergie versions prior to v1.9.03.001 --------- End Update B part 3 of 5 ---------.","CVE-2022-41701, CVE-2022-40965, CVE-2022-41555, CVE-2022-41702, CVE-2022-41651, CVE-2022-40967, CVE-2022-41133, CVE-2022-41773, CVE-2022-41775, CVE-2022-43447, CVE-2022-43506, CVE-2022-43457, CVE-2022-43452, CVE-2023-0822",8.8,High,"CWE-79, CWE-89, CWE-285",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2255,10/25/2022,1/10/2023,2022,ICSA-22-298-07,Delta Electronics InfraSuite Device Master (Update A),Delta Electronics,InfraSuite Device Master,"The following versions of InfraSuite Device Master, a real-time device monitoring software, are affected: Version 00.00.01a and prior --------- Begin Update A part 1 of 2 --------- InfraSuite Device Master: Versions prior to 1.0.3 (CVE-2022-41657 and CVE-2022-40202 only) --------- End Update A part 1 of 2 ---------.","CVE-2022-41778, CVE-2022-38142, CVE-2022-41779, CVE-2022-41657, CVE-2022-41772, CVE-2022-40202, CVE-2022-41688, CVE-2022-41644, CVE-2022-41776, CVE-2022-41629",9.8,Critical,"CWE-502, CWE-22, CWE-306",Energy,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2254,10/20/2022,10/20/2022,2022,ICSA-22-293-01,Bentley Systems MicroStation Connect,Bentley Systems,MicroStation Connect,"The following versions of Bentley Systems MicroStation Connect, a software management platform, are affected: v10.17.0.209 and prior.","CVE-2022-40201, CVE-2022-41613",7.8,High,"CWE-121, CWE-125",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2253,10/18/2022,10/18/2022,2022,ICSA-22-291-01,Advantech R-SeeNet,Advantech,R-SeeNet,"The following versions of R-SeeNet, a software management platform, are affected: Version 2.4.19 and prior Version 2.4.17 and prior (CVE-2022-3386 and CVE-2022-3385 only).","CVE-2022-3387, CVE-2022-3386, CVE-2022-3385",9.8,Critical,"CWE-22, CWE-121",Critical Manufacturing; Energy; Water and Wastewater Systems,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2252,10/13/2022,10/13/2022,2022,ICSA-22-286-01,Siemens LOGO!,Siemens,LOGO!,"The following versions of LOGO!, a programmable logic controller, are affected: LOGO! 8 BM (including SIPLUS variants): All versions prior to 8.3.",CVE-2022-3636,6.1,Medium,CWE-345,Commercial Facilities; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2251,10/13/2022,10/13/2022,2022,ICSA-22-286-02,Siemens Industrial Edge Management,Siemens,Industrial Edge Management,"The following versions of Industrial Edge Management, an application and device management platform, are affected: All versions prior to V1.5.1.",CVE-2022-40147,7.4,High,CWE-295,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2250,10/13/2022,10/13/2022,2022,ICSA-22-286-03,Siemens Solid Edge,Siemens,Solid Edge,"The following versions of Siemens Solid Edge, a portfolio of software tools, are affected: Solid Edge: all versions prior to SE2022MP9.",CVE-2022-37864,7.8,High,CWE-122,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2249,10/13/2022,10/13/2022,2022,ICSA-22-286-04,Siemens SIMATIC S7-1200 and S7-1500 CPU Families,Siemens,SIMATIC S7-1200 and S7-1500 CPU families,Siemens reports this vulnerability affects the SIMATIC S7-1200 and S7-1500 CPU product families: SIMATIC Drive Controller family: All versions prior to 2.9.2 SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (including SIPLUS variants): All versions prior to 21.9 SIMATIC ET 200SP Open controller CPU 1515SP PC (including SIPLUS variants): All versions SIMATIC S7-1200 CPU family (including SIPLUS variants): All versions prior to V4.5.0 SIMATIC S7-1500 CPU family (including related ET200 CPUs and SIPLUS variants): All versions prior to 2.9.2 SIMATIC S7-1500 Software Controller: All version prior to 21.9 SIMCATIC S7-PLCSIM Advanced: All version prior to 4.0.,CVE-2022-38465,9.3,Critical,CWE-522,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2248,10/13/2022,10/13/2022,2022,ICSA-22-286-05,Hitachi Energy Lumada Asset Performance Management Prognostic Model Executor Service,Hitachi Energy,Lumada Asset Performance Manager (APM),The following versions of Lumada Asset Performance Manager with the Prognostic Model Executor Service enabled are affected: Lumada Asset Performance Manager (APM) online service (SaaS) version 6.3.220323.0 and prior Lumada Asset Performance Manager (APM) versions 6.0.0.0 to 6.0.0.4 Lumada Asset Performance Manager (APM) versions 6.1.0.0 and 6.1.0.1 Lumada Asset Performance Manager (APM) versions 6.2.0.0 to 6.2.0.2 Lumada Asset Performance Manager (APM) versions 6.3.0.0 to 6.3.0.2.,"CVE-2022-22950, CVE-2022-22965",7.5,High,"CWE-770, CWE-94",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2247,10/13/2022,10/13/2022,2022,ICSA-22-286-06,Siemens Desigo PXM Devices Webserver,Siemens,Desigo PXM Devices,The following Desigo devices contain the affected webserver: Desigo PXM30-1: All versions prior to V02.20.126.11-41 Desigo PXM30.E: All versions prior to V02.20.126.11-41 Desigo PXM40-1: All versions prior to V02.20.126.11-41 Desigo PXM40.E: All versions prior to V02.20.126.11-41 Desigo PXM50-1: All versions prior to V02.20.126.11-41 Desigo PXM50.E: All versions prior to V02.20.126.11-41 PXG3.W100-1: All versions prior to V02.20.126.11-37 PXG3.W100-2: All versions prior to V02.20.126.11-41 PXG3.W200-1: All versions prior to V02.20.126.11-37 PXG3.W200-2: All versions prior to V02.20.126.11-41.,"CVE-2022-40176, CVE-2022-40177, CVE-2022-40178, CVE-2022-40179, CVE-2022-40180, CVE-2022-40181, CVE-2022-40182",8.8,High,"CWE-78, CWE-200, CWE-79, CWE-352, CWE-84",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2246,10/13/2022,12/15/2022,2022,ICSA-22-286-07,Siemens Nucleus RTOS FTP Server (Update A),Siemens,Nucleus Real-Time Operating System (RTOS) FTP Server,The following Nucleus RTOS components contain the affected File Transport Protocol (FTP) server: Nucleus NET: All versions --------- Begin Update A Part 1 of 4 --------- Nucleus ReadyStart V3: All versions --------- End Update A Part 1 of 4 --------- Nucleus Source Code: Versions including affected FTP server.,CVE-2022-38371,7.5,High,CWE-400,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2245,10/13/2022,10/13/2022,2022,ICSA-22-286-08,Siemens TCP Event Service of SCALANCE and RUGGEDCOM Devices,Siemens,"SCALANCE, RUGGEDCOM","The following versions of Smart Security Manager, a software management platform, are affected: RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2): All versions prior to v7.1.2 RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2): All versions prior to v7.1.2 SCALANCE M804PB (6GK5804-0AP00-2AA2): All versions prior to v7.1.2 SCALANCE M812-1 ADSL-Router (Annex A) (6GK5812-1AA00-2AA2): All versions prior to v7.1.2 SCALANCE M812-1 ADSL-Router (Annex B) (6GK5812-1BA00-2AA2): All versions prior to v7.1.2 SCALANCE M816-1 ADSL-Router (Annex A) (6GK5816-1AA00-2AA2): All versions prior to v7.1.2 SCALANCE M816-1 ADSL-Router (Annex B) (6GK5816-1BA00-2AA2): All versions prior to v7.1.2 SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2): All versions prior to v7.1.2 SCALANCE M874-2 (6GK5874-2AA00-2AA2): All versions prior to v7.1.2 SCALANCE M874-3 (6GK5874-3AA00-2AA2): All versions prior to v7.1.2 SCALANCE M876-3 (EVDO) (6GK5876-3AA02-2BA2): All versions prior to v7.1.2 SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2): All versions prior to v7.1.2 SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2): All versions prior to v7.1.2 SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2): All versions prior to v7.1.2 SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1): All versions prior to v7.1.2 SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1): All versions prior to v7.1.2 SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1): All versions prior to v7.1.2 SCALANCE S615 (6GK5615-0AA00-2AA2): All versions prior to v7.1.2 SCALANCE WAM763-1 (6GK5763-1AL00-7DA0): All versions v1.1.0 and newer SCALANCE WAM766-1 (6GK5766-1GE00-7DA0): All versions v1.1.0 and newer SCALANCE WAM766-1 (6GK5766-1GE00-7DB0): All versions v1.1.0 and newer SCALANCE WAM766-1 6GHz (6GK5766-1JE00-7DA0): All versions v1.1.0 and newer SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0): All versions v1.1.0 and newer SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TB0): All versions v1.1.0 and newer SCALANCE WAM766-1 EEC 6GHz (6GK5766-1JE00-7TA0): All versions v1.1.0 and newer SCALANCE WUM763-1 (6GK5763-1AL00-3AA0): All versions v1.1.0 and newer SCALANCE WUM763-1 (6GK5763-1AL00-3DA0): All versions v1.1.0 and newer SCALANCE WUM766-1 (6GK5766-1GE00-3DA0): All versions v1.1.0 and newer SCALANCE WUM766-1 (6GK5766-1GE00-3DB0): All versions v1.1.0 and newer.",CVE-2022-31766,8.6,High,CWE-20,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2244,10/13/2022,12/15/2022,2022,ICSA-22-286-09,Siemens SICAM P850 and P855 Devices (Update A),Siemens,SICAM P850 and P855 devices,The following versions of Siemens SICAM P850 and P855 are affected: SICAM P850 (7KG8500-0AA00-0AA0): All versions prior to v3.10 SICAM P850 (7KG8500-0AA00-2AA0): All versions prior to v3.10 SICAM P850 (7KG8500-0AA10-0AA0): All versions prior to v3.10 SICAM P850 (7KG8500-0AA10-2AA0): All versions prior to v3.10 SICAM P850 (7KG8500-0AA30-0AA0): All versions prior to v3.10 SICAM P850 (7KG8500-0AA30-2AA0): All versions prior to v3.10 SICAM P850 (7KG8501-0AA01-0AA0): All versions prior to v3.10 SICAM P850 (7KG8501-0AA01-2AA0): All versions prior to v3.10 SICAM P850 (7KG8501-0AA02-0AA0): All versions prior to v3.10 SICAM P850 (7KG8501-0AA02-2AA0): All versions prior to v3.10 SICAM P850 (7KG8501-0AA11-0AA0): All versions prior to v3.10 SICAM P850 (7KG8501-0AA11-2AA0): All versions prior to v3.10 SICAM P850 (7KG8501-0AA12-0AA0): All versions prior to v3.10 SICAM P850 (7KG8501-0AA12-2AA0): All versions prior to v3.10 SICAM P850 (7KG8501-0AA31-0AA0): All versions prior to v3.10 SICAM P850 (7KG8501-0AA31-2AA0): All versions prior to v3.10 SICAM P850 (7KG8501-0AA32-0AA0): All versions prior to v3.10 SICAM P850 (7KG8501-0AA32-2AA0): All versions prior to v3.10 SICAM P855 (7KG8550-0AA00-0AA0): All versions prior to v3.10 SICAM P855 (7KG8550-0AA00-2AA0): All versions prior to v3.10 SICAM P855 (7KG8550-0AA10-0AA0): All versions prior to v3.10 SICAM P855 (7KG8550-0AA10-2AA0): All versions prior to v3.10 SICAM P855 (7KG8550-0AA30-0AA0): All versions prior to v3.10 SICAM P855 (7KG8550-0AA30-2AA0): All versions prior to v3.10 SICAM P855 (7KG8551-0AA01-0AA0): All versions prior to v3.10 SICAM P855 (7KG8551-0AA01-2AA0): All versions prior to v3.10 SICAM P855 (7KG8551-0AA02-0AA0): All versions prior to v3.10 SICAM P855 (7KG8551-0AA02-2AA0): All versions prior to v3.10 SICAM P855 (7KG8551-0AA11-0AA0): All versions prior to v3.10 SICAM P855 (7KG8551-0AA11-2AA0): All versions prior to v3.10 SICAM P855 (7KG8551-0AA12-0AA0): All versions prior to v3.10 SICAM P855 (7KG8551-0AA12-2AA0): All versions prior to v3.10 SICAM P855 (7KG8551-0AA31-0AA0): All versions prior to v3.10 SICAM P855 (7KG8551-0AA31-2AA0): All versions prior to v3.10 SICAM P855 (7KG8551-0AA32-0AA0): All versions prior to v3.10 SICAM P855 (7KG8551-0AA32-2AA0): All versions prior to v3.10.,"CVE-2022-40226, CVE-2022-41665",9.8,Critical,"CWE-384, CWE-141",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2243,10/13/2022,10/13/2022,2022,ICSA-22-286-10,Siemens JT Open Toolkit and Simcenter Femap,Siemens,JT Open Toolkit and Simcenter Femap,"Siemens reports the following versions of JT Open Toolkit (JTTK), an API for JT-enabled software; and Simcenter Femap, a modeling editing and simulation application, are affected: JTTK: versions prior to V11.1.1.0 Simcenter Femap V2022.1: versions prior to V2022.1.3 Simcenter Femap V2022.2: versions prior to V2022.2.2.",CVE-2022-41851,7.8,High,CWE-824,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2242,10/13/2022,12/15/2022,2022,ICSA-22-286-11,Siemens SCALANCE and RUGGEDCOM Products (Update B),Siemens,Multiple SCALANCE and RUGGEDCOM products,"The following types and versions of SCALANCE and RUGGEDCOM devices are affected: RUGGEDCOM RM1224 LTE(4G) EU (6GK6108- 4AM00-2BA2): All versions prior to V7.1.2 RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2): All versions prior to V7.1.2 SCALANCE M804PB (6GK5804-0AP00-2AA2): All versions prior to V7.1.2 SCALANCE M812-1 ADSL-Router (Annex A) (6GK5812-1AA00-2AA2): All versions prior to V7.1.2 SCALANCE M812-1 ADSL-Router (Annex B) (6GK5812-1BA00-2AA2): All versions prior to V7.1.2 SCALANCE M816-1 ADSL-Router (Annex A) (6GK5816-1AA00-2AA2): All versions prior to V7.1.2 SCALANCE M816-1 ADSL-Router (Annex B) (6GK5816-1BA00-2AA2): All versions prior to V7.1.2 SCALANCE M826-2 SHDSL-Router (6GK5826- 2AB00-2AB2): All versions prior to V7.1.2 SCALANCE M874-2 (6GK5874-2AA00-2AA2): All versions prior to V7.1.2 SCALANCE M874-3 (6GK5874-3AA00-2AA2): All versions prior to V7.1.2 SCALANCE M876-3 (EVDO) (6GK5876-3AA02- 2BA2): All versions prior to V7.1.2 SCALANCE M876-3 (ROK) (6GK5876-3AA02- 2EA2): All versions prior to V7.1.2 SCALANCE M876-4 (EU) (6GK5876-4AA00- 2BA2): All versions prior to V7.1.2 SCALANCE M876-4 (NAM) (6GK5876-4AA00- 2DA2): All versions prior to V7.1.2 SCALANCE MUM853-1 (EU) (6GK5853-2EA00- 2DA1): All versions prior to V7.1.2 SCALANCE MUM856-1 (EU) (6GK5856-2EA00- 3DA1): All versions prior to V7.1.2 SCALANCE MUM856-1 (RoW) (6GK5856- 2EA00-3AA1): All versions prior to V7.1.2 SCALANCE S615 (6GK5615-0AA00-2AA2): All versions prior to V7.1.2 --------- Begin Update B part 1 of 1 --------- SCALANCE SC622-2C (6GK5622-2GS00- 2AC2): All versions prior to V3.0 SCALANCE SC632-2C (6GK5632-2GS00- 2AC2): All versions prior to V3.0 SCALANCE SC636-2C (6GK5636-2GS00- 2AC2): All versions prior to V3.0 SCALANCE SC642-2C (6GK5642-2GS00- 2AC2): All versions prior to V3.0 SCALANCE SC646-2C (6GK5646-2GS00- 2AC2): All versions prior to V3.0 --------- End Update B part 1 of 1 --------- SCALANCE SC622-2C (6GK5622-2GS00- 2AC2): All versions SCALANCE SC632-2C (6GK5632-2GS00- 2AC2): All versions SCALANCE SC636-2C (6GK5636-2GS00- 2AC2): All versions SCALANCE SC642-2C (6GK5642-2GS00- 2AC2): All versions SCALANCE SC646-2C (6GK5646-2GS00- 2AC2): All versions SCALANCE W721-1 RJ45 (6GK5721-1FC00- 0AA0): All versions SCALANCE W721-1 RJ45 (6GK5721-1FC00- 0AB0): All versions SCALANCE W722-1 RJ45 (6GK5722-1FC00- 0AA0): All versions SCALANCE W722-1 RJ45 (6GK5722-1FC00- 0AB0): All versions SCALANCE W722-1 RJ45 (6GK5722-1FC00- 0AC0): All versions SCALANCE W734-1 RJ45 (6GK5734-1FX00- 0AA0): All versions SCALANCE W734-1 RJ45 (6GK5734-1FX00- 0AA6): All versions SCALANCE W734-1 RJ45 (6GK5734-1FX00- 0AB0): All versions SCALANCE W734-1 RJ45 (USA) (6GK5734- 1FX00-0AB6): All versions SCALANCE W738-1 M12 (6GK5738-1GY00- 0AA0): All versions SCALANCE W738-1 M12 (6GK5738-1GY00- 0AB0): All versions SCALANCE W748-1 M12 (6GK5748-1GD00- 0AA0): All versions SCALANCE W748-1 M12 (6GK5748-1GD00- 0AB0): All versions SCALANCE W748-1 RJ45 (6GK5748-1FC00- 0AA0): All versions SCALANCE W748-1 RJ45 (6GK5748-1FC00- 0AB0): All versions SCALANCE W761-1 RJ45 (6GK5761-1FC00- 0AA0): All versions SCALANCE W761-1 RJ45 (6GK5761-1FC00- 0AB0): All versions SCALANCE W774-1 M12 EEC (6GK5774-1FY00- 0TA0): All versions SCALANCE W774-1 M12 EEC (6GK5774-1FY00- 0TB0): All versions SCALANCE W774-1 RJ45 (6GK5774-1FX00- 0AA0): All versions SCALANCE W774-1 RJ45 (6GK5774-1FX00- 0AA6): All versions SCALANCE W774-1 RJ45 (6GK5774-1FX00- 0AB0): All versions SCALANCE W774-1 RJ45 (6GK5774-1FX00- 0AC0): All versions SCALANCE W774-1 RJ45 (USA) (6GK5774- 1FX00-0AB6): All versions SCALANCE W778-1 M12 (6GK5778-1GY00- 0AA0): All versions SCALANCE W778-1 M12 (6GK5778-1GY00- 0AB0): All versions SCALANCE W778-1 M12 EEC (6GK5778- 1GY00-0TA0): All versions SCALANCE W778-1 M12 EEC (USA) (6GK5778- 1GY00-0TB0): All versions SCALANCE W786-1 RJ45 (6GK5786-1FC00- 0AA0): All versions SCALANCE W786-1 RJ45 (6GK5786-1FC00- 0AB0): All versions SCALANCE W786-2 RJ45 (6GK5786-2FC00- 0AA0): All versions SCALANCE W786-2 RJ45 (6GK5786-2FC00- 0AB0): All versions SCALANCE W786-2 RJ45 (6GK5786-2FC00- 0AC0): All versions SCALANCE W786-2 SFP (6GK5786-2FE00- 0AA0): All versions SCALANCE W786-2 SFP (6GK5786-2FE00- 0AB0): All versions SCALANCE W786-2IA RJ45 (6GK5786-2HC00- 0AA0): All versions SCALANCE W786-2IA RJ45 (6GK5786-2HC00- 0AB0): All versions SCALANCE W788-1 M12 (6GK5788-1GD00- 0AA0): All versions SCALANCE W788-1 M12 (6GK5788-1GD00- 0AB0): All versions SCALANCE W788-1 RJ45 (6GK5788-1FC00- 0AA0): All versions SCALANCE W788-1 RJ45 (6GK5788-1FC00- 0AB0): All versions SCALANCE W788-2 M12 (6GK5788-2GD00- 0AA0): All versions SCALANCE W788-2 M12 (6GK5788-2GD00- 0AB0): All versions SCALANCE W788-2 M12 EEC (6GK5788- 2GD00-0TA0): All versions SCALANCE W788-2 M12 EEC (6GK5788- 2GD00-0TB0): All versions SCALANCE W788-2 M12 EEC (6GK5788- 2GD00-0TC0): All versions SCALANCE W788-2 RJ45 (6GK5788-2FC00- 0AA0): All versions SCALANCE W788-2 RJ45 (6GK5788-2FC00- 0AB0): All versions SCALANCE W788-2 RJ45 (6GK5788-2FC00- 0AC0): All versions SCALANCE W1748-1 M12 (6GK5748-1GY01- 0AA0): All versions SCALANCE W1748-1 M12 (6GK5748-1GY01- 0TA0): All versions SCALANCE W1788-1 M12 (6GK5788-1GY01- 0AA0): All versions SCALANCE W1788-2 EEC M12 (6GK5788- 2GY01-0TA0): All versions SCALANCE W1788-2 M12 (6GK5788-2GY01- 0AA0): All versions SCALANCE W1788-2IA M12 (6GK5788-2HY01- 0AA0): All versions SCALANCE WAM763-1 (6GK5763-1AL00- 7DA0): All versions SCALANCE WAM766-1 (6GK5766-1GE00- 7DA0): All versions SCALANCE WAM766-1 (6GK5766-1GE00- 7DB0): All versions SCALANCE WAM766-1 6GHz (6GK5766-1JE00- 7DA0): All versions SCALANCE WAM766-1 EEC (6GK5766-1GE00- 7TA0): All versions SCALANCE WAM766-1 EEC (6GK5766-1GE00- 7TB0): All versions SCALANCE WAM766-1 EEC 6GHz (6GK5766- 1JE00-7TA0): All versions SCALANCE WUM763-1 (6GK5763-1AL00- 3AA0): All versions SCALANCE WUM763-1 (6GK5763-1AL00- 3DA0): All versions SCALANCE WUM766-1 (6GK5766-1GE00- 3DA0): All versions SCALANCE WUM766-1 (6GK5766-1GE00- 3DB0): All versions SCALANCE WUM766-1 6GHz (6GK5766-1JE00- 3DA0): All versions SCALANCE XB205-3 (SC, PN) (6GK5205- 3BB00-2AB2): All versions SCALANCE XB205-3 (ST, E/IP) (6GK5205- 3BB00-2TB2): All versions SCALANCE XB205-3 (ST, E/IP) (6GK5205- 3BD00-2TB2): All versions SCALANCE XB205-3 (ST, PN) (6GK5205-3BD00- 2AB2): All versions SCALANCE XB205-3LD (SC, E/IP) (6GK5205- 3BF00-2TB2): All versions SCALANCE XB205-3LD (SC, PN) (6GK5205- 3BF00-2AB2): All versions SCALANCE XB208 (E/IP) (6GK5208-0BA00- 2TB2): All versions SCALANCE XB208 (PN) (6GK5208-0BA00- 2AB2): All versions SCALANCE XB213-3 (SC, E/IP) (6GK5213- 3BD00-2TB2): All versions SCALANCE XB213-3 (SC, PN) (6GK5213- 3BD00-2AB2): All versions SCALANCE XB213-3 (ST, E/IP) (6GK5213- 3BB00-2TB2): All versions SCALANCE XB213-3 (ST, PN) (6GK5213-3BB00- 2AB2): All versions SCALANCE XB213-3LD (SC, E/IP) (6GK5213- 3BF00-2TB2): All versions SCALANCE XB213-3LD (SC, PN) (6GK5213- 3BF00-2AB2): All versions SCALANCE XB216 (E/IP) (6GK5216-0BA00- 2TB2): All versions SCALANCE XB216 (PN) (6GK5216-0BA00- 2AB2): All versions SCALANCE XC206-2 (SC) (6GK5206-2BD00- 2AC2): All versions SCALANCE XC206-2 (ST/BFOC) (6GK5206- 2BB00-2AC2): All versions SCALANCE XC206-2G PoE (6GK5206-2RS00- 2AC2): All versions SCALANCE XC206-2G PoE (54 V DC) (6GK5206-2RS00-5AC2): All versions SCALANCE XC206-2G PoE EEC (54 V DC) (6GK5206-2RS00-5FC2): All versions SCALANCE XC206-2SFP (6GK5206-2BS00- 2AC2): All versions SCALANCE XC206-2SFP EEC (6GK5206- 2BS00-2FC2): All versions SCALANCE XC206-2SFP G (6GK5206-2GS00- 2AC2): All versions SCALANCE XC206-2SFP G (EIP DEF.) (6GK5206-2GS00-2TC2): All versions SCALANCE XC206-2SFP G EEC (6GK5206- 2GS00-2FC2): All versions SCALANCE XC208 (6GK5208-0BA00-2AC2): All versions SCALANCE XC208EEC (6GK5208-0BA00- 2FC2): All versions SCALANCE XC208G (6GK5208-0GA00-2AC2): All versions SCALANCE XC208G (EIP def.) (6GK5208- 0GA00-2TC2): All versions SCALANCE XC208G EEC (6GK5208-0GA00- 2FC2): All versions SCALANCE XC208G PoE (6GK5208-0RA00- 2AC2): All versions SCALANCE XC208G PoE (54 V DC) (6GK5208- 0RA00-5AC2): All versions SCALANCE XC216 (6GK5216-0BA00-2AC2): All versions SCALANCE XC216-3G PoE (6GK5216-3RS00- 2AC2): All versions SCALANCE XC216-3G PoE (54 V DC) (6GK5216-3RS00-5AC2): All versions SCALANCE XC216-4C (6GK5216-4BS00- 2AC2): All versions SCALANCE XC216-4C G (6GK5216-4GS00- 2AC2): All versions SCALANCE XC216-4C G (EIP Def.) (6GK5216- 4GS00-2TC2): All versions SCALANCE XC216-4C G EEC (6GK5216- 4GS00-2FC2): All versions SCALANCE XC216EEC (6GK5216-0BA00- 2FC2): All versions SCALANCE XC224 (6GK5224-0BA00-2AC2): All versions SCALANCE XC224-4C G (6GK5224-4GS00- 2AC2): All versions SCALANCE XC224-4C G (EIP Def.) (6GK5224- 4GS00-2TC2): All versions SCALANCE XC224-4C G EEC (6GK5224- 4GS00-2FC2): All versions SCALANCE XF204 (6GK5204-0BA00-2GF2): All versions SCALANCE XF204 DNA (6GK5204-0BA00- 2YF2): All versions SCALANCE XF204-2BA (6GK5204-2AA00- 2GF2): All versions SCALANCE XF204-2BA DNA (6GK5204-2AA00- 2YF2): All versions SCALANCE XM408-4C (6GK5408-4GP00- 2AM2): All versions SCALANCE XM408-4C (L3 int.) (6GK5408- 4GQ00-2AM2): All versions SCALANCE XM408-8C (6GK5408-8GS00- 2AM2): All versions SCALANCE XM408-8C (L3 int.) (6GK5408- 8GR00-2AM2): All versions SCALANCE XM416-4C (6GK5416-4GS00- 2AM2): All versions SCALANCE XM416-4C (L3 int.) (6GK5416- 4GR00-2AM2): All versions SCALANCE XP208 (6GK5208-0HA00-2AS6): All versions SCALANCE XP208 (Ethernet/IP) (6GK5208- 0HA00-2TS6): All versions SCALANCE XP208EEC (6GK5208-0HA00- 2ES6): All versions SCALANCE XP208PoE EEC (6GK5208-0UA00- 5ES6): All versions SCALANCE XP216 (6GK5216-0HA00-2AS6): All versions SCALANCE XP216 (Ethernet/IP) (6GK5216- 0HA00-2TS6): All versions SCALANCE XP216EEC (6GK5216-0HA00- 2ES6): All versions SCALANCE XP216POE EEC (6GK5216-0UA00- 5ES6): All versions SCALANCE XR324WG (24 x FE, AC 230V) (6GK5324-0BA00-3AR3): All versions SCALANCE XR324WG (24 X FE, DC 24V) (6GK5324-0BA00-2AR3): All versions SCALANCE XR326-2C PoE WG (6GK5326- 2QS00-3AR3): All versions SCALANCE XR326-2C PoE WG (without UL) (6GK5326-2QS00-3RR3): All versions SCALANCE XR328-4C WG (24xFE,4xGE, AC230V) (6GK5328-4FS00- 3AR3): All versions SCALANCE XR328-4C WG (24xFE,4xGE, AC230V) (6GK5328-4FS00- 3RR3): All versions SCALANCE XR328-4C WG (24XFE, 4XGE, 24V) (6GK5328-4FS00-2AR3): All versions SCALANCE XR328-4C WG (24xFE, 4xGE, DC24V) (6GK5328-4FS00-2RR3): All versions SCALANCE XR328-4C WG (28xGE, AC 230V) (6GK5328-4SS00-3AR3): All versions SCALANCE XR328-4C WG (28xGE, DC 24V) (6GK5328-4SS00-2AR3): All versions SCALANCE XR524-8C, 1x230V (6GK5524- 8GS00-3AR2): All versions SCALANCE XR524-8C, 1x230V (L3 int.) (6GK5524-8GR00-3AR2): All versions SCALANCE XR524-8C, 2x230V (6GK5524- 8GS00-4AR2): All versions SCALANCE XR524-8C, 2x230V (L3 int.) (6GK5524-8GR00-4AR2): All versions SCALANCE XR524-8C, 24V (6GK5524-8GS00- 2AR2): All versions SCALANCE XR524-8C, 24V (L3 int.) (6GK5524- 8GR00-2AR2): All versions SCALANCE XR526-8C, 1x230V (6GK5526- 8GS00-3AR2): All versions SCALANCE XR526-8C, 1x230V (L3 int.) (6GK5526-8GR00-3AR2): All versions SCALANCE XR526-8C, 1x230V (L3 int.) (6GK5526-8GR00-3AR2): All versions SCALANCE XR526-8C, 2x230V (L3 int.) (6GK5526-8GR00-4AR2): All versions SCALANCE XR526-8C, 24V (6GK5526-8GS00- 2AR2): All versions SCALANCE XR526-8C, 24V (L3 int.) (6GK5526- 8GR00-2AR2): All versions SCALANCE XR528-6M (6GK5528-0AA00- 2AR2): All versions SCALANCE XR528-6M (2HR2) (6GK5528- 0AA00-2HR2): All versions SCALANCE XR528-6M (2HR2, L3 int.) (6GK5528-0AR00-2HR2): All versions SCALANCE XR528-6M (L3 int.) (6GK5528- 0AR00-2AR2): All versions SCALANCE XR552-12M (6GK5552-0AA00- 2AR2): All versions SCALANCE XR552-12M (2HR2) (6GK5552- 0AA00-2HR2): All versions SCALANCE XR552-12M (2HR2) (6GK5552- 0AR00-2HR2): All versions SCALANCE XR552-12M (2HR2, L3 int.) (6GK5552-0AR00-2AR2): All versions SIPLUS NET SCALANCE XC206-2 (6AG1206- 2BB00-7AC2): All versions SIPLUS NET SCALANCE XC206-2SFP (6AG1206-2BS00-7AC2): All versions SIPLUS NET SCALANCE XC208 (6AG1208- 0BA00-7AC2): All versions SIPLUS NET SCALANCE XC216-4C (6AG1216- 4BS00-7AC2): All versions.",CVE-2022-31765,8.8,High,CWE-862,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2241,10/13/2022,10/13/2022,2022,ICSA-22-286-12,"Siemens APOGEE, TALON and Desigo PXC/PXM Products",Siemens,"FTP Server of Nucleus RTOS based APOGEE, TALON and Desigo PXC/PXM Products",Siemens reports this vulnerability affects the following products which use FTP Server of Nucleus RTOS: APOGEE MBC (PPC) (BACnet): All versions APOGEE MBC (PPC) (P2 Ethernet): All versions APOGEE MEC (PPC) (BACnet): All versions APOGEE MEC (PPC) (P2 Ethernet): All versions APOGEE PXC Compact (BACnet): All versions APOGEE PXC Compact (P2 Ethernet): All versions APOGEE PXC Modular (BACnet): All versions APOGEE PXC Modular (P2 Ethernet): All versions Desigo PXC00-E.D: All versions since and including V2.3 Desigo PXC00-U: All versions since and including V2.3 Desigo PXC001-E.D: All versions since and including V2.3 Desigo PXC12-E.D: All versions since and including V2.3 Desigo PXC22-E.D: All versions since and including V2.3 Desigo PXC22.1-E.D: All versions since and including V2.3 Desigo PXC36.1-E.D: All versions since and including V2.3 Desigo PXC50-E.D: All versions since and including V2.3 Desigo PXC64-U: All versions since and including V2.3 Desigo PXC100-E.D: All versions since and including V2.3 Desigo PXC128-U: All versions since and including V2.3 Desigo PXC200-E.D: All versions since and including V2.3 Desigo PXM20-E: All versions since and including V2.3 TALON TC Compact (BACnet): All versions TALON TC Modular (BACnet): All versions.,CVE-2022-38371,9.8,Critical,CWE-400,Commercial Facilities; Government Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2240,10/13/2022,10/13/2022,2022,ICSA-22-286-13,Siemens LOGO! 8 BM Devices,Siemens,LOGO! 8 BM Devices,Siemens reports these vulnerabilities affect the following LOGO! 8 BM (Base Module) devices: LOGO! 8 BM (incl. SIPLUS variants): All versions.,"CVE-2022-36361, CVE-2022-36362, CVE-2022-36363",9.8,Critical,"CWE-120, CWE-20, CWE-1285","Chemical, Energy; Food and Agriculture; Water and Wastewater Systems",Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2239,10/13/2022,10/13/2022,2022,ICSA-22-286-14,Siemens SIMATIC HMI Panels,Siemens,SIMATIC Human Machine Interface (HMI) Panels,The following versions of SIMATIC HMIs are affected: SIMATIC HMI Comfort Panels (incl. SIPLUS variants): All versions prior to V17 Update 4 SIMATIC HMI KTP400 Basic (6AV2123-2DB03-0AX0): All versions prior to V17 Update 5 SIMATIC HMI KTP700 Basic (6AV2123-2GB03-0AX0): All versions prior to V17 Update 5 SIMATIC HMI KTP900 Basic (6AV2123-2JB03-0AX0): All versions prior to V17 Update 5 SIMATIC HMI KTP1200 Basic (6AV2123-2MB03-0AX0): All versions prior to V17 Update 5 SIMATIC HMI KTP Mobile Panels: All versions prior to V17 Update 4 SIPLUS HMI KTP400 BASIC (6AG1123-2DB03-2AX0): All versions prior to V17 Update 5 SIPLUS HMI KTP700 BASIC (6AG1123-2GB03-2AX0): All versions prior to V17 Update 5 SIPLUS HMI KTP900 BASIC (6AG1123-2JB03-2AX0): All versions prior to V17 Update 5 SIPLUS HMI KTP1200 BASIC (6AG1123-2MB03-2AX0): All versions prior to V17 Update 5.,CVE-2022-40227,7.5,High,CWE-20,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2238,10/13/2022,11/10/2022,2022,ICSA-22-286-15,Siemens SCALANCE X-200 and X-200IRT Families (Update A),Siemens,SCALANCE X-200 and X-200IRT Families,"The following versions of SCALANCE X-200 and X-200IRT devices, industrial ethernet switches, are affected: SCALANCE X200-4P IRT (6GK5200-4AH00-2BA3): All versions prior to V5.5.0 SCALANCE X201-3P IRT (6GK5201-3BH00-2BA3): All versions prior to V5.5.0 SCALANCE X201-3P IRT PRO (6GK5201-3JR00-2BA6): All versions prior to V5.5.0 SCALANCE X202-2IRT (6GK5202-2BB10-2BA3): All versions prior to V5.5.0 SCALANCE X202-2P IRT (6GK5202-2BH00-2BA3): All versions prior to V5.5.0 SCALANCE X202-2P IRT PRO (6GK5202-2JR00-2BA6): All versions prior to V5.5.0 SCALANCE X204-2 (6GK5204-2BB10-2AA3): All versions prior to V5.2.5 SCALANCE X204-2FM (6GK5204-2BB11-2AA3): All versions prior to V5.2.5 SCALANCE X204-2LD (6GK5204-2BC10-2AA3): All versions prior to V5.2.5 SCALANCE X204-2LD TS (6GK5204-2BC10-2CA2): All versions prior to V5.2.5 SCALANCE X204-2TS (6GK5204-2BB10-2CA2): All versions prior to V5.2.5 SCALANCE X204IRT (6GK5204-0BA00-2BA3): All versions prior to V5.5.0 SCALANCE X204IRT PRO (6GK5204-0JA00-2BA6): All versions prior to V5.5.0 SCALANCE X206-1 (6GK5206-1BB10-2AA3): All versions prior to V5.2.5 SCALANCE X206-1LD (6GK5206-1BC10-2AA3): All versions prior to V5.2.5 SCALANCE X208 (6GK5208-0BA10-2AA3): All versions prior to V5.2.5 SCALANCE X208PRO (6GK5208-0HA10-2AA6): All versions prior to V5.2.5 SCALANCE X212-2 (6GK5212-2BB00-2AA3): All versions prior to V5.2.5 SCALANCE X212-2LD (6GK5212-2BC00-2AA3): All versions prior to V5.2.5 SCALANCE X216 (6GK5216-0BA00-2AA3): All versions prior to V5.2.5 SCALANCE X224 (6GK5224-0BA00-2AA3): All versions prior to V5.2.5 SCALANCE XF201-3P IRT (6GK5201-3BH00-2BD2): All versions prior to V5.5.0 SCALANCE XF202-2P IRT (6GK5202-2BH00-2BD2): All versions prior to V5.5.0 SCALANCE XF204 (6GK5204-0BA00-2AF2): All versions prior to V5.2.5 SCALANCE XF204-2 (6GK5204-2BC00-2AF2): All versions prior to V5.2.5 SCALANCE XF204-2BA IRT (6GK5204-2AA00-2BD2): All versions prior to V5.5.0 SCALANCE XF204IRT (6GK5204-0BA00-2BF2): All versions prior to V5.5.0 SCALANCE XF206-1 (6GK5206-1BC00-2AF2): All versions prior to V5.2.5 SCALANCE XF208 (6GK5208-0BA00-2AF2): All versions prior to V5.2.5 SIPLUS NET SCALANCE X202-2P IRT (6AG1202-2BH00-2BA3): All versions prior to V5.5.0.",CVE-2022-40631,9.6,Critical,CWE-79,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2237,10/13/2022,10/13/2022,2022,ICSA-22-286-16,Siemens Desigo CC and Cerberus DMS,Siemens,Desigo CC and Cerberus DMS,The following versions of Siemens management stations are affected: Desigo CC: All versions Desigo CC Compact: All versions Cerberus DMS: All versions.,CVE-2022-33139,9.8,Critical,CWE-603,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2236,10/11/2022,10/11/2022,2022,ICSA-22-284-01,Altair HyperView Player,Altair,HyperView Player,"The following versions of Altair HyperView Player, a standalone 3D viewer, are affected: HyperView Player: Versions 2021.1.0.27 and prior.","CVE-2022-2947, CVE-2022-2949, CVE-2022-2950, CVE-2022-2951",7.8,High,"CWE-119, CWE-908, CWE-129",Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2235,10/11/2022,10/11/2022,2022,ICSA-22-284-02,Daikin SVMPC1 and SVMPC2,Daikin Holdings Singapore Pte Ltd,"SVMPC1, SVMPC2","The following versions of Daikin Holdings Singapore Pte Ltd. SVMPC1 and SVMPC2, both an office and remote controller, are affected: SVMPC1: Version 2.1.22 and prior SVMPC2: Version 1.2.3 and prior.","CVE-2022-41653, CVE-2022-38355",9.8,Critical,"CWE-259, CWE-284",Energy,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2234,10/11/2022,10/11/2022,2022,ICSA-22-284-03,Sensormatic Electronics C-CURE 9000,Sensormatic Electronics LLC (Subsidiary of Johnson Controls),C-CURE 9000,Johnson Controls Inc. reports this vulnerability affects the following Sensormatic Electronics C-CURE 9000 security management systems: C-CURE 9000 version 2.90 and prior.,CVE-2021-36201,4.3,Medium,CWE-204,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2233,10/6/2022,10/6/2022,2022,ICSA-22-279-01,Rockwell Automation FactoryTalk VantagePoint,Rockwell Automation,FactoryTalk VantagePoint software,The following Rockwell Automation products are affected: FactoryTalk VantagePoint: Firmware versions prior to 8.0 FactoryTalk VantagePoint: Firmware versions between 8.0 and 8.10 FactoryTalk VantagePoint: Firmware versions between 8.10 and 8.20 FactoryTalk VantagePoint: Firmware versions between 8.20 and 8.30 FactoryTalk VantagePoint: Firmware versions between 8.30 and 8.31.,"CVE-2022-38743, CVE-2022-3158",9.9,Critical,"CWE-284, CWE-89",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2232,10/6/2022,10/6/2022,2022,ICSA-22-279-02,HIWIN Robot System Software (HRSS),HIWIN,HIWIN Robot System Software (HRSS),"The following version of HIWIN Robot System Software, a human-machine interface (HMI), is affected: HIWIN HRSS: version 3.3.21.9869.",CVE-2022-3382,7.5,High,CWE-284,Multiple Critical Sectors,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2231,10/4/2022,10/4/2022,2022,ICSA-22-277-01,Johnson Controls Metasys ADX Server,Johnson Controls Inc.,Metasys ADX (Extended Application and Data Server) Server running MVE (Metasys for Validated Environments),Johnson Controls reports this vulnerability affects the following Metasys ADX Server running MVE: Metasys ADX Server version 12.0 running MVE.,CVE-2022-21936,8.1,High,CWE-287,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2230,10/4/2022,10/4/2022,2022,ICSA-22-277-02,Hitachi Energy Modular Switchgear Monitoring,Hitachi Energy,Modular Switchgear Monitoring (MSM),"The following versions of MSM, a monitoring system for high voltage switchgear, are affected: MSM version 2.2 and prior.","CVE-2021-40335, CVE-2021-40336",5.0,Medium,"CWE-352, CWE-113",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2229,10/4/2022,10/4/2022,2022,ICSA-22-277-03,Horner Automation Cscape,Horner Automation,Cscape,"The following versions of Cscape, a PLC control software, are affected: Cscape Version 9.90 SP 6 and prior Cscape Version 9.90 SP 7 and prior (CVE-2022-3379 and CVE-2022-3378 only).","CVE-2022-3379, CVE-2022-3378, CVE-2022-3377",7.8,High,"CWE-787, CWE-824",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2228,10/4/2022,10/4/2022,2022,ICSA-22-277-04,Omron CX-Programmer,Omron,CX-Programmer,"The following versions of CX-Programmer, part of a software automation suite, are affected: CX-Programmer: Version 9.78 and prior.","CVE-2022-3398, CVE-2022-3396, CVE-2022-3397",7.8,High,"CWE-787, CWE-824",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2227,10/4/2022,10/4/2022,2022,ICSMA-22-277-01,BD Totalys MultiProcessor,"Becton, Dickinson and Company (BD)",Totalys MultiProcessor,The following BD products and versions are affected: BD Totalys MultiProcessor: All versions 1.70 and prior.,CVE-2022-40263,6.6,Medium,CWE-798,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2226,9/29/2022,9/29/2022,2022,ICSA-22-272-01,Hitachi Energy MicroSCADA Pro X SYS600_8DBD000106,Hitachi Energy,MicroSCADA Pro/X SYS600,Hitachi Energy reports this vulnerability affects the following SCADA products used for monitoring and controlling power systems: SYS600 10.3.1 and earlier SYS600 9.4 FP2 Hotfix 4 and earlier versions.,"CVE-2022-1778, CVE-2022-2277, CVE-2022-29490, CVE-2022-29492, CVE-2022-29922",8.5,High,"CWE-20, CWE-269, CWE-284, CWE-241",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2225,9/29/2022,9/29/2022,2022,ICSA-22-272-02,Hitachi Energy MicroSCADA Pro X SYS600_8DBD000107,Hitachi Energy,MicroSCADA Pro/X SYS600,Hitachi Energy reports this vulnerability affects the following SCADA products used for monitoring and controlling power systems: SYS600 10.3.1 and earlier SYS600 9.x versions CVE-2020-25692 impacts SYS600 if the Authentication Service is installed; it is not installed by default but needs to be either enabled during the installation process of SYS600 or manually installed later. Authentication Service (previously ABB Authentication Service) is needed only when SYS600 users are authenticated using centralized SDM600 user account management.,"CVE-2020-25692, CVE-2022-0778",7.5,High,CWE-1357,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2224,9/27/2022,9/27/2022,2022,ICSA-22-270-01,Hitachi Energy AFS660/AFS665,Hitachi Energy,AFS660/AFS665 industrial switches,Hitachi Energy reports this vulnerability affects the following AFS660/AFS665 industrial switches: Releases 7.0.02 or prior.,CVE-2020-6994,9.8,Critical,CWE-20,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2223,9/27/2022,9/27/2022,2022,ICSA-22-270-02,Hitachi Energy APM Edge,Hitachi Energy,Lumada Asset Performance Management (APM) Edge,The following versions of APM are affected: Lumada APM Edge Version 1.0 Lumada APM Edge Version 2.0 Lumada APM Edge Version 3.0 Lumada APM Edge Version 4.0.,"CVE-2022-0492, CVE-2021-4034",7.8,High,"CWE-287, CWE-787",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2222,9/27/2022,9/27/2022,2022,ICSA-22-270-03,Rockwell Automation ThinManager ThinServer,Rockwell Automation,ThinManager ThinServer,"Rockwell Automation reports this vulnerability affects the following versions of ThinManager ThinServer, a thin client and remote desktop protocol (RDP) server management software: Versions 11.0.0 through 11.0.4 Versions 11.1.0 through 11.1.4 Versions 11.2.0 through 11.2.5 Versions 12.0.0 through 12.0.2 Versions 12.1.0 through 12.1.3 Version 13.0.0",CVE-2022-38742,8.1,High,CWE-122,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2221,9/22/2022,9/22/2022,2022,ICSA-22-265-01,Measuresoft ScadaPro Server,Measuresoft,ScadaPro Server,Measuresoft reports this vulnerability affects the following product: ScadaPro Server: version 6.7.,CVE-2022-3263,7.8,High,CWE-284,Energy; Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2220,9/20/2022,9/20/2022,2022,ICSA-22-263-01,Hitachi Energy PROMOD IV,Hitachi Energy,PROMOD IV,"The following versions of PROMOD IV and the PROMOD-Generator, an energy planning, transmission congestion, and price forecasting system, are affected: Hitachi Energy PROMOD IV Version: 11.2, 11.3, and 11.4.",CVE-2010-3591,9.0,Critical,CWE-284,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2219,9/20/2022,9/20/2022,2022,ICSA-22-263-02,Hitachi Energy AFF660/665 Series,Hitachi Energy,AFF660/665 Firewall,"The following versions of Hitachi Energy AFF660/665, an industrial firewall, are affected: Hitachi Energy AFF660 FW: Versions 03.0.02 and prior Hitachi Energy AFF665 FW: Versions 03.0.02 and prior.",CVE-2020-6994,9.8,Critical,CWE-121,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2218,9/20/2022,9/20/2022,2022,ICSMA-22-263-01,Medtronic NGP 600 Series Insulin Pumps,Medtronic,"MiniMed 600 Series Insulin Pumps, Guardian Link 3 Transmitter, Guardian 2 Link Transmitter, Carelink USB, Contour Next Link 2.4","The following versions of the Medtronic NGP 600 Series Insulin Pumps and accessory components are affected: MiniMed 620G: MMT-1710 MiniMed 630G: MMT-1715, MMT-1754, MMT-1755 MiniMed 640G: MMT-1711, MMT-1712, MMT-1751, MMT-1752 MiniMed 670G: MMT-1740, MMT-1741, MMT-1742, MMT-1760, MMT-1762, MMT-1762, MMT-1780, MMT-1781, MMT-1782.",CVE-2022-32537,4.8,Medium,CWE-693,Healthcare and Public Health,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2217,9/20/2022,5/4/2023,2022,ICSA-22-263-03,Dataprobe iBoot-PDU (Update A),Dataprobe,iBoot-PDU FW,"The following versions of Dataprobe iBoot-PDU, a power distribution unit, are affected: Dataprobe iBoot-PDU FW: All Versions prior to 1.42.06162022.","CVE-2022-3183, CVE-2022-3184, CVE-2022-3185, CVE-2022-3186, CVE-2022-3187, CVE-2022-3188, CVE-2022-3189, CVE-2022-46658, CVE-2022-46738, CVE-2022-47320, CVE-2022-47311, CVE-2022-4945",9.8,Critical,"CWE-78, CWE-22, CWE-200, CWE-284, CWE-285, CWE-863, CWE-918, CWE-121, CWE-1391, CWE-288, CWE-256",Critical Manufacturing,Multiple Countries,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2216,9/20/2022,9/20/2022,2022,ICSA-22-263-04,Host Engineering Communications Module,Host Engineering,H0-ECOM100 Communications Module,"The following firmware versions of H0-ECOM100 Communications Module, a module to communicate with programmable logic controllers, are affected: Firmware v5.0.155 and prior.",CVE-2022-3228,6.5,Medium,CWE-121,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2215,9/15/2022,9/15/2022,2022,ICSA-22-258-01,Siemens Mobility CoreShield OWG Software,Siemens Mobility,CoreShield One-Way Gateway (OWG) Software,"The following versions of CoreShield OWG software, which enable unidirectional exchange of information between network zones, are affected: CoreShield OWG Software: All versions prior to 2.2.",CVE-2022-38466,7.8,High,CWE-284,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2214,9/15/2022,9/15/2022,2022,ICSA-22-258-02,Siemens Simcenter Femap and Parasolid,Siemens,Simcenter Femap and Parasolid,"""¯Siemens reports these vulnerabilities as affecting the following products: Parasolid, a 3D geometric modeling tool Version V33.1 All versions prior to V33.1.262 Versions V33.1.262 up to V33.1.263; only affected by CVE-2022-39156, CVE-2022- 39155, CVE-2022-39154, CVE-2022-39153, CVE-2022-39152, CVE-2022-39151, CVE-2022- 39150, CVE-2022-39149, CVE-2022-39148, CVE-2022-39147, CVE-2022-39146, CVE-2022- 39145, CVE-2022-39144, CVE-2022-39143, CVE-2022-39142 Version V34.0 All versions prior to V34.0.252 Version V34.1 All versions prior to V34.1.242 Version V35.0 All versions prior to V35.0.161 Versions V35.0.161 up to V35.0.164; only affected by CVE-2022-39156, CVE-2022- 39155, CVE-2022-39154, CVE-2022-39153, CVE-2022-39152, CVE-2022-39151, CVE-2022- 39150, CVE-2022-39149, CVE-2022-39148, CVE-2022-39147, CVE-2022-39146, CVE-2022- 39145, CVE-2022-39144, CVE-2022-39143, CVE-2022-39142 Simcenter Femap, a modeling and simulation software V2022.1 All versions prior to V2022.1.3 V2022.2 All versions prior to V2022.2.2.","CVE-2022-39137, CVE-2022-39138, CVE-2022-39139, CVE-2022-39140, CVE-2022-39141, CVE-2022-39142, CVE-2022-39143, CVE-2022-39144, CVE-2022-39145, CVE-2022-39146, CVE-2022-39147, CVE-2022-39148, CVE-2022-39149, CVE-2022-39150, CVE-2022-39151, CVE-2022-39152, CVE-2022-39153, CVE-2022-39154, CVE-2022-39155, CVE-2022-39156",7.8,High,"CWE-125, CWE-787, CWE-125, CWE-824",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2213,9/15/2022,11/10/2022,2022,ICSA-22-258-03,Siemens RUGGEDCOM ROS (Update A),Siemens,RUGGEDCOM ROS,"The following versions of RUGGEDCOM ROS-based devices, typically switches and serial-to-Ethernet devices, are affected: --------- Begin Update A part 1 of 2 --------- RUGGEDCOM ROS RMC8388 V5.X: All versions prior to V5.6.0 RUGGEDCOM ROS RS416Pv2 V5.X: All versions prior to V5.6.0 RUGGEDCOM ROS RS416v2 V5.X: All versions prior to V5.6.0 RUGGEDCOM ROS RS900 (32M) V5.X: All versions prior to V5.6.0 RUGGEDCOM ROS RS900G (32M) V5.X: All versions prior to V5.6.0 RUGGEDCOM ROS RSG907R V5.X: All versions prior to V5.6.0 RUGGEDCOM ROS RSG908C V5.X: All versions prior to V5.6.0 RUGGEDCOM ROS RSG909R V5.X: All versions prior to V5.6.0 RUGGEDCOM ROS RSG910C V5.X: All versions prior to V5.6.0 RUGGEDCOM ROS RSG920P V5.X: All versions prior to V5.6.0 RUGGEDCOM ROS RSG2100 (32M) V5.X: All versions prior to V5.6.0 RUGGEDCOM ROS RSG2288 V5.X: All versions prior to V5.6.0 RUGGEDCOM ROS RSG2300 V5.X: All versions prior to V5.6.0 RUGGEDCOM ROS RSG2300P V5.X: All versions prior to V5.6.0 RUGGEDCOM ROS RSG2488 V5.X: All versions prior to V5.6.0 RUGGEDCOM ROS RSL910 V5.X: All versions prior to V5.6.0 RUGGEDCOM ROS RST916C V5.X: All versions prior to V5.6.0 RUGGEDCOM ROS RST916P V5.X: All versions prior to V5.6.0 RUGGEDCOM ROS RST2228 V5.X: All versions prior to V5.6.0 RUGGEDCOM ROS RST2228P V5.X: All versions prior to V5.6.0 --------- End Update A part 1 of 2 ---------.",CVE-2022-39158,5.3,Medium,CWE-400,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2212,9/15/2022,12/15/2022,2022,ICSA-22-258-04,Siemens Mendix SAML Module (Update B),Siemens,Mendix SAML Module,"Siemens reported this vulnerability affects the following versions of Mendix SAML Module, a SAML cloud authentication application: For CVE-2022-37011 Mendix SAML Module (Mendix 7 compatible): All versions prior to V1.17.0 Mendix SAML Module (Mendix 8 compatible): All versions prior to V2.3.0 Mendix SAML Module (Mendix 9 compatible): All versions prior to V3.3.1 For CVE-2022-44457 Mendix SAML Module (Mendix 7 compatible): Versions V1.17.0 and later. Mendix SAML Module (Mendix 8 compatible): Versions V2.3.0 and later, up to but not including Version V2.3.2. Mendix SAML Module (Mendix 9 compatible): Versions V3.3.1 and later, up to but not including Version V3.3.5.","CVE-2022-37011, CVE-2022-44457",7.4,High,CWE-294,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2211,9/15/2022,9/15/2022,2022,ICSA-22-258-05,Siemens SINEC INS,Siemens,SINEC INS,"The following versions of Siemens SINEC INS, a software tool for central network services, are affected: Siemens SINEC INS: All versions prior to V1.0 SP2.","CVE-2020-7793, CVE-2020-12762, CVE-2020-28168, CVE-2020-28500, CVE-2021-3749, CVE-2021-4160, CVE-2021-23337, CVE-2021-23839, CVE-2021-23841, CVE-2021-25220, CVE-2021-25217, CVE-2022-0155, CVE-2022-0235, CVE-2022-0396",8.8,High,"CWE-400, CWE-190, CWE-918, CWE-20, CWE-77, CWE-326, CWE-311, CWE-119, CWE-359, CWE-601, CWE-404",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2210,9/13/2022,9/13/2022,2022,ICSA-22-256-01,Hitachi Energy TXpert Hub CoreTec 4 Sudo Vulnerability,Hitachi Energy,TXpert Hub CoreTec 4,"The following versions of TXpert Hub CoreTec 4, a digital transformer monitoring and diagnostics device, are affected: TXpert Hub CoreTec 4 version 2.0.0, 2.0.1 TXpert Hub CoreTec 4 version 2.1.0, 2.1.1, 2.1.2, 2.1.3 TXpert Hub CoreTec 4 version 2.2.0, 2.2.1.",CVE-2021-3156,7.8,High,CWE-193,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2209,9/13/2022,9/13/2022,2022,ICSA-22-256-02,Honeywell SoftMaster,Honeywell,SoftMaster,"Honeywell reports these vulnerabilities affect the following SoftMaster desktop application, a PLC software application: SoftMaster: version 4.51.","CVE-2022-2333, CVE-2022-2332",8.8,High,"CWE-427, CWE-732",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2208,9/13/2022,6/1/2023,2022,ICSA-22-256-03,Delta Electronics DIAEnergie (Update A),Delta Electronics,DIAEnergie,"--------- Begin Update A Part 1 of 2 --------- Delta Electronics reports this vulnerability affects the following versions of DIAEnergie, an industrial energy management system: DIAEnergie: versions prior to 1.9.03.009 --------- End Update A Part 1 of 2 ---------",CVE-2022-32145,9.8,Critical,CWE-798,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2207,9/13/2022,9/13/2022,2022,ICSA-22-256-04,Kingspan TMS300 CS,Kingspan,TMS300 CS,"All versions of Kingspan TMS300 CS, a water tank management system, are affected. Kingspan TMS300 CS: All versions.",CVE-2022-2757,9.8,Critical,CWE-287,Water and Wastewater Systems,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2206,9/8/2022,9/29/2022,2022,ICSMA-22-251-01,Baxter Sigma Spectrum Infusion Pump (Update A),Baxter,Sigma and Baxter Spectrum Infusion Pumps,"The following versions of Sigma Spectrum Infusion systems are affected: Sigma Spectrum v6.x model 35700BAX Sigma Spectrum v8.x model 35700BAX2 Baxter Spectrum IQ (v9.x) model 35700BAX3 Sigma Spectrum LVP v6.x Wireless Battery Modules v16, v16D38, v17, v17D19, v20D29 to v20D32, and v22D24 to v22D28 Sigma Spectrum LVP v8.x Wireless Battery Modules v17, v17D19, v20D29 to v20D32, and v22D24 to v22D28 Baxter Spectrum IQ LVP (v9.x) with Wireless Battery Modules v22D19 to v22D28.","CVE-2022-26390, CVE-2022-26392, CVE-2022-26393, CVE-2022-26394",7.5,High,"CWE-311, CWE-134, CWE-306",Healthcare and Public Health,"United States, Canada, Puerto Rico, Caribbean",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2205,9/8/2022,9/8/2022,2022,ICSA-22-251-01,MZ Automation libIEC61850,MZ Automation GmbH,libIEC61850,"The following versions of libIEC61850, IEC 61850 implementation software, are affected: libIEC61850 Versions 1.4 and prior libIEC61850 Version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e.","CVE-2022-2970, CVE-2022-2972, CVE-2022-2971, CVE-2022-2973",10.0,Critical,"CWE-121, CWE843, CWE-476",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2204,9/6/2022,9/6/2022,2022,ICSA-22-249-01,Triangle Microworks Libraries,Triangle MicroWorks,TMW IEC 61850 Software Library and TMW IEC 60870-6 (ICCP/TASE.2) Software Library,"TMW Library: IEC 61850 Any client or server using the C language library with a version number of 11.2.0 or earlier. Any client or server using the C++, C#, or Java language library with a version number of 5.0.1 or earlier. TMW Library: IEC 60870-6 (ICCP/Tase.2) Any client or server using a C++ language library with a version number of 4.4.3 or earlier.",CVE-2022-38138,7.5,High,CWE-824,Energy; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2203,9/6/2022,9/6/2022,2022,ICSA-22-249-02,AVEVA Edge 2020 R2 SP1 and all prior versions,AVEVA,AVEVA Edge 2020 R2 SP1 and all prior versions,"The following versions of AVEVA Edge, an industrial software system, are affected: AVEVA Edge: 2020 R2 SP1 and all prior versions.","CVE-2022-36970, CVE-2022-28686, CVE-2022-28687, CVE-2022-28688, CVE-2022-28685, CVE-2022-36969",7.8,High,"CWE-357, CWE-427, CWE-502, CWE-611",Critical Manufacturing,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2202,9/6/2022,9/6/2022,2022,ICSA-22-249-03,Cognex 3D-A1000 Dimensioning System,Cognex,3D-A1000 Dimensioning System,"The following versions of Cognex 3D-A1000 Dimensioning System, an industrial smart camera, are affected: Cognex 3D-A1000 Dimensioning System: Firmware Version: 1.0.3 (3354) and prior.","CVE-2022-1368, CVE-2022-1522, CVE-2022-1525",9.8,Critical,"CWE-306, CWE-117, CWE-602",Commercial Facilities; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2201,9/6/2022,9/6/2022,2022,ICSA-22-249-04,Hitachi Energy TXpert Hub CoreTec 4,Hitachi Energy,TXpert Hub CoreTec 4,"The following versions of TXpert Hub CoreTec 4, a digital transformer monitoring and diagnostics device, are affected: TXpert Hub CoreTec 4 version 2.0.0, 2.0.1 TXpert Hub CoreTec 4 version 2.1.0, 2.1.1, 2.1.2, 2.1.3 TXpert Hub CoreTec 4 version 2.2.0, 2.2.1.","CVE-2021-35530, CVE-2021-35531, CVE-2021-35532",6.0,Medium,"CWE-288, CWE-20, CWE-494",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2200,9/1/2022,1/30/2025,2022,ICSMA-22-244-01,Contec Health CMS8000 Patient Monitor (Update A),Contec Health,CMS8000 CONTEC ICU CCU Vital Signs Patient Monitor,The following Contec Health products are affected: CMS8000 CONTEC ICU CCU Vital Signs Patient Monitor: Versions smart3250-2.6.27-wlan2.1.7.cramfs and prior CMS8000 CONTEC ICU CCU Vital Signs Patient Monitor: Versions CMS7.820.075.08/0.74(0.75) and prior CMS8000 CONTEC ICU CCU Vital Signs Patient Monitor: Versions CMS7.820.120.01/0.93(0.95) and prior.,"CVE-2022-3027, CVE-2022-36385, CVE-2022-38069, CVE-2022-38100, CVE-2022-38453",8.7,High,"CWE-1263, CWE-770, CWE-798, CWE-489, CWE-419",Healthcare and Public Health,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2199,9/1/2022,9/29/2022,2022,ICSA-22-244-01,Delta Electronics DOPSoft (Update A),Delta Electronics,DOPSoft,"The following versions of DOPSoft, a software supporting the DOP-100 series HMI screens, are affected: DOPSoft: All versions",CVE-2022-2966,3.3,Low,CWE-125,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2198,8/30/2022,8/30/2022,2022,ICSA-22-242-01,Hitachi Energy FACTS Control Platform (FCP) Product,Hitachi Energy,FACTS Control Platform (FCP) Product,Hitachi Energy reports multiple open-source software related vulnerabilities in the following FACTS Control Platform (FCP) product versions: FCP 1.1.0 - 1.3.0 FCP 2.1.0 - 2.3.0 FCP 3.0.0 - 3.12.0.,"CVE-2020-1968, CVE-2020-8172, CVE-2020-8174, CVE-2020-8201, CVE-2020-8252, CVE-2020-8265, CVE-2020-8287",7.5,High,CWE-1357,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2197,8/30/2022,8/30/2022,2022,ICSA-22-242-02,Hitachi Energy Gateway Station (GWS) Product,Hitachi Energy,Gateway Station (GWS) Product,Hitachi Energy reported multiple open-source software related vulnerabilities in the following GWS Product versions: GWS 2.0.0.0 and earlier GWS 2.1.0.0 GWS 2.2.0.0 GWS 2.3.0.0 GWS 2.4.0.0 GWS 3.0.0.0 GWS 3.1.0.0.,"CVE-2020-1968, CVE-2020-8172, CVE-2020-8174, CVE-2020-8201, CVE-2020-8252, CVE-2020-8265, CVE-2020-8287",7.5,High,CWE-1357,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2196,8/30/2022,8/30/2022,2022,ICSA-22-242-03,Hitachi Energy MSM Product,Hitachi Energy,MSM Product,Hitachi Energy reports multiple open-source software related vulnerabilities in the following MSM product versions: MSM version 2.2 and earlier.,"CVE-2015-6584, CVE-2016-7103, CVE-2011-4273, CVE-2018-16842, CVE-2016-9586, CVE-2016-8617, CVE-2016-8618, CVE-2016-8619, CVE-2016-8621, CVE-2016-7167, CVE-2014-3707, CVE-2013-2174, CVE-2014-0138",7.5,High,CWE-1357,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2195,8/30/2022,8/30/2022,2022,ICSA-22-242-04,Hitachi Energy RTU500 series,Hitachi Energy,RTU500 series,Hitachi Energy reported this vulnerability affects the following RTU500 series in which HCI Modbus TCP is configured and enabled by project configuration: RTU500 series CMU Firmware version 12.0.* RTU500 series CMU Firmware version 12.2.* RTU500 series CMU Firmware version 12.4.* RTU500 series CMU Firmware version 12.6.* RTU500 series CMU Firmware version 12.7.* RTU500 series CMU Firmware version 13.2.*,CVE-2022-28613,7.5,High,CWE-20,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2194,8/30/2022,8/30/2022,2022,ICSA-22-242-05,Fuji Electric D300win,Fuji Electric,D300win,"The following versions of D300win, a programming support tool expert, are affected: D300win: versions prior to 3.7.1.17.","CVE-2022-1738, CVE-2022-1523",8.7,High,"CWE-125, CWE-123",Multiple Critical Sectors,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2193,8/30/2022,8/30/2022,2022,ICSA-22-242-06,Honeywell ControlEdge,Honeywell,ControlEdge,"The following versions of ControlEdge, a PLC, are affected: ControlEdge: All versions prior to 151.2.",CVE-2022-30318,9.8,Critical,CWE-798,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2192,8/30/2022,8/30/2022,2022,ICSA-22-242-07,Honeywell Experion LX,Honeywell,Experion LX,"The following versions of Experion LX, a distributed control system (DCS), are affected: Experion LX: All versions.",CVE-2022-30317,9.1,Critical,CWE-306,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2191,8/30/2022,8/30/2022,2022,ICSA-22-242-08,Honeywell Trend Controls Inter-Controller Protocol,Honeywell,Trend Controls IQ Series that utilize Inter-Controller (IC) protocol,"The following versions of Trend Controls IQ Series IC, an industrial communication controller, are affected: IQ Series Controllers that utilize Inter-Controller (IC) protocol: All versions.",CVE-2022-30312,7.1,High,CWE-319,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2190,8/30/2022,8/30/2022,2022,ICSA-22-242-09,Omron CX-Programmer,Omron,CX-Programmer,"The following Omron product, part of a software automation suite, is affected: Omron CX-Programmer: All versions prior to v9.78.",CVE-2022-2979,7.8,High,CWE-416,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2189,8/30/2022,9/8/2022,2022,ICSA-22-242-10,PTC Kepware KEPServerEX (Update A),PTC,Kepware KEPServerEX,"The following PTC products are affected by vulnerabilities found in Kepware KEPServerEX, a connectivity platform: Kepware KEPServerEX: Versions prior to 6.12 ThingWorkx Kepware Server: Versions prior to 6.12 ThingWorkx Industrial Connectivity: All versions OPC-Aggregator: Versions prior to 6.12 ThingWorkx Kepware Edge: Versions 1.4 and prior The following products are known to be vulnerable: Rockwell Automation KEPServer Enterprise: Versions prior to v6.12 GE Digital Industrial Gateway Server: Versions prior to v7.612 Software Toolbox TOP Server: Versions prior to v6.12.","CVE-2022-2848, CVE-2022-2825",9.8,Critical,"CWE-122, CWE-121",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2188,8/30/2022,8/30/2022,2022,ICSA-22-242-11,Sensormatic Electronics iSTAR,Sensormatic Electronics LLC (Subsidiary of Johnson Controls),iSTAR Ultra,"The following versions of Sensormatic iSTAR Ultra, a network-ready door controller, are affected: iSTAR Ultra: All versions prior to 6.8.9. CU01.",CVE-2022-21941,10.0,Critical,CWE-77,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2187,8/25/2022,8/25/2022,2022,ICSA-22-237-01,FATEK Automation FvDesigner,FATEK Automation,FvDesigner,The following versions of the FvDesigner software tool are affected: FvDesigner: Versions 1.5.103 and prior.,CVE-2022-2866,7.8,High,CWE-787,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2186,8/23/2022,8/23/2022,2022,ICSA-22-235-06,Measuresoft ScadaPro Server and Client,Measuresoft,ScadaPro Server and Client,"The following versions of ScadaPro, a supervisory control and data acquisition (SCADA) system, are affected: ScadaPro Server and Client: All Versions.","CVE-2022-2894, CVE-2022-2895, CVE-2022-2896, CVE-2022-2897, CVE-2022-2898",7.8,High,"CWE-822, CWE-121, CWE-416, CWE-59",Energy; Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2185,8/23/2022,8/23/2022,2022,ICSA-22-235-05,Measuresoft ScadaPro Server,Measuresoft,ScadaPro Server,"The following versions of ScadaPro Server, a supervisory control and data acquisition (SCADA) system, are affected: ScadaPro Server: Versions prior to 6.8.0.1.",CVE-2022-2892,7.8,High,CWE-787,Energy; Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2184,8/23/2022,8/23/2022,2022,ICSA-22-235-07,Hitachi Energy RTU500,Hitachi Energy,RTU500 Series,The following versions of Hitachi Energy's RTU500 firmware are affected: RTU500 series CMU Firmware version 12.0.1-12.0.13 RTU500 series CMU Firmware version 12.2.1-12.2.11 RTU500 series CMU Firmware version 12.4.1-12.4.11 RTU500 series CMU Firmware version 12.6.1-12.6.7 RTU500 series CMU Firmware version 12.7.1-12.7.3 RTU500 series CMU Firmware version 13.2.1-13.2.4 RTU500 series CMU Firmware version 13.3.1.,CVE-2022-2081,7.5,High,CWE-121,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2183,8/23/2022,8/23/2022,2022,ICSA-22-235-03,mySCADA myPRO,mySCADA Technologies,mySCADA myPRO,mySCADA reports this vulnerability affects the following myPRO HMI/SCADA systems: myPRO: Versions 8.26.0 and prior.,CVE-2022-2234,9.9,Critical,CWE-77,Energy; Food and Agriculture; Transportation Systems; Water and Wastewater Systems,Worldwide,Czech Republic,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2182,8/23/2022,9/29/2022,2022,ICSA-22-235-01,ARC Informatique PcVue (Update A),ARC Informatique,PcVue,The following ARC Informatique product components are affected: --------- Begin Update A part 1 of 2 --------- PcVue 12 OAuth web service configuration versions prior to 12.0.27 PcVue 15 OAuth web service configuration versions prior to 15.2.3 --------- End Update A part 1 of 2 --------- PcVue 12 OAuth web service configuration PcVue 15 OAuth web service configuration.,CVE-2022-2569,5.5,Medium,CWE-312,Multiple Critical Sectors,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2181,8/23/2022,8/23/2022,2022,ICSA-22-235-02,Delta Industrial Automation DIALink,Delta Electronics,Delta Industrial Automation DIALink,The following versions of the DIALink Industrial Automation server are affected: Delta Industrial Automation DIALink: Version 1.4.0.0 and prior.,CVE-2022-2660,9.8,Critical,CWE-321,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2180,8/16/2022,8/16/2022,2022,ICSA-22-228-01,Yokogawa CENTUM Controller FCS,Yokogawa,CENTUM VP & CS 3000 Controller FCS,"Yokogawa reports this vulnerability affects the following CENTUM VP/CS 3000 Controller FCS products: CENTUM VP/CS 3000 controller FCS CP31, CP33, CP345 CP401, CP451.",CVE-2022-33939,6.5,Medium,CWE-399,Multiple Critical Sectors,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2179,8/16/2022,11/10/2022,2022,ICSA-22-228-02,LS ELECTRIC PLC and XG5000 (Update A),"LS ELECTRIC, LS Industrial Systems (LSIS) Co. Ltd",LS ELEC PLC and XG5000,"The following versions of LS ELECTRIC PLC, a PLC, and XG5000, a PLC programming software, are affected: --------- Begin Update A part 1 of 3 --------- LS Electric PLC: XGK-CPUU/H/A/S/E: All versions prior to V3.50 XGI-CPUU/UD/H/S/E: All versions prior to V3.20 XGR-CPUH: All versions prior to V1.80 XGB-XBMS: All versions prior to V3.00 XGB-XBCH: All versions prior to V1.90 XGB-XECH: All versions prior to V1.30 LS Electric XG5000: All versions prior to V4.0 --------- End Update A part 1 of 3 ---------.",CVE-2022-2758,6.5,Medium,CWE-326,Multiple Critical Sectors,Worldwide,South Korea,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2178,8/16/2022,8/16/2022,2022,ICSA-22-228-04,Softing Secure Integration Server,Softing Industrial Automation GmbH,Secure Integration Server,Softing reports these vulnerabilities affect the following products: Secure Integration Server: Version 1.22. edgeConnector: Version 3.1. edgeAggregator: Version 3.1. OPC UA C++ Server SDK: Version 6. OPC Suite: Version 5.2. uaGate: Version 1.74.,"CVE-2022-1069, CVE-2022-2334, CVE-2022-2336, CVE-2022-1373, CVE-2022-2338, CVE-2022-1748, CVE-2022-2337, CVE-2022-2547, CVE-2022-2335",7.5,High,"CWE-125, CWE-427, CWE-287, CWE-23, CWE-319, CWE-476, CWE-191",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2177,8/16/2022,8/16/2022,2022,ICSA-22-228-03,Delta Industrial Automation DRAS,Delta Electronics,Delta Robot Automation Studio (DRAS),"The following versions of DRAS, a controller software suite, are affected: DRAS: All versions prior to 1.13.20.",CVE-2022-2759,5.5,Medium,CWE-611,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2176,8/16/2022,8/16/2022,2022,ICSA-22-228-05,B&R Industrial Automation Automation Studio 4,B&R Industrial Automation GmbH,Automation Studio 4,"B&R Automation reports the vulnerabilities affect the following versions of Automation Studio, a programmable logic controller (PLC) automation programming software: Automation Studio 4: All versions.",CVE-2021-22289,8.3,High,CWE-20,Chemical; Critical Manufacturing; Energy,Worldwide,Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2175,8/16/2022,8/16/2022,2022,ICSA-22-228-06,Emerson Proficy Machine Edition,Emerson,Proficy Machine Edition,"The following versions of Proficy Machine Edition, an engineering workstation that is part of the PACSystems control system software platform, are affected: Proficy Machine Edition Version 9.80 and prior.","CVE-2022-2793, CVE-2022-2792, CVE-2022-2791, CVE-2022-2790, CVE-2022-2789, CVE-2022-2788",9.3,Critical,"CWE-353, CWE-284, CWE-434, CWE-347, CWE-345, CWE-29",Commercial Facilities; Critical Manufacturing; Dams; Defense Industrial Base; Energy; Food and Agriculture; Government Facilities; Information Technology; Transportation Systems; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2174,8/16/2022,8/16/2022,2022,ICSA-22-228-07,Sequi PortBloque S,Sequi,Sequi PortBloque S,"The following versions of Sequi PortBloque S, a serial Modbus firewall, are affected: Sequi PortBloque S: All versions.","CVE-2022-2662, CVE-2022-2661",9.9,Critical,"CWE-287, CWE-285",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2173,8/11/2022,8/11/2022,2022,ICSA-22-223-01,Siemens Simcenter STAR-CCM+,Siemens,Simcenter STAR-CCM+,The following versions of Simcenter STAR-CCM+ are affected: Simcenter STAR-CCM+: All versions.,CVE-2022-34659,5.3,Medium,CWE200,Critical Manufacturing,Multiple Countries,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2172,8/11/2022,8/11/2022,2022,ICSA-22-223-02,Siemens Teamcenter,Siemens,Teamcenter,"The following versions of Teamcenter, a product lifecycle management software, are affected: Teamcenter v12.4: All versions prior to v12.4.0.15 Teamcenter v13.0: All versions prior to v13.0.0.10 Teamcenter v13.1: All versions prior to v13.1.0.10 Teamcenter v13.2: All versions prior to v13.2.0.9 Teamcenter v13.3: All versions prior to v13.3.0.5 Teamcenter v14.0: All versions prior to v14.0.0.2.","CVE-2022-34660, CVE-2022-34661",7.6,High,"CWE-77, CWE-835",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2171,8/11/2022,8/11/2022,2022,ICSA-22-223-03,"Schneider Electric EcoStruxure, EcoStruxure Process Expert, SCADAPack RemoteConnect for x70",Schneider Electric,"EcoStruxure, EcoStruxure Process Expert, SCADAPack RemoteConnect for x70",Schneider Electric reported these vulnerabilities affect the following products using AT&T Labs Compressor (XMill) and Decompressor (XDemill): EcoStruxure Control Expert: All versions (including former Unity Pro) prior to V15.1 HF001 EcoStruxure Process Expert: All versions (including former HDCS) prior to V2021 SCADAPack RemoteConnect for x70: All versions prior to R2.7.3.,"CVE-2021-21810, CVE-2021-21825, CVE-2021-21829, CVE-2021-21830, CVE-2021-21811, CVE-2021-21812, CVE-2021-21813, CVE-2021-21814, CVE-2021-21815, CVE-2021-21826, CVE-2021-21827, CVE-2021-21828, CVE-2022-26507",9.8,Critical,"CWE-122, CWE-191, CWE-120, CWE-125",Multiple Critical Sectors,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2170,8/11/2022,8/11/2022,2022,ICSA-22-223-04,"Emerson ROC800, ROC800L and DL8000",Emerson,"ROC800, ROC800L and DL8000","The following versions of ROC800, a remote automation controller, are affected: ROC800: All versions ROC800L: All versions DL8000: All versions.",CVE-2022-30264,6.3,Medium,CWE-345,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2169,8/11/2022,8/11/2022,2022,ICSA-22-223-05,Siemens SICAM A8000 Web Server Module,Siemens,"SICAM A8000 CP-8000, CP-8021, CP-8022",Siemens has reported that this vulnerability affects the following SICAM A8000 Web Server Module products and versions: CP-8000 MASTER MODULE WITH I/O -25/+70°C (6MF2101-0AB10-0AA0): All Versions CP-8000 MASTER MODULE WITH I/O -40/+70°C (6MF2101-1AB10-0AA0): All Versions CP-8021 MASTER MODULE (6MF2802-1AA00): All Versions CP-8022 MASTER MODULE WITH GPRS (6MF2802-2AA00): All Versions The affected protocol firmware utilized with the web server modules includes the following: AGPMT0 (AGP Master) DNPiT1 (DNP3 TCP/IP Server) DNPiT2 (DNP3 TCP/IP Client) DNPMT0 (DNP3 Master seriell) DNPST0 (DNP3 Slave seriell) ET83 (61850 Ed.1) ET85 (61850 Ed.2) MBCiT0 (MODBUS TCP/IP Client) MBSiT0 (MODBUS TCP/IP Server) MODMT2 (MODBUS Master seriell) OPUPT0 (OPCUA Pub/Sub) OPUPT1 (Mindconnect).,CVE-2021-46304,4.3,Medium,CWE-284,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2168,8/11/2022,8/11/2022,2022,ICSA-22-223-06,Siemens SICAM TOOLBOX II,Siemens,SICAM TOOLBOX II,"The following versions of SICAM TOOLBOX II, a control and monitoring system, are affected: SICAM TOOLBOX II: All versions.",CVE-2021-45106,9.9,Critical,CWE-798,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2167,8/11/2022,9/15/2022,2022,ICSA-22-223-07,Siemens SCALANCE (Update A),Siemens,SCALANCE,"Siemens reports these vulnerabilities affects the following SCALANCE products: M-800 / S615: All versions SC-600 Family: All versions prior to V2.3.1 W-700 IEEE 802.11ax Family: All versions W-700 IEEE 802.11n Family: All versions W-1700 IEEE 802.11ac Family: All versions XB-200 Switch Family: All versions XC-200 Switch Family: All versions XF-200BA Switch Family: All versions XM-400 Family: All versions XP-200 Switch Family: All versions XR-300WG Switch Family: All versions XR-500 Family: All versions --------- Begin Update A Part 1 of 2 --------- RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2): All versions < V7.1.2 RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2): All versions < V7.1.2 SCALANCE M804PB (6GK5804-0AP00-2AA2): All versions < V7.1.2 SCALANCE M812-1 ADSL-Router (Annex A) (6GK5812-1AA00-2AA2): All versions < V7.1.2 SCALANCE M812-1 ADSL-Router (Annex B) (6GK5812-1BA00-2AA2): All versions < V7.1.2: All versions < V7.1.2 SCALANCE M816-1 ADSL-Router (Annex B) (6GK5816-1BA00-2AA2): All versions < V7.1.2 SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2): All versions < V7.1.2 SCALANCE M874-2 (6GK5874-2AA00-2AA2): All versions < V7.1.2 SCALANCE M874-3 (6GK5874-3AA00-2AA2): All versions < V7.1.2 SCALANCE M876-3 (EVDO) (6GK5876-3AA02-2BA2): All versions < V7.1.2 SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2): All versions < V7.1.2 SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2): All versions < V7.1.2 SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2): All versions < V7.1.2 SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1): All versions < V7.1.2 SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1): All versions < V7.1.2 SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1): All versions < V7.1.2 SCALANCE S615 (6GK5615-0AA00-2AA2): All versions < V7.1.2 SCALANCE SC622-2C (6GK5622-2GS00-2AC2): All versions < V2.3.1 SCALANCE SC632-2C (6GK5632-2GS00-2AC2): All versions < V2.3.1 SCALANCE SC636-2C (6GK5636-2GS00-2AC2): All versions < V2.3.1 SCALANCE SC642-2C (6GK5642-2GS00-2AC2): All versions < V2.3.1 SCALANCE SC646-2C (6GK5646-2GS00-2AC2): All versions < V2.3.1 SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0): All versions SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0): All versions SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0): All versions SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0): All versions SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0): All versions SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0): All versions SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6): All versions SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0): All versions SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6): All versions SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0): All versions SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0): All versions SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0): All versions SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0): All versions SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0): All versions SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0): All versions SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0): All versions SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0): All versions SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0): All versions SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0): All versions SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0): All versions SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6): All versions SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0): All versions SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0): All versions SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6): All versions SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0): All versions SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0): All versions SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0): All versions SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0): All versions SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0): All versions SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0): All versions SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0): All versions SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0): All versions SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0): All versions SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0): All versions SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0): All versions SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0): All versions SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0): All versions SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0): All versions SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0): All versions SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0): All versions SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0): All versions SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0): All versions SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0): All versions SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0): All versions SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0): All versions SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0): All versions SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0): All versions SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0): All versions SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0): All versions SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0): All versions SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0): All versions SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0): All versions SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0): All versions SCALANCE W1788-2 M12 (6GK5788-2GY01-0AA0): All versions SCALANCE W1788-2IA M12 (6GK5788-2HY01-0AA0): All versions SCALANCE WAM763-1 (6GK5763-1AL00-7DA0): All versions SCALANCE WAM766-1 (6GK5766-1GE00-7DA0): All versions SCALANCE WAM766-1 (6GK5766-1GE00-7DB0): All versions SCALANCE WAM766-1 6GHz (6GK5766-1JE00-7DA0): All versions SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0): All versions SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TB0): All versions SCALANCE WAM766-1 EEC 6GHz (6GK5766-1JE00-7TA0): All versions SCALANCE WUM763-1 (6GK5763-1AL00-3AA0): All versions SCALANCE WUM763-1 (6GK5763-1AL00-3DA0): All versions SCALANCE WUM766-1 (6GK5766-1GE00-3DA0): All versions SCALANCE WUM766-1 (6GK5766-1GE00-3DB0): All versions SCALANCE WUM766-1 6GHz (6GK5766-1JE00-3DA0): All versions SCALANCE XB205-3 (SC) (6GK5205-3BD00-2TB2): All versions SCALANCE XB205-3 (SC, PN) (6GK5205-3BB00-2AB2): All versions SCALANCE XB205-3 (ST, PN) (6GK5205-3BD00-2AB2): All versions SCALANCE XB205-3 (ST/BFOC) (6GK5205-3BB00-2TB2): All versions SCALANCE XB205-3LD (6GK5205-3BF00-2TB2): All versions SCALANCE XB205-3LD (SC, PN) (6GK5205-3BF00-2AB2): All versions SCALANCE XB208 (6GK5208-0BA00-2TB2): All versions SCALANCE XB208 (PN) (6GK5208-0BA00-2AB2): All versions SCALANCE XB213-3 (SC) (6GK5213-3BD00-2TB2): All versions SCALANCE XB213-3 (SC, PN) (6GK5213-3BD00-2AB2): All versions SCALANCE XB213-3 (ST, PN) (6GK5213-3BB00-2AB2): All versions SCALANCE XB213-3 (ST/BFOC) (6GK5213-3BB00-2TB2): All versions SCALANCE XB213-3LD (6GK5213-3BF00-2TB2): All versions SCALANCE XB213-3LD (SC, PN) (6GK5213-3BF00-2AB2): All versions SCALANCE XB216 (6GK5216-0BA00-2TB2): All versions SCALANCE XB216 (PN) (6GK5216-0BA00-2AB2): All versions SCALANCE XC206-2 (SC) (6GK5206-2BD00-2AC2): All versions SCALANCE XC206-2 (ST/BFOC) (6GK5206-2BB00-2AC2): All versions SCALANCE XC206-2G PoE (6GK5206-2RS00-2AC2): All versions SCALANCE XC206-2G PoE (54 V DC) (6GK5206-2RS00-5AC2): All versions SCALANCE XC206-2G PoE EEC (54 V DC) (6GK5206-2RS00-5FC2): All versions SCALANCE XC206-2SFP (6GK5206-2BS00-2AC2): All versions SCALANCE XC206-2SFP EEC (6GK5206-2BS00-2FC2): All versions SCALANCE XC206-2SFP G (6GK5206-2GS00-2AC2): All versions SCALANCE XC206-2SFP G (EIP DEF.) (6GK5206-2GS00-2TC2): All versions SCALANCE XC206-2SFP G EEC (6GK5206-2GS00-2FC2): All versions SCALANCE XC208 (6GK5208-0BA00-2AC2): All versions SCALANCE XC208EEC (6GK5208-0BA00-2FC2): All versions SCALANCE XC208G (6GK5208-0GA00-2AC2): All versions SCALANCE XC208G (EIP def.) (6GK5208-0GA00-2TC2): All versions SCALANCE XC208G EEC (6GK5208-0GA00-2FC2): All versions SCALANCE XC208G PoE (6GK5208-0RA00-2AC2): All versions SCALANCE XC208G PoE (54 V DC) (6GK5208-0RA00-5AC2): All versions SCALANCE XC216 (6GK5216-0BA00-2AC2): All versions SCALANCE XC216-3G PoE (6GK5216-3RS00-2AC2): All versions SCALANCE XC216-3G PoE (54 V DC) (6GK5216-3RS00-5AC2): All versions SCALANCE XC216-4C (6GK5216-4BS00-2AC2): All versions SCALANCE XC216-4C G (6GK5216-4GS00-2AC2): All versions SCALANCE XC216-4C G (EIP Def.) (6GK5216-4GS00-2TC2): All versions SCALANCE XC216-4C G EEC (6GK5216-4GS00-2FC2): All versions SCALANCE XC216EEC (6GK5216-0BA00-2FC2): All versions SCALANCE XC224 (6GK5224-0BA00-2AC2): All versions SCALANCE XC224-4C G (6GK5224-4GS00-2AC2): All versions SCALANCE XC224-4C G (EIP Def.) (6GK5224-4GS00-2TC2): All versions SCALANCE XC224-4C G EEC (6GK5224-4GS00-2FC2): All versions SCALANCE XF204 (6GK5204-0BA00-2GF2): All versions SCALANCE XF204 DNA (6GK5204-0BA00-2YF2): All versions SCALANCE XF204-2BA (6GK5204-2AA00-2GF2): All versions SCALANCE XF204-2BA DNA (6GK5204-2AA00-2YF2): All versions SCALANCE XM408-4C (6GK5408-4GP00-2AM2): All versions SCALANCE XM408-4C (L3 int.) (6GK5408-4GQ00-2AM2): All versions SCALANCE XM408-8C (6GK5408-8GS00-2AM2): All versions SCALANCE XM408-8C (L3 int.) (6GK5408-8GR00-2AM2): All versions SCALANCE XM416-4C (6GK5416-4GS00-2AM2): All versions SCALANCE XM416-4C (L3 int.) (6GK5416-4GR00-2AM2): All versions SCALANCE XP208 (6GK5208-0HA00-2AS6): All versions SCALANCE XP208 (6GK5208-0HA00-2TS6): All versions SCALANCE XP208EEC (6GK5208-0HA00-2ES6): All versions SCALANCE XP208PoE EEC (6GK5208-0UA00-5ES6): All versions SCALANCE XP216 (6GK5216-0HA00-2AS6): All versions SCALANCE XP216 (6GK5216-0HA00-2TS6): All versions SCALANCE XP216EEC (6GK5216-0HA00-2ES6): All versions SCALANCE XP216POE EEC (6GK5216-0UA00-5ES6): All versions SCALANCE XR324WG (24 x FE, AC 230V) (6GK5324-0BA00-3AR3): All versions SCALANCE XR324WG (24 X FE, DC 24V) (6GK5324-0BA00-2AR3): All versions SCALANCE XR326-2C PoE WG (6GK5326-2QS00-3AR3): All versions SCALANCE XR326-2C PoE WG (without UL) (6GK5326-2QS00-3RR3): All versions SCALANCE XR328-4C WG (24xFE,4xGE,AC230V) (6GK5328-4FS00-3AR3): All versions SCALANCE XR328-4C WG (24xFE,4xGE,AC230V) (6GK5328-4FS00-3RR3): All versions SCALANCE XR328-4C WG (24XFE, 4XGE, 24V) (6GK5328-4FS00-2AR3): All versions SCALANCE XR328-4C WG (24xFE, 4xGE,DC24V) (6GK5328-4FS00-2RR3): All versions SCALANCE XR328-4C WG (28xGE, AC 230V) (6GK5328-4SS00-3AR3): All versions SCALANCE XR328-4C WG (28xGE, DC 24V) (6GK5328-4SS00-2AR3): All versions SCALANCE XR524-8C, 1x230V (6GK5524-8GS00-3AR2): All versions SCALANCE XR524-8C, 1x230V (L3 int.) (6GK5524-8GR00-3AR2): All versions SCALANCE XR524-8C, 2x230V (6GK5524-8GS00-4AR2): All versions SCALANCE XR524-8C, 2x230V (L3 int.) (6GK5524-8GR00-4AR2): All versions SCALANCE XR524-8C, 24V (6GK5524-8GS00-2AR2): All versions SCALANCE XR524-8C, 24V (L3 int.) (6GK5524-8GR00-2AR2): All versions SCALANCE XR526-8C, 1x230V (6GK5526-8GS00-3AR2): All versions SCALANCE XR526-8C, 1x230V (L3 int.) (6GK5526-8GR00-3AR2): All versions SCALANCE XR526-8C, 2x230V (6GK5526-8GS00-4AR2): All versions SCALANCE XR526-8C, 2x230V (L3 int.) (6GK5526-8GR00-4AR2): All versions SCALANCE XR526-8C, 24V (6GK5526-8GS00-2AR2): All versions SCALANCE XR526-8C, 24V (L3 int.) (6GK5526-8GR00-2AR2): All versions SCALANCE XR528-6M (6GK5528-0AA00-2AR2): All versions SCALANCE XR528-6M (2HR2) (6GK5528-0AA00-2HR2): All versions SCALANCE XR528-6M (2HR2, L3 int.) (6GK5528-0AR00-2HR2): All versions SCALANCE XR528-6M (L3 int.) (6GK5528-0AR00-2AR2): All versions SCALANCE XR552-12M (6GK5552-0AA00-2AR2): All versions SCALANCE XR552-12M (2HR2) (6GK5552-0AA00-2HR2): All versions SCALANCE XR552-12M (2HR2) (6GK5552-0AR00-2HR2): All versions SCALANCE XR552-12M (2HR2, L3 int.) (6GK5552-0AR00-2AR2): All versions SIPLUS NET SCALANCE XC206-2 (6AG1206-2BB00-7AC2): All versions SIPLUS NET SCALANCE XC206-2SFP (6AG1206-2BS00-7AC2): All versions SIPLUS NET SCALANCE XC208 (6AG1208-0BA00-7AC2): All versions SIPLUS NET SCALANCE XC216-4C (6AG1216-4BS00-7AC2): All versions --------- End Update A Part 1 of 2 ---------.","CVE-2022-36323, CVE-2022-36324, CVE-2022-36325",9.1,Critical,"CWE-74, CWE-770, CWE-80",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2166,8/9/2022,2/2/2023,2022,ICSA-22-221-01,Mitsubishi Electric Multiple Factory Automation Products (Update D),Mitsubishi Electric,"GOT2000 compatible HMI software, CC-Link IE TSN Industrial Managed Switch, MELSEC iQ-R Series OPC UA Server Module","The following version of GT SoftGOT2000 is affected: GOT2000 compatible HMI software (GT SoftGOT2000): Version 1.275M CC-Link IE TSN Industrial Managed Switch (NZ2MHG-TSNT8F2, NZ2MHG-TSNT4): Version 03 and prior [affected by CVE-2022-0778 only] MELSEC iQ-R Series OPC UA Server Module (RD81OPC96): Version 08 and prior [affected by CVE-2022-0778 only].","CVE-2022-0778, CVE-2022-1292",9.8,Critical,"CWE-835, CWE-78",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2165,8/9/2022,8/9/2022,2022,ICSA-22-221-02,Emerson ControlWave,Emerson,ControlWave,"The following versions of ControlWave, a programmable controller, are affected: ControlWave: All versions.",CVE-2022-30262,9.1,Critical,CWE-345,Oil and Gas; Petrochemical; Chemical; Life Sciences; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2164,8/9/2022,8/9/2022,2022,ICSA-22-221-03,Emerson OpenBSI,Emerson,OpenBSI,"The following versions of OpenBSI, a set of network communication services, are affected: OpenBSI: Versions 5.9 SP3 and prior.","CVE-2022-29959, CVE-2022-29960",9.6,Critical,"CWE-327, CWE-321",Oil and Gas; Petrochemical; Chemical; Life Sciences; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2163,8/4/2022,8/4/2022,2022,ICSA-22-216-01,Digi ConnectPort X2D,"Digi International, Inc.",ConnectPort X2D Gateway,The following Digi products are affected: Digi ConnectPort X2D Gateway: All firmware versions in devices manufactured prior to January 2020.,CVE-2022-2634,10.0,Critical,CWE-250,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2162,7/28/2022,7/28/2022,2022,ICSA-22-209-01,Rockwell Products Impacted by Chromium Type Confusion,Rockwell Automation,"FactoryTalk Software, Enhanced HIM for PowerFlex, Connected Components Workbench","The following versions of Rockwell products are affected: FactoryTalk Linx Enterprise software: Versions 6.20, 6.21, and 6.30 Enhanced HIM (eHIM) for PowerFlex 6000T: Version 1.001 Connected Components Workbench software: Versions 11, 12, 13, and 20 FactoryTalk View Site Edition: Version 13.",CVE-2022-1096,4.0,Medium,CWE-843,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2161,7/26/2022,7/26/2022,2022,ICSA-22-207-04,MOXA NPort 5110,Moxa,NPort 5110,The following versions of the MOXA NPort 5110 device server are affected: NPort 5110: Firmware Versions 2.10.,"CVE-2022-2044, CVE-2022-2043",8.2,High,CWE-787,Critical Manufacturing; Energy; Transportation Systems,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2160,7/26/2022,7/26/2022,2022,ICSA-22-207-03,Honeywell Saia Burgess PG5 PCD,Honeywell,Saia Burgess PG5 PCD,"The following versions of Saia Burgess PG5 PCD, a PLC, are affected: Saia Burgess PG5 PCD: All versions.","CVE-2022-30319, CVE-2022-30320",7.6,High,"CWE-288, CWE-327",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2159,7/26/2022,7/26/2022,2022,ICSA-22-207-02,Honeywell Safety Manager,Honeywell,Safety Manager,"The following versions of Safety Manager, a safety solution of the Experion Process Knowledge System, are affected: Safety Manager: (CVE-2022-30315, CVE-2022-30313, and CVE-2022-30316) All versions Safety Manager: (CVE-2022-30314) Versions prior to R160.1.","CVE-2022-30316, CVE-2022-30315, CVE-2022-30314, CVE-2022-30313",7.7,High,"CWE-345, CWE-798, CWE-306",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2158,7/26/2022,8/4/2022,2022,ICSA-22-207-01,Inductive Automation Ignition (Update A),Inductive Automation,Ignition,The following versions of Inductive Automation Ignition software are affected: -------- Begin Update A Part 1 of 1 --------- Inductive Automation Ignition: All versions from 8.1 to those prior to v8.1.8 Inductive Automation Ignition: All 7.9 versions prior to v7.9.21 --------- End Update A Part 1 of 1 ---------,CVE-2022-1704,8.5,High,CWE-611,Critical Manufacturing; Energy; Information Technology,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2157,7/21/2022,7/21/2022,2022,ICSA-22-202-05,AutomationDirect Stride Field I/O,AutomationDirect,Stride Field I/O,"AutomationDirect reports this vulnerability affects Stride Field I/O products with the following part numbers: SIO-MB04RTDS, firmware version prior to v8.3.4.0 SIO- MB04ADS, firmware version prior to v8.4.3.0 SIO-MB04THMS, firmware version prior to v8.5.4.0 SIO-MB08ADS-1, firmware version prior to v8.6.3.0 SIO-MB08ADS-2, firmware version prior to v8.7.3.0 SIO-MB08THMS, firmware version prior to v8.8.4.0 SIO-MB04DAS, firmware version prior to v8.11.3.0 SIO-MB12CDR, firmware version prior to v8.0.4.0 SIO-MB16CDD2, firmware version prior to v8.1.4.0 SIO-MB16ND3, firmware version prior to v8.2.4.00 SIO-MB12CDR, batch number (B/N) 5714442222 SIO-MB04ADS, B/N 5714442222 SIO-MB04THMS, B/N 57141862221 SIO-MB04DAS, B/N 4714432222.",CVE-2022-2485,9.6,Critical,CWE-319,Commercial Facilities; Critical Manufacturing; Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2156,7/21/2022,7/21/2022,2022,ICSA-22-202-03,Rockwell Automation ISaGRAF Workbench,Rockwell Automation,ISaGRAF Workbench,"Rockwell Automation reports these vulnerabilities affect the following versions of ISaGRAF Workbench, an automation development tool: ISaGRAF Workbench Version 6.0 through 6.6.9.","CVE-2022-2465, CVE-2022-2464, CVE-2022-2463",8.6,High,"CWE-22, CWE-502",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2155,7/21/2022,7/21/2022,2022,ICSA-22-202-02,"Johnson Controls Metasys ADS, ADX, OAS",Johnson Controls Inc.,"Metasys ADS, ADX, OAS with MUI","The following versions of Metasys ADS, ADX, OAS are affected: Johnson Controls Metasys ADS, ADX, OAS with MUI: Version 10 Johnson Controls Metasys ADS, ADX, OAS with MUI: Version 11.",CVE-2021-36200,5.3,Medium,CWE-306,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2154,7/21/2022,7/21/2022,2022,ICSA-22-202-01,"ABB Drive Composer, Automation Builder, Mint Workbench",ABB,"Drive Composer, Automation Builder, Mint Workbench",The following ABB products are affected: ABB Drive Composer Entry: Versions 2.0 to 2.7 ABB Drive Composer Pro: Versions 2.0 to 2.7 ABB Automation Builder: Versions 1.1.0 to 2.5.0 Mint Workbench: Builds 5866 and prior.,"CVE-2022-31216, CVE-2022-31217, CVE-2022-31218, CVE-2022-31219, CVE-2022-26057",7.8,High,CWE-269,Multiple Critical Sectors,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2153,7/19/2022,9/20/2022,2022,ICSA-22-200-01,MiCODUS MV720 GPS tracker (Update A),MiCODUS,MV720 GPS tracker,The following versions of MV720 GPS tracker are affected: MV720 model.,"CVE-2022-2107, CVE-2022-2141, CVE-2022-2199, CVE-2022-34150, CVE-2022-33944",9.8,Critical,"CWE-798, CWE-287, CWE-79, CWE-639",Transportation Systems; Government Facilities; Financial Services; Critical Manufacturing,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2152,7/14/2022,7/14/2022,2022,ICSA-22-195-02,Siemens SICAM GridEdge,Siemens,SICAM GridEdge,The following versions of SICAM GridEdge are affected: SICAM GridEdge Essential ARM (6MD7881-2AA30): All versions. SICAM GridEdge Essential Intel (6MD7881-2AA40): All versions prior to v2.7.3 SICAM GridEdge Essential with GDS ARM (6MD7881-2AA10): All versions. SICAM GridEdge Essential with GDS Intel(6MD7881-2AA20): All versions prior to v2.7.3.,CVE-2022-34464,6.3,Medium,CWE-668,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2151,7/14/2022,9/15/2022,2022,ICSA-22-195-09,Simcenter Femap and Parasolid (Update B),Siemens,Simcenter Femap and Parasolid,"The following versions of Simcenter Femap, an advanced simulation application, and Parasolid, a 3D geometric modeling tool, are affected: Parasolid v33.1: All versions prior to V33.1.264 Parasolid v34.0: All versions prior to v34.0.250 Parasolid v34.1: All versions prior to v34.1.233 --------- Begin Update B Part 1 of 2 --------- Simcenter Femap V2022.1: All versions prior to V2022.1.3 Simcenter Femap V2022.2: All versions prior to V2022.2.2 --------- End Update B Part 1 of 2 ---------.",CVE-2022-34465,7.8,High,CWE-125,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2150,7/14/2022,7/14/2022,2022,ICSA-22-195-01,Siemens SCALANCE X Switch Devices,Siemens,SCALANCE X Switch Devices,"The following versions of SCALANCE X Switch Devices, industrial ethernet switches, are affected: SCALANCE X200-4P IRT (6GK5200-4AH00-2BA3): All versions SCALANCE X200-4P IRT (6GK5200-4AH10-2BA3): All versions SCALANCE X201-3P IRT (6GK5201-3BH00-2BA3): All versions SCALANCE X201-3P IRT (6GK5201-3BH10-2BA3): All versions SCALANCE X201-3P IRT PRO (6GK5201-3BH00-2BD2): All versions SCALANCE X201-3P IRT PRO (6GK5201-3JR10-2BA6): All versions SCALANCE X202-2IRT (6GK5202-2BB00-2BA3): All versions SCALANCE X202-2IRT (6GK5202-2BB10-2BA3): All versions SCALANCE X202-2P IRT (6GK5202-2BH00-2BA3): All versions SCALANCE X202-2P IRT (6GK5202-2BH10-2BA3): All versions SCALANCE X202-2P IRT PRO (6GK5202-2JR00-2BA6): All versions SCALANCE X202-2P IRT PRO (6GK5202-2JR10-2BA6): All versions SCALANCE X204-2 (6GK5204-2BB10-2AA3): All versions prior to v5.2.6 SCALANCE X204-2FM (6GK5204-2BB11-2AA3): All versions prior to v5.2.6 SCALANCE X204-2LD (6GK5204-2BC10-2AA3): All versions prior to v5.2.6 SCALANCE X204-2LD TS (6GK5204-2BC10-2CA2): All versions prior to v5.2.6 SCALANCE X204-2TS (6GK5204-2BB10-2CA2): All versions prior to v5.2.6 SCALANCE X204IRT (6GK5204-0BA00-2BA3): All versions SCALANCE X204IRT (6GK5204-0BA10-2BA3): All versions SCALANCE X204IRT PRO (6GK5204-0JA00-2BA6): All versions SCALANCE X204IRT PRO (6GK5204-0JA10-2BA6): All versions SCALANCE X206-1 (6GK5206-1BB10-2AA3): All versions prior to v5.2.6 SCALANCE X206-1LD (6GK5206-1BC10-2AA3): All versions prior to v5.2.6 SCALANCE X208 (6GK5208-0BA10-2AA3): All versions prior to v5.2.6 SCALANCE X208PRO (6GK5208-0HA10-2AA6): All versions prior to v5.2.6 SCALANCE X212-2 (6GK5212-2BB00-2AA3): All versions prior to v5.2.6 SCALANCE X212-2LD (6GK5212-2BC00-2AA3): All versions prior to v5.2.6 SCALANCE X216 (6GK5216-0BA00-2AA3): All versions prior to v5.2.6 SCALANCE X224 (6GK5224-0BA00-2AA3): All versions prior to v5.2.6 SCALANCE XF201-3P IRT (6GK5201-3JR00-2BA6): All versions SCALANCE XF202-2P IRT (6GK5202-2BH00-2BD2): All versions SCALANCE XF204 (6GK5204-0BA00-2AF2): All versions prior to v5.2.6 SCALANCE XF204-2 (6GK5204-2BC00-2AF2): All versions prior to v5.2.6 SCALANCE XF204-2BA IRT (6GK5204-2AA00-2BD2): All versions SCALANCE XF204IRT (6GK5204-0BA00-2BF2): All versions SCALANCE XF204IRT (6GK5204-0BA10-2BF2): All versions SCALANCE XF206-1 (6GK5206-1BC00-2AF2): All versions prior to v5.2.6 SCALANCE XF208 (6GK5208-0BA00-2AF2): All versions prior to v5.2.6.","CVE-2022-26647, CVE-2022-26648, CVE-2022-26649",9.6,Critical,"CWE-330, CWE-120",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2149,7/14/2022,7/14/2022,2022,ICSA-22-195-03,Siemens SIMATIC MV500 Devices,Siemens,SIMATIC MV500 Devices,"The following versions of SIMATIC MV500 Devices, Optical Readers, are affected: SIMATIC MV540 H (6GF3540-0GE10): All versions prior to v3.3 SIMATIC MV540 S (6GF3540-0CD10): All versions prior to v3.3 SIMATIC MV550 H (6GF3550-0GE10): All versions prior to v3.3 SIMATIC MV550 S (6GF3550-0CD10): All versions prior to v3.3 SIMATIC MV560 U (6GF3560-0LE10): All versions prior to v3.3 SIMATIC MV560 X (6GF3560-0HE10): All versions prior to v3.3.","CVE-2022-33137, CVE-2022-33138",8.0,High,"CWE-613, CWE-306",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2148,7/14/2022,7/14/2022,2022,ICSA-22-195-11,Open Design Alliance Drawings SDK,Open Design Alliance,Drawings SDK,"The following versions of Drawing SDK, a professional SDK platform, are affected: Drawing SDK (CVE-2022-28807): All versions prior to 2023.2 Drawing SDK (CVE-2022-28808): All versions prior to 2023.3 Drawing SDK (CVE-2022-28809): All versions prior to 2023.3.","CVE-2022-28807, CVE-2022-28808, CVE-2022-28809",7.8,High,CWE-125,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2147,7/14/2022,7/14/2022,2022,ICSA-22-195-13,Siemens Mendix,Siemens,Mendix,"The following versions of Mendix, a high productivity app platform, are affected: Mendix Applications using Mendix 7: All versions prior to v7.23.31 Mendix Applications using Mendix 8: All versions prior to v8.18.18 Mendix Applications using Mendix 9: All versions prior to v9.14.0 Mendix Applications using Mendix 9 (V9.6): All versions prior to v9.6.12 Mendix Applications using Mendix 9 (V9.12): All versions prior to v9.12.2.",CVE-2022-31257,4.9,Medium,CWE-284,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2146,7/14/2022,7/14/2022,2022,ICSA-22-195-04,Siemens Simcenter Femap,Siemens,Simcenter Femap,"Siemens reports the following versions of Simcenter Femap, a complex model simulator, are affected: All versions prior to v2022.2.",CVE-2022-34748,7.8,High,CWE-787,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2145,7/14/2022,7/14/2022,2022,ICSA-22-195-14,Siemens CPC80 Firmware of SICAM A8000,Siemens,CPC80 Firmware of SICAM A8000,"The following Siemens products are affected: CP-8000 MASTER MODULE WITH I/O -25/+70°C (6MF2101-0AB10-0AA0): All versions prior to CPC80 v16.30 CP-8000 MASTER MODULE WITH I/O -40/+70°C"" (6MF2101-1AB10-0AA0): All version prior to CPC80 v16.30 CP-8021 MASTER MODULE (6MF2802-1AA00): All versions prior to CPC80 v16.30 CP-8022 MASTER MODULE WITH GPRS (6MF2802-2AA00): All versions prior to CPC80 v16.30.",CVE-2022-29884,7.5,High,CWE-772,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2144,7/14/2022,7/14/2022,2022,ICSA-22-195-10,Siemens Mendix Applications,Siemens,Mendix Applications,"The following versions of Mendix Applications, high productivity app platform, are affected: Mendix Applications using Mendix 9: All versions between v9.11 v9.15 Mendix Applications using Mendix 9 (v9.12): All versions prior to v9.12.3.",CVE-2022-34466,6.5,Medium,CWE-74,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2143,7/14/2022,8/11/2022,2022,ICSA-22-195-12,Siemens SRCS VPN Feature in SIMATIC CP Devices (Update A),Siemens,SIMATIC CP Devices,"The following versions of SIMATIC CP Devices, communication processors, are affected: --------- Begin Update A Part 1 of 2 --------- SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0): All versions prior to V3.3.46 SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0): All versions prior to V3.3.46 SIMATIC CP 1243-7 LTE EU (6GK7243-7KX30-0XE0): All versions prior to V3.3.46 SIMATIC CP 1243-7 LTE US (6GK7243-7SX30-0XE0): All versions prior to V3.3.46 SIMATIC CP 1243-8 IRC (6GK7243-8RX30-0XE0): All versions prior to V3.3.46 SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0): All versions v2.0 and later SIMATIC CP 1543-1 (6GK7543-1AX00-0XE0): All versions prior to v3.0.22 SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0): All versions v2.0 and later SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0): All versions v2.0 and later SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0): All versions v2.0 and later SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0): All versions v2.0 and later SIPLUS NET CP 1242-7 V2 (6AG1242-7KX31-7XE0): All versions prior to V3.3.46 SIPLUS NET CP 1543-1 (6AG1543-1AX00-2XE0): All versions prior to v3.0.22 SIPLUS S7-1200 CP 1243-1 (6AG1243-1BX30-2AX0): All versions prior to V3.3.46 SIPLUS S7-1200 CP 1243-1 RAIL (6AG2243-1BX30-1XE0): All versions prior to V3.3.46 --------- End Update A Part 1 of 2 ---------","CVE-2022-34819, CVE-2022-34820, CVE-2022-34821",10.0,Critical,"CWE-122, CWE-77, CWE-94",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2142,7/14/2022,7/14/2022,2022,ICSA-22-195-15,Siemens SIMATIC eaSie Core Package,Siemens,SIMATIC eaSie,"The following versions of SIMATIC eaSie, a digital automation manager, are affected: Core Package (6DL5424-0AX00-0AV8): All versions prior to v22.00.","CVE-2021-44221, CVE-2021-44222",10.0,Critical,"CWE-20, CWE-306",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2141,7/14/2022,7/14/2022,2022,ICSA-22-195-05,Siemens RUGGEDCOM ROX,Siemens,RUGGEDCOM ROX,The following Siemens products are affected: RUGGEDCOM ROX MX5000: All versions prior to 2.15.1 RUGGEDCOM ROXMX5000RE: All versions prior to 2.15.1 RUGGEDCOM ROX RX1400: All versions prior to 2.15.1 RUGGEDCOM ROX RX1500: All versions prior to 2.15.1 RUGGEDCOM ROX RX1501: All versions prior to 2.15.1 RUGGEDCOM ROX RX1510: All versions prior to 2.15.1 RUGGEDCOM ROX RX1511: All versions prior to 2.15.1 RUGGEDCOM ROX RX1512: All versions prior to 2.15.1 RUGGEDCOM ROX RX1524: All versions prior to 2.15.1 RUGGEDCOM ROX RX1536: All versions prior to 2.15.1 RUGGEDCOM ROX RX5000: All versions prior to 2.15.1.,CVE-2022-29560,7.2,High,CWE-77,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2140,7/14/2022,7/14/2022,2022,ICSA-22-195-06,Siemens Mendix Excel Importer,Siemens,Mendix Excel Importer Module,The following Siemens products are affected: Mendix Excel Importer Module (Mendix 8 compatible): All versions prior to v9.2.2 Mendix Excel Importer Module (Mendix 9 compatible): All versions prior to v10.1.2.,CVE-2022-34467,6.5,Medium,CWE-776,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2139,7/14/2022,7/14/2022,2022,ICSA-22-195-08,Siemens PADS Standard/Plus Viewer,Siemens,PADS Standard/Plus Viewer,"The following versions of PADS Standard and Standard Plus, a PCB schematic design and layout environment, are affected: PADS Standard/Plus Viewer: All versions.","CVE-2022-34272, CVE-2022-34273, CVE-2022-34274, CVE-2022-34275, CVE-2022-34276, CVE-2022-34277, CVE-2022-34278, CVE-2022-34279, CVE-2022-34280, CVE-2022-34281, CVE-2022-34282, CVE-2022-34283, CVE-2022-34284, CVE-2022-34285, CVE-2022-34286, CVE-2022-34287, CVE-2022-34288, CVE-2022-34289, CVE-2022-34290, CVE-2022-34291",7.8,High,"CWE-125, CWE-787, CWE-119, CWE-125",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2138,7/14/2022,8/11/2022,2022,ICSA-22-195-18,Siemens RUGGEDCOM ROS (Update A),Siemens,RUGGEDCOM ROS,Siemens reports this vulnerability affects the following RUGGEDCOM ROS-based devices: RUGGEDCOM ROS i800: All versions RUGGEDCOM ROS i801: All versions RUGGEDCOM ROS i802: All versions RUGGEDCOM ROS i803: All versions RUGGEDCOM ROS M969: All versions RUGGEDCOM ROS M2100: All versions RUGGEDCOM ROS M2200: All versions RUGGEDCOM ROS RMC: All versions RUGGEDCOM ROS RMC20: All versions RUGGEDCOM ROS RMC30: All versions RUGGEDCOM ROS RMC40: All versions RUGGEDCOM ROS RMC41: All versions RUGGEDCOM ROS RMC8388: All versions prior to v5.6.0 RUGGEDCOM ROS RP110: All versions RUGGEDCOM ROS RS400: All versions RUGGEDCOM ROS RS401: All versions RUGGEDCOM ROS RS416: All versions RUGGEDCOM ROS RS416v2: All versions prior to v5.6.0 RUGGEDCOM ROS RS900 (32M): All versions prior to v5.6.0 RUGGEDCOM ROS RS900G: All versions RUGGEDCOM ROS RS900G (32M): All versions prior to v5.6.0 RUGGEDCOM ROS RS900GP: All versions RUGGEDCOM ROS RS900L: All versions RUGGEDCOM ROS RS900W: All versions RUGGEDCOM ROS RS910: All versions RUGGEDCOM ROS RS910L: All versions RUGGEDCOM ROS RS910W: All versions RUGGEDCOM ROS RS920L: All versions RUGGEDCOM ROS RS920W: All versions RUGGEDCOM ROS RS930L: All versions RUGGEDCOM ROS RS930W: All versions RUGGEDCOM ROS RS940G: All versions RUGGEDCOM ROS RS969: All versions --------- Begin Update A Part 1 of 1 --------- RUGGEDCOM ROS RS900: All versions RUGGEDCOM ROS RS1600: All versions RUGGEDCOM ROS RS1600F: All versions RUGGEDCOM ROS RS1600T: All versions --------- End Update A Part 1 of 1 --------- RUGGEDCOM ROS RS8000: All versions RUGGEDCOM ROS RS8000A: All versions RUGGEDCOM ROS RS8000H: All versions RUGGEDCOM ROS RS8000T: All versions RUGGEDCOM ROS RSG907R: All versions prior to v5.6.0 RUGGEDCOM ROS RSG908C: All versions prior to v5.6.0 RUGGEDCOM ROS RSG909R: All versions prior to v5.6.0 RUGGEDCOM ROS RSG910C: All versions prior to v5.6.0 RUGGEDCOM ROS RSG920P: All versions prior to v5.6.0 RUGGEDCOM ROS RSG2100: All versions RUGGEDCOM ROS RSG2100 (32M): All versions prior to v5.6.0 RUGGEDCOM ROS RSG2100P: All versions RUGGEDCOM ROS RSG2200: All versions RUGGEDCOM ROS RSG2288: All versions prior to v5.6.0 RUGGEDCOM ROS RSG2300: All versions prior to v5.6.0 RUGGEDCOM ROS RSG2300P: All versions prior to v5.6.0 RUGGEDCOM ROS RSG2488: All versions prior to v5.6.0 RUGGEDCOM ROS RSL910: All versions prior to v5.6.0 RUGGEDCOM ROS RST916C: All versions prior to v5.6.0 RUGGEDCOM ROS RST916P: All versions prior to v5.6.0 RUGGEDCOM ROS RST2228: All versions prior to v5.6.0 RUGGEDCOM ROS RST2228P: All versions prior to v5.6.0.,CVE-2022-34663,8.0,High,CWE-94,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2137,7/14/2022,7/14/2022,2022,ICSA-22-195-16,Siemens EN100 Ethernet Module,Siemens,EN100 Ethernet Module,Siemens reports this vulnerability affects the following ethernet modules: EN100 Ethernet module DNP3 IP variant: All versions EN100 Ethernet module IEC 104 variant: All versions EN100 Ethernet module IEC 61850 variant: All versions prior to v4.40 EN100 Ethernet module Modbus TCP variant: All versions EN100 Ethernet module PROFINET IO variant: All versions.,CVE-2022-30938,8.6,High,CWE-119,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2136,7/14/2022,8/11/2022,2022,ICSA-22-195-07,Siemens Datalogics File Parsing Vulnerability (Update A),Siemens,Teamcenter Visualization and JT2Go,The following Siemens products are affected: Teamcenter Visualization V13.3: All versions prior to 13.3.0.5 --------- Begin Update A Part 1 of 3 --------- Teamcenter Visualization V14.0: All versions prior to 14.0.0.2 --------- End Update A Part 1 of 3 ---------. JT2go: All versions prior to 13.3.0.5,CVE-2022-2069,7.8,High,CWE-122,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2135,7/14/2022,7/14/2022,2022,ICSA-22-195-17,Siemens Opcenter Quality,Siemens,Opcenter Quality,Siemens reports this vulnerability affects the following quality management systems: Opcenter Quality V13.1: All versions prior to v13.1.20220624 Opcenter Quality V13.2: All versions prior to v13.2.20220624.,CVE-2022-33736,9.6,Critical,CWE-303,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2134,7/12/2022,7/19/2022,2022,ICSA-22-193-01,Dahua ASI7213X-T1 (Update A),"Dahua Technology Co., Ltd",DHI-ASI7213X-T1,"The following versions of Dahua video products, are affected: --------- Begin Update A Part 2 of 4 --------- Dahua ASI7XXX: Versions prior to v1.000.0000009.0.R.220620 Dahua IPC-HDBW2XXX: Versions prior to v2.820.0000000.48.R.220614 Dahua IPC-HX2XXX: Versions Prior to v2.820.0000000.48.R.220614 --------- End Update A Part 2 of 4 ---------.","CVE-2022-30560, CVE-2022-30561, CVE-2022-30562, CVE-2022-30563",8.1,High,"CWE-434, CWE-294, CWE-209",Multiple Critical Sectors,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2133,7/7/2022,7/7/2022,2022,ICSA-22-188-01,Rockwell Automation MicroLogix,Rockwell Automation,MicroLogix 1100/1400,Rockwell Automation reports this vulnerability affects the following MicroLogix controllers: MicroLogix 1400: Versions 21.007 and prior MicroLogix 1100: All versions.,CVE-2022-21798,6.5,Medium,CWE-1021,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2132,7/7/2022,7/7/2022,2022,ICSA-22-188-02,Bently Nevada ADAPT 3701/4X Series and 60M100,Bently Nevada (Subsidiary of Baker Hughes),3701/4X series and 60M100 (3701/60) Condition Monitoring System,The following versions of Bently Nevada 3700 machinery monitors are affected: Bently Nevada 3701/40: All versions prior to 4.1 Bently Nevada 3701/44: All versions prior to 4.1 Bently Nevada 3701/46: All versions prior to 4.1 Bently Nevada 60M100 (3701/60): All versions.,"CVE-2022-29953, CVE-2022-29952",9.1,Critical,"CWE-798, CWE-306",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2131,6/30/2022,6/30/2022,2022,ICSA-22-181-01,Exemys RME1,Exemys,RME1,"The following versions of Exemys RME1, an analog acquisition module, are affected: Exemys RME1-AI firmware: All versions prior to and including 2.1.6.",CVE-2022-2197,9.8,Critical,CWE-287,Multiple Critical Sectors,Worldwide,Argentina,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2130,6/30/2022,6/30/2022,2022,ICSA-22-181-02,Yokogawa Wide Area Communication Router,Yokogawa,Wide Area Communication Router (WAC Router),Yokogawa reports this vulnerability affects the communication module for the following WAC Router: Wide Area Communication Router (for AW810D) VI461: Vnet/IP firmware (F) R12 or earlier.,CVE-2022-32284,5.9,Medium,CWE-330,Critical Manufacturing; Energy; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2129,6/30/2022,6/30/2022,2022,ICSA-22-181-03,Emerson DeltaV Distributed Control System,Emerson,DeltaV Distributed Control System,"The following versions of DeltaV Distributed Control System, a software management platform, are affected: DeltaV M-series: All versions DeltaV S-series: All versions DeltaV P-series: All versions DeltaV SIS: All versions DeltaV CIOC/EIOC/WIOC IO cards: All versions.","CVE-2022-29957, CVE-2022-29962, CVE-2022-29963, CVE-2022-29964, CVE-2022-30260, CVE-2022-29965",8.8,High,"CWE-306, CWE-798, CWE-345, CWE-327",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2128,6/30/2022,6/30/2022,2022,ICSA-22-181-04,Distributed Data Systems WebHMI,Distributed Data Systems,WebHMI,The following versions of WebHMI are affected: WebHMI 4.1.1.7662 (and possibly prior versions).,"CVE-2022-2254, CVE-2022-2253",9.1,Critical,"CWE-79, CWE-78",Commercial Facilities; Critical Manufacturing; Food and Agriculture; Water and Wastewater Systems,"Europe, North America",Ukraine,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2127,6/28/2022,6/28/2022,2022,ICSA-22-179-01,ABB e-Design,ABB,e-Design,The following versions of e-Design engineering software are affected: e-Design: All versions prior to 1.12.2.0006.,"CVE-2022-28702, CVE-2022-29483",7.8,High,CWE-276,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2126,6/28/2022,2/9/2023,2022,ICSA-22-179-02,Omron SYSMAC CS-CJ-CP Series and NJ-NX Series (Update A),Omron,SYSMAC CS/CJ/CP Series and NJ/NX Series,"""¯The following versions of the Omron SYSMAC CS/CJ/CP Series and NJ/NX Series, a programmable logic controller, are affected: --------- Begin Update A part 1 of 4 --------- SYSMAC CS1H/CJ1G: Versions prior to 4.1 SYSMAC CS1D-CPU H/P/HA: Versions prior to 1.4 SYSMAC CS1D-CPU S/SA: Versions prior to 2.1 --------- End Update A part 1 of 4 --------- SYSMAC CJ2M: Versions prior to 2.1 SYSMAC CJ2H: Versions prior to 1.5 SYSMAC CP1E/CP1H: Versions prior to 1.30 --------- Begin Update A part 2 of 4 --------- SYSMAC CP1L: Versions prior to 1.1 --------- End Update A part 2 of 4 --------- CP1W-CIF41: All versions SYSMAC CX-Programmer: Versions prior to 9.6 SYSMAC NJ/NX Series: Versions prior to 1.49 (1.29 for NX7)","CVE-2022-31204, CVE-2022-31205, CVE-2022-31207, CVE-2022-31206",6.5,Medium,"CWE-319, CWE-256, CWE-345, CWE-347",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2125,6/28/2022,6/28/2022,2022,ICSA-22-179-03,Advantech iView,Advantech,iView,The following versions of Advantech iView management software are affected: Advantech iView: All versions prior to 5_7_04_6469.,"CVE-2022-2135, CVE-2022-2136, CVE-2022-2137, CVE-2022-2142, CVE-2022-2138, CVE-2022-2139, CVE-2022-2143",9.8,Critical,"CWE-89, CWE-306, CWE-23, CWE-77",Multiple Critical Sectors,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2124,6/28/2022,6/28/2022,2022,ICSA-22-179-04,Motorola Solutions MOSCAD IP and ACE IP Gateways,Motorola Solutions,MOSCAD IP Gateway and ACE IP Gateway,The following versions of Motorola MDLC are affected: MOSCAD IP gateway (IPGW): All versions ACE IP gateway (CPU 4600): All versions.,CVE-2022-30276,7.5,High,CWE-306,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2123,6/28/2022,6/28/2022,2022,ICSA-22-179-05,Motorola Solutions MDLC,Motorola Solutions,MDLC,"The following versions of the Motorola Solutions MDLC protocol parser are affected: MDLC: Versions 4.80.0024, 4.82.004, and 4.83.001.","CVE-2022-30273, CVE-2022-30275",7.5,High,"CWE-327, CWE-256",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2122,6/28/2022,6/28/2022,2022,ICSA-22-179-06,Motorola Solutions ACE1000,Motorola Solutions,ACE1000,"The following versions of ACE1000, a remote terminal unit, are affected: Motorola Solutions ACE1000: All versions.","CVE-2022-30271, CVE-2022-30270, CVE-2022-30274, CVE-2022-30269, CVE-2022-30272",9.8,Critical,"CWE-321, CWE-798, CWE-345",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2121,6/23/2022,6/23/2022,2022,ICSMA-22-174-01,OFFIS DCMTK,OFFIS,DCMTK,"The following versions of DCMTK, libraries and software that process DICOM image files, are affected: DCMTK: All versions prior to 3.6.7.","CVE-2022-2119, CVE-2022-2120, CVE-2022-2121",7.5,High,"CWE-22, CWE-23, CWE-476",Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2120,6/23/2022,6/23/2022,2022,ICSA-22-174-01,Yokogawa STARDOM,Yokogawa,STARDOM,"The following versions of STARDOM, a network control system, are affected: STARDOM FCN/FCJ: Versions R1.01 through R4.31 STARDOM FCN/FCJ: Versions R4.10 through R4.31, dual CPU modules only; only affected by CVE-2022-30997.","CVE-2022-2951, CVE-2022-30997",6.3,Medium,"CWE-319, CWE-798",Multiple Critical Sectors,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2119,6/23/2022,6/23/2022,2022,ICSA-22-174-02,Yokogawa CAMS for HIS,Yokogawa,Consolidation Alarm Management Software for Human Interface Station (CAMS for HIS),"The following products that use CAMS for HIS, are affected: CENTUM CS 3000 (including CENTUM CS 3000 Entry Class): Versions R3.08.10 through R3.09.00. These vulnerabilities affect this product if LHS4800 (CAMS for HIS) is installed. CENTUM VP (including CENTUM VP Entry Class): Versions R4.01.00 through R4.03.00 (these product versions are affected only if CAMS function is used), Versions R5.01.00 through R5.04.20, and R6.01.00 through R6.09.00 (these product versions are affected regardless of whether CAMS function is used or not). Exaopc: Versions R3.72.00 through R3.80.00 (these product versions are affected if NTPF100-S6 ""For CENTUM VP Support CAMS for HIS"" is installed). B/M9000CS: Versions R5.04.01 - R5.05.01 B/M9000 VP: Versions R6.01.01 - R8.03.01.",CVE-2022-30707,6.4,Medium,CWE-657,Critical Manufacturing; Energy; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2118,6/23/2022,6/23/2022,2022,ICSA-22-174-03,Secheron SEPCOS Control and Protection Relay,Secheron,SEPCOS Control and Protection Relay,The following firmware versions of the Secheron SEPCOS Control and Protection Relay are affected: SEPCOS Single Package firmware (1.23.xx feature level): All versions prior to 1.23.21 SEPCOS Single Package firmware (1.24.xx feature level): All versions prior to 1.24.8 SEPCOS Single Package firmware (1.25.xx feature level): All versions prior to 1.25.3.,"CVE-2022-2105, CVE-2022-1667, CVE-2022-2102, CVE-2022-1668, CVE-2022-2103, CVE-2022-2104, CVE-2022-1666",9.9,Critical,"CWE-841, CWE-521, CWE-284, CWE-269, CWE-522",Multiple Critical Sectors,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2117,6/23/2022,6/23/2022,2022,ICSA-22-174-04,Pyramid Solutions EtherNet/IP Adapter Development Kit,"Pyramid Solutions, Inc.",EtherNet/IP Adapter Development Kit,The following versions of Pyramid Solutions' products are affected: EtherNet/IP Adapter Development Kit (EADK): Versions 4.4.0 and prior EtherNet/IP Adapter DLL Kit (EIPA): Versions 4.4.0 and prior EtherNet/IP Scanner Development Kit (EDKS): Versions 4.4.0 and prior. EtherNet/IP Scanner DLL Kit (EIPS): Versions 4.4.0 and prior,CVE-2022-1737,9.8,Critical,CWE-787,Critical Manufacturing; Financial Services,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2116,6/23/2022,6/23/2022,2022,ICSA-22-174-05,Elcomplus SmartICS,Elcomplus,SmartICS,Elcomplus reports these vulnerabilities affect the following SmartICS web-based HMI: SmartICS v2.3.4.0.,"CVE-2022-2140, CVE-2022-2106, CVE-2022-2088",8.8,High,"CWE-79, CWE-23, CWE-284",Communications; Commercial Facilities; Energy; Water and Wastewater Systems,Worldwide,Russia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2115,6/14/2022,6/4/2024,2022,ICSA-22-172-01,"Mitsubishi Electric MELSEC iQ-R, Q, L Series and MELIPC Series (Update C)",Mitsubishi Electric,"MELSEC iQ-R, Q, and L Series CPU Module; MELIPC Series CPU",The following Mitsubishi Electric products are affected: MELSEC iQ-R Series R12CCPU-V CPU Firmware: Version 16 and prior MELSEC Q Series Q03UDECPU: Versions with the first 5 digits of serial number 24061 and prior MELSEC Q Series Q04UDECPU: Versions with the first 5 digits of serial number 24061 and prior MELSEC Q Series Q06UDECPU: Versions with the first 5 digits of serial number 24061 and prior MELSEC Q Series Q10UDECPU: Versions with the first 5 digits of serial number 24061 and prior MELSEC Q Series Q13UDECPU: Versions with the first 5 digits of serial number 24061 and prior MELSEC Q Series Q20UDECPU: Versions with the first 5 digits of serial number 24061 and prior MELSEC Q Series Q26UDECPU: Versions with the first 5 digits of serial number 24061 and prior MELSEC Q Series Q50UDECPU: Versions with the first 5 digits of serial number 24061 and prior MELSEC Q Series Q100UDECPU: Versions with the first 5 digits of serial number 24061 and prior MELSEC Q Series Q03UDVCPU: Versions with the first 5 digits of serial number 24051 and prior MELSEC Q Series Q04UDVCPU: Versions with the first 5 digits of serial number 24051 and prior MELSEC Q Series Q06UDVCPU: Versions with the first 5 digits of serial number 24051 and prior MELSEC Q Series Q13UDVCPU: Versions with the first 5 digits of serial number 24051 and prior MELSEC Q Series Q26UDVCPU: Versions with the first 5 digits of serial number 24051 and prior MELSEC Q Series Q04UDPVCPU: Versions with the first 5 digits of serial number 24051 and prior MELSEC Q Series Q06UDPVCPU: Versions with the first 5 digits of serial number 24051 and prior MELSEC Q Series Q13UDPVCPU: Versions with the first 5 digits of serial number 24051 and prior MELSEC Q Series Q26UDPVCPU: Versions with the first 5 digits of serial number 24051 and prior MELSEC Q Series Q12DCCPU-V: Versions with the first 5 digits of serial number 25061 and prior MELSEC Q Series Q24DHCCPU-V(G): Versions with the first 5 digits of serial number 25061 and prior MELSEC Q Series Q24DHCCPU-LS: Versions with the first 5 digits of serial number 25061 and prior MELSEC Q Series Q26DHCCPU-LS: Versions with the first 5 digits of serial number 25061 and prior MELSEC L Series L02CPU(-P): Versions with the first 5 digits of serial number 24051 and prior MELSEC L Series L06CPU(-P): Versions with the first 5 digits of serial number 24051 and prior MELSEC L Series L26CPU(-P): Versions with the first 5 digits of serial number 24051 and prior MELSEC L Series L26CPU-(P)BT: Versions with the first 5 digits of serial number 24051 and prior MELIPC Series MI5122-VW CPU Firmware: Version 05 and prior.,CVE-2022-24946,7.5,High,CWE-413,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2114,6/21/2022,6/21/2022,2022,ICSA-22-172-02,JTEKT TOYOPUC,JTEKT ELECTRONICS CORPORATION,TOYOPUC Products,"The following versions of TOYOPUC products, a programmable logic controller, are affected: PC10G-CPU Type=TCC-6353: All versions PC10GE Type=TCC-6464: All versions PC10P Type=TCC-6372: All versions PC10P-DP Type=TCC-6726: All versions PC10P-DP-IO Type=TCC-6752: All versions PC10B-P Type=TCC-6373: All versions PC10B Type=TCC-1021: All versions PC10E Type=TCC-4737: All versions PC10EL Type=TCC-4747: All versions Plus CPU Type=TCC-6740: All versions PC3JX Type=TCC-6901: All versions PC3JX-D Type=TCC-6902: All versions PC10PE Type=TCC-1101: All versions PC10PE-1616P Type=TCC-1102: All versions PCDL Type=TKC-6688: All versions Nano 10GX Type=TUC-1157: All versions Nano CPU Type=TUC-6941: All versions.","CVE-2022-29951, CVE-2022-29958",7.7,High,"CWE-306, CWE-345",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2113,6/21/2022,6/21/2022,2022,ICSA-22-172-03,Phoenix Contact Classic Line Controllers,PHOENIX CONTACT,"ILC, AXC, RFC, PC WORX, FC","The following versions of the classic line industrial controllers, are affected: ILC 1x0 All variants ILC 1x1 All variants ILC 1x1 GSM/GPRS: Article number 2700977 ILC 3xx All variants AXC 1050: Article number 2700988 AXC 1050 XC: Article number 2701295 AXC 3050: Article number 2700989 RFC 480S PN 4TX: Article number 2404577 RFC 470 PN 3TX: Article number 2916600 RFC 470S PN 3TX: Article number 2916794 FC 460R PN 3TX: Article number 2700784 RFC 460R PN 3TX-S: Article number 1096407 RFC 430 ETH-IB: Article number 2730190 RFC 450 ETH-IB: Article number 2730200 PC WORX SRT: Article number 2701680 PC WORX RT BASIC: Article number 2700291 FC 350 PCI ETH: Article number 2730844.",CVE-2022-31800,9.8,Critical,CWE-345,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2112,6/21/2022,6/21/2022,2022,ICSA-22-172-04,Phoenix Contact ProConOS and MULTIPROG,PHOENIX CONTACT,ProConOS/ProConOS eCLR and MULTIPROG,"The following versions of ProConOS, a software development kit, are affected: ProConOS: All versions ProConOS eCLR: All versions MULTIPROG: All versions.",CVE-2022-31801,9.8,Critical,CWE-345,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2111,6/21/2022,6/21/2022,2022,ICSA-22-172-05,Phoenix Contact Classic Line Industrial Controllers,PHOENIX CONTACT,"ILC 131 ETH, ILC 131 ETH/XC, ILC 151 ETH, ILC 151 ETH/XC, ILC 171 ETH 2TX, ILC 191 ETH 2TX, ILC 191 ME/AN, and AXC 1050",The following versions of the classic line industrial controllers are affected: ILC 1x0: All variants ILC 1x1: All variants ILC 3xx: All variants AXC 1050: Article number 2700988 AXC 1050XC: Article number 2701295 AXC 3050: Article number 2700989 RFC 480S: Article number 2404577 RFC 470S: Article number 2916794 RFC 460R: Article number 2700784 RFC 430 ETH: Article number 2730190 RFC 450 ETH: Article number 2730200 PC WORX SRT: Article number 2701680 PC WORX RT BASIC: Article number 2700291 FC 350 PCI ETH: Article number 2730844.,CVE-2019-9201,9.8,Critical,CWE-306,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2110,6/21/2022,6/21/2022,2022,ICSA-22-172-06,Siemens WinCC OA,Siemens,SIMATIC WinCC OA,"The following versions of SIMATIC WinCC OA, a SCADA HMI system, are affected: SIMATIC WinCC OA v3.16: All versions SIMATIC WinCC OA v3.17: All versions SIMATIC WinCC OA v3.18: All versions.",CVE-2022-33139,9.8,Critical,CWE-603,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2109,6/16/2022,6/16/2022,2022,ICSMA-22-167-01,Hillrom Medical Device Management,Hillrom,Welch Allyn medical devices,"The following Hillrom products, are affected: Welch Allyn ELI 380 Resting Electrocardiograph: Versions 2.6.0 and prior Welch Allyn ELI 280/BUR280/MLBUR 280 Resting Electrocardiograph: Versions 2.3.1 and prior Welch Allyn ELI 250c/BUR 250c Resting Electrocardiograph: Versions 2.1.2 and prior Welch Allyn ELI 150c/BUR 150c/MLBUR 150c Resting Electrocardiograph: Versions 2.2.0 and prior.","CVE-2022-26388, CVE-2022-26389",7.7,High,"CWE-259, CWE-284",Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2108,6/16/2022,6/16/2022,2022,ICSA-22-167-01,AutomationDirect C-More EA9 HMI,AutomationDirect,C-more EA9 HMI,"The following versions of C-more EA9, an industrial touch screen HMI, are affected: C-more EA9 with the following part numbers, all versions prior to 6.73: EA9-T6CL EA9-T6CL-R EA9-T7CL EA9-T7CL-R EA9-T8CL EA9-T10CL EA9-T10WCL EA9-T12CL EA9-T15CL EA9-T15CL-R EA9-RHMI EA9-PGMSW.","CVE-2022-2006, CVE-2022-2005",7.8,High,"CWE-427, CWE-319",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2107,6/16/2022,9/20/2022,2022,ICSA-22-167-02,AutomationDirect DirectLOGIC with Serial Communication (Update A),AutomationDirect,DirectLOGIC with Serial Communication,"The following versions of DirectLOGIC with serial communication, a programmable controller, are affected: The following D0-06 series CPUs, prior to v2.72: D0-06DD1 D0-06DD2 D0-06DR D0-06DA D0-06AR D0-06AA D0-06DD1-D D0-06DD2-D D0-06DR-D D0-06DD2-D D0-06DR-D --------- Begin Update A part 1 of 2 --------- D0-05DD: All versions prior to V5.41 D0-05DR: All versions prior to V5.41. D0-05DA: All versions prior to V5.41 D0-05AR: All versions prior to V5.41 D0-05AA: All versions prior to V5.41 D0-05AD: All versions prior to V5.41 D0-05DD-D: All versions prior to V5.41 D0-05DR-D: All versions prior to V5.41 D2-230: All versions D2-240: All versions D2-250: All versions D2-250-1: All versions prior to V4.91 D2-260: All versions prior to V2.71 D2-262: All versions prior to V1.06 D3-350: All versions D4-430: All versions D4-440: All versions D4-450: All versions D4-454: All versions prior to V1.04 F1-130AA: All versions F1-130AD: All versions F1-130DA: All versions F1-130DD: All versions F1-130DD-D: All versions F1-130DR-D: All versions F1-130AR: All versions F1-130DR: All versions --------- End Update A part 1 of 2 ---------.",CVE-2022-2003,7.7,High,CWE-319,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2106,6/16/2022,9/20/2022,2022,ICSA-22-167-03,AutomationDirect DirectLOGIC with Ethernet (Update A),AutomationDirect,DirectLOGIC with Ethernet Communication Modules,"The following versions of DirectLOGIC with Ethernet communication modules, a PLC Ethernet module, are affected: All versions of H0-ECOM and H0-ECOM100 when installed in the following D0-06 series CPUs versions prior to v2.72: D0-06DD1 D0-06DD2 D0-06DR D0-06DA D0-06AR D0-06AA D0-06DD1-D D0-06DD2-D D0-06DR-D --------- Begin Update A part 1 of 2 --------- All versions of H0-ECOM and H0-ECOM100 when installed in the following D0-05 series CPUs versions prior to v5.41 D0-05DD D0-05DR D0-05DA D0-05AR D0-05AA D0-05AD D0-05DD-D D0-05DR-D All versions of H2-ECOM and H2-ECOM100 when installed in the following: D2-240: All versions D2-250: All versions D2-250-1: All versions prior to 4.91 D2-260: All versions prior to 2.71 D2-262: All versions prior to 1.06 All versions of H4-ECOM and All versions of H4-ECOM100 when installed in the following: D4-430: All versions D4-440: All versions D4-450: All versions D4-454: All versions prior to 1.04 --------- End Update A part 1 of 2 ---------DirectLOGIC with Serial Communication.","CVE-2022-2004, CVE-2022-2003",7.5,High,"CWE-400, CWE-319",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2105,6/16/2022,6/16/2022,2022,ICSA-22-167-04,Siemens Mendix SAML Module,Siemens,Mendix SAML Module,Siemens reports these vulnerabilities affect the following Mendix SAML Modules: Mendix SAML Module (Mendix 7 compatible): all versions prior to v1.16.6 Mendix SAML Module (Mendix 8 compatible): all versions prior to v2.2.2 Mendix SAML Module (Mendix 9 compatible): all versions prior to v3.2.3.,"CVE-2022-32285, CVE-2022-32286",8.3,High,"CWE-611, CWE-79",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2104,6/16/2022,6/16/2022,2022,ICSA-22-167-05,Siemens EN100 Ethernet Module,Siemens,EN100 Ethernet Module,The following versions of EN100 Ethernet Module are affected: EN100 Ethernet module DNP3 IP variant: all versions EN100 Ethernet module IEC 104 variant: all versions EN100 Ethernet module IEC 61850 variant: all versions prior to v4.37 EN100 Ethernet module Modbus TCP variant: all versions EN100 Ethernet module PROFINET IO variant: all versions.,CVE-2022-30937,8.6,High,CWE-119,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2103,6/16/2022,10/13/2022,2022,ICSA-22-167-06,Siemens Apache HTTP Server (Update A),Siemens,Apache HTTP Server,The following Siemens products are affected: RUGGEDCOM NMS: All versions when using the device firmware upgrade mechanism --------- Begin Update A part 1 of 3 --------- SINEC NMS: All versions prior to v1.0.3 --------- End Update A part 1 of 3 --------- SINEMA Remote Connect Server: All versions prior to v3.1 SINEMA Server v14: All versions.,"CVE-2021-34798, CVE-2021-39275, CVE-2021-40438",9.8,Critical,"CWE-476, CWE-787, CWE-918",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2102,6/16/2022,6/16/2022,2022,ICSA-22-167-07,Siemens SINEMA Remote Connect Server,Siemens,SINEMA Remote Connect Server,Siemens reports these vulnerabilities affect the following SINEMA Remote Connect management platform: SINEMA Remote Connect Server: all versions prior to v3.0 SP2.,"CVE-2022-27219, CVE-2022-27220",4.2,Medium,CWE-358,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2101,6/16/2022,6/16/2022,2022,ICSA-22-167-08,Siemens SICAM GridEdge,Siemens,SICAM GridEdge Essential ARM,The following Siemens products are affected: SICAM GridEdge Essential ARM: All versions prior to v2.6.6 SICAM GridEdge Essential Intel: All versions prior to v2.6.6 SICAM GridEdge Essential with GDS ARM: All versions prior to v2.6.6 SICAM GridEdge Essential with GDS Intel: All versions prior to v2.6.6.,"CVE-2022-30229, CVE-2022-30230, CVE-2022-30231",10.0,Critical,"CWE-306, CWE-402",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2100,6/16/2022,6/16/2022,2022,ICSA-22-167-09,Siemens SCALANCE LPE9403 Third-Party Vulnerabilities,Siemens,SCALANCE LPE9403,"The following versions of SCALANCE LPE9403 (Local Processing Engine), a processing power extension for the SCALANCE family of products, are affected: All versions prior to v2.0 The vulnerabilities exist within the third-party components CivetWeb, Docker, Linux kernel and system, which are part of the SCALANCE LPE9403.","CVE-2020-27304, CVE-2021-20317, CVE-2021-33910, CVE-2021-36221, CVE-2021-39293, CVE-2021-41089, CVE-2021-41091, CVE-2021-41092, CVE-2021-41103, CVE-2022-0847",9.8,Critical,"CWE-22, CWE-665, CWE-770, CWE-362, CWE-281, CWE-732, CWE-200",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2099,6/16/2022,6/16/2022,2022,ICSA-22-167-10,Siemens SCALANCE XM-400 and XR-500,Siemens,SCALANCE XM-400 and XR-500,"The following versions of SCALANCE X industrial switches are affected: XM408-4C: All versions prior to v6.5 XM408-4C (L3 int.): All versions prior to v6.5 XM408-8C: All versions prior to v6.5 XM408-8C (L3 int.): All versions prior to v6.5 XM416-4C: All versions prior to v6.5 XM416-4C (L3 int.): All versions prior to v6.5 XR524-8C, 1x230V: All versions prior to v6.5 XR524-8C, 1x230V (L3 int.): All versions prior to v6.5 XR524-8C, 2x230V: All versions prior to v6.5 XR524-8C, 2x230V (L3 int.): All versions prior to v6.5 XR524-8C, 24V: All versions prior to v6.5 XR524-8C, 24V (L3 int.): All versions prior to v6.5 XR526-8C, 1x230V: All versions prior to v6.5 XR526-8C, 1x230V (L3 int.): All versions prior to v6.5 XR526-8C, 2x230V: All versions prior to v6.5 XR526-8C, 2x230V (L3 int.): All versions prior to v6.5 XR526-8C, 24V: All versions prior to v6.5 XR526-8C, 24V (L3 int.): All versions prior to v6.5 XR528-6M: All versions prior to v6.5 XR528-6M (2HR2): All versions prior to v6.5 XR528-6M (2HR2, L3 int.): All versions prior to v6.5 XR528-6M (L3 int.): All versions prior to v6.5 XR552-12M: All versions prior to v6.5 XR552-12M (2HR2): All versions prior to v6.5 XR552-12M (2HR2): All versions prior to v6.5 XR552-12M (2HR2, L3 int.): All versions prior to v6.5.",CVE-2021-37182,5.9,Medium,CWE-354,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2098,6/16/2022,6/16/2022,2022,ICSA-22-167-11,Siemens Xpedition Designer,Siemens,Xpedition Designer,Siemens reports this vulnerability affects the following PCB design flow products: Xpedition Designer: All versions prior to vX.2.11.,CVE-2022-31465,7.8,High,CWE-732,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2097,6/16/2022,6/16/2022,2022,ICSA-22-167-12,Siemens Spectrum Power Systems,Siemens,Spectrum Power,"The following versions of Spectrum Power, a SCADA, data modeling and monitoring system, are affected: Spectrum Power 4: All versions using Shared HIS Spectrum Power 7: All versions using Shared HIS Spectrum Power MGMS: All versions using Shared HIS.",CVE-2022-26476,8.8,High,CWE-798,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2096,6/16/2022,8/11/2022,2022,ICSA-22-167-13,Siemens Teamcenter (Update A),Siemens,Teamcenter,"The following versions of Teamcenter, a product lifecycle management software, are affected: Teamcenter v12.4: All versions prior to v12.4.0.13 Teamcenter v13.0: All versions prior to v13.0.0.9 Teamcenter v13.1: All versions prior to v13.1.0.9 --------- Begin Update A Part 1 of 4 --------- Teamcenter V13.2, all versions prior to V13.2.0.9 --------- End Update A Part 1 of 4 --------- Teamcenter V13.3, all versions prior to V13.3.0.3 --------- Begin Update A Part 2 of 4 --------- Teamcenter V14.0, all versions prior to V14.0.0.2 --------- End Update A Part 2 of 4 --------- This vulnerability only affects software using the Java EE Server Manager HTML Adaptor, which is not installed by default.",CVE-2022-31619,9.9,Critical,CWE-798,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2095,6/16/2022,12/15/2022,2022,ICSA-22-167-14,Siemens OpenSSL Affected Industrial Products (Update E),Siemens,Multiple industrial products,"The following Siemens industrial products are affected: Industrial Edge - OPC UA Connector: All versions prior to v1.7 Industrial Edge - SIMATIC S7 Connector App: All versions prior to v1.7.0 RUGGEDCOM CROSSBOW Station Access Controller: All versions only when running on ROX II versions prior to V2.15.1 RUGGEDCOM RM1224 LTE(4G) EU (6GK6108- 4AM00-2BA2): All versions RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2): All versions RUGGEDCOM ROX MX5000: All versions prior to v2.15.1 RUGGEDCOM ROX MX5000RE: All versions prior to v2.15.1 RUGGEDCOM ROX RX1400: All versions prior to v2.15.1 RUGGEDCOM ROX RX1500: All versions prior to v2.15.1 RUGGEDCOM ROX RX1501: All versions prior to v2.15.1 RUGGEDCOM ROX RX1510: All versions prior to v2.15.1 RUGGEDCOM ROX RX1511: All versions prior to v2.15.1 RUGGEDCOM ROX RX1512: All versions prior to v2.15.1 RUGGEDCOM ROX RX1524: All versions prior to v2.15.1 RUGGEDCOM ROX RX1536: All versions prior to v2.15.1 RUGGEDCOM ROX RX5000: All versions prior to v2.15.1 SCALANCE LPE9403 (6GK5998-3GS00-2AC2): All versions prior to v2.0 SCALANCE M804PB (6GK5804-0AP00-2AA2): All versions SCALANCE M812-1 ADSL-Router (Annex A) (6GK5812-1AA00-2AA2): All versions SCALANCE M812-1 ADSL-Router (Annex B) (6GK5812-1BA00-2AA2): All versions SCALANCE M816-1 ADSL-Router (Annex A) (6GK5816-1AA00-2AA2): All versions SCALANCE M816-1 ADSL-Router (Annex B) (6GK5816-1BA00-2AA2): All versions SCALANCE M826-2 SHDSL-Router (6GK5826- 2AB00-2AB2): All versions SCALANCE M874-2 (6GK5874-2AA00-2AA2): All versions SCALANCE M874-3 (6GK5874-3AA00-2AA2): All versions SCALANCE M876-3 (EVDO) (6GK5876-3AA02- 2BA2): All versions SCALANCE M876-3 (ROK) (6GK5876-3AA02- 2EA2): All versions SCALANCE M876-4 (EU) (6GK5876-4AA00- 2BA2): All versions SCALANCE M876-4 (NAM) (6GK5876-4AA00- 2DA2): All versions SCALANCE MUM853-1 (EU) (6GK5853-2EA00- 2DA1): All versions SCALANCE MUM853-1 (RoW) (6GK5853- 2EA00-2AA1): All versions SCALANCE MUM856-1 (EU) (6GK5856-2EA00- 3DA1): All versions SCALANCE MUM856-1 (NAM) (6GK5856- 2EA00-3BA1): All versions SCALANCE MUM856-1 (RoW) (6GK5856- 2EA00-3AA1): All versions SCALANCE S615 (6GK5615-0AA00-2AA2): All versions SCALANCE SC622-2C (6GK5622-2GS00- 2AC2): All versions prior to v2.3.1 SCALANCE SC632-2C (6GK5632-2GS00- 2AC2): All versions prior to v2.3.1 SCALANCE SC636-2C (6GK5636-2GS00- 2AC2): All versions prior to v2.3.1 SCALANCE SC642-2C (6GK5642-2GS00- 2AC2): All versions prior to v2.3.1 SCALANCE SC646-2C (6GK5646-2GS00- 2AC2): All versions prior to v2.3.1 SCALANCE W721-1 RJ45 (6GK5721-1FC00- 0AA0) SCALANCE W721-1 RJ45 (6GK5721-1FC00- 0AB0) SCALANCE W722-1 RJ45 (6GK5722-1FC00- 0AA0) SCALANCE W722-1 RJ45 (6GK5722-1FC00- 0AB0) SCALANCE W722-1 RJ45 (6GK5722-1FC00- 0AC0) SCALANCE W734-1 RJ45 (6GK5734-1FX00- 0AA0) SCALANCE W734-1 RJ45 (6GK5734-1FX00- 0AA6) SCALANCE W734-1 RJ45 (6GK5734-1FX00- 0AB0) SCALANCE W734-1 RJ45 (USA) (6GK5734- 1FX00-0AB6) SCALANCE W738-1 M12 (6GK5738-1GY00- 0AA0) SCALANCE W738-1 M12 (6GK5738-1GY00- 0AB0) SCALANCE W748-1 M12 (6GK5748-1GD00- 0AA0) SCALANCE W748-1 M12 (6GK5748-1GD00- 0AB0) SCALANCE W748-1 RJ45 (6GK5748-1FC00- 0AA0) SCALANCE W748-1 RJ45 (6GK5748-1FC00- 0AB0) SCALANCE W761-1 RJ45 (6GK5761-1FC00- 0AA0) SCALANCE W761-1 RJ45 (6GK5761-1FC00- 0AB0) SCALANCE W774-1 M12 EEC (6GK5774-1FY00- 0TA0) SCALANCE W774-1 M12 EEC (6GK5774-1FY00- 0TB0) SCALANCE W774-1 RJ45 (6GK5774-1FX00- 0AA0) SCALANCE W774-1 RJ45 (6GK5774-1FX00- 0AA6) SCALANCE W774-1 RJ45 (6GK5774-1FX00- 0AB0) SCALANCE W774-1 RJ45 (6GK5774-1FX00- 0AC0) SCALANCE W774-1 RJ45 (USA) (6GK5774- 1FX00-0AB6) SCALANCE W778-1 M12 (6GK5778-1GY00- 0AA0) SCALANCE W778-1 M12 (6GK5778-1GY00- 0AB0) SCALANCE W778-1 M12 EEC (6GK5778- 1GY00-0TA0) SCALANCE W778-1 M12 EEC (USA) (6GK5778- 1GY00-0TB0) SCALANCE W786-1 RJ45 (6GK5786-1FC00- 0AA0) SCALANCE W786-1 RJ45 (6GK5786-1FC00- 0AB0) SCALANCE W786-2 RJ45 (6GK5786-2FC00- 0AA0) SCALANCE W786-2 RJ45 (6GK5786-2FC00- 0AB0) SCALANCE W786-2 RJ45 (6GK5786-2FC00- 0AC0) SCALANCE W786-2 SFP (6GK5786-2FE00- 0AA0) SCALANCE W786-2 SFP (6GK5786-2FE00- 0AB0) SCALANCE W786-2IA RJ45 (6GK5786-2HC00- 0AA0) SCALANCE W786-2IA RJ45 (6GK5786-2HC00- 0AB0) SCALANCE W788-1 M12 (6GK5788-1GD00- 0AA0) SCALANCE W788-1 M12 (6GK5788-1GD00- 0AB0) SCALANCE W788-1 RJ45 (6GK5788-1FC00- 0AA0) SCALANCE W788-1 RJ45 (6GK5788-1FC00- 0AB0) SCALANCE W788-2 M12 (6GK5788-2GD00- 0AA0) SCALANCE W788-2 M12 (6GK5788-2GD00- 0AB0) SCALANCE W788-2 M12 EEC (6GK5788- 2GD00-0TA0) SCALANCE W788-2 M12 EEC (6GK5788- 2GD00-0TB0) SCALANCE W788-2 M12 EEC (6GK5788- 2GD00-0TC0) SCALANCE W788-2 RJ45 (6GK5788-2FC00- 0AA0) SCALANCE W788-2 RJ45 (6GK5788-2FC00- 0AB0) SCALANCE W788-2 RJ45 (6GK5788-2FC00- 0AC0) SCALANCE W1748-1 M12 (6GK5748-1GY01- 0AA0) SCALANCE W1748-1 M12 (6GK5748-1GY01- 0TA0) SCALANCE W1750D (JP) (6GK5750-2HX01- 1AD0): All versions SCALANCE W1750D (ROW) (6GK5750-2HX01- 1AA0): All versions SCALANCE W1750D (USA) (6GK5750-2HX01- 1AB0): All versions SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0) SCALANCE W1788-2 EEC M12 (6GK5788- 2GY01-0TA0) SCALANCE W1788-2 M12 (6GK5788-2GY01-0AA0) SCALANCE W1788-2IA M12 (6GK5788-2HY01-0AA0) SCALANCE WAM763-1 (6GK5763-1AL00-7DA0) SCALANCE WAM766-1 (6GK5766-1GE00-7DA0) SCALANCE WAM766-1 (6GK5766-1GE00-7DB0) SCALANCE WAM766-1 6GHz (6GK5766-1JE00-7DA0) SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0) SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TB0) SCALANCE WAM766-1 EEC 6GHz (6GK5766-1JE00-7TA0) SCALANCE WUM763-1 (6GK5763-1AL00-3AA0) SCALANCE WUM763-1 (6GK5763-1AL00-3DA0) SCALANCE WUM766-1 (6GK5766-1GE00-3DA0) SCALANCE WUM766-1 (6GK5766-1GE00-3DB0) SCALANCE WUM766-1 6GHz (6GK5766-1JE00-3DA0) SCALANCE X200-4P IRT (6GK5200-4AH00- 2BA3): All versions SCALANCE X200-4P IRT (6GK5200-4AH10- 2BA3): All versions SCALANCE X201-3P IRT (6GK5201-3BH00- 2BA3): All versions SCALANCE X201-3P IRT (6GK5201-3BH10- 2BA3): All versions SCALANCE X201-3P IRT PRO (6GK5201- 3BH00-2BD2): All versions SCALANCE X201-3P IRT PRO (6GK5201-3JR10- 2BA6): All versions SCALANCE X202-2IRT (6GK5202-2BB00- 2BA3): All versions SCALANCE X202-2IRT (6GK5202-2BB10- 2BA3): All versions SCALANCE X202-2P IRT (6GK5202-2BH00- 2BA3): All versions SCALANCE X202-2P IRT (6GK5202-2BH10- 2BA3): All versions SCALANCE X202-2P IRT PRO (6GK5202-2JR00- 2BA6): All versions SCALANCE X202-2P IRT PRO (6GK5202-2JR10- 2BA6): All versions SCALANCE X204-2 (6GK5204-2BB10-2AA3): All versions SCALANCE X204-2FM (6GK5204-2BB11- 2AA3): All versions SCALANCE X204-2LD (6GK5204-2BC10- 2AA3): All versions SCALANCE X204-2LD TS (6GK5204-2BC10- 2CA2): All versions SCALANCE X204-2TS (6GK5204-2BB10- 2CA2): All versions SCALANCE X204IRT (6GK5204-0BA00-2BA3): All versions SCALANCE X204IRT (6GK5204-0BA10-2BA3): All versions SCALANCE X204IRT PRO (6GK5204-0JA00- 2BA6): All versions SCALANCE X204IRT PRO (6GK5204-0JA10- 2BA6): All versions SCALANCE X206-1 (6GK5206-1BB10-2AA3): All versions SCALANCE X206-1LD (6GK5206-1BC10- 2AA3): All versions SCALANCE X208 (6GK5208-0BA10-2AA3): All versions SCALANCE X208PRO (6GK5208-0HA10- 2AA6): All versions SCALANCE X212-2 (6GK5212-2BB00-2AA3): All versions SCALANCE X212-2LD (6GK5212-2BC00- 2AA3): All versions SCALANCE X216 (6GK5216-0BA00-2AA3): All versions SCALANCE X224 (6GK5224-0BA00-2AA3): All versions SCALANCE X302-7 EEC (2x 24V) (6GK5302- 7GD00-2EA3): All versions SCALANCE X302-7 EEC (2x 24V, coated) (6GK5302-7GD00-2GA3): All versions SCALANCE X302-7 EEC (2x 230V) (6GK5302- 7GD00-4EA3): All versions SCALANCE X302-7 EEC (2x 230V, coated) (6GK5302-7GD00-4GA3): All versions SCALANCE X302-7 EEC (24V) (6GK5302- 7GD00-1EA3): All versions SCALANCE X302-7 EEC (24V, coated) (6GK5302-7GD00-1GA3): All versions SCALANCE X302-7 EEC (230V) (6GK5302- 7GD00-3EA3): All versions SCALANCE X302-7 EEC (230V, coated) (6GK5302-7GD00-3GA3): All versions SCALANCE X304-2FE (6GK5304-2BD00- 2AA3): All versions SCALANCE X306-1LD FE (6GK5306-1BF00- 2AA3): All versions SCALANCE X307-2 EEC (2x 24V) (6GK5307- 2FD00-2EA3): All versions SCALANCE X307-2 EEC (2x 24V, coated) (6GK5307-2FD00-2GA3): All versions SCALANCE X307-2 EEC (2x 230V) (6GK5307- 2FD00-4EA3): All versions SCALANCE X307-2 EEC (2x 230V, coated) (6GK5307-2FD00-4GA3): All versions SCALANCE X307-2 EEC (24V) (6GK5307- 2FD00-1EA3): All versions SCALANCE X307-2 EEC (24V, coated) (6GK5307-2FD00-1GA3): All versions SCALANCE X307-2 EEC (230V) (6GK5307- 2FD00-3EA3): All versions SCALANCE X307-2 EEC (230V, coated) (6GK5307-2FD00-3GA3): All versions SCALANCE X307-3 (6GK5307-3BL00-2AA3): All versions SCALANCE X307-3 (6GK5307-3BL10-2AA3): All versions SCALANCE X307-3LD (6GK5307-3BM00- 2AA3): All versions SCALANCE X307-3LD (6GK5307-3BM10- 2AA3): All versions SCALANCE X308-2 (6GK5308-2FL00-2AA3): All versions SCALANCE X308-2 (6GK5308-2FL10-2AA3): All versions SCALANCE X308-2LD (6GK5308-2FM00- 2AA3): All versions SCALANCE X308-2LD (6GK5308-2FM10- 2AA3): All versions SCALANCE X308-2LH (6GK5308-2FN00- 2AA3): All versions SCALANCE X308-2LH (6GK5308-2FN10- 2AA3): All versions SCALANCE X308-2LH+ (6GK5308-2FP00- 2AA3): All versions SCALANCE X308-2LH+ (6GK5308-2FP10- 2AA3): All versions SCALANCE X308-2M (6GK5308-2GG00-2AA2): All versions SCALANCE X308-2M (6GK5308-2GG10-2AA2): All versions SCALANCE X308-2M PoE (6GK5308-2QG00- 2AA2): All versions SCALANCE X308-2M PoE (6GK5308-2QG10- 2AA2): All versions SCALANCE X308-2M TS (6GK5308-2GG00- 2CA2): All versions SCALANCE X308-2M TS (6GK5308-2GG10- 2CA2): All versions SCALANCE X310 (6GK5310-0FA00-2AA3): All versions SCALANCE X310 (6GK5310-0FA10-2AA3): All versions SCALANCE X310FE (6GK5310-0BA00-2AA3): All versions SCALANCE X310FE (6GK5310-0BA10-2AA3): All versions SCALANCE X320-1 FE (6GK5320-1BD00- 2AA3): All versions SCALANCE X320-1-2LD FE (6GK5320-3BF00- 2AA3): All versions SCALANCE X408-2 (6GK5408-2FD00-2AA2): All versions SCALANCE XB205-3 (SC, PN) (6GK5205-3BB00-2AB2): All versions SCALANCE XB205-3 (ST, E/IP) (6GK5205-3BB00-2TB2): All versions SCALANCE XB205-3 (ST, E/IP) (6GK5205-3BD00-2TB2): All versions SCALANCE XB205-3 (ST, PN) (6GK5205-3BD00- 2AB2): SCALANCE XB205-3LD (SC, PN) (6GK5205- 3BF00-2AB2): All versions SCALANCE XB205-3LD (SC, E/IP) (6GK5205- 3BF00-2TB2): All versions SCALANCE XB208 (PN) (6GK5208-0BA00- 2AB2): All versions SCALANCE XB208 (E/IP) (6GK5208-0BA00- 2TB2): All versions SCALANCE XB213-3 (SC, PN) (6GK5213- 3BD00-2AB2): All versions SCALANCE XB213-3 (SC, E/IP) (6GK5213- 3BD00-2TB2): All versions SCALANCE XB213-3 (ST, PN) (6GK5213-3BB00- 2AB2): All versions SCALANCE XB213-3 (ST, E/IP) (6GK5213- 3BB00-2TB2): All versions SCALANCE XB213-3LD (SC, PN) (6GK5213- 3BF00-2AB2): All versions SCALANCE XB213-3LD (SC, E/IP) (6GK5213- 3BF00-2TB2): All versions SCALANCE XB216 (PN) (6GK5216-0BA00- 2AB2): All versions SCALANCE XB216 (E/IP) (6GK5216-0BA00- 2TB2): All versions SCALANCE XB205-3 (SC) (6GK5205-3BD00- 2AB2): All versions SCALANCE XB205-3 (SC) (6GK5205-3BD00- 2TB2): All versions SCALANCE XB205-3 (ST/BFOC) (6GK5205- 3BB00-2AB2): All versions SCALANCE XB205-3 (ST/BFOC) (6GK5205- 3BB00-2TB2): All versions SCALANCE XB205-3LD (6GK5205-3BF00- 2AB2): All versions SCALANCE XB205-3LD (6GK5205-3BF00- 2TB2): All versions SCALANCE XB208 (6GK5208-0BA00-2AB2): All versions SCALANCE XB208 (6GK5208-0BA00-2TB2): All versions SCALANCE XB213-3 (SC) (6GK5213-3BD00- 2AB2): All versions SCALANCE XB213-3 (SC) (6GK5213-3BD00- 2TB2): All versions SCALANCE XB213-3 (ST/BFOC) (6GK5213- 3BB00-2AB2): All versions SCALANCE XB213-3 (ST/BFOC) (6GK5213- 3BB00-2TB2): All versions SCALANCE XB213-3LD (6GK5213-3BF00- 2AB2): All versions SCALANCE XB213-3LD (6GK5213-3BF00- 2TB2): All versions SCALANCE XB216 (6GK5216-0BA00-2AB2): All versions SCALANCE XB216 (6GK5216-0BA00-2TB2): All versions SCALANCE XC206-2 (SC) (6GK5206-2BD00- 2AC2): All versions SCALANCE XC206-2 (ST/BFOC) (6GK5206- 2BB00-2AC2): All versions SCALANCE XC206-2SFP (6GK5206-2BS00- 2AC2): All versions SCALANCE XC206-2SFP EEC (6GK5206- 2BS00-2FC2): All versions SCALANCE XC206-2SFP G (6GK5206-2GS00- 2AC2): All versions SCALANCE XC206-2SFP G (6GK5206-2GS00- 2TC2): All versions SCALANCE XC206-2SFP G EEC (6GK5206- 2GS00-2FC2): All versions SCALANCE XC208 (6GK5208-0BA00-2AC2): All versions SCALANCE XC208EEC (6GK5208-0BA00- 2FC2): All versions SCALANCE XC208G (6GK5208-0GA00-2AC2): All versions SCALANCE XC208G (6GK5208-0GA00-2TC2): All versions SCALANCE XC208G EEC (6GK5208-0GA00- 2FC2): All versions SCALANCE XC216 (6GK5216-0BA00-2AC2): All versions SCALANCE XC216-4C (6GK5216-4BS00- 2AC2): All versions SCALANCE XC216-4C G (6GK5216-4GS00- 2AC2): All versions SCALANCE XC216-4C G (EIP Def.) (6GK5216- 4GS00-2TC2): All versions SCALANCE XC216-4C G EEC (6GK5216- 4GS00-2FC2): All versions SCALANCE XC216EEC (6GK5216-0BA00- 2FC2): All versions SCALANCE XC224 (6GK5224-0BA00-2AC2): All versions SCALANCE XC224-4C G (6GK5224-4GS00- 2AC2): All versions SCALANCE XC224-4C G (EIP Def.) (6GK5224- 4GS00-2TC2): All versions SCALANCE XC224-4C G EEC (6GK5224- 4GS00-2FC2): All versions SCALANCE XF201-3P IRT (6GK5201-3JR00- 2BA6): All versions SCALANCE XF202-2P IRT (6GK5202-2BH00- 2BD2): All versions SCALANCE XF204 (6GK5204-0BA00-2AF2): All versions SCALANCE XF204 (6GK5204-0BA00-2GF2): All versions SCALANCE XF204 DNA (6GK5204-0BA00- 2YF2): All versions SCALANCE XF204-2 (6GK5204-2BC00-2AF2): All versions SCALANCE XF204-2BA (6GK5204-2AA00- 2GF2): All versions SCALANCE XF204-2BA DNA (6GK5204-2AA00- 2YF2): All versions SCALANCE XF204-2BA IRT (6GK5204-2AA00- 2BD2): All versions SCALANCE XF204IRT (6GK5204-0BA00- 2BF2): All versions SCALANCE XF204IRT (6GK5204-0BA10- 2BF2): All versions SCALANCE XF206-1 (6GK5206-1BC00-2AF2): All versions SCALANCE XF208 (6GK5208-0BA00-2AF2): All versions SCALANCE XM408-4C (6GK5408-4GP00-2AM2): All versions prior to V6.5 SCALANCE XM408-4C (L3 int.) (6GK5408-4GQ00-2AM2): All versions prior to V6.5 SCALANCE XM408-8C (6GK5408-8GS00-2AM2): All versions prior to V6.5 SCALANCE XM408-8C (L3 int.) (6GK5408-8GR00-2AM2): All versions prior to V6.5 SCALANCE XM416-4C (6GK5416-4GS00-2AM2): All versions prior to V6.5 SCALANCE XM416-4C (L3 int.) (6GK5416-4GR00-2AM2): All versions prior to V6.5 SCALANCE XP208 (6GK5208-0HA00-2AS6): All versions SCALANCE XP208 (6GK5208-0HA00-2TS6): All versions SCALANCE XP208EEC (6GK5208-0HA00- 2ES6): All versions SCALANCE XP208PoE EEC (6GK5208-0UA00- 5ES6): All versions SCALANCE XP216 (6GK5216-0HA00-2AS6): All versions SCALANCE XP216 (6GK5216-0HA00-2TS6): All versions SCALANCE XP216EEC (6GK5216-0HA00- 2ES6): All versions SCALANCE XP216POE EEC (6GK5216-0UA00- 5ES6): All versions SCALANCE XR324-4M EEC (2x 24V, ports on front) (6GK5324-4GG00-2ER2): All versions SCALANCE XR324-4M EEC (2x 24V, ports on front) (6GK5324-4GG10-2ER2): All versions SCALANCE XR324-4M EEC (2x 24V, ports on rear) (6GK5324-4GG00-2JR2): All versions SCALANCE XR324-4M EEC (2x 24V, ports on rear) (6GK5324-4GG10-2JR2): All versions SCALANCE XR324-4M EEC (2x 100-240VAC/60- 250VDC, ports on front) (6GK5324-4GG00- 4ER2): All versions SCALANCE XR324-4M EEC (2x 100-240VAC/60- 250VDC, ports on front) (6GK5324-4GG10- 4ER2): All versions SCALANCE XR324-4M EEC (2x 100-240VAC/60- 250VDC, ports on rear) (6GK5324-4GG00- 4JR2): All versions SCALANCE XR324-4M EEC (2x 100-240VAC/60- 250VDC, ports on rear) (6GK5324-4GG10- 4JR2): All versions SCALANCE XR324-4M EEC (24V, ports on front) (6GK5324-4GG00-1ER2): All versions SCALANCE XR324-4M EEC (24V, ports on front) (6GK5324-4GG10-1ER2): All versions SCALANCE XR324-4M EEC (24V, ports on rear) (6GK5324-4GG00-1JR2): All versions SCALANCE XR324-4M EEC (24V, ports on rear) (6GK5324-4GG10-1JR2): All versions SCALANCE XR324-4M EEC (100-240VAC/60- 250VDC, ports on front) (6GK5324-4GG00- 3ER2): All versions SCALANCE XR324-4M EEC (100-240VAC/60- 250VDC, ports on front) (6GK5324-4GG10- 3ER2): All versions SCALANCE XR324-4M EEC (100-240VAC/60- 250VDC, ports on rear) (6GK5324-4GG00- 3JR2): All versions SCALANCE XR324-4M EEC (100-240VAC/60- 250VDC, ports on rear) (6GK5324-4GG10- 3JR2): All versions SCALANCE XR324-4M PoE (24V, ports on front) (6GK5324-4QG00-1AR2): All versions SCALANCE XR324-4M PoE (24V, ports on rear) (6GK5324-4QG00-1HR2): All versions SCALANCE XR324-4M PoE (230V, ports on front) (6GK5324-4QG00-3AR2): All versions SCALANCE XR324-4M PoE (230V, ports on rear) (6GK5324-4QG00-3HR2): All versions SCALANCE XR324-4M PoE TS (24V, ports on front) (6GK5324-4QG00-1CR2): All versions SCALANCE XR324-12M (24V, ports on front) (6GK5324-0GG00-1AR2): All versions SCALANCE XR324-12M (24V, ports on front) (6GK5324-0GG10-1AR2): All versions SCALANCE XR324-12M (24V, ports on rear) (6GK5324-0GG00-1HR2): All versions SCALANCE XR324-12M (24V, ports on rear) (6GK5324-0GG10-1HR2): All versions SCALANCE XR324-12M (230V, ports on front) (6GK5324-0GG00-3AR2): All versions SCALANCE XR324-12M (230V, ports on front) (6GK5324-0GG10-3AR2): All versions SCALANCE XR324-12M (230V, ports on rear) (6GK5324-0GG00-3HR2): All versions SCALANCE XR324-12M (230V, ports on rear) (6GK5324-0GG10-3HR2): All versions SCALANCE XR324-12M TS (24V) (6GK5324- 0GG00-1CR2): All versions SCALANCE XR324-12M TS (24V) (6GK5324- 0GG10-1CR2): All versions SCALANCE XR324WG (24 x FE, AC 230V) (6GK5324-0BA00-3AR3): All versions SCALANCE XR324WG (24 X FE, DC 24V) (6GK5324-0BA00-2AR3): All versions SCALANCE XR328-4C WG (24xFE,4xGE,AC230V) (6GK5328-4FS00- 3AR3): All versions SCALANCE XR328-4C WG (24xFE,4xGE,AC230V) (6GK5328-4FS00- 3RR3): All versions SCALANCE XR328-4C WG (24XFE, 4XGE, 24V) (6GK5328-4FS00-2AR3): All versions SCALANCE XR328-4C WG (24xFE, 4xGE,DC24V) (6GK5328-4FS00-2RR3): All versions SCALANCE XR328-4C WG (28xGE, AC 230V) (6GK5328-4SS00-3AR3): All versions SCALANCE XR328-4C WG (28xGE, DC 24V) (6GK5328-4SS00-2AR3): All versions SCALANCE XR524-8C, 1x230V (6GK5524-8GS00-3AR2): All versions prior to V6.5 SCALANCE XR524-8C, 1x230V (L3 int.) (6GK5524-8GR00-3AR2): All versions prior to V6.5 SCALANCE XR524-8C, 2x230V (6GK5524-8GS00-4AR2): All versions prior to V6.5 SCALANCE XR524-8C, 2x230V (L3 int.) (6GK5524-8GR00-4AR2): All versions prior to V6.5 SCALANCE XR524-8C, 24V (6GK5524-8GS00-2AR2): All versions prior to V6.5 SCALANCE XR524-8C, 24V (L3 int.) (6GK5524-8GR00-2AR2): All versions prior to V6.5 SCALANCE XR526-8C, 1x230V (6GK5526-8GS00-3AR2): All versions prior to V6.5 SCALANCE XR526-8C, 1x230V (L3 int.) (6GK5526-8GR00-3AR2): All versions prior to V6.5 SCALANCE XR526-8C, 2x230V (6GK5526-8GS00-4AR2): All versions prior to V6.5 SCALANCE XR526-8C, 2x230V (L3 int.) (6GK5526-8GR00-4AR2): All versions prior to V6.5 SCALANCE XR526-8C, 24V (6GK5526-8GS00-2AR2): All versions prior to V6.5 SCALANCE XR526-8C, 24V (L3 int.) (6GK5526-8GR00-2AR2): All versions prior to V6.5 SCALANCE XR528-6M (6GK5528-0AA00-2AR2): All versions prior to V6.5 SCALANCE XR528-6M (2HR2) (6GK5528-0AA00-2HR2): All versions prior to V6.5 SCALANCE XR528-6M (2HR2, L3 int.) (6GK5528-0AR00-2HR2): All versions prior to V6.5 SCALANCE XR528-6M (L3 int.) (6GK5528-0AR00-2AR2): All versions prior to V6.5 SCALANCE XR552-12M (6GK5552-0AA00-2AR2): All versions prior to V6.5 SCALANCE XR552-12M (2HR2) (6GK5552-0AA00-2HR2): All versions prior to V6.5 SCALANCE XR552-12M (2HR2) (6GK5552-0AR00-2HR2): All versions prior to V6.5 SCALANCE XR552-12M (2HR2, L3 int.) (6GK5552-0AR00-2AR2): All versions prior to V6.5 Security Configuration Tool (SCT): All versions SIMATIC Cloud Connect 7 CC712 (6GK1411- 1AC00): All versions prior to v1.9 SIMATIC Cloud Connect 7 CC716 (6GK1411- 5AC00): All versions prior to v1.9 SIMATIC CP 343-1 Advanced (6GK7343-1GX31- 0XE0): All versions SIMATIC CP 443-1 Advanced (6GK7443-1GX30- 0XE0): All versions SIMATIC CP 443-1 OPC UA (6GK7443-1UX00- 0XE0): All versions SIMATIC CP 1242-7 V2 (6GK7242-7KX31- 0XE0): All versions SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0): All versions SIMATIC CP 1243-7 LTE EU (6GK7243-7KX30- 0XE0): All versions SIMATIC CP 1243-7 LTE US (6GK7243-7SX30- 0XE0): All versions SIMATIC CP 1243-8 IRC (6GK7243-8RX30- 0XE0): All versions SIMATIC CP 1542SP-1 (6GK7542-6UX00- 0XE0): All versions SIMATIC CP 1543-1 (6GK7543-1AX00-0XE0): All versions SIMATIC CP 1543SP-1 (6GK7543-6WX00- 0XE0): All versions SIMATIC CP 1545-1 (6GK7545-1GX00-0XE0): All versions SIMATIC CP 1626 (6GK1162-6AA01): All versions SIMATIC CP 1628 (6GK1162-8AA00): All versions --------- Begin Update E Part 1 of 8 --------- SIMATIC Drive Controller family: All versions prior to v3.0.1 --------- End Update E Part 1 of 8 --------- SIMATIC ET 200SP Open Controller (incl. SIPLUS variants): All versions --------- Begin Update E Part 2 of 8 --------- SIMATIC HMI Unified Comfort Panels: All versions prior to v18 --------- End Update E Part 2 of 8 --------- SIMATIC Logon: All versions prior to v1.6 Upd6 SIMATIC MV540 H (6GF3540-0GE10): All versions prior to v3.3 SIMATIC MV540 S (6GF3540-0CD10): All versions prior to v3.3 SIMATIC MV550 H (6GF3550-0GE10): All versions prior to v3.3 SIMATIC MV550 S (6GF3550-0CD10): All versions prior to v3.3 SIMATIC MV560 U (6GF3560-0LE10): All versions prior to v3.3 SIMATIC MV560 X (6GF3560-0HE10): All versions prior to v3.3 SIMATIC NET PC Software v14: All versions SIMATIC NET PC Software v15: All versions SIMATIC NET PC Software v16: All versions prior to v16 Update 6 SIMATIC NET PC Software v17: All versions SIMATIC PCS 7 TeleControl: All versions --------- Begin Update E Part 3 of 8 --------- SIMATIC PCS neo (Administration Console): All versions prior to v4.0 --------- End Update E Part 3 of 8 --------- SIMATIC PDM: All versions prior to v9.2.2 --------- Begin Update E Part 4 of 8 --------- SIMATIC Process Historian OPC UA Server: All versions prior to v2020 SP1 Upd1 --------- End Update E Part 4 of 8 --------- SIMATIC RF166C (6GT2002-0EE20): All versions prior to v2.0.1 SIMATIC RF185C (6GT2002-0JE10): All versions prior to v2.0.1 SIMATIC RF186C (6GT2002-0JE20): All versions prior to v2.0.1 SIMATIC RF186CI (6GT2002-0JE50): All versions prior to v2.0.1 SIMATIC RF188C (6GT2002-0JE40): All versions prior to v2.0.1 SIMATIC RF188CI (6GT2002-0JE60): All versions prior to v.2.0.1 SIMATIC RF360R (6GT2801-5BA30): All versions prior to v2.0.1 SIMATIC RF610R (6GT2811-6BC10): All versions prior to v4.0.1 SIMATIC RF615R (6GT2811-6CC10): All versions prior to v4.0.1 SIMATIC RF650R (6GT2811-6AB20): All versions prior to v4.0.1 SIMATIC RF680R (6GT2811-6AA10): All versions prior to v4.0.1 SIMATIC RF685R (6GT2811-6CA10): All versions prior to v4.0.1 --------- Begin Update E Part 5 of 8 --------- SIMATIC S7-1200 CPU family (incl. SIPLUS variants): All versions prior to v4.6.0 SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions prior to v3.0.1 --------- End Update E Part 5 of 8 --------- SIMATIC S7-1500 Software Controller (incl. F): All versions --------- Begin Update E Part 6 of 8 --------- SIMATIC S7-PLCSIM Advanced: All versions prior to v5.0 --------- End Update E Part 6 of 8 --------- SIMATIC STEP 7 (TIA Portal): All versions SIMATIC STEP 7 V5.X: All versions prior to v5.7 HF4 SIMATIC WinCC (TIA Portal): All versions SIMATIC WinCC Unified (TIA Portal): All versions prior to V17 Update 5 SINAUT Software ST7sc: All versions SINAUT ST7CC: All versions SINEC INS: All versions prior to V1.0 SP2 SINEC NMS: All versions prior to V1.0.3 SINEC NMS: All versions SINEMA Remote Connect Server: All versions prior to v3.1 SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0): All versions SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0): All versions SIPLUS NET CP 343-1 Advanced (6AG1343- 1GX31-4XE0): All versions SIPLUS NET CP 443-1 Advanced (6AG1443- 1GX30-4XE0): All versions SIPLUS NET CP 1242-7 v2 (6AG1242-7KX31- 7XE0): All versions SIPLUS NET CP 1543-1 (6AG1543-1AX00- 2XE0): All versions SIPLUS NET SCALANCE X202-2P IRT (6AG1202-2BH00-2BA3): All versions SIPLUS NET SCALANCE X308-2 (6AG1308- 2FL10-4AA3): All versions SIPLUS NET SCALANCE XC206-2 (6AG1206- 2BB00-7AC2): All versions SIPLUS NET SCALANCE XC206-2SFP (6AG1206-2BS00-7AC2): All versions SIPLUS NET SCALANCE XC208 (6AG1208- 0BA00-7AC2): All versions SIPLUS NET SCALANCE XC216-4C (6AG1216- 4BS00-7AC2): All versions SIPLUS S7-1200 CP 1243-1 (6AG1243-1BX30- 2AX0): All versions SIPLUS S7-1200 CP 1243-1 RAIL (6AG2243- 1BX30-1XE0): All versions SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0): All versions TeleControl Server Basic v3: All versions prior to v3.1.1 --------- Begin Update E Part 7 of 8 --------- TIA Administrator: All versions prior to v1.0 SP8 --------- End Update E Part 7 of 8 --------- TIA Portal Cloud: All versions TIA Portal v15: All versions TIA Portal v16: All versions --------- Begin Update E Part 8 of 8 --------- TIA Portal v17: All versions prior to v17 Update 5 --------- End Update E Part 8 of 8 --------- TIM 1531 IRC (6GK7543-1MX00-0XE0): All versions.",CVE-2022-0778,7.5,High,CWE-835,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2094,6/16/2022,6/16/2022,2022,ICSA-22-167-15,Siemens Teamcenter Active Workspace,Siemens,Teamcenter Active Workspace,"The following versions of Smart Security Manager, a software management platform, are affected: Teamcenter Active Workspace v5.2: All versions prior to 5.2.9 Teamcenter Active Workspace v6.0: All versions prior to 6.0.3.",CVE-2022-32145,6.1,Medium,CWE-798,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2093,6/16/2022,6/16/2022,2022,ICSA-22-167-16,Siemens SCALANCE LPE 4903 and SINUMERIK Edge,Siemens,SCALANCE LPE 4903 and SINUMERIK Edge,The following products and versions are affected: SCALANCE LPE9403: All versions prior to v2.0 SINUMERIK Edge: All versions prior to v3.3.0.,CVE-2021-4034,7.8,High,CWE-787,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2092,6/16/2022,6/16/2022,2022,ICSA-22-167-17,Siemens SINEMA Remote Connect Server,Siemens,SINEMA Remote Connect Server,The following Siemens products are affected: Siemens SINEMA Remote Connect Server: All versions prior to v3.1.,"CVE-2021-22924, CVE-2021-22925, CVE-2021-45960, CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824, CVE-2022-22825, CVE-2022-22826, CVE-2022-22827, CVE-2022-23852, CVE-2022-23990, CVE-2022-25235, CVE-2022-25236, CVE-2022-25313, CVE-2022-25314, CVE-2022-25315, CVE-2022-27221, CVE-2022-29034, CVE-2022-32251, CVE-2022-32252, CVE-2022-32253, CVE-2022-32254, CVE-2022-32255, CVE-2022-32256, CVE-2022-32258, CVE-2022-32259, CVE-2022-32260, CVE-2022-32261, CVE-2022-32262",9.8,Critical,"CWE-706, CWE-908, CWE-400, CWE-190, CWE-116, CWE-668, CWE-310, CWE-79, CWE-306, CWE-345, CWE-20, CWE-532, CWE-284, CWE-448, CWE-1244, CWE-286, CWE-223, CWE-77",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2091,6/14/2022,6/14/2022,2022,ICSA-22-165-01,Johnson Controls Metasys ADS ADX OAS Servers,Johnson Controls Inc.,Metasys ADS/ADX/OAS Servers,The following versions of Metasys ADS/ADX/OAS Servers are affected: All Metasys ADS/ADX/OAS Versions 10 and 11.,"CVE-2022-21935, CVE-2022-21937, CVE-2022-21938",8.7,High,"CWE-620, CWE-79",Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2090,6/14/2022,6/14/2022,2022,ICSA-22-165-02,Meridian Cooperative Meridian,Meridian Cooperative,Meridian,The following versions of Meridian utility software are affected: Version 22.02 Version 22.03.,CVE-2022-29578,7.5,High,CWE-284,Energy,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2089,6/14/2022,6/14/2022,2022,ICSA-22-165-03,Mitsubishi Electric MELSEC-Q/L and MELSEC iQ-R,Mitsubishi Electric,MELSEC-Q/L Series and iQ-R Series,"The following versions of MELSEC-Q Ethernet Interface Module, MELSEC-L Ethernet Interface Module, and MELSEC iQ-R MES Interface Module are affected: MELSEC-Q Series QJ71E71-100: First five digits of serial number 24061 and prior MELSEC-L Series LJ71E71-100: First five digits of serial number 24061 and prior MELSEC iQ-R Series RD81MES96N: firmware Version 08 and prior.",CVE-2022-25163,8.1,High,CWE-20,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2088,6/9/2022,6/9/2022,2022,ICSA-22-160-01,Mitsubishi Electric Air Conditioning Systems,Mitsubishi Electric,Air Conditioning Systems,The firmware on the following Mitsubishi Electric products is affected: G-150AD: Versions 3.21 and prior AG-150A-A: Versions 3.21 and prior AG-150A-J: Versions 3.21 and prior GB-50AD: Versions 3.21 and prior GB-50ADA-A: Versions 3.21 and prior GB-50ADA-J: Versions 3.21 and prior EB-50GU-A: Versions. 7.10 and prior EB-50GU-J: Versions 7.10 and prior AE-200J: Versions 7.97 and prior AE-200A: Versions 7.97 and prior AE-200E: Versions 7.97 and prior AE-50J: Versions 7.97 and prior AE-50A: Versions 7.97 and prior AE-50E: Versions 7.97 and prior EW-50J: Versions 7.97 and prior EW-50A: Versions 7.97 and prior EW-50E: Versions 7.97 and prior TE-200A: Versions 7.97 and prior TE-50A: Versions 7.97 and prior TW-50A: Versions 7.97 and prior.,"CVE-2022-24296, CVE-2016-2183, CVE-2013-2566, CVE-2015-2808, CVE-2009-3555",7.5,High,"CWE-327, CWE-200, CWE-300",Commercial Facilities,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2087,6/3/2022,6/3/2022,2022,ICSA-22-154-01,Vulnerabilities Affecting Dominion Voting Systems ImageCast X,Dominion Voting Systems,Democracy Suite ImageCast X,"The following versions of the Dominion Voting Systems ImageCast X software are known to be affected (other versions were not able to be tested): ImageCast X firmware based on Android 5.1, as used in Dominion Democracy Suite Voting System Version 5.5-A ImageCast X application Versions 5.5.10.30 and 5.5.10.32, as used in Dominion Democracy Suite Voting System Version 5.5-A NOTE: After following the vendor's procedure to upgrade the ImageCast X from Version 5.5.10.30 to 5.5.10.32, or after performing other Android administrative actions, the ImageCast X may be left in a configuration that could allow an attacker who can attach an external input device to escalate privileges and/or install malicious code. Instructions to check for and mitigate this condition are available from Dominion Voting Systems. Any jurisdictions running ImageCast X are encouraged to contact Dominion Voting Systems to understand the vulnerability status of their specific implementation.","CVE-2022-1739, CVE-2022-1740, CVE-2022-1741, CVE-2022-1742, CVE-2022-1743, CVE-2022-1744, CVE-2022-1745, CVE-2022-1746, CVE-2022-1747",Not Assigned,Not Assigned,"CWE-347, CWE-1283, CWE-912, CWE-424, CWE-24, CWE-250, CWE-290, CWE-266, CWE-346",Government Facilities/Election Infrastructure,Multiple Countries,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2086,6/2/2022,6/2/2022,2022,ICSA-22-153-01,Carrier LenelS2 HID Mercury access panels,Carrier LenelS2,HID Mercury access panels sold by LenelS2,Carrier reports these vulnerabilities affect the following HID Mercury access panels sold by LenelS2: LNL-X2210 LNL-X2220 LNL-X3300 LNL-X4420 LNL-4420 S2-LP-1501 S2-LP-4502 S2-LP-2500 S2-LP-1502.,"CVE-2022-31479, CVE-2022-31480, CVE-2022-31481, CVE-2022-31483, CVE-2022-31482, CVE-2022-31484, CVE-2022-31485, CVE-2022-31486",10.0,Critical,"CWE-693, CWE-425, CWE-120, CWE-22, CWE-425, CWE-78",Commercial Facilities,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2085,6/2/2022,8/23/2022,2022,ICSA-22-153-02,Illumina Local Run Manager (Update A),Illumina,Local Run Manager (LRM),The following devices and instruments using LRM software are affected: Illumina In Vitro Diagnostic (IVD) devices: NextSeq 550Dx: LRM Versions 1.3 to 3.1 MiSeq Dx: LRM Versions 1.3 to 3.1 Researcher Use Only (ROU) instruments: NextSeq 500 Instrument: LRM Versions 1.3 to 3.1 NextSeq 550 Instrument: LRM Versions 1.3 to 3.1 MiSeq Instrument: LRM Versions 1.3 to 3.1 iSeq 100 Instrument: LRM Versions 1.3 to 3.1 MiniSeq Instrument: LRM Versions 1.3 to 3.1.,"CVE-2022-1517, CVE-2022-1518, CVE-2022-1519, CVE-2022-1521, CVE-2022-1524",10.0,Critical,"CWE-250, CWE-22, CWE-434, CWE-284, CWE-319",Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2084,5/31/2022,5/31/2022,2022,ICSMA-22-151-01,BD Pyxis,"Becton, Dickinson and Company (BD)",Pyxis,"The following BD Pyxis products, an automated medication dispensing system, are affected: BD Pyxis ES Anesthesia Station BD Pyxis CIISafe BD Pyxis Logistics BD Pyxis MedBank BD Pyxis MedStation 4000 BD Pyxis MedStation ES BD Pyxis MedStation ES Server BD Pyxis ParAssist BD Pyxis Rapid Rx BD Pyxis StockStation BD Pyxis SupplyCenter BD Pyxis SupplyRoller BD Pyxis SupplyStation BD Pyxis SupplyStation EC BD Pyxis SupplyStation RF auxiliary BD Rowa Pouch Packaging Systems.",CVE-2022-22767,8.8,High,CWE-262,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2083,5/31/2022,5/31/2022,2022,ICSMA-22-151-02,BD Synapsys,"Becton, Dickinson and Company (BD)",Synapsys,"The following versions of BD Synapsys, a microbiology informatics software platform, are affected: BD Synapsys: Versions 4.20, 4.20 SR1 and 4.30.",CVE-2022-30277,5.7,Medium,CWE-613,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2082,5/31/2022,5/31/2022,2022,ICSA-22-151-01,Fuji Electric Alpha7 PC Loader,Fuji Electric,Alpha7 PC Loader,"The following versions of Alpha7 PC Loader, a servo drive system, are affected: Alpha7 PC Loader: All versions.",CVE-2022-1888,7.8,High,CWE-121,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2081,5/26/2022,5/26/2022,2022,ICSA-22-146-02,Horner Automation Cscape Csfont,Horner Automation,Cscape Csfont,The following versions of Horner Automation Cscape PLC management software are affected: Horner Automation Cscape Csfont: Versions 9.90 SP5 (v9.90.196) and prior.,"CVE-2022-27184, CVE-2022-28690, CVE-2022-29488, CVE-2022-30540",7.8,High,"CWE-787, CWE-125, CWE-122",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2080,5/26/2022,5/26/2022,2022,ICSA-22-146-01,Keysight N6854A Geolocation server and N6841A RF Sensor software,Keysight Technologies Inc.,N6854A Geolocation server and N6841A RF Sensor software,"The following version of Keysight N6854A Geolocation and server and N6841A Sensor software, a spectrum monitoring platform, are affected: Keysight N6854A and N6841A RF: Version 2.4.0 or later.","CVE-2022-1661, CVE-2022-1660",9.8,Critical,"CWE-23, CWE-502",Critical Manufacturing; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2079,5/24/2022,5/24/2022,2022,ICSA-22-144-01,Rockwell Automation Logix Controllers,Rockwell Automation,Logix Controllers,Rockwell Automation reports this vulnerability affects the following Logix Controllers: CompactLogix 5380 controllers: firmware Versions 32.013 and earlier Compact GuardLogix 5380 controllers: firmware Versions 32.013 and earlier CompactLogix 5480 controllers: firmware Versions 32.013 and earlier ControlLogix 5580 controllers: firmware Versions 32.013 and earlier GuardLogix 5580 controllers: firmware Versions 32.013 and earlier CompactLogix 5370 controllers: firmware Versions 33.013 and earlier Compact GuardLogix 5370 controllers: firmware Versions 33.013 and earlier ControlLogix 5570 controllers: firmware Versions 33.013 and earlier GuardLogix 5570 controllers: firmware Versions 33.013 and earlier.,CVE-2022-1797,6.8,Medium,CWE-400,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2078,5/24/2022,5/24/2022,2022,ICSA-22-144-02,Matrikon OPC Server,Matrikon (Subsidiary of Honeywell),Matrikon OPC Server,The following versions of Makitron OPC software are affected: Matrikon OPC Server: All versions.,CVE-2022-1261,5.8,Medium,CWE-284,Multiple Critical Sectors,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2077,5/19/2022,2/28/2023,2022,ICSA-22-139-01,Mitsubishi Electric MELSEC iQ-F Series (Update B),Mitsubishi Electric,MELSEC iQ-F Series,"The following versions of the MELSEC iQ-F series a CPU module are affected: --------- Begin Update A Part 1 of 3 --------- MELSEC iQ-F FX5U-xMy/z x=32,64,80, y=T,R, z=ES,DS,ESS,DSS with serial number 17X**** or later: All versions prior to 1.270 MELSEC iQ-F FX5U-xMy/z x=32,64,80, y=T,R, z=ES,DS,ESS,DSS with Serial number 179**** and prior: All versions prior to 1.073 MELSEC iQ-F FX5UC-xMy/z x=32,64,96, y=T,R, z=D,DSS with serial number 17X**** or later: All versions prior to 1.270 MELSEC iQ-F FX5UC-xMy/z x=32,64,96, y=T,R, z=D,DSS with Serial number 179**** and prior: All versions prior to 1.073 --------- End Update A Part 1 of 3 --------- MELSEC iQ-F FX5UC-32MT/DS-TS, FX5UC-32MT/DSS-TS, FX5UC-32MR/DS-TS: All versions prior to 1.270 MELSEC iQ-F FX5UJ-xMy/z x=24,40,60, y=T,R, z=ES,ESS: All versions prior to 1.030 --------- Begin Update A Part 2 of 3 --------- MELSEC iQ-F FX5UJ-xMy/ES-A x=24,40,60, y=T.R: All versions prior to 1.031 (These products are sold in limited regions) MELSEC iQ-F FX5S-xMy/z x=30,40,60,80, y=T.R, z=ES,ESS: Version 1.000 (These products are sold in limited regions) --------- End Update A Part 2 of 3 ---------.","CVE-2022-25161, CVE-2022-25162",8.6,High,CWE-20,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2076,5/17/2022,5/17/2022,2022,ICSA-22-137-01,Circutor COMPACT DC-S BASIC,Circutor,COMPACT DC-S BASIC,"The following versions of Circutor COMPACT DC-S BASIC, a smart metering concentrator, are affected: Circutor COMPACT DC-S BASIC: CIR_CDC_v1.2.17.",CVE-2022-1669,6.8,Medium,CWE-121,Critical Manufacturing,Worldwide,Spain,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2075,5/12/2022,5/12/2022,2022,ICSA-22-132-01,Delta Electronics CNCSoft,Delta Electronics,CNCSoft,"The following versions of CNCSoft, a software management platform, are affected: CNCSoft: All versions prior to 1.01.32.","CVE-2022-1405, CVE-2022-1404",7.8,High,"CWE-121, CWE-125",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2074,5/12/2022,5/12/2022,2022,ICSA-22-132-02,Mitsubishi Electric MELSOFT iQ AppPortal,Mitsubishi Electric,MELSOFT iQ AppPortal,"The following MELSOFT iQ AppPortal versions using the vulnerable open-source software used by VisualSVN Server, are affected: MELSOFT iQ AppPortal (SW1DND-IQAPL-M): Versions 1.00A through 1.26C.","CVE-2020-13938, CVE-2021-26691, CVE-2021-34798, CVE-2021-3711, CVE-2021-44790, CVE-2022-22720, CVE-2022-23943, CVE-2022-0778",9.8,Critical,"CWE-862, CWE-787, CWE-476, CWE-120, CWE-444, CWE-835",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2073,5/12/2022,5/12/2022,2022,ICSA-22-132-03,Inkscape in Industrial Products,Inkscape,"Inkscape, an open-source graphics editor",The following versions of the Inkscape open-source graphics editor are affected: Inkscape Version 0.91.,"CVE-2021-42700, CVE-2021-42702, CVE-2021-42704",7.8,High,"CWE-125, CWE-824, CWE-787",Multiple Critical Sectors,Worldwide,Open-source,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2072,5/12/2022,5/12/2022,2022,ICSA-22-132-04,Cambium Networks cnMaestro,Cambium Networks,cnMaestro,"The following versions of cnMaestro, a Network management system, are affected: cnMaestro On-Premises: All versions prior to 3.0.3-r32 cnMaestro On-Premises: All versions prior to 2.4.2-r29 cnMaestro On-Premises: All versions prior to 3.0.0-r34.","CVE-2022-1357, CVE-2022-1358, CVE-2022-1361, CVE-2022-1360, CVE-2022-1362, CVE-2022-1359, CVE-2022-1356",9.8,Critical,"CWE-78, CWE-89, CWE-22, CWE-676",Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2071,5/12/2022,12/15/2022,2022,ICSA-22-132-05,Siemens Industrial PCs and CNC devices (Update A),Siemens,Industrial PCs and CNC devices,Siemens reports these vulnerabilities affect the following Industrial PCs and CNC devices: SIMATIC Drive Controller family: All versions prior to v05.00.01.00 SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions prior to v0209_0105 SIMATIC Field PG M5: All BIOS versions prior to v22.01.08 --------- Begin Update A Part 1 of 2 --------- SIMATIC Field PG M6: All versions prior to v26.01.08 --------- End Update A Part 1 of 2 --------- SIMATIC IPC127E: All versions SIMATIC IPC427E (incl. SIPLUS variants): All BIOS versions prior to v21.01.15 SIMATIC IPC477E: All BIOS versions prior to v21.01.15 SIMATIC IPC477E Pro: All BIOS versions prior to v21.01.15 SIMATIC IPC527G: All BIOS versions prior to v1.4.0 SIMATIC IPC527G: All BIOS versions prior to v1.4.0 SIMATIC IPC547G: All versions prior to R1.30.0 SIMATIC IPC627E: All BIOS versions prior to v25.02.08 SIMATIC IPC647E: All BIOS versions prior to v25.02.08 SIMATIC IPC677E: All BIOS versions prior to v25.02.08 SIMATIC IPC847E: All BIOS versions prior to v25.02.08 SIMATIC ITP1000: All BIOS versions prior to v23.01.08 SINUMERIK 828D HW PU.4: All versions prior to v08.00.00.00 SINUMERIK MC MCU 1720: All versions prior to v05.00.00.00 SINUMERIK ONE / SINUMERIK 840D sl Handheld Terminal HT 10: All versions SINUMERIK ONE NCU 1740: All versions prior to v04.00.00.00 SINUMERIK ONE PPU 1740: All versions prior to v06.00.00.00.,"CVE-2020-8694, CVE-2020-0590, CVE-2020-8698, CVE-2020-8745",7.8,High,"CWE-20, CWE-287, CWE-1189, CWE-269",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2070,5/12/2022,6/16/2022,2022,ICSA-22-132-06,Siemens SIMATIC WinCC (Update A),Siemens,"SIMATIC PCS, WinCC",The following Siemens products are affected: SIMATIC PCS 7 v9.0: All versions SIMATIC PCS 7 v9.1: All versions SIMATIC WinCC Runtime Professional v16: All versions --------- Begin Update A Part 1 of 2 --------- SIMATIC WinCC Runtime Professional v17: All versions prior to v17 Upd4 --------- End Update A Part 1 of 2 --------- SIMATIC WinCC v7.4: All versions SIMATIC WinCC v7.5: All versions prior to 7.5 SP2 Update 8.,CVE-2022-24287,7.8,High,CWE-1188,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2069,5/12/2022,5/12/2022,2022,ICSA-22-132-07,Siemens SICAM P850 and SICAM P855,Siemens,Siemens SICAM P850 and SICAM P855,"The following versions of SICAM P850 and SICAM P855, electrical variable measuring devices, are affected: SICAM P850 7KG8500-0AA00-0AA0: All versions prior to v3.0 SICAM P850 7KG8500-0AA00-2AA0: All versions prior to v3.0 SICAM P850 7KG8500-0AA10-0AA0: All versions prior to v3.0 SICAM P850 7KG8500-0AA10-2AA0: All versions prior to v3.0 SICAM P850 7KG8500-0AA30-0AA0: All versions prior to v3.0 SICAM P850 7KG8500-0AA30-2AA0: All versions prior to v3.0 SICAM P850 7KG8501-0AA01-0AA0: All versions prior to v3.0 SICAM P850 7KG8501-0AA01-2AA0: All versions prior to v3.0 SICAM P850 7KG8501-0AA02-0AA0: All versions prior to v3.0 SICAM P850 7KG8501-0AA02-2AA0: All versions prior to v3.0 SICAM P850 7KG8501-0AA11-0AA0: All versions prior to v3.0 SICAM P850 7KG8501-0AA11-2AA0: All versions prior to v3.0 SICAM P850 7KG8501-0AA12-0AA0: All versions prior to v3.0 SICAM P850 7KG8501-0AA12-2AA0: All versions prior to v3.0 SICAM P850 7KG8501-0AA31-0AA0: All versions prior to v3.0 SICAM P850 7KG8501-0AA31-2AA0: All versions prior to v3.0 SICAM P850 7KG8501-0AA32-0AA0: All versions prior to v3.0 SICAM P850 7KG8501-0AA32-2AA0: All versions prior to v3.0 SICAM P855 7KG8550-0AA00-0AA0: All versions prior to v3.0 SICAM P855 7KG8550-0AA00-2AA0: All versions prior to v3.0 SICAM P855 7KG8550-0AA10-0AA0: All versions prior to v3.0 SICAM P855 7KG8550-0AA10-2AA0: All versions prior to v3.0 SICAM P855 7KG8550-0AA30-0AA0: All versions prior to v3.0 SICAM P855 7KG8550-0AA30-2AA0: All versions prior to v3.0 SICAM P855 7KG8551-0AA01-0AA0: All versions prior to v3.0 SICAM P855 7KG8551-0AA01-2AA0: All versions prior to v3.0 SICAM P855 7KG8551-0AA02-0AA0: All versions prior to v3.0 SICAM P855 7KG8551-0AA02-2AA0: All versions prior to v3.0 SICAM P855 7KG8551-0AA11-0AA0: All versions prior to v3.0 SICAM P855 7KG8551-0AA11-2AA0: All versions prior to v3.0 SICAM P855 7KG8551-0AA12-0AA0: All versions prior to v3.0 SICAM P855 7KG8551-0AA12-2AA0: All versions prior to v3.0 SICAM P855 7KG8551-0AA31-0AA0: All versions prior to v3.0 SICAM P855 7KG8551-0AA31-2AA0: All versions prior to v3.0 SICAM P855 7KG8551-0AA32-0AA0: All versions prior to v3.0 SICAM P855 7KG8551-0AA32-2AA0: All versions prior to v3.0.","CVE-2022-29872, CVE-2022-29873, CVE-2022-29874, CVE-2022-29876, CVE-2022-29877, CVE-2022-29878, CVE-2022-29879, CVE-2022-29880, CVE-2022-29881, CVE-2022-29882, CVE-2022-29883",9.8,Critical,"CWE-141, CWE-319, CWE-79, CWE-306, CWE-294, CWE-287",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2068,5/12/2022,10/13/2022,2022,ICSA-22-132-08,Siemens Industrial Products with OPC UA (Update C),Siemens,"SIMATIC NET PC, SITOP Manager, TeleControl Server Basic","The following Siemens industrial products are affected: SIMATIC NET PC Software v14: All versions prior to 14 SP1 Update 14 SIMATIC NET PC Software v15: All versions SIMATIC NET PC Software v16: All versions prior to 16 Update 6 SIMATIC NET PC Software v17: All versions prior to 17 SP1 SITOP Manager: All versions --------- Begin Update C Part 1 of 3 --------- SIMATIC HMI Comfort Outdoor Panels 7"" and 15"" (including SIPLUS variants): All versions prior to 17 Update 5 SIMATIC HMI Comfort Panels 4"" to 22"" (including SIPLUS variants): All versions prior to 17 Update 5 SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F: All versions prior to 17 Update 5 --------- End Update C Part 1 of 3 ---------.",CVE-2021-45117,6.5,Medium,CWE-476,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2067,5/12/2022,5/12/2022,2022,ICSA-22-132-09,Siemens JT2GO and Teamcenter Visualization,Siemens,"JT2GO, Teamcenter Visualization",The following Siemens products are affected: JT2GO: All versions prior to v13.3.0.3 Teamcenter Visualization v13.3: All versions prior to v13.3.0.3 Teamcenter Visualization v14.0: All versions prior to v14.0.0.1.,"CVE-2022-29029, CVE-2022-29028, CVE-2022-29030, CVE-2022-29031, CVE-2022-29032, CVE-2022-29033",7.8,High,"CWE-835, CWE-476, CWE-680, CWE-415, CWE-824",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2066,5/12/2022,6/16/2022,2022,ICSA-22-132-10,Siemens Desigo PXC and DXR Devices (Update A),Siemens,PXC and DXR Devices,Siemens reports this vulnerability affects the following Desigo DXR and PXC controllers: Desigo DXR2: All versions prior to v01.21.142.5-22 Desigo PXC3: All versions prior to v01.21.142.4-18 Desigo PXC4: All versions prior to v02.20.142.10-10884 Desigo PXC5: All versions prior to v02.20.142.10-10884.,"CVE-2022-24039, CVE-2022-24040, CVE-2022-24041, CVE-2022-24042, CVE-2022-24043, CVE-2022-24044, CVE-2022-24045, CVE-2021-41545",9.0,Critical,"CWE-75, CWE-400, CWE-916, CWE-613, CWE-203, CWE-307, CWE-614, CWE-248",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2065,5/12/2022,5/12/2022,2022,ICSA-22-132-11,Siemens SIMATIC CP 44x-1 RNA,Siemens,"SIMATIC CP 442-1 RNA, 443-1 RNA",The following Siemens products are affected: SIMATIC CP 442-1 RNA: All versions prior to v1.5.18 SIMATIC CP 443-1 RNA: All versions prior to v1.5.18.,CVE-2022-27640,7.4,High,CWE-400,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2064,5/12/2022,12/15/2022,2022,ICSA-22-132-12,Siemens Industrial Products (Update C),Siemens,OPC Foundation Local Discovery Server of several industrial products,Siemens reports this vulnerability affects the OPC Foundation Local Discovery Server of the following Siemens industrial products: SIMATIC NET PC Software v14: All versions prior to v14 SP1 Update 14 SIMATIC NET PC Software v15: All versions SIMATIC NET PC Software v16: All versions prior to V16 Update 6 SIMATIC NET PC Software v17: All versions prior to v17 SP1 SIMATIC Process Historian OPC UA Server: All versions prior to 2020 SP1 SIMATIC WinCC: All versions --------- Begin Update C Part 1 of 2 --------- SIMATIC WinCC Runtime Professional: All versions prior 10 v18 SIMATIC WinCC Unified Scada Runtime: All versions prior 10 v18 --------- End Update C Part 1 of 2 --------- TeleControl Server Basic v3: All versions prior to v3.1.1,CVE-2021-40142,7.5,High,CWE-119,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2063,5/12/2022,8/11/2022,2022,ICSA-22-132-13,Siemens Industrial Devices using libcurl (Update B),Siemens,Industrial devices using libcurl,Siemens reports these vulnerabilities affect the following Siemens Industrial Devices using libcurl: LOGO! CMR family: All versions RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2): All versions prior to v7.1 RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2): All versions prior to v7.1 SCALANCE M804PB (6GK5804-0AP00-2AA2): All versions prior to v7.1 SCALANCE M812-1 ADSL-Router (Annex A) (6GK5812-1AA00-2AA2): All versions prior to v7.1 SCALANCE M812-1 ADSL-Router (Annex B) (6GK5812-1BA00-2AA2): All versions prior to v7.1 SCALANCE M816-1 ADSL-Router (Annex A) (6GK5816-1AA00-2AA2): All versions prior to v7.1 SCALANCE M816-1 ADSL-Router (Annex B) (6GK5816-1BA00-2AA2): All versions prior to v7.1 SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2): All versions prior to v7.1 SCALANCE M874-2 (6GK5874-2AA00-2AA2): All versions prior to v7.1 SCALANCE M874-3 (6GK5874-3AA00-2AA2): All versions prior to v7.1 SCALANCE M876-3 (EVDO) (6GK5876-3AA02-2BA2): All versions prior to v7.1 SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2): All versions prior to v7.1 SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2): All versions prior to v7.1 SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2): All versions prior to v7.1 SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1): All versions prior to v7.1 SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1): All versions prior to v7.1 SCALANCE S615 (6GK5615-0AA00-2AA2): All versions prior to v7.1 --------- Begin Update B Part 1 of 2 --------- SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0): All versions prior to v3.3.46 SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0): All versions prior to v3.3.46 SIMATIC CP 1243-7 LTE EU (6GK7243-7KX30-0XE0): All versions prior to v3.3.46 SIMATIC CP 1243-7 LTE US (6GK7243-7SX30-0XE0): All versions prior to v3.3.46 SIMATIC CP 1243-8 IRC (6GK7243-8RX30-0XE0): All versions prior to v3.3.46 SIPLUS NET CP 1242-7 V2 (6AG1242-7KX31-7XE0): All versions prior to V3.3.46 SIPLUS S7-1200 CP 1243-1 RAIL (6AG2243-1BX30-1XE0): All versions prior to V3.3.46 --------- End Update B Part 1 of 2 --------- SIMATIC CP 1543-1 (6GK7543-1AX00-0XE0): All versions prior to v3.0.22 SIMATIC CP 1545-1 (6GK7545-1GX00-0XE0): All versions prior to v1.1 SINEMA Remote Connect Client: All versions prior to v3.1 SIMATIC RTU3010C (6NH3112-0BA00-0XX0): All versions prior to v5.0 SIMATIC RTU3030C (6NH3112-3BA00-0XX0): All versions prior to v5.0 SIMATIC RTU3031C (6NH3112-3BB00-0XX0): All versions prior to v5.0 SIMATIC RTU3041C (6NH3112-4BB00-0XX0): All versions prior to v5.0 SIPLUS NET CP 1543-1 (6AG1543-1AX00-2XE0): All versions prior to v3.0.22.,"CVE-2021-22901, CVE-2021-22924",8.1,High,CWE-416,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2062,5/12/2022,5/12/2022,2022,ICSA-22-132-14,Siemens Simcenter Femap,Siemens,Simcenter Femap,"The following versions of Simcenter Femap, an advanced simulation application, are affected: Simcenter Femap: All versions prior to v2020.2.",CVE-2022-27653,7.8,High,CWE-787,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2061,5/12/2022,5/12/2022,2022,ICSA-22-132-15,Siemens OpenV2G,Siemens,OpenV2G,Siemens reports this vulnerability affects the following open-source implementation of the ISO/IEC vehicle-to-grid communication interface (V2G CI) standard: OpenV2G: v0.9.4.,CVE-2022-27242,6.2,Medium,CWE-120,Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2060,5/12/2022,8/11/2022,2022,ICSA-22-132-16,Siemens Teamcenter (Update B),Siemens,Teamcenter,Siemens reports these vulnerabilities affect the following Teamcenter product lifecycle management software: Teamcenter v12.4: All versions prior to v12.4.0.13 Teamcenter v13.0: All versions prior to v13.0.0.9 Teamcenter v13.1: All versions Teamcenter v13.2: All versions prior to v13.2.0.8 Teamcenter v13.3: All versions prior to v13.3.0.3 --------- Begin Update B Part 1 of 2 --------- Teamcenter v14.0: All versions prior to v14.0.0.2 --------- End Update B Part 2 of 2 -----------,"CVE-2022-24290, CVE-2022-29801",7.8,High,"CWE-121, CWE-611",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2059,5/10/2022,5/10/2022,2022,ICSA-22-130-01,Adminer in Industrial Products,Adminer,Adminer,"The following versions of Adminer, a database management tool, are affected: Adminer: Versions 1.112.0 to 4.6.2.",CVE-2021-43008,7.5,High,CWE-552,Multiple Critical Sectors,Worldwide,Czech Republic,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2058,5/10/2022,5/10/2022,2022,ICSA-22-130-02,Eaton Intelligent Power Protector,Eaton,Intelligent Power Protector (IPP),"The following versions of Eaton IPP, a power protection platform, are affected: Eaton Intelligent Power Protector (IPP): All versions prior to v1.69 release 166.",CVE-2021-23283,5.2,Medium,CWE-79,Multiple Critical Sectors,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2057,5/10/2022,5/10/2022,2022,ICSA-22-130-03,Eaton Intelligent Power Manager Infrastructure,Eaton,Intelligent Power Manager Infrastructure,The following Eaton Intelligent power monitoring products are affected: Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure): All versions including v1.5.0 plus205.,"CVE-2021-23284, CVE-2021-23285, CVE-2021-23286",5.7,Medium,"CWE-79, CWE-1236",Multiple Critical Sectors,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2056,5/10/2022,5/10/2022,2022,ICSA-22-130-04,Eaton Intelligent Power Manager,Eaton,Intelligent Power Manager (IPM) v1,"The following versions of Eaton IPM, a power management platform, are affected: Eaton Intelligent Power Manager (IPM) v1: All versions prior to v1.70.",CVE-2021-23282,5.2,Medium,CWE-79,Multiple Critical Sectors,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2055,5/10/2022,5/10/2022,2022,ICSA-22-130-05,AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere,AVEVA,AVEVA InTouch Access Anywhere and AVEVA Plant SCADA Access Anywhere,AVEVA reports this vulnerability affects the following HMI products: AVEVA InTouch Access Anywhere: All versions; AVEVA Plant SCADA Access Anywhere (formerly known as AVEVA Citect Anywhere and Schneider Electric Citect Anywhere): All versions.,CVE-2022-1467,7.4,High,CWE-668,"Chemical, Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater Systems",Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2054,5/10/2022,5/10/2022,2022,ICSA-22-130-06,Mitsubishi Electric MELSOFT GT OPC UA,Mitsubishi Electric,MELSOFT GT OPC UA Client,The following products and version combinations using OPC UA Client Connections are affected: MELSOFT GT OPC UA Client: Versions 1.00A to 1.02C; GT SoftGOT2000: Versions 1.215Z to 1.270G.,"CVE-2021-3712, CVE-2021-23840",7.5,High,"CWE-125, CWE-190",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2053,5/5/2022,5/5/2022,2022,ICSA-22-125-01,Johnson Controls Metasys,Johnson Controls Inc.,Metasys ADS/ADX/OAS Servers,Johnson Controls reports this vulnerability affects the following Metasys ADS/ADX/OAS Servers: Metasys ADS/ADX/OAS Servers: Versions 10 and 11.,CVE-2022-21934,8.0,High,CWE-620,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2052,5/3/2022,5/3/2022,2022,ICSA-22-123-01,Yokogawa CENTUM and ProSafe-RS,Yokogawa,CENTUM and ProSafe-RS,"The following versions of CENTUM (a Distributed Control System) and ProSafe-RS (Safety Instrumented System), are affected: CVE-2022-27188: CENTUM VP series: CENTUM VP (Including CENTUM VP Entry Class): R4.01.00 through R4.03.00 (if VP6E5150 is installed) B/M9000 VP: R6.01.01 through R6.03.02 CVE-2022-26034: CENTUM VP (Including CENTUM VP Entry Class): R6.01.10 through R6.09.00 (if VP6E5000 is installed) B/M9000 VP R8.01.01 through R8.03.01 Prosafe-RS: R4.01.00 through R4.07.00 - if RS4E5000 is installed CVE-2019-0203, CVE-2018-11782, CVE-2015-0248: CENTUM VP (Including CENTUM VP Entry Class): R6.01.10 through R6.07.10 if VP6E5000 or VP6E5100 are installed B/M9000 VP R8.01.01 through R8.03.01 Prosafe-RS: R4.01.00 through R4.05.00 - if RS4E5000 or RS4E5100 are installed.","CVE-2022-27188, CVE-2022-26034, CVE-2019-0203, CVE-2018-11782, CVE-2015-0248",7.5,High,"CWE-78, CWE-287, CWE-476, CWE-20, CWE-399",Critical Manufacturing; Energy; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2051,4/28/2022,4/28/2022,2022,ICSA-22-118-01,Johnson Controls Metasys,Johnson Controls Inc.,Metasys ADS/ADX/OAS Servers,Johnson Controls reports this vulnerability affects the following Metasys ADS/ADX/OAS Servers:All Metasys ADS/ADX/OAS Servers: Versions 10 and 11,CVE-2021-36207,9.8,Critical,CWE-269,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2050,4/26/2022,4/26/2022,2022,ICSA-22-116-01,Hitachi Energy System Data Manager,Hitachi Energy,System Data Manager - SDM600,Hitachi Energy reports these vulnerabilities affect the following System Data Manager products: All System Data Manager - SDM600 versions prior to version 1.2 FP2 HF10 (Build Nr. 1.2.14002.506).,"CVE-2020-1968, CVE-2020-12243, CVE-2020-25709, CVE-2020-25710, CVE-2020-36229, CVE-2020-36230, CVE-2021-23840",7.5,High,"CWE-203, CWE-674, CWE-617, CWE-843, CWE-190",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2049,4/21/2022,4/21/2022,2022,ICSA-22-111-01,Delta Electronics ASDA-Soft,Delta Electronics,ASDA-Soft,The following versions of ASDA-Soft servo software are affected: ASDA-Soft: Version 5.4.1.0 and prior.,"CVE-2022-1402, CVE-2022-1403",7.8,High,"CWE-125, CWE-787",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2048,4/21/2022,4/21/2022,2022,ICSA-22-111-02,Johnson Controls Metasys SCT Pro,Johnson Controls Inc.,Metasys,The following versions of Johnson Controls SCT and SCT Pro building automation software are affected: Metasys System Configuration Tool (SCT): All versions prior to 14.2.2 Metasys System Configuration Tool Pro (SCT Pro): All versions prior to 14.2.2.,CVE-2021-36203,5.3,Medium,CWE-918,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2047,4/21/2022,4/21/2022,2022,ICSA-22-111-03,Hitachi Energy MicroSCADA Pro/X SYS600,Hitachi Energy,MicroSCADA Pro/X SYS600,"The following versions of MicroSCADA Pro/X SYS600, a SCADA product, are affected: SYS600: Versions 10.1.1 and prior (OpenSSL Vulnerability) SYS600: Versions 9.4 FP1 through 10.2.1 (Node.js vulnerabilities) SYS600: Versions 10.0.0 through 10.2.1 (PostgreSQL vulnerabilities).","CVE-2020-1968, CVE-2020-8265, CVE-2020-8287, CVE-2020-8201, CVE-2020-8252, CVE-2020-8172, CVE-2020-8174, CVE-2021-32027, CVE-2021-32028",8.8,High,"CWE-203, CWE-444, CWE-120, CWE-295, CWE-119, CWE-200",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2046,4/19/2022,4/19/2022,2022,ICSA-22-109-01,Interlogix Hills ComNav,Interlogix (Carrier Global Corporation),Hills ComNav,Carrier reports these vulnerabilities affect the following Hills ComNav remote access integration modules: Hills ComNav: versions prior to 3002-19.,"CVE-2022-26519, CVE-2022-1318",6.2,Medium,"CWE-307, CWE-326",Commercial Facilities,Australia,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2045,4/19/2022,4/19/2022,2022,ICSA-22-109-02,Automated Logic WebCTRL,Automated Logic,WebCtrl Server,Carrier reports this vulnerability affects the following Automated Logic WebCtrl Server building automation software products: WebCtrl Server: All versions up to 7.0.,CVE-2022-1019,5.2,Medium,CWE-601,Commercial Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2044,4/19/2022,4/19/2022,2022,ICSA-22-109-03,FANUC ROBOGUIDE Simulation Platform,FANUC Corporation / FANUC America Corporation,ROBOGUIDE,"The following versions of ROBOGUIDE, a simulation platform software suite for FANUC Robots, are affected: ROBOGUIDE v9.40083.00.05 (Rev T) and earlier. Note: This offline simulation software program does not provide any control or management of physical devices or processes. It is included because it is used in Industrial Control Systems (ICS).","CVE-2021-38483, CVE-2021-43986, CVE-2021-43988, CVE-2021-43990, CVE-2021-43933",6.1,Medium,"CWE-732, CWE-284, CWE22, CWE-611, CWE-400",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2043,4/19/2022,4/19/2022,2022,ICSA-22-109-03,FANUC ROBOGUIDE Simulation Platform,FANUC Corporation / FANUC America Corporation,ROBOGUIDE,"The following versions of ROBOGUIDE, a simulation platform software suite for FANUC Robots, are affected: ROBOGUIDE v9.40083.00.05 (Rev T) and earlier. Note: This offline simulation software program does not provide any control or management of physical devices or processes. It is included because it is used in Industrial Control Systems (ICS).","CVE-2021-38483, CVE-2021-43986, CVE-2021-43988, CVE-2021-43990, CVE-2021-43933",6.1,Medium,"CWE-732, CWE-284, CWE22, CWE-611, CWE-400",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2042,4/19/2022,4/19/2022,2022,ICSA-22-109-04,Elcomplus SmartPPT SCADA,Elcomplus,SmartPPT,"The following version of SmartPPT SCADA, an integrated voice and data dispatch software, is affected: SmartPPT SCADA v1.1.","CVE-2021-43932, CVE-2021-43939, CVE-2021-43934, CVE-2021-43930",9.8,Critical,"CWE-79, CWE-285, CWE-434, CWE-22",Communications,Worldwide,Russia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2041,4/19/2022,4/19/2022,2022,ICSA-22-109-05,Elcomplus SmartPPT SCADA Server,Elcomplus,SmartPPT SCADA Server,"The following version of SmartPPT SCADA Server, an integrated voice and data dispatch software, is affected: SmartPPT SCADA Server v1.4.","CVE-2021-43932, CVE-2021-43938, CVE-2021-43934, CVE-2021-43930, CVE-2021-43937",9.8,Critical,"CWE-79, CWE-200, CWE-434, CWE-35, CWE-352",Communications,Worldwide,Russia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2040,4/14/2022,4/14/2022,2022,ICSA-22-104-01,Delta Electronics DMARS,Delta Electronics,DMARS,"The following versions of DMARS, a Motion Controller program development tool, are affected:DMARS: All versions prior to v2.1.10.24.",CVE-2022-1331,5.5,Medium,CWE-611,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2039,4/14/2022,4/14/2022,2022,ICSA-22-104-02,Johnson Controls Metasys,Johnson Controls Inc.,Metasys ADS/ADX/OAS Servers,Johnson Controls reports this vulnerability affects the following Metasys ADS/ADX/OAS servers for building management systems: All Metasys ADS/ADX/OAS Servers: Versions 10 and 11.,CVE-2021-36205,8.1,High,CWE-459,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2038,4/14/2022,4/14/2022,2022,ICSA-22-104-03,Red Lion DA50N,Red Lion Controls,DA50N,"The following versions of Red Lion DA50N, a networking gateway, are affected: DA50N: All versions.","CVE-2022-26516, CVE-2022-1039, CVE-2022-27179",9.6,Critical,"CWE-345, CWE-521, CWE-1104, CWE-522",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2037,4/14/2022,4/14/2022,2022,ICSA-22-104-04,Siemens SCALANCE FragAttacks,Siemens,SCALANCE family devices,The following Siemens products are affected:SCALANCE W721-1 RJ45: All versions SCALANCE W722-1 RJ45: All versions SCALANCE W734-1 RJ45: All versions SCALANCE W738-1 M12: All versions SCALANCE W748-1 M12: All versions SCALANCE W738-1 RJ45: All versions SCALANCE W761-1 RJ45: All versions SCALANCE W774-1 M12 EEC: All versions SCALANCE W774-1 RJ45: All versions SCALANCE W778-1 M12 EEC: All versions SCALANCE W786-1 RJ45: All versions SCALANCE W786-2 RJ45: All versions SCALANCE W786-2 SFP: All versions SCALANCE W786-2IA RJ45: All versions SCALANCE W788-1 M12: All versions SCALANCE W788-1 RJ45: All versions SCALANCE W788-2 M12: All versions SCALANCE W788-1 M12 EEC: All versions SCALANCE W788-2 RJ45: All versions SCALANCE W1748-1 M12: All versions prior to v3.0.0 SCALANCE W1750D M12: All versions prior to v8.7.1.3 SCALANCE W1788-1 M12: All versions prior to v3.0.0 SCALANCE W1788-2 EEC M12: All versions prior to v3.0.0 SCALANCE W1788-2 M12: All versions prior to v3.0.0 SCALANCE W17.,"CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26143, CVE-2020-26144, CVE-2020-26145, CVE-2020-26146, CVE-2020-26147",6.5,Medium,"CWE-306, CWE-287, CWE-74, CWE-354, CWE-20",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2036,4/14/2022,8/11/2022,2022,ICSA-22-104-05,Siemens OpenSSL Vulnerabilities in Industrial Products (Update B),Siemens,Siemens Industrial Products,"Siemens reports this vulnerability affects the following products: RUGGEDCOM CROSSBOW Station Access Controller: All versions since and including v5.2.0 only when running on ROX v2.14.0 RUGGEDCOM RCM1224: Versions 6.2 through 7.1 SCALANCE LPE9403 (6GK5998-3GS00-2AC2): All versions prior to v1.1 SCALANCE M804PB (6GK5804-0AP00-2AA2): Versions 6.2 through 7.1 SCALANCE M812-1 ADSL-Router (Annex A) (6GK5812-1AA00-2AA2): Versions 6.2 through 7.1 SCALANCE M812-1 ADSL-Router (Annex B) (6GK5812-1BA00-2AA2): Versions 6.2 through 7.1 SCALANCE M816-1 ADSL-Router (Annex A) (6GK5816-1AA00-2AA2): Versions 6.2 through 7.1 SCALANCE M816-1 ADSL-Router (Annex B) (6GK5816-1BA00-2AA2): Versions 6.2 through 7.11 SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2): Versions 6.2 through 7.1 SCALANCE M874-2 (6GK5874-2AA00-2AA2): Versions 6.2 through 7.1 SCALANCE M874-3 (6GK5874-3AA00-2AA2): Versions 6.2 through 7.1SCALANCE M876-3 (6GK5876-3AA02-2BA2): Versions 6.2 through 7.1SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2): Versions 6.2 through 7.1SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2): Versions 6.2 through 7.1SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2): Versions 6.2 through 7.1 SCALANCE S602: All versions since and including v4.1 SCALANCE S612: All versions since and including v4.1 SCALANCE S615 (6GK5615-0AA00-2AA2): Versions 6.2 through 7.1 SCALANCE S623: All versions since and including v4.1 SCALANCE S627-2M: All versions since and including v4.1 SCALANCE SC622-2C (6GK5622-2GS00-2AC2): Versions 2.0 through 2.1.4 SCALANCE SC632-2C (6GK5632-2GS00-2AC2): Versions 2.0 through 2.1.4 SCALANCE SC636-2C (6GK5636-2GS00-2AC2): Versions 2.0 through 2.1.4 SCALANCE SC642-2C (6GK5642-2GS00-2AC2): Versions 2.0 through 2.1.4 SCALANCE SC646-2C (6GK5646-2GS00-2AC2): Versions 2.0 through 2.1.4SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0): Versions 2.0 through 3.0 SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0): Versions 2.0 through 3.0 SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0): Versions 2.0 through 3.0 SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0): Versions 2.0 through 3.0 SCALANCE W1788-2 M12 (6GK5788-2GY01-0AA0): Versions 2.0 through 3.0 SCALANCE W1788-2IA M12 (6GK5788-2HY01-0AA0): Versions 2.0 through 3.0 SCALANCE W-700 IEEE 802.11n family: All versions since and including v6.5 SCALANCE XB-200: All versions prior to v4.3 SCALANCE XC-200: All versions prior to v4.3 SCALANCE XF-200BA: All versions prior to v4.3 SCALANCE XM-400: All versions prior to v6.4 SCALANCE XP-200: All versions prior to v4.3 SCALANCE XR-300WG: All versions prior to v4.3 SCALANCE XR-500 Family: All versions prior to v6.4 SIMATIC Cloud Connect 7 CC712 (6GK1411-1AC00): Versions 1.1 through 1.6 SIMATIC Cloud Connect 7 CC716 (6GK1411-5AC00): Versions 1.1 through 1.6 --------- Begin Update B Part 1 of 1 --------- SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0): Versions since v3.1 and prior to v3.3.46 SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0): Versions since v3.1 and prior to v3.3.46 SIMATIC CP 1243-7 LTE EU (6GK7243-7KX30-0XE0): Versions since v3.1 and prior to v3.3.46 SIMATIC CP 1243-7 LTE US (6GK7243-7SX30-0XE0): Versions since v3.1 and prior to v3.3.46 SIMATIC CP 1243-8 IRC (6GK7243-8RX30-0XE0): Versions since v3.1 and prior to v3.3.46 --------- End Update B Part 1 of 1 --------- SIMATIC CP 1542SP-1 IRC (incl. SIPLUS variants): All versions since and including v2.1 SIMATIC CP 1543-1 (6GK7543-1AX00-0XE0): Versions 2.2 through 3.0 SIMATIC CP 1543SP-1 (incl. SIPLUS variants): All versions since and including v2.1 SIMATIC CP 1545-1 (6GK7545-1GX00-0XE0): All versions since and including v1.0 SIMATIC HMI Comfort Outdoor Panels 7"" & 15"" (incl. SIPLUS variants): All versions prior to V17.0 Upd 2 SIMATIC HMI Comfort Panels 4"" - 22"" (incl. SIPLUS variants): All versions prior to V17.0 Upd 2 SIMATIC HMI KTP Mobile Panels: All versions prior to v17.0 Upd 2 SIMATIC Logon: Versions 1.6 Upd 2 through 1.6 Upd 5 SIMATIC MV540 H (6GF3540-0GE10): All versions prior to v3.1 SIMATIC MV540 S (6GF3540-0CD10): All versions prior to v3.1 SIMATIC MV550 H (6GF3550-0GE10): All versions prior to v3.1 SIMATIC MV550 S (6GF3550-0CD10): All versions prior to v3.1 SIMATIC MV560 U (6GF3560-0LE10): All versions prior to v3.1 SIMATIC MV560 X (6GF3560-0HE10): All versions prior to v3.1 SIMATIC PCS 7 TeleControl: All versions prior to v9.1 SIMATIC PCS neo: All versions prior to v3.1 SIMATIC PDM: Versions 9.1 Upd 7 through 9.2 SP 1 SIMATIC Process Historian OPC UA Server: All versions 2019 through 2020 Upd1 SIMATIC RF166C (6GT2002-0EE20): All versions prior to v2.0 SIMATIC RF185C (6GT2002-0JE10): All versions prior to v2.0 SIMATIC RF186C (6GT2002-0JE20): All versions prior to v2.0 SIMATIC RF186CI (6GT2002-0JE50): All versions prior to v2.0 SIMATIC RF188C (6GT2002-0JE40): All versions prior to v2.0 SIMATIC RF188CI (6GT2002-0JE60): All versions prior to v2.0 SIMATIC RF360R (6GT2801-5BA30): All versions prior to v2.0 SIMATIC RF610R (6GT2811-6BC10): All versions prior to v4.0 SIMATIC RF615R (6GT2811-6CC10): All versions prior to v4.0 SIMATIC RF650R (6GT2811-6AB20): All versions prior to v4.0 SIMATIC RF680R (6GT2811-6AA10): All versions prior to v4.0 SIMATIC RF685R (6GT2811-6CA10): All versions prior to v4.0 SIMATIC S7-1200 CPU family (incl. SIPLUS variants): All versions prior to v4.5.2 SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (MLFB: 6ES7518-4AX00-1AC0, 6AG1518-4AX00-4AC0, incl. SIPLUS variant): All versions prior to v2.9.3 SIMATIC WinCC Runtime Advanced: All versions prior to v17 Update 1 SIMATIC WinCC TeleControl: All versions SINAMICS Connect 300: All versions SINEC NMS: Versions 1.0 SP1 through 1.0 SP2 SINEMA Server: Versions 14 through 14 SP3 SINUMERIK OPC UA Server: All versions prior to v3.1 SP1 SIPLUS NET CP 1543-1 (6AG1543-1AX00-2XE0): Versions 2.2 through 3.0 SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0): Versions 2.0 through 2.2 TIA Administrator: All versions prior to v1.0 SP4 TIM 1531 IRC (6GK7543-1MX00-0XE0): Versions 2.0 through 2.2.",CVE-2021-3449,5.9,Medium,CWE-476,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2035,4/14/2022,12/15/2022,2022,ICSA-22-104-06,Siemens PROFINET Stack Integrated on Interniche Stack (Update E),Siemens,PROFINET Stack Integrated on Interniche Stack,"The following products are affected: SIMATIC CFU DIQ (6ES7655-5PX31-1XX0): All versions SIMATIC CFU PA (6ES7655-5PX11-0XX0): All versions SIMATIC ET200AL IM157-1 PN: All versions SIMATIC ET200ecoPN, CM 8x IO-Link, M12-L (6ES7148-6JG00-0BB0): Versions 5.1.1 and later SIMATIC ET200ecoPN, DI 8x24VDC, M12-L (6ES7141-6BG00-0BB0): Versions 5.1.1 and later SIMATIC ET200ecoPN, DI 16x24VDC, M12-L (6ES7141-6BH00-0BB0): Versions 5.1.1 and later SIMATIC ET200ecoPN, DIQ 16x24VDC/2A, M12-L (6ES7143-6BH00-0BB0): Versions 5.1.1 and later SIMATIC ET200ecoPN, DQ 8x24VDC/0,5A, M12-L (6ES7142-6BG00-0BB0): Versions 5.1.1 and later SIMATIC ET200ecoPN, DQ 8x24VDC/2A, M12-L (6ES7142-6BR00-0BB0): Versions 5.1.1 and later SIMATIC ET200MP IM155-5 PN HF (incl. SIPLUS variants): Versions 4.2 and later SIMATIC ET200SP IM155-6 MF HF: All versions SIMATIC ET200SP IM155-6 PN HA (incl. SIPLUS variants): All versions SIMATIC ET200SP IM155-6 PN HF (incl. SIPLUS variants): Versions 4.2 and later SIMATIC ET200SP IM155-6 PN/2 HF (incl. SIPLUS variants): Versions 4.2 and later SIMATIC ET200SP IM155-6 PN/3 HF (incl. SIPLUS variants): Versions 4.2 and later SIMATIC ET 200pro IM154-8 PN/DP CPU(6ES7154-8AB01-0AB0): All versions prior to V3.2.19 SIMATIC ET 200pro IM154-8F PN/DP CPU(6ES7154-8FB01-0AB0): All versions prior to V3.2.19 SIMATIC ET 200pro IM154-8FX PN/DP CPU(6ES7154-8FX00-0AB0): All versions prior to V3.2.19 SIMATIC ET 200S IM151-8 PN/DP CPU(6ES7151-8AB01-0AB0): All versions prior to V3.2.19 SIMATIC ET 200S IM151-8F PN/DP CPU(6ES7151-8FB01-0AB0): All versions prior to V3.2.19 SIMATIC PN/MF Coupler (6ES7158-3MU10-0XA0): All versions SIMATIC PN/PN Coupler (6ES7158-3AD10-0XA0): Versions 4.2 and later SIMATIC S7-300 CPU 314C-2 PN/DP (6ES7314-6EH04-0AB0): All versions prior to V3.3.19 SIMATIC S7-300 CPU 315-2 PN/DP (6ES7315-2EH14-0AB0): All versions prior to V3.2.19 SIMATIC S7-300 CPU 315F-2 PN/DP (6ES7315-2FJ14-0AB0): All versions prior to V3.2.19 SIMATIC S7-300 CPU 315T-3 PN/DP (6ES7315-7TJ10-0AB0): All versions prior to V3.2.19 SIMATIC S7-300 CPU 317-2 PN/DP (6ES7317-2EK14-0AB0): All versions prior to V3.2.19 SIMATIC S7-300 CPU 317F-2 PN/DP (6ES7317-2FK14-0AB0): All versions prior to V3.2.19 SIMATIC S7-300 CPU 317T-3 PN/DP (6ES7317-7TK10-0AB0): All versions prior to V3.2.19 SIMATIC S7-300 CPU 317TF-3 PN/DP (6ES7317-7UL10-0AB0): All versions prior to V3.2.19 SIMATIC S7-300 CPU 319-3 PN/DP (6ES7318-3EL01-0AB0): All versions prior to V3.2.19 SIMATIC S7-300 CPU 319F-3 PN/DP (6ES7318-3FL01-0AB0): All versions prior to V3.2.19 SIMATIC S7-400 H V6 CPU family (incl. SIPLUS variants): All versions prior to v6.0.10 SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants): All versions SIMATIC S7-410 V8 CPU family (incl. SIPLUS variants): All versions prior to V8.2.3 --------- Begin Update E Part 1 of 4 --------- SIMATIC S7-410 V10 CPU family (incl. SIPLUS variants): All versions prior to V10.1.1 --------- End Update E Part 1 of 4 --------- SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions prior to v2.0.0 --------- Begin Update E Part 2 of 4 --------- SIMATIC TDC CP51M1: All versions prior to V1.1.10 SIMATIC TDC CPU555: All versions prior to V1.2.1 --------- End Update E Part 2 of 4 --------- SIMATIC WinAC RTX: All versions SIMIT Simulation Platform: All versions SINAMICS DCM: All versions with Ethernet interface SINAMICS G110M: All versions with Ethernet interface SINAMICS G115D: All versions with Ethernet interface SINAMICS G120 (incl. SIPLUS variants): All versions with Ethernet interface SINAMICS G130: All versions SINAMICS G150: All versions SINAMICS S110: All versions with Ethernet interface SINAMICS S120 (incl. SIPLUS variants): All versions SINAMICS S150: All versions SINAMICS S210: All versions SINAMICS V90: All versions with Ethernet interface SIPLUS HCS4200 CIM4210 (6BK1942-1AA00-0AA0): All versions SIPLUS HCS4200 CIM4210C (6BK1942-1AA00-0AA1): All versions SIPLUS HCS4300 CIM4310 (6BK1943-1AA00-0AA0): All versions SIPLUS NET PN/PN Coupler (6AG2158-3AD10-4XA0): Versions 4.2 and later SIPLUS S7-300 CPU 314C-2 PN/DP (6AG1314-6EH04-7AB0): All versions prior to V3.3.19 SIPLUS S7-300 CPU 315-2 PN/DP (6AG1315-2EH14-7AB0): All versions prior to V3.2.19 SIPLUS S7-300 CPU 315F-2 PN/DP (6AG1315-2FJ14-2AB0): All versions prior to V3.2.19 SIPLUS S7-300 CPU 317-2 PN/DP (6AG1317-2EK14-7AB0): All versions prior to V3.2.19 SIPLUS S7-300 CPU 317F-2 PN/DP (6AG1317-2FK14-2AB0): All versions prior to V3.2.19.",CVE-2022-25622,5.3,Medium,CWE-400,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2034,4/14/2022,7/14/2022,2022,ICSA-22-104-07,Siemens Mendix (Update B),Siemens,Mendix,"The following versions of Mendix, a software platform to build mobile and web applications, are affected: -------- Begin Update B Part 1 of 2 --------- Mendix applications using Mendix 7: All versions prior to 7.23.31 Mendix applications using Mendix 8: All versions prior to 8.18.18 Mendix applications using Mendix 9: All versions prior to 9.11 Mendix applications using Mendix 9 (v9.6): All versions prior to 9.6.12 --------- End Update B Part 1 of 2 ---------.",CVE-2022-27241,5.3,Medium,CWE-200,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2033,4/14/2022,4/14/2022,2022,ICSA-22-104-08,Siemens SCALANCE W1700,Siemens,SCALANCE W1700,"The following versions of SCALANCE, a wireless communication device, are affected:SCLANCE W1788-1 M12: All versions prior to 3.0.0 SCALANCE W1788-2 ECC M12: All versions prior to 3.0.0 SCALANCE W1788-2 M12: All versions prior to 3.0.0 SCALANCE W1788-2IA M12: All versions prior to 3.0.0.","CVE-2022-27481, CVE-2022-28328, CVE-2022-28329",7.4,High,"CWE-362, CWE-20",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2032,4/14/2022,4/14/2022,2022,ICSA-22-104-09,Siemens SCALANCE X-300 Switches,Siemens,SCALANCE X-300 switch family devices,The following Siemens products are affected: SCALANCE X302-7 EEC: All versions prior to v4.1.4; SCALANCE X304-2FE: All versions prior to v4.1.4; SCALANCE X306-1LD FE: All versions prior to v4.1.4 SCALANCE X307-2 EEC: All versions prior to v4.1.4; SCALANCE X307-3: All versions prior to v4.1.4 SCALANCE X307-3LD: All versions prior to v4.1.4 SCALANCE X308-2: All versions prior to v4.1.4; SCALANCE X308-2LD: All versions prior to v4.1.4; SCALANCE X308-2LH: All versions prior to v4.1.4; SCALANCE X308-2LH+: All versions prior to v4.1.4; SCALANCE X308-2M: All versions prior to v4.1.4; SCALANCE X308-2M POE: All versions prior to v4.1.4 SCALANCE X308-2M TS: All versions prior to v4.1.4; SCALANCE X310: All versions prior to v4.1.4; SCALANCE X310FE: All versions prior to v4.1.4 SCALANCE X320-1 FE: All versions prior to v4.1.4; SCALANCE X320-1-2LD FE: All versions prior to v4.1.4; SCALANCE X408-2: All versions prior to v4.1.4; SCALANCE XR324-4M EEC: All versions prior to v4.1.4; SCALANCE XR324-4M PoE: All versions prior to v4.1.4; SCALANCE XR324-4M PoE TS: All versions prior to v4.1.4; SCALANCE XR324-12M: All versions prior to v4.1.4; SCALANCE XR324-12M TS: All versions prior to v4.1.4; SIPLUS NET SCALANCE X308-2: All versions prior to v4.1.4; Smart Security Manager: Versions 1.5 and prior.,"CVE-2022-25751, CVE-2022-25752, CVE-2022-25753, CVE-2022-25754, CVE-2022-25755, CVE-2022-25756, CVE-2022-26334, CVE-2022-26335, CVE-2022-26380",9.6,Critical,"CWE-20, CWE-330, CWE-121, CWE-352, CWE-284, CWE-80, CWE-120, CWE-125",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2031,4/14/2022,4/14/2022,2022,ICSA-22-104-10,Siemens SICAM A8000,Siemens,SICAM A8000,The following Siemens products are affected: SICAM A8000 CP-8031: All versions prior to v4.80 SICAM A8000 CP-8050: All versions prior to v4.80.,CVE-2022-27480,5.3,Medium,CWE-306,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2030,4/14/2022,4/14/2022,2022,ICSA-22-104-11,Siemens SIMATIC Energy Manager,Siemens,SIMATIC Energy Manager,The following Siemens products are affected: SIMATIC Energy Manager Basic: All versions prior to v7.3 Update 1 SIMATIC Energy Manager PRO: All versions prior to v7.3 Update 1.,"CVE-2022-23448, CVE-2022-23449, CVE-2022-23450",10.0,Critical,"CWE-732, CWE-427, CWE-502",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2029,4/14/2022,8/11/2022,2022,ICSA-22-104-12,Siemens SIMATIC S7-400 (Update A),Siemens,SIMATIC S7-400,The following Siemens S7-400 products are affected: SIMATIC S7-400 HV6 CPU family (incl. SIPLUS variants): All versions prior to v6.0.10 SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants): All versions --------- Begin Update A Part 1 of 2 --------- SIMATIC S7-410 V8 CPU family (incl. SIPLUS variants): All versions prior to v8.2.3 --------- End Update A Part 1 of 2 --------- SIMATIC S7-410 V10 CPU family (incl. SIPLUS variants): All versions prior to v10.1.,CVE-2021-40368,7.5,High,CWE-119,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2028,4/14/2022,12/15/2022,2022,ICSA-22-104-13,Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem (Update A),Siemens,SIMATIC S7-1500 CPU GNU/Linux subsystem,Siemens reports these vulnerabilities affect the GNU/Linux subsystem of the following products: --------- Begin Update A Part 1 of 1 --------- SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant): firmware version V3.0 SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant): firmware version V2.9.4 SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant): firmware version V2.9.3 --------- End Update A Part 1 of 1 ---------.,SeeSSB-439005,9.8,Critical,CWE-1104,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2027,4/14/2022,4/14/2022,2022,ICSA-22-104-14,Siemens SIMATIC STEP 7 (TIA Portal),Siemens,STEP 7 (TIA Portal),The following Siemens products are affected: SIMATIC STEP 7 (TIA Portal) v15: All versions; SIMATIC STEP 7 (TIA Portal) v16: All versions prior to v16 Update 5; SIMATIC STEP 7 (TIA Portal) v17: All versions prior to v17 Update 2.,CVE-2021-42029,6.4,Medium,CWE-284,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2026,4/14/2022,4/14/2022,2022,ICSA-22-104-15,Siemens Simcenter Femap,Siemens,Simcenter Femap,"The following versions of Simcenter Femap, a simulation application, are affected: Simcenter Femap: All versions prior to v2022.1.2.","CVE-2022-28661, CVE-2022-28662, CVE-2022-28663",7.8,High,"CWE-125, CWE-787",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2025,4/14/2022,7/14/2022,2022,ICSA-22-104-16,Siemens TIA Administrator (Update A),Siemens,"SIMATICS PCS neo (Admin Console), SINTEPLAN, TIA Portal","TIA Administrator in the following Siemens products is affected: SIMATICS PCS neo (Administration Console): All versions prior to v3.1 SP1 --------- Begin Update A Part 1 of 2 --------- SINETPLAN: All versions TIA Portal: Versions 15, 15.1, 16, and 17 --------- End Update A Part 1 of 2 ---------.",CVE-2022-27194,7.5,High,CWE-400,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2024,4/14/2022,4/14/2022,2022,ICSA-22-104-17,Siemens Mendix,Siemens,Mendix,"The following versions of Mendix, a software platform to build mobile and web applications, are affected: Mendix applications using Mendix 7: All versions prior to 7.23.27; Mendix applications using Mendix 8: All versions prior to 8.18.14; Mendix applications using Mendix 9: All versions prior to 9.12.0; Mendix applications using Mendix 9 (9.6): All versions prior to 9.6.3.",CVE-2022-25650,3.1,Low,CWE-284,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2023,4/12/2022,4/12/2022,2022,ICSA-22-102-01,Valmet DNA,Valmet,DNA,"The following versions of Valmet DNA, a distributed control system, are affected: Valmet DNA: Versions from Collection 2012 to Collection 2021.",CVE-2021-26726,8.8,High,CWE-326,Multiple Critical Sectors,Worldwide,Finland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2022,4/12/2022,4/12/2022,2022,ICSA-22-102-02,Mitsubishi Electric MELSEC-Q Series C Controller Module,Mitsubishi Electric,MELSEC-Q Series C Controller Module,The following versions of MELSEC-Q Series C Controller Module using Wind River VxWorks Version 6.4 are affected: Module Q12DCCPU-V: First 5 digits of serial number 24031 and prior.,CVE-2021-29998,9.0,Critical,CWE-122,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2021,4/12/2022,4/12/2022,2022,ICSA-22-102-03,Inductive Automation Ignition,Inductive Automation,Ignition,The following versions of Inductive Automation Ignition software are affected:Inductive Automation Ignition: All 8.0 versions after 8.0.4 Inductive Automation Ignition: All 8.1 versions prior to 8.1.10.,CVE-2022-1264,6.8,Medium,CWE-22,Critical Manufacturing; Energy; Information Technology,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2020,4/12/2022,5/12/2022,2022,ICSA-22-102-04,Mitsubishi Electric GT25-WLAN (Update A),Mitsubishi Electric,Wireless LAN communication unit GT25-WLAN in GOT2000 Series GT25 or GT27,"The following versions of Wireless LAN communication unit GT25-WLAN in GOT2000 Series GT25 or GT27, are affected: Begin Update A: GT25-WLAN: Version 01.39.000 and earlier End Update A.","CVE-2020-24586, CVE-2020-24587, CVE-2020-24588, CVE-2020-26140, CVE-2020-26143, CVE-2020-26144, CVE-2020-26146",6.5,Medium,"CWE-212, CWE-326, CWE-306, CWE-74, CWE-20",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2019,4/12/2022,4/12/2022,2022,ICSA-22-102-05,Aethon TUG Home Base Server,Aethon (owned by ST Engineering),TUG Home Base Server,"Aethon reports these vulnerabilities affect the following versions of TUG Home Base Server, a server used to control and communicate with autonomous mobile robots in hospitals: All versions prior to Version 24.","CVE-2022-1066, CVE-2022-26423, CVE-2022-1070, CVE-2022-27494, CVE-2022-1059",9.8,Critical,"CWE-862, CWE-300, CWE-79",Healthcare and Public Health,"East Asia, United States",Singapore,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2018,4/7/2022,4/7/2022,2022,ICSA-22-097-01,Pepperl+Fuchs WirelessHART-Gateway,PEPPERL+FUCHS,WirelessHART-Gateway,"The following versions of WirelessHART-Gateway industrial networking devices are affected:WHA-GW-F2D2-0-AS- Z2-ETH: Versions 3.0.7, 3.0.8, 3.0.9; WHA-GW-F2D2-0-AS-Z2-ETH.EIP: Versions 3.0.7, 3.0.8, 3.0.9.","CVE-2021-34565, CVE-2016-10707, CVE-2021-34561, CVE-2021-33555, CVE-2014-6071, CVE-2012-6708, CVE-2015-9251, CVE-2020-11023, CVE-2020-11022, CVE-2019-11358, CVE-2020-7656, CVE-2021-34560, CVE-2021-34564, CVE-2021-34559, CVE-2021-34562, CVE-2007-2379, CVE-2011-4969, CVE-2021-34563, CVE-2013-0169",9.8,Critical,"CWE-798, CWE-400, CWE-350, CWE-22, CWE-79, CWE-200, CWE-315, CWE-444, CWE-1004, CWE-310",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2017,4/7/2022,4/7/2022,2022,ICSA-22-097-02,ABB SPIET800 and PNI800,ABB,Symphony Plus SPIET800 and PNI800,The following versions of Symphony Plus network interface modules are affected:SPIET800: Firmware Version A_B or prior PNI800: Firmware Version A_B or prior.,"CVE-2021-22286, CVE-2021-22285, CVE-2021-22288",7.5,High,"CWE-372, CWE-241, CWE-400",Multiple Critical Sectors,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2016,4/5/2022,4/5/2022,2022,ICSMA-22-095-01,LifePoint Informatics Patient Portal,LifePoint Informatics,Patient Portal,"The following version of LifePoint Informatics Patient Portal, a website containing patient health data, is affected:Patient Portal Version LPI 3.5.12.P30.",CVE-2022-1067,6.5,Medium,CWE-288,Healthcare and Public Health,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2015,4/5/2022,4/5/2022,2022,ICSA-22-095-01,Rockwell Automation ISaGRAF,Rockwell Automation,ISaGRAF,The following Rockwell Automation products are affected:Connected Component Workbench: v13.00.00 and prior ISaGRAF Workbench: v6.0 though v6.6.9 Safety Instrumented Systems Workstation: v1.2 and prior (for Trusted Controllers).,CVE-2022-1118,8.6,High,CWE-502,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2014,4/5/2022,4/5/2022,2022,ICSA-22-095-02,Johnson Controls Metasys,Johnson Controls Inc.,Metasys,"The following versions of Metasys, a building automation system, are affected:Metasys ADS/ADX/OAS Versions 10 and 11.",CVE-2021-36202,8.4,High,CWE-918,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2013,3/31/2022,3/31/2022,2022,ICSA-22-090-01,Schneider Electric SCADAPack Workbench,Schneider Electric,SCADAPack Workbench,The following versions of SCADAPack Workbench software are affected: SCADAPack Workbench Versions 6.6.8a and prior.,CVE-2022-0221,5.5,Medium,CWE-611,Multiple Critical Sectors,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2012,3/31/2022,3/31/2022,2022,ICSA-22-090-02,Hitachi Energy e-mesh EMS,Hitachi Energy,e-mesh EMS,"The following version of e-mesh EMS, an optimizer software for energy resources, is affected: e-mesh EMS Version 1.0.","CVE-2020-8174, CVE-2020-8265, CVE-2020-11080, CVE-2021-22883",7.5,High,"CWE-119, CWE-400, CWE-416",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2011,3/31/2022,3/31/2022,2022,ICSA-22-090-03,Fuji Electric Alpha5,Fuji Electric,Alpha5,"The following versions of Fuji Electric's Alpha5, a servo drive system, are affected: Alpha5: All versions prior to 4.3.","CVE-2022-21168, CVE-2022-21202, CVE-2022-24383, CVE-2022-21228, CVE-2022-21214",7.8,High,"CWE-824, CWE-125, CWE-121, CWE-122",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2010,3/31/2022,5/31/2022,2022,ICSA-22-090-04,Mitsubishi Electric FA Products (Update A),Mitsubishi Electric,FA products,"The following FA CPU module products are affected: MELSEC iQ-F Series FX5U(C) CPU modules, All models: All versions MELSEC iQ-F Series FX5UJ CPU modules, All models: All versions --------- Begin Update A Part 1 of 2 --------- MELSEC iQ-R series: All Versions of the following: R00/01/02CPU: R04/08/16/32/120(EN)CPU R08/16/32/120SFCPU R08/16/32/120PCPU R08/16/32/120PSFCPU R16/32/64MTCPU RJ71GN11-T2 RJ71GN11-EIP RJ71C24(-R2/R4) RJ71EN71 RJ71GF11-T2 RJ71GP21(S)-SX RJ72GF15-T2 MELSEC Q series: All Versions of the following: Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU Q03/04/06/13/26UDVCPU Q04/06/13/26UDPVCPU QJ71C24N(-R2/R4) QJ71E71-100 QJ72BR15 QJ72LP25(-25/G/GE) MELSEC L series: All Versions of the following: L02/06/26CPU(-P), L26CPU-(P)BT LJ71C24(-R2) LJ71E71-100 LJ72GF15-T2 --------- End Update A Part 1 of 2 ---------","CVE-2022-25155, CVE-2022-25156, CVE-2022-25157, CVE-2022-25158, CVE-2022-25159, CVE-2022-25160",7.4,High,"CWE-836, CWE-328, CWE-312, CWE-294",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2009,3/31/2022,3/31/2022,2022,ICSA-22-090-05,Rockwell Automation Logix Controllers,Rockwell Automation,Logix Controllers,Rockwell Automation reports the vulnerability affects the following products: 1768 CompactLogix controllers; 1769 CompactLogix controllers; CompactLogix 5370 controllers; CompactLogix 5380 controllers; CompactLogix 5480 controllers; Compact GuardLogix 5370 controllers; Compact GuardLogix 5380 controllers; ControlLogix 5550 controllers; ControlLogix 5560 controllers; ControlLogix 5570 controllers; ControlLogix 5580 controllers; GuardLogix 5560 controllers; GuardLogix 5570 controllers; GuardLogix 5580 controllers; FlexLogix 1794-L34 controllers; DriveLogix 5730 controllers; SoftLogix 5800 controllers.,CVE-2022-1161,10.0,Critical,CWE-829,Multiple Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2008,3/31/2022,3/31/2022,2022,ICSA-22-090-06,General Electric Renewable Energy MDS Radios,General Electric Renewable Energy,MDS iNET/iNET II/SD/TD220/TD220MAX Radios,General Electric reports these vulnerabilities affect the following radios: iNET/iNET II series radio firmware versions prior to rev. 8.3.0; SD series radio firmware versions prior to rev. 6.4.7; TD220X series radio firmware versions prior to rev. 2.0.16; TD220MAX series radio firmware versions prior to rev. 1.2.6.,"CVE-2017-17562, CVE-2022-24119, CVE-2022-24116, CVE-2022-24118, CVE-2022-24120, CVE-2022-24117",10.0,Critical,"CWE-20, CWE-912, CWE-326, CWE-400, CWE-256, CWE-494",Communications; Critical Manufacturing; Energy; Healthcare and Public Health; Transportation Systems; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2007,3/31/2022,3/31/2022,2022,ICSA-22-090-07,Rockwell Automation Studio 5000 Logix Designer,Rockwell Automation,Studio 5000 Logix Designer,"Rockwell Automation reports this vulnerability affects the following Studio 5000 Logix Designer design, configuration hardware, and software products: ControlLogix 5580 controllers; GuardLogix 5580 controllers; CompactLogix 5380 controllers; CompactLogix 5480 controllers Compact GuardLogix 5380 controllers.",CVE-2022-1159,7.7,High,CWE-94,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2006,3/29/2022,3/29/2022,2022,ICSMA-22-088-01,Philips e-Alert,Philips,e-Alert,"The following versions of e-Alert, an MRI system monitoring platform, are affected: e-Alert Version 2.7 and prior.",CVE-2022-0922,6.5,Medium,CWE-306,Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2005,3/29/2022,7/21/2022,2022,ICSA-22-088-01,Rockwell Automation ISaGRAF Update A,Rockwell Automation,ISaGRAF,The following Rockwell Automation software products are affected: Connected Component Workbench: v12.00 and prior --------- Begin Update A Part 1 of 2 --------- ISaGRAF Workbench: All versions prior to v6.6.10 --------- End Update A Part 1 of 2 --------- ISaGRAF Workbench: v6.6.9 and prior Safety Instrumented Systems Workstation: v1.1 and prior.,CVE-2022-1018,5.5,Medium,CWE-611,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2004,3/29/2022,3/29/2022,2022,ICSA-22-088-02,Omron CX-Position,Omron,CX-Position,"The following versions of CX-Position, a position control software, are affected: CX-Position Versions 2.5.3 and prior.","CVE-2022-26419, CVE-2022-25959, CVE-2022-26417, CVE-2022-26022",7.8,High,"CWE-121, CWE-119, CWE-416, CWE-787",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2003,3/29/2022,3/29/2022,2022,ICSA-22-088-03,Hitachi Energy LinkOne WebView,Hitachi Energy,LinkOne WebView,"The following versions of LinkOne WebView, an enterprise graphical parts catalog, are affected: LinkOne WebView v3.20; LinkOne WebView v3.22; LinkOne WebView v3.23; LinkOne; WebView v3.24; LinkOne WebView v3.25; LinkOne WebView v3.26.","CVE-2021-40337, CVE-2021-40338, CVE-2021-40339, CVE-2021-40340",4.2,Medium,"CWE-79, CWE-309, CWE-16, CWE-200",Multiple Critical Sectors,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2002,3/29/2022,3/29/2022,2022,ICSA-22-088-04,Modbus Tools Modbus Slave,Modbus Tools,Modbus Slave,"The following versions of Modbus Slave, a PLC programming simulation tool, are affected: Modbus Slave Versions 7.4.2 and prior.",CVE-2022-1068,5.5,Medium,CWE-121,Multiple Critical Sectors,Worldwide,Denmark,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2001,3/24/2022,3/24/2022,2022,ICSA-22-083-01,Yokogawa CENTUM and Exaopc,Yokogawa,CENTUM and Exaopc,"Yokogawa reports these vulnerabilities affect the following distributed control system and software products: CENTUM CS 3000 (Including CENTUM CS 3000 Entry Class): R3.08.10 - R3.09.00 CENTUM VP (Including CENTUM VP Entry Class): R4.01.00 - R4.03.00 R5.01.00 - R5.04.20 R6.01.00 - R6.08.00 Exaopc: (R3.72.00 - R3.79.00) Yokogawa reports the following products are not directly affected by the vulnerabilities, but may be indirectly affected by the existence of CENTUM installed on the same PC:B/M9000CS: (R5.04.01 - R5.05.01) B/M9000 VP: (R6.01.01 - R8.03.01) Usage of the CAMS function may determine whether an installation is affected. Please see Yokogawa's full report (YSAR-22-0001) for details.","CVE-2022-21194, CVE-2022-23402, CVE-2022-21808, CVE-2022-22729, CVE-2022-22151, CVE-2022-21177, CVE-2022-22145, CVE-2022-22148, CVE-2022-22141, CVE-2022-23401",8.6,High,"CWE-798, CWE-23, CWE-117, CWE-78, CWE-264, CWE-427",Critical Manufacturing; Energy; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2000,3/24/2022,3/24/2022,2022,ICSA-22-083-02,mySCADA myPRO,mySCADA Technologies,myPRO,mySCADA reports this vulnerability affects the following myPRO HMI /SCADA products: myPRO Versions 8.25.0 and prior.,CVE-2022-0999,8.8,High,CWE-77,"Energy, Food and Agriculture, Transportation Systems, Water and Wastewater Systems",Worldwide,Czech Republic,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1999,3/22/2022,8/2/2022,2022,ICSA-22-081-01,Delta Electronics DIAEnergie (Update C),Delta Electronics,DIAEnergie,"The following versions of DIAEnergie, an industrial energy management, are affected: --------- Begin Update C Part 1 of 2 --------- DIAEnergie: All versions prior to 1.9 --------- End Update C Part 1 of 2 ---------.","CVE-2022-25347, CVE-2022-26839, CVE-2022-25980, CVE-2022-26069, CVE-2022-27175, CVE-2022-26338, CVE-2022-26059, CVE-2022-26065, CVE-2022-26013, CVE-2022-26836, CVE-2022-0923, CVE-2022-26666, CVE-2022-26887, CVE-2022-25880, CVE-2022-26514, CVE-2022-1366, CVE-2022-1367, CVE-2022-1378, CVE-2022-1377, CVE-2022-1376, CVE-2022-1375, CVE-2022-1374, CVE-2022-1372, CVE-2022-1371, CVE-2022-1370, CVE-2022-1369",9.8,Critical,"CWE-37, CWE-276, CWE-89",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1998,3/15/2022,3/15/2022,2022,ICSA-22-074-01,ABB OPC Server for AC 800M,ABB,OPC Server for AC 800M,"The following versions of OPC Server, a run-time data reader, are affected: 800xA, Control Software for AC 800M: OPC Server for AC 800M: Versions 5.1.0-x, 5.1.1-x, 6.0.0-1 to 6.0.0-3 Control Builder Safe, 1.x and 2.0 including: OPC Server for AC 800M: Versions 5.1.1-1 and 6.0.0-1 Compact Product Suite - Control and I/O: OPC Server for AC 800M: Versions 5.1.0-x, 5.1.1-x, 6.0.0-x.",CVE-2021-22284,8.4,High,CWE-250,Multiple Critical Sectors,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1997,3/8/2022,3/31/2022,2022,ICSA-22-067-01,PTC Axeda agent and Axeda Desktop Server (Update C),PTC,"Axeda agent, Axeda Desktop Server","The following versions of Axeda agent and Axeda Desktop Server, a remote asset connectivity software used as part of a cloud based IoT platform, are affected: Axeda agent: All versions Axeda Desktop Server for Windows: All versions. See the following links for more information on products that may be dependent on the affected Axeda agent and Axeda Desktop Server: Accuray: accuray.com/services/customer-resources Agilent: community.agilent.com/resources/b/support-announcements/posts/remote-advisor-security-notification BD: cybersecurity.bd.com/bulletins-and-patches/third-party-vulnerability-axeda-software-products Bayer: radiologysolutions.bayer.com/information-technology-advisory Beckman Coulter: beckmancoulter.com/en/about-beckman-coulter/product-security Elekta: community.elekta.com (Login Required) General Electric: gehealthcare.com/security Update C: Hologic: https://www.hologic.com/support/usa/breast-skeletal-products-cybersecurity Roche Diagnostics: diagnostics.roche.com/global/en/legal/product-security-advisory.html Smiths Medical: smiths-medical.com/en-us/company-information/smiths-medical-cyber-security-updates Varian: varian.com/resources-support/cybersecurity-varian","CVE-2022-25246, CVE-2022-25247, CVE-2022-25248, CVE-2022-25249, CVE-2022-25250, CVE-2022-25251, CVE-2022-25252",9.8,Critical,"CWE-798, CWE-306, CWE-200, CWE-22, CWE-703",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1996,3/10/2022,12/15/2022,2022,ICSA-22-069-01,Siemens RUGGEDCOM Devices (Update D),Siemens,RUGGEDCOM Devices,The following versions of RUGGEDCOM communication equipment are affected: RUGGEDCOM ROS i800 V4.X: All Versions RUGGEDCOM ROS i801 V4.X: All Versions RUGGEDCOM ROS i802 V4.X: All Versions RUGGEDCOM ROS i803 V4.X: All Versions RUGGEDCOM ROS RMC30 V4.X: All Versions RUGGEDCOM ROS RMC8388 V4.X: All Versions RUGGEDCOM ROS RP110 V4.X: All Versions RUGGEDCOM ROS RS1600 V4.X: All Versions RUGGEDCOM ROS RS1600F V4.X: All Versions RUGGEDCOM ROS RS1600T V4.X: All Versions RUGGEDCOM ROS RS400 V4.X: All Versions RUGGEDCOM ROS RS401 V4.X: All Versions RUGGEDCOM ROS RS416Pv2 V4.X: All Versions RUGGEDCOM ROS RS416v2 V4.X: All Versions RUGGEDCOM ROS RS8000 V4.X: All Versions RUGGEDCOM ROS RS8000A V4.X: All Versions RUGGEDCOM ROS RS8000H V4.X: All Versions RUGGEDCOM ROS RS8000T V4.X: All Versions RUGGEDCOM ROS RS900 (32M) V4.X: All Versions RUGGEDCOM ROS RS900 V4.X: All Versions RUGGEDCOM ROS RS900G (32M) V4.X: All Versions RUGGEDCOM ROS RS900G V4.X: All Versions RUGGEDCOM ROS RS900GP V4.X: All Versions RUGGEDCOM ROS RS900L V4.X: All Versions RUGGEDCOM ROS RS900M V4.X: All Versions RUGGEDCOM ROS RS900W V4.X: All Versions RUGGEDCOM ROS RS910 V4.X: All Versions RUGGEDCOM ROS RS910L V4.X: All Versions RUGGEDCOM ROS RS910W V4.X: All Versions RUGGEDCOM ROS RS920L V4.X: All Versions RUGGEDCOM ROS RS920W V4.X: All Versions RUGGEDCOM ROS RS930L V4.X: All Versions RUGGEDCOM ROS RS930W V4.X: All Versions RUGGEDCOM ROS RS940G V4.X: All Versions RUGGEDCOM ROS RSG2100 (32M) V4.X: All Versions RUGGEDCOM ROS RSG2100 V4.X: All Versions RUGGEDCOM ROS RSG2100P V4.X: All Versions RUGGEDCOM ROS RSG2200 V4.X: All Versions RUGGEDCOM ROS RSG2288 V4.X: All Versions RUGGEDCOM ROS RSG2300 V4.X: All Versions RUGGEDCOM ROS RSG2300P V4.X: All Versions RUGGEDCOM ROS RSG2488 V4.X: All Versions --------- Begin Update D Part 1 of 2--------- RUGGEDCOM ROS RMC8388 V5.X: All Versions prior to v5.7.0 RUGGEDCOM ROS RS416Pv2 V5.X: All Versions prior to v5.7.0 RUGGEDCOM ROS RS416v2 V5.X: All Versions prior to v5.7.0 RUGGEDCOM ROS RS900 (32M) V5.X: All Versions prior to v5.7.0 RUGGEDCOM ROS RS900G (32M) V5.X: All Versions prior to v5.7.0 RUGGEDCOM ROS RSG2100 (32M) V5.X: All Versions prior to v5.7.0 RUGGEDCOM ROS RSG2288 V5.X: All Versions prior to v5.7.0 RUGGEDCOM ROS RSG2300P V5.X: All Versions prior to v5.7.0 RUGGEDCOM ROS RSG2300 V5.X: All Versions prior to v5.7.0 RUGGEDCOM ROS RSG2488 V5.X: All Versions prior to v5.7.0 RUGGEDCOM ROS RSG907R V5.X: All Versions prior to v5.7.0 RUGGEDCOM ROS RSG908C V5.X: All Versions prior to v5.7.0 RUGGEDCOM ROS RSG909R V5.X: All Versions prior to v5.7.0 RUGGEDCOM ROS RSG910C V5.X: All Versions prior to v5.7.0 RUGGEDCOM ROS RSG920P V4.X: All Versions prior to v5.7.0 RUGGEDCOM ROS RSG920P V5.X: All Versions prior to v5.7.0 RUGGEDCOM ROS RSL910 V5.X: All Versions prior to v5.7.0 RUGGEDCOM ROS RST2228 V5.X: All Versions prior to v5.7.0 RUGGEDCOM ROS RST2228P V5.X: All Versions prior to v5.7.0 RUGGEDCOM ROS RST916C V5.X: All Versions prior to v5.7.0 RUGGEDCOM ROS RST916P V5.X: All Versions prior to v5.7.0 --------- End Update D Part 1 of 2---------.,CVE-2021-37209,6.7,Medium,CWE-326,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1995,3/10/2022,3/10/2022,2022,ICSA-22-069-02,Siemens SIMOTICS CONNECT 400,Siemens,SIMOTICS CONNECT 400,"The following versions of SIMOTICS CONNECT 400, a connectivity module, are affected: SIMOTICS CONNECT 400: All versions prior to v0.5.0.0; SIMOTICS CONNECT 400: All versions prior to v1.0.0.0; only affected by CVE-2021-31344, CVE-2021-31346, CVE-2021-31890.","CVE-2021-31344, CVE-2021-31346, CVE-2021-31889, CVE-2021-31890",8.2,High,"CWE-843, CWE-1284, CWE-191, CWE-240",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1994,3/10/2022,3/10/2022,2022,ICSA-22-069-03,Siemens SINEC NMS,Siemens,SINEC NMS,"The following versions of Siemens SINEC NMS, a network management system, are affected: SINEC NMS: All versions.","CVE-2022-24281, CVE-2022-24282, CVE-2022-25311",7.3,High,"CWE-89, CWE-502, CWE-269",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1993,3/10/2022,3/10/2022,2022,ICSA-22-069-04,Siemens SINEMA Mendix Forgot Password Appstore,Siemens,Mendix Forgot Password Appstore module,"The following versions of Mendix Forgot Password Appstore, a password management module, are affected: Mendix Forgot Password Appstore module: All versions after v3.3.0 and prior to v3.5.1; Mendix Forgot Password Appstore module (Mendix 7 compatible): All versions prior to v3.2.2 (only affected by CVE-2022-26314).","CVE-2022-26313, CVE-2022-26314",9.1,Critical,"CWE-284, CWE-307",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1992,3/10/2022,3/10/2022,2022,ICSA-22-069-05,Siemens Simcenter STAR-CCM+ Viewer,Siemens,Simcenter STAR-CCM+ Viewer,"The following versions of Simcenter STAR-CCM+ Viewer, a computational fluid dynamics software, are affected: Simcenter STAR-CCM+ Viewer: All versions prior to 2022.1.",CVE-2022-24661,7.8,High,CWE-119,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1991,3/10/2022,3/10/2022,2022,ICSA-22-069-06,Siemens COMOS,Siemens,COMOS,"The following versions of Siemens COMOS, a unified platform for collaborative plan design, are affected: Siemens COMOS: All versions prior to v10.4.1.","CVE-2021-25173, CVE-2021-25174, CVE-2021-25175, CVE-2021-25176, CVE-2021-25177, CVE-2021-25178, CVE-2021-31784, CVE-2021-32936, CVE-2021-32938, CVE-2021-32940, CVE-2021-32944, CVE-2021-32946, CVE-2021-32948, CVE-2021-32950, CVE-2021-32952",7.8,High,"CWE-789, CWE-822, CWE-843, CWE-121, CWE-787, CWE-125, CWE-416, CWE-754, CWE-787",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1990,3/10/2022,3/10/2022,2022,ICSA-22-069-07,Siemens Climatix POL909,Siemens,Climatix POL909 (AWB and AWM modules),"The following versions of Climatix POL909 (AWM and AWB modules), advanced web modules, are affected: Climatix POL909 (AWM module): All versions prior to v11.34; Climatix POL909 (AWB module): All versions prior to v11.34.","CVE-2021-41541, CVE-2021-41542, CVE-2021-41543",6.5,Medium,"CWE-79, CWE-284",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1989,3/10/2022,3/10/2022,2022,ICSA-22-069-08,Siemens Polarion ALM,Siemens,Polarion ALM,Siemens reports this vulnerability affects the following Polarion Subversion Webclient: Polarion Subversion Webclient: v21 R1.,CVE-2021-44478,6.5,Medium,CWE-79,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1988,3/10/2022,3/10/2022,2022,ICSA-22-069-09,Siemens SINEC INS,Siemens,SINEC INS,Siemens reports this vulnerability affects the following SINEC INS (Infrastructure Network Services) web-based application: SINEC INS: All versions prior to v1.0.1.1.,"CVE-2019-19242, CVE-2019-19244, CVE-2019-19317, CVE-2019-19603, CVE-2019-19645, CVE-2019-19646, CVE-2019-19880, CVE-2019-19923, CVE-2019-19924, CVE-2019-19925, CVE-2019-19926, CVE-2020-1971, CVE-2020-7774, CVE-2020-8169, CVE-2020-8177, CVE-2020-8231, CVE-2020-8265, CVE-2020-8284, CVE-2020-8285, CVE-2020-8286, CVE-2020-8287, CVE-2020-8625, CVE-2020-9327, CVE-2020-11655, CVE-2020-11656, CVE-2020-13630, CVE-2020-13631, CVE-2020-13632, CVE-2020-13871, CVE-2020-15358, CVE-2020-27304, CVE-2021-3449, CVE-2021-3450, CVE-2021-3672, CVE-2021-3711, CVE-2021-3712, CVE-2021-22876, CVE-2021-22883, CVE-2021-22884, CVE-2021-22890, CVE-2021-22897, CVE-2021-22898, CVE-2021-22901, CVE-2021-22918, CVE-2021-22921, CVE-2021-22922, CVE-2021-22923, CVE-2021-22924, CVE-2021-22925, CVE-2021-22926, CVE-2021-22930, CVE-2021-22931, CVE-2021-22939, CVE-2021-22940, CVE-2021-22945, CVE-2021-22946, CVE-2021-22947, CVE-2021-23362, CVE-2021-23840, CVE-2021-25214, CVE-2021-25215, CVE-2021-25216, CVE-2021-25219, CVE-2021-27290, CVE-2021-32803, CVE-2021-32804, CVE-2021-37701, CVE-2021-37712, CVE-2021-37713, CVE-2021-39134, CVE-2021-39135.",9.8,Critical,CWE-1035,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1987,3/10/2022,3/10/2022,2022,ICSA-22-069-10,Siemens Simcenter Femap,Siemens,Simcenter Femap,Siemens reports these vulnerabilities affect the following Simcenter Femap simulation applications: Simcenter Femap: All versions prior to v2022.1.,"CVE-2021-46162, CVE-2021-46699",7.8,High,"CWE-787, CWE-121",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1986,3/10/2022,3/10/2022,2022,ICSA-22-069-11,Siemens SINUMERIK MC,Siemens,SINUMERIK MC,Siemens reports this vulnerability affects the following versions of the SINUMERIK MC CNC system control system for customized machines: SINUMERIK MC: All versions prior to v1.15 SP1; SINUMERIK ONE: All versions prior to v6.15 SP1,CVE-2022-24408,7.8,High,CWE-269,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1985,3/10/2022,3/10/2022,2022,ICSA-22-069-12,Siemens RUGGEDCOM ROS,Siemens,RUGGEDCOM ROS,Siemens reports this vulnerability affects the following RUGGEDCOM ROS-based devices: RUGGEDCOM ROS M2100: All versions prior to v5.6.0; RUGGEDCOM ROS RMC8388 devices: All versions prior to v5.6.0; RUGGEDCOM ROS RS416v2: All versions prior to v5.6.0; RUGGEDCOM ROS RS900G: All versions prior to v5.6.0; RUGGEDCOM ROS RS900G (32M): All versions prior to v5.6.0; RUGGEDCOM ROS RSG900 v5.X: All versions prior to v5.6.0; RUGGEDCOM ROS RSG920P v5.X: All versions prior to v5.6.0; RUGGEDCOM ROS RSG2100 (32M) v5.X: All versions prior to v5.6.0; RUGGEDCOM ROS RSG2100P: All versions prior to v5.6.0; RUGGEDCOM ROS RSG2100P (32M) v5.X: All versions prior to v5.6.0; RUGGEDCOM ROS RSG2288 v5.X: All versions prior to v5.6.0; RUGGEDCOM ROS RSG2300 v5.X: All versions prior to v5.6.0; RUGGEDCOM ROS RSG2300P v5.X: All versions prior to v5.6.0; RUGGEDCOM ROS RSG2488 v5.X: All versions prior to v5.6.0; RUGGEDCOM ROS RSL910: All versions prior to v5.6.0; RUGGEDCOM ROS RST916C: All versions prior to v5.6.0; RUGGEDCOM ROS RST916P: All versions prior to v5.6.0; RUGGEDCOM ROS RST2228: All versions prior to v5.6.0.,"CVE-2021-37208, CVE-2021-42016, CVE-2021-42017, CVE-2021-42018, CVE-2021-42019, CVE-2021-42020",7.5,High,CWE-1035,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1984,3/10/2022,3/10/2022,2022,ICSA-22-069-13,Siemens Mendix,Siemens,Mendix,"The following versions of Mendix, an application development platform, are affected: Mendix Applications using Mendix 7: All versions prior to v7.23.29; Mendix Applications using Mendix 8: All versions prior to v8.18.16; Mendix Applications using Mendix 9: All versions.",CVE-2022-24309,5.9,Medium,CWE-284,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1983,3/8/2022,3/31/2022,2022,ICSA-22-067-01,PTC Axeda agent and Axeda Desktop Server (Update A),PTC,Axeda agent; Axeda Desktop Server,"The following versions of Axeda agent and Axeda Desktop Server, a remote asset connectivity software used as part of a cloud based IoT platform, are affected: Axeda agent: All versions; Axeda Desktop Server for Windows: All versions. Update A: See the following links for more information on products that may be dependent on the affected Axeda agent and Axeda Desktop Server: Accuray: accuray.com/services/customer-resources Agilent: community.agilent.com/resources/b/support-announcements/posts/remote-advisor-security-notification Bayer: radiologysolutions.bayer.com/information-technology-advisory BD: cybersecurity.bd.com/bulletins-and-patches/third-party-vulnerability-axeda-software-products Elekta: community.elekta.com (Login Required) General Electric: gehealthcare.com/security Roche Diagnostics: diagnostics.roche.com/global/en/legal/product-security-advisory.html Smiths Medical: smiths-medical.com/en-us/company-information/smiths-medical-cyber-security-updates Varian: varian.com/resources-support/cybersecurity-varian","CVE-2022-25246, CVE-2022-25247, CVE-2022-25248, CVE-2022-25249, CVE-2022-25250, CVE-2022-25251, CVE-2022-25252",9.8,Critical,"CWE-798, CWE-306, CWE-200, CWE-22, CWE-703",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1982,3/8/2022,3/8/2022,2022,ICSA-22-067-02,AVEVA System Platform,AVEVA,System Platform,"The following versions of AVEVA System Platform, a software management platform, are affected: AVEVA System Platform 2020 R2 P01; AVEVA System Platform 2020 R2S; AVEVA System Platform 2020.",CVE-2022-0835,8.1,High,CWE-316,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1981,2/3/2022,3/8/2022,2022,ICSA-22-034-01,Sensormatic PowerManage (Update A),Sensormatic Electronics LLC (Subsidiary of Johnson Controls),PowerManage,"The following versions of Sensormatic Electronics, LLC PowerManage, an operating platform, are affected: PowerManage Versions 4.0 to 4.8.",CVE-2021-44228,10.0,Critical,CWE-20,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1980,3/4/2022,3/4/2022,2022,ICSA-22-063-01,Trailer Power Line Communications (PLC) J2497,Not Applicable,Power Line Communications (PLC): J2497 (a.k.a. PLC4TRUCKS),"Power Line Communications (PLC): J2497 (a.k.a. PLC4TRUCKS), a bidirectional, serial communications link over the vehicle power supply line, is affected.","CVE-2022-25922, CVE-2022-26131",9.3,Critical,"CWE-306, CWE-1319",Transportation Systems,"United States, Canada, Mexico",Not Applicable,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1979,3/3/2022,3/3/2022,2022,ICSMA-22-062-01,BD Pyxis,"Becton, Dickinson and Company (BD)",Pyxis,"The following BD Pyxis products, an automated medication dispensing system, are affected: BD Pyxis Anesthesia Station ES; BD Pyxis Anesthesia Station 4000; BD Pyxis CATO; BD Pyxis CIISafe; BD Pyxis Inventory Connect; BD Pyxis IV Prep; BD Pyxis JITrBUD; BD Pyxis KanBan RF; BD Pyxis Logistics; BD Pyxis Med Link Family; BD Pyxis MedBank; BD Pyxis MedStation 4000; BD Pyxis MedStation ES; BD Pyxis MedStation ES Server; BD Pyxis ParAssist; BD Pyxis PharmoPack; BD Pyxis ProcedureStation (including EC); BD Pyxis Rapid Rx; BD Pyxis StockStation; BD Pyxis SupplyCenter; BD Pyxis SupplyRoller; BD Pyxis SupplyStation (including RF, EC, CP); BD Pyxis Track and Deliver; BD Rowa Pouch Packaging Systems.",CVE-2022-22766,7.0,High,CWE-798,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1978,3/3/2022,3/3/2022,2022,ICSMA-22-062-02,BD Viper LT,"Becton, Dickinson and Company (BD)",Viper LT,"The following versions of BD Viper LT, an automated molecular testing system, are affected: BD Viper LT system: All Versions 2.0 and later.",CVE-2022-22765,8.0,High,CWE-798,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1977,3/3/2022,3/3/2022,2022,ICSA-22-062-01,IPCOMM ipDIO,IPCOMM,ipDIO,"The following versions of IPCOMM ipDIO, a telecontrol communication device, are affected: Firmware Version 3.9 2016/04/18 / IPDIO SW 3.9.","CVE-2022-24432, CVE-2022-21146, CVE-2022-24915, CVE-2022-22985",8.8,High,"CWE-79, CWE-94",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1976,2/24/2022,2/24/2022,2022,ICSA-22-055-01,FATEK Automation FvDesigner,FATEK Automation,FvDesigner,"The following versions of FvDesigner, a software tool used to design and develop FATEK FV HMI series product projects, are affected: FvDesigner: Versions 1.5.100 and prior.","CVE-2022-25170, CVE-2022-23985, CVE-2022-21209",7.8,High,"CWE-121, CWE-787, CWE-125",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1975,2/24/2022,2/24/2022,2022,ICSA-22-055-02,Mitsubishi Electric EcoWebServerIII,Mitsubishi Electric,Energy Saving Data Collecting Server (EcoWebServerIII),"Mitsubishi Electric reports these vulnerabilities affect the following versions of EcoWebServerIII, an energy saving data collecting server: MES3-255C-EN: Versions 3.0.0 to 3.3.0, MES3-255C-DM-EN: Versions 3.0.0 to 3.3.0, MES3-255C-CN: Versions 3.0.0 to 3.3.0, MES3-255C-DM-CN: Versions 3.0.0 to 3.3.0.","CVE-2016-10735, CVE-2018-14040, CVE-2018-14042, CVE-2018-20676, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, CVE-2017-18214, CVE-2020-7746",7.5,High,"CWE-79, CWE-400, CWE-915",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1974,2/24/2022,7/12/2022,2022,ICSA-22-055-03,Schneider Electric Easergy P5 and P3 (Update A),Schneider Electric,Easergy P5 and P3,"The following versions of Easergy P5, a medium voltage protection relay, are affected: --------- Begin Update A Part 2 of 4 --------- All firmware versions prior to v01.401.102 --------- End Update A Part 2 of 4 --------- The following versions of Easergy P3, a medium voltage protection relay, are affected: All versions prior to v30.205.","CVE-2022-22722, CVE-2022-22723, CVE-2022-22725, CVE-2022-34758",8.8,High,"CWE-798, CWE-120, CWE-20",Commercial Facilities; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1973,8/19/2021,8/19/2021,2021,ICSA-21-231-02,Baker Hughes Bently Nevada 3500,Bently Nevada (Subsidiary of Baker Hughes),3500,"The following software versions are affected: System 1 6.x, Part No. 3060/00, Versions 6.98 and prior, Released Dec 2020; System 1, Part No. 3071/xx & 3072/xx, Versions 21.1 HF1 and prior, Released July 2021; 3500 Rack Configuration, Part No. 129133-01, Versions 6.4 and prior, Released May 2020; 3500/22M Firmware, Part No. 288055-01, Versions 5.05 and prior, Released May 2021.",CVE-2021-32997,8.2,High,CWE-916,Critical Manufacturing; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1972,2/22/2022,2/22/2022,2022,ICSA-22-053-01,GE Proficy CIMPLICITY-IPM,GE,Proficy CIMPLICITY,"The following versions of Proficy CIMPLICITY, an HMI and SCADA platform, are affected: Proficy CIMPLICITIY v11.1 and prior versions.",CVE-2022-23921,7.5,High,CWE-269,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1971,2/22/2022,2/22/2022,2022,ICSA-22-053-02,GE Proficy CIMPLICITY-Cleartext,GE,Proficy CIMPLICITY,"The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which can be easily spoofed and used to log in to make operational changes to the system.",CVE-2022-21798,7.5,High,CWE-319,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1970,2/22/2022,2/22/2022,2022,ICSA-22-053-03,WIN-911 2021,WIN-911,WIN-911 2021,"The following versions of WIN-911, an alarm notification platform, are affected: WIN-911 2021 R1 - 5.21.10; WIN-911 2021 R2 - 5.21.17.","CVE-2022-23922, CVE-2022-23104",5.6,Medium,"CWE-276, CWE-276",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1969,2/15/2022,2/15/2022,2022,ICSA-22-046-01,Schneider Electric IGSS,Schneider Electric,IGSS (Interactive Graphical SCADA System),Schneider Electric reports these vulnerabilities affect the following IGSS Data Server module: IGSS Data Server (IGSSdataServer.exe): v15.0.0.22020 and prior.,"CVE-2022-24310, CVE-2022-24311, CVE-2022-24312, CVE-2022-24313, CVE-2022-24314, CVE-2022-24315, CVE-2022-24316, CVE-2022-24317",9.8,Critical,"CWE-190, CWE-22, CWE-120, CWE-125, CWE-665, CWE-862",Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1968,2/10/2022,7/14/2022,2022,ICSA-22-041-01,Siemens SIMATIC Industrial Products (Update B),Siemens,Siemens SIMATIC Industrial Products,"The following versions of Siemens Industrial Products with SIMATIC Firmware, a software platform, are affected: SIMATIC Drive Controller family: All versions prior to v2.9.4 SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions ------- Begin Update B Part 1 of 3 ------- SIMATIC ET 200SP Open Controller CPU 1515SP PC2 Ready4Linux: All versions SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants): All versions ------- End Update B Part 1 of 3 ------- SIMATIC S7-1200 CPU family (incl. SIPLUS variants): Version 4.5.0 and all following versions prior to v4.5.2 SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants): Version 2.9.2 and all following versions prior to v2.9.4 SIMATIC S7-1500 Software Controller: All versions SIMATIC S7-PLCSIM Advanced: All versions v4.0 SP1 TIM 1531 IRC (incl. SIPLUS NET variants): Version 2.2 and all following versions.",CVE-2021-37185,7.5,High,CWE-601,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1967,2/10/2022,8/11/2022,2022,ICSA-22-041-02,Siemens SIMATIC WinCC and PCS (Update C),Siemens,SIMATIC WinCC and PCS,"Siemens reports these vulnerabilities affect the following SIMATIC products: SIMATIC PCS 7 v9.1: All versions prior to v9.1 SP1 SIMATIC PCS 7 v8.2: All versions prior to v7.4 SP1 Update 19 SIMATIC PCS 7 v9.0: All versions prior to v9.0 SP3 UpdateCollection4 SIMATIC WinCC v7.4: All versions prior to v7.4 SP1 Update 19 SIMATIC WinCC v7.5: All versions prior to v7.5 Update 6 SIMATIC WinCC v15 and earlier: All versions prior to v15 SP1 Update 7 SIMATIC WinCC v16: All versions prior to v16 Update 5 SIMATIC WinCC v17: All versions prior to v17 Update 2 --------- Begin Update C Part 1 of 2 --------- SIMATIC WinCC v17: All versions after and including v17 Update 2, but prior to v17 Update 4 are only affected by CVE-2021-40363 --------- End Update C Part 1 of 2 ---------.","CVE-2021-40360, CVE-2021-40363",6.3,Medium,"CWE-200, CWE-538",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1966,2/10/2022,2/10/2022,2022,ICSA-22-041-03,Siemens Simcenter Femap,Siemens,Simcenter Femap,"The following versions of Simcenter Femap, an advanced simulation application, are affected: Simcenter Femap v2020.2: All versions Simcenter Femap v2021.1: All versions.","CVE-2021-46151, CVE-2021-46152, CVE-2021-46153, CVE-2021-46154, CVE-2021-46155, CVE-2021-46156, CVE-2021-46157, CVE-2021-46158, CVE-2021-46159, CVE-2021-46160, CVE-2021-46161",7.8,High,"CWE-119, CWE-121, CWE-787, CWE-843",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1965,2/10/2022,2/10/2022,2022,ICSA-22-041-04,SINEMA Remote Connect Server,Siemens,SINEMA Remote Connect Server,"The following versions of SINEMA Remote Server, a management platform for remote networks, are affected: SINEMA Remote Connect Server: All versions prior to v2.0.",CVE-2022-23102,5.4,Medium,CWE-601,Multiple Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1964,2/10/2022,3/10/2022,2022,ICSA-22-041-05,Siemens SICAM TOOLBOX II (Update A),Siemens,SICAM TOOLBOX II,"The following versions of SICAM TOOLBOX II, a software platform, are affected: SICAM TOOLBOX II: All versions.",CVE-2021-45106,9.9,Critical,CWE-798,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1963,2/10/2022,2/10/2022,2022,ICSA-22-041-06,Siemens Spectrum Power 4,Siemens,SINEMA Spectrum Power 4,The following versions of Siemens Spectrum Power 4 communications and data modeling software are affected: Siemens Spectrum Power 4: All versions prior to v4.70 SP9 Security Patch 1.,CVE-2022-23312,5.4,Medium,CWE-79,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1962,1/13/2022,4/14/2022,2022,ICSA-22-013-05,Siemens COMOS Web (Update B),Siemens,COMOS,"The following versions of COMOS Web, a unified data platform, are affected: COMOS v10.2: All versions (only if web components are used) Update B COMOS v10.3: All versions prior to v10.3.3.3 (only if web components are used) COMOS v10.3: All versions prior to v10.3.3.3 (only if web components are used) (only affected by CVE-2021-37196) End of Update B COMOS v10.4: All versions prior to v10.4.1 (only if web components are used).","CVE-2021-37194, CVE-2021-37195, CVE-2021-37196, CVE-2021-37197, CVE-2021-37198",8.8,High,"CWE-23, CWE-352, CWE-434, CWE-80, CWE-89",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1961,12/16/2021,2/10/2022,2021,ICSA-21-350-16,Siemens Healthineers syngo fastView (Update A),Siemens Healthineers (Subsidiary of Siemens),syngo fastView,"The following versions of syngo fastView, a software for digital imaging and communications, are affected: Syngo fastView: All versions.","CVE-2021-40367, CVE-2021-42028, CVE-2021-45465",7.8,High,"CWE-123, CWE-787",Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1960,11/11/2021,7/14/2022,2022,ICSA-21-315-03,Siemens SIMATIC WinCC (Update E),Siemens,SIMATIC WinCC,Siemens reports these vulnerabilities affects the following SIMATIC SCADA HMI system products: OpenPCSPCS 7 v8.2: All versions OpenPCS PCS 7 v9.0: All versions prior to v9.0 Upd4 OpenPCS PCS 7 v9.1: All versions SIMATIC BATCH v8.2: All versions SIMATIC BATCH v9.0: All versions SIMATIC BATCH v9.1: All versions SIMATIC NET PC Software v14: All versions SIMATIC NET PC Software v15: All versions --------- Begin Update E Part 1 of 2 --------- SIMATIC NET PC Software v16: All versions prior to v16 Update 6 --------- End Update E Part 1 of 2 --------- SIMATIC NET PC Software v17: All versions prior to v17 SP1 SIMATIC PCS 7 v8.2: All versions SIMATIC PCS 7 v9.0: All versions SIMATIC PCS 7 V9.1: All versions prior to v9.1 SP1 SIMATIC Route Control v8.2: All versions SIMATIC Route Control v9.0: All versions SIMATIC Route Control v9.1: All versions SIMATIC WinCC v7.4 and earlier: All versions prior to v7.4 SP1 Update 19 SIMATIC WinCC v7.5: All versions prior to v7.5 SP2 Update 5 SIMATIC WinCC v15 and earlier: All versions prior to v15 SP1 Update 7 SIMATIC WinCC v16: All versions prior to v16 Update 5 SIMATIC WinCC v17: All versions prior to v17 Update 2.,"CVE-2021-40358, CVE-2021-40359, CVE-2021-40364",9.9,Critical,"CWE-22, CWE-532",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1959,9/14/2021,9/14/2021,2021,ICSA-21-257-13,Siemens LOGO! CMR and SIMATIC RTU 3000,Siemens,"LOGO! CMR, SIMATIC RTU 3000",The following versions of LOGO! controllers and SIMATIC monitors are affected: LOGO! CMR2020 (6GK7142-7BX00-0AX0): All versions prior to v2.2 LOGO! CMR2040 (6GK7142-7EX00-0AX0): All versions prior to v2.2 SIMATIC RTU 3000 family: All versions SIMATIC RTU3010C (6NH3112-0BA00-0XX0): All versions prior to v4.0.9 SIMATIC RTU3030C (6NH3112-3BA00-0XX0): All versions prior to v4.0.9 SIMATIC RTU3031C (6NH3112-3BB00-0XX0): All versions prior to v4.0.9 SIMATIC RTU3041C (6NH3112-4BB00-0XX0): All versions prior to v4.0.9.,CVE-2021-37186,5.4,Medium,CWE-330,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1958,8/10/2021,12/15/2022,2021,ICSA-21-222-05,Siemens Industrial Products Intel CPUs (Update G),Siemens,"SIMATIC, SINUMERIK","The following Siemens products are affected: SIMATIC Drive Controller Family: All versions SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions SIMATIC Field PG M5: All versions SIMATIC Field PG M6: All versions SIMATIC IPC127E: All versions SIMATIC IPC427E: All versions SIMATIC IPC477E: All versions SIMATIC IPC477E Pro: All versions SIMATIC IPC527GE: All versions SIMATIC IPC547G: All versions SIMATIC IPC627E: All versions SIMATIC IPC647E: All versions SIMATIC IPC677E: All versions SIMATIC IPC847E: All BIOS versions prior to v25.02.10 SIMATIC ITP1000: All versions SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (MLFB: 6ES7518-4AX00-1AC0, 6AG1518-4AX00-4AC0, incl. SIPLUS variant): All versions SIMATIC S7-1500 CPU 1518F-4 PN-DP MFP (MLFB: 6ES7518-4FX00-1AC0): All versions SINUMERIK 828D HW PPU.4: All versions SINUMERIK MC MCU 1720: All versions SINUMERIK ONE / SINUMERIK 840D sl Handheld Terminal HT 10: All versions SINUMERIK ONE PPU 1740: All versions SINUMERIK ONE NCU 1740: All versions prior to v05.00.00.00 SIMATIC IPC127E: All versions prior to v21.01.07 SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions prior to v0209_0105 SIMATIC IPC427E: All versions prior to v21.01.16 SIMATIC IPC477E: All versions prior to v21.01.16 SIMATIC IPC477E Pro: All versions prior to v21.01.16 SIMATIC ITP1000: All versions SIMATIC Field PG M6: All versions SIMATIC IPC347G: All versions prior to v01.04.00 SIMATIC IPC3000 SMART V3: All versions prior to v01.04.00 --------- Begin Update G Part 1 of 2 --------- SINUMERIK 828D HW PPU.4: All versions prior to v08.00.00.00 SINUMERIK MC MCU 1720: All versions prior to v05.00.00.00 SINUMERIK ONE / SINUMERIK 840D sl Handheld Terminal HT 10: All versions prior to v08.00.00.00 SINUMERIK ONE PPU 1740: All versions prior to v06.00.00.00 --------- End Update G Part 1 of 2 ---------.","CVE-2020-12357, CVE-2020-12358, CVE-2020-12360, CVE-2020-24486, CVE-2020-24506, CVE-2020-24507, CVE-2020-24511, CVE-2020-24512, CVE-2020-24513, CVE-2020-8670, CVE-2020-8703, CVE-2020-8704",7.5,High,CWE-311,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1957,3/9/2021,3/9/2021,2021,ICSA-21-068-06,Siemens TCP/IP Stack Vulnerabilities-AMNESIA:33 in SENTRON PAC / 3VA Devices (Update B),Siemens,"SENTRON 3VA COM100/800, SENTRON 3VA DSP800, SENTRON PAC2200, SENTRON PAC3200T, SENTRON PAC3200, SENTRON PAC3220, SENTRON PAC4200",The following products are affected: SENTRON 3VA COM100/800: all versions prior to v4.4.1 SENTRON 3VA DSP800: all versions prior to v4.0 SENTRON PAC2200 (with CLP Approval): all versions; SENTRON PAC2200 (with MID Approval): all versions prior to v3.2.2 SENTRON PAC2200 (without MID Approval): all versions prior to v3.2.2 SENTRON PAC3200: all versions prior to v2.4.7 SENTRON PAC3200T: all versions prior to v3.2.2; SENTRON PAC3220: all versions prior to v3.2.0 SENTRON PAC4200: all versions prior to v2.3.0.,"CVE-2020-13987, CVE-2020-17437",6.5,Medium,"CWE-125, CWE-787",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1956,4/14/2020,4/14/2020,2022,ICSA-20-105-07,Siemens SCALANCE & SIMATIC (Update E),Siemens,"SCALANCE, SIMATIC",The following versions of SCALANCE are affected: SIMATIC CP 442-1 RNA (6GK7442-1RX00-0XE0): All versions SIMATIC CP 443-1 RNA (6GK7443-1RX00- 0XE0): All versions; SCALANCE X-200 switch family (incl. SIPLUS NET variants): versions prior to v5.2.5SCALANCE X-200IRT switch family (incl. SIPLUS NET variants): versions prior to v5.5.0 SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants): all versions The following versions of SIMATIC are affected: SIMATIC CP 443-1 (incl. SIPLUS NET variants): all versions SIMATIC CP 443-1 Advanced (incl. SIPLUS NET variants): all versions SIMATIC RF180C: all versions SIMATIC RF182C: all versions.,CVE-2019-19301,7.5,High,CWE-400,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1955,2/11/2020,2/11/2020,2022,ICSA-20-042-02,Siemens Industrial Products SNMP Vulnerabilities (Update D),Siemens,"Various SCALANCE, SIMATIC, SIPLUS products",The following Siemens products are affected: IE/PB LINK PN IO (including SIPLUS NET variants): All versions prior to v4.0.1 SCALANCE S602: All versions prior to v4.1 SCALANCE S612: All versions prior to v4.1 SCALANCE S623: All versions prior to v4.1 SCALANCE S627-2M: All versions prior to v4.1; SIMATIC CP 343-1 Advanced (6GK7343-1GX31-0XE0):All versions SIMATIC CP 443-1 (6GK7443-1EX30-0XE0): All versions SIMATIC CP 443-1 Advanced (6GK7443-1GX30-0XE0):: All versions SIMATIC CP 443-1 OPC UA (6GK7443-1UX00-0XE0): All versions SIMATIC CP 1623 (6GK1162-3AA00): All versions prior to v14.00.15.00_51.25.00.01 SIMATIC CP 1626 (6GK1162-6AA01): All versions prior to v1.1.1 SIMATIC CP 1628(6GK1162-8AA00): All versions prior to v14.00.15.00_51.25.00.01 SIPLUS NET CP 343-1 Advanced (6AG1343-1GX31-4XE0): All versions SIPLUS NET CP 443-1 (6AG1443-1EX30-4XE0): All versions SIPLUS NET CP 443-1 Advanced (6AG1443-1GX30-4XE0): All versions; TIM 1531 IRC (including SIPLUS NET variants): All versions.,"CVE-2018-18065, CVE-2015-5621",7.5,High,"CWE-19, CWE-476",Chemical; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1954,1/14/2020,6/16/2022,2022,ICSA-20-014-03,Siemens SCALANCE X Switches (Update B),Siemens,SCALANCE X Switches,"The following versions of SCALANCE X Switches, used to connect industrial components, are affected: SCALANCE X-200RNA (HSA): All versions SCALANCE X-200RNA (PRP): All versions SCALANCE X-200RNA EEC (HSR): All versions SCALANCE X-200RNA EEC (PRP): All versions --------- Begin Update B Part 1 of 1 --------- SCALANCE X302-7 EEC: All versions prior to v4.1.3 SCALANCE X304-2FE: All versions prior to v4.1.3 SCALANCE X306-1LD FE: All versions prior to v4.1.3 SCALANCE X307-2 EEC: All versions prior to v4.1.3 SCALANCE X307-2: All versions prior to v4.1.3 SCALANCE X307-3: All versions prior to v4.1.3 SCALANCE X307-3LD: All versions prior to v4.1.3 SCALANCE X308-2: All versions prior to v4.1.3 SCALANCE X308-2LD: All versions prior to v4.1.3 SCALANCE X308-2LH: All versions prior to v4.1.3 SCALANCE X308-2LH+: All versions prior to v4.1.3 SCALANCE X308-2M: All versions prior to v4.1.3 SCALANCE X308-2M TS: All versions prior to v4.1.3 SCALANCE X310: All versions prior to v4.1.3 SCALANCE X310FE: All versions prior to v4.1.3 SCALANCE X320-1 FE: All versions prior to v4.1.3 SCALANCE X320-1-2LD FE: All versions prior to v4.1.3 SCALANCE X408-2: All versions prior to v4.1.3 SCALANCE XR324-4M EEC: All versions prior to v4.1.3 SCALANCE XR324-4M PoE: All versions prior to v4.1.3 SCALANCE XR324-12M: All versions prior to v4.1.3 SCALANCE XR324-12M TS: All versions prior to v4.1.3 SIPLUS NET SCALANCE X308-2: All versions prior to v4.1.3 --------- End Update B Part 1 of 1 ---------.",CVE-2019-13933,8.8,High,CWE-306,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1953,8/13/2019,8/13/2019,2019,ICSA-19-225-03,Siemens SCALANCE X Switches (Update C),Siemens,SCALANCE X switches,The following versions of SCALANCE X switches are affected: SCALANCE X204RNA (HSR) (6GK5204-0BA00-2MB2): All versions SCALANCE X204RNA (PRP) (6GK5204-0BA00-2KB2): All versions SCALANCE X204RNA EEC (HSR) (6GK5204-0BS00-2NA3): All versions SCALANCE X204RNA EEC (PRP) (6GK5204-0BS00-3LA3): All versions SCALANCE X204RNA EEC (PRP/HSR) (6GK5204-0BS00-3PA3): All versions; SCALANCE X-200IRT switch family (incl. SIPLUS NET variants): All versions prior to 5.5.0 SCALANCE X-200RNA: All versions.,CVE-2019-10942,8.6,High,CWE-410,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1952,2/10/2022,6/16/2022,2022,ICSA-22-041-07,"Siemens Solid Edge, JT2Go, and Teamcenter Visualization (Update C)",Siemens,"Solid Edge, JT2Go, and Teamcenter Visualization","Siemens reports these vulnerabilities affect the following visualization software products: JT2Go: All versions prior to v13.2.0.7 Teamcenter Visualization v13.2: All versions prior to v13.2.0.7 Solid Edge SE2021: All versions prior to SE2021MP9 Solid Edge SE2022: All versions prior to SE2022MP1 Teamcenter Visualization v12.4: All versions prior to v12.4.0.13 --------- Begin Update C Part 1 of 2 --------- Teamcenter Visualization v13.1: All versions prior to v13.1.0.8 Teamcenter Visualization v13.1: All versions prior to v13.1.0.9 --------- End Update C Part 1 of 2 --------- Teamcenter Visualization v13.2: All versions prior to v13.2.0.7 Teamcenter Visualization v13.3: All versions prior to v13.3.0.1 Not all the above products are affected by all the vulnerabilities below. For a complete list of how they correspond, please see Siemens security advisory SSA-301589.","CVE-2021-38405, CVE-2021-43336, CVE-2021-44000, CVE-2021-44016, CVE-2021-44018",7.8,High,"CWE-119, CWE-122, CWE-125, CWE-787",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1951,5/9/2017,5/9/2017,2022,ICSA-17-129-02,Siemens PROFINET DCP (Update U),Siemens,Devices using the PROFINET Discovery and Configuration Protocol (DCP),"Siemens reports these vulnerabilities affect the following products using PROFINET DCP: Development/Evaluation Kits DK Standard Ethernet Controller: All versions prior to v4.1.1 Patch04 Development/Evaluation Kits for PROFINET IO EK-ERTEC 200: All versions prior to v4.2.1 Patch03 Development/Evaluation Kits for PROFINET IO EK-ERTEC 200P: All versions prior to v4.4.0 Patch01 IE/AS-i Link PN IO: All versions IE/PB-Link: All versions prior to v3.0 SCALANCE M-800 / S615: All versions prior to v04.03 SCALANCE W700: All versions prior to v6.1 SCALANCE X408: All versions prior to v4.1.0 SCALANCE X414: All versions prior to v3.10.2 SCALANCE X-200 switch family (incl. SIPLUS NET variants): All versions prior to v5.2.2 SCALANCE X-200IRT switch family (incl. SIPLUS NET variants): All versions prior to v5.4.0 SCALANCE X-300 switch family (incl. SIPLUS NET variants): All versions prior to v4.1.0 SCALANCE XM-400, XR-500 families: All versions prior to v6.1 SIMATIC CM 1542-1: All versions prior to v2.0 SIMATIC CM 1542SP-1: All versions prior to v1.0.15 SIMATIC CP 343-1 (incl. SIPLUS variants): All versions prior to v3.1.3 SIMATIC CP 343-1 Advanced (incl. SIPLUS variants): All versions SIMATIC CP 343-1 Lean (incl. SIPLUS variants): All versions prior to v3.1.3 SIMATIC CP 443-1 (incl. SIPLUS variants): All versions prior to v3.2.17 SIMATIC CP 443-1 Advanced (incl. SIPLUS variants): All versions prior to v3.2.17 SIMATIC CP 443-1 OPC-UA: All versions SIMATIC CP 1243-1 (incl. SIPLUS variants): All versions prior to v2.1.82 SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants): All versions SIMATIC CP 1243-1 IEC (incl. SIPLUS variants): All versions SIMATIC CP 1243-1 IRC (incl. SIPLUS variants): All versions prior to v2.1.82 SIMATIC CP 1542SP-1 IRC (incl. SIPLUS variants): All versions prior to v1.0.15 SIMATIC CP 1543-1 (incl. SIPLUS variants): All versions prior to v2.1 SIMATIC CP 1543SP-1 (incl. SIPLUS variants): All versions prior to v1.0.15 SIMATIC CP 1604: All versions prior to v2.7 SIMATIC CP 1616: All versions prior to v2.7 SIMATIC DK-16xx PN IO: All versions prior to v2.7 SIMATIC ET 200AL: All versions prior to v1.0.2 SIMATIC ET200ecoPN, 4AO U/I 4xM12 (6ES7145-6HD00-0AB0): All versions SIMATIC ET200ecoPN, 8 DIO, DC24V/1,3A, 8xM12 (6ES7147-6BG00-0AB0): All versions SIMATIC ET200ecoPN, 8 DO, DC24V/2A, 8xM12 (6ES7142-6BR00-0AB0): All versions SIMATIC ET200ecoPN, 8AI RTD/TC 8xM12 (6ES7144-6KD50-0AB0): All versions SIMATIC ET200ecoPN, 8AI; 4 U/I; 4 RTD/TC 8xM12 (6ES7144-6KD00-0AB0): All versions SIMATIC ET200ecoPN, 8DI, DC24V, 4xM12 (6ES7141-6BF00-0AB0): All versions SIMATIC ET200ecoPN, 8DI, DC24V, 8xM12 (6ES7141-6BG00-0AB0): All versions SIMATIC ET200ecoPN, 8DO, DC24V/0,5A, 4xM12 (6ES7142-6BF50-0AB0): All versions SIMATIC ET200ecoPN, 8DO, DC24V/1,3A, 4xM12 (6ES7142-6BF00-0AB0): All versions SIMATIC ET200ecoPN, 8DO, DC24V/1,3A, 8xM12 (6ES7142-6BG00-0AB0): All versions SIMATIC ET200ecoPN, 16DI, DC24V, 8xM12 (6ES7141-6BH00-0AB0): All versions SIMATIC ET200ecoPN, 16DO DC24V/1,3A, 8xM12 (6ES7142-6BH00-0AB0): All versions SIMATIC ET200ecoPN: IO-Link Master (6ES7148-6JA00-0AB0): All versions SIMATIC ET200M (incl. SIPLUS variants): All versions SIMATIC ET200MP IM155-5 PN BA (incl. SIPLUS variants): All versions prior to v4.0.1 SIMATIC ET200MP IM155-5 PN HF (incl. SIPLUS variants): All versions prior to v4.2 SIMATIC ET200MP IM155-5 PN ST (incl. SIPLUS variants): All versions prior to v4.1 SIMATIC ET200pro: All versions SIMATIC ET200S (incl. SIPLUS variants): All versions SIMATIC ET200SP (incl. SIPLUS variants, except IM155-6 PN ST and IM155-6 PN HF): All versions SIMATIC ET200SP IM155-6 PN HF (incl. SIPLUS variants): All versions prior to v4.2.0 SIMATIC ET200SP IM155-6 PN HS (incl. SIPLUS variants): All versions prior to v4.0.1 SIMATIC ET200SP IM155-6 PN ST (incl. SIPLUS variants): All versions prior to v4.1.0 SIMATIC HMI Comfort Panels, HMI Multi Panels, HMI Mobile Panels (incl. SIPLUS variants): All versions prior to v15.1 SIMATIC MV400 family: All versions prior to v7.0.6 SIMATIC PN/PN Coupler (incl. SIPLUS NET variants): All versions prior to v4.0 SIMATIC RF650R: All versions prior to v3.0 SIMATIC RF680R: All versions prior to v3.0 SIMATIC RF685R: All versions prior to v3.0 SIMATIC S7-200 SMART: All versions prior to v2.3 SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions prior to v3.X.14 SIMATIC S7-400 H V6 CPU family (incl. SIPLUS variants): All versions prior to v6.0.7 SIMATIC S7-400 PN/DP V6 CPU family (incl. SIPLUS variants): All versions prior to v6.0.6 SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants): All versions prior to v7.0.2 SIMATIC S7-410 CPU family (incl. SIPLUS variants): All versions prior to v8.2 SIMATIC S7-1200 CPU family (incl. SIPLUS variants): All versions prior to v4.2.1 SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions prior to v2.1 SIMATIC S7-1500 Software Controller (incl. F): All versions prior to v2.1 SIMATIC TDC CP51M1: All versions prior to v1.1.8 SIMATIC TDC CPU555: All versions prior to v1.1.1 SIMATIC Teleservice Adapter IE Advanced: All versions SIMATIC Teleservice Adapter IE Basic: All versions SIMATIC Teleservice Adapter IE Standard: All versions SIMATIC WinAC RTX (F) 2010: All versions prior to SIMATIC WinAC RTX 2010 SP3 SIMOCODE pro V PN (incl. SIPLUS variants): All versions prior to v2.0.0 SIMOTION (incl. SIPLUS variants): All versions prior to v4.5 HF1 SINAMICS DCM w. PN: All versions prior to v1.4 SP1 HF5 SINAMICS DCP w. PN: All versions prior to v1.2 HF1 SINAMICS G110M w. PN: All versions prior to v4.7 SP6 HF3 SINAMICS G120(C/P/D) w. PN (incl. SIPLUS variants): All versions prior to v4.7 SP6 HF3 SINAMICS G130 v4.7 w. PN: All versions prior to v4.7 HF27 SINAMICS G130 v4.8 w. PN: All versions prior to v4.8 HF4 SINAMICS G150 v4.7 w. PN: v4.7: All versions prior to v4.7 HF27 SINAMICS G150 v4.8 w. PN: All versions prior to v4.8 HF4 SINAMICS S110 w. PN: All versions prior to V4.4 SP3 HF5 SINAMICS S120 prior to v4.7 w. PN (incl. SIPLUS variants): All versions prior to v4.7 SINAMICS S120 v4.7 SP1 w. PN (incl. SIPLUS variants): All versions SINAMICS S120 v4.7 w. PN (incl. SIPLUS variants): All versions prior to v4.7 HF27 SINAMICS S120 v4.8 w. PN (incl. SIPLUS variants): All versions prior to v4.8 HF4 SINAMICS S150 v4.7 w. PN: All versions prior to v4.7 HF27 SINAMICS S150 v4.8 w. PN: All versions prior to v4.8 HF4 SINAMICS V90 w. PN: All versions prior to v1.01 SINUMERIK 828D v4.5 and prior: All versions prior to v4.5 SP6 HF2 SINUMERIK 828D v4.7: All versions prior to v4.7 SP4 HF1 SINUMERIK 840D sl v4.5 and prior: All versions prior to v4.5 SP6 HF2 SINUMERIK 840D sl v4.7: All versions prior to v4.7 SP4 HF1 SIRIUS ACT 3SU1 interface module PROFINET: All versions prior to v1.1.0 SIRIUS Motor Starter M200D PROFINET: All versions SIRIUS Soft Starter 3RW44 PN: All versions SITOP PSU8600 PROFINET: All versions prior to v1.2.0 SITOP UPS1600 PROFINET (incl. SIPLUS variants): All versions prior to v2.2.0 Softnet PROFINET IO for PC-based Windows systems: All versions prior to v14 SP1.","CVE-2017-2680, CVE-2017-2681",6.5,Medium,CWE-400,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1950,2/10/2022,6/16/2022,2022,ICSA-22-041-07,"Siemens Solid Edge, JT2Go, and Teamcenter Visualization",Siemens,"Solid Edge, JT2Go, and Teamcenter Visualization","Siemens reports these vulnerabilities affect the following visualization software products: JT2Go: All versions Solid Edge SE2021: All versions prior to SE2021MP9 Solid Edge SE2022: All versions prior to SE2022MP1 Teamcenter Visualization v12.4: All versions Teamcenter Visualization v13.1: All versions Teamcenter Visualization v13.1: All versions prior to v13.1.0.8 Teamcenter Visualization v13.2: All versions Teamcenter Visualization v13.3: All versions Teamcenter Visualization v13.3: All versions prior to v13.3.0.1 Not all the above products are affected by all the vulnerabilities below. For a complete list of how they correspond, please see Siemens security advisory SSA-301589.","CVE-2021-38405, CVE-2021-43336, CVE-2021-44000, CVE-2021-44016, CVE-2021-44018",7.8,High,"CWE-119, CWE-122, CWE-125, CWE-787",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1949,2/18/2021,6/5/2025,2021,ICSA-21-049-02,Mitsubishi Electric FA Engineering Software Products (Update H),Mitsubishi Electric,FA Engineering Software Products,"Mitsubishi Electric reports these vulnerabilities affect the following FA Engineering Software Products that communicate with MELSEC, FREQROL, or GOT products: CPU Module Logging Configuration Tool: Version 1.112R and prior CW Configurator: Version 1.011M and prior Data Transfer: Version 3.44W and prior EZSocket: Version 5.4 and prior FR Configurator: All versions FR Configurator SW3: All versions FR Configurator2: Version 1.24A and prior GT Designer3 Version1(GOT1000): Version 1.250L and prior GT Designer3 Version1(GOT2000): Version 1.250L and prior GT SoftGOT1000 Version3: Version 3.245F and prior GT SoftGOT2000 Version1: Version 1.250L and prior GX Configurator-DP: Version 7.14Q and prior GX Configurator-QP: All versions GX Developer: Version 8.506C and prior GX Explorer: All versions GX IEC Developer: All versions GX LogViewer: Version 1.115U and prior GX RemoteService-I: All versions GX Works2: Version 1.597X and prior GX Works3: Version 1.070Y and prior iQ Monozukuri ANDON (Data Transfer): Version 1.003D and prior iQ Monozukuri Process Remote Monitoring (Data Transfer): Version 1.002C and prior M_CommDTM-HART: All versions M_CommDTM-IO-Link: Version 1.03D and prior MELFA-Works: Version 4.4 and prior MELSEC WinCPU Setting Utility: All versions MELSOFT EM Software Development Kit (EM Configurator): Version 1.015R and prior MELSOFT Navigator: Version 2.74C and prior MH11 SettingTool Version2: Version 2.004E and prior MI Configurator: Version 1.004E and prior MT Works2: Version 1.167Z and prior MX Component: Version 5.001B and prior Network Interface Board CC IE Control utility: Version 1.29F and prior Network Interface Board CC IE Field Utility: Version 1.16S and prior Network Interface Board CC-Link Ver.2 Utility: Version 1.23Z and prior Network Interface Board MNETH utility: Version 34L and prior PX Developer: Version 1.53F and prior RT ToolBox2: Version 3.73B and prior RT ToolBox3: Version 1.82L and prior Setting/monitoring tools for the C Controller module (SW4PVC-CCPU): Version 4.12N and prior SLMP Data Collector: Version 1.04E and prior.","CVE-2021-20587, CVE-2021-20588",8.7,High,"CWE-122, CWE-130",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1948,7/30/2020,5/28/2026,2020,ICSA-20-212-04,Mitsubishi Electric Factory Automation Engineering Products (Update L),Mitsubishi Electric,Mitsubishi Electric Factory Automation Engineering Products,"Mitsubishi Electric C Controller Interface Module utility: <=2.00, Mitsubishi Electric CC-Link IE Control Network Data Collector: 1.00A, Mitsubishi Electric CC-Link IE Field Network Data Collector: 1.00A, Mitsubishi Electric CC-Link IE TSN Data Collector: 1.00A, Mitsubishi Electric CPU Module Logging Configuration Tool: <=1.100E, Mitsubishi Electric CW Configurator: <=1.010L, Mitsubishi Electric Data Transfer: <=3.42U, Mitsubishi Electric EZSocket: <=5.1, Mitsubishi Electric FR Configurator SW3: vers:all/*, Mitsubishi Electric FR Configurator2: <=1.26C, Mitsubishi Electric GT Designer2 Classic: vers:all/*, Mitsubishi Electric GT Designer3 Version1 (GOT1000): <=1.241B, Mitsubishi Electric GT Designer3 Version1 (GOT2000): <=1.241B, Mitsubishi Electric GT SoftGOT1000 Version3: <=3.200J, Mitsubishi Electric GT SoftGOT2000 Version1: <=1.241B, Mitsubishi Electric GX Developer: <=8.504A, Mitsubishi Electric GX LogViewer: <=1.100E, Mitsubishi Electric GX Works2: <=1.601B, Mitsubishi Electric GX Works3: <=1.063R, Mitsubishi Electric M_CommDTM-IO-Link: <=1.03D, Mitsubishi Electric MELFA-Works: <=4.4, Mitsubishi Electric MELSEC WinCPU Setting Utility: vers:all/*, Mitsubishi Electric MELSOFT Complete Clean Up Tool: <=1.06G, Mitsubishi Electric MELSOFT EM Software Development Kit: <=1.015R, Mitsubishi Electric MELSOFT iQ AppPortal: <=1.17T, Mitsubishi Electric MELSOFT Navigator: <=2.74C, Mitsubishi Electric MI Configurator: <=1.004E, Mitsubishi Electric Motion Control Setting: <=1.005F, Mitsubishi Electric Motorizer: <=1.005F, Mitsubishi Electric MR Configurator2: <=1.125F, Mitsubishi Electric MT Works2: <=1.167Z, Mitsubishi Electric MTConnect Data Collector: <=1.1.4.0, Mitsubishi Electric MX Component: <=4.20W, Mitsubishi Electric MX MESInterface: <=1.21X, Mitsubishi Electric MX MESInterface-R: <=1.12N, Mitsubishi Electric MX Sheet: <=2.15R, Mitsubishi Electric Network Interface Board CC IE Control Utility: <=1.29F, Mitsubishi Electric Network Interface Board CC IE Field Utility: <=1.16S, Mitsubishi Electric Network Interface Board CC-Link Ver.2 Utility: <=1.23Z, Mitsubishi Electric Network Interface Board MNETH Utility: <=34L, Mitsubishi Electric Position Board utility 2: <=3.20, Mitsubishi Electric PX Developer: <=1.53F, Mitsubishi Electric RT ToolBox2: <=3.73B, Mitsubishi Electric RT ToolBox3: <=1.82L, Mitsubishi Electric Setting/monitoring tools for the C Controller module (SW3PVC-CCPU): <=3.13P, Mitsubishi Electric Setting/monitoring tools for the C Controller module (SW4PVC-CCPU): <=4.12N, Mitsubishi Electric SLMP Data Collector: <=1.04E, Mitsubishi Electric QD72P3C3 FB Library (Japanese): 1.00A, Mitsubishi Electric QD62(E/D), LD62(D) FB Library (Japanese): 1.00A, Mitsubishi Electric QD64D2 FB Library (Japanese): 1.00A, Mitsubishi Electric Simple Motion Module (Positioning Control) FB Library (Japanese): <=1.04E, Mitsubishi Electric Simple Motion Module (Positioning Control) FB Library (Other languages): <=1.04E, Mitsubishi Electric Simple Motion Module (Synchronous Control) FB Library (Japanese): <=1.02C, Mitsubishi Electric Simple Motion Module (Synchronous Control) FB Library (Other languages): <=1.02C",CVE-2020-14521,8.3,High,CWE-428,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1947,2/3/2022,3/8/2022,2022,ICSA-22-034-01,Sensormatic PowerManage,Sensormatic Electronics LLC (Subsidiary of Johnson Controls),PowerManage,"The following versions of Sensormatic Electronics, LLC PowerManage, an operating platform, are affected: PowerManage Versions 4.0 to 4.8.",CVE-2021-44228,10.0,Critical,CWE-20,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1946,2/3/2022,2/3/2022,2022,ICSA-22-034-02,Airspan Networks Mimosa,Airspan Networks,Mimosa by Airspan product line,"The following products of the Mimosa by Airspan product line, a network management software platform, are affected: MMP: All versions prior to v1.0.3 PTP C-series: Device versions prior to v2.8.6.1 PTMP C-series and A5x: Device versions prior to v2.5.4.1.","CVE-2022-0138, CVE-2022-21141, CVE-2022-21143, CVE-2022-21176, CVE-2022-21196, CVE-2022-21215, CVE-2022-21800",10.0,Critical,"CWE-285, CWE-327, CWE-502, CWE-78, CWE-863, CWE-89, CWE-918",Communications,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1945,8/31/2021,8/31/2021,2021,ICSA-21-243-02,FANUC Robot Controllers,FANUC,R-30iA and R-30iB series controllers,"The following products and versions are affected: R-30iA, R-30iA Mate; v7: v7.20, v7.30, v7.40, v7.43, v7.50, v 7.63, v7.70 R-30iB, R-30iB Mate, R-30iB Compact; v8: v8.10, v8.13, v8.20, v8.23, v8.26, v8.30, v8.33, v8.36 R-30iB Plus, R-30iB Mate Plus, R-30iB Compact Plus, R-30iB Mini Plus; v9: v9.10, v9.13, v9.16, v9.30, v9.36, v9.40.","CVE-2021-32996, CVE-2021-32998",7.4,High,"CWE-192, CWE-787",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1944,2/1/2022,2/1/2022,2022,ICSA-22-032-01,Ricon Mobile Industrial Cellular Router,"Ricon Mobile, Inc.",Industrial Cellular Router,"The following versions of Ricon Industrial Cellular Router, a mobile network router, are affected: S9922XL Version 16.10.3 S9922L Version 16.10.3.",CVE-2022-0365,9.1,Critical,CWE-78,Communications,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1943,2/1/2022,2/1/2022,2022,ICSA-22-032-02,Advantech ADAM-3600,Advantech,ADAM-3600,"The following versions of ADAM-3600, a remote terminal unit, are affected: ADAM-3600: Version 2.6.2 and prior.",CVE-2022-22987,9.8,Critical,CWE-321,Energy; Water and Wastewater Systems,"East Asia, United States, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1942,11/11/2021,2/1/2022,2021,ICSA-21-315-02,Multiple Data Distribution Service (DDS) Implementations (Update A),"Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing","CycloneDDS, FastDDS, GurumDDS, OpenDDS, Connext DDS Professional, Connext DDS Secure, Connext DDS Micro, CoreDX DDS","The following implementations of OMG DDS are affected: Eclipse CycloneDDS: All versions prior to 0.8.0 eProsima Fast DDS: All versions prior to 2.4.0 (#2269) GurumNetworks GurumDDS: All versions Object Computing, Inc. (OCI) OpenDDS: All versions prior to 3.18.1 Real-Time Innovations (RTI) Connext DDS Professional and Connext DDS Secure: Versions 4.2x to 6.1.0 RTI Connext DDS Micro: Versions 3.0.0 and later TwinOaks Computing CoreDX DDS: All versions prior to 5.9.1.","CVE-2021-38441, CVE-2021-38443, CVE-2021-38425, CVE-2021-38423, CVE-2021-38439, CVE-2021-38445, CVE-2021-38447, CVE-2021-38429, CVE-2021-38427, CVE-2021-38433, CVE-2021-38435, CVE-2021-38487, CVE-2021-43547",8.6,High,"CWE-121, CWE-122, CWE-123, CWE-130, CWE-131, CWE-228, CWE-405, CWE-406",Multiple Critical Sectors,Worldwide,Multiple,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1941,12/21/2021,1/27/2022,2021,ICSMA-21-355-01,Fresenius Kabi Agilia Connect Infusion System (Update A),Fresenius Kabi,Agilia Connect Infusion System,"The following accesories of the Agilia Connect Infusion System, are affected: Agilia Connect WiFi module of the pumps vD25 and prior Agilia Link+ v3.0 D15 and prior Vigilant Software Suite v1.0: Vigilant Centerium, Vigilant MasterMed and Vigilant Insight Agilia Partner maintenance software v3.3.0 and prior.","CVE-2021-23195, CVE-2021-23196, CVE-2021-23207, CVE-2021-23233, CVE-2021-23236, CVE-2021-31562, CVE-2021-33843, CVE-2021-33846, CVE-2021-33848, CVE-2021-41835, CVE-2021-43355, CVE-2021-44464, CVE-2020-35340",7.5,High,"CWE-1104, CWE-256, CWE-284, CWE-327, CWE-400, CWE-522, CWE-548, CWE-552, CWE-603, CWE-798, CWE-79",Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1940,11/30/2021,11/9/2023,2021,ICSA-21-334-02,Mitsubishi Electric MELSEC and MELIPC Series (Update G),Mitsubishi Electric,MELSEC and MELIPC Series,"The following versions of MELSEC series CPU modules and MELIPC Series Industrial Computers are affected: MELSEC iQ-R Series R00/01/02CPU: Firmware Versions 24 and prior MELSEC iQ-R Series R04/08/16/32/120(EN)CPU: Firmware Versions 57 and prior MELSEC iQ-R Series R08/16/32/120SFCPU: Firmware Versions 26 and prior MELSEC iQ-R Series R08/16/32/120PCPU: Firmware Versions 29 and prior MELSEC iQ-R Series R08/16/32/120PSFCPU: Firmware Versions 08 and prior MELSEC iQ-R Series R16/32/64MTCPU: Operating system software Versions 23 and prior MELSEC iQ-R Series R12CCPU-V: Firmware Versions 16 and prior MELSEC Q Series Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: The first 5 digits of serial No. 23121 and prior MELSEC Q Series Q03/04/06/13/26UDVCPU: The first 5 digits of serial No. 23071 and prior MELSEC Q Series Q04/06/13/26UDPVCPU: The first 5 digits of serial No. 23071 and prior MELSEC Q Series Q12DCCPU-V, Q24DHCCPU-V(G), Q24/26DHCCPU-LS: The first 5 digits of serial No. 24031 and prior MELSEC Q Series MR-MQ100: Operating system software version F and prior MELSEC Q Series Q172/173DCPU-S1: Operating system software version W and prior MELSEC Q Series Q172/173DSCPU: Operating system software version Y and prior MELSEC Q Series Q170MCPU: Operating system software version W and prior MELSEC Q Series Q170MSCPU(-S1): Operating system software version Y and prior MELSEC L Series L02/06/26CPU(-P), L26CPU-(P)BT: The first 5 digits of serial No. 23121 and prior MELIPC Series MI5122-VW: Firmware Versions 05 and prior","CVE-2021-20609, CVE-2021-20610, CVE-2021-20611",7.5,High,"CWE-400, CWE-130, CWE-20",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1939,1/25/2022,1/25/2022,2022,ICSA-22-025-01,GE Gas Power ToolBoxST,GE,ToolBoxST,GE reports these vulnerabilities affect the following software platform for programming: ToolBoxST OS: All versions prior to 07.09.07C.,"CVE-2021-44477, CVE-2018-16202",7.5,High,"CWE-22, CWE-611",Communications; Critical Manufacturing; Energy; Healthcare and Public Health; Transportation Systems; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1938,1/20/2022,3/10/2026,2022,ICSA-22-020-01,Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric HMI SCADA (Update B),Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric,Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric HMI SCADA,"Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: <=10.96.2, Mitsubishi Electric Iconics Digital Solutions GENESIS64: <=10.96.2, Mitsubishi Electric Iconics Digital Solutions Hyper Historian: <=10.96.2, Mitsubishi Electric Iconics Digital Solutions AnalytiX: <=10.96.2, Mitsubishi Electric Iconics Digital Solutions MobileHMI: <=10.96.2, Mitsubishi Electric MC Works64: <=4.04E","CVE-2022-23127, CVE-2022-23128, CVE-2022-23129, CVE-2022-23130",9.8,Critical,"CWE-126, CWE-184, CWE-256, CWE-79",Critical Manufacturing,Worldwide,"United States, Japan",Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1937,7/6/2021,2/21/2023,2021,ICSMA-21-187-01,Philips Vue PACS (Update C),Philips,Vue PACS,Philips reports these vulnerabilities affect the following Vue PACS products: Vue PACS: Versions 12.2.x.x and prior Vue MyVue: Versions 12.2.x.x and prior Vue Speech: Versions 12.2.x.x and prior Vue Motion: Versions 12.2.1.5 and prior.,"CVE-2021-27493, CVE-2021-27497, CVE-2021-27501, CVE-2021-33018, CVE-2021-33020, CVE-2021-33022, CVE-2021-33024, CVE-2021-39369, CVE-2020-1938, CVE-2020-4670, CVE-2019-9636, CVE-2018-10115, CVE-2018-11218, CVE-2018-12326, CVE-2018-8014, CVE-2015-9251, CVE-2012-1708",9.8,Critical,"CWE-1188, CWE-119, CWE-1214, CWE-176, CWE-20, CWE-23, CWE-287, CWE-319, CWE-324, CWE-327, CWE-522, CWE-665, CWE-693, CWE-707, CWE-710, CWE-79",Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1936,5/11/2021,1/21/2022,2021,ICSA-21-131-02,Mitsubishi Electric GOT and Tension Controller (Update A),Mitsubishi Electric,GOT and Tension Controller,Mitsubishi Electric reports the vulnerability affects the MODBUS/TCP slave communication function of the following devices: GOT2000 series GT27 model: Versions 01.19.000 - 01.38.000 GT25 model: Versions 01.19.000 - 01.38.000 GT23 model: Versions 01.19.000 - 01.38.000 GT21 model: Versions 01.21.000 - 01.39.000 GOT SIMPLE series GS21 model: Versions 01.21.000 - 01.39.000 GT SoftGOT2000: Versions 1.170C - 1.250L LE7-40GU-L Screen package data for MODBUS/TCP: v1.00 Please see Mitsubishi Electric report number 2021-002 to learn how to check which version is in use..,CVE-2021-20589,5.9,Medium,CWE-805,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1935,12/8/2020,12/8/2020,2022,ICSA-20-343-02,Mitsubishi Electric GOT and Tension Controller (Update B),Mitsubishi Electric,GOT and Tension Controller,"Mitsubishi Electric reports that the vulnerability affects the following human-machine interface (GOT) and Tension Controller products: GOT2000 series, GT21 model: GT2107-WTBD versions v01.39.000 and earlier GT2107-WTSD versions v01.39.000 and earlier GT2104-RTBD versions v01.39.000 and earlier GT2104-PMBD versions v01.39.000 and earlier GT2103-PMBD versions v01.39.000 and earlier GOT SIMPLE series, GS21 model: GS2110-WTBD versions v01.39.000 and earlier GS2107-WTBD versions v01.39.000 and earlier GS2110-WTBD-N versions v01.39.000 and earlier GS2107-WTBD-N versions v01.39.000 and earlier; Tension Controller: LE7-40GU-L Screen package data for CC-Link IEF Basic v1.00 LE7-40GU-L Screen package data for MODBUS/TCP v1.00 LE7-40GU-L Screen package data for SLMP v1.00 Refer to the user manual to determine which version is in use. The latest version of the manual of GOT is available at the Mitsubishi Electric Global Website. Contact a Mitsubishi Electric representative for the latest version of the Tension Controller manual.",CVE-2020-5675,7.5,High,CWE-125,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1934,1/13/2022,1/17/2022,2022,ICSA-22-013-01,Mitsubishi Electric MELSEC-F Series,Mitsubishi Electric,MELSEC-F Series,"The following versions of MELSEC-F Series with FX3U-ENET, an Ethernet-Internet block, are affected: FX3U-ENET Firmware Version 1.14 and prior FX3U-ENET-L Firmware Version 1.14 and prior FX3U-ENET-P502 Firmware Version 1.14 and prior.",CVE-2021-20612,7.5,High,CWE-671,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1933,1/13/2022,1/13/2022,2022,ICSA-22-013-02,Siemens SICAM A8000,Siemens,SICAM A8000,"The following versions of SICAM A8000, a remote terminal unit, are affected: CP-8000 MASTER MODULE WITH I/O - 25/+70°C (6MF2101-0AB10-0AA0): All versions prior to v16.20 CP-8000 MASTER MODULE WITH I/O - 40/+70°C (6MF2101-1AB10-0AA0): All versions prior to v16.20 CP-8021 MASTER MODULE (6MF2802-1AA00): All versions prior to v16.20 CP-8022 MASTER MODULE WITH GPRS (6MF2802-2AA00): All versions prior to v16.20.","CVE-2021-45033, CVE-2021-45034",9.9,Critical,"CWE-284, CWE-798",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1932,1/13/2022,1/13/2022,2022,ICSA-22-013-03,Siemens Energy PLUSCONTROL,Siemens,PLUSCONTROL,"The following versions of PLUSCONTROL, a control device for high-power energy transmission, are affected: PLUSCONTROL 1st Gen: All versions.","CVE-2021-31344, CVE-2021-31345, CVE-2021-31346, CVE-2021-31885, CVE-2021-31889, CVE-2021-31890",8.2,High,"CWE-1284, CWE-191, CWE-240, CWE-805, CWE-843",Multiple Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1931,1/13/2022,1/13/2022,2022,ICSA-22-013-04,Siemens SIPROTEC 5 Devices,Siemens,SIPROTEC 5 products,"Siemens reports this vulnerability affects the following SIPROTEC 5 products: Devices with the hardware variants CP050, CP100, and CP300 A full list of the affected devices was published in the Siemens Security Advisory SSA-439673.",CVE-2021-41769,6.5,Medium,CWE-20,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1930,1/13/2022,1/13/2022,2022,ICSA-22-013-06,Siemens SICAM PQ Analyzer,Siemens,SICAM PQ Analyzer,The following versions of SICAM PQ Analyzer power quality system software are affected: All versions prior to v3.18.,CVE-2021-45460,3.4,Low,CWE-428,Chemical; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1929,1/13/2022,1/13/2022,2022,ICSA-22-013-07,Mitsubishi Electric MELSEC-F Series,Mitsubishi Electric,MELSEC-F Series,"The following versions of MELSEC-F Series with FX3U-ENET, an Ethernet-Internet block, are affected: FX3U-ENET: Firmware Version 1.16 and prior FX3U-ENET-L: Firmware Version 1.16 and prior FX3U-ENET-P502: Firmware Version 1.16 and prior.",CVE-2021-20613,7.5,High,CWE-665,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1928,9/23/2021,9/23/2021,2021,ICSA-21-266-01,Trane Symbio (Update B),Trane U.S. Inc.,Symbio 700 and Symbio 800 controllers,The following Trane building automation products deployed on the following HVAC equipment are affected: Symbio 700: Odyssey Split Systems: All versions prior to v1.00.0023 Symbio 800: IntelliPak Rooftop Air Conditioner: All versions prior to v1.30.0008 Ascend Air-Cooled Chiller Model ACR: All versions prior to v1.10.0010 Agility Water-Cooled Chiller Model HDWA: All versions prior to v1.00.0010.,CVE-2021-38448,7.5,High,CWE-94,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1927,4/13/2021,1/13/2022,2021,ICSA-21-103-14,Siemens Nucleus DNS (Update A),Siemens,Nucleus,"The following Nucleus products and versions are affected: Nucleus NET, All versions Nucleus RTOS, All versions that include affected DNS modules Nucleus ReadyStart, All versions prior to v2013.08 Nucleus Source Code, All versions that include the affected DNS modules VSTAR, All versions that include the affected DNS modules.",CVE-2021-27393,5.3,Medium,CWE-330,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1926,10/29/2020,9/5/2024,2020,ICSA-20-303-01,"Mitsubishi Electric MELSEC iQ-R, Q, and L Series (Update E)",Mitsubishi Electric,"MELSEC iQ-R, Q, and L Series",Mitsubishi Electric reports that the following MELSEC programmable controllers are affected: MELSEC iQ-R R00 CPU firmware: versions 20 and earlier MELSEC iQ-R R01 CPU firmware: versions 20 and earlier MELSEC iQ-R R02 CPU firmware: versions 20 and earlier MELSEC iQ-R R04 (EN) CPU firmware: versions 52 and earlier MELSEC iQ-R R08 (EN) CPU firmware: versions 52 and earlier MELSEC iQ-R R16 (EN) CPU firmware: versions 52 and earlier MELSEC iQ-R R32 (EN) CPU firmware: versions 52 and earlier MELSEC iQ-R R120 (EN) CPU firmware: versions 52 and earlier MELSEC iQ-R R08 SFCPU firmware: versions 22 and earlier MELSEC iQ-R R16 SFCPU firmware: versions 22 and earlier MELSEC iQ-R R32 SFCPU firmware: versions 22 and earlier MELSEC iQ-R R120 SFCPU firmware: versions 22 and earlier MELSEC iQ-R R08 PCPU firmware: versions 24 and earlier MELSEC iQ-R R16 PCPU firmware: versions 24 and earlier MELSEC iQ-R R32 PCPU firmware: versions 24 and earlier MELSEC iQ-R R120 PCPU firmware: versions 24 and earlier MELSEC iQ-R R08 PSFCPU firmware: versions 06 and earlier MELSEC iQ-R R16 PSFCPU firmware: versions 06 and earlier MELSEC iQ-R R32 PSFCPU firmware: versions 06 and earlier MELSEC iQ-R R120 PSFCPU firmware: versions 06 and earlier MELSEC iQ-R R16 MTCPU operating system software: versions 21 and earlier MELSEC iQ-R R32 MTCPU operating system software: versions 21 and earlier MELSEC iQ-R R64 MTCPU operating system software: versions 21 and earlier MELSEC Q Q03 UDECPU: the first 5 digits of serial number 22081 and earlier MELSEC Q Q04 UDEHCPU: the first 5 digits of serial number 22081 and earlier MELSEC Q Q06 UDEHCPU: the first 5 digits of serial number 22081 and earlier MELSEC Q Q10 UDEHCPU: the first 5 digits of serial number 22081 and earlier MELSEC Q Q13 UDEHCPU: the first 5 digits of serial number 22081 and earlier MELSEC Q Q20 UDEHCPU: the first 5 digits of serial number 22081 and earlier MELSEC Q Q26 UDEHCPU: the first 5 digits of serial number 22081 and earlier MELSEC Q Q50 UDEHCPU: the first 5 digits of serial number 22081 and earlier MELSEC Q Q100 UDEHCPU: the first 5 digits of serial number 22081 and earlier MELSEC Q Q03 UDVCPU: the first 5 digits of serial number 22031 and earlier MELSEC Q Q04 UDVCPU: the first 5 digits of serial number 22031 and earlier MELSEC Q Q06 UDVCPU: the first 5 digits of serial number 22031 and earlier MELSEC Q Q13 UDVCPU: the first 5 digits of serial number 22031 and earlier MELSEC Q Q26 UDVCPU: the first 5 digits of serial number 22031 and earlier MELSEC Q Q04 UDPVCPU: the first 5 digits of serial number 22031 and earlier MELSEC Q Q06 UDPVCPU: the first 5 digits of serial number 22031 and earlier MELSEC Q Q13 UDPVCPU: the first 5 digits of serial number 22031 and earlier MELSEC Q Q26 UDPVCPU: the first 5 digits of serial number 22031 and earlier MELSEC Q Q172 DCPU-S1 operating system software: versions V and earlier MELSEC Q Q173 DCPU-S1 operating system software: versions V and earlier MELSEC Q Q172 DSCPU operating system software: versions W and earlier MELSEC Q Q173 DSCPU operating system software: versions W and earlier MELSEC Q Q170 MCPU operating system software: versions V and earlier MELSEC Q Q170 MSCPU(-S1) operating system software: versions W and earlier MELSEC Q MR-MQ100 operating system software: versions E and earlier. This product is sold in limited regions. MELSEC L L02 CPU (-P): the first 5 digits of serial number 23121 and earlier MELSEC L L06 CPU (-P): the first 5 digits of serial number 23121 and earlier MELSEC L L26 CPU (-P): the first 5 digits of serial number 23121 and earlier MELSEC L L26 CPU - (P) BT: the first 5 digits of serial number 23121 and earlier.,CVE-2020-5652,7.5,High,CWE-400,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1925,1/11/2022,1/11/2022,2022,ICSA-22-011-01,Johnson Controls VideoEdge,Sensormatic Electronics LLC (Subsidiary of Johnson Controls),VideoEdge,"The following versions of VideoEdge, a network video recorder, are affected: VideoEdge: Versions 5.4.1 to 5.7.1.",CVE-2021-36199,5.3,Medium,CWE-228,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1924,1/6/2022,1/6/2022,2022,ICSMA-22-006-01,Philips Engage Software,Philips,Engage Software,"The following versions of Engage, a customer support software platform, are affected: Engage Software Versions 6.2.1 and prior.",CVE-2021-23173,2.6,Low,CWE-284,Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1923,1/6/2022,1/6/2022,2022,ICSA-22-006-01,Omron CX-One,Omron,CX-One,The following versions of CX-One automation software are affected: CX-One: Versions 4.60 and prior.,CVE-2022-21137,7.8,High,CWE-121,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1922,1/6/2022,1/6/2022,2022,ICSA-22-006-02,Fernhill SCADA,Fernhill Software Ltd.,Fernhill SCADA Server,"Fernhill SCADA Server Version 3.77 and earlier on all supported platforms (Windows, Linux, macOS).",CVE-2022-21155,7.5,High,CWE-400,Energy; Water and Wastewater; Food and Agriculture; Critical Manufacturing,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1921,1/6/2022,1/6/2022,2022,ICSA-22-006-03,IDEC PLCs,IDEC,PLCs (Programmable Logic Controllers),The following IDEC PLCs are affected: FC6A MICROSmart All-in-One CPU Module: v2.32 and earlier FC6B MICROSmart All-in-One CPU Module: v2.31 and earlier FC6A MICROSmart Plus CPU Module: v1.91 and earlier FC6B MICROSmart Plus CPU Module: v2.31 and earlier FT1A Controller SmartAXIS Pro/Lite: v2.31 and earlier WindLDR: v8.19.1 and earlier WindEDIT Lite: v1.3.1 and earlier Data File Manager: v2.12.1 and earlier FC6A MICROSmart All-in-One CPU Module: v2.32 and earlier FC6A MICROSmart Plus CPU Module: v1.91 and earlier WindLDR: v8.19.1 and earlier WindEDIT: Lite v1.3.1 and earlier Data File Manager: v2.12.1 and earlier.,"CVE-2021-20826, CVE-2021-20827, CVE-2021-37400, CVE-2021-37401",7.6,High,"CWE-256, CWE-523",Multiple Critical Sectors,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1920,12/23/2021,12/23/2021,2021,ICSA-21-357-01,Moxa MGate Protocol Gateways,Moxa,MGate Protocol Gateways,"The following firmware versions of MGate MB3000 Series, a serial-to-Ethernet Modbus gateway, are affected: MGate MB3180 Series: Firmware Version 2.2 or lower MGate MB3280 Series: Firmware Version 4.1 or lower MGate MB3480 Series: Firmware Version 3.2 or lower.",CVE-2021-4161,9.8,Critical,CWE-319,Multiple Critical Sectors,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1919,12/23/2021,12/23/2021,2021,ICSA-21-357-02,Johnson Controls exacq Enterprise Manager,Exacq Technologies Inc (Subsidiary of Johnson Controls),Johnson Controls exacq Enterprise Manager,"The following versions of Exacq Technologies Enterprise Manager, an enterprise management tool, are affected: Exacq Enterprise Manager: All Versions 21.12 and prior.",CVE-2021-44228,10.0,Critical,CWE-20,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1918,12/21/2021,1/27/2022,2021,ICSMA-21-355-01,Fresenius Kabi Agilia Connect Infusion System,Fresenius Kabi,Agilia Connect Infusion System,"The following components of the Agilia Connect Infusion System, are affected: Agilia Connect WiFi module of the pumps vD25 and prior Agilia Link+ v3.0 D15 and prior Vigilant Software Suite v1.0: Vigilant Centerium, Vigilant MasterMed and Vigilant Insight Agilia Partner maintenance software v3.3.0 and prior.","CVE-2021-23195, CVE-2021-23196, CVE-2021-23207, CVE-2021-23233, CVE-2021-23236, CVE-2021-31562, CVE-2021-33843, CVE-2021-33846, CVE-2021-33848, CVE-2021-41835, CVE-2021-43355, CVE-2021-44464, CVE-2020-35340",7.5,High,"CWE-400, CWE-327, CWE-522, CWE-284, CWE-256, CWE-552, CWE-548, CWE-79, CWE-798, CWE-327, CWE-603, CWE-1104",Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1917,12/21/2021,12/21/2021,2021,ICSA-21-355-01,mySCADA myPRO,mySCADA Technologies,myPRO,"The following versions of myPRO, an HMI/SCADA system, are affected: myPRO: Versions 8.20.0 and prior.","CVE-2021-22657, CVE-2021-23198, CVE-2021-43981, CVE-2021-43984, CVE-2021-43985, CVE-2021-43987, CVE-2021-43989, CVE-2021-44453",10.0,Critical,"CWE-288, CWE-912, CWE-78, CWE-916",Energy; Food and Agriculture; Transportation Systems; Water and Wastewater Systems,Worldwide,Czech Republic,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1916,12/21/2021,12/21/2021,2021,ICSA-21-355-02,Horner Automation Cscape EnvisionRV,Horner Automation,Cscape EnvisionRV,Horner Automation reports this vulnerability affects the following Cscape industrial remote viewing software products: Cscape EnvisionRV v4.50.3.1 and prior.,CVE-2021-44462,7.8,High,CWE-20,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1915,12/21/2021,12/21/2021,2021,ICSA-21-355-03,WECON LeviStudioU,WECON,LeviStudioU,"The following versions of LeviStudioU, an HMI programming software, are affected: LeviStudioU: Versions 2019-09-21 and prior.","CVE-2021-23138, CVE-2021-23157",7.8,High,"CWE-122, CWE-121",Critical Manufacturing; Energy; Water and Wastewater Systems,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1914,12/21/2021,12/21/2021,2021,ICSA-21-355-04,Emerson DeltaV,Emerson,DeltaV,Emerson reports these vulnerabilities affect the following versions: DeltaV Distributed Control System Controllers and Workstations: All versions.,"CVE-2021-26264, CVE-2021-44463",8.1,High,"CWE-306, CWE-427",Chemical; Critical Manufacturing; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1913,12/14/2021,12/14/2021,2021,ICSA-21-348-02,Schneider Electric Rack PDU,Schneider Electric,Rack PDU,The following products of the Rack Power Distribution Unit (PDU) are affected: AP7xxxx and AP8xxx with NMC2: v6.9.6 and prior AP7xxx and AP8xxx with NMC3: v1.1.0.3 and prior APDU9xxx with NMC3: v1.0.0.28 and prior.,CVE-2021-22825,6.5,Medium,CWE-200,Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1912,12/16/2021,12/16/2021,2021,ICSA-21-350-01,Xylem AquaView,Xylem Inc,AquaView,"The following versions of AquaView, a SCADA system, are affected: AquaView: Versions 1.60, 7.x, 8.x.",CVE-2021-42833,9.3,Critical,CWE-798,Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1911,12/16/2021,12/16/2021,2021,ICSA-21-350-02,Delta Electronics CNCSoft,Delta Electronics,CNCSoft,The following versions of CNCSoft industrial automation software are affected: CNCSoft Versions 1.01.30 and prior.,CVE-2021-44768,6.1,Medium,CWE-125,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1910,12/16/2021,12/16/2021,2021,ICSA-21-350-03,Wibu-Systems CodeMeter Runtime,Wibu-Systems AG,CodeMeter Runtime,"The following versions of CodeMeter Runtime, a license manger, are affected: CodeMeter Runtime: All versions prior to Version 7.30a.",CVE-2021-41057,7.1,High,CWE-269,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1909,12/16/2021,12/16/2021,2021,ICSA-21-350-04,Mitsubishi Electric GX Works2,Mitsubishi Electric,GX Works2,"The following versions of GX Works2, an engineering software suite, are affected: GX Works2: Versions 1.606G and prior.",CVE-2021-20608,5.3,Medium,CWE-130,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1908,12/16/2021,7/28/2022,2021,ICSA-21-350-05,Mitsubishi Electric FA Engineering Software (Update B),Mitsubishi Electric,FA Engineering Software,"The following versions of FA Engineering Software, an engineering software suite, are affected: GX Works2: Versions 1.606G and prior MELSOFT Navigator: Versions 2.84N and prior EZSocket: All versions --------- Begin Update A Part 1 of 2 --------- EZSocket: Versions 5.4 and prior --------- End Update A Part 1 of 2 ---------.","CVE-2021-20606, CVE-2021-20607",5.5,Medium,"CWE-191, CWE-125",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1907,12/16/2021,11/10/2022,2021,ICSA-21-350-06,Siemens Capital VSTAR (Update A),Siemens,Capital VSTAR,"The following versions of Capital VSTAR software platform are affected because of their use of Nucleus NET, the networking stack of Nucleus RTOS (real-time operating system): Capital VSTAR: All versions with enabled Ethernet options.","CVE-2021-31344, CVE-2021-31345, CVE-2021-31346, CVE-2021-31881, CVE-2021-31882, CVE-2021-31883, CVE-2021-31889, CVE-2021-31890",8.8,High,"CWE-843, CWE-240, CWE-119, CWE-191, CWE-125, CWE-1248",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1906,12/16/2021,12/16/2021,2021,ICSA-21-350-07,Siemens POWER METER SICAM Q100,Siemens,POWER METER SICAM Q100,"The following versions of the POWER METER SICAM Q100 power monitoring device, are affected: POWER METER SICAM Q100 (7KG9501-0AA01-0AA1, 7KG9501-0AA01-2AA1, 7KG9501-0AA31-0AA1, 7KG9501-0AA31-2AA1): All versions prior to v2.41.",CVE-2021-44165,9.1,Critical,CWE-121,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1905,12/16/2021,12/16/2021,2021,ICSA-21-350-08,Siemens JTTK and JT Utilities,Siemens,JTTK and JT Utilities,"The following versions of JT Open Toolkit (JTTK), an application programming interface, and JT Utilities, a series of command line utilities, are affected: JT Utilities: All versions prior to v13.0.3.0 JTTK: All versions prior to v11.0.3.0.","CVE-2021-44446, CVE-2021-44447, CVE-2021-44448",7.8,High,"CWE-125, CWE-787, CWE-416",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1904,12/16/2021,12/16/2021,2021,ICSA-21-350-09,Siemens SINUMERIK Edge,Siemens,SINUMERIK Edge,"The following versions of SINUMERIK Edge, a hardware and software digital production support and optimization platform, are affected: SINUMERIK Edge: All versions prior to 3.2.",CVE-2021-42027,7.4,High,CWE-295,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1903,12/16/2021,12/16/2021,2021,ICSA-21-350-10,Siemens JT2Go and Teamcenter Visualization,Siemens,JT2Go and Teamcenter Visualization,The following versions of JT2Go and Teamcenter Visualization software tools are affected: JT2Go: All versions prior to v13.2.0.5 Teamcenter Visualization: All versions prior to v13.2.0.5.,"CVE-2021-44001, CVE-2021-44002, CVE-2021-44003, CVE-2021-44004, CVE-2021-44005, CVE-2021-44006, CVE-2021-44007, CVE-2021-44008, CVE-2021-44009, CVE-2021-44010, CVE-2021-44011, CVE-2021-44012, CVE-2021-44013, CVE-2021-44014, CVE-2021-44015, CVE-2021-44017",7.8,High,"CWE-125, CWE-193, CWE-416, CWE-457, CWE-787",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1902,12/16/2021,12/16/2021,2021,ICSA-21-350-11,Siemens SIMATIC eaSie PCS 7 Skill Package,Siemens,SIMATIC eaSie PCS 7 Skill Package,"The following versions of SIMATIC eaSie PCS 7 Skill Package, a digital assistant, are affected: SIMATIC eaSie PCS 7 Skill Package (6DL5424-0BX00-0AV8): All versions prior to 21.00 SP3.",CVE-2021-42022,6.5,Medium,CWE-22,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1901,12/16/2021,12/16/2021,2021,ICSA-21-350-12,Siemens SIMATIC ITC,Siemens,SIMATIC ITC,Siemens reports these vulnerabilities affect the following SIMATIC Industrial Thin Clients: SIMATIC ITC1500 V3: All versions prior to v3.2.1.0 SIMATIC ITC1500 V3 PRO: All versions prior to v3.2.1.0 SIMATIC ITC1900 V3: All versions prior to v3.2.1.0 SIMATIC ITC1900 V3 PRO: All versions prior to v3.2.1.0 SIMATIC ITC2200 V3: All versions prior to v3.2.1.0 SIMATIC ITC2200 V3 PRO: All versions prior to v3.2.1.0.,"CVE-2020-14396, CVE-2020-14397, CVE-2020-14398, CVE-2020-14401, CVE-2020-14402, CVE-2020-14403, CVE-2020-14404, CVE-2020-14405, CVE-2019-15681, CVE-2019-15690, CVE-2019-20788, CVE-2019-20839, CVE-2019-20840, CVE-2018-20019, CVE-2018-20748, CVE-2018-20749, CVE-2018-20750, CVE-2018-21247, CVE-2017-18922",9.8,Critical,CWE-1035,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1900,12/16/2021,11/10/2022,2021,ICSA-21-350-13,Siemens Questa and ModelSim (Update A),Siemens,Questa Simulation and ModelSim Simulation,"The following versions of Questa and ModelSim, integrated circuit simulators, are affected: ModelSim Simulation: All Versions Questa Simulation: All Versions.",CVE-2021-42023,9.0,Critical,CWE-522,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1899,12/16/2021,12/16/2021,2021,ICSA-21-350-14,Siemens Siveillance Identity,Siemens,Siveillance Identity,"The following versions of Siveillance Identity, a web-based self-service portal, are affected: Siveillance Identity v1.5: All versions Siveillance Identity v1.6: All versions prior to v1.6.284.0.","CVE-2021-44522, CVE-2021-44523, CVE-2021-44524",7.5,High,CWE-668,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1898,12/16/2021,12/16/2021,2021,ICSA-21-350-15,Siemens Simcenter STAR-CCM+ Viewer,Siemens,Simcenter STAR-CCM+ Viewer,"The following versions of Simcenter STAR-CCM+ Viewer, a multiphysics computational fluid dynamics (CFD) software, are affected: Simcenter STAR-CCM+ Viewer: All versions prior to 2021.3.1.",CVE-2021-42024,7.8,High,CWE-787,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1897,12/16/2021,2/10/2022,2021,ICSA-21-350-16,Siemens Healthineers syngo fastView,Siemens Healthineers (Subsidiary of Siemens),syngo fastView,"The following versions of syngo fastView, a software for digital imaging and communications, are affected: Syngo fastView: All versions.","CVE-2021-40367, CVE-2021-42028",7.8,High,CWE-787,Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1896,12/16/2021,12/16/2021,2021,ICSA-21-350-17,Siemens JT Utilities and JT Open Toolkit,Siemens,JT Utilities and JT Open Toolkit,"The following versions of JT Open Toolkit (JTTK), an application programming interface, and JT Utilities, a series of command line utilities, are affected: JT Utilities: All versions prior to v13.1.1.0 JTTK: All versions prior to v11.1.1.0.","CVE-2021-44430, CVE-2021-44431, CVE-2021-44432, CVE-2021-44433, CVE-2021-44434, CVE-2021-44435, CVE-2021-44436, CVE-2021-44437, CVE-2021-44438, CVE-2021-44439, CVE-2021-44440, CVE-2021-44441, CVE-2021-44442, CVE-2021-44443, CVE-2021-44444, CVE-2021-44445",7.8,High,"CWE-122, CWE-119, CWE-125, CWE-787, CWE-121, CWE-416",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1895,12/16/2021,12/16/2021,2021,ICSA-21-350-18,Siemens Teamcenter Active Workspace,Siemens,Teamcenter Active Workspace,"The following versions of Teamcenter Active Workspace, a collaboration tool, are affected: Teamcenter Active Workspace v4.3: All versions prior to v4.3.11 Teamcenter Active Workspace v5.0: All versions prior to v5.0.10 Teamcenter Active Workspace v5.1: All versions prior to v5.1.6 Teamcenter Active Workspace v5.2: All versions prior to v5.2.3.",CVE-2021-41547,6.8,Medium,CWE-22,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1894,12/16/2021,12/16/2021,2021,ICSA-21-350-19,Siemens SiPass Integrated,Siemens,SiPass Integrated,"The following versions of Siemens SiPass integrated, an access control system, are affected: SiPass Integrated v2.64: All versions SiPass Integrated v2.80: All versions SiPass Integrated v2.85: All versions.","CVE-2021-44522, CVE-2021-44523, CVE-2021-44524",7.5,High,CWE-668,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1893,12/16/2021,12/16/2021,2021,ICSA-21-350-20,Siemens JTTK and JT Utilities,Siemens,JTTK and JT Utilities,"The following versions of JT Open Toolkit (JTTK), an application programming interface, and JT Utilities, a series of command line utilities, are affected: JT Utilities: All versions prior to v12.8.1.1 JTTK: All versions prior to v10.8.1.1.","CVE-2021-44449, CVE-2021-44450",7.8,High,"CWE-125, CWE-787",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1892,11/11/2021,5/12/2022,2022,ICSA-21-315-07,Siemens Nucleus RTOS-based APOGEE and TALON Products (Update C),Siemens,Nucleus RTOS based APOGEE and TALON Products,"The following Nucleus RTOS based APOGEE and TALON Products, direct digital control (DDC) devices, are affected: APOGEE MBC (PPC) (BACnet): All versions APOGEE MBC (PPC) (P2 Ethernet): All versions APOGEE MEC (PPC) (BACnet): All versions APOGEE MEC (PPC) (P2 Ethernet): All versions Begin Update C: APOGEE PXC Compact (BACnet): All versions prior to v3.5.4 APOGEE PXC Compact (P2 Ethernet): All versions prior to v2.8.19 APOGEE PXC Modular (BACnet): All versions prior to v3.5.4 APOGEE PXC Modular (P2 Ethernet): All versions prior to v2.8.19 Desigo PXC00-E.D: Versions 2.3 and later and prior to v6.30.016 Desigo PXC00-U: Versions 2.3 and later and prior to v6.30.016 Desigo PXC001-E.D: Versions 2.3 and later and prior to v6.30.016 Desigo PXC12-E.D: Versions 2.3 and later and prior to v6.30.016 Desigo PXC22-E.D: Versions 2.3 and later and prior to v6.30.016 Desigo PXC22.1-E.D: Versions 2.3 and later and prior to v6.30.016 Desigo PXC36.1-E.D: Versions 2.3 and later and prior to v6.30.016 Desigo PXC50-E.D: Versions 2.3 and later and prior to v6.30.016 Desigo PXC64-U: Versions 2.3 and later and prior to v6.30.016 Desigo PXC100-E.D: Versions 2.3 and later and prior to v6.30.016 Desigo PXC128-U: Versions 2.3 and later and prior to v6.30.016 Desigo PXC200-E.D: Versions 2.3 and later and prior to v6.30.016 Desigo PXM20-E: Versions 2.3 and later and prior to v6.30.016 TALON TC Compact (BACnet): All versions prior to v3.5.4 TALON TC Modular (BACnet): All versions prior to v3.5.4 End Update C:","CVE-2021-31344, CVE-2021-31345, CVE-2021-31346, CVE-2021-31881, CVE-2021-31882, CVE-2021-31883, CVE-2021-31884, CVE-2021-31885, CVE-2021-31886, CVE-2021-31887, CVE-2021-31888, CVE-2021-31889, CVE-2021-31890",9.8,Critical,"CWE-843, CWE-805, CWE-240, CWE-170, CWE-119, CWE-1284, CWE-191, CWE-125",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1891,8/26/2021,8/2/2022,2021,ICSA-21-238-03,Delta Electronics DIAEnergie (Update C),Delta Electronics,DIAEnergie,The following versions of DIAEnergie are affected: -------- Begin Update C Part 1 of 2 --------- DIAEnergie: All versions prior to 1.9 --------- End Update C Part 1 of 2 ---------.,"CVE-2021-23228, CVE-2021-31558, CVE-2021-32955, CVE-2021-32967, CVE-2021-32983, CVE-2021-32991, CVE-2021-33003, CVE-2021-38390, CVE-2021-38391, CVE-2021-38393, CVE-2021-44471, CVE-2021-44544, CVE-2022-0988",9.8,Critical,"CWE-288, CWE-352, CWE-79, CWE-89, CWE-434, CWE-916, CWE-319",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1890,8/5/2021,12/16/2021,2021,ICSA-21-217-01,"HCC Embedded InterNiche TCP/IP stack, NicheLite (Update A)",HCC Embedded,"InterNiche stack (NicheStack), NicheLite",The following embedded component TCP/IP stacks are affected: InterNiche stack: All versions prior to v4.3 NicheLite: All versions prior to v4.3.,"CVE-2021-27565, CVE-2021-31226, CVE-2021-31227, CVE-2021-31228, CVE-2021-31400, CVE-2021-31401, CVE-2021-36762, CVE-2020-25767, CVE-2020-25926, CVE-2020-25927, CVE-2020-25928, CVE-2020-35683, CVE-2020-35684, CVE-2020-35685",9.8,Critical,"CWE-466, CWE-130, CWE-330, CWE-20, CWE-248, CWE-839, CWE-340, CWE-703, CWE-170",Multiple Critical Sectors,Worldwide,Hungary,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1889,5/11/2021,8/18/2022,2021,ICSA-21-131-03,Siemens Linux-based Products (Update J),Siemens,Linux based products,"The following Siemens Linux-based products are affected: RUGGEDCOM RM1224: All versions between v5.0 and v6.4 SCALANCE M-800: All versions between v5.0 and v6.4 SCALANCE S615: All versions between v5.0 and v6.4 SCALANCE SC-600: All versions prior to v2.1.3 SCALANCE W1750D: v8.3.0.1, v8.6.0, and v8.7.0 SIMATIC MV500 Family: All versions SIMATIC CP 1243-7 LTE EU: Versions 3.1.39 and later, and prior to Version 3.3 SIMATIC CP 1243-7 LTE US: Versions 3.1.39 and later, and prior to Version 3.3 SIMATIC CP 1242-7 GPRS V2: Versions 3.1.39 and prior to Version 3.3 SIMATIC CP 1542SP-1 IRC (incl. SIPLUS variants): Versions 2.0 and later SIMATIC CP 1542SP-1: Versions 2.0 and later SIMATIC CP 1543-1 (incl. SIPLUS variants): Versions prior to 3.0 SIMATIC CP 1543SP-1 (incl SIPLUS variants): Versions 2.0 and later SIMATIC CP 1545-1: All versions prior to v1.1 --------- Begin Update J Part 1 of 2 --------- SIPLUS NET CP 1242-7 V2 (6AG1242-7KX31-7XE0): Versions between and including v3.1.39 and v3.3 SIPLUS S7-1200 CP 1243-1 (6AG1243-1BX30-2AX0): Versions between and including v3.1.39 and v3.3.46 SIPLUS S7-1200 CP 1243-1 RAIL (6AG2243-1BX30-1XE0): Versions between and including v3.1.39 and v3.3.46 -------- End Update J Part 1 of 2 ---------- SIMATIC CP 1243-1 (incl. SIPLUS variants): All versions 3.1.39 and newer to those prior to v3.3.3 SIMATIC CP 1243-8 IRC: All versions 3.1.39 and newer to those prior to v3.3.46 SIMATIC MV540 H (6GF3540-0GE10): All versions prior to 3.1 SIMATIC MV540 S (6GF3540-0CD10): All versions prior to 3.1 SIMATIC MV550 H (6GF3550-0GE10): All versions prior to 3.1 SIMATIC MV550 S (6GF3550-0CD10): All versions prior to 3.1 SIMATIC MV560 U (6GF3560-0LE10): All versions prior to 3.1 SIMATIC MV560 X (6GF3560-0HE10): All versions prior to 3.1 SIMATIC Cloud Connect 7 CC712 (6GK1411-1AC00): All versions from 1.0 to those prior to v1.6 SIMATIC Cloud Connect 7 CC716 (6GK1411-5AC00): All versions from 1.0 to those prior to v1.6 TIM 1531 IRC (6GK7543-1MX00-0XE0): All versions prior to 2.2 Update 1 SIPLUS TIM 1532 (6AG1543-1MX00-7XE0): All versions prior to 2.2 Update 1 SINEMA Remote Connect Server: All versions prior to v3.0 SP1.",CVE-2020-25705,7.4,High,CWE-330,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1888,11/19/2020,11/19/2020,2021,ICSA-20-324-05,Mitsubishi Electric MELSEC iQ-R Series (Update B),Mitsubishi Electric,MELSEC iQ-R Series,Mitsubishi Electric reports the vulnerability affects the following MELSEC iQ-R series CPU module products: R00/01/02CPU firmware Versions 19 and earlier R04/08/16/32/120(EN)CPU firmware Versions 51 and earlier R08/16/32/120SFCPU firmware Versions 22 and earlier; R08/16/32/120PCPU firmware Versions 25 and earlier R08/16/32/120PSFCPU firmware Versions 06 and earlier; RJ71EN71 firmware Versions 47 and earlier RJ71GF11-T2 firmware Versions 47 and earlier RJ72GF15-T2 firmware Versions 07 and earlier RJ71GP21-SX firmware Versions 47 and earlier RJ71GP21S-SX firmware Versions 47 and earlier RJ71C24(-R2/R4) all versions RJ71GN11-T2 all versions.,CVE-2020-5668,7.5,High,CWE-400,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1887,4/14/2020,5/12/2022,2021,ICSA-20-105-06,"Siemens SIMOTICS, Desigo, APOGEE, and TALON (Update D)",Siemens,"SIMOTICS, Desigo, APOGEE, and TALON","Siemens reports the vulnerability affects the following products and versions: APOGEE MEC/MBC/PXC (P2): All versions prior to 2.8.2 Begin Update D: APOGEE PXC Series (P2): All versions between 2.8.2 and v2.8.19 End Update D Desigo PXC00-E.D: All versions, 2.3x to v6.00.327 Desigo PXC00-U: All versions, 2.3x to v6.00.327 Desigo PXC001-E.D: All versions, 2.3x to v6.00.327 Desigo PXC12-E.D: All versions, 2.3x to v6.00.327 Desigo PXC22-E.D: All versions, 2.3x to v6.00.327 Desigo PXC22.1-E.D: All versions, 2.3x to v6.00.327 Desigo PXC36.1-E.D: All versions, 2.3x to v6.00.327 Desigo PXC50-E.D: All versions, 2.3x to v6.00.327 Desigo PXC64-U: All versions, 2.3x to v6.00.327 Desigo PXC100-E.D: All versions, 2.3x to v6.00.327 Desigo PXC128-U: All versions, 2.3x to v6.00.327 Desigo PXC200-E.D: All versions, 2.3x to v6.00.327 Desigo PXM20-E: All versions, 2.3x to v6.00.327 SIMOTICS CONNECT 400: All versions prior to 0.3.0.330 TALON TC Series (BACnet): All versions prior to 3.5.3 APOGEE PXC Series (BACnet): All versions prior to 3.5.3.","CVE-2019-1393, CVE-2019-13939",7.1,High,CWE-84,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1886,1/14/2020,8/11/2022,2020,ICSA-20-014-05,Siemens TIA Portal (Update F),Siemens,TIA Portal,"The following versions of TIA Portal, the Totally Integrated Automation Portal, are affected: TIA Portal v14: All versions TIA Portal v15: All versions prior to v15.1 Update 7 --------- Begin Update F Part 1 of 2 --------- TIA Portal v16: All versions prior to v16 update 6 --------- End Update F Part 1 of 2 --------- TIA Portal v17: All versions prior to v17 update 4.","CVE-2019-1093, CVE-2019-10934",7.8,High,CWE-22,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1885,12/14/2021,12/14/2021,2021,ICSA-21-348-01,Advantech R-SeeNet,Advantech,R-SeeNet,"The following versions of R-SeeNet, a monitoring application, are affected: R-SeeNet: Versions 2.4.16 and prior.","CVE-2021-21910, CVE-2021-21911, CVE-2021-21912, CVE-2021-21915, CVE-2021-21916, CVE-2021-21917, CVE-2021-21918, CVE-2021-21919, CVE-2021-21920, CVE-2021-21921, CVE-2021-21922, CVE-2021-21923, CVE-2021-21924, CVE-2021-21925, CVE-2021-21926, CVE-2021-21927, CVE-2021-21928, CVE-2021-21929, CVE-2021-21930, CVE-2021-21931, CVE-2021-21932, CVE-2021-21933, CVE-2021-21934, CVE-2021-21935, CVE-2021-21936, CVE-2021-21937",8.8,High,"CWE-89, CWE-269",Critical Manufacturing; Energy; Water and Wastewater Systems,"East Asia, Europe, Middle East, South America, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1884,6/1/2021,11/22/2022,2021,ICSMA-21-152-01,Hillrom Medical Device Management (Update C),Hillrom,Welch Allyn medical device management tools,"The following Hillrom products, are affected: Welch Allyn Service Tool: versions prior to v1.10 Welch Allyn Connex Device Integration Suite - Network Connectivity Engine (NCE): versions prior to v5.3 Welch Allyn Software Development Kit (SDK): versions prior to v3.2 Welch Allyn Connex Central Station (CS): versions prior to v1.8.4 Service Pack 01 Welch Allyn Service Monitor: versions prior to v1.7.0.0 Welch Allyn Connex Vital Signs Monitor (CVSM): versions prior to v2.43.02 Welch Allyn Connex Integrated Wall System (CIWS): versions prior to v2.43.02 Welch Allyn Connex Spot Monitor (CSM): versions prior to v1.52 Welch Allyn Spot Vital Signs 4400 Device (Spot 4400) / Welch Allyn Spot 4400 Vital Signs Extended Care Device: versions prior to v1.11.00.","CVE-2021-27410, CVE-2021-27408",5.9,Medium,"CWE-787, CWE-125",Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1883,12/9/2021,12/9/2021,2021,ICSMA-21-343-01,Hillrom Welch Allyn Cardio Products,Hillrom,Welch Allyn Cardio Products,"The following Hillrom cardiology products, when configured to use single sign-on (SSO), are affected: Welch Allyn Q-Stress Cardiac Stress Testing System: Versions 6.0.0 through 6.3.1 Welch Allyn X-Scribe Cardiac Stress Testing System: Versions 5.01 through 6.3.1 Welch Allyn Diagnostic Cardiology Suite: Version 2.1.0 Welch Allyn Vision Express: Versions 6.1.0 through 6.4.0 Welch Allyn H-Scribe Holter Analysis System: Versions 5.01 through 6.4.0 Welch Allyn R-Scribe Resting ECG System: Versions 5.01 through 7.0.0 Welch Allyn Connex Cardio: Versions 1.0.0 through 1.1.1.",CVE-2021-43935,8.1,High,CWE-288,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1882,12/9/2021,3/21/2023,2021,ICSA-21-343-01,"Hitachi Energy GMS600, PWC600, and Relion (Update A)",Hitachi Energy,"GMS600, PWC600, and Relion 670/650/SAM600-IO","The following versions of Hitachi Energy GMS600 and PWC600 circuit breaker monitoring systems are affected: GMS600: Version 1.2.0 GMS600: Version 1.3.0 GMS600: Version 1.3.1.0 PWC600: Version 1.1.0.0 PWC600: Version 1.1.0.1 PWC600: Version 1.0.1.0 PWC600: Version 1.0.1.1 PWC600: Version 1.0.1.3 PWC600: Version 1.0.1.4 Relion 670/650 series: Version 2.2.0, all revisions Relion 670/650/SAM600-IO series: Version 2.2.1, all revisions Relion 670 series: Version 2.2.2, all revisions Relion 670 series: Version 2.2.3, revisions up to 2.2.3.4 Relion 670/650 series: Version 2.2.4, all revisions Relion 670/650/SAM600-IO series: Version 2.2.5, revisions up to 2.2.5.1 Relion 670/650 series: Version 2.1, all revisions Relion 670 series: Version 2.0, all revisions Relion 650 series: Version 1.3, all revisions Relion 650 series: Version 1.2, all revisions Relion 650 series: Version 1.1, all revisions Relion 650 series: Version 1.0, all revisions.",CVE-2021-35534,7.2,High,CWE-284,Multiple Critical Sectors,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1881,12/9/2021,12/9/2021,2021,ICSA-21-343-02,WECON LeviStudioU,WECON,LeviStudioU,The following versions of LeviStudioU HMI programming software are affected: LeviStudioU: Versions 2019-09-21 and prior.,CVE-2021-43983,7.8,High,CWE-121,Critical Manufacturing; Energy; Water and Wastewater Systems,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1880,12/7/2021,12/7/2021,2021,ICSA-21-341-01,Hitachi Energy RTU500 OpenLDAP,Hitachi Energy,RTU500 OpenLDAP,"The following versions of RTU500 Series, a remote terminal unit, are affected: RTU500 Series CMU Firmware Version 12.4.X RTU500 Series CMU Firmware Version 12.6.X RTU500 Series CMU Firmware Version 12.7.X RTU500 Series CMU Firmware Version 13.0.X RTU500 Series CMU Firmware Version 13.1.X RTU500 Series CMU Firmware Version 13.2.1.","CVE-2020-36229, CVE-2020-36230",7.5,High,"CWE-843, CWE-617",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1879,12/7/2021,12/7/2021,2021,ICSA-21-341-02,Hitachi Energy XMC20 and FOX61x,Hitachi Energy,XMC20 and FOX61x,"The following versions of XMC20 and FOX61x, multi-service network elements, are affected: XMC20: All versions prior to R15A FOX61x: All versions prior to R15A.","CVE-2021-40333, CVE-2021-40334",9.0,Critical,"CWE-431, CWE-521",Multiple Critical Sectors,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1878,8/31/2021,8/31/2021,2021,ICSA-21-243-02,FANUC Robot Controllers,FANUC,R-30iA and R-30iB series controllers,"The following products and versions are affected: R-30iA, R-30iA Mate; v7: v7.20, v7.30, v7.40, v7.43, v7.50, v.7.63, v7.70 R-30iB, R-30iB Mate, R-30iB Compact; v8: v8.10, v8.13, v8.20, v8.23, v8.26, v8.30, v8.33, v8.36 R-30iB Plus, R-30iB Mate Plus, R-30iB Compact Plus, R-30iB Mini Plus; v9: v9.10, v9.13, v9.16, v9.30, v9.36, v9.40.","CVE-2021-32996, CVE-2021-32998",7.4,High,"CWE-192, CWE-787",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1877,12/2/2021,12/2/2021,2021,ICSA-21-336-01,Schneider Electric SESU,Schneider Electric,SESU,"The following versions of Schneider Electric Software Update, are affected: Schneider Electric Software Update: v2.3.0 through v2.5.1 Schneider Electric Software Update is used by the following products: EcoStruxure Augmented Operator Advisor EcoStruxure Control Expert (formerly known as Unity Pro) EcoStruxure Process Expert (formerly known as EcoStruxure Hybrid Distributed Control System) EcoStruxure Machine Expert (formerly known as SoMachine or SoMachine Motion) EcoStruxure Machine Expert Basic EcoStruxure Operator Terminal Expert EcoStruxure Plant Builder EcoStruxure Power Design EcoStruxure Automation Expert EcoStruxure Automation Maintenance Expert Eurotherm Data Reviewer Eurotherm iTools eXLhoist Configuration Software Schneider Electric Floating License Manager Schneider Electric License Manager Harmony XB5SSoft SoMove Versatile Software BLUE Vijeo Designer OsiSense XX Configuration Software Zelio Soft 2 Note: This vulnerability affects all products listed above, but this is not a complete list of products. Some of the products might not deliver SESU as part of the product package; however, SESU can be downloaded and used to manage product updates. It may also be possible more components for one product are listed in the ""SESU Managed Products"" dialog for update.",CVE-2021-22799,3.8,Low,CWE-331,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1876,12/2/2021,12/4/2021,2021,ICSA-21-336-02,Johnson Controls Entrapass,Sensormatic Electronics LLC (Subsidiary of Johnson Controls),Johnson Controls Entrapass,"The following versions of Sensormatic Electronics Entrapass, a security management software, are affected: Entrapass: All versions prior to 8.40.",CVE-2021-36198,8.3,High,CWE-200,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1875,12/2/2021,12/2/2021,2021,ICSA-21-336-03,Distributed Data Systems WebHMI,Distributed Data Systems,WebHMI,"The following versions of WebHMI, a SCADA system with built-in web server capability, are affected: All versions prior to 4.1.","CVE-2021-43931, CVE-2021-43936",10.0,Critical,"CWE-305, CWE-434",Critical Manufacturing,"Germany, Poland, Ukraine, United States",Ukraine,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1874,12/2/2021,12/2/2021,2021,ICSA-21-336-04,Hitachi Energy RTU500 series BCI,Hitachi Energy,RTU500 series BCI,"The following firmware versions of RTU500 series, a remote terminal unit, are affected: RTU500 series CMU Firmware Version 12.0: All versions RTU500 series CMU Firmware Version 12.2: All versions RTU500 series CMU Firmware Version 12.4: All versions.",CVE-2021-35533,7.5,High,CWE-20,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1873,12/2/2021,6/5/2025,2021,ICSA-21-336-05,Hitachi Energy Relion 670/650/SAM600-IO (Update A),Hitachi Energy,Relion 670/650/SAM600-IO,Hitachi Energy reports this vulnerability affects the following Relion products: Relion 670/650 series: Version 2.2.0 Relion 670/650/SAM600-IO series: Versions 2.2.1 through 2.2.1.6 Relion 670 series: Versions 2.2.2 through 2.2.2.4 Relion 670 series: Versions 2.2.3 through 2.2.3.3 Relion 670/650 series: Versions 2.2.4 through 2.2.4.2.,CVE-2021-35535,8.9,High,CWE-1188,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1872,12/2/2021,10/18/2022,2021,ICSA-21-336-06,Hitachi Energy APM Edge (Update A),Hitachi Energy,APM Edge,Hitachi Energy reports this vulnerability affects the following APM product versions: APM Edge Version 1.0 APM Edge Version 2.0 APM Edge Version 3.0.,"CVE-2021-3449, CVE-2020-1971, CVE-2019-1563, CVE-2019-1549, CVE-2019-1547, CVE-2021-23840, CVE-2021-23841, CVE-2017-8872, CVE-2019-20388, CVE-2020-24977, CVE-2021-3516, CVE-2021-3517, CVE-2021-3518, CVE-2021-3537, CVE-2021-3541, CVE-2020-10713, CVE-2020-14308, CVE-2020-14309, CVE-2020-14310, CVE-2020-14311, CVE-2020-15705, CVE-2020-15706, CVE-2020-15707, CVE-2020-14372, CVE-2020-25632, CVE-2020-27749, CVE-2020-27779, CVE-2021-20225, CVE-2021-20233",8.2,High,"CWE-1357, CWE-787, CWE-190, CWE-476, CWE-416, CWE-776, CWE-120, CWE-122, CWE-184, CWE-347, CWE-362, CWE-125, CWE-121, CWE-285, CWE-330, CWE-327, CWE-203, CWE-401",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1871,12/2/2021,12/2/2021,2021,ICSA-21-336-07,Hitachi Energy PCM600 Update Manager,Hitachi Energy,PCM600 Update Manager,"The following versions of PCM600 Update Manager, an update manager for the PCM600 software (a protection and control IED manager), are affected: PCM600 Update Manager: Versions 2.1, 2.1.0.4, 2.2, 2.2.0.1, 2.2.0.2, 2.2.0.23, 2.3.0.60, 2.4.20041.1, and 2.4.20119.2.",CVE-2021-22278,6.7,Medium,CWE-295,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1870,12/2/2021,12/2/2021,2021,ICSA-21-336-08,Hitachi Energy RTU500 series,Hitachi Energy,RTU500 series,"The following versions of the RTU500 series, a remote terminal unit, are affected: RTU500 series CMU Firmware: Version 11.* RTU500 series CMU Firmware: Version 12.0.* RTU500 series CMU Firmware: Version 12.2.* RTU500 series CMU Firmware: Version 12.4.* RTU500 series CMU Firmware: Version 12.6.* RTU500 series CMU Firmware: Version 12.7.* RTU500 series CMU Firmware: Version 13.0.* RTU500 series CMU Firmware: Version 13.1.* RTU500 series CMU Firmware: Version 13.2.1.","CVE-2021-3517, CVE-2020-1968, CVE-2020-24977",8.6,High,"CWE-126, CWE-203, CWE-125",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1869,11/30/2021,11/30/2021,2021,ICSA-21-334-01,Xylem Aanderaa GeoView,Xylem Inc,Aanderaa GeoView,"The following versions of Aanderaa GeoView, a web-based data display, are affected: AADI GeoView Webservice: All versions prior to v2.1.3.",CVE-2021-41063,8.2,High,CWE-89,Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1868,11/30/2021,11/9/2023,2021,ICSA-21-334-02,Mitsubishi MELSEC and MELIPC Series (Update F),Mitsubishi Electric,MELSEC and MELIPC Series,"The following versions of MELSEC series CPU modules and MELIPC Series Industrial Computers are affected: MELSEC iQ-R Series R00/01/02CPU: Firmware Versions 24 and prior MELSEC iQ-R Series R04/08/16/32/120(EN)CPU: Firmware Versions 57 and prior ---------- Begin Update F Part 1 of 2 ---------- MELSEC iQ-R Series R08/16/32/120SFCPU: Firmware Versions 26 and prior ---------- End Update F Part 1 of 2 ---------- MELSEC iQ-R Series R08/16/32/120PCPU: Firmware Versions 29 and prior MELSEC iQ-R Series R08/16/32/120PSFCPU: Firmware Versions 08 and prior MELSEC iQ-R Series R16/32/64MTCPU: Operating system software Versions 23 and prior MELSEC iQ-R Series R12CCPU-V: Firmware Versions 16 and prior MELSEC Q Series Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: The first 5 digits of serial No. 23121 and prior MELSEC Q Series Q03/04/06/13/26UDVCPU: The first 5 digits of serial No. 23071 and prior MELSEC Q Series Q04/06/13/26UDPVCPU: The first 5 digits of serial No. 23071 and prior MELSEC Q Series Q12DCCPU-V, Q24DHCCPU-V(G), Q24/26DHCCPU-LS: The first 5 digits of serial No. 24031 and prior MELSEC Q Series MR-MQ100: Operating system software version F and prior MELSEC Q Series Q172/173DCPU-S1: Operating system software version W and prior MELSEC Q Series Q172/173DSCPU: All versions MELSEC Q Series Q170MCPU: Operating system software version W and prior MELSEC Q Series Q170MSCPU(-S1): All versions MELSEC L Series L02/06/26CPU(-P), L26CPU-(P)BT: The first 5 digits of serial No. 23121 and prior MELIPC Series MI5122-VW: Firmware Versions 05 and prior","CVE-2021-20609, CVE-2021-20610, CVE-2021-20611",7.5,High,"CWE-400, CWE-130, CWE-20",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1867,11/30/2021,11/30/2021,2021,ICSA-21-334-03,Delta Electronics CNCSoft,Delta Electronics,CNCSoft,"The following versions of CNCSoft, a software management platform, are affected: CNCSoft: Version 1.01.30 and prior.",CVE-2021-43982,7.8,High,CWE-121,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1866,11/30/2021,11/30/2021,2021,ICSA-21-334-04,Johnson Controls CEM Systems AC2000,Controlled Electronic Management Systems Ltd (CEM) (Subsidiary of Johnson Controls),CEM Systems AC2000,"The following versions of Controlled Electronic Management Systems Ltd. CEM Systems AC2000, an access control system, are affected: CEM Systems AC2000: All versions prior to Version 10.6.",CVE-2021-3156,7.8,High,CWE-193,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1865,11/30/2021,11/30/2021,2021,ICSA-21-334-05,Hitachi Energy Retail Operations and CSB Software,Hitachi Energy,Retail Operations and CSB Software,Hitachi Energy reports the following versions of Retail Operations and CSB software systems are affected: Retail Operations: Version 5.7.3 and prior Counterparty Settlement and Billing (CSB): Version 5.7.3 and prior.,CVE-2021-35528,7.2,High,CWE-284,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1864,10/7/2021,11/30/2021,2021,ICSA-21-280-05,InHand Networks IR615 Router (Update A),InHand Networks,IR615 Router,The following versions of the InHand Networks IR615 Router are affected: IR615 Router: Versions 2.3.0.r5417 and prior.,"CVE-2021-38462, CVE-2021-38464, CVE-2021-38466, CVE-2021-38468, CVE-2021-38470, CVE-2021-38472, CVE-2021-38474, CVE-2021-38476, CVE-2021-38478, CVE-2021-38480, CVE-2021-38482, CVE-2021-38484, CVE-2021-38486",9.8,Critical,"CWE-1021, CWE-285, CWE-352, CWE-326, CWE-307, CWE-434, CWE-79, CWE-78, CWE-204, CWE-521",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1863,4/29/2021,4/19/2022,2021,ICSA-21-119-04,Multiple RTOS (Update E),Multiple Vendors,Multiple RTOS,Amazon FreeRTOS; Version 10.4.1 Apache Nuttx OS; Version 9.1.0 ARM CMSIS-RTOS2; versions prior to 2.1.3 ARM Mbed OS; Version 6.3.0 ARM mbed-ualloc; Version 1.3.0 Cesanta Software Mongoose OS; v2.17.0 eCosCentric eCosPro RTOS; Versions 2.0.1 through 4.5.3 Google Cloud IoT Device SDK; Version 1.0.2 Linux Zephyr RTOS; versions prior to 2.4.0 Media Tek LinkIt SDK; versions prior to 4.6.1 Micrium OS; Versions 5.10.1 and prior; Micrium uCOS II/uCOS III Versions 1.39.0 and prior Micrium uC/OS: uC/LIB Versions 1.38.xx; Version 1.39.00; NXP MCUXpresso SDK; versions prior to 2.8.2 NXP MQX; Versions 5.1 and prior Redhat newlib; versions prior to 4.0.0 RIOT OS; Version 2020.01.1 Samsung Tizen RT RTOS; versions prior 3.0.GBB TencentOS-tiny; Version 3.1.0 Texas Instruments CC32XX; versions prior to 4.40.00.07 Texas Instruments SimpleLink MSP432E4XX Texas Instruments SimpleLink-CC13XX; versions prior to 4.40.00 Texas Instruments SimpleLink-CC26XX; versions prior to 4.40.00 Texas Instruments SimpleLink-CC32XX; versions prior to 4.10.03 Uclibc-NG; versions prior to 1.0.36 Windriver VxWorks; prior to 7.0 Micrium uC/LIB Version 1.38.xx; Version 1.39.00 Zephyr Project RTOS; versions prior to 2.5.,"CVE-2021-22636, CVE-2021-22680, CVE-2021-22684, CVE-2021-26461, CVE-2021-26706, CVE-2021-27411, CVE-2021-27417, CVE-2021-27419, CVE-2021-27421, CVE-2021-27425, CVE-2021-27427, CVE-2021-27429, CVE-2021-27431, CVE-2021-27433, CVE-2021-27435, CVE-2021-27439, CVE-2021-27502, CVE-2021-27504, CVE-2021-30636, CVE-2021-31571, CVE-2021-31572, CVE-2021-3420, CVE-2020-13603, CVE-2020-28895, CVE-2020-35198",9.8,Critical,CWE-190,Multiple Critical Sectors,Worldwide,Multiple,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1862,11/18/2021,11/18/2021,2021,ICSMA-21-322-01,Philips IntelliBridge EC 40 and EC 80 Hub,Philips,IntelliBridge EC 40 and EC 80 Hub,"The following versions of IntelliBridge are affected: IntelliBridge EC 40 Hub, C.00.04 and prior IntelliBridge EC 80 Hub, C.00.04 and prior.","CVE-2021-32993, CVE-2021-33017",8.1,High,"CWE-288, CWE-798",Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1861,11/18/2021,1/12/2023,2021,ICSMA-21-322-02,Philips Patient Information Center iX (PIC iX) and Efficia CM Series (Update A),Philips,Patient Information Center iX (PIC iX) and Efficia CM Series,"The following versions of Patient Information Center iX (PIC iX) and Efficia CM Series are affected: Patient Information Center iX (PIC iX): Versions B.02, C.02, C.03 Efficia CM Series: Revisions A.01 to C.0x and 4.0","CVE-2021-43548, CVE-2021-43550, CVE-2021-43552",6.5,Medium,"CWE-20, CWE-327, CWE-321",Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1860,9/23/2021,9/23/2021,2021,ICSA-21-266-01,Trane Symbio (Update A),Trane,Trane Symbio,The following Trane building automation products deployed on the following HVAC equipment are affected: Symbio 700: Odyssey Split Systems: All versions prior to v1.00.0023 Symbio 800: IntelliPak Rooftop Air Conditioner: All versions prior to v1.30.0008 Ascend Air-Cooled Chiller Model ACR: All versions prior to v1.10.0010 Agility Water-Cooled Chiller Model HDWA: All versions prior to v1.00.0010.,CVE-2021-38448,7.5,High,CWE-94,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1859,9/12/2020,12/14/2023,2020,ICSMA-20-254-01,Philips Patient Monitoring Devices (Update C),Philips,"Patient Information Center iX (PICiX); PerformanceBridge Focal Point; IntelliVue Patient Monitors MX100, MX400-MX850, and MP2-MP90; and IntelliVue X2, and X3","The following versions of the patient monitoring devices are affected: Patient Information Center iX (PICiX): Versions B.02, C.02, C.03 PerformanceBridge Focal Point: Version A.01 IntelliVue patient monitors MX100, MX400-MX850, and MP2-MP90: Versions N and prior IntelliVue X3 and X2: Versions N and prior","CVE-2020-16214, CVE-2020-16218, CVE-2020-16222, CVE-2020-16228, CVE-2020-16224, CVE-2020-16220, CVE-2020-16216, CVE-2020-16212",6.8,Medium,"CWE-1236, CWE-79, CWE-287, CWE-299, CWE-130, CWE-1286, CWE-20, CWE-668",Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1858,3/24/2020,3/24/2020,2021,ICSA-20-084-01,VISAM Automation Base (VBASE) (Update B),VISAM,Automation Base (VBASE),The following versions of VBASE - automation platform are affected: VBASE Editor; Version 11.5.0.2 VBASE Web-Remote Module.,"CVE-2020-10599, CVE-2020-10601, CVE-2020-7000, CVE-2020-7004, CVE-2020-7008",9.0,Critical,"CWE-326, CWE-276, CWE-922, CWE-23, CWE-121",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1857,11/16/2021,11/16/2021,2021,ICSA-21-320-01,FATEK Automation WinProladder,FATEK Automation,WinProladder,"The following versions of WinProladder, a PLC programming software, are affected: WinProladder: Versions 3.30_24518 and prior.","CVE-2021-43554, CVE-2021-43556",7.8,High,"CWE-787, CWE-121",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1856,11/16/2021,11/16/2021,2021,ICSA-21-320-02,Mitsubishi Electric GOT products,Mitsubishi Electric,GOT products,The following Mitsubishi Electric human-machine interface (HMI) products are affected: GOT2000 series GT27 model: All versions GT25 model: All versions GT23 model: All versions GT21 model: All versions GOT SIMPLE series GS21 model: All versions GT SoftGOT2000: All versions.,CVE-2021-20601,7.5,High,CWE-20,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1855,11/11/2021,11/11/2021,2021,ICSA-21-315-01,WECON PLC Editor,WECON,PLC Editor,The following versions of PLC Editor ladder logic software are affected: PLC Editor: Versions 1.3.8 and prior.,"CVE-2021-42705, CVE-2021-42707",7.8,High,"CWE-787, CWE-121",Critical Manufacturing; Energy; Water and Wastewater Systems,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1854,11/11/2021,2/1/2022,2021,ICSA-21-315-02,Multiple Data Distribution Service (DDS) Implementations,"Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing",CycloneDDS,"The following implementations of OMG DDS are affected: Eclipse CycloneDDS: All versions prior to 0.8.0 eProsima Fast DDS: All versions prior to 2.4.0 (#2269) GurumNetworks GurumDDS: All versions Object Computing, Inc. (OCI) OpenDDS: All versions prior to 3.18.1 Real-Time Innovations (RTI) Connext DDS Professional and Connext DDS Secure: Versions 4.2x to 6.1.0 RTI Connext DDS Micro: Versions 3.0.0 and later TwinOaks Computing CoreDX DDS: All versions prior to 5.9.1.","CVE-2021-38423, CVE-2021-38425, CVE-2021-38427, CVE-2021-38429, CVE-2021-38433, CVE-2021-38435, CVE-2021-38439, CVE-2021-38441, CVE-2021-38443, CVE-2021-38445, CVE-2021-38447, CVE-2021-38487, CVE-2021-43547",8.6,High,"CWE-405, CWE-122, CWE-130, CWE-228, CWE-131, CWE-406, CWE-121, CWE-123",Multiple Critical Sectors,Worldwide,Multiple,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1853,11/11/2021,7/14/2022,2021,ICSA-21-315-03,Siemens SIMATIC WinCC,Siemens,SIMATIC WinCC,Siemens reports these vulnerabilities affects the following SIMATIC SCADA HMI system products: SIMATIC PCS 7 v8.2 and earlier: All versions SIMATIC PCS 7 v9.0: All versions SIMATIC PCS 7 v9.1: All versions SIMATIC WinCC v7.4 and earlier: All versions SIMATIC WinCC v7.5: All versions prior to v7.5 SP2 Update 5 SIMATIC WinCC v15 and earlier: All versions SIMATIC WinCC v16: All versions SIMATIC WinCC v17: All versions.,"CVE-2021-40358, CVE-2021-40359, CVE-2021-40364",9.9,Critical,"CWE-22, CWE-532",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1852,11/11/2021,11/11/2021,2021,ICSA-21-315-04,Siemens Mendix,Siemens,Mendix,"The following versions of Mendix, an application platform, are affected: Mendix Applications using Mendix 7: All versions prior to v7.23.26 Mendix Applications using Mendix 8: All versions prior to v8.18.12 Mendix Applications using Mendix 9: All versions prior to v9.6.1.",CVE-2021-42015,4.0,Medium,CWE-525,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1851,11/11/2021,11/11/2021,2021,ICSA-21-315-05,Siemens Mendix Studio Pro,Siemens,Mendix Studio Pro,Siemens reports these vulnerabilities affect the following Mendix products: Mendix Applications using Mendix 8: All versions prior to v8.18.13 Mendix Applications using Mendix 9: All versions prior to v9.6.2.,"CVE-2021-42025, CVE-2021-42026",5.3,Medium,CWE-863,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1850,11/11/2021,10/13/2022,2021,ICSA-21-315-06,Siemens SCALANCE W1750D (Update A),Siemens,SCALANCE W1750D,"The following versions of SCALANCE W1750D, a wireless access point, are affected: SCALANCE W1750D: All versions prior to v8.7.1.3 --------- Begin Update A part 1 of 3 --------- SCALANCE W1750D: Versions from 8.7.1.3 to those prior to v8.7.1.9 (only affected by CVE-2021-37727, CVE-2021-37730, and CVE-2021-37734) --------- End Update A part 1 of 3 ---------.","CVE-2021-37726, CVE-2021-37727, CVE-2021-37730, CVE-2021-37732, CVE-2021-37734, CVE-2021-37735",9.8,Critical,"CWE-22, CWE-77, CWE-119",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1849,11/11/2021,12/10/2021,2021,ICSA-21-315-08,Siemens NX OBJ Translator,Siemens,NX OBJ Translator,Siemens reports these vulnerabilities affects the following NX products: NX 1953 Series: All versions prior to v1973.3700 NX 1980 Series: All versions prior to v1988.,"CVE-2021-41535, CVE-2021-41538",7.8,High,"CWE-824, CWE-416",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1848,11/11/2021,3/10/2022,2021,ICSA-21-315-09,Siemens Climatix POL909 (Update A),Siemens,Climatix POL909,"The following versions of Climatix POL909 (AWM module), an advanced web module, are affected: Climatix POL909 (AWM module): All versions prior to v11.34. Update: Climatix POL909 (AWB module): All versions prior to v11.34",CVE-2021-40366,6.4,Medium,CWE-311,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1847,11/11/2021,11/11/2021,2021,ICSA-21-315-10,Siemens SENTRON powermanager,Siemens,SENTRON powermanager,"The following versions of Siemens SENTRON powermanager, a power monitoring software to analyze energy consumption, are affected: SENTRON powermanager Version 3: All versions.",CVE-2021-37207,7.8,High,CWE-732,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1846,11/11/2021,11/11/2021,2021,ICSA-21-315-11,Siemens SIMATIC RTLS Locating Manager,Siemens,SIMATIC RTLS Locating Manager,"The following versions of Siemens SIMATIC RTLS Locating Manager, a scalable digital twin locating system, is affected: All versions prior to v2.12.","CVE-2020-10052, CVE-2020-10053, CVE-2020-10054",5.5,Medium,"CWE-312, CWE-20, CWE-532",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1845,11/11/2021,11/11/2021,2021,ICSA-21-315-12,Siemens NX JT Translator,Siemens,NX JT Translator,Siemens reports these vulnerabilities affect the following NX design software products: NX 1980 Series: All versions prior to v1984.,"CVE-2021-41533, CVE-2021-41534",3.3,Low,"CWE-824, CWE-125",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1844,11/11/2021,11/11/2021,2021,ICSA-21-315-13,Siemens Siveillance Video DLNA Server,Siemens,Siveillance Video DLNA Server,"The following versions of Siveillance Video DLNA Server, a video DLNA server, are affected: Siveillance Video DLNA Server 2019 R1: All versions Siveillance Video DLNA Server 2019 R2: All versions Siveillance Video DLNA Server 2019 R3: All versions Siveillance Video DLNA Server 2020 R1: All versions Siveillance Video DLNA Server 2020 R2: All versions Siveillance Video DLNA Server 2020 R3: All versions Siveillance Video DLNA Server 2021 R1: All versions.",CVE-2021-42021,8.6,High,CWE-26,Communications,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1843,4/13/2021,11/11/2021,2021,ICSA-21-103-04,Siemens Nucleus Products DNS Module (Update A),Siemens,Siemens Nucleus Products DNS Module,The following Nucleus products are affected: Nucleus NET: All versions prior to v5.2 Nucleus RTOS: Versions including affected DNS modules Nucleus Source Code: Versions including affected DNS modules VSTAR: Versions including affected DNS modules.,"CVE-2020-15795, CVE-2020-27009",8.1,High,"CWE-787, CWE-823",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1842,4/13/2021,11/11/2021,2021,ICSA-21-103-05,Siemens Nucleus Products IPv6 Stack (Update A),Siemens,Siemens Nucleus Products IPv6 Stack,The following Nucleus products are affected: Nucleus 4: All versions prior to v4.1.0 Nucleus NET: All versions Nucleus ReadyStart: All versions Nucleus Source Code: Versions including the affected IPv6 stack VSTAR: Versions including the affected IPv6 stack.,"CVE-2021-25663, CVE-2021-25664",7.5,High,CWE-835,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1841,2/11/2021,2/11/2021,2021,ICSA-21-042-01,Multiple Embedded TCP/IP Stacks (Update B),Multiple Vendors,Multiple Embedded TCP/IP Stacks,The following have been reported to be affected: Nut/Net; Version 5.1 and prior CycloneTCP; Version 1.9.6 and prior NDKTCPIP; Version 2.25 and prior FNET; Version 4.6.3 uIP-Contiki-OS (end-of-life [EOL]); Version 3.0 and prior uC/TCP-IP (EOL); Version 3.6.0 and prior uIP-Contiki-NG; Version 4.5 and prior uIP (EOL); Version 1.0 and prior picoTCP-NG; Version 1.7.0 and prior picoTCP (EOL); Version 1.7.0 and prior MPLAB Net; Version 3.6.1 and prior Nucleus NET; All versions prior to Version 5.2 Nucleus ReadyStart for ARM; MIPS; and PPC; All versions prior to Version 2012.12.,"CVE-2020-27213, CVE-2020-27630, CVE-2020-27631, CVE-2020-27632, CVE-2020-27633, CVE-2020-27634, CVE-2020-27635, CVE-2020-27636, CVE-2020-28388",7.5,High,CWE-330,Multiple Critical Sectors,Worldwide,Multiple,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1840,6/9/2020,12/15/2022,2020,ICSA-20-161-04,"Siemens SIMATIC, SINAMICS, SINEC, SINEMA, SINUMERIK (Update K)",Siemens,"SIMATIC, SINAMICS, SINEC, SINEMA, SINUMERIK",The following Siemens products are affected: SIMATIC Automation Tool: All versions SIMATIC NET PC software: All versions after v16 and prior to v16 Upd3 SIMATIC PCS neo: All versions prior to v3.0 SP1 SIMATIC ProSave: All versions SIMATIC S7-1500 Software Controller: All versions prior to v21.8 SINAMICS STARTER: All versions prior to v5.4 HF2 SIMATIC STEP 7: All versions prior to v5.6 SP2 HF3 SIMATIC STEP 7 (TIA Portal) v13: All versions prior to SP2 Update 4 SIMATIC STEP 7 (TIA Portal) v14: All versions prior to v14 SP1 Update 10 SIMATIC WinCC Runtime Professional v14: All versions prior to v14 SP1 Update 10 SIMATIC STEP 7 (TIA Portal) v15: All versions prior to v15.1 Update 5 SIMATIC STEP 7 (TIA Portal) v16: All versions prior to v16 Update 2 SIMATIC WinCC OA v3.16: All versions prior to P018 SIMATIC WinCC OA v3.17: All versions prior to P003 SIMATIC WinCC Runtime Advanced: All versions prior to v16 Update 2 SIMATIC WinCC Runtime Professional v13: All versions prior to v13 SP2 Update 4 SIMATIC WinCC Runtime Professional v14: All versions SIMATIC WinCC Runtime Professional v15: All versions prior to v15.1 Update 5 SIMATIC WinCC Runtime Professional v16: All versions prior to v16 Update 2 SIMATIC WinCC v7.4: All versions prior to v7.4 SP1 Update 14 SIMATIC WinCC v7.5: All versions prior to v7.5 SP1 Update 3 SINAMICS Startdrive: All versions SINEMA Server: All versions prior to v14 SP3 SIMATIC ProSave: All versions prior to v17 SIMATIC NET PC software v14: All versions prior to v14 Update 14 SIMATIC NET PC software v15: All versions SIMATIC NET PC software v16: All versions prior to v16 Upd3 SINUMERIK ONE virtual: All versions prior to v6.14 SINUMERIK Operate: All versions prior to v6.14 SIMATIC Automation Tool: All versions prior to v4 SP2 SINEC NMS: All versions prior to v1.0 SP2.,CVE-2020-7580,8.8,High,CWE-428,Chemical; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1839,11/9/2021,11/24/2021,2021,ICSMA-21-313-01,Philips MRI 1.5T and 3T,Philips,MRI 1.5T and 3T,Philips reports the vulnerabilities affect the following MRI products: MRI 1.5T: Version 5.x.x MRI 3T: Version 5.x.x.,"CVE-2021-26248, CVE-2021-26262, CVE-2021-42744",6.2,Medium,"CWE-200, CWE-284, CWE-708",Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1838,11/9/2021,11/9/2021,2021,ICSA-21-313-01,Schneider Electric NMC cards and Embedded Devices,Schneider Electric,NMC cards and Embedded Devices,"The following products are affected, see Schneider Electric's Security Notification SEVD-2021-313-03 for more details on the affected products: Uninterruptible Power Supply (UPS) Products 1-Phase Uninterruptible Power Supply (UPS) using NMC2, including Smart-UPS, Symmetra, and Galaxy 3500 with Network Management Card 2 (NMC2): NMC2 AOS v6.9.8 and prior 3-Phase Uninterruptible Power Supply (UPS) using NMC2, including Symmetra PX 250/500 (SYPX) Network Management Card 2 (NMC2): NMC2 AOS v6.9.6 and prior 3-Phase Uninterruptible Power Supply (UPS) using NMC2 including Symmetra PX 48/96/100/160 kW UPS (PX2), Symmetra PX 20/40 kW UPS (SY3P), Gutor (SXW, GVX), and Galaxy (GVMTS, GVMSA, GVXTS, GVXSA, G7K, GFC, G9KCHU): NMC2 AOS v6.9.6 and prior 1-Phase Uninterruptible Power Supply (UPS) using NMC3 including Smart-UPS, Symmetra, and Galaxy 3500 with Network Management Card 3 (NMC3): NMC3 AOS v1.4.2.1 and prior APC Power Distribution Products APC Rack Power Distribution Units (PDU) using NMC2: NMC2 AOS v6.9.6 and prior APC Rack Power Distribution Units (PDU) using NMC3: NMC3 AOS v1.4.0 and prior APC 3-Phase Power Distribution Products using NMC2: NMC2 AOS v6.9.6 and prior Network Management Card 2 (NMC2) for InfraStruxure 150 kVA PDU with 84 Poles (X84P): NMC2 AOS v6.9.6 and prior Network Management Card 2 for InfraStruxure 40/60kVA PDU (XPDU): NMC2 AOS v6.9.6 and prior Network Management Card 2 for Modular 150/175kVA PDU (XRDP): NMC2 AOS v6.9.6 and prior Network Management Card 2 for 400 and 500 kVA (PMM): NMC2 AOS v6.9.6 and prior Network Management Card 2 for Modular PDU (XRDP2G): NMC2 AOS v6.9.6 and prior Rack Automatic Transfer Switches (ATS): NMC2 AOS v6.9.6 and prior Environmental Monitoring Environmental Monitoring Unit with embedded NMC2 (NB250) NetBotz NBRK0250: NMC2 AOS v6.9.6 and prior Cooling Products Network Management Card 2 (NMC2) Cooling Products: NMC2 AOS v6.9.6 and prior Battery Management Products Network Management Card 2 (NMC2) AP9922 Battery Management System (BM4): NMC2 AOS v6.9.6 and prior.","CVE-2021-22810, CVE-2021-22811, CVE-2021-22812, CVE-2021-22813, CVE-2021-22814, CVE-2021-22815",6.8,Medium,"CWE-200, CWE-79",Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1837,11/9/2021,11/9/2021,2021,ICSA-21-313-02,Schneider Electric GUIcon,Schneider Electric,GUIcon,The following versions of GUIcon software are affected GUIcon: Versions 2.0 (Build 683.003) and prior.,"CVE-2021-22807, CVE-2021-22808, CVE-2021-22809",7.8,High,"CWE-125, CWE-787, CWE-416",Critical Manufacturing,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1836,11/9/2021,11/17/2021,2021,ICSA-21-313-03,Siemens Nucleus RTOS TCP/IP Stack,Siemens,Nucleus RTOS TCP/IP Stack,The following products and versions of the Nucleus RTOS are affected: Capital VSTAR: All versions Nucleus NET: All versions Nucleus ReadyStart v3: All versions prior to v2017.02.4 Nucleus ReadyStart v4: All versions prior to v4.1.1 Nucleus Source Code: All versions.,"CVE-2021-31344, CVE-2021-31345, CVE-2021-31346, CVE-2021-31881, CVE-2021-31882, CVE-2021-31883, CVE-2021-31884, CVE-2021-31885, CVE-2021-31886, CVE-2021-31887, CVE-2021-31888, CVE-2021-31889, CVE-2021-31890",9.8,Critical,"CWE-843, CWE-805, CWE-240, CWE-170, CWE-119, CWE-1284, CWE-191, CWE-125",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1835,11/9/2021,11/10/2021,2021,ICSA-21-313-04,mySCADA myDESIGNER,mySCADA Technologies,myDESIGNER,The following versions of mySCADA myDESIGNER project creation software are affected: myDESIGNER: Versions 8.20.0 and prior.,CVE-2021-43555,7.3,High,CWE-23,Energy; Food and Agriculture; Transportation Systems; Water and Wastewater Systems,Worldwide,Czech Republic,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1834,11/9/2021,11/10/2021,2021,ICSA-21-313-05,OSIsoft PI Vision,OSIsoft,OSIsoft PI Vision,"The following versions of PI Vision, a data management platform, are affected: PI:Vision: All versions prior to 2021.","CVE-2021-43551, CVE-2021-43553",6.5,Medium,"CWE-79, CWE-863",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1833,11/9/2021,11/10/2021,2021,ICSA-21-313-06,OSIsoft PI Web API,OSIsoft,OSIsoft PI Web API,"The following versions of PI Web API, a data management platform, are affected: All versions of PI Web API 2019 SPI and prior.",CVE-2021-43549,6.9,Medium,CWE-79,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1832,6/22/2021,11/10/2021,2021,ICSA-21-173-01,Advantech WebAccess HMI Designer (Update A),Advantech,WebAccess HMI Designer,The following versions of Advantech WebAccess HMI Designer are affected: WebAccess HMI Designer Versions 2.1.9.95 and prior.,"CVE-2021-33000, CVE-2021-33002, CVE-2021-33004",7.8,High,"CWE-122, CWE-119, CWE-787",Critical Manufacturing; Energy; Water and Wastewater,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1831,11/4/2021,11/4/2021,2021,ICSMA-21-308-01,Philips Tasy EMR,Philips,Tasy EMR,Philips reports these vulnerabilities affect the following Philips Healthcare Tasy Electronic Medical Record (EMR) products: Tasy EMR HTML5 3.06.1803 and prior.,"CVE-2021-39375, CVE-2021-39376",8.8,High,CWE-89,Healthcare and Public Health,"Argentina, Brazil, Colombia, Dominican Republic, Mexico",Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1830,11/4/2021,11/9/2021,2021,ICSA-21-308-01,VISAM VBASE Editor,VISAM,VBASE Editor,"The following version of VISAM VBASE Editor, an automation platform, are affected: VBASE Pro-RT/ Server-RT (Web Remote): Version 11.6.0.6.","CVE-2021-34803, CVE-2021-38417, CVE-2021-42535, CVE-2021-42537, CVE-2020-13699, CVE-2019-18988, CVE-2018-14333, CVE-2018-16550, CVE-2005-2475",7.4,High,"CWE-284, CWE-79, CWE-611, CWE-1035",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1829,11/4/2021,11/4/2021,2021,ICSA-21-308-02,AzeoTech DAQFactory,AzeoTech,DAQFactory,"The following versions of DAQFactory, a software and application development platform, are affected: DAQFactory: All Versions 18.1 Build 2347 and prior.","CVE-2021-42543, CVE-2021-42698, CVE-2021-42699, CVE-2021-42701",7.8,High,"CWE-319, CWE-502, CWE-471, CWE-242",Critical Manufacturing; Energy; Water and Wastewater Systems,"United States, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1828,11/2/2021,11/2/2021,2021,ICSA-21-306-01,Sensormatic Electronics VideoEdge,Sensormatic Electronics LLC (Subsidiary of Johnson Controls),VideoEdge,"The following versions of VideoEdge, a network video recorder, are affected: VideoEdge: All versions prior to v5.7.1.",CVE-2020-11023,6.1,Medium,CWE-79,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1827,10/4/2018,11/2/2021,2021,ICSA-18-277-01,WECON PI Studio (Update A),WECON,PI Studio,The following versions of PI Studio - HMI project programmer are affected: PI Studio HMI: Versions 4.1.9 and prior | PI Studio Versions.,"CVE-2018-14818, CVE-2018-14810, CVE-2018-17889, CVE-2018-14814",9.8,Critical,"CWE-611, CWE-125, CWE-787, CWE-121",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1826,10/28/2021,10/29/2021,2021,ICSA-21-301-01,Sensormatic Electronics victor,Sensormatic Electronics LLC (Subsidiary of Johnson Controls),victor,"The following versions of victor, a video management system, are affected: victor: Versions 5.7 and prior.",CVE-2019-19492,7.8,High,CWE-798,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1825,10/7/2021,7/7/2022,2021,ICSA-21-280-04,Mitsubishi Electric MELSEC iQ-R Series C Controller Module (Update B),Mitsubishi Electric,MELSEC iQ-R Series C Controller Module R12CCPU-V,The following modules of the MELSEC iQ-R Series C Controller Module are affected: --------- Begin Update B Part 1 of 2 --------- R12CCPU-V: All versions --------- End Update B Part 1 of 2 ---------.,CVE-2021-20600,6.8,Medium,CWE-400,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1824,8/26/2021,10/28/2021,2021,ICSA-21-238-04,Delta Electronics DOPSoft (Update A),Delta Electronics,DOPSoft,The following versions of DOPSoft are affected: DOPSoft Version 4.00.11 and prior.,CVE-2021-33019,7.8,High,CWE-121,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1823,10/26/2021,10/28/2021,2021,ICSA-21-299-01,Fuji Electric Tellus Lite V-Simulator and V-Server Lite,Fuji Electric,Tellus Lite V-Simulator and V-Server Lite,The following Fuji Electric remote monitoring and operation software products are affected: V-Server Lite: Versions prior to v4.0.12.0 Tellus Lite V-Simulator: Versions prior to v4.0.12.0.,"CVE-2021-38401, CVE-2021-38409, CVE-2021-38413, CVE-2021-38415, CVE-2021-38419, CVE-2021-38421",7.8,High,"CWE-824, CWE-122, CWE-125, CWE-787, CWE-121, CWE-822",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1822,10/21/2021,10/20/2022,2021,ICSMA-21-294-01,B. Braun Infusomat Space Large Volume Pump (Update A),B. Braun Melsungen AG,Infusomat Space Large Volume Pump,"B. Braun reports these vulnerabilities affect the following products in the following areas: Within the United States and Canada: Battery pack SP with WiFi: All software Versions 028U000061 and earlier, which have been installed in an Infusomat Space Infusion Pump or a Perfusor Space Infusion pump SpaceStation with SpaceCom 2: All software Versions 012U000061 and earlier Outside the United States and Canada: Battery Pack SP with Wi-Fi: All software Versions L81 and earlier that have been installed in a Perfusor Space, Infusomat Space, or Infusomat Space P pump SpaceStation with SpaceCom 2: All software Versions L81 and earlier Data module compactPlus: All software Versions A10 and A11 that have been installed in a Perfusor compactPlus, Infusomat compactPlus, or Infusomat P compactPlus pump","CVE-2021-33882, CVE-2021-33883, CVE-2021-33884, CVE-2021-33885, CVE-2021-33886",9.0,Critical,"CWE-319, CWE-20, CWE-345, CWE-306, CWE-434",Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1821,10/21/2021,10/21/2021,2021,ICSA-21-294-01,ICONICS GENESIS64 and Mitsubishi Electric MC Works64,"ICONICS, Mitsubishi Electric",MC Works64,"The vulnerabilities affect the following HMI SCADA products: GENESIS64 (all versions up to and including 10.97) MC Works64 (all version of MC Works64, up to and including Version 4.04E).","CVE-2021-27040, CVE-2021-27041",7.8,High,"CWE-125, CWE-787",Multiple Critical Sectors; Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1820,10/21/2021,10/21/2021,2021,ICSA-21-294-01,ICONICS GENESIS64 and Mitsubishi Electric MC Works64,"ICONICS, Mitsubishi Electric",MC Works64,"The vulnerabilities affect the following HMI SCADA products: GENESIS64 (all versions up to and including 10.97) MC Works64 (all version of MC Works64, up to and including Version 4.04E).","CVE-2021-27040, CVE-2021-27041",7.8,High,"CWE-125, CWE-787",Multiple Critical Sectors; Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1819,10/21/2021,10/21/2021,2021,ICSA-21-294-02,Delta Electronics DIALink,Delta Electronics,DIALink,The following versions of the DIALink industrial automation server are affected: DIALink: Versions 1.2.4.0 and prior.,"CVE-2021-38403, CVE-2021-38407, CVE-2021-38411, CVE-2021-38416, CVE-2021-38418, CVE-2021-38420, CVE-2021-38422, CVE-2021-38424, CVE-2021-38428, CVE-2021-38488",8.8,High,"CWE-312, CWE-319, CWE-1236, CWE-79, CWE-276, CWE-427",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1818,10/21/2021,10/21/2021,2021,ICSA-21-294-03,ICONICS GENESIS64 and Mitsubishi Electric MC Works64 OPC UA,"ICONICS, Mitsubishi Electric",MC Works64 OPC UA,The following ICONICS and Mitsubishi Electric modules are affected in some third-party OPC Foundation products: GENESIS64: Versions 10.97 and prior Hyper Historian: Versions 10.97 and prior AnalytiX: Versions 10.97 and prior MobileHMI: Versions 10.97 and prior MC Works64: Versions 4.04E and prior.,CVE-2021-27432,7.5,High,CWE-674,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1817,10/21/2021,10/21/2021,2021,ICSA-21-294-03,ICONICS GENESIS64 and Mitsubishi Electric MC Works64 OPC UA,"ICONICS, Mitsubishi Electric",MC Works64 OPC UA,The following ICONICS and Mitsubishi Electric modules are affected in some third-party OPC Foundation products: GENESIS64: Versions 10.97 and prior Hyper Historian: Versions 10.97 and prior AnalytiX: Versions 10.97 and prior MobileHMI: Versions 10.97 and prior MC Works64: Versions 4.04E and prior.,CVE-2021-27432,7.5,High,CWE-674,Multiple Critical Sectors,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1816,10/19/2021,10/21/2021,2021,ICSA-21-292-01,AUVESY Versiondog,AUVESY,Versiondog,"The following versions of Versiondog, a data management software for automated production, are affected: Versiondog: All versions prior to v8.0.","CVE-2021-38449, CVE-2021-38451, CVE-2021-38453, CVE-2021-38455, CVE-2021-38457, CVE-2021-38459, CVE-2021-38461, CVE-2021-38463, CVE-2021-38465, CVE-2021-38467, CVE-2021-38469, CVE-2021-38471, CVE-2021-38473, CVE-2021-38475, CVE-2021-38477, CVE-2021-38479, CVE-2021-38481",9.8,Critical,"CWE-15, CWE-119, CWE-123, CWE-125, CWE-20, CWE-284, CWE-294, CWE-321, CWE-400, CWE-416, CWE-434, CWE-427, CWE-73, CWE-732, CWE-787, CWE-89",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1815,10/19/2021,10/19/2021,2021,ICSA-21-292-02,Trane HVAC Systems Controls,Trane,Trane HVAC Systems Controls,"The following versions of Trane building automation products, a device used to coordinate building controls, is affected: Tracer SC: Firmware v3.8 and prior.",CVE-2021-42534,6.3,Medium,CWE-79,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1814,10/14/2021,10/14/2021,2021,ICSA-21-287-01,Schneider Electric CNM,Schneider Electric,CNM,"The following versions of CNM, ethernet network management software, are affected: ConneXium Network Manager: All versions.",CVE-2021-22801,7.8,High,CWE-269,Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1813,10/14/2021,10/18/2021,2021,ICSA-21-287-02,Uffizio GPS Tracker,Uffizio,GPS Tracker,All versions of GPS Tracker software.,"CVE-2021-32927, CVE-2021-32929, CVE-2020-17483, CVE-2020-17484, CVE-2020-17485",9.8,Critical,"CWE-352, CWE-284, CWE-79, CWE-434, CWE-601",Transportation Systems,Worldwide,India,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1812,8/6/2021,4/18/2024,2021,ICSA-21-287-03,Mitsubishi Electric MELSEC iQ-R Series (Update B),Mitsubishi Electric,MELSEC iQ-R Series CPU Module,"Mitsubishi Electric reports the vulnerability affects the following MELSEC CPU Modules: MELSEC iQ-R series Safety CPU R08SFCPU: Firmware versions ""26"" and prior MELSEC iQ-R series Safety CPU R16SFCPU: Firmware versions ""26"" and prior MELSEC iQ-R series Safety CPU R32SFCPU: Firmware versions ""26"" and prior MELSEC iQ-R series Safety CPU R120SFCPU: Firmware versions ""26"" and prior MELSEC iQ-R series SIL2 Process CPU R08PSFCPU: Firmware versions ""11"" and prior MELSEC iQ-R series SIL2 Process CPU R16PSFCPU: Firmware versions ""11"" and prior MELSEC iQ-R series SIL2 Process CPU R32PSFCPU: Firmware versions ""11"" and prior MELSEC iQ-R series SIL2 Process CPU R120PSFCPU: Firmware versions ""11"" and prior.",CVE-2021-20599,9.1,Critical,CWE-319,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1811,10/14/2021,10/14/2021,2021,ICSA-21-287-04,Siemens SINUMERIK,Siemens,SINUMERIK,The following versions of SINUMERIK controllers are affected: SINUMERIK 808D: All versions SINUMERIK 828D: All versions prior to v4.95.,CVE-2021-37199,7.5,High,CWE-122,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1810,10/14/2021,10/14/2021,2021,ICSA-21-287-05,Siemens SINEC NMS,Siemens,SINEC NMS,The following versions of Siemens SINEC NMS software are affected: SINEC NMS: Versions prior to v1.0 SP2 Update 1.,"CVE-2021-33722, CVE-2021-33723, CVE-2021-33724, CVE-2021-33725, CVE-2021-33726, CVE-2021-33727, CVE-2021-33728, CVE-2021-33729, CVE-2021-33730, CVE-2021-33731, CVE-2021-33732, CVE-2021-33733, CVE-2021-33734, CVE-2021-33735, CVE-2021-33736",8.8,High,"CWE-22, CWE-89, CWE-200, CWE-285, CWE-502",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1809,10/14/2021,10/14/2021,2021,ICSA-21-287-06,Siemens Solid Edge,Siemens,Solid Edge,The following Siemens products are affected: Solid Edge SE2021: All versions prior to SE2021MP8.,"CVE-2021-37202, CVE-2021-37203, CVE-2021-41533, CVE-2021-41534, CVE-2021-41535, CVE-2021-41536, CVE-2021-41537, CVE-2021-41538, CVE-2021-41539, CVE-2021-41540",7.8,High,"CWE-824, CWE-125, CWE-416",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1808,10/14/2021,10/13/2022,2021,ICSA-21-287-07,Siemens SCALANCE (Update A),Siemens,SCALANCE,"The following versions of SCALANCE W1750D, a software management platform, are affected: SCALANCE W1750D: All versions prior to v8.7.1.3 --------- Begin Update A part 1 of 3 --------- SCALANCE W1750D: All version 8.7.1.9 and prior (Only affected by CVE-2019-5318) SCALANCE W1750D: All versions from 8.7.1.3 to 8.7.1.8 (Only affected by CVE-2019-5318, CVE-2020-37719, CVE-2021-37717, CVE-2021-37718, CVE-2021-37720, CVE-2021-37721, CVE-2021-37722, CVE-2021-37728) --------- End Update A part 1 of 3 ---------.","CVE-2021-37716, CVE-2021-37717, CVE-2021-37718, CVE-2021-37720, CVE-2021-37721, CVE-2021-37722, CVE-2021-37723, CVE-2021-37724, CVE-2021-37725, CVE-2021-37728, CVE-2021-37729, CVE-2021-37731, CVE-2021-37733, CVE-2020-3771, CVE-2019-5318",9.8,Critical,"CWE-120, CWE-352, CWE-22, CWE-77, CWE-78, CWE-311",Chemical; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1807,10/14/2021,12/22/2021,2021,ICSA-21-287-08,Siemens RUGGEDCOM ROX Devices,Siemens,RUGGEDCOM ROX Devices,"The following versions of RUGGEDCOM ROX, switches and serial-to-Ethernet devices, are affected: RUGGEDCOM ROX MX5000: All versions prior to v2.14.1 RUGGEDCOM ROX RX1400: All versions prior to v2.14.1 RUGGEDCOM ROX RX1500: All versions prior to v2.14.1 RUGGEDCOM ROX RX1501: All versions prior to v2.14.1 RUGGEDCOM ROX RX1510: All versions prior to v2.14.1 RUGGEDCOM ROX RX1511: All versions prior to v2.14.1 RUGGEDCOM ROX RX1512: All versions prior to v2.14.1 RUGGEDCOM ROX RX1524: All versions prior to v2.14.1 RUGGEDCOM ROX RX1536: All versions prior to v2.14.1 RUGGEDCOM ROX RX5000: All versions prior to v2.14.1.",CVE-2021-41546,7.5,High,CWE-400,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1806,10/14/2021,10/14/2021,2021,ICSA-21-287-09,Siemens SIMATIC Process Historian,Siemens,SIMATIC Process Historian,"The following versions of SIMATIC Process Historian, a long-term archive system, are affected: SIMATIC Process Historian 2013 and earlier: All versions SIMATIC Process Historian 2014: All versions prior to SP3 Update 6 SIMATIC Process Historian 2019: All versions SIMATIC Process Historian 2020: All versions.",CVE-2021-27395,9.8,Critical,CWE-306,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1805,9/16/2021,10/14/2021,2021,ICSA-21-259-01,Siemens RUGGEDCOM ROX (Update A),Siemens,RUGGEDCOM ROX,The following versions of RUGGEDCOM ROX are affected: RUGGEDCOM ROX MX5000: All versions prior to v2.14.1 RUGGEDCOM ROX RX1400: All versions prior to v2.14.1 RUGGEDCOM ROX RX1500: All versions prior to v2.14.1 RUGGEDCOM ROX RX1501: All versions prior to v2.14.1 RUGGEDCOM ROX RX1510: All versions prior to v2.14.1 RUGGEDCOM ROX RX1511: All versions prior to v2.14.1 RUGGEDCOM ROX RX1512: All versions prior to v2.14.1 RUGGEDCOM ROX RX1524: All versions prior to v2.14.1 RUGGEDCOM ROX RX1536: All versions prior to v2.14.1 RUGGEDCOM ROX RX5000: All versions prior to v2.14.1.,"CVE-2021-37173, CVE-2021-37174, CVE-2021-37175",8.8,High,"CWE-250, CWE-280, CWE-269",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1804,9/14/2021,10/14/2021,2021,ICSA-21-257-10,Siemens SIPROTEC 5 relays (Update A),Siemens,SIPROTEC 5 relays,The following versions of SIPROTEC 5 relays are affected: SIPROTEC 5 relays with CPU variants CP050: All versions prior to 8.80 SIPROTEC 5 relays with CPU variants CP100: All versions prior to 8.80 SIPROTEC 5 relays with CPU variants CP300: All versions prior to 8.80.,"CVE-2021-33719, CVE-2021-33720",9.8,Critical,CWE-120,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1803,9/14/2021,10/14/2021,2021,ICSA-21-257-16,Siemens SIPROTEC 5 (Update A),Siemens,SIPROTEC 5,The following Siemens products are affected: SIPROTEC 5 relays with CPU variants CP050: All versions prior to v8.80 SIPROTEC 5 relays with CPU variants CP100: All versions prior to v8.80; SIPROTEC 5 relays with CPU variants CP200: All versions; SIPROTEC 5 relays with CPU variants CP300: All versions prior to v8.80.,CVE-2021-37206,7.5,High,CWE-20,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1802,7/13/2021,4/14/2022,2021,ICSA-21-194-03,Siemens PROFINET Devices (Update D),Siemens,PROFINET Devices,"The following Siemens products are affected:SIMATIC PROFINET Driver: SIMATIC PROFINET Driver: All versions prior to v2.3 SIMATIC NET CM 1542-1: All versions prior to v3.0 SCALANCE X204-2 (incl. SIPLUS NET variant): All versions prior to v5.2.5 SCALANCE X204-2FM: All versions prior to v5.2.5 SCALANCE X204-2LD (incl. SIPLUS NET variant): All versions prior to v5.2.5 SCALANCE X20204-2LD TS: All versions prior to v5.2.5 SCALANCE X204 -2TS: All versions prior to v5.2.5 SCALANCE X206-1: All versions prior to v5.2.5 SCALANCE X206-1LD (incl. SIPLUS NET variant): All versions prior to v5.2.5 SCALANCE X208 (incl. SIPLUS NET variant): All versions prior to v5.2.5 SCALANCE X208PRO: All versions prior to v5.2.5 SCALANCE X212-2: All versions prior to v5.2.5 SCALANCE X12-2LD: All versions prior to v5.2.5 SCALANCE X216: All versions prior to v5.2.5 SCALANCE X224: All versions prior to v5.2.5 Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller: All versions Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200: All versions Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200P: All versions RUGGEDCOM RM1224: All versions prior to v6.4 SCALANCE M-800: All versions prior to v6.4 SCALANCE S615: All versions prior to v6.4 SCALANCE W700 IEEE 802.11n: All versions SCALANCE W700 IEEE 802.11ac: All versions SCALANCE X200-4 P IRT: All versions prior to v5.5.0 SCALANCE X201-3P IRT: All versions prior to v5.5.0 SCALANCE X201-3P IRT PRO: All versions prior to v5.5.0 SCALANCE X202-2 IRT: All versions prior to v5.5.0 SCALANCE X202-2P IRT (incl. SIPLUS NET variant): All versions prior to v5.5.0 SCALANCE X202-2P IRT PRO: All versions prior to v5.5.0 SCALANCE X204 IRT: All versions prior to v5.5.0 SCALANCE X204 IRT PRO: All versions prior to v5.5.0 SCALANCE X204-2 (incl. SIPLUS NET variant): All versions SCALANCE X204-2FM: All versions SCALANCE X204-2LD (incl. SIPLUS NET variant): All versions SCALANCE X20204-2LD TS: All versions SCALANCE X204 -2TS: All versions SCALANCE X206-1: All versions SCALANCE X206-1LD (incl. SIPLUS NET variant): All versions SCALANCE X208 (incl. SIPLUS NET variant): All versions SCALANCE X208PRO: All versions SCALANCE X212-2: All versions SCALANCE X12-2LD: All versions SCALANCE X216: All versions SCALANCE X224: All versions SCALANCE X302-7EEC: All versions SCALANCE 304-2FE: All versions Update D SCALANCE W1748-1 M12: All versions prior to v3.0.0 SCALANCE W1788-1 M12: All versions prior to v3.0.0 SCALANCE W1788-2 EEC M12: All versions prior to v3.0.0 SCALANCE W1788-2 M12: All versions prior to v3.0.0 SCALANCE W1788-2IA M12: All versions prior to v3.0.0 SCALANCE X302-7EEC: All versions prior to v4.1.4 SCALANCE X306-1LDFE: All versions prior to v4.1.4 SCALANCE X307-2EEC: All versions prior to v4.1.4 SCALANCE X307-3: All versions prior to v4.1.4 SCALANCE X307-3LD: All versions prior to v4.1.4 SCALANCE X308-2 (incl. SIPLUS NET variant) All versions prior to v4.1.4 SCALANCE X308-2LD: All versions prior to v4.1.4 SCALANCE X308-2LH: All versions prior to v4.1.4 SCALANCE X308-2LH+: All versions prior to v4.1.4 SCALANCE X308-2M: All versions prior to v4.1.4 SCALANCE X308-2M POE: All versions prior to v4.1.4 SCALANCE X308-2M TS: All versions prior to v4.1.4 SCALANCE X310: All versions prior to v4.1.4 SCALANCE X310FE: All versions prior to v4.1.4 SCALANCE X320-1FE: All versions prior to v4.1.4 SCALANCE X320-3LDFE: All versions prior to v4.1.4 SCALANCE X408-2: All versions prior to v4.1.4 End Update D SCALANCE XB-200: All versions SCALANCE XC-200: All versions SCALANCE XF201-3P IRT: All versions prior to v5.5.0 SCALANCE XF202-2P IRT: All versions prior to v5.5.0 SCALANCE XF204: All versions SCALANCE XF204 IRT: All versions prior to v5.5.0 SCALANCE XF204-2 (incl. SIPLUS NET variant): All versions SCALANCE XF204-2BA IRT: All versions prior to v5.5.0 SCALANCE XF206-1: All versions SCALANCE XF208: All versions SCALANCE XF-200BA: All versions SCALANCE XM400: All versions prior to v6.3.1 SCALANCE XP-200: All versions SCALANCE XR324-4M EEC: All versions SCALANCE XR324-4M POE: All versions SCALANCE XR324-4M POE TS: All versions SCALANCE XR324-12M: All versions SCALANCE XR324-12M TS: All versions SCALANCE XR500: All versions prior to v6.3.1 SCALANCE XR-300WG: All versions SIMATIC CFU PA: All versions SIMATIC IE/PB-LINK V3: All versions SIMATIC MV500 family: All versions prior to v3.0 SIMATIC NET CM 1542-1: All versions SIMATIC NET CP1616/CP1604: All Versions 2.7 and prior SIMATIC NET CP1626: All versions SIMATIC NET DK-16xx PN IO: All Versions 2.7 and prior SIMATIC Power Line Booster PLB, Base Module (MLFB: 6ES7972-5AA10-0AB0): All versions SIMATIC S7-1200 CPU family (incl. SIPLUS variants): All versions prior to v4.5 SIMOCODE proV Ethernet/IP: All versions prior to v1.1.3 SIMOCODE proV PROFINET: All versions prior to v2.1.3 SOFTNET-IE PNIO: All versions",CVE-2020-28400,7.5,High,CWE-770,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1801,5/11/2021,5/11/2021,2021,ICSA-21-131-12,Siemens SIMATIC SmartVNC HMI WinCC Products (Update B),Siemens,SIMATIC SmartVNC HMI WinCC Products,"The following Siemens SIMATIC HMIs/WinCC products are affected: SIMATIC HMI Comfort Outdoor Panels 7' and 15' (incl. SIPLUS variants): All versions prior to v16 Update 4 SIMATIC HMI Comfort Panels 4'-22' (incl. SIPLUS variants): All versions prior to v16 Update 4 SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900, KTP900F: All versions prior to v16 Update 4 SIMATIC WinCC Runtime Advanced: All versions prior to v16 Update 4.","CVE-2021-25660, CVE-2021-25661, CVE-2021-25662, CVE-2021-27383, CVE-2021-27384, CVE-2021-27385, CVE-2021-27386",9.8,Critical,"CWE-788, CWE-755, CWE-119, CWE-400",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1800,5/11/2021,5/11/2021,2021,ICSA-21-131-14,Siemens SCALANCE W1750D (Update B),Siemens,SCALANCE W1750D,"The following versions of SCALANCE W1750D, a software management platform, are affected: SCALANCE W1750D: All versions prior to 8.7.0 SCALANCE W1750D: Version 8.7.0 (Only affected by CVE-2020-24635, CVE-2020-24636, CVE-2021-25145, CVE-2021-25146, CVE-2021-25155, CVE-2021-25156, CVE-2021-25157, CVE-2021-25158, CVE-2021-25159, CVE-2021-25160, CVE-2021-25161, and CVE-2021-25162).","CVE-2021-25143, CVE-2021-25144, CVE-2021-25145, CVE-2021-25146, CVE-2021-25148, CVE-2021-25149, CVE-2021-25150, CVE-2021-25155, CVE-2021-25156, CVE-2021-25157, CVE-2021-25158, CVE-2021-25159, CVE-2021-25160, CVE-2021-25161, CVE-2021-25162, CVE-2020-24635, CVE-2020-24636, CVE-2019-5317, CVE-2019-5319",9.8,Critical,"CWE-20, CWE-77, CWE-79, CWE-120, CWE-287, CWE-362",Chemical; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1799,2/11/2020,6/16/2022,2021,ICSA-20-042-04,Siemens PROFINET-IO Stack (Update H),Siemens,PROFINET-IO Stack,"Products that include the Siemens PROFINET-IO (PNIO) stack in versions prior to v06.00 are affected. Additionally, Siemens recommends other vendors of PROFINET devices check their products for vulnerable versions of the Siemens PNIO stack as part of the Siemens Development/Evaluation Kits. SIMATIC ET200ecoPN, 4AO U/I 4xM12 (6ES7145-6HD00-0AB0): All versions SIMATIC ET200ecoPN, 8 DIO, DC24V/1,3A, 8xM12 (6ES7147-6BG00-0AB0): All versions SIMATIC ET200ecoPN, 8 DO, DC24V/2A, 8xM12 (6ES7142-6BR00-0AB0): All versions SIMATIC ET200ecoPN, 8AI RTD/TC 8xM12 (6ES7144-6KD50-0AB0): All versions SIMATIC ET200ecoPN, 8AI; 4 U/I; 4 RTD/TC 8xM12 (6ES7144-6KD00-0AB0): All versions SIMATIC ET200ecoPN, 8DI, DC24V, 4xM12 (6ES7141-6BF00-0AB0): All versions SIMATIC ET200ecoPN, 8DI, DC24V, 8xM12 (6ES7141-6BG00-0AB0): All versions SIMATIC ET200ecoPN, 8DO, DC24V/0,5A, 4xM12 (6ES7142-6BF50-0AB0): All versions SIMATIC ET200ecoPN, 8DO, DC24V/1,3A, 4xM12 (6ES7142-6BF00-0AB0): All versions SIMATIC ET200ecoPN, 8DO, DC24V/1,3A, 8xM12 (6ES7142-6BG00-0AB0): All versions SIMATIC ET200ecoPN, 16DI, DC24V, 8xM12 (6ES7141-6BH00-0AB0): All versions SIMATIC ET200ecoPN, 16DO DC24V/1,3A, 8xM12 (6ES7142-6BH00-0AB0): All versions SIMATIC ET200ecoPN: IO-Link Master (6ES7148-6JA00-0AB0): All versions SCALANCE XB-200: All versions prior to v3.0 SCALANCE XC-200: All versions prior to v3.0 SCALANCE XP-200: All versions prior to v3.0 SCALANCE XF-200BA: All versions prior to v3.0 SCALANCE XR-300WG: All versions prior to v3.0 SCALANCE M-800: All versions prior to v4.3 SCALANCE S615: All versions prior to v4.3 Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller: All versions EK-ERTEC 200: All versions prior to 4.5 EK-ERTEC 200P: All versions prior to 4.6 PROFINET Driver for Controller: All versions prior to 2.1 RUGGEDCOM RM1224: All versions prior to 4.3 SCALANCE M-800 / S615: All versions prior to 4.3 SCALANCE W700 IEEE 802.11n: All versions prior to 6.0.1 SCALANCE X-200 switch family (incl. SIPLUS NET variants): All versions SCALANCE X-200IRT switch family (incl. SIPLUS NET variants): All versions prior to 5.3 SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants): All versions SCALANCE XB-200, XC-200, XP-200, XF-200BA and XR-300WG: All versions prior to 3.0 SCALANCE XM-400 switch family: All versions prior to 6.0 SCALANCE XR-500 switch family: All versions prior to 6.0 SIMATIC CP 1616 and CP 1604: all versions prior to 2.8 SIMATIC CP 343-1 (incl. SIPLUS NET variants): All versions SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variants): All versions SIMATIC CP 343-1 ERPC: All versions SIMATIC CP 343-1 LEAN (incl. SIPLUS NET variants): All versions SIMATIC CP 443-1 (incl. SIPLUS NET variants): All versions SIMATIC CP 443-1 Advanced (incl. SIPLUS NET variants): All versions SIMATIC CP 443-1 OPC UA: All versions SIMATIC ET200AL IM 157-1 PN: All versions SIMATIC ET200M IM153-4 PN IO HF (incl. SIPLUS variants): All versions SIMATIC ET200M IM153-4 PN IO ST (incl. SIPLUS variants): All versions SIMATIC ET200MP IM155-5 PN HF (incl. SIPLUS variants): All versions prior to 4.2.0 SIMATIC ET200MP IM155-5 PN ST (incl. SIPLUS variants): All versions prior to 4.1.0 SIMATIC ET200S (incl. SIPLUS variants): all versions SIMATIC ET200SP IM155-6 PN Basic (incl. SIPLUS variants): All versions SIMATIC ET200SP IM155-6 PN HF (incl. SIPLUS variants): All versions prior to 3.3.1 SIMATIC ET200SP IM155-6 PN ST (incl. SIPLUS variants): All versions prior to 4.1.0 SIMATIC ET200ecoPN (except 6ES7141-6BG00-0BB0, 6ES7141-6BH00-0BB0, 6ES7142-6BG00-0BB0, 6ES7142-6BR00-0BB0, 6S7143-6BH00-0BB0, 6ES7146-6FF00-0AB0, 6ES7148-6JD00-0AB0 and 6ES7148-6JG00-0BB0): All versions SIMATIC ET200ecoPN (except 6ES7148-6JD00-0AB0 and 6ES7146-6FF00-0AB0): all versions SIMATIC ET200pro, IM 154-3 PN HF: all versions SIMATIC ET200pro, IM 154-4 PN HF: all versions SIMATIC IPC Support, Package for VxWorks: all versions SIMATIC MV400 family: all versions SIMATIC PN/PN Coupler 6ES7158-3AD01-0XA0 (incl. SIPLUS NET variant): all versions SIMATIC RF180C: all versions SIMATIC RF182C: all versions SIMATIC RF600 family: all versions prior to 3 SIMOTION C: All versions prior v4.5 SIMOTION D (incl. SIPLUS variants): All versions prior to v4.5 SIMOTION P: All versions prior to v4.5 SINAMICS DCP: all versions prior to 1.3 SOFTNET-IE PNIO: all versions --------- Begin Update H Part 1 of 2 --------- SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants): All versions prior to v4.1.4 --------- End Update H Part 1 of 2 ---------.",CVE-2019-13946,7.5,High,CWE-400,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1798,10/10/2019,10/10/2019,2021,ICSA-19-283-01,Siemens Industrial Real-Time (IRT) Devices (Update F),Siemens,Industrial Real-Time (IRT) Devices,"Siemens CP1604/CP1616: All versions prior to 2.8 Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller: All versions prior to 4.1.1 Patch 05 EK-ERTEC 200: All versions prior to 4.5.0 Patch 01 EK-ERTEC 200P: All versions prior to 4.5.0 SCALANCE X-200IRT: All versions prior to 5.2.1 SIMATIC ET 200M: All versions SIMATIC ET 200S: All versions SIMATIC ET 200ecoPN (except 6ES7148-6JD00-0AB0 and 6ES7146-6FF00-0AB0): All versions SIMATIC ET 200pro: All versions SIMATIC PN/PN Coupler 6ES7158-3AD01-0XA0: All versions SIMATIC S7-300 CPU family (incl. F): All versions SIMATIC S7-400 (incl. F) v6 and below: All versions SIMATIC S7-400 PN/DP v7 (incl. F): All versions SIMATIC WinAC RTX (F) 2010: All versions prior to SP3 SIMOTION: All versions SINAMICS DCM: All versions prior to 1.5 HF1 SINAMICS DCP: All versions prior to 1.3 SINAMICS G110M v4.7 (Control Unit): All versions prior to 4.7 SP10 HF5 SINAMICS G120 v4.7 (Control Unit): All versions prior to 4.7 SP10 HF5 SINAMICS G130 v4.7 (Control Unit): All versions prior to 4.7 HF29 SINAMICS G150 (Control Unit): All versions prior to 4.8 SINAMICS GH150 v4.7 (Control Unit): All versions SINAMICS GL150 v4.7 (Control Unit): All versions SINAMICS GM150 v4.7 (Control Unit): All versions SINAMICS S110 (Control Unit): All versions SINAMICS S120 v4.7 (Control Unit and CBE20): All versions prior to 4.7 HF34 SINAMICS S150 (Control Unit): All versions prior to 4.8 SCALANCE X-200IRT switch family (incl. SIPLUS NET variants): All versions prior to 5.2.1 SIMATIC ET 200M (incl. SIPLUS variants): All versions SIMATIC ET 200S (incl. SIPLUS variants): All versions SIMATIC ET 200pro (incl. SIPLUS variants): All versions. SIMATIC ET200ecoPN (except 6ES7141-6BG00-0BB0, 6ES7141-6BH00-0BB0, 6ES7142-6BG00-0BB0, 6ES7142-6BR00-0BB0, 6ES7143-6BH00-0BB0, 6ES7146-6FF00-0AB0, 6ES7148-6JD00-0AB0, and 6ES7148-6JG00-0BB0): All versions. SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions prior to 3.X.17 SIMATIC S7-400 (incl. F) v6 and below CPU family (incl. SIPLUS variants): All versions SIMATIC S7-400 PN/DP v7 CPU family (incl. SIPLUS variants): All versions SIMOTION (incl. SIPLUS variants): All versions SINAMICS G120 v4.7 Control Unit (incl. SIPLUS variants): All versions prior to 4.7 SP10 HF5 SINAMICS S120 v4.7 Control Unit and CBE20 (incl. SIPLUS variants): All versions prior to 4.7 HF34 SINAMICS SL150 v4.7 (Control Unit): All versions prior to 4.7 HF33 SINAMICS SL150 v4.7 (Control Unit): All versions SINAMICS SM120 v4.7 (Control Unit): All versions SINUMERIK 828D: All versions prior to 4.8 SP5 SINUMERIK 840D sl: All versions.",CVE-2019-10923,7.5,High,CWE-20,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Food and Agriculture; Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1797,10/10/2019,12/15/2022,2019,ICSA-19-283-02,Siemens PROFINET Devices (Update L),Siemens,PROFINET Devices,"Siemens reports the vulnerability affects the following PROFINET devices: Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller: All versions EK-ERTEC 200: All version EK-ERTEC 200P: All versions prior to 4.6 Patch 01 SIMATIC S7-410 V8 CPU family (incl. SIPLUS variants): All versions prior to 8.2.2 SIMATIC CFU PA: All versions prior to 1.2.0 SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants): All versions prior to 2.0 SIMATIC ET 200AL: All versions SIMATIC ET 200M (incl. SIPLUS variants): All versions SIMATIC ET 200MP IM 155-5 PN BA (incl. SIPLUS variants): All versions prior to 4.2.3 SIMATIC ET 200MP IM 155-5 PN HF (incl. SIPLUS variants): All versions prior to 4.4.0 SIMATIC ET 200MP IM 155-5 PN ST (incl. SIPLUS variants): All versions SIMATIC ET 200S (incl. SIPLUS variants): All versions SIMATIC ET 200SP IM 155-6 PN BA (incl. SIPLUS variants): All versions SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS variants): All versions prior to 1.2.1 SIMATIC ET 200ecoPN, 4AO U/I 4xM12 (6ES7145-6HD00-0AB0): All versions SIMATIC ET 200ecoPN, 8 DIO, DC24V/1,3A, 8xM12 (6ES7147-6BG00-0AB0): All versions SIMATIC ET 200ecoPN, 8 DO, DC24V/2A, 8xM12 (6ES7142-6BR00-0AB0): All versions SIMATIC ET 200ecoPN, 8AI RTD/TC 8xM12 (6ES7144-6KD50-0AB0): All versions SIMATIC ET 200ecoPN, 8AI; 4 U/I; 4 RTD/TC 8xM12 (6ES7144-6KD00-0AB0): All versions SIMATIC ET 200ecoPN, 8DI, DC24V, 4xM12 (6ES7141-6BF00-0AB0): All versions SIMATIC ET 200ecoPN, 8DI, DC24V, 8xM12 (6ES7141-6BG00-0AB0): All versions SIMATIC ET 200ecoPN, 8DO, DC24V/0,5A, 4xM12 (6ES7142-6BF50-0AB0): All versions SIMATIC ET 200ecoPN, 8DO, DC24V/1,3A, 4xM12 (6ES7142-6BF00-0AB0): All versions SIMATIC ET 200ecoPN, 8DO, DC24V/1,3A, 8xM12 (6ES7142-6BG00-0AB0): All versions SIMATIC ET 200ecoPN, 16DI, DC24V, 8xM12 (6ES7141-6BH00-0AB0): All versions SIMATIC ET 200ecoPN, 16DO DC24V/1,3A, 8xM12 (6ES7142-6BH00-0AB0): All versions SIMATIC ET 200ecoPN, IO-Link Master (6ES7148-6JA00-0AB0): All versions SIMATIC ET 200SP IM 155-6 PN HF (incl. SIPLUS variants): All versions prior to 4.2.2 SIMATIC ET 200SP IM 155-6 PN HS (incl. SIPLUS variants): All versions prior to 4.0.1 SIMATIC ET 200SP IM 155-6 PN ST (incl. SIPLUS variants): All versions SIMATIC ET 200SP IM 155-6 PN/2 HF (incl. SIPLUS variants): All versions prior to 4.2.2 SIMATIC ET 200SP IM 155-6 PN/3 HF (incl. SIPLUS variants): All versions prior to 4.2.1 SIMATIC ET 200pro: All versions SIMATIC HMI Comfort Outdoor Panels 7"" & 15"" (incl. SIPLUS variants): All versions SIMATIC HMI Comfort Panels 4"" - 22"" (incl. SIPLUS variants): All versions SIMATIC HMI KTP Mobile Panels: All versions SIMATIC PROFINET Driver: All versions prior to 2.1 SIMATIC S7-1200 CPU family (incl. SIPLUS variants): All versions prior to 4.4.0 SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions prior to 2.0 SIMATIC S7-1500 CPU Software Controller: All versions prior to 2.0 SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions prior to 3.X.17 SIMATIC S7-400 H V6 CPU family (incl. SIPLUS variants): All versions prior to 6.0.9 SIMATIC S7-400 PN/DP V6 and below CPU family (incl. SIPLUS variants): All versions SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants): All versions SIMATIC TDC CP51M1: All versions prior to 1.1.8 SIMATIC TDC CPU555: All versions prior to 1.1.1 SIMATIC WinAC RTX (F) 2010: All versions prior to SP3 SINAMICS DCM: All versions prior to 1.5 HF1 SINAMICS DCP: All versions prior to 1.3 SINAMICS G110M v4.7 PN Control Unit: All versions prior to 4.7 SP10 HF5 SINAMICS G120 v4.7 PN Control Unit (incl. SIPLUS variants): All versions prior to 4.7 SP10 HF5 SINAMICS G130 v4.7 Control Unit: All versions prior to 4.8 SINAMICS G150 Control Unit: All versions prior to 4.8 SINAMICS GH150 v4.7 Control Unit: All versions SINAMICS GL150 v4.7 Control Unit: All versions SINAMICS GM150 v4.7 Control Unit: All versions SINAMICS S110 Control Unit: All versions SINAMICS S120 v4.7 Control Unit (incl. SIPLUS variants): All versions SINAMICS S150 Control Unit: All versions prior to 4.8 SINAMICS SL150 v4.7 Control Unit: All versions prior to 4.7 HF33 SINAMICS SM120 v4.7 Control Unit: All versions SINUMERIK 828D: All versions prior to 4.8 SP5 --------- Begin Update L Part 1 of 3 --------- SINUMERIK 840D sl: All versions prior to 4.8 SP6 --------- End Update L Part 1 of 3 --------- SIMATIC PN/PN Coupler (incl. SIPLUS NET variants): All versions prior to v4.2.1.",CVE-2019-10936,7.5,High,CWE-400,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1796,3/26/2019,7/14/2022,2019,ICSA-19-085-01,Siemens SCALANCE X (Update D),Siemens,SCALANCE X,"The following SCALANCE products are affected: SCALANCE X204-2 (6GK5204-2BB10-2AA3): All versions SCALANCE X204-2FM (6GK5204-2BB11-2AA3): All versions SCALANCE X204-2LD (6GK5204-2BC10-2AA3): All versions SCALANCE X204-2LD TS (6GK5204-2BC10-2CA2): All versions SCALANCE X204-2TS (6GK5204-2BB10-2CA2): All versions SCALANCE X206-1 (6GK5206-1BB10-2AA3): All versions SCALANCE X206-1LD (6GK5206-1BC10-2AA3): All versions SCALANCE X208 (6GK5208-0BA10-2AA3): All versions SCALANCE X208PRO (6GK5208-0HA10-2AA6): All versions SCALANCE X212-2 (6GK5212-2BB00-2AA3): All versions SCALANCE X212-2LD (6GK5212-2BC00-2AA3): All versions SCALANCE X216 (6GK5216-0BA00-2AA3): All versions SCALANCE X224 (6GK5224-0BA00-2AA3): All versions SCALANCE X302-7 EEC (2x 24V) (6GK5302-7GD00-2EA3): All versions prior to v4.1.3 SCALANCE X302-7 EEC (2x 24V, coated) (6GK5302-7GD00-2GA3): All versions prior to v4.1.3 SCALANCE X302-7 EEC (2x 230V) (6GK5302-7GD00-4EA3): All versions prior to v4.1.3 SCALANCE X302-7 EEC (2x 230V, coated) (6GK5302-7GD00-4GA3): All versions prior to v4.1.3 SCALANCE X302-7 EEC (24V) (6GK5302-7GD00-1EA3): All versions prior to v4.1.3 SCALANCE X302-7 EEC (24V, coated) (6GK5302-7GD00-1GA3): All versions prior to v4.1.3 SCALANCE X302-7 EEC (230V) (6GK5302-7GD00-3EA3): All versions prior to v4.1.3 SCALANCE X302-7 EEC (230V, coated) (6GK5302-7GD00-3GA3): All versions prior to v4.1.3 SCALANCE X304-2FE (6GK5304-2BD00-2AA3): All versions prior to v4.1.3 SCALANCE X306-1LD FE (6GK5306-1BF00-2AA3): All versions prior to v4.1.3 SCALANCE X307-2 EEC (2x 24V) (6GK5307-2FD00-2EA3): All versions prior to v4.1.3 SCALANCE X307-2 EEC (2x 24V, coated) (6GK5307-2FD00-2GA3): All versions prior to v4.1.3 SCALANCE X307-2 EEC (2x 230V) (6GK5307-2FD00-4EA3): All versions prior to v4.1.3 SCALANCE X307-2 EEC (2x 230V, coated) (6GK5307-2FD00-4GA3): All versions prior to v4.1.3 SCALANCE X307-2 EEC (24V) (6GK5307-2FD00-1EA3): All versions prior to v4.1.3 SCALANCE X307-2 EEC (24V, coated) (6GK5307-2FD00-1GA3): All versions prior to v4.1.3 SCALANCE X307-2 EEC (230V) (6GK5307-2FD00-3EA3): All versions prior to v4.1.3 SCALANCE X307-2 EEC (230V, coated) (6GK5307-2FD00-3GA3): All versions prior to v4.1.3 SCALANCE X307-3 (6GK5307-3BL00-2AA3): All versions prior to v4.1.3 SCALANCE X307-3 (6GK5307-3BL10-2AA3): All versions prior to v4.1.3 SCALANCE X307-3LD (6GK5307-3BM00-2AA3): All versions prior to v4.1.3 SCALANCE X307-3LD (6GK5307-3BM10-2AA3): All versions prior to v4.1.3 SCALANCE X308-2 (6GK5308-2FL00-2AA3): All versions prior to v4.1.3 SCALANCE X308-2 (6GK5308-2FL10-2AA3): All versions prior to v4.1.3 SCALANCE X308-2LD (6GK5308-2FM00-2AA3): All versions prior to v4.1.3 SCALANCE X308-2LD (6GK5308-2FM10-2AA3): All versions prior to v4.1.3 SCALANCE X308-2LH (6GK5308-2FN00-2AA3): All versions prior to v4.1.3 SCALANCE X308-2LH (6GK5308-2FN10-2AA3): All versions prior to v4.1.3 SCALANCE X308-2LH+ (6GK5308-2FP00-2AA3): All versions prior to v4.1.3 SCALANCE X308-2LH+ (6GK5308-2FP10-2AA3): All versions prior to v4.1.3 SCALANCE X308-2M (6GK5308-2GG00-2AA2): All versions prior to v4.1.3 SCALANCE X308-2M (6GK5308-2GG10-2AA2): All versions prior to v4.1.3 SCALANCE X308-2M PoE (6GK5308-2QG00-2AA2): All versions prior to v4.1.3 SCALANCE X308-2M PoE (6GK5308-2QG10-2AA2): All versions prior to v4.1.3 SCALANCE X308-2M TS (6GK5308-2GG00-2CA2): All versions prior to v4.1.3 SCALANCE X308-2M TS (6GK5308-2GG10-2CA2): All versions prior to v4.1.3 SCALANCE X310 (6GK5310-0FA00-2AA3): All versions prior to v4.1.3 SCALANCE X310 (6GK5310-0FA10-2AA3): All versions prior to v4.1.3 SCALANCE X310FE (6GK5310-0BA00-2AA3): All versions prior to v4.1.3 SCALANCE X310FE (6GK5310-0BA10-2AA3): All versions prior to v4.1.3 SCALANCE X320-1 FE (6GK5320-1BD00-2AA3): All versions prior to v4.1.3 SCALANCE X320-1-2LD FE (6GK5320-3BF00-2AA3): All versions prior to v4.1.3 SCALANCE X408-2 (6GK5408-2FD00-2AA2): All versions prior to v4.1.3 SCALANCE XB205-3 (SC) (6GK5205-3BD00-2AB2): All versions prior to v4.1 SCALANCE XB205-3 (SC) (6GK5205-3BD00-2TB2): All versions prior to v4.1 SCALANCE XB205-3 (ST/BFOC) (6GK5205-3BB00-2AB2): All versions prior to v4.1 SCALANCE XB205-3 (ST/BFOC) (6GK5205-3BB00-2TB2): All versions prior to v4.1 SCALANCE XB205-3LD (6GK5205-3BF00-2AB2): All versions prior to v4.1 SCALANCE XB205-3LD (6GK5205-3BF00-2TB2): All versions prior to v4.1 SCALANCE XB208 (6GK5208-0BA00-2AB2): All versions prior to v4.1 SCALANCE XB208 (6GK5208-0BA00-2TB2): All versions prior to v4.1 SCALANCE XB213-3 (SC) (6GK5213-3BD00-2AB2): All versions prior to v4.1 SCALANCE XB213-3 (SC) (6GK5213-3BD00-2TB2): All versions prior to v4.1 SCALANCE XB213-3 (ST/BFOC) (6GK5213-3BB00-2AB2): All versions prior to v4.1 SCALANCE XB213-3 (ST/BFOC) (6GK5213-3BB00-2TB2): All versions prior to v4.1 SCALANCE XB213-3LD (6GK5213-3BF00-2AB2): All versions prior to v4.1 SCALANCE XB213-3LD (6GK5213-3BF00-2TB2): All versions prior to v4.1 SCALANCE XB216 (6GK5216-0BA00-2AB2): All versions prior to v4.1 SCALANCE XB216 (6GK5216-0BA00-2TB2): All versions prior to v4.1 SCALANCE XC206-2 (SC) (6GK5206-2BD00-2AC2): All versions prior to v4.1 SCALANCE XC206-2 (ST/BFOC) (6GK5206-2BB00-2AC2): All versions prior to v4.1 SCALANCE XC206-2SFP (6GK5206-2BS00-2AC2): All versions prior to v4.1 SCALANCE XC206-2SFP EEC (6GK5206-2BS00-2FC2): All versions prior to v4.1 SCALANCE XC206-2SFP G (6GK5206-2GS00-2AC2): All versions prior to v4.1 SCALANCE XC206-2SFP G (6GK5206-2GS00-2TC2): All versions prior to v4.1 SCALANCE XC206-2SFP G EEC (6GK5206-2GS00-2FC2): All versions prior to v4.1 SCALANCE XC208 (6GK5208-0BA00-2AC2): All versions prior to v4.1 SCALANCE XC208EEC (6GK5208-0BA00-2FC2): All versions prior to v4.1 SCALANCE XC208G (6GK5208-0GA00-2AC2): All versions prior to v4.1 SCALANCE XC208G (6GK5208-0GA00-2TC2): All versions prior to v4.1 SCALANCE XC208G EEC (6GK5208-0GA00-2FC2): All versions prior to v4.1 SCALANCE XC216 (6GK5216-0BA00-2AC2): All versions prior to v4.1 SCALANCE XC216-4C (6GK5216-4BS00-2AC2): All versions prior to v4.1 SCALANCE XC216-4C G (6GK5216-4GS00-2AC2): All versions prior to v4.1 SCALANCE XC216-4C G (EIP Def.) (6GK5216-4GS00-2TC2): All versions prior to v4.1 SCALANCE XC216-4C G EEC (6GK5216-4GS00-2FC2): All versions prior to v4.1 SCALANCE XC216EEC (6GK5216-0BA00-2FC2): All versions prior to v4.1 SCALANCE XC224 (6GK5224-0BA00-2AC2): All versions prior to v4.1 SCALANCE XC224-4C G (6GK5224-4GS00-2AC2): All versions prior to v4.1 SCALANCE XC224-4C G (EIP Def.) (6GK5224-4GS00-2TC2): All versions prior to v4.1 SCALANCE XC224-4C G EEC (6GK5224-4GS00-2FC2): All versions prior to v4.1 SCALANCE XF204 (6GK5204-0BA00-2AF2): All versions SCALANCE XF204 (6GK5204-0BA00-2GF2): All versions prior to v4.1 SCALANCE XF204 DNA (6GK5204-0BA00-2YF2): All versions prior to v4.1 SCALANCE XF204-2 (6GK5204-2BC00-2AF2): All versions SCALANCE XF204-2BA (6GK5204-2AA00-2GF2): All versions prior to v4.1 SCALANCE XF204-2BA DNA (6GK5204-2AA00-2YF2): All versions prior to v4.1 SCALANCE XF206-1 (6GK5206-1BC00-2AF2): All versions SCALANCE XF208 (6GK5208-0BA00-2AF2): All versions SCALANCE XP208 (6GK5208-0HA00-2AS6): All versions prior to v4.1 SCALANCE XP208 (6GK5208-0HA00-2TS6): All versions prior to v4.1 SCALANCE XP208EEC (6GK5208-0HA00-2ES6): All versions prior to v4.1 SCALANCE XP208PoE EEC (6GK5208-0UA00-5ES6): All versions prior to v4.1 SCALANCE XP216 (6GK5216-0HA00-2AS6): All versions prior to v4.1 SCALANCE XP216 (6GK5216-0HA00-2TS6): All versions prior to v4.1 SCALANCE XP216EEC (6GK5216-0HA00-2ES6): All versions prior to v4.1 SCALANCE XP216POE EEC (6GK5216-0UA00-5ES6): All versions prior to v4.1 SCALANCE XR324-4M EEC (2x 24V, ports on front) (6GK5324-4GG00-2ER2): All versions prior to v4.1.3 SCALANCE XR324-4M EEC (2x 24V, ports on front) (6GK5324-4GG10-2ER2): All versions prior to v4.1.3 SCALANCE XR324-4M EEC (2x 24V, ports on rear) (6GK5324-4GG00-2JR2): All versions prior to v4.1.3 SCALANCE XR324-4M EEC (2x 24V, ports on rear) (6GK5324-4GG10-2JR2): All versions prior to v4.1.3 SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front)(6GK5324-4GG00-4ER2): All versions prior to v4.1.3 SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front)(6GK5324-4GG10-4ER2): All versions prior to v4.1.3 SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear)(6GK5324-4GG00-4JR2): All versions prior to v4.1.3 SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear)(6GK5324-4GG10-4JR2): All versions prior to v4.1.3 SCALANCE XR324-4M EEC (24V, ports on front) (6GK5324-4GG00-1ER2): All versions prior to v4.1.3 SCALANCE XR324-4M EEC (24V, ports on front) (6GK5324-4GG10-1ER2): All versions prior to v4.1.3 SCALANCE XR324-4M EEC (24V, ports on rear) (6GK5324-4GG00-1JR2): All versions prior to v4.1.3 SCALANCE XR324-4M EEC (24V, ports on rear) (6GK5324-4GG10-1JR2): All versions prior to V4.1.3 SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front)(6GK5324-4GG00-3ER2): All versions prior to v4.1.3 SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front)(6GK5324-4GG10-3ER2): All versions prior to v4.1.3 SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG00-3JR2): All versions prior to v4.1.3 SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG10-3JR2): All versions prior to v4.1.3 SCALANCE XR324-4M PoE (24V, ports on front) (6GK5 324-4QG10-1AR2): All versions prior to v4.1.3 SCALANCE XR324-4M PoE (24V, ports on front) (6GK5324-4QG00-1AR2): All versions prior to v4.1.3 SCALANCE XR324-4M PoE (24V, ports on rear) (6GK5 324-4QG10-1HR2): All versions prior to v4.1.3 SCALANCE XR324-4M PoE (24V, ports on rear) (6GK5324-4QG00-1HR2): All versions prior to v4.1.3 SCALANCE XR324-4M PoE (230V, ports on front) (6GK5 324-4QG10-3AR2): All versions prior to v4.1.3 SCALANCE XR324-4M PoE (230V, ports on front) (6GK5324-4QG00-3AR2): All versions prior to v4.1.3 SCALANCE XR324-4M PoE (230V, ports on rear) (6GK5 324-4QG10-3HR2): All versions prior to v4.1.3 SCALANCE XR324-4M PoE (230V, ports on rear) (6GK5324-4QG00-3HR2): All versions prior to v4.1.3 SCALANCE XR324-4M PoE TS (24V, ports on front) (6GK5 324-4QG10-1CR2): All versions prior to v4.1.3 SCALANCE XR324-4M PoE TS (24V, ports on front) (6GK5324-4QG00-1CR2): All versions prior to v4.1.3 SCALANCE XR324-12M (24V, ports on front) (6GK5324-0GG00-1AR2): All versions prior to v4.1.3 SCALANCE XR324-12M (24V, ports on front) (6GK5324-0GG10-1AR2): All versions prior to v4.1.3 SCALANCE XR324-12M (24V, ports on rear) (6GK5324-0GG00-1HR2): All versions prior to v4.1.3 SCALANCE XR324-12M (24V, ports on rear) (6GK5324-0GG10-1HR2): All versions prior to v4.1.3 SCALANCE XR324-12M (230V, ports on front) (6GK5324-0GG00-3AR2): All versions prior to v4.1.3 SCALANCE XR324-12M (230V, ports on front) (6GK5324-0GG10-3AR2): All versions prior to v4.1.3 SCALANCE XR324-12M (230V, ports on rear) (6GK5324-0GG00-3HR2): All versions prior to v4.1.3 SCALANCE XR324-12M (230V, ports on rear) (6GK5324-0GG10-3HR2): All versions prior to v4.1.3 SCALANCE XR324-12M TS (24V) (6GK5324-0GG00-1CR2): All versions prior to v4.1.3 SCALANCE XR324-12M TS (24V) (6GK5324-0GG10-1CR2): All versions prior to v4.1.3 SCALANCE XR324WG (24 x FE, AC 230V) (6GK5324-0BA00-3AR3): All versions prior to v4.1 SCALANCE XR324WG (24 X FE, DC 24V) (6GK5324-0BA00-2AR3): All versions prior to v4.1 SCALANCE XR328-4C WG (24xFE,4xGE,AC230V) (6GK5328-4FS00-3AR3): All versions prior to v4.1 SCALANCE XR328-4C WG (24xFE,4xGE,AC230V) (6GK5328-4FS00-3RR3): All versions prior to v4.1 SCALANCE XR328-4C WG (24XFE, 4XGE, 24V) (6GK5328-4FS00-2AR3): All versions prior to v4.1 SCALANCE XR328-4C WG (24xFE, 4xGE,DC24V) (6GK5328-4FS00-2RR3): All versions prior to v4.1 SCALANCE XR328-4C WG (28xGE, AC 230V) (6GK5328-4SS00-3AR3): All versions prior to v4.1 SCALANCE XR328-4C WG (28xGE, DC 24V) (6GK5328-4SS00-2AR3): All versions prior to v4.1 SIPLUS NET SCALANCE X308-2 (6AG1308-2FL10-4AA3): All versions prior to v4.1.3 SIPLUS NET SCALANCE XC206-2 (6AG1206-2BB00-7AC2): All versions prior to v4.1 SIPLUS NET SCALANCE XC206-2SFP (6AG1206-2BS00-7AC2): All versions prior to v4.1 SIPLUS NET SCALANCE XC208 (6AG1208-0BA00-7AC2): All versions prior to v4.1 SIPLUS NET SCALANCE XC216-4C (6AG1216-4BS00-7AC2): All versions prior to v4.1.",CVE-2019-6569,5.4,Medium,CWE-440,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1795,12/5/2017,12/5/2017,2021,ICSA-17-339-01,Siemens Industrial Products (Update S),Siemens,Industrial Products,"Siemens reports the vulnerability affects the following industrial products: Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller: All versions prior to v4.1.1 Patch 05 Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200P: All versions prior to v4.5 Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200: All versions prior to v4.5 SIMATIC Compact Field Unit: All versions SIMATIC ET 200AL: All versions SIMATIC ET 200M (incl. SIPLUS variants): All versions SIMATIC ET 200MP IM155-5 PN BA (incl. SIPLUS variants): All versions prior to v4.0.2 SIMATIC ET 200MP IM155-5 PN HF (incl. SIPLUS variants): All versions prior to v4.2 SIMATIC ET 200MP IM155-5 PN ST (incl. SIPLUS variants): All versions prior to v4.1 SIMATIC ET 200S (incl. SIPLUS variants): All versions SIMATIC ET 200SP IM 155-6 PN BA (incl. SIPLUS variants): All versions SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS variants): All versions prior to v1.1.0 SIMATIC ET 200SP IM 155-6 PN HF (incl. SIPLUS variants): All versions prior to v4.2.0. SIMATIC ET 200SP IM 155-6 PN HS (incl. SIPLUS variants): All versions prior to v4.0.1. SIMATIC ET 200SP IM 155-6 PN ST (incl. SIPLUS variants): All versions SIMATIC ET 200ecoPN: All versions: (except 6ES7141-6BG00-0BB0, 6ES7141-6BH00-0BB0, 6ES7142-6BG00-0BB0, 6ES7142-6BR00-0BB0, 6S7143-6BH00-0BB0, 6ES7146-6FF00-0AB0, 6ES7148-6JD00-0AB0 and 6ES7148-6JG00-0BB0) SIMATIC ET 200pro: All versions SIMATIC PN/PN Coupler (incl. SIPLUS NET variants): All versions prior to v4.2.0 SIMATIC S7-200 Smart: All versions prior to v2.03.01 SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions prior to v3.X.16 SIMATIC S7-400 H v6 CPU family and below (incl. SIPLUS variants): All versions prior to v6.0.8 SIMATIC S7-400 PN/DP v6 CPU family and below (incl. SIPLUS variants): All versions prior to v6.0.6 SIMATIC S7-400 PN/DP v7 CPU family (incl. SIPLUS variants): All versions prior to v7.0.2 SIMATIC S7-410 v8 CPU family (incl. SIPLUS variants): All versions prior to v8.2.1 SIMATIC S7-1200 CPU family (incl. SIPLUS variants): All versions prior to v4.2.3 SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions prior to v2.0 SIMATIC S7-1500 Software Controller: All versions prior to v2.0 SIMATIC TDC CP51M1: All versions prior to v1.1.8 SIMATIC TDC CPU555: All versions prior to v1.1.1 SIMATIC WinAC RTX (F) 2010: All versions prior to SP3 SIMOCODE pro V PN (incl. SIPLUS variants): All versions prior to v2.1.1 SIMOTION C: All versions prior to v5.1 HF1 SIMOTION D (incl. SIPLUS variants): All versions prior to v5.1 HF1 SIMOTION P v4.4 and v4.5: All versions prior to v4.5 HF5 SIMOTION P v5: All versions prior to v5.1 HF1 SINAMICS DCM w. PN: All versions prior to v1.4 SP1 HF6 SINAMICS DCP w. PN: All versions prior to v1.2 HF2 SINAMICS G110M w. PN: All versions prior to v4.7 SP9 HF1 SINAMICS G120(C/P/D) w. PN (incl. SIPLUS variants): All versions prior to v4.7 SP9 HF1 SINAMICS G130 v4.7 w. PN: All versions prior to v4.7 HF29 SINAMICS G130 v4.8 w. PN: All versions prior to v4.8 HF4 SINAMICS G150 v4.7 w. PN: All versions prior to v4.7 HF29 SINAMICS G150 v4.8 w. PN: All versions prior to v4.8 HF4 SINAMICS S110 w. PN: All versions prior to v4.4 SP3 HF6 SINAMICS S120 v4.7 SP1 w. PN (incl. SIPLUS variants): All versions SINAMICS S120 v4.7 w. PN (incl. SIPLUS variants): All versions prior to v4.7 HF29 SINAMICS S120 v4.8 w. PN: All versions prior to v4.8 HF5 SINAMICS S120 prior to V4.7 w. PN (incl. SIPLUS variants): All versions prior to V4.7 SINAMICS S150 V4.7 w. PN: All versions prior to v4.7 HF29 SINAMICS S150 V4.8 w. PN:All versions prior to v4.8 HF4 SINAMICS v90 w. PN: All versions prior to v1.02 SINUMERIK 840D sl: All versions prior to 4.8 SP3 SIRIUS Soft starter 3RW44 PN: All versions.",CVE-2017-12741,7.5,High,CWE-20,Commercial Facilities; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1794,5/9/2017,5/9/2017,2021,ICSA-17-129-02,Siemens PROFINET DCP (Update U),Siemens,PROFINET DCP,"Siemens reports that these vulnerabilities affect the following products using PROFINET DCP: Development/Evaluation Kits DK Standard Ethernet Controller: All versions prior to v4.1.1 Patch04 Development/Evaluation Kits EK-ERTEC 200P PN IO: All versions prior to v4.4.0 Patch01 Development/Evaluation Kits EK-ERTEC 200 PN IO: All versions prior to v4.2.1 Patch03 IE/AS-i Link PN IO: All versions IE/PB-Link: All versions prior to v3.0 SCALANCE M-800, S615: All versions prior to v04.03 SCALANCE W700: All versions prior to v6.1 SCALANCE X408: All versions prior to v4.1.0 SCALANCE X414: All versions prior to v3.10.2 SCALANCE X-200 switch family (incl. SIPLUS NET variants): All versions prior to v5.2.2 SCALANCE X-200IRT switch family (incl. SIPLUS NET variants): All versions prior to v5.4.0 SCALANCE X-300 switch family (incl. SIPLUS NET variants): All versions prior to v4.1.0 SCALANCE XM-400, XR-500: All versions prior to v6.1 SIMATIC DK-16xx PN IO: All versions prior to v2.7 SIMATIC ET 200AL: All versions prior to v1.0.2 SIMATIC ET200M (incl. SIPLUS variants): All versions SIMATIC ET200MP IM155-5 PN BA (incl. SIPLUS variants): All versions prior to v4.0.1 SIMATIC ET200MP IM155-5 PN HF (incl. SIPLUS variants): All versions prior to v4.2 SIMATIC ET200MP IM155-5 PN ST (incl. SIPLUS variants): All versions prior to v4.1 SIMATIC ET200S (incl. SIPLUS variants): All versions. SIMATIC ET200SP (incl. SIPLUS variants, except IM155-6 PN ST and IM155-6 PN HF): All versions SIMATIC ET200SP IM155-6 PN HF (incl. SIPLUS variants): All versions prior to v4.2.0 SIMATIC ET200SP IM155-6 PN HS (incl. SIPLUS variants): All versions prior to v4.0.1 SIMATIC ET200SP IM155-6 PN ST (incl. SIPLUS variants): All versions prior to v4.1.0. SIMATIC ET200ecoPN (except 6ES7141-6BG00-0BB0, 6ES7141-6BH00-0BB0, 6ES7142-6BG00-0BB0, 6ES7142-6BR00-0BB0, 6S7143-6BH00-0BB0, 6ES7146-6FF00-0AB0, 6ES7148-6JD00-0AB0 and 6ES7148-6JG00-0BB0): All versions SIMATIC ET200pro: All versions SIMATIC HMI Comfort Panels, HMI Multi Panels, HMI Mobile Panels (incl. SIPLUS variants): All versions prior to V15.1 SIMATIC MV400 family: All versions prior to v7.0.6 SIMATIC NET CM 1542-1: All versions prior to v2.0 SIMATIC NET CM 1542SP-1: All versions prior to v1.0.15 SIMATIC NET CP 343-1 Advanced (incl. SIPLUS variants): All versions SIMATIC NET CP 343-1 Lean (incl. SIPLUS variants): All versions prior to v3.1.3 SIMATIC NET CP 343-1 Standard (incl. SIPLUS variants): All versions prior to v3.1.3 SIMATIC NET CP 443-1 Advanced (incl. SIPLUS variants): All versions prior to v3.2.17 SIMATIC NET CP 443-1 OPC-UA: All versions SIMATIC NET CP 443-1 Standard (incl. SIPLUS variants): All versions prior to v3.2.17 SIMATIC NET CP 1243-1 (incl. SIPLUS variants): All versions prior to v2.1.82 SIMATIC NET CP 1243-1 DNP3 (incl. SIPLUS variants): All versions SIMATIC NET CP 1243-1 IEC (incl. SIPLUS variants): All versions SIMATIC NET CP 1243-1 IRC (incl. SIPLUS variants): All versions prior to v2.1.82 SIMATIC NET CP 1542SP-1 IRC (incl. SIPLUS variants): All versions prior to v1.0.15 SIMATIC NET CP 1543-1 (incl. SIPLUS variants): All versions prior to v2.1 SIMATIC NET CP 1543SP-1 (incl. SIPLUS variants): All versions prior to v1.0.15 SIMATIC NET CP 1604: All versions prior to v2.7 SIMATIC NET CP 1616: All versions prior to v2.7 SIMATIC PN/PN Coupler (incl. SIPLUS NET variants): All versions prior to v4.0 SIMATIC RF650R: All versions prior to v3.0 SIMATIC RF680R: All versions prior to v3.0 SIMATIC RF685R: All versions prior to v3.0 SIMATIC S7-200 SMART: All versions prior to v2.3 SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions prior to v3.X.14 SIMATIC S7-400 H V6 CPU family (incl. SIPLUS variants): All versions prior to v6.0.7 SIMATIC S7-400 PN/DP V6 CPU family (incl. SIPLUS variants): All versions prior to v6.0.6 SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants): All versions prior to v7.0.2 SIMATIC S7-410 CPU family (incl. SIPLUS variants): All versions prior to v8.2 SIMATIC S7-1200 CPU family (incl. SIPLUS variants): All versions prior to v4.2.1 SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions prior to v2.1 SIMATIC S7-1500 Software Controller (incl. F): All versions prior to v2.1 SIMATIC TDC CP51M1: All versions prior to v1.1.8 SIMATIC TDC CPU555: All versions prior to v1.1.1 SIMATIC Teleservice Adapter IE Advanced: All versions SIMATIC Teleservice Adapter IE Basic: All versions SIMATIC Teleservice Adapter IE Standard: All versions SIMATIC WinAC RTX (F) 2010: All versions prior to SIMATIC WinAC RTX 2010 SP3 SIMOCODE pro V PN (incl. SIPLUS variants): All versions prior to v2.0.0 SIMOTION (incl. SIPLUS variants): All versions prior to v4.5 HF1 SINAMICS DCM w. PN: All versions prior to v1.4 SP1 HF5 SINAMICS DCP w. PN: All versions prior to v1.2 HF1 SINAMICS G110M w. PN: All versions prior to v4.7 SP6 HF3 SINAMICS G120(C/P/D) w. PN (incl. SIPLUS variants): All versions prior to v4.7 SP6 HF3 SINAMICS G130 v4.7 w. PN: All versions prior to v4.7 HF27 SINAMICS G130 v4.8 w. PN: All versions prior to v4.8 HF4 SINAMICS G150 v4.7 w. PN: v4.7: All versions prior to v4.7 HF27 SINAMICS G150 v4.8 w. PN: All versions prior to v4.8 HF4 SINAMICS S110 w. PN: All versions prior to V4.4 SP3 HF5 SINAMICS S120 v4.7 SP1 w. PN (incl. SIPLUS variants): All versions SINAMICS S120 v4.7 w. PN (incl. SIPLUS variants): All versions prior to v4.7 HF27 SINAMICS S120 v4.8 w. PN (incl. SIPLUS variants): All versions prior to v4.8 HF4 SINAMICS S120 prior to v4.7 w. PN (incl. SIPLUS variants): All versions prior to v4.7 SINAMICS S150 v4.7 w. PN: All versions prior to v4.7 HF27 SINAMICS S150 v4.8 w. PN: All versions prior to v4.8 HF4 SINAMICS V90 w. PN: All versions prior to v1.01 SINUMERIK 828D v4.5 and prior: All versions prior to v4.5 SP6 HF2 SINUMERIK 828D v4.7: All versions prior to v4.7 SP4 HF1 SINUMERIK 840D sl v4.5 and prior: All versions prior to v4.5 SP6 HF2 SINUMERIK 840D sl v4.7: All versions prior to v4.7 SP4 HF1 SIRIUS ACT 3SU1 interface module PROFINET: All versions prior to v1.1.0 SIRIUS Motor Starter M200D PROFINET: All versions SIRIUS Soft Starter 3RW44 PN: All versions SITOP PSU8600 PROFINET: All versions prior to v1.2.0 SITOP UPS1600 PROFINET (incl. SIPLUS variants): All versions prior to v2.2.0 Softnet PROFINET IO for PC-based Windows systems: All versions prior to v14 SP1.","CVE-2017-2680, CVE-2017-2681",6.5,Medium,CWE-400,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1793,10/12/2021,10/12/2021,2021,ICSA-21-285-01,Advantech WebAccess SCADA,Advantech,WebAccess SCADA,"The following versions of WebAccess/SCADA, an HMI platform, are affected: WebAccess/SCADA: Versions 9.0.3 and prior.",CVE-2021-38431,4.3,Medium,CWE-862,Critical Manufacturing; Energy; Water and Wastewater Systems,"East Asia, United States, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1792,10/12/2021,10/12/2021,2021,ICSA-21-285-02,Advantech WebAccess,Advantech,WebAccess,"The following versions of WebAccess, an HMI platform, are affected: WebAccess Versions 9.02 and prior.","CVE-2021-33023, CVE-2021-38389",9.8,Critical,"CWE-122, CWE-121",Critical Manufacturing; Energy; Water and Wastewater Systems,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1791,10/12/2021,10/12/2021,2021,ICSA-21-285-03,Schneider Electric IGSS,Schneider Electric,IGSS,The following versions of IGSS software are affected: IGSS Data Collector (dc.exe): v15.0.0.21243 and prior.,"CVE-2021-22802, CVE-2021-22803, CVE-2021-22804, CVE-2021-22805",9.8,Critical,"CWE-120, CWE-22, CWE-306, CWE-434",Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1790,10/7/2021,10/7/2021,2021,ICSA-21-280-01,Johnson Controls exacqVision Server Bundle,Exacq Technologies Inc (Subsidiary of Johnson Controls),Johnson Controls exacqVision Server Bundle,The following versions of Exacq Technologies exacqVision products are affected: exacqVision Web Service Version 21.06.11.0 or older.,CVE-2021-27664,9.8,Critical,CWE-269,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1789,10/7/2021,10/7/2021,2021,ICSA-21-280-02,Mobile Industrial Robots Vehicles and MiR Fleet Software,Mobile Industrial Robots (MiR),"MiR100, MiR200, MiR250, MiR500, MiR1000, MiR Fleet","MiR reports the vulnerabilities affect the following products: MiR100, MiR200, MiR250, MiR500, MiR1000 in MiR Robot Software versions prior to 2.10.2.1 MiR Fleet in MiR Fleet Software versions prior to 2.10.2.1 NOTE: the MiR Hook and Shelf Carrier are not affected.","CVE-2020-10271, CVE-2020-10272, CVE-2020-10273, CVE-2020-10276, CVE-2020-10277, CVE-2020-10278, CVE-2020-10279, CVE-2020-10280, CVE-2017-18255, CVE-2017-7184",9.8,Critical,"CWE-668, CWE-239, CWE-284, CWE-276, CWE-190, CWE-306, CWE-311",Critical Manufacturing; Healthcare and Public Health; Transportation Systems,Worldwide,Denmark,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1788,10/7/2021,10/7/2021,2021,ICSA-21-280-03,Johnson Controls exacqVision,Exacq Technologies Inc (Subsidiary of Johnson Controls),Johnson Controls exacqVision,The following versions of Exacq Technologies' exacqVision surveillance video software products are affected: exacqVision Server 32-bit: Versions 21.06.11.0 and prior.,CVE-2021-27665,7.5,High,CWE-190,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1787,10/7/2021,11/16/2021,2021,ICSA-21-280-06,FATEK Automation WinProladder,FATEK Automation,WinProladder,"The following versions of FATEK Automation WinProladder, a PLC programming software are affected: WinProladder: Versions 3.30 and prior.","CVE-2021-38426, CVE-2021-38430, CVE-2021-38434, CVE-2021-38436, CVE-2021-38438, CVE-2021-38440, CVE-2021-38442",7.8,High,"CWE-119, CWE-125, CWE-787, CWE-121, CWE-194, CWE-416",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1786,10/7/2021,11/16/2021,2021,ICSA-21-280-07,FATEK Automation Communication Server,FATEK Automation,Communication Server,The following versions of Communication Server are affected: Communication Server: Versions 1.13 and prior.,CVE-2021-38432,9.8,Critical,CWE-121,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1785,10/5/2021,4/7/2022,2021,ICSA-21-278-01,Mitsubishi Electric GOT and Tension Controller (Update A),Mitsubishi Electric,GOT and Tension Controller,"Update A: Mitsubishi Electric PSIRT has informed CISA that further research has shown the vulnerabilities listed in this advisory do not impact the devices listed below. Mitsubishi Electric will be removing its vulnerability notice from its website on April 7, 2022. Any questions regarding this new information should be directed to Mitsubishi Electric [https://www.mitsubishielectric.com/fa/support/index.html] The following Mitsubishi Electric products are affected: GOT2000 Series GT21 Model GT2107-WTBD: All versions GT2107-WTSD: All versions GT2104-RTBD: All versions GT2104-PMBD: All versions GT2103-PMBD: All versions GOT SIMPLE Series GS21 Model GS2110-WTBD: All versions GS2107-WTBD: All versions GS2110-WTBD-N: All versions GS2107-WTBD-N: All versions Tension Controller LE7-40GU-L: All versions.","CVE-2021-20602, CVE-2021-20603, CVE-2021-20604, CVE-2021-20605",7.5,High,"CWE-755, CWE-20",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1784,10/5/2021,10/19/2021,2021,ICSA-21-278-02,Emerson WirelessHART Gateway,Emerson,WirelessHART Gateway,The following versions of Emerson WirelessHART Gateway network communication devices are affected: WirelessHART 1410 Gateway: All versions prior to v4.7.94 WirelessHART 1410D Gateway: All versions prior to v4.7.94 WirelessHART 1420 Gateway: All versions prior to v4.7.94.,"CVE-2021-38485, CVE-2021-42536, CVE-2021-42538, CVE-2021-42539, CVE-2021-42540, CVE-2021-42542",8.0,High,"CWE-200, CWE-20, CWE-22, CWE-78, CWE-306, CWE-123",Chemical; Critical Manufacturing; Dams; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1783,10/5/2021,10/5/2021,2021,ICSA-21-278-03,Moxa MXview Network Management Software,Moxa,MXview Network Management Software,"The following versions of MXview, a network management software, are affected: MXview Network Management Software: Versions 3.x to 3.2.2.","CVE-2021-38452, CVE-2021-38454, CVE-2021-38456, CVE-2021-38458, CVE-2021-38460",10.0,Critical,"CWE-284, CWE-22, CWE-74, CWE-523, CWE-259",Critical Manufacturing; Energy; Transportation Systems,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1782,10/5/2021,10/5/2021,2021,ICSA-21-278-04,Honeywell Experion PKS and ACE Controllers,Honeywell,Experion PKS and ACE Controllers,"The following versions of Experion PKS, a process control system, are affected: C200: All versions C200E: All versions C300 and ACE controllers: All versions.","CVE-2021-38395, CVE-2021-38397, CVE-2021-38399",10.0,Critical,"CWE-74, CWE-23, CWE-434",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1781,8/7/2018,10/5/2021,2021,ICSMA-18-219-02,Medtronic MiniMed MMT-500/MMT-503 Remote Controllers (Update A),Medtronic,MiniMed 508 Insulin Pump,The following supported Medtronic products are affected: MMT - 508 MiniMed insulin pump | MMT - 522 / MMT - 722 Paradigm REAL-TIME | MMT - 523 / MMT - 723 Paradigm Revel | MMT - 523K / MMT - 723K Paradigm Revel and MMT - 551 / MMT - 751 MiniMed 530G.,"CVE-2018-10634, CVE-2018-14781",5.3,Medium,"CWE-294, CWE-319",Healthcare and Public Health,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1780,9/30/2021,9/30/2021,2021,ICSMA-21-273-01,Boston Scientific Zoom Latitude,Boston Scientific,Zoom Latitude,Boston Scientific reports these vulnerabilities affects the ZOOM LATITUDE Programmer/Recorder/Monitor (PRM) Model 3120.,"CVE-2021-38392, CVE-2021-38394, CVE-2021-38396, CVE-2021-38398, CVE-2021-38400",6.9,Medium,"CWE-284, CWE-1278, CWE-353, CWE-1329, CWE-916",Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1779,9/23/2021,9/27/2021,2021,ICSA-21-266-02,Trane Tracer,Trane,Tracer,The following versions of Trane building automation products: Tracer SC: All versions prior to v4.4 SP7 Tracer SC+: All versions prior to v5.5 SP3 Tracer Concierge: All versions prior to v5.5 SP3.,CVE-2021-38450,9.9,Critical,CWE-94,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1778,2/23/2021,9/23/2021,2021,ICSA-21-054-04,Ovarro TBox (Update A),Ovarro,Ovarro TBox,The following versions of TBox - remote terminal unit (RTU) are affected: TBoxLT2 (All models) TBox MS-CPU32 TBox MS-CPU32-S2 TBox RM2 (All models) TBox TG2 (All models) All versions prior to TWinSoft 12.4 and Firmware 1.46.,"CVE-2021-22640, CVE-2021-22642, CVE-2021-22644, CVE-2021-22646, CVE-2021-22648",8.8,High,"CWE-94, CWE-732, CWE-522, CWE-400, CWE-321",Critical Manufacturing,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1777,9/16/2021,9/20/2021,2021,ICSA-21-259-02,Schneider Electric EcoStruxure and SCADAPack,Schneider Electric,EcoStruxure and SCADAPack,"The following products and versions are affected: EcoStruxure Control Expert: All versions, including former Unity Pro EcoStruxure Process Expert: All versions, including former HDCS SCADAPack RemoteConnect for x70: All versions.",CVE-2021-22797,7.8,High,CWE-22,Commercial Facilities; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater Systems,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1776,9/14/2021,9/14/2021,2021,ICSA-21-257-01,Digi PortServer TS 16,"Digi International, Inc.",Digi PortServer TS 16,The following firmware versions of Digi PortServer TS 16 are affected: Firmware Version 82000684 Firmware Version 82000685.,CVE-2021-38412,9.6,Critical,CWE-287,Critical Manufacturing; Communications; Information Technology; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1775,9/14/2021,12/13/2021,2021,ICSA-21-257-02,Johnson Controls Sensormatic Electronics KT-1,Sensormatic Electronics LLC (Subsidiary of Johnson Controls),Johnson Controls Sensormatic Electronics KT-1,Johnson Controls reports this vulnerability affects the following versions of KT-1 door controllers: Versions up to and including 3.01.,CVE-2021-27662,8.6,High,CWE-294,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1774,9/14/2021,12/13/2021,2021,ICSA-21-257-02,Johnson Controls Sensormatic Electronics KT-1,Sensormatic Electronics LLC (Subsidiary of Johnson Controls),Johnson Controls Sensormatic Electronics KT-1,Johnson Controls reports this vulnerability affects the following versions of KT-1 door controllers: Versions up to and including 3.01.,CVE-2021-27662,8.6,High,CWE-294,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1773,9/14/2021,9/14/2021,2021,ICSA-21-257-03,Schneider Electric Struxureware Data Center Expert,Schneider Electric,Struxureware Data Center Expert,"The following versions of Struxureware Data Center Expert, a monitoring software, are affected: Struxureware Data Center Expert Versions 7.8.1 and prior.","CVE-2021-22794, CVE-2021-22795",9.1,Critical,"CWE-22, CWE-78",Commercial Facilities; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater Systems,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1772,9/14/2021,9/14/2021,2021,ICSA-21-257-04,Siemens Simcenter Femap,Siemens,Simcenter Femap,"The following versions of Simcenter Femap, a simulation application, are affected: Simcenter Femap v2020.2: All versions Simcenter Femap v2021.1: All versions.",CVE-2021-37176,3.3,Low,CWE-125,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1771,9/14/2021,9/14/2021,2021,ICSA-21-257-05,Siemens Simcenter STAR-CCM+ Viewer,Siemens,Simcenter STAR-CCM+ Viewer,"The following versions of Simcenter STAR-CCM+ Viewer, a simulation application, are affected: Simcenter STAR-CCM+ Viewer: All versions prior to 2021.2.1.",CVE-2021-25665,7.8,High,CWE-787,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1770,9/14/2021,6/16/2022,2021,ICSA-21-257-06,Siemens SIMATIC CP (Update A),Siemens,SIMATIC CP,"The following versions of SIMATIC, a communication processor, are affected: SIMATIC CP 1543-1 (incl. SIPLUS variants): All versions prior to v3.0 --------- Begin Update A Part 1 of 2 --------- SIMATIC CP 1545-1: All versions prior to v1.1 --------- End Update A Part 1 of 2 ---------.",CVE-2021-33716,6.5,Medium,CWE-312,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1769,9/14/2021,9/14/2021,2021,ICSA-21-257-07,Siemens APOGEE and TALON,Siemens,APOGEE and TALON,The following products are affected: APOGEE MBC (PPC) (P2 Ethernet): v2.6.3 and newer APOGEE MEC (PPC) (P2 Ethernet): v2.6.3 and newer APOGEE PXC Compact (BACnet): All versions prior to v3.5.3 APOGEE PXC Compact (P2 Ethernet): v2.8 and newer APOGEE PXC Modular (BACnet): All versions prior to v3.5.3 APOGEE PXC Modular (P2 Ethernet): v2.8 and newer TALON TC Compact (BACnet): All versions prior to v3.5.3 TALON TC Modular (BACnet): All versions prior to v3.5.3.,CVE-2021-27391,9.8,Critical,CWE-120,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1768,9/14/2021,9/16/2021,2021,ICSA-21-257-08,Siemens Teamcenter,Siemens,Teamcenter,"The following versions of Teamcenter, a virtualization platform, are affected: Teamcenter 12.4: All versions prior to 12.4.0.8 Teamcenter 13.0: All versions prior to 13.0.0.7 Teamcenter 13.1: All versions prior to 13.1.0.5 Teamcenter 13.2: All versions prior to 13.2.0.2.","CVE-2021-40354, CVE-2021-40355, CVE-2021-40356",7.2,High,"CWE-639, CWE-611, CWE-267",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1767,9/14/2021,9/14/2021,2021,ICSA-21-257-09,Siemens NX,Siemens,NX,The following versions of NX are affected: NX 1980 Series: All versions prior to v1984.,"CVE-2021-37202, CVE-2021-37203",7.8,High,"CWE-125, CWE-416",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1766,9/14/2021,9/14/2021,2021,ICSA-21-257-11,Siemens SIMATIC RFID,Siemens,SIMATIC RFID,The following versions of SIMATIC RFID are affected: SIMATIC RF350M: All versions SIMATIC RF650M: All versions.,CVE-2020-7461,7.3,High,CWE-787,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1765,9/14/2021,9/14/2021,2021,ICSA-21-257-12,Siemens SINEMA Server,Siemens,SINEMA Server,"The following versions of SINEMA Server, a network monitoring and management software, are affected: SINEMA Server: All versions prior to v14 SP3.",CVE-2019-10941,4.7,Medium,CWE-306,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1764,9/14/2021,9/14/2021,2021,ICSA-21-257-13,Siemens LOGO! CMR and SIMATIC RTU 3000,Siemens,LOGO! CMR and SIMATIC RTU 3000,The following versions of LOGO! controllers and SIMATIC monitors are affected: LOGO! CMR2020: All versions prior to v2.2 LOGO! CMR2040: All versions prior to v2.2 SIMATIC RTU 3000 family: All versions.,CVE-2021-37186,5.4,Medium,CWE-330,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1763,9/14/2021,9/14/2021,2021,ICSA-21-257-14,Siemens SINEC NMS,Siemens,SINEC NMS,The following versions of SINEC NMS are affected: SINEC NMS: All versions prior to v1.0 SP1.,"CVE-2021-37200, CVE-2021-37201",8.8,High,"CWE-352, CWE-22",Communications,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1762,9/14/2021,9/14/2021,2021,ICSA-21-257-15,Siemens SIMATIC NET CP Modules,Siemens,SIMATIC NET CP Modules,"The following versions of SIMATIC NET CP Modules, a communication processor, are affected: SIMATIC CP 343-1 (incl. SIPLUS variants) all versions SIMATIC CP 343-1 Advanced (incl. SIPLUS variants) all versions SIMATIC CP 343-1 ERPC all versions SIMATIC CP 343-1 Lean (incl. SIPLUS variants) all versions SIMATIC CP 443-1 (incl. SIPLUS variants) all versions SIMATIC CP 443-1 Advanced (incl. SIPLUS variants) all versions.",CVE-2021-33737,7.5,High,CWE-119,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1761,9/14/2021,9/22/2021,2021,ICSA-21-257-17,Siemens Desigo CC Family,Siemens,Desigo CC Family,The following Siemens danger management station products are affected: Cerberus DMS v4.0: All versions Cerberus DMS v4.1: All versions Cerberus DMS v4.2: All versions Cerberus DMS v5.0: All versions prior to v5.0 QU1 Desigo CC Compact v4.0: All versions Desigo CC Compact v4.1: All versions Desigo CC Compact v4.2: All versions Desigo CC Compact v5.0: All versions prior to v5.0 QU1 Desigo CC v4.0: All versions Desigo CC v4.1: All versions Desigo CC v4.2: All versions Desigo CC v5.0: All versions prior to v5.0 QU1.,CVE-2021-37181,10.0,Critical,CWE-502,Commercial Facilities; Government Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1760,9/14/2021,9/14/2021,2021,ICSA-21-257-18,Siemens Siveillance OIS,Siemens,Siveillance OIS,Siemens reports the vulnerability affects the following Siveillance OIS Building Management Systems products: Desigo CC: All versions with OIS Extension Module GMA-Manager: All versions with OIS running on Debian 9 or earlier Operation Scheduler: All versions with OIS running on Debian 9 or earlier Siveillance Control: All versions with OIS running on Debian 9 or earlier Siveillance Control Pro: All versions.,CVE-2021-31891,10.0,Critical,CWE-78,Commercial Facilities; Government Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1759,9/14/2021,9/14/2021,2021,ICSA-21-257-19,Siemens SINEMA Remote Connect Server,Siemens,SINEMA Remote Connect Server,Siemens reports the vulnerability affects the following SINEMA Remote Connect Server products: SINEMA Remote Connect Server: All versions prior to V3.0 SP2.,"CVE-2021-37177, CVE-2021-37183, CVE-2021-37190, CVE-2021-37191, CVE-2021-37192, CVE-2021-37193",7.4,High,"CWE-200, CWE-284, CWE-799, CWE-471",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1758,9/14/2021,9/14/2021,2021,ICSA-21-257-20,Siemens LOGO! CMR and SIMATIC RTU 3000,Siemens,LOGO! CMR and SIMATIC RTU 3000,The following versions of LOGO! CMR and SIMATIC RTU 3000 are affected: LOGO! CMR2020 all versions prior to v2.2 LOGO! CMR2040 all versions prior to v2.2 SIMATIC RTU 3000 family all versions.,CVE-2020-3647,7.5,High,"CWE-295, CWE-131",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1757,9/14/2021,9/14/2021,2021,ICSA-21-257-21,Siemens Industrial Edge,Siemens,Industrial Edge,"The following versions of Industrial Edge, an app and device management platform, are affected: Industrial Edge Management: All versions prior to v1.3.",CVE-2021-37184,9.8,Critical,CWE-639,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1756,9/14/2021,9/14/2021,2021,ICSA-21-257-22,Siemens Teamcenter Active Workspace,Siemens,Teamcenter Active Workspace,"The following versions of Teamcenter Active Workspace, a product lifecycle management (PLM) system, are affected: Teamcenter Active Workspace v4.3: All versions prior to v4.3.10 Teamcenter Active Workspace v5.0: All versions prior to v5.0.8 Teamcenter Active Workspace v5.1: All versions prior to v5.1.5 Teamcenter Active Workspace v5.2: All versions prior to v5.2.1.",CVE-2021-40357,4.5,Medium,CWE-22,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1755,9/14/2021,9/15/2021,2021,ICSA-21-257-23,Siemens SIMATIC and TIM,Siemens,SIMATIC and TIM,The following Siemens products are affected: SIMATIC Drive Controller family: All versions prior to v2.9.2 SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions prior to v21.9 SIMATIC S7 PLCSIM Advanced: All versions higher than v2 and prior to v4 SIMATIC S7-1200 CPU family (incl. SIPLUS variants): Version 4.4 SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions higher than v2.5 and prior to v2.9.2 SIMATIC S7-1500 Software Controller: All versions higher than v2.5 TIM 1531 IRC (incl. SIPLUS NET variants): Version 2.1.,CVE-2020-28397,5.3,Medium,CWE-863,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1754,8/10/2021,9/14/2021,2021,ICSA-21-222-03,Siemens JT2Go and Teamcenter Visualization (Update A),Siemens,JT2Go and Teamcenter Visualization,The following Siemens products are affected: JT2Go: All versions prior to v13.2.0.2 Teamcenter Visualization: All versions prior to v13.2.0.2.,"CVE-2021-32946, CVE-2021-32952, CVE-2021-33738",7.8,High,"CWE-754, CWE-125, CWE-787",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1753,8/10/2021,9/14/2021,2021,ICSA-21-222-09,Siemens SIMATIC S7-1200 (Update A),Siemens,SIMATIC S7-1200,The following versions of SIMATIC are affected: S7-1200 CPU family (incl. SIPLUS variants): Version 4.5.0.,CVE-2021-37172,8.1,High,CWE-287,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1752,7/13/2021,8/11/2022,2021,ICSA-21-194-06,Siemens SIMATIC Software Products (Update B),Siemens,SIMATIC Software Products,Siemens reports this vulnerability affects the following SIMATIC software products: SIMATIC PCS 7 V8.2 and earlier: All versions --------- Begin Update B Part 1 of 2 --------- SIMATIC PCS 7 V9.X: All versions prior to V9.1 SP2 SIMATIC PDM: All versions prior to V9.2 SP2 --------- End Update B Part 1 of 2 --------- SIMATIC STEP 7 V5.X: All versions prior to v5.7 SINAMICS STARTER (containing STEP 7 OEM version): All versions prior to 5.4 SP2 HF1.,CVE-2021-31894,7.3,High,CWE-732,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1751,7/13/2021,9/14/2021,2021,ICSA-21-194-13,Siemens SINAMICS PERFECT HARMONY GH180 (Update A),Siemens,SINAMICS PERFECT HARMONY GH180,"The following versions and models of SINAMICS PERFECT HARMONY are affected: SINAMICS PERFECT HARMONY GH180 Drives manufactured before 2021-8-13; 6SR5 with options A84, A85, E06, W41 with X30 air to air hex 6SR4 with option W41 with X30 air to air hex.",CVE-2020-15782,8.1,High,CWE-119,Critical Manufacturing; Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1750,7/13/2021,9/14/2021,2021,ICSA-21-194-17,Siemens SINUMERIK ONE and SINUMERIK MC (Update A),Siemens,SINUMERIK ONE and SINUMERIK MC,The following versions of SINUMERIK are affected: SINUMERIK MC: All versions prior to v6.15 SINUMERIK ONE: All versions prior to v6.15.,CVE-2020-15782,8.1,High,CWE-119,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1749,6/1/2021,9/14/2021,2021,ICSA-21-152-01,Siemens SIMATIC S7-1200 and S7-1500 CPU Families (Update A),Siemens,SIMATIC S7-1200 and S7-1500 CPU Families,Siemens reports this vulnerability affects the following SIMATIC S7-1200 and S7-1500 CPU products: SIMATIC Drive Controller family: All versions prior to v2.9.2 SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants): All versions SIMATIC S7-1200 CPU family (incl. SIPLUS variants): All versions prior to v4.5.0 SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions prior to v2.9.2 SIMATIC S7-1500 Software Controller: All versions SIMATIC S7-PLCSIM Advanced: All versions prior to v4.0.,CVE-2020-15782,8.1,High,CWE-119,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1748,4/13/2021,9/14/2021,2021,ICSA-21-103-07,Siemens Web Server of SCALANCE X200 (Update A),Siemens,Siemens Web Server of SCALANCE X200,The following Siemens products are affected: SCALANCE X200-4P IRT: All versions prior to 5.5.1 SCALANCE X201-3P IRT: All versions prior to 5.5.1 SCALANCE X201-3P IRT PRO: All versions prior to 5.5.1 SCALANCE X202-2 IRT: All versions prior to 5.5.1 SCALANCE X202-2P IRT (incl. SIPLUS NET variant): All versions prior to 5.5.1 SCALANCE X202-2P IRT PRO: All versions prior to 5.5.1 SCALANCE X204 IRT: All versions prior to 5.5.1 SCALANCE X204 IRT PRO: All versions prior to 5.5.1 SCALANCE X204-2 (incl. SIPLUS NET variant): All versions SCALANCE X204-2FM: All versions SCALANCE X204-2LD (incl. SIPLUS NET variant): All versions SCALANCE X204-2LD TS: All versions SCALANCE X204-2TS: All versions SCALANCE X206-1: All versions SCALANCE X206-1LD: All versions SCALANCE X208 (incl. SIPLUS NET variant): All versions SCALANCE X208PRO: All versions SCALANCE X212-2 (incl. SIPLUS NET variant): All versions SCALANCE X212-2LD: All versions SCALANCE X216: All versions SCALANCE X224: All versions SCALANCE XF201-3P IRT: All versions prior to 5.5.1 SCALANCE XF202-2P IRT: All versions prior to 5.5.1 SCALANCE XF204: All versions SCALANCE XF204 IRT: All versions prior to 5.5.1 SCALANCE XF204-2 (incl. SIPLUS NET variant): All versions SCALANCE XF204-2BA IRT: All versions prior to 5.5.1 SCALANCE XF206-1: All versions SCALANCE XF208: All versions.,"CVE-2021-25668, CVE-2021-25669",9.8,Critical,"CWE-122, CWE-121",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1747,3/9/2021,3/9/2021,2021,ICSA-21-068-10,Siemens SCALANCE and SIMATIC libcurl (Update B),Siemens,Siemens SCALANCE and SIMATIC libcurl,The following Siemens products are affected by the third-party component libcurl: SCALANCE SC600 Family: all versions prior to v2.0 SIMATIC NET CM 1542-1: all versions; SIMATIC NET CP 343-1 Advanced (incl. SIPLUS variants): v3.0.33; v3.0.44 and v3.0.53.,CVE-2019-3823,7.5,High,CWE-125,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1746,2/9/2021,9/14/2021,2021,ICSA-21-040-05,Siemens TIA Administrator (Update A),Siemens,Siemens TIA Administrator,The following Siemens products are affected: PCS neo (Administration Console): v3.0 TIA Portal: v15; v15.1; and v16.,CVE-2020-25238,7.8,High,CWE-284,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1745,1/12/2021,12/15/2022,2021,ICSA-21-012-02,Siemens SCALANCE X Switches (Update C),Siemens,"SCALANCE X200, X200IRT, X300",The following Siemens products are affected: SCALANCE X-200 switch family (incl. SIPLUS NET variants): All versions prior to v5.2.5 --------- Begin Update C Part 1 of 2 --------- SCALANCE X-200RNA switch family: All versions prior to v3.2.7 --------- End Update C Part 1 of 2 --------- SCALANCE X-200IRT switch family (incl. SIPLUS NET variants): All versions prior to v5.5.0 SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants): All versions prior to v4.1.0.,"CVE-2020-28391, CVE-2020-28395",9.1,Critical,CWE-321,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1744,1/12/2021,1/12/2021,2021,ICSA-21-012-05,Siemens SCALANCE X Products (Update B),Siemens,Siemens SCALANCE X Products,Siemens reports that these vulnerabilities affect the following SCALANCE X products: SCALANCE X-200 switch family (incl. SIPLUS NET variants): All versions; SCALANCE X-200IRT switch family (incl. SIPLUS NET variants): All versions prior to v5.5.0 SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants): All versions prior to v4.1.0; only affected by CVE-2020-15800.,"CVE-2020-15799, CVE-2020-15800, CVE-2020-25226",9.8,Critical,"CWE-122, CWE-306",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1743,4/14/2020,4/14/2020,2021,ICSA-20-105-07,Siemens SCALANCE and SIMATIC (Update H),Siemens,"SCALANCE, SIMATIC","Siemens reports this vulnerability affects the following products: SCALANCE X200-4P IRT (6GK5200-4AH00-2BA3): All versions prior to v5.5.0 SCALANCE X201-3P IRT (6GK5201-3BH00-2BA3): All versions prior to v5.5.0 SCALANCE X201-3P IRT PRO (6GK5201-3BH00-2BD2): All versions prior to v5.5.0 SCALANCE X202-2IRT (6GK5202-2BB00-2BA3): All versions prior to v5.5.0 SCALANCE X202-2P IRT (6GK5202-2BH00-2BA3): All versions prior to v5.5.0 SCALANCE X202-2P IRT PRO (6GK5202-2JR00-2BA6): All versions prior to v5.5.0 SCALANCE X204-2 (6GK5204-2BB10-2AA3): All versions prior to v5.2.5 SCALANCE X204-2FM (6GK5204-2BB11-2AA3): All versions prior to v5.2.5 SCALANCE X204-2LD (6GK5204-2BC10-2AA3): All versions prior to v5.2.5 SCALANCE X204-2LD TS (6GK5204-2BC10-2CA2): All versions prior to v5.2.5 SCALANCE X204-2TS (6GK5204-2BB10-2CA2): All versions prior to v5.2.5 SCALANCE X204IRT (6GK5204-0BA00-2BA3): All versions prior to v5.5.0 SCALANCE X204IRT PRO (6GK5204-0JA00-2BA6): All versions prior to v5.5.0 SCALANCE X206-1 (6GK5206-1BB10-2AA3): All versions prior to v5.2.5 SCALANCE X206-1LD (6GK5206-1BC10-2AA3): All versions prior to v5.2.5 SCALANCE X208 (6GK5208-0BA10-2AA3): All versions prior to v5.2.5 SCALANCE X208PRO (6GK5208-0HA10-2AA6): All versions prior to v5.2.5 SCALANCE X212-2 (6GK5212-2BB00-2AA3): All versions prior to v5.2.5 SCALANCE X212-2LD (6GK5212-2BC00-2AA3): All versions prior to v5.2.5 SCALANCE X216 (6GK5216-0BA00-2AA3): All versions prior to v5.2.5 SCALANCE X224 (6GK5224-0BA00-2AA3): All versions prior to v5.2.5 SCALANCE X302-7 EEC (2x 24V) (6GK5302-7GD00-2EA3): All versions prior to v4.1.4 SCALANCE X302-7 EEC (2x 24V, coated) (6GK5302-7GD00-2GA3): All versions prior to v4.1.4 SCALANCE X302-7 EEC (2x 230V) (6GK5302-7GD00-4EA3): All versions prior to v4.1.4 SCALANCE X302-7 EEC (2x 230V, coated) (6GK5302-7GD00-4GA3): All versions prior to v4.1.4 SCALANCE X302-7 EEC (24V) (6GK5302-7GD00-1EA3): All versions prior to v4.1.4 SCALANCE X302-7 EEC (24V, coated) (6GK5302-7GD00-1GA3): All versions prior to v4.1.4 SCALANCE X302-7 EEC (230V) (6GK5302-7GD00-3EA3): All versions prior to v4.1.4 SCALANCE X302-7 EEC (230V, coated) (6GK5302-7GD00-3GA3): All versions prior to v4.1.4 SCALANCE X304-2FE (6GK5304-2BD00-2AA3): All versions prior to v4.1.4 SCALANCE X306-1LD FE (6GK5306-1BF00-2AA3): All versions prior to v4.1.4 SCALANCE X307-2 EEC (2x 24V) (6GK5307-2FD00-2EA3): All versions prior to v4.1.4 SCALANCE X307-2 EEC (2x 24V, coated) (6GK5307-2FD00-2GA3): All versions prior to v4.1.4 SCALANCE X307-2 EEC (2x 230V) (6GK5307-2FD00-4EA3): All versions prior to v4.1.4 SCALANCE X307-2 EEC (2x 230V, coated) (6GK5307-2FD00-4GA3): All versions prior to v4.1.4 SCALANCE X307-2 EEC (24V) (6GK5307-2FD00-1EA3): All versions prior to v4.1.4 SCALANCE X307-2 EEC (24V, coated) (6GK5307-2FD00-1GA3): All versions prior to v4.1.4 SCALANCE X307-2 EEC (230V) (6GK5307-2FD00-3EA3): All versions prior to v4.1.4 SCALANCE X307-2 EEC (230V, coated) (6GK5307-2FD00-3GA3): All versions prior to v4.1.4 SCALANCE X307-3 (6GK5307-3BL00-2AA3): All versions prior to v4.1.4 SCALANCE X307-3 (6GK5307-3BL10-2AA3): All versions prior to v4.1.4 SCALANCE X307-3LD (6GK5307-3BM00-2AA3): All versions prior to v4.1.4 SCALANCE X307-3LD (6GK5307-3BM10-2AA3): All versions prior to v4.1.4 SCALANCE X308-2 (6GK5308-2FL00-2AA3): All versions prior to v4.1.4 SCALANCE X308-2 (6GK5308-2FL10-2AA3): All versions prior to v4.1.4 SCALANCE X308-2LD (6GK5308-2FM00-2AA3): All versions prior to v4.1.4 SCALANCE X308-2LD (6GK5308-2FM10-2AA3): All versions prior to v4.1.4 SCALANCE X308-2LH (6GK5308-2FN00-2AA3): All versions prior to v4.1.4 SCALANCE X308-2LH (6GK5308-2FN10-2AA3): All versions prior to v4.1.4 SCALANCE X308-2LH+ (6GK5308-2FP00-2AA3): All versions prior to v4.1.4 SCALANCE X308-2LH+ (6GK5308-2FP10-2AA3): All versions prior to v4.1.4 SCALANCE X308-2M (6GK5308-2GG00-2AA2): All versions prior to v4.1.4 SCALANCE X308-2M (6GK5308-2GG10-2AA2): All versions prior to v4.1.4 SCALANCE X308-2M PoE (6GK5308-2QG00-2AA2): All versions prior to v4.1.4 SCALANCE X308-2M PoE (6GK5308-2QG10-2AA2): All versions prior to v4.1.4 SCALANCE X308-2M TS (6GK5308-2GG00-2CA2): All versions prior to v4.1.4 SCALANCE X308-2M TS (6GK5308-2GG10-2CA2): All versions prior to v4.1.4 SCALANCE X310 (6GK5310-0FA00-2AA3): All versions prior to v4.1.4 SCALANCE X310 (6GK5310-0FA10-2AA3): All versions prior to v4.1.4 SCALANCE X310FE (6GK5310-0BA00-2AA3): All versions prior to v4.1.4 SCALANCE X310FE (6GK5310-0BA10-2AA3): All versions prior to v4.1.4 SCALANCE X320-1 FE (6GK5320-1BD00-2AA3): All versions prior to v4.1.4 SCALANCE X320-1-2LD FE (6GK5320-3BF00-2AA3): All versions prior to v4.1.4 SCALANCE X408-2 (6GK5408-2FD00-2AA2): All versions prior to v4.1.4 SCALANCE XF201-3P IRT (6GK5201-3JR00-2BA6): All versions prior to v5.5.0 SCALANCE XF202-2P IRT (6GK5202-2BH00-2BD2): All versions prior to v5.5.0 SCALANCE XF204 (6GK5204-0BA00-2AF2): All versions prior to v5.2.5 SCALANCE XF204-2 (6GK5204-2BC00-2AF2): All versions prior to v5.2.5 SCALANCE XF204-2BA IRT (6GK5204-2AA00-2BD2): All versions prior to v5.5.0 SCALANCE XF204IRT (6GK5204-0BA00-2BF2): All versions prior to v5.5.0 SCALANCE XF206-1 (6GK5206-1BC00-2AF2): All versions prior to v5.2.5 SCALANCE XF208 (6GK5208-0BA00-2AF2): All versions prior to v5.2.5 SCALANCE XR324-4M EEC (2x 24V, ports on front) (6GK5324-4GG00-2ER2): All versions prior to v4.1.4 SCALANCE XR324-4M EEC (2x 24V, ports on front) (6GK5324-4GG10-2ER2): All versions prior to v4.1.4 SCALANCE XR324-4M EEC (2x 24V, ports on rear) (6GK5324-4GG00-2JR2): All versions prior to v4.1.4 SCALANCE XR324-4M EEC (2x 24V, ports on rear) (6GK5324-4GG10-2JR2): All versions prior to v4.1.4 SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front) (6GK5324-4GG00-4ER2): All versions prior to v4.1.4 SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front) (6GK5324-4GG10-4ER2): All versions prior to v4.1.4 SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG00-4JR2): All versions prior to v4.1.4 SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG10-4JR2): All versions prior to v4.1.4 SCALANCE XR324-4M EEC (24V, ports on front) (6GK5324-4GG00-1ER2): All versions prior to v4.1.4 SCALANCE XR324-4M EEC (24V, ports on front) (6GK5324-4GG10-1ER2): All versions prior to v4.1.4 SCALANCE XR324-4M EEC (24V, ports on rear) (6GK5324-4GG00-1JR2): All versions prior to v4.1.4 SCALANCE XR324-4M EEC (24V, ports on rear) (6GK5324-4GG10-1JR2): All versions prior to v4.1.4 SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front) (6GK5324-4GG00-3ER2): All versions prior to v4.1.4 SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front) (6GK5324-4GG10-3ER2): All versions prior to v4.1.4 SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG00-3JR2): All versions prior to v4.1.4 SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG10-3JR2): All versions prior to v4.1.4 SCALANCE XR324-4M PoE (24V, ports on front) (6GK5324-4QG00-1AR2): All versions prior to v4.1.4 SCALANCE XR324-4M PoE (24V, ports on rear) (6GK5324-4QG00-1HR2): All versions prior to v4.1.4 SCALANCE XR324-4M PoE (230V, ports on front) (6GK5324-4QG00-3AR2): All versions prior to v4.1.4 SCALANCE XR324-4M PoE (230V, ports on rear) (6GK5324-4QG00-3HR2): All versions prior to v4.1.4 SCALANCE XR324-4M PoE TS (24V, ports on front) (6GK5324-4QG00-1CR2): All versions prior to v4.1.4 SCALANCE XR324-12M (24V, ports on front) (6GK5324-0GG00-1AR2): All versions prior to v4.1.4 SCALANCE XR324-12M (24V, ports on front) (6GK5324-0GG10-1AR2): All versions prior to v4.1.4 SCALANCE XR324-12M (24V, ports on rear) (6GK5324-0GG00-1HR2): All versions prior to v4.1.4 SCALANCE XR324-12M (24V, ports on rear) (6GK5324-0GG10-1HR2): All versions prior to v4.1.4 SCALANCE XR324-12M (230V, ports on front) (6GK5324-0GG00-3AR2): All versions prior to v4.1.4 SCALANCE XR324-12M (230V, ports on front) (6GK5324-0GG10-3AR2): All versions prior to v4.1.4 SCALANCE XR324-12M (230V, ports on rear) (6GK5324-0GG00-3HR2): All versions prior to v4.1.4 SCALANCE XR324-12M (230V, ports on rear) (6GK5324-0GG10-3HR2): All versions prior to v4.1.4 SCALANCE XR324-12M TS (24V) (6GK5324-0GG00-1CR2): All versions prior to v4.1.4 SCALANCE XR324-12M TS (24V) (6GK5324-0GG10-1CR2): All versions prior to v4.1.4 SIMATIC CP 442-1 RNA (6GK7442-1RX00-0XE0): All versions SIMATIC CP 443-1 (6GK7443-1EX30-0XE0): All versions SIMATIC CP 443-1 Advanced (6GK7443-1GX30-0XE0): All versions SIMATIC CP 443-1 RNA (6GK7443-1RX00-0XE0): All versions SIMATIC RF180C (6GT2002-0JD00): All versions SIMATIC RF182C (6GT2002-0JD10): All versions SIPLUS NET CP 443-1 (6AG1443-1EX30-4XE0): All versions SIPLUS NET CP 443-1 Advanced (6AG1443-1GX30-4XE0): All versions SIPLUS NET SCALANCE X308-2 (6AG1308-2FL10-4AA3): All versions prior to v4.1.4 Begin Update H: SIMATIC CP 442-1 RNA (6GK7442-1RX00-0XE0): All versions prior to v1.5.1 SIMATIC CP 443-1 RNA (6GK7443-1RX00-0XE0): All versions prior to v1.5.18 End Update H.","CVE-2019-1930, CVE-2019-19301",7.5,High,CWE-400,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1742,9/10/2019,5/12/2022,2021,ICSA-19-253-03,Siemens Industrial Products (Update R),Siemens,Industrial Products,"Siemens reports the vulnerabilities affect the following industrial products: CloudConnect 712: All versions prior to 1.1.5 CloudConnect 712: All versions prior to 1.1.5 ROX II: All versions prior to 2.13.3 RUGGEDCOM APE 1404 Linux: All versions prior to Debian 9 Linux Image 2019-12-13 RUGGEDCOM RM1224 (6GK6108-4AM00): All versions prior to v6.2 RUGGEDCOM RX 1400 VPE Debian Linux: All versions prior to Debian 9 Linux Image 2019-12-13 RUGGEDCOM RX 1400 VPE Linux CloudConnect: All versions prior to Debian 9 Linux Image 2019-12-13 13 (only affected by CVE-2019-11479) SCALANCE M804PB (6GK5804-0AP00-2AA2): All versions prior to v6.2 SCALANCE M812-1 ADSL-Router (Annex A) (6GK5812-1AA00-2AA2): All versions prior to v6.2 SCALANCE M812-1 ADSL-Router (Annex B) (6GK5812-1BA00-2AA2): All versions prior to v6.2 SCALANCE M816-1 ADSL-Router (Annex A) (6GK5816-1AA00-2AA2): All versions prior to v6.2 SCALANCE M816-1 ADSL-Router (Annex B) (6GK5816-1BA00-2AA2): All versions prior to v6.2 SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2): All versions prior to v6.2 SCALANCE M874-2 (6GK5874-2AA00-2AA2): All versions prior to v6.2 SCALANCE M874-3 (6GK5874-3AA00-2AA2): All versions prior to v6.2 SCALANCE M875: All versions SCALANCE M876-3 (6GK5876-3AA02-2BA2): All versions prior to v6.2 SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2): All versions prior to v6.2 SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2): All versions prior to v6.2 SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2): All versions prior to v6.2 SCALANCE S602: All versions prior to v4.1 SCALANCE S612: All versions prior to v4.1 SCALANCE S615 (6GK5615-0AA00-2AA2): All versions prior to v6.2 SCALANCE S623: All versions prior to v4.1 SCALANCE S627-2M: All versions prior to v4.1 SCALANCE SC622-2C (6GK5622-2GS00-2AC2): All versions prior to v2.0.1 SCALANCE SC632-2C (6GK5632-2GS00-2AC2): All versions prior to v2.0.1 SCALANCE SC636-2C (6GK5636-2GS00-2AC2): All versions prior to v2.0.1 SCALANCE SC642-2C (6GK5642-2GS00-2AC2): All versions prior to v2.0.1 SCALANCE SC646-2C (6GK5646-2GS00-2AC2): All versions prior to v2.0.1 SCALANCE W1750D: All versions prior to v8.6.0 SCALANCE W-700 IEEE 802.11n family: All versions prior to v6.4 SCALANCE W-1700 IEEE 802.11ac family: All versions prior to v2.0 SCALANCE WLC711: All versions SCALANCE WLC712: All versions SIMATIC CM 1542-1: All versions prior to 3.0 SIMATIC CP 343-1 Advanced (incl. SIPLUS variants): All versions Begin Update R: SIMATIC CP 442-1 RNA (6GK7442-1RX00-0XE0): All versions prior to v1.5.18 SIMATIC CP 443-1 (incl. SIPLUS variants): All versions SIMATIC CP 443-1 Advanced (incl. SIPLUS variants): All versions SIMATIC CP 443-1 OPC UA (6GK7443-1UX00-0XE0): All versions SIMATIC CP 443-1 RNA (6GK7443-1RX00-0XE0): All versions prior to v1.5.18 End Update R SIMATIC CP 1242-7C: All versions prior to v3.2 SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0): All versions prior to v3.2 SIMATIC CP 1243-7 LTE EU (6GK7243-7KX30-0XE0): All versions prior to v3.2 SIMATIC CP 1243-7 LTE US (6GK7243-7SX30-0XE0): All versions prior to v3.2 SIMATIC CP 1243-8 IRC (6GK7243-8RX30-0XE0): All versions prior to v3.2 SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0): All versions prior to v2.1 SIMATIC CP 1542SP-1 IRC (incl. SIPLUS variants): All versions prior to v2.1 SIMATIC CP 1543-1 (6GK7543-1AX00-0XE0): All versions prior to v2.2 SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0): All versions prior to v2.1 SIMATIC CP 1623 (6GK1162-3AA00): All versions prior to v14.00.15.00_51.25.00.01 SIMATIC CP 1628 (6GK1162-8AA00): All versions prior to v17.0 SIMATIC ITC1500: All versions prior to v3.1.1.0 SIMATIC ITC1500 PRO: All versions prior to v3.1.1.0 SIMATIC ITC1900: All versions prior to v3.1.1.0 SIMATIC ITC1900 PRO: All versions prior to v3.1.1.0 SIMATIC ITC2200: All versions prior to v3.1.1.0 SIMATIC ITC2200 PRO: All versions prior to v3.1.1.0 SIMATIC MV540 H (6GF3540-0GE10): All versions prior to v2.1 SIMATIC MV540 S (6GF3540-0CD10): All versions prior to v2.1 SIMATIC MV550 H (6GF3550-0GE10): All versions prior to v2.1 SIMATIC MV550 S (6GF3550-0CD10): All versions prior to v2.1 SIMATIC MV560 U (6GF3560-0LE10): All versions prior to v2.1 SIMATIC MV560 X (6GF3560-0HE10): All versions prior to v2.1 SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0): All versions prior to v4.0 SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0): All versions prior to v4.0 SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0): All versions prior to v4.0 SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0): All versions prior to v4.0 SIMATIC Reader RF615R ETSI (6GT2811-6CC10-0AA0): All versions prior to v4.0 SIMATIC Reader RF615R FCC (6GT2811-6CC10-1AA0): All versions prior to v4.0 SIMATIC Reader RF650R ARIB (6GT2811-6AB20-4AA0): All versions prior to v4.0 SIMATIC Reader RF650R CMIIT (6GT2811-6AB20-2AA0): All versions prior to v4.0 SIMATIC Reader RF650R ETSI (6GT2811-6AB20-0AA0): All versions prior to v4.0 SIMATIC Reader RF650R FCC (6GT2811-6AB20-1AA0): All versions prior to v4.0 SIMATIC Reader RF680R ARIB (6GT2811-6AA10-4AA0): All versions prior to v4.0 SIMATIC Reader RF680R CMIIT (6GT2811-6AA10-2AA0): All versions prior to v4.0 SIMATIC Reader RF680R ETSI (6GT2811-6AA10-0AA0): All versions prior to v4.0 SIMATIC Reader RF680R FCC (6GT2811-6AA10-1AA0): All versions prior to v4.0 SIMATIC Reader RF685R ARIB (6GT2811-6CA10-4AA0): All versions prior to v4.0 SIMATIC Reader RF685R CMIIT (6GT2811-6CA10-2AA0): All versions prior to v4.0 SIMATIC Reader RF685R ETSI (6GT2811-6CA10-0AA0): All versions prior to v4.0 SIMATIC Reader RF685R FCC (6GT2811-6CA10-1AA0): All versions prior to v4.0 SIMATIC RF185C: All versions prior to v1.3 SIMATIC RF186C: All versions prior to v1.3 SIMATIC RF186CI: All versions prior to v1.3 SIMATIC RF188C: All versions prior to v1.3 SIMATIC RF188CI: All versions prior to v1.3 SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (MLFB: 6ES7518-4AX00-1AC0, 6AG1518-4AX00-4AC0, incl. SIPLUS variant): All versions prior to v2.8.4 SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0): All versions prior to v2.8.4 SIMATIC Teleservice Adapter IE Advanced: All versions SIMATIC Teleservice Adapter IE Basic: All versions SINEMA Remote Connect Server: All versions prior to v2.1 SINUMERIK 808D: All versions prior to v4.92 SINUMERIK 828D: All versions prior to v4.8 SP5 SINUMERIK 840D sl: All versions prior to v4.8 SP5 SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0): All versions prior to v2.1 SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0): All versions prior to v2.1 SIPLUS NET CP 1543-1 (6AG1543-1AX00-2XE0): All versions prior to v2.2 SIPLUS S7-1200 CP 1243-1 (6AG1243-1BX30-2AX0): All versions prior to v3.2 SIPLUS S7-1200 CP 1243-1 RAIL (6AG2243-1BX30-1XE0): All versions prior to v3.2 SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0): All versions prior to v2.1 TIM 3V-IE (incl. SIPLUS NET variants): All versions TIM 3V-IE Advanced (incl. SIPLUS NET variants): All versions TIM 3V-IE DNP3 (incl. SIPLUS NET variants): All versions TIM 4R-IE (incl. SIPLUS NET variants): All versions TIM 4R-IE DNP3 (incl. SIPLUS NET variants): All versions TIM 1531 IRC (incl. SIPLUS NET variants): All versions prior to 2.1","CVE-2019-8460, CVE-2019-11477, CVE-2019-11478, CVE-2019-11479",7.5,High,"CWE-1049, CWE-190, CWE-400",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1741,8/13/2019,8/13/2019,2021,ICSA-19-225-03,Siemens SCALANCE X Switches (Update C),Siemens,SCALANCE X Switches,SCALANCE X-200 switch family (incl. SIPLUS NET variants): All versions SCALANCE X-200IRT switch family (incl. SIPLUS NET variants): All versions prior to 5.5.0. SCALANCE X-200RNA: All versions.,CVE-2019-10942,8.6,High,CWE-410,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1740,9/9/2021,9/9/2021,2021,ICSA-21-252-01,AVEVA PCS Portal,AVEVA,PCS Portal,"The following versions of the AVEVA Software Platform Common Services (PCS) Portal are affected: PCS Versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 The following products ship a vulnerable version of the PCS Portal application and are affected: AVEVA System Platform 2020 R2 P01, 2020 R2, and 2020 AVEVA Work Tasks 2020 Update 1 AVEVA Work Tasks 2020 AVEVA Mobile Operator 2020 AVEVA Manufacturing Execution System 2020 AVEVA Batch Management 2020 AVEVA Enterprise Data Management 2021.",CVE-2021-38410,7.3,High,CWE-427,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1739,9/9/2021,9/6/2022,2021,ICSA-21-252-02,Delta Electronics DOPSoft 2 (Update A),Delta Electronics,DOPSoft 2,The following versions of DOPSoft 2 are affected: DOPSoft 2: Version 2.00.07 and prior.,"CVE-2021-38402, CVE-2021-38404, CVE-2021-38406",7.8,High,"CWE-122, CWE-787, CWE-121",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1738,9/9/2021,9/9/2021,2021,ICSA-21-252-03,Mitsubishi Electric Europe B.V. smartRTU and INEA ME-RTU,Mitsubishi Electric Europe B.V.,smartRTU and INEA ME-RTU,The following products are affected: smartRTU and INEA ME-RTU: All firmware versions prior to Version 3.3.,"CVE-2019-14925, CVE-2019-14926, CVE-2019-14927, CVE-2019-14928, CVE-2019-14929, CVE-2019-14930, CVE-2019-14931",9.8,Critical,"CWE-284, CWE-78, CWE-79, CWE-276, CWE-256, CWE-798",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1737,9/1/2020,6/13/2024,2020,ICSA-20-245-01,Mitsubishi Electric Multiple Products (Update G),Mitsubishi Electric,Multiple products,Mitsubishi Electric reports the vulnerability affects the following products: QJ71MES96: all versions QJ71WS96: all versions Q06CCPU-V: all versions Q24DHCCPU-V: the first 5 digits of serial number 24031 and prior Q24DHCCPU-VG: the first 5 digits of serial number 24031 and prior R12CCPU-V: Version 13 and prior RD55UP06-V: Version 09 and prior RD55UP12-V: Version 01 RJ71GN11-T2: Version 11 and prior RD78G4: Version 14 and prior RD78G8: Version 14 and prior RD78G16: Version 14 and prior RD78G32: Version 14 and prior RD78G64: Version 14 and prior RD78GHV: Version 14 and prior RD78GHW: Version 14 and prior NZ2FT-MT: all versions NZ2FT-EIP: all versions Q03UDECPU: the first 5 digits of serial number 22081 and prior Q04UDEHCPU: the first 5 digits of serial number 22081 and prior Q06UDEHCPU: the first 5 digits of serial number 22081 and prior Q10UDEHCPU: the first 5 digits of serial number 22081 and prior Q13UDEHCPU: the first 5 digits of serial number 22081 and prior Q20UDEHCPU: the first 5 digits of serial number 22081 and prior Q26UDEHCPU: the first 5 digits of serial number 22081 and prior Q50UDEHCPU: the first 5 digits of serial number 22081 and prior Q100UDEHCPU: the first 5 digits of serial number 22081 and prior Q03UDVCPU: the first 5 digits of serial number 22031 and prior Q04UDVCPU: the first 5 digits of serial number 22031 and prior Q06UDVCPU: the first 5 digits of serial number 22031 and prior Q13UDVCPU: the first 5 digits of serial number 22031 and prior Q26UDVCPU: the first 5 digits of serial number 22031 and prior Q04UDPVCPU: the first 5 digits of serial number 22031 and prior Q06UDPVCPU: the first 5 digits of serial number 22031 and prior Q13UDPVCPU: the first 5 digits of serial number 22031 and prior Q26UDPVCPU: the first 5 digits of serial number 22031 and prior L02CPU(-P): the first 5 digits of serial number 22051 and prior L06CPU(-P): the first 5 digits of serial number 22051 and prior L26CPU(-P): the first 5 digits of serial number 22051 and prior L26CPU-(P)BT: the first 5 digits of serial number 22051 and prior R00CPU: Version 18 and prior R01CPU: Version 18 and prior R02CPU: Version 18 and prior R04CPU: Version 50 and prior R08CPU: Version 50 and prior R16CPU: Version 50 and prior R32CPU: Version 50 and prior R120CPU: Version 50 and prior R04ENCPU: Version 50 and prior R08ENCPU: Version 50 and prior R16ENCPU: Version 50 and prior R32ENCPU: Version 50 and prior R120ENCPU: Version 50 and prior R08SFCPU: Version 22 and prior R16SFCPU: Version 22 and prior R32SFCPU: Version 22 and prior R120SFCPU: Version 22 and prior R08PCPU: Version 24 and prior R16PCPU: Version 24 and prior R32PCPU: Version 24 and prior R120PCPU: Version 24 and prior R08PSFCPU: Version 05 and prior R16PSFCPU: Version 05 and prior R32PSFCPU: Version 05 and prior R120PSFCPU: Version 05 and prior FX5U(C)-**M*/** Serial number 17X**** or later: Version 1.210 and prior FX5U(C)-**M*/** Serial number 179**** and prior: Version 1.070 and prior FX5UC-32M*/**-TS: Version 1.210 and prior FX5UJ-**M*/**: Version 1.000 FX5-ENET: Version 1.002 and prior FX5-ENET/IP: Version 1.002 and prior FX3U-ENET-ADP: Version 1.22 and prior FX3GE-**M*/**: the first 3 digits of serial number 20X and prior FX3U-ENET: Version 1.14 and prior FX3U-ENET-L: Version 1.14 and prior FX3U-ENET-P502: Version 1.14 and prior FX5-CCLGN-MS: Version 1.000 IU1-1M20-D: all versions LE7-40GU-L screen package data: version 1.01 and prior GOT2000 Series GT21 Model: Version 01.44.000 and prior GS Series GS21 Model: Version 01.44.000 and prior GOT1000 Series GT14 Model: all versions FR-A800-E Series: production date December 2020 and prior FR-F800-E Series: production date December 2020 and prior FR-A8NCG: Production date August 2020 and prior FR-E800-EPA Series: Production date July 2020 and prior FR-E800-EPB Series: Production date July 2020 and prior Conveyor Tracking Application APR-1TR3FH (Discontinued product): all versions Conveyor Tracking Application APR-1TR6FH (Discontinued product): all versions Conveyor Tracking Application APR-1TR12FH (Discontinued product): all versions Conveyor Tracking Application APR-1TR20FH (Discontinued product): all versions Conveyor Tracking Application APR-2TR3FH (Discontinued product): all versions Conveyor Tracking Application APR-2TR6FH (Discontinued product): all versions Conveyor Tracking Application APR-2TR12FH (Discontinued product): all versions Conveyor Tracking Application APR-2TR20FH (Discontinued product): all versions MR-JE-C: all versions MR-J4-TM: all versions RJ71EN71: Version 48 and prior QJ71E71-100: the first 5 digits of serial number 21092 and prior LJ71E71-100: the first 5 digits of serial number 21092 and prior QJ71MT91: the first 5 digits of serial number 20082 and prior NZ2GACP620-60: Version 1.03D and prior NZ2GACP620-300: Version 1.03D and prior GT25-J71GN13-T2: Version 03 and prior.,CVE-2020-16226,7.3,High,CWE-342,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1736,9/7/2021,4/18/2024,2021,ICSA-21-250-01,Mitsubishi Electric MELSEC iQ-R Series (Update B),Mitsubishi Electric,MELSEC iQ-R Series CPU Module,"Mitsubishi Electric reports these vulnerabilities affect the following MELSEC products. Users may use the manual ( MELSEC iQ-R Module Configuration Manual ""Appendix 1 Checking Production Information and Firmware Version"" ) to learn how to check the firmware version: MELSEC iQ-R series Safety CPU R08SFCPU: Firmware versions ""26"" and prior (CVE-2021-20594 and CVE-2021-20597) MELSEC iQ-R series Safety CPU R16SFCPU: Firmware versions ""26"" and prior (CVE-2021-20594 and CVE-2021-20597) MELSEC iQ-R series Safety CPU R32SFCPU: Firmware versions ""26"" and prior (CVE-2021-20594 and CVE-2021-20597) MELSEC iQ-R series Safety CPU R120SFCPU: Firmware versions ""26"" and prior (CVE-2021-20594 and CVE-2021-20597) MELSEC iQ-R series Safety CPU R08SFCPU: all versions (CVE-2021-20598) MELSEC iQ-R series Safety CPU R16SFCPU: all versions (CVE-2021-20598) MELSEC iQ-R series Safety CPU R32SFCPU: all versions (CVE-2021-20598) MELSEC iQ-R series Safety CPU R120SFCPU: all versions (CVE-2021-20598) MELSEC iQ-R series SIL2 Process CPU R08PSFCPU: Firmware versions ""11"" and prior (CVE-2021-20594 and CVE-2021-20597) MELSEC iQ-R series SIL2 Process CPU R16PSFCPU: Firmware versions ""11"" and prior (CVE-2021-20594 and CVE-2021-20597) MELSEC iQ-R series SIL2 Process CPU R32PSFCPU: Firmware versions ""11"" and prior (CVE-2021-20594 and CVE-2021-20597) MELSEC iQ-R series SIL2 Process CPU R120PSFCPU: Firmware versions ""11"" and prior (CVE-2021-20594 and CVE-2021-20597) MELSEC iQ-R series SIL2 Process CPU R08PSFCPU: all versions (CVE-2021-20598) MELSEC iQ-R series SIL2 Process CPU R16PSFCPU: all versions (CVE-2021-20598) MELSEC iQ-R series SIL2 Process CPU R32PSFCPU: all versions (CVE-2021-20598) MELSEC iQ-R series SIL2 Process CPU R120PSFCPU: all versions (CVE-2021-20598).","CVE-2021-20594, CVE-2021-20597, CVE-2021-20598",7.4,High,"CWE-200, CWE-522, CWE-645",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1735,9/7/2021,9/7/2021,2021,ICSA-21-250-02,Hitachi ABB Power Grids System Data Manager,Hitachi and ABB,Power Grids System Data Manager,The following versions of System Data Manager are affected: SDM600: All versions prior to 1.2 FP2 HF6 (Build Nr. 1.2.14002.257).,CVE-2021-35526,6.3,Medium,CWE-312,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1734,9/2/2021,9/2/2021,2021,ICSA-21-245-01,Johnson Controls Sensormatic Electronics Illustra,Sensormatic Electronics LLC (Subsidiary of Johnson Controls),Johnson Controls Sensormatic Electronics Illustra,"Johnson Controls reports this vulnerability affects the following Sensormatic Electronics Illustra camera systems: Pro Gen 3, All versions prior to 2.8.0 Flex Gen 2, All versions prior to 1.9.4 Pro 2, All versions Insight, All versions prior to 1.4.0.",CVE-2021-3156,7.8,High,CWE-193,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1733,9/2/2021,9/2/2021,2021,ICSA-21-245-02,JTEKT TOYOPUC Products,JTEKT ELECTRONICS CORPORATION,JTEKT TOYOPUC Products,The following versions of these TOYOPUC products are affected: TOYOPUC-PC10 Series: PC10G-CPU TCC-6353: All versions PC10GE TCC-6464: All versions PC10P TCC-6372: All versions PC10P-DP TCC-6726: All versions PC10P-DP-IO TCC-6752: All versions PC10B-P TCC-6373: All versions PC10B TCC-1021: All versions PC10B-E/C TCU-6521: All versions PC10E TCC-4637: All versions PC10PE TCC-1101: All versions PC10PE-1616P TCC-1102: All versions EF10 TCU-6982: All versions TOYOPUC-Plus Series: Plus CPU TCC-6740: All versions Plus EX TCU-6741: All versions Plus EX2 TCU-6858: All versions Plus EFR TCU-6743: All versions Plus EFR2 TCU-6859: All versions Plus 2P-EFR TCU-6929: All versions Plus BUS-EX TCU-6900: All versions TOYOPUC-PC3J/PC2J Series: FL/ET-T-V2H THU-6289: All versions 2PORT-EFR THU-6404: All versions TOYOPUC-Nano Series Nano 10GX TUC-1157: All versions Nano CPU TUC-6941: All versions Nano 2ET TUU-6949: All versions Nano Safety TUC-1085: All versions Nano Safety RS00IP TUU-1086: All versions Nano Safety RS01IP TUU-1087: All versions.,CVE-2021-33011,4.3,Medium,CWE-770,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1732,9/2/2021,9/3/2021,2021,ICSA-21-245-03,Advantech WebAccess,Advantech,WebAccess,"The following versions of WebAccess, an HMI platform, are affected: WebAccess: Versions 9.02 and prior.",CVE-2021-38408,9.8,Critical,CWE-121,Critical Manufacturing; Energy; Water and Wastewater Systems,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1731,8/31/2021,8/31/2021,2021,ICSA-21-243-01,Sensormatic Electronics KT-1,Sensormatic Electronics LLC (Subsidiary of Johnson Controls),KT-1,"The following versions of KT-1, an Ethernet-ready single-door controller, are affected: KT-1: Versions 2.09.02 and prior.",CVE-NA,Not Applicable,Not Applicable,CWE-1104,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1730,8/26/2021,8/26/2021,2021,ICSA-21-238-01,Johnson Controls Controlled Electronic Management Systems CEM Systems AC2000,Controlled Electronic Management Systems Ltd (CEM) (Subsidiary of Johnson Controls),CEM Systems AC2000,Johnson Controls reports this vulnerability affects the following versions of CEM Systems AC2000: Versions 10.1 through 10.5 This vulnerability applies only to users who have implemented Single Sign On (SSO) and have installed the AC2000 Application Programming Interface (API).,CVE-2021-27663,8.2,High,CWE-285,Commercial Facilities; Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1729,8/26/2021,8/26/2021,2021,ICSA-21-238-02,Annke Network Video Recorder,Annke,N48PBB (NVR),This vulnerability affects following versions of N48PBB (NVR): V3.4.106 build 200422 and prior.,CVE-2021-32941,9.4,Critical,CWE-121,Commercial Facilities,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1728,8/24/2021,8/24/2021,2021,ICSA-21-236-01,Hitachi ABB Power Grids TropOS,Hitachi and ABB,TropOS,Hitachi ABB Power Grids reports these vulnerabilities affect the following products: TropOS: Firmware Version 8.9.4.8 and prior.,"CVE-2020-24586, CVE-2020-24587, CVE-2020-24588, CVE-2020-26139, CVE-2020-26140, CVE-2020-26141, CVE-2020-26142, CVE-2020-26143, CVE-2020-26144, CVE-2020-26145, CVE-2020-26146, CVE-2020-26147",7.5,High,"CWE-287, CWE-20, CWE-74, CWE-354, CWE-326, CWE-306",Critical Manufacturing; Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1727,8/24/2021,8/26/2021,2021,ICSA-21-236-02,Hitachi ABB Power Grids Retail Operations and CSB Products,Hitachi and ABB,Retail Operations and Counterparty Settlement Billing (CSB),Hitachi ABB Power Grids reports this vulnerability affects the following utility usage and billing software products: Retail Operations: All Versions 5.7.2 and prior Counterparty Settlement and Billing (CSB): All Versions 5.7.2 and prior.,CVE-2021-35529,7.7,High,CWE-522,Critical Manufacturing; Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1726,8/24/2021,8/24/2021,2021,ICSA-21-236-03,Delta Electronics TPEditor,Delta Electronics,TPEditor,"The following versions of TPEditor, programming software for Delta Electronics text panels, are affected: TPEditor: v1.98.06 and prior.",CVE-2021-33007,7.8,High,CWE-122,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1725,6/17/2021,8/24/2021,2021,ICSA-21-168-03,Advantech WebAccess/SCADA (Update A),Advantech,WebAccess/SCADA,"The following versions of Advantech WebAccess/SCADA, a browser-based SCADA software package, are affected: WebAccess/SCADA Versions 9.0.1 and prior.","CVE-2021-32954, CVE-2021-32956",7.3,High,"CWE-23, CWE-601",Critical Manufacturing; Energy; Water and Wastewater,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1724,8/19/2021,8/19/2021,2021,ICSA-21-231-01,AVEVA SuiteLink Server,AVEVA,SuiteLink Server,AVEVA reports the following products ship a vulnerable version of the SuiteLink Server and are affected: AVEVA System Platform 2020 R2 P01 and all prior versions AVEVA InTouch 2020 R2 P01 and all prior versions AVEVA Historian 2020 R2 P01 and all prior versions AVEVA Communication Drivers Pack 2020 R2 and all prior versions AVEVA Operations Integration Core 3.0 and all prior versions AVEVA Data Acquisition Servers all versions AVEVA Batch Management 2020 and all prior versions AVEVA MES 2014 R2 and all prior versions.,"CVE-2021-32959, CVE-2021-32963, CVE-2021-32971, CVE-2021-32979, CVE-2021-32987, CVE-2021-32999",8.1,High,"CWE-122, CWE-755, CWE-476",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1723,8/17/2021,8/17/2021,2021,ICSA-21-229-01,ThroughTek Kalay P2P SDK,ThroughTek,Kalay P2P SDK,The following versions of Kalay P2P Software Development Kit (SDK) are affected: Versions 3.1.5 and prior SDK versions with the nossl tag Device firmware that does not use AuthKey for IOTC connection Device firmware using the AVAPI module without enabling DTLS mechanism Device firmware using P2PTunnel or RDT module.,CVE-2021-28372,9.6,Critical,CWE-284,Communications,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1722,8/17/2021,8/17/2021,2021,ICSA-21-229-02,Advantech WebAccess/NMS,Advantech,WebAccess/NMS,"The following versions of WebAccess/NMS, a network management system, are affected: WebAccess/NMS: Versions prior to v3.0.3_Build6299.",CVE-2021-32951,5.3,High,CWE-287,Critical Manufacturing; Energy; Water and Wastewater Systems,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1721,8/17/2021,8/17/2021,2021,ICSA-21-229-03,xArrow SCADA,xArrow,SCADA,"The following versions of xArrow, a SCADA/HMI, are affected: Versions 7.2 and prior.","CVE-2021-33001, CVE-2021-33021, CVE-2021-33025",6.1,High,"CWE-22, CWE-79",Critical Manufacturing; Energy; Water and Wastewater Systems,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1720,8/12/2021,8/12/2021,2021,ICSA-21-224-01,Cognex In-Sight OPC Server,Cognex,In-Sight OPC Server,The following versions of In-Sight OPC Server are affected: v5.7.4 (96) and prior.,CVE-2021-32935,8.8,High,CWE-502,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1719,8/12/2021,8/12/2021,2021,ICSA-21-224-02,Horner Automation Cscape,Horner Automation,Cscape,"The following versions of Cscape, a control system application programming software, are affected: Cscape: All Versions prior to 9.90 SP5.","CVE-2021-32975, CVE-2021-32995, CVE-2021-33015",7.8,High,"CWE-824, CWE-125, CWE-787",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1718,7/1/2021,8/12/2021,2021,ICSA-21-182-02,Sensormatic Electronics C-CURE 9000 (Update A),Sensormatic Electronics LLC (Subsidiary of Johnson Controls),C-CURE 9000,Johnson Controls reports the vulnerability affects the following product: C-CURE 9000: All versions prior to 2.80.,CVE-2021-27660,8.8,High,CWE-20,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1717,8/10/2021,8/10/2021,2021,ICSA-21-222-01,Siemens JT2Go and Teamcenter Visualization products,Siemens,JT2Go and Teamcenter Visualization products,The following Siemens products are affected: JT2Go: All versions prior to v13.2.0.1 Teamcenter Visualization: All versions prior to v13.2.0.1.,"CVE-2021-32936, CVE-2021-32938, CVE-2021-32940, CVE-2021-32944, CVE-2021-32948, CVE-2021-32950, CVE-2021-33717",7.8,High,"CWE-476, CWE-125, CWE-787, CWE-416",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1716,8/10/2021,8/10/2021,2021,ICSA-21-222-02,Siemens Automation License Manager,Siemens,Automation License Manager,The following versions of Automation License Manager are affected: Automation License Manager 5: All versions Automation License Manager 6: All versions prior to v6.0 SP9 Update 2.,CVE-2021-25659,5.9,High,CWE-400,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1715,8/10/2021,8/10/2021,2021,ICSA-21-222-04,Siemens SINEC NMS,Siemens,SINEC NMS,The following versions of SINEC NMS are affected: SINEC NMS: All versions prior to v1.0 SP2.,CVE-2021-33721,7.2,High,CWE-78,Chemical; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1714,8/10/2021,12/15/2022,2021,ICSA-21-222-05,Siemens Industrial Products Intel CPUs (Update C),Siemens,"SIMATIC, SINUMERIK","The following Siemens products are affected: SIMATIC Drive Controller Family: All versions SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions SIMATIC Field PG M5: All versions SIMATIC Field PG M6: All versions SIMATIC IPC127E: All versions SIMATIC IPC427E: All versions SIMATIC IPC477E: All versions SIMATIC IPC477E Pro: All versions SIMATIC IPC527GE: All versions SIMATIC IPC547G: All versions SIMATIC IPC627E: All versions SIMATIC IPC647E: All versions SIMATIC IPC677E: All versions SIMATIC IPC847E: All BIOS versions prior to v25.02.10 SIMATIC ITP1000: All versions SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (MLFB: 6ES7518-4AX00-1AC0, 6AG1518-4AX00-4AC0, incl. SIPLUS variant): All versions SIMATIC S7-1500 CPU 1518F-4 PN-DP MFP (MLFB: 6ES7518-4FX00-1AC0): All versions SINUMERIK 828D HW PPU.4: All versions SINUMERIK MC MCU 1720: All versions SINUMERIK ONE / SINUMERIK 840D sl Handheld Terminal HT 10: All versions SINUMERIK ONE PPU 1740: All versions SINUMERIK ONE NCU 1740: All versions prior to v05.00.00.00 SIMATIC IPC127E: All versions prior to v21.01.07 SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions prior to v0209_0105 Update C SIMATIC IPC427E: All versions prior to v21.01.16 SIMATIC IPC477E: All versions prior to v21.01.16 SIMATIC IPC477E Pro: All versions prior to v21.01.16 End Update C.","CVE-2020-12357, CVE-2020-12358, CVE-2020-12360, CVE-2020-24486, CVE-2020-24506, CVE-2020-24507, CVE-2020-24511, CVE-2020-24512, CVE-2020-24513, CVE-2020-8670, CVE-2020-8703, CVE-2020-8704",7.5,High,CWE-311,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1713,8/10/2021,8/10/2021,2021,ICSA-21-222-06,Siemens Energy AGT and SGT Solutions,Siemens,Energy AGT and SGT Solutions,The following Siemens products are affected: SGT-100: All versions SGT-200: All versions SGT-300: All versions SGT-400: All versions SGT-A20: All versions SGT-A35: All versions SGT-A64: All versions.,CVE-2016-20009,9.8,Critical,CWE-787,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1712,8/10/2021,6/16/2022,2021,ICSA-21-222-07,Siemens SIMATIC CP (Update A),Siemens,SIMATIC NET CP,The following Siemens products are affected: SIMATIC NET CP 1543-1 (Incl. SIPLUS NET variants): All versions prior to v3.0 --------- Begin Update A Part 1 of 2 --------- SIMATIC CP 1545-1 (6GK7545-1GX00-0XE0): All versions prior to v1.1 --------- End Update A Part 1 of 2 ---------.,"CVE-2020-9272, CVE-2020-9273",8.8,High,"CWE-125, CWE-416",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1711,8/10/2021,8/19/2021,2021,ICSA-21-222-08,Siemens Solid Edge,Siemens,Solid Edge,The following versions of Solid Edge are affected: Solid Edge SE2021: All versions prior to SE2021MP7.,"CVE-2021-37178, CVE-2021-37179, CVE-2021-37180",7.8,High,"CWE-824, CWE-611, CWE-416",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1710,7/13/2021,8/18/2022,2021,ICSA-21-194-07,Siemens Industrial Products LLDP (Update D),Siemens,Industrial Products,Siemens reports these vulnerabilities affect the following products: SIMATIC HMI Unified Comfort Panels: All versions prior to v17 SIMATIC NET CP 1542SP-1 (6GK7542-6UX00-0XE0): All versions SIMATIC NET CP 1542SP-1 IRC (incl. SIPLUS variants) (6GK7243-8RX30-0XE0): All versions SIMATIC NET CP 1543-1 (incl. SIPLUS variants): All versions SIMATIC NET CP 1543SP-1 (incl. SIPLUS variants): All versions SIMATIC NET CP 1545-1 (6GK7545-1GX00-0XE0): All versions prior to v1.1 --------- Begin Update D Part 1 of 2 --------- SIPLUS S7-1200 CP 1243-1 (6AG1243-1BX30-2AX0): All versions prior to v3.3.46 SIPLUS S7-1200 CP 1243-1 RAIL (6AG2243-1BX30-1XE0): All versions prior to v3.3.46 --------- End Update D Part 1 of 2 --------- SIMATIC NET 1243-1 (incl. SIPLUS variants) (6GK7243-1BX30-0XE0): All versions prior to v3.3.46 SIMATIC NET 1243-8 IRC (6GK7243-8RX30-0XE0): All versions prior to v3.3.46 SINUMERIK ONE MCP: All versions prior to v2.0.1 TIM 1531 IRC (incl. SIPLUS NET variants): All versions prior to v2.2.,"CVE-2020-27827, CVE-2015-8011",9.8,Critical,"CWE-120, CWE-400",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1709,5/11/2021,5/11/2021,2021,ICSA-21-131-04,Siemens SINAMICS Medium Voltage Products Remote Access (Update B),Siemens,SINAMICS Medium Voltage Products,Siemens reports this vulnerability affects the following SINAMICS products with Telnet enabled on SIMATIC HMI Comfort Panels: SINAMICS SL150: All versions SINAMICS SM150: All versions SINAMICS SM150i: All versions.,CVE-2021-31337,7.7,High,"CWE-788, CWE-122, CWE-665, CWE-170, CWE-119, CWE-125, CWE-121, CWE-400",Chemical; Commercial Facilities; Critical Manufacturing; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1708,5/11/2021,8/10/2021,2021,ICSA-21-131-13,Siemens SINAMICS Medium Voltage Products Telnet (Update A),Siemens,SINAMICS Medium Voltage Products,Siemens reports this vulnerability affects the following SINAMICS products with telnet enabled on SIMATIC comfort HMI Panels: SINAMICS GH150: All versions SINAMICS GL150 (with option X30): All versions SINAMICS GM150 (with option X30): All versions SINAMICS SH150: All versions SINAMICS SL150: All versions SINAMICS SM120: All versions SINAMICS SM150: All versions SINAMICS SM150i: All versions.,CVE-2020-15798,7.7,High,CWE-306,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1707,3/9/2021,3/9/2021,2021,ICSA-21-068-06,Siemens TCP/IP Stack Vulnerabilities-AMNESIA:33 in SENTRON PAC / 3VA Devices (Update B),Siemens,Siemens TCP/IP Stack Vulnerabilities-AMNESIA:33 in SENTRON PAC / 3VA Devices,The following products are affected: SENTRON 3VA COM100/800: all versions SENTRON 3VA DSP800: all versions SENTRON PAC2200 (with CLP Approval): all versions SENTRON PAC2200 (with MID Approval): all versions SENTRON PAC2200 (without MID Approval): all versions SENTRON PAC3200: all versions prior to v2.4.7 SENTRON PAC3200T: all versions SENTRON PAC3220: all versions prior to v3.2.0 SENTRON PAC4200: all versions prior to v2.3.0.,"CVE-2020-13987, CVE-2020-17437",6.5,Medium,"CWE-125, CWE-787",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1706,11/10/2020,8/10/2021,2021,ICSA-20-315-04,Siemens SIMATIC S7-300 CPUs and SINUMERIK Controller (Update A),Siemens,SIMATIC S7-300 CPUs and SINUMERIK Controller,Siemens reports the vulnerability affects the following products: SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions SINUMERIK 840D sl: All versions.,"CVE-2020-1578, CVE-2020-15783",5.9,Medium,CWE-400,Chemical; Critical Manufacturing; Food and Agriculture,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1705,3/10/2020,3/10/2020,2021,ICSA-20-070-01,Siemens and PKE SiNVR/SiVMS Video Server (Update B),Siemens and PKE,SiNVR/SiVMS Video Server,The following versions of SiNVR/SiVMS Video Server - a video management solution are affected: SiNVR 3 Central Control Server (CCS): All versions Moved to SSA-761844 and ICSA-21-103-10 SiNVR/SiVMS Video Server: All versions prior to v5.0.0 SiNVR/SiVMS Video Server: v5.0.0 and later is affected by CVE-2019-19298 and CVE-2019-19299.,"CVE-2019-19290, CVE-2019-19291, CVE-2019-19292, CVE-2019-19293, CVE-2019-19294, CVE-2019-19295, CVE-2019-19296, CVE-2019-19297, CVE-2019-19298, CVE-2019-19299",7.5,High,"CWE-313, CWE-20, CWE-22, CWE-327",Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1704,8/5/2021,8/5/2021,2021,ICSA-21-217-02,FATEK Automation FvDesigner,FATEK Automation,FvDesigner,"The following versions of FvDesigner, a software tool used to design and develop FATEK FV HMI series product projects, are affected: FvDesigner, Versions 1.5.88 and prior.","CVE-2021-32931, CVE-2021-32939, CVE-2021-32947",7.8,High,"CWE-824, CWE-787, CWE-121",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1703,8/5/2021,8/5/2021,2021,ICSA-21-217-03,mySCADA myPRO,mySCADA Technologies,myPRO,The following versions of myPro are affected: All versions prior to 8.20.0.,"CVE-2021-27505, CVE-2021-33005, CVE-2021-33009, CVE-2021-33013",8.2,High,"CWE-548, CWE-284, CWE-22, CWE-434",Energy; Food and Agriculture; Transportation Systems; Water and Wastewater Systems,Worldwide,Czech Republic,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1702,8/5/2021,8/5/2021,2021,ICSA-21-217-04,Advantech WebAccess SCADA,Advantech,WebAccess SCADA,"The following versions of WebAccess/SCADA, a browser-based SCADA software package, are affected: WebAccess/SCADA versions prior to 8.4.5 WebAccess/SCADA versions prior to 9.0.1.","CVE-2021-22674, CVE-2021-22676, CVE-2021-32943",9.8,Critical,"CWE-79, CWE-23, CWE-121",Critical Manufacturing; Energy; Water and Wastewater Systems,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1701,8/3/2021,8/3/2021,2021,ICSMA-21-215-01,Swisslog Healthcare Translogic PTS,Swisslog Healthcare,Translogic PTS,"Swisslog Healthcare reports the vulnerabilities affect the following Translogic Pneumatic Tube Systems: Nexus Control Panel, versions prior to 7.2.5.7.","CVE-2021-37160, CVE-2021-37161, CVE-2021-37162, CVE-2021-37163, CVE-2021-37164, CVE-2021-37165, CVE-2021-37166, CVE-2021-37167",9.8,Critical,"CWE-494, CWE-250, CWE-287, CWE-191, CWE-787, CWE-259",Healthcare,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1700,7/29/2021,7/29/2021,2021,ICSA-21-210-01,Hitachi ABB Power Grids eSOMS,Hitachi and ABB,eSOMS,Hitachi ABB Power Grids reports this vulnerability affects the following product: eSOMS: All Versions 6.3 and prior.,CVE-2021-35527,7.5,High,CWE-522,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1699,7/29/2021,7/29/2021,2021,ICSA-21-210-02,Wibu-Systems CodeMeter Runtime,Wibu-Systems AG,CodeMeter Runtime,"The following versions of CodeMeter Runtime, a license manager, are affected: CodeMeter Runtime: All versions prior to v7.21a This license manager is used in the products of many different vendors.","CVE-2021-20093, CVE-2021-20094",9.1,Critical,CWE-126,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1698,7/27/2021,7/27/2021,2021,ICSA-21-208-01,KUKA KR C4,KUKA,KR C4,The following versions of KR C4 are affected: KR C4: All versions prior to 8.7 KSS: All versions.,"CVE-2021-33014, CVE-2021-33016",9.8,Critical,CWE-798,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1697,7/27/2021,7/27/2021,2021,ICSA-21-208-02,Mitsubishi Electric GOT2000 series and GT SoftGOT2000,Mitsubishi Electric,GOT2000 series and GT SoftGOT2000,"Mitsubishi Electric reports this vulnerability affects the MODBUS/TCP slave communication function of following products: GOT2000 models GT27, GT25, GT23: All communication driver versions between 01.19.000 and 01.39.010. These versions are affected when using the ""MODBUS/TCP Slave, Gateway"" communication driver. GT SoftGOT2000: All versions between 1.170C and 1.256S. These versions are affected when configured to use ""MODBUS/TCP Slave"" communication.",CVE-2021-20592,5.9,High,CWE-820,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1696,7/27/2021,7/27/2021,2021,ICSA-21-208-03,Geutebruck G-Cam E2 and G-Code,Geutebruck,G-Cam E2 and G-Code,"The following Geutebruck devices contain the affected third-party firmware provided by UDP Technology: E2 Series cameras - G-CAM; Versions 1.12.0.27 and prior, Versions 1.12.13.2 and 1.12.14.5 EBC-21xx EFD-22xx ETHC-22xx EWPC-22xx Encoder G-Code; Versions 1.12.0.27 and prior, Versions 1.12.13.2 and 1.12.14.5 EEC-2xx EEN-20xx.","CVE-2021-33543, CVE-2021-33544, CVE-2021-33545, CVE-2021-33546, CVE-2021-33547, CVE-2021-33548, CVE-2021-33549, CVE-2021-33550, CVE-2021-33551, CVE-2021-33552, CVE-2021-33553, CVE-2021-33554",9.8,Critical,"CWE-77, CWE-306, CWE-121",Commercial Facilities; Energy; Financial Services; Government Facilities; Healthcare and Public Health; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1695,7/27/2021,7/27/2021,2021,ICSA-21-208-04,LCDS LAquis SCADA,LCDS - Leao Consultoria e Desenvolvimento de Sistemas Ltda ME,LCDS LAquis SCADA,The following versions of LAquis SCADA are affected: Versions 4.3.1.1011 and prior.,CVE-2021-32989,9.3,Critical,CWE-79,Chemical; Commercial Facilities; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater Systems,South America,Brazil,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1694,7/27/2021,7/27/2021,2021,ICSA-21-208-05,Delta Electronics DIAScreen,Delta Electronics,DIAScreen,The following versions of DIAScreen sofware are affected: All versions prior to v1.1.0.,"CVE-2021-32965, CVE-2021-32969",7.8,High,"CWE-843, CWE-787",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1693,7/13/2021,7/27/2021,2021,ICSA-21-194-02,Schneider Electric Modicon Controllers and Software (Update A),Schneider Electric,Modicon Controllers and Software,"Schneider Electric reports these vulnerabilities affect the following control products: EcoStruxure Control Expert, all versions prior to v15.0 SP1 Including all versions of Unity Pro (former name of EcoStruxure Control Expert) EcoStruxure Control Expert v15.0 SP1 EcoStruxure Process Expert, all versions Including all versions of EcoStruxure Hybrid DCS (former name of EcoStruxure Process Expert) SCADAPack RemoteConnect for x70, all versions; SCADAPack 470, 474, 570, 574, and 575 RTUs, all versions; Modicon M580 CPU (part numbers BMEP* and BMEH*), all versions Modicon M340 CPU (part numbers BMXP34*), all versions Please note not all the vulnerabilities listed below affect all the products above. See SEVD-2021-194-01 to see how they correlate.","CVE-2021-22778, CVE-2021-22779, CVE-2021-22780, CVE-2021-22781, CVE-2021-22782, CVE-2020-12525",9.8,Critical,"CWE-290, CWE-502, CWE-522, CWE-311",Commercial Facilities; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater Systems,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1692,7/1/2021,9/29/2022,2021,ICSA-21-182-03,Delta Electronics DOPSoft (Update B),Delta Electronics,DOPSoft,"The following versions of DOPSoft, a software supporting the DOP-100 series HMI screens, are affected: DOPSoft Version 4.0.10.17 and prior.","CVE-2021-27412, CVE-2021-27455",7.8,High,CWE-125,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1691,6/29/2021,7/27/2021,2021,ICSA-21-180-05,AVEVA System Platform (Update A),AVEVA,AVEVA System Platform,AVEVA reports the vulnerability affects AVEVA System Platform versions 2017 through 2020 R2 P01 (inclusive).,"CVE-2021-33008, CVE-2021-33010",8.8,High,"CWE-306, CWE-248",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1690,4/22/2021,7/28/2021,2021,ICSA-21-112-02,Mitsubishi Electric GOT (Update A),Mitsubishi Electric,Mitsubishi Electric GOT,Mitsubishi Electric reports the vulnerability affects the VNC function of the following devices: GOT2000 series GT27 model: All versions GT25 model: All versions GT21 model: All versions GT2107-WTBD: All versions GT2107-WTSD: All versions GOT SIMPLE series GS21 model GS2110-WTBD-N: All versions GS2107-WTBD-N: All versions.,CVE-2021-20590,5.9,Medium,CWE-287,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1689,7/20/2021,7/20/2021,2021,ICSA-21-201-01,Mitsubishi Electric MELSEC-F Series,Mitsubishi Electric,MELSEC-F Series,Mitsubishi Electric reports this vulnerability exists in the following MELSEC-F series Ethernet interface block: FX3U-ENET: Firmware Version 1.14 and prior FX3U-ENET-L: Firmware Version 1.14 and prior FX3U-ENET-P502: Firmware Version 1.14 and prior.,CVE-2021-20596,7.5,High,CWE-476,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1688,7/15/2021,7/15/2021,2021,ICSMA-21-196-01,Ypsomed mylife,Ypsomed,"mylife Cloud, mylife Mobile Application","The following versions of Ypsomed mylife diabetes management platform, are affected: Ypsomed mylife Cloud: All versions prior to 1.7.2 Ypsomed mylife App: All versions prior to 1.7.5.","CVE-2021-27491, CVE-2021-27495, CVE-2021-27499, CVE-2021-27503",6.3,High,"CWE-522, CWE-329, CWE-798",Healthcare and Public Health,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1687,7/13/2021,7/13/2021,2021,ICSA-21-194-01,Schneider Electric C-Bus Toolkit,Schneider Electric,C-Bus Toolkit,The following versions of C-Bus Toolkit are affected: C-Bus Toolkit Versions 1.15.8 and prior.,CVE-2021-22784,6.5,High,CWE-306,Commercial Facilities,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1686,7/13/2021,7/13/2021,2021,ICSA-21-194-04,Siemens SINUMERIK Integrate Operate Client,Siemens,SINUMERIK Integrate Operate Client,The following versions of SINUMERIK are affected: SINUMERIK Analyze MyCondition: All versions SINUMERIK Analyze MyPerformance: All versions SINUMERIK Analyze MyPerformance / OEE-Monitor: All versions SINUMERIK Analyze MyPerformance / OEE-Tuning: All versions SINUMERIK Integrate Client 02: All versions including v02.00.12 and up to but not including v02.00.18 SINUMERIK Integrate Client 03: All versions between v03.00.12 and up to but not including v03.00.18 SINUMERIK Integrate Client 04: Version v04.00.02 and all versions including v04.00.15 up to but not including v04.00.18 SINUMERIK Integrate for Production 4.1: All versions prior to v4.1 SP10 HF3 SINUMERIK Integrate for Production 5.1: Version 5.1 SINUMERIK Manage MyMachines: All versions SINUMERIK Manage MyMachines / Remote: All versions SINUMERIK Manage MyMachines / Spindel Monitor: All versions SINUMERIK Manage MyPrograms: All versions SINUMERIK Manage MyResources / Programs: All versions SINUMERIK Manage MyResources / Tools: All versions SINUMERIK Manage My Tools: All versions SINUMERIK Operate v4.8: All versions prior to v4.8 SP8 SINUMERIK Operate v4.93: All versions prior to v4.93 HF7 SINUMERIK Operate v4.94: All versions prior to v4.94 HF5 SINUMERIK Optimize MyProgramming / NX-Cam Editor: All versions.,CVE-2021-31892,7.4,High,CWE-295,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1685,7/13/2021,7/13/2021,2021,ICSA-21-194-05,Siemens SIMATIC Software Products,Siemens,SIMATIC Software Products,Siemens reports this vulnerability affects the following SIMATIC software products: SIMATIC PCS 7 v8.2 and earlier: All versions SIMATIC PCS 7 v9.0: All versions prior to 9.0 SP3 SIMATIC PDM: All versions prior to v9.2 SIMATIC STEP 7 v5.X: All versions prior to v5.6 SP2 HF3 SINAMICS STARTER (containing STEP 7 OEM version): All versions prior to v5.4 HF2.,CVE-2021-31893,7.8,High,CWE-120,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1684,7/13/2021,7/14/2021,2021,ICSA-21-194-08,Siemens Solid Edge,Siemens,Solid Edge,"The following versions of Siemens Solid Edge, a portfolio of software tools, are affected: All versions prior to SE2021MP5.","CVE-2021-34326, CVE-2021-34327, CVE-2021-34328, CVE-2021-34329",7.8,High,CWE-122,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1683,7/13/2021,7/13/2021,2021,ICSA-21-194-09,Siemens JT Utilities,Siemens,JT Utilities,The following versions of Siemens JT Utilities are affected: All versions prior to v13.0.2.0.,"CVE-2021-33713, CVE-2021-33714, CVE-2021-33715",5.5,High,"CWE-688, CWE-476",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1682,7/13/2021,7/13/2021,2021,ICSA-21-194-10,Siemens RUGGEDCOM ROS,Siemens,RUGGEDCOM ROS,The following Siemens products are affected: RUGGEDCOM ROS i800: All versions prior to 4.3.7 RUGGEDCOM ROS i801: All versions prior to 4.3.7 RUGGEDCOM ROS i802: All versions prior to 4.3.7 RUGGEDCOM ROS i803: All versions prior to 4.3.7 RUGGEDCOM ROS M969: All versions prior to 4.3.7 RUGGEDCOM ROS M2100: All versions prior to 4.3.7 RUGGEDCOM ROS M2200: All versions prior to 4.3.7 RUGGEDCOM ROS RMC: All versions prior to 4.3.7 RUGGEDCOM ROS RMC20: All versions prior to 4.3.7 RUGGEDCOM ROS RMC30: All versions prior to 4.3.7 RUGGEDCOM ROS RMC40: All versions prior to 4.3.7 RUGGEDCOM ROS RMC41: All versions prior to 4.3.7 RUGGEDCOM ROS RMC8388 V4.X: All versions prior to 4.3.7 RUGGEDCOM ROS RMC8388 V5.X: All versions prior to 5.5.4 RUGGEDCOM ROS RP110: All versions prior to 4.3.7 RUGGEDCOM ROS RS400: All versions prior to 4.3.7 RUGGEDCOM ROS RS401: All versions prior to 4.3.7 RUGGEDCOM ROS RS416: All versions prior to 4.3.7 RUGGEDCOM ROS RS416V2 V4.X: All versions prior to 4.3.7 RUGGEDCOM ROS RS416V2 V5.X: All versions prior to 5.5.4 RUGGEDCOM ROS RS900 (32M) V4.X: All versions prior to 4.3.7 RUGGEDCOM ROS RS900 (32M) V5.X: All versions prior to 5.5.4 RUGGEDCOM ROS RS900G: All versions prior to 4.3.7 RUGGEDCOM ROS RS900G (32M) V4.X: All versions prior to 4.3.7 RUGGEDCOM ROS RS900G (32M) V5.X: All versions prior to 5.5.4 RUGGEDCOM ROS RS900GP: All versions prior to 4.3.7 RUGGEDCOM ROS RS900L: All versions prior to 4.3.7 RUGGEDCOM ROS PS900W: All versions prior to 4.3.7 RUGGEDCOM ROS RS910: All versions prior to 4.3.7 RUGGEDCOM ROS RS910L: All versions prior to 4.3.7 RUGGEDCOM ROS RS910W: All versions prior to 4.3.7 RUGGEDCOM ROS RS920L: All versions prior to 4.3.7 RUGGEDCOM ROS RS920W: All versions prior to 4.3.7 RUGGEDCOM ROS RS930L: All versions prior to 4.3.7 RUGGEDCOM ROS RS930W: All versions prior to 4.3.7 RUGGEDCOM ROS RS940G: All versions prior to 4.3.7 RUGGEDCOM ROS RS969: All versions prior to 4.3.7 RUGGEDCOM ROS RS8000: All versions prior to 4.3.7 RUGGEDCOM ROS RS8000A: All versions prior to 4.3.7 RUGGEDCOM ROS RS8000H: All versions prior to 4.3.7 RUGGEDCOM ROS RS8000T: All versions prior to 4.3.7 RUGGEDCOM ROS RSG900 V4.X: All versions prior to 4.3.7 RUGGEDCOM ROS RSG900 V5.X: All versions prior to 5.5.4 RUGGEDCOM ROS RSG900C: All versions prior to 5.5.4 RUGGEDCOM ROS RSG900G V4.X: All versions prior to 4.3.7 RUGGEDCOM ROS RSG800G V5.X: All versions prior to 5.5.4 RUGGEDCOM ROS RSG900R: All versions prior to 5.5.4 RUGGEDCOM ROS RSG920P V4.X: All versions prior to 4.3.7 RUGGEDCOM ROS RSG920P V5.X: All versions prior to 5.5.4 RUGGEDCOM ROS RSG2100 (32M) V4.X: All versions prior to 4.3.7 RUGGEDCOM ROS RSG2100 (32M) V5.X: All versions prior to 5.5.4 RUGGEDCOM ROS RSG2100 V4.X: All versions prior to 4.3.7 RUGGEDCOM ROS RSG2100P: All versions prior to 4.3.7 RUGGEDCOM ROS RSG2100P (32M) V4.X: All versions prior to 4.3.7 RUGGEDCOM ROS RSG2100P (32M) V5.X: All versions prior to 5.5.4 RUGGEDCOM ROS RSG2200: All versions prior to 4.3.7 RUGGEDCOM ROS RSG2288 V4.X: All versions prior to 4.3.7 RUGGEDCOM ROS RSG2288 V5.X: All versions prior to 5.5.4 RUGGEDCOM ROS RSG2300 V4.X: All versions prior to 4.3.7 RUGGEDCOM ROS RSG2300 V5.X: All versions prior to 5.5.4 RUGGEDCOM ROS RSG2300P V4.X: All versions prior to 4.3.7 RUGGEDCOM ROS RSG2300P V5.X: All versions prior to 5.5.4 RUGGEDCOM ROS RSG2488 V4.X: All versions prior to 4.3.7 RUGGEDCOM ROS RSG2488 V5.X: All versions prior to 5.5.4 RUGGEDCOM ROS RSL910: All versions prior to 5.5.4 RUGGEDCOM ROS RST916C: All versions prior to 5.5.4 RUGGEDCOM ROS RST916P: All versions prior to 5.5.4 RUGGEDCOM ROS RST2228: All versions prior to 5.5.4.,CVE-2021-31895,8.1,High,CWE-120,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1681,7/13/2021,7/13/2021,2021,ICSA-21-194-11,Siemens Teamcenter Active Workspace,Siemens,Teamcenter Active Workspace,"The following versions of Smart Security Manager, a software management platform, are affected: Teamcenter Active Workspace v4: All versions prior to v4.3.9 Teamcenter Active Workspace v5.0: All versions prior to v5.0.7 Teamcenter Active Workspace v5.1: All versions prior to v5.1.4.","CVE-2021-33709, CVE-2021-33710, CVE-2021-33711",6.1,High,"CWE-200, CWE-79, CWE-209",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1680,7/13/2021,7/14/2022,2021,ICSA-21-194-12,Siemens VxWorks-based Industrial Products (Update C),Siemens,Wind River VxWorks-based Industrial Products,"Siemens reports this vulnerability affects the following Wind River VxWorks-based industrial products: RUGGEDCOM WIN5100 series subscriber unit: All versions RUGGEDCOM WIN5200 series subscriber unit: All versions SCALANCE X200-4P IRT (6GK5200-4AH00-2BA3): All versions SCALANCE X201-3P IRT (6GK5201-3BH00-2BA3): All versions SCALANCE X201-3P IRT PRO (6GK5201-3BH00-2BD2): All versions SCALANCE X202-2IRT (6GK5202-2BB00-2BA3): All versions SCALANCE X202-2P IRT (6GK5202-2BH00-2BA3): All versions SCALANCE X202-2P IRT PRO (6GK5202-2JR00-2BA6): All versions SCALANCE X204-2 (6GK5204-2BB10-2AA3): All versions SCALANCE X204-2FM (6GK5204-2BB11-2AA3): All versions SCALANCE X204-2LD (6GK5204-2BC10-2AA3): All versions SCALANCE X204-2LD TS (6GK5204-2BC10-2CA2): All versions SCALANCE X204-2TS (6GK5204-2BB10-2CA2): All versions SCALANCE X204IRT (6GK5204-0BA00-2BA3): All versions SCALANCE X204IRT PRO (6GK5204-0JA00-2BA6): All versions SCALANCE X206-1 (6GK5206-1BB10-2AA3): All versions SCALANCE X206-1LD (6GK5206-1BC10-2AA3): All versions SCALANCE X208 (6GK5208-0BA10-2AA3): All versions SCALANCE X208PRO (6GK5208-0HA10-2AA6): All versions SCALANCE X212-2 (6GK5212-2BB00-2AA3): All versions SCALANCE X212-2LD (6GK5212-2BC00-2AA3): All versions SCALANCE X216 (6GK5216-0BA00-2AA3): All versions SCALANCE X224 (6GK5224-0BA00-2AA3): All versions SCALANCE X302-7 EEC (2x 24V) (6GK5302-7GD00-2EA3): All versions SCALANCE X302-7 EEC (2x 24V, coated) (6GK5302-7GD00-2GA3): All versions SCALANCE X302-7 EEC (2x 230V) (6GK5302-7GD00-4EA3): All versions SCALANCE X302-7 EEC (2x 230V, coated) (6GK5302-7GD00-4GA3): All versions SCALANCE X302-7 EEC (24V) (6GK5302-7GD00-1EA3): All versions SCALANCE X302-7 EEC (24V, coated) (6GK5302-7GD00-1GA3): All versions SCALANCE X302-7 EEC (230V) (6GK5302- 7GD00-3EA3): All versions SCALANCE X302-7 EEC (230V, coated) (6GK5302-7GD00-3GA3): All versions SCALANCE X304-2FE (6GK5304-2BD00-2AA3): All versions SCALANCE X306-1LD FE (6GK5306-1BF00-2AA3): All versions SCALANCE X307-2 EEC (2x 24V) (6GK5307-2FD00-2EA3): All versions SCALANCE X307-2 EEC (2x 24V, coated) (6GK5307-2FD00-2GA3): All versions SCALANCE X307-2 EEC (2x 230V) (6GK5307-2FD00-4EA3): All versions SCALANCE X307-2 EEC (2x 230V, coated) (6GK5307-2FD00-4GA3): All versions SCALANCE X307-2 EEC (24V) (6GK5307-2FD00-1EA3): All versions SCALANCE X307-2 EEC (24V, coated) (6GK5307-2FD00-1GA3): All versions SCALANCE X307-2 EEC (230V) (6GK5307-2FD00-3EA3): All versions SCALANCE X307-2 EEC (230V, coated) (6GK5307-2FD00-3GA3): All versions SCALANCE X307-3 (6GK5307-3BL00-2AA3): All versions SCALANCE X307-3 (6GK5307-3BL10-2AA3): All versions SCALANCE X307-3LD (6GK5307-3BM00-2AA3): All versions SCALANCE X307-3LD (6GK5307-3BM10-2AA3): All versions SCALANCE X308-2 (6GK5308-2FL00-2AA3): All versions SCALANCE X308-2 (6GK5308-2FL10-2AA3): All versions SCALANCE X308-2LD (6GK5308-2FM00-2AA3): All versions SCALANCE X308-2LD (6GK5308-2FM10-2AA3): All versions SCALANCE X308-2LH (6GK5308-2FN00-2AA3): All versions SCALANCE X308-2LH (6GK5308-2FN10-2AA3): All versions SCALANCE X308-2LH+ (6GK5308-2FP00-2AA3): All versions SCALANCE X308-2LH+ (6GK5308-2FP10-2AA3): All versions SCALANCE X308-2M (6GK5308-2GG00-2AA2): All versions SCALANCE X308-2M (6GK5308-2GG10-2AA2): All versions SCALANCE X308-2M PoE (6GK5308-2QG00-2AA2): All versions SCALANCE X308-2M PoE (6GK5308-2QG10-2AA2): All versions SCALANCE X308-2M TS (6GK5308-2GG00-2CA2): All versions SCALANCE X308-2M TS (6GK5308-2GG10-2CA2): All versions SCALANCE X310 (6GK5310-0FA00-2AA3): All versions SCALANCE X310 (6GK5310-0FA10-2AA3): All versions SCALANCE X310FE (6GK5310-0BA00-2AA3): All versions SCALANCE X310FE (6GK5310-0BA10-2AA3): All versions SCALANCE X320-1 FE (6GK5320-1BD00-2AA3): All versions SCALANCE X320-1-2LD FE (6GK5320-3BF00-2AA3): All versions SCALANCE X408-2 (6GK5408-2FD00-2AA2): All versions SCALANCE XF201-3P IRT (6GK5201-3JR00-2BA6): All versions SCALANCE XF202-2P IRT (6GK5202-2BH00-2BD2): All versions SCALANCE XF204 (6GK5204-0BA00-2AF2): All versions SCALANCE XF204-2 (6GK5204-2BC00-2AF2): All versions SCALANCE XF204-2BA IRT (6GK5204-2AA00-2BD2): All versions SCALANCE XF204IRT (6GK5204-0BA00-2BF2): All versions SCALANCE XF206-1 (6GK5206-1BC00-2AF2): All versions SCALANCE XF208 (6GK5208-0BA00-2AF2): All versions SCALANCE XR324-4M EEC (2x 24V, ports on front) (6GK5324-4GG00-2ER2): All versions SCALANCE XR324-4M EEC (2x 24V, ports on front) (6GK5324-4GG10-2ER2): All versions SCALANCE XR324-4M EEC (2x 24V, ports on rear) (6GK5324-4GG00-2JR2): All versions SCALANCE XR324-4M EEC (2x 24V, ports on rear) (6GK5324-4GG10-2JR2): All versions SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front) (6GK5324-4GG00-4ER2): All versions SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front) (6GK5324-4GG10-4ER2): All versions SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG00-4JR2): All versions SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG10-4JR2): All versions SCALANCE XR324-4M EEC (24V, ports on front) (6GK5324-4GG00-1ER2): All versions SCALANCE XR324-4M EEC (24V, ports on front) (6GK5324-4GG10-1ER2): All versions SCALANCE XR324-4M EEC (24V, ports on rear) (6GK5324-4GG00-1JR2): All versions SCALANCE XR324-4M EEC (24V, ports on rear) (6GK5324-4GG10-1JR2): All versions SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front) (6GK5324-4GG00-3ER2): All versions SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front) (6GK5324-4GG10-3ER2): All versions SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG00-3JR2): All versions SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear) (6GK5324-4GG10-3JR2): All versions SCALANCE XR324-4M PoE (24V, ports on front) (6GK5324-4QG00-1AR2): All versions SCALANCE XR324-4M PoE (24V, ports on rear) (6GK5324-4QG00-1HR2): All versions SCALANCE XR324-4M PoE (230V, ports on front) (6GK5324-4QG00-3AR2): All versions SCALANCE XR324-4M PoE (230V, ports on rear) (6GK5324-4QG00-3HR2): All versions SCALANCE XR324-4M PoE TS (24V, ports on front) (6GK5324-4QG00-1CR2): All versions SCALANCE XR324-12M (24V, ports on front) (6GK5324-0GG00-1AR2): All versions SCALANCE XR324-12M (24V, ports on front) (6GK5324-0GG10-1AR2): All versions SCALANCE XR324-12M (24V, ports on rear) (6GK5324-0GG00-1HR2): All versions SCALANCE XR324-12M (24V, ports on rear) (6GK5324-0GG10-1HR2): All versions SCALANCE XR324-12M (230V, ports on front) (6GK5324-0GG00-3AR2): All versions SCALANCE XR324-12M (230V, ports on front) (6GK5324-0GG10-3AR2): All versions SCALANCE XR324-12M (230V, ports on rear) (6GK5324-0GG00-3HR2): All versions SCALANCE XR324-12M (230V, ports on rear) (6GK5324-0GG10-3HR2): All versions SCALANCE XR324-12M TS (24V) (6GK5324-0GG00-1CR2): All versions SCALANCE XR324-12M TS (24V) (6GK5324-0GG10-1CR2): All versions SIMATIC RF180C (6GT2002-0JD00): All versions SIMATIC RF182C (6GT2002-0JD10): All versions SIMATIC RFID 181EIP (6GT2002-0JD20): All versions SIPLUS NET SCALANCE X308-2 (6AG1308-2FL10-4AA3): All versions --------- Begin Update C Part 1 of 2 --------- SINAMICS PERFECT HARMONY GH180 Drives: Drives manufactured between 2015 and 2021 (Drives manufactured in 2022 are not affected) --------- End Update C Part 1 of 2 ---------.",CVE-2021-29998,9.8,Critical,CWE-122,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1679,7/13/2021,7/13/2021,2021,ICSA-21-194-14,Siemens RWG Universal Controllers,Siemens,RWG Universal Controllers,Siemens reports this vulnerability affects the following RWG controllers: RWG1.M8: All versions prior to v1.16.16 RWG1.M12: All versions prior to v1.16.16 RWG1.M12D: All versions prior to v1.16.16.,CVE-2021-25671,6.5,High,CWE-770,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1678,7/13/2021,7/13/2021,2021,ICSA-21-194-15,Siemens JT2Go and Teamcenter Visualization,Siemens,JT2Go and Teamcenter Visualization,The following Siemens products are affected: JT2Go: All versions prior to v13.2 Teamcenter Visualization: All versions prior to v13.2.,"CVE-2021-34291, CVE-2021-34292, CVE-2021-34293, CVE-2021-34294, CVE-2021-34295, CVE-2021-34296, CVE-2021-34297, CVE-2021-34298, CVE-2021-34299, CVE-2021-34300, CVE-2021-34301, CVE-2021-34302, CVE-2021-34303, CVE-2021-34304, CVE-2021-34305, CVE-2021-34306, CVE-2021-34307, CVE-2021-34308, CVE-2021-34309, CVE-2021-34310, CVE-2021-34311, CVE-2021-34312, CVE-2021-34313, CVE-2021-34314, CVE-2021-34315, CVE-2021-34316, CVE-2021-34317, CVE-2021-34318, CVE-2021-34319, CVE-2021-34320, CVE-2021-34321, CVE-2021-34322, CVE-2021-34323, CVE-2021-34324, CVE-2021-34325, CVE-2021-34326, CVE-2021-34327, CVE-2021-34328, CVE-2021-34329, CVE-2021-34330, CVE-2021-34331, CVE-2021-34332, CVE-2021-34333",7.8,High,"CWE-126, CWE-415, CWE-122, CWE-119, CWE-835, CWE-125, CWE-787, CWE-416",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1677,7/13/2021,7/13/2021,2021,ICSA-21-194-16,Siemens Mendix,Siemens,Mendix,The following Mendix Applications are affected: Mendix Applications using Mendix 7: All versions prior to v7.23.22 Mendix Applications using Mendix 8: All versions prior to v8.18.7 Mendix Applications using Mendix 9: All versions prior to v9.3.0.,CVE-2021-33718,5.3,High,CWE-863,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1676,3/8/2018,3/8/2018,2021,ICSA-18-067-01,"Siemens SIPROTEC 4, SIPROTEC Compact, DIGSI 4, and EN100 Ethernet Module (Update D)",Siemens,"SIPROTEC 4, SIPROTEC Compact, DIGSI 4, and EN100 Ethernet Module",Siemens reports that the vulnerabilities affect the following products: DIGSI 4: All versions prior to v4.92 | EN100 Ethernet module IEC 61850 variant: All versions prior to v4.30 | EN100 Ethernet module PROFINET IO variant: All versions | EN100 Ethernet module Modbus TCP variant: All versions | EN100 Ethernet module DNP3 variant: All versions | EN100 Ethernet module IEC 104 variant: All versions | SIPROTEC Compact 7SJ80: All versions prior to v4.77. Only affected by CVE-2018-4839 | SIPROTEC Compact 7SK80: All versions prior to v4.77. Only affected by CVE-2018-4839 | SIPROTEC 4 7SJ61 | 7SJ62 and 7SJ64: All versions prior to v4.96. Only affected by CVE-2018-4839 | SIPROTEC 4 7SJ66: All versions prior to v4.30. Only affected by CVE-2018-4839 | SIPROTEC 4 7SD80: All versions prior to v4.70. Only affected by CVE-2018-4839 |Other SIPROTEC Compact relays: All versions. Only affected by CVE-2018-4839 andOther SIPROTEC 4 relays: All versions. Only affected by CVE-2018-4839.,"CVE-2018-4839, CVE-2018-4840",7.5,High,"CWE-326, CWE-306",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1675,7/14/2020,7/14/2020,2021,ICSA-20-196-05,Siemens UMC Stack (Update H),Siemens,UMC Stack,Siemens reports that some of the vulnerabilities affect the following UMC components. For a complete list of which specific vulnerabilities affect each of these products; please see Siemens security advisory SSA-841348: Opcenter Execution Discrete: All versions prior to v3.2 Opcenter Execution Foundation: All versions prior to v3.2 Opcenter Execution Process: All versions prior to v3.2. Opcenter Intelligence: All versions prior to v3.3; Opcenter RD&L: v8.0 SIMATIC IT LMS: All versions SIMATIC IT Production Suite: All versions prior to v8.0. Only affected by CVE-2020-7587 and CVE-2020-7588 SIMATIC Notifier Server for Windows: All versions SIMATIC PCS neo: All versions prior to v3.0 SP1 SIMATIC STEP 7 (TIA Portal) v15: All versions prior to v15.1 update 5 SIMATIC STEP 7 (TIA Portal) v16: All versions prior to v16 Update 2 SIMOCODE ES v16: All versions prior to v16 Update 1 SIMOCODE ES v15.1: All versions prior to v15.1 Update 4 Soft Starter ES v15.1: All versions prior to v15.1 Update 3 Soft Starter ES v16: All versions prior to v16 Update 1.,"CVE-2020-7581, CVE-2020-7587, CVE-2020-7588",6.7,Medium,"CWE-20, CWE-400, CWE-428",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1674,7/8/2021,7/8/2021,2021,ICSA-21-189-01,Rockwell Automation MicroLogix 1100,Rockwell Automation,MicroLogix 1100,Rockwell Automation reports the vulnerability affects the following products: MicroLogix 1100: All versions.,CVE-2021-33012,8.6,High,CWE-20,Chemical; Critical Manufacturing; Food and Agriculture; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1673,7/8/2021,7/8/2021,2021,ICSA-21-189-02,MDT AutoSave,MDT Software,MDT AutoSave,MDT Software reports the vulnerabilities affect the following MDT Autosave products: MDT AutoSave versions prior to v6.02.06 MDT AutoSave v7.00-7.04 AutoSave for System Platform (A4SP) versions prior to 4.01 A4SP Version 5.00.,"CVE-2021-32933, CVE-2021-32937, CVE-2021-32945, CVE-2021-32949, CVE-2021-32953, CVE-2021-32957, CVE-2021-32961",10.0,Critical,"CWE-77, CWE-89, CWE-326, CWE-209, CWE-23, CWE-427, CWE-434",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Healthcare and Public Health; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1672,7/6/2021,2/21/2023,2021,ICSMA-21-187-01,Philips Vue PACS,Philips,Vue PACS,Philips reports these vulnerabilities affect the following Vue PACS products: Vue PACS: Versions 12.2.x.x and prior Vue MyVue: Versions 12.2.x.x and prior Vue Speech: Versions 12.2.x.x and prior Vue Motion: Versions 12.2.1.5 and prior.,"CVE-2021-27493, CVE-2021-27497, CVE-2021-27501, CVE-2021-33018, CVE-2021-33020, CVE-2021-33022, CVE-2021-33024, CVE-2020-1938, CVE-2020-4670, CVE-2019-9636, CVE-2018-10115, CVE-2018-11218, CVE-2018-12326, CVE-2018-8014, CVE-2015-9251, CVE-2012-1708",9.8,Critical,"CWE-119, CWE-176, CWE-1188, CWE-1214, CWE-20, CWE-287, CWE-319, CWE-324, CWE-327, CWE-522, CWE-665, CWE-693, CWE-79, CWE-707, CWE-710",Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1671,7/6/2021,7/6/2021,2021,ICSA-21-187-01,Moxa NPort IAW5000A-I/O Series Serial Device Server,Moxa,NPort IAW5000A-I/O Series Serial Device Server,Moxa reports these vulnerabilities affect the following wireless device server: NPort IAW5000A-I/O Series firmware Version 2.2 or earlier.,"CVE-2021-32968, CVE-2021-32970, CVE-2021-32974, CVE-2021-32976",9.8,Critical,"CWE-120, CWE-20, CWE-78, CWE-121",Energy Sector,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1670,7/1/2021,7/1/2021,2021,ICSA-21-182-01,Johnson Controls Facility Explorer,Johnson Controls Inc.,Facility Explorer,Johnson Controls reports this vulnerability affects the following product: Facility Explorer SNC Series Supervisory Controller: Version 11.,CVE-2021-27661,8.8,High,CWE-269,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1669,7/1/2021,7/1/2021,2021,ICSA-21-182-04,Mitsubishi Electric Air Conditioning System,Mitsubishi Electric,Air Conditioning System,"Mitsubishi Electric reports this vulnerability affects the following air conditioning systems: Air Conditioning System / Centralized Controllers affected: G-50A: Version 2.50 to Version 3.35 GB-50A: Version 2.50 to Version 3.35 AG-150A-A: Versions 3.20 and prior AG-150A-J: Versions 3.20 and prior GB-50ADA-A: Versions 3.20 and prior GB-50ADA-J: Versions 3.20 and prior EB-50GU-A: Versions 7.09 and prior EB-50GU-J: Versions 7.09 and prior AE-200A: Versions 7.93 and prior AE-200E: Versions 7.93 and prior AE-50A: Versions 7.93 and prior AE-50E: Versions 7.93 and prior EW-50A: Versions 7.93 and prior EW-50E: Versions 7.93 and prior TE-200A: Versions 7.93 and prior TE-50A: Versions 7.93 and prior TW-50A: Versions 7.93 and prior CMS-RMD-J: Versions 1.30 and prior Air Conditioning System / Expansion Controllers are affected: PAC-YG50ECA: Versions 2.20 and prior To learn how to determine the version number of equipment, please see publication number 2021-004 from Mitsubishi Electric.",CVE-2021-20593,7.1,High,CWE-303,Commercial Facilities,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1668,7/1/2021,7/1/2021,2021,ICSA-21-182-05,Mitsubishi Electric Air Conditioning Systems,Mitsubishi Electric,Air Conditioning Systems,"Mitsubishi Electric reports this vulnerability affects the following air conditioning systems: Air Conditioning System/Centralized Controllers: G-50A: Versions 3.35 and prior GB-50A: Versions 3.35 and prior GB-24A: Versions 9.11 and prior AG-150A-A: Versions 3.20 and prior AG-150A-J: Versions 3.20 and prior GB-50ADA-A: Versions 3.20 and prior GB-50ADA-J: Versions 3.20 and prior EB-50GU-A: Versions 7.09 and prior EB-50GU-J: Versions 7.09 and prior AE-200A: Versions 7.93 and prior AE-200E: Versions 7.93 and prior AE-50A: Versions 7.93 and prior AE-50E: Versions 7.93 and prior EW-50A: Versions 7.93 and prior EW-50E: Versions 7.93 and prior TE-200A: Versions 7.93 and prior TE-50A: Versions 7.93 and prior TW-50A: Versions 7.93 and prior CMS-RMD-J: Versions 1.30 and prior Air Conditioning System/Expansion Controllers: PAC-YG50ECA: Versions 2.20 and prior Air Conditioning System/BM adapter: BAC-HD150: Versions 2.21 and prior To learn how to determine the version number of equipment, please see publication number 2021-005 from Mitsubishi Electric.",CVE-2021-20595,9.3,Critical,CWE-611,Commercial Facilities,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1667,1/26/2021,7/22/2021,2021,ICSA-21-026-02,All Bachmann M1 System Processor Modules,Bachmann Electronic GmbH,All Bachmann M1 System Processor Modules,"All M-Base Operating Systems and Middleware versions since MSYS v1.06.14 are affected, which include the following M1 Hardware Controllers: MX207, MX213, MX220, MC206, MC212, MC220, MH230. This list indicates actively supported controllers. MC205, MC210, MH212, ME203, CS200, MP213, MP226, MPC240, MPC265, MPC270, MPC293, MPE270, CPC210. This list indicates End-of-Life controllers.",CVE-2020-16231,7.2,High,CWE-916,Energy; Transportation Systems,Worldwide,Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1666,6/29/2021,8/18/2021,2021,ICSA-21-180-01,Exacq Technologies exacqVision Web Service,Exacq Technologies Inc (Subsidiary of Johnson Controls),exacqVision Web Service,The following versions of Exacq Technologies exacqVision Web Service software are affected: exacqVision Web Service: Version 21.03 and prior.,CVE-2021-27659,5.3,Medium,CWE-79,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1665,6/29/2021,8/18/2021,2021,ICSA-21-180-02,Exacq Technologies exacqVision Enterprise Manager,Exacq Technologies Inc (Subsidiary of Johnson Controls),exacqVision Enterprise Manager,The following versions of Exacq Technologies exacqVision Enterprise Manager software are affected: exacqVision Enterprise Manager: Version 20.12 and prior.,CVE-2021-27658,4.3,Medium,CWE-79,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1664,6/29/2021,6/29/2021,2021,ICSA-21-180-03,Panasonic FPWIN Pro,Panasonic,FPWIN Pro,Panasonic reports this vulnerability affects the following products: FPWIN Pro programming control software: All Versions 7.5.1.1 and prior.,CVE-2021-32972,5.9,Medium,CWE-611,Commercial Facilities; Critical Manufacturing; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1663,6/29/2021,7/1/2021,2021,ICSA-21-180-04,JTEKT TOYOPUC PLC,JTEKT ELECTRONICS CORPORATION,TOYOPUC PLC,The following versions of the PLC are affected: PC10G-CPU 2PORT-EFR Plus CPU Plus EX Plus EX2 Plus EFR Plus EFR2 Plus 2P-EFR PC10P-DP PC10P-DP-IO Plus BUS-EX Nano 10GX Nano 2ET PC10PE PC10PE-16/16P PC10E FL/ET-T-V2H PC10B PC10B-P Nano CPU PC10P PC10GE.,CVE-2021-27477,6.5,Medium,CWE-119,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1662,6/29/2021,6/29/2021,2021,ICSA-21-180-06,Claroty Secure Remote Access Site,Claroty,Secure Remote Access Site,The following versions of SRA are affected: Versions 3.0 through 3.2.,CVE-2021-32958,5.5,Medium,CWE-288,Critical Manufacturing; Energy; Healthcare and Public Health; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1661,6/24/2021,6/24/2021,2021,ICSMA-21-175-01,Philips Interoperability Solution XDS,Philips,Interoperability Solution XDS,The following versions of the Philips Interoperability Solution XDS document sharing system are affected: Versions 2.5 through 3.11 Versions 2018-1 through 2021-1.,CVE-2021-32966,3.7,Low,CWE-319,Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1660,6/24/2021,11/16/2021,2021,ICSA-21-175-01,FATEK Automation WinProladder,FATEK Automation,WinProladder,"The following versions of FATEK Automation WinProladder, a PLC, are affected: WinProladder: Versions 3.30 and prior.","CVE-2021-32988, CVE-2021-32990, CVE-2021-32992",7.8,High,"CWE-119, CWE-125, CWE-787",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1659,6/22/2021,6/22/2021,2021,ICSA-21-173-02,CODESYS V2 web server,CODESYS GmbH,CODESYS V2 web server,CODESYS reports all CODESYS V2 web servers running stand-alone or as part of the CODESYS runtime system prior to Version 1.1.9.20 are affected..,"CVE-2021-30189, CVE-2021-30190, CVE-2021-30191, CVE-2021-30192, CVE-2021-30193, CVE-2021-30194",9.8,Critical,"CWE-120, CWE-284, CWE-358, CWE-125, CWE-787, CWE-121",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1658,6/22/2021,6/22/2021,2021,ICSA-21-173-03,CODESYS Control V2 communication,CODESYS GmbH,CODESYS Control V2 communication,"CODESYS reports the following CODESYS V2 runtime systems are affected, regardless of the CPU type or operating system: CODESYS Runtime Toolkit 32-bit full prior to v2.4.7.55 CODESYS PLCWinNT prior to v2.4.7.55.","CVE-2021-30186, CVE-2021-30188, CVE-2021-30195",9.8,Critical,"CWE-122, CWE-20, CWE-121",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1657,6/22/2021,6/22/2021,2021,ICSA-21-173-04,CODESYS Control V2 Linux SysFile library,CODESYS GmbH,CODESYS Control V2 Linux SysFile library,CODESYS reports all runtime systems for Linux based on a CODESYS V2 Runtime Toolkit 32-bit full prior Version 2.4.7.55 are affected..,CVE-2021-30187,5.3,Medium,CWE-78,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1656,6/17/2021,6/17/2021,2021,ICSA-21-168-01,Schneider Electric Enerlin'X Com'X 510,Schneider Electric,Enerlin'X Com'X 510,The following versions of Enerlin'X Com'X 510 energy servers are affected: Enerlin'X Com'X 510: All versions prior to v6.8.4.,CVE-2021-22769,8.5,High,CWE-269,Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1655,6/17/2021,6/17/2021,2021,ICSA-21-168-02,Softing OPC-UA C++ SDK,Softing Industrial Automation GmbH,OPC-UA C++ SDK,"Softing reports the vulnerability affects functions in the following software library, which may be used in other products: OPC UA C++ SDK (Software Development Kit) Versions from 5.59 to 5.64.",CVE-2021-32994,7.5,High,CWE-119,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1654,1/21/2021,9/20/2021,2021,ICSA-21-021-05,WAGO M&M Software fdtCONTAINER (Update C),M&M Software GmbH (Subsidiary of WAGO Kontakttechnik),WAGO M&M Software fdtCONTAINER,The following products are affected: fdtCONTAINER component Versions between 3.5.0 and 3.5.20304.x Versions between 3.6.0 and 3.6.20304.x Versions older than 3.5 fdtCONTAINER application Versions between 4.5.0 and 4.5.20304.x Versions between 4.6.0 and 4.6.20304.x Versions older than 4.5 dtmINSPECTOR Version 3 (Based on FDT 1.2.x) There are reports indicating the following products incorporate the affected component: Emerson Rosemount Transmitter Interface Software (RTIS) SKUs: 04088-9000-0001; 4088-9000-0002; and 7000003-312 PEPPERL+FUCHS PACTware 5.0; up to and including Version 5.0.5.31 Weidmuller WI Manager up to and including Version 2.5.1; Mitsubishi Electric MELSOFT FieldDeviceConfigurator; all versions.,CVE-2020-12525,7.3,High,CWE-502,Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1653,10/6/2020,6/17/2021,2021,ICSA-20-280-01,Rockwell Automation ISaGRAF5 Runtime (Update A),Rockwell Automation,ISaGRAF5 Runtime,"Rockwell Automation reports these vulnerabilities affect all ISaGRAF Runtime Versions 4.x and 5.x The following Rockwell Automation products are based on ISaGRAF5 to design integrated automation solutions: AADvance Controller version 1.40 and earlier ISaGRAF Free Runtime in ISaGRAF6 Workbench Version 6.6.8 and earlier Micro800 family, all versions GE reports that GE Steam Power's ALSPA S6 MFC3000 and MFC1000 (all versions), a distributed control system, are impacted by vulnerabilities in Rockwell's ISaGRAF runtime. Xylem reports that MultiSmart Gen-1 devices and MultiSmart Gen-2 devices running firmware prior to Version 3.2.0 contain a version of ISaGRAF 5.x. If ISaGRAF is enabled on those devices, then they might be affected by these vulnerabilities. Other vendors may also use ISaGRAF5 in their products.","CVE-2020-25176, CVE-2020-25178, CVE-2020-25180, CVE-2020-25182, CVE-2020-25184",9.1,Critical,"CWE-319, CWE-23, CWE-427, CWE-256, CWE-321",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1652,6/15/2021,6/15/2021,2021,ICSA-21-166-01,ThroughTek P2P SDK,ThroughTek,P2P SDK,The following versions of P2P Software Development Kit (SDK) are affected: Versions 3.1.5 and prior SDK versions with nossl tag Device firmware that does not use AuthKey for IOTC connection Device firmware using the AVAPI module without enabling DTLS mechanism Device firmware using P2PTunnel or RDT module.,CVE-2021-32934,9.1,Critical,CWE-319,Communications,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1651,6/15/2021,6/15/2021,2021,ICSA-21-166-02,Automation Direct CLICK PLC CPU Modules,AutomationDirect,CLICK PLC CPU Modules,Automation Direct reports these vulnerabilities affect the following CLICK PLC CPU modules: CLICK PLC CPU Modules: C0-1x CPUs with All firmware prior to v3.00.,"CVE-2021-32978, CVE-2021-32980, CVE-2021-32982, CVE-2021-32984, CVE-2021-32986",9.8,Critical,"CWE-288, CWE-319, CWE-256",Commercial Facilities; Critical Manufacturing; Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1650,7/2/2020,7/2/2020,2021,ICSMA-20-184-01,OpenClinic GA (Update B),OpenClinic GA,OpenClinic GA,"The following versions of OpenClinic GA, an open-source integrated hospital information management system, are affected: OpenClinic GA Version 5.09.02 OpenClinic GA Version 5.89.05b.","CVE-2020-14484, CVE-2020-14485, CVE-2020-14486, CVE-2020-14487, CVE-2020-14488, CVE-2020-14489, CVE-2020-14490, CVE-2020-14491, CVE-2020-14492, CVE-2020-14493, CVE-2020-14494, CVE-2016-1181, CVE-2016-1182, CVE-2014-0114",9.8,Critical,"CWE-288, CWE-307, CWE-287, CWE-862, CWE-250, CWE-434, CWE-22, CWE-285, CWE-79, CWE-1104, CWE-522, CWE-912",Healthcare and Public Health,Worldwide,Open-source,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1649,6/10/2021,6/10/2021,2021,ICSMA-21-161-01,ZOLL Defibrillator Dashboard,ZOLL,Defibrillator Dashboard,"The following versions of ZOLL Defibrillator Dashboard, a Defibrillator device management platform, are affected: Defibrillator Dashboard: All versions prior to 2.2.","CVE-2021-27479, CVE-2021-27481, CVE-2021-27483, CVE-2021-27485, CVE-2021-27487, CVE-2021-27489",9.9,Critical,"CWE-312, CWE-79, CWE-269, CWE-257, CWE-434, CWE-321",Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1648,6/10/2021,6/10/2021,2021,ICSA-21-161-01,Rockwell Automation FactoryTalk Services Platform,Rockwell Automation,FactoryTalk Services Platform,"Rockwell Automation reports this vulnerability affects the following versions of FactoryTalk Security, part of FactoryTalk Service Platform: FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed.",CVE-2021-32960,8.5,High,CWE-693,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Government Facilities; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1647,6/10/2021,6/10/2021,2021,ICSA-21-161-02,AGG Software Web Server Plugin,AGG Software,Web Server Plugin,The following versions of Web Server may be bundled with any Data Logger: v4.0.40.1014 and prior (webserver.dll).,"CVE-2021-32962, CVE-2021-32964",8.2,High,"CWE-79, CWE-23",Multiple Critical Sectors,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1646,6/8/2021,6/8/2021,2021,ICSA-21-159-01,Johnson Controls Metasys,Johnson Controls Inc.,Metasys,Johnson Controls reports the vulnerability affects the following Metasys building automation products: Metasys: All versions.,CVE-2021-27657,8.8,High,CWE-269,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1645,6/8/2021,6/8/2021,2021,ICSA-21-159-02,Open Design Alliance Drawings SDK,Open Design Alliance,Drawings SDK,"The following versions of Drawings SDK, a software development kit for DWG and DGN, are affected: Drawings SDK: All versions prior to 2022.4 Drawing SDK: Version 2022.4 is affected by CVE-2021-32946 and CVE-2021-32952.","CVE-2021-32936, CVE-2021-32938, CVE-2021-32940, CVE-2021-32944, CVE-2021-32946, CVE-2021-32948, CVE-2021-32950, CVE-2021-32952",7.8,High,"CWE-754, CWE-125, CWE-787, CWE-416",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1644,6/8/2021,6/8/2021,2021,ICSA-21-159-03,AVEVA InTouch,AVEVA,InTouch,AVEVA reports the vulnerability affects the following InTouch products: InTouch 2020 R2 and all prior versions.,CVE-2021-32942,6.6,Medium,CWE-316,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1643,6/8/2021,6/8/2021,2021,ICSA-21-159-04,Schneider Electric IGSS,Schneider Electric,IGSS,The following versions of Interactive Graphical SCADA System (IGSS) are affected: IGSS Definition (Def.exe) v15.0.0.21140 and prior.,"CVE-2021-22750, CVE-2021-22751, CVE-2021-22752, CVE-2021-22753, CVE-2021-22754, CVE-2021-22755, CVE-2021-22756, CVE-2021-22757, CVE-2021-22758, CVE-2021-22759, CVE-2021-22760, CVE-2021-22761, CVE-2021-22762",7.8,High,"CWE-824, CWE-22, CWE-119, CWE-125, CWE-787, CWE-763, CWE-416",Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1642,6/8/2021,6/8/2021,2021,ICSA-21-159-05,Schneider Electric Modicon X80,Schneider Electric,Modicon X80,The following versions of Modicon X80 are affected: Modicon X80 BMXNOR0200H RTU SV1.70 IR22 and prior.,CVE-2021-22749,5.3,Medium,CWE-200,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1641,6/8/2021,6/8/2021,2021,ICSA-21-159-06,Thales Sentinel LDK Run-Time Environment,Thales,Sentinel LDK Run-Time Environment,"Machines that previously ran and then uninstalled the following versions of Sentinel LDK Run Time Environment are affected: Sentinel LDK Run-Time Environment: Versions 7.6 and prior This RTE is used in products by many different vendors. As new instances are discovered/reported, they will be added to this list of affected products.",CVE-2021-32928,9.6,Critical,CWE-459,Multiple Critical Sectors,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1640,6/8/2021,6/8/2021,2021,ICSA-21-159-07,Siemens Mendix SAML Module,Siemens,Mendix SAML Module,Siemens reports the vulnerability affects the following products: Mendix SAML Module: All versions prior to 2.1.2.,CVE-2021-33712,8.1,High,CWE-345,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1639,6/8/2021,6/8/2021,2021,ICSA-21-159-08,Siemens TIM 1531 IRC,Siemens,TIM 1531 IRC,The following Siemens products are affected: TIM 1531 IRC (incl. SIPLUS NET variants): All versions prior to v2.2.,CVE-2018-0732,7.5,High,CWE-400,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1638,6/8/2021,6/8/2021,2021,ICSA-21-159-09,Siemens Solid Edge,Siemens,Solid Edge,"The following versions of Siemens Solid Edge, a portfolio of software tools, are affected: Solid Edge SE2020 - All versions before 2020MP14 Solid Edge SE2021 - All versions before SE2021MP5.","CVE-2021-31342, CVE-2021-31343",7.8,High,CWE-787,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1637,6/8/2021,6/29/2021,2021,ICSA-21-159-10,Siemens SIMATIC TIM libcurl,Siemens,SIMATIC TIM libcurl,"The following devices are affected by the third-party component libcurl: SIMATIC TIM 1531 IRC (incl. SIPLUS NET variants), All versions prior to v2.2. The libcurl library Versions 7.62.0 to and including 7.70.0 are vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to DNS servers. The libcurl library Versions 7.41.0 to 7.73.0 are vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. This vulnerability could allow an attacker to pass a revoked certificate as valid.","CVE-2020-8169, CVE-2020-8286",7.5,High,"CWE-200, CWE-295",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1636,6/8/2021,6/8/2021,2021,ICSA-21-159-11,Siemens SIMATIC NET CP 443-1 OPC UA,Siemens,SIMATIC NET CP 443-1 OPC UA,The following versions of SIMATIC NET CP 443-1 OPC UA are affected: SIMATIC NET CP 443-1 OPC UA: All versions.,"CVE-2016-9042, CVE-2017-6458, CVE-2016-7431, CVE-2016-7433, CVE-2015-7853, CVE-2016-4953, CVE-2016-4954, CVE-2016-4955, CVE-2016-4956, CVE-2015-7705, CVE-2015-8138, CVE-2016-1547, CVE-2016-1548, CVE-2016-1550, CVE-2016-2518",9.8,Critical,"CWE-19, CWE-20, CWE-119, CWE-120, CWE-125, CWE-200, CWE-287, CWE-362, CWE-682",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1635,6/8/2021,6/8/2021,2021,ICSA-21-159-12,Siemens Simcenter Femap,Siemens,Simcenter Femap,"The following versions of Simcenter Femap are affected: Simcenter Femap 2020.2, all versions prior to v2020.2.MP3 Simcenter Femap 2021.1, all versions prior to v2021.1.MP3.","CVE-2021-27387, CVE-2021-27399",7.8,High,CWE-787,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1634,6/8/2021,5/12/2022,2021,ICSA-21-159-13,Siemens SIMATIC RFID (Update B),Siemens,SIMATIC RF Products,"The following versions of SIMATIC RF and SIMATIC Reader RF are affected: SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0): All versions between v3.0 and v4.0 SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0): All versions between v3.0 and v4.0 SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0): All versions between V3.0 and V4.0 SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0): All versions between v3.0 and v4.0 SIMATIC Reader RF615R ETSI (6GT2811-6CC10-0AA0): All versions between v3.0 and v4.0 SIMATIC Reader RF615R FCC (6GT2811-6CC10-1AA0): All versions between v3.0 and v4.0 SIMATIC Reader RF650R ARIB (6GT2811-6AB20-4AA0): All versions between v3.0 and v4.0 SIMATIC Reader RF650R CMIIT (6GT2811-6AB20-2AA0): All versions between v3.0 and v4.0 SIMATIC Reader RF650R ETSI (6GT2811-6AB20-0AA0): All versions between v3.0 and v4.0 SIMATIC Reader RF650R FCC (6GT2811-6AB20-1AA0): All versions between v3.0 and v4.0 SIMATIC Reader RF680R ARIB (6GT2811-6AA10-4AA0): All versions between v3.0 and v4.0 SIMATIC Reader RF680R CMIIT (6GT2811-6AA10-2AA0): All versions between v3.0 and v4.0 SIMATIC Reader RF680R ETSI (6GT2811-6AA10-0AA0): All versions between v3.0 and v4.0 SIMATIC Reader RF680R FCC (6GT2811-6AA10-1AA0): All versions between v3.0 and v4.0 SIMATIC Reader RF685R ARIB (6GT2811-6CA10-4AA0): All versions between v3.0 and v4.0 SIMATIC Reader RF685R CMIIT (6GT2811-6CA10-2AA0): All versions between v3.0 and v4.0 SIMATIC Reader RF685R ETSI (6GT2811-6CA10-0AA0): All versions between v3.0 and v4.0 SIMATIC Reader RF685R FCC (6GT2811-6CA10-1AA0): All versions between v3.0 and v4.0 SIMATIC RF166C, all versions between v1.1 and v1.3.2 SIMATIC RF185C, all versions between v1.1 and v1.3.2 SIMATIC RF186C, all versions between v1.1 and v1.3.2 SIMATIC RF186CI, all versions between v1.1 and v1.3.2 SIMATIC RF188C, all versions between v1.1 and v1.3.2 SIMATIC RF188CI, all versions between v1.1 and v1.3.2 Begin Update B: SIMATIC RF360R, all versions prior to v2.0 End Update B.",CVE-2021-31340,7.5,High,CWE-400,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1633,6/8/2021,6/8/2021,2021,ICSA-21-159-14,Siemens JT2Go and Teamcenter Visualization,Siemens,JT2Go and Teamcenter Visualization,Siemens reports the vulnerability affects the following products: JT2Go: All versions prior to 13.1.0.3 Teamcenter Visualization: All versions prior to 13.1.0.3.,CVE-2021-27390,7.8,High,CWE-787,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1632,4/13/2021,6/8/2021,2021,ICSA-21-103-06,Siemens Solid Edge File Parsing (Update A),Siemens,Siemens Solid Edge File Parsing,The following versions of Siemens Solid Edge - portfolio of software tools are affected: Solid Edge SE2020: All versions before SE2020MP13 Solid Edge SE2020: SE2020MP13 Solid Edge SE2021: All versions before SE2021MP4.,"CVE-2021-25678, CVE-2021-27380, CVE-2021-27382, CVE-2020-26997, CVE-2020-28385",7.8,High,"CWE-787, CWE-121, CWE-822",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1631,9/8/2020,6/8/2021,2021,ICSA-20-252-06,Siemens SIMATIC HMI Products (Update A),Siemens,SIMATIC HMI Products,"The following versions of Siemens SIMATIC HMI Products are affected: SIMATIC HMI Basic Panels, 2nd Generation (incl. SIPLUS variants): All versions prior to v16 are affected by CVE-2020-15786; SIMATIC HMI Comfort Panels (incl. SIPLUS variants): All versions up to and including v16 are affected by CVE-2020-15786; SIMATIC HMI Mobile Panels: All versions up to and including v16 are affected by CVE-2020-15786; SIMATIC HMI United Comfort Panels: All versions up to and including v16.","CVE-2020-15786, CVE-2020-15787",6.5,Medium,"CWE-305, CWE-307",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1630,9/8/2020,3/10/2022,2021,ICSA-20-252-07,Siemens Industrial Products (Update F),Siemens,Industrial Products,SIMATIC Field PG M4: All versions. SIMATIC Field PG M5: All BIOS versions prior to v22.01.08 SIMATIC Field PG M6: All BIOS versions prior to v26.01.07 SIMATIC IPC3000 SMART: All versions SIMATIC IPC347E: All versions SIMATIC IPC427D (incl. SIPLUS variants): All versions SIMATIC IPC427E (incl. SIPLUS variants): All versions prior to v21.01.14 SIMATIC IPC477D: All versions SIMATIC IPC477E: All versions prior to v21.01.14 SIMATIC IPC477E Pro: All versions prior to v21.01.14. SIMATIC IPC527G: All BIOS versions prior to v1.4.0. SIMATIC IPC527G: All versions SIMATIC IPC547E: All versions SIMATIC IPC547G: All versions prior to R1.28.0 SIMATIC IPC627D: All versions SIMATIC IPC627E: All BIOS versions prior to v25.02.06 SIMATIC IPC647D: All versions SIMATIC IPC647E: All BIOS versions prior to v25.02.06 SIMATIC IPC677D: All versions SIMATIC IPC677E: All BIOS versions prior to v25.02.06 SIMATIC IPC827D: All versions SIMATIC IPC847D: All versions SIMATIC IPC847E: All BIOS versions prior to v25.02.06 SIMATIC ITP1000: All BIOS versions prior to v23.01.08 SIMOTION P320-4E: All versions SIMOTION P320-4S: All versions. Update: SIMATIC IPC3000 SMART v2: All versions prior to v1.B.,CVE-2020-0543,5.5,Medium,CWE-200,Critical manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1629,6/3/2021,6/3/2021,2021,ICSA-21-154-01,Advantech iView,Advantech,iView,The following versions of Advantech's iView product are affected: iView versions prior to v5.7.03.6182.,"CVE-2021-32930, CVE-2021-32932",9.1,Critical,"CWE-89, CWE-306",Multiple Critical Sectors,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1628,5/27/2021,5/27/2021,2021,ICSA-21-147-01,GENIVI Alliance DLT,GENIVI Alliance,DLT,"The following software component, which is open-source and maintained by GENIVI Alliance, is affected: dlt-daemon (diagnostic log and trace) versions prior to 2.18.6.",CVE-2020-36244,9.8,Critical,CWE-122,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1627,5/27/2021,5/27/2021,2021,ICSA-21-147-02,Johnson Controls Sensormatic Electronics VideoEdge,Sensormatic Electronics LLC (Subsidiary of Johnson Controls),Electronics VideoEdge,Johnson Controls reports the vulnerability affects the following Sensormatic Electronics products: VideoEdge versions prior to 5.7.0.,CVE-2021-3156,7.8,High,CWE-193,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1626,5/27/2021,5/27/2021,2021,ICSA-21-147-03,MesaLabs AmegaView,Mesa Labs,AmegaView,"The following versions of AmegaView, a continuous monitoring hardware and software platform, are affected: AmegaView Versions 3.0 and prior.","CVE-2021-27445, CVE-2021-27447, CVE-2021-27449, CVE-2021-27451, CVE-2021-27453",10.0,Critical,"CWE-288, CWE-287, CWE-77, CWE-269",Healthcare and Public Health; Food and Agriculture,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1625,5/27/2021,5/27/2021,2021,ICSA-21-147-04,Siemens JT2Go and Teamcenter Visualization,Siemens,JT2Go and Teamcenter Visualization,The following products are affected: JT2Go: All versions prior to v13.1.0.2 Teamcenter Visualization: All versions prior to v13.1.0.2.,"CVE-2020-26991, CVE-2020-26998, CVE-2020-26999, CVE-2020-27001, CVE-2020-27002",7.8,High,"CWE-125, CWE-121, CWE-822",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1624,5/27/2021,5/28/2021,2021,ICSA-21-147-05,Mitsubishi Electric MELSEC iQ-R Series,Mitsubishi Electric,MELSEC iQ-R Series,The following MELSEC iQ-R series CPU modules are affected: R00/01/02CPU: All versions R04/08/16/32/120(EN)CPU: All versions R08/16/32/120SFCPU: All versions R08/16/32/120PCPU: All versions R08/16/32/120PSFCPU: All versions.,CVE-2021-20591,5.3,Medium,CWE-400,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1623,2/9/2021,5/27/2021,2021,ICSA-21-040-06,Siemens JT2Go and Teamcenter Visualization (Update A),Siemens,Siemens JT2Go and Teamcenter Visualization,The following products are affected: JT2Go: All versions prior to v13.1.0.1 Teamcenter Visualization: All versions prior to v13.1.0.1.,"CVE-2021-25173, CVE-2021-25174, CVE-2021-25175, CVE-2021-25176, CVE-2021-25177, CVE-2021-25178, CVE-2021-31784, CVE-2020-26989, CVE-2020-26990, CVE-2020-26991, CVE-2020-26998, CVE-2020-26999, CVE-2020-27000, CVE-2020-27001, CVE-2020-27002, CVE-2020-27003, CVE-2020-27004, CVE-2020-27005, CVE-2020-27006, CVE-2020-27007, CVE-2020-27008, CVE-2020-28383, CVE-2020-28394",7.8,High,"CWE-119, CWE-121, CWE-125, CWE-704, CWE-787, CWE-789, CWE-822, CWE-843",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1622,1/12/2021,1/12/2021,2021,ICSA-21-012-03,Siemens JT2Go and Teamcenter Visualization (Update B),Siemens,Siemens JT2Go and Teamcenter Visualization,The following products are affected: JT2Go: All versions prior to v13.1.0 JT2Go: Version 13.1.0. only affected by CVE-2020-26989; CVE-2020-26990; CVE-2020-26991 Teamcenter Visualization: All versions prior to v13.1.0 Teamcenter Visualization: Version 13.1.0 only affected by CVE-2020-26989; CVE-2020-26990; CVE-2020-26991.,"CVE-2020-26980, CVE-2020-26981, CVE-2020-26982, CVE-2020-26983, CVE-2020-26984, CVE-2020-26985, CVE-2020-26986, CVE-2020-26987, CVE-2020-26988, CVE-2020-26989, CVE-2020-26990, CVE-2020-26991, CVE-2020-26992, CVE-2020-26993, CVE-2020-26994, CVE-2020-26995, CVE-2020-26996, CVE-2020-28383",7.8,High,"CWE-843, CWE-122, CWE-611, CWE-125, CWE-787, CWE-121",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1621,7/30/2020,8/2/2022,2021,ICSA-20-212-03,Mitsubishi Electric Factory Automation Products Path Traversal (Update C),Mitsubishi Electric,Factory Automation Products,"The following products and versions are affected: CW Configurator,Versions 1.010L and prior FR Configurator2, Versions 1.22Y and prior GX Works2, Versions 1.595V and prior GX Works3, Versions 1.063R and prior MELSEC iQ-R Series Motion Module, Versions 10 and prior MELSOFT iQ AppPortal, Version 1.17T and prior MELSOFT Navigator, 2.70Y and prior --------- Begin Update C Part 1 of 2 --------- MI Configurator, versions 1.004E and prior --------- End Update C Part 1 of 2 --------- MR Configurator2, Version 1.110Q and prior MT Works2, Versions 1.156N and prior MX Component, Version 4.20W and prior RT ToolBox3, Versions 1.70Y and prior.",CVE-2020-14523,8.3,High,CWE-22,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1620,5/25/2021,5/25/2021,2021,ICSA-21-145-01,Datakit Libraries bundled in Luxion KeyShot,Datakit,Libraries bundled in Luxion KeyShot,"The following modules of Datakit CrossCADWare, Versions 2021.1 and earlier, a library embedded in end-user applications, are affected: CatiaV5_3dRead CatiaV6_3dRead Step3dRead Ug3dReadPsr Jt3dReadPsr The following versions of Luxion software, 3D rendering and animation software, are bundled with the affected Datakit libraries: KeyShot: Versions v10.1 and prior.","CVE-2021-27488, CVE-2021-27490, CVE-2021-27492, CVE-2021-27494, CVE-2021-27496",7.8,High,"CWE-611, CWE-125, CWE-787, CWE-121, CWE-822",Multiple Critical Sectors,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1619,5/25/2021,5/25/2021,2021,ICSA-21-145-02,Rockwell Automation Micro800 and MicroLogix 1400,Rockwell Automation,Micro800 and MicroLogix 1400,The following controllers are affected: Micro800: All versions MicroLogix 1400: Version 21 and later when Enhanced Password Security enabled.,CVE-2021-32926,6.1,Medium,CWE-300,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1618,5/18/2021,5/18/2021,2021,ICSA-21-138-01,Emerson Rosemount X-STREAM,Emerson,Rosemount X-STREAM,"The following versions of Emerson's Rosemount X-STREAM gas analysis software, are affected: X-STREAM enhanced XEGP - all revisions X-STREAM enhanced XEGK - all revisions X-STREAM enhanced XEFD - all revisions X-STREAM enhanced XEXF - all revisions.","CVE-2021-27457, CVE-2021-27459, CVE-2021-27461, CVE-2021-27463, CVE-2021-27465, CVE-2021-27467",7.5,High,"CWE-22, CWE-79, CWE-1021, CWE-326, CWE-434, CWE-539",Energy; Chemical,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1617,1/21/2021,5/18/2021,2021,ICSA-21-021-04,Mitsubishi Electric MELFA (Update A),Mitsubishi Electric,Mitsubishi Electric MELFA,Mitsubishi Electric reports the vulnerability affects the following MELFA robot controllers: MELFA FR Series MELFA CR Series MELFA ASSISTA For more detailed information on affected models and firmware versions; please see the Mitsubishi Electric advisory.,CVE-2021-20586,7.5,High,CWE-400,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1616,11/19/2020,8/22/2024,2020,ICSA-20-282-02,Mitsubishi Electric MELSEC iQ-R Series (Update D),Mitsubishi Electric,MELSEC iQ-R Series,"The following versions of Mitsubishi Electric MELSEC iQ-R Series, a Programmable Controller, are affected: iQ-R series R00CPU: Versions ""20"" and prior iQ-R series R01CPU: Versions ""20"" and prior iQ-R series R02CPU; Versions ""20"" and prior iQ-R series R04CPU: Versions ""52"" and prior iQ-R series R08CPU: Versions ""52"" and prior iQ-R series R16CPU: Versions ""52"" and prior iQ-R series R32CPU: Versions ""52"" and prior iQ-R series R120CPU: Versions ""52"" and prior iQ-R series R04ENCPU: Versions ""52"" and prior iQ-R series R08ENCPU: Versions ""52"" and prior iQ-R series R16ENCPU: Versions ""52"" and prior iQ-R series R32ENCPU: Versions ""52"" and prior iQ-R series R120ENCPU: Versions ""52"" and prior iQ-R series R08FCPU: Versions ""22"" and prior iQ-R series R16FCPU: Versions ""22"" and prior iQ-R series R32FCPU: Versions ""22"" and prior iQ-R series R120FCPU: Versions ""22"" and prior iQ-R series R08PCPU: Versions ""25"" and prior iQ-R series R16PCPU: Versions ""25"" and prior iQ-R series R32PCPU: Versions ""25"" and prior iQ-R series R120PCPU: Versions ""25"" and prior iQ-R series R16MTCPU Operating system software: Versions ""21"" and prior iQ-R series R32MTCPU Operating system software: Versions ""21"" and prior iQ-R series R64MTCPU Operating system software: Versions ""21"" and prior.",CVE-2020-16850,8.6,High,CWE-400,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1615,5/13/2021,5/13/2021,2021,ICSA-21-133-01,Rockwell Automation Connected Components Workbench,Rockwell Automation,Connected Components Workbench,Rockwell Automation reports these vulnerabilities affect the following Connected Components Workbench versions: Connected Components Workbench v12.00.00 and prior.,"CVE-2021-27471, CVE-2021-27473, CVE-2021-27475",8.6,High,"CWE-502, CWE-20, CWE-22",Commercial Facilities; Defense Industrial Base; Energy; Government Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1614,5/13/2021,5/13/2021,2021,ICSA-21-133-02,Johnson Controls Sensormatic Tyco AI,Sensormatic Electronics LLC (Subsidiary of Johnson Controls),Tyco AI,Johnson Controls reports this vulnerability affects the following Sensormatic Electronics products: Tyco AI: All versions up to and including v1.2.,CVE-2021-3156,7.0,High,CWE-193,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1613,5/13/2021,5/13/2021,2021,ICSA-21-133-03,OPC Foundation UA Products Built with .NET Framework,OPC Foundation,OPC UA Products Built with .NET Framework,The following OPC UA products are affected: OPC UA .NET Standard: versions prior to 1.4.365.48 OPC UA .NET Legacy.,CVE-2021-27432,7.5,High,CWE-674,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1612,5/13/2021,5/13/2021,2021,ICSA-21-133-04,"OPC UA Products Built with the .NET Framework 4.5, 4.0, and 3.5",Unified Automation GmbH,"OPC UA Products Built with the .NET Framework 4.5, 4.0, and 3.5","The following OPC UA products are affected: Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework versions only).","CVE-2021-27434, CVE-2015-6096",7.2,High,CWE-200,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1611,5/11/2021,5/11/2021,2021,ICSA-21-131-01,Omron CX-One,Omron,CX-One,"The following versions of CX-One, an automation software suite, are affected: CX-One Versions 4.60 and prior, including the following applications: CX-Server Versions 5.0.29.0 and prior.",CVE-2021-27413,7.8,High,CWE-121,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1610,5/11/2021,1/21/2022,2021,ICSA-21-131-02,Mitsubishi Electric GOT and Tension Controller,Mitsubishi Electric,GOT and Tension Controller,Mitsubishi Electric reports the vulnerability affects the MODBUS/TCP slave communication function of the following devices: GOT2000 series GT27 model: Versions 01.19.000 - 01.38.000 GT25 model: Versions 01.19.000 - 01.38.000 GT23 model: Versions 01.19.000 - 01.38.000 GT21 model: Versions 01.21.000 - 01.39.000 GOT SIMPLE series GS21 model: Versions 01.21.000 - 01.39.000 GT SoftGOT2000: Versions 1.170C - 1.250L LE7-40GU-L: Screen package data for MODBUS/TCP v1.00 Please see Mitsubishi Electric's report number 2021-002 to learn how to check which version is in use.,CVE-2021-20589,5.9,Medium,CWE-805,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1609,5/11/2021,5/11/2021,2021,ICSA-21-131-05,Siemens Mendix Database Replication Module,Siemens,Mendix Database Replication Module,The following Siemens products are affected: Mendix Database Replication: All versions prior to v7.0.1.,CVE-2021-31341,4.3,Medium,CWE-209,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1608,5/11/2021,5/11/2021,2021,ICSA-21-131-06,Siemens SNMP Implementation of WinCC Runtime,Siemens,SNMP Implementation of WinCC Runtime,The following products are affected due to the SNMP implementation of WinCC Runtime: SIMATIC HMI Comfort Panels 1st Generation (incl. SIPLUS variants): All versions prior to v16 update 4 SIMATIC HMI KTP Mobile Panels: All versions prior to v16 update 4.,CVE-2019-19276,5.3,Medium,CWE-787,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1607,5/11/2021,5/11/2021,2021,ICSA-21-131-07,Siemens SIMATIC NET CP343-1,Siemens,SIMATIC NET CP343-1,The following versions of SIMATIC are affected: SIMATIC NET CP 343-1 Advanced (including SIPLUS variants): All versions SIMATIC NET CP 343-1 Lean (including SIPLUS variants): All versions SIMATIC NET CP 343-1 Standard (including SIPLUS variants): All versions.,CVE-2020-25242,7.5,High,CWE-400,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1606,5/11/2021,5/11/2021,2021,ICSA-21-131-08,Siemens Tecnomatix Plant Simulation,Siemens,Tecnomatix Plant Simulation,The following versions of Tecnomatix Plant Simulation are affected: Tecnomatix Plant Simulation: All Versions prior to 16.0.5.,"CVE-2021-27396, CVE-2021-27397, CVE-2021-27398",7.8,High,"CWE-119, CWE-121",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1605,5/11/2021,5/11/2021,2021,ICSA-21-131-09,Siemens Mendix Excel Importer Module,Mendix (Subsidiary of Siemens),Mendix Excel Importer Module,"The following versions of Mendix Excel Importer, a module that imports Excel data sheets into Mendix applications, are affected: Mendix Excel Importer Module: All versions prior to v9.0.3.",CVE-2021-31339,4.3,Medium,CWE-209,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1604,5/11/2021,5/11/2021,2021,ICSA-21-131-10,Siemens SCALANCE XM-400 and XR-500 Devices,Siemens,SCALANCE XM-400 and XR-500 Devices,The following Siemens products are affected: SCALANCE XM-400 Family: All versions prior to v6.4 SCALANCE XR-500 Family: All versions prior to v6.4.,CVE-2020-28393,7.5,High,CWE-682,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1603,5/11/2021,5/11/2021,2021,ICSA-21-131-11,Siemens SIMATIC UltraVNC HMI WinCC Products,Siemens,SIMATIC UltraVNC HMI WinCC Products,"The following Siemens SIMATIC HMIs/WinCC products are affected: SIMATIC HMI Comfort Outdoor Panels 7' and 15' (incl. SIPLUS variants): All versions prior to v16 Update 4 SIMATIC HMI Comfort Panels 4'to 22' (incl. SIPLUS variants): All versions prior to v16 Update 4 SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900, and KTP900F: All versions prior to v16 Update 4 SIMATIC WinCC Runtime Advanced: All versions prior to v16 Update 4.","CVE-2019-8259, CVE-2019-8260, CVE-2019-8261, CVE-2019-8262, CVE-2019-8263, CVE-2019-8264, CVE-2019-8265, CVE-2019-8275, CVE-2019-8277, CVE-2019-8280",9.8,Critical,"CWE-788, CWE-122, CWE-665, CWE-170, CWE-125, CWE-121",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1602,5/11/2021,5/11/2021,2021,ICSA-21-131-15,Siemens SIMATIC S7-1500,Siemens,SIMATIC S7-1500,"The following versions of SIMATIC S7-1500 CPU 1518-4, are affected by vulnerabilities in Intel products: SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (MLFB: 6ES7518-4AX00-1AC0, 6AG1518-4AX00-4AC0, incl. SIPLUS variant): All versions SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (MLFB: 6ES7518-4FX00-1AC0): All versions.","CVE-2020-0591, CVE-2020-8744",7.8,High,"CWE-665, CWE-119",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1601,2/9/2021,5/11/2021,2021,ICSA-21-040-08,Siemens SIMARIS Configuration (Update A),Siemens,Siemens SIMARIS Configuration,The following versions of SIMARIS configuration - electrical planning software are affected: SIMARIS configuration: All versions prior to 4.0.1.,CVE-2020-28392,4.4,Medium,CWE-276,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1600,12/8/2020,12/8/2020,2021,ICSA-20-343-02,Mitsubishi Electric GOT and Tension Controller (Update A),Mitsubishi Electric,GOT and Tension Controller,Mitsubishi Electric reports that the vulnerability affects the following human-machine interface (GOT) and Tension Controller products: GOT2000 series; GT21 model: GT2107-WTBD versions v01.39.000 and earlier GT2107-WTSD versions v01.39.000 and earlier GT2104-RTBD versions v01.39.000 and earlier GT2104-PMBD versions v01.39.000 and earlier GT2103-PMBD versions v01.39.000 and earlier GOT SIMPLE series; GS21 model: GS2110-WTBD versions v01.39.000 and earlier GS2107-WTBD versions v01.39.000 and earlier GS2110-WTBD-N versions v01.39.000 and earlier GS2107-WTBD-N versions v01.39.000 and earlier Tension Controller LE7-40GU-L All versions Refer to the user manual to determine which version is in use. The latest version of the manual is available at the Mitsubishi Electric website. Consult a Mitsubishi Electric representative for the latest version of the Tension Controller manual.,CVE-2020-5675,7.5,High,CWE-125,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1599,12/8/2020,5/11/2021,2021,ICSA-20-343-08,Siemens Products using TightVNC (Update A),Siemens,Products using TightVNC,"Vulnerabilities in TightVNC (v1.X) - a remote-control software package - do not affect the following Siemens products. The previous version of this advisory stated the following products were affected: SIMATIC HMI Comfort Outdoor Panels 7"" and 15"" (including SIPLUS variants): All versions prior to Version 16 update 3 SIMATIC HMI Comfort Panel 4"" to 22"" (including SIPLUS variants): All versions prior to Version 16 update 3 SIMATIC HMI KTP Mobile Panels KTP400F; KTP700; KTP700F; KTP900 and KTP900F: All versions prior to Version 16 update 3 SIMATIC ITC1500 v3.1: All versions SIMATIC ITC1500 v3.1 PRO: All versions SIMATIC ITC1900 v3.1: All versions SIMATIC ITC1900 v3.1 Pro: All versions SIMATIC ITC2200 v3.1: All versions SIMATIC ITC2200 v3.1 PRO: All versions SIMATIC WinCC Runtime Advanced: All versions prior to Version 16 update 3 SIMATIC WinCC Runtime Professional: All version prior to Version 16 update 3.","CVE-2019-15678, CVE-2019-15679, CVE-2019-15680, CVE-2019-8287",9.8,Critical,"CWE-120, CWE-122, CWE-476",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1598,2/16/2021,5/6/2021,2021,ICSA-21-047-01,Open Design Alliance Drawings SDK (Update A),Open Design Alliance,Open Design Alliance Drawings SDK,The following versions of Drawings SDK - software development kit for DWG and DGN are affected: Drawings SDK: All versions prior to 2021.6 on all supported by ODA platforms in static configuration. Note: CVE-2021-31784 only affects this version. Drawings SDK: All versions prior to 2021.12 (Version 2021.11 is only affected by CVE-2021-25174 and CVE-2021-25173).,"CVE-2021-25173, CVE-2021-25174, CVE-2021-25175, CVE-2021-25176, CVE-2021-25177, CVE-2021-25178, CVE-2021-31784",7.8,High,"CWE-843, CWE-704, CWE-789, CWE-787, CWE-121, CWE-822",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1597,5/4/2021,6/10/2021,2021,ICSA-21-124-01,Advantech WISE-PaaS RMM,Advantech,Advantech WISE-PaaS RMM,The following Advantech products are affected: WISE-PaaS/RMM versions prior to 3.3.29.,CVE-2021-27437,9.1,Critical,CWE-798,Critical Manufacturing; Energy; Water and Wastewater Systems,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1596,5/4/2021,5/6/2021,2021,ICSA-21-124-02,Delta Electronics CNCSoft ScreenEditor,Delta Electronics,Delta Electronics CNCSoft ScreenEditor,The following versions of CNCSoft ScreenEditor - software management platform are affected: CNCSoft ScreenEditor versions prior to v1.01.30.,CVE-2021-22672,7.8,High,CWE-787,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1595,4/29/2021,4/29/2021,2021,ICSA-21-119-01,Texas Instruments SimpleLink,Texas Instruments,Texas Instruments SimpleLink,The following Texas Instruments products are affected: SimpleLink MSP432E4 SDK: v4.20.00.12 and prior SimpleLink CC32XX SDK: v4.30.00.06 and prior SimpleLink CC13X0 SDK: versions prior to v4.10.03 SimpleLink CC13X2 SDK: versions prior to v4.40.00 SimpleLink CC26XX SDK: versions prior to v4.40.00 CC3200 SDK: v1.5.0 and prior CC3100 SDK: v1.3.0 and prior.,"CVE-2021-22671, CVE-2021-22673, CVE-2021-22675, CVE-2021-22677, CVE-2021-22679",9.8,Critical,"CWE-190, CWE-121",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1594,4/29/2021,11/2/2021,2021,ICSA-21-119-02,Cassia Networks Access Controller,Cassia Networks,Cassia Networks Access Controller,The following versions of Access Contoller are affected: Access Controller: All versions prior to 2.0.1.,CVE-2021-22685,6.2,Medium,CWE-22,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1593,4/29/2021,4/29/2021,2021,ICSA-21-119-03,Johnson Controls Exacq Technologies exacqVision,Exacq Technologies Inc (Subsidiary of Johnson Controls),Johnson Controls Exacq Technologies exacqVision,Johnson Controls reports the vulnerability affects the following products running on unpatched versions of the Ubuntu operating system: Linux based Z-Series and A-Series Q-Series G-Series Legacy LC-Series Legacy ELP-Series exacqVision Network Video Recorders (NVR) Linux based C-Series Workstations S-Series Storage Servers.,CVE-2021-3156,7.0,High,CWE-193,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1592,4/22/2021,4/22/2021,2021,ICSA-21-112-01,Horner Automation Cscape,Horner Automation,Horner Automation Cscape,The following versions of Cscape - control system application programming software are affected: Cscape: All versions prior to 9.90 SP4.,"CVE-2021-22678, CVE-2021-22682",8.4,High,"CWE-284, CWE-20",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1591,4/20/2021,4/20/2021,2021,ICSA-21-110-01,Hitachi ABB Power Grids Ellipse APM,Hitachi and ABB,Hitachi ABB Power Grids Ellipse APM,Hitachi ABB Power Grids reports the vulnerability affects the following Ellipse APM products: Ellipse APM Versions 5.3.0.1 and earlier Ellipse APM Versions 5.2.0.3 and earlier Ellipse APM Versions 5.1.0.6 and earlier.,CVE-2021-27887,6.3,Medium,CWE-79,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1590,4/20/2021,4/20/2021,2021,ICSA-21-110-02,Rockwell Automation Stratix Switches,Rockwell Automation,Rockwell Automation Stratix Switches,Rockwell Automation reports the vulnerabilities affect the following Stratix switches: Stratix 5800: Versions 16.12.01 and earlier Stratix 8000: Versions 15.2(7)E3 and earlier Stratix 5700: Versions 15.2(7)E3 and earlier Stratix 5410: Versions 15.2(7)E3 and earlier Stratix 5400: Versions 15.2(7)E3 and earlier Please see the Rockwell Automation security advisory for more detailed information.,"CVE-2021-1220, CVE-2021-1352, CVE-2021-1356, CVE-2021-1392, CVE-2021-1403, CVE-2021-1442, CVE-2021-1443, CVE-2021-1452",7.8,High,"CWE-20, CWE-77, CWE-78, CWE-532, CWE-345, CWE-522, CWE-823",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1589,4/20/2021,4/20/2021,2021,ICSA-21-110-03,Delta Industrial Automation COMMGR,Delta Electronics,Delta Industrial Automation COMMGR,The following versions of COMMGR - communication management software; and accompanying PLC simulators are affected: COMMGR: Version 1.12 and prior.,CVE-2021-27480,9.8,Critical,CWE-121,Commercial Facilities; Communications; Critical Manufacturing; Energy; Healthcare and Public Health,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1588,4/20/2021,4/20/2021,2021,ICSA-21-110-04,Delta Electronics CNCSoft ScreenEditor,Delta Electronics,Delta Electronics CNCSoft ScreenEditor,The following versions of CNCSoft ScreenEditor are affected: CNCSoft Versions 1.01.28 (with ScreenEditor Version 1.01.2) and prior.,CVE-2021-22668,7.8,High,CWE-125,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1587,4/20/2021,4/20/2021,2021,ICSA-21-110-05,Delta Electronics CNCSoft-B,Delta Electronics,Delta Electronics CNCSoft-B,The following versions of CNCSoft-B - software management platform are affected: CNCSoft-B Versions 1.0.0.3 and prior.,"CVE-2021-22660, CVE-2021-22664",7.8,High,"CWE-125, CWE-787",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1586,4/20/2021,4/20/2021,2021,ICSA-21-110-06,Eaton Intelligent Power Manager,Eaton,Eaton Intelligent Power Manager,Eaton reports these vulnerabilities affect the following Intelligent Power Manager products: Eaton Intelligent Power Manager (IPM) - All versions prior to 1.69 Eaton Intelligent Power Manager Virtual Appliance (IPM VA) - All versions prior to 1.69 Eaton Intelligent Power Protector (IPP) - All versions prior to 1.68.,"CVE-2021-23276, CVE-2021-23277, CVE-2021-23278, CVE-2021-23279, CVE-2021-23280, CVE-2021-23281",8.7,High,"CWE-94, CWE-20, CWE-95, CWE-89, CWE-434",Energy,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1585,4/20/2021,4/20/2021,2021,ICSA-21-110-07,Siemens Mendix,Siemens,Siemens Mendix,Siemens reports the vulnerability affects the following Mendix products: Mendix Applications using Mendix 7: All versions prior to v7.23.19 Mendix Applications using Mendix 8: All versions prior to v8.17.0 Mendix Applications using Mendix 8 (v8.12): All versions prior to v8.12.5 Mendix Applications using Mendix 8 (v8.6): All versions prior to v8.6.9 Mendix Applications using Mendix 9: All versions prior to v9.0.5.,CVE-2021-27394,8.1,High,CWE-269,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1584,4/6/2021,6/1/2023,2021,ICSA-21-096-01,Hitachi Energy Relion 670 650 SAM600IO (Update B),Hitachi Energy,"Relion 670, 650, and SAM600-IO","--------- Begin Update B Part 1 of 2 --------- Hitachi Energy reports the vulnerability affects the following products with IEC 61850 interfaces: Relion 670 series: Versions 1.1, 1.2.3, 2.0, 2.1, 2.2.2, 2.2.3 Relion 670/650 series: Version 2.2.0 Relion 670/650/SAM600-IO series: Version 2.2.1 Relion 650 series: Versions 1.1, 1.2, 1.3 --------- End Update B Part 1 of 2 ---------",CVE-2021-27196,7.5,High,CWE-20,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1583,6/9/2020,6/9/2020,2021,ICSA-20-161-02,Mitsubishi Electric MELSEC iQ-R Series (Update C),Mitsubishi Electric,SiNVR/SiVMS Video Server,The following versions of SiNVR/SiVMS Video Server - a video management solution are affected: SiNVR 3 Central Control Server (CCS): All versions Moved to SSA-761844 and ICSA-21-103-10 SiNVR/SiVMS Video Server: All versions prior to v5.0.0 SiNVR/SiVMS Video Server: v5.0.0 and later is affected by CVE-2019-19298 and CVE-2019-19299.,"CVE-2019-19290, CVE-2019-19291, CVE-2019-19292, CVE-2019-19293, CVE-2019-19294, CVE-2019-19295, CVE-2019-19296, CVE-2019-19297, CVE-2019-19298, CVE-2019-19299",7.5,High,CWE-400,Information Technology,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1582,4/15/2021,4/15/2021,2021,ICSA-21-105-01,Schneider Electric C-Bus Toolkit,Schneider Electric,Schneider Electric C-Bus Toolkit,The following versions of C-Bus Toolkit are affected: C-Bus Toolkit v1.15.7 and prior.,"CVE-2021-22716, CVE-2021-22717, CVE-2021-22718, CVE-2021-22719, CVE-2021-22720",8.8,High,"CWE-22, CWE-269",Commercial Facilities,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1581,4/15/2021,4/15/2021,2021,ICSA-21-105-02,EIPStackGroup OpENer Ethernet/IP,EIPStackGroup,EIPStackGroup OpENer Ethernet/IP,The following versions of OpENer EtherNet/IP are affected: https://github.com/EIPStackGroup/OpENer/ commits and versions prior to Feb 10 2021.,"CVE-2021-27478, CVE-2021-27482, CVE-2021-27498, CVE-2021-27500",8.2,High,"CWE-681, CWE-125, CWE-617",Multiple Critical Sectors,Worldwide,Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1580,4/13/2021,4/13/2021,2021,ICSA-21-103-01,Schneider Electric SoMachine Basic,Schneider Electric,Schneider Electric SoMachine Basic,Schneider Electric reports this vulnerability affects the following SoMachine Basic: SoMachine Basic; all versions prior to v1.6 SP1.,CVE-2018-7783,8.6,High,CWE-611,Critical Manufacturing; Dams; Defense Industrial Base; Energy; Food and Agriculture; Government Facilities; Nuclear Reactors; Materials; and Waste; Transportation Systems; Water and Wastewater Systems,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1579,4/13/2021,4/13/2021,2021,ICSA-21-103-02,Advantech WebAccessSCADA,Advantech,Advantech WebAccessSCADA,The following versions of WebAccess/SCADA - browser-based SCADA software package are affected: WebAccess/SCADA Versions 9.0.1 and prior.,CVE-2021-22669,8.8,High,CWE-732,Critical Manufacturing; Energy; Water and Wastewater Systems,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1578,4/13/2021,4/13/2021,2021,ICSA-21-103-03,JTEKT TOYOPUC products,JTEKT ELECTRONICS CORPORATION,JTEKT TOYOPUC products,The following versions of these TOYOPUC product series are affected: TOYOPUC-PC10 Series: PC10G-CPU TCC-6353: All versions PC10GE TCC-6464: All versions PC10P TCC-6372: All versions PC10P-DP TCC-6726: All versions PC10P-DP-IO TCC-6752: All versions PC10B-P TCC-6373: All versions PC10B TCC-1021: All versions PC10B-E/C TCU-6521: All versions PC10E TCC-4737: All versions TOYOPUC-Plus Series: Plus CPU TCC-6740: All versions Plus EX TCU-6741: All versions Plus EX2 TCU-6858: All versions Plus EFR TCU-6743: All versions Plus EFR2 TCU-6859: All versions Plus 2P-EFR TCU-6929: All versions Plus BUS-EX TCU-6900: All versions TOYOPUC-PC3J/PC2J Series: FL/ET-T-V2H THU-6289: All versions 2PORT-EFR THU-6404: All versions.,CVE-2021-27458,7.5,High,CWE-404,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1577,4/13/2021,4/13/2021,2021,ICSA-21-103-08,Siemens SINEMA Remote Connect Server,Siemens,Siemens SINEMA Remote Connect Server,The following Siemens products are affected: SINEMA Remote Connect Server: All versions prior to v3.0.,"CVE-2020-7595, CVE-2019-19956",7.5,High,"CWE-835, CWE-772",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1576,4/13/2021,6/14/2021,2021,ICSA-21-103-09,Siemens LOGO! Soft Comfort,Siemens,Siemens LOGO! Soft Comfort,Siemens reports that these vulnerabilities affect the following LOGO! engineering software products: LOGO! Soft Comfort: All versions.,"CVE-2020-25243, CVE-2020-25244",8.4,High,"CWE-22, CWE-427",Commercial Facilities; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1575,4/13/2021,4/13/2021,2021,ICSA-21-103-10,Siemens and PKE Control Center Server,Siemens and PKE,Siemens and PKE Control Center Server,The following versions of CCS - video management platform are affected: CCS: All versions prior to v1.5.0 CCS: v1.5.0 and later are affected by CVE-2019-18340.,"CVE-2019-13947, CVE-2019-18337, CVE-2019-18338, CVE-2019-18340, CVE-2019-18341, CVE-2019-18342, CVE-2019-19290, CVE-2019-19291, CVE-2019-19292, CVE-2019-19293, CVE-2019-19294, CVE-2019-19295",9.9,Critical,"CWE-317, CWE-287, CWE-23, CWE-327, CWE-287, CWE-749, CWE-22, CWE-313, CWE-89, CWE-79, CWE-778",Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1574,4/13/2021,4/13/2021,2021,ICSA-21-103-11,Siemens TIM 4R-IE Devices,Siemens,Siemens TIM 4R-IE Devices,The following Siemens products TIM 4R-IE communication modules are affected: TIM 4R-IE (incl. SIPLUS NET variants): All versions TIM 4R-IE DNP3 (incl. SIPLUS NET variants): All versions.,"CVE-2016-1547, CVE-2016-1548, CVE-2016-1550, CVE-2016-4953, CVE-2016-4954, CVE-2015-5219, CVE-2015-7705, CVE-2015-7855, CVE-2015-7871, CVE-2015-7973, CVE-2015-7974, CVE-2015-7977, CVE-2015-7979, CVE-2015-8138",9.8,Critical,"CWE-254, CWE-362, CWE-200, CWE-287, CWE-20, CWE-704, CWE-19, CWE-476",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1573,4/13/2021,4/13/2021,2021,ICSA-21-103-12,Siemens Tecnomatix RobotExpert,Siemens,Siemens Tecnomatix RobotExpert,The following versions of Tecnomatix RobotExpert are affected: All versions prior to v16.1.,CVE-2021-25670,7.8,High,CWE-787,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1572,4/13/2021,3/10/2022,2021,ICSA-21-103-13,Siemens SIMOTICS CONNECT 400 (Update A,Siemens,Siemens SIMOTICS CONNECT 400,The following products and versions are affected: SIMOTICS CONNECT 400; All versions prior to v0.5.0.0 SIMOTICS CONNECT 400; v0.5.0.0 and later only affected by CVE-2021-25677.,"CVE-2021-25677, CVE-2020-27736, CVE-2020-27737, CVE-2020-27738",6.5,Medium,"CWE-788, CWE-170, CWE-125",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1571,4/13/2021,1/13/2022,2021,ICSA-21-103-14,Siemens Nucleus DNS,Siemens,Siemens Nucleus DNS,The following Nucleus products and versions are affected: Nucleus NET; All versions Nucleus RTOS; All version which include affected DNS modules Nucleus ReadyStart; All versions prior to v2013.08 Nucleus Source Code; All versions which include the affected DNS modules VSTAR; All versions which include the affected DNS modules.,CVE-2021-27393,5.3,Medium,CWE-330,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1570,4/13/2021,4/13/2021,2021,ICSA-21-103-15,Siemens and Milestone Siveillance Video Open Network Bridge,Siemens and Milestone,Siemens and Milestone Siveillance Video Open Network Bridge,The following versions of Milestone XProtect Open Network Bridge and Siemens Siveillance Video Open Network Bridge are affected: 2020 R3 2020 R2 2020 R1 2019 R3 2019 R2 2019 R1 2018 R3 2018 R2.,CVE-2021-27392,9.9,Critical,CWE-321,Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1569,3/9/2021,4/13/2021,2021,ICSA-21-068-02,Siemens SCALANCE and RUGGEDCOM Devices SSH (Update A),Siemens,Siemens SCALANCE and RUGGEDCOM Devices SSH,The following Siemens products are affected: RUGGEDCOM RM1224: v6.3 SCALANCE M-800: v6.3 SCALANCE: S615: v6.3 SCALANCE SC-600: All versions from v2.1 and prior to v2.1.3.,CVE-2021-25676,8.6,High,CWE-307,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1568,3/9/2021,4/13/2021,2021,ICSA-21-068-03,Siemens SCALANCE and RUGGEDCOM Devices (Update A),Siemens,Siemens SCALANCE and RUGGEDCOM Devices,The following Siemens products are affected: RUGGEDCOM RM1224: All versions from v4.3 and prior to v4.6 SCALANCE M-800: All versions from v4.3 and prior to v4.6 SCALANCE S615: All versions from v4.3 and prior to v4.6 SCALANCE XR-300WG: All versions prior to v4.1 SCALANCE XB-200: All versions prior to v4.1 SCALANCE XC-200: All versions prior to v4.1 SCALANCE XF-200BA: All versions prior to v4.1 SCALANCE XP-200: All versions prior to v4.1; SCALANCE SC-600 Family: All versions from v2.0 and prior to v2.1.3 SCALANCE XM400: All versions prior to v6.2 SCALANCE XR500: All versions prior to v6.2.,CVE-2021-25667,8.8,High,CWE-121,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1567,12/8/2020,12/8/2020,2021,ICSA-20-343-05,Siemens Embedded TCP/IP Stack Vulnerabilities-AMNESIA:33 (Update C),Siemens,Embedded TCP/IP Stack,The following products are affected: SENTRON 3VA COM100/800: all versions prior to v4.2 SENTRON 3VA DSP800: all versions prior to v2.0 SENTRON PAC2200 (without MID Approval): all versions prior to v3.0.5 SENTRON PAC3200: all versions prior to v2.4.5 SENTRON PAC3200T: all versions prior to v3.0.5 SENTRON PAC4200: all versions prior to v2.0.1 SIRIUS 3RW5 communication module Modbus TCP: all versions prior to v1.1.1.,CVE-2020-13988,6.5,Medium,CWE-190,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1566,6/9/2020,6/9/2020,2021,ICSA-20-161-05,"Siemens SIMATIC, SINAMICS (Update C)",Siemens,"SIMATIC, SINAMICS",The following Siemens products are affected: SIMATIC PCS 7: All versions including v8.2 and prior SIMATIC PCS 7 v9.0: All versions prior to 9.0 SP3; SIMATIC PDM: All versions prior to 9.2; SIMATIC STEP 7 v5.X: All versions prior to 5.6 SP2 HF3 SINAMICS STARTER (containing STEP 7 OEM version): All versions prior to 5.4 HF2.,"CVE-2020-7585, CVE-2020-7586",7.8,High,"CWE-122, CWE-427",Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1565,2/11/2020,2/11/2020,2021,ICSA-20-042-02,Siemens Industrial Products SNMP (Update F),Siemens,"Various SCALANCE, SIMATIC, SIPLUS products",The following Siemens products are affected: IE/PB LINK PN IO (including SIPLUS NET variants): All versions prior to v4.0.1 SCALANCE S602: All versions prior to v4.1 SCALANCE S612: All versions prior to v4.1 SCALANCE S623: All versions prior to v4.1 SCALANCE S627-2M: All versions prior to v4.1; SIMATIC CP 1623: All versions prior to Version 14.00.15.00_51.25.00.01 SIMATIC CP 1626: All versions prior to v1.1.1 SIMATIC CP 1628: All versions prior to Version 14.00.15.00_51.25.00.01 SIMATIC CP 343-1 Advanced (including SIPLUS NET variants): All versions SIMATIC CP 443-1 (including SIPLUS NET variants): All versions SIMATIC CP 443-1 Advanced (including SIPLUS NET variants): All versions SIMATIC CP 443-1 OPC UA: All versions TIM 1531 IRC (including SIPLUS NET variants): All versions.,"CVE-2018-18065, CVE-2015-5621",7.5,High,"CWE-19, CWE-476",Chemical; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1564,2/11/2020,12/15/2022,2020,ICSA-20-042-07,Siemens SCALANCE X Switches (Update C),Siemens,SCALANCE X switches,"The following versions of SCALANCE X Switches, used to connect industrial components, are affected: SCALANCE X-200 switch family (including SIPLUS NET variants): All versions prior to Version 5.2.4 SCALANCE X-200IRT switch family (including SIPLUS NET variants): All versions prior to v5.5.0 SCALANCE X-300 switch family (including X408 and SIPLUS NET variants): All versions prior to Version 4.1.3 --------- Begin Update C Part 1 of 2 --------- SCALANCE X-200RNA switch family: All versions prior to v3.2.7 --------- End Update C Part 1 of 2 --------- SCALANCE S602: All versions prior to 4.1 SCALANCE S612: All versions prior to 4.1 SCALANCE S623: All versions prior to 4.1 SCALANCE S627-2M: All versions prior to 4.1.",CVE-2019-13924,4.2,Medium,CWE-693,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1563,2/11/2020,2/11/2020,2021,ICSA-20-042-10,Siemens SCALANCE S-600 (Update B),Siemens,SCALANCE S-600,The following versions of SCALANCE S-600 are affected: SCALANCE S602; all versions v3.0 or higher and prior to v4.1 SCALANCE S612; all versions v3.0 or higher and prior to v4.1 SCALANCE S623; all versions v3.0 or higher and prior to v4.1 SCALANCE S627-2M; all versions v3.0 or higher and prior to v4.1.,"CVE-2019-13925, CVE-2019-13926, CVE-2019-6585",7.5,High,"CWE-80, CWE-400",Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1562,12/10/2019,4/14/2021,2021,ICSA-19-344-02,"Siemens and PKE SiNVR, SiVMS Video Server (Update A)",Siemens and PKE,SiNVR 3,SiNVR 3 Central Control Server (CCS): all versions Moved to SSA-761844 and ICSA-21-103-10 SiNVR/SiVMS Video Server: All versions prior to v5.0.0 SiNVR/SiVMS Video Server: v5.0.0 and later is affected by CVE-2019-18340.,"CVE-2019-18340, CVE-2019-13947, CVE-2019-18337, CVE-2019-18338, CVE-2019-18339, CVE-2019-18341, CVE-2019-18342",9.8,Critical,"CWE-306, CWE-261",Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1561,12/1/2015,12/1/2015,2021,ICSA-15-335-03,Siemens SIMATIC Communication Processor Vulnerability (Update C),Siemens,SIMATIC Communication Processor,Siemens Communication Processor modules in affect the following versions of Siemens' SIMATIC S7-300/S7-400 CPUs: SIMATIC NET CP 342-5 (incl. SIPLUS variants): All versions SIMATIC CP 343-1 Advanced (incl. SIPLUS variants): All firmware versions prior to v3.0.44 | SIMATIC CP 343-1 Lean (incl. SIPLUS variants): All firmware versions prior to v3.1.1 | SIMATIC NET CP 343-1 Standard (incl. SIPLUS variants): All versions prior to v3.1.1 SIMATIC NET CP 443-1 Advanced (incl. SIPLUS variants): All versions prior to v3.2.9 SIMATIC NET CP 443-1 Standard (incl. SIPLUS variants): All versions prior to v3.2.9 SIMATIC NET CP 443-5 Basic (incl. SIPLUS variants): All versions SIMATIC NET CP 443-5 Extended: All versions TIM 3V-IE / TIM 3V-IE Advanced (incl. SIPLUS NET variants): All versions prior to v2.6.0 TIM 3V-IE DNP3 (incl. SIPLUS NET variants): All versions prior to v3.1.0 TIM 4R-IE (incl. SIPLUS NET variants): All versions prior to v2.6.0 TIM 4R-IE DNP3 (incl. SIPLUS NET variants): All versions prior to v3.1.0.,CVE-2015-8214,9.8,Critical,CWE-306,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1560,4/8/2021,4/9/2021,2021,ICSA-21-098-01,FATEK Automation WinProladder,FATEK Automation,FATEK Automation WinProladder,The following versions of FATEK Automation WinProladder - PLC are affected: WinProladder Versions 3.30 and prior.,CVE-2021-27486,7.8,High,CWE-191,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1559,3/21/2019,3/21/2019,2021,ICSMA-19-080-01,Medtronic Conexus Radio Frequency Telemetry Protocol (Update C),Medtronic,Conexus Radio Frequency Telemetry Protocol,"MyCareLink Monitor, Versions 24950 and 24952 CareLink Monitor, Version 2490C CareLink 2090 Programmer Amplia CRT-D (all models) Claria CRT-D (all models) Compia CRT-D (all models) Concerto CRT-D (all models) Concerto II CRT-D (all models) Consulta CRT-D (all models) Evera ICD (all models) Maximo II CRT-D and ICD (all models) Mirro ICD (all models) Nayamed ND ICD (all models) Primo ICD (all models) Protecta ICD and CRT-D (all models) Secura ICD (all models) Virtuoso ICD (all models) Virtuoso II ICD (all models) Visia AF ICD (all models) Viva CRT-D (all models) Brava CRT-D (all models) Mirro MRI ICD (all models).","CVE-2019-6538, CVE-2019-6540",9.3,Critical,"CWE-319, CWE-284",Healthcare and Public Health,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1558,4/1/2021,4/1/2021,2021,ICSA-21-091-01,Rockwell Automation FactoryTalk AssetCentre,Rockwell Automation,Rockwell Automation FactoryTalk AssetCentre,Rockwell Automation reports these vulnerabilities affects the following products: FactoryTalk AssetCentre; v10.00 and earlier.,"CVE-2021-27460, CVE-2021-27462, CVE-2021-27464, CVE-2021-27466, CVE-2021-27468, CVE-2021-27470, CVE-2021-27472, CVE-2021-27474, CVE-2021-27476",10.0,Critical,"CWE-502, CWE-78, CWE-89, CWE-676",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1557,3/25/2021,3/25/2021,2021,ICSMA-21-084-01,Philips Gemini PET/CT Family,Philips,Philips Gemini PET/CT Family,Philips reports the vulnerability affects the following Gemini PET/CT products: 882300 Gemini 16 Slice 882160 Gemini Dual 882400 Gemini GXL 10 Slice 882390 Gemini GXL 6 Slice 882410 Gemini GXL 16 Slice 882412 GEMINI LXL 882473 Gemini TF Ready 882470 Gemini TF 16 w/ TOF Performance 882471 Gemini TF 64 w/ TOF Performance 882476 Gemini TF Big Bore 882438 TruFlight Select PET/CT.,CVE-2021-27456,2.4,Low,CWE-921,Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1556,3/23/2021,3/23/2021,2021,ICSA-21-082-01,Weintek EasyWeb cMT,Weintek,Weintek EasyWeb cMT,The following models and OS versions of cMT are affected: cMT-SVR-1xx/2xx; versions prior to 20210305 cMT-G01/G02; versions prior to 20210209 cMT-G03/G04; versions prior to 20210222 cMT3071/cMT3072/cMT3090/cMT3103/cMT3151; versions prior to 20210218 cMT-HDM; versions prior to 20210204 cMT-FHD; versions prior to 20210208 cMT-CTRL01; versions prior to 20210302.,"CVE-2021-27442, CVE-2021-27444, CVE-2021-27446",10.0,Critical,"CWE-284, CWE-94, CWE-79",Commercial Facilities; Water and Wastewater Systems,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1555,3/23/2021,3/23/2021,2021,ICSA-21-082-02,GE MU320E,GE,GE MU320E,The following firmware versions of MU320E are affected: All firmware versions prior to v04A00.1.,"CVE-2021-27448, CVE-2021-27450, CVE-2021-27452",9.8,Critical,"CWE-250, CWE-326, CWE-259",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1554,3/23/2021,3/23/2021,2021,ICSA-21-082-03,GE Reason DR60,GE,GE Reason DR60,GE reports these vulnerabilities affect the following Reason DR60 digital fault recorder products: DR60: All firmware versions prior to 02A04.1.,"CVE-2021-27438, CVE-2021-27440, CVE-2021-27454",9.8,Critical,"CWE-250, CWE-94, CWE-259",Communications; Critical Manufacturing; Energy; Healthcare and Public Health; Transportation Systems; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1553,3/2/2021,3/23/2021,2021,ICSA-21-061-02,Rockwell Automation CompactLogix 5370 and ControlLogix 5570 Controllers (Update A),Rockwell Automation,Rockwell Automation CompactLogix 5370 and ControlLogix 5570 Controllers,The following versions of Rockwell Automation devices are affected: Armor Compact GuardLogix 5370 controllers; Versions 33 and prior Armor GuardLogix; Safety Controllers; Versions 33 and prior CompactLogix 5370 L1 controllers; Versions 33 and prior CompactLogix 5370 L2 controllers; Versions 33 and prior CompactLogix 5370 L3 controllers; Versions 33 and prior Compact GuardLogix 5370 controllers; Versions 33 and prior ControlLogix 5570 controllers; Versions 33 and prior.,CVE-2020-6998,5.8,Medium,CWE-22,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1552,2/2/2021,3/23/2021,2021,ICSA-21-033-01,Rockwell Automation MicroLogix 1400 (Update A),Rockwell Automation,Rockwell Automation MicroLogix 1400,Rockwell Automation reports the vulnerability affects the following MicroLogix 1400 controllers: MicroLogix 1400; All series Version 21.6 and below.,CVE-2021-22659,8.1,High,CWE-120,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1551,3/18/2021,3/18/2021,2021,ICSA-21-077-01,Johnson Controls Exacq Technologies exacqVision,Exacq Technologies Inc (Subsidiary of Johnson Controls),Johnson Controls Exacq Technologies exacqVision,Johnson Controls reports the vulnerability affects the following Exacq Technologies products: exacqVision Web Service: All supported versions up to and including v20.12.02.0.,CVE-2021-27656,5.3,Medium,CWE-200,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1550,3/18/2021,3/18/2021,2021,ICSA-21-077-02,Hitachi ABB Power Grids eSOMS,Hitachi and ABB,Hitachi ABB Power Grids eSOMS,Hitachi ABB Power Grids reports this vulnerability affects the following eSOMS products: eSOMS Version 6.0 prior to 6.0.4.2.2 eSOMS Version 6.1 prior to 6.1.4 eSOMS versions prior to 6.3.,CVE-2021-26845,7.5,High,CWE-200,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1549,3/18/2021,3/18/2021,2021,ICSA-21-077-03,Hitachi ABB Power Grids eSOMS Telerik,Hitachi and ABB,Hitachi ABB Power Grids eSOMS Telerik,Hitachi ABB Power Grids reports the vulnerabilities affect the following eSOMS products: eSOMS; all versions prior to 6.3 using a version of Telerik software.,"CVE-2019-18935, CVE-2019-19790, CVE-2014-2217, CVE-2014-4958",9.8,Critical,"CWE-502, CWE-20, CWE-22, CWE-326, CWE-522",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1548,2/25/2021,3/18/2021,2021,ICSA-21-056-03,Rockwell Automation Logix Controllers (Update A),Rockwell Automation,Rockwell Automation Logix Controllers,The following versions of Rockwell software are affected: RSLogix 5000: Versions 16 through 20 Studio 5000 Logix Designer: Versions 21 and later FactoryTalk Security; part of the FactoryTalk Services Platform; if configured and deployed v2.10 and later. The following Rockwell Logix Controllers are affected: CompactLogix 1768 CompactLogix 1769 CompactLogix 5370 CompactLogix 5380 CompactLogix 5480 ControlLogix 5550 ControlLogix 5560 ControlLogix 5570 ControlLogix 5580 DriveLogix 5560 DriveLogix 5730 DriveLogix 1794-L34 Compact GuardLogix 5370 Compact GuardLogix 5380 GuardLogix 5570 GuardLogix 5580 SoftLogix 5800.,CVE-2021-22681,10.0,Critical,CWE-522,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1547,3/16/2021,3/18/2021,2021,ICSA-21-075-01,Advantech WebAccess/SCADA,Advantech,Advantech WebAccess/SCADA,The following versions of WebAccess/SCADA - browser-based SCADA software package are affected: WebAccess/SCADA Versions 9.0 and prior.,CVE-2021-27436,5.4,Medium,CWE-79,Critical Manufacturing; Energy; Water and Wastewater Systems,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1546,3/16/2021,3/16/2021,2021,ICSA-21-075-02,GE UR family,GE,GE UR family,"GE reports the vulnerabilities affect the following UR family (B30; B90; C30; C60; C70; C95; D30; D60; F35; F60; G30; G60; L30; L60; L90; M60; N60; T35; T60) of advanced protection and control relays: Vulnerabilities related to SSH Support: firmware versions 7.4x to 8.0x (CyberSentry option) Web server vulnerabilities: all firmware versions prior to version 8.1x Protection from unintended firmware upload: all firmware versions prior to 8.1x with basic security option Provisions to disable Factory Mode: all firmware versions prior to 8.1x with basic security option Access to ""Last-key pressed"" register: all firmware versions prior to 8.1x with basic security option Weakness in UR bootloader binary: all bootloader versions prior to 7.03/7.04 Please see GE publication GES-2021-004 (login required) for more information.","CVE-2021-27418, CVE-2021-27420, CVE-2021-27422, CVE-2021-27424, CVE-2021-27426, CVE-2021-27428, CVE-2021-27430, CVE-2016-2183, CVE-2013-2566",9.8,Critical,"CWE-200, CWE-20, CWE-326, CWE-453, CWE-384, CWE-434, CWE-798",Communications; Critical Manufacturing; Energy; Healthcare and Public Health; Transportation Systems; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1545,3/16/2021,3/16/2021,2021,ICSA-21-075-03,Hitachi ABB Power Grids AFS Series,Hitachi and ABB,Hitachi ABB Power Grids AFS Series,Hitachi ABB Power Grids reports the vulnerability affects the following products in the AFS Series: AFS660/AFS665 Version 7.0.07; including the following variants: AFS660-SR AFS665-SR.,CVE-2020-9307,6.5,Medium,CWE-835,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1544,01/17/2017,3/16/2021,2021,ICSMA-17-017-02,BD Alaris 8015 PC Unit (Update B),"Becton, Dickinson and Company (BD)",Alaris 8015,The following Alaris PC unit versions are affected: Alaris 8015 PC unit | Version 9.5 and prior versions and Alaris 8015 PC unit | Version 9.7. Alaris 8015 PC unit | Versions 9.33 and prior.,"CVE-2016-8375, CVE-2016-9355",6.8,Medium,"CWE-254, CWE-522",Healthcare and Public Health,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1543,3/11/2021,3/11/2021,2021,ICSA-21-070-01,Schneider Electric IGSS SCADA Software,Schneider Electric,Schneider Electric IGSS SCADA Software,The following products and versions are affected: IGSS Definition (Def.exe) Version 15.0.0.21041 and prior.,"CVE-2021-22709, CVE-2021-22710, CVE-2021-22711, CVE-2021-22712",7.8,High,CWE-119,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1542,3/9/2021,3/9/2021,2021,ICSA-21-068-01,Siemens SIMATIC S7-PLCSIM,Siemens,Siemens SIMATIC S7-PLCSIM,The following Siemens products are affected: SIMATICS S7-PLCSIM v5.4: All versions.,"CVE-2021-25673, CVE-2021-25674, CVE-2021-25675",5.5,Medium,"CWE-369, CWE-835, CWE-476",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1541,3/9/2021,3/9/2021,2021,ICSA-21-068-04,Siemens SINEMA Remote Connect Server,Siemens,Siemens SINEMA Remote Connect Server,The following versions of SINEMA Remote Connect Server are affected: SINEMA Remote Connect Server: All versions prior to v3.0.,"CVE-2020-25239, CVE-2020-25240",8.8,High,CWE-863,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1540,3/9/2021,3/9/2021,2021,ICSA-21-068-05,Siemens LOGO! 8 BM,Siemens,Siemens LOGO! 8 BM,The following versions of LOGO! 8 - programmable logic controller are affected: LOGO! 8 BM (incl. SIPLUS variants): All versions.,CVE-2020-25236,5.5,Medium,CWE-755,Commercial Facilities; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1539,3/9/2021,3/9/2021,2021,ICSA-21-068-07,Siemens TCP Stack of SIMATIC MV400,Siemens,Siemens TCP Stack of SIMATIC MV400,The following products are affected: SIMATIC MV400 family: All versions prior to v7.0.6.,"CVE-2020-25241, CVE-2020-27632",7.5,High,"CWE-1285, CWE-330",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1538,3/9/2021,3/9/2021,2021,ICSA-21-068-08,Siemens Energy PLUSCONTROL 1st Gen,Siemens,Siemens Energy PLUSCONTROL 1st Gen,Siemens reports the vulnerability affects the following products: PLUSCONTROL 1st Gen: all versions.,CVE-2020-28388,6.5,Medium,CWE-342,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1537,3/9/2021,3/9/2021,2021,ICSA-21-068-09,Siemens Solid Edge File Parsing,Siemens,Siemens Solid Edge File Parsing,The following versions of Siemens Solid Edge - portfolio of software tools are affected: Solid Edge SE2020: All versions before SE2020MP13 Solid Edge SE2021: Versions SE2021MP3 and prior.,"CVE-2021-27380, CVE-2021-27381, CVE-2020-28385, CVE-2020-28387",7.8,High,"CWE-611, CWE-125, CWE-787",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1536,2/4/2021,3/9/2021,2021,ICSA-21-035-01,Luxion KeyShot (Update A),Luxion,Luxion KeyShot,The following versions of Luxion software; 3D rendering and animation software are affected: KeyShot versions prior to 10.1 KeyShot Viewer versions prior to 10.1 KeyShot Network Rendering versions prior to 10.1 KeyVR versions prior to 10.1.,"CVE-2021-22643, CVE-2021-22645, CVE-2021-22647, CVE-2021-22649, CVE-2021-22651",7.8,High,"CWE-22, CWE-357, CWE-125, CWE-787, CWE-822",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1535,1/19/2021,3/9/2021,2021,ICSA-21-019-01,dnsmasq by Simon Kelley (Update A),dnsmasq by Simon Kelley,dnsmasq by Simon Kelley,The following versions of dnsmasq DNS and DHCP server are affected: Version 2.8.2 and prior.,"CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686, CVE-2020-25687",8.1,High,"CWE-122, CWE-345, CWE-327",Multiple Critical Sectors,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1534,4/14/2020,12/15/2022,2020,ICSA-20-105-08,"Siemens KTK, SIDOOR, SIMATIC, and SINAMICS (Update D)",Siemens,"KTK, SIDOOR, SIMATIC, and SINAMICS","The following Siemens products are affected: Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200: All Versions Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200P: All Versions KTK ATE530S: All versions SIDOOR ATD430W: All versions SIDOOR ATE530S COATED: All versions SIDOOR ATE531S: All versions SIMATIC ET200AL IM157-1 PN: All versions SIMATIC ET200ecoPN, CM 8x IO-Link, M12-L (6ES7148-6JG00-0BB0): Versions 5.1.1 and later SIMATIC ET200ecoPN, DI 8x24VDC, M12-L (6ES7141-6BG00-0BB0): Versions 5.1.1 and later SIMATIC ET200ecoPN, DI 16x24VDC, M12-L (6ES7141-6BH00-0BB0): Versions 5.1.1 and later SIMATIC ET200ecoPN, DIQ 16x24VDC/2A, M12-L (6ES7143-6BH00-0BB0): Versions 5.1.1 and later SIMATIC ET200ecoPN, DQ 8x24VDC/0,5A, M12-L (6ES7142-6BG00-0BB0): Versions 5.1.1 and later SIMATIC ET200ecoPN, DQ 8x24VDC/2A, M12-L (6ES7142-6BR00-0BB0): Versions 5.1.1 and later SIMATIC ET200SP IM155-6 MF HF: All versions SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants): All versions prior to 2.0 SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions prior to 2.0 SIMATIC ET200MP IM155-5 PN HF (incl. SIPLUS variants): Versions 4.2 and later SIMATIC ET200SP IM155-6 PN HA (incl. SIPLUS variants): All versions SIMATIC ET200SP IM155-6 PN HF (incl. SIPLUS variants): Versions 4.2 and later SIMATIC ET200SP IM155-6 PN/2 HF (incl. SIPLUS variants): Versions 4.2 and later SIMATIC ET200SP IM155-6 PN/3 HF (incl. SIPLUS variants): Versions 4.2 and later SIMATIC MICRO-DRIVE PDC: All versions SIMATIC PN/PN Coupler (incl. SIPLUS NET variants): Versions 4.2 and later SIMATIC S7-1200 CPU family (incl. SIPLUS variants): All versions prior to 4.4.0 SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions prior to 2.0 SIMATIC S7-1500 Software Controller: All versions prior to 2.0 SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions SIMATIC S7-400 H V6 CPU family and below (incl. SIPLUS variants): All Versions SIMATIC S7-400 PN/DP V7 and below CPU family (incl. SIPLUS variants): All versions --------- Begin Update D Part 1 of 3 --------- SIMATIC S7-410 CPU family (incl. SIPLUS variants): All versions prior to 10.1.1 --------- End Update D Part 1 of 3 --------- SIMATIC TDC CP51M1: All versions SIMATIC TDC CPU555: All versions SIMATIC WinAC RTX (F) 2010: All versions SINAMICS S/G Control Unit w. PROFINET: All versions.",CVE-2019-19300,7.5,High,CWE-400,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1533,6/11/2019,3/9/2021,2021,ICSA-19-162-02,Siemens SIMATIC Ident MV440 Family (Update A),Siemens,SIMATIC Ident MV420 and MV440 Families,SIMATIC MV440 family: All versions prior to v7.0.6.,"CVE-2019-10925, CVE-2019-10926",7.1,High,"CWE-319, CWE-269",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1532,4/9/2019,3/9/2021,2021,ICSA-19-099-04,Siemens SINEMA Remote Connect (Update A),Siemens,SINEMA Remote Connect,SINEMA Remote Connect Client; all versions prior to v2.0 HF1 SINEMA Remote Connect Server; all versions prior to v2.0.,"CVE-2018-14618, CVE-2018-16890, CVE-2019-3822, CVE-2019-3823, CVE-2019-6570",8.3,High,"CWE-280, CWE-131, CWE-125, CWE-121",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1531,3/4/2021,3/4/2021,2021,ICSA-21-063-01,Rockwell Automation 1734-AENTR Series B and Series C,Rockwell Automation,Rockwell Automation 1734-AENTR Series B and Series C,The following versions of 1734-AENTR are affected: Series B; Versions 4.001 to 4.005; and 5.011 to 5.017 Series C; Versions 6.011 and 6.012.,"CVE-2020-14502, CVE-2020-14504",7.5,High,"CWE-284, CWE-79",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1530,3/4/2021,3/8/2021,2021,ICSA-21-063-02,Schneider Electric EcoStruxure Building Operation (EBO),Schneider Electric,Schneider Electric EcoStruxure Building Operation (EBO),Schneider Electric reports these vulnerabilities affect the following EcoStruxure Building Operation products: WebReports v1.9 - v3.1 WebStation v2.0 - v3.1 Enterprise Server installer v1.9 - v3.1 Enterprise Central installer v2.0 - v3.1 Note: Please see SEVD-2020-315-04 to see which vulnerabilities affect each specific product.,"CVE-2020-28209, CVE-2020-28210, CVE-2020-7569, CVE-2020-7570, CVE-2020-7571, CVE-2020-7572, CVE-2020-7573",6.7,Medium,"CWE-284, CWE-79, CWE-611, CWE-428, CWE-434",Commercial Facilities; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater Systems,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1529,3/2/2021,3/2/2021,2021,ICSA-21-061-01,Hitachi ABB Power Grids Ellipse EAM,Hitachi and ABB,Hitachi ABB Power Grids Ellipse EAM,Hitachi ABB Power Grids reports these vulnerabilities affect the following Ellipse Enterprise Asset Management (EAM) products: Ellipse EAM versions prior to and including 9.0.25.,"CVE-2021-27414, CVE-2021-27416",5.5,Medium,"CWE-79, CWE-451",Energy Sector,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1528,3/2/2021,3/2/2021,2021,ICSA-21-061-03,"MB connect line mbCONNECT24, mymbCONNECT24",MB Connect line,"MB connect line mbCONNECT24, mymbCONNECT24",The following products and versions are affected: mymbCONNECT24 v2.6.1 and prior mbCONNECT24 v2.6.1 and prior.,"CVE-2020-10384, CVE-2020-12527, CVE-2020-12528, CVE-2020-12529, CVE-2020-12530, CVE-2020-35557, CVE-2020-35558, CVE-2020-35559, CVE-2020-35560, CVE-2020-35561, CVE-2020-35563, CVE-2020-35564, CVE-2020-35565, CVE-2020-35566, CVE-2020-35567, CVE-2020-35568, CVE-2020-35569, CVE-2020-35570",7.8,High,"CWE-79, CWE-98, CWE-200, CWE-269, CWE-400, CWE-522, CWE-601, CWE-798, CWE-918, CWE-1188",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1527,2/25/2021,3/18/2021,2021,ICSA-21-056-01,PerFact OpenVPN-Client,PerFact,PerFact OpenVPN-Client,The following versions of OpenVPN-Client are affected: OpenVPN-Client; Versions 1.4.1.0 and prior.,CVE-2021-27406,8.8,High,CWE-15,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1526,2/25/2021,4/8/2021,2021,ICSA-21-056-02,FATEK Automation FvDesigner,FATEK Automation,FATEK Automation FvDesigner,The following versions of FATEK Automation FvDesigner - software tool used to design and develop FATEK FV HMI series product projects are affected: FvDesigner Version 1.5.76 and prior.,"CVE-2021-22638, CVE-2021-22662, CVE-2021-22666, CVE-2021-22670, CVE-2021-22683",7.8,High,"CWE-824, CWE-125, CWE-787, CWE-121, CWE-416",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1525,2/25/2021,2/25/2021,2021,ICSA-21-056-04,ProSoft Technology ICX35,ProSoft Technology,ProSoft Technology ICX35,The following ProSoft Technology products; industrial cellular gateways are affected: ICX35-HWC-A: Versions 1.9.62 and prior ICX35-HWC-E: Versions 1.9.62 and prior.,CVE-2021-22661,8.2,High,CWE-264,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1524,2/23/2021,2/23/2021,2021,ICSA-21-054-01,Rockwell Automation FactoryTalk Services Platform,Rockwell Automation,Rockwell Automation FactoryTalk Services Platform,FactoryTalk Services Platform Versions 6.10.00 and 6.11.00.,CVE-2020-14516,10.0,Critical,CWE-916,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Government Facilities; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1523,2/23/2021,2/23/2021,2021,ICSA-21-054-02,Advantech BB-ESWGP506-2SFP-T,Advantech,Advantech BB-ESWGP506-2SFP-T,The following Advantech products are affected: BB-ESWGP506-2SFP-T industrial ethernet switches: Versions 1.01.09 and prior.,CVE-2021-22667,9.8,Critical,CWE-798,Multiple Critical Sectors,"East Asia, United States, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1522,2/23/2021,2/23/2021,2021,ICSA-21-054-03,Advantech Spectre RT Industrial Routers,Advantech,Advantech Spectre RT Industrial Routers,The following versions of Advantech Spectre RT Industrial Routers are affected: Spectre RT ERT351 firmware Versions 5.1.3 and prior.,"CVE-2019-18231, CVE-2019-18233, CVE-2019-18235, CVE-2018-20679, CVE-2016-0799, CVE-2016-2842, CVE-2016-6301, CVE-2016-6304, CVE-2015-9261",10.0,Critical,"CWE-319, CWE-79, CWE-307, CWE-327, CWE-1103",Critical Manufacturing; Energy; Water and Wastewater Systems,"East Asia, Europe, United States, South America, Middle East",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1521,2/18/2021,2/23/2021,2021,ICSA-21-049-01,Johnson Controls Metasys Reporting Engine (MRE) Web Services,Johnson Controls Inc.,Johnson Controls Metasys Reporting Engine (MRE) Web Services,Johnson Controls reports the vulnerability affects the following versions of Metasys Reporting Engine (MRE) Web Services: MRE - v2.0 MRE - v2.1.,CVE-2020-9050,7.5,High,CWE-22,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1520,1/12/2021,2/18/2021,2021,ICSA-21-012-01,Schneider Electric EcoStruxure Power Build-Rapsody (Update A),Schneider Electric,Schneider Electric EcoStruxure Power Build-Rapsody,EcoStruxure Power Build-Rapsody software Versions 2.1.13 and prior.,"CVE-2021-22697, CVE-2021-22698",7.8,High,CWE-434,Commercial Facilities; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater Systems,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1519,2/16/2021,2/16/2021,2021,ICSMA-21-047-01,Hamilton-T1,Hamilton Medical AG,Hamilton-T1,The following versions of the Hamilton-T1 Ventilator are affected: T1 Ventilator Versions 2.2.3 and prior.,"CVE-2020-27278, CVE-2020-27282, CVE-2020-27290",4.3,Medium,"CWE-200, CWE-112, CWE-798",Healthcare and Public Health,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1518,2/16/2021,2/16/2021,2021,ICSA-21-047-02,Rockwell Automation Allen-Bradley Micrologix 1100,Rockwell Automation,Rockwell Automation Allen-Bradley Micrologix 1100,Rockwell Automation reports the vulnerability affects the following Allen-Bradley MicroLogix 1100 Programmable Logic Controller: Allen-Bradley MicroLogix 1100 revision number 1.0.,CVE-2020-6111,7.5,High,CWE-130,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1517,2/11/2021,2/11/2021,2021,ICSA-21-042-02,Rockwell Automation DriveTools SP and Drives AOP,Rockwell Automation,Rockwell Automation DriveTools SP and Drives AOP,Rockwell Automation reports the vulnerability affects the following products: DriveTools SP v5.13 and below DriveExecutive v5.13 and below Drives AOP v4.12 and below (supports Logix Versions v16-v30).,CVE-2021-22665,7.5,High,CWE-427,Food and Agriculture; Transportation Systems; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1516,7/21/2020,3/10/2022,2021,ICSA-20-203-01,Wibu-Systems CodeMeter (Update F),Wibu-Systems AG,CodeMeter,The following versions of CodeMeter Runtime - a license manager are affected: All versions prior to 7.10a are affected by CVE-2020-14509 and CVE-2020-14519 All versions prior to 7.10a are affected by CVE-2020-14517 All versions prior to 7.10 are affected by CVE-2020-16233 All versions prior to 6.81 are affected by CVE-2020-14513 All versions prior to 6.90 are affected by CVE-2020-14515 when using CmActLicense update files with CmActLicense Firm Code This license manager is used in products by many different vendors. As new instances are discovered/reported; they will be added to this list of affected products. Update: Siemens: SSA-455843 and SSA-455844.,"CVE-2020-14509, CVE-2020-14513, CVE-2020-14515, CVE-2020-14517, CVE-2020-14519, CVE-2020-16233",10.0,Critical,"CWE-805, CWE-20, CWE-404, CWE-347, CWE-326, CWE-346",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1515,2/9/2021,2/9/2021,2021,ICSA-21-040-01,GE Digital HMI/SCADA iFIX,GE Digital,GE Digital HMI/SCADA iFIX,The following product is affected: HMI/SCADA iFIX: Versions 6.1 and prior.,"CVE-2019-18243, CVE-2019-18255",6.1,Medium,CWE-732,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1514,2/9/2021,2/9/2021,2021,ICSA-21-040-02,Advantech iView,Advantech,Advantech iView,The following versions of Advantech iView - device management application are affected: iView versions prior to v5.7.03.6112.,"CVE-2021-22652, CVE-2021-22654, CVE-2021-22656, CVE-2021-22658",9.8,Critical,"CWE-22, CWE-89, CWE-306",Critical Manufacturing; Energy; Water and Wastewater Systems,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1513,2/9/2021,2/9/2021,2021,ICSA-21-040-03,Siemens SINEMA Server & SINEC NMS,Siemens,Siemens SINEMA Server & SINEC NMS,The following versions of Siemens products are affected: SINEC NMS: All versions prior to v1.0 SP1 Update 1 SINEMA Server: All versions prior to v14.0 SP2 Update 2.,CVE-2020-25237,8.8,High,CWE-22,Chemical; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1512,2/9/2021,2/9/2021,2021,ICSA-21-040-04,Siemens RUGGEDCOM ROX II,Siemens,Siemens RUGGEDCOM ROX II,The following Siemens products are affected: RUGGEDCOM ROX MX5000: All versions prior to v2.14.0 RUGGEDCOM ROX RX1400: All versions prior to v2.14.0 RUGGEDCOM ROX RX1500: All versions prior to v2.14.0 RUGGEDCOM ROX RX1501: All versions prior to v2.14.0 RUGGEDCOM ROX RX1510: All versions prior to v2.14.0 RUGGEDCOM ROX RX1511: All versions prior to v2.14.0 RUGGEDCOM ROX RX1512: All versions prior to v2.14.0 RUGGEDCOM ROX RX500: All versions prior to v2.14.0.,"CVE-2020-1763, CVE-2019-11745, CVE-2019-17006, CVE-2019-17007, CVE-2018-12404, CVE-2018-18508",9.8,Critical,"CWE-295, CWE-20, CWE-345, CWE-476, CWE-125, CWE-787",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1511,2/9/2021,2/9/2021,2021,ICSA-21-040-07,Siemens SCALANCE W780 and W740,Siemens,Siemens SCALANCE W780 and W740,The following Siemens products are affected: SCALANCE W780 and W740 (IEEE 802.11n) family: All versions prior to v6.3.,CVE-2021-25666,4.3,Medium,CWE-770,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1510,2/9/2021,2/9/2021,2021,ICSA-21-040-09,SIMATIC WinCC Graphics Designer,Siemens,SIMATIC WinCC Graphics Designer,Siemens reports this vulnerability affects WinCC Graphics Designer used with the following DCS and SCADA products: SIMATIC PCS 7: All versions SIMATIC WinCC: All versions prior to 7.5 SP2.,CVE-2020-10048,6.2,Medium,CWE-288,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1509,2/9/2021,2/9/2021,2021,ICSA-21-040-10,Siemens DIGSI 4,Siemens,Siemens DIGSI 4,The following Siemens products are affected: DIGSI 4: All versions prior to v4.94 SP1 HF 1.,CVE-2020-25245,7.8,High,CWE-276,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1508,4/14/2020,2/9/2021,2021,ICSA-20-105-04,Siemens Climatix (Update A),Siemens,Climatix,The following products of the Climatix product line are affected: Climatix POL908 (BACnet/IP module); all versions; Climatix POL909 (AWM module); all versions prior to v11.32.,"CVE-2020-7574, CVE-2020-7575",6.1,Medium,"CWE-79, CWE-80",Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1507,6/11/2019,6/11/2019,2021,ICSA-19-162-04,Siemens SCALANCE X (Update B),Siemens,SCALANCE X,SCALANCE X-200 switch family (including SIPLUS NET variants): all versions prior to v5.2.4. SCALANCE X-200IRT switch family (including SIPLUS NET variants): all versions prior to v5.5.0. SCALANCE X-300 switch family (including SIPLUS NET variants): all versions prior to v4.1.3 SCALANCE X-414-3E: all versions.,CVE-2019-6567,7.1,High,CWE-257,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1506,2/4/2021,2/4/2021,2021,ICSA-21-035-02,Horner Automation Cscape,Horner Automation,Horner Automation Cscape,The following versions of Cscape - control system application programming software are affected: Cscape: All versions prior to 9.90 SP3.5.,CVE-2021-22663,7.8,High,CWE-125,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1505,2/2/2021,2/2/2021,2021,ICSA-21-033-02,Siemens SIMATIC HMI Comfort Panels & SIMATIC HMI KTP Mobile Panels,Siemens,Siemens SIMATIC HMI Comfort Panels & SIMATIC HMI KTP Mobile Panels,The following versions of these Siemens SIMATIC HMI products; which are used for operator control and monitoring of machines and plants are affected: SIMATIC HMI Comfort Panel (including SIPLUS variants): All versions before v16 Update 3a SIMATIC HMI KTP Mobile Panels: All versions before v16 Update 3a.,CVE-2020-15798,8.1,High,CWE-306,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1504,1/28/2021,1/28/2021,2021,ICSA-21-028-01,Rockwell Automation FactoryTalk Linx and FactoryTalk Services Platform,Rockwell Automation,Rockwell Automation FactoryTalk Linx and FactoryTalk Services Platform,Rockwell Automation reports these vulnerabilities affect the following products: FactoryTalk Linx software: Versions 6.20 and prior (CVE-2020-5806 only affects Versions 6.10; 6.11; and 6.20) FactoryTalkServices Platform: Versions 6.20 and prior (Only affected by CVE-2020-5807).,"CVE-2020-5801, CVE-2020-5802, CVE-2020-5806, CVE-2020-5807",7.5,High,"CWE-120, CWE-703",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1503,1/26/2021,1/26/2021,2021,ICSA-21-026-01,Fuji Electric Tellus Lite V-Simulator and V-Server Lite,Fuji Electric,Fuji Electric Tellus Lite V-Simulator and V-Server Lite,The following Fuji Electric products are affected: Tellus Lite V-Simulator: Versions prior to v4.0.10.0 V-Server Lite: Versions prior to v4.0.10.0.,"CVE-2021-22637, CVE-2021-22639, CVE-2021-22641, CVE-2021-22653, CVE-2021-22655",7.8,High,"CWE-824, CWE-122, CWE-125, CWE-787, CWE-121",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1502,1/7/2021,1/26/2021,2021,ICSA-21-007-03,Eaton EASYsoft (Update A),Eaton,Eaton EASYsoft,Versions 7.20 and prior of EASYsoft are affected.,"CVE-2020-6655, CVE-2020-6656",5.8,Medium,"CWE-843, CWE-125",Critical Manufacturing; Energy; Water and Wastewater Systems,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1501,12/18/2020,1/26/2021,2021,ICSA-20-353-01,Treck TCP/IP Stack (Update A),Treck Inc,Treck TCP/IP Stack,The following components of Treck TCP/IP stack Version 6.0.1.67 and prior are affected: HTTP Server IPv6 DHCPv6.,"CVE-2020-25066, CVE-2020-27336, CVE-2020-27337, CVE-2020-27338",9.8,Critical,"CWE-122, CWE-125, CWE-787",Critical Manufacturing; Information Technology; Healthcare and Public Health; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1500,1/21/2021,1/21/2021,2021,ICSA-21-021-01,Delta Electronics ISPSoft,Delta Electronics,Delta Electronics ISPSoft,The following versions of ISPSoft - PLC program development tool are affected: ISPSoft: v3.12 and prior.,CVE-2020-27280,7.8,High,CWE-416,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1499,1/21/2021,1/21/2021,2021,ICSA-21-021-02,Delta Electronics TPEditor,Delta Electronics,Delta Electronics TPEditor,The following versions of TPEditor - programming software for Delta text panels are affected: TPEditor: v1.98 and prior.,"CVE-2020-27284, CVE-2020-27288",7.8,High,"CWE-787, CWE-822",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1498,1/21/2021,1/21/2021,2021,ICSA-21-021-03,Honeywell OPC UA Tunneller,Matrikon (Subsidiary of Honeywell),Honeywell OPC UA Tunneller,Honeywell reports the vulnerabilities affect the following Matrikon products: OPC UA Tunneller: All versions prior to 6.3.0.8233.,"CVE-2020-27274, CVE-2020-27295, CVE-2020-27297, CVE-2020-27299",9.8,Critical,"CWE-122, CWE-754, CWE-125, CWE-400",Multiple Critical Sectors,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1497,1/19/2021,1/19/2021,2021,ICSMA-21-019-01,Philips Interventional Workstations,Philips,Philips Interventional Workstations,This issue affects four Haswell workstations labeled with 12NC identification numbers (4598 009 39471; 4598 009 39481; 4598 009 70861; 4598 009 98531) when running the following versions of interventional software: Interventional Workspot (Release 1.3.2; 1.4.0; 1.4.1; 1.4.3; 1.4.5) Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0) ViewForum (Release 6.3V1L10).,CVE-2020-27298,6.5,Medium,CWE-78,Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1496,1/19/2021,1/19/2021,2021,ICSA-21-019-02,Reolink P2P Cameras,Reolink,Reolink P2P Cameras,The following Reolink devices use P2P: RLC-4XX series RLC-5XX series RLN-X10 series.,"CVE-2020-25169, CVE-2020-25173",9.1,Critical,"CWE-319, CWE-321",Communications,Worldwide,Hong Kong,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1495,1/12/2021,1/12/2021,2021,ICSMA-21-012-01,SOOIL Dana Diabecare RS Products,SOOIL Development Co. Ltd.,SOOIL Dana Diabecare RS Products,The following versions of Dana Diabecare Insulin Pumps and mobile applications are affected: Dana Diabecare RS: All versions prior to 3.0 AnyDana-i: All versions prior to 3.0 AnyDana-A: All versions prior to 3.0.,"CVE-2020-27256, CVE-2020-27258, CVE-2020-27264, CVE-2020-27266, CVE-2020-27268, CVE-2020-27269, CVE-2020-27270, CVE-2020-27272, CVE-2020-27276",7.6,High,"CWE-798, CWE-522, CWE-330, CWE-603, CWE-602, CWE-294, CWE-523, CWE-322, CWE-290",Healthcare and Public Health,"Europe, Asia",South Korea,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1494,1/12/2021,1/12/2021,2021,ICSA-21-012-04,Siemens Solid Edge,Siemens,Siemens Solid Edge,The following versions of Solid Edge - portfolio of software tools are affected: Solid Edge: All versions prior to SE2021MP2.,"CVE-2020-26989, CVE-2020-28381, CVE-2020-28382, CVE-2020-28383, CVE-2020-28384, CVE-2020-28386",7.8,High,"CWE-787, CWE-121",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1493,7/14/2020,7/14/2020,2021,ICSA-20-196-07,Siemens Opcenter Execution Core (Update B),Siemens,Opcenter Execution Core,The following products are affected: Camstar Enterprise Platform: All versions. Only affected by CVE-2020-7576; CVE-2020-7577; CVE-2020-7578 Opcenter Execution Core: All versions prior to v8.2. Affected by CVE-2020-7576; CVE-2020-7577; CVE-2020-7578 Opcenter Execution Core: Version 8.2. Affected by CVE-2020-7576; CVE-2020-28390 Opcenter Execution Core: Versions 8.3. Affected by CVE-2020-28390.,"CVE-2020-28390, CVE-2020-7576, CVE-2020-7577, CVE-2020-7578",8.5,High,"CWE-284, CWE-79, CWE-89, CWE-522",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1492,2/11/2020,4/14/2022,2021,ICSA-20-042-06,"Siemens SIMATIC PCS 7, SIMATIC WinCC, and SIMATIC NET PC (Update G)",Siemens,"SIMATIC PCS 7, SIMATIC WinCC, SIMATIC NET PC",The following versions of SIMATIC software are affected: OpenPCS 7 v8.1: all versions OpenPCS 7 v8.2: all versions OpenPCS 7 v9.0: all versions prior to v9.0 Upd3 SIMATIC BATCH v8.1: all versions SIMATIC BATCH v8.2: all versions SIMATIC BATCH v9.0: all versions prior to v9.0 SP1 Upd5 Update G SIMATIC NET PC Software v14: All versions prior to v14 SP1 Update 14 SIMATIC NET PC Software v15: All versions SIMATIC NET PC Software v16: All versions prior to v16 Update 1 End Update G. SIMATIC NET PC Software: all versions prior to v16 update 1 SIMATIC PCS 7 v8.1: all versions SIMATIC PCS 7 v8.2: all versions SIMATIC PCS 7 v9.0: all versions prior to v9.0 SP3 SIMATIC Route Control v8.1: all versions SIMATIC Route Control v8.2: all versions SIMATIC Route Control v9.0: all versions prior to v9.0 Upd4 SIMATIC WinCC (TIA Portal) v13: all versions prior to v13 SP2 SIMATIC WinCC (TIA Portal) v14: all versions SIMATIC WinCC (TIA Portal) v15.1: all versions prior to v15.1 Update 5 SIMATIC WinCC (TIA Portal) v16: all versions prior to v16 Update 1 SIMATIC WinCC v7.3: all versions SIMATIC WinCC v7.4: all versions prior to v7.4 SP1 Update 14 SIMATIC WinCC v7.5: all versions prior to v7.5.1 Upd1.,"CVE-2019-1928, CVE-2019-19282",7.5,High,CWE-131,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1491,1/7/2021,1/7/2021,2021,ICSMA-21-007-01,Innokas Yhtymä Oy Vital Signs Monitor,Innokas Yhtymä Oy,Innokas Yhtymä Oy Vital Signs Monitor,The following versions of Innokas Yhtymä Oy Vital Signs Monitors are affected: VC150 prior to Version 1.7.15.,"CVE-2020-27260, CVE-2020-27262",5.3,Medium,"CWE-79, CWE-74",Healthcare and Public Health,Worldwide,Finland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1490,1/7/2021,1/7/2021,2021,ICSA-21-007-01,Hitachi ABB Power Grids FOX615 Multiservice-Multiplexer,Hitachi and ABB,Hitachi ABB Power Grids FOX615 Multiservice-Multiplexer,Hitachi ABB Power Grids reports a vulnerability exists in the libssh library included in the following products: FOX61x R1 using CESM1/CESM2: All versions prior to cesne_r1h07_12.esw FOX61x R2 using CESM1/CESM2: All versions prior to cesne_r2d14_03.esw.,CVE-2018-10933,9.1,Critical,CWE-287,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1489,1/7/2021,1/7/2021,2021,ICSA-21-007-02,Omron CX-One,Omron,Omron CX-One,The following versions of CX-One; an Automation Software Suite are affected: CX-One Versions 4.60 and prior; including the following applications: CX-Protocol Versions 2.02 and prior CX-Server Versions 5.0.28 and prior CX-Position Versions 2.52 and prior.,"CVE-2020-27257, CVE-2020-27259, CVE-2020-27261",7.8,High,"CWE-843, CWE-121, CWE-822",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1488,1/7/2021,1/7/2021,2021,ICSA-21-007-04,Delta Electronics CNCSoft-B,Delta Electronics,Delta Electronics CNCSoft-B,The following versions of CNCSoft-B - software management platform are affected: CNCSoft-B Versions 1.0.0.2 and prior.,"CVE-2020-27287, CVE-2020-27289, CVE-2020-27291, CVE-2020-27293",7.8,High,"CWE-843, CWE-125, CWE-787, CWE-822",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1487,1/5/2021,1/5/2021,2021,ICSA-21-005-01,Schneider Electric Web Server on Modicon M340,Schneider Electric,Schneider Electric Web Server on Modicon M340,Schneider Electric reports these vulnerabilities affect the following Modicon products: M340 CPUs BMX P34x; all versions M340 Communication Ethernet modules BMX NOE 0100 (H); all versions BMX NOE 0110 (H); all versions BMX NOC 0401; all versions BMX NOR 0200H; all versions Premium processors with integrated Ethernet COPRO TSXP574634; TSXP575634; TSXP576634; all versions Premium communication modules TSXETY4103; all versions TSXETY5103; all versions Quantum processors with integrated Ethernet COPRO 140CPU65xxxxx; all versions Quantum communication modules 140NOE771x1; all versions 140NOC78x00; all versions 140NOC77101; all versions.,"CVE-2020-7562, CVE-2020-7563, CVE-2020-7564",6.3,Medium,"CWE-120, CWE-125, CWE-787",Commercial Facilities; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater Systems,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1486,1/5/2021,1/12/2021,2021,ICSA-21-005-02,Panasonic FPWIN Pro,Panasonic,Panasonic FPWIN Pro,The following versions of FPWIN Pro - programming software for all FP Series PLCs are affected: FPWIN Pro Version 7.5.0.0 and prior.,CVE-2020-16236,7.3,High,CWE-125,Commercial Facilities; Critical Manufacturing; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1485,1/5/2021,1/5/2021,2021,ICSA-21-005-03,GE Reason RT43X Clocks,GE,GE Reason RT43X Clocks,GE reports the vulnerabilities affect the following GNSS clocks: RT430; RT431 & RT434: All firmware versions prior to Version 08A06.,"CVE-2020-25193, CVE-2020-25197",9.8,Critical,"CWE-94, CWE-321",Communications; Critical Manufacturing; Energy; Healthcare and Public Health; Transportation Systems; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1484,1/5/2021,1/5/2021,2021,ICSA-21-005-04,Red Lion Crimson 3.1,Red Lion Controls,Red Lion Crimson 3.1,The following versions of Crimson 3.1 for the DA10D Protocol Converter are affected: Crimson 3.1: Build versions prior to 3119.001.,"CVE-2020-27279, CVE-2020-27283, CVE-2020-27285",7.5,High,"CWE-404, CWE-306, CWE-476",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1483,1/5/2021,1/5/2021,2021,ICSA-21-005-05,Delta Electronics DOPSoft,Delta Electronics,Delta Electronics DOPSoft,The following versions of DOPSoft - software that supports the DOP-100 series HMI screens are affected: DOPSoft Version 4.0.8.21 and prior.,"CVE-2020-27275, CVE-2020-27277",7.8,High,"CWE-787, CWE-822",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1482,1/5/2021,1/6/2021,2021,ICSA-21-005-06,Delta Electronics CNCSoft ScreenEditor,Delta Electronics,Delta Electronics CNCSoft ScreenEditor,The following versions of CNCSoft ScreenEditor are affected: CNCSoft ScreenEditor Versions 1.01.26 and prior.,CVE-2020-27281,7.8,High,CWE-121,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1481,12/17/2020,1/5/2021,2021,ICSA-20-352-02,PTC Kepware KEPServerEX (Update A),PTC,KEPServerEX,The following products are affected by the vulnerabilities found in Kepware KEPServerEX - a connectivity platform: KEPServerEX: v6.0 to v6.9 ThingWorx Kepware Server: v6.8 and v6.9 ThingWorx Industrial Connectivity: All versions OPC-Aggregator: All versions. The following products may have a vulnerable component: Rockwell Automation KEPServer Enterprise: v6.6.504.0 and v6.9.572.0 GE Digital Industrial Gateway Server: v7.68.804 and v7.66 Software Toolbox TOP Server: All 6.x versions.,"CVE-2020-27263, CVE-2020-27265, CVE-2020-27267",9.8,Critical,"CWE-122, CWE-121, CWE-416",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1480,11/3/2020,1/5/2021,2021,ICSA-20-308-03,ARC Informatique PcVue (Update A),ARC Informatique,PcVue,The following versions of PcVue are affected: PcVue Versions 8.10 to versions prior to 12.0.17.,"CVE-2020-26867, CVE-2020-26868, CVE-2020-26869",9.8,Critical,"CWE-767, CWE-502, CWE-200",Multiple Critical Sectors,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1479,10/8/2020,1/5/2021,2021,ICSA-20-282-01,Johnson Controls Sensormatic Electronics American Dynamics victor Web Client and Software House C¢CURE Web Client (Update A),Sensormatic Electronics LLC (Subsidiary of Johnson Controls),American Dynamics victor Web Client and Software House C¢CURE Web Client,Johnson Controls reports that the vulnerability affects the following versions of victor Web Client and C¢CURE Web Client software: American Dynamics victor Web Client: All versions up to and including v5.4.1; Software House C¢CURE Web Client: All versions up to and including v2.80.,CVE-2020-9048,7.1,High,CWE-285,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1478,8/11/2020,1/5/2021,2021,ICSA-20-224-01,Yokogawa CENTUM (Update A),Yokogawa,CENTUM,Yokogawa reports that the vulnerability affects the following CENTUM distributed control system products: Exaopc (R3.72.00 - R3.78.00); CENTUM CS 3000 versions R3.08.10 - R3.09.50 (Including CENTUM CS 3000 Entry Class) CENTUM VP versions R4.01.00 - R6.07.00 (Including CENTUM VP Entry Class) B/M9000CS versions R5.04.01 - R5.05.01 B/M9000 VP versions R6.01.01 - R8.03.01.,"CVE-2020-5608, CVE-2020-5609",8.1,High,"CWE-287, CWE-22",Critical Manufacturing; Energy; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1477,7/30/2020,9/22/2022,2021,ICSA-20-212-02,Mitsubishi Electric Factory Automation Engineering Software (Update D),Mitsubishi Electric,"Mitsubishi Electric, Multiple Factory Automation Engineering Software products","The following products and versions are affected: CPU Module Logging Configuration Tool, versions 1.100E and prior CW Configurator, Versions 1.010L and prior Data Transfer, Versions 3.40S and prior EZSocket, Versions 4.5 and prior FR Configurator2, Versions 1.22Y and prior GT Designer3 Version1 (GOT2000), Versions 1.235V and prior GT SoftGOT1000 Version3, 3.200J and prior GT SoftGOT1000 Version3, all versions GT SoftGOT2000 Version1, Bersions 1.235V and prior GX LogViewer, Versions 1.100E and prior GX Works2, Versions 1.592S and prior GX Works3, Versions 1.063R and prior M_CommDTM-HART, Version 1.00A M_CommDTM-IO-Link, Versions 1.03D and prior MELFA-Works, versions 4.3 and prior --------- Begin Update D Part 1 of 2--------- MELSEC WinCPU Setting Utility, Versions 1.03D and prior --------- End Update D Part 1 of 2--------- MELSOFT EM Software Development Kit (EM Configurator), Versions 1.010L and prior MELSOFT FieldDeviceConfigurator, Versions 1.03D and prior MELSOFT Navigator, Versions 2.62Q and prior MH11 SettingTool Version2, versions 2.002C and prior MI Configurator, Versions 1.004E and prior Motorizer, Versions 1.005F and prior MR Configurator2, Versions 1.105K and prior MT Works2, Versions 1.156N and prior MX Component, Versions 4.19V and prior Network Interface Board CC IE Control utility, Versions 1.29F and prior Network Interface Board CC IE Field Utility, Versions 1.16S and prior Network Interface Board CC-Link Ver.2 Utility, Versions 1.23Z and prior Network Interface Board MNETH utility, Versions 34L and prior PX Developer, Versions 1.52E and prior RT ToolBox2, Versions 3.72A and prior RT ToolBox3, Versions 1.70Y and prior Setting/monitoring tools for the C Controller module (SW4PVC-CCPU), Versions 4.12N and prior.",CVE-2020-14496,8.3,High,CWE-275,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1476,12/17/2020,12/18/2020,2020,ICSA-20-352-01,Emerson Rosemount X-STREAM,Emerson,Rosemount X-STREAM,The following versions of Emerson's Rosemount X-STREAM gas analysis software are affected: X-STREAM enhanced XEGP - all revisions X-STREAM enhanced XEGK - all revisions X-STREAM enhanced XEFD - all revisions X-STREAM enhanced XEXF - all revisions.,CVE-2020-27254,7.5,High,CWE-287,Energy; Chemical,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1475,12/17/2020,12/17/2020,2020,ICSA-20-352-03,PTC Kepware LinkMaster,PTC,LinkMaster,The following versions of PTC Kepware LinkMaster - a Windows application linking data between OPC servers are affected: Kepware LinkMaster Version 3.0.94.0 and prior.,CVE-2020-13535,9.3,Critical,CWE-276,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1474,11/3/2020,12/15/2020,2020,ICSA-20-308-01,WAGO Series 750-88x and 750-352 (Update A),WAGO,750-88x and 750-352,The firmware versions prior to FW11 of the following WAGO Series products are affected: 750-352 750-831/xxx-xxx 750-852 750-880/xxx-xxx 750-881 750-889; 750-331/xxx-xxx 750-829 750-882 750-885.,CVE-2020-12516,7.5,High,CWE-400,Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1473,12/10/2020,12/10/2020,2020,ICSMA-20-345-01,Medtronic MyCareLink Smart,Medtronic,MyCareLink Smart,The following versions of the Medtronic MyCareLink Smart Patient Reader are affected: Smart Model 25000 Patient Reader; all versions.,"CVE-2020-25183, CVE-2020-25187, CVE-2020-27252",8.8,High,"CWE-122, CWE-287, CWE-367",Healthcare and Public Health,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1472,12/10/2020,12/10/2020,2020,ICSA-20-345-01,Mitsubishi Electric MELSEC iQ-F Series,Mitsubishi Electric,MELSEC iQ-F Series,Mitsubishi Electric reports that the vulnerability affects the following MELSEC iQ-F series FX5U(C) CPU modules: FX5U(C) CPU module: firmware Version 1.060 or earlier.,CVE-2020-5665,7.4,High,CWE-703,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1471,12/10/2020,12/10/2020,2020,ICSA-20-345-02,Host Engineering H2-ECOM100 Module,Host Engineering,Host Engineering H2-ECOM100 Module,The following versions of the Host Engineering ECOM100 Module - Ethernet communications module for PLC systems are affected: H0-ECOM100 Module: Hardware Versions 6x and prior with Firmware Versions 4.0.348 and prior Hardware Version 7x with Firmware Versions 4.1.113 and prior Hardware Version 9x with Firmware Versions 5.0.149 and prior H2-ECOM100 Module: Hardware Versions 5x and prior with Firmware Versions 4.0.2148 and prior Hardware Version 8x with Firmware Versions 5.0.1043 and prior H4-ECOM100 Module: Firmware Versions 4.0.2148 and prior NOTE: Products only vulnerable if web server is enabled which is disabled by default.,CVE-2020-25195,7.5,High,CWE-20,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1470,12/8/2020,12/8/2020,2020,ICSMA-20-343-01,GE Healthcare Imaging and Ultrasound Products,GE Healthcare,Imaging and Ultrasound Products,The following versions of GE imaging and ultrasound products are affected: Modality Product MR 3.0T Signa HDxt / 3.0T Signa HDx; versions HD 16; HD23 1.5T Brivo MR355 / Optima MR360; versions SV20.1; SV23.0 1.5T Signa HDx / 1.5T Signa HDx; Signa HDi / Signa VIBRANT; versions HD16; HD23 Ultrasound; General Imaging LOGIQ 5 [BT03]; LOGIQ 7 (BT03; BT04; BT06]; LOGIQ 9 [BT02; BT03; BT04; BT06] Ultrasound; Cardiovascular Vivid I [BT06]; Vivid 7 {BT02-BT06]; EchoPAC (Turnkey) [BT06]; Image Vault (Turnkey) [4.3] Ultrasound; Women's Health Voluson 730 [BT05; BT08] Advanced Visualization AW 4.0 to AW 4.6; AWS2.0 to AW3.0 Affected versions of the following can be determined by visiting the GE Customer Portal Interventional Innova 2000; 3100; 4100; 2100-IQ; 3100-IQ; 4100-IQ; 212-IQ; 313-IQ Optima 320; CL320i; CL323i; CL320; 3100 Optima IGS 320; 330; Innova IGS 5x0; 6x0; 7x0 Advanced Visualization AW 4.0 to AW 4.6; AWS2.0 to AW3.0 X-Ray Brivo XR118; XR383; XR515; XR575; Definium 5000; 6000; 8000; AMX 700; Discovery XR650; XR656; XR656+; Optima XR640; XR646; XR220amx; XR200amx; Precision 500D; WDR1 Mammography Seno 200D; DS; Essential; Senographe Pristina Computed Tomography BrightSpeed Elite; Elite Select; Edge; Edge Select Brivo CT385 Discovery CT590RT; CT750HD LightSpeed VCT; Pro16; RT16 Optima Advance; CT520; CT540; CT660; CT580; CT580RT; CT580W; CT670; CT680 Quantum; Expert & Professional Revolution EVO; HD; ACT; ACTs; CT; Discovery CT; Frontier; Frontier ES Nuclear Medicine; PET/CT Brivo NM 615 Discovery NM 630; NM 750b; NM D530c; NM/CT D570c; NM/CT 670 Infinia Discovery NM830; NM/CT 860; NM/CT850; NM/CT 870; MI MI DR; IQ Optima NM/CT 640 Ventri Xeleris PET Discovery IQ; IQ upgrade PETrace 800.,"CVE-2020-25175, CVE-2020-25179",9.8,Critical,"CWE-497, CWE-523",Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1469,12/8/2020,12/9/2020,2020,ICSA-20-343-01,Multiple Embedded TCP/IP Stacks,Multiple (Open-source),Multiple Embedded TCP/IP Stacks,The following are affected: uIP-Contiki-OS (end-of-life [EOL]); Version 3.0 and prior uIP-Contiki-NG; Version 4.5 and prior uIP (EOL); Version 1.0 and prior open-iscsi; Version 2.1.12 and prior picoTCP-NG; Version 1.7.0 and prior picoTCP (EOL); Version 1.7.0 and prior FNET; Version 4.6.3 Nut/Net; Version 5.1 and prior.,"CVE-2020-13984, CVE-2020-13985, CVE-2020-13986, CVE-2020-13987, CVE-2020-13988, CVE-2020-17437, CVE-2020-17438, CVE-2020-17439, CVE-2020-17440, CVE-2020-17441, CVE-2020-17442, CVE-2020-17443, CVE-2020-17444, CVE-2020-17445, CVE-2020-17467, CVE-2020-17468, CVE-2020-17469, CVE-2020-17470, CVE-2020-24334, CVE-2020-24335, CVE-2020-24336, CVE-2020-24337, CVE-2020-24338, CVE-2020-24339, CVE-2020-24340, CVE-2020-24341, CVE-2020-24383, CVE-2020-25107, CVE-2020-25108, CVE-2020-25109, CVE-2020-25110, CVE-2020-25111, CVE-2020-25112",9.8,Critical,"CWE-20, CWE-170, CWE-190, CWE-835, CWE-125, CWE-787",Multiple Critical Sectors,Worldwide,Open-source,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1468,12/8/2020,12/8/2020,2020,ICSA-20-343-03,Schneider Electric Easergy T300,Schneider Electric,Easergy T300,Schneider Electric reports this vulnerability affects the following firmware versions of the Easergy T300 products: Easergy T300 with firmware Versions 2.7 and prior.,"CVE-2020-28215, CVE-2020-28216, CVE-2020-28217, CVE-2020-28218, CVE-2020-7561",10.0,Critical,"CWE-1021, CWE-306, CWE-862, CWE-311",Commercial Facilities; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1467,12/8/2020,12/8/2020,2020,ICSA-20-343-04,Schneider Electric Modicon M221 Programmable Logic Controller,Schneider Electric,Modicon M221 Programmable Logic Controller,Schneider Electric reports these vulnerabilities affect the following Modicon products: Modicon M221: All versions.,"CVE-2020-28214, CVE-2020-7565, CVE-2020-7566, CVE-2020-7567, CVE-2020-7568",7.1,High,"CWE-200, CWE-326, CWE-311, CWE-334, CWE-760",Commercial Facilities; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1466,12/8/2020,12/8/2020,2020,ICSA-20-343-06,Siemens XHQ Operations Intelligence,Siemens,XHQ Operations Intelligence,The following versions of XHQ Operations Intelligence are affected: XHQ: All versions prior to 6.1.,"CVE-2019-19283, CVE-2019-19284, CVE-2019-19285, CVE-2019-19286, CVE-2019-19287, CVE-2019-19288, CVE-2019-19289",8.1,High,"CWE-352, CWE-200, CWE-79, CWE-80, CWE-89, CWE-23",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1465,12/8/2020,12/8/2020,2020,ICSA-20-343-07,Siemens SICAM A8000 RTUs,Siemens,SICAM A8000 RTUs,The following versions of Siemens SICAM A8000 - a remote terminal unit (RTU) are affected: SICAM A8000 CP-8000: All versions prior to Version 16 SICAM A8000 CP-8021: All versions prior to Version 16 SICAM A8000 CP-8022: All versions prior to Version 16.,CVE-2020-28396,8.1,High,CWE-693,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1464,12/8/2020,12/8/2020,2020,ICSA-20-343-09,Siemens SIMATIC Controller Web Servers,Siemens,SIMATIC Controller Web Servers,Siemens reports the vulnerability affects the web server of the following SIMATIC controllers: SIMATIC ET 200SP Open Controller (incl. SIPLUS variants): Version 20.8 SIMATIC S7-1500 Software Controller: Version 20.8.,CVE-2020-15796,5.3,Medium,CWE-248,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1463,12/8/2020,12/8/2020,2020,ICSA-20-343-10,Siemens LOGO! 8 BM,Siemens,LOGO! 8 BM,Siemens reports the vulnerabilities affect the following LOGO! products: LOGO! 8 BM (incl. SIPLUS variants): All versions prior to 8.3 LOGO! Soft Comfort: All versions prior to 8.3 (only affected by CVE-2020-25231; CVE-2020-25234).,"CVE-2020-25228, CVE-2020-25229, CVE-2020-25230, CVE-2020-25231, CVE-2020-25232, CVE-2020-25233, CVE-2020-25234, CVE-2020-25235",9.8,Critical,"CWE-522, CWE-306, CWE-327, CWE-321",Commercial Facilities; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1462,9/8/2020,9/8/2020,2020,ICSA-20-252-02,Siemens SIMATIC S7-300 and S7-400 CPUs (Update C),Siemens,SIMATIC S7-300 and S7-400 CPUs,Siemens reports the vulnerability affects the following versions of SIMATIC S7-300 and S7-400 CPU families: SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions SIMATIC S7-400 CPU family (incl. SIPLUS variants): All versions SIMATIC WinAC RTX (F) 2010: All versions SINUMERIK 840D sl: All versions.,CVE-2020-15791,5.9,Medium,CWE-522,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1461,8/11/2020,12/8/2020,2020,ICSA-20-224-05,"Siemens SIMATIC, SIMOTICS (Update A)",Siemens,"SIMATIC, SIMOTICS",The following Siemens products are affected: SIMATIC RF350M: All versions SIMATIC RF650M: All versions; SIMOTICS CONNECT 400: All versions prior to 0.4.0.22.,CVE-2019-15126,3.1,Low,CWE-367,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1460,6/9/2020,12/8/2020,2020,ICSA-20-161-03,Siemens LOGO! (Update A),Siemens,LOGO!,The following versions of LOGO! are affected: LOGO!8 BM (incl. SIPLUS variants): All versions.,CVE-2020-7589,9.4,Critical,CWE-306,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1459,5/14/2019,12/8/2020,2020,ICSA-19-134-03,Siemens LOGO! Soft Comfort (Update A),Siemens,LOGO! Soft Comfort,LOGO! Soft Comfort: All versions prior to v8.3.,CVE-2019-10924,7.8,High,CWE-502,Commercial Facilities; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1458,5/14/2019,12/8/2020,2020,ICSA-19-134-04,Siemens LOGO! 8 BM (Update A),Siemens,LOGO!8 BM,Siemens LOGO! 8 BM: All versions prior to 8.3.,"CVE-2019-10919, CVE-2019-10920, CVE-2019-10921",9.4,Critical,"CWE-231, CWE-306, CWE-256",Commercial Facilities; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1457,6/14/2018,6/14/2018,2020,ICSA-18-165-01,"Siemens SCALANCE X Switches, RUGGEDCOM WiMAX, RFID 181-EIP, and SIMATIC RF182C (Update D)",Siemens,"SCALANCE X Switches, RUGGEDCOM WiMAX, RFID 181-EIP, and SIMATIC RF182C",Siemens reports the vulnerability affects the following products: RFID 181-EIP: All versions RUGGEDCOM Win: v4.4 | v4.5 | v5.0 and v5.1 SCALANCE X-200 switch family (incl. SIPLUS NET variants): All versions prior to v5.2.3 SCALANCE X-200 IRT switch family (incl. SIPLUS NET variants): All versions prior to v5.4.1 SCALANCE X-200RNA: All versions prior to v3.2.6 SCALANCE X-300 switch family (incl. SIPLUS NET variants): All versions prior to v4.1.3 SCALANCE X408: All versions prior to v4.1.3 SCALANCE X414: All versions SIMATIC RF182C: All versions.,CVE-2018-4833,7.5,High,CWE-122,Chemical; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1456,8/31/2017,12/8/2020,2020,ICSA-17-243-02,Siemens LOGO! (Update A),Siemens,LOGO!,Siemens reports the vulnerabilities affect the following LOGO! devices: LOGO! 8 BM (incl. SIPLUS variants): All versions prior to v1.81.2 LOGO! 8 BM (incl. SIPLUS variants): All versions prior to v8.3.,"CVE-2017-12734, CVE-2017-12735",7.5,High,"CWE-300, CWE-522",Commercial Facilities; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1455,12/3/2020,12/3/2020,2020,ICSA-20-338-01,National Instruments CompactRIO,National Instruments Corp (NI),CompactRIO,The following versions of CompactRIO - a real-time embedded industrial controller are affected: CompactRIO: Driver versions prior to 20.5.,CVE-2020-25191,7.5,High,CWE-732,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1454,8/25/2020,8/25/2020,2020,ICSA-20-238-03,WECON LeviStudioU (Update C),WECON,LeviStudioU,The following versions of LeviStudioU are reported to be affected: LeviStudioU: Release Build 2019-09-21 and prior. If you have questions about the affected products; please contact WECON.,"CVE-2020-16243, CVE-2020-25186, CVE-2020-25199",7.8,High,"CWE-122, CWE-611, CWE-121",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1453,12/1/2020,12/10/2020,2020,ICSA-20-336-01,Schneider Electric EcoStruxure Operator Terminal Expert runtime (Vijeo XD),Schneider Electric,EcoStruxure Operator Terminal Expert runtime (Vijeo XD),Schneider Electric reports the vulnerability affects the following EcoStruxure Operator Terminal Expert products: EcoStruxure Operator Terminal Expert Runtime 3.1 Service Pack 1A and prior installed on: Windows PC using legacy BIOS Harmony iPC (HMIG5U; HMIG5U2) using legacy BIOS NOTE: Windows PCs using UEFI are not impacted by this vulnerability.,CVE-2020-7544,7.4,High,CWE-269,Commercial Facilities; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1452,11/24/2020,11/24/2020,2020,ICSA-20-329-01,Rockwell Automation FactoryTalk Linx,Rockwell Automation,FactoryTalk Linx,The following versions of FactoryTalk Linx are affected: FactoryTalk Linx: Version 6.11 and prior.,"CVE-2020-27251, CVE-2020-27253, CVE-2020-27255",9.8,Critical,"CWE-122, CWE-20",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1451,11/24/2020,11/24/2020,2020,ICSA-20-329-02,Fuji Electric V-Server Lite,Fuji Electric,Electric V-Server Lite,The following versions of V-Server Lite - a data collection and management service are affected: V-Server Lite; all versions prior to 3.3.24.0.,CVE-2020-25171,7.8,High,CWE-787,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1450,11/19/2020,11/19/2020,2020,ICSA-20-324-01,Johnson Controls Sensormatic Electronics American Dynamics victor Web Client,Sensormatic Electronics LLC (Subsidiary of Johnson Controls),American Dynamics victor Web Client,Johnson Controls reports this vulnerability affects the following products: All versions of victor Web Client up to and including v5.6 All versions of C¢CURE Web Client up to and including v2.90 NOTE: This does not affect the new web-based C¢CURE 9000 client that was introduced in C¢CURE 9000 v2.90.,CVE-2020-9049,7.1,High,CWE-285,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1449,11/19/2020,9/13/2022,2020,ICSA-20-324-02,Paradox IP150 (Update A),Paradox,IP150,The following versions of Paradox IP150 are affected: --------- Begin Update A part 1 of 1 --------- Paradox IP150: All firmware versions --------- End Update A part 1 of 1 --------- Paradox IP150 firmware Version 5.02.09.,"CVE-2020-25185, CVE-2020-25189",9.8,Critical,"CWE-120, CWE-121",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1448,11/19/2020,11/19/2020,2020,ICSA-20-324-03,Real Time Automation EtherNet/IP,Real Time Automation (RTA),EtherNet/IP,The following versions of 499ES EtherNet/IP Adaptor Source Code - a TCP/IP stack are affected: All versions prior to 2.28.,CVE-2020-25159,9.8,Critical,CWE-121,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1447,11/19/2020,11/19/2020,2020,ICSA-20-324-04,Schneider Electric Interactive Graphical SCADA System (IGSS),Schneider Electric,Interactive Graphical SCADA System (IGSS),The following versions of IGSS are affected: IGSS Definition (Def.exe) Version 14.0.0.20247 and prior.,"CVE-2020-7550, CVE-2020-7551, CVE-2020-7552, CVE-2020-7553, CVE-2020-7554, CVE-2020-7555, CVE-2020-7556, CVE-2020-7557, CVE-2020-7558",7.8,High,"CWE-119, CWE-125, CWE-787",Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1446,11/12/2020,3/15/2021,2020,ICSMA-20-317-01,BD Alaris 8015 PC Unit and BD Alaris Systems Manager,"Becton, Dickinson and Company (BD)",Alaris 8015 PC Unit and BD Alaris Systems Manager,The following versions of BD Alaris infusion products are affected: BD Alaris PC Unit; Model 8015; Versions 9.33.1 and earlier BD Alaris Systems Manager; Versions 4.33 and earlier.,CVE-2020-25165,6.5,Medium,CWE-287,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1445,11/12/2020,11/12/2020,2020,ICSA-20-317-01,Mitsubishi Electric MELSEC iQ-R Series,Mitsubishi Electric,MELSEC iQ-R Series,Mitsubishi Electric reports the vulnerability affects the following MELSEC iQ-R series CPU module products: R00/01/02 CPU Firmware versions from 05 to 19 R04/08/16/32/120(EN) CPU Firmware versions from 35 to 51.,CVE-2020-5666,6.8,Medium,CWE-400,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1444,11/10/2020,11/10/2020,2020,ICSA-20-315-01,OSIsoft PI Interface for OPC XML-DA,OSIsoft,PI Interface for OPC XML-DA,All versions of PI Interface for OPC XML-DA prior to 1.7.3.x are affected.,CVE-2013-0006,8.1,High,CWE-189,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1443,11/10/2020,11/10/2020,2020,ICSA-20-315-02,OSIsoft PI Vision,OSIsoft,PI Vision,All versions prior to PI Vision 2020 are affected.,"CVE-2020-25163, CVE-2020-25167",7.7,High,"CWE-79, CWE-863",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1442,11/10/2020,11/10/2020,2020,ICSA-20-315-03,Schneider Electric PLC Simulator for EcoStruxure Control Expert,Schneider Electric,PLC Simulator for EcoStruxure Control Expert,Schneider Electric reports the vulnerability affects the following PLC simulators: PLC Simulator for EcoStruxure Control Expert; all versions PLC Simulator for Unity Pro (former name of EcoStruxure Control Expert); all versions.,CVE-2020-7538,7.5,High,CWE-754,Commercial Facilities; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1441,11/10/2020,11/10/2020,2020,ICSA-20-315-05,Siemens SCALANCE W 1750D,Siemens,SCALANCE W 1750D,The following versions of SCALANCE are affected: SCALANCE W 1750D: All versions.,CVE-2016-2031,9.8,Critical,CWE-20,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1440,11/5/2020,11/5/2020,2020,ICSA-20-310-01,WECON PLC Editor,WECON,PLC Editor,The following versions of PLC Editor - a ladder logic software are affected: PLC Editor Versions 1.3.8 and prior.,"CVE-2020-25177, CVE-2020-25181",7.8,High,"CWE-122, CWE-121",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1439,11/5/2020,11/5/2020,2020,ICSA-20-310-02,Mitsubishi Electric GT14 Model of GOT1000 Series,Mitsubishi Electric,GT14 Model of GOT1000 Series,The following models of GOT1000 with CoreOS Version 05.65.00.BD and prior - a graphic operation terminal are affected: GT1455-QTBDE GT1450-QMBDE GT1450-QLBDE GT1455HS-QTBDE GT1450HS-QMBDE.,"CVE-2020-5644, CVE-2020-5645, CVE-2020-5646, CVE-2020-5647, CVE-2020-5648, CVE-2020-5649",9.8,Critical,"CWE-284, CWE-88, CWE-119, CWE-476, CWE-399, CWE-384",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1438,11/3/2020,11/3/2020,2020,ICSA-20-308-02,NEXCOM NIO50,NEXCOM,NIO50,All versions of NEXCOM NIO 50 are affected.,"CVE-2020-25151, CVE-2020-25155",5.3,Medium,"CWE-319, CWE-20",Multiple Critical Sectors,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1437,10/29/2020,10/30/2020,2020,ICSA-20-303-02,Mitsubishi Electric MELSEC iQ-R,Mitsubishi Electric,MELSEC iQ-R,The following modules of MELSEC iQ-R Series are affected: EtherNet/IP Network Interface Module; RJ71EIP91: First 2 digits of serial number are 02 or before. PROFINET IO Controller Module; RJ71PN92: First 2 digits of serial number are 01 or before High Speed Data Logger Module; RD81DL96: First 2 digits of serial number are 08 or before MES Interface Module; RD81MES96N: First 2 digits of serial number are 04 or before OPC UA Server Module; RD81OPC96: First 2 digits of serial number are 04 or before.,"CVE-2020-5653, CVE-2020-5654, CVE-2020-5655, CVE-2020-5656, CVE-2020-5657, CVE-2020-5658",9.8,Critical,"CWE-284, CWE-88, CWE-119, CWE-476, CWE-399, CWE-384",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1436,10/27/2020,10/27/2020,2020,ICSA-20-301-01,SHUN HU Technology JUUKO Industrial Radio Remote Control,SHUN HU Technology Co Ltd,Industrial Radio Remote Control,The following versions of JUUKO Industrial Radio Remote Control are affected: JUUKO K-800 and K-808: Firmware versions prior to numbers ending ...9A; ...9B; ...9C; etc. If you have any questions on what is affected; please contact SHUN HU Technology technical support.,"CVE-2018-17932, CVE-2018-19025",8.3,High,"CWE-294, CWE-77",Communications,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1435,10/22/2020,10/22/2020,2020,ICSMA-20-296-01,B. Braun OnlineSuite,B. Braun Melsungen AG,OnlineSuite,The following versions of OnlineSuite are affected: AP 3.0 and earlier.,"CVE-2020-25170, CVE-2020-25172, CVE-2020-25174",8.6,High,"CWE-1236, CWE-23, CWE-427",Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1434,10/22/2020,10/20/2022,2022,ICSMA-20-296-02,"B. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplus (Update A)",B. Braun Melsungen AG,"SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplus","""The following versions of B. Braun products are affected: SpaceCom, software Versions U61 and earlier (United States), L81 and earlier (outside the United States) Battery pack with Wi-Fi, software Versions U61 and earlier (United States), L81 and earlier (outside the United States) Data module compactplus, software Versions A10 and A11 (not distributed in the United States).""","CVE-2020-16238, CVE-2020-25150, CVE-2020-25152, CVE-2020-25154, CVE-2020-25156, CVE-2020-25158, CVE-2020-25160, CVE-2020-25162, CVE-2020-25164, CVE-2020-25166, CVE-2020-25168",7.6,High,"CWE-79, CWE-601, CWE-643, CWE-384, CWE-759, CWE-23, CWE-347, CWE-269, CWE-798, CWE-489, CWE-284",Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1433,10/20/2020,10/27/2020,2020,ICSA-20-294-01,Rockwell Automation 1794-AENT Flex I/O Series B,Rockwell Automation,1794-AENT Flex I/O Series B,The following versions of 1794-AENT Flex I/O Series B - Ethernet/IP adapter are affected: 1794-AENT Flex I/O; Series B; Versions 4.003 and prior.,"CVE-2020-6083, CVE-2020-6084, CVE-2020-6085, CVE-2020-6086, CVE-2020-6087",7.5,High,CWE-120,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1432,10/20/2020,10/20/2020,2020,ICSA-20-294-02,Hitachi ABB Power Grids XMC20 Multiservice-Multiplexer,Hitachi and ABB,Power Grids XMC20 Multiservice-Multiplexer,Hitachi ABB Power Grids reports the vulnerability affects the following XMC20 Multiservice-Multiplexer products: XMC20 R4 using COGE5 versions older than co5ne_r1h07_12.esw XMC20 R6 using COGE5 versions older than co5ne_r2d14_03.esw.,CVE-2018-10933,9.1,Critical,CWE-287,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1431,7/14/2020,10/20/2020,2020,ICSMA-20-196-01,Capsule Technologies SmartLinx Neuron 2 (Update A),Capsule Technologies Inc,SmartLinx Neuron 2,The following versions of Capsule Technologies SmartLinx Neuron 2 - a medical device platform are affected: Capsule Technologies SmartLinx Neuron 2: Firmware Versions 9.0.3 and older.,CVE-2019-5024,7.6,High,CWE-693,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1430,10/15/2020,10/15/2020,2020,ICSA-20-289-01,Advantech WebAccess/SCADA,Advantech,WebAccess/SCADA,The following versions of WebAccess/SCADA - a browser-based SCADA software package are affected: WebAccess/SCADA Versions 9.0 and prior.,CVE-2020-25161,8.8,High,CWE-73,Critical Manufacturing; Energy; Water and Wastewater,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1429,10/15/2020,10/15/2020,2020,ICSA-20-289-02,Advantech R-SeeNet,Advantech,R-SeeNet,The following versions of R-SeeNet - a monitoring application are affected: R-SeeNet Versions 1.5.1 through 2.4.10.,CVE-2020-25157,7.5,High,CWE-89,Critical Manufacturing; Energy; Water and Wastewater,"East Asia, Europe, Middle East, South America, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1428,10/13/2020,10/13/2020,2020,ICSA-20-287-01,MOXA NPort IAW5000A-I/O Series,Moxa,NPort IAW5000A-I/O Series,The following software versions on NPort IAW5000A-I/O - integrated serial device server are affected: NPort: Firmware Version 2.1 or lower.,"CVE-2020-25153, CVE-2020-25190, CVE-2020-25192, CVE-2020-25194, CVE-2020-25196, CVE-2020-25198",9.8,Critical,"CWE-319, CWE-200, CWE-269, CWE-307, CWE-384, CWE-521",Energy,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1427,10/13/2020,10/13/2020,2020,ICSA-20-287-02,LCDS LAquis SCADA,LCDS - Leao Consultoria e Desenvolvimento de Sistemas Ltda ME,LAquis SCADA,The following versions of LAquis SCADA are affected: LAquis SCADA versions prior to 4.3.1.870.,CVE-2020-25188,7.8,High,CWE-125,Chemical; Commercial Facilities; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,South America,Brazil,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1426,10/13/2020,10/13/2020,2020,ICSA-20-287-03,Flexera InstallShield,Flexera,InstallShield,The following versions of Flexera InstallShield are affected: Flexera InstallShield through 2015 SP1 Flexera InstallShield is integrated into many products sold by other companies.,CVE-2016-2542,7.3,High,CWE-426,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1425,10/13/2020,10/13/2020,2020,ICSA-20-287-04,Fieldcomm Group HART-IP and hipserver,Fieldcomm Group,HART-IP and hipserver,The following products and versions are affected: HART-IP Developer kit; Release 1.0.0.0 hipserver; Release 3.6.1.,CVE-2020-16209,9.8,Critical,CWE-121,Commercial Facilities; Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1424,10/13/2020,10/13/2020,2020,ICSA-20-287-05,Siemens Desigo Insight,Siemens,Desigo Insight,The following Siemens products are affected: Desigo Insight: All versions.,"CVE-2020-15792, CVE-2020-15793, CVE-2020-15794",5.4,Medium,"CWE-200, CWE-89, CWE-1021",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1423,10/13/2020,10/13/2020,2020,ICSA-20-287-06,Siemens SIPORT MP,Siemens,SIPORT MP,The following versions of SIPORT MP - a system for access control and time management within the Siveillance Access Suite are affected: SIPORT MP: Versions 3.2.1 and prior.,CVE-2020-7591,8.8,High,CWE-603,Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1422,11/28/2017,11/28/2017,2020,ICSA-17-332-01,"Siemens SCALANCE W1750D, M800, S615, and RUGGEDCOM RM1224 (Update C)",Siemens,"SCALANCE W1750D, M800, and S615",The following versions of SCALANCE | network interfaces are affected: SCALANCE W1750D: All versions prior to v 6.5.1.5 | SCALANCE M800/S615: All versions prior to v5.0. RUGGEDCOM RM1224 all versions prior to v5.0.,"CVE-2017-13704, CVE-2017-14495, CVE-2017-14496, CVE-2017-14491",8.1,High,"CWE-119, CWE-400",Chemical; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1421,9/29/2020,9/30/2020,2020,ICSA-20-273-01,"MB Connect line mbCONNECT24, mymbCONNECT24",MB Connect line,"mbCONNECT24, mymbCONNECT24",The following products and versions are affected: mymbCONNECT24 v2.6.1 and prior mbCONNECT24 v2.6.1 and prior.,"CVE-2020-24568, CVE-2020-24569, CVE-2020-24570",9.8,Critical,"CWE-352, CWE-77, CWE-89",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1420,9/29/2020,9/29/2020,2020,ICSA-20-273-02,Yokogawa WideField3,Yokogawa,WideField3,Yokogawa reports that the vulnerability affects the tool for programming FA-M3 PLCs: WideField3 R1.01 - R4.03.,CVE-2020-16232,2.8,Low,CWE-120,Critical Manufacturing; Energy; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1419,9/29/2020,9/30/2020,2020,ICSA-20-273-03,B&R Automation SiteManager and GateManager,B&R Industrial Automation GmbH,SiteManager and GateManager,The following versions of SiteManager and GateManager are affected: SiteManager all versions prior to v9.2.620236042 GateManager 4260 and 9250 all versions prior to v9.0.20262 GateManager 8250 all versions prior to v9.2.620236042.,"CVE-2020-11641, CVE-2020-11642, CVE-2020-11643, CVE-2020-11644, CVE-2020-11645, CVE-2020-11646",7.7,High,"CWE-200, CWE-287, CWE-22, CWE-400",Chemical; Critical Manufacturing; Energy,Worldwide,Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1418,1/11/2013,9/24/2020,2020,ICSA-13-011-01,3S CoDeSys (Update A),3S-Smart Software Solutions,CoDeSys,CODESYS Control Runtime embedded Versions prior to 2.3.2.8 | CODESYS Control Runtime full Versions prior to 2.4.7.40 | CODESYS Control RTE: Versions prior to 2.3.7.17.,"CVE-2012-6068, CVE-2012-6069",10.0,Critical,"CWE-284, CWE-23",Energy; Transportation Systems,"China, Germany",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1417,9/22/2020,9/22/2020,2020,ICSA-20-266-01,GE Digital APM Classic,GE Digital,APM Classic,The following versions of GE Digital APM Classic - a tool to analyze and process data are affected: APM Classic; Versions 4.4 and prior.,"CVE-2020-16240, CVE-2020-16244",7.5,High,"CWE-639, CWE-759",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1416,9/22/2020,9/28/2020,2020,ICSA-20-266-02,GE Reason S20 Ethernet Switch,GE,Reason S20 Ethernet Switch,The following versions of Reason S20 managed Ethernet switches are affected: S2020; All firmware versions prior to 07A06 S2024; All firmware versions prior to 07A06.,"CVE-2020-16242, CVE-2020-16246",6.1,Medium,CWE-79,Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1415,9/17/2020,9/17/2020,2020,ICSMA-20-261-01,Philips Clinical Collaboration Platform,Philips,Clinical Collaboration Platform,The following versions of Clinical Collaboration Platform - HMI data management platform are affected: Clinical Collaboration Platform Versions 12.2.1 and prior NOTE: The product is registered as Vue PACS but was re-branded to Philips Clinical Collaboration Platform when Philips acquired Carestream HCIS.,"CVE-2020-14506, CVE-2020-14525, CVE-2020-16198, CVE-2020-16200, CVE-2020-16247",6.8,Medium,"CWE-352, CWE-83, CWE-16, CWE-693, CWE-757",Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1414,9/17/2020,9/17/2020,2020,ICSA-20-261-01,Advantech WebAccess Node,Advantech,WebAccess Node,The following versions of WebAccess Node - HMI platform are affected: WebAccess Node: All versions prior to 9.0.1.,CVE-2020-16202,7.8,High,CWE-732,Critical Manufacturing; Energy; Water and Wastewater,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1413,6/25/2020,9/15/2020,2020,ICSA-20-177-01,ENTTEC Lighting Controllers (Update A),ENTTEC,Lighting Controllers,ENTTEC reports these vulnerabilities affect firmware Version 70044_update_05032019-482 and prior for the following lighting control products: Datagate Mk2 Storm 24 Pixelator; E-Streamer Mk2 (End of Life).,"CVE-2019-12774, CVE-2019-12775, CVE-2019-12776, CVE-2019-12777",8.8,High,"CWE-284, CWE-79, CWE-732, CWE-321",Commercial Facilities,Worldwide,Australia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1412,9/10/2020,9/10/2020,2020,ICSA-20-254-01,AVEVA Enterprise Data Management Web,AVEVA,Enterprise Data Management Web,The following versions of Enterprise Data Management Web (formerly eDNA Web) - a data management platform are affected: Enterprise Data Management Web v2019 and prior.,"CVE-2020-13499, CVE-2020-13500, CVE-2020-13501",9.6,Critical,CWE-89,Critical Manufacturing; Information Technology,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1411,9/10/2020,9/14/2020,2020,ICSA-20-254-02,FATEK Automation PLC WinProladder,FATEK Automation,PLC WinProladder,The following versions of PLC WinProladder are affected: PLC WinProladder Version 3.28 and prior.,CVE-2020-16234,7.8,High,CWE-121,Critical Manufacturing; Commercial Facilities,"Europe, Asia",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1410,9/10/2020,9/10/2020,2020,ICSA-20-254-03,HMS Networks Ewon Flexy and Cosy,HMS Industrial Networks,Ewon Flexy and Cosy,The following Ewon products are affected: Flexy and Cosy: All versions prior to 14.1.,CVE-2020-16230,2.3,Low,CWE-942,Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,Worldwide,Sweden,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1409,9/8/2020,9/8/2020,2020,ICSA-20-252-01,Siemens SIMATIC RTLS Locating Manager,Siemens,SIMATIC RTLS Locating Manager,Siemens reports that the vulnerabilities affect the following versions of SIMATIC RTLS Locating Manager: SIMATIC RTLS Locating Manager; all versions prior to v2.10.2.,"CVE-2020-10049, CVE-2020-10050, CVE-2020-10051",8.4,High,"CWE-276, CWE-428",Critical Manufacturing; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1408,9/8/2020,9/21/2020,2020,ICSA-20-252-03,Siemens License Management Utility,Siemens,License Management Utility,The following versions of License Management Utility (LMU) - a license management system are affected: LMU: All versions prior to v2.4.,CVE-2020-10056,7.8,High,CWE-250,Commercial Facilities; Government Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1407,9/8/2020,9/8/2020,2020,ICSA-20-252-04,Siemens Spectrum Power,Siemens,Spectrum Power,The following versions of Spectrum Power are affected: Spectrum Power: All versions prior to v4.70 SP8.,"CVE-2020-15784, CVE-2020-15790",3.7,Low,"CWE-312, CWE-548",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1406,9/8/2020,9/8/2020,2020,ICSA-20-252-05,Siemens Siveillance Video Client,Siemens,Siveillance Video Client,The following versions of Siveillance Video Client - IP video management software are affected: Siveillance Video Client: all versions.,CVE-2020-15785,5.3,Medium,CWE-319,Commercial facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1405,9/8/2020,9/8/2020,2020,ICSA-20-252-08,Siemens Polarion Subversion Webclient,Siemens,Polarion Subversion Webclient,The following versions of Siemens Polarion Subversion Webclient are affected: Polarion Subversion Webclient; all versions.,"CVE-2020-15788, CVE-2020-15789",8.1,High,"CWE-352, CWE-80",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1404,4/14/2020,4/14/2020,2020,ICSA-20-105-05,"Siemens RUGGEDCOM, SCALANCE, SIMATIC, SINEMA (Update B)",Siemens,"RUGGEDCOM, SCALANCE, SIMATIC, SINEMA",The following Siemens products are affected: RUGGEDCOM RM1224: All versions prior to 6.1 RUGGEDCOM ROX II: All versions prior to 2.13.3 (only affected by CVE-2018-5391) SCALANCE M-800 family: All versions prior to 6.1 SCALANCE S615: All versions prior to 6.1 SCALANCE SC-600: All versions prior to 2.0 SCALANCE W1700 IEEE 802.11ac: All versions prior to 2.0 SCALANCE W700 IEEE 802.11a/b/g/n: All versions prior to 6.4 SIMATIC CP 1242-7: All versions prior to 3.2 SIMATIC CP 1243-1 (incl. SIPLUS NET variants): All versions prior to 3.2 SIMATIC CP 1243-7 LTE EU: All versions prior to 3.2 SIMATIC CP 2243-7 LTE US: All versions prior to 3.2 SIMATIC CP 1243-8 IRC: All versions prior to 3.2 SIMATIC CP 1542SP-1: All versions prior to 2.1 SIMATIC CP 1542SP-1 IRC (incl. SIPLUS NET variants): All versions prior to 2.1 SIMATIC CP 1543-1 (incl. SIPLUS NET variants): All versions prior to 2.2 SIMATIC CP 1543SP-1 (incl. SIPLUS NET variants): All versions prior to 2.1; SIMATIC RF185C: All versions prior to v1.3 SIMATIC RF186C: All versions prior to v1.3 SIMATIC RF186CI: All versions prior to v1.3 SIMATIC RF188C: All versions prior to v1.3 SIMATIC RF188CI: All versions prior to v1.3; SINEMA Remote Connect Server: All versions newer than 1.1 and prior to 2.0.1.,"CVE-2018-5390, CVE-2018-5391",7.5,High,"CWE-20, CWE-400",Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1403,8/27/2020,8/27/2020,2020,ICSA-20-240-01,"Red Lion N-Tron 702-W, 702M12-W",Red Lion Controls,"N-Tron 702-W, 702M12-W",The following Red Lion products are affected: N-Tron 702-W: All versions N-Tron 702M12-W: All versions.,"CVE-2020-16204, CVE-2020-16206, CVE-2020-16208, CVE-2020-16210, CVE-2017-16544",9.8,Critical,"CWE-352, CWE-912, CWE-79, CWE-1104",Commercial Facilities; Energy; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1402,8/25/2020,8/25/2020,2020,ICSA-20-238-01,Advantech iView,Advantech,iView,The following versions of iView - a device management application are affected: iView Versions 5.7 and prior.,CVE-2020-16245,9.8,Critical,CWE-22,Critical Manufacturing; Energy; Water and Wastewater,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1401,8/25/2020,8/25/2020,2020,ICSA-20-238-02,Emerson OpenEnterprise,Emerson,OpenEnterprise,Emerson reports that the vulnerability affects the following products: OpenEnterprise All versions through 3.3.5.,CVE-2020-16235,3.8,Low,CWE-326,Chemical; Energy; Healthcare and Public Health; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1400,8/20/2020,8/20/2020,2020,ICSMA-20-233-01,Philips SureSigns VS4,Philips,SureSigns VS4,The following versions of SureSigns VS4 - a vital signs patient monitor are affected: SureSigns VS4 A.07.107 and prior.,"CVE-2020-16237, CVE-2020-16239, CVE-2020-16241",6.3,Medium,"CWE-284, CWE-287, CWE-20",Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1399,6/16/2020,9/19/2024,2020,ICSA-20-168-01,Treck TCP/IP (Update I),Treck Inc,TCP/IP,"The Treck TCP/IP stack is affected, including: Treck Inc TCP/IP: IPv4 Treck Inc TCP/IP: IPv6 Treck Inc TCP/IP: UDP Treck Inc TCP/IP: DNS Treck Inc TCP/IP: DHCP Treck Inc TCP/IP: TCP Treck Inc TCP/IP: ICMPv4 Treck Inc TCP/IP: ARP.","CVE-2020-11896, CVE-2020-11897, CVE-2020-11898, CVE-2020-11899, CVE-2020-11900, CVE-2020-11901, CVE-2020-11902, CVE-2020-11903, CVE-2020-11904, CVE-2020-11905, CVE-2020-11906, CVE-2020-11907, CVE-2020-11908, CVE-2020-11909, CVE-2020-11910, CVE-2020-11911, CVE-2020-11912, CVE-2020-11913, CVE-2020-11914",10.0,Critical,"CWE-20, CWE-125, CWE-130, CWE-170, CWE-190, CWE-284, CWE-415",Energy; Critical Manufacturing; Information Technology; Healthcare and Public Health; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1398,8/11/2020,8/11/2020,2020,ICSA-20-224-02,Schneider Electric APC Easy UPS On-Line,Schneider Electric,APC Easy UPS On-Line,The following versions of APC Easy UPS On-Line Software are affected: SFAPV9601 v2.0 and earlier.,"CVE-2020-7521, CVE-2020-7522",9.8,Critical,CWE-22,Multiple Critical Sectors,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1397,8/11/2020,8/11/2020,2020,ICSA-20-224-03,Tridium Niagara,Tridium,Niagara,The following versions of Niagara are affected: Niagara: Versions 4.6.96.28; 4.7.109.20; 4.7.110.32; 4.8.0.110 Niagara Enterprise Security: Versions 2.4.31; 2.4.45; 4.8.0.35.,CVE-2020-14483,4.3,Medium,CWE-1088,Commercial Facilities; Critical Manufacturing; Government Facilities; Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1396,8/11/2020,8/11/2020,2020,ICSA-20-224-04,"Siemens SCALANCE, RUGGEDCOM",Siemens,"SCALANCE, RUGGEDCOM",The following Siemens products are affected: RUGGEDCOM RM1224: All versions prior to 6.3 SCALANCE M-800 / S615: All versions prior to 6.3.,CVE-2020-8597,9.8,Critical,CWE-120,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1395,8/11/2020,8/11/2020,2020,ICSA-20-224-06,Siemens Desigo CC,Siemens,Desigo CC,The following Siemens products and versions are affected: Desigo CC: Versions 3.x and 4.x; and Desigo CC Compact: Versions 3.x and 4.x.,CVE-2020-10055,9.8,Critical,CWE-94,Commercial Facilities; Government Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1394,8/11/2020,8/11/2020,2020,ICSA-20-224-07,Siemens Automation License Manager,Siemens,Automation License Manager,The following versions of Automation License Manager (ALM) - a software management platform are affected: Automation License Manager 5: All versions Automation License Manager 6: All versions prior to v6.0.8.,CVE-2020-7583,7.3,High,CWE-285,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1393,8/11/2020,8/11/2020,2020,ICSA-20-224-08,Siemens SICAM A8000 RTUs,Siemens,SICAM A8000 RTUs,The following versions of SICAM A8000 RTUs are affected: SICAM WEB firmware: all versions prior to C05.30.,CVE-2020-15781,8.3,High,CWE-79,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1392,4/9/2019,4/9/2019,2020,ICSA-19-099-06,"Siemens SIMATIC, SIMOCODE, SINAMICS, SITOP, and TIM (Update I)",Siemens,"CP, SIMATIC, SIMOCODE, SINAMICS, SITOP, and TIM","SIMATIC CP 1616 and CP 1604: All versions SIMATIC CP443-1 (incl. SIPLUS NET variants): All versions SIMATIC CP443-1 Advanced (incl. SIPLUS NET variants): All versions SIMATIC CP443-1 OPC UA (incl. SIPLUS NET variants): All versions SIMATIC CP343-1 Advanced (incl. SIPLUS NET variants): All versions SIMATIC ET 200 SP Open Controller CPU 1515SP PC (incl. SIPLUS variants): All versions prior to v2.1.6 SIMATIC ET 200 SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions prior to v2.7 SIMATIC HMI Comfort Outdoor Panels 7"" & 15"" (incl. SIPLUS variants): All versions prior to v15.1 Upd 4 SIMATIC HMI Comfort Panels 4"" - 22"" (incl. SIPLUS variants): All versions prior to v15.1 Upd 4 SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (incl. SIPLUS variants): All versions prior to v 15.1 Upd 4 SIMATIC IPC DiagMonitor: All versions SIMATIC RF182C: All versions SIMATIC RF185C: All versions prior to v1.10 SIMATIC RF186C: All versions prior to v1.10 SIMATIC RF188C: All versions prior to v1.10 SIMATIC RF600 family: All versions prior to v3.2.1 SIMATIC RF181-EIP: All versions SIMATIC S7-1500 Software Controller: All versions prior to v2.7 SIMATIC Teleservice Adapter IE Advanced: All versions SIMATIC Teleservice Adapter IE Basic: All versions SIMATIC Teleservice Adapter IE Standard: All versions SIMATIC WinAC RTX (F) 2010: All versions prior to SP3 SIMATIC S7-1500 CPU Family (incl. related ET200 CPUs and SIPLUS variants): All versions prior to v2.6.1 SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions prior to v3.X.16 SIMATIC S7-400 PN/DP v6 and below CPU family (incl. SIPLUS variants): All versions SIMATIC S7-400 PN/DP v7 CPU family (incl. SIPLUS variants): All versions SIMATIC S7-PLCSIM Advanced: All versions prior to v2.0 SP1 UPD1 SIMATIC WinCC Runtime Advanced: All versions prior to v15.1 Upd 4 SIMOCODE pro VPN (incl. SIPLUS variants): All versions prior to v2.1.3. SIMOCODE pro V EIP (incl. SIPLUS variants): All versions prior to 1.1.3 SIMATIC Teleservice Adapter IE Advanced: All versions SIMATIC Teleservice Adapter IE Basic: All versions SIMATIC Teleservice Adapter IE Standard: All versions. SINAMICS S120 v4.6 Control Unit (incl. SIPLUS variants): All versions prior to v5.2 SINAMICS S120 v4.7 Control Unit (incl. SIPLUS variants): All versions SINAMICS S120 v4.7 SP1 Control Unit (incl. SIPLUS variants): All versions prior to v5.2 SINAMICS S120 v4.8 Control Unit (incl. SIPLUS variants): All versions prior to v4.8 HF6 SINAMICS S120 v5.1 Control Unit (incl. SIPLUS variants): All versions SINAMICS S120 v5.1 SP1 Control Unit (incl. SIPLUS variants): All versions prior to v5.1 SP1 HF4 SINAMICS G130 v4.6 Control Unit: All versions prior to v5.2 SINAMICS G130 v4.7 Control Unit: All versions prior to v5.2 SINAMICS G130 v4.7 SP1 Control Unit: All versions prior to v5.2 SINAMICS G130 v4.8 Control Unit: All versions prior to v4.8 HF6 SINAMICS G130 v5.1 Control Unit: All versions SINAMICS G130 v5.1 SP1 Control Unit: All versions prior to v5.1 SP1 HF4 SINAMICS G150 v4.6 Control Unit: All versions prior to v5.2 SINAMICS G150 v4.7 Control Unit: All versions SINAMICS G150 v4.7 SP1 Control Unit: All versions prior to v5.2 SINAMICS G150 v4.8 Control Unit: All versions prior to v4.8 HF6 SINAMICS G150 v5.1 Control Unit: All versions SINAMICS G150 v5.1 SP1 Control Unit: All versions prior to v5.1 SP1 HF4 SINAMICS S150 v4.6 Control Unit: All versions prior to v5.2 SINAMICS S150 v4.7 Control Unit: All versions SINAMICS S150 v4.7 SP1 Control Unit: All versions prior to v5.2 SINAMICS S150 v4.8 Control Unit: All versions prior to v4.8 HF6 SINAMICS S150 v5.1 Control Unit: All versions SINAMICS S150 v5.1 SP1 Control Unit: All versions prior to v5.1 SP1 HF4 SINAMICS S210 v5.1 Control Unit: All versions SINAMICS S210 v5.1 SP1 Control Unit: All versions SITOP Manager: All versions prior to v1.1 SITOP UPS1600 (incl. SIPLUS variants): All versions prior to v2.3 RFID 181EIP: All versions SITOP PSU8600: All versions prior to v1.5 TIM 1531 IRC (incl. SIPLUS NET variants): All versions prior to v2 SIMATIC IPC DiagMonitor: All versions prior to v5.1.3.",CVE-2019-6568,7.5,High,CWE-125,Commercial Facilities; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1391,8/31/2017,4/14/2022,2020,ICSA-17-243-01,Siemens OPC UA Protocol Stack Discovery Service (Update E),Siemens,SIMATIC,"Siemens reports that the vulnerability affects the following industrial products, which use the Discovery Service of the OPC UA protocol stack by the OPC foundation: SIMATIC IT Production Suite: Versions between v6.5 and v7.1 Update E SIMATIC NET PC Software 14: All versions prior to v14 SP1 Update 14 SIMATIC PCS 7: Versions v8.0, v8.1 SIMATIC WinCC: All versions prior to v7.2 SIMATIC WinCC Runtime Professional v13: All versions SIMATIC WinCC Runtime Professional v14: All versions prior to v14 SP1 End Update E.",CVE-2017-12069,8.2,High,CWE-611,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1390,8/6/2020,8/6/2020,2020,ICSA-20-219-01,Trailer Power Line Communications,Multiple Trailer and Brake Manufacturers,Trailer Power Line Communications,All trailer power line communications are affected.,CVE-2020-14514,4.3,Medium,CWE-201,Transportation Systems,Worldwide,Not Applicable,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1389,8/6/2020,8/6/2020,2020,ICSA-20-219-02,Advantech WebAccess HMI Designer,Advantech,WebAccess HMI Designer,The following versions of Advantech WebAccess HMI Designer - a Human Machine Interface (HMI) runtime development software are affected: WebAccess HMI Designer Versions 2.1.9.31 and prior.,"CVE-2020-16207, CVE-2020-16211, CVE-2020-16213, CVE-2020-16215, CVE-2020-16217, CVE-2020-16229",9.8,Critical,"CWE-843, CWE-415, CWE-122, CWE-125, CWE-787, CWE-121",Critical Manufacturing; Energy; Water and Wastewater,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1388,8/6/2020,8/6/2020,2020,ICSA-20-219-03,Geutebruck G-Cam and G-Code,Geutebruck,G-Cam and G-Code,Geutebruck reports the vulnerability affects firmware Versions 1.12.0.25 and prior as well as the limited Versions 1.12.13.2 and 1.12.14.5 of the following Encoder and E2 Series Camera models: G-Code: EEC-2xxx G-Cam: EBC-21xx EFD-22xx ETHC-22xx EWPC-22xx.,CVE-2020-16205,7.2,High,CWE-78,Commercial Facilities; Energy; Financial Services; Government Facilities; Healthcare and Public Health; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1387,8/6/2020,8/6/2020,2020,ICSA-20-219-04,Delta Industrial Automation TPEditor,Delta Electronics,TPEditor,The following versions of TPEditor - a programming software for Delta text panels are affected: TPEditor Versions 1.97 and prior.,"CVE-2020-16219, CVE-2020-16221, CVE-2020-16223, CVE-2020-16225, CVE-2020-16227",7.8,High,"CWE-122, CWE-20, CWE-125, CWE-121, CWE-123",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1386,8/4/2020,8/4/2020,2020,ICSA-20-217-01,Delta Industrial Automation CNCSoft ScreenEditor,Delta Electronics,CNCSoft ScreenEditor,The following versions of Industrial Automation CNCSoft ScreenEditor - HMI are affected: Industrial Automation CNCSoft ScreenEditor Versions 1.01.23 and prior.,"CVE-2020-16199, CVE-2020-16201, CVE-2020-16203",7.8,High,"CWE-824, CWE-125, CWE-121",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1385,7/30/2020,7/30/2020,2020,ICSMA-20-212-01,Philips DreamMapper,Philips,DreamMapper,The following versions of DreamMapper - a mobile app used to manage sleep apnea are affected: DreamMapper Version 2.24 and prior.,CVE-2020-14518,5.3,Medium,CWE-532,Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1384,7/30/2020,7/30/2020,2020,ICSA-20-212-01,Inductive Automation Ignition 8,Inductive Automation,Inductive Automation Ignition 8,The following versions of Inductive Automation Ignition are affected: Inductive Automation Ignition 8: All versions prior to 8.0.13.,CVE-2020-14520,7.5,High,CWE-862,Critical Manufacturing; Energy; Information Technology,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1383,7/28/2020,7/28/2020,2020,ICSA-20-210-01,Secomea GateManager,Secomea,GateManager,The following versions of GateManager - a VPN server are affected: All versions prior to 9.2c.,"CVE-2020-14500, CVE-2020-14508, CVE-2020-14510, CVE-2020-14512",10.0,Critical,"CWE-158, CWE-193, CWE-798, CWE-916",Critical Manufacturing,Worldwide,Denmark,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1382,7/28/2020,7/28/2020,2020,ICSA-20-210-02,Softing Industrial Automation OPC,Softing Industrial Automation GmbH,OPC,The following versions of OPC are affected: All versions prior to the latest build of Version 4.47.0.,"CVE-2020-14522, CVE-2020-14524",9.8,Critical,"CWE-122, CWE-400",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1381,7/28/2020,7/28/2020,2020,ICSA-20-210-03,HMS Industrial Networks eCatcher,HMS Industrial Networks,eCatcher,The following versions of eCatcher - a VPN client are affected: All versions prior to 6.5.5.,CVE-2020-14498,9.6,Critical,CWE-121,Critical Manufacturing,Worldwide,Sweden,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1380,6/30/2020,7/28/2020,2020,ICSA-20-182-01,Delta Industrial Automation DOPSoft (Update A),Delta Electronics,DOPSoft,The following versions of DOPSoft - a Human Machine Interface (HMI) editing software are affected: DOPSoft Version 4.00.08.15 and prior.,"CVE-2020-10597, CVE-2020-14482",7.8,High,"CWE-122, CWE-125",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1379,7/23/2020,7/23/2020,2020,ICSA-20-205-01,Schneider Electric Triconex TriStation and Tricon Communication Module,Schneider Electric,TriStation and Tricon Communication Module,Schneider Electric has discovered and remediated multiple vulnerabilities affecting the following legacy versions of its Triconex brand safety instrumented system: TriStation 1131; v1.0.0 to v4.9.0; v4.10.0; and 4.12.0; operating on Windows NT; Windows XP; or Windows 7. Tricon Communications Module (TCM) Models 4351; 4352; 4351A/B; and 4352A/B installed in Tricon v10.0 to v10.5.3 systems. Users of current and more recent versions of the identified firmware and software are not exposed to these specific vulnerabilities.,"CVE-2020-7483, CVE-2020-7484, CVE-2020-7485, CVE-2020-7486, CVE-2020-7491",10.0,Critical,"CWE-319, CWE-912, CWE-284, CWE-400",Multiple Critical Sectors,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1378,7/14/2020,7/14/2020,2020,ICSA-20-196-01,Advantech iView,Advantech,iView,The following versions of iView - a device management application are affected: iView Versions 5.6 and prior.,"CVE-2020-14497, CVE-2020-14499, CVE-2020-14501, CVE-2020-14503, CVE-2020-14505, CVE-2020-14507",9.8,Critical,"CWE-284, CWE-20, CWE-22, CWE-77, CWE-89, CWE-306",Critical Manufacturing; Energy; Water and Wastewater,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1377,7/14/2020,7/14/2020,2020,ICSA-20-196-02,Moxa EDR-G902 and EDR-G903 Series Routers,Moxa,EDR-G902 and EDR-G903 Series Routers,The following Moxa Series routers are affected: EDR-G902 Series: firmware versions 5.4 and prior EDR-G903 Series: firmware versions 5.4 and prior.,CVE-2020-14511,9.8,Critical,CWE-121,Critical Manufacturing; Energy; Transportation Systems,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1376,7/14/2020,7/14/2020,2020,ICSA-20-196-03,"Siemens SICAM MMU, SICAM T, and SICAM SGU",Siemens,"SICAM MMU, SICAM T, and SICAM SGU",The following Siemens products are affected: SICAM MMU: All versions prior to 2.05 SICAM SGU: All versions SICAM T: All versions prior to 2.18.,"CVE-2020-10037, CVE-2020-10038, CVE-2020-10039, CVE-2020-10040, CVE-2020-10041, CVE-2020-10042, CVE-2020-10043, CVE-2020-10044, CVE-2020-10045",9.8,Critical,"CWE-294, CWE-120, CWE-79, CWE-80, CWE-306, CWE-311, CWE-125, CWE-916",Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1375,7/14/2020,7/14/2020,2020,ICSA-20-196-04,Siemens SIMATIC HMI Panels,Siemens,SIMATIC HMI Panels,The following Siemens products are affected: SIMATIC HMI Basic Panels 1st Generation (incl. SIPLUS variants): All versions SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants): All versions SIMATIC HMI Comfort Panels (incl. SIPLUS variants): All versions SIMATIC HMI KTP700F Mobile Arctic: All versions SIMATIC HMI Mobile Panels 2nd Generation: All versions SIMATIC WinCC Runtime Advanced: All versions.,CVE-2020-7592,5.7,Medium,CWE-319,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1374,7/14/2020,7/14/2020,2020,ICSA-20-196-06,Siemens SIMATIC S7-200 SMART CPU Family,Siemens,SIMATIC S7-200 SMART CPU Family,The following versions of SIMATIC are affected: SIMATIC S7-200 SMART CPU family: v2.2 and later; prior to v2.5.1.,CVE-2020-7584,7.5,High,CWE-400,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1373,7/14/2020,7/14/2020,2020,ICSA-20-196-08,Siemens LOGO! Web Server,Siemens,LOGO! Web Server,The following versions of LOGO! Web Server are affected: LOGO! 8 BM (incl. SIPLUS variants): Versions between 1.81.01 and 1.81.03 Version 1.82.01 Version 1.82.02.,CVE-2020-7593,9.8,Critical,CWE-120,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1372,6/18/2020,7/28/2020,2020,ICSMA-20-170-02,Baxter PrismaFlex and PrisMax (Update B),Baxter,Baxter PrismaFlex and PrisMax,The following models and versions of Baxter medical systems are affected: PrismaFlex all versions PrisMax all versions prior to 3.x.,"CVE-2020-12035, CVE-2020-12036, CVE-2020-12037",7.6,High,"CWE-319, CWE-287, CWE-259",Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1371,3/10/2020,7/14/2020,2020,ICSA-20-070-02,Siemens SIMATIC S7-300 CPUs and SINUMERIK Controller over Profinet (Update A),Siemens,SIMATIC S7-300 CPUs and SINUMERIK Controller over Profinet,The following versions of SIMATIC and SINUMERIK are affected: SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions prior to 3.X.17; SIMATIC TDC CP51M1: All versions prior to 1.1.8 SIMATIC TDC CPU555: All versions prior to 1.1.1 SINUMERIK 840D sl: All versions prior to 4.8.6 SINUMERIK 840D sl: All versions prior to 4.94.,CVE-2019-18336,7.5,High,CWE-400,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1370,11/14/2019,11/14/2019,2020,ICSA-19-318-02,Siemens S7-1200 and S7-200 SMART CPUs (Update B),Siemens,S7-1200 and S7-200 SMART CPUs,SIMATIC S7-1200 CPU family v4.x (including SIPLUS variants): all versions with Function State (FS) < 11; SIMATIC S7-1200 CPU family prior to v4.x (including SIPLUS variants): all versions. SIMATIC S7-200 SMART CPU ST20 (6ES7 288-1ST20-0AA0): all versions prior to and including v2.5.0 and Function State (FS) <= 9. SIMATIC S7-200 SMART CPU ST30 (6ES7 288-1ST30-0AA0): all versions prior to and including v2.5.0 and Function State (FS) <= 9. SIMATIC S7-200 SMART CPU ST40 (6ES7 288-1ST40-0AA0): all versions prior to and including v2.5.0 and Function State (FS) <= 8. SIMATIC S7-200 SMART CPU ST60 (6ES7 288-1ST60-0AA0): all versions prior to and including v2.5.0 and Function State (FS) <= 8. SIMATIC S7-200 SMART CPU SR20 (6ES7 288-1SR20-0AA0): all versions prior to and including v2.5.0 and Function State (FS) <= 11. SIMATIC S7-200 SMART CPU SR30 (6ES7 288-1SR30-0AA0): all versions prior to and including v2.5.0 and Function State (FS) <= 10. SIMATIC S7-200 SMART CPU SR40 (6ES7 288-1SR40-0AA0): all versions prior to and including v2.5.0 and Function State (FS) <= 10. SIMATIC S7-200 SMART CPU SR60 (6ES7 288-1SR60-0AA0): all versions prior to and including v2.5.0 and Function State (FS) <= 12. SIMATIC S7-200 SMART CPU CR40 (6ES7 288-1CR40-0AA0): all versions prior to and including v2.2.2 and Function State (FS) <= 8. SIMATIC S7-200 SMART CPU CR60 (6ES7 288-1CR60-0AA0): all versions prior to and including v2.2.2 and Function State (FS) <= 10. SIMATIC S7-200 SMART CPU CR20s (6ES7 288-1CR20-0AA0): all versions prior to and including v2.3.0 and Function State (FS) <= 3. SIMATIC S7-200 SMART CPU CR30s (6ES7 288-1CR30-0AA0): all versions prior to and including v2.3.0 and Function State (FS) <= 3. SIMATIC S7-200 SMART CPU CR40s (6ES7 288-1CR40-0AA0): all versions prior to and including v2.3.0 and Function State (FS) <= 3. SIMATIC S7-200 SMART CPU CR60s (6ES7 288-1CR60-0AA0): all versions prior to and including v2.3.0 and Function State (FS) <= 3.,CVE-2019-13945,6.8,Medium,CWE-749,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1369,8/15/2019,7/14/2020,2020,ICSA-19-227-03,Siemens SCALANCE Products (Update A),Siemens,SCALANCE Products,SCALANCE SC-600: v2.0 SCALANCE XB-200: v4.1 (only affected by CVE-2019-10927) SCALANCE XC-200: v4.1 (only affected by CVE-2019-10927) SCALANCE XF-200BA: v4.1 (only affected by CVE-2019-10927) SCALANCE XP-200: v4.1 (only affected by CVE-2019-10927) SCALANCE XR-300WG: v4.1 (only affected by CVE-2019-10927).,"CVE-2019-10927, CVE-2019-10928",6.6,Medium,CWE-710,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1368,7/9/2020,7/9/2020,2020,ICSA-20-191-01,Phoenix Contact Automation Worx Software Suite,PHOENIX CONTACT,Automation Worx Software Suite,The following components and versions of Automation Worx Software Suite are affected: PC Worx version 1.87 and prior PC Worx Express version 1.87 and prior.,"CVE-2020-12497, CVE-2020-12498",7.8,High,"CWE-125, CWE-121",Communications; Critical Manufacturing; Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1367,7/9/2020,7/9/2020,2020,ICSA-20-191-02,Rockwell Automation Logix Designer Studio 5000,Rockwell Automation,Logix Designer Studio 5000,The following versions of Logix Designer Studio 500 are affected: Logix Designer Studio 5000 Versions 32.00; 32.01; and 32.02.,CVE-2020-12025,3.6,Low,CWE-611,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1366,6/11/2020,7/14/2020,2020,ICSA-20-163-02,Rockwell Automation FactoryTalk Linx Software (Update A),Rockwell Automation,FactoryTalk Linx Software,The following products are affected: FactoryTalk Linx Versions 6.00; 6.10; and 6.11; RSLinx Classic v4.11.00 and prior (Versions removed from the scope of this advisory); The following products that utilize FactoryTalk Linx Software are affected: Connected Components Workbench: Version 12 and prior ControlFLASH: Version 14 and later ControlFLASH Plus: Version 1 and later FactoryTalk Asset Centre: Version 9 and later FactoryTalk Linx CommDTM: Version 1 and later Studio 5000 Launcher: Version 31 and later Studio 5000 Logix Designer software: Version 32 and prior.,"CVE-2020-11999, CVE-2020-12001, CVE-2020-12003, CVE-2020-12005",9.6,Critical,"CWE-20, CWE-22, CWE-434",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1365,7/7/2020,7/7/2020,2020,ICSA-20-189-01,Grundfos CIM 500,Grundfos Pumps Corporation,Grundfos CIM 500,The following versions of Grundfos CIM 500 are affected: All versions prior to v06.16.00.,"CVE-2020-10605, CVE-2020-10609",7.5,High,"CWE-306, CWE-256",Water,Worldwide,Denmark,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1364,7/7/2020,7/7/2020,2020,ICSA-20-189-02,Mitsubishi Electric GOT2000 Series,Mitsubishi Electric,GOT2000 Series,The following models of GOT2000 CoreOS Version -Y and earlier are affected: GT27 model GT25 model GT23 model.,"CVE-2020-5595, CVE-2020-5596, CVE-2020-5597, CVE-2020-5598, CVE-2020-5599, CVE-2020-5600",9.8,Critical,"CWE-284, CWE-88, CWE-119, CWE-476, CWE-399, CWE-384",Multiple Critical Sectors,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1363,6/23/2020,7/14/2020,2020,ICSA-20-175-01,"Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L and FX Series CPU Modules (Update A)",Mitsubishi Electric,"MELSEC iQ-R, iQ-F, Q, L and FX Series CPU Modules",Mitsubishi Electric reports the vulnerability affects the following MELSEC products: MELSEC iQ-R; iQ-F; Q; L and FX series CPU modules; all versions.,CVE-2020-5594,10.0,Critical,CWE-319,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1362,7/2/2020,7/2/2020,2020,ICSA-20-184-01,Nortek Linear eMerge 50P/5000P,Nortek,Linear eMerge 50P/5000P,The following versions of Linear eMerge products are affected: Linear eMerge 50P/5000P Versions 4.6.07 (revision 79330) and prior.,"CVE-2019-7266, CVE-2019-7267, CVE-2019-7268, CVE-2019-7269, CVE-2019-7270",10.0,Critical,"CWE-352, CWE-35, CWE-287, CWE-77, CWE-434",Commercial Facilities,Worldwide,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1361,7/2/2020,7/2/2020,2020,ICSA-20-184-02,ABB System 800xA Information Manager,ABB,System 800xA Information Manager,The following versions of System 800xA Information Manager are affected: Versions prior to 5.1 Rev E/5.1 FP4 Rev E TC6 Versions prior to 6.0.3.3 RU1 Versions prior to 6.1 RU1.,CVE-2020-8477,8.8,High,CWE-79,Chemical; Critical Manufacturing; Dams; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1360,6/18/2020,7/14/2020,2020,ICSA-20-170-01,Johnson Controls exacqVision (Update A),Exacq Technologies Inc (Subsidiary of Johnson Controls),exacqVision,Johnson Controls reports the vulnerability affects the following exacqVision products: exacqVision Web Service: All versions up to and including v20.06.3.0 exacqVision Enterprise Manager: All versions up to and including v20.06.4.0.,CVE-2020-9047,6.8,Medium,CWE-347,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1359,6/30/2020,6/30/2020,2020,ICSA-20-182-02,Mitsubishi Electric Factory Automation Engineering Software Products,Mitsubishi Electric,Factory Automation Engineering Software Products,The following versions of Factory Automation engineering software products are affected: CPU Module Logging Configuration Tool; Versions 1.94Y and prior CW Configurator; Versions 1.010L and prior EM Software Development Kit (EM Configurator); Versions 1.010L and prior GT Designer3 (GOT2000); Versions 1.221F and prior GX LogViewer; Versions 1.96A and prior GX Works2; Versions 1.586L and prior GX Works3; Versions 1.058L and prior M_CommDTM-HART; Version 1.00A M_CommDTM-IO-Link; Versions 1.02C and prior MELFA-Works; Versions 4.3 and prior MELSEC-L Flexible High-Speed I/O Control Module Configuration Tool; Versions 1.004E and prior MELSOFT FieldDeviceConfigurator; Versions 1.03D and prior MELSOFT iQ AppPortal; Versions 1.11M and prior MELSOFT Navigator; Versions 2.58L and prior MI Configurator; Versions 1.003D and prior Motion Control Setting; Versions 1.005F and prior MR Configurator2; Versions 1.72A and prior MT Works2; Versions 1.156N and prior RT ToolBox2; Versions 3.72A and prior RT ToolBox3; Versions 1.50C and prior.,"CVE-2020-5602, CVE-2020-5603",7.5,High,"CWE-611, CWE-400",Multiple Critical Sectors,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1358,5/26/2020,7/14/2020,2020,ICSA-20-147-01,Inductive Automation Ignition (Update B),Inductive Automation,Inductive Automation Ignition,The following versions of Inductive Automation Ignition are affected: Inductive Automation Ignition 7 Gateway versions prior to 7.9.14 Inductive Automation Ignition 8 Gateway versions prior to 8.0.10.,"CVE-2020-10644, CVE-2020-12000, CVE-2020-12004, CVE-2020-1447, CVE-2020-14479",9.8,Critical,"CWE-502, CWE-306",Critical Manufacturing; Energy; Information Technology,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1357,6/25/2020,6/25/2020,2020,ICSMA-20-177-01,Philips Ultrasound Systems,Philips,Ultrasound Systems,The following versions of Philips Ultrasound Systems are affected: Ultrasound ClearVue Versions 3.2 and prior Ultrasound CX Versions 5.0.2 and prior Ultrasound EPIQ/Affiniti Versions VM5.0 and prior Ultrasound Sparq Version 3.0.2 and prior and Ultrasound Xperius all versions.,CVE-2020-14477,3.6,Low,CWE-288,Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1356,6/25/2020,6/30/2020,2020,ICSA-20-177-02,Rockwell FactoryTalk Services Platform XXE,Rockwell Automation,Rockwell FactoryTalk Services Platform XXE,The following versions of FactoryTalk Services Platform are affected: Versions 6.11.00 and earlier.,CVE-2020-14478,8.4,High,CWE-611,Food and Agriculture; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1355,6/25/2020,6/25/2020,2020,ICSA-20-177-03,Rockwell FactoryTalk View SE,Rockwell Automation,Rockwell FactoryTalk View SE,The following versions of FactoryTalk View SE are affected: FactoryTalk View SE Versions 9.0 and earlier FactoryTalk View SE Version 10.0.,"CVE-2020-14480, CVE-2020-14481",8.8,High,"CWE-312, CWE-261",Chemical; Commercial Facilities; Critical Manufacturing; Energy; Government Facilities; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1354,6/23/2020,6/23/2020,2020,ICSA-20-175-02,Honeywell ControlEdge PLC and RTU,Honeywell,ControlEdge PLC and RTU,The following versions of ControlEdge PLC and RTU are affected: ControlEdge PLC R130.2; R140; R150; and R151 ControlEdge RTU R101; R110; R140; R150; and R151.,"CVE-2020-10624, CVE-2020-10628",5.9,Medium,CWE-319,Chemical; Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1353,6/23/2020,6/23/2020,2020,ICSA-20-175-03,ABB Device Library Wizard,ABB,Device Library Wizard,The following products of Device Library Wizard are affected: Device Library Wizard: Versions 6.0.X; 6.0.3.1; and 6.0.3.2.,CVE-2020-8482,7.8,High,CWE-922,Chemical; Critical Manufacturing; Dams; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1352,6/18/2020,7/28/2020,2020,ICSMA-20-170-01,Baxter ExactaMix (Update A),Baxter,ExactaMix,The following versions of Baxter ExactaMix Systems are affected: ExactaMix EM2400 Versions 1.10; 1.11; 1.13; 1.14; ExactaMix EM1200 Versions 1.1; 1.2; 1.4; 1.5.,"CVE-2020-12008, CVE-2020-12012, CVE-2020-12016, CVE-2020-12020, CVE-2020-12024, CVE-2020-12032, CVE-2017-0143",8.1,High,"CWE-319, CWE-668, CWE-284, CWE-20, CWE-311, CWE-259",Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1351,6/18/2020,7/28/2020,2020,ICSMA-20-170-03,Baxter Phoenix Hemodialysis Delivery System (Update A),Baxter,Phoenix Hemodialysis Delivery System,The following versions of the Phoenix Hemodialysis Delivery System are affected: Phoenix Hemodialysis Delivery System SW 3.36 and 3.40.,CVE-2020-12048,7.5,High,CWE-319,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1350,6/18/2020,8/11/2022,2020,ICSMA-20-170-04,Baxter Sigma Spectrum Infusion Pumps (Update B),Baxter,Sigma Spectrum Infusion Pumps,"The following versions of Sigma Spectrum Infusion systems, are affected: Sigma Spectrum v6.x model 35700BAX Baxter Spectrum v8.x model 35700BAX2 --------- Begin Update B Part 1 of 6 --------- Baxter Spectrum v9.x model 35700BAX3 Sigma Spectrum LVP v6.x with Wireless Battery Modules v9, v11, v13, v14, v15, v16, v16D38, v17, v17D19, v20D29 to v20D32, and v22D24 to v22D28 Baxter Spectrum LVP v8.x with Wireless Battery Modules v17, v17D19, v20D29 to v20D32, and v22D24 to v22D28 Baxter Spectrum LVP v9.x with Wireless Battery Module v22D19 to v22D28 --------- End Update B Part 1 of 6 --------- .","CVE-2020-12039, CVE-2020-12040, CVE-2020-12041, CVE-2020-12043, CVE-2020-12045, CVE-2020-12047",8.6,High,"CWE-319, CWE-732, CWE-672, CWE-259",Healthcare and Public Health,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1349,6/18/2020,3/15/2021,2020,ICSMA-20-170-06,BD Alaris PCU (Update A),"Becton, Dickinson and Company (BD)",Alaris PCU,The following versions of the BD Alaris PCU that has implemented the Linux Kernel v4.4.97 within the Laird Wireless Module WB40N are affected: Alaris PC Unit: Versions 9.13; 9.19; 9.33; and 12.1.,CVE-2019-11479,5.3,Medium,CWE-400,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1348,6/18/2020,6/18/2020,2020,ICSMA-20-170-05,BIOTRONIK CardioMessenger II,BIOTRONIK,CardioMessenger II,The following versions of the CardioMessenger II - a home monitoring unit are affected: CardioMessenger II-S T-Line T4APP 2.20 CardioMessenger II-S GSM T4APP 2.20.,"CVE-2019-18246, CVE-2019-18248, CVE-2019-18252, CVE-2019-18254, CVE-2019-18256",4.6,Medium,"CWE-319, CWE-287, CWE-311, CWE-257",Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1347,6/18/2020,6/18/2020,2020,ICSA-20-170-02,"Mitsubishi Electric MC Works64, MC Works32",Mitsubishi Electric,"MC Works64, MC Works32",The following products versions are affected: MC Works64 Version 4.02C (10.95.208.31) and earlier; all versions MC Works32 Version 3.00A (9.50.255.02).,"CVE-2020-12007, CVE-2020-12009, CVE-2020-12011, CVE-2020-12013, CVE-2020-12015",9.4,Critical,"CWE-502, CWE-94, CWE-787",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1346,6/18/2020,6/18/2020,2020,ICSA-20-170-03,"ICONICS GENESIS64, GENESIS32",ICONICS,"GENESIS64, GENESIS32",The following products using GenBroker64; Platform Services; Workbench; FrameWorX Server; v10.96 and prior are affected: GENESIS64 Hyper Historian AnalytiX MobileHMI The following products using GenBroker32 v9.5 and prior are affected: GENESIS32 BizViz.,"CVE-2020-12007, CVE-2020-12009, CVE-2020-12011, CVE-2020-12013, CVE-2020-12015",9.4,Critical,"CWE-502, CWE-94, CWE-787",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1345,6/18/2020,6/18/2020,2020,ICSA-20-170-04,Rockwell Automation FactoryTalk Services Platform,Rockwell Automation,FactoryTalk Services Platform,All versions of FactoryTalk Services Platform are affected.,CVE-2020-12033,7.5,High,CWE-20,Food and Agriculture; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1344,6/18/2020,6/18/2020,2020,ICSA-20-170-05,Rockwell Automation FactoryTalk View SE,Rockwell Automation,FactoryTalk View SE,All versions of FactoryTalk View SE are affected.,"CVE-2020-12027, CVE-2020-12028, CVE-2020-12029, CVE-2020-12031",9.0,Critical,"CWE-200, CWE-20, CWE-119, CWE-264",Chemical; Commercial Facilities; Critical Manufacturing; Energy; Government Facilities; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1343,6/11/2020,6/11/2020,2020,ICSMA-20-163-01,Philips IntelliBridge Enterprise IBE,Philips,IntelliBridge Enterprise IBE,The following versions of IntelliBridge Enterprise (IBE) - interface are affected: IntelliBridge Enterprise (IBE) Versions B.12 and prior The IntelliBridge Enterprise (IBE) provides HL7 interface interoperability between Philips products and a hospital's clinical information system or electronic medical records by providing a single integration point to the enterprise. The IBE software and connection licenses serve as the main messaging service that implements communications; mapping; message delivery; data transformation; and routing of data to and from the Philips products to external systems. IntelliBridge Enterprise has no clinical user interface; nor does it interpret; inspect; or provide additional analytical functionality for medical device data. Workflows affected: IntelliBridge Enterprise system integration with; SureSigns (VS4) EarlyVue (VS30) IntelliVue Guardian (IGS).,CVE-2020-12023,2.0,Low,CWE-532,Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1342,6/11/2020,6/11/2020,2020,ICSA-20-163-01,OSIsoft PI Web API 2019,OSIsoft,PI Web API 2019,The following versions of PI Web API are affected: PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions.,CVE-2020-12021,7.7,High,CWE-79,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Government Facilities; Healthcare and Public Health; Information Technology; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1341,6/9/2020,6/10/2020,2020,ICSA-20-161-01,Advantech WebAccess Node,Advantech,WebAccess Node,The following versions of WebAccess Node - HMI platform are affected: WebAccess Node Version 8.4.4 and prior.,CVE-2020-12019,9.8,Critical,CWE-121,Critical Manufacturing; Energy; Water and Wastewater,"East Asia, United States, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1340,6/9/2020,6/12/2020,2020,ICSA-20-161-06,Siemens SINUMERIK,Siemens,SINUMERIK,Siemens reports the vulnerabilities affect the following SINUMERIK products: SINUMERIK Access MyMachine/P2P: All versions prior to 4.8 SINUMERIK PCU base Win10 software/IPC: All versions prior to 14.00 SINUMERIK PCU base Win7 software/IPC: All versions prior to 12.01 HF4.,"CVE-2019-8258, CVE-2019-8259, CVE-2019-8260, CVE-2019-8261, CVE-2019-8262, CVE-2019-8263, CVE-2019-8264, CVE-2019-8265, CVE-2019-8266, CVE-2019-8267, CVE-2019-8268, CVE-2019-8269, CVE-2019-8270, CVE-2019-8271, CVE-2019-8272, CVE-2019-8273, CVE-2019-8274, CVE-2019-8275, CVE-2019-8276, CVE-2019-8277, CVE-2019-8280, CVE-2018-15361",9.8,Critical,"CWE-121, CWE-122, CWE-124, CWE-125, CWE-170, CWE-193, CWE-665, CWE-788",Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1339,5/12/2020,7/27/2020,2020,ICSA-20-133-02,OSIsoft PI System (Update A),OSIsoft,PI System,The following versions of PI System are affected: CVE-2020-10610; CVE-2020-10608; CVE-2020-10606: Applications using PI Asset Framework (AF) Client versions prior to and including PI AF Client 2018 SP3 Patch 1; Version 2.10.7.283 Applications using PI Software Development Kit (SDK) versions prior to and including PI SDK 2018 SP1; Version 1.4.7.602 PI API for Windows Integrated Security versions prior to and including 2.0.2.5; PI API versions prior to and including 1.6.8.26 PI Buffer Subsystem versions prior to and including 4.8.0.18 PI Connector for BACnet; versions prior to and including 1.2.0.6 PI Connector for CygNet; versions prior to and including 1.4.0.17 PI Connector for DC Systems RTscada; versions prior to and including 1.2.0.42 PI Connector for Ethernet/IP; versions prior to and including 1.1.0.10 PI Connector for HART-IP; versions prior to and including 1.3.0.1 PI Connector for Ping; versions prior to and including 1.0.0.54 PI Connector for Wonderware Historian; versions prior to and including 1.5.0.88 PI Connector Relay; versions prior to and including 2.5.19.0 PI Data Archive versions prior to and including PI Data Archive 2018 SP3; Version 3.4.430.460 PI Data Collection Manager; versions prior to and including 2.5.19.0 PI Integrator for Business Analytics versions prior to and including 2018 R2 SP1; Version 2.2.0.183 PI Interface Configuration Utility (ICU) versions prior to and including 1.5.0.7 PI to OCS versions prior to and including 1.1.36.0; PI Connector for IEC 60870-5-104; versions prior to and including 1.2.2.79 PI Connector for OPC-UA; versions prior to and including 1.3.0.130 PI Connector for Siemens Simatic PCS 7; versions prior to and including 1.2.1.71 PI Connector for UFL; versions prior to and including 1.3.1.135; CVE-2020-10604; CVE-2020-10602: PI Data Archive 2018 and 2018 SP2 only CVE-2020-10600: PI Data Archive 2018 SP2 and prior versions CVE-2019-10768: PI Vision 2019 and prior PI Manual Logger 2017 R2 Patch 1 and prior RtReports Version 4.1 and prior CVE-2020-10600; CVE-2020-10614; CVE-2019-18244: PI Vision 2019 and prior versions.,"CVE-2020-10600, CVE-2020-10602, CVE-2020-10604, CVE-2020-10606, CVE-2020-10608, CVE-2020-10610, CVE-2020-10614, CVE-2020-10643, CVE-2019-10768, CVE-2019-11358, CVE-2019-18244",7.8,High,"CWE-20, CWE-79, CWE-347, CWE-532, CWE-276, CWE-476, CWE-248, CWE-427",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1338,8/16/2018,6/9/2020,2020,ICSMA-18-228-01,"Philips PageWriter TC10, TC20, TC30, TC50, and TC70 Cardiographs (Update A)",Philips,"PageWriter TC10, TC20, TC30, TC50, and TC70 Cardiographs",The following versions of PageWriter TC10 | TC20 | TC30 | TC50 | TC70 Cardiographs are affected: All versions prior to May 2018.,"CVE-2018-14799, CVE-2018-14801",6.1,Medium,"CWE-20, CWE-798",Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1337,6/2/2020,6/2/2020,2020,ICSA-20-154-01,ABB System 800xA,ABB,System 800xA,The following products of System 800xA are affected: OPC Server for AC 800M: Versions 6.0 and prior Control Builder M Professional: Versions 6.1 and prior MMS Server for AC 800M: Versions 6.1 and prior Base Software for SoftControl: Versions 6.1 and prior ABB System 800xA Base: Versions 6.1 and prior.,"CVE-2020-8472, CVE-2020-8473",7.3,High,CWE-276,Chemical; Critical Manufacturing; Dams; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1336,6/2/2020,6/2/2020,2020,ICSA-20-154-02,ABB System 800xA Base,ABB,System 800xA Base,The following versions of System 800xA Base are affected: System 800xA Base: Versions 6.0 and prior.,CVE-2020-8474,7.8,High,CWE-732,Chemical; Critical Manufacturing; Dams; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1335,6/2/2020,6/2/2020,2020,ICSA-20-154-03,ABB Multiple System 800xA Products,ABB,Multiple System 800xA Products,The following products of System 800xA are affected: OPC Server for AC 800M: all versions MMS Server for AC 800M: all versions Base Software for SoftControl: all versions ABB System 800xA Base: all versions 800xA for DCI: all versions 800xA for MOD 300: all versions 800xA RNRP: all versions 800xA Batch Management: all versions 800xA Information Management: all versions.,"CVE-2020-8478, CVE-2020-8484, CVE-2020-8485, CVE-2020-8486, CVE-2020-8487, CVE-2020-8488, CVE-2020-8489",7.8,High,CWE-276,Chemical; Critical Manufacturing; Dams; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1334,6/2/2020,6/2/2020,2020,ICSA-20-154-04,ABB Central Licensing System,ABB,Central Licensing System,The following ABB CLS products and versions are affected: ABB Ability System 800xA and related system extensions: Versions 5.1; 6.0; 6.1 Compact HMI: Versions 5.1; 6.0 Control Builder Safe: Versions 1.0; 1.1; 2.0 ABB Ability Symphony Plus - S+ Operations: Versions 3.0 to 3.2 ABB Ability Symphony Plus - S+ Engineering: Versions 1.1 to 2.2 Composer Harmony: Versions 5.1; 6.0; 6.1 Composer Melody (incl. SPE for Melody 1.0 SPx): Versions 5.3; 6.1; 6.2; 6.3 Harmony OPC Server (HAOPC): Standalone Versions 6.0; 6.1; 7.0 ABB Ability System 800xA / Advant OCS Control Builder A: Versions 1.3; 1.4 Advant OCS AC 100 OPC Server: Versions 5.1; 6.0; 6.1 Composer CTK: Versions 6.1; 6.2 AdvaBuild: Versions 3.7 SP1; 3.7 SP2 OPC Server MOD 300 (non-800xA): Version 1.4 OPC Data Link: Versions 2.1; 2.2 ABB Ability Knowledge Manager: Versions 8.0; 9.0; 9.1 ABB Ability Manufacturing Operations Management: Versions 1812; 1909.,"CVE-2020-8471, CVE-2020-8475, CVE-2020-8476, CVE-2020-8479, CVE-2020-8481",9.8,Critical,"CWE-200, CWE-284, CWE-611, CWE-264, CWE-400",Chemical; Critical Manufacturing; Dams; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1333,6/2/2020,6/2/2020,2020,ICSA-20-154-05,GE Grid Solutions Reason RT Clocks,GE,Grid Solutions Reason RT Clocks,The following versions of Grid Solutions Reason RT Clocks - a source of temporal synchronization signals in different formats and protocols are affected: RT430; RT431; and RT434; all firmware versions prior to 08A05.,CVE-2020-12017,9.6,Critical,CWE-306,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1332,6/2/2020,6/2/2020,2020,ICSA-20-154-06,SWARCO CPU LS4000,SWARCO,SWARCO CPU LS4000,CERT VDE reports the vulnerability affects the following traffic light controller: CPU LS4000: All OS versions starting with G4.,"CVE-2020-1249, CVE-2020-12493",10.0,Critical,CWE-284,Transportation Systems,Europe,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1331,5/26/2020,5/26/2020,2020,ICSA-20-147-02,Johnson Controls Kantech EntraPass,Kantech (Subsidiary of Johnson Controls),EntraPass,Johnson Controls reports the vulnerability affects the following Kantech EntraPass software: Special Edition: All versions up to and including v8.22 Corporate Edition: All versions up to and including v8.22 Global Edition: All versions up to and including v8.22.,CVE-2020-9046,8.8,High,CWE-284,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1330,5/21/2020,5/21/2020,2020,ICSA-20-142-01,Johnson Controls Software House C-CURE 9000 and American Dynamics victor VMS,Sensormatic Electronics LLC (Subsidiary of Johnson Controls),Software House C-CURE 9000 and American Dynamics victor VMS,The following products are affected: Software House C¢CURE 9000: Version 2.70 American Dynamics victor Video Management System: Version 5.2.,CVE-2020-9045,9.9,Critical,CWE-312,Commercial Facilities; Critical Manufacturing; Financial Services; Government Facilitates; Healthcare and Public Health; Transportation Systems,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1329,5/21/2020,5/21/2020,2020,ICSA-20-142-02,Schneider Electric EcoStruxure Operator Terminal Expert,Schneider Electric,EcoStruxure Operator Terminal Expert,Schneider Electric reports these vulnerabilities affect the following EcoStruxure products: EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD).,"CVE-2020-7493, CVE-2020-7494, CVE-2020-7495, CVE-2020-7496, CVE-2020-7497",8.6,High,"CWE-22, CWE-88, CWE-89",Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1328,5/19/2020,5/20/2020,2020,ICSA-20-140-01,Rockwell Automation EDS Subsystem,Rockwell Automation,EDS Subsystem,The following products that utilize the EDS Subsystem (Version 28.0.1 and prior) are affected: FactoryTalk Linx software (Previously called RSLinx Enterprise): Versions 6.00; 6.10; and 6.11 RSLinx Classic: Version 4.11.00 and prior RSNetWorx software: Version 28.00.00 and prior Studio 5000 Logix Designer software: Version 32 and prior.,"CVE-2020-12034, CVE-2020-12038",8.2,High,"CWE-89, CWE-119",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1327,5/19/2020,5/20/2020,2020,ICSA-20-140-02,Emerson OpenEnterprise,Emerson,OpenEnterprise,Emerson reports that these vulnerabilities affect the following OpenEnterprise SCADA Software: OpenEnterprise: all versions through 3.3.4.,"CVE-2020-10632, CVE-2020-10636, CVE-2020-10640",10.0,Critical,"CWE-282, CWE-326, CWE-306",Energy; Chemical; Critical Manufacturing; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1326,5/14/2020,5/14/2020,2020,ICSA-20-135-01,Opto 22 SoftPAC Project,Opto 22,SoftPAC Project,The following versions of Opto 22 SoftPAC Project - a virtual PLC are affected: SoftPAC Project Version 9.6 and prior.,"CVE-2020-10612, CVE-2020-10616, CVE-2020-10620, CVE-2020-12042, CVE-2020-12046",9.8,Critical,"CWE-73, CWE-284, CWE-285, CWE-347, CWE-427",Commercial Facilities; Critical Manufacturing; Information Technology; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1325,5/14/2020,5/14/2020,2020,ICSA-20-135-02,Emerson WirelessHART Gateway,Emerson,WirelessHART Gateway,Emerson reports that the vulnerability affects the following products when the VLAN feature is enabled: Wireless 1410 Gateway; revisions 4.6.43 to 4.7.84 Wireless 1420 Gateway; revisions 4.6.43 to 4.7.84 Wireless 1552WU Gateway; revisions 4.6.43 to 4.7.84 Note that this is not an issue with the WirelessHART communication protocol. Wireless field devices; Smart Wireless Field Link; AMS Wireless SNAP-ON; and AMS Wireless Configurator are unaffected.,CVE-2020-12030,10.0,Critical,CWE-284,Chemical; Critical Manufacturing; Dams; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1324,8/1/2019,5/14/2020,2020,ICSA-19-213-04,3S-Smart Software Solutions GmbH CODESYS V3 (Update A),3S-Smart Software Solutions,CODESYS V3,CODESYS Control for BeagleBone CODESYS Control for emPC-A/iMX6 CODESYS Control for IOT2000 CODESYS Control for Linux CODESYS Control for PFC100 CODESYS Control for PFC200 CODESYS Control for Raspberry Pi CODESYS Control RTE V3 CODESYS Control RTE V3 (for Beckhoff CX) CODESYS Control Win V3 (also part of the CODESYS Development System setup) CODESYS V3 Simulation Runtime (part of the CODESYS Development System) CODESYS Control V3 Runtime System Toolkit CODESYS HMI V3.,CVE-2019-9013,8.8,High,CWE-522,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1323,5/12/2020,5/12/2020,2020,ICSA-20-133-01,Eaton Intelligent Power Manager,Eaton,Intelligent Power Manager,The following versions of Intelligent Power Manager - a software monitoring and management platform are affected: Intelligent Power Manager v1.67 and prior.,"CVE-2020-6651, CVE-2020-6652",8.8,High,"CWE-20, CWE-266",Energy,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1322,10/1/2019,9/24/2024,2019,ICSA-19-274-01,Interpeak IPnet TCP/IP Stack (Update E),"ENEA, Green Hills Software, ITRON, IP Infusion, Wind River","OSE by ENEA, INTEGRITY RTOS by Green Hills Software, ITRON, ZebOS by IP Infusion, and VxWorks by Wind River","The following products of Wind River, are affected: ENEA OSE: OSE4 ENEA OSE: OSE5 Green Hills Software INTEGRITY RTOS: All versions from 2003 to 2006 Wind River VxWorks under CURRENT support (6.9.4.11, Vx7 SR540, Vx7 SR610): All versions Wind River VxWorks: All versions after 6.5 Wind River VxWorks bootrom network stack: All versions Wind River VxWorks: 653 MCE 3.x Wind River Advanced Networking Technology (ANT): All versions Wind River IPnet TCP/IP Stack: All versions (Affected by CVE-2019-12255, CVE-2019-12262, and CVE-2019-12264).","CVE-2019-12255, CVE-2019-12256, CVE-2019-12257, CVE-2019-12258, CVE-2019-12259, CVE-2019-12260, CVE-2019-12261, CVE-2019-12262, CVE-2019-12263, CVE-2019-12264, CVE-2019-12265",9.8,Critical,"CWE-121, CWE-122, CWE-191, CWE-119, CWE-362, CWE-88, CWE-476",Critical Manufacturing; Information Technology; Healthcare and Public Health; Transportation Systems; Water and Wastewater Systems,Worldwide,Sweden,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1321,10/1/2019,9/24/2024,2019,ICSA-19-274-01,Interpeak IPnet TCP/IP Stack (Update E),"ENEA, Green Hills Software, ITRON, IP Infusion, Wind River","OSE by ENEA, INTEGRITY RTOS by Green Hills Software, ITRON, ZebOS by IP Infusion, and VxWorks by Wind River","The following products of Wind River, are affected: ENEA OSE: OSE4 ENEA OSE: OSE5 Green Hills Software INTEGRITY RTOS: All versions from 2003 to 2006 Wind River VxWorks under CURRENT support (6.9.4.11, Vx7 SR540, Vx7 SR610): All versions Wind River VxWorks: All versions after 6.5 Wind River VxWorks bootrom network stack: All versions Wind River VxWorks: 653 MCE 3.x Wind River Advanced Networking Technology (ANT): All versions Wind River IPnet TCP/IP Stack: All versions (Affected by CVE-2019-12255, CVE-2019-12262, and CVE-2019-12264).","CVE-2019-12255, CVE-2019-12256, CVE-2019-12257, CVE-2019-12258, CVE-2019-12259, CVE-2019-12260, CVE-2019-12261, CVE-2019-12262, CVE-2019-12263, CVE-2019-12264, CVE-2019-12265",9.8,Critical,"CWE-121, CWE-122, CWE-191, CWE-119, CWE-362, CWE-88, CWE-476",Critical Manufacturing; Information Technology; Healthcare and Public Health; Transportation Systems; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1320,9/12/2019,5/12/2020,2020,ICSA-19-255-02,3S-Smart Software Solutions GmbH CODESYS V3 Library Manager (Update A),3S-Smart Software Solutions,CODESYS V3 Library Manager,All 32 and 64 bit CODESYS Development System V3 versions prior to 3.5.16.0 are affected by this vulnerability.,CVE-2019-13538,8.6,High,CWE-79,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1319,8/15/2019,8/15/2019,2020,ICSA-19-227-04,Siemens SINAMICS (Update C),Siemens,SINAMICS,SINAMICS GH150 v4.7 (Control Unit): All versions SINAMICS GH150 v4.8 (Control Unit): All versions prior to v4.8 SP2 HF6 SINAMICS GL150 v4.7 (Control Unit): All versions SINAMICS GL150 v4.8 (Control Unit): All versions prior to v4.8 SP2 HF7 SINAMICS GM150 v4.7 (Control Unit): All versions SINAMICS GM150 v4.8 (Control Unit): All versions prior to v4.8 SP2 HF9 SINAMICS SL150 v4.7 (Control Unit): All versions prior to v4.7 HF33. SINAMICS SL150 v4.8 (Control Unit): All versions prior to v5.2 SP2. SINAMICS SM120 v4.7 (Control Unit): All versions prior to v4.8 SP2 HF10SINAMICS SM120 v4.8 (Control Unit): All versions prior to v4.8 SP2 HF10 SINAMICS SM150 v4.8 (Control Unit): All versions.,CVE-2019-6568,7.5,High,CWE-400,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1318,7/9/2019,7/9/2019,2020,ICSA-19-190-05,Siemens SIPROTEC 5 and DIGSI 5 (Update C),Siemens,SIPROTEC 5 and DIGSI 5,SIPROTEC 5 (All versions prior to v7.90) with CPU variants CP300 and CP100 and the respective Ethernet communication modules listed below: 6MD85 6MD86 6MD89 7UM85 7SA87 7SD87 7SL87 7VK87 7SA82 7SA86 7SD82 7SD86 7SL82 7SL86 7SJ86 7SK82 7SK85 7SJ82 7SJ85 7UT82 7UT85 7UT86 7UT87 7VE85 All types not listed above All versions. SIPROTEC 5: All versions prior to v8.01 7SS85 7KE85. SIPROTEC 5 with CPU variants CP200 and the respective Ethernet communication modules CVE-2019-10931: All versions prior to v7.59 CVE-2019-10930: All Versions DIGSI 5 All Versions prior to v7.90.,"CVE-2019-10930, CVE-2019-10931",7.5,High,CWE-20,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1317,5/7/2020,5/7/2020,2020,ICSA-20-128-01,Advantech WebAccess Node,Advantech,WebAccess Node,The following versions of WebAccess Node - HMI platform are affected: WebAccess Node Version 8.4.4 and prior WebAccess Node Version 9.0.0.,"CVE-2020-10638, CVE-2020-12002, CVE-2020-12006, CVE-2020-12010, CVE-2020-12014, CVE-2020-12018, CVE-2020-12022, CVE-2020-12026",9.8,Critical,"CWE-122, CWE-129, CWE-23, CWE-89, CWE-125, CWE-121",Critical Manufacturing; Energy; Water and Wastewater,"East Asia, United States, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1316,5/5/2020,5/5/2020,2020,ICSA-20-126-01,Fazecast jSerialComm,Fazecast,jSerialComm,The following versions of jSerialComm - a platform-independent serial communication for Java are affected: Version 2.2.2 and prior Schneider Electric reports the vulnerability affects the following EcoStruxure IT Gateway versions: Versions 1.5.x; 1.6.x; 1.7.x CISA will update this document as more mitigations are identified by affected vendors.,CVE-2020-10626,7.8,High,CWE-427,Critical Manufacturing; Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1315,5/5/2020,5/5/2020,2020,ICSA-20-126-02,SAE IT-systems FW-50 Remote Telemetry Unit (RTU),SAE IT-systems GmbH & Co KG,FW-50 Remote Telemetry Unit (RTU),The following version of FW-50 RTU - a modular telecontrol system are affected: FW-50 RTU; Series: 5 Series; CPU-type: CPU-5B; Hardware Revision: 2; CPLD Revision: 6.,"CVE-2020-10630, CVE-2020-10634",9.1,Critical,"CWE-22, CWE-79",Critical Manufacturing; Energy; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1314,4/28/2020,10/13/2020,2020,ICSA-20-119-01,LCDS LAquis SCADA,LCDS - Leao Consultoria e Desenvolvimento de Sistemas Ltda ME,LAquis SCADA,The following versions of LAquis SCADA are affected: LAquis SCADA Versions 4.3.1 and prior.,"CVE-2020-10618, CVE-2020-10622",6.5,Medium,CWE-200,Chemical; Commercial Facilities; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,South America,Brazil,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1313,5/2/2019,5/2/2019,2020,ICSA-19-122-03,Sierra Wireless AirLink ALEOS (Update B),Sierra Wireless,AirLink ALEOS,"AirLink ALEOS versions and products: LS300, GX400, GX440, and ES440: All versions prior to 4.4.9. GX450 and ES450: All versions prior to 4.9.4 MP70, MP70E, RV50, RV50X, LX40, and LX60: All versions prior to 4.12","CVE-2018-4061, CVE-2018-4062, CVE-2018-4063, CVE-2018-4065, CVE-2018-4066, CVE-2018-4067, CVE-2018-4069",9.1,Critical,"CWE-352, CWE-200, CWE-78, CWE-79, CWE-311, CWE-434, CWE-798",Commercial Facilities; Communications; Emergency Services; Energy; Government Facilities; Transportation Systems; Water and Wastewater,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1312,4/21/2020,4/21/2020,2020,ICSA-20-112-01,Inductive Automation Ignition,Inductive Automation,Ignition,The following versions of Ignition 8 Gateway are affected if running the Perspective Module: Ignition 8 Gateway versions prior to 8.0.10.,CVE-2020-10641,9.1,Critical,CWE-284,Critical Manufacturing; Energy; Information Technology,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1311,4/14/2020,4/14/2020,2020,ICSA-20-105-01,Eaton HMiSoft VU3,Eaton,HMiSoft VU3,The following versions of HMiSoft VU3 - a HMI Operator Interface are affected: HMiSoft VU3 Version 3.00.23 and prior; however; the HMIVU runtimes are not impacted by these issues.,"CVE-2020-10637, CVE-2020-10639",7.8,High,"CWE-125, CWE-121",Energy,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1310,4/14/2020,4/15/2020,2020,ICSA-20-105-02,Triangle MicroWorks DNP3 Outstation Libraries,Triangle MicroWorks,DNP3 Outstation Libraries,The following versions of DNP3 Outstation .NET Protocol components and DNP3 Outstation ANSI C source code libraries are affected: 3.16.00 through 3.25.01.,CVE-2020-6996,7.5,High,CWE-121,Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1309,4/14/2020,4/15/2020,2020,ICSA-20-105-03,Triangle MicroWorks SCADA Data Gateway,Triangle MicroWorks,SCADA Data Gateway,The following versions of SCADA Data Gateway software are affected: 2.41.0213 through 4.0.122.,"CVE-2020-10611, CVE-2020-10613, CVE-2020-10615",7.5,High,"CWE-843, CWE-125, CWE-121",Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1308,4/14/2020,4/14/2020,2020,ICSA-20-105-09,Siemens TIM 3V-IE and 4R-IE Family Devices,Siemens,TIM 3V-IE and 4R-IE Family Devices,The following versions of TIM communication modules for SIMATIC S7-300 and S7-400 devices are affected: TIM 3V-IE (incl. SIPLUS NET variants): all versions prior to v2.8 TIM 3V-IE Advanced (incl. SIPLUS NET variants): all versions prior to v2.8 TIM 3V-IE DNP3 (incl. SIPLUS NET variants): all versions prior to v3.3 TIM 4R-IE (incl. SIPLUS NET variants): all versions prior to v2.8 TIM 4R-IE DNP3 (incl. SIPLUS NET variants): all versions prior to v3.3.,CVE-2019-10939,9.0,Critical,CWE-489,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1307,2/11/2020,2/11/2020,2020,ICSA-20-042-05,Siemens SIMATIC S7 (Update B),Siemens,SIMATIC S7,The following versions of SIMATIC S7 devices are affected: SIMATIC S7-1200 CPU family (incl. SIPLUS variants) all versions prior to v4.1 SIMATIC S7-300 PN/DP CPU family (incl. related ET200 CPUs and SIPLUS variants) all versions prior to V3.x.17 SIMATIC S7-400 PN/DP v6 and below CPU family (incl. SIPLUS variants) all versions SIMATIC S7-400 PN/DP v7 CPU family (incl. SIPLUS variants) all versions; SIMATIC WinAC (F) 2010 all versions.,CVE-2019-13940,5.3,Medium,CWE-400,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1306,4/9/2020,4/29/2020,2020,ICSA-20-100-01,Rockwell Automation RSLinx Classic,Rockwell Automation,RSLinx Classic,The following versions of RSLinx Classic PLC communications software are affected: RSLinx Versions 4.11.00 and prior.,CVE-2020-10642,8.8,High,CWE-732,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1305,4/7/2020,4/7/2020,2020,ICSA-20-098-01,Advantech WebAccess/NMS,Advantech,WebAccess/NMS,The following versions of WebAccess/NMS - a network management system are affected: WebAccess/NMS versions prior to 3.0.2.,"CVE-2020-10603, CVE-2020-10617, CVE-2020-10619, CVE-2020-10621, CVE-2020-10623, CVE-2020-10625, CVE-2020-10629, CVE-2020-10631",9.8,Critical,"CWE-78, CWE-89, CWE-611, CWE-306, CWE-23, CWE-434",Critical Manufacturing; Energy; Water and Wastewater,"East Asia, United States, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1304,4/7/2020,4/7/2020,2020,ICSA-20-098-02,GE Digital CIMPLICITY,GE Digital,CIMPLICITY,GE Digital CIMPLICITY v10.0 and prior are affected by this vulnerability.,CVE-2020-6992,6.0,Medium,CWE-269,Chemical; Critical Manufacturing; Energy; Food and Agriculture Water,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1303,4/7/2020,4/7/2020,2020,ICSA-20-098-03,HMS Networks eWON Flexy and Cosy,HMS Industrial Networks,eWON Flexy and Cosy,The following eWON products are affected: eWON Flexy: All firmware versions prior to 14.1s0 eWON Cosy: All firmware versions prior to 14.1s0.,CVE-2020-10633,6.1,Medium,CWE-79,Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,Worldwide,Sweden,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1302,4/7/2020,4/7/2020,2020,ICSA-20-098-04,Fuji Electric V-Server Lite,Fuji Electric,V-Server Lite,The following versions of V-Server Lite - a data collection and management service are affected: V-Server Lite; all versions prior to 4.0.9.0.,CVE-2020-10646,7.8,High,CWE-122,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1301,4/7/2020,4/7/2020,2020,ICSA-20-098-05,KUKA.Sim Pro,KUKA,Sim Pro,KUKA.Sim Pro Version 3.1 simulation and machine-programming software is affected by this vulnerability.,CVE-2020-10635,4.3,Medium,CWE-924,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1300,2/11/2020,4/7/2020,2020,ICSA-20-042-01,Synergy Systems & Solutions HUSKY RTU (Update A),Synergy Systems & Solutions (SSS),HUSKY RTU,The following versions of HUSKY RTU - a remote terminal unit are affected: HUSKY RTU 6049-E70; with firmware Versions 5.0 and prior.,"CVE-2020-7800, CVE-2020-7801, CVE-2020-7802, CVE-2019-16879, CVE-2019-20045, CVE-2019-20046",9.8,Critical,"CWE-200, CWE-287, CWE-754, CWE-20, CWE-276, CWE-306",Energy; Transportation Systems,Asia,India,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1299,4/2/2020,4/3/2020,2020,ICSA-20-093-01,B&R Automation Studio,B&R Industrial Automation GmbH,Studio,B&R Automation reports the vulnerabilities affect the following versions of Automation Studio: Automation Studio; Versions 4.0.x Automation Studio; Versions 4.1.x Automation Studio; Versions 4.2.x Automation Studio; versions prior to 4.3.11SP Automation Studio; versions prior to 4.4.9SP Automation Studio; versions prior to 4.5.4SP Automation Studio; versions prior to 4.6.3SP Automation Studio; versions prior to 4.7.2 Automation Studio; versions prior to 4.8.1.,"CVE-2019-19100, CVE-2019-19101, CVE-2019-19102",7.5,High,"CWE-22, CWE-269, CWE-325",Chemical; Critical Manufacturing; Energy,Worldwide,Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1298,3/31/2020,3/31/2020,2020,ICSMA-20-091-01,BD Pyxis MedStation and Pyxis Anesthesia (PAS) ES System,"Becton, Dickinson and Company (BD)",Pyxis MedStation and Pyxis Anesthesia (PAS) ES System,The following versions of Pyxis MedStation and Anesthesia (PAS) ES Systems are affected: Pyxis MedStation ES System; v1.6.1 Pyxis Anesthesia (PAS) ES System; v1.6.1.,CVE-2020-10598,6.8,Medium,CWE-693,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1297,3/31/2020,3/31/2020,2020,ICSA-20-091-01,Hirschmann Automation and Control HiOS and HiSecOS Products,Hirschmann Automation and Control GmbH (Division of Belden Inc),HiOS and HiSecOS Products,The following devices using HiOS Version 07.0.02 and lower are affected: RSP; RSPE; RSPS; RSPL; MSP; EES; EES; EESX; GRS; OS; RED The following devices using HiSecOS Version 03.2.00 and lower are affected: EAGLE20/30.,CVE-2020-6994,9.8,Critical,CWE-120,Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1296,3/31/2020,3/31/2020,2020,ICSA-20-091-02,Mitsubishi Electric MELSEC,Mitsubishi Electric,MELSEC,The following versions of MELSEC programmable controllers with MELSOFT transmission port (UDP/IP) are affected: MELSEC; iQ-R; iQ-F; Q; L; and F series; all versions.,CVE-2020-5527,5.3,Medium,CWE-400,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1295,1/16/2020,4/3/2020,2020,ICSA-20-016-01,Schneider Electric Modicon Controllers (Update A),Schneider Electric,Modicon Controllers,The following versions of Modicon controllers - a PLC are affected: For CVE-2019-6857; the following Modicon controllers are affected: Modicon M580; all versions prior to v2.80 Modicon M340; all versions prior to v3.01 Modicon Premium; all versions prior to v3.20 Modicon Quantum; all versions prior to v3.60 For CVE-2019-6856 and CVE-2018-7794; the following Modicon controllers are affected: Modicon M580; all versions prior to v2.80 Modicon M340; all versions prior to v3.01 Modicon Premium; all versions prior to v3.20 Modicon Quantum; all versions prior to v3.52.,"CVE-2019-6856, CVE-2019-6857, CVE-2018-7794",7.5,High,CWE-754,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1294,3/26/2020,3/26/2020,2020,ICSA-20-086-01,Advantech WebAccess,Advantech,WebAccess,The following versions of WebAccess - HMI platform are affected: WebAccess Versions 8.4.2 and prior.,CVE-2020-10607,8.8,High,CWE-121,Critical Manufacturing; Energy; Water and Wastewater,"East Asia, United States, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1293,3/24/2020,4/3/2020,2020,ICSA-20-084-02,Schneider Electric IGSS SCADA Software,Schneider Electric,IGSS SCADA Software,The following versions of IGSS are affected: Versions 14 and prior using the service IGSSupdate.,"CVE-2020-7478, CVE-2020-7479",7.8,High,"CWE-22, CWE-306",Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1292,3/19/2020,11/30/2021,2020,ICSMA-20-079-01,Insulet Omnipod,Insulet,Omnipod Insulin Management System,The following versions of the Omnipod Insulin Management System are affected: Product ID/Reorder number: 19191 and 40160 UDI/Model/NDC number: ZXP425 (10-Pack) and ZXR425 (10-Pack Canada).,CVE-2020-10627,7.3,High,CWE-284,Healthcare and Public Health,"United States, Canada, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1291,3/19/2020,3/19/2020,2020,ICSA-20-079-01,Systech NDS-5000 Terminal Server,Systech Corporation,NDS-5000 Terminal Server,The following versions of NDS-5000 Terminal Server - a network server are affected: NDS-5000 Terminal Server; NDS/5008 (8 Port; RJ45); firmware Version 02D.30.,CVE-2020-7006,6.8,Medium,CWE-79,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1290,3/17/2020,3/17/2020,2020,ICSA-20-077-01,Delta Electronics Industrial Automation CNCSoft ScreenEditor,Delta Electronics,CNCSoft ScreenEditor,The following versions of CNCSoft ScreenEditor - a user interface are affected: CNCSoft ScreenEditor v1.00.96 and prior.,"CVE-2020-6976, CVE-2020-7002",7.8,High,"CWE-125, CWE-121",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1289,3/12/2020,3/31/2020,2020,ICSA-20-072-01,ABB eSOMS,ABB,eSOMS,The following versions of eSOMS are affected: eSOMS 6.02 and prior.,"CVE-2019-19000, CVE-2019-19001, CVE-2019-19002, CVE-2019-19003, CVE-2019-19089, CVE-2019-19090, CVE-2019-19091, CVE-2019-19092, CVE-2019-19093, CVE-2019-19094, CVE-2019-19095, CVE-2019-19096, CVE-2019-19097",7.6,High,"CWE-525, CWE-1021, CWE-644, CWE-1004, CWE-693, CWE-614, CWE-200, CWE-642, CWE-521, CWE-89, CWE-79, CWE-312, CWE-326",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1288,3/12/2020,3/12/2020,2020,ICSA-20-072-02,ABB Asset Suite,ABB,Asset Suite,The following versions of Asset Suite are affected: Asset Suite Versions 9.6 and prior; excluding 9.4.2.6 and 9.5.3.2.,CVE-2019-18998,7.1,High,CWE-639,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1287,3/12/2020,3/12/2020,2020,ICSA-20-072-03,Rockwell Automation Allen-Bradley Stratix 5950,Rockwell Automation,Allen-Bradley Stratix 5950,The following versions of the Allen-Bradley Stratix 5950 Security Appliance are affected: 1783-SAD4T0SBK9 1783-SAD4T0SPK9 1783-SAD2T2SBK9 1783-SAD2T2SPK9.,CVE-2019-1649,6.7,Medium,CWE-284,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1286,3/10/2020,3/10/2020,2020,ICSA-20-070-03,Siemens Spectrum Power 5,Siemens,Spectrum Power 5,The following versions of Spectrum Power 5 grid control system are affected: Spectrum Power 5: All version prior to 5.50 HF02.,CVE-2020-7579,6.1,Medium,CWE-80,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1285,3/10/2020,3/11/2020,2020,ICSA-20-070-04,Johnson Controls Kantech EntraPass,Kantech (Subsidiary of Johnson Controls),EntraPass,The following versions of Kantech EntraPass security management software are affected: Corporate Edition: All versions prior to v8.10 Global Edition: All versions prior to v8.10.,CVE-2019-7589,9.8,Critical,CWE-20,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1284,3/10/2020,3/10/2020,2020,ICSA-20-070-05,Johnson Controls Metasys,Johnson Controls Inc.,Metasys,The following versions of Metasys are affected by this vulnerability: Application and Data Server (ADS; ADS-Lite): Release 10.1 and prior Extended Application and Data Server (ADX): Release 10.1 and prior Open Data Server (ODS): Release 10.1 and prior Open Application Server (OAS): Release 10.1 Network Automation Engine (NAE55 only): Releases 9.0.1; 9.0.2; 9.0.3; 9.0.5; 9.0.6 Network Integration Engine (NIE55/NIE59): Releases 9.0.1; 9.0.2; 9.0.3; 9.0.5; 9.0.6 NAE85 and NIE85: Release 10.1 and prior LonWorks Control Server (LCS): Release 10.1 and prior System Configuration Tool (SCT): Release 13.2 and prior Smoke Control Network Automation Engine (NAE55; UL 864 UUKL/ORD-C100-13 UUKLC 10th Edition Listed) Release 8.1.,CVE-2020-9044,7.5,High,CWE-611,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1283,3/10/2020,3/10/2020,2020,ICSA-20-070-06,Rockwell Automation MicroLogix Controllers and RSLogix 500 Software,Rockwell Automation,MicroLogix Controllers and RSLogix 500 Software,The following versions of Rockwell Automation products are affected: MicroLogix 1400 Controllers Series B v21.001 and prior Series A; all versions MicroLogix 1100 Controller; all versions RSLogix 500 Software v12.001 and prior.,"CVE-2020-6980, CVE-2020-6984, CVE-2020-6988, CVE-2020-6990",9.8,Critical,"CWE-312, CWE-327, CWE-603, CWE-321",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1282,2/11/2020,3/10/2020,2020,ICSA-20-042-11,Siemens SIMATIC S7-1500 (Update A),Siemens,SIMATIC S7-1500,The following versions of SIMATIC are affected: SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions; SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions v2.5 or higher and lower than v20.8; SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions v2.5 or higher and lower than v2.8 SIMATIC S7-1500 Software Controller: All versions v2.5 or higher and lower than v20.8.,CVE-2019-19281,7.5,High,CWE-400,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1281,12/17/2019,3/10/2020,2020,ICSA-19-351-02,Siemens SPPA-T3000 (Update A),Siemens,SPPA-T3000,Siemens SPPA-T3000 products: Application Server: all versions prior to Service Pack R8.2 SP2. MS3000 Migration Server: All Versions.,"CVE-2018-4832, CVE-2019-18283, CVE-2019-18284, CVE-2019-18285, CVE-2019-18286, CVE-2019-18287, CVE-2019-18288, CVE-2019-18289, CVE-2019-18290, CVE-2019-18291, CVE-2019-18292, CVE-2019-18293, CVE-2019-18294, CVE-2019-18295, CVE-2019-18296, CVE-2019-18297, CVE-2019-18298, CVE-2019-18299, CVE-2019-18300, CVE-2019-18301, CVE-2019-18302, CVE-2019-18303, CVE-2019-18304, CVE-2019-18305, CVE-2019-18306, CVE-2019-18307, CVE-2019-18308, CVE-2019-18309, CVE-2019-18310, CVE-2019-18311, CVE-2019-18312, CVE-2019-18313, CVE-2019-18314, CVE-2019-18315, CVE-2019-18316, CVE-2019-18317, CVE-2019-18318, CVE-2019-18319, CVE-2019-18320, CVE-2019-18321, CVE-2019-18322, CVE-2019-18323, CVE-2019-18324, CVE-2019-18325, CVE-2019-18326, CVE-2019-18327, CVE-2019-18328, CVE-2019-18329, CVE-2019-18330, CVE-2019-18331, CVE-2019-18332, CVE-2019-18333, CVE-2019-18334, CVE-2019-18335",9.8,Critical,"CWE-20, CWE-502, CWE-287, CWE-319, CWE-434, CWE-122, CWE-190, CWE-125, CWE-284, CWE-121, CWE-952, CWE-502, CWE-200",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1280,12/10/2019,4/14/2022,2020,ICSA-19-344-04,Siemens SIMATIC Products (Update C),Siemens,SIMATIC CP 1626; HMI Panel (incl. SIPLUS variants); NET PC software; STEP 7 (TIA Portal); WinCC (TIA Portal); WinCC OA; WinCC Runtime (Pro and Advanced); TIM 1531 IRC (incl. SIPLUS variant),"The following Siemens products are affected: Update C SIMATIC CP 1626: all versions SIMATIC NET PC Software v14: all versions prior to v14 SP1 Update 14 SIMATIC NET PC Software v15: all versions End Update C. SIMATIC HMI Panel (incl. SIPLUS variants): all versions SIMATIC STEP 7 (TIA Portal): all versions prior to v16 SIMATIC WinCC (TIA Portal): all versions prior to v16 SIMATIC WinCC OA: all versions prior to, and including, v3.15 SIMATIC WinCC OA: all versions prior to, and including, v3.16 patch 12 SIMATIC WinCC Runtime Advanced: all versions SIMATIC WinCC Runtime Professional: all versions TIM 1531 IRC (incl. SIPLUS NET variants): all versions prior to v2.1.",CVE-2019-10929,3.7,Low,CWE-327,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1279,12/10/2019,8/11/2022,2020,ICSA-19-344-06,Siemens SIMATIC S7-1200 and S7-1500 CPU Families (Update B),Siemens,SIMATIC S7-1200 and S7-1500 CPU families,Siemens reports that these vulnerabilities affect the following SIMATIC products: SIMATIC ET200SP (incl. SIPLUS variants) Open Controller CPU 1515SP PC: All versions --------- Begin Update B Part 1 of 2 --------- SIMATIC Drive Controller family: All versions (only affected by CVE-2019-10943) SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions prior to V20.8 SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): Versions 20.8 and later (only affected by CVE-2019-10943) SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants): All versions SIMATIC S7-1200 CPU family (incl. SIPLUS variants): All versions prior to V4.4.0 SIMATIC S7-1200 CPU family (incl. SIPLUS variants): Versions 4.4.0 and later (only affected by CVE-2019-10943) SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants): All versions prior to V2.8.1 SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants): Versions 2.8.1 and later (only affected by CVE-2019-10943) SIMATIC S7-1500 Software Controller: All versions prior to V20.8 SIMATIC S7-1500 Software Controller Versions 20.8 and later (only affected by CVE-2019-10943) SIMATIC S7-PLCSIM Advanced: All versions prior to V3.0 SIMATIC S7-PLCSIM Advanced: Versions 3.0 and later (only affected by CVE-2019-10943) --------- End Update B Part 1 of 2 ---------.,"CVE-2019-10929, CVE-2019-10943",5.3,Medium,"CWE-353, CWE-327",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1278,4/9/2019,8/11/2022,2019,ICSA-19-099-03,Siemens Industrial Products with OPC UA (Update H),Siemens,"SIMATIC, SINEC-NMS, SINEMA, SINEMURIK Industrial Control Products with OPC UA","The following Siemens industrial products are affected: SIMATIC CP443-1 OPC UA (including SIPLUS NET variants): all versions SIMATIC ET 200 Open Controller CPU 1515SP PC2 (including SIPLUS variants): all versions prior to v2.7 SIMATIC HMI Comfort Outdoor Panels 7"" & 15"" (including SIPLUS variants): all versions prior to v15.1 Upd 4 SIMATIC HMI Comfort Panels 4"" 22"" (including SIPLUS variants): all versions prior to v15.1 Upd 4 SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900, KTP900F (including SIPLUS variants): all versions prior to v15.1 Upd 4 SIMATIC IPC DiagMonitor: all versions prior to v5.1.3 SIMATIC NET PC Software v13: all versions SIMATIC NET PC Software v14: all versions prior to v14 SP1 Update 14 SIMATIC NET PC Software v15: all versions SIMATIC RF188C: all versions prior to v1.1.0 SIMATIC RF600R: all versions prior to v3.2.1 SIMATIC S7-1500 CPU Family (including related ET200 CPUs and SIPLUS variants): all versions, v2.5 and newer, and prior to v2.6.1 SIMATIC S7-1500 Software Controller: all versions between v2.5 (including) and v2.7 (excluding) SIMATIC WinCC OA: all versions prior to v3.15-P018 SIMATIC WinCC Runtime Advanced: all versions prior to v15.1 Upd 4 SINEC-NMS: all versions prior to v1.0 SP1 SINEMA Server: all versions prior to v14 SP2 SINUMERIK OPC UA Server: all versions prior to v2.1 --------- Begin Update H Part 1 of 2 --------- TeleControl Server Basic: all versions prior to v3.1.1 --------- End Update H Part 1 of 2 ---------.",CVE-2019-6575,7.5,High,CWE-248,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1277,12/13/2016,12/13/2016,2020,ICSA-16-348-05,Siemens S7-300/400 PLC Vulnerabilities (Update E),Siemens,S7-300/400 PLC,SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) all versions SIMATIC S7-400 PN/DP V6 and below CPU family (incl. SIPLUS variants) all versions SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants) all versions SIMATIC S7-410 V8 CPU family (incl. SIPLUS variants) all versions (only affected by CVE-2016-9159).,"CVE-2016-9159, CVE-2016-9158",7.5,High,CWE-200,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1276,3/5/2020,3/5/2020,2020,ICSA-20-065-01,WAGO I/O-CHECK,WAGO,I/O-CHECK,The following versions of I/O-CHECK software are affected by the listed vulnerabilities: Series PFC100 (750-81xx/xxx-xxx) Series PFC200 (750-82xx/xxx-xxx) 750-852; 750-831/xxx-xxx; 750-881; 750-880/xxx-xxx; 750-889 750-823; 750-832/xxx-xxx; 750-862; 750-890/xxx-xxx; 750-891.,"CVE-2019-5073, CVE-2019-5074, CVE-2019-5075, CVE-2019-5077, CVE-2019-5078, CVE-2019-5079, CVE-2019-5080, CVE-2019-5081, CVE-2019-5082",10.0,Critical,"CWE-805, CWE-120, CWE-201, CWE-306",Commercial Facilities; Energy; Critical Manufacturing; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1275,3/3/2020,3/3/2020,2020,ICSA-20-063-01,Emerson ValveLink,Emerson,ValveLink,The following versions of ValveLink digital valve controller software are affected: ValveLink; v12.0.264 to v13.4.118.,CVE-2020-6971,7.8,High,CWE-284,Chemical; Critical Manufacturing; Dams; Energy; Food and Agriculture; Healthcare and Public Health; Nuclear Reactors Materials and Waste; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1274,3/3/2020,3/3/2020,2020,ICSA-20-063-02,PHOENIX CONTACT Emalytics Controller ILC,PHOENIX CONTACT,Emalytics Controller ILC,The following versions of Emalytics Controller are affected: ILC 2050 BI (Article number 2403160): all versions prior to 1.2.3 ILC 2050 BI-L (Article number 2404671): all versions prior to 1.2.3.,CVE-2020-8768,9.4,Critical,CWE-732,Commercial Facilities; Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1273,3/3/2020,3/3/2020,2020,ICSA-20-063-03,Omron PLC CJ Series,Omron,PLC CJ Series,The following versions of Omron programmable logic controllers are affected: Omron PLC CJ series; all versions.,CVE-2020-6986,7.5,High,CWE-400,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1272,3/3/2020,3/3/2020,2020,ICSA-20-063-04,Moxa AWK-3131A Series Industrial AP/Bridge/Client,Moxa,AWK-3131A Series Industrial AP/Bridge/Client,Moxa reports that the vulnerabilities affect the following versions of AWK-3131A - a wireless networking appliance: Moxa AWK-3131A firmware; Version 1.13 and prior.,"CVE-2019-5136, CVE-2019-5137, CVE-2019-5138, CVE-2019-5139, CVE-2019-5140, CVE-2019-5141, CVE-2019-5142, CVE-2019-5143, CVE-2019-5148, CVE-2019-5153, CVE-2019-5162, CVE-2019-5165",9.9,Critical,"CWE-288, CWE-120, CWE-78, CWE-284, CWE-125, CWE-121, CWE-798, CWE-321",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1271,2/25/2020,2/25/2020,2020,ICSA-20-056-01,Moxa MB3xxx Series Protocol Gateways,Moxa,MB3xxx Series Protocol Gateways,Moxa reports these vulnerabilities affects the following protocol gateways: MB3170 series firmware; Version 4.0 or lower MB3270 series firmware; Version 4.0 or lower MB3180 series firmware; Version 2.0 or lower MB3280 series firmware; Version 3.0 or lower MB3480 series firmware; Version 3.0 or lower MB3660 series firmware; Version 2.2 or lower.,"CVE-2019-9095, CVE-2019-9096, CVE-2019-9097, CVE-2019-9098, CVE-2019-9099, CVE-2019-9101, CVE-2019-9102, CVE-2019-9103, CVE-2019-9104",9.8,Critical,"CWE-121, CWE-680, CWE-352, CWE-327, CWE-200, CWE-319, CWE-521, CWE-312, CWE-941",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1270,2/25/2020,2/25/2020,2020,ICSA-20-056-02,"Moxa ioLogik 2542-HSPA Series Controllers and IOs, and IOxpress Configuration Utility",Moxa,"ioLogik 2542-HSPA Series Controllers and IOs, and IOxpress Configuration Utility",Moxa reports these vulnerabilities affects the following products: ioLogik 2500 series firmware; Version 3.0 or lower IOxpress configuration utility; Version 2.3.0 or lower.,"CVE-2020-7003, CVE-2019-18238, CVE-2019-18242",7.5,High,"CWE-312, CWE-319, CWE-941",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1269,2/25/2020,2/25/2020,2020,ICSA-20-056-03,Moxa PT-7528 and PT-7828 Series Ethernet Switches,Moxa,PT-7528 and PT-7828 Series Ethernet Switches,Moxa reports these vulnerabilities affect the following Ethernet switches: PT-7528 series firmware; Version 4.0 or lower PT-7828 series firmware; Version 3.9 or lower.,"CVE-2020-6983, CVE-2020-6985, CVE-2020-6987, CVE-2020-6989, CVE-2020-6993, CVE-2020-6995",10.0,Critical,"CWE-200, CWE-121, CWE-327, CWE-798, CWE-321, CWE-521",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1268,2/25/2020,3/26/2020,2020,ICSA-20-056-04,Moxa EDS-G516E and EDS-510E Series Ethernet Switches,Moxa,EDS-G516E and EDS-510E Series Ethernet Switches,Moxa reports the vulnerabilities affect the following Ethernet switches: EDS-G516E Series firmware; Version 5.2 or lower EDS-510E Series firmware; Version 5.2 or lower.,"CVE-2020-6979, CVE-2020-6981, CVE-2020-6991, CVE-2020-6997, CVE-2020-6999, CVE-2020-7001, CVE-2020-7007",9.8,Critical,"CWE-120, CWE-319, CWE-121, CWE-327, CWE-798, CWE-321, CWE-521",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1267,2/25/2020,2/25/2020,2020,ICSA-20-056-05,Honeywell WIN-PAK,Honeywell,WIN-PAK,The following versions of WIN-PAK - a monitoring platform are affected: WIN-PAK 4.7.2; Web and prior versions.,"CVE-2020-6978, CVE-2020-6982, CVE-2020-7005",8.1,High,"CWE-352, CWE-644, CWE-477",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1266,2/20/2020,2/27/2020,2020,ICSA-20-051-01,B&R Automation Studio and Automation Runtime,B&R Industrial Automation GmbH,Studio and Automation Runtime,The following versions of B&R products are affected: Automation Studio Versions 2.7; 3.0.71; 3.0.80; 3.0.81; 3.0.90; 4.0.x to 4.6.4; and 4.7.2 Automation Runtime Versions 2.96; 3.00; 3.01; 3.06; 3.07; 3.08 to 3.10; 4.00 to 4.03; 4.04 to 4.03; 4.04 to 4.63; 4.72 and above.,CVE-2019-19108,9.4,Critical,CWE-285,Chemical; Critical Manufacturing; Energy,Worldwide,Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1265,2/20/2020,5/18/2023,2020,ICSA-20-051-02,Rockwell Automation FactoryTalk Diagnostics Update B,Rockwell Automation,FactoryTalk Diagnostics,"--------- Begin Update A part 1 of 2 --------- The following versions of FactoryTalk Diagnostic software, a subsystem of the FactoryTalk Service Platform, are affected: FactoryTalk Diagnostics software: Versions 2.00 to 6.11 --------- End Update A part 1 of 2 --------- All versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, are affected.",CVE-2020-6967,9.8,Critical,CWE-502,Food and Agriculture; Transportation Systems; Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1264,2/20/2020,2/20/2020,2020,ICSA-20-051-03,Honeywell NOTI-FIRE-NET Web Server (NWS-3),Honeywell,NOTI-FIRE-NET Web Server (NWS-3),The following versions of Notifier Web Server (NWS) are affected: Version 3.50 and earlier.,"CVE-2020-6972, CVE-2020-6974",9.4,Critical,"CWE-294, CWE-22",Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1263,2/20/2020,2/20/2020,2020,ICSA-20-051-04,"Auto-Maskin RP210E, DCU210E, and Marine Observer Pro (Android App)",Auto-Maskin,"RP210E, DCU210E, and Marine Observer Pro (Android App)",The following versions of RP210E and DCU 210 - a remote panel and digital control unit are affected: RP210E Versions 3.7 and prior DCU210E Versions 3.7 and prior.,"CVE-2019-6558, CVE-2019-6560, CVE-2018-5399, CVE-2018-5400, CVE-2018-5401, CVE-2018-5402",9.8,Critical,"CWE-319, CWE-346, CWE-798, CWE-640, CWE-521",Transportation Systems,Worldwide,Norway,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1262,2/18/2020,2/18/2020,2020,ICSMA-20-049-01,Spacelabs Xhibit Telemetry Receiver (XTR),Spacelabs,Xhibit Telemetry Receiver (XTR),The following versions and operating systems of Spacelabs Xhibit Telemetry Receiver are affected: Xhibit Telemetry Receiver (XTR); Model number 96280; v1.0.2 Arkon (99999); all versions - previously sold by Spacelabs; no longer a supported product The following Microsoft Windows operating systems; including both 32- and 64-bit versions; as well as all Service Pack versions are affected: Windows 2000 Windows Vista Windows XP Windows 7 Windows Server 2003 Windows Server 2003 R2 Windows Server 2008 Windows Server 2008 R2.,CVE-2019-0708,9.8,Critical,CWE-20,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1261,2/18/2020,5/16/2024,2020,ICSMA-20-049-02,GE Healthcare Ultrasound Products (Update A),GE Healthcare,Ultrasound Products,"GE Healthcare reports that the following ultrasound products are affected: Vivid products, not including EchoPAC: all versions LOGIQ, not including LOGIQ 100 Pro: all versions Voluson, not including ImageVault: all versions Versana Essential: all versions Invenia ABUS Scan station, not including VScan product line: all versions Venue, not including Venue 40 R1-3 and Venue 50 R4-5: all versions.","CVE-2020-6977, CVE-2024-1486",8.4,High,"CWE-693, CWE-286",Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1260,2/18/2020,2/19/2020,2020,ICSA-20-049-01,Honeywell INNCOM INNControl 3,Honeywell,INNCOM INNControl 3,The following versions of INNCOM INNControl 3 - energy management platform are affected: INNControl 3; Versions 3.21 and prior.,CVE-2020-6968,6.6,Medium,CWE-269,Commercial Facilities; Critical Manufacturing; Energy; Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1259,2/18/2020,2/18/2020,2020,ICSA-20-049-02,Emerson OpenEnterprise,Emerson,OpenEnterprise,The following versions of OpenEnterprise SCADA Server are affected: OpenEnterprise Server 2.83 is affected if Modbus or ROC Interfaces have been installed and are in use OpenEnterprise 3.1 through 3.3.3; all versions.,CVE-2020-6970,8.1,High,CWE-121,Energy; Chemical; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1258,2/13/2020,2/13/2020,2020,ICSA-20-044-01,Schneider Electric Modicon Ethernet Serial RTU,Schneider Electric,Modicon Ethernet Serial RTU,Schneider Electric reports these vulnerabilities affect the following products: BMXNOR0200H Ethernet/Serial RTU module; all firmware versions The BMXNOR0200H Ethernet/Serial RTU module is part of the Modicon X80 I/O product category. Modicon X80 I/Os are a common platform of modules for Modicon M580 and M340 PLCs.,"CVE-2019-6810, CVE-2019-6813, CVE-2019-6831",8.6,High,"CWE-284, CWE-754",Commercial Facilities,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1257,2/13/2020,2/13/2020,2020,ICSA-20-044-02,Schneider Electric Magelis HMI Panels,Schneider Electric,Magelis HMI Panels,The following versions of the Magelis HMI Panels are affected: Magelis HMIGTO series; all firmware versions Magelis HMISTO series; all firmware versions Magelis XBTGH series; all firmware versions Magelis HMIGTU series; all firmware versions Magelis HMIGTUX series; all firmware versions Magelis HMISCU series; all firmware versions Magelis HMISTU series; all firmware versions Magelis XBTGT series; all firmware versions Magelis XBTGC series; all firmware versions Magelis HMIGXO series; all firmware versions Magelis HMIGXU series; all firmware versions.,CVE-2019-6833,7.4,High,CWE-754,Critical Manufacturing; Food and Agriculture,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1256,2/11/2020,2/11/2020,2020,ICSA-20-042-03,Siemens SIMATIC CP 1543-1,Siemens,SIMATIC CP 1543-1,The following versions of Siemens SIMATIC CP 1543-1; including SIPLUS NET variants are affected: All versions starting at 2.0 and prior to 2.2.,"CVE-2019-12815, CVE-2019-18217",9.8,Critical,"CWE-284, CWE-835",Chemical; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1255,2/11/2020,2/11/2020,2020,ICSA-20-042-08,Siemens SIPORT MP,Siemens,SIPORT MP,SIPORT MP: All versions prior to 3.1.4 are affected.,CVE-2019-19277,6.5,Medium,CWE-778,Commercial Facilities; Government Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1254,2/11/2020,2/11/2020,2020,ICSA-20-042-09,Siemens OZW Web Server,Siemens,OZW Web Server,The following versions of OZW web server are affected: OZW672 and OZW772: All versions prior to 10.0.,CVE-2019-13941,5.3,Medium,CWE-552,Commercial Facilities; Government Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1253,2/11/2020,2/11/2020,2020,ICSA-20-042-12,Siemens SIPROTEC 4 and SIPROTEC Compact,Siemens,SIPROTEC 4 and SIPROTEC Compact,Siemens reports that the vulnerability affects the following SIPROTECT devices equipped with EN100 Ethernet communication modules: SIPROTEC 4; all versions SIPROTEC Compact; all versions.,CVE-2019-19279,7.5,High,CWE-20,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1252,2/11/2020,2/11/2020,2020,ICSA-20-042-13,Digi ConnectPort LTS 32 MEI,"Digi International, Inc.",ConnectPort LTS 32 MEI,The following versions of ConnectPort LTS 32 MEI; which provides serial over Ethernet connectivity are affected: ConnectPort LTS 32 MEI: firmware Version 1.4.3 (82002228_K 08/09/2018); bios Version 1.2.,"CVE-2020-6973, CVE-2020-6975",2.4,Low,"CWE-79, CWE-434",Commercial Facilities; Critical Manufacturing; Food and Agriculture; Healthcare and Public Health; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1251,2/4/2020,2/4/2020,2020,ICSA-20-035-01,AutomationDirect C-More Touch Panels,AutomationDirect,C-More Touch Panels,The following versions of C-More Touch Panels - a software management platform are affected: C-More Touch Panels EA9 series: firmware versions prior to 6.53.,CVE-2020-6969,10.0,Critical,CWE-522,Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1250,2/27/2018,2/27/2018,2020,ICSMA-18-058-01,Medtronic 2090 Carelink Programmer Vulnerabilities (Update C),Medtronic,2090 Carelink Programmer,The following versions of the Medtronic CareLink 2090 Programmer - device used by trained personnel at hospitals and clinics to program and manage Medtronic cardiac devices are affected: 2090 CareLink Programmer | all versions and 29901 Encore Programmer | all versions.,"CVE-2018-5446, CVE-2018-5448, CVE-2018-10596",7.1,High,"CWE-923, CWE-23, CWE-257",Healthcare and Public Health,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1249,1/23/2020,1/23/2020,2020,ICSMA-20-023-01,"GE CARESCAPE, ApexPro, and Clinical Information Center systems",GE,"CARESCAPE, ApexPro, and Clinical Information Center systems",The following versions of GE Healthcare Monitoring platforms are affected: ApexPro Telemetry Server; Versions 4.2 and prior CARESCAPE Telemetry Server; Versions 4.2 and prior Clinical Information Center (CIC); Versions 4.X and 5.X CARESCAPE Telemetry Server; Version 4.3 (Impacted by CVE-2020- 6962 and CVE-2020-6961) CARESCAPE Central Station (CSCS); Versions 1.X CARESCAPE Central Station (CSCS); Versions 2.X (Impacted by CVE-2020- 6962 and CVE-2020-6964) B450; Version 2.X (Impacted by CVE-2020- 6962 and CVE-2020-6965) B650; Version 1.X (Impacted by CVE-2020- 6962 and CVE-2020-6965) B650; Version 2.X (Impacted by CVE-2020- 6962 and CVE-2020-6965) B850; Version 1.X (Impacted by CVE-2020- 6962 and CVE-2020-6965) B850; Version 2.X (Impacted by CVE-2020- 6962 and CVE-2020-6965).,"CVE-2020-6961, CVE-2020-6962, CVE-2020-6963, CVE-2020-6964, CVE-2020-6965, CVE-2020-6966",10.0,Critical,"CWE-20, CWE-326, CWE-306, CWE-256, CWE-434, CWE-798",Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1248,1/21/2020,1/21/2020,2020,ICSA-20-021-01,Honeywell Maxpro VMS & NVR,Honeywell,Maxpro VMS & NVR,The following versions of MAXPRO VMS and NVR; video management systems are affected: MAXPRO VMS: HNMSWVMS prior to Version VMS560 Build 595 T2-Patch HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch.,"CVE-2020-6959, CVE-2020-6960",9.8,Critical,"CWE-502, CWE-89",Commercial Facilities; Critical Manufacturing; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1247,1/14/2020,1/16/2020,2020,ICSA-20-014-01,GE PACSystems RX3i,GE/Emerson,PACSystems RX3i,Emerson reports this vulnerability affects the following GE PACSystem products and versions: CPE100: All versions prior to R9.85 CPE115: All versions prior to R9.85 CPE302: All versions prior to R9.90 CPE305: All versions prior to R9.90 CPE310: All versions prior to R9.90 CRU320: (End of Life; Upgrade to CPE330) CPE330: All versions prior to R9.90 CPE400: All versions prior to R9.90 CPL410: All versions prior to R9.90.,CVE-2019-13524,7.5,High,CWE-20,Commercial Facilities; Critical Manufacturing; Dams; Defense Industrial Base; Energy; Food and Agriculture; Government Facilities; Information Technology; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1246,1/14/2020,1/14/2020,2020,ICSA-20-014-02,Siemens SINEMA Server,Siemens,SINEMA Server,The following versions of SINEMA Server - a network management software are affected: All versions prior to Version 14.0 SP2 Update 1.,CVE-2019-10940,9.9,Critical,CWE-266,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1245,1/14/2020,6/16/2022,2020,ICSA-20-014-03,Siemens SCALANCE X Switches (Update B),Siemens,SCALANCE X Switches,"The following versions of SCALANCE X Switches, used to connect industrial components, are affected: --------- Begin Update B Part 1 of 2 --------- SCALANCE X-200RNA (HSA): All versions prior to v3.2.7 SCALANCE X-200RNA (PRP): All versions prior to v3.2.7 SCALANCE X-200RNA EEC (HSR): All versions prior to v3.2.7 SCALANCE X-200RNA EEC (PRP): All versions prior to v3.2.7 --------- End Update B Part 1 of 2 --------- SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants): All versions prior to v4.1.3.",CVE-2019-13933,8.8,High,CWE-306,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1244,1/14/2020,1/14/2020,2020,ICSA-20-014-04,Siemens SINAMICS PERFECT HARMONY GH180,Siemens,SINAMICS PERFECT HARMONY GH180,The following versions of SINAMICS PERFECT HARMONY GH180 - a voltage converter are affected: All versions of SINAMICS PERFECT HARMONY GH180 Drives: MLFB 6SR32..-. . . ..-. . . . MLFB 6SR4. . . -. . . ..-. . . . MLFB 6SR5. . . -. . . ..-. . . .; with option A30 (HMIs 12 inches or larger) All versions of SINAMICS PERFECT HARMONY GH180 Drives: MLFB 6SR325.-. . . ..-. . . . (High Availability).,CVE-2019-19278,6.8,Medium,CWE-693,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1243,1/14/2020,1/14/2020,2020,ICSA-20-014-06,OSIsoft PI Vision,OSIsoft,PI Vision,The following versions of PI Vision - a visualization tool are affected: CVE-2019-18275 and CVE-2019-18271: All versions of PI Vision prior to 2019 CVE-2019-18273: PI Vision 2017 R2 and PI Vision 2017 R2 SP1 CVE-2019-18244: PI Vision 2017 R2; PI Vision 2017 R2 SP1; PI Vision 2019.,"CVE-2019-18244, CVE-2019-18271, CVE-2019-18273, CVE-2019-18275",7.1,High,"CWE-352, CWE-284, CWE-79, CWE-532",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1242,12/10/2019,1/14/2020,2020,ICSA-19-344-07,Siemens EN100 Ethernet Module (Update A),Siemens,EN100 Ethernet Module,"Versions of EN100, an ethernet module, are affected: EN100 Ethernet module for IEC 61850: versions prior to 4.37 EN100 Ethernet module for PROFINET IO: all versions EN100 Ethernet module for Modbus TCP: all versions EN100 Ethernet module for DNP3: all versions EN100 Ethernet module for IEC104: all versions. The above EN100 modules are included in SIPROTEC 4, SIPROTEC Compact, Reyrolle, and SWT3000 devices.","CVE-2019-13942, CVE-2019-13943, CVE-2019-13944",7.5,High,"CWE-79, CWE-119, CWE-23",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1241,10/8/2019,1/14/2020,2020,ICSA-19-281-03,Siemens SIMATIC WinAC RTX (F) 2010 (Update A),Siemens,SIMATIC WinAC RTX (F) 2010,"Siemens SIMATIC WinAC RTX (F) 2010, software controller for PC-based automation solutions, are affected: SIMATIC WinAC RTX (F) 2010 all versions prior to SP3 Update 1.",CVE-2019-13921,7.5,High,CWE-410,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1240,6/12/2018,12/15/2022,2018,ICSA-18-163-02,Siemens SCALANCE X Switches (Update B),Siemens,SCALANCE X switches,Siemens reports the vulnerabilities affects the following SCALANCE X switch products: SCALANCE X-200 switch family (incl. SIPLUS NET variants): All versions prior to v5.2.3 (only affected by CVE-2018-4848) SCALANCE X-200 IRT switch family (incl. SIPLUS NET variants): All versions prior to v5.4.1 SCALANCE X300 switch family (incl. SIPLUS NET variants): All versions prior to v4.1.3 --------- Begin Update B Part 1 of 2 --------- SCALANCE X-200RNA switch family: All versions prior to v3.2.7 --------- End Update B Part 1 of 2 ---------,"CVE-2018-4842, CVE-2018-4848",5.8,Medium,CWE-79,Chemical; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1239,10/1/2019,10/1/2019,2020,ICSMA-19-274-01,Interpeak IPnet TCP/IP Stack (Update D),"ENEA, Green Hills Software, ITRON, IP Infusion, Wind River",Interpeak IPnet TCP/IP Stack,"The Interpeak IPnet stack has been identified to be affected by CVE-2019-12255, CVE-2019-12262, and CVE-2019-12264. The following RTOS are affected: ENEA reports that OSE4 and OSE5 may have been bundled with Interpeak IPnet from 2004-2006. In 2007, ENEA replaced Interpeak IPnet with OSENet. Green Hills Software reports Interpeak IPnet was a third-party add-on for INTREGRITY RTOS from 2003-2006. Wind River reports the following versions of VxWorks are affected: All versions of VxWorks under CURRENT support (6.9.4.11, Vx7 SR540, Vx7 SR610) are affected by one or more of the CVE numbers detailed below. Older, end-of-life versions of VxWorks back to 6.5 are also affected by one or more of the CVE numbers below. All versions of the discontinued product Advanced Networking Technology (ANT) are likely affected by one or more of the CVE numbers below. The VxWorks bootrom network stack leverages the same IPnet source as VxWorks and, as a result, is also technically vulnerable to CVE-2019-12256. The same patches and mitigations apply to VxWorks and the bootrom network stack; however, the bootrom normally uses statically assigned IP-addresses, not DHCP. If that is true, then the defects related to those protocols do not apply in practice. Also, a successful exploit of the bootrom network stack has a more difficult timing component. In typical applications, the bootrom does not listen to TCP-ports, which means that the TCP-related issues must be timed with the target downloading data from the network. VxWorks 653 MCE 3.x may be affected. Contact Wind River customer support (support@windriver.com) for more details. The following VxWorks products are not affected: The latest release of VxWorks, VxWorks 7 SR620, is NOT affected by any of these CVEs VxWorks 5.3 through VxWorks 6.4 inclusive are NOT affected. VxWorks Cert versions are NOT affected. VxWorks 653 Versions 2.x and earlier are NOT affected. VxWorks 653 MCE 3.x Cert Edition and later are NOT affected. CISA will update this document as more mitigations are identified by affected vendors.","CVE-2019-12256, CVE-2019-12257, CVE-2019-12255, CVE-2019-12260, CVE-2019-12261, CVE-2019-12263, CVE-2019-12258, CVE-2019-12259, CVE-2019-12262, CVE-2019-12264, CVE-2019-12265",9.8,Critical,"CWE-362, CWE-122, CWE-88, CWE-119, CWE-191, CWE-476, CWE-121",Critical Manufacturing; Information Technology; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1238,10/1/2019,10/1/2019,2020,ICSMA-19-274-01,Interpeak IPnet TCP/IP Stack (Update D),"ENEA, Green Hills Software, ITRON, IP Infusion, Wind River",Interpeak IPnet TCP/IP Stack,"The Interpeak IPnet stack has been identified to be affected by CVE-2019-12255, CVE-2019-12262, and CVE-2019-12264. The following RTOS are affected: ENEA reports that OSE4 and OSE5 may have been bundled with Interpeak IPnet from 2004-2006. In 2007, ENEA replaced Interpeak IPnet with OSENet. Green Hills Software reports Interpeak IPnet was a third-party add-on for INTREGRITY RTOS from 2003-2006. Wind River reports the following versions of VxWorks are affected: All versions of VxWorks under CURRENT support (6.9.4.11, Vx7 SR540, Vx7 SR610) are affected by one or more of the CVE numbers detailed below. Older, end-of-life versions of VxWorks back to 6.5 are also affected by one or more of the CVE numbers below. All versions of the discontinued product Advanced Networking Technology (ANT) are likely affected by one or more of the CVE numbers below. The VxWorks bootrom network stack leverages the same IPnet source as VxWorks and, as a result, is also technically vulnerable to CVE-2019-12256. The same patches and mitigations apply to VxWorks and the bootrom network stack; however, the bootrom normally uses statically assigned IP-addresses, not DHCP. If that is true, then the defects related to those protocols do not apply in practice. Also, a successful exploit of the bootrom network stack has a more difficult timing component. In typical applications, the bootrom does not listen to TCP-ports, which means that the TCP-related issues must be timed with the target downloading data from the network. VxWorks 653 MCE 3.x may be affected. Contact Wind River customer support (support@windriver.com) for more details. The following VxWorks products are not affected: The latest release of VxWorks, VxWorks 7 SR620, is NOT affected by any of these CVEs VxWorks 5.3 through VxWorks 6.4 inclusive are NOT affected. VxWorks Cert versions are NOT affected. VxWorks 653 Versions 2.x and earlier are NOT affected. VxWorks 653 MCE 3.x Cert Edition and later are NOT affected. CISA will update this document as more mitigations are identified by affected vendors.","CVE-2019-12256, CVE-2019-12257, CVE-2019-12255, CVE-2019-12260, CVE-2019-12261, CVE-2019-12263, CVE-2019-12258, CVE-2019-12259, CVE-2019-12262, CVE-2019-12264, CVE-2019-12265",9.8,Critical,"CWE-362, CWE-122, CWE-88, CWE-119, CWE-191, CWE-476, CWE-121",Critical Manufacturing; Information Technology; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,Sweden,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1237,12/19/2019,12/19/2019,2019,ICSMA-19-353-01,"Philips Veradius Unity, Pulsera, and Endura Dual WAN Routers",Philips,"Veradius Unity, Pulsera, and Endura Dual WAN Routers","Veradius Unity, Pulsera, and Endura Dual WAN Routers are affected: Veradius Unity (718132) with wireless option (shipped between 2016-August 2018) Veradius Unity (718132) with ViewForum option (shipped between 2016-August 2018) Pulsera (718095) and Endura (718075) with wireless option (shipped between 26-June-2017 through 07-August 2018) Pulsera (718095) and Endura (718075) with ViewForum option (shipped between 26-June-2017 through 07-August 2018)",CVE-2019-18263,5.3,Medium,CWE-326,Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1236,12/19/2019,12/19/2019,2019,ICSA-19-353-01,Moxa EDS Ethernet Switches,Moxa,EDS Ethernet Switches,EDS-G508E Series: Firmware Version 6.0 and prior EDS-G512E Series: Firmware Version 6.0 and prior EDS-G516E Series: Firmware Version 6.0 and prior.,CVE-2019-19707,7.5,High,CWE-400,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1235,12/19/2019,12/19/2019,2019,ICSA-19-353-02,Equinox Control Expert,Equinox,Control Expert,"Control Expert, all current and older versions could be affected.",CVE-2019-18234,9.8,Critical,CWE-89,Multiple Critical Sectors,"Argentina, Uruguay",Argentina,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1234,12/19/2019,12/19/2019,2019,ICSA-19-353-03,WECON PLC Editor,WECON,PLC Editor,"Version of PLC Editor, a ladder logic software, is reported to be affected: Version 1.3.5_20190129.",CVE-2019-18236,7.8,High,CWE-121,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1233,12/19/2019,12/19/2019,2019,ICSA-19-353-04,Reliable Controls MACH-ProWebCom/Sys,Reliable Controls,MACH-ProWebCom/Sys,MACH-ProWebSys: All versions prior to 2.15 (Firmware versions prior to 8.26.4) MACH-ProWebCom: All versions prior to 2.15 (Firmware versions prior to 8.26.4).,CVE-2019-18249,8.2,High,CWE-79,Commercial Facilities,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1232,11/14/2019,12/19/2019,2019,ICSA-19-318-04,Omron CX-Supervisor (Update A),Omron,CX-Supervisor,"Versions of both ""Full Development"" and ""Runtime Only"" packages of Omron's SCADA and HMI package CX-Supervisor are affected: CX-Supervisor Versions 3.5 (12) and prior.",CVE-2019-18251,8.8,High,CWE-477,Energy,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1231,10/17/2019,12/19/2019,2019,ICSA-19-290-01,AVEVA Vijeo Citect and Citect SCADA (Update A),"AVEVA, Schneider Electric",Vijeo Citect and Citect SCADA,Versions of the IEC870IP driver used in AVEVA's Vijeo Citect and Citect SCADA and Schneider Electric's Power SCADA Operation are affected: IEC870IP driver v4.14.02 and prior.,CVE-2019-13537,7.5,High,CWE-121,Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1230,12/17/2019,12/17/2019,2019,ICSA-19-351-01,GE S2020/S2020G Fast Switch 61850,GE,S2020/S2020G Fast Switch 61850,"GE S2020/S2020G Fast Switch 61850, a managed Ethernet switch version affected: Versions 07A03 and prior.",CVE-2019-18267,4.6,Medium,CWE-79,Critical Manufacturing; Energy; Transportation,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1229,12/12/2019,12/12/2019,2019,ICSA-19-346-01,Advantech DiagAnywhere Server,Advantech,DiagAnywhere Server,DiagAnywhere Server Versions 3.07.11 and prior.,CVE-2019-18257,9.8,Critical,CWE-121,Critical Manufacturing; Energy; Water and Wastewater,"East Asia, United States, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1228,12/12/2019,4/18/2023,2019,ICSA-19-346-02,Omron PLC CJ and CS Series (Update B),Omron,PLC CJ and CS Series,"The following versions of Omron Programmable Logic Controllers are affected: Omron PLC CJ series, all versions Omron PLC CS series, all versions Omron PLC NX1P2 series, all versions.","CVE-2019-18259, CVE-2019-13533, CVE-2019-18269",8.6,High,"CWE-290, CWE-294, CWE-412",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1227,12/12/2019,12/12/2019,2019,ICSA-19-346-03,"Omron PLC CJ, CS and NJ Series",Omron,"PLC CJ, CS and NJ Series","Omron PLC CS series, all versions Omron PLC CJ series, all versions Omron PLC NJ series, all versions",CVE-2019-18261,6.5,Medium,CWE-307,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1226,11/14/2019,12/12/2019,2019,ICSMA-19-318-01,Philips IntelliBridge EC40/80 (Update A),Philips,IntelliBridge EC40/80,"IntelliBridge EC40 Hub, all versions IntelliBridge EC80 Hub, all versions.",CVE-2019-18241,6.3,Medium,CWE-326,Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1225,4/16/2019,12/17/2019,2019,ICSA-19-106-03,PLC Cycle Time Influences (Update A),ABB,PLC Cycle Time Influences,ABB 1SAP120600R0071 PM554-TP-ETH,CVE-2019-10953,7.5,High,CWE-400,Chemical; Commercial Facilities; Critical Manufacturing; Dams; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1224,4/16/2019,12/17/2019,2019,ICSA-19-106-03,PLC Cycle Time Influences (Update A),PHOENIX CONTACT,PLC Cycle Time Influences,Phoenix Contact 2700974 ILC 151 ETH | Phoenix Contact ILC 191 ETH 2TX,CVE-2019-10953,7.5,High,CWE-400,Chemical; Commercial Facilities; Critical Manufacturing; Dams; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1223,4/16/2019,12/17/2019,2019,ICSA-19-106-03,PLC Cycle Time Influences (Update A),Schneider Electric,PLC Cycle Time Influences,Schneider Modicon M221,CVE-2019-10953,7.5,High,CWE-400,Chemical; Commercial Facilities; Critical Manufacturing; Dams; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1222,4/16/2019,12/17/2019,2019,ICSA-19-106-03,PLC Cycle Time Influences (Update A),Siemens,PLC Cycle Time Influences,Siemens 6ES7211-1AE40-0XB0 Simatic S7-1211 | Siemens 6ES7314-6EH04-0AB0 Simatic S7-314 | Siemens 6ED1052-1CC01-0BA8 Logo! 8,CVE-2019-10953,7.5,High,CWE-400,Chemical; Commercial Facilities; Critical Manufacturing; Dams; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1221,4/16/2019,12/17/2019,2019,ICSA-19-106-03,PLC Cycle Time Influences (Update A),WAGO,PLC Cycle Time Influences,WAGO 750-889 Controller KNX IP | WAGO 750-8100 Controller PFC100 | WAGO 750-880 Controller ETH | WAGO 750-831 Controller BACnet/IP,CVE-2019-10953,7.5,High,CWE-400,Chemical; Commercial Facilities; Critical Manufacturing; Dams; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1220,12/10/2019,12/10/2019,2019,ICSA-19-344-01,Siemens SCALANCE W700 and W1700,Siemens,SCALANCE W700 and W1700,"SCALANCE W700 and W1700, wireless communication devices, are affected: SCALANCE W700 Versions 6.3 and prior.",CVE-2018-14526,6.5,Medium,CWE-924,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1219,12/10/2019,9/15/2022,2019,ICSA-19-344-03,Siemens RUGGEDCOM ROS (Update A),Siemens,RUGGEDCOM ROS,"--------- Begin Update A Part 1 of 2 --------- The following versions of RUGGEDCOM ROS, an ethernet switch, are affected: RUGGEDCOM ROS RMC8388: All versions with U-Boot prior to V2016.05RS09 (only affected by CVE-2018-18440) RUGGEDCOM ROS RSG900C: All versions with U-Boot prior to V2016.05RS09 (only affected by CVE-2018-18440) RUGGEDCOM ROS RSG900R: All versions with U-Boot prior to V2016.05RS09 (only affected by CVE-2018-18440) RUGGEDCOM ROS RSG907R: All versions with U-Boot prior to V2016.05RS09 (only affected by CVE-2018-18440) RUGGEDCOM ROS RSG908C: All versions with U-Boot prior to V2016.05RS09 (only affected by CVE-2018-18440) RUGGEDCOM ROS RSG909R: All versions with U-Boot prior to V2016.05RS09 (only affected by CVE-2018-18440) RUGGEDCOM ROS RSG910C: All versions with U-Boot prior to V2016.05RS09 (only affected by CVE-2018-18440) RUGGEDCOM ROS RSG920P: Versions 2016.05RS09 and later (only affected by CVE-2019-13103) RUGGEDCOM ROS RSG920P: All versions with U-Boot prior to V2016.05RS09 RUGGEDCOM ROS RSG2488: Versions 2016.05RS09 and later (only affected by CVE-2019-13103) RUGGEDCOM ROS RSG2488: All versions with U-Boot prior to V2016.05RS09 RUGGEDCOM ROS RSL910: All versions with U-Boot prior to V2016.05RS09 (only affected by CVE-2018-18440) RUGGEDCOM ROS RST2228: Versions 2016.05RS09 and later (only affected by CVE-2019-13103) RUGGEDCOM ROS RST2228: All versions with U-Boot prior to V2016.05RS09 --------- End Update A Part 1 of 2 ---------.","CVE-2018-18440, CVE-2019-13103",7.8,High,"CWE-119, CWE-399",Energy; Healthcare and Public Health; Transportation Systems;,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1218,12/10/2019,12/10/2019,2019,ICSA-19-344-05,Siemens XHQ Operations Intelligence,Siemens,XHQ Operations Intelligence,Siemens Operations Intelligence products: XHQ: All versions prior to v6.0.0.2.,"CVE-2019-13930, CVE-2019-13931, CVE-2019-13932",8.8,High,"CWE-352, CWE-20, CWE-80",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1217,11/22/2016,11/22/2016,2019,ICSA-16-327-02,Siemens SIMATIC CP 343-1/CP 443-1 Modules and SIMATIC S7-300/S7-400 CPUs Vulnerabilities (Update B),Siemens,SIMATIC CP 343-1/CP 443-1 Modules and SIMATIC S7-300/S7-400 CPUs,SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variant): All versions prior to v3.0.53 SIMATIC CP 443-1 Advanced (incl. SIPLUS NET variant): All versions prior to v3.2.17 SIMATIC S7-300 CPU family (incl. SIPLUS NET variant): All firmware versions SIMATIC S7-400 CPU family (incl. SIPLUS NET variant): All firmware versions.,"CVE-2016-8673, CVE-2016-8672",6.3,Medium,"CWE-345, CWE-614",Chemical; Critical Manufacturing; Food and Agriculture,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1216,5/29/2013,12/10/2019,2019,ICSA-13-149-01,Siemens SCALANCE Privilege Escalation Vulnerabilities (Update A),Siemens,SCALANCE,SCALANCE: SCALANCE X-200 switch family (incl. SIPLUS NET variants): versions prior to v4.5.0 SCALANCE X-200IRT switch family (incl. SIPLUS NET variants): versions prior to v5.1.0.,"CVE-2013-3633, CVE-2013-3634",7.6,High,"CWE-287, CWE-264",Chemical; Communications; Critical Manufacturing; Dams; Defense Industrial Base; Energy; Food and Agriculture; Government Facilities; Transportation Systems;: Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1215,12/5/2019,12/5/2019,2019,ICSA-19-339-01,Thales DIS SafeNet Sentinel LDK License Manager Runtime,Thales DIS,SafeNet Sentinel LDK License Manager Runtime,"SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected).",CVE-2019-18232,7.3,High,CWE-59,Multiple Critical Sectors,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1214,12/5/2019,12/5/2019,2019,ICSA-19-339-02,Weidmueller Industrial Ethernet Switches,Weidmueller,Industrial Ethernet Switches,The following versions of industrial Ethernet switches are affected: IE-SW-VL05M-5TX firmware v3.6.6 Build 16102415 and prior IE-SW-VL05MT-5TX firmware v3.6.6 Build 16102415 and prior IE-SW-VL05M-3TX-2SC firmware v3.6.6 Build 16102415 and prior IE-SW-VL05MT-3TX-2SC firmware v3.6.6 Build 16102415 and prior IE-SW-VL05M-3TX-2ST firmware v3.6.6 Build 16102415 and prior IE-SW-VL05MT-3TX-2ST firmware v3.6.6 Build 16102415 and prior IE-SW-VL08MT-8TX firmware v3.5.2 Build 16102415 and prior IE-SW-VL08MT-5TX-3SC firmware v3.5.2 Build 16102415 and prior IE-SW-VL08MT-5TX-1SC-2SCS firmware v3.5.2 Build 16102415 and prior IE-SW-VL08MT-6TX-2ST firmware v3.5.2 Build 16102415 and prior IE-SW-VL08MT-6TX-2SC firmware v3.5.2 Build 16102415 and prior IE-SW-VL08MT-6TX-2SCS firmware v3.5.2 Build 16102415 and prior IE-SW-PL08M-8TX firmware v3.3.8 Build 16102416 and prior IE-SW-PL08MT-8TX firmware v3.3.8 Build 16102416 and prior IE-SW-PL08M-6TX-2SC firmware v3.3.8 Build 16102416 and prior IE-SW-PL08MT-6TX-2SC firmware v3.3.8 Build 16102416 and prior IE-SW-PL08M-6TX-2ST firmware v3.3.8 Build 16102416 and prior IE-SW-PL08MT-6TX-2ST firmware v3.3.8 Build 16102416 and prior IE-SW-PL08M-6TX-2SCS firmware v3.3.8 Build 16102416 and prior IE-SW-PL08MT-6TX-2SCS firmware v3.3.8 Build 16102416 and prior IE-SW-PL10M-3GT-7TX firmware v3.3.16 Build 16102416 and prior IE-SW-PL10MT-3GT-7TX firmware v3.3.16 Build 16102416 and prior IE-SW-PL10M-1GT-2GS-7TX firmware v3.3.16 Build 16102416 and prior IE-SW-PL10MT-1GT-2GS-7TX firmware v3.3.16 Build 16102416 and prior IE-SW-PL16M-16TX firmware v3.4.2 Build 16102416 and prior IE-SW-PL16MT-16TX firmware v3.4.2 Build 16102416 and prior IE-SW-PL16M-14TX-2SC firmware v3.4.2 Build 16102416 and prior IE-SW-PL16MT-14TX-2SC firmware v3.4.2 Build 16102416 and prior IE-SW-PL16M-14TX-2ST firmware v3.4.2 Build 16102416 and prior IE-SW-PL16MT-14TX-2ST firmware v3.4.2 Build 16102416 and prior IE-SW-PL18M-2GC-16TX firmware v3.4.4 Build 16102416 and prior IE-SW-PL18MT-2GC-16TX firmware v3.4.4 Build 16102416 and prior IE-SW-PL18M-2GC14TX2SC firmware v3.4.4 Build 16102416 and prior IE-SW-PL18MT-2GC14TX2SC firmware v3.4.4 Build 16102416 and prior IE-SW-PL18M-2GC14TX2ST firmware v3.4.4 Build 16102416 and prior IE-SW-PL18MT-2GC14TX2ST firmware v3.4.4 Build 16102416 and prior IE-SW-PL18M-2GC14TX2SCS firmware v3.4.4 Build 16102416 and prior IE-SW-PL18MT-2GC14TX2SCS firmware v3.4.4 Build 16102416 and prior IE-SW-PL09M-5GC-4GT firmware v3.3.4 Build 16102416 and prior IE-SW-PL09MT-5GC-4GT firmware v3.3.4 Build 16102416 and prior.,"CVE-2019-16670, CVE-2019-16671, CVE-2019-16672, CVE-2019-16673, CVE-2019-16674",9.8,Critical,"CWE-307, CWE-311, CWE-341, CWE-400, CWE-256",Critical Manufacturing; Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1213,12/3/2019,12/3/2019,2019,ICSA-19-337-01,Reliable Controls LicenseManager,Reliable Controls,LicenseManager,RC-LicenseManager: Versions 3.4 and prior.,CVE-2019-18245,7.8,High,CWE-428,Commercial Facilities; Critical Manufacturing; Government Facilities,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1212,12/3/2019,12/3/2019,2019,ICSA-19-337-02,Moxa AWK-3121,Moxa,AWK-3121,AWK-3121: All Versions 1.14 and prior.,"CVE-2018-10690, CVE-2018-10691, CVE-2018-10692, CVE-2018-10693, CVE-2018-10694, CVE-2018-10695, CVE-2018-10696, CVE-2018-10697, CVE-2018-10698, CVE-2018-10699, CVE-2018-10700, CVE-2018-10701, CVE-2018-10702, CVE-2018-10703",9.8,Critical,"CWE-284, CWE-319, CWE-1004, CWE-119, CWE-352, CWE-77, CWE-79",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1211,11/26/2019,11/26/2019,2019,ICSA-19-330-01,ABB Relion 670 Series,ABB,Relion 670 Series,Relion 670 series versions 1p1r26 and prior Relion 670 series versions 1.2.3.17 and prior Relion 670 series versions 2.0.0.10 and prior (RES670 2.0.0.4 and prior) Relion 670 series versions 2.1.0.1 and prior.,CVE-2019-18253,10.0,Critical,CWE-22,Critical Manufacturing; Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1210,11/26/2019,11/26/2019,2019,ICSA-19-330-02,ABB Relion 650 and 670 Series,ABB,Relion 650 and 670 Series,Relion 650 series versions 1.3.0.5 and prior Relion 670 series versions 1.2.3.18 and prior Relion 670 series versions 2.0.0.11 and prior Relion 670 series versions 2.1.0.1 and prior.,CVE-2019-18247,5.3,Medium,CWE-20,Critical Manufacturing; Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1209,11/19/2019,11/19/2019,2019,ICSA-19-323-01,Flexera FlexNet Publisher,Flexera,FlexNet Publisher,FlexNet Publisher Version 2018 R3 and prior.,"CVE-2018-20031, CVE-2018-20032, CVE-2018-20033, CVE-2018-20034",9.8,Critical,"CWE-20, CWE-119",Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1208,11/14/2019,11/14/2019,2019,ICSA-19-318-01,Siemens Mentor Nucleus Networking Module,Siemens,Mentor Nucleus Networking Module,"Nucleus NET: All versions Nucleus RTOS: All versions Nucleus ReadyStart for ARM, MIPS, and PPC: All versions prior to v2017.02.2 with patch ""Nucleus 2017.02.02 Nucleus NET Patch"" Nucleus SafetyCert: All versions Nucleus Source Code: All versions VSTAR: All versions.",CVE-2019-13939,7.1,High,CWE-20,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1207,11/14/2019,11/14/2019,2019,ICSA-19-318-03,Siemens Desigo PX Devices,Siemens,Desigo PX Devices,"Desigo PX automation controllers are affected: PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D with Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2: All firmware versions prior to V6.00.320 PXC00-U, PXC64-U, PXC128-U with Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2: All firmware versions prior to V6.00.320 PXC22.1-E.D, PXC36-E.D, PXC36.1-E.D with activated web server: All firmware versions prior to V6.00.320.",CVE-2019-13927,5.3,Medium,CWE-472,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1206,11/14/2019,11/14/2019,2019,ICSA-19-318-05,ABB Power Generation Information Manager (PGIM) and Plant Connect,ABB,Power Generation Information Manager (PGIM) and Plant Connect,Power Generation Information Manager (PGIM): All versions Plant Connect: All versions.,CVE-2019-18250,9.8,Critical,CWE-288,Chemical; Critical Manufacturing; Dams; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1205,4/30/2019,11/7/2019,2019,ICSMA-19-120-01,Philips Tasy EMR (Update A),Philips,Tasy EMR,Tasy EMR Versions 3.02.1744 and prior Tasy WebPortal Versions 3.02.1757 and prior.,"CVE-2019-6562, CVE-2019-13557",4.3,Medium,"CWE-200, CWE-79",Healthcare and Public Health,"Brazil, Mexico",Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1204,11/7/2019,11/7/2019,2019,ICSMA-19-311-01,Medtronic Valleylab FT10 and LS10,Medtronic,Valleylab FT10 and LS10,Medtronic Valleylab energy and electrosurgery products affected: Valleylab FT10 Energy Platform (VLFT10GEN) Version 2.1.0 and lower Version 2.0.3 and lower Valleylab LS10 Energy Platform (VLLS10GEN”not available in the United States) Version 1.20.2 and lower.,"CVE-2019-13531, CVE-2019-13535",4.8,Medium,"CWE-287, CWE-693",Healthcare and Public Health,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1203,11/7/2019,11/7/2019,2019,ICSMA-19-311-02,Medtronic Valleylab FT10 and FX8,Medtronic,Valleylab FT10 and FX8,"Medtronic Valleylab energy products affected: Valleylab Exchange Client, Version 3.4 and below Valleylab FT10 Energy Platform (VLFT10GEN) software Version 4.0.0 and below Valleylab FX8 Energy Platform (VLFX8GEN) software Version 1.1.0 and below.","CVE-2019-13539, CVE-2019-13543, CVE-2019-3463, CVE-2019-3464",9.8,Critical,"CWE-20, CWE-328, CWE-798",Healthcare and Public Health,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1202,11/7/2019,11/7/2019,2019,ICSA-19-311-01,Mitsubishi Electric MELSEC-Q Series and MELSEC-L Series CPU Modules,Mitsubishi Electric,MELSEC-Q Series and MELSEC-L Series CPU Modules,"[MELSEC-Q Series] Q03/04/06/13/26UDVCPU: serial number 21081 and prior, Q04/06/13/26UDPVCPU: serial number 21081 and prior, and Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: serial number 21081 and prior. [MELSEC-L Series] L02/06/26CPU, L26CPU-BT: serial number 21101 and prior, L02/06/26CPU-P, L26CPU-PBT: serial number 21101 and prior, and L02/06/26CPU-CM, L26CPU-BT-CM: serial number 21101 and prior.",CVE-2019-13555,7.5,High,CWE-400,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1201,11/7/2019,11/7/2019,2019,ICSA-19-311-02,Fuji Electric V-Server,Fuji Electric,V-Server,V-Server - data collection and management service versions affected: V-Server 4.0.6 and prior.,CVE-2019-18240,7.8,High,CWE-122,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1200,11/5/2019,11/6/2019,2019,ICSA-19-309-01,Omron CX-Supervisor,Omron,CX-Supervisor,Full Development and Runtime Only packages of Omron's SCADA and HMI package CX-Supervisor versions affected: CX-Supervisor Versions 3.5 (12) and prior.,"CVE-2010-3128, CVE-2018-14333, CVE-2018-16550, CVE-2019-11769",9.8,Critical,CWE-477,Energy,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1199,5/14/2019,11/5/2019,2019,ICSA-19-134-01,Omron Network Configurator for DeviceNet (Update A),Omron,Network Configurator for DeviceNet,Network Configurator for DeviceNet Safety 3.41 and prior.,CVE-2019-10971,7.3,High,CWE-426,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1198,10/31/2019,10/31/2019,2019,ICSA-19-304-01,Advantech WISE-PaaS/RMM,Advantech,WISE-PaaS/RMM,Versions of WISE-PaaS/RMM - IoT device remote monitoring and management platform are affected: WISE-PaaS/RMM Versions 3.3.29 and prior.,"CVE-2019-13547, CVE-2019-13551, CVE-2019-18227, CVE-2019-18229",9.8,Critical,"CWE-22, CWE-89, CWE-611, CWE-862",Critical Manufacturing; Energy Water,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1197,10/31/2019,10/31/2019,2019,ICSA-19-304-02,Honeywell equIP Series IP Cameras,Honeywell,equIP Series IP Cameras,Honeywell equIP Series IP camera products and versions affected: H4L2GR1 2.420.HW01.33.20190812 | HBL2GR1 2.420.HW01.33.20190812 | HCL2G 2.420.HW01.33.20190812 | H4W2GR1 1.000.HW00.21.20190812 | H4W2GR2 1.000.HW00.21.20190812 H4W4GR1 1.000.HW00.21.20190812 | H3W2GR2 1.000.HW00.21.20190812 | H3W4GR1 1.000.HW00.21.20190812 | HBW2GR1 1.000.HW00.21.20190812 | HBW4GR1 1.000.HW00.21.20190812 | HBW2GR3 1.000.HW00.21.20190812 | HCW2G 1.000.HW00.21.20190812 | HCW4G 1.000.HW00.21.20190812.,CVE-2019-18228,7.5,High,CWE-20,Commercial Facilities; Critical Manufacturing; Energy; Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1196,10/31/2019,10/31/2019,2019,ICSA-19-304-03,Honeywell equIP and Performance Series IP Cameras,Honeywell,equIP and Performance Series IP Cameras,equIP Series Cameras and versions affected: H2W2GR1 1.000.0000.18.20190409 | H3W2GR1 1.000.HW00.21.20190812 | * H3W2GR1V 1.000.0000.18.20190409 | H3W2GR2 1.000.HW00.21.20190812 | H3W4GR1 1.000.HW00.21.20190812 | * H3W4GR1V 1.000.0000.18.20190409 | * H4D8GR1 2.420.HW00.9.20180510 | H4L2GR1 1.000.0000.18.20190423 | * H4L2GR1V 1.000.0000.18.20190423 | H4L6GR2 1.000.HW02.8.20190813 | H4LGGR2 1.000.HW04.3.20190813 | H4W2GR1 1.000.HW00.21.20190812 | * H4W2GR1V 1.000.0000.18.20190409 | H4W2GR2 1.000.HW00.21.20190812 | H4W4GR1 1.000.HW00.21.20190812 | * H4W4GR1V 1.000.0000.18.20190409 | * HBD8GR1 2.420.HW00.9.20180510 | HBL2GR1 2.420.HW01.33.20190812 | * HBL2GR1V 1.000.0000.18.20190423 | HBL6GR2 1.000.HW04.3.20190813 | HBL6GR2 1.000.HW02.8.20190813 | HBW2GR1 1.000.HW00.21.20190812 | * HBW2GR1V 1.000.0000.18.20190409 | HBW2GR3 1.000.HW00.21.20190812 | * HBW2GR3V 1.000.0000.18.20190409 | HBW4GR1 1.000.HW00.21.20190812 | * HBW4GR1V 1.000.0000.18.20190409 | * HCD8G 2.420.HW00.9.20180510 | HCL2G 1.000.0000.18.20190423 | * HCL2GV 1.000.0000.18.20190423 | HCW2G 1.000.HW00.21.20190812 | * HCW2GV 1.000.0000.18.20190409 | HCW4G 1.000.HW00.21.20190812 | * HDZ302D 1.000.0041.20180530 | * HDZ302DE 1.000.0041.20180530 | * HDZ302DIN 1.000.0041.20180530 | * HDZ302DIN-C1 1.000.0041.20180530 | * HDZ302DIN-S1 1.000.0041.20180530 | * HDZ302LIK 1.000.61.1.20180607 | * HDZ302LIW 1.000.61.1.20180607 | * HFD6GR1 1.000.HW00.9.20180510 | * HFD8GR1 1.000.HW00.9.20180510 | HM4L8GR1 1.000.HW02.8.20190813 | HMBL8GR1 1.000.HW02.8.20190813. Performance Series Cameras and versions affected: H4D8PR1 1.000.HW01.3.20190820 | HFD5PR1 1.000.HW01.1.20190822 | HPW2P1 1.000.HW01.3.20190820 | * HDZP304DI 1.000.HW10.5.20190812 | * HDZP252DI 1.000.HW02.3.20181109.,CVE-2019-18230,7.5,High,CWE-306,Commercial Facilities; Critical Manufacturing; Energy; Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1195,10/31/2019,10/31/2019,2019,ICSA-19-304-04,Honeywell equIP and Performance Series IP Cameras and Recorders,Honeywell,equIP and Performance Series IP Cameras and Recorders,equIP Series Cameras and version: H2W2GR1 1.000.0000.19.20190819 | H3W2GR1 1.000.HW00.21.20190812 | H3W2GR1V 1.000.0000.19.20190819 | H3W2GR2 1.000.HW00.21.20190812 | H3W4GR1 1.000.HW00.21.20190812 | H3W4GR1V 1.000.0000.19.20190819 | H4D8GR1 2.420.HW00.12.20190819 | H4L2GR1 2.420.HW01.33.20190812 | H4L2GR1V 1.000.0000.19.20190819 | H4L6GR2 1.000.HW02.8.20190813 | H4W2GR1 1.000.HW00.21.20190812 | H4W2GR1V 1.000.0000.19.20190819 | H4W2GR2 1.000.HW00.21.20190812 | H4W4GR1 1.000.HW00.21.20190812 | H4W4GR1V 1.000.0000.19.20190819 | HBD8GR1 2.420.HW00.12.20190819 | HBL2GR1 2.420.HW01.33.20190812 | HBL2GR1V 1.000.0000.19.20190819 | HBL6GR2 1.000.HW02.8.20190813 | HBW2GR1 1.000.HW00.21.20190812 | HBW2GR1V 1.000.0000.19.20190819 | HBW2GR3 1.000.HW00.21.20190812 | HBW2GR3V 1.000.0000.19.20190819 | HBW4GR1 1.000.HW00.21.20190812 | HBW4GR1V 1.000.0000.19.20190819 | HCD8G 2.420.HW00.12.20190819 | HCL2G 2.420.HW01.33.20190812 | HCL2GV 1.000.0000.19.20190819 | HCPB302 1.000.0040.3.20190820 | HCW2G 1.000.HW00.21.20190812 | HCW2GV 1.000.0000.19.20190819 | HCW4G 1.000.HW00.21.20190812 | HDZ302D 1.000.0043.6.20190820 | HDZ302DE 1.000.0043.6.20190820 | HDZ302DIN 1.000.0043.6.20190820 | HDZ302DIN-C1 1.000.0043.6.20190820 | HDZ302DIN-S1 1.000.0043.6.20190820 | HDZ302LIK 1.000.0062.3.20190816 | HDZ302LIW 1.000.0062.3.20190816 | HEPB302W01A04 1.000.0040.3.20190820 | HEPB302W01A10 1.000.0040.3.20190820 | HEPZ302W0 1.000.0039.3.20190820 | HFD6GR1 1.000.HW00.12.20190819 | HFD8GR1 1.000.HW00.12.20190819 | HM4L8GR1 1.000.HW02.8.20190813 | HMBL8GR1 1.000.HW02.8.20190813 | HSW2G1 2.460.HW00.5.R.20190827 | HSW2G1 2.460.HW00.5.R.20190827 | HSWB2G1 2.460.HW00.5.R.20190827 | HSWB2G1 2.460.HW00.5.R.20190827 | Performance Series Cameras and version: H2W2PC1M 1.000.HW01.3.20190820 | H2W2PER3 1.000.HW01.3.20190820 | H2W2PRV3 1.000.HW01.1.190813 | H2W4PER3 1.000.HW01.3.20190820 | H2W4PRV3 1.000.HW01.1.190813 H4D3PRV2 1.000.HW01.1.190814 | H4D3PRV3 1.000.HW01.1.190814 | H4D8PR1 1.000.HW01.3.20190820 | H4W2PER2 1.000.HW01.3.20190820 | H4W2PER3 1.000.HW01.3.20190820 | H4W2PRV2 1.000.HW01.1.190814 | H4W4PER2 1.000.HW01.3.20190820 | H4W4PER3 1.000.HW01.3.20190820 | H4W4PRV2 1.000.HW01.1.190814 | H4W4PRV3 1.000.HW01.1.190813 | H4W8PR2 1.000.HW01.3.20190820 | HBD2PER1 1.000.HW01.3.20190820 | HBD3PR1 1.000.HW01.1.190814 | HBD3PR2 1.000.HW01.1.190814 | HBD8PR1 1.000.HW01.3.20190820 | HBW2PER1 1.000.HW01.3.20190820 | HBW2PER2 1.000.HW01.3.20190820 | HBW2PR1 1.000.HW01.1.190813 | HBW2PR2 1.000.HW01.1.190814 | HBW4PER1 1.000.HW01.3.20190820 | HBW4PER2 1.000.HW01.3.20190820 | HBW4PR1 1.000.HW01.1.190813 | HBW4PR2 1.000.HW01.1.190814 | HBW8PR2 1.000.HW01.3.20190820 | HDZP252DI 1.000.HW02.4.20190813 | HDZP304DI 1.000.HW10.5.20190812 | HED2PER3 1.000.HW01.3.20190820 | HED3PR3 1.000.HW01.1.190814 | HED8PR1 1.000.HW01.3.20190820 | HEW2PER2 1.000.HW01.3.20190820 | HEW2PER3 1.000.HW01.3.20190820 | HEW2PR1 1.000.HW01.1.190813 | HEW2PR2 1.000.HW01.1.190814 | HEW2PRW1 1.000.HW01.1.190813 | HEW4PER2 1.000.HW01.3.20190820 | HEW4PER2B 1.000.HW01.3.20190820 | HEW4PER3 1.000.HW01.3.20190820 | HEW4PER3B 1.000.HW01.3.20190820 | HEW4PR2 1.000.HW01.1.190814 | HEW4PR3 1.000.HW01.1.190813 | HEW4PRW3 1.000.HW01.1.190813 | HFD5PR1 1.000.HW01.1.20190822 | HPW2P1 1.000.HW01.3.20190820 | Recorders and versions affected: HEN04102 2.000.HW00.0.R.20190823 | HEN04112 2.000.HW00.0.R.20190823 | HEN04122 2.000.HW00.0.R.20190823 | HEN08102 2.000.HW00.0.R.20190823 | HEN08112 2.000.HW00.0.R.20190823 | HEN08122 2.000.HW00.0.R.20190823 | HEN08142 2.000.HW00.0.R.20190823 | HEN08162 2.000.HW00.0.R.20190823 | HEN16102 2.000.HW00.0.R.20190823 | HEN16122 2.000.HW00.0.R.20190823 | HEN16142 2.000.HW00.0.R.20190823 | HEN16162 2.000.HW00.0.R.20190823 | HEN04103 3.215.00HW001.2.20190821 | HEN04113 3.215.00HW001.2.20190821 | HEN04123 3.215.00HW001.2.20190821 | HEN08103 3.215.00HW001.2.20190821 | HEN08113 3.215.00HW001.2.20190821 | HEN08123 3.215.00HW001.2.20190821 | HEN08143 3.215.00HW001.2.20190821 | HEN16103 3.215.00HW001.2.20190821 | HEN16123 3.215.00HW001.2.20190821 | HEN16143 3.215.00HW001.2.20190821 | HEN16163 3.215.00HW001.2.20190821 | HEN04103L 3.215.00HW001.2.20190821 | HEN08103L 3.215.00HW001.2.20190821 | HEN16103L 3.215.00HW001.2.20190821 | HEN32103L 3.215.00HW001.2.20190821 | HEN08104 3.215.00HW002.2.20190829 | HEN08144 3.215.00HW002.2.20190829 | HEN081124 3.215.00HW002.2.20190829 | HEN16104 3.215.00HW002.2.20190829 | HEN16144 3.215.00HW002.2.20190829 | HEN16184 3.215.00HW002.2.20190829 | HEN32104 3.215.00HW002.2.20190829 | HEN321124 3.215.00HW002.2.20190829 | HEN16204 3.215.00HW002.2.20190829 | HEN16284 3.215.00HW002.2.20190829 | HEN162244 3.215.00HW002.2.20190829 | HEN32204 3.215.00HW002.2.20190829 | HEN32284 3.215.00HW002.2.20190829 | HEN322164 3.215.00HW002.2.20190829 | HEN64204 3.215.00HW002.2.20190829 | HEN642164 3.215.00HW002.2.20190829 | HEN16304 3.215.00HW002.2.20190829 | HEN16384 3.215.00HW002.2.20190829 | HEN32304 3.215.00HW002.2.20190829 | HEN32384 3.215.00HW002.2.20190829 | HEN323164 3.215.00HW002.2.20190829 | HEN64304 3.215.00HW002.2.20190829 | HEN643164 3.215.00HW002.2.20190829 | HEN643324 3.215.00HW002.2.20190829 | HEN643484 3.215.00HW002.2.20190829 |HRHT4040 1.000.00HW001.2.190822 | HRHT4041 1.000.00HW001.2.190822 | HRHT4042 1.000.00HW001.2.190822 | HRHT4080 1.000.00HW001.2.190822 | HRHT4082 1.000.00HW001.2.190822 | HRHT4084 1.000.00HW001.2.190822 | HRHT4160 1.000.00HW001.2.190822 | HRHT4162 1.000.00HW001.2.190822 | HRHT4164 1.000.00HW001.2.190822 | HRHT4166 1.000.00HW001.2.190822 | HRHT41612 1.000.00HW001.2.190822 | HRHQ1040 1.000.00HW001.1.190822 | HRHQ1040L 1.000.00HW001.1.190822 | HRHQ1041 1.000.00HW001.1.190822 | HRHQ1080 1.000.00HW001.1.190822 | HRHQ1080L 1.000.00HW001.1.190822 | HRHQ1081 1.000.00HW001.1.190822 | HRHQ1082 1.000.00HW001.1.190822 | HRHQ1160 1.000.00HW001.1.190822 | HRHQ1161 1.000.00HW001.1.190822 | HRHQ1162 1.000.00HW001.1.190822 | HRHQ1164 1.000.00HW001.1.190822 |,CVE-2019-18226,7.5,High,CWE-294,Commercial Facilities; Critical Manufacturing; Energy; Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1194,10/29/2019,10/29/2019,2019,ICSA-19-302-01,PHOENIX CONTACT Automation Worx Software Suite,PHOENIX CONTACT,Automation Worx Software Suite,PC Worx Versions 1.86 and prior PC Worx Express Versions 1.86 and prior Config+ Versions 1.86 and prior,CVE-2019-16675,7.8,High,CWE-20,Communications; Critical Manufacturing; Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1193,2/26/2019,10/24/2019,2019,ICSA-19-057-01,"Moxa IKS, EDS (Update A)",Moxa,"IKS, EDS",IKS-G6824A series Version 5.6 and prior EDS-405A series Version 3.8 and prior EDS-408A series Version 3.8 and prior EDS-510A series Version 3.8 and prior.,"CVE-2019-6518, CVE-2019-6520, CVE-2019-6522, CVE-2019-6524, CVE-2019-6526, CVE-2019-6557, CVE-2019-6559, CVE-2019-6561, CVE-2019-6563, CVE-2019-6565",9.8,Critical,"CWE-120, CWE-352, CWE-79, CWE-284, CWE-307, CWE-311, CWE-125, CWE-256, CWE-341, CWE-400",Critical Manufacturing; Energy; Transportation,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1192,10/24/2019,10/24/2019,2019,ICSMA-19-297-01,Philips IntelliSpace Perinatal,Philips,IntelliSpace Perinatal,Versions of IntelliSpace Perinatal - obstetrics information management system are affected: IntelliSpace Perinatal Versions K and prior.,CVE-2019-13546,6.1,Medium,CWE-668,Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1191,10/24/2019,10/24/2019,2019,ICSA-19-297-01,Rittal Chiller SK 3232-Series,Rittal,Chiller SK 3232-Series,Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 - B1.2.4.,"CVE-2019-13549, CVE-2019-13553",9.1,Critical,"CWE-306, CWE-798",Commercial Facilities; Communications; Critical Manufacturing; Energy; Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1190,10/24/2019,10/24/2019,2019,ICSA-19-297-02,Honeywell IP-AK2,Honeywell,IP-AK2,IP-AK2 Access Control Panel Version 1.04.07 and prior.,CVE-2019-13525,5.3,Medium,CWE-306,Commercial Facilities; Critical Manufacturing; Energy; Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1189,10/22/2019,10/22/2019,2019,ICSA-19-295-01,Schneider Electric ProClima,Schneider Electric,ProClima,ProClima building and automation control products: ProClima: all versions prior to 8.0.0.,"CVE-2019-6823, CVE-2019-6824, CVE-2019-6825",9.8,Critical,"CWE-94, CWE-119, CWE-427",Commercial Facilities; Critical Manufacturing; Energy,"United States, Asia, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1188,10/17/2019,10/23/2019,2019,ICSA-19-290-02,Horner Automation Cscape,Horner Automation,Cscape,Cscape 9.90 and prior.,"CVE-2019-13541, CVE-2019-13545",7.5,High,"CWE-20, CWE-787",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1187,7/11/2019,7/11/2019,2019,ICSA-19-192-02,Siemens SIMATIC WinCC and PCS7 (Update C),Siemens,SIMATIC WinCC and PCS7,SIMATIC PCS 7 v8.0: all versions SIMATIC PCS 7 v8.1: all versions prior to v8.1 with WinCC v7.3 Upd 19 SIMATIC PCS 7 v8.2: all versions prior to v8.2 SP1 with WinCC v7.4 SP1 Upd 11 SIMATIC PCS 7 v9.0: all versions prior to v9.0 SP2 with WinCC v7.4 SP1 Upd 11 SIMATIC WinCC Professional (TIA Portal v13): all versions,CVE-2019-10935,7.2,High,CWE-434,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1186,5/14/2019,5/14/2019,2019,ICSA-19-134-08,"Siemens SIMATIC PCS7, WinCC, TIA Portal (Update D)",Siemens,"SIMATIC PCS7, WinCC, TIA Portal",Siemens SIMATIC products affected: SIMATIC WinCC (TIA Portal v14): all versions prior to v14 SP1 Upd 9 SIMATIC WinCC (TIA Portal v15): all versions prior to v15.1 Upd 3 SIMATIC WinCC Runtime Professional v14: all versions prior to v14.1 Upd 8 SIMATIC WinCC Runtime Professional v15: all versions prior to v15.1 Upd 3. SIMATIC PCS7 v8.0 and earlier: all versions SIMATIC PCS7 v8.1: all versions prior to v8.1 with WinCC v7.3 Upd 19 SIMATIC PCS7 v8.2: all versions prior to v8.2 SP1 with WinCC v7.4 SP1 Upd 11 SIMATIC PCS7 v9.0: all versions prior to v9.0 SP2 with WinCC v7.4 SP1 Upd 11 SIMATIC WinCC (TIA Portal) v13: all versions SIMATIC WinCC Runtime Professional v13: all versions SIMATIC WinCC v7.2 and earlier: all versions SIMATIC WinCC v7.3: all versions prior to v7.3 Upd 19 SIMATIC WinCC v7.4: all versions prior to v7.4 with WinCC v7.4 SP1 Upd 11 SIMATIC WinCC v7.5: all versions prior to v7.5 Upd 3.,"CVE-2019-10916, CVE-2019-10917, CVE-2019-10918",9.1,Critical,"CWE-749, CWE-89, CWE-248",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1185,5/3/2018,10/10/2019,2019,ICSMA-18-123-01,Philips Brilliance Computed Tomography (CT) System (Update A),Philips,Brilliance Computed Tomography (CT) System,Philips reports the vulnerabilities affect the following Brilliance CT Scanners: Brilliance 64 Versions 2.6.2 and below Brilliance iCT Versions 4.1.6 and below Brilliance iCT SP Versions 3.2.4 and below Brilliance CT Big Bore Versions 2.3.5 and below. MX8000 Dual EXP Systems (CVE-2018-8857 only).,"CVE-2018-8853, CVE-2018-8861, CVE-2018-8857",8.4,High,"CWE-250, CWE-668, CWE-798",Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1184,11/8/2016,11/8/2016,2019,ICSA-16-313-02,Siemens Industrial Products Local Privilege Escalation Vulnerability (Update I),Siemens,Industrial Products,Siemens Primary Setup Tool (PST): All versions prior to v4.2 HF1 SIMATIC IT Production Suite: All versions prior to v7.0 SP1 HFX 2 SIMATIC NET PC-Software: All versions prior to v14 SIMATIC PCS 7 v7.1 and earlier versions SIMATIC PCS 7 v8.0: All versions SIMATIC PCS 7 v8.1: All versions SIMATIC PCS 7 v8.2: All versions prior to v8.2 SP1 SIMATIC STEP 7 (TIA Portal) v13: All versions prior to v13 SP2 SIMATIC STEP 7 v5.X: All versions prior to v5.5 SP4 HF11 | SIMATIC WinAC RTX (F) 2010 SP2: All versions prior to SIMATIC WinAC RTX 2010 SP3 | SIMATIC WinCC (TIA Portal) Basic | Comfort | Advanced: All versions prior to v14 SIMATIC WinCC (TIA Portal) Professional v13: All versions prior to v13 SP2 SIMATIC WinCC (TIA Portal) Professional v14: All versions prior to v14 SP1 SIMATIC WinCC Runtime Professional v13: All versions prior to v13 SP2 SIMATIC WinCC Runtime Professional v14: All versions prior to v14 SP1 SIMATIC WinCC v7.0 SP2 and earlier versions prior to v7.0 SP2 Update 12 SIMATIC WinCC v7.0 SP3: All versions prior to v7.0 SP3 Update 8 SIMATIC WinCC v7.2: All versions prior to v7.2 Update 14 SIMATIC WinCC v7.3: All versions prior to v7.3 Update 11 SIMATIC WinCC v7.4: All versions prior to v7.4 SP1 SIMIT: All versions prior to v9.0 SP1 SINEMA Remote Connect Client: All versions prior to v1.0 SP3 SINEMA Server: All versions prior to v13 SP2 SOFTNET Security Client v5.0: All versions Security Configuration Tool (SCT): All versions prior to v4.3 HF1 TeleControl Server Basic: All versions prior to v3.0 SP2.,CVE-2016-7165,6.4,Medium,CWE-269,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1183,10/8/2019,10/8/2019,2019,ICSA-19-281-01,SMA Solar Technology AG Sunny WebBox,SMA Solar Technology AG,Sunny WebBox,Sunny WebBox Firmware versions affected: Version 1.6 and prior.,CVE-2019-13529,9.6,Critical,CWE-352,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1182,10/8/2019,10/15/2019,2019,ICSA-19-281-02,GE Mark VIe Controller,GE,Mark VIe Controller,All versions of the GE Mark VIe Controller are affected by at least one of the vulnerabilities. Some versions are affected by both. For more information contact GE.,"CVE-2019-13554, CVE-2019-13559",6.8,Medium,"CWE-285, CWE-798",Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1181,10/8/2019,10/8/2019,2019,ICSA-19-281-04,Siemens SIMATIC IT UADM,Siemens,SIMATIC IT UADM,SIMATIC IT UADM: All versions prior to 1.3.,CVE-2019-13929,6.8,Medium,CWE-321,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1180,10/1/2019,10/1/2019,2019,ICSA-19-274-02,Yokogawa Products,Yokogawa,Products,Exaopc (R1.01.00 - R3.77.00) Exaplog (R1.10.00 - R3.40.00) Exaquantum (R1.10.00 - R3.02.00) Exaquantum/Batch (R1.01.00 - R2.50.40) Exasmoc (All Revisions) Exarqe (All Revisions) GA10 (R1.01.01 - R3.05.01) InsightSuiteAE (R1.01.00 - R1.06.00).,CVE-2019-6008,8.4,High,CWE-428,Critical Manufacturing; Energy; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1179,10/1/2019,10/2/2019,2019,ICSA-19-274-03,Moxa EDR 810 Series,Moxa,EDR 810 Series,Moxa EDR 810 router version affected: All versions 5.1 and prior.,"CVE-2019-10963, CVE-2019-10969",7.2,High,"CWE-284, CWE-20",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1178,9/19/2019,9/19/2019,2019,ICSA-19-262-01,Tridium Niagara,Tridium,Niagara,The following Tridium products are affected: Niagara AX 3.8u4 (JACE 3e | JACE 6e | JACE 7 | JACE-8000) Niagara 4.4u3 (JACE 3e | JACE 6e | JACE 7 | JACE-8000) Niagara 4.7u1 (JACE-8000 | Edge 10) Niagara Windows and Linux Supervisor installations are not impacted.,"CVE-2019-8998, CVE-2019-13528",7.8,High,"CWE-200, CWE-285",Commercial Facilities; Critical Manufacturing; Government Facilities; Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1177,9/17/2019,9/18/2019,2019,ICSA-19-260-01,Advantech WebAccess,Advantech,WebAccess,WebAccess - HMI platform versions affected: Versions 8.4.1 and prior.,"CVE-2019-13550, CVE-2019-13552, CVE-2019-13556, CVE-2019-13558",9.8,Critical,"CWE-285, CWE-94, CWE-77, CWE-121",Critical Manufacturing; Energy; Water and Wastewater,"East Asia, United States, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1176,9/17/2019,9/17/2019,2019,ICSA-19-260-02,Siemens SINEMA Remote Connect Server,Siemens,SINEMA Remote Connect Server,SINEMA Remote Connect Server versions prior to 2.0 SP1.,"CVE-2019-13918, CVE-2019-13920, CVE-2019-13922, CVE-2019-34623",8.1,High,"CWE-352, CWE-200, CWE-307, CWE-916",Food and Agriculture; Chemical; Critical Manufacturing; Energy; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1175,9/17/2019,9/17/2019,2019,ICSA-19-260-03,Honeywell Performance IP Cameras and Performance NVRs,Honeywell,Performance IP Cameras and Performance NVRs,Versions of Honeywell Performance IP Series cameras and Performance Series NVRs affected: HBD3PR2 H4D3PRV3 HED3PR3 H4D3PRV2 HBD3PR1 H4W8PR2 HBW8PR2 H2W2PC1M H2W4PER3 H2W2PER3 HEW2PER3 HEW4PER3B HBW2PER1 HEW4PER2 HEW4PER2B HEW2PER2 H4W2PER2 HBW2PER2 H4W2PER3 HPW2P1 Performance Series NVRs: HEN08104 HEN08144 HEN081124 HEN16104 HEN16144 HEN16184 HEN16204 HEN162244 HEN16284 HEN16304 HEN16384 HEN32104 HEN321124 HEN32204 HEN32284 HEN322164 HEN32304 HEN32384 HEN323164 HEN64204 HEN64304 HEN643164 HEN643324 HEN643484 HEN04103 HEN04113 HEN04123 HEN08103 HEN08113 HEN08123 HEN08143 HEN16103 HEN16123 HEN16143 HEN16163 HEN04103L HEN08103L HEN16103L HEN32103L.,CVE-2019-13523,5.3,Medium,CWE-200,Commercial Facilities; Critical Manufacturing; Energy; Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1174,9/12/2019,9/12/2019,2019,ICSMA-19-255-01,Philips IntelliVue WLAN,Philips,IntelliVue WLAN,"Philips IntelliVue WLAN - portable patient monitors affected: IntelliVue MP monitors MP20-MP90 (M8001A/2A/3A/4A/5A/7A/8A/10A) WLAN Version A, Firmware A.03.09 IntelliVue MP monitors MP5/5SC (M8105A/5AS) WLAN Version A, Firmware A.03.09, Part #: M8096-67501 IntelliVue MP monitors MP2/X2 (M8102A/M3002A) WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C) IntelliVue MP monitors MX800/700/600 ((865240/41/42) WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C).","CVE-2019-13530, CVE-2019-13534",6.4,Medium,"CWE-494, CWE-259",Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1173,9/12/2019,9/12/2019,2019,ICSA-19-255-01,3S-Smart Software Solutions GmbH CODESYS V3 Web Server,3S-Smart Software Solutions,CODESYS V3 Web Server,"CODESYS V3 runtime systems, all versions prior to 3.5.14.10, containing the web server (CmpWebServer) affected: CODESYS Control for BeagleBone CODESYS Control for emPC-A/iMX6 CODESYS Control for IOT2000 CODESYS Control for Linux CODESYS Control for PFC100 CODESYS Control for PFC200 CODESYS Control for Raspberry Pi CODESYS Control RTE V3 CODESYS Control RTE V3 (for Beckhoff CX) CODESYS Control Win V3 (also part of the CODESYS Development System setup) CODESYS HMI V3 CODESYS Control V3 Runtime System Toolkit CODESYS V3 Embedded Target Visu Toolkit CODESYS V3 Remote Target Visu Toolkit.","CVE-2019-13532, CVE-2019-13548",10.0,Critical,"CWE-22, CWE-121",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1172,9/12/2019,9/12/2019,2019,ICSA-19-255-03,3S-Smart Software Solutions GmbH CODESYS Control V3 Online User Management,3S-Smart Software Solutions,CODESYS Control V3 Online User Management,CODESYS V3 runtime systems - all versions prior to 3.5.13.0 containing the CmpUserMgr component affected: CODESYS Control for BeagleBone CODESYS Control for emPC-A/iMX6 CODESYS Control for IOT2000 CODESYS Control for PFC100 CODESYS Control for PFC200 CODESYS Control for Raspberry Pi CODESYS Control RTE V3 CODESYS Control RTE V3 (for Beckhoff CX) CODESYS Control Win V3 (also part of the CODESYS Development System setup) CODESYS V3 Simulation Runtime (part of the CODESYS Development System) CODESYS HMI V3.,CVE-2019-9008,8.8,High,CWE-732,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1171,9/12/2019,9/12/2019,2019,ICSA-19-255-04,3S-Smart Software Solutions GmbH CODESYS Control V3 OPC UA Server,3S-Smart Software Solutions,CODESYS Control V3 OPC UA Server,CODESYS V3 runtime systems - all versions 3.5.11.0 to 3.5.15.0 containing the CODESYS OPC UA server supporting OPC UA Security affected: CODESYS Control for BeagleBone CODESYS Control for emPC-A/iMX6 CODESYS Control for IOT2000 CODESYS Control for Linux CODESYS Control for PFC100 CODESYS Control for PFC200 CODESYS Control for Raspberry Pi CODESYS Control RTE V3 CODESYS Control RTE V3 (for Beckhoff CX) CODESYS Control Win V3 (also part of the CODESYS Development System setup) CODESYS Control V3 Runtime System Toolkit.,CVE-2019-13542,6.5,Medium,CWE-476,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1170,9/12/2019,9/12/2019,2019,ICSA-19-255-05,3S-Smart Software Solutions GmbH CODESYS V3 Products Containing a CODESYS Communication Server,3S-Smart Software Solutions,CODESYS V3 Products Containing a CODESYS Communication Server,CODESYS V3 runtime systems - all versions prior to 3.5.15.0 containing communication server for the CODESYS communication protocol affected: CODESYS Control for BeagleBone CODESYS Control for emPC-A/iMX6 CODESYS Control for IOT2000 CODESYS Control for Linux CODESYS Control for PFC100 CODESYS Control for PFC200 CODESYS Control for Raspberry Pi CODESYS Control RTE V3 CODESYS Control RTE V3 (for Beckhoff CX) CODESYS Control Win V3 (part of the CODESYS Development System setup) CODESYS Control V3 Runtime System Toolkit CODESYS V3 Safety SIL2 CODESYS Gateway V3 CODESYS HMI V3 CODESYS V3 Simulation Runtime (part of the CODESYS Development System).,CVE-2019-9009,7.5,High,CWE-390,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1169,9/10/2019,9/10/2019,2019,ICSA-19-253-01,Delta Electronics TPEditor,Delta Electronics,TPEditor,Versions of the TPEditor - programming software for Delta text panels affected: TPEditor Versions 1.94 and prior.,"CVE-2019-13536, CVE-2019-13540, CVE-2019-13544",7.8,High,"CWE-122, CWE-787, CWE-121",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1168,9/10/2019,9/10/2019,2019,ICSA-19-253-02,Siemens SINETPLAN,Siemens,SINETPLAN,SINETPLAN - automation systems planner version affected: SINETPLAN Version 2.0.,CVE-2019-10915,8.0,High,CWE-285,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1167,9/10/2019,9/10/2019,2019,ICSA-19-253-04,Siemens IE-WSN-PA Link WirelessHART Gateway,Siemens,IE-WSN-PA Link WirelessHART Gateway,All versions of IE/WSN-PA Link WirelessHART Gateway are affected.,CVE-2019-13923,7.5,High,CWE-79,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1166,9/10/2019,9/10/2019,2019,ICSA-19-253-05,Siemens SIMATIC TDC CP51M1,Siemens,SIMATIC TDC CP51M1,SIMATIC TDC CP51M1 - multiprocessor automation system version affected: All versions prior to 1.1.7.,CVE-2019-10937,7.5,High,CWE-20,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1165,9/10/2019,9/10/2019,2019,ICSA-19-253-06,OSIsoft PI SQL Client,OSIsoft,PI SQL Client,OSIsoft PI SQL Client - component interface that enables data access via SQL queries to the PI System affected: PI SQL Client OLEDB 2018.,CVE-2017-9765,8.1,High,CWE-190,Commercial Facilities; Critical Manufacturing; Energy; Government Facilities; Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1164,9/5/2019,10/8/2019,2019,ICSMA-19-248-01,BD Pyxis (Update A),"Becton, Dickinson and Company (BD)",Pyxis,"Pyxis ES Versions 1.3.4 through to 1.5.3 Pyxis Enterprise Server, with Windows Server Versions 4.4 through 4.12.",CVE-2019-13517,7.6,High,CWE-384,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1163,9/5/2019,9/16/2019,2019,ICSA-19-248-01,Red Lion Controls Crimson,Red Lion Controls,Crimson,Crimson - windows configuration software versions affected: Crimson Versions 3.0 and prior Crimson Versions 3.1 prior to release 3112.00.,"CVE-2019-10978, CVE-2019-10984, CVE-2019-10990, CVE-2019-10996",7.8,High,"CWE-119, CWE-465, CWE-416, CWE-321",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1162,9/3/2019,9/3/2019,2019,ICSA-19-246-01,EZAutomation EZ Touch Editor,EZAutomation,EZ Touch Editor,EZ Touch Editor - Human-Machine Interface editor version affected: Versions 2.1.0 and prior.,CVE-2019-13518,7.8,High,CWE-121,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1161,9/3/2019,9/3/2019,2019,ICSA-19-246-02,EZAutomation EZ PLC Editor,EZAutomation,EZ PLC Editor,EZ PLC Editor Versions 1.8.41 and prior.,CVE-2019-13522,7.8,High,CWE-119,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1160,8/29/2019,8/29/2019,2019,ICSMA-19-241-01,Change Healthcare McKesson and Horizon Cardiology,Change Healthcare,McKesson and Horizon Cardiology,Change Health Cardiology Devices affected: Horizon Cardiology 11.x and earlier Horizon Cardiology 12.x McKesson Cardiology 13.x McKesson Cardiology 14. x Change Healthcare Cardiology 14.1.x.,CVE-2018-18630,7.8,High,CWE-276,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1159,8/29/2019,8/29/2019,2019,ICSMA-19-241-02,Philips HDI 4000 Ultrasound,Philips,HDI 4000 Ultrasound,"Philips HDI 4000 Ultrasound systems - diagnostic ultrasound system - affected versions: All versions running on old, unsupported operating systems such as Windows 2000.",CVE-2019-10988,3.0,Low,CWE-477,Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1158,8/27/2019,8/27/2019,2019,ICSA-19-239-01,Delta Controls enteliBUS Controllers,Delta Controls,enteliBUS Controllers,Delta Controls enteliBUS - industrial control system versions affected: enteliBUS Manager firmware Versions 3.40 R5 build 571848 and prior enteliBUS Manager Touch (eBMGR-TCH) firmware Versions 3.40 R5 build 571848 and prior enteliBUS Controller (eBCON) firmware Versions 3.40 R5 build 571848 and prior.,CVE-2019-9569,9.8,Critical,CWE-120,Commercial Facilities; Government Facilities,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1157,8/27/2019,8/27/2019,2019,ICSA-19-239-02,Datalogic AV7000 Linear Barcode Scanner,Datalogic,AV7000 Linear Barcode Scanner,AV7000 - linear barcode scanner versions affected: All versions prior to 4.6.0.0.,CVE-2019-13526,8.8,High,CWE-288,Critical Manufacturing,Worldwide,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1156,8/20/2019,8/20/2019,2019,ICSA-19-232-01,Zebra Industrial Printers,Zebra,Industrial Printers,All Zebra Industrial Printers.,CVE-2019-10960,5.3,Medium,CWE-522,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1155,8/15/2019,8/15/2019,2019,ICSA-19-227-01,Johnson Controls Metasys,Johnson Controls Inc.,Metasys,Metasys building automation system versions affected: versions prior to 9.0.,"CVE-2019-7593, CVE-2019-7594",6.8,Medium,"CWE-323, CWE-321",Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1154,8/15/2019,8/15/2019,2019,ICSA-19-227-02,Fuji Electric Alpha5 Smart Loader,Fuji Electric,Alpha5 Smart Loader,Alpha5 Smart Loader: All versions prior to 4.2.,CVE-2019-13520,7.8,High,CWE-121,Commercial Facilities; Critical Manufacturing,"Europe, Asia",Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1153,8/13/2019,8/13/2019,2019,ICSA-19-225-01,Delta Industrial Automation DOPSoft,Delta Electronics,DOPSoft,DOPSoft - Human Machine Interface editing software versions affected: Version 4.00.06.15 and prior.,"CVE-2019-13513, CVE-2019-13514",7.8,High,"CWE-125, CWE-416",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1152,8/13/2019,8/13/2019,2019,ICSA-19-225-02,OSIsoft PI Web API,OSIsoft,PI Web API,"OSIsoft PI Web API, a RESTful service access layer, are affected: PI Web API 2018 and prior.","CVE-2019-13515, CVE-2019-13516",8.5,High,"CWE-532, CWE-693",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Government Facilities; Healthcare and Public Health; Information Technology; Metals and Mining; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1151,8/1/2019,8/1/2019,2019,ICSA-19-213-01,Advantech WebAccess HMI Designer,Advantech,WebAccess HMI Designer,Advantech WebAccess HMI Designer Version 2.1.9.23 and prior.,CVE-2019-10961,7.8,High,CWE-787,Critical Manufacturing; Energy; Water and Wastewater,"East Asia, Europe, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1150,8/1/2019,8/5/2019,2019,ICSA-19-213-02,Fuji Electric FRENIC Loader,Fuji Electric,FRENIC Loader,"FRENIC Loader, an AC drive, are affected: FRENIC Loader 3.5.0.0 and prior.",CVE-2019-13512,4.4,Medium,CWE-125,Commercial Facilities,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1149,8/1/2019,8/1/2019,2019,ICSA-19-213-03,3S-Smart Software Solutions GmbH CODESYS V3,3S-Smart Software Solutions,CODESYS V3,"CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone CODESYS Control for emPC-A/iMX6 CODESYS Control for IOT2000 CODESYS Control for Linux CODESYS Control for PFC100 CODESYS Control for PFC200 CODESYS Control for Raspberry Pi CODESYS Control V3 Runtime System Toolkit CODESYS Gateway V3 CODESYS V3 Development System.","CVE-2019-9010, CVE-2019-9012",9.0,Critical,"CWE-789, CWE-283",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1148,8/1/2019,8/1/2019,2019,ICSA-19-213-06,LCDS LAquis SCADA LQS File Parsing,LCDS - Leao Consultoria e Desenvolvimento de Sistemas Ltda ME,LAquis SCADA LQS File Parsing,Laquis SCADA industrial automation software version affected: SCADA 4.3.1.71.,"CVE-2019-10980, CVE-2019-10994",7.8,High,"CWE-843, CWE-125",Chemical; Commercial Facilities; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,South America,Brazil,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1147,8/1/2019,9/20/2019,2019,ICSA-19-213-05,Rockwell Automation Arena Simulation Software (Update B),Rockwell Automation,Arena Simulation Software,"Arena Simulation - an event simulationand automation software platform affected: Arena Software for Manufacturing, Cat. 9502-Ax, Versions 16.00.00 and earlier.","CVE-2019-13510, CVE-2019-13511, CVE-2019-13519, CVE-2019-13521, CVE-2019-13527",8.6,High,"CWE-843, CWE-824, CWE-200, CWE-357, CWE-416",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1146,7/30/2019,10/5/2020,2019,ICSA-19-211-01,Wind River VxWorks (Update A),Wind River,VxWorks,"Wind River versions of VxWorks are affected: All versions of VxWorks under CURRENT support (6.9.4.11, Vx7 SR540, Vx7 SR610) are affected by one or more of the CVE numbers detailed below. Older, End-of-Life versions of VxWorks back to 6.5 are also affected by one or more of the CVE numbers below. All versions of the discontinued product Advanced Networking Technology (ANT) are likely affected by one or more of the CVE numbers below. The VxWorks bootrom network stack leverages the same IPnet source as VxWorks and, as a result, is also technically vulnerable to CVE-2019-12256. The same patches and mitigations apply to VxWorks and the bootrom network stack. However, the bootrom normally uses statically assigned IP-addresses, not DHCP. If that is true, then the defects related to those protocols do not apply in practice. Also a successful exploit of the bootrom network stack has a more difficult timing component. In typical applications, the bootrom does not listen to TCP-ports, which means that the TCP-related issues must be timed with the target downloading data from the network. VxWorks 653 MCE 3.x may be affected. Contact Wind River customer support (support@windriver.com) for more details. The following VxWorks products are not affected: The latest release of VxWorks, VxWorks 7 SR620, is NOT affected by any of these CVEs VxWorks 5.3 through VxWorks 6.4 inclusive are NOT affected. VxWorks Cert versions are NOT affected. VxWorks 653 Versions 2.x and earlier are NOT affected. VxWorks 653 MCE 3.x Cert Edition and later are NOT affected.","CVE-2019-12255, CVE-2019-12256, CVE-2019-12257, CVE-2019-12258, CVE-2019-12259, CVE-2019-12260, CVE-2019-12261, CVE-2019-12262, CVE-2019-12263, CVE-2019-12264, CVE-2019-12265",9.8,Critical,"CWE-362, CWE-122, CWE-88, CWE-119, CWE-191, CWE-476, CWE-121",Critical Manufacturing; Information Technology; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1145,7/30/2019,7/30/2019,2019,ICSA-19-211-02,Prima Systems FlexAir,Prima Systems,FlexAir,Prima Systems FlexAir - access control platform versions affected: Prima FlexAir Versions 2.3.38 and prior.,"CVE-2019-7280, CVE-2019-7281, CVE-2019-7666, CVE-2019-7667, CVE-2019-7669, CVE-2019-7670, CVE-2019-7671, CVE-2019-7672, CVE-2019-9189",10.0,Critical,"CWE-78, CWE-434, CWE-352, CWE-334, CWE-79, CWE-530, CWE-287, CWE-798",Commercial Facilities; Government Facilities; Healthcare and Public Health; Information Technology; Transportation Systems,Worldwide,Slovenia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1144,7/23/2019,7/23/2019,2019,ICSA-19-204-01,Mitsubishi Electric FR Configurator2,Mitsubishi Electric,FR Configurator2,Mitsubishi FR Configurator2 - used for configuring Mitsubishi variable frequency drives versions affected: FR Configurator2 Version 1.16S and prior.,"CVE-2019-10972, CVE-2019-10976",7.1,High,"CWE-611, CWE-400",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1143,7/23/2019,7/23/2019,2019,ICSA-19-204-02,NREL EnergyPlus,National Renewable Energy Laboratory (NREL),EnergyPlus,EnergyPlus - Energy simulation program version affected: EnergyPlus Versions 8.6.0 and potentially prior releases.,CVE-2019-10974,6.1,Medium,CWE-121,Energy,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1142,7/18/2019,7/24/2019,2019,ICSA-19-199-01,Johnson Controls exacqVision Server,Exacq Technologies Inc (Subsidiary of Johnson Controls),exacqVision Server,exacqVision server versions affected: Versions 9.6 and 9.8.,CVE-2019-7590,6.7,Medium,CWE-428,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1141,7/11/2019,7/11/2019,2019,ICSMA-19-192-01,Philips Holter 2010 Plus,Philips,Holter 2010 Plus,Holter 2010 Plus - 12-lead EKG analysis software program version affected: all versions.,CVE-2019-10968,1.9,Low,CWE-477,Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1140,7/11/2019,7/11/2019,2019,ICSA-19-192-01,Delta Industrial Automation CNCSoft ScreenEditor,Delta Electronics,CNCSoft ScreenEditor,Delta Electronics - CNCSoft ScreenEditor versions affected: Versions 1.00.89 and prior.,"CVE-2019-10982, CVE-2019-10992",7.8,High,"CWE-122, CWE-125",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1139,7/11/2019,7/11/2019,2019,ICSA-19-192-03,Siemens TIA Administrator (TIA Portal),Siemens,TIA Administrator (TIA Portal),TIA Administrator versions affected: All versions prior to v1.0 SP1 Upd1.,CVE-2019-10915,8.0,High,CWE-284,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1138,7/11/2019,7/11/2019,2019,ICSA-19-192-04,Siemens SIMATIC RF6XXR,Siemens,SIMATIC RF6XXR,All versions prior to 3.2.1 of the following SIMATIC RF6XXR UHF RFID products are affected: RF615R RF68XR.,"CVE-2011-3389, CVE-2013-0169, CVE-2016-6329",5.9,Medium,"CWE-310, CWE-20",Critical Manufacturing; Food and Agriculture; Transportation,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1137,7/11/2019,7/11/2019,2019,ICSA-19-192-05,AVEVA Vijeo Citect and Citect SCADA Floating License Manager,"AVEVA, Schneider Electric",Vijeo Citect and Citect SCADA Floating License Manager,Floating License Manager - used in Vijeo Citect and Citect SCADA - versions affected: Floating License Manager Version 2.3.0.0 and earlier.,"CVE-2018-20031, CVE-2018-20032, CVE-2018-20033, CVE-2018-20034",9.8,Critical,"CWE-20, CWE-119",Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1136,7/11/2019,7/11/2019,2019,ICSA-19-192-06,Schneider Electric Interactive Graphical SCADA System,Schneider Electric,Interactive Graphical SCADA System,IGSS Version 14 and prior.,CVE-2019-6827,7.0,High,CWE-787,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1135,7/11/2019,7/11/2019,2019,ICSA-19-192-07,Schneider Electric Floating License Manager,Schneider Electric,Floating License Manager,Floating License Manager Version 2.3.0.0 and earlier.,"CVE-2018-20031, CVE-2018-20032, CVE-2018-20033, CVE-2018-20034",9.8,Critical,"CWE-20, CWE-119",Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1134,7/9/2019,7/24/2019,2019,ICSMA-19-190-01,GE Aestiva and Aespire Anesthesia (Update A),GE,Aestiva and Aespire Anesthesia,"GE Aestiva 7100, 7900, MRI GE Aespire 7100, 7900, 100, Protiva, Carestation, View GE Aisys, Aisys CS2 Avance, Amingo, Avance CS2 GE Carestation 620, 650, 650c.",CVE-2019-10966,5.3,Medium,CWE-287,Healthcare and Public Health,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1133,7/9/2019,7/9/2019,2019,ICSA-19-190-01,Emerson DeltaV Distributed Control System,Emerson,DeltaV Distributed Control System,Versions of DeltaV DCS - software management platform include the Smart Switch Command Center: 11.3.x 12.3.x.,CVE-2018-11691,6.1,Medium,CWE-798,Chemical; Critical Manufacturing; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1132,7/9/2019,7/9/2019,2019,ICSA-19-190-02,Rockwell Automation PanelView 5510,Rockwell Automation,PanelView 5510,"All versions manufactured before March 13, 2019, that have never been updated to v4.003, v5.002, or later.",CVE-2019-10970,7.5,High,CWE-284,Critical Manufacturing; Food and Agriculture; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1131,7/9/2019,7/9/2019,2019,ICSA-19-190-03,Schneider Electric Zelio Soft 2,Schneider Electric,Zelio Soft 2,Zelio Soft 2 - program platform versions affected: Versions 5.2 and prior.,CVE-2019-6822,7.8,High,CWE-416,Critical Manufacturing,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1130,7/9/2019,8/13/2019,2019,ICSA-19-190-04,Siemens Spectrum Power (Update A),Siemens,Spectrum Power,Versions of Siemens Spectrum Power are affected: Spectrum Power 3 (Corporate User Interface): versions v3.11 and prior Spectrum Power 4 (Corporate User Interface): version v4.75. Spectrum Power 5 (Corporate User Interface): all versions prior to v5.50 and prior. Spectrum Power 7 (Corporate User Interface): versions v2.20 and prior.,CVE-2019-10933,4.7,Medium,CWE-79,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1129,7/2/2019,7/2/2019,2019,ICSA-19-183-01,Schneider Electric Modicon Controllers,Schneider Electric,Modicon Controllers,Versions of Modicon Controllers - PLC and PAC controller for industrial control systems affected: Modicon M340: Firmware versions prior to v3.01 Modicon M580: Firmware versions prior to v2.80 Modicon Quantum: All firmware versions Modicon Premium: All firmware versions.,CVE-2019-6819,7.5,High,CWE-754,Multiple Critical Sectors,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1128,7/2/2019,7/2/2019,2019,ICSA-19-183-02,Quest KACE Systems Management Appliance,Quest,KACE Systems Management Appliance,KACE System Management Appliance (SMA) affected: All versions 8.0.x KACE SMA: All versions 8.1.x KACE SMA: All versions 9.0.x.,CVE-2019-10973,2.7,Low,CWE-20,Information Technology,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1127,6/27/2019,6/27/2019,2019,ICSMA-19-178-01,Medtronic MiniMed 508 and Paradigm Series Insulin Pumps,Medtronic,MiniMed 508 and Paradigm Series Insulin Pumps,Versions of Medtronic MiniMed Insulin Pumps affected: MiniMed 508 pump - All versions MiniMed Paradigm 511 pump - All versions MiniMed Paradigm 512/712 pumps - All versions MiniMed Paradigm 712E pump - All versions MiniMed Paradigm 515/715 pumps - All versions MiniMed Paradigm 522/722 pumps - All versions MiniMed Paradigm 522K/722K pumps - All versions MiniMed Paradigm 523/723 pumps - Software versions 2.4A or lower MiniMed Paradigm 523K/723K pumps - Software versions 2.4A or lower MiniMed Paradigm Veo 554/754 pumps - Software versions 2.6A or lower MiniMed Paradigm Veo 554CM and 754CM models only - Software versions 2.7A or lower.,CVE-2019-10964,7.1,High,CWE-284,Healthcare and Public Health,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1126,6/27/2019,6/27/2019,2019,ICSA-19-178-01,ABB PB610 Panel Builder 600,ABB,PB610 Panel Builder 600,"PB610 Panel Builder 600 - engineering tool for designing HMI applications and the runtime for control panels - used for the operations of automation systems affected: PB610 Panel Builder 600 - order code: 1SAP500900R0101, Versions 1.91 ""¦ 2.8.0.367 and prior.","CVE-2019-7225, CVE-2019-7226, CVE-2019-7227, CVE-2019-7228, CVE-2019-7230, CVE-2019-7231, CVE-2019-7232",8.8,High,"CWE-287, CWE-20, CWE-23, CWE-121, CWE-798",Chemical; Critical Manufacturing; Dams; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1125,6/27/2019,6/27/2019,2019,ICSA-19-178-02,ABB CP651 HMI,ABB,CP651 HMI,"ABB CP651 HMI products affected: CP651, order code: 1SAP551100R0001, revision index B1 with BSP UN30 v1.76 and prior CP651-WEB, order code: 1SAP551200R0001, revision index A0 with BSP UN30 v1.76 and prior CP661, order code: 1SAP561100R0001, revision index B1 with BSP UN30 v1.76 and prior CP661-WEB, order code: 1SAP561200R0001, revision index A0 with BSP UN30 v1.76 and prior CP665, order code: 1SAP565100R0001, revision index B1 with BSP UN30 v1.76 and prior CP665-WEB, order code: 1SAP565200R0001, revision index A0 with BSP UN30 v1.76 and prior CP676, order code: 1SAP576100R0001, revision index B1 with BSP UN30 v1.76 and prior CP676-WEB, order code: 1SAP576200R0001, revision index A0 with BSP UN30 v1.76 and prior.",CVE-2019-10995,8.8,High,CWE-798,Critical Manufacturing,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1124,6/27/2019,6/27/2019,2019,ICSA-19-178-03,ABB CP635 HMI,ABB,CP635 HMI,"ABB CP635 HMI products affected: CP620, order code: 1SAP520100R0001, revision index G1 with BSP UN31 v1.76 and prior CP620, order code: 1SAP520100R4001, revision index G1 with BSP UN31 v1.76 and prior CP620-WEB, order code: 1SAP520200R0001, revision index G1 with BSP UN31 v1.76 and prior CP630, order code: 1SAP530100R0001, revision index G1 with BSP UN31 v1.76 and prior CP630-WEB, order code: 1SAP530200R0001, revision index G1 with BSP UN31 v1.76 and prior CP635, order code: 1SAP535100R0001, revision index G1 with BSP UN31 v1.76 and prior CP635, order code: 1SAP535100R5001, revision index G1 with BSP UN31 v1.76 and prior CP635-B, order code: 1SAP535100R2001, revision index G1 with BSP UN31 v1.76 and prior CP635-WEB, order code: 1SAP535200R0001, revision index G1 with BSP UN31 v1.76 and prior.",CVE-2019-7225,8.8,High,CWE-798,Critical Manufacturing,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1123,6/27/2019,6/27/2019,2019,ICSA-19-178-04,SICK MSC800,SICK,MSC800,MSC800 - programmable logic controller affected: all versions prior to Version 4.0.,CVE-2019-10979,9.8,Critical,CWE-798,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1122,6/27/2019,6/27/2019,2019,ICSA-19-178-05,Advantech WebAccess/SCADA,Advantech,WebAccess/SCADA,WebAccess/SCADA Versions 8.3.5 and prior.,"CVE-2019-10983, CVE-2019-10985, CVE-2019-10987, CVE-2019-10989, CVE-2019-10991, CVE-2019-10993",9.8,Critical,"CWE-122, CWE-22, CWE-125, CWE-787, CWE-121, CWE-822",Critical Manufacturing; Energy; Water and Wastewater,"East Asia, United States, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1121,6/20/2019,8/5/2019,2019,ICSA-19-171-01,PHOENIX CONTACT Automation Worx Software Suite,PHOENIX CONTACT,Automation Worx Software Suite,Components of Automation Worx Software Suite Version 1.86 and earlier affected: PC Worx PC Worx Express Config+.,"CVE-2019-12869, CVE-2019-12870, CVE-2019-12871",7.5,High,"CWE-824, CWE-125, CWE-416",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1120,6/13/2019,6/14/2019,2019,ICSMA-19-164-01,BD Alaris Gateway Workstation,"Becton, Dickinson and Company (BD)",Alaris Gateway Workstation,Versions of BD's Alaris Gateway Workstation affected: 1.0.131.1.3 Build 101.1.3 MR Build 111.1.51.1.6.,"CVE-2019-10959, CVE-2019-10962",10.0,Critical,"CWE-284, CWE-434",Healthcare and Public Health,"Europe, Asia",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1119,6/13/2019,6/13/2019,2019,ICSA-19-164-01,Johnson Controls exacqVision Enterprise System Manager,Johnson Controls Inc.,exacqVision Enterprise System Manager,exacqVision ESM v5.12.2 and prior. All Microsoft Windows operating systems are affected with the exception of Microsoft Windows Server.,CVE-2019-7588,6.7,Medium,CWE-285,Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1118,6/13/2019,6/13/2019,2019,ICSA-19-164-02,"WAGO Industrial Managed Switches 852-303, 852-1305, and 852-1505",WAGO,"Industrial Managed Switches 852-303, 852-1305, and 852-1505",AGO industrial managed switches versions affected: 852-303: All versions prior to v1.2.2.S0852-1305: All versions prior to v1.1.6.S0852-1505: All versions prior to v1.1.5.S0.,"CVE-2019-12549, CVE-2019-12550",9.8,Critical,"CWE-798, CWE-321",Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1117,6/11/2019,6/11/2019,2019,ICSA-19-162-01,Siemens Siveillance VMS,Siemens,Siveillance VMS,Siemens Siveillance VMS versions affected: 2017 R2 all versions prior to v11.2a2018 R1 all versions prior to v12.1a2018 R2 all versions prior to v12.2a2018 R3 all versions prior to v12.3a2019 R1 all versions prior to v13.1a.,"CVE-2019-6580, CVE-2019-6581, CVE-2019-6582",8.8,High,"CWE-285, CWE-286, CWE-862",Critical Manufacturing; Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1116,6/11/2019,6/11/2019,2019,ICSA-19-162-03,Siemens LOGO!8 Devices,Siemens,LOGO!8 Devices,SIEMENS LOGO!8 devices - used for basic small-scale automation tasks - versions affected: 6ED1052-xyyxx-0BA8 FS:01 to FS:06 / Firmware v1.80.xx and v1.81.xxSIEMENS LOGO!8: 6ED1052-xyy08-0BA0 FS:01 / Firmware version prior to v1.82.02.,"CVE-2019-6571, CVE-2019-6584",7.5,High,"CWE-119, CWE-384",Commercial Facilities; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1115,6/6/2019,6/6/2019,2019,ICSA-19-157-01,Optergy Proton Enterprise Building Management System,Optergy,Proton Enterprise Building Management System,Proton/Enterprise Building Management Systems versions affected: Versions 2.3.0a and prior.,"CVE-2019-7272, CVE-2019-7273, CVE-2019-7274, CVE-2019-7275, CVE-2019-7276, CVE-2019-7277, CVE-2019-7278, CVE-2019-7279",10.0,Critical,"CWE-352, CWE-749, CWE-200, CWE-912, CWE-434, CWE-601, CWE-798",Commercial Facilities; Government Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1114,6/6/2019,6/10/2019,2019,ICSA-19-157-02,Panasonic Control FPWIN Pro,Panasonic,Control FPWIN Pro,FPWIN Pro - PLC programming software versions affected: Version 7.3.0.0 and prior.,"CVE-2019-6530, CVE-2019-6532",7.3,High,"CWE-843, CWE-122",Commercial Facilities; Critical Manufacturing; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1113,6/4/2019,6/4/2019,2019,ICSA-19-155-01,PHOENIX CONTACT PLCNext AXC F 2152,PHOENIX CONTACT,PLCNext AXC F 2152,Phoenix Contact firmware versions 1.x for PLCNext AXC F2152 products affected: AXC F 2152: article number 2404267AXC F 2152: article number 1046568 (Starterkit).,"CVE-2018-7559, CVE-2019-10998, CVE-2019-10997",7.6,High,"CWE-300, CWE-284, CWE-320",Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1112,6/4/2019,6/4/2019,2019,ICSA-19-155-02,PHOENIX CONTACT FL NAT SMx,PHOENIX CONTACT,FL NAT SMx,Phoenix Contact FL NAT SMx industrial Ethernet switches versions affected: FL NAT SMN 8TX-M (2702443)FL NAT SMN 8TX-M-DMG (2989352)FL NAT SMN 8TX (2989365)FL NAT SMCS 8TX (2989378).,CVE-2019-9744,8.8,High,CWE-284,Communications; Critical Manufacturing; Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1111,6/4/2019,6/4/2019,2019,ICSA-19-155-03,Geutebruck G-Cam and G-Code,Geutebruck,G-Cam and G-Code,Geutebruck Encoder and E2 Series Camera versions and models affected: G-Code: All versions 1.12.0.25 and priorEEC-2xxxG-Cam: All versions 1.12.0.25 and priorEBC-21xxEFD-22xxETHC-22xxEWPC-22xx.,"CVE-2019-10956, CVE-2019-10957, CVE-2019-10958",7.2,High,"CWE-79, CWE-78",Commercial Facilities; Energy; Financial Services; Government Facilities; Healthcare and Public Health; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1110,5/30/2019,5/30/2019,2019,ICSA-19-150-01,AVEVA Vijeo Citect and CitectSCADA,"AVEVA, Schneider Electric",Vijeo Citect and CitectSCADA,Vijeo Citect and CitectSCADA - Supervisory Control and Data Acquistions (SCADA) software versions affected: Vijeo Citect 7.30 and 7.40 CitectSCADA 7.30 and 7.40.,CVE-2019-10981,6.5,Medium,CWE-522,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1109,5/28/2019,5/28/2019,2019,ICSA-19-148-01,Emerson Ovation OCR400 Controller,Emerson,Ovation OCR400 Controller,Emerson Ovation OCR400 - process control devices - affected versions: Emerson Ovation OCR400 Controller running Ovation Version 3.3.1 or earlier.,"CVE-2019-10965, CVE-2019-10967",6.8,Medium,"CWE-122, CWE-121",Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1108,5/21/2019,5/21/2019,2019,ICSA-19-141-01,Computrols CBAS Web,Computrols,CBAS Web,All versions of CBAS Web - a Web Building Management System (BMS) - prior to the following versions are affected: 19.0.1 | 18.0.1 | 15.0.1 | 14.0.1 | 8.0.7 | 7.2.1-Beta | 6.9.2 | 4.8.2 | 3.15.1.,"CVE-2019-10846, CVE-2019-10847, CVE-2019-10848, CVE-2019-10849, CVE-2019-10851, CVE-2019-10852, CVE-2019-10853, CVE-2019-10854, CVE-2019-10855",8.8,High,"CWE-352, CWE-203, CWE-79, CWE-77, CWE-540, CWE-321, CWE-89, CWE-288, CWE-326",Commercial Facilities; Government Facilities; Healthcare and Public Health,North America,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1107,5/21/2019,5/21/2019,2019,ICSA-19-141-02,Mitsubishi Electric MELSEC-Q Series Ethernet Module,Mitsubishi Electric,MELSEC-Q Series Ethernet Module,MELSEC-Q series Ethernet module affected: QJ71E71-100 serial number 20121 and prior.,CVE-2019-10977,7.5,High,CWE-400,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1106,5/16/2019,6/18/2019,2019,ICSA-19-136-01,Schneider Electric Modicon Controllers,Schneider Electric,Modicon Controllers,Modicon products affected: Modicon M580 firmware versions prior to Version 2.30Modicon M340 firmware | all versionsModicon Premium | all firmware versions | Modicon Quantum | all firmware versions.,CVE-2019-6821,5.4,Medium,CWE-330,Multiple Critical Sectors,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1105,5/16/2019,5/16/2019,2019,ICSA-19-136-02,Fuji Electric Alpha7 PC Loader,Fuji Electric,Alpha7 PC Loader,Alpha7 PC Loader Versions 1.1 and prior,CVE-2019-10975,3.3,Low,CWE-125,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1104,5/14/2019,5/14/2019,2019,ICSA-19-134-02,Siemens SIMATIC WinCC and SIMATIC PCS 7,Siemens,SIMATIC WinCC and SIMATIC PCS 7,"Siemen SIMATIC prodcts affected: SIMATIC PCS 7 v8.0 and earlier | SIMATIC PCS 7 v8.1 and newer (if ""Encrypted Communication"" is disabled) | SIMATIC WinCC v7.2 and earlier | SIMATIC WinCC v7.3 and newer (if ""Encrypted Communication"" is disabled).",CVE-2019-10922,9.8,Critical,CWE-306,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1103,5/14/2019,5/14/2019,2019,ICSA-19-134-05,Siemens SINAMICS PERFECT HARMONY GH180 Drives NXG I and NXG II,Siemens,SINAMICS PERFECT HARMONY GH180 Drives NXG I and NXG II,"Siemens SINAMICS PERFECT HARMONY products affected: SINAMICS PERFECT HARMONY GH180 with NXG I control, MLFBs: 6SR2. . . -, 6SR3. . . -, 6SR4. . . -: All versions with option G28SINAMICS PERFECT HARMONY GH180 with NXG II control, MLFBs: 6SR2. . . -, 6SR3. . . -, 6SR4. . . -: All versions with option G28.",CVE-2019-6578,7.5,High,CWE-400,Chemical; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1102,5/14/2019,5/14/2019,2019,ICSA-19-134-06,Siemens SINAMICS PERFECT HARMONY GH180 Fieldbus Network,Siemens,SINAMICS PERFECT HARMONY GH180 Fieldbus Network,"Siemens SINAMICS PERFECT HARMONY products affected: SINAMICS PERFECT HARMONY GH180 with NXG I control, MLFBs: 6SR2. . . -, 6SR3. . . -, 6SR4. . . -: All versions with option G21, G22, G23, G26, G28, G31, G32, G38, G43 or G46SINAMICS PERFECT HARMONY GH180 with NXG II control, MLFBs: 6SR2. . . -, 6SR3. . . -, 6SR4. . . -: All versions with option G21, G22, G23, G26, G28, G31, G32, G38, G43 or G46.",CVE-2019-6574,7.5,High,CWE-20,Chemical; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1101,5/14/2019,5/14/2019,2019,ICSA-19-134-07,Siemens SCALANCE W1750D,Siemens,SCALANCE W1750D,Siemens SCALANCE W1750D - direct access point versions affected: W1750D: All versions prior to 8.4.0.1.,"CVE-2018-16417, CVE-2018-7064, CVE-2018-7082, CVE-2018-7083, CVE-2018-7084",9.8,Critical,"CWE-200, CWE-20, CWE-79, CWE-77, CWE-7",Chemical; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1100,5/14/2019,5/14/2019,2019,ICSA-19-134-09,Siemens SIMATIC Panels and WinCC (TIA Portal),Siemens,SIMATIC Panels and WinCC (TIA Portal),"SIMATIC HMI Comfort Panels, 4"" - 22""; all versions prior to v15.1 Update 1SIMATIC HMI Comfort Outdoor Panels, 7"" & 15""; all versions prior to v15.1 Update 1SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900, KTP900F; all versions prior to v15.1 Update 1SIMATIC WinCC Runtime Advanced; all versions prior to v15.1 Update 1SIMATIC WinCC Runtime Professional; all versions prior to v15.1 Update 1SIMATIC WinCC (TIA Portal); all versions prior to v15.1 Update 1SIMATIC HMI Classic Devices (TP/MP/OP/MP Mobile Panel); all versions.","CVE-2019-6572, CVE-2019-6576, CVE-2019-6577",6.5,Medium,"CWE-79, CWE-522, CWE-798",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1099,5/2/2019,5/6/2019,2019,ICSA-19-122-01,Orpak SiteOmat,Orpak,SiteOmat,SiteOmat - software for fuel station management versions affected: SiteOmat versions prior to 6.4.414.122 only are vulnerable to stack-based buffer overflow CVE-2017-14854 and Code Injection CVE-2017-14853SiteOmat Versions prior to 6.4.414.084.,CVE-2017-14854,9.8,Critical,"CWE-94, CWE-79, CWE-89, CWE-311, CWE-121, CWE-798",Commercial Facilities; Energy; Transportation Systems,Worldwide,Israel,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1098,5/2/2019,5/2/2019,2019,ICSA-19-122-02,GE Communicator,GE,Communicator,GE Communicator components - all versions prior to 4.0.517 are affected: Communicator Installer | Communicator Application | Communicator PostGreSQL | Communicator MeterManager | Communicator WISE Uninstaller.,"CVE-2019-6544, CVE-2019-6546, CVE-2019-6548, CVE-2019-6564, CVE-2019-6566",8.1,High,"CWE-284, CWE-427, CWE-798",Critical Manufacturing; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1097,4/30/2019,6/29/2023,2019,ICSA-19-120-01,Rockwell Automation CompactLogix 5370 (Update A),Rockwell Automation,CompactLogix 5370,--------- Begin Update A Part 1 of 1 --------- Rockwell Automation reports these vulnerabilities affect the following CompactLogix 5370 programmable automation controllers: CompactLogix 5370 L1 controllers: versions 20 - 30 and earlier CompactLogix 5370 L2 controllers: versions 20 - 30 and earlier CompactLogix 5370 L3 controllers: versions 20 - 30 and earlier Compact GuardLogix 5370 controllers: versions 20 - 30 and earlier Armor Compact GuardLogix 5370 controllers: versions 20 - 30 and earlier --------- End Update A Part 1 of 1 -------.,"CVE-2019-10952, CVE-2019-10954",8.6,High,"CWE-400, CWE-121",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1096,4/23/2019,4/23/2019,2019,ICSMA-19-113-01,Fujifilm FCR Capsula X/Carbon X,Fujifilm,FCR Capsula X/Carbon X,Fujifilm Computed Radiography cassette reader models and versions affected: CR-IR 357 FCR Carbon XCR-IR 357 FCR XC-2CR-IR 357 FCR Capsula X.,"CVE-2019-10948, CVE-2019-10950",9.8,Critical,"CWE-284, CWE-400",Healthcare and Public Health,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1095,4/23/2019,4/23/2019,2019,ICSA-19-113-01,Rockwell Automation MicroLogix 1400 and CompactLogix 5370 Controllers,Rockwell Automation,MicroLogix 1400 and CompactLogix 5370 Controllers,"Rockwell Automation products affected: MicroLogix 1400 ControllersSeries A - All Versions Series B, v15.002 and earlier | MicroLogix 1100 Controllers v14.00 and earlier | CompactLogix 5370 L1 controllers v30.014 and earlier | CompactLogix 5370 L2 controllers v30.014 and earlier | CompactLogix 5370 L3 controllers (includes CompactLogix GuardLogix controllers) v30.014 and earlier.",CVE-2019-10955,7.1,High,CWE-601,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1094,4/16/2019,4/16/2019,2019,ICSA-19-106-01,Delta Industrial Automation CNCSoft,Delta Electronics,CNCSoft,Delta Industrial Automation CNCSoft affected: CNCSoft ScreenEditor Version 1.00.88 and prior.,"CVE-2019-10947, CVE-2019-10949, CVE-2019-10951",7.8,High,"CWE-122, CWE-125, CWE-121",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1093,4/16/2019,4/16/2019,2019,ICSA-19-106-02,WAGO Series 750-88x and 750-87x,WAGO,Series 750-88x and 750-87x,WAGO versions of Series 750-88x and 750-87x - programmable logic controllers affected: Series 750-88x750-330 firmware versions prior to FW14750-352 firmware versions prior to FW14 750-829 firmware versions prior to FW14750-831 firmware versions prior to FW14750-852 firmware versions prior to FW14 750-880 firmware versions prior to FW14 750-881 firmware versions prior to FW14 750-882 firmware versions prior to FW14 750-884 firmware versions prior to FW14 750-885 firmware versions prior to FW14 750-889 firmware versions prior to FW14 Series 750-87x750-830 firmware versions prior to FW06 750-849 firmware versions prior to FW08 750-871 firmware versions prior to FW11 750-872 firmware versions prior to FW07 750-873 firmware versions prior to FW07.,CVE-2019-10712,9.8,Critical,CWE-798,Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1092,4/9/2019,4/9/2019,2019,ICSA-19-099-01,Siemens SIMOCODE pro V EIP,Siemens,SIMOCODE pro V EIP,Siemens versions of SIMOCODE pro V EIP - motor management system for low-voltage motors affected: SIMOCODE pro V EIP all versions prior to v1.0.2.,CVE-2017-12741,7.5,High,CWE-400,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1091,4/9/2019,4/9/2019,2019,ICSA-19-099-02,Siemens Spectrum Power 4.7,Siemens,Spectrum Power 4.7,Versions of Spectrum Power - system that provides basic components for SCADA communications and data modeling for control and monitoring systems - versions affected: Spectrum Power 4 with Web Office Portal.,CVE-2019-6579,10.0,Critical,CWE-77,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1090,4/9/2019,4/9/2019,2019,ICSA-19-099-05,Siemens RUGGEDCOM ROX II,Siemens,RUGGEDCOM ROX II,Siemens RUGGEDCOM products affected: RUGGEDCOM ROX II: All versions prior to v2.13.0.,"CVE-2018-5379, CVE-2018-5380, CVE-2018-5381",9.8,Critical,"CWE-415, CWE-125, CWE-400",Energy; Healthcare and Public Health; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1089,4/4/2019,4/4/2019,2019,ICSA-19-094-01,Omron CX-Programmer,Omron,CX-Programmer,Versions of CX-Programmer within CX-One affected: CX-Programmer v9.70 and prior | Common Components January 2019 and prior.,CVE-2019-6556,6.6,Medium,CWE-416,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1088,4/4/2019,4/5/2019,2019,ICSA-19-094-02,Rockwell Automation Stratix 5400/5410/5700 and ArmorStratix 5700,Rockwell Automation,Stratix 5400/5410/5700 and ArmorStratix 5700,Rockwell Automation Stratix Industrial Switches affected by this vulnerability in the Cisco Open Plug-n-Play agent: Allen-Bradley Stratix 5400: All versions prior to 15.2(6)E2a | Allen-Bradley Stratix 5410: All versions prior to 15.2(6)E2a | Allen-Bradley Stratix 5700: All versions prior to 15.2(6)E2a | Allen-Bradley Armor Stratix 5700: All versions prior to 15.2(6)E2a.,CVE-2018-15377,6.8,Medium,CWE-400,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1087,4/4/2019,4/5/2019,2019,ICSA-19-094-03,Rockwell Automation Stratix 5400/5410/5700/8000/8300 and ArmorStratix 5700,Rockwell Automation,Stratix 5400/5410/5700/8000/8300 and ArmorStratix 5700,Allen-Bradley Stratix 5400 versions affected: All versions 15.2(6)E0a and prior | Allen-Bradley Stratix 5410: All versions 15.2(6)E0a and prior | Allen-Bradley Stratix 5700: All versions 15.2(6)E0a and prior | Allen-Bradley Armor Stratix 5700: All versions 15.2(6)E0a and prior | Allen-Bradley Stratix 8000: All versions 15.2(6)E0a and prior | Allen-Bradley Stratix 8300: All versions prior to 15.2(4)EA7.,"CVE-2018-0466, CVE-2018-0467, CVE-2018-0470, CVE-2018-0473, CVE-2018-15373",8.6,High,"CWE-20, CWE-399",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1086,4/4/2019,4/5/2019,2019,ICSA-19-094-04,Rockwell Automation Stratix 5950,Rockwell Automation,Stratix 5950,Allen-Bradley Stratix 5950 security appliance products affected by the vulnerability in the Cisco IPsec driver code: 1783-SAD4T0SBK9 | 1783-SAD4T0SPK9 | 1783-SAD2T2SBK9 | 1783-SAD2T2SPK9.,CVE-2018-0472,8.6,High,CWE-20,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1085,4/2/2019,4/2/2019,2019,ICSA-19-092-01,Advantech WebAccess/SCADA,Advantech,WebAccess/SCADA,WebAccess/SCADA Versions 8.3.5 and prior.,"CVE-2019-6550, CVE-2019-6552, CVE-2019-6554",9.8,Critical,"CWE-284, CWE-77, CWE-121",Critical Manufacturing; Energy; Water and Wastewater,"East Asia, United States, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1084,3/28/2019,3/28/2019,2019,ICSA-19-087-01,Rockwell Automation PowerFlex 525 AC Drives,Rockwell Automation,PowerFlex 525 AC Drives,PowerFlex 525 AC Drives with embedded EtherNet/IP and Safety Versions 5.001 and earlier.,CVE-2018-19282,7.5,High,CWE-400,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1083,3/26/2019,3/26/2019,2019,ICSA-19-085-02,PHOENIX CONTACT RAD-80211-XD,PHOENIX CONTACT,RAD-80211-XD,Phoenix Contact products affected: RAD-80211-XD (2885728) and RAD-80211-XD/HP-BUS (2900047).,CVE-2019-9743,9.9,Critical,CWE-77,Communications; Critical Manufacturing; Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1082,3/26/2019,3/26/2019,2019,ICSA-19-085-03,ENTTEC Lighting Controllers,ENTTEC,Lighting Controllers,NTTEC products and versions affected: Datagate MK2 all firmware prior to 70044_update_05032019-482 | Storm 24 all firmware prior to 70050_update_05032019-482 and Pixelator all firmware prior to 70060_update_05032019-482.,CVE-2019-6542,7.5,High,CWE-306,Commercial Facilities,Worldwide,Australia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1081,3/19/2019,3/19/2019,2019,ICSA-19-078-01,AVEVA InduSoft Web Studio and InTouch Edge HMI,AVEVA,InduSoft Web Studio and InTouch Edge HMI,AVEVA InduSoft Web Studio and InTouch Edge HMI versions affected: InduSoft Web Studio versions prior to v8.1 SP3 | InTouch Edge HMI versions prior to 2017 Update 3.,CVE-2019-6534,6.5,Medium,CWE-427,Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems; Water and Wastewater,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1080,3/19/2019,3/19/2019,2019,ICSA-19-078-02,Columbia Weather Systems MicroServer,Columbia Weather Systems,MicroServer,Weather MicroServer - weather monitoring system - affected: Weather MicroServer firmware Version MS_2.6.9900 and prior.,"CVE-2018-18875, CVE-2018-18876, CVE-2018-18877, CVE-2018-18878, CVE-2018-18879, CVE-2018-18880",9.8,Critical,"CWE-287, CWE-94, CWE-20, CWE-22, CWE-79",Information Technology,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1079,3/14/2019,3/14/2019,2019,ICSA-19-073-01,LCDS - Leao Consultoria e Desenvolvimento de Sistemas Ltda ME LAquis SCADA ELS Files,LCDS - Leao Consultoria e Desenvolvimento de Sistemas Ltda ME,LAquis SCADA ELS Files,Laquis SCADA - industrial automation software version affected: SCADA 4.1.0.4150.,CVE-2019-6536,7.8,High,CWE-787,Chemical; Commercial Facilities; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,South America,Brazil,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1078,3/14/2019,3/14/2019,2019,ICSA-19-073-02,Gemalto Sentinel UltraPro,Gemalto,Sentinel UltraPro,"Sentinel UltraPro encryption keys affected: Sentinel UltraPro Client Library ux32w.dll Versions 1.3.0, 1.3.1, and 1.3.2.",CVE-2019-6534,6.5,Medium,CWE-427,Communications; Financial Services; Government Facilities; Healthcare and Public Health; Information Technology,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1077,3/14/2019,3/14/2019,2019,ICSA-19-073-03,PEPPERL+FUCHS WirelessHART-Gateways,PEPPERL+FUCHS,WirelessHART-Gateways,PEPPERL+FUCHS products affected: all WHA-GW-* products.,CVE-2018-16059,5.3,Medium,CWE-22,Critical Manufacturing; Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1076,3/5/2019,3/5/2019,2019,ICSA-19-064-01,Rockwell Automation RSLinx Classic,Rockwell Automation,RSLinx Classic,Rockwell Automation RSLinx Classic - PLC communications software versions affected: RSLinx Classic Versions 4.10.00 and prior.,CVE-2019-6553,10.0,Critical,CWE-121,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1075,2/28/2019,2/28/2019,2019,ICSA-19-059-01,PSI GridConnect Telecontrol,PSI GridConnect GmbH (formerly known as PSI Nentec GmbH),Telecontrol,"PSI GridConnect products affected: Telecontrol Gateway 3G Versions 4.2.21, 5.0.27, 5.1.19, 6.0.16 and prior; Telecontrol Gateway XS-MU Versions 4.2.21, 5.0.27, 5.1.19, 6.0.16 and prior; Telecontrol Gateway VM Versions 4.2.21, 5.0.27, 5.1.19, 6.0.16 and prior;Smart Telecontrol Unit TCG Versions 5.0.27, 5.1.19, 6.0.16 and prior; and IEC104 Security Proxy Version 2.2.10 and prior.",CVE-2019-6528,8.5,High,CWE-79,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1074,2/19/2019,2/19/2019,2019,ICSA-19-050-01,Intel Data Center Manager SDK,Intel,Data Center Manager SDK,Intel product affected: Intel Data Center Manager SDK prior to Version 5.0.2.,"CVE-2019-0102, CVE-2019-0103, CVE-2019-0104, CVE-2019-0105, CVE-2019-0106, CVE-2019-0107, CVE-2019-0108, CVE-2019-0109, CVE-2019-0110, CVE-2019-0111, CVE-2019-0112",8.8,High,"CWE-287, CWE-691, CWE-320, CWE-693, CWE-275",Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1073,2/19/2019,2/19/2019,2019,ICSA-19-050-02,Delta Industrial Automation CNCSoft,Delta Electronics,CNCSoft,Delta Industrial Automation CNCSoft versions affected: CNCSoft ScreenEditor Version 1.00.84 and prior.,CVE-2019-6547,4.4,Medium,CWE-125,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1072,2/19/2019,2/19/2019,2019,ICSA-19-050-03,Horner Automation Cscape,Horner Automation,Cscape,Horner Automation Cscap - control system application programming software versions affected: Cscape 9.80 SP4 and prior.,CVE-2019-6555,7.8,High,CWE-20,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1071,2/19/2019,9/5/2019,2019,ICSA-19-050-04,Rockwell Automation Allen-Bradley PowerMonitor 1000 (Update A),Rockwell Automation,Allen-Bradley PowerMonitor 1000,Rockwell Automation - Allen-Bradley PowerMonitor 1000 - monitoring platform versions affected: all versions.,"CVE-2018-19615, CVE-2018-19616",6.1,Medium,"CWE-288, CWE-79",Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1070,2/14/2019,2/14/2019,2019,ICSA-19-045-01,Pangea Communications Internet FAX ATA,Pangea Communications,Internet FAX ATA,Pangea Internet FAX ATA - Analog Telephone Adapter - versions affected: Internet FAX ATA Version 3.1.8 and prior.,CVE-2019-6551,7.5,High,CWE-288,Communication; Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1069,11/6/2018,11/6/2018,2019,ICSA-18-310-01,gpsd Open Source Project,gpsd Open Source Project,gpsd Open Source,The following versions of gpsd and microjson - an open-source GPS framework are affected: gpsd | Versions 2.90 to 3.17 microjson Versions 1.0 to 1.3. As reported on the gpsd website - gpsd can be found in many mobile embedded systems such as Android phones | drones | robot submarines | driverless cars | manned aircraft | marine navigation systems and military vehicles. Google has been contacted regarding this vulnerability. They have examined it and believe the vulnerability does not apply to Android.,CVE-2018-17937,8.3,High,CWE-121,Communications; Defense Industrial Base; Emergency Services; Transportation Systems,Worldwide,Open-source,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1068,2/12/2019,2/12/2019,2019,ICSA-19-043-01,OSIsoft PI Vision,OSIsoft,PI Vision,"OSIsoft PI Vision - process visualization tool - versions affected: PI Vision 2017, and PI Vision 2017 R2.",CVE-2018-19006,4.8,Medium,CWE-79,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1067,2/12/2019,2/12/2019,2019,ICSA-19-043-02,Siemens EN100 Ethernet Communication Module and SIPROTEC 5 Relays,Siemens,EN100 Ethernet Communication Module and SIPROTEC 5 Relays,Versions of the Siemens EN100 Ethernet communications module and SIPROTEC 5 relays affected: Firmware variant IEC 61850 for EN100 Ethernet module: All versions prior to v4.35 | Firmware variant MODBUS TCP for EN100 Ethernet module: All versions | Firmware variant DNP3 TCP for EN100 Ethernet module: All versions | Firmware variant IEC104 for EN100 Ethernet module: All versions | Firmware variant Profinet IO for EN100 Ethernet module: All versions | SIPROTEC 5 relays with CPU variants CP300 and CP100 and the respective Ethernet communication modules: All versions prior to v7.82 | SIPROTEC 5 relays with CPU variants CP200 and the respective Ethernet communication modules: All versions prior to v7.58.,CVE-2018-16563,7.5,High,CWE-20,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1066,2/12/2019,5/14/2019,2019,ICSA-19-043-03,WIBU SYSTEMS AG WibuKey Digital Rights Management (Update D),Wibu-Systems AG,WIBU SYSTEMS AG WibuKey Digital Rights Management,"Siemens products affected: WibuKey Digital Rights Management (DRM): Siemens SICAM 230: All Versions 7.20 and prior, Siemens SIMATIC WinCC OA:3.14: All versions prior to vP0253.15: All versions prior to vP0183.16: All versions prior to vP007. Siemens SISHIP EMCS, IMAC, IPMS: All versions. | COPA-DATA zenon products: All Versions 7.20 and prior (7.50 and 7.60 may also be affected if WibuKey was installed manually) COPA-DATA straton workbench: All Versions 9.2 and prior | Sprecher Automation SPRECON-V460 products: All Versions 7.20 and prior (7.50 and 7.60 may also be affected if WibuKey was installed manually) | Phoenix Contact MEVIEW3: All versions prior to 3.14.25 and 3.15.18.","CVE-2018-3989, CVE-2018-3990, CVE-2018-3991",10.0,Critical,"CWE-200, CWE-122, CWE-787",Commercial Facilities; Communications; Critical Manufacturing; Energy; Financial Services; Healthcare and Public Health; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1065,2/12/2019,2/12/2019,2019,ICSA-19-043-04,Siemens SIMATIC S7-300 CPU,Siemens,SIMATIC S7-300 CPU,Siemens products affected: SIMATIC S7-300 CPUs: All versions prior to v3.X.16.,CVE-2018-16561,7.5,High,CWE-20,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1064,2/12/2019,2/12/2019,2019,ICSA-19-043-05,Siemens Intel Active Management Technology of SIMATIC IPCs,Siemens,Intel Active Management Technology of SIMATIC IPCs,"Siemens products affected: SIMATIC FieldPG M5: All versions prior to v22.01.06, SIMATIC IPC427E: All versions prior to v21.01.09; SIMATIC IPC477E: All versions prior to v21.01.09; SIMATIC IPC547E: All versions prior to R1.30.0; SIMATIC IPC547G: All versions prior to R1.23.0; SIMATIC IPC627D: All versions prior to v19.02.11; SIMATIC IPC647D: All versions prior to v19.01.14; SIMATIC IPC677D: All versions prior to v19.02.11; SIMATIC IPC827D: All versions prior to v19.02.11; SIMATIC IPC847D: All versions prior to v19.01.14; and SIMATIC ITP1000: All versions prior to v23.01.04.","CVE-2018-3616, CVE-2018-3657, CVE-2018-3658",6.7,Medium,"CWE-310, CWE-119, CWE-399",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1063,2/12/2019,7/9/2019,2019,ICSA-19-043-06,Siemens CP1604 and CP1616 (Update A),Siemens,CP1604 and CP1616,Siemens products affected: CP 1604 and 1616: All versions prior to v2.8.,"CVE-2018-13808, CVE-2018-13809, CVE-2018-13810",9.1,Critical,"CWE-319, CWE-352, CWE-79",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1062,2/7/2019,2/7/2019,2019,ICSA-19-038-01,Siemens SICAM A8000 RTU Series,Siemens,SICAM A8000 RTU Series,Siemens SICAM A8000 RTU - telecontrol and automation device - products affected: SICAM A8000 CP-8000 versions prior to v14; SICAM A8000 CP-802X versions prior to v14; and SICAM A8000 CP-8050 versions prior to v2.,CVE-2018-13798,5.3,Medium,CWE-248,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1061,2/7/2019,2/7/2019,2019,ICSA-19-038-02,Siemens EN100 Ethernet Module,Siemens,EN100 Ethernet Module,"Versions of EN100 Ethernet module, a communication module for SWT 3000 management platform - affected: Firmware variant IEC 61850 for EN100 Ethernet module version prior to 4.33.","CVE-2018-11451, CVE-2018-11452",7.5,High,CWE-20,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1060,2/5/2019,2/5/2019,2019,ICSA-19-036-01,AVEVA InduSoft Web Studio and InTouch Edge HMI,AVEVA,InduSoft Web Studio and InTouch Edge HMI,Versions of AVEVA products are affected: InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update.,"CVE-2019-6543, CVE-2019-6545",9.8,Critical,"CWE-99, CWE-306",Chemical; Commercial Facilities; Critical Manufacturing; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1059,2/5/2019,2/19/2019,2019,ICSA-19-036-02,Rockwell Automation EtherNet/IP Web Server Modules,Rockwell Automation,EtherNet/IP Web Server Modules,"Versions of EtherNet/IP web server module - a web server module - affected: 1756-EWEB (includes 1756-EWEBK) Version 5.001 and earlier, andCompactLogix 1768-EWEB Version 2.005 and earlier.",CVE-2018-19016,5.3,Medium,CWE-20,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1058,2/5/2019,2/5/2019,2019,ICSA-19-036-04,Siemens SIMATIC S7-1500 CPU,Siemens,SIMATIC S7-1500 CPU,Siemens products affected: SIMATIC S7-1500 CPU all versions v1.8.5 and prior and SIMATIC S7-1500 CPU all versions prior to v2.5 down to and including v2.0.,"CVE-2018-16558, CVE-2018-16559",7.5,High,CWE-20,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1057,2/5/2019,3/5/2019,2019,ICSA-19-036-05,Kunbus PR100088 Modbus Gateway (Update B),Kunbus,PR100088 Modbus Gateway,PR100088 Modbus gateway: All versions prior to Release R02 (or Software Version 1.1.13166).,"CVE-2019-6527, CVE-2019-6529, CVE-2019-6531, CVE-2019-6533, CVE-2019-6549",10.0,Critical,"CWE-312, CWE-287, CWE-20, CWE-306, CWE-598",Communications,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1056,2/5/2019,9/20/2019,2019,ICSA-19-036-03,WECON LeviStudioU (Update A),WECON,LeviStudioU,WECON products affected: LeviStudioU Versions 1.8.69 and prior.,"CVE-2019-6537, CVE-2019-6539, CVE-2019-6541",7.8,High,"CWE-122, CWE-119, CWE-121",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1055,1/31/2019,3/5/2019,2019,ICSA-19-031-02,IDenticard PremiSys (Update A),IDenticard,PremiSys,Versions of IDenticard PremiSys - access control system -affected: PremiSys all versions prior to 4.2CVE-2019-3906 was resolved in Version 4.1.,"CVE-2019-3906, CVE-2019-3907, CVE-2019-3908",8.8,High,"CWE-326, CWE-798, CWE-259",Commercial Facilities; Government Facilities; Healthcare and Public Health; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1054,1/31/2019,1/31/2019,2019,ICSA-19-031-01,Schneider Electric EVLink Parking,Schneider Electric,EVLink Parking,Versions of EVLink Parking - electric vehicle charging station - affected: EVLink Parking Versions 3.2.0-12_v1 and prior.,"CVE-2018-7800, CVE-2018-7801, CVE-2018-7802",9.8,Critical,"CWE-94, CWE-89, CWE-798",Transportation Systems,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1053,1/29/2019,1/29/2019,2019,ICSMA-19-029-01,Stryker Medical Beds,Stryker,Medical Beds,Stryker medical products affected: Secure II MedSurg Bed (enabled with iBed Wireless); Model: 3002; S3 MedSurg Bed (enabled with iBed Wireless); Models: 3002 S3 and 3005 S3 and InTouch ICU Bed (enabled with Bed Wireless); Models 2131 and 2141.,CVE-2017-13077,6.8,Medium,CWE-323,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1052,1/29/2019,2/5/2019,2019,ICSMA-19-029-02,BD FACSLyric (Update A),"Becton, Dickinson and Company (BD)",FACSLyric,"BD FACSLyric flow cytometry solution versions affected: BD FACSLyric Research Use Only - Windows 10 Professional Operating System - U.S. and Malaysian Releases, between November 2017 and November 2018, and BD FACSLyric IVD Windows 10 Professional Operating System U.S. release.",CVE-2019-6517,6.8,Medium,CWE-284,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1051,1/29/2019,1/29/2019,2019,ICSA-19-029-01,Yokogawa License Manager Service,Yokogawa,License Manager Service,Equipment and versions utilizing Yokogawa License Manager Services affected: CENTUM VP (R5.01.00 - R6.06.00); CENTUM VP Entry Class (R5.01.00 - R6.06.00); ProSafe-RS (R3.01.00 - R4.04.00); PRM (R4.01.00 - R4.02.00); andB/M9000 VP (R7.01.01 - R8.02.03).,CVE-2019-5909,8.1,High,CWE-434,Critical Manufacturing; Energy; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1050,1/29/2019,6/24/2025,2019,ICSA-19-029-02,Mitsubishi Electric MELSEC-Q Series PLCs (Update B),Mitsubishi Electric,MELSEC-Q series PLCs,"The following MELSEC-Q series PLCs are affected: Q03/04/06/13/26UDVCPU: serial number 20081 and prior Q04/06/13/26UDPVCPU: serial number 20081 and prior Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: serial number 20101 and prior.",CVE-2019-6535,7.5,High,CWE-400,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1049,1/29/2019,1/29/2019,2019,ICSA-19-029-03,AVEVA Wonderware System Platform,AVEVA,Wonderware System Platform,Wonderware System Platform - unifying supervisory platform versions affected: Wonderware System Platform 2017 Update 2 and prior.,CVE-2019-6525,8.8,High,CWE-522,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1048,1/24/2019,1/24/2019,2019,ICSA-19-024-01,Advantech WebAccess/SCADA,Advantech,WebAccess/SCADA,WebAccess/SCADA Version 8.3.,"CVE-2019-6519, CVE-2019-6521, CVE-2019-6523",9.8,Critical,"CWE-288, CWE-287, CWE-89",Critical Manufacturing; Energy; Water and Wastewater,"East Asia, United States, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1047,1/24/2019,1/24/2019,2019,ICSA-19-024-02,PHOENIX CONTACT FL SWITCH,PHOENIX CONTACT,FL SWITCH,Phoenix Contact versions affected: FL SWITCH 3xxx; 4xxx and 48xx versions prior to Version 1.35.,"CVE-2017-3735, CVE-2018-13990, CVE-2018-13991, CVE-2018-13992, CVE-2018-13993, CVE-2018-13994",8.8,High,"CWE-319, CWE-352, CWE-307, CWE-119, CWE-922, CWE-400",Communications; Critical Manufacturing; Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1046,1/22/2019,1/22/2019,2019,ICSMA-19-022-01,Drager Infinity Delta,Drager,Infinity Delta,Drager patient monitoring medical devices versions affected: Infinity Delta: all versions | Delta XL: all versions | Kappa: all version | Infinity Explorer C700: all versions.,"CVE-2018-19010, CVE-2018-19012, CVE-2018-19014",8.4,High,"CWE-20, CWE-269, CWE-532",Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1045,1/22/2019,1/22/2019,2019,ICSA-19-022-01,Johnson Controls Facility Explorer,Johnson Controls Inc.,Facility Explorer,"Facility Explorer leverages Tridium Niagara technology and the following versions are affected: Versions 14.x prior to 14.4u1, andVersions 6.x prior to 6.6.","CVE-2017-16744, CVE-2017-16748",7.4,High,"CWE-287, CWE-22",Critical Manufacturing,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1044,1/17/2019,2/7/2019,2019,ICSA-19-017-01,Omron CX-Supervisor (Update A),Omron,CX-Supervisor,Omron product and versions affected: CX-Supervisor: Versions 3.42 and prior.,"CVE-2018-19011, CVE-2018-19013, CVE-2018-19015, CVE-2018-19017, CVE-2018-19018, CVE-2018-19019, CVE-2018-19020",7.3,High,"CWE-843, CWE-824, CWE-94, CWE-77, CWE-125, CWE-416",Energy,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1043,1/17/2019,1/17/2019,2019,ICSA-19-017-02,ABB CP400 Panel Builder TextEditor 2.0,ABB,CP400 Panel Builder TextEditor 2.0,ABB CP400PB - Panel Builder for CP405 and CP408 versions affected: Versions 2.0.7.05 and prior.,CVE-2018-19008,7.0,High,CWE-20,Chemical; Critical Manufacturing; Dams; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1042,1/17/2019,1/17/2019,2019,ICSA-19-017-03,ControlByWeb X-320M,ControlByWeb,X-320M,ControlByWeb X-320M - web-enabled weather station - versions affected: X-320M-I firmware revision v1.05 and prior.,"CVE-2018-18881, CVE-2018-18882",7.6,High,"CWE-287, CWE-79",Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1041,1/15/2019,1/15/2019,2019,ICSA-19-015-01,LCDS - Leao Consultoria e Desenvolvimento de Sistemas Ltda ME LAquis SCADA,LCDS - Leao Consultoria e Desenvolvimento de Sistemas Ltda ME,LAquis SCADA,LAquis SCADA - industrial automation software versions affected: SCADA 4.1.0.3870.,"CVE-2018-18986, CVE-2018-18988, CVE-2018-18990, CVE-2018-18992, CVE-2018-18994, CVE-2018-18996, CVE-2018-18998, CVE-2018-19000, CVE-2018-19002, CVE-2018-19004, CVE-2018-19029",7.8,High,"CWE-20, CWE-125, CWE-94, CWE-822, CWE-787, CWE-23, CWE-74, CWE-798, CWE-288",Chemical; Commercial Facilities; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,South America,Brazil,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1040,1/10/2019,1/10/2019,2019,ICSA-19-010-01,Emerson DeltaV,Emerson,DeltaV,"DeltaV Distributed Control System (DCS) Workations versions affected: DeltaV DCS Versions 11.3.1, 11.3.2, 12.3.1, 13.3.1, 14.3, R5.1, R6 and prior.",CVE-2018-19021,8.8,High,CWE-307,Chemical; Critical Manufacturing; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1039,1/10/2019,1/10/2019,2019,ICSA-19-010-02,Omron CX-One CX-Protocol,Omron,CX-One CX-Protocol,Omron CX-One Versions 4.50 and prior - including the following are affected: CX-Protocol Versions 2.0 and prior.,CVE-2018-19027,6.6,Medium,CWE-843,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1038,1/10/2019,1/10/2019,2019,ICSA-19-010-03,Pilz PNOZmulti Configurator,Pilz,PNOZmulti Configurator,Pilz PNOZmulti Configurator - safety circuit configuration tool versions affected: all versions prior to 10.9.,CVE-2018-19009,3.3,Low,CWE-312,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1037,11/29/2018,11/29/2018,2019,ICSA-18-333-02,"Tridium Niagara Enterprise Security, Niagara AX, and Niagara 4",Tridium,"Niagara Enterprise Security, Niagara AX, and Niagara 4",The following Tridium products are affected: Niagara Enterprise Security 2.3u1 | all versions prior to 2.3.118.6 | Niagara AX 3.8u4 | all versions prior to 3.8.401.1 | Niagara 4.4u2 | all versions prior to 4.4.93.40.2 and Niagara 4.6 | all versions prior to 4.6.96.28.4.,CVE-2018-18985,5.7,Medium,CWE-79,Commercial Facilities; Critical Manufacturing; Government Facilities; Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1036,1/8/2019,1/8/2019,2019,ICSA-19-008-01,Schneider Electric Zelio Soft 2,Schneider Electric,Zelio Soft 2,Schneider Electric products affected: Zelio Soft 2 Versions 5.1 and prior.,CVE-2018-7817,7.8,High,CWE-416,Critical Manufacturing,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1035,1/8/2019,1/15/2019,2019,ICSA-19-008-02,Schneider Electric IIoT Monitor (Update A),Schneider Electric,IIoT Monitor,Schneider Electric IIoT Monitor - monitoring platform - versions affected: Versions 3.1.38 and prior.,"CVE-2018-7835, CVE-2018-7836, CVE-2018-7837, CVE-2018-7839",9.3,Critical,"CWE-310, CWE-22, CWE-611, CWE-434",Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1034,1/3/2019,1/3/2019,2019,ICSA-19-003-01,Schneider Electric Pro-face GP-Pro EX,Schneider Electric,Pro-face GP-Pro EX,Schneider Electric products affected: Pro-face GP-Pro EX Version 4.08 and prior.,CVE-2018-7832,9.0,Critical,CWE-20,Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1033,1/3/2019,1/3/2019,2019,ICSA-19-003-02,Yokogawa Vnet/IP Open Communication Driver,Yokogawa,Vnet/IP Open Communication Driver,Equipment and versions utilizing Yokogawa Vnt/IP Open communications driver affected: CENTUM CS 3000 (R3.05.00 - R3.09.50); CENTUM CS 3000 Entry Class (R3.05.00 - R3.09.50); CENTUM VP (R4.01.00 - R6.03.10); CENTUM VP Entry Class (R4.01.00 - R6.03.10); Exaopc (R3.10.00 - R3.75.00); PRM (R2.06.00 - R3.31.00); ProSafe-RS (R1.02.00 - R4.02.00); FAST/TOOLS (R9.02.00 - R10.02.00); and B/M9000 VP (R6.03.01 - R8.01.90).,CVE-2018-16196,7.5,High,CWE-399,Critical Manufacturing; Energy; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1032,1/3/2019,1/3/2019,2019,ICSA-19-003-03,Hetronic Nova-M,Hetronic,Nova-M,Hetronic Nova-M - remote control transmitter and receiver versions affected: Transmitters: Nova-M: all versions prior to r161; Receivers:ES-CAN-HL: all versions prior to Main r1864; Estop_v24; BMS-HL: all versions prior to Main r1175; Estop_v24; MLC: all versions prior to Main r1600; Estop_v24; andDC Mobile: all versions prior to Main r515; Estop_v24.,CVE-2018-19023,7.6,High,CWE-294,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1031,12/20/2018,12/20/2018,2018,ICSA-18-354-01,Horner Automation Cscape,Horner Automation,Cscape,The following versions of Cscape - Control System Application programming software are affected: Cscape Version 9.80.75.3 SP3 and prior.,CVE-2018-19005,6.6,Medium,CWE-20,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1030,12/20/2018,12/20/2018,2018,ICSA-18-354-02,Schneider Electric EcoStruxure,Schneider Electric,EcoStruxure,The following versions of EcoStruxure - IoT-enabled architecture and platform are affected: EcoStruxure Power Monitoring Expert (PME) Version 8.2 (all editions) | EcoStruxure Energy Expert 1.3 (formerly Power Manager) | EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module | EcoStruxure Power Monitoring Expert (PME) Version 9.0 | EcoStruxure Energy Expert Version 2.0 andEcoStruxure Power SCADA Operation (PSO) 9.0 Advanced Reports and Dashboards Module.,CVE-2018-7797,7.4,High,CWE-601,Commercial Facilities; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1029,11/27/2018,11/27/2018,2018,ICSA-18-331-02,Rockwell Automation FactoryTalk Services Platform,Rockwell Automation,FactoryTalk Services Platform,The following versions of FactoryTalk Services Platform - services-oriented architecture platform are affected: FactoryTalk Services Platform | v2.90 and earlier.,CVE-2018-18981,7.5,High,CWE-122,Food and Agriculture; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1028,12/18/2018,12/18/2018,2018,ICSA-18-352-01,ABB GATE-E2,ABB,GATE-E2,The following versions of the Gateway Ethernet devices used in Pluto Safety PLC systems are affected: GATE-E1 (EOL 2013) andGATE-E2 (EOL OCT 2018).,"CVE-2018-18995, CVE-2018-18997",9.8,Critical,"CWE-79, CWE-306",Critical Manufacturing,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1027,12/18/2018,12/18/2018,2018,ICSA-18-352-02,Advantech WebAccess/SCADA,Advantech,WebAccess/SCADA,The following versions of WebAccess/SCADA - SCADA software platform are affected: WebAccess/SCADA Version 8.,CVE-2018-18999,7.3,High,CWE-20,Critical Manufacturing; Energy; Water and Wastewater,"Taiwan, United States, Asia, East Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1026,12/18/2018,12/18/2018,2018,ICSA-18-352-03,3S-Smart Software Solutions GmbH CODESYS Control V3 Products,3S-Smart Software Solutions GmbH,CODESYS Control V3 Products,3S-Smart Software Solutions GmbH reports the vulnerability affects all variants of CODESYS Control V3 products containing the CmpSecureChannel or CmpUserMgr components prior to Version 3.5.14.0 of the following products - regardless of the CPU type or operating system: Control for BeagleBone | CODESYS Control for BeagleBone | CODESYS Control for emPC-A/iMX6 | CODESYS Control for IOT2000 | CODESYS Control for Linux | CODESYS Control for PFC100 | CODESYS Control for PFC200 | CODESYS Control for Raspberry Pi | CODESYS Control RTE V3 | CODESYS Control RTE V3 (for Beckhoff CX) | CODESYS Control Win V3 (also part of the CODESYS setup) | CODESYS V3 Simulation Runtime (part of the CODESYS Development System) | CODESYS Control V3 Runtime System Toolkit and CODESYS HMI V3.,CVE-2018-10612,9.8,Critical,CWE-284,Critical Manufacturing; Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1025,12/18/2018,12/18/2018,2018,ICSA-18-352-04,3S-Smart Software Solutions GmbH CODESYS V3 Products,3S-Smart Software Solutions GmbH,CODESYS V3 Products,3S-Smart Software Solutions GmbH reports these vulnerabilities affect the following CODESYS V3 products: CODESYS Control for BeagleBone | CODESYS Control for emPC-A/iMX6 | CODESYS Control for IOT2000 | CODESYS Control for Linux | CODESYS Control for PFC100 | CODESYS Control for PFC200 | CODESYS Control for Raspberry Pi | CODESYS Control RTE V3 | CODESYS Control RTE V3 (for Beckhoff CX) | CODESYS Control Win V3 (also part of the CODESYS Development System setup) | CODESYS Control V3 Runtime System Toolkit | CODESYS V3 Embedded Target Visu Toolkit | CODESYS V3 Remote Target Visu Toolkit | CODESYS V3 Safety SIL2 | CODESYS Gateway V3 | CODESYS HMI V3 | CODESYS OPC Server V3 | CODESYS PLC Handler SDK | CODESYS V3 Development System andCODESYS V3 Simulation Runtime (part of the CODESYS Development System).,"CVE-2018-20025, CVE-2018-20026",9.4,Critical,"CWE-923, CWE-330",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1024,12/18/2018,9/25/2020,2018,ICSA-18-352-05,Siemens TIM 1531 IRC Modules,Siemens,TIM 1531 IRC Modules,The following versions of TIM 1531 IRC - communication module for SIMATIC S7-1500 | S7-400 and S7-300 with SINAUT ST7 are affected: TIM 1531 IRC all versions prior to 2.0.,CVE-2018-13816,10.0,Critical,CWE-306,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1023,12/18/2018,12/18/2018,2018,ICSA-18-352-06,ABB CMS-770,ABB,CMS-770,The following versions of CMS-770 from ABB and Busch-Jaeger brands are affected: CMS-770: Software Versions 1.7.1 and prior.,CVE-2018-17928,8.8,High,CWE-287,Multiple Critical Sectors,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1022,12/18/2018,12/18/2018,2018,ICSA-18-352-07,ABB M2M ETHERNET,ABB,M2M ETHERNET,The following versions of M2M ETHERNET - network analyzer are affected: M2M ETHERNET: FW Versions 2.22 and prior | ETH-FW Versions 1.01 and prior.,CVE-2018-17926,6.3,Medium,CWE-287,Multiple Critical Sectors,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1021,12/13/2018,5/13/2020,2018,ICSMA-18-347-01,"Medtronic 9790, 2090 CareLink, and 29901 Encore Programmers",Medtronic,"9790, 2090 CareLink, and 29901 Encore Programmers",The following versions of Medtronic CareLink and Encore Programmers | devices used by trained personnel at hospitals and clinics to program and manage Medtronic cardiac devices are affected: CareLink 9790 Programmer | all versions | CareLink 2090 Programmer | all versions and 29901 Encore Programmer | all versions.,CVE-2018-18984,4.6,Medium,CWE-311,Healthcare and Public Health,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1020,12/13/2018,12/13/2018,2018,ICSA-18-347-01,Schneider Electric GUIcon Eurotherm,Schneider Electric,GUIcon Eurotherm,The following product is affected: Eurotherm by Schneider Electric GUIcon Version 2.0 (Gold Build 683.0).,"CVE-2018-7813, CVE-2018-7815, CVE-2018-7814",7.8,High,"CWE-843, CWE-121",Critical Manufacturing,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1019,12/13/2018,2/12/2019,2018,ICSA-18-347-02,Siemens EN100 Ethernet Communication Module and SIPROTEC 5 Relays (Update A),Siemens,EN100 Ethernet Communication Module and SIPROTEC 5 Relays,Siemens reports the vulnerabilities affect the following versions of the EN100 Ethernet Communication Module and SIPROTEC 5 relays: Firmware variant IEC 61850 for EN100 Ethernet module: All versions prior to v4.33 | Firmware variant PROFINET IO for EN100 Ethernet module: All versions | Firmware variant Modbus TCP for EN100 Ethernet module: All versions | Firmware variant DNP3 TCP for EN100 Ethernet module: All versions | Firmware variant IEC104 for EN100 Ethernet module: All versions prior to v1.22 | Firmware variant IEC104 for EN100 Ethernet module: All versions | SIPROTEC 5 relays with CPU variants CP300 and CP100 and the respective Ethernet communication modules: All versions prior to v7.80 | SIPROTEC 5 relays with CPU variants CP200 and the respective Ethernet communication modules: All versions prior to v7.58 | Some products are only affected by one of the two vulnerabilities. Please see Siemens advisory SSA-635129 for additional details.,"CVE-2018-11451, CVE-2018-11452",7.5,High,CWE-20,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1018,12/13/2018,12/13/2018,2018,ICSA-18-347-03,Geutebruck GmbH E2 Series IP Cameras,Geutebruck,GmbH E2 Series IP Cameras,Geutebruck reports the vulnerability affect the following IP cameras: E2 series cameras running firmware versions prior to 1.12.0.25.,CVE-2018-19007,7.2,High,CWE-78,Commercial Facilities; Energy; Financial Services; Healthcare and Public Health,"Australia, Germany, United States, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1017,12/13/2018,12/13/2018,2018,ICSA-18-347-04,"GE Mark VIe, EX2100e, EX2100e_Reg, and LS2100e",GE,"Mark VIe, EX2100e, EX2100e_Reg, and LS2100e",The following versions of the Mark Vie - distributed control system and associated products are affected: Mark VIe Versions 03.03.28C to 05.02.04C | EX2100e All versions prior to v04.09.00C | EX2100e_Reg All versions prior to v04.09.00C and LS2100e All versions prior to v04.09.00C.,CVE-2018-19003,7.4,High,CWE-22,Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1016,12/11/2018,12/11/2018,2018,ICSA-18-345-01,Siemens SINAMICS PERFECT HARMONY GH180,Siemens,SINAMICS PERFECT HARMONY GH180,Siemens has analyzed the vulnerability and has determined this vulnerability applies to the following HMIs: SINAMICS PERFECT HARMONY GH180 Drives: Serial numbers beginning MLFB 6SR32 with option A30 (HMIs 12 inch or larger) SINAMICS PERFECT HARMONY GH180 Drives: Serial numbers beginning MLFB 6SR42 with option A30 (HMIs 12 inch or larger) SINAMICS PERFECT HARMONY GH180 Drives: Serial numbers beginning MLFB 6SR52 with option A30 (HMIs 12 inch or larger | SINAMICS PERFECT HARMONY GH180 Drives: Serial numbers beginning MLFB 6SR325 (High Availability) SINAMICS PERFECT HARMONY GH180 Drives: Serial numbers beginning MLFB 6SR32 with option A30 (HMIs 12 inch or larger) where the HMI is operating under Microsoft Windows XP SINAMICS PERFECT HARMONY GH180 Drives: Serial numbers beginning MLFB 6SR42 with option A30 (HMIs 12 inch or larger) where the HMI is operating under Microsoft Windows XP SINAMICS PERFECT HARMONY GH180 Drives: Serial numbers beginning MLFB 6SR52 with option A30 (HMIs 12 inch or larger) where the HMI is operating under Microsoft Windows XP SINAMICS PERFECT HARMONY GH180 Drives: Serial numbers beginning MLFB 6SR325 (High Availability) where the HMI is operating under Microsoft Windows.,CVE-2018-6690,7.1,High,CWE-284,Chemical; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1015,12/11/2018,3/12/2019,2018,ICSA-18-345-02,Siemens SINUMERIK Controllers (Update A),Siemens,SINUMERIK Controllers,Siemens reports the vulnerabilities affect the following versions of the SINUMERIK CNC controllers: SINUMERIK 808D v4.7 all versions prior to v4.91 | SINUMERIK 808D v4.8 all versions prior to v4.91 | SINUMERIK 828D v4.7 all versions prior to v4.7 SP6 HF1 | SINUMERIK 840D sl v4.7 all versions prior to v4.7 SP6 HF5 and SINUMERIK 840D sl v4.8 all versions prior to v4.8 SP3 | Some products are not affected by all of the vulnerabilities. Please see Siemens advisory SSA-170881 for additional details.,"CVE-2018-11457, CVE-2018-11458, CVE-2018-11459, CVE-2018-11460, CVE-2018-11461, CVE-2018-11462, CVE-2018-11463, CVE-2018-11464, CVE-2018-11465, CVE-2018-11466",10.0,Critical,"CWE-122, CWE-190, CWE-264, CWE-693, CWE-121, CWE-248",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1014,12/6/2018,12/6/2018,2018,ICSMA-18-340-01,Philips HealthSuite Health Android App,Philips,HealthSuite Health Android App,Philips reports the vulnerability affects all versions of the Philips HealthSuite Health Android App.,CVE-2018-19001,3.5,Low,CWE-326,Healthcare and Public Health,"Germany, United Kingdom, Netherlands, United States",Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1013,12/6/2018,12/6/2018,2018,ICSA-18-340-01,GE Proficy GDS,GE,Proficy GDS,The following versions of GE Cimplicity ship with the affected GDS service: Cimplicity 9.0 R2 | Cimplicity 9.5 andCimplicity 10.0.,CVE-2018-15362,8.2,High,CWE-611,Chemical; Critical Manufacturing; Dams; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1012,11/6/2018,11/6/2018,2018,ICSA-18-310-02,Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules,Rockwell Automation,MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules,Rockwell Automation reports the vulnerability affects the following PLC products: MicroLogix 1400 Controllers Series A | all versions Series B | v21.003 and earlier Series C | v21.003 and earlier1756 ControlLogix EtherNet/IP Communications Modules1756-ENBT | all versions1756-EWEB Series A | all versions Series B | all versions1756-EN2F Series A | all versions Series B | all versions Series C | v10.10 and earlier1756-EN2T Series A | all versions Series B | all versions Series C | all versions Series D | v10.10 and earlier1756-EN2TRSeries A | all versions Series B | all versions Series C | v10.10 and earlier1756-EN3TR Series A | all versions Series B | v10.10 and earlier.,CVE-2018-17924,8.6,High,CWE-306,Critical Manufacturing; Food and Agriculture; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1011,12/4/2018,12/4/2018,2018,ICSA-18-338-01,Omron CX-One,Omron,CX-One,CX-One Versions 4.42 and prior - including the following applications: CX-Programmer Versions 9.66 and prior andCX-Server Versions 5.0.23 and prior.,CVE-2018-18993,6.6,Medium,"CWE-121, CWE-416",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1010,12/4/2018,12/4/2018,2018,ICSA-18-338-02,SpiderControl SCADA WebServer,SpiderControl,SCADA WebServer,The following versions of SCADA WebServer - software management platform are affected: SCADA WebServer: versions prior to 2.03.0001.,CVE-2018-18991,6.1,Medium,CWE-79,Critical Manufacturing,"Switzerland, Europe",Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1009,11/29/2018,11/29/2018,2018,ICSA-18-333-01,INVT Electric VT-Designer,INVT Electric,VT-Designer,ZDI reports the following versions of VT-Designer are affected: VT-Designer 2.1.7.31. Other versions could also be affected.,"CVE-2018-18987, CVE-2018-18983",6.3,Medium,"CWE-502, CWE-122",Commercial Facilities; Critical Manufacturing; Energy; Information Technology; Transportation Systems,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1008,11/27/2018,11/27/2018,2018,ICSA-18-331-01,AVEVA Vijeo Citect and Citect SCADA,AVEVA,Vijeo Citect and Citect SCADA,AVEVA reports that a vulnerability in Schneider Electric Software Update utility versions prior to v2.2.0 affects the following AVEVA products: Vijeo Citect v7.40 |Vijeo Citect 2015 | Citect SCADA v7.40 | Citect SCADA 2015 andCitect SCADA 2016.,CVE-2018-7799,7.8,High,CWE-427,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1007,11/20/2018,11/20/2018,2018,ICSA-18-324-01,Teledyne DALSA Sherlock,Teledyne DALSA,Sherlock,The following versions of Sherlock - machine vision software interface are affected: Sherlock Version 7.2.7.4 and prior.,CVE-2018-17930,7.3,High,CWE-121,Critical Manufacturing,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1006,11/20/2018,11/20/2018,2018,ICSA-18-324-02,Schneider Electric Modicon M221,Schneider Electric,Modicon M221,Schneider Electric reports that the vulnerability affects the following Modicon products: Modicon M221 | all versions.,CVE-2018-7798,8.2,High,CWE-345,Commercial Facilities,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1005,11/13/2018,11/13/2018,2018,ICSA-18-317-01,"Siemens IEC 61850 System Configurator, DIGSI 5, DIGSI 4, SICAM PAS/PQS, SICAM PQ Analyzer, and SICAM SCC",Siemens,"IEC 61850 System Configurator, DIGSI 5, DIGSI 4, SICAM PAS/PQS, SICAM PQ Analyzer, and SICAM SCC",The following versions of Siemens products are affected: IEC 61850 system configurator all versions prior to v5.80 | DIGSI 5 (affected as IEC 61850 system configurator is incorporated) all versions prior to v7.80 | DIGSI 4 all versions prior to v4.93 | SICAM PAS/PQS all versions prior to v8.11 | SICAM PQ Analyzer all versions prior to v3.11 and SICAM SCC all versions prior to v9.02 HF3.,CVE-2018-4858,4.2,Medium,CWE-284,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1004,11/13/2018,8/11/2022,2018,ICSA-18-317-02,Siemens S7-400 CPUs (Update A),Siemens,S7-400 CPUs,"Siemens reports that the vulnerabilities affect the following SIMATIC S7-400 products: S7-400 v6 (including F) and below all versions, S7-400 PN/DP v7 (including F) all versions, S7-400H v4.5 and below all versions, --------- Begin Update A Part 1 of 3 -------- S7-400H v6, all versions prior to v6.0.9 --------- End Update A Part 1 of 3 ---------- S7-410 all versions prior to v8.2.1.",CVE-2018-16556,8.2,High,CWE-20,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1003,11/13/2018,11/13/2018,2018,ICSA-18-317-03,Siemens SIMATIC Panels and SIMATIC WinCC (TIA Portal),Siemens,SIMATIC Panels and SIMATIC WinCC (TIA Portal),"Siemens reports the vulnerability affects the following versions of SIMATIC Panel software and SIMATIC WinCC (TIA Portal): SIMATIC HMI Comfort Panels 4"" - 22"": All versions prior to v14 | SIMATIC HMI Comfort Outdoor Panels 7"" and 15"": All versions prior to v14 | SIMATIC HMI KTP Mobile Panels KTP400F | KTP700 | KTP700F | KTP900 und KTP900F: All versions prior to v14 | SIMATIC WinCC Runtime Advanced: All versions prior to v14 | SIMATIC WinCC Runtime Professional: All versions prior to v14 | SIMATIC WinCC (TIA Portal): All versions prior to v14 andSIMATIC HMI Classic Devices (TP/MP/OP/MP Mobile Panel): All versions.",CVE-2018-13814,4.3,Medium,CWE-94,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1002,11/13/2018,11/13/2018,2018,ICSA-18-317-04,Siemens SCALANCE S,Siemens,SCALANCE S,Siemens reports the following SCALANCE S products are affected: SCALANCE S602: All versions prior to v4.0.1.1 | SCALANCE S612: All versions prior to v4.0.1.1 | SCALANCE S623: All versions prior to v4.0.1.1 andSCALANCE S627-2M: All versions prior to v4.0.1.1.,CVE-2018-16555,4.7,Medium,CWE-79,Chemical; Communications; Critical Manufacturing; Dams; Defense Industrial Base; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1001,11/13/2018,3/12/2019,2018,ICSA-18-317-05,Siemens SIMATIC S7 (Update A),Siemens,SIMATIC S7,Siemens reports the following SIMATIC S7 products are affected: SIMATIC S7-1200: All versions prior to v4.3 and SIMATIC S7-1500: All versions prior to 2.6.,CVE-2018-13815,5.3,Medium,CWE-400,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1000,11/13/2018,11/13/2018,2018,ICSA-18-317-06,Siemens SIMATIC STEP 7 (TIA Portal),Siemens,SIMATIC STEP 7 (TIA Portal),Siemens reports the following SIMATIC STEP 7 product is affected: SIMATIC STEP 7 (TIA Portal): All versions prior to 15.1.,CVE-2018-13811,4.0,Medium,CWE-256,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 999,11/13/2018,11/13/2018,2018,ICSA-18-317-07,Siemens SIMATIC IT Production Suite,Siemens,SIMATIC IT Production Suite,Siemens reports this vulnerability affects the following products: SIMATIC IT LMS all versions | SIMATIC IT Production Suite: Versions 7.1 prior to Version 7.1 Upd3 and SIMATIC IT UA Discrete Manufacturing versions prior to Version 2.4.,CVE-2018-13804,7.7,High,CWE-287,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 998,11/13/2018,11/13/2018,2018,ICSA-18-317-08,Siemens SIMATIC Panels,Siemens,SIMATIC Panels,"Siemens reports the following SIMATIC products affected: SIMATIC HMI Comfort Panels 4""-22"" all versions prior to v15 Update 4 | SIMATIC HMI Comfort Outdoor Panels 7"" & 15"" all versions prior to v15 Update 4 | SIMATIC HMI KTP Mobile Panels all versions prior to v15 Update 4 KTP400F | KTP700 | KTP700F | KTP900 and KTP900F | SIMATIC WinCC Runtime Advanced all versions prior to v15 Update 4 | SIMATIC WinCC Runtime Professional all versions prior to v15 Update 4 | SIMATIC WinCC (TIA Portal) all versions prior to v15 Update 4 and SIMATIC HMI Classic Devices (TP/MP/OP/MP Mobile Panel) all versions.","CVE-2018-13812, CVE-2018-13813",7.5,High,"CWE-22, CWE-601",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 997,11/8/2018,11/8/2018,2018,ICSMA-18-312-01,Philips iSite and IntelliSpace PACS,Philips,iSite and IntelliSpace PACS,Philips reports the following versions of iSite and IntelliSpace PACS are affected: iSite PACS | all versions and IntelliSpace PACS | all versions.,CVE-2018-17906,6.3,Medium,CWE-521,Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 996,11/6/2018,11/8/2018,2018,ICSMA-18-310-01,Roche Diagnostics Point of Care Handheld Medical Devices (Update A),Roche,Diagnostics Point of Care Handheld Medical Devices,The following versions of Roche Diagnostics handheld medical devices are affected: Accu-Chek Inform II CoaguChek Pro II CoaguChek XS Plus CoaguChek XS Procobas h 232 POC Including the related base units (BU) | base unit hubs and handheld base units (HBU). Accu-Chek Units Not affected: Accu-Chek Inform II Base Unit Light Accu-Chek Inform II Base Unit NEW with Software 04.00.00 or newer.,"CVE-2018-18561, CVE-2018-18562, CVE-2018-18563, CVE-2018-18564, CVE-2018-18565",8.3,High,"CWE-284, CWE-287, CWE-78, CWE-434",Healthcare and Public Health,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 995,11/1/2018,11/1/2018,2018,ICSA-18-305-01,AVEVA InduSoft Web Studio and InTouch Edge HMI (formerly InTouch Machine Edition),AVEVA,InduSoft Web Studio and InTouch Edge HMI (formerly InTouch Machine Edition),AVEVA reports that these vulnerabilities affect the following products: InduSoft Web Studio versions prior to 8.1 SP2 andInTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2.,"CVE-2018-17916, CVE-2018-17914",9.8,Critical,"CWE-258, CWE-121",Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems; Water and Wastewater,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 994,11/1/2018,11/6/2018,2018,ICSA-18-305-02,Schneider Electric Software Update (SESU) (Update A),Schneider Electric,Software Update,Schneider Electric reports the vulnerability affects the following Software Update products: Schneider Electric Software Update (SESU) | all versions prior to v2.2.0. For a list of products that can optionally install the software - please see Schneider Electric's security notice SEVD-2018-298-01 available at the following location: https: //www.schneider-electric.com/en/download/document/SEVD-2018-298-01.,CVE-2018-7799,7.8,High,CWE-427,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 993,11/1/2018,11/1/2018,2018,ICSA-18-305-03,Circontrol CirCarLife,Circontrol,CirCarLife,The following versions of CirCarLife - electric vehicle charging station are affected: CirCarLife all versions prior to 4.3.1.,"CVE-2018-17918, CVE-2018-17922",10.0,Critical,"CWE-288, CWE-522",Transportation Systems,"Spain, Netherlands, Asia, Europe",Spain,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 992,11/1/2018,11/1/2018,2018,ICSA-18-305-04,Fr. Sauter AG CASE Suite,Fr. Sauter AG,CASE Suite,The following versions of CASE Suite are affected: CASE Suite Versions 3.10 and prior.,CVE-2018-17912,7.5,High,CWE-611,Critical Manufacturing,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 991,10/30/2018,10/30/2018,2018,ICSA-18-303-01,PEPPERL+FUCHS CT50-Ex,PEPPERL+FUCHS,CT50-Ex,The following versions of the CT50-Ex ecom mobile computer are affected: CT50-Ex running Android OS v4.4 and v6.0. The original manufacturer was Honeywell.,CVE-2018-14825,7.6,High,CWE-269,Communications; Critical Manufacturing; Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 990,10/25/2018,10/25/2018,2018,ICSA-18-298-01,GEOVAP Reliance 4 SCADA/HMI,GEOVAP,Reliance 4 SCADA/HMI,The following versions of Reliance 4 SCADA/HMI - SCADA/HMI system designed for the monitoring and control of industrial processes and for building automation are affected: Reliance SCADA Version 4.7.3 Update 3 and prior.,CVE-2018-17904,6.1,Medium,CWE-79,Critical Manufacturing; Energy; Transportation Systems; Water and Wastewater,Worldwide,Czech Republic,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 989,10/25/2018,10/25/2018,2018,ICSA-18-298-02,Advantech WebAccess,Advantech,WebAccess,The following versions of WebAccess are affected: WebAccess Versions 8.,"CVE-2018-17908, CVE-2018-17910",8.4,High,"CWE-284, CWE-121",Critical Manufacturing; Energy; Water and Wastewater,"Taiwan, United States, Asia, East Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 988,10/23/2018,10/23/2018,2018,ICSA-18-296-01,Advantech WebAccess,Advantech,WebAccess,The following versions of WebAccess are affected: WebAccess Versions 8.3.1 and prior.,"CVE-2018-14816, CVE-2018-14820, CVE-2018-14828, CVE-2018-14806",9.8,Critical,"CWE-73, CWE-22, CWE-269, CWE-121",Critical Manufacturing; Energy; Water and Wastewater,"Taiwan, United States, Asia, East Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 987,10/23/2018,10/25/2018,2018,ICSA-18-296-02,GAIN Electronic Co. Ltd SAGA1-L Series,GAIN Electronic Co. Ltd,SAGA1-L Series,According to GAIN Electronic Co. Ltd - the following product is affected: SAGA1-L8B: All firmware versions prior to A0.10.,"CVE-2018-17903, CVE-2018-17921, CVE-2018-17923",8.3,High,"CWE-294, CWE-284, CWE-287",Communications,"Taiwan, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 986,10/23/2018,10/23/2018,2018,ICSA-18-296-03,Telecrane F25 Series,Telecrane,F25 Series,The following versions of Telecrane remote controls are affected: F25 Series all versions prior to 00.0A.,CVE-2018-17935,7.6,High,CWE-294,Multiple Critical Sectors,"Taiwan, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 985,10/17/2018,1/31/2019,2018,ICSA-18-290-01,Omron CX-Supervisor (Update A),Omron,CX-Supervisor,The following versions of CX-Supervisor are affected: CX-Supervisor Versions 3.4.1.0 and prior.,"CVE-2018-17905, CVE-2018-17907, CVE-2018-17909, CVE-2018-17913",7.0,High,"CWE-119, CWE-704, CWE-125, CWE-416",Energy,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 984,10/16/2018,1/15/2019,2018,ICSA-18-289-01,LCDS - Leao Consultoria e Desenvolvimento de Sistemas Ltda ME LAquis SCADA,LCDS - Leao Consultoria e Desenvolvimento de Sistemas Ltda ME,LAquis SCADA,The following versions of LAquis SCADA - industrial automation software are affected: Smart Security Manager Versions 4.1.0.3870 and prior.,"CVE-2018-17893, CVE-2018-17895, CVE-2018-17897, CVE-2018-17899, CVE-2018-17901, CVE-2018-17911",7.8,High,"CWE-22, CWE-680, CWE-125, CWE-787, CWE-121, CWE-822",Chemical; Commercial Facilities; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,"Brazil, South America",Brazil,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 983,10/11/2018,10/11/2018,2018,ICSA-18-284-01,NUUO NVRmini2 and NVRsolo,NUUO,NVRmini2 and NVRsolo,The following versions of Nuuo NVRmini2 and NVRsolo - network video recorders are affected: All Versions 3.8.0 and prior.,"CVE-2018-1149, CVE-2018-1150",10.0,Critical,"CWE-489, CWE-121",Commercial Facilities; Financial Services; Government Facilities; Healthcare and Public Health; Transportation Systems,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 982,10/11/2018,11/20/2018,2018,ICSA-18-284-02,NUUO CMS (Update A),NUUO,CMS,The following versions of NUUO CMS - central software management platform are affected: CMS Versions 3.1 and prior. CMS Versions 3.3 and prior.,"CVE-2018-17888, CVE-2018-17890, CVE-2018-17892, CVE-2018-17894, CVE-2018-17934, CVE-2018-17936, CVE-2018-18982",9.8,Critical,"CWE-22, CWE-89, CWE-732, CWE-434, CWE-798, CWE-330, CWE-477",Commercial Facilities; Financial Services; Government Facilities; Healthcare and Public Health; Transportation Systems,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 981,10/11/2018,10/11/2018,2018,ICSA-18-284-03,Delta Industrial Automation TPEditor,Delta Electronics,TPEditor,The following versions of Delta Industrial Automation TPEditor - programming software for Delta text panels operating on Windows are affected: TPEditor Versions 1.90 and prior.,"CVE-2018-17929, CVE-2018-17927",6.6,Medium,"CWE-787, CWE-121",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 980,10/9/2018,10/9/2018,2018,ICSA-18-282-01,GE iFix,GE,iFix,GE reports this vulnerability in a Gigasoft component affects the following iFix HMI products: iFIX 2.0 - 5.0 | iFIX 5.1 | iFIX 5.5 and iFIX 5.8 Gigasoft components older than Version 8.0 are likely to be used in other products from other vendors also.,CVE-2018-17925,5.3,Medium,CWE-623,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 979,10/9/2018,10/9/2018,2018,ICSA-18-282-02,Siemens SCALANCE W1750D,Siemens,SCALANCE W1750D,Siemens reports the vulnerability affects the following SCALANCE W1750D products: SCALANCE W1750D: All versions prior to v8.3.0.1.,CVE-2017-13099,5.9,Medium,CWE-310,Chemical; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 978,10/9/2018,10/9/2018,2018,ICSA-18-282-03,Siemens ROX II,Siemens,ROX II,Siemens reports these vulnerabilities affect the following ROX II products: ROX II: All versions prior to v2.12.1.,"CVE-2018-13801, CVE-2018-13802",8.8,High,CWE-269,Energy; Healthcare and Public Health; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 977,10/9/2018,10/9/2018,2018,ICSA-18-282-04,Siemens SIMATIC S7-1200 CPU Family Version 4,Siemens,SIMATIC S7-1200 CPU Family Version 4,Siemens reports the vulnerability affects the following SIMATIC S7-1200 CPU products: SIMATIC S7-1200 CPU Family Version 4: All versions prior to 4.2.3.,CVE-2018-13800,7.5,High,CWE-352,Chemical; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 976,10/9/2018,2/12/2019,2018,ICSA-18-282-05,"Siemens SIMATIC S7-1500, SIMATIC S7-1500 Software Controller and SIMATIC ET 200SP OpenController (Update A)",Siemens,"SIMATIC S7-1500, SIMATIC S7-1500 Software Controller and SIMATIC ET 200SP OpenController",Siemens reports that this vulnerability affects the following products and versions: Simatic S7-1500 (incl. F) | all versions prior to v2.5 down to and including v2.0 | Simatic S7-1500 Software Controller all versions prior to v2.5 down to and including v2.0 | Simatic ET 200SP Open Controller all versions prior to v2.5 down to and including v2.0.,CVE-2018-13805,5.3,Medium,CWE-20,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 975,10/9/2018,10/9/2018,2018,ICSA-18-282-06,"Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server","Hangzhou Xiongmai Technology Co., Ltd",XMeye P2P Cloud Server,"All products using XMeye P2P Cloud Server are affected. Hangzhou Xiongmai Technology Co. Ltd acts primarily as an Original Equipment Manufacturer (OEM) and sells few - if any Xiongmai-branded products. Various vendors sell branded devices with Hangzhou Xiongmai Technology Co. Ltd hardware/firmware inside. Use the following methods to check the hardware/firmware: Check if the product documentation/specifications mention the ""XMEye"" feature.Access the err.htm page on the device (http: ///err.htm). Xiongmai or XMeye will be referenced.","CVE-2018-17917, CVE-2018-17919, CVE-2018-17915",8.1,High,"CWE-912, CWE-311, CWE-341",Multiple Critical Sectors,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 974,10/9/2018,10/9/2018,2018,ICSA-18-282-07,Fuji Electric Energy Savings Estimator,Fuji Electric,Energy Savings Estimator,The following versions of Fuji Electric Smart Security Manager - software management platform are affected: Fuji Electric Energy Savings Estimator Versions V.1.0.2.0 and prior.,CVE-2018-14812,7.3,High,CWE-427,Critical Manufacturing; Energy,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 973,10/4/2018,10/4/2018,2018,ICSMA-18-277-01,Carestream Vue RIS,Carestream,Vue RIS,The following versions of Carestream Vue RIS - web-based radiology information system are affected: RIS Client Builds: Version 11.2 and prior running on a Windows 8.1 machine with IIS/7.5.,CVE-2018-17891,3.7,Low,CWE-209,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 972,10/4/2018,10/4/2018,2018,ICSMA-18-277-02,Change Healthcare PeerVue Web Server,Change Healthcare,PeerVue Web Server,Change Healthcare reports the vulnerability affects the following product: PeerVue Web Server all versions up to 7.6.2.,CVE-2018-10624,4.3,Medium,CWE-209,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 971,10/2/2018,10/2/2018,2018,ICSA-18-275-01,Delta Electronics ISPSoft,Delta Electronics,ISPSoft,The following versions of ISPSoft - PLC program development tool are affected: ISPSoft Version 3.0.5 and prior.,CVE-2018-14800,5.3,Medium,CWE-121,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 970,10/2/2018,10/2/2018,2018,ICSA-18-275-02,GE Communicator,GE,Communicator,The following versions of Communicator - application for programming and monitoring supported metering devices are affected: Third party product Gigasoft | v5 and prior included in Communicator 3.15 and prior.,CVE-2017-7908,7.6,High,CWE-122,Critical Manufacturing; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 969,10/2/2018,10/2/2018,2018,ICSA-18-275-03,Entes EMG 12,Entes,EMG 12,The following versions of EMG 12 - Ethernet Modbus Gateway are affected: EMG12 Ethernet Modbus Gateway Firmware Version 2.57 and prior.,"CVE-2018-14826, CVE-2018-14822",9.8,Critical,"CWE-287, CWE-598",Critical Manufacturing; Energy,Worldwide,Turkey,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 968,9/27/2018,9/27/2018,2018,ICSA-18-270-01,Emerson AMS Device Manager,Emerson,AMS Device Manager,The following versions of AMS Device Manager - Asset Management System are affected: AMS Device Manager: v12.0 to v13.5.,"CVE-2018-14804, CVE-2018-14808",10.0,Critical,"CWE-284, CWE-269",Chemical; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 967,9/27/2018,2/7/2019,2018,ICSA-18-270-02,Fuji Electric Alpha5 Smart Loader (Update A),Fuji Electric,Alpha5 Smart Loader,The following versions of Alpha5 Smart Loader - servo drive are affected: Alpha5 Smart Loader Versions 3.7 and prior.,"CVE-2018-14788, CVE-2018-14794",9.8,Critical,"CWE-120, CWE-122",Commercial Facilities; Critical Manufacturing,"Japan, Asia, Europe",Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 966,9/27/2018,2/14/2019,2018,ICSA-18-270-03,Fuji Electric FRENIC Devices (Update A),Fuji Electric,FRENIC Devices,The following versions of FRENIC Loader | FRENIC-Mini (C1) | FRENIC-Mini (C2) | FRENIC-Eco | FRENIC-Multi | FRENIC-MEGA | FRENIC-Ace | HVAC drive devices are affected: FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1) | FRENIC-Mini (C2) | FRENIC-Eco | FRENIC-Multi | FRENIC-MEGA | FRENIC-Ace.,"CVE-2018-14790, CVE-2018-14798, CVE-2018-14802",9.8,Critical,"CWE-126, CWE-125, CWE-121",Commercial Facilities,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 965,9/27/2018,9/27/2018,2018,ICSA-18-270-04,Delta Electronics Delta Industrial Automation PMSoft,Delta Electronics,Delta Industrial Automation PMSoft,The following versions of Delta Industrial Automation PMSoft - software development tool for motion controllers are affected: Delta Industrial Automation PMSoft v2.11 or prior.,CVE-2018-14824,4.3,Medium,CWE-125,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 964,9/20/2018,9/20/2018,2018,ICSA-18-263-01,Tec4Data SmartCooler,Tec4Data,SmartCooler,The following versions of SmartCooler - cooling appliance are affected: SmartCooler | all versions prior to firmware 180806.,CVE-2018-14796,7.5,High,CWE-306,Commercial Facilities,Worldwide,Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 963,9/20/2018,10/10/2018,2018,ICSA-18-263-02,Rockwell Automation RSLinx Classic,Rockwell Automation,RSLinx Classic,The following versions of RSLinx Classic - software platform that allows Logix5000 Programmable Automation Controllers to connect to a wide variety of Rockwell Software applications are affected: RSLinx Classic Versions 4.00.01 and prior.,"CVE-2018-14829, CVE-2018-14821, CVE-2018-14827",10.0,Critical,"CWE-122, CWE-121, CWE-400",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 962,9/18/2018,9/18/2018,2018,ICSA-18-261-01,WECON PLC Editor,WECON,PLC Editor,The following version of PLC Editor - ladder logic software are reported to be affected: 1.3.3U. Additional versions may also be vulnerable.,CVE-2018-14792,6.3,Medium,CWE-121,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 961,9/13/2018,9/13/2018,2018,ICSA-18-256-01,Honeywell Mobile Computers with Android Operating Systems,Honeywell,Mobile Computers with Android Operating Systems,The following versions of Honeywell Mobile Computers (hand-held computers) are affected: CT60 running Android OS 7.1 | CN80 running Android OS 7.1 | CT40 running Android OS 7.1 | CK75 running Android OS 6.0 | CN75 running Android OS 6.0 | CN75e running Android OS 6.0 | CT50 running Android OS 6.0 | D75e running Android OS 6.0 | CT50 running Android OS 4.4 | D75e running Android OS 4.4 | CN51 running Android OS 6.0 | EDA50k running Android 4.4 | EDA50 running Android OS 7.1 | EDA50k running Android OS 7.1 | EDA70 running Android OS 7.1 | EDA60k running Android OS 7.1 andEDA51 running Android OS 8.1.,CVE-2018-14825,7.6,High,CWE-269,Commercial Facilities; Critical Manufacturing; Energy; Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 960,9/11/2018,9/13/2018,2018,ICSA-18-254-01,Fuji Electric V-Server,Fuji Electric,V-Server,The following versions of V-Server - data collection and management service are affected: V-Server 4.0.3.0 and prior.,"CVE-2018-14809, CVE-2018-14811, CVE-2018-14813, CVE-2018-14815, CVE-2018-14817, CVE-2018-14819, CVE-2018-14823",7.3,High,"CWE-122, CWE-191, CWE-125, CWE-787, CWE-121, CWE-822, CWE-416",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 959,9/11/2018,9/11/2018,2018,ICSA-18-254-02,Fuji Electric V-Server Lite,Fuji Electric,V-Server Lite,The following versions of V-Server Lite - data collection and management service are affected: V-Server Lite 4.0.3.0 and prior.,CVE-2018-10637,7.8,High,CWE-120,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 958,9/11/2018,9/11/2018,2018,ICSA-18-254-03,Siemens TD Keypad Designer,Siemens,TD Keypad Designer,According to Siemens the following products are affected: TD Keypad Designer: All versions.,CVE-2018-13806,7.3,High,CWE-427,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 957,9/11/2018,9/11/2018,2018,ICSA-18-254-04,Siemens SIMATIC WinCC OA,Siemens,SIMATIC WinCC OA,The following versions of SIMATIC WinCC OA - client-server HMI are affected: SIMATIC WinCC OA Version 3.14 and prior.,CVE-2018-13799,9.1,Critical,CWE-284,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 956,9/11/2018,9/11/2018,2018,ICSA-18-254-05,Siemens SCALANCE X Switches,Siemens,SCALANCE X Switches,The following versions of SCALANCE X Switches which are used to connect industrial components like programmable logic controllers (PLCs) or human machine interfaces (HMIs) are affected: SCALANCE X300: All versions prior to 4.0.0 | SCALANCE X408: All versions prior to 4.0.0 and SCALANCE X414: All versions.,CVE-2018-13807,8.6,High,CWE-20,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 955,9/6/2018,9/6/2018,2018,ICSA-18-249-01,Ice Qube Thermal Management Center,Ice Qube,Thermal Management Center,The following versions of Thermal Management Center - environmental software management platform are affected: Thermal Management Center | all versions prior to 4.13.,"CVE-2017-14026, CVE-2017-16714",8.6,High,"CWE-287, CWE-256",Commercial Facilities; Critical Manufacturing; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 954,9/4/2018,10/18/2018,2018,ICSA-18-247-01,Opto 22 PAC Control Basic and PAC Control Professional,Opto 22,PAC Control Basic and PAC Control Professional,The following versions of PAC Control - control programing software are affected: PAC Control Basic Versions R10.0a and prior and PAC Control Professional Versions R10.0a and prior.,CVE-2018-14807,8.4,High,CWE-121,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 953,8/30/2018,8/30/2018,2018,ICSA-18-242-01,Philips e-Alert Unit,Philips,e-Alert Unit,The following Philips e-Alert versions are affected: Version R2.1 and prior.,"CVE-2018-8850, CVE-2018-8846, CVE-2018-14803, CVE-2018-8848, CVE-2018-8842, CVE-2018-8844, CVE-2018-8852, CVE-2018-8854, CVE-2018-8856",9.8,Critical,"CWE-319, CWE-352, CWE-200, CWE-20, CWE-79, CWE-276, CWE-384, CWE-400, CWE-798",Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 952,8/28/2018,8/28/2018,2018,ICSMA-18-240-01,Qualcomm Life Capsule,Qualcomm Life,Capsule,The following versions of Capsule Datacaptor Terminal Server (DTS) | part of a medical device information system are affected: Allegro RomPager embedded web server versions 4.01 through 4.34 included in Capsule DTS | all versions affected.,CVE-2014-9222,9.8,Critical,CWE-17,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 951,8/28/2018,8/28/2018,2018,ICSA-18-240-01,Schneider Electric Modicon M221,Schneider Electric,Modicon M221,Schneider Electric reports the vulnerabilities affect the following Modicon M221 products: Modicon M221 | all references | all versions prior to firmware v1.6.2.0.,"CVE-2018-7790, CVE-2018-7791, CVE-2018-7792",7.7,High,"CWE-199, CWE-264",Commercial Facilities,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 950,8/28/2018,8/28/2018,2018,ICSA-18-240-02,Schneider Electric Modicon M221,Schneider Electric,Modicon M221,The following versions of Modicon M221 - programmable logic controller (PLC) are affected: Modicon M221 all references and versions prior to firmware v1.6.2.0.,CVE-2018-7789,4.8,Medium,CWE-754,Commercial Facilities,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 949,8/28/2018,8/28/2018,2018,ICSA-18-240-03,Schneider Electric PowerLogic PM5560,Schneider Electric,PowerLogic PM5560,The following versions of PowerLogic PM5560 - power management system are affected: PowerLogic PM5560 all versions prior to firmware Version 2.5.4.,CVE-2018-7795,8.2,High,CWE-79,Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 948,8/28/2018,10/2/2018,2018,ICSA-18-240-04,ABB eSOMS (Update A),ABB,eSOMS,The following version of ABB eSOMS - electronic shift operations management system is affected: eSOMS Version 6.0.2.,CVE-2018-14805,9.8,Critical,CWE-287,Chemical; Defense Industrial Base; Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 947,8/23/2018,8/23/2018,2018,ICSMA-18-235-01,BD Alaris Plus,"Becton, Dickinson and Company (BD)",Alaris Plus,The following versions of Alaris Plus - medical syringe pumps | Versions 2.3.6 and prior are affected: Alaris GS | Alaris GH | Alaris CC andAlaris TIVA.,CVE-2018-14786,9.4,Critical,CWE-287,Healthcare and Public Health,"United States, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 946,8/21/2018,10/11/2018,2018,ICSMA-18-233-01,Philips IntelliVue Information Center iX (Update B),Philips,IntelliVue Information Center iX,The following versions of Philips IntelliVue Information Center iX - real-time central monitoring system are affected: Philips IntelliVue Information Center iX Versions B.02.,CVE-1999-0103,5.7,Medium,CWE-400,Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 945,8/21/2018,8/21/2018,2018,ICSA-18-233-01,"Yokogawa iDefine, STARDOM, ASTPLANNER, and TriFellows",Yokogawa,"iDefine, STARDOM, ASTPLANNER, and TriFellows",According to Yokogawa the following products are affected: ASTPLANNER: R15.01 and prior | iDefine for ProSafe-RS: R1.16.3 and prior | STARDOM: VDS R7.50 and prior and FCN/FCJ Simulator R4.20 and prior and TriFellows: Version 5.04 and prior.,CVE-2018-0651,8.6,High,CWE-121,Critical Manufacturing; Energy; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 944,8/16/2018,9/5/2018,2018,ICSA-18-228-01,Emerson DeltaV DCS Workstations,Emerson,DeltaV DCS Workstations,The following versions of DeltaV - Distributed Control System (DCS) are affected: DeltaV: v11.3.1 | v12.3.1 | v13.3.0 | v13.3.1 | R5.,"CVE-2018-14797, CVE-2018-14795, CVE-2018-14791, CVE-2018-14793",9.6,Critical,"CWE-269, CWE-23, CWE-121, CWE-427",Chemical; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 943,7/10/2018,10/30/2018,2018,ICSA-18-191-03,Tridium Niagara,Tridium,Niagara,The following versions of Tridum Niagara are affected while running on the Microsoft Windows operating system: Niagara AX Framework Version 3.8 and prior and Niagara 4 Framework Versions 4.4 and prior.,"CVE-2017-16744, CVE-2017-16748",7.4,High,"CWE-287, CWE-22",Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 942,8/14/2018,8/14/2018,2018,ICSMA-18-226-01,Philips IntelliSpace Cardiovascular Vulnerabilities,Philips,IntelliSpace Cardiovascular,The following versions of Philips' IntelliSpace Cardiovascular (ISCV) products - comprehensive cardiac image and information management software are affected: IntelliSpace Cardiovascular | Version 3.1 or prior and Xcelera Version 4.1 or prior.,"CVE-2018-14787, CVE-2018-14789",7.3,High,"CWE-269, CWE-428",Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 941,8/14/2018,10/9/2018,2018,ICSA-18-226-01,Siemens SIMATIC STEP 7 and SIMATIC WinCC (Update A),Siemens,SIMATIC STEP 7 and SIMATIC WinCC,Siemens reports these vulnerabilities affect the following SIMATIC STEP 7 products: SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) v10 | v11 | v12: All versions | SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) v13: All versions prior to v13 SP2 Update 2 | SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) v14: All versions < v14 SP1 Update 6 and SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) v15: All versions < v15 Update 2.,"CVE-2018-11453, CVE-2018-11454",8.6,High,CWE-276,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 940,8/14/2018,4/9/2019,2018,ICSA-18-226-02,Siemens OpenSSL Vulnerability in Industrial Products (Update E),Siemens,OpenSSL in Industrial Products,"Siemens reports that the vulnerability affects the following industrial products: MindConnect IoT2040: All versions prior to v03.01 | MindConnect Nano (IPC227D): All versions prior to v03.01 | SIMATIC ET 200SP Open Controller CPU 1515SP PC: All versions prior to v2.1.6 | SIMATIC HMI WinCC Flexible: All versions prior to v15.1 | SIMATIC IPC DiagMonitor: All versions prior to v5.0.3 | SIMATIC IPC DiagBase: All versions prior to v2.1.1.0 | SIMATIC S7-1200: All versions prior to v4.2.3SIMATIC STEP 7 (TIA Portal) v13: All versions prior to v13 SP2 Update 2 | SIMATIC STEP 7 (TIA Portal) v14: All versionsSIMATIC STEP 7 (TIA Portal) v15: All versions prior to v15 SP2 Update 2 | SIMATIC WinCC (TIA Portal) v13: All versions prior to v13 SP2 Update 2 | SIMATIC WinCC (TIA Portal) v14: All versions prior to v14 SP1 Update 6 | SIMATIC WinCC (TIA Portal) v15: All versions prior to v15 SP2 Update 2 | SIMATIC S7-1500: All versions prior to v2.5.2 | SIMATIC S7-1500 Software Controller: All versions prior to v2.6 | SIMATIC WinCC OA v3.14: All versions | SIMATIC WinCC OA v3.15: All versions | SIMATIC WinCC OA v3.16: All versions | SINUMERIK Integrate Access MyMachine service engineer client as part of Sinumerik Integrate Product suite: All versions prior to and including v4.1.7, and SINUMERIK Integrate Operate Client as part of Sinumerik Integrate Product suite: All versions prior to and including v2.0.11 / v3.0.11.",CVE-2017-3737,5.9,Medium,CWE-319,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 939,8/14/2018,8/14/2018,2018,ICSA-18-226-03,Siemens Automation License Manager,Siemens,Automation License Manager,According to Siemens the following products are affected: Automation License Manager 5: All versions prior to 5.3.4.4 and Automation License Manager 6: All versions prior to 6.0.1 (only affected by CVE-2018-11455).,"CVE-2018-11455, CVE-2018-11456",8.8,High,"CWE-20, CWE-23",Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 938,8/9/2018,8/21/2018,2018,ICSA-18-221-01,Crestron TSW-X60 and MC3,Crestron,TSW-X60 and MC3,The following products and versions are affected: TSW-X60 | all versions prior to 2.001.0037.001; and MC3 | all versions prior to 1.502.0047.001.,"CVE-2018-11228, CVE-2018-11229, CVE-2018-10630, CVE-2018-13341",9.8,Critical,"CWE-284, CWE-78, CWE-522",Commercial Facilities; Government Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 937,8/9/2018,8/9/2018,2018,ICSA-18-221-02,NetComm Wireless 4G LTE Light Industrial M2M Router,NetComm Wireless,4G LTE Light Industrial M2M Router,The following versions of the 4G LTE Light Industrial M2M Router (NWL-25) - cellular router are affected: 4G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior.,"CVE-2018-14782, CVE-2018-14783, CVE-2018-14784, CVE-2018-14785",9.8,Critical,"CWE-352, CWE-548, CWE-200, CWE-79",Communications,Worldwide,Australia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 936,8/7/2018,5/7/2026,2018,ICSMA-18-219-01,Medtronic MyCareLink 24950 Patient Monitor (Update A),Medtronic,Medtronic MyCareLink 24950 Patient Monitor (Update A),"Medtronic 24950 MyCareLink Monitor: vers:all/*, Medtronic 24952 MyCareLink Monitor: vers:all/*","CVE-2018-10626, CVE-2018-10622",6.8,Medium,"CWE-313, CWE-345",Healthcare and Public Health,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 935,8/7/2018,9/20/2018,2018,ICSA-18-219-01,Delta Electronics CNCSoft and ScreenEditor,Delta Electronics,CNCSoft and ScreenEditor,According to Delta Electronics the following products are affected: CNCSoft Version 1.00.83 and prior and the accompanying ScreenEditor Version 1.00.54.,"CVE-2018-10636, CVE-2018-10598",8.8,High,"CWE-125, CWE-121",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 934,7/31/2018,7/31/2018,2018,ICSA-18-212-01,Davolink DVW-3200N,Davolink,DVW-3200N,The following versions of DVW-3200N - networking switch are affected: DVW-3200N all version prior to Version 1.00.06.,CVE-2018-10618,9.8,Critical,CWE-916,Information Technology,"South Korea, Asia, Europe",South Korea,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 933,7/31/2018,7/31/2018,2018,ICSA-18-212-02,Johnson Controls Metasys and BCPro,Johnson Controls Inc.,Metasys and BCPro,Johnson Controls reports that the vulnerability affects the following products: Metasys System | Versions 8.0 and prior andBCPro (BCM) | all versions prior to 3.0.2.,CVE-2018-10624,4.3,Medium,CWE-209,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 932,7/31/2018,10/2/2018,2018,ICSA-18-212-03,WECON LeviStudioU (Update A),WECON,LeviStudioU,According to Zero Day Initiative (ZDI) the following product and versions are affected: LeviStudioU | Versions 1.8.29 and 1.8.44.,"CVE-2018-10602, CVE-2018-10606, CVE-2018-10610, CVE-2018-10614",8.8,High,"CWE-122, CWE-611, CWE-787, CWE-121",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 931,7/31/2018,7/31/2018,2018,ICSA-18-212-04,AVEVA InTouch Access Anywhere,AVEVA,InTouch Access Anywhere,The following versions of InTouch Access Anywhere - remote access software - use the vulnerable jQuery library: 2017 Update 2 and prior. Vulnerable versions of jQuery are those prior to Version 3.0.0.,CVE-2015-9251,6.1,Medium,CWE-79,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 930,7/31/2018,7/31/2018,2018,ICSA-18-212-05,AVEVA Wonderware License Server,AVEVA,Wonderware License Server,"The following versions of Wonderware License Server use the vulnerable Flexara Imgrd (Versions 11.13.1.1 and prior): Wonderware License Server v4.0.13100 and prior. Only users with the Counted Licenses feature with ""ArchestrAServer.lic"" in Wonderware License Server are affected. Wonderware License Server is delivered by: Wonderware Information Server 4.0 SP1 and prior and Historian Client 2014 R4 SP2 P02 and prior.",CVE-2015-8277,9.8,Critical,CWE-119,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 929,7/19/2018,7/19/2018,2018,ICSA-18-200-01,AVEVA InduSoft Web Studio and InTouch Machine Edition,AVEVA,InduSoft Web Studio and InTouch Machine Edition,The following versions of InduSoft Web Studio and InTouch Machine Edition - HMI are affected: InduSoft Web Studio v8.1 and v8.1SP1 and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1.,CVE-2018-10620,9.8,Critical,CWE-121,Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems; Water and Wastewater,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 928,7/19/2018,7/19/2018,2018,ICSA-18-200-02,AVEVA InTouch,AVEVA,InTouch,The following versions of AVEVA InTouch - HMI Platform are affected: InTouch 2014 R2 SP1 and prior | InTouch 2017 | InTouch 2017 Update 1 and InTouch 2017 Update 2.,CVE-2018-10628,9.8,Critical,CWE-121,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 927,7/19/2018,9/18/2018,2018,ICSA-18-200-03,"Echelon SmartServer 1, SmartServer 2, SmartServer 3, i.LON 100, i.LON 600 (Update A)",Echelon,"SmartServer 1, SmartServer 2, SmartServer 3, i.LON 100, i.LON 600",The following Smart Server and i.LON products which are network devices are affected: SmartServer 1 all versions | SmartServer 2 all versions prior to release 4.11.007 | i.LON 100 all versions and i.LON 600 all versions.,"CVE-2018-10627, CVE-2018-8859, CVE-2018-8851, CVE-2018-8855",9.8,Critical,"CWE-288, CWE-319, CWE-200, CWE-256",Commercial Facilities; Critical Manufacturing; Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 926,7/19/2018,7/19/2018,2018,ICSA-18-200-04,Moxa NPort 5210 5230 5232,Moxa,NPort 5210 5230 5232,The following versions of NPort - serial network interface are affected: NPort 5210 | 5230 and 5232 Versions 2.9 build 17030709 and prior.,CVE-2018-10632,7.5,High,CWE-400,Critical Manufacturing; Energy; Transportation,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 925,7/17/2018,7/17/2018,2018,ICSA-18-198-01,ABB Panel Builder 800,ABB,Panel Builder 800,The following versions of Panel Builder 800 - engineering tool for the process panels included in the product suite Panel 800 are affected: Panel Builder 800 | all versions.,CVE-2018-10616,7.0,High,CWE-20,Chemical; Critical Manufacturing; Dams; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 924,7/17/2018,7/17/2018,2018,ICSA-18-198-02,WAGO e!DISPLAY Web-Based-Management,WAGO,e!DISPLAY Web-Based-Management,The following versions of WAGO e!DISPLAY - HMI running firmware FW 01 are affected: 762-3000 | 762-3001 | 762-3002 and 762-3003.,"CVE-2018-12981, CVE-2018-12980, CVE-2018-12979",8.0,High,"CWE-79, CWE-732, CWE-434",Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 923,7/17/2018,7/17/2018,2018,ICSA-18-198-03,"PEPPERL+FUCHS VisuNet RM, VisuNet PC, and Box Thin Client",PEPPERL+FUCHS,"VisuNet RM, VisuNet PC, and Box Thin Client",The following PEPPERL+FUCHS product families are affected: VisuNet RM All models | VisuNet PC All models andBTC All models.,CVE-2018-0886,7.5,High,CWE-287,Communications; Critical Manufacturing; Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 922,7/12/2018,7/12/2018,2018,ICSA-18-193-01,Eaton 9000X Drive,Eaton,9000X Drive,The following version of Eaton 9000X Drive is affected: 9000X Drive | Versions 2.0.29 and prior.,CVE-2018-8847,5.6,Medium,CWE-121,Energy,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 921,7/10/2018,7/10/2018,2018,ICSA-18-191-01,Universal Robots Robot Controllers,Universal Robots,Robot Controllers,The following versions of robot controllers are affected: CB 3.1 | SW Version 3.4.5-100.,"CVE-2018-10633, CVE-2018-10635",9.8,Critical,"CWE-306, CWE-798",Critical Manufacturing; Transportation Systems,Worldwide,Denmark,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 920,7/10/2018,7/11/2018,2018,ICSA-18-191-02,"Schweitzer Engineering Laboratories, Inc. Compass and AcSELerator Architect",Schweitzer Engineering Laboratories,Compass and AcSELerator Architect,The following products from SEL are affected. Not all products are affected by all vulnerabilities.Compass Version 3.0.5.1 and prior and AcSELerator Architect Version 2.2.24.0 and prior.,"CVE-2018-10604, CVE-2018-10600, CVE-2018-10608",8.2,High,"CWE-611, CWE-276, CWE-400",Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 919,7/3/2018,7/3/2018,2018,ICSA-18-184-01,Rockwell Automation Allen-Bradley Stratix 5950,Rockwell Automation,Allen-Bradley Stratix 5950,The Allen-Bradley Stratix 5950 uses the Cisco Systems Inc. - Adaptive Security Appliance (ASA) as its central operating system. Cisco has released advisories disclosing multiple vulnerabilities in the ASA software.The following Allen-Bradley Stratix 5950 Security Appliances - running the Cisco ASA v9.6.2 and earlier are affected: 1783-SAD4T0SBK9 |1783-SAD4T0SPK9 |1783-SAD2T2SBK9 and 1783-SAD2T2SPK9.,"CVE-2018-0228, CVE-2018-0227, CVE-2018-0231, CVE-2018-0240, CVE-2018-0296",8.6,High,"CWE-295, CWE-20, CWE-29, CWE-39, CWE-399",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 918,6/28/2018,6/28/2018,2018,ICSMA-18-179-01,Medtronic MyCareLink Patient Monitor,Medtronic,MyCareLink Patient Monitor,The following MyCareLink Monitors are affected: 24950 MyCareLink Monitor | all versions | 24952 MyCareLink Monitor | all versions.,"CVE-2018-8870, CVE-2018-8868",6.4,Medium,"CWE-749, CWE-259",Healthcare and Public Health,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 917,6/21/2018,6/21/2018,2018,ICSA-18-172-01,Delta Electronics Delta Industrial Automation COMMGR,Delta Electronics,Delta Industrial Automation COMMGR,The following versions of Delta Industrial Automation COMMGR - communication management software and accompanying PLC simulators are affected: COMMGR Version 1.08 and prior. DVPSimulator EH2 | EH3 | ES2 | SE | SS2AHSIM_5x0 | AHSIM_5x1.,CVE-2018-10594,7.3,High,CWE-121,Commercial Facilities; Communications; Critical Manufacturing; Energy; Healthcare and Public Health,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 916,6/21/2018,7/17/2018,2018,ICSA-18-172-02,Rockwell Automation Allen-Bradley CompactLogix and Compact GuardLogix (Update A),Rockwell Automation,Allen-Bradley CompactLogix and Compact GuardLogix,According to Rockwell Automation | the following products are affected: Allen-Bradley CompactLogix 5370 L1 controllers | Versions 30.014 and prior | Allen-Bradley CompactLogix 5370 L2 controllers | Versions 30.014 and prior | Allen-Bradley CompactLogix 5370 L3 controllers | Versions 30.014 and prior | Allen-Bradley Armor CompactLogix 5370 L3 controllers | Versions 30.014 and prior | Allen-Bradley Compact GuardLogix 5370 controllers | Versions 30.014 and prior and Allen-Bradley Armor Compact GuardLogix 5370 controllers | Versions 30.014 and prior.,CVE-2017-9312,8.6,High,CWE-20,Chemical; Critical Manufacturing; Food and Agriculture; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 915,6/14/2018,6/14/2018,2018,ICSMA-18-165-01,Natus Xltek NeuroWorks,Natus Medical Inc,Xltek NeuroWorks,The following version of Natus Xltek NeuroWorks | used in Natus Xltek EEG medical products are affected: Natus Xltek NeuroWorks Version 8.,"CVE-2017-2852, CVE-2017-2853, CVE-2017-2858, CVE-2017-2860, CVE-2017-2861, CVE-2017-2867, CVE-2017-2868, CVE-2017-2869",10.0,Critical,"CWE-125, CWE-121",Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 914,6/12/2018,6/18/2018,2018,ICSA-18-163-01,Schneider Electric U.motion Builder,Schneider Electric,U.motion Builder,The following U.motion Builder Software versions are affected: U.motion Builder versions prior to 1.3.4.,"CVE-2018-7784, CVE-2018-7785, CVE-2018-7786, CVE-2018-7787",10.0,Critical,"CWE-20, CWE-79, CWE-78, CWE-121",Commercial Facilities; Critical Manufacturing; Energy,"France, United States, Asia, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 913,6/7/2018,6/7/2018,2018,ICSA-18-158-01,Rockwell Automation RSLinx Classic and FactoryTalk Linx Gateway,Rockwell Automation,RSLinx Classic and FactoryTalk Linx Gateway,The following versions of RSLinx Classic - software platform that allows Logix5000 Programmable Automation Controllers to connect to a wide variety of Rockwell Software applications and FactoryTalk Linx Gateway - software that provides an Open Platform Communications (OPC) Unified Architecture (UA) server interface to allow the delivery of information from Rockwell Software applications to Allen-Bradley controllers are affected: RSLinx Classic Versions 3.90.01 and prior andFactoryTalk Linx Gateway Versions 3.90.00 and prior.,CVE-2018-10619,8.8,High,CWE-428,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 912,6/5/2018,6/5/2018,2018,ICSMA-18-156-01,Philips' IntelliVue Patient and Avalon Fetal Monitors,Philips,IntelliVue Patient and Avalon Fetal Monitors,The following IntelliVue Patient Monitors versions are affected: IntelliVue Patient Monitors MP Series (includingMP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M and IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only). The following Avalon Fetal/Maternal Monitors versions are affected: Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0 | G.0 and J.3.,"CVE-2018-10597, CVE-2018-10599, CVE-2018-10601",8.3,High,"CWE-200, CWE-287, CWE-121",Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 911,6/5/2018,6/5/2018,2018,ICSA-18-156-01,ABB IP Gateway,ABB,IP Gateway,The following versions of IP Gateway - building management system are affected. The IP Gateway is available under two brands; ABB and Busch-Jaeger. Busch-Jaeger Elektro GmbH is part of the ABB Group. IP Gateway Versions 3.39 and prior.,"CVE-2017-7931, CVE-2017-7906, CVE-2017-7933",9.8,Critical,"CWE-352, CWE-287, CWE-256",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 910,5/31/2018,5/31/2018,2018,ICSA-18-151-01,Delta Industrial Automation DOPSoft,Delta Electronics,DOPSoft,The following versions of DOPSoft - Human Machine Interface (HMI) editing software are affected: DOPSoft Version 4.00.04 and prior.,"CVE-2018-10623, CVE-2018-10617, CVE-2018-10621",7.3,High,"CWE-122, CWE-125, CWE-121",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 909,5/31/2018,5/31/2018,2018,ICSA-18-151-02,GE MDS PulseNET and MDS PulseNET Enterprise,GE,MDS PulseNET and MDS PulseNET Enterprise,GE reports that the vulnerabilities affect the following MDS PulseNET products: PulseNET Version.,"CVE-2018-10611, CVE-2018-10613, CVE-2018-10615",7.3,High,"CWE-287, CWE-611, CWE-23",Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 908,5/31/2018,10/11/2018,2018,ICSA-18-151-03,Yokogawa STARDOM Controllers (Update A),Yokogawa,STARDOM Controllers,Yokogawa reports the vulnerability affects the following STARDOM Controller products: FCJ (R4.02 and prior) | FCN-100 (R4.02 and prior) | FCN-RTU (R4.02 and prior) | FCN-500 (R4.02 and prior) | FCJ (R4.10 and prior) | FCN-100 (R4.10 and prior) | FCN-RTU (R4.10 and prior) and FCN-500 (R4.10 and prior).,"CVE-2018-10592, CVE-2018-17900, CVE-2018-17902, CVE-2018-17896, CVE-2018-17898",9.8,Critical,"CWE-79, CWE-522, CWE-384, CWE-400, CWE-798",Critical Manufacturing; Energy; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 907,5/24/2018,5/29/2018,2018,ICSMA-18-144-01,BeaconMedaes TotalAlert Scroll Medical Air Systems,BeaconMedaes,TotalAlert Scroll Medical Air Systems,The following TotalAlert Scroll Medical Air Systems web applications are affected: TotalAlert Scroll Medical Air Systems running software Versions 4107600010.23 and prior.,"CVE-2018-7526, CVE-2018-7518, CVE-2018-7510",7.5,High,"CWE-284, CWE-522, CWE-256",Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 906,5/24/2018,5/24/2018,2018,ICSA-18-144-01,Schneider Electric Floating License Manager,Schneider Electric,Floating License Manager,The following products use the vulnerable Schneider Electric Floating License Manager - license management platform: SCADA Expert Vijeo Citect / CitectSCADA Version 7.30 | 7.40 | CitectSCADA Version 2015 | 2016 | Vijeo Historian/CitectHistorian Version 4.40 | 4.50 | CitectHistorian Version 2016 | Citect Anywhere | PlantStruxure PES V4.3 SP1 and prior and EcoStruxure Modicon Builder V3.0 and prior. The following products are only affected by CVE-2016-10395: EcoStruxure Power Monitoring Expert 8.2 (Standard | DC | HC Editions) | StruxureWare Power Monitoring Expert 8.1 (Standard | DC | HC Editions) | StruxureWare Power Monitoring Expert 8.0 (Standard | DC | HC | Buildings Editions) | StruxureWare Power Monitoring Expert 7.2.x | Energy Expert 1.x (formerly Power Manager) and EcoStruxure Power SCADA Operations 8.x (formerly PowerSCADA Expert) (Only with Advanced Reports and Dashboards Module).,"CVE-2016-10395, CVE-2016-2177, CVE-2017-5571",9.8,Critical,"CWE-122, CWE-119, CWE-601",Commercial Facilities; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 905,5/22/2018,10/11/2018,2018,ICSMA-18-142-01,BD Kiestra and InoquIA Systems (Update A),"Becton, Dickinson and Company (BD)",Kiestra and InoquIA Systems,BD reports these vulnerabilities affect applications used by the following BD Kiestra systems: BD Kiestra TLA |BD Kiestra WCA andBD InoqulA+ specimen processor. All three BD Kiestra systems listed above use the following vulnerable applications: Database (DB) Manager | Version 3.0.1.0 |ReadA Overview | Version 1.1.0.2 and previous andPerformA | Version 3.0.0.0 and previous versions.,"CVE-2018-10593, CVE-2018-10595",6.3,Medium,CWE-356,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 904,5/22/2018,8/30/2018,2018,ICSA-18-142-01,Martem TELEM-GW6/GWM (Update B),Martem,TELEM-GW6/GWM,The following TELEM products with insecure configurations are affected: GW6 versions prior to 2.0.87-4018403-k4 and GWM versions prior to 2.0.87-4018403-k4. Not all versions are affected by all vulnerabilities.,"CVE-2018-10603, CVE-2018-10605, CVE-2018-10607, CVE-2018-10609",10.0,Critical,"CWE-79, CWE-276, CWE-306, CWE-400",Energy,"Estonia, Finland, Lithuania, Latvia",Estonia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 903,5/17/2018,7/12/2018,2018,ICSMA-18-137-01,Medtronic N'Vision Clinician Programmer (Update A),Medtronic,N'Vision Clinician Programmer,The N'Vision Clinician Programmer is a small portable device that offers a single programming platform for Medtronic Neurological implantable therapy devices such as Medtronic neurostimulators and drug pumps. The following products are affected: 8840 N'Vision Clinician Programmer | all versions and 8870 N'Vision removable Application Card | all versions.,"CVE-2018-8849, CVE-2018-10631",6.3,Medium,"CWE-311, CWE-693",Healthcare and Public Health,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 902,5/17/2018,5/21/2018,2018,ICSA-18-137-01,"GE PACSystems CPE305/310, CPE330, CPE400, RSTi-EP CPE 100, CPU320/CRU320, RXi",GE,"PACSystems CPE305/310, CPE330, CPE400, RSTi-EP CPE 100, CPU320/CRU320, RXi",The following versions of PACSystems - industrial Internet controller are affected: PACSystems RX3i CPE305/310 version 9.20 and prior | RX3i CPE330 version 9.21 and prior | RX3i CPE 400 version 9.30 and prior | PACSystems RSTi-EP CPE 100 all versions and PACSystems CPU320/CRU320 and RXi all versions.,CVE-2018-8867,7.5,High,CWE-20,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 901,5/17/2018,5/17/2018,2018,ICSA-18-137-02,PHOENIX CONTACT FL SWITCH 3xxx/4xxx/48xx Series,PHOENIX CONTACT,FL SWITCH 3xxx/4xxx/48xx Series,All FL SWITCH 3xxx | 4xxx and 48xxx Series products running firmware Version 1.0 to 1.32 are affected.,"CVE-2018-10730, CVE-2018-10729, CVE-2018-10728, CVE-2018-10731",9.1,Critical,"CWE-200, CWE-77, CWE-121",Communications; Critical Manufacturing; Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 900,5/17/2018,9/11/2018,2018,ICSA-18-137-03,Siemens SIMATIC S7-400 CPU (Update A),Siemens,SIMATIC S7-400 CPU,The following versions of SIMATIC S7-400 - CPU used for process controls are affected: SIMATIC S7-400 (incl. F) CPU all hardware versions prior to - including | hardware v4.0 | SIMATIC S7-400 (incl. F) CPU hardware v5.0 with firmware versions prior to v5.2 and SIMATIC S7-400H CPU all hardware versions prior to v4.5.,CVE-2018-4850,7.5,High,CWE-20,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 899,5/17/2018,6/20/2018,2018,ICSA-18-137-04,Delta Electronics Delta Industrial Automation TPEditor (Update A),Delta Electronics,Delta Industrial Automation TPEditor,The following versions of Delta Industrial Automation TPEditor - programming software for Delta text panels operating on Windows are affected: Delta Industrial Automation TPEditor | Version 1.89 or prior.,CVE-2018-8871,7.3,High,CWE-122,Commercial Facilities; Communications; Critical Manufacturing; Energy; Healthcare and Public Health,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 898,5/15/2018,5/18/2018,2018,ICSA-18-135-01,Advantech WebAccess,Advantech,WebAccess,The following versions of WebAccess products are affected: WebAccess versions V8.2_20170817 and prior | WebAccess versions V8.3.0 and prior | WebAccess Dashboard versions V.2.0.15 and prior | WebAccess Scada Node versions prior to 8.3.1 | WebAccess/NMS 2.0.3 and prior.,"CVE-2018-7501, CVE-2018-10590, CVE-2018-7505, CVE-2018-7503, CVE-2018-10589, CVE-2018-7499, CVE-2018-8845, CVE-2018-7497, CVE-2018-7495, CVE-2018-10591, CVE-2018-8841",9.8,Critical,"CWE-89, CWE-548, CWE-264, CWE-22, CWE-121, CWE-122, CWE-822, CWE-73, CWE-346, CWE-269",Critical Manufacturing; Energy; Water and Wastewater,"Taiwan, United States, Asia, East Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 897,5/10/2018,5/10/2018,2018,ICSA-18-130-01,MatrikonOPC Explorer,MatrikonOPC,Explorer,According to MatrikonOPC the following product is affected: MatrikonOPC Explorer | Versions 5.0 and prior.,CVE-2018-8714,6.7,Medium,CWE-552,Chemical; Energy,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 896,5/10/2018,5/10/2018,2018,ICSA-18-130-02,Rockwell Automation Arena,Rockwell Automation,Arena,The following versions of Arena - simulation software for manufacturing are affected: Arena versions 15.10.00 and prior.,CVE-2018-8843,5.5,Medium,CWE-416,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 895,4/12/2018,5/31/2018,2018,ICSA-18-102-02,Rockwell Automation FactoryTalk Activation Manager (Update B),Rockwell Automation,FactoryTalk Activation Manager,Rockwell Automation reports these vulnerabilities affect licensing management software in the following FactoryTalk Activation Manager products: FactoryTalk Activation Manager v4.00 and v4.01 Ships with Wibu-Systems CodeMeter v6.50b and earlier | FactoryTalk Activation Manager v4.00 and earlier Ships with FlexNet Publisher v11.11.1.1 and earlier.The following products require FactoryTalk Activation Manager to store and keep track of Rockwell Automation software products and activation files. Users who recognize products from the following list are using FactoryTalk Activation Manager: ArenaEmonitorFactoryTalk AssetCentreFactoryTalk BatchFactoryTalk EnergyMetrixFactoryTalk eProcedureFactoryTalk GatewayFactoryTalk Historian ClassicFactoryTalk Historian Site Edition (SE)FactoryTalk Information ServerFactoryTalk MetricsFactoryTalk Transaction ManagerFactoryTalk VantagePointFactoryTalk View Machine Edition (ME)FactoryTalk View Site Edition (SE)FactoryTalk ViewPointRSFieldBusRSLinx ClassicRSLogix 500RSLogix 5000RSLogix5RSLogix Emulate 5000RSNetWorxRSView32SoftLogix 5800Studio 5000 ArchitectStudio 5000 Logix DesignerStudio 5000 Logix EmulateStudio 5000 View Designer.,"CVE-2017-13754, CVE-2015-8277",9.8,Critical,"CWE-79, CWE-119",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 894,5/8/2018,6/5/2018,2018,ICSMA-18-128-01,Silex Technology SX-500/SD-320AN or GE Healthcare MobileLink (Update B),Silex Technology,SX-500/SD-320AN or GE Healthcare MobileLink,The following products from Silex Technology are affected. Some are not affected by both vulnerabilities (see Mitigations Section): GEH-500 Version 1.54 and prior (integrated into GE MobileLink) | SX-500 All Versions (end-of-life 2011) |GEH-SD-320AN Version GEH-1.1 and prior (integrated into GE MobileLink) andSD-320AN Version 2.01 and prior (end-of-life Nov 2017). The following models of GE MAC Resting ECG analysis system may use the vulnerable MobileLink technology: MAC 3500 | MAC 5000 (end-of-life 2012) | MAC 5500 and MAC 5500 HD.,"CVE-2018-6020, CVE-2018-6021, CVE-2018-6020, CVE-2018-6021",7.4,High,"CWE-287, CWE-78",Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 893,5/8/2018,10/9/2018,2018,ICSA-18-128-01,Siemens Medium Voltage SINAMICS Products (Update A),Siemens,Medium Voltage SINAMICS Products,Siemens reports that these vulnerabilities affect the following products: SINAMICS GH150 V4.7 w. PROFINET: All versions prior to V4.7 SP5 HF7 | SINAMICS GL150 V4.7 w. PROFINET: All versions prior to V4.8 SP2 | SINAMICS GM150 V4.7 w. PROFINET: All versions prior to V4.8 SP2 | SINAMICS SL150 V4.7.0 w. PROFINET: All versions prior to V4.7 HF30 | SINAMICS SL150 V4.7.4 w. PROFINET: All versions prior to V4.8 SP2 | SINAMICS SL150 V4.7.5 w. PROFINET: All versions prior to V4.8 SP2 | SINAMICS SM120 V4.7 w. PROFINET: All versions prior to V4.8 SP2 and SINAMICS GM150 v4.7 w. PROFINET: All versions prior to v4.7 HF31 and SIMOTION D4xx v4.4 for SINAMICS SM150i-2 w. PROFINET: All versions prior to v4.4 HF26.,"CVE-2017-12741, CVE-2017-2680",7.5,High,CWE-20,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 892,5/8/2018,5/24/2018,2018,ICSA-18-128-02,Siemens Siveillance VMS (Update A),Siemens,Siveillance VMS,The following versions of Siveillance VMS - IP video management software are affected: Siveillance VMS 2016 R1 | all versions prior to V10.0a | Siveillance VMS 2016 R2 | all versions prior to V10.1a | Siveillance VMS 2016 R3 | all versions prior to V10.2b | Siveillance VMS 2017 R1 | all versions prior to V11.1a | Siveillance VMS 2017 R2 | all versions prior to V11.2a and Siveillance VMS 2018 R1 | all versions prior to V12.1a.,CVE-2018-7891,8.1,High,CWE-502,Commercial Facilities; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 891,5/8/2018,5/8/2018,2018,ICSA-18-128-03,Siemens Siveillance VMS Video Mobile App,Siemens,Siveillance VMS Video Mobile App,Siemens reports that the vulnerability affects the following Siveillance VMS Video Mobile Apps: Siveillance VMS Video for Android | all versions prior to V12.1a (2018 R1) and Siveillance VMS Video for iOS: all versions prior to V12.1a (2018 R1).,CVE-2018-4849,4.8,Medium,CWE-295,Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 890,5/3/2018,5/3/2018,2018,ICSA-18-123-01,Lantech IDS 2102,Lantech,IDS 2102,The following versions of IDS 2102 - Ethernet device server are affected: IDS 2102 versions 2.0 and prior.,"CVE-2018-8869, CVE-2018-8865",9.8,Critical,"CWE-20, CWE-121",Critical Manufacturing; Dams,"Australia, China, Taiwan, North America, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 889,4/26/2018,4/26/2018,2018,ICSA-18-116-01,Delta Electronics PMSoft,Delta Electronics,PMSoft,The following versions of PMSoft - software development tool for motion controllers are affected: PMSoft v 2.10 or prior.,CVE-2018-8839,7.1,High,CWE-121,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 888,4/26/2018,4/26/2018,2018,ICSA-18-116-02,"WECON Technology Co., Ltd. LeviStudio HMI Editor and PI Studio HMI Project Programmer",WECON,"Technology Co., Ltd. LeviStudio HMI Editor and PI Studio HMI Project Programmer","The following versions of LEVI Studio HMI Editor and PI Studio HMI Project Programmer - HMI programming software products are affected: WECON LeviStudioU Version 1.10 part of Wecon LeviStudioU 1.8.29 and prior andPI Studio HMI Project Programmer Build: November 11, 2017 and prior.",CVE-2018-7527,5.9,Medium,CWE-121,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 887,4/24/2018,4/24/2018,2018,ICSMA-18-114-01,BD Pyxis,"Becton, Dickinson and Company (BD)",Pyxis,The following versions of BD Pyxis products - medication and supply management system are affected: BD Pyxis Anesthesia ES | BD Pyxis Anesthesia System 4000 | BD Pyxis Anesthesia System 3500 | BD Pyxis MedStation 4000 T2 | BD Pyxis MedStation ES | BD Pyxis SupplyStation | BD Pyxis Supply Roller | BD Pyxis ParAssist System | BD Pyxis PARx | BD Pyxis CIISafe - Workstation |BD Pyxis StockStation System and BD Pyxis Parx handheld.,"CVE-2017-13077, CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, CVE-2017-13081, CVE-2017-13082, CVE-2017-13086, CVE-2017-13087, CVE-2017-13088",6.8,Medium,CWE-323,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 886,4/24/2018,10/30/2018,2018,ICSA-18-114-01,Vecna VGo Robot (Update A),Vecna,VGo Robot,The following versions of VGo Robot - remote controlled robot are affected: VGo Robot: Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected.,"CVE-2018-8866, CVE-2018-8860, CVE-2018-17933, CVE-2018-17931, CVE-2018-8858",8.8,High,"CWE-319, CWE-284, CWE-285, CWE-78, CWE-522",Communications,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 885,4/24/2018,4/24/2018,2018,ICSA-18-114-02,Intel 2G Modem,Intel Corporation,2G Modem,The following products use the vulnerable Intel modem with 2G capability and ETWS enabled: Intel XMM71xxIntel XMM72xxIntel XMM73xxIntel XMM74xxSofia 3GSofia 3G-RSofia 3G-R WVersions that support 2G and the ETWS feature delivered to system manufactures prior to the disclosure of CVE-2018-3624 may be affected.,CVE-2018-3624,8.2,High,CWE-120,Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 884,4/24/2018,4/24/2018,2018,ICSA-18-114-03,Advantech WebAccess HMI Designer,Advantech,WebAccess HMI Designer,The following version of Advantech WebAccess HMI Designer - Human Machine Interface (HMI) Runtime Development Software is affected: Advantech WebAccess HMI Designer | Version 2.1.7.32 and prior.,"CVE-2018-8833, CVE-2018-8835, CVE-2018-8837",6.3,Medium,"CWE-415, CWE-122, CWE-787",Critical Manufacturing; Energy; Water and Wastewater,"Taiwan, United States, Asia, East Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 883,4/19/2018,10/9/2018,2018,ICSA-18-109-01,Siemens SIMATIC WinCC OA Operator IOS App (Update A),Siemens,SIMATIC WinCC OA Operator IOS App,Siemens reports this vulnerability affects the following product: SIMATIC WinCC OA Operator iOS App: All versions prior to v1.4.,CVE-2018-4847,4.0,Medium,CWE-538,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 882,4/17/2018,4/25/2018,2018,ICSMA-18-107-01,Abbott Laboratories Defibrillator,Abbott Laboratories,Defibrillator,"The following ICDs and CRT-Ds manufactured and distributed prior to April 19, 2018 are affected: Fortify | Fortify Assura | Quadra Assura | Quadra Assura MP | Unify | Unify Assura | Unify Quadra | Promote Quadra | Ellipse | Current | Promote.","CVE-2017-12712, CVE-2017-12714",7.5,High,"CWE-287, CWE-920",Healthcare and Public Health,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 881,4/17/2018,4/17/2018,2018,ICSMA-18-107-02,Biosense Webster Carto 3 System Vulnerabilities,Biosense Webster,Carto 3 System,The following CARTO 3 Systems versions are affected: CARTO 3 Systems manufactured before April 2018.,"CVE-2013-6629, CVE-2017-0005, CVE-2017-0014, CVE-2017-0022, CVE-2017-0025, CVE-2017-0038, CVE-2017-0039, CVE-2017-0042, CVE-2017-0043, CVE-2017-0045, CVE-2017-0047, CVE-2017-0050, CVE-2017-0055, CVE-2017-0056, CVE-2017-0058, CVE-2017-0060, CVE-2017-0061, CVE-2017-0062, CVE-2017-0063, CVE-2017-0064, CVE-2017-0072, CVE-2017-0073, CVE-2017-0075, CVE-2017-0076, CVE-2017-0077, CVE-2017-0083, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, CVE-2017-0127, CVE-2017-0128, CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, CVE-2017-0147, CVE-2017-0148, CVE-2017-0155, CVE-2017-0156, CVE-2017-0158, CVE-2017-0163, CVE-2017-0166, CVE-2017-0167, CVE-2017-0168, CVE-2017-0170, CVE-2017-0171, CVE-2017-0175, CVE-2017-0180, CVE-2017-0182, CVE-2017-0183, CVE-2017-0184, CVE-2017-0190, CVE-2017-0191, CVE-2017-0192, CVE-2017-0193, CVE-2017-0199, CVE-2017-0213, CVE-2017-0214, CVE-2017-0084, CVE-2017-0085, CVE-2017-0086, CVE-2017-0087, CVE-2017-0088, CVE-2017-0089, CVE-2017-0090, CVE-2017-0091, CVE-2017-0092, CVE-2017-0096, CVE-2017-0097, CVE-2017-0099, CVE-2017-0100, CVE-2017-0101, CVE-2017-0102, CVE-2017-0103, CVE-2017-0104, CVE-2017-0108, CVE-2017-0109, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0220, CVE-2017-0222, CVE-2017-0226, CVE-2017-0231, CVE-2017-0238, CVE-2017-0242, CVE-2017-0244, CVE-2017-0245, CVE-2017-0246, CVE-2017-0248, CVE-2017-0258, CVE-2017-0260, CVE-2017-0263, CVE-2017-0267, CVE-2017-0268, CVE-2017-0269, CVE-2017-0270, CVE-2017-0271, CVE-2017-0272, CVE-2017-0273, CVE-2017-0274, CVE-2017-0275, CVE-2017-0276, CVE-2017-0277, CVE-2017-0278, CVE-2017-0279, CVE-2017-0280, CVE-2017-0282, CVE-2017-0283, CVE-2017-0284, CVE-2017-0285, CVE-2017-0286, CVE-2017-0287, CVE-2017-0288, CVE-2017-0289, CVE-2017-0294, CVE-2017-0296, CVE-2017-0297, CVE-2017-0298, CVE-2017-0300, CVE-2017-8462, CVE-2017-8463, CVE-2017-8464, CVE-2017-8467, CVE-2017-8469, CVE-2017-8470, CVE-2017-8471, CVE-2017-8472, CVE-2017-8473, CVE-2017-8475, CVE-2017-8476, CVE-2017-8477, CVE-2017-8478, CVE-2017-8479, CVE-2017-8480, CVE-2017-8481, CVE-2017-8482, CVE-2017-8483, CVE-2017-8484, CVE-2017-8485, CVE-2017-8486, CVE-2017-8488, CVE-2017-8489, CVE-2017-8490, CVE-2017-8491, CVE-2017-8492, CVE-2017-8495, CVE-2017-8527, CVE-2017-8528, CVE-2017-8531, CVE-2017-8532, CVE-2017-8533, CVE-2017-8534, CVE-2017-8543, CVE-2017-8544, CVE-2017-8552, CVE-2017-8553, CVE-2017-8554, CVE-2017-8556, CVE-2017-8557, CVE-2017-8564, CVE-2017-8565, CVE-2017-8573, CVE-2017-8577, CVE-2017-8578, CVE-2017-8580, CVE-2017-8581, CVE-2017-8582, CVE-2017-8587, CVE-2017-8588, CVE-2017-8589, CVE-2017-8590, CVE-2017-8592",5.0,Medium,"CWE-200, CWE-264, CWE-284, CWE-611, CWE-119, CWE-287, CWE-254, CWE-19, CWE-20, CWE-190, CWE-79, CWE-352",Healthcare and Public Health,"United States, Asia, Europe, Africa, Middle East",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 880,4/17/2018,4/25/2018,2018,ICSA-18-107-01,Schneider Electric InduSoft Web Studio and InTouch Machine Edition,Schneider Electric,InduSoft Web Studio and InTouch Machine Edition,The following versions of InduSoft Web Studio and InTouch Machine Edition - HMI are affected: InduSoft Web Studio v8.1 and prior versions and InTouch Machine Edition 2017 v8.1 and prior versions.,CVE-2018-8840,9.8,Critical,CWE-121,Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 879,4/17/2018,12/18/2018,2018,ICSA-18-107-02,Schneider Electric Triconex Tricon (Update B),Schneider Electric,Triconex Tricon,The following versions of Triconex Tricon - Safety Instrumented System are affected: MP Model 3008 firmware versions 10.0-10.4.,"CVE-2018-8872, CVE-2018-7522",9.0,Critical,CWE-119,Multiple Critical Sectors,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 878,4/17/2018,4/25/2018,2018,ICSA-18-107-03,Rockwell Automation Stratix Services Router,Rockwell Automation,Stratix Services Router,The following versions of Allen-Bradley Stratix Services Router use a vulnerable version of Cisco IOS or IOS XE: Allen-Bradley Stratix 5900 Services Router | version 15.6.3M1 and earlier.,"CVE-2018-0158, CVE-2018-0151, CVE-2018-0175",9.8,Critical,"CWE-20, CWE-119, CWE-134",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 877,4/17/2018,4/25/2018,2018,ICSA-18-107-04,Rockwell Automation Stratix and ArmorStratix Switches,Rockwell Automation,Stratix and ArmorStratix Switches,The following versions of Allen-Bradley Stratix and ArmorStratix Switches use a vulnerable version of Cisco IOS or IOS XE: Allen-Bradley Stratix 5400 Industrial Ethernet Switches | versions 15.2(6)E0a and earlier; Allen-Bradley Stratix 5410 Industrial Distribution Switches | versions 15.2(6)E0a and earlier; Allen-Bradley Stratix 5700 Industrial Managed Ethernet Switches | versions 15.2(6)E0a and earlier; Allen-Bradley Stratix 8000 Modular Managed Ethernet Switches | versions 15.2(6)E0a and earlier; Allen-Bradley ArmorStratix 5700 Industrial Managed Ethernet Switches for extreme environments | versions 15.2(6)E0a and earlier.,"CVE-2018-0171, CVE-2018-0156, CVE-2018-0174, CVE-2018-0172, CVE-2018-0173, CVE-2018-0158, CVE-2018-0167, CVE-2018-0175",9.8,Critical,"CWE-20, CWE-119, CWE-399, CWE-134",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 876,4/17/2018,4/25/2018,2018,ICSA-18-107-05,Rockwell Automation Stratix Industrial Managed Ethernet Switch,Rockwell Automation,Stratix Industrial Managed Ethernet Switch,The following versions of Allen-Bradley Stratix Industrial Managed Ethernet Switch use a vulnerable version of Cisco IOS or IOS XE: Allen-Bradley Stratix 8300 Industrial Managed Ethernet Switches | versions 15.2(4a)EA5 and earlier.,"CVE-2018-0171, CVE-2018-0156, CVE-2018-0155, CVE-2018-0174, CVE-2018-0172, CVE-2018-0173, CVE-2018-0167, CVE-2018-0175",9.8,Critical,"CWE-20, CWE-119, CWE-388, CWE-399, CWE-134",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 875,4/12/2018,4/13/2018,2018,ICSA-18-102-01,Yokogawa CENTUM and Exaopc,Yokogawa,CENTUM and Exaopc,The following versions of Yokogawa products are affected: CENTUM seriesCENTUM CS 1000 all versions | CENTUM CS 3000 versions R3.09.50 and prior | CENTUM CS 3000 Small versions R3.09.50 and prior | CENTUM VP versions R6.03.10 and prior | CENTUM VP Small versions R6.03.10 and prior | CENTUM VP Basic versions R6.03.10 and prior.Exaopc versions R3.75.00 and prior |B/M9000 CS all versions andB/M9000 VP versions R8.01.01 and prior.,CVE-2018-8838,6.5,Medium,CWE-264,Critical Manufacturing; Energy; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 874,4/10/2018,4/10/2018,2018,ICSA-18-100-01,ATI Systems Emergency Mass Notification Systems,ATI Systems,Emergency Mass Notification Systems,The following ATI's Emergency Mass Notification Systems devices are affected: HPSS16HPSS32MHPSS andALERT4000.,"CVE-2018-8862, CVE-2018-8864",5.3,Medium,"CWE-287, CWE-311",Commercial Facilities; Defense Industrial Base; Emergency Services; Government Facilities; Nuclear Reactors Materials and Waste,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 873,4/10/2018,4/10/2018,2018,ICSA-18-100-02,Omron CX-One,Omron,CX-One,The following versions of CX-One are affected: CX-One Versions 4.42 and prior | including the following applications: CX-FLnet versions 1.00 and prior | CX-Protocol versions 1.992 and prior | CX-Programmer versions 9.65 and prior | CX-Server versions 5.0.22 and prior | Network Configurator versions 3.63 and prior andSwitch Box Utility versions 1.68 and prior.,"CVE-2018-8834, CVE-2018-7514, CVE-2018-7530",5.3,Medium,"CWE-843, CWE-122, CWE-121",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 872,4/5/2018,9/17/2018,2018,ICSA-18-095-01,Rockwell Automation MicroLogix,Rockwell Automation,MicroLogix,The following versions of MicroLogix Controllers - PLC (Programmable Logic Controller) are affected: MicroLogix 1400 Versions FRN 21.003 and prior and MicroLogix 1100 Versions FRN 16.00 and prior.,"CVE-2017-12088, CVE-2017-12089, CVE-2017-12090, CVE-2017-12092, CVE-2017-12093",10.0,Critical,CWE-287,Critical Manufacturing; Food and Agriculture; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 871,4/5/2018,4/5/2018,2018,ICSA-18-095-02,Moxa MXview,Moxa,MXview,The following versions of MXview | network management software are affected: MXview versions 2.8 and prior.,CVE-2018-7506,7.5,High,CWE-200,Critical Manufacturing; Energy; Transportation,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 870,4/5/2018,1/15/2019,2018,ICSA-18-095-03,LCDS - Leao Consultoria e Desenvolvimento de Sistemas Ltda ME LAquis SCADA,LCDS - Leao Consultoria e Desenvolvimento de Sistemas Ltda ME,LAquis SCADA,The following versions of LAquis SCADA - industrial automation software are affected: LAquis SCADA software versions 4.1.0.3391 and prior.,CVE-2018-5463,7.0,High,CWE-703,Chemical; Commercial Facilities; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,"Brazil, South America",Brazil,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 869,4/3/2018,4/5/2018,2018,ICSA-18-093-01,Siemens Building Technologies Products (Update A),Siemens,Building Technologies Products,Siemens License Management System (LMS) which includes a vulnerable version of Gemalto Sentinel LDK RTE is used by the following Siemens products and solutions: License Management System (LMS) All versions prior to V2.1 SP3(2.1.670) | Annual Shading V1.0.4 and 1.1 | Desigo ABT Versions | MP1.1 Build 845 | MP1.15 Build 360 | MP1.16 Build 055 | MP1.2 Build 850 | MP1.2.1 Build 318 | MP2.1 Build 965 | Desigo CC Versions | MP1.1 | MP2.0 | MP2.1 | MP3.0 | Desigo Configuration Manager (DCM) V6.10.140 | Desigo XWP | V5.00.204 | V5.00.260 | V5.10.142 | V5.10.212 | V6.00.184 | V6.00.342 | V6.10.172 | SiteIQ Analytics | V1.1 | V1.2 | V1.3 | Siveillance Identity V1.1.,"CVE-2017-11496, CVE-2017-11497, CVE-2017-12819, CVE-2017-12821, CVE-2017-11498, CVE-2017-12818, CVE-2017-12820, CVE-2017-12822",9.8,Critical,"CWE-121, CWE-254, CWE-119, CWE-476, CWE-776, CWE-122, CWE-284",Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 868,3/29/2018,10/2/2018,2018,ICSMA-18-088-01,Philips iSite/IntelliSpace PACS Vulnerabilities (Update A),Philips,iSite/IntelliSpace PACS,Philips reports these vulnerabilities affect all versions of iSite and IntelliSpace PACS.,CVE-NA,10.0,Critical,"CWE-17, CWE-19, CWE-119, CWE-20, CWE-254, CWE-255, CWE-262, CWE-264, CWE-284, CWE-287, CWE-310, CWE-326, CWE-362, CWE-399, CWE-400, CWE-416, CWE-476, CWE-428, CWE-521, CWE-798, CWE-200, CWE-94, CWE-928, CWE-78, CWE-79, CWE-287, CWE-295, CWE-319, CWE-613, CWE-611",Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 867,3/29/2018,3/29/2018,2018,ICSA-18-088-01,WAGO 750 Series,WAGO,750 Series,The following versions of 750 series PLC are affected: 750-880 firmware version 10 and prior | 750-881 firmware version 10 and prior | 750-852 firmware version 10 and prior | 750-882 firmware version 10 and prior | 750-885 firmware version 10 and prior | 750-831 firmware version 10 and prior | 750-889 firmware version 10 and prior and 750-829 firmware version 10 and prior.,CVE-2018-8836,5.3,Medium,CWE-404,Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,"China, Germany, India, Poland, Switzerland, United States",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 866,3/29/2018,3/29/2018,2018,ICSA-18-088-02,Siemens TIM 1531 IRC,Siemens,TIM 1531 IRC,Siemens reports that the vulnerability affects the following TIM 1531 IRC communications modules: TIM 1531 IRC | all versions prior to v1.1.,CVE-2018-4841,9.8,Critical,CWE-303,Chemical; Critical Manufacturing; Food and Agriculture,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 865,3/29/2018,3/12/2019,2018,ICSA-18-088-03,"Siemens SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional, and SIMATIC NET PC Software (Update G)",Siemens,"SIMATIC PCS 7, SIMATIC WinCC, SIMATIC WinCC Runtime Professional, and SIMATIC NET PC Software",Siemens reports that the vulnerability affects the following SIMATIC products: OpenPCS 7 v7.1 and earlier |OpenPCS 7 v8.0: All versions prior to 8.2 SP1 |OpenPCS 7 v8.1: All versions prior to v8.1 Upd5 |OpenPCS 7 v8.2: All versions |OpenPCS 7 v9.0: All versions prior to v9.0 Upd1 | SIMATIC BATCH v7.1 and earlier | SIMATIC BATCH v8.0: All versions prior to v8.0 SP1 Upd21 | SIMATIC BATCH v8.1: All versions prior to v8.1 SP1 Upd16 | SIMATIC BATCH v8.2: All versions prior to v8.2 Upd10 | SIMATIC BATCH v9.0: All versions prior to v9.0 SP1 | SIMATIC NET PC-Software: All versions prior to v15 SP1 | SIMATIC PCS 7 v7.1 and earlier | SIMATIC PCS 7 v8.0: All versions | SIMATIC PCS 7 v8.1: All versions | SIMATIC PCS 7 v9.0: All versions prior to v9.0 SP1 | SIMATIC Route Control v7.1 and earlier | SIMATIC Route Control v8.0: All versions | SIMATIC Route Control v8.1: All versions | SIMATIC PCS 7 v8.2: All versions prior to v8.2 SP1 | SIMATIC Route Control v8.2: All versions | SIMATIC Route Control v9.0: All versions prior to v9.0 Upd1 | SIMATIC WinCC Runtime Professional v13: All versions prior to v13 SP2 Upd2 | SIMATIC WinCC Runtime Professional v14: All versions prior to v14 SP1 Upd5 | SIMATIC WinCC 7.2 and earlier: All versions prior to WinCC 7.2 Upd 15 | SIMATIC WinCC 7.3: All versions prior to WinCC 7.3 Upd16 and SIMATIC WinCC 7.4: All versions prior to v7.4 SP1 Upd 4.,CVE-2018-4832,7.5,High,CWE-20,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 864,3/27/2018,3/27/2018,2018,ICSA-18-086-01,"Schneider Electric Modicon Premium, Modicon Quantum, Modicon M340, and Modicon BMXNOR0200",Schneider Electric,"Modicon Premium, Modicon Quantum, Modicon M340, and Modicon BMXNOR0200",The following versions of Modicon PLCs are affected: Modicon Premium all versions | Modicon Quantum all versions | Modicon M340 all versions and Modicon X80 RTU (BMXNOR0200H) all versions.,"CVE-2018-7240, CVE-2018-7241, CVE-2018-7242",5.9,Medium,"CWE-121, CWE-327, CWE-798",Critical Manufacturing,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 863,3/27/2018,12/13/2018,2018,ICSMA-18-086-01,Philips Alice 6 Vulnerabilities (Update B),Philips,Alice 6,The following versions of the Philips Alice 6 System are affected: Version R8.0.3 or prior.,"CVE-2018-5451, CVE-2018-7498",5.3,Medium,"CWE-287, CWE-311",Healthcare and Public Health,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 862,3/22/2018,3/22/2018,2018,ICSA-18-081-01,Siemens SIMATIC WinCC OA UI Mobile App,Siemens,SIMATIC WinCC OA UI Mobile App,Siemens reports that this vulnerability affects the following products: SIMATIC WinCC OA UI for Android: All versions prior to V3.15.10 and SIMATIC WinCC OA UI for IOS: All versions prior to V3.15.10.,CVE-2018-4844,5.1,Medium,CWE-284,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 861,3/22/2018,3/22/2018,2018,ICSA-18-081-02,Beckhoff TwinCAT,Beckhoff Automation,TwinCAT,Beckhoff reports that the vulnerability affects the following TwinCAT PLC products: TwinCAT 3.1 Build 4022.4 or prior |TwinCAT 2.11 R3 2259 or prior andTwinCAT 3.1 C++ / Matlab (TC1210/TC1220/TC1300/TC1320).,CVE-2018-7502,7.8,High,CWE-822,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 860,3/20/2018,3/20/2018,2018,ICSA-18-079-01,Geutebruck IP Cameras,Geutebruck,IP Cameras,Geutebruck reports that the vulnerabilities affect the following IP cameras: G-Cam/EFD-2250 (part n° 5.02024) firmware version 1.12.0.4 andTopline TopFD-2125 (part n° 5.02820) firmware version 3.15.1.,"CVE-2018-7532, CVE-2018-7528, CVE-2018-7524, CVE-2018-7520, CVE-2018-7516, CVE-2018-7512",9.8,Critical,"CWE-352, CWE-284, CWE-287, CWE-79, CWE-89, CWE-918",Commercial Facilities; Energy; Financial Services,"Australia, Germany, United States, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 859,3/20/2018,10/8/2019,2018,ICSA-18-079-02,"Siemens SIMATIC, SINUMERIK, and PROFINET IO (Update D)",Siemens,"SIMATIC, SINUMERIK, and PROFINET IO",Siemens reports that the vulnerability affects the following products: SIMATIC CP 343-1 Advanced: All versions | SIMATIC CP 343-1 Standard: All versions | SIMATIC CP 443-1 Advanced: All versions | SIMATIC CP 443-1 Standard: All versions | SIMATIC S7-1500 Software Controller incl. F: All versions prior to v1.7.0 | SIMATIC S7-1500 incl. F: All versions prior to v1.7.0 | SIMATIC S7-300 incl. F and T: All versions prior to v3.X.16 | SIMATIC S7-400 H v6: All versions prior to v6.0.9 | SIMATIC S7-400 PN/DP v6 incl. F: All versions prior to v6.0.7 | SIMATIC S7-400 PN/DP v7 incl. F: All versions | SIMATIC S7-410: All versions prior to v8.1 | SIMATIC WinAC RTX (F) 2010: All versions prior to SP3 | SINUMERIK 828D: All versions prior to v4.7 SP6 | HF1 Softnet PROFINET IO for PC-based Windows systems: All versions.,CVE-2018-4843,5.3,Medium,CWE-20,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 858,3/13/2018,12/20/2018,2018,ICSA-18-072-01,Omron CX-Supervisor (Update A),Omron,CX-Supervisor,The following versions of CX-Supervisor are affected: Versions 3.40 and prior.,"CVE-2018-7513, CVE-2018-7521, CVE-2018-7515, CVE-2018-7523, CVE-2018-7517, CVE-2018-7525, CVE-2018-7519",5.3,Medium,"CWE-824, CWE-415, CWE-122, CWE-787, CWE-121, CWE-822, CWE-416",Energy,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 857,3/13/2018,3/13/2018,2018,ICSA-18-072-02,OSIsoft PI Data Archive,OSIsoft,PI Data Archive,The following versions of PI Data Archive - data storage solution are affected: PI Data Archive versions 2017 and prior.,"CVE-2018-7529, CVE-2018-7533, CVE-2018-7531",7.5,High,"CWE-502, CWE-20, CWE-276",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 856,3/13/2018,3/13/2018,2018,ICSA-18-072-03,OSIsoft PI Vision,OSIsoft,PI Vision,The following versions of PI Vision - data visualization framework are affected: PI Vision versions 2017 and prior.,"CVE-2018-7504, CVE-2018-7496",6.1,Medium,"CWE-200, CWE-693",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 855,3/13/2018,3/13/2018,2018,ICSA-18-072-04,OSIsoft PI Web API,OSIsoft,PI Web API,OSIsoft reports that the vulnerabilities affect the following PI Web API products: PI Web API versions 2017 R2 and priorNOTE: Not all configurations of PI Web API listed above are affected. Please see the OSIsoft alerts referenced in the Mitigation section.,"CVE-2018-7500, CVE-2018-7508",9.3,Critical,"CWE-79, CWE-264",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 854,2/6/2018,2/6/2018,2018,ICSMA-18-037-02,GE Medical Devices Vulnerability,GE,Medical Devices,The following GE Healthcare products are affected: Optima 520 which are medical imaging systems | all versions |Optima 540 which are medical imaging systems | all versions |Optima 640 which are medical imaging systems | all versions |Optima 680 which are medical imaging systems | all versions | Discovery NM530c which is a nuclear medical imaging system | versions prior to Version 1.003 | Discovery NM750b which is a dedicated breast imaging system | versions prior to Version 2.003 | Discovery XR656 and Discovery XR656 Plus which are digital radiographic imaging systems | all versions |Revolution XQ/i which is a medical imaging system | all versions |THUNIS-800+ which is a stationary diagnostic radiographic and fluoroscopic X-ray system | all versions | Centricity PACS Server which is used to support a medical imaging archiving and communication system | all versions | Centricity PACS RA1000 which is used for diagnostic image analysis | all versions | Centricity PACS-IW which is an integrated web-based system for medical imaging | all versions including Version 3.7.3.7 and Version 3.7.3.8 | Centricity DMS which is a data management software | all versions | Discovery VH / Millenium VG which are nuclear medical imaging systems | all versions | ENTEGRA 2.0/2.5 Processing and Review Workstation which is a nuclear medicine workstation for displaying - archiving and communicating medical imaging | all versions | CADstream which is a medical imaging software | all versions |Optima MR360 which is a medical imaging system | all versions |GEMNet License server (EchoServer) | all versions | Image Vault 3.x medical imaging software | all versions |Infinia / Infinia with Hawkeye 4 / 1 which are medical imaging systems | all versions | Millenium MG / Millenium NC / Millenium MyoSIGHT which are nuclear medical imaging systems | all versions | Precision MP/i which is a medical imaging system | all versions andXeleris 1.0 / 1.1 / 2.1 / 3.0 / 3.1 which are medical imaging workstations | all versions.,"CVE-2010-5306, CVE-2009-5143, CVE-2013-7404, CVE-2014-7232, CVE-2010-5310, CVE-2014-7233, CVE-2012-6693, CVE-2012-6694, CVE-2012-6695, CVE-2013-7442, CVE-2017-14008, CVE-2011-5322, CVE-2007-6757, CVE-2003-1603, CVE-2001-1594, CVE-2010-5309, CVE-2010-5307, CVE-2017-14004, CVE-2004-2777, CVE-2017-14002, CVE-2002-2446, CVE-2012-6660, CVE-2017-14006",9.8,Critical,CWE-287,Healthcare and Public Health,"Canada, United States",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 853,3/8/2018,2/12/2019,2018,ICSA-18-067-02,"Siemens SIPROTEC 4, SIPROTEC Compact, and Reyrolle Devices using the EN100 Ethernet Communication Module Extension (Update B)",Siemens,"SIPROTEC 4, SIPROTEC Compact, and Reyrolle Devices using the EN100 Ethernet Communication Module Extension",Siemens reports that the vulnerability affects the following EN100 Ethernet module products: EN100 Ethernet module IEC 61850 variant: All versions prior to V4.30 | EN100 Ethernet module PROFINET IO variant: All versions | EN100 Ethernet module Modbus TCP variant: All versions | EN100 Ethernet module DNP3 variant: All versions prior to v1.04 andEN100 Ethernet module IEC 104 variant: All versions prior to v1.22.,CVE-2018-4838,7.5,High,CWE-306,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 852,3/6/2018,3/6/2018,2018,ICSA-18-065-01,Hirschmann Automation and Control GmbH Classic Platform Switches,Hirschmann Automation and Control GmbH,Classic Platform Switches,Hirschmann reports that the vulnerabilities affect the following Classic Platform Switches products: RS all versions | RSR all versions | RSB all versions | MACH100 all versions | MACH1000 all versions | MACH4000 all versions | MS all versions and OCTOPUS all versions.,"CVE-2018-5465, CVE-2018-5467, CVE-2018-5471, CVE-2018-5461, CVE-2018-5469, CVE-2018-5465, CVE-2018-5467, CVE-2018-5471, CVE-2018-5461, CVE-2018-5469",7.5,High,"CWE-319, CWE-307, CWE-326, CWE-384, CWE-598",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 851,3/6/2018,3/6/2018,2018,ICSA-18-065-02,Schneider Electric SoMove Software and DTM Software Components,Schneider Electric,SoMove Software and DTM Software Components,Schneider Electric reports the vulnerability affects the following SoMove software and DTM software components: SoMove software | versions prior to 2.6.2ATV320 DTM | versions prior to 1.1.6ATV340 DTM | versions prior to 1.2.3ATV6xx DTM | versions prior to 1.8.0ATV9xx DTM | versions prior to 1.3.5AltivarDtm Library | versions prior to 12.7.0ATV32 DTMATV71 DTMATV61 DTMATV LIFT DTMATV31/312 DTMATV212 DTMATV12 DTM.,CVE-2018-7239,7.8,High,CWE-427,Critical Manufacturing,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 850,3/6/2018,3/6/2018,2018,ICSA-18-065-03,Eaton ELCSoft,Eaton,ELCSoft,ELCSoft is programming software for all Eaton ELC programmable logic controllers. The ELC programmable logic controllers are not affected by this vulnerability. The following versions of ELCSoft are affected: ELCSoft Versions 2.04.02 and prior.,CVE-2018-7511,6.3,Medium,CWE-20,Energy,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 849,3/1/2018,4/19/2018,2018,ICSA-18-060-01,"Siemens SIMATIC, SIMOTION, and SINUMERIK (Update A)",Siemens,"SIMATIC, SIMOTION, and SINUMERIK",Siemens reports that the vulnerabilities affect the following Industrial PCs and BIOS versions: SIMATIC Field-PG M3: ME prior to V6.2.61.3535 | SIMATIC Field-PG M4: BIOS prior to V18.01.06 | SIMATIC Field-PG M5: BIOS prior to V22.01.04 | SIMATIC HMI IPC677C: ME prior to V6.2.61.3535 | SIMATIC IPC427D: BIOS prior to V17.0?.10 | SIMATIC IPC427E: BIOS prior to V21.01.07 | SIMATIC IPC477D: BIOS prior to V17.0?.10 | SIMATIC IPC477D PRO: BIOS prior to V17.0?.10 | SIMATIC IPC477E: BIOS prior to V21.01.07 | SIMATIC IPC547D: ME prior to V7.1.91.3272 | SIMATIC IPC547E: ME prior to V9.1.41.3024 | SIMATIC IPC547G: ME prior to V11.8.50.3425 and BIOS prior to R1.21.0 | SIMATIC IPC627C: ME prior to V6.2.61.3535 | SIMATIC IPC627D: ME prior to V9.1.41.3024 | SIMATIC IPC647C: ME prior to V6.2.61.3535 | SIMATIC IPC647D: ME prior to V9.1.41.3024 | SIMATIC IPC677D: ME prior to V9.1.41.3024 | SIMATIC IPC827C: ME prior to V6.2.61.3535 | SIMATIC IPC827D: ME prior to V9.1.41.3024 | SIMATIC IPC847C: ME prior to V6.2.61.3535 | SIMATIC IPC847D: ME prior to V9.1.41.3024 | SIMATIC ITP1000: BIOS prior to V23.01.03 | SINUMERIK PCU50.5-C | WIN7: ME prior to V6.2.61.3535 | SINUMERIK PCU50.5-C | WINXP: ME prior to V6.2.61.3535 | SINUMERIK PCU50.5-P | WIN7: ME prior to V6.2.61.3535 | SINUMERIK PCU50.5-P | WINXP: ME prior to V6.2.61.3535 andSIMOTION P320-4S: BIOS prior to S17.02.06.83.1.,"CVE-2017-5705, CVE-2017-5706, CVE-2017-5707, CVE-2017-5712, CVE-2017-5708, CVE-2017-5709, CVE-2017-5710",8.2,High,"CWE-264, CWE-121",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 848,3/1/2018,3/1/2018,2018,ICSA-18-060-02,Moxa OnCell G3100-HSPA Series,Moxa,OnCell G3100-HSPA Series,The following versions of OnCell - high-speed industrial-grade IP gateway are affected: OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior.,"CVE-2018-5455, CVE-2018-5453, CVE-2018-5449",9.8,Critical,"CWE-130, CWE-476, CWE-565",Commercial Facilities; Critical Manufacturing; Transportation Systems,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 847,3/1/2018,3/1/2018,2018,ICSA-18-060-03,Delta Electronics Delta Industrial Automation DOPSoft,Delta Electronics,Delta Industrial Automation DOPSoft,The following version of Delta Industrial Automation DOPSoft - human machine interface (HMI) | is affected: Delta Industrial Automation DOPSoft | Version 4.00.01 or prior.,CVE-2018-5476,6.3,Medium,CWE-121,Commercial Facilities; Communications; Critical Manufacturing; Energy; Healthcare and Public Health,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 846,2/27/2018,3/20/2018,2018,ICSA-18-058-01,Siemens SIMATIC Industrial PCs (Update A),Siemens,SIMATIC Industrial PCs,Siemens reports that the vulnerability affects the following versions of SIMATIC Industrial PCs using a version of Infineon's Trusted Platform Module (TPM): SIMATIC Field-PG M5 all versions prior to v22.01.04 | SIMATIC IPC227E all versions prior to v20.01.10 | SIMATIC IPC277E all versions prior to v20.01.10 | SIMATIC IPC427E all versions prior to v21.01.07 | SIMATIC IPC477E all versions prior to v21.01.07 | SIMATIC IPC547G all versions prior to R1.21.0 and SIMATIC ITP1000 all versions prior to v23.01.03.,CVE-2017-15361,5.9,Medium,CWE-310,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 845,2/27/2018,2/27/2018,2018,ICSA-18-058-02,Delta Electronics WPLSoft,Delta Electronics,WPLSoft,The following versions of WPLSoft - PLC programming software are affected: WPLSoft | Versions 2.45.0 and prior.,"CVE-2018-7494, CVE-2018-7507, CVE-2018-7509",8.3,High,"CWE-122, CWE-787, CWE-121",Commercial Facilities; Critical Manufacturing; Energy,"Taiwan, United States, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 844,2/27/2018,8/22/2018,2018,ICSA-18-058-03,Emerson ControlWave Micro Process Automation Controller,Emerson,ControlWave Micro Process Automation Controller,The following versions of ControlWave Micro firmware - family of SCADA RTUs | PLCs | PACs and flow computers are affected: ControlWave Micro [ProConOS v.4.01.280] - firmware: CWM v.05.78.00 and prior.,CVE-2018-5452,7.5,High,CWE-121,Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 843,2/27/2018,2/27/2018,2018,ICSMA-18-058-02,Philips Intellispace Portal ISP Vulnerabilities,Philips,Intellispace Portal ISP,Philips reports that these vulnerabilities affect the following versions of the ISP: IntelliSpace Portal | all 8.0.x versions and IntelliSpace Portal | all 7.0.x versions.,"CVE-2018-5474, CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, CVE-2017-0148, CVE-2017-0272, CVE-2017-0277, CVE-2017-0278, CVE-2017-0279, CVE-2017-0269, CVE-2017-0273, CVE-2017-0280, CVE-2017-0147, CVE-2017-0267, CVE-2017-0268, CVE-2017-0270, CVE-2017-0271, CVE-2017-0274, CVE-2017-0275, CVE-2017-0276, CVE-2018-5472, CVE-2018-5468, CVE-2017-0199, CVE-2005-1794, CVE-2018-5470, CVE-2018-5454, CVE-2018-5458, CVE-2018-5462, CVE-2018-5464, CVE-2018-5466, CVE-2011-3389, CVE-2004-2761, CVE-2014-3566, CVE-2016-2183",6.1,Medium,"CWE-489, CWE-310, CWE-200, CWE-20, CWE-264, CWE-428",Healthcare and Public Health,"United States, North America, South America, Asia, Europe, Africa, Middle East",Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 842,2/20/2018,2/22/2018,2018,ICSA-18-051-01,ABB netCADOPS Web Application,ABB,netCADOPS Web Application,The following versions of netCADOPS Web Application - web interface are affected: netCADOPS Web Application Version 3.4 and prior | NetCADOPS Web Application Version 7.1 and prior | NetCADOPS Web Application Version 7.2x and prior | netCADOPS Web Application Version 8.0 and prior and netCADOPS Web Application Version 8.1 and prior.,CVE-2018-5477,5.8,Medium,CWE-200,Critical Manufacturing; Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 841,2/15/2018,2/19/2018,2018,ICSA-18-046-01,Nortek Linear eMerge E3 Series,Nortek,Linear eMerge E3 Series,The following Linear eMerge - access control interface versions are affected: Linear eMerge E3 series Versions V0.32-07e and prior.,CVE-2018-5439,9.8,Critical,CWE-77,Commercial Facilities,Worldwide,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 840,2/15/2018,2/15/2018,2018,ICSA-18-046-02,GE D60 Line Distance Relay,GE,D60 Line Distance Relay,The following versions of the D60 Line Distance Relay are affected: D60 devices running firmware Version 7.11 and prior.,"CVE-2018-5475, CVE-2018-5473",9.8,Critical,"CWE-119, CWE-121",Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 839,2/15/2018,2/15/2018,2018,ICSA-18-046-03,Schneider Electric IGSS Mobile,Schneider Electric,IGSS Mobile,Schneider Electric reports that the vulnerabilities affect the following IGSS Mobile products: IGSS Mobile for Android | version 3.01 and all versions prior andIGSS Mobile for iOS | version 3.01 and all versions prior.,"CVE-2017-9968, CVE-2017-9969",6.4,Medium,"CWE-295, CWE-256",Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 838,2/15/2018,2/15/2018,2018,ICSA-18-046-04,Schneider Electric StruxureOn Gateway,Schneider Electric,StruxureOn Gateway,Schneider Electric reports that the vulnerability affects the following versions of StruxureOn Gateway - software management platform: StruxureOn Gateway | all versions prior to 1.2.,CVE-2017-9970,7.2,High,CWE-434,Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 837,2/13/2018,2/15/2018,2018,ICSA-18-044-01,WAGO PFC200 Series,WAGO,PFC200 Series,The following 3S CoDeSys Runtime versions of the PFC200 Series are affected: CoDeSys Version 2.3.XCoDeSys Version 2.4.XThe affected CoDeSys Runtime version is part of WAGO PFC200 Firmware prior to 02.07.07(10) | affected PFC200 devices: 750-8202 |750-8202/025-000 |750-8202/025-001 |750-8202/025-002 |750-8202/040-001 |750-8203 |750-8203/025-000 |750-8204 |750-8204/025-000 |750-8206 |750-8206/025-000 |750-8206/025-001 |750-8207 |750-8207/025-000 |750-8207/025-001 |750-8208 and750-8208/025-000.,CVE-2018-5459,9.8,Critical,CWE-287,Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,"China, Germany, India, Poland, Switzerland, United States",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 836,2/13/2018,2/13/2018,2018,ICSA-18-044-02,Schneider Electric IGSS SCADA Software,Schneider Electric,IGSS SCADA Software,Schneider Electric reports that the vulnerability affects the following IGSS SCADA Software products: IGSS SCADA Software V12 and all previous versions.,CVE-2017-9967,7.0,High,CWE-815,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 835,2/6/2018,1/10/2020,2018,ICSMA-18-037-01,Vyaire Medical CareFusion Upgrade Utility Vulnerability,Vyaire Medical,CareFusion Upgrade Utility,The following versions of CareFusion Upgrade Utility | designed to upgrade compatible units to the latest software versions are affected: CareFusion Upgrade Utility used with Windows XP systems | Versions 2.0.2.2 and prior versions.,CVE-2018-5457,6.7,Medium,CWE-427,Healthcare and Public Health,"United States, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 834,2/1/2018,2/1/2018,2018,ICSA-18-032-01,Fuji Electric V-Server VPR,Fuji Electric,V-Server VPR,The following versions of V-Server VPR - data collection and management service are affected: V-Server VPR 4.0.1.0 and prior.,CVE-2018-5442,8.6,High,CWE-121,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 833,2/1/2018,2/1/2018,2018,ICSA-18-032-02,3S-Smart Software Solutions GmbH CODESYS Web Server,3S-Smart Software Solutions GmbH,CODESYS Web Server,All Microsoft Windows (also WinCE) based CODESYS web servers running stand-alone Version 2.3 | or as part of the CODESYS runtime system running prior to Version V1.1.9.19 are affected.,CVE-2018-5440,9.8,Critical,CWE-121,Critical Manufacturing; Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 832,2/1/2018,2/8/2018,2018,ICSA-18-032-03,Gemalto Sentinel License Manager,Gemalto,Sentinel License Manager,The following Sentinel License Manger services are affected: All HASP SRM | Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE 7.55,"CVE-2017-11498, CVE-2017-11497, CVE-2017-11496, CVE-2017-12818, CVE-2017-12821, CVE-2017-12820, CVE-2017-12822",9.9,Critical,"CWE-122, CWE-284, CWE-476, CWE-121",Communications; Financial Services; Government Facilities; Healthcare and Public Health; Information Technology,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 831,1/30/2018,1/30/2018,2018,ICSA-18-030-01,PHOENIX CONTACT mGuard,PHOENIX CONTACT,mGuard,The following versions of mGuard - network device are affected: mGuard firmware versions 7.2 to 8.6.0.,CVE-2018-5441,7.8,High,CWE-354,Communications; Critical Manufacturing; Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 830,1/30/2018,1/30/2018,2018,ICSA-18-030-02,Siemens TeleControl Server Basic,Siemens,TeleControl Server Basic,The following versions of TeleControl Server Basic - monitoring platform are affected: TeleControl Server Basic versions prior to V3.1.,"CVE-2018-4835, CVE-2018-4836, CVE-2018-4837",8.8,High,"CWE-288, CWE-264, CWE-400",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 829,1/25/2018,5/3/2018,2018,ICSA-18-025-01,Nari PCS-9611 (Update A),Nari,PCS-9611,All versions of the PCS-9611 relay - control and monitoring unit are affected.,CVE-2018-5447,9.8,Critical,CWE-20,Energy,"China, Asia",China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 828,1/25/2018,3/12/2019,2018,ICSA-18-025-02,Siemens Desigo PXC (Update C),Siemens,Desigo PXC,Siemens reports that the vulnerability affects all versions prior to v4.10.111 | v5.00.171 | v5.10.069 and v6.00.204 of the following products: Desigo Automation Controllers Compact PXC12/22/36-E.D | Desigo Automation Controllers Modular PXC00/50/100/200-E.D | Desigo Automation Controllers PXC00/64/128-U with Web module | Desigo Automation Controllers for Integration PXC001-E.D andDesigo Operator Unit PXM20-E.,CVE-2018-4834,9.8,Critical,CWE-287,Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 827,1/25/2018,1/25/2018,2018,ICSMA-18-025-01,Philips IntelliSpace Cardiovascular System Vulnerability,Philips,IntelliSpace Cardiovascular System,Philips reports that the vulnerability affects the following versions of the IntelliSpace Cardiovascular: IntelliSpace Cardiovascular | Version 2.3.0 and prior.,CVE-2018-5438,6.7,Medium,CWE-613,Healthcare and Public Health,"United States, North America, South America, Asia, Europe, Africa, Middle East",Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 826,1/23/2018,1/23/2018,2018,ICSA-18-023-01,Advantech WebAccess/SCADA,Advantech,WebAccess/SCADA,The following versions of WebAccess/SCADA - SCADA software platform are affected: WebAccess/SCADA versions prior to V8.2_20170817.,"CVE-2018-5445, CVE-2018-5443",5.3,Medium,"CWE-22, CWE-89",Critical Manufacturing; Energy; Water and Wastewater,"Taiwan, United States, Asia, East Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 825,1/23/2018,2/12/2019,2018,ICSA-18-023-02,Siemens Industrial Products (Update A),Siemens,Industrial Products,"Siemens reports that this vulnerability affects the following products using PROFINET DCP: SIMATIC CP 1242-7 GPRS v2: All versions prior to v2.1.82 | SIMATIC CP 1243-7 LTE EU/US: All versions prior to v2.1.82 | SIMATIC CP 1243-8: All versions prior to v2.1.82 | SIMATIC CP 1626: All versions prior to v1.1 | Extension Unit 12"" PROFINET: All versions prior to v01.01.01 | Extension Unit 15"" PROFINET: All versions prior to v01.01.01 | Extension Unit 19"" PROFINET: All versions prior to v01.01.01 andExtension Unit 22"" PROFINET: All versions prior to v01.01.01.",CVE-2017-2680,6.5,Medium,CWE-20,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 824,1/18/2018,2/27/2018,2018,ICSA-18-018-01,Siemens SIMATIC WinCC Add-On (Update A),Siemens,SIMATIC WinCC Add-On,Siemens reports that the vulnerabilities affect the following versions of SIMATIC WinCC Add-On: SIMATIC WinCC Add-On Historian CONNECT ALARM all versions prior to and including v5.x | SIMATIC WinCC Add-On PI CONNECT ALARM all versions prior to and including v2.x | SIMATIC WinCC Add-On PI CONNECT AUDIT TRAIL all versions prior to and including v1.x | SIMATIC WinCC Add-On PM-AGENT all versions prior to and including v5.x | SIMATIC WinCC Add-On PM-ANALYZE all versions prior to and including v7.x | SIMATIC WinCC Add-On PM-CONTROL all versions prior to and including v10.x | SIMATIC WinCC Add-On PM-MAINT all versions prior to and including v9.x | SIMATIC WinCC Add-On PM-OPEN EXPORT all versions prior to and including v7.x | SIMATIC WinCC Add-On PM-OPEN HOST-S all versions prior to and including v7.x | SIMATIC WinCC Add-On PM-OPEN IMPORT all versions prior to and including v6.x | SIMATIC WinCC Add-On PM-OPEN PI all versions prior to and including v7.x | SIMATIC WinCC Add-On PM-OPEN PV02 all versions prior to and including v1.x | SIMATIC WinCC Add-On PM-OPEN TCP/IP all versions prior to and including v8.x | SIMATIC WinCC Add-On PM-QUALITY all versions prior to and including v9.x | SIMATIC WinCC Add-On SICEMENT IT MIS all versions prior to and including v7.x andSIMATIC WinCC Add-On SIPAPER IT MIS all versions prior to and including v7.x.,"CVE-2017-11496, CVE-2017-11497, CVE-2017-11498, CVE-2017-12818, CVE-2017-12819, CVE-2017-12820, CVE-2017-12821, CVE-2017-12822",9.8,Critical,"CWE-121, CWE-20, CWE-119, CWE-254, CWE-284",Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 823,1/11/2018,1/18/2018,2018,ICSA-18-011-01,"WECON Technology Co., Ltd. LeviStudio HMI Editor",WECON,"Technology Co., Ltd. LeviStudio HMI Editor",The following versions of LEVI Studio HMI Editor - HMI programming software product are affected: LEVI Studio HMI Editor v1.8.29 and prior.,"CVE-2017-16739, CVE-2017-16737",5.3,Medium,"CWE-122, CWE-121",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 822,1/11/2018,1/11/2018,2018,ICSA-18-011-02,Moxa MXview,Moxa,MXview,The following versions of MXview - network management software are affected: MXview v2.8 and prior.,CVE-2017-14030,7.8,High,CWE-428,Critical Manufacturing; Energy; Transportation,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 821,1/11/2018,1/11/2018,2018,ICSA-18-011-03,PHOENIX CONTACT FL SWITCH,PHOENIX CONTACT,FL SWITCH,All FL SWITCH 3xxx | 4xxx and 48xxx Series products running firmware Version 1.0 to 1.32 are affected.,"CVE-2017-16743, CVE-2017-16741",9.8,Critical,"CWE-200, CWE-285",Communications; Critical Manufacturing; Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 820,1/9/2018,1/9/2018,2018,ICSA-18-009-01,Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers,Rockwell Automation,Allen-Bradley MicroLogix 1400 Controllers,The following versions of MicroLogix 1400 Controllers - PLC are affected: MicroLogix 1400 Controllers | Series B and C Versions 21.002 and earlier Rockwell Automation reports that the following catalogs are affected: 1766-L32AWA1766-L32AWAA1766-L32BWA1766-L32BWAA1766-L32BXB1766-L32BXBA.,CVE-2017-16740,8.6,High,CWE-120,Critical Manufacturing; Food and Agriculture; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 819,8/22/2017,4/3/2018,2018,ICSA-17-234-04,General Motors and Shanghai OnStar (SOS) iOS Client,"General Motors (GM), Shanghai OnStar",OnStar (SOS) iOS Client,The following version of Shanghai OnStar iOS Client - vehicle management mobile application is affected: Shanghai OnStar iOS Client Version 7.1.,"CVE-2017-9663, CVE-2017-12697, CVE-2017-12695",9.8,Critical,"CWE-300, CWE-312, CWE-287",Transportation Systems,"United States, North America, Asia",China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 818,8/22/2017,4/3/2018,2018,ICSA-17-234-04,General Motors and Shanghai OnStar (SOS) iOS Client,"General Motors (GM), Shanghai OnStar",OnStar (SOS) iOS Client,The following version of Shanghai OnStar iOS Client - vehicle management mobile application is affected: Shanghai OnStar iOS Client Version 7.1.,"CVE-2017-9663, CVE-2017-12697, CVE-2017-12695",9.8,Critical,"CWE-300, CWE-312, CWE-287",Transportation Systems,"United States, North America, Asia",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 817,1/4/2018,1/5/2018,2018,ICSA-18-004-01,Delta Electronics Delta Industrial Automation Screen Editor,Delta Electronics,Delta Industrial Automation Screen Editor,The following versions of Delta Industrial Automation Screen Editor - graphical user interface (GUI) are affected: Delta Industrial Automation Screen Editor | Version 2.00.23.00 or prior.,"CVE-2017-16751, CVE-2017-16749, CVE-2017-16747, CVE-2017-16745",5.5,Medium,"CWE-843, CWE-787, CWE-121, CWE-416",Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 816,1/4/2018,1/11/2018,2018,ICSA-18-004-02,Advantech WebAccess (Update A),Advantech,WebAccess,Advantech reports the vulnerabilities affect the following WebAccess products: WebAccess versions prior to 8.3,"CVE-2017-16728, CVE-2017-16724, CVE-2017-16720, CVE-2017-16716, CVE-2017-16753, CVE-2017-16736, CVE-2017-16732",8.2,High,"CWE-20, CWE-22, CWE-89, CWE-121, CWE-434, CWE-822, CWE-416",Critical Manufacturing; Energy; Water and Wastewater,"Taiwan, United States, Asia, East Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 815,12/21/2017,12/21/2017,2017,ICSA-17-355-01,Moxa NPort W2150A and W2250A,Moxa,NPort W2150A and W2250A,The following versions of NPort - serial network interface are affected: NPort W2150A Versions prior to 1.11 and NPort W2250A Versions prior to 1.11.,CVE-2017-16727,6.5,Medium,CWE-255,Critical Manufacturing; Energy; Transportation,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 814,12/21/2017,12/21/2017,2017,ICSA-17-355-02,Schneider Electric Pelco VideoXpert Enterprise,Schneider Electric,Pelco VideoXpert Enterprise,Schneider Electric reports that the vulnerabilities affect the following Pelco VideoXpert Enterprise products: Pelco VideoXpert Enterprise all versions prior to 2.1.,"CVE-2017-9964, CVE-2017-9965, CVE-2017-9966",7.1,High,"CWE-284, CWE-22",Commercial Facilities,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 813,12/19/2017,12/19/2017,2017,ICSA-17-353-01,ABB Ellipse,ABB,Ellipse,ABB reports that the vulnerability affects Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellipse Select).,CVE-2017-16731,6.5,Medium,CWE-523,Critical Manufacturing; Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 812,12/19/2017,12/19/2017,2017,ICSA-17-353-02,PEPPERL+FUCHS/ecom instruments WLAN Capable Devices using the WPA2 Protocol,"PEPPERL+FUCHS, ecom instrument",WLAN Capable Devices using the WPA2 Protocol,PEPPERL+FUCHS/ecom instruments reports that these vulnerabilities affect all versions of the following WLAN capable devices using the WPA2 Protocol: Tab-Ex 01 | Ex-Handy 09 | Ex-Handy 209 | Smart-Ex 01 | Smart-Ex 201 | Pad-Ex 01 | i.roc Ci70-Ex | CK70A-ATEX | CK71A-ATEX | CN70A-ATEX and CN70E-ATEX.,"CVE-2017-13077, CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, CVE-2017-13081, CVE-2017-13082, CVE-2017-13086, CVE-2017-13087, CVE-2017-13088",8.1,High,"CWE-323, CWE-330",Communications; Critical Manufacturing; Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 811,12/19/2017,12/19/2017,2017,ICSA-17-353-03,Ecava IntegraXor,Ecava,IntegraXor,The following version of IntegraXor - web SCADA/HMI solution is affected: Ecava IntegraXor v 6.1.1030.1 and prior.,"CVE-2017-16733, CVE-2017-16735",5.3,Medium,CWE-89,Critical Manufacturing; Energy; Water and Wastewater,"Australia, Canada, Estonia, United Kingdom, Malaysia, Poland, United States",Malaysia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 810,12/19/2017,12/19/2017,2017,ICSA-17-353-04,Siemens LOGO! Soft Comfort,Siemens,LOGO! Soft Comfort,Siemens reports that the vulnerability affects the following LOGO! Soft Comfort engineering software products: LOGO! Soft Comfort: All versions prior to V8.2.,CVE-2017-12740,5.9,Medium,CWE-494,Commercial Facilities; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 809,12/19/2017,2/20/2018,2017,ICSA-17-353-05,"WECON Technology Co., Ltd. LeviStudio HMI Editor",WECON,"Technology Co., Ltd. LeviStudio HMI Editor",All versions of LeviStudio HMI an HMI editor are affected.,CVE-2017-16717,7.3,High,CWE-122,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 808,12/7/2017,12/7/2017,2017,ICSA-17-341-01,Xiongmai Technology IP Cameras and DVRs,Xiongmai,Technology IP Cameras and DVRs,The following versions of Xiongmai Technology IP cameras and DVRs are affected: All IP Cameras and DVRs using the NetSurveillance Web interface.,CVE-2017-16725,9.8,Critical,CWE-121,Unknown,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 807,12/7/2017,12/7/2017,2017,ICSA-17-341-02,Rockwell Automation FactoryTalk Alarms and Events,Rockwell Automation,FactoryTalk Alarms and Events,The following versions of FactoryTalk Alarms and Events - component of the Factory Talk Services Platform are affected: FactoryTalk Alarms and Events | Version 2.90 and earlier FactoryTalk Alarms and Events is used in the following Rockwell Automation products: FactoryTalk Services (RSLinx Enterprise) all versions. FactoryTalk View SE | versions 5.00 and later. Studio 5000 Logix Designer | versions 24 and later.,CVE-2017-14022,7.5,High,CWE-20,Chemical; Critical Manufacturing; Food and Agriculture; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 806,12/7/2017,12/7/2017,2017,ICSA-17-341-03,"PHOENIX CONTACT FL COMSERVER, FL COM SERVER, and PSI-MODEM/ETH",PHOENIX CONTACT,"FL COMSERVER, FL COM SERVER, and PSI-MODEM/ETH",The following models running firmware versions prior to 1.99 | 2.20 or 2.40 of FL COMSERVER | FL COM SERVER and PSI-MODEM/ETH | industrial networking equipment are affected: FL COMSERVER BASIC 232/422/485 | FL COMSERVER UNI 232/422/485 | FL COMSERVER BAS 232/422/485-T | FL COMSERVER UNI 232/422/485-T | FL COM SERVER RS232 | FL COM SERVER RS485 and PSI-MODEM/ETH.,CVE-2017-16723,8.2,High,CWE-79,Communications; Critical Manufacturing; Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 805,11/30/2017,11/30/2017,2017,ICSA-17-334-01,Siemens SWT3000,Siemens,SWT3000,Siemens reports that the vulnerabilities affect the following SWT 3000 Teleprotection system products: EN100 for SWT3000 (iSWT3000): IEC 61850 firmware: All versions prior to V4.29.01 TPOP firmware: All versions prior to V01.01.00.,"CVE-2016-4784, CVE-2016-4785, CVE-2016-7112, CVE-2016-7113, CVE-2016-7114",5.3,Medium,"CWE-288, CWE-287, CWE-20",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 804,11/30/2017,10/25/2018,2017,ICSA-17-334-02,GEOVAP Reliance SCADA,GEOVAP,Reliance SCADA,The following versions of Reliance SCADA - software management platforms are affected: Reliance SCADA Version 4.7.3 Update 2 and prior.,CVE-2017-16721,6.1,Medium,CWE-79,Critical Manufacturing; Energy; Transportation Systems; Water and Wastewater,Worldwide,Czech Republic,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 803,11/28/2017,12/1/2017,2017,ICSMA-17-332-01,Ethicon Endo-Surgery Generator G11 Vulnerability,Ethicon,Endo-Surgery Generator G11,"The following versions of the Ethicon Endo-Surgery Generator Gen11 are affected: Ethicon Endo-Surgery Generator Gen11 | all versions released before November 29, 2017.",CVE-2017-14018,4.8,Medium,CWE-287,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 802,11/21/2017,11/21/2017,2017,ICSA-17-325-01,PHOENIX CONTACT WLAN Capable Devices using the WPA2 Protocol,PHOENIX CONTACT,WLAN Capable Devices using the WPA2 Protocol,PHOENIX CONTACT reports that these vulnerabilities affect all versions of the following WLAN capable devices using the WPA2 Protocol: BL2 BPC | BL2 PPC | FL COMSERVER WLAN 232/422/485 | FL WLAN 110x | FL WLAN 210x | FL WLAN 510x | FL WLAN 230 AP 802-11 | FL WLAN 24 AP 802-11 | FL WLAN 24 DAP 802-11 | FL WLAN 24 EC 802-11 | FL WLAN EPA | FL WLAN SPA | ITC 8113 | RAD-80211-XD | RAD-WHG/WLAN-XD | TPC 6013 | VMT 30xx | VMT 50xx and VMT 70xx.,"CVE-2017-13080, CVE-2017-13078, CVE-2017-13077",6.8,Medium,CWE-323,Communications; Critical Manufacturing; Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 801,11/16/2017,11/16/2017,2017,ICSA-17-320-01,"Moxa NPort 5110, 5130, and 5150",Moxa,"NPort 5110, 5130, and 5150",The following versions of NPort - serial network interface are affected: NPort 5110 Version 2.2 | NPort 5110 Version 2.4 | NPort 5110 Version 2.6 | NPort 5110 Version 2.7 | NPort 5130 Version 3.7 and prior and NPort 5150 Version 3.7 and prior.,"CVE-2017-16719, CVE-2017-16715, CVE-2017-14028",8.6,High,"CWE-200, CWE-74, CWE-400",Critical Manufacturing; Dams; Energy; Transportation,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 800,11/16/2017,11/16/2017,2017,ICSA-17-320-02,Siemens SICAM,Siemens,SICAM,Siemens reports that the vulnerabilities affect the following SICAM products: SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00 | ERAC00 | ETA2 | ETLS00 | MODi00 | DNPi00: All versions.,"CVE-2017-12737, CVE-2017-12738, CVE-2017-12739",9.8,Critical,"CWE-94, CWE-79, CWE-306",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 799,11/14/2017,4/9/2019,2017,ICSA-17-318-01,"Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update F)",Siemens,"SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products",Siemens reports that the key reinstallation attacks (KRACK) potentially affect the following Siemens industrial products: RUGGEDCOM RS9xxW: All versions | RUGGEDCOM RX1400 with WLAN interface: All versions prior to v2.11.2 | SCALANCE W-700 (IEEE 802.11a/b/g): All versions | SCALANCE W-700 (IEEE 802.11n): All versions prior to v6.2.1 | SCALANCE W1750D: All versions prior to v6.5.1.5-4.3.1.8 | SCALANCE WLC711: All versions prior to v9.21.19.003 | SCALANCE WLC712: All versions prior to v9.21.19.003 | SIMATIC ET200 PRO IM154-6 PN IWLAN: All versions | SIMATIC IWLAN-PB/LINK: All versions | SIMATIC Mobile Panel 277(F) IWLAN: All versions. SINAMICS v20 Smart Access Module: All versions prior to v01.03.01. SIMATIC RF350M: All versions with Summit Client Utility prior to v22.3.5.16 | SIMATIC RF650M: All versions with Summit Client Utility prior to v22.3.5.164.2,"CVE-2017-13077, CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, CVE-2017-13081, CVE-2017-13082, CVE-2017-13084, CVE-2017-13086, CVE-2017-13087, CVE-2017-13088",6.8,Medium,CWE-254,Chemical; Energy; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 798,11/14/2017,2/15/2018,2017,ICSA-17-318-02,ABB TropOS (Update A),ABB,TropOS,ABB reports that the key reinstallation attacks (KRACK) potentially affect all TropOS broadband mesh routers and bridges operating on Mesh OS release 8.5.2 or prior.,"CVE-2017-13077, CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, CVE-2017-13081, CVE-2017-13082, CVE-2017-13084, CVE-2017-13086, CVE-2017-13087, CVE-2017-13088",6.8,Medium,CWE-254,Critical Manufacturing; Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 797,11/14/2017,11/14/2017,2017,ICSMA-17-318-01,Philips IntelliSpace Cardiovascular System and Xcelera System Vulnerability,Philips,IntelliSpace Cardiovascular System and Xcelera System,Philips reports that the vulnerability affects the following versions of the IntelliSpace Cardiovascular and Xcelera cardiac image and information management systems: IntelliSpace Cardiovascular | Version 2.3.0 and prior and Xcelera | R4.1L1 and prior.,CVE-2017-14111,7.2,High,CWE-522,Healthcare and Public Health,"Netherlands, North America, South America, Asia, Europe, Africa, Middle East",Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 796,11/9/2017,7/24/2018,2017,ICSA-17-313-01,"AutomationDirect CLICK, C-More, C-More Micro, Do-more Designer, GS Drives, SL-Soft SOLO, DirectSOFT (Update B)",AutomationDirect,"CLICK, C-More, C-More Micro, Do-more Designer, GS Drives, SL-Soft SOLO, DirectSOFT",The following AutomationDirect products are affected: CLICK Programming Software (Part Number C0-PGMSW) Versions 2.10 and prior | C-More Programming Software (Part Number EA9-PGMSW) Versions 6.30 and prior | C-More Micro (Part Number EA-PGMSW) Versions 4.20.01.0 and prior | Do-more Designer Software (Part Number DM-PGMSW) Versions 2.0.3 and prior | GS Drives Configuration Software (Part Number GSOFT) Versions 4.0.6 and prior and SL-SOFT SOLO Temperature Controller Configuration Software (Part Number SL-SOFT) Versions 1.1.0.5 and prior. DirectSOFT Programming Software Versions 6.1 and prior.,CVE-2017-14020,6.7,Medium,CWE-427,Commercial Facilities; Critical Manufacturing; Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 795,11/9/2017,11/9/2017,2017,ICSA-17-313-02,Schneider Electric InduSoft Web Studio and InTouch Machine Edition,Schneider Electric,InduSoft Web Studio and InTouch Machine Edition,The following versions of InduSoft Web Studio and InTouch Machine Edition an HMI are affected: InduSoft Web Studio v8.0 SP2 Patch 1 and prior versions and InTouch Machine Edition v8.0 SP2 Patch 1 and prior versions.,CVE-2017-14024,9.8,Critical,CWE-121,Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 794,11/2/2017,6/12/2018,2017,ICSA-17-306-01,Siemens SIMATIC PCS 7 (Update A),Siemens,SIMATIC PCS 7,The following versions of SIMATIC PCS 7 - distributed control system are affected: v8.1 all versions prior to v8.1 SP1 with WinCC v7.3 Upd 13 and v8.2 all versions prior to v8.2 SP1.,CVE-2017-6867,4.9,Medium,CWE-20,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 793,11/2/2017,11/2/2017,2017,ICSA-17-306-02,Advantech WebAccess,Advantech,WebAccess,The following versions of WebAccess an HMI platform are affected: WebAccess versions prior to V8.2_20170817.,"CVE-2017-14016, CVE-2017-12719",7.3,High,"CWE-121, CWE-822",Critical Manufacturing; Energy; Water and Wastewater,"Taiwan, United States, Asia, East Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 792,10/31/2017,10/31/2017,2017,ICSA-17-304-01,ABB FOX515T,ABB,FOX515T,The following versions of FOX515T - communication interface are affected: FOX515T release 1.0.,CVE-2017-14025,6.2,Medium,CWE-20,Communications,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 791,10/31/2017,10/31/2017,2017,ICSA-17-304-02,Trihedral Engineering Limited VTScada,Trihedral Engineering Limited,VTScada,Trihedral Engineering Limited reports that the vulnerability affects the following versions of the VTScada HMI and SCADA software: VTScada 11.3.03 and prior.,"CVE-2017-14031, CVE-2017-14029",7.8,High,"CWE-284, CWE-427",Chemical; Communications; Critical Manufacturing; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,"Canada, North America, Europe",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 790,10/26/2017,10/26/2017,2017,ICSA-17-299-01,Korenix JetNet,Korenix,JetNet,The following versions of JetNet an Ethernet switch are affected: JetNet5018G version 1.4 | JetNet5310G version 1.4a | JetNet5428G-2G-2FX version 1.4 | JetNet5628G-R version 1.4 | JetNet5628G version 1.4 | JetNet5728G-24P version 1.4 | JetNet5828G version 1.1d | JetNet6710G-HVDC version 1.1e and JetNet6710G version 1.1,"CVE-2017-14021, CVE-2017-14027",9.8,Critical,"CWE-798, CWE-321",Commercial Facilities; Critical Manufacturing ;Transportation,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 789,10/26/2017,11/1/2018,2017,ICSA-17-299-02,Rockwell Automation Stratix 5100 (Update A),Rockwell Automation,Stratix 5100,Rockwell Automation reports the vulnerability affects the following wireless access point/workgroup bridge products: Stratix 5100 Version 15.3(3) JC1 and earlier.4.2,CVE-2017-13082,6.9,Medium,CWE-323,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 788,10/19/2017,10/19/2017,2017,ICSA-17-292-01,SpiderControl MicroBrowser,SpiderControl,MicroBrowser,The following versions of SpiderControl MicroBrowser - touch panel operating system are affected: MicroBrowser Windows XP | Vista 7 | 8 and 10 | Versions 1.6.30.144 and prior.,CVE-2017-14010,8.8,High,CWE-427,Critical Manufacturing,"Switzerland, Europe",Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 787,10/19/2017,10/19/2017,2017,ICSMA-17-292-01,Boston Scientific ZOOM LATITUDE PRM Vulnerabilities,Boston Scientific,ZOOM LATITUDE PRM,The following ZOOM LATITUDE PRM versions are affected: ZOOM LATITUDE PRM - Model 3120 all versions.,"CVE-2017-14014, CVE-2017-14012",4.6,Medium,"CWE-311, CWE-321",Healthcare and Public Health,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 786,10/17/2017,10/17/2017,2017,ICSA-17-290-01,Progea Movicon SCADA/HMI,Progea,Movicon SCADA/HMI,The following versions of Movicon HMI an HMI software platform are affected: Movicon Version 11.5.1181 and prior.,"CVE-2017-14017, CVE-2017-14019",6.8,Medium,"CWE-427, CWE-428",Critical Manufacturing; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,"India, Italy, United States, Europe",Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 785,10/12/2017,10/12/2017,2017,ICSA-17-285-01,ProMinent MultiFLEX M10a Controller,ProMinent,MultiFLEX M10a Controller,The following versions of MultiFLEX Controller - water treatment controller are affected: All versions of MultiFLEX M10a Controller web interface.,"CVE-2017-14013, CVE-2017-14007, CVE-2017-14011, CVE-2017-14009, CVE-2017-14005",8.8,High,"CWE-602, CWE-352, CWE-200, CWE-613, CWE-620",Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 784,10/12/2017,10/12/2017,2017,ICSA-17-285-02,"WECON Technology Co., Ltd. LeviStudio HMI Editor",WECON,"Technology Co., Ltd. LeviStudio HMI Editor",The following versions of LEVI Studio HMI Editor an HMI programming software product are affected: LEVI Studio HMI Editor v1.8.1 and prior.,CVE-2017-13999,7.5,High,CWE-121,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 783,10/12/2017,10/12/2017,2017,ICSA-17-285-03,Envitech Ltd. EnviDAS Ultimate,Envitech Ltd.,EnviDAS Ultimate,The following versions of EnviDAS Ultimate - web application for environmental monitoring are affected: EnviDAS Ultimate Versions prior to v1.0.0.5.,CVE-2017-9625,8.2,High,CWE-287,Commercial Facilities; Communications; Water and Wastewater,Worldwide,Israel,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 782,10/12/2017,2/1/2018,2017,ICSA-17-285-04,NXP Semiconductors MQX RTOS (Update A),NXP Semiconductors,MQX RTOS,The following versions of MQX Real-Time Operating System (RTOS) are used in NXP's ColdFire microcontrollers | Kinetis microcontrollers | i.MX processors and Vybrid processors which are affected by the vulnerabilities listed below.Versions susceptible to Classic Buffer Overflow Vulnerability: MQX RTOS | Version 5.0 and prior versions and Versions susceptible to Out-of-Bounds Read Vulnerability: MQX RTOS | Version 4.1 and prior versions.,"CVE-2017-12718, CVE-2017-12722",8.1,High,"CWE-120, CWE-125",Communications; Critical Manufacturing; Healthcare and Public Health; Transportation Systems,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 781,10/12/2017,6/16/2022,2017,ICSA-17-285-05,Siemens BACnet Field Panels (Update A),Siemens,BACnet Field Panels,Siemens reports that the vulnerabilities affect the following BACnet field panels: --------- Begin Update A Part 1 of 3 --------- APOGEE PXC Compact (BACnet): All versions prior to v3.5 APOGEE PXC Compact (P2 Ethernet): All versions APOGEE PXC Modular (BACnet): All versions prior to v3.5 APOGEE PXC Modular (P2 Ethernet): All versions TALON TC Compact (BACnet): All versions prior to v3.5 TALON TC Modular (BACnet): All versions prior to v3.5 --------- End Update A Part 1 of 3 ---------.,"CVE-2017-9946, CVE-2017-9947",7.5,High,"CWE-288, CWE-22",Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 780,10/10/2017,10/10/2017,2017,ICSA-17-283-01,LAVA Computer MFG Inc. Ether-Serial Link,LAVA Computer MFG Inc.,Ether-Serial Link,The following versions of LAVA Computer MFG Inc.'s Ether-Serial Links (ESL) are affected: All ESLs running firmware versions 6.01.00/29.03.2007 and prior versions.,CVE-2017-14003,8.1,High,CWE-290,Commercial Facilities; Critical Manufacturing,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 779,10/10/2017,10/12/2017,2017,ICSA-17-283-02,JanTek JTC-200,JanTek,JTC-200,The following versions of JTC-200 - TCP/IP converter are affected: JTC-200 all versions.,"CVE-2016-5789, CVE-2016-5791",9.8,Critical,"CWE-352, CWE-287",Critical Manufacturing,"Taiwan, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 778,10/5/2017,10/10/2017,2017,ICSA-17-278-01,GE CIMPLICITY (Update A),GE,CIMPLICITY,The following versions of CIMPLICITY an HMI/SCADA management platform are affected: CIMPLICITY Versions 9.0 and prior. From CIMPLICITY 6.1 forward - users have been advised that S90 drivers were no longer supported and an alternate tool was provided. CIMPLICITY 9.5 removed the drivers from the product.,CVE-2017-12732,6.8,Medium,CWE-121,Chemical; Critical Manufacturing; Dams; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 777,10/5/2017,10/5/2017,2017,ICSA-17-278-02,Siemens 7KT PAC1200 Data Manager,Siemens,7KT PAC1200 Data Manager,Siemens reports that the vulnerability affects the following versions of the 7KT PAC1200 data manager (7KT1260) from the SENTRON portfolio: 7KT PAC1200 data manager: All versions prior to V2.03.,CVE-2017-9944,9.8,Critical,CWE-288,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 776,9/28/2017,2/27/2018,2017,ICSA-17-271-01,"Siemens Ruggedcom ROS, SCALANCE (Update B)",Siemens,"Ruggedcom ROS, SCALANCE",Siemens reports that the vulnerability affects the following devices using the Ruggedcom Discovery Protocol (RCDP): RUGGEDCOM ROS for RSL910 devices: All versions prior to ROS v5.0.1 | RUGGEDCOM ROS for all other devices: All versions prior to ROS v4.3.4 | SCALANCE XB-200/XC-200/XP-200/XR300-WG: All versions between v3.0 and v3.0.2 | SCALANCE XR-500/XM-400: All versions between v6.1 and 6.1.1.,CVE-2017-12736,8.8,High,CWE-284,Energy; Healthcare and Public Health; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 775,9/21/2017,9/21/2017,2017,ICSA-17-264-01,"Schneider Electric InduSoft Web Studio, InTouch Machine Edition",Schneider Electric,"InduSoft Web Studio, InTouch Machine Edition",Schneider Electric reports that the vulnerability affects the following InduSoft Web Studio products: InduSoft Web Studio v8.0 SP2 or prior and InTouch Machine Edition v8.0 SP2 or prior.,CVE-2017-13997,9.8,Critical,CWE-306,Critical Manufacturing; Energy; Healthcare and Public Health; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 774,9/21/2017,9/21/2017,2017,ICSA-17-264-02,"Ctek, Inc. SkyRouter","Ctek, Inc.",SkyRouter,The following versions of SkyRouter - wireless and automation solution are affected: SkyRouter Series 4200 and 4400 all versions prior to V6.00.11.,CVE-2017-14000,8.6,High,CWE-287,Commercial Facilities; Communications; Food and Agriculture; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 773,9/21/2017,9/21/2017,2017,ICSA-17-264-03,Digium Asterisk GUI,"Digium, Inc.",Asterisk GUI,The following versions of Asterisk GUI - framework for configuring graphical user interfaces are affected: Asterisk GUI 2.1.0 and prior.,CVE-2017-14001,8.8,High,CWE-78,Commercial Facilities; Communications; Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 772,9/21/2017,9/21/2017,2017,ICSA-17-264-04,iniNet Solutions GmbH SCADA Webserver,iniNet Solutions GmbH,SCADA Webserver,The following versions of iniNet Solutions GmbH's SCADA Webserver - third-party web-based server software are affected: iniNet Webserver all versions prior to V2.02.0100.,CVE-2017-13995,10.0,Critical,CWE-287,Critical Manufacturing,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 771,8/22/2017,8/22/2017,2017,ICSA-17-234-05,Saia Burgess Controls PCD Controllers,Saia Burgess Controls,PCD Controllers,ProductsSaia Burgess Controls reports that the vulnerability affects the following PCD Controllers: PCD firmware versions prior to 1.28.16 or 1.24.69.,CVE-2017-9628,5.3,Medium,CWE-200,Chemical; Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 770,9/19/2017,9/19/2017,2017,ICSA-17-262-01,PHOENIX CONTACT mGuard Device Manager,PHOENIX CONTACT,mGuard Device Manager,The following versions of mGuard Device Manager - device management software for mGuard devices are affected: mGuard Device Manager 1.8.0 and older.,"CVE-2017-10102, CVE-2017-10116, CVE-2017-10078, CVE-2017-10115, CVE-2017-10118, CVE-2017-10176, CVE-2017-10198, CVE-2017-10135, CVE-2017-10053, CVE-2017-10108",9.0,Critical,CWE-284,Communications; Critical Manufacturing; Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 769,9/14/2017,9/14/2017,2017,ICSA-17-257-01,LOYTEC LVIS-3ME,LOYTEC electronics GmbH,LVIS-3ME,The following versions of LVIS-3ME an HMI Touch Panel are affected: LVIS-3ME versions prior to 6.2.0.,"CVE-2017-13996, CVE-2017-13992, CVE-2017-13994, CVE-2017-13998",8.1,High,"CWE-79, CWE-331, CWE-522, CWE-23",Critical Manufacturing; Energy,Worldwide,Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 768,9/12/2017,9/12/2017,2017,ICSA-17-255-01,mySCADA myPRO,mySCADA Technologies,myPRO,The following versions of myPRO an HMI/SCADA management platform are affected: myPRO Versions 7.0.26 and prior.,CVE-2017-12730,7.8,High,CWE-428,Energy Food and Agriculture; Transportation Systems; Water and Wastewater,Worldwide,Czech Republic,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 767,9/12/2017,9/12/2017,2017,ICSMA-17-255-01,Philips' IntelliView MX40 Patient Worn Monitor (WLAN) Vulnerabilities,Philips,IntelliView MX40 Patient Worn Monitor (WLAN),The following versions of the IntelliVue MX40 Patient Worn Monitor are affected: IntelliVue MX40 Patient Worn Monitor (WLAN only) all versions prior to Version B.06.18. Vulnerabilities only affect MX40 WLAN monitors operating on a user-provided 802.11 wireless LAN. MX40 monitors with 1.4 GHz and 2.4 GHz Smart-Hopping radios are not affected.,"CVE-2017-9657, CVE-2017-9658",6.5,Medium,"CWE-460, CWE-755",Healthcare and Public Health,"Australia, Canada, Netherlands, United States, North America, South America, Asia, Europe, Africa, Middle East",Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 766,9/7/2017,9/7/2017,2017,ICSA-17-250-01,SpiderControl SCADA Web Server,SpiderControl,SCADA Web Server,The following versions of SCADA Web Server - software management platform are affected: SCADA Web Server Version 2.02.0007 and prior.,CVE-2017-12728,5.3,Medium,CWE-269,Critical Manufacturing,"Switzerland, Europe",Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 765,9/7/2017,9/7/2017,2017,ICSA-17-250-02,"PHOENIX CONTACT, Innominate Security Technologies mGuard Firmware","PHOENIX CONTACT, Innominate Security Technologies",mGuard Firmware,The following versions of mGuard firmware versions 8.0.0 to 8.5.1 - running on these mGuard Network Security Appliances are affected: FL MGUARD RS4000 TX/TX VPN | FL MGUARD GT/GT | FL MGUARD GT/GT VPN | FL MGUARD RS4000 TX/TX | FL MGUARD SMART2 VPN | FL MGUARD SMART2 | FL MGUARD RS2000 TX/TX VPN | FL MGUARD DELTA TX/TX | FL MGUARD DELTA TX/TX VPN | FL MGUARD PCI4000 | FL MGUARD PCI4000 VPN | FL MGUARD PCIE4000 VPN | FL MGUARD RS2005 TX VPN | FL MGUARD RS4004 TX/DTX | FL MGUARD RS4004 TX/DTX VPN | FL MGUARD RS4000 TX/TX-P | FL MGUARD RS4000 TX/TX VPN-M | FL MGUARD CENTERPORT | FL MGUARD RS | FL MGUARD RS VPN ANALOG | TC MGUARD RS2000 3G VPN | TC MGUARD RS4000 3G VPN | TC MGUARD RS2000 4G VPN and TC MGUARD RS4000 4G VPN.,CVE-2013-6466,7.5,High,CWE-476,Communications; Critical Manufacturing; Information Technology,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 764,9/7/2017,9/8/2017,2017,ICSMA-17-250-01,"i-SENS, Inc. SmartLog Diabetes Management Software",I-SENS Inc.,SmartLog Diabetes Management Software,The following SmartLog Diabetes Management Software versions are affected: SmartLog Diabetes Management Software | Version 2.4.0 and prior versions.,CVE-2017-13993,7.3,High,CWE-428,Healthcare and Public Health,"Chile, China, Germany, India, South Korea, Peru, United States",South Korea,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 763,9/7/2017,12/12/2017,2017,ICSMA-17-250-02,Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump Vulnerabilities (Update A),Smiths Medical,Medfusion 4000 Wireless Syringe Infusion Pump,The following Medfusion 4000 Wireless Syringe Infusion Pump versions are affected: Medfusion 4000 Wireless Syringe Infusion Pump | Version 1.1 | Medfusion 4000 Wireless Syringe Infusion Pump | Version 1.5 and Medfusion 4000 Wireless Syringe Infusion Pump | Version 1.6.,"CVE-2017-12718, CVE-2017-12722, CVE-2017-12725, CVE-2017-12720, CVE-2017-12724, CVE-2017-12726, CVE-2017-12721, CVE-2017-12723",7.0,High,"CWE-120, CWE-125, CWE-798, CWE-284, CWE-259, CWE-295, CWE-260",Healthcare and Public Health,"United Kingdom, United States",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 762,8/31/2017,9/11/2017,2017,ICSA-17-243-03,Siemens 7KM PAC Switched Ethernet,Siemens,7KM PAC Switched Ethernet,Siemens reports that the vulnerability affects the following 7KM PAC Switched Ethernet PROFINET expansion modules: 7KM PAC Switched Ethernet PROFINET expansion module: All versions prior to V2.1.3,CVE-2017-9945,4.3,Medium,CWE-400,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 761,8/31/2017,8/31/2017,2017,ICSA-17-243-04,OPW Fuel Management Systems SiteSentinel Integra and SiteSentinel iSite,OPW Fuel Management Systems,SiteSentinel Integra and SiteSentinel iSite,ProductsOPW Fuel Management Systems (OPW) reports that the vulnerabilities affect SiteSentinel Integra 100 | SiteSentinel Integra 500 and SiteSentinel iSite ATG consoles with the following software versions: Older than V175 | V175-V189 | V191-V195 and V16Q3.1.,"CVE-2017-12733, CVE-2017-12731",9.8,Critical,"CWE-89, CWE-306",Energy; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 760,8/31/2017,9/5/2017,2017,ICSA-17-243-05,Moxa SoftCMS Live Viewer,Moxa,SoftCMS Live Viewer,The following versions of SoftCMS Live Viewer - video surveillance software designed for industrial automation systems are affected: SoftCMS Live Viewer | Version 1.6 and prior versions.,CVE-2017-12729,9.8,Critical,CWE-89,Critical Manufacturing; Energy; Transportation,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 759,5/30/2017,5/30/2017,2017,ICSA-17-150-01,"Automated Logic Corporation ALC WebCTRL, Liebert SiteScan, Carrier i-VU",Automated Logic,"ALC WebCTRL, Liebert SiteScan, Carrier i-VU",The following ALC web-based building automation applications are affected: Liebert SiteScan Web Version 6.5 and prior; ALC WebCTRL Version 6.5 and prior; andCarrier i-Vu Version 6.5 and prior.,CVE-2016-5795,6.5,Medium,CWE-611,Commercial Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 758,8/29/2017,4/16/2018,2017,ICSMA-17-241-01,"Abbott Laboratories' Accent/Anthem, Accent MRI, Assurity/Allure, and Assurity MRI Pacemaker Vulnerabilities",Abbott Laboratories,"Accent/Anthem, Accent MRI, Assurity/Allure, and Assurity MRI Pacemaker","The following pacemakers manufactured prior to August 28, 2017, are affected:Accent/Anthem | Accent MRI | Assurity | Allure and Assurity MRI.","CVE-2017-12712, CVE-2017-12714, CVE-2017-12716",5.3,Medium,"CWE-287, CWE-920, CWE-311",Healthcare and Public Health,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 757,8/29/2017,8/29/2017,2017,ICSA-17-241-01,AzeoTech DAQFactory,AzeoTech,DAQFactory,AzeoTech reports that the vulnerabilities affect the following versions of DAQFactory HMI: DAQFactory versions prior to 17.1.,"CVE-2017-12699, CVE-2017-5147",7.1,High,"CWE-276, CWE-427",Energy,"United States, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 756,8/29/2017,8/29/2017,2017,ICSA-17-241-02,Advantech WebAccess,Advantech,WebAccess,The following versions of WebAccess an HMI platform are affected: WebAccess versions prior to V8.2_20170817.,"CVE-2017-12710, CVE-2017-12708, CVE-2017-12706, CVE-2017-12704, CVE-2017-12702, CVE-2017-12698, CVE-2017-12713, CVE-2017-12711, CVE-2017-12717",7.8,High,"CWE-89, CWE-119, CWE-121, CWE-122, CWE-134, CWE-287, CWE-732, CWE-266, CWE-427",Critical Manufacturing; Energy; Water and Wastewater,"Taiwan, United States, Asia, East Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 755,8/24/2017,8/28/2017,2017,ICSA-17-236-01,"Westermo MRD-305-DIN, MRD-315, MRD-355, and MRD-455",Westermo,"MRD-305-DIN, MRD-315, MRD-355, and MRD-455",The following Westermo router models and firmware versions are affected: MRD-305-DIN versions older than 1.7.5.0 and MRD-315 | MRD-355 | MRD-455 versions older than 1.7.5.0,"CVE-2017-12703, CVE-2017-12709, CVE-2016-5816",10.0,Critical,"CWE-352, CWE-798, CWE-321",Commercial Facilities; Critical Manufacturing; Energy,Worldwide,Sweden,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 754,7/27/2017,8/28/2017,2017,ICSA-17-208-04,Rockwell Automation Allen-Bradley Stratix and ArmorStratix,Rockwell Automation,Allen-Bradley Stratix and ArmorStratix,The following versions of Allen-Bradley Stratix and ArmorStratix switches are affected: All Versions 15.2(5)EA.fc4 and earlierAllen-Bradley Stratix 5400 Industrial Ethernet SwitchesAllen-Bradley Stratix 5410 Industrial Distribution SwitchesAllen-Bradley Stratix 5700 and ArmorStratixâžÂ¢ 5700 Industrial Managed Ethernet SwitchesAllen-Bradley Stratix 8000 Modular Managed Ethernet SwitchesAll Versions 15.6(3)M1 and earlierAllen-Bradley Stratix 5900 Services RouterAll Versions 15.2(4)EA and earlierStratix 8300 Modular Managed Ethernet Switches,"CVE-2017-6736, CVE-2017-6737, CVE-2017-6738, CVE-2017-6739, CVE-2017-6740, CVE-2017-6741, CVE-2017-6742, CVE-2017-6743, CVE-2017-6744",8.8,High,CWE-119,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 753,8/22/2017,8/22/2017,2017,ICSA-17-234-01,"Automated Logic Corporation WebCTRL, i-VU, SiteScan",Automated Logic,"WebCTRL, i-VU, SiteScan",The following versions of WebCTRL | i-Vu | SiteScan Web | building automation platforms are affected: ALC WebCTRL | i-Vu | SiteScan Web 6.5 and prior -LC WebCTRL | SiteScan Web 6.1 and prior -LC WebCTRL | i-Vu 6.0 and prior -LC WebCTRL | i-Vu | SiteScan Web 5.5 and prior and ALC WebCTRL | i-Vu | SiteScan Web 5.2 and prior.,"CVE-2017-9644, CVE-2017-9640, CVE-2017-9650",8.3,High,"CWE-22, CWE-428, CWE-434",Commercial Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 752,8/22/2017,8/22/2017,2017,ICSA-17-234-02,SpiderControl SCADA MicroBrowser,SpiderControl,SCADA MicroBrowser,The following versions of SCADA MicroBrowser - software management platform are affected: SCADA MicroBrowser Versions 1.6.30.144 and prior.,CVE-2017-12707,7.3,High,CWE-121,Critical Manufacturing,"Switzerland, Europe",Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 751,8/22/2017,8/22/2017,2017,ICSA-17-234-03,SpiderControl SCADA Web Server,SpiderControl,SCADA Web Server,The following versions of SpiderControl SCADA Web Server - software management platform are affected: SCADA Web Server,CVE-2017-12694,5.3,Medium,CWE-22,Critical Manufacturing,"Switzerland, Europe",Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 750,8/17/2017,8/17/2017,2017,ICSMA-17-229-01,Philips' DoseWise Portal Vulnerabilities,Philips,DoseWise Portal Vulnerabilities,The following Philips DWP versions are affected: DoseWise Portal | Versions 1.1.7.333 and 2.1.1.3069,"CVE-2017-9656, CVE-2017-9654",7.8,High,"CWE-312, CWE-798",Healthcare and Public Health,"Australia, Japan, Netherlands, United States, North America, South America, Asia, Europe, Africa, Middle East",Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 749,8/15/2017,8/15/2017,2017,ICSA-17-227-01,Advantech WebOP,Advantech,WebOP,Researchers report that all versions of Advantech WebOP operator panels are affected.,CVE-2017-12705,4.8,Medium,CWE-122,Critical Manufacturing,"Taiwan, North America, Asia, East Asia",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 748,8/15/2017,8/15/2017,2017,ICSMA-17-227-01,BMC Medical and 3B Medical Luna CPAP Machine,"BMC Medical, 3B Medical",Luna CPAP Machine,The following versions of the Luna CPAP Machine are affected: Luna CPAP Machine all devices released prior to July 1 | 2017.,CVE-2017-12701,4.6,Medium,CWE-20,Healthcare and Public Health,"China, United States",China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 747,8/15/2017,8/15/2017,2017,ICSMA-17-227-01,BMC Medical and 3B Medical Luna CPAP Machine,"BMC Medical, 3B Medical",Luna CPAP Machine,The following versions of the Luna CPAP Machine are affected: Luna CPAP Machine all devices released prior to July 1 | 2017.,CVE-2017-12701,4.6,Medium,CWE-20,Healthcare and Public Health,"China, United States",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 746,8/10/2017,8/10/2017,2017,ICSA-17-222-01,SIMPlight SCADA Software,SIMPlight,SCADA Software,The following versions of SIMPlight SCADA software | software for building management systems and automated facilities are affected: SCADA Software version 4.3.0.27 and prior.,CVE-2017-9661,7.0,High,CWE-427,Chemical; Commercial Facilities; Critical Manufacturing; Defense Industrial Base; Energy; Food and Agriculture; Government Facilities; Healthcare and Public Health; Nuclear Reactors Materials and Waste,Russia,Russia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 745,8/10/2017,8/10/2017,2017,ICSA-17-222-02,Solar Controls Heating Control Downloader (HCDownloader),Solar Controls,Heating Control Downloader (HCDownloader),The following versions of Solar Controls' Heating Control Downloader (HCDownloader) are affected: HCDownloader | Version 1.0.1.15 and prior.,CVE-2017-9646,7.8,High,CWE-427,Energy,Czech Republic,Czech Republic,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 744,8/10/2017,8/10/2017,2017,ICSA-17-222-03,Solar Controls WATTConfig M Software,Solar Controls,WATTConfig M Software,The following versions of Solar Controls' WATTConfig M Software for Windows 2.5.10 for M SSR/MAX PLCs are affected: WATTConfig M Software | Version 2.5.10.1 and prior.,CVE-2017-9648,7.8,High,CWE-427,Energy,Czech Republic,Czech Republic,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 743,8/10/2017,8/10/2017,2017,ICSA-17-222-04,Fuji Electric Monitouch V-SFT,Fuji Electric,Monitouch V-SFT,The following versions of Monitouch V-SFT - screen configuration software are affected: Monitouch V-SFT | versions prior to Version 5.4.43.0.,"CVE-2017-9659, CVE-2017-9660, CVE-2017-9662",7.3,High,"CWE-122, CWE-269, CWE-121",Critical Manufacturing; Energy,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 742,8/10/2017,8/10/2017,2017,ICSA-17-222-05,ABB SREA-01 and SREA-50,ABB,SREA-01 and SREA-50,ABB reports that the vulnerability affects the following SREA-01 and SREA-50 legacy remote monitoring tools and Ethernet adapters: SREA-01 revisions A | B | C: application versions up to 3.31.5 and SREA-50 revision A: application versions up to 3.32.8.,CVE-2017-9664,9.8,Critical,CWE-23,Critical Manufacturing; Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 741,8/8/2017,8/8/2017,2017,ICSA-17-220-01,OSIsoft PI Integrator,OSIsoft,PI Integrator,The following versions of PI Integrator - data management platform are affected: PI Integrator for SAP HANA 2016 | PI Integrator for Business Analytics 2016 - Data Warehouse (All Editions) | PI Integrator for Business Analytics 2016 - Business Intelligence (All Editions) | PI Integrator for Business Analytics and SAP HANA SQL Utility 2016 and PI Integrator for Microsoft Azure 2016.,"CVE-2017-9655, CVE-2017-9653",9.8,Critical,"CWE-285, CWE-79",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 740,8/8/2017,8/8/2017,2017,ICSA-17-220-02,Moxa SoftNVR-IA Live Viewer,Moxa,SoftNVR-IA Live Viewer,The following versions of SoftNVR-IA Live Viewer - video surveillance software designed for industrial automation systems are affected: SoftNVR-IA Live Viewer | Version 3.30.3122 and prior versions.,CVE-2017-5170,7.2,High,CWE-427,Critical Manufacturing; Energy; Transportation,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 739,8/3/2017,8/3/2017,2017,ICSA-17-215-01,Schneider Electric Pro-face GP-Pro EX,Schneider Electric,Pro-face GP-Pro EX,The following versions of Pro-face GP-Pro EX software an HMI management platform are affected: GP Pro EX version 4.07.000,CVE-2017-9961,7.2,High,CWE-427,Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 738,8/3/2017,8/3/2017,2017,ICSMA-17-215-01,Siemens Molecular Imaging Vulnerabilities,Siemens,Molecular Imaging,Siemens reports that the vulnerability affects the following products: Siemens PET/CT Systems: All Windows XP-based versions | Siemens SPECT/CT Systems: All Windows XP-based versions | Siemens SPECT Systems: All Windows XP-based versions and Siemens SPECT Workplaces/Symbia.net: All Windows XP-based versions.,"CVE-2008-4250, CVE-2017-7269",9.8,Critical,"CWE-94, CWE-119",Healthcare and Public Health,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 737,8/3/2017,8/9/2017,2017,ICSMA-17-215-02,Siemens Molecular Imaging Vulnerabilities,Siemens,Molecular Imaging,Siemens reports that the vulnerabilities affect the following products: Siemens PET/CT Systems: All Windows 7-based versions | Siemens SPECT/CT Systems: All Windows 7-based versions | Siemens SPECT Systems: All Windows 7-based versions and Siemens SPECT Workplaces/Symbia.net: All Windows 7-based versions.,"CVE-2015-1635, CVE-2015-1497, CVE-2015-7860, CVE-2015-7861",9.8,Critical,"CWE-94, CWE-119, CWE-264",Healthcare and Public Health,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 736,8/1/2017,8/1/2017,2017,ICSA-17-213-01,Mitsubishi Electric Europe B.V. E-Designer,Mitsubishi Electric Europe B.V.,E-Designer,The following version of E-Designer - Mitsubishi Electric Europe B.V. product to program HMIs for E1000 products is affected: E-Designer | Version 7.52 Build 344.,"CVE-2017-9638, CVE-2017-9636, CVE-2017-9634",9.8,Critical,"CWE-122, CWE-787, CWE-121",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 735,8/1/2017,8/1/2017,2017,ICSA-17-213-02,Schneider Electric Trio TView,Schneider Electric,Trio TView,The following versions of Schneider Electric Trio TView - management and diagnostics software are affected: Trio TView Software | TBUMPROG-TVIEW | Version 3.27.0 and prior.,CVE-NA,10.0,Critical,CWE-NA,Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 734,7/27/2017,7/27/2017,2017,ICSA-17-208-01,Continental AG Infineon S-Gold 2 (PMB 8876),Continental AG,Infineon S-Gold 2 (PMB 8876),All telematics control modules (TCUs) built by Continental AG that contain the S-Gold 2 (PMB 8876) cellular baseband chipset are affected. The S-Gold 2 (PMB 8876) is found in the following vehicles: BMW several models produced between 2009-2010 Ford - program to update 2G modems has been active since 2016 and impact is restricted to the limited number of P-HEV vehicles equipped with this older technology that remain in service.Infiniti 2013 JX35 Infiniti 2014-2016 QX60 Infiniti 2014-2016 QX60 Hybrid Infiniti 2014-2015 QX50 Infiniti 2014-2015 QX50 Hybrid Infiniti 2013 M37/M56 Infiniti 2014-2016 Q70 Infiniti 2014-2016 Q70L Infiniti 2015-2016 Q70 Hybrid Infiniti 2013 QX56 Infiniti 2014-2016 QX 80 Nissan 2011-2015 Leaf.,"CVE-2017-9647, CVE-2017-9633",8.8,High,"CWE-119, CWE-121",Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 733,7/27/2017,7/27/2017,2017,ICSA-17-208-02,Mirion Technologies Telemetry Enabled Devices,Mirion Technologies,Telemetry Enabled Devices,The following telemetry enabled devices are affected: DMC 3000 Transmitter Module | iPam Transmitter f/DMC 2000 | RDS-31 iTX and variants (incl. RSD31-AM Package) | DRM-1/2 and variants (incl. Solar PWR Package) | DRM and RDS Based Boundary Monitors | External Transmitters | Telepole II and MESH Repeater.,"CVE-2017-9649, CVE-2017-9645",5.0,Medium,"CWE-326, CWE-321","Nuclear Reactors, Materials, and Waste","United States, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 732,7/27/2017,7/27/2017,2017,ICSA-17-208-03,"PDQ Manufacturing, Inc. LaserWash, Laser Jet and ProTouch","PDQ Manufacturing, Inc.","LaserWash, Laser Jet and ProTouch",The following versions of LaserWash | Laser Jet and ProTouch | in-bay automatic car wash systems are affected: LaserWash G5 and G5 S Series all versions | LaserWash M5 all versions | LaserWash 360 and 360 Plus all versions | LaserWash AutoXpress and AutoExpress Plus all versions | LaserJet all versions | ProTouch Tandem all versions | ProTouch ICON all versions and ProTouch AutoGloss all versions.,"CVE-2017-9630, CVE-2017-9632",9.4,Critical,"CWE-287, CWE-311",Commercial Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 731,6/1/2017,6/1/2017,2017,ICSA-17-152-02,NXP i.MX Product Family,NXP Semiconductors,i.MX Product Family,The following i.MX Devices - used on logic boards are affected: Devices affected by the Stack Buffer Overflow vulnerability: i.MX 50 | i.MX 53 | i.MX 6ULL | i.MX 6UltraLite | i.MX 6SoloLite | i.MX 6Solo | i.MX 6DualLite | i.MX 6SoloX | i.MX 6Dual | i.MX 6Quad | i.MX 6DualPlus | i.MX 6QuadPlus | Vybrid VF3xx | Vybrid VF5xx and Vybrid VF6xxDevices Affected by the Improper Certificate Validation Vulnerability: i.MX 28i.MX 50 | i.MX 53 | i.MX 7Soloi.MX 7DualVybrid VF3xx | Vybrid VF5xx | Vybrid VF6xx | i.MX 6ULL | i.MX 6UltraLite | i.MX 6SoloLite | i.MX 6Solo | i.MX 6DualLite | i.MX 6SoloX | i.MX 6Dual | i.MX 6Quad | i.MX 6DualPlus and i.MX 6QuadPlus,"CVE-2017-7936, CVE-2017-7932",6.0,Medium,"CWE-295, CWE-121",Critical Manufacturing; Transportation Systems,Worldwide,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 730,7/20/2017,7/20/2017,2017,ICSA-17-201-01,Schneider Electric PowerSCADA Anywhere and Citect Anywhere,Schneider Electric,PowerSCADA Anywhere and Citect Anywhere,Schneider Electric reports that the vulnerabilities affect the following versions of PowerSCADA Anywhere and Citect Anywhere mobile extensions: Version 1.0 of PowerSCADA Anywhere redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 | Citect Anywhere version 1.0,"CVE-2017-7969, CVE-2017-7970, CVE-2017-7971, CVE-2017-7972",8.1,High,"CWE-352, CWE-200, CWE-146, CWE-298",Commercial Facilities,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 729,5/18/2017,5/18/2017,2017,ICSA-17-138-03,Rockwell Automation MicroLogix 1100 Controllers,Rockwell Automation,MicroLogix 1100 Controllers,The following versions of MicroLogix 1100 controllers are affected: 1763-L16BWA | 1763-L16AWA | 1763-L16BBB and 1763-L16DWD.,CVE-2017-7924,7.5,High,CWE-20,Critical Manufacturing; Food and Agriculture; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 728,7/13/2017,7/13/2017,2017,ICSA-17-194-01,Siemens SiPass integrated,Siemens,SiPass integrated,Siemens reports that the vulnerabilities affect the following SiPass integrated access control system: SiPass integrated: All versions prior to V2.70.,"CVE-2017-9939, CVE-2017-9940, CVE-2017-9941, CVE-2017-9942",9.8,Critical,"CWE-300, CWE-287, CWE-269, CWE-257",Energy; Healthcare and Public Health; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 727,7/13/2017,7/13/2017,2017,ICSA-17-194-03,Siemens SIMATIC Sm@rtClient Android App,Siemens,SIMATIC Sm@rtClient Android App,Siemens reports that the vulnerabilities affect the following SIMATIC Sm@rtClient Android apps for remote operation and monitoring of SIMATIC HMI systems: SIMATIC WinCC Sm@rtClient for Android: All versions prior to V1.0.2.2 | SIMATIC WinCC Sm@rtClient Lite for Android: All versions prior to V1.0.2.2.,"CVE-2017-6870, CVE-2017-6871",7.4,High,"CWE-288, CWE-300",Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 726,7/11/2017,7/11/2017,2017,ICSA-17-192-01,Siemens SIMATIC Logon,Siemens,SIMATIC Logon,Siemens reports that the vulnerability affects the following SIMATIC Logon products: SIMATIC Logon: All versions prior to V1.6.,CVE-2017-9938,5.3,Medium,CWE-787,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 725,7/11/2017,7/11/2017,2017,ICSA-17-192-02,Fuji Electric V-Server,Fuji Electric,V-Server,The following versions of V-Server - data collection and management service are affected: V-Server Version 3.3.22.0 and prior.,CVE-2017-9639,7.3,High,CWE-119,Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 724,7/11/2017,7/18/2017,2017,ICSA-17-192-03,ABB VSN300 WiFi Logger Card,ABB,VSN300 WiFi Logger Card,The following versions of VSN300 WiFi Logger Card - device for solar system monitoring are affected: VSN300 WiFi Logger Card versions 1.8.15 and prior. VSN300 WiFi Logger Card for React versions 2.1.3 and prior.,"CVE-2017-7920, CVE-2017-7916",7.5,High,"CWE-287, CWE-264",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 723,7/11/2017,7/11/2017,2017,ICSA-17-192-04,OSIsoft PI Coresight,OSIsoft,PI Coresight,OSIsoft reports that the vulnerability affects the following PI Coresight products: PI Coresight 2016 R2 and earlier versions.,CVE-2017-9641,7.1,High,CWE-352,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 722,7/11/2017,7/11/2017,2017,ICSA-17-192-05,OSIsoft PI ProcessBook and PI ActiveView,OSIsoft,PI ProcessBook and PI ActiveView,OSIsoft reports that the vulnerability affects the following PI products: PI ProcessBook 2015 R2 (3.6.0) and earlier and PI ActiveView 2015 R2 (3.6.0) and earlier.,CVE-NA,9.9,Critical,CWE-NA,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 721,7/11/2017,3/14/2018,2017,ICSA-17-192-06,"Schweitzer Engineering Laboratories, Inc. SEL-3620 and SEL-3622",Schweitzer Engineering Laboratories,SEL-3620 and SEL-3622,The following versions of SEL-3620 and SEL-3622 an Ethernet Security Gateway are affected: Security Gateway Versions R202 and | R203 | R203-V1 | R203-V2 and | R204 | R204-V1.,CVE-2017-7928,7.2,High,CWE-284,Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 720,7/6/2017,7/6/2017,2017,ICSA-17-187-01,Siemens OZW672 and OZW772,Siemens,OZW672 and OZW772,Siemens reports that the vulnerability affects the following OZW672 and OZW772 devices for monitoring building controller devices: OZW672: All versions and OZW772: All versions.,"CVE-2017-6872, CVE-2017-6873",7.4,High,CWE-306,Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 719,7/6/2017,7/6/2017,2017,ICSA-17-187-02,Siemens Reyrolle,Siemens,Reyrolle,Siemens reports that the vulnerabilities affect the following Reyrolle integration | control | measurement and automation products: EN100 Ethernet modules as optional for Reyrolle: All versions prior to V4.29.01.,"CVE-2016-4784, CVE-2016-4785, CVE-2016-7112, CVE-2016-7113, CVE-2016-7114",7.5,High,"CWE-287, CWE-20, CWE-862",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 718,7/6/2017,3/20/2018,2017,ICSA-17-187-03F,Siemens SIPROTEC 4 and SIPROTEC Compact (Update F),Siemens,SIPROTEC 4 and SIPROTEC Compact,Siemens reports that the vulnerabilities affect the following SIPROTEC 4 and SIPROTEC Compact protection | control | measurement and automation devices: Firmware variants for EN100 Ethernet modules as options for SIPROTEC 4 and SIPROTEC Compact: Firmware variant PROFINET IO: All versions prior to V1.04.01 | Firmware variant Modbus TCP: All versions prior to V1.11.00 | Firmware variant DNP3 TCP: All versions prior to V1.03 and Firmware variant IEC 104: All versions prior to V1.21EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80: All firmware versions prior to V1.02.02SIPROTEC 7SJ686: All versions prior to V4.87 | SIPROTEC 7UT686: All versions prior to V4.02 | SIPROTEC 7SD686: All versions prior V4.05 | SIPROTEC 7SJ66: All versions prior to V4.30Please note that not all of the devices above are affected by all of these vulnerabilities. Please see Siemens Security Advisory SSA-323211 for more detailed information.,"CVE-2015-5374, CVE-2016-4784, CVE-2016-4785, CVE-2016-7112, CVE-2016-7113, CVE-2016-7114",8.6,High,"CWE-287, CWE-20, CWE-862",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 717,7/6/2017,7/6/2017,2017,ICSA-17-187-04,Schneider Electric Wonderware ArchestrA Logger,Schneider Electric,Wonderware ArchestrA Logger,Schneider Electric reports that the following versions of Wonderware ArchestrA Logger - logging software are affected: Wonderware ArchestrA Logger | versions 2017.426.2307.1 and prior.,"CVE-2017-9629, CVE-2017-9627, CVE-2017-9631",9.8,Critical,"CWE-476, CWE-121, CWE-400",Critical Manufacturing; Dams; Defense Industrial Base; Energy; Food and Agriculture;Government Facilities; Nuclear Reactors Materials and Waste; Transportation Systems; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 716,7/6/2017,7/6/2017,2017,ICSA-17-187-05,Schneider Electric Ampla MES,Schneider Electric,Ampla MES,Schneider Electric reports that the vulnerability affects the following Ampla Manufacturing Execution System (MES) operational efficiency products: Ampla MES versions 6.4 and prior.,"CVE-2017-9637, CVE-2017-9635",6.7,Medium,"CWE-319, CWE-326",Critical Manufacturing; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 715,6/29/2017,7/11/2017,2017,ICSA-17-180-01,"Siemens SIMATIC Industrial PCs, SINUMERIK Panel Control Unit, and SIMOTION P320 (Update A)",Siemens,"SIMATIC Industrial PCs, SINUMERIK Panel Control Unit, and SIMOTION P320",Siemens reports that the vulnerability affects Siemens Industrial products which use Intel processors (Intel Core i5 | Intel Core i7 and Intel XEON): SIMATIC Industrial PCs | SINUMERIK Panel Control Unit (PCU) | SIMOTION P320. Please see Siemens Security Advisory SSA-874235 for the full list of affected versions.,CVE-2017-5689,9.8,Critical,CWE-264,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 714,6/29/2017,1/8/2019,2017,ICSA-17-180-02,Schneider Electric U.motion Builder (Update A),Schneider Electric,U.motion Builder,The following U.motion Builder Software versions are affected: U.motion Builder Versions 1.2.1 and prior.,"CVE-2017-7973, CVE-2017-7974, CVE-2017-9956, CVE-2017-9957, CVE-2017-9958, CVE-2017-9959, CVE-2017-9960",10.0,Critical,"CWE-89, CWE-22, CWE-287, CWE-259, CWE-284, CWE-730, CWE-209, CWE-20, CWE-94",Commercial Facilities; Critical Manufacturing; Energy,"France, United States, Asia, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 713,6/29/2017,6/29/2017,2017,ICSA-17-180-03,Siemens Viewport for Web Office Portal,Siemens,Viewport for Web Office Portal,Siemens reports that the vulnerability affects the following ViewPort for Web Office Portal products: ViewPort for Web Office Portal: versions prior to revision number 1453.,CVE-2017-6869,9.8,Critical,CWE-287,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 712,6/27/2017,6/27/2017,2017,ICSA-17-178-01,"Newport XPS-Cx, XPS-Qx",Newport,"XPS-Cx, XPS-Qx",The following versions of XPS-Cx and XPS-Qx - universal motion controller are affected: XPS-Cx all versions and XPS-Qx all versions.,CVE-2017-7919,7.5,High,CWE-287,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 711,6/22/2017,6/22/2017,2017,ICSA-17-173-01,Siemens SIMATIC CP 44x-1 Redundant Network Access Modules,Siemens,SIMATIC CP 44x-1 Redundant Network Access Modules,The following versions of the SIMATIC CP 44x-1 RNA which connect SIMATIC S7-400 CPUs to Industrial Ethernet are affected: SIMATIC CP 44x-1 RNA all versions prior to Versions 1.4.1.,CVE-2017-6868,9.8,Critical,CWE-287,Chemical; Critical Manufacturing; Food and Agriculture,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 710,6/22/2017,6/22/2017,2017,ICSA-17-173-02,Siemens XHQ,Siemens,XHQ,Siemens reports that the vulnerability affects the following versions of the XHQ operations intelligence product line: XHQ 4: All versions prior to V4.7.1.3XHQ 5: All versions prior to V5.0.0.2,CVE-2017-6866,6.5,Medium,CWE-284,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 709,6/20/2017,6/20/2017,2017,ICSA-17-171-01,Ecava IntegraXor,Ecava,IntegraXor,The following versions of IntegraXor - web SCADA/HMI solution are affected: IntegraXor Versions 5.2.1231.0 and prior.,CVE-2017-6050,7.3,High,CWE-89,Critical Manufacturing; Energy; Water and Wastewater,"Australia, Canada, Estonia, United Kingdom, Malaysia, Poland, United States",Malaysia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 708,6/15/2017,6/15/2017,2017,ICSA-17-166-01,Cambium Networks ePMP,Cambium Networks,ePMP,Cambium reports that the vulnerabilities affect the following ePMP Network Access Control products: ePMP All Models.,"CVE-2017-7918, CVE-2017-7922",7.6,High,"CWE-284, CWE-269",Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 707,6/13/2017,10/31/2017,2017,ICSA-17-164-01,Trihedral Engineering Limited VTScada,Trihedral Engineering Limited,VTScada,The following versions of VTScada an HMI SCADA software are affected: VTScada Versions prior to 11.2.26,"CVE-2017-6043, CVE-2017-6053, CVE-2017-6045",7.5,High,"CWE-548, CWE-79, CWE-400",Chemical; Communications; Critical Manufacturing; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,"Canada, North America, Europe",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 706,6/13/2017,6/13/2017,2017,ICSA-17-164-02,OSIsoft PI Server 2017,OSIsoft,PI Server 2017,OSIsoft reports that the vulnerabilities affect the following PI Server products: PI Data Archive versions prior to 2017.,"CVE-2017-7930, CVE-2017-7934",8.9,High,CWE-287,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 705,6/13/2017,6/13/2017,2017,ICSA-17-164-03,OSIsoft PI Web API 2017,OSIsoft,PI Web API 2017,OSIsoft reports that the vulnerability affects the following PI Web API products: PI Web API versions prior to 2017 (1.9.0).,CVE-2017-7926,7.1,High,CWE-352,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 704,6/6/2017,6/6/2017,2017,ICSA-17-157-01,Rockwell Automation PanelView Plus 6 700-1500,Rockwell Automation,PanelView Plus 6 700-1500,The following versions of PanelView Plus 6 700-1500 - graphic terminals and logic module products are affected: 6.00.04 | 6.00.05 | 6.00.42 | 6.00-20140306 | 6.10.20121012 | 6.10-20140122 | 7.00-20121012 | 7.00-20130108 | 7.00-20130325 | 7.00-20130619 | 7.00-20140128 | 7.00-20140310 | 7.00-20140429 | 7.00-20140621 | 7.00-20140729 | 7.00-20141022 | 8.00-20140730 and 8.00-20141023Additionally | Rockwell Automation reports that graphic terminals running OS 2.31 or greater are not affected by this vulnerability.,CVE-2017-7914,8.6,High,CWE-862,Critical Manufacturing; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 703,6/6/2017,6/13/2017,2017,ICSA-17-157-02,Digital Canal Structural Wind Analysis,Digital Canal Structural,Wind Analysis,The following versions of Wind Analysis - structural engineering software platform are affected: Wind Analysis versions 9.1 and prior.,CVE-2017-7910,7.5,High,CWE-121,Commercial Facilities,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 702,6/1/2017,6/1/2017,2017,ICSA-17-152-01,Phoenix Broadband Technologies LLC PowerAgent SC3 Site Controller,Phoenix Broadband Technologies LLC,PowerAgent SC3 Site Controller,Phoenix Broadband Technologies LLC reports that the following versions of PowerAgent SC3 - remote battery monitoring system (BMS) are affected: PowerAgent SC3 BMS all versions prior to v6.87,CVE-2017-6039,5.3,Medium,CWE-259,Communications; Energy; Government Facilities; Information Technology; Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 701,5/23/2017,5/23/2017,2017,ICSA-17-143-01,Moxa OnCell,Moxa,OnCell,The following versions of OnCell - high-speed industrial-grade IP gateway are affected: OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions | OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions | OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions | OnCell 5104-HSDPA | OnCell 5104-HSPA and OnCell 5004-HSPA.,"CVE-2017-7915, CVE-2017-7913, CVE-2017-7917",9.8,Critical,"CWE-352, CWE-307, CWE-256",Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 700,4/25/2017,4/25/2017,2017,ICSA-17-115-04,Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400,Rockwell Automation,Allen-Bradley MicroLogix 1100 and 1400,The following versions of the Allen-Bradley MicroLogix 1100 programmable-logic controller are affected: 1763-L16AWA | Series A and B | Version 16.00 and prior versions;1763-L16BBB | Series A and B | Version 16.00 and prior versions;1763-L16BWA | Series A and B | Version 16.00 and prior versions; and1763-L16DWD | Series A and B | Version 16.00 and prior versions.The following versions of the Allen-Bradley MicroLogix 1400 programmable logic controller are affected: 1766-L32AWA | Series A and B | Version 16.00 and prior versions;1766-L32BWA | Series A and B | Version 16.00 and prior versions;1766-L32BWAA | Series A and B | Version 16.00 and prior versions;1766-L32BXB | Series A and B | Version 16.00 and prior versions;1766-L32BXBA | Series A and B | Version 16.00 and prior versions; and1766-L32AWAA | Series A and B | Version 16.00 and prior versions.,"CVE-2017-7901, CVE-2017-7902, CVE-2017-7899, CVE-2017-7898, CVE-2017-7903",9.8,Critical,"CWE-200, CWE-307, CWE-343, CWE-323, CWE-521",Food and Agriculture; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 699,3/23/2017,10/22/2020,2017,ICSMA-17-082-02,B. Braun Medical SpaceCom Open Redirect Vulnerability,B. Braun Medical Inc.,SpaceCom,The following versions of the SpaceCom module - used with the SpaceStation docking station are affected: SpaceStation with SpaceCom module (integrated as part number 8713142U) | software versions prior to Version 012U000040 and SpaceStation (part number 8713140U) with installed SpaceCom module (part number 8713160U) | software versions prior to Version 012U000040.,CVE-2017-6018,5.4,Medium,CWE-601,Healthcare and Public Health,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 698,5/18/2017,5/18/2017,2017,ICSA-17-138-01,Miele Professional PG 85 Series,Miele Professional,PG 85 Series,Miele Professional reports that the following versions of the PG 85 product series - large capacity cleaner and disinfector and their embedded webservers are affected: PG8527 | version 2.02 | 2.51 | 2.52 and 2.54PG8528 | version 2.02 | 2.51 | 2.52 and 2.54PG8535 | version 1.00 and 1.04PG8536 | version 1.10 and 1.14,CVE-2017-7240,7.3,High,CWE-22,Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 697,5/18/2017,5/18/2017,2017,ICSA-17-138-02,Schneider Electric Wonderware InduSoft Web Studio,Schneider Electric,Wonderware InduSoft Web Studio,The following versions of Schneider Electric's Wondeware InduSoft Web Studio are affected: Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions.,CVE-2017-7968,7.3,High,CWE-276,Critical Manufacturing; Energy; Healthcare and Public Health; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 696,5/16/2017,5/16/2017,2017,ICSA-17-136-01,Detcon SiteWatch Gateway,Detcon,SiteWatch Gateway,The following versions of Detcon SiteWatch Gateway - Ethernet Notification System are affected: All SiteWatch Gateway versions are affected.Detcon reports Cellular versions not impacted.,"CVE-2017-6049, CVE-2017-6047",9.1,Critical,"CWE-287, CWE-256",Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,"United States, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 695,5/16/2017,5/16/2017,2017,ICSA-17-136-02,Schneider Electric SoMachine HVAC,Schneider Electric,SoMachine HVAC,The following version of SoMachine HVAC - PLC programming software is affected: SoMachine HVAC Versions 2.1.0 and prior.,"CVE-2017-7965, CVE-2017-7966",7.8,High,"CWE-121, CWE-427",Critical Manufacturing; Dams; Defense Industrial Base; Energy; Food and Agriculture; Government Facilities; Nuclear Reactors Materials and Waste; Transportation Systems; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 694,5/16/2017,5/16/2017,2017,ICSA-17-136-03,Hanwha Techwin SRN-4000,Hanwha Techwin,SRN-4000,The following versions of SRN-4000 - network video management platform are affected: SRN-4000 firmware versions prior to SRN4000_v2.16_170401.,CVE-2017-7912,9.8,Critical,CWE-284,Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,Worldwide,South Korea,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 693,5/16/2017,5/16/2017,2017,ICSA-17-136-04,Schneider Electric VAMPSET,Schneider Electric,VAMPSET,Schneider Electric reports that the vulnerability affects the following VAMPSET setting and configuration software products: VAMPSET | versions prior to v2.2.189.,CVE-2017-7967,5.6,Medium,CWE-20,Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 692,5/11/2017,9/19/2017,2017,ICSA-17-131-01,PHOENIX CONTACT mGuard,PHOENIX CONTACT,mGuard,The following versions of mGuard - network device are affected: mGuard firmware versions 8.3.0 to 8.4.2,"CVE-2017-7935, CVE-2017-7937",8.6,High,"CWE-287, CWE-400",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 691,5/11/2017,5/11/2017,2017,ICSA-17-131-02,Satel Iberia SenNet Data Logger and Electricity Meters,Satel Iberia,SenNet Data Logger and Electricity Meters,The following versions of SenNet Data Logger and Electricity Meters - monitoring platforms are affected: SenNet Optimal DataLogger V5.37c-1.43c and prior | SenNet Solar Datalogger V5.03-1.56a and prior and SenNet Multitask Meter V5.21a-1.18b and prior.,CVE-2017-6048,8.8,High,CWE-77,Critical Manufacturing; Energy; Transportation,"Spain, Europe",Spain,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 690,5/9/2017,2/14/2019,2017,ICSA-17-129-01,Siemens devices using the PROFINET Discovery and Configuration Protocol (Update K),Siemens,devices using the PROFINET Discovery and Configuration Protocol,Siemens reports that the vulnerability affects the following products using the PROFINET DCP: SIMATIC WinCC (TIA Portal) v13: All versions prior to v13 SP2 and v14: All versions prior to v14 SP1 | SIMATIC STEP 7 (TIA Portal) v13: All versions prior to v13 SP2 and v14: All versions prior to v14 SP1 | SIMATIC STEP 7 v5.X: All versions prior to v5.6STEP 7 - Micro/WIN SMART: All versions prior to v2.3SMART PC Access v2.3 | SIMATIC Automation Tool: All versions prior to v3.0 | SIMATIC WinCCv7.2 and prior: All versionsv7.3: All versions prior to v7.3 Update 15v7.4: All versions prior to v7.4 SP1 Upd1 | SIMATIC PCS 7 v8.1: All versions | SIMATIC PCS 7 v8.2: All versions prior to v8.2 SP1 | SIMATIC NET PC-Software: All versions prior to v14 SP1 | Primary Setup Tool (PST): All versions prior to v4.2 HF1Security Configuration Tool (SCT): All versions prior to v5.0SINEMA Server: All versions prior to v14. SINAUT ST7CC: All versions installed in conjunction with SIMATIC WinCC prior to v7.3 Update 15. SINAUT ST7CC: All versions | SIMATIC WinAC RTX 2010 SP2: All versions | SIMATIC WinAC RTX F 2010 SP2: All versions | SINUMERIK 808D Programming Tool: All versions prior to v4.7 SP4 HF2 and SIMATIC WinCC flexible 2008: All versions prior to flexible 2008 SP5.,CVE-2017-6865,6.5,Medium,CWE-20,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 689,5/9/2017,5/9/2017,2017,ICSA-17-129-03,Siemens SIMATIC WinCC and SIMATIC WinCC Runtime Professional,Siemens,SIMATIC WinCC and SIMATIC WinCC Runtime Professional,Siemens reports that the vulnerability affects the following versions of SIMATIC WinCC | SIMATIC WinCC (TIA Portal) and SIMATIC WinCC Runtime Professional: SIMATIC WinCC: V7.3: All versions prior to V7.3 Update 11 and V7.4: All versions prior to V7.4 SP1.SIMATIC WinCC Runtime Professional: V13: All versions prior to V13 SP2 and V14: All versions prior to V14 SP1.SIMATIC WinCC (TIA Portal) Professional: V13: All versions prior to V13 SP2 and V14: All versions prior to V14 SP1.,CVE-2017-6867,4.9,Medium,CWE-20,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 688,4/4/2017,5/10/2017,2017,ICSA-17-094-04,Rockwell Automation Stratix 5900,Rockwell Automation,Stratix 5900,Rockwell Automation reports that these vulnerabilities affect the following Stratix 5900 Services Routers: Stratix 5900 all Versions prior to 15.6.3.,"CVE-2016-6380, CVE-2016-6393, CVE-2016-6384, CVE-2016-6381, CVE-2016-6382, CVE-2016-6415, CVE-2016-1409, CVE-2016-1350, CVE-2016-1344, CVE-2015-7691, CVE-2015-7692, CVE-2015-7701, CVE-2015-7702, CVE-2015-7703, CVE-2015-7704, CVE-2015-7705, CVE-2015-7848, CVE-2015-7849, CVE-2015-7850, CVE-2015-7851, CVE-2015-7852, CVE-2015-7853, CVE-2015-7854, CVE-2015-7855, CVE-2015-7871, CVE-2015-1798, CVE-2015-1799, CVE-2015-0642, CVE-2015-0643, CVE-2015-0646, CVE-2015-0207, CVE-2015-0209, CVE-2015-0285, CVE-2015-0287, CVE-2015-0288, CVE-2015-0289, CVE-2015-0290, CVE-2015-0291, CVE-2015-0292, CVE-2015-0293, CVE-2015-1787, CVE-2014-3566, CVE-2014-3359, CVE-2014-3355, CVE-2014-3361, CVE-2014-3354, CVE-2014-3360, CVE-2014-3299, CVE-2010-5298, CVE-2014-0076, CVE-2014-0195, CVE-2014-0198, CVE-2014-0221, CVE-2014-0224, CVE-2014-3470, CVE-2014-2113, CVE-2014-2108, CVE-2014-2109, CVE-2014-2111, CVE-2014-2106, CVE-2014-2112",10.0,Critical,"CWE-20, CWE-399, CWE-200, CWE-190, CWE-119, CWE-22, CWE-264, CWE-287, CWE-310, CWE-189, CWE-362, CWE-476",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 687,5/4/2017,5/4/2017,2017,ICSA-17-124-01,Hikvision Cameras,Hikvision,Cameras,Hikvision reports that the following cameras and versions are affected: DS-2CD2xx2F-I SeriesV5.2.0 build 140721 to V5.4.0 build 160530DS-2CD2xx0F-I SeriesV5.2.0 build 140721 to V5.4.0 Build 160401DS-2CD2xx2FWD SeriesV5.3.1 build 150410 to V5.4.4 Build 161125DS- 2CD4x2xFWD SeriesV5.2.0 build 140721 to V5.4.0 Build 160414DS-2CD4xx5 SeriesV5.2.0 build 140721 to V5.4.0 Build 160421DS-2DFx SeriesV5.2.0 build 140805 to V5.4.5 Build 160928DS-2CD63xx SeriesV5.0.9 build 140305 to V5.3.5 Build 160106.,"CVE-2017-7921, CVE-2017-7923",10.0,Critical,"CWE-287, CWE-260",Critical Manufacturing,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 686,5/4/2017,5/4/2017,2017,ICSA-17-124-02,"Dahua Technology Co., Ltd Digital Video Recorders and IP Cameras","Dahua Technology Co., Ltd",Digital Video Recorders and IP Cameras,The following Dahua Technology Co. Ltd (Dahua) network cameras are affected: DH-IPC-HDBW23A0RN-ZS | DH-IPC-HDBW13A0SN | DH-IPC-HDW1XXX | DH-IPC-HDW2XXX | DH-IPC-HDW4XXX | DH-IPC-HFW1XXX | DH-IPC-HFW2XXX | DH-IPC-HFW4XXX | DH-SD6CXX | DHanVR1XXX | DH-HCVR4XXX and DH-HCVR5XXX.The following Dahua Digital Video Recorders (DVRs) are affected: DHI-HCVR51A04HE-S3 | DHI-HCVR51A08HE-S3 and DHI-HCVR58A32S-S2.,"CVE-2017-7927, CVE-2017-7925",9.8,Critical,"CWE-260, CWE-836",Commercial Facilities; Critical Manufacturing; Financial Services; Government Facilities; Transportation Systems,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 685,5/4/2017,5/4/2017,2017,ICSA-17-124-03,Advantech WebAccess,Advantech,WebAccess,The following WebAccess versions are affected: WebAccess Version 8.1 and prior.,CVE-2017-7929,7.1,High,CWE-36,Critical Manufacturing,"Taiwan, United States, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 684,4/4/2017,4/4/2017,2017,ICSA-17-094-05,Rockwell Automation ControlLogix 5580 and CompactLogix 5380,Rockwell Automation,ControlLogix 5580 and CompactLogix 5380,The following versions of ControlLogix 5580 and CompactLogix 5380 - programmable automation controllers are affected: ControlLogix 5580 controllers V28.011 | V28.012 and V28.013 | ControlLogix 5580 controllers V29.011 | CompactLogix 5380 controllers V28.011 and CompactLogix 5380 controllers V29.011.,CVE-2017-6024,6.8,Medium,CWE-400,Critical Manufacturing; Food and Agriculture; Transportation,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 683,5/2/2017,5/2/2017,2017,ICSA-17-122-01,Schneider Electric Wonderware Historian Client,Schneider Electric,Wonderware Historian Client,The following versions of Wonderware Historian Client - analysis and reporting software are affected: Wonderware Historian Client 2014 R2 SP1 and prior.,CVE-2017-7907,6.6,Medium,CWE-611,Critical Manufacturing; Energy; Healthcare and Public Health; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 682,5/2/2017,5/2/2017,2017,ICSA-17-122-02,CyberVision Kaa IoT Platform,CyberVision,Kaa IoT Platform,The following version of Kaa IoT Platform - middleware platform is affected: Kaa IoT Platform | Version 0.7.4 and possibly other versions.,CVE-2017-7911,6.3,Medium,CWE-485,Commercial Facilities; Critical Manufacturing; Food and Agriculture; Healthcare and Public Health; Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 681,5/2/2017,5/2/2017,2017,ICSA-17-122-03,Advantech B+B SmartWorx MESR901,Advantech B+B SmartWorx,MESR901,The following versions of MESR901 - Modbus gateway are affected: MESR901 firmware versions 1.5.2 and prior.,CVE-2017-7909,9.8,Critical,CWE-603,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 680,4/27/2017,7/25/2017,2017,ICSA-17-117-01,"GE Multilin SR, UR, and URplus Protective Relays (Update B)",GE,"Multilin SR, UR, and URplus Protective Relays",The following versions of Multilin SR protective relays are affected: 750 Feeder Protection Relay | firmware versions prior to Version 7.47 | 760 Feeder Protection Relay | firmware versions prior to Version 7.47 | 469 Motor Protection Relay | firmware versions prior to Version 5.23 | 489 Generator Protection Relay | firmware versions prior to Version 4.06 | 745 Transformer Protection Relay | firmware versions prior to Version 5.23 and 369 Motor Protection Relay | firmware versions prior to Version 3.63.The following versions of the Multilin Universal Relay (UR) and URplus relay families are affected: Universal Relay | firmware Version 6.02 (excluding Version 5.83 | Version 5.92 and all subsequent minor releases) and URplus (D90 | C90 | B95) all versions.GE has identified additional legacy products that are affected: MM300 Motor Management Relay | firmware versions prior to Version 1.71 | MM200 Motor Management System | firmware versions prior to Version 1.25 | MX350 Relay | firmware versions prior to Version 1.27 | RPTCS | firmware versions prior to Version 1.29 | 350 Feeder Protection Relay | firmware versions prior to Version 2.30 | 345 Transformer Protection Relay | firmware versions prior to Version 2.30 | 339 Motor Protection Relay | firmware versions prior to Version 2.30 and T1000 Switch | firmware versions prior to Version 03A02.,CVE-2017-7905,8.1,High,CWE-261,Chemical; Critical Manufacturing; Dams; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 679,4/25/2017,4/25/2017,2017,ICSA-17-115-01,BLF-Tech LLC VisualView HMI,BLF-Tech LLC,VisualView HMI,The following VisualView HMI versions are affected: VisualView HMI Version 9.9.14.0 and prior.,CVE-2017-6051,7.0,High,CWE-427,Critical Manufacturing; Water and Wastewater,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 678,4/25/2017,4/25/2017,2017,ICSA-17-115-02,Sierra Wireless AirLink Raven XE and XT,Sierra Wireless,AirLink Raven XE and XT,The following Sierra Wireless gateways are affected: AirLink Raven XE all versions prior to 4.0.14 and AirLink Raven XT all versions prior to 4.0.11.,"CVE-2017-6044, CVE-2017-6042, CVE-2017-6046",10.0,Critical,"CWE-352, CWE-285, CWE-522",Critical Manufacturing; Energy,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 677,4/25/2017,4/25/2017,2017,ICSA-17-115-03,Hyundai Motor America Blue Link,Hyundai Motor America,Blue Link,The following versions of Blue Link - a mobile application for Hyundai vehicle management are affected: Blue Link Version 3.9.5 and Blue Link Version 3.9.4.,"CVE-2017-6052, CVE-2017-6054",7.5,High,"CWE-300, CWE-321",Transportation Systems,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 676,4/13/2017,4/26/2018,2017,ICSA-17-103-01,Wecon Technologies LEVI Studio HMI Editor,WECON,Technologies LEVI Studio HMI Editor,The following versions of LEVI Studio HMI Editor - HMI programming software are affected: LEVI Studio HMI Editor all versions.,"CVE-2017-6037, CVE-2017-6035",8.8,High,"CWE-122, CWE-121",Critical Manufacturing,Worldwide,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 675,4/13/2017,7/20/2017,2017,ICSA-17-103-02,Schneider Electric Modicon M221 PLCs and SoMachine Basic (Update A),Schneider Electric,Modicon M221 PLCs and SoMachine Basic,Schneider Electric reports that these vulnerabilities affect the following PLCs and tools for configuring and developing automation machinery: All Modicon M221 PLCs with firmware version up to v1.5.0.1 and associated SoMachine Basic software (up to v1.5).,"CVE-2017-7574, CVE-2017-7575",10.0,Critical,"CWE-693, CWE-321",Commercial Facilities,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 674,4/11/2017,4/11/2017,2017,ICSA-17-101-01,Schneider Electric Modicon Modbus Protocol,Schneider Electric,Modicon Modbus Protocol,The following versions of Modicon Modbus protocol - used with the Modicon family of programmable logic controllers (PLCs) are affected: Modicon Modbus protocol all versions.,"CVE-2017-6034, CVE-2017-6032",10.0,Critical,"CWE-294, CWE-657",Critical Manufacturing; Dams; Defense Industrial Base; Energy; Food and Agriculture; Government Facilities; Nuclear Reactors Materials and Waste; Transportation Systems; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 673,4/6/2017,4/27/2017,2017,ICSA-17-096-01,Certec EDV GmbH atvise scada (Update A),Certec EDV GmbH,atvise scada,The following versions of atvise scada - human machine interface configuration platform are affected: atvise scada prior to Version 3.0 without the vendor built-in security mechanism activated.,"CVE-2017-6031, CVE-2017-6029",6.1,Medium,"CWE-644, CWE-79",Critical Manufacturing,Worldwide,Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 672,4/4/2017,4/4/2017,2017,ICSA-17-094-01,Schneider Electric Interactive Graphical SCADA System Software,Schneider Electric,Interactive Graphical SCADA System Software,Schneider Electric reports that the vulnerability affects the following IGSS HMI desktop application: IGSS Software | Version 12 and previous versions.,CVE-2017-6033,6.8,Medium,CWE-427,Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 671,4/4/2017,10/12/2017,2017,ICSA-17-094-02,Marel Food Processing Systems (Update B),Marel,Food Processing Systems,The following Marel food processing products are affected: All M3000 terminal-based products contain hard-coded password and unrestricted file upload vulnerabilities: Graders using M3000 terminal | Portioning Machines using M3000 terminal | Flowline systems using M3000 terminal | Packing systems using M3000 terminal | SensorX machines using M3000 terminal | Target Batchers using M3000 terminal and SpeedBatchers using M3000 terminal.All devices operating the Pluto platform contain an access control vulnerability: Graders using Pluto platform | Portioning Machines using Pluto platform | Flowline systems using Pluto platform | Packing systems using Pluto platform | SensorX machines using Pluto platform | Target Batchers using Pluto platform and SpeedBatchers using Pluto platform.,"CVE-2016-9358, CVE-2017-6041, CVE-2017-9626",9.8,Critical,"CWE-284, CWE-434, CWE-259",Food and Agriculture,"Iceland, United States, South America, Asia, Europe",Iceland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 670,4/4/2017,4/4/2017,2017,ICSA-17-094-03,Rockwell Automation Allen-Bradley Stratix and Allen-Bradley ArmorStratix,Rockwell Automation,Allen-Bradley Stratix and Allen-Bradley ArmorStratix,The following versions of the Allen-Bradley Stratix and ArmorStratix Industrial Ethernet and Distribution switches are affected: Allen-Bradley Stratix 5400 Industrial Ethernet Switches all Versions 15.2(5)EA.fc4 and earlier allen-Bradley Stratix 5410 Industrial Distribution Switches all Versions 15.2(5)EA.fc4 and earlier allen-Bradley Stratix 5700 and ArmorStratix 5700 Industrial Managed Ethernet Switches all Versions 15.2(5)EA.fc4 and earlier allen-Bradley Stratix 8000 Modular Managed Industrial Ethernet Switches all Versions 15.2(5)EA.fc4 and earlier and Allen-Bradley Stratix 8300 Modular Managed Industrial Ethernet Switches all Versions 15.2(4a)EA5 and earlier.,CVE-2017-3881,9.8,Critical,CWE-20,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 669,3/30/2017,3/30/2017,2017,ICSA-17-089-01,Schneider Electric Wonderware InTouch Access Anywhere,Schneider Electric,Wonderware InTouch Access Anywhere,The following Wonderware InTouch Access Anywhere versions are affected: Wonderware InTouch Access Anywhere | version 11.5.2 and prior.,"CVE-2017-5156, CVE-2017-5158, CVE-2017-5160",8.8,High,"CWE-352, CWE-200, CWE-326",Critical Manufacturing; Energy; Healthcare and Public Health; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 668,3/30/2017,3/30/2017,2017,ICSA-17-089-02,Schneider Electric Modicon PLCs,Schneider Electric,Modicon PLCs,The following versions of the Modicon M221 | M241 and M251 programmable logic controllers (PLCs) are affected by a predictable value range from previous values vulnerability: Modicon M221 | firmware versions prior to Version 1.5.0.0 | Modicon M241 | firmware versions prior to Version 4.0.5.11 and Modicon M251 | firmware versions prior to Version 4.0.5.11.The following versions of the Modicon M241 and M251 PLCs are affected by a use of insufficiently random values vulnerability: Modicon M241 | firmware versions prior to Version 4.0.5.11 and Modicon M251 | firmware versions prior to Version 4.0.5.11.The following versions of the Modicon M241 and M251 PLCs are affected by an insufficiently protected credentials vulnerability: Modicon M241 all firmware versions and Modicon M251 all firmware versions.,"CVE-2017-6030, CVE-2017-6026, CVE-2017-6028",7.5,High,"CWE-522, CWE-343, CWE-330",Critical Manufacturing; Food and Agriculture; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 667,3/28/2017,3/28/2017,2017,ICSA-17-087-01,Siemens RUGGEDCOM ROX I,Siemens,RUGGEDCOM ROX I,Siemens reports that the vulnerability affects the following RUGGEDCOM VPN endpoints and firewall devices: RUGGEDCOM ROX I: All versions.,"CVE-2017-2686, CVE-2017-2687, CVE-2017-2688, CVE-2017-2689, CVE-2017-6864",8.8,High,"CWE-352, CWE-285, CWE-79, CWE-80",Energy; Healthcare and Public Health; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 666,3/28/2017,3/28/2017,2017,ICSA-17-087-02,3S-Smart Software Solutions GmbH CODESYS Web Server,3S-Smart Software Solutions,CODESYS Web Server,The following versions of CODESYS Web Server - part of the CODESYS WebVisu web browser visualization software are affected: CODESYS Web Server Versions 2.3 and prior.,"CVE-2017-6027, CVE-2017-6025",9.8,Critical,"CWE-121, CWE-434",Critical Manufacturing; Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 665,3/23/2017,1/15/2019,2017,ICSA-17-082-01,LCDS - Leao Consultoria e Desenvolvimento de Sistemas Ltda ME LAquis SCADA,LCDS - Leao Consultoria e Desenvolvimento de Sistemas Ltda ME,LAquis SCADA,The following versions of LAquis SCADA - industrial automation software are affected: LAquis SCADA software | versions prior to version 4.1.0.3237.,CVE-2017-6020,5.3,Medium,CWE-22,Chemical; Commercial Facilities; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,"Brazil, South America",Brazil,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 664,3/23/2017,3/23/2017,2017,ICSMA-17-082-01,BD Kiestra PerformA and KLA Journal Service Applications Hard-Coded Passwords Vulnerability,"Becton, Dickinson and Company (BD)",Kiestra PerformA and KLA Journal Service Applications,The following BD products are affected: PerformA | Version 2.0.14.0 and prior versions and KLA Journal Service | Version 1.0.51 and prior versions.,CVE-2017-6022,7.3,High,CWE-259,Healthcare and Public Health,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 663,2/16/2017,2/16/2017,2017,ICSA-17-047-01,Rockwell Automation Connected Components Workbench,Rockwell Automation,Connected Components Workbench,The following Connected Components Workbench (CCW) - software configuration platform versions are affected: Connected Components Workbench - Developer Edition | v9.01.00 and earlier.9328-CCWDEVENE | 9328-CCWDEVZHE | 9328-CCWDEVFRE | 9328-CCWDEVITE | 9328-CCWDEVDEE | 9328-CCWDEVESE and 9328-CCWDEVPTE.Connected Components Workbench - Free Standard Edition (All Supported Languages) | v9.01.00 and earlier.,CVE-2017-5176,7.0,High,CWE-427,Commercial Facilities; Defense Industrial Base; Energy; Government Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 662,2/16/2017,2/16/2017,2017,ICSA-17-047-02,Rockwell Automation FactoryTalk Activation,Rockwell Automation,FactoryTalk Activation,The following versions of FactoryTalk Activation - component of FactoryTalk Services Platform are affected: FactoryTalk Activation Service | Version 4.00.02 and prior versions.FactoryTalk Activation is used in the following Rockwell Automation products: Arena | Emonitor | FactoryTalk AssetCentre | FactoryTalk Batch | FactoryTalk EnergyMetrix | FactoryTalk eProcedure | FactoryTalk Gateway | FactoryTalk Historian Site Edition (SE) | FactoryTalk Historian Classic | FactoryTalk Information Server | FactoryTalk Metrics | FactoryTalk Transaction Manager | FactoryTalk VantagePoint | FactoryTalk View Machine Edition (ME) | FactoryTalk View Site Edition (SE) | FactoryTalk ViewPoint | RSFieldBus | RSLinx Classic | RSLogix 500 | RSLogix 5000 | RSLogix 5 | RSLogix Emulate 5000 | RSNetWorx | RSView32 | SoftLogix 5800 | Studio 5000 Architect | Studio 5000 Logix Designer | Studio 5000 View Designer and Studio 5000 Logix Emulate.,CVE-2017-6015,8.8,High,CWE-428,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 661,3/16/2017,1/15/2019,2017,ICSA-17-075-01,LCDS - Leao Consultoria e Desenvolvimento de Sistemas Ltda ME LAquis SCADA,LCDS - Leao Consultoria e Desenvolvimento de Sistemas Ltda ME,LAquis SCADA,"The following versions of LAquis SCADA - industrial automation software are affected: LAquis SCADA software | Versions 4.1 and prior versions released before January 20, 2017.",CVE-2017-6016,7.3,High,CWE-284,Chemical; Commercial Facilities; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,"Brazil, South America",Brazil,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 660,3/14/2017,4/8/2021,2017,ICSA-17-073-01,FATEK Automation PLC Ethernet Module,FATEK Automation,Automation PLC Ethernet Module,The affected Ether_cfg software configuration tool runs on the following Fatek PLCs: CBEH versions prior to V3.6 Build 170215 | CBE versions prior to V3.6 Build 170215 | CM55E versions prior to V3.6 Build 170215 and CM25E versions prior to V3.6 Build 170215.,CVE-2017-6023,7.3,High,CWE-121,Commercial Facilities; Critical Manufacturing,"Taiwan, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 659,3/9/2017,3/9/2017,2017,ICSA-17-068-01,Schneider Electric ClearSCADA,Schneider Electric,ClearSCADA,The following versions of ClearSCADA - server and communications driver processes are affected: All supported versions including: ClearSCADA 2014 R1 (build 75.5210) and prior | ClearSCADA 2014 R1.1 (build 75.5387) and prior | ClearSCADA 2015 R1 (build 76.5648) and prior | ClearSCADA 2015 R2 (build 77.5882) and prior.,CVE-2017-6021,7.5,High,CWE-20,Critical Manufacturing,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 658,3/7/2017,3/7/2017,2017,ICSA-17-066-01,Schneider Electric Wonderware Intelligence,Schneider Electric,Wonderware Intelligence,The following versions of Wonderware Intelligence - operations management software are affected: Tableau Server/Desktop Versions 7.0 to 10.1.3 included in Wonderware Intelligence Versions 2014R3 and prior.,CVE-2017-5178,9.8,Critical,CWE-255,Critical Manufacturing; Energy; Healthcare and Public Health; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 657,3/2/2017,3/13/2017,2017,ICSA-17-061-01,Eaton xComfort Ethernet Communication Interface,Eaton,xComfort Ethernet Communication Interface,The following versions of xComfort Ethernet Communication Interface (ECI) - building automation system are affected: xComfort ECI Versions 1.07 and prior.,CVE-2016-9368,7.5,High,CWE-284,Commercial Facilities,Worldwide,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 656,3/2/2017,3/2/2017,2017,ICSA-17-061-02,Schneider Electric Conext ComBox,Schneider Electric,Conext ComBox,Schneider Electric reports that the vulnerability affects the following Conext ComBox solar battery monitor: Conext ComBox - model 865-1058: all firmware versions prior to V3.03 BN 830.,CVE-2017-6019,7.5,High,CWE-400,Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 655,3/2/2017,3/2/2017,2017,ICSA-17-061-03,Siemens SINUMERIK Integrate and SINUMERIK Operate,Siemens,SINUMERIK Integrate and SINUMERIK Operate,Siemens reports that the vulnerability affects the following SINUMERIK Integrate and Operate product suite versions: SINUMERIK Integrate Access MyMachine/Ethernet withAMM Service Engineer Client (ActiveX): All versions. SINUMERIK Integrate Access MyMachine/Ethernet and Analyze MyCondition withSINUMERIK Integrate Operate Client: All versions between 2.0.3.00.016 (including) and 2.0.6 (excluding) and All versions between 3.0.4.00.032 (including) and 3.0.6 (excluding).Affected SINUMERIK Integrate Operate clients are included in the following Operate releases: All versions between V4.5 SP6 (including) and V4.5 SP6 Hotfix 8 (excluding) and All versions between V4.7 SP2 Hotfix 1 (including) and V4.7 SP4 (excluding).,CVE-2017-2685,7.4,High,CWE-300,Energy; Healthcare and Public Health; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 654,2/28/2017,2/28/2017,2017,ICSA-17-059-01,Siemens RUGGEDCOM NMS,Siemens,RUGGEDCOM NMS,Siemens reports that the vulnerability affects the following RUGGEDCOM monitoring products: RUGGEDCOM NMS: All versions prior to V2.1.0 (Windows and Linux).,"CVE-2017-2682, CVE-2017-2683",8.8,High,"CWE-352, CWE-79",Energy; Healthcare and Public Health; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 653,2/23/2017,3/28/2017,2017,ICSA-17-054-02,"Red Lion Controls Sixnet-Managed Industrial Switches, AutomationDirect STRIDE-Managed Ethernet Switches Vulnerability","Red Lion Controls, AutomationDirect","Sixnet-Managed Industrial Switches, AutomationDirect STRIDE-Managed Ethernet Switches",The following Red Lion Controls Sixnet-Managed Industrial Switches are affected: Sixnet-Managed Industrial Switches running firmware Version 5.0.196 and prior.The following AutomationDirect STRIDE-Managed Ethernet Switch models which are manufactured by Red Lion Controls are affected: Stride-Managed Ethernet Switches running firmware Version 5.0.190 and prior.,CVE-2016-9335,10.0,Critical,CWE-321,Critical Manufacturing,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 652,2/23/2017,2/23/2017,2017,ICSA-17-054-01,VIPA Controls WinPLC7,VIPA Controls,WinPLC7,The following versions of WinPLC7 - PLC programming software are affected: WinPLC Versions 5.0.45.5921 and prior.,CVE-2017-5177,7.5,High,CWE-121,Commercial Facilities; Critical Manufacturing,"Australia, Germany, Asia, Europe, Africa, Middle East",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 651,2/23/2017,1/10/2019,2017,ICSA-17-054-03,Schneider Electric Modicon M340 PLC (Update A),Schneider Electric,Modicon M340 PLC,Schneider Electric reports the vulnerability affects the following products: M340 CPUs with firmware prior to v2.9 | M580 CPUs with firmware prior to v2.3 | Quantum CPUs with firmware prior to v3.52 | Premium CPUs all versions | M1E CPUs all versions.,CVE-2017-6017,7.5,High,CWE-400,Defense Industrial Base; Energy; Government Facilities; Nuclear Reactors Materials and Waste; Transportation Systems; Water and Wastewater,"China, France, India, Russia, United States",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 650,2/14/2017,2/14/2017,2017,ICSA-17-045-01,Advantech WebAccess,Advantech,WebAccess,The following WebAccess HMI versions are affected: Advantech WebAccess Versions 8.1 and prior.,CVE-2017-5175,7.1,High,CWE-427,Critical Manufacturing,"Taiwan, United States, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 649,2/14/2017,2/14/2017,2017,ICSA-17-045-02,Geutebruck IP Cameras,Geutebruck,IP Cameras,The following Geutebruck G-Cam IP camera version is affected: G-Cam/EFD-2250 Version 1.11.0.12.,"CVE-2017-5174, CVE-2017-5173",9.8,Critical,"CWE-288, CWE-78",Commercial Facilities; Energy; Healthcare and Public Health,"Australia, Germany, United States, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 648,2/14/2017,6/12/2018,2017,ICSA-17-045-03,Siemens SIMATIC Authentication Bypass (Update D),Siemens,SIMATIC,Siemens reports this vulnerability affects the following software applications used for central user administration: SIMATIC Logon: All versions prior to v1.5 SP3 Update 2. The following products include affected versions of SIMATIC Logon: SIMATIC WinCC: All versions prior to v7.4 SP1 | SIMATIC WinCC Runtime Professional: All versions prior to v14 SP1 | SIMATIC PCS 7: All versions prior to v8.2 SP1 | SIMATIC PDM: All versions prior to v9.1 and SIMATIC IT: All versions prior to v7.1.,CVE-2017-2684,9.0,Critical,CWE-287,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 647,2/9/2017,2/9/2017,2017,ICSA-17-040-01,Hanwha Techwin Smart Security Manager,Hanwha Techwin,Smart Security Manager,The following Smart Security Manager - software management platform | versions are affected: Smart Security Manager Versions 1.5 and prior.,"CVE-2017-5168, CVE-2017-5169",7.5,High,"CWE-352, CWE-22",Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,South Korea Korea,South Korea,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 646,2/7/2017,2/7/2017,2017,ICSA-17-038-01,Sielco Sistemi Winlog SCADA Software,Sielco Sistemi,Winlog SCADA Software,The following Sielco Sistemi products are affected: Winlog Lite SCADA Software | versions prior to Version 3.02.01 and Winlog Pro SCADA Software | versions prior to Version 3.02.01,CVE-2017-5161,7.2,High,CWE-427,Communications; Critical Manufacturing; Energy; Water and Wastewater,Worldwide,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 645,1/17/2017,3/23/2017,2017,ICSMA-17-017-01,BD Alaris 8000 Insufficiently Protected Credentials Vulnerability,"Becton, Dickinson and Company (BD)",Alaris 8000,The following Alaris 8000 PC unit versions are affected: Alaris 8000 PC unit all versions,CVE-2016-8375,4.9,Medium,CWE-522,Healthcare and Public Health,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 644,2/2/2017,2/2/2017,2017,ICSA-17-033-01,Honeywell XL Web II Controller Vulnerabilities,Honeywell,XL Web II Controller,The following XL Web II controller versions are affected: XL1000C500 XLWebExe-2-01-00 and prior and XLWeb 500 XLWebExe-1-02-08 and prior.,"CVE-2017-5139, CVE-2017-5140, CVE-2017-5141, CVE-2017-5142, CVE-2017-5143",8.7,High,"CWE-269, CWE-522, CWE-23, CWE-384, CWE-256",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 643,1/31/2017,2/7/2017,2017,ICSA-17-031-01,BINOM3 Electric Power Quality Meter (Update A),BINOM3,Electric Power Quality Meter,The following BINOM3 power meters are affected: Universal multifunctional electric power quality meter.,"CVE-2017-5164, CVE-2017-5162, CVE-2017-5165, CVE-2017-5166, CVE-2017-5167",10.0,Critical,"CWE-352, CWE-200, CWE-284, CWE-79, CWE-259",Energy,Russia,Russia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 642,1/31/2017,2/14/2017,2017,ICSA-17-031-02,Ecava IntegraXor,Ecava,IntegraXor,The following IntegraXor version is affected: IntegraXor Version 5.0.413.0.,CVE-2016-8341,7.3,High,CWE-89,Critical Manufacturing; Energy; Transportation Systems; Water and Wastewater,"Australia, Canada, Estonia, United Kingdom, Malaysia, Poland, United States",Malaysia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 641,1/26/2017,1/26/2017,2017,ICSA-17-026-01,Eaton ePDU Path Traversal Vulnerability,Eaton,ePDU,"ePDU Products are past end-of-life (EoL) and is no longer supported | Eaton has provided defense-in-depth mitigation instructions to protect devices that are still in use.This vulnerability could be exploited remotely. Eaton reports that the vulnerability affects the following products: EAMxxx prior to June 30, 2015 | EMAxxx prior to January 31, 2014 | EAMAxx prior to January 31, 2014 | EMAAxx prior to January 31, 2014 and ESWAxx prior to January 31, 2014.",CVE-2016-9357,5.3,Medium,CWE-22,Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 640,1/26/2017,4/18/2017,2017,ICSA-17-026-02,Belden Hirschmann GECKO (Update A),Belden,Hirschmann GECKO,The following GECKO switch versions are affected: Hirschmann GECKO Lite Managed switch | Version 2.0.00 and prior versions.,"CVE-2017-5163, CVE-2017-6036, CVE-2017-6038, CVE-2017-6040",7.1,High,"CWE-352, CWE-200, CWE-22, CWE-918",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 639,1/24/2017,1/24/2017,2017,ICSA-17-024-01,Schneider Electric Wonderware Historian,Schneider Electric,Wonderware Historian,The following Wonderware Historian versions are affected: Wonderware Historian 2014 R2 SP1 P01 and earlier.,CVE-2017-5155,7.3,High,CWE-255,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,France,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 638,1/19/2017,4/13/2017,2017,ICSA-17-019-01,Schneider Electric homeLYnk Controller (Update A),Schneider Electric,homeLYnk Controller,Schneider Electric reports that the vulnerability affects the following products: homeLYnk Controller | LSS100100 all versions prior to V1.5.0,"CVE-2017-5157, CVE-2017-7689",8.8,High,"CWE-79, CWE-77",Commercial Facilities,"France, United States",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 637,1/17/2017,9/19/2017,2017,ICSA-17-017-01,PHOENIX CONTACT mGuard,PHOENIX CONTACT,mGuard,PHOENIX CONTACT reports that the vulnerability affects the following mGuard products: Only devices that have been updated to Version 8.4.0 are affected.,CVE-2017-5159,9.8,Critical,CWE-99,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 636,12/1/2016,5/18/2017,2017,ICSA-16-336-05B,"GE Proficy HMI/SCADA iFIX, Proficy HMI/SCADA CIMPLICITY, and Proficy Historian Vulnerability (Update B)",GE,"Proficy HMI/SCADA iFIX, Proficy HMI/SCADA CIMPLICITY, and Proficy Historian",Proficy HMI/SCADA iFIX Version 5.8 SIM 13 and prior versions |Proficy HMI/SCADA CIMPLICITY Version 9.0 and prior versions and Proficy Historian Version 6.0 and prior versions.,CVE-2016-9360,6.4,Medium,CWE-522,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 635,1/12/2017,1/19/2017,2017,ICSA-17-012-01,Advantech WebAccess,Advantech,WebAccess,The following WebAccess version is affected: WebAccess Version 8.1.,"CVE-2017-5154, CVE-2017-5152",9.8,Critical,"CWE-89, CWE-592",Commercial Facilities; Critical Manufacturing; Energy; Government Facilities,Taiwan,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 634,1/12/2017,1/19/2017,2017,ICSA-17-012-02,VideoInsight Web Client,VideoInsight,Web Client,The following Web Client versions are affected: Web Client Version 6.3.5.11 and previous versions.,CVE-2017-5151,7.3,High,CWE-89,Multiple Critical Sectors,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 633,1/12/2017,1/19/2017,2017,ICSA-17-012-03,Carlo Gavazzi VMU-C EM and VMU-C PV,Carlo Gavazzi,VMU-C EM and VMU-C PV,ProductsCarlo Gavazzi reports that the vulnerabilities affect the following versions: VMU-C EM prior to firmware Version A11_U05 and VMU-C PV prior to firmware Version A17.,"CVE-2017-5144, CVE-2017-5145, CVE-2017-5146",10.0,Critical,"CWE-284, CWE-352, CWE-200",Energy,"Canada, Italy, United States, Asia, Europe",Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 632,1/10/2017,7/11/2017,2017,ICSA-17-010-01,OSIsoft PI Coresight and PI Web API (Update A),OSIsoft,PI Coresight and PI Web API,OSIsoft reports that the vulnerability affects the following versions: PI Coresight 2016 R2 and earlier versions and PI Web API 2016 R2 when deployed using the PI AF Services 2016 R2 integrated install kit.,CVE-2017-5153,6.1,Medium,CWE-533,Multiple Critical Sectors,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 631,1/9/2017,2/6/2017,2017,ICSMA-17-009-01,St. Jude Merlin@home Transmitter Vulnerability (Update A),St. Jude Medical,Merlin@home Transmitter,The following Merlin@home transmitters are affected: Merlin@home | versions prior to Version 8.2.2: RF models: EX1150 | Inductive models: EX1100 and Inductive models: EX1100 with MerlinOnDemand capability.,CVE-2017-5149,8.9,High,CWE-300,Healthcare and Public Health,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 630,12/8/2016,9/18/2018,2017,ICSA-16-343-05,Rockwell Automation Logix5000 Programmable Automation Controller Buffer Overflow Vulnerability (Update B),Rockwell Automation,Logix5000 Programmable Automation Controller,Firmware versions for the Logix5000 Controller product line are affected | excluding all firmware versions prior to Version 16.00 | which are not affected: FRN 16.00PowerFlex 700S drives with Phase II control and the embedded DriveLogix 5730 controller option installed (v16.020 through v16.022) | ControlLogix 5560 controllers (v16.020 through v16.022) |ControlLogix L55 controllers (v16.020 through v16.022) |ControlLogix 5560 Redundant controllers (all versions ) |GuardLogix 5560 controllers (all versions) |FlexLogix L34 controllers (all versions) |1769 CompactLogix L23x controllers (all versions) |1769 CompactLogix L3x controllers (v16.020 through v16.023) | 1768 CompactLogix L4x controllers | (v16.020 through v16.025).FRN 17.00PowerFlex 700S drives with Phase II control and the embedded DriveLogix 5730 controller option installed (v17.003 and v17.004) |SoftLogix 5800 controllers (all versions) |ControlLogix 5560 controllers (all versions) |GuardLogix 5560 controllers (all versions) |1769 CompactLogix L23x controllers (all versions) |1769 CompactLogix L3x controllers (all versions) | 1768 CompactLogix L4x controllers (all versions).FRN 18.00SoftLogix 5800 controllers (all versions) |RSLogix Emulate 5000 (all versions) |ControlLogix 5560 controllers (all versions) |ControlLogix 5570 controllers (all versions) | GuardLogix 5560 controllers (all versions) |1769 CompactLogix L23x controllers (all versions) | 1769 CompactLogix L3x controllers (all versions) |1768 CompactLogix L4x controllers (all versions) | 1768 Compact GuardLogix L4xS (all versions). FRN 19.00 SoftLogix 5800 controllers (all versions) | RSLogix Emulate 5000 (all versions) | ControlLogix 5560 controllers (all versions) | ControlLogix 5570 controllers (all versions) | ControlLogix 5560 Redundant controllers (all versions) | GuardLogix 5560 controllers (all versions) | 1769 CompactLogix L23x controllers (all versions) | 1769 CompactLogix L3x controllers (all versions) | 1768 CompactLogix L4x controllers (all versions) | 1768 Compact GuardLogix L4xS controllers (all versions). FRN 20.00 SoftLogix 5800 controllers (all versions) |RSLogix Emulate 5000 (all versions) |ControlLogix 5560 controllers (v20.010 through v20.013) |ControlLogix 5570 controllers (v20.010 through v20.013) | ControlLogix 5560 Redundant controllers (v20.050 through v20.055) | ControlLogix 5570 Redundant controllers (v20.050 through v20.055) | GuardLogix 5560 controllers (v20.010 through v20.017) | GuardLogix 5570 controllers (v20.010 through v20.017) | 1769 CompactLogix L23x controllers (v20.010 through v20.013) | 1769 CompactLogix L3x controllers (v20.010 through v20.013) | 1769 CompactLogix 5370 L1 controllers (v20.010 through v20.013) | 1769 CompactLogix 5370 L2 controllers (v20.010 through v20.013) | 1769 CompactLogix 5370 L3 controllers (v20.010 through v20.013) |1768 CompactLogix L4x controllers (v20.011 through v20.016) | 1768 Compact GuardLogix L4xS controllers (v20.011 through v20.013). FRN 21.00 SoftLogix 5800 controllers (all versions) | RSLogix Emulate 5000 (all versions) | ControlLogix 5570 controllers (all versions) | ControlLogix 5570 Redundant controllers (all versions) | GuardLogix 5570 controllers (all versions) | 1769 CompactLogix 5370 L1 controllers (all versions) | 1769 CompactLogix 5370 L2 controllers (all versions) | 1769 CompactLogix 5370 L3 controllers (all versions).4.2,CVE-2016-9343,10.0,Critical,CWE-121,Critical Manufacturing; Food and Agriculture; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 629,12/1/2016,12/1/2016,2017,ICSA-16-336-06,Rockwell Automation MicroLogix 1100 and 1400 Vulnerabilities,Rockwell Automation,MicroLogix 1100 and 1400,Allen-Bradley MicroLogix 1100 controller versions affected: 1763-L16AWA | Series A and B | Version 14.000 and prior versions; 1763-L16BBB | Series A and B | Version 14.000 and prior versions; 1763-L16BWA | Series A and B | Version 14.000 and prior versions; and 1763-L16DWD | Series A and B | Version 14.000 and prior versions.The following Allen-Bradley MicroLogix 1400 controller versions affected: 1766-L32AWA | Series A and B | Version 15.004 and prior versions; 1766-L32BWA | Series A and B | Version 15.004 and prior versions; 1766-L32BWAA | Series A and B | Version 15.004 and prior versions; 1766-L32BXB | Series A and B | Version 15.004 and prior versions; 1766-L32BXBA | Series A and B | Version 15.004 and prior versions; and 1766-L32AWAA | Series A and B | Version 15.004 and prior versions.,"CVE-2016-9334, CVE-2016-9338",4.6,Medium,"CWE-319, CWE-732",Food and Agriculture; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 628,12/22/2016,12/22/2016,2016,ICSA-16-357-01,Fidelix FX-20 Series Controllers Path Traversal Vulnerability,Fidelix,FX-20 Series Controllers,FX-20 series controllers: FX-20 series controllers | versions prior to 11.50.19.,CVE-2016-9364,7.5,High,CWE-22,Commercial Facilities,"Finland, Europe",Finland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 627,12/22/2016,12/22/2016,2016,ICSA-16-357-02,WAGO Ethernet Web-based Management Authentication Bypass Vulnerability,WAGO,Ethernet Web-based Management,WAGO 750-8202/PFC200 prior to FW04 (released August 2015) |WAGO 750-881 prior to FW09 (released August 2016) | WAGO 0758-0874-0000-0111.,CVE-2016-9362,9.1,Critical,CWE-592,Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,"China, Germany, India, Poland, Switzerland",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 626,12/20/2016,12/20/2016,2016,ICSA-16-355-01,Siemens Desigo PX Web Module Insufficient Entropy Vulnerability,Siemens,Desigo PX Web Module,Desigo PX Web modules and versions: Desigo PX Web modules PXA40-W0 | PXA40-W1 | PXA40-W2 for Desigo PX automation controllers PXC00-E.D | PXC50-E.D | PXC100-E.D | PXC200-E.D: All firmware versions prior to V6.00.046 | Desigo PX Web modules PXA30-W0 | PXA30-W1 | PXA30-W2 for Desigo PX automation controllers PXC00-U | PXC64-U | PXC128-U: All firmware versions prior to V6.00.046.,CVE-2016-9154,5.9,Medium,CWE-332,Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 625,12/15/2016,4/8/2021,2016,ICSA-16-350-01,FATEK Automation PLC WinProladder Stack-Based Buffer Overflow Vulnerability,FATEK Automation,Automation PLC WinProladder,PLC WinProladder version affected: PLC WinProladder Version 3.11 Build 14701.,CVE-2016-8377,8.0,High,CWE-121,Commercial Facilities; Critical Manufacturing,"Taiwan, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 624,12/15/2016,12/15/2016,2016,ICSA-16-350-02,OmniMetrix OmniView Vulnerabilities,OmniMetrix,OmniView,OmniView versions: Version 1.2,"CVE-2016-5786, CVE-2016-5801",7.5,High,"CWE-319, CWE-521",Commercial Facilities; Energy,"United States, South America, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 623,12/13/2016,12/13/2016,2016,ICSA-16-348-01,Visonic PowerLink2 Vulnerabilities,Visonic,PowerLink2,PowerLink2 versions affected: All versions prior to October 2016 firmware release.,"CVE-2016-5811, CVE-2016-5813",5.7,Medium,"CWE-200, CWE-79",Commercial Facilities,"Australia, China, Germany, Denmark, Spain, United Kingdom, Israel, Poland, Singapore, United States, Asia, Europe",Israel,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 622,12/13/2016,12/13/2016,2016,ICSA-16-348-02,Moxa DACenter Vulnerabilities,Moxa,DACenter,DACenter: Versions 1.4 and older.,"CVE-2016-9354, CVE-2016-9356",7.2,High,"CWE-400, CWE-428",Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,"Brazil, China, Germany, France, United Kingdom, India, Russia, Taiwan, United States, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 621,12/13/2016,12/13/2016,2016,ICSA-16-348-03,"Delta Electronics WPLSoft, ISPSoft, and PMSoft Vulnerabilities",Delta Electronics,"WPLSoft, ISPSoft, and PMSoft",Delta Electronics products and versions affected: WPLSoft | Versions prior to V2.42.11 |ISPSoft | Versions prior to 3.02.11 | PMSoft | Versions prior to 2.10.10.,"CVE-2016-5805, CVE-2016-5802",7.8,High,"CWE-122, CWE-787",Critical Manufacturing,"Brazil, China, India, Japan, South Korea, Singapore, Taiwan, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 620,12/13/2016,12/13/2016,2016,ICSA-16-348-04,Siemens SIMATIC WinCC and SIMATIC PCS 7 ActiveX Vulnerability,Siemens,SIMATIC WinCC and SIMATIC PCS 7,Siemens versions of SIMATIC: SIMATIC WinCC: All versions prior to SIMATIC WinCC V7.2 | SIMATIC PCS 7: All versions prior to SIMATIC PCS 7 V8.0 SP1.,CVE-2016-9160,4.2,Medium,CWE-119,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 619,12/8/2016,12/8/2016,2016,ICSA-16-343-01,Moxa MiiNePort Session Hijack Vulnerabilities,Moxa,MiiNePort,Moxa affected versions of MiiNePort: MiiNePort E1 versions prior to 1.8 |MiiNePort E2 versions prior to 1.4 | MiiNePort E3 versions prior to 1.1.,"CVE-2016-9344, CVE-2016-9346",5.3,Medium,"CWE-312, CWE-264",Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,"Brazil, China, Germany, France, United Kingdom, India, Russia, Taiwan, United States, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 618,12/8/2016,12/8/2016,2016,ICSA-16-343-02,Sauter NovaWeb Web HMI Authentication Bypass Vulnerability,SAUTER Controls,NovaWeb Web HMI,NovaWeb versions affected: NovaWeb web HMI | all versions.,CVE-2016-5782,7.2,High,CWE-784,Commercial Facilities; Critical Manufacturing,"Germany, Switzerland, Europe",Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 617,12/8/2016,12/8/2016,2016,ICSA-16-343-03,Adcon Telemetry A850 Telemetry Gateway Base Station Vulnerabilities,Adcon Telemetry,A850 Telemetry Gateway Base Station,A850 Telemetry Gateway Base Station versions affected: A850 Telemetry Gateway Base Station | all versions.,CVE-2016-2274,9.8,Critical,CWE-79,Commercial Facilities; Critical Manufacturing; Water and Wastewater,"Austria, Germany, United States, Europe",Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 616,12/8/2016,12/8/2016,2016,ICSA-16-343-04,INTERSCHALT VDR G4e Path Traversal Vulnerability,INTERSCHALT,VDR G4e,INTERSCHALT versions of VDR G4e: Versions 5.220 and prior.,CVE-2016-9339,5.3,Medium,CWE-22,Transportation Systems,"China, Germany, United States, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 615,12/6/2016,12/6/2016,2016,ICSA-16-341-01,Tesla Gateway ECU Vulnerability,Tesla,Gateway ECU,Vehicle firmware build versions affected: All firmware versions before version 7.1 (2.36.31) with web browser functionality enabled.,CVE-2016-9337,6.8,Medium,CWE-77,Transportation Systems,"Japan, Netherlands, United States, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 614,8/18/2016,8/18/2016,2016,ICSA-16-231-01,Locus Energy LGate Command Injection Vulnerability,Navis,WebAccess,WebAccess versions affected: Navis WebAccess | all versions released prior to August 10 | 2016.,CVE-2016-5817,7.3,High,CWE-89,Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 613,12/1/2016,6/15/2017,2016,ICSA-16-336-01A,Siemens SICAM PAS Vulnerabilities (Update A),Siemens,SICAM PAS,SICAM PAS versions affected: SICAM PAS: All versions prior to 8.09.,"CVE-2016-8567, CVE-2016-8566, CVE-2016-9156, CVE-2016-9157",8.9,High,"CWE-552, CWE-257, CWE-798, CWE-633",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 612,12/1/2016,3/21/2017,2016,ICSA-16-336-02A,Moxa NPort Device Vulnerabilities (Update A),Moxa,NPort Device,Moxa versions of NPort affected: NPort 5110 versions prior to 2.7 | NPort 5130/5150 Series versions prior to 3.7 | NPort 5200 Series versions prior to 2.9 | NPort 5400 Series versions prior to 3.12 | NPort 5600 Series versions prior to 3.8 | NPort 5100A Series & NPort P5150A versions prior to 1.4 | NPort 5200A Series versions prior to 1.4 | NPort 5150AI-M12 Series versions prior to 1.3 | NPort 5250AI-M12 Series versions prior to 1.3 | NPort 5450AI-M12 Series versions prior to 1.3 | NPort 5600-8-DT Series versions prior to 2.5 | NPort 5600-8-DTL Series versions prior to 2.5 | NPort IA5450A versions prior to v1.4 | NPort 6000 series versions prior to 1.16 | NPort 6110 series all versions.,"CVE-2016-9361, CVE-2016-9369, CVE-2016-9363, CVE-2016-9371, CVE-2016-9365, CVE-2016-9366, CVE-2016-9348, CVE-2016-9367",7.8,High,"CWE-255, CWE-264, CWE-120, CWE-79, CWE-352, CWE-307, CWE-256, CWE-400",Critical Manufacturing; Energy; Transportation,"Brazil, China, Germany, France, United Kingdom, India, Russia, Taiwan, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 611,12/1/2016,12/1/2016,2016,ICSA-16-336-03,Mitsubishi Electric MELSEC-Q Series Ethernet Interface Module Vulnerabilities,Mitsubishi Electric,MELSEC-Q Series Ethernet Interface Module,MELSEC-Q series versions affected: QJ71E71-100 | all versions |QJ71E71-B5 | all versions | QJ71E71-B2 | all versions.,"CVE-2016-8370, CVE-2016-8368",8.6,High,"CWE-412, CWE-327",Commercial Facilities; Critical Manufacturing; Food and Agriculture,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 610,12/1/2016,12/1/2016,2016,ICSA-16-336-04,Advantech SUSIAccess Server Vulnerabilities,Advantech,SUSIAccess Server,SUSIAccess Server versions affected: SUISAccess Server Version 3.0 and prior.,"CVE-2016-9349, CVE-2016-9351, CVE-2016-9353",8.0,High,"CWE-200, CWE-22, CWE-264",Commercial Facilities; Critical Manufacturing; Energy; Government Facilities,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 609,11/1/2016,9/7/2017,2016,ICSMA-16-306-01,Smiths Medical CADD-Solis Medication Safety Software Vulnerabilities,Smiths Medical,CADD-Solis Medication Safety Software,CADD-Solis Medication Safety Software versions affected: Smiths Medical CADD-Solis Medication Safety Software | Version 1.0; Smiths Medical CADD-Solis Medication Safety Software | Version 2.0; Smiths Medical CADD-Solis Medication Safety Software | Version 3.0; and Smiths Medical CADD-Solis Medication Safety Software | Version 3.1.,"CVE-2016-8355, CVE-2016-8358",9.2,Critical,"CWE-300, CWE-732",Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 608,11/29/2016,11/30/2016,2016,ICSA-16-334-01,Emerson Liebert SiteScan XML External Entity Vulnerability,Emerson,Liebert SiteScan XML External Entity,Liebert SiteScan versions affected: SiteScan Web Version 6.5 | prior.,CVE-2016-8348,7.5,High,CWE-611,Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 607,11/29/2016,11/29/2016,2016,ICSA-16-334-02,Emerson DeltaV Easy Security Management Application Vulnerability,Emerson,DeltaV Easy Security Management Application,Emerson DeltaV Easy Security Management application which is present on the following systems: DeltaV V12.3 |DeltaV V12.3.1 | DeltaV V13.3.,CVE-2016-9345,6.8,Medium,CWE-269,Chemical; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 606,11/29/2016,11/30/2016,2016,ICSA-16-334-03,Emerson DeltaV Wireless I/O Card Open SSH Port Vulnerability,Emerson,DeltaV Wireless I/O Card Open SSH Port,Emerson products affected: SE4801T0X Redundant Wireless I/O Card V13.3 | SE4801T1X Simplex Wireless I/O Card V13.3Note: The DeltaV system is not susceptible to this vulnerability except for the products and versions listed above.,CVE-2016-9347,5.0,Medium,CWE-306,Chemical; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 605,11/22/2016,4/14/2022,2016,ICSA-16-327-01,Siemens SIMATIC CP 1543-1 (Update A),Siemens,SIMATIC CP 1543-1,Siemens reports that the vulnerabilities affect the following versions of the SIMATIC CP 1543-1 communication processor: Update A SIMATIC CP 1543-1 (6GK7543-1AX00-0XE0): All versions prior to v2.0.28 SIPLUS NET CP 1543-1 (6AG1543-1AX00-2XE0): All versions prior to v2.0.28 End Update A,"CVE-2016-8561, CVE-2016-8562",6.0,Medium,"CWE-20, CWE-269",Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 604,11/17/2016,11/17/2016,2016,ICSA-16-322-01,Vanderbilt Industries Siemens IP CCTV Cameras Vulnerability,Siemens,IP CCTV Cameras,Versions of Siemens-branded IP cameras built by Vanderbilt Industries: CCMW3025: All versions prior to 1.41_SP18_S1 | CVMW3025-IR: All versions prior to 1.41_SP18_S1 | CFMW3025: All versions prior to 1.41_SP18_S1 | CCPW3025: All versions prior to 0.1.73_S1 | CCPW5025: All versions prior to 0.1.73_S1 | CCMD3025-DN18: All versions prior to v1.394_S1 | CCID1445-DN18: All versions prior to v2635 | CCID1445-DN28: All versions prior to v2635 | CCID1445-DN36: All versions prior to v2635 | CFIS1425: All versions prior to v2635 |CCIS1425: All versions prior to v2635 | CFMS2025: All versions prior to v2635 |CCMS2025: All versions prior to v2635 | CVMS2025-IR: All versions prior to v2635 |CFMW1025: All versions prior to v2635 | CCMW1025: All versions prior to v2635.,CVE-2016-9155,9.8,Critical,CWE-522,Commercial Facilities; Government Facilities; Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 603,11/17/2016,11/17/2016,2016,ICSA-16-322-02,Moxa SoftCMS Vulnerabilities,Moxa,SoftCMS,Moxa versions of SoftCMS: SoftCMS versions prior to Version 1.6.,"CVE-2016-9332, CVE-2016-8360, CVE-2016-9333",8.5,High,"CWE-415, CWE-20, CWE-89",Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,"Brazil, China, Germany, France, United Kingdom, India, Russia, Taiwan, United States, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 602,11/15/2016,11/15/2016,2016,ICSA-16-320-01,Lynxspring JENEsys BAS Bridge Vulnerabilities,Lynxspring,JENEsys BAS Bridge,BAS Bridge versions affected: BAS Bridge versions 1.1.8 and older.,"CVE-2016-8357, CVE-2016-8361, CVE-2016-8378, CVE-2016-8369",8.5,High,"CWE-352, CWE-522, CWE-306, CWE-264",Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 601,11/10/2016,1/3/2017,2016,ICSA-16-315-01B,CA Unified Infrastructure Management Directory Traversal Vulnerability (Update B),CA Technologies,Unified Infrastructure Management,Unified Infrastructure Management versions affected: Unified Infrastructure Management Version 8.47 and earlier.,CVE-2016-5803,8.6,High,CWE-23,Information Technology,"Brazil, China, Germany, France, United Kingdom, India, Japan, South Korea, Netherlands, United States, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 600,11/8/2016,1/24/2019,2016,ICSA-16-313-01,Phoenix Contact ILC PLC Authentication Vulnerabilities,PHOENIX CONTACT,ILC PLC,Phoenix Contact versions of ILC PLCs: All ILC 1xx PLCs.,"CVE-2016-8366, CVE-2016-8371, CVE-2016-8380",7.3,High,"CWE-767, CWE-312, CWE-592",Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,"Germany, North America, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 599,11/8/2016,11/8/2016,2016,ICSA-16-313-03,OSIsoft PI System Incomplete Model of Endpoint Features Vulnerability,OSIsoft,PI System Incomplete Model of Endpoint Features,PI System software versions affected: Applications using PI Asset Framework (AF) Client versions prior to PI AF Client 2016 | Version 2.8.0 |Applications using PI Software Development Kit (SDK) versions prior to PI SDK 2016 | Version 1.4.6 |PI Buffer Subsystem | versions prior to and including | Version 4.4 | PI Data Archive versions prior to PI Data Archive 2015 | Version 3.4.395.64.,CVE-2016-8365,7.1,High,CWE-437,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 598,11/3/2016,10/23/2019,2016,ICSA-16-308-01,Moxa OnCell Security Vulnerabilities,Moxa,OnCell Security,Moxa OnCell versions affected: OnCellG3470A-LTE | AWK-1131A/3131A/4131A Series | AWK-3191 Series | AWK-5232/6232 Series | AWK-1121/1127 Series | WAC-1001 V2 Series | WAC-2004 Series | AWK-3121-M12-RTG Series | AWK-3131-M12-RCC Series | AWK-5232-M12-RCC Series | TAP-6226 Series | AWK-3121/4121 Series | AWK-3131/4131 Series | AWK-5222/6222 Series.,"CVE-2016-8362, CVE-2016-8363",7.8,High,"CWE-287, CWE-264",Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,"Brazil, China, Germany, France, United Kingdom, India, Russia, Taiwan, United States, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 597,11/3/2016,7/27/2017,2016,ICSA-16-308-02B,Schneider Electric Magelis HMI Resource Consumption Vulnerabilities (Update B),Schneider Electric,Magelis HMI,Schneider Electric versions of Magelis HMI: Magelis GTO Advanced Optimum Panels | all versions |Magelis GTU Universal Panel | all versions |Magelis STO5xx and STU Small panels | all versions |Magelis XBT GH Advanced Hand -held Panels | all versions |Magelis XBT GK Advanced Touchscreen Panels with Keyboard | all versions |Magelis XBT GT Advanced Touchscreen Panels | all versions | Magelis XBT GTW Advanced Open Touchscreen Panels (Windows XPe).,"CVE-2016-8367, CVE-2016-8374",6.4,Medium,CWE-400,Critical Manufacturing; Food and Agriculture,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 596,11/3/2016,11/3/2016,2016,ICSA-16-308-03,Schneider Electric IONXXXX Series Power Meter Vulnerabilities,Schneider Electric,IONXXXX Series Power Meter,IONXXXX series power meter versions affected: ION73XX series |ION75XX series |ION76XX series |ION8650 series |ION8800 series | PM5XXX series.,"CVE-2016-5809, CVE-2016-5815",8.5,High,"CWE-352, CWE-284",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 595,11/1/2016,11/10/2016,2016,ICSA-16-306-01,Schneider Electric ConneXium Buffer Overflow Vulnerability,Schneider Electric,ConneXium,ConneXium firewalls versions affected: TCSEFEC23F3F20 all versions |TCSEFEC23F3F21 all versions |TCSEFEC23FCF20 all versions |TCSEFEC23FCF21 all versions | TCSEFEC2CF3F20 all versions.,CVE-2016-8352,10.0,Critical,CWE-121,Commercial Facilities,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 594,11/1/2016,11/1/2016,2016,ICSA-16-306-02,IBHsoftec S7-SoftPLC CPX43 Heap-based Buffer Overflow Vulnerability,IBHsoftec GmbH,S7-SoftPLC CPX43,IBHsoftec versions of S7-SoftPLC: S7-SoftPLC versions prior to 4.12b.,CVE-2016-8364,9.8,Critical,CWE-122,Critical Manufacturing; Energy; Water and Wastewater,"United States, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 593,11/1/2016,11/1/2016,2016,ICSA-16-306-03,Schneider Electric Unity PRO Control Flow Management Vulnerability,Schneider Electric,Unity PRO Control Flow Management,Schneider Electric versions of Unity PRO: Unity PRO | all versions prior to V11.1.,CVE-2016-8354,7.5,High,CWE-691,Commercial Facilities; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 592,10/27/2016,10/27/2016,2016,ICSA-16-301-01,Honeywell Experion PKS Improper Input Validation Vulnerability,Honeywell,Experion PKS,Experion PKS versions affected: Experion PKS | Release 3xx and prior |Experion PKS | Release 400 |Experion PKS | Release 410 |Experion PKS | Release 430 | Experion PKS | Release 431.,CVE-2016-8344,3.7,Low,CWE-20,Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,"United States, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 591,10/25/2016,11/7/2016,2016,ICSA-16-299-01,Siemens SICAM RTU Devices Denial-of-Service Vulnerability,Siemens,SICAM RTU Devices,Siemens versions of SICAM: ETA4 firmware (all versions prior to Revision 08) of the SM-2558 extension module for: SICAM AK |SICAM TM 1703 |SICAM BC 1703 | SICAM AK 3ETA2 firmware (Revision 11.01 and earlier) of the SM-2556 extension module for: SICAM AK |SICAM TM | SICAM BC.,CVE-2016-7987,7.5,High,CWE-400,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 590,10/20/2016,10/23/2019,2016,ICSA-16-294-01,Moxa EDR-810 Industrial Secure Router Privilege Escalation Vulnerability,Moxa,EDR-810 Industrial Secure Router,EDR-810 versions affected: EDR-810 using firmware versions prior to V3.13.,CVE-2016-8346,7.5,High,CWE-284,Critical Manufacturing; Energy; Water and Wastewater,"Argentina, Brazil, Chile, China, Germany, France, United Kingdom, India, Peru, Russia, Taiwan, United States, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 589,10/18/2016,10/18/2016,2016,ICSA-16-292-01,Schneider Electric PowerLogic PM8ECC Hard-coded Password Vulnerability,Schneider Electric,PowerLogic PM8ECC,PowerLogic PM8ECC versions affected: PM8ECC Version 2.651 and older.,CVE-2016-5818,9.1,Critical,CWE-259,Commercial Facilities,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 588,10/13/2016,10/13/2016,2016,ICSA-16-287-01,OSIsoft PI Web API 2015 R2 Service Account Permissions Vulnerability,OSIsoft,PI Web API 2015 R2,OSIsoft versions of PI Web API: PI Web API 2015 R2 (Version 1.5.1).,CVE-2016-8353,6.4,Medium,CWE-264,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 587,10/13/2016,10/13/2016,2016,ICSA-16-287-02,Siemens Automation License Manager Vulnerabilities,Siemens,Automation License Manager,Siemens versions of ALM: All versions prior to V5.3 SP3 Update 1.,"CVE-2016-8563, CVE-2016-8564, CVE-2016-8565",7.7,High,"CWE-22, CWE-89, CWE-400",Energy; Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 586,10/13/2016,10/13/2016,2016,ICSA-16-287-03,Siemens SIMATIC STEP 7 (TIA Portal) Information Disclosure Vulnerabilities,Siemens,SIMATIC STEP 7 (TIA Portal),Siemens versions of SIMATIC STEP 7 (TIA Portal): SIMATIC STEP 7 (TIA Portal): All versions prior to V14,"CVE-2016-7959, CVE-2016-7960",2.5,Low,"CWE-310, CWE-326",Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 585,10/13/2016,10/13/2016,2016,ICSA-16-287-04,Rockwell Automation Stratix Denial-of-Service and Memory Leak Vulnerabilities,Rockwell Automation,Stratix,Rockwell Automation Allen-Bradley Stratix industrial switches are affected: Allen-Bradley Stratix 5400 Industrial Ethernet Switches versions 15.2(4)EA3 and earlier |Allen-Bradley Stratix 5410 Industrial Distribution Switches versions 15.2(4)EA3 and earlier |Allen-Bradley Stratix 5700 Industrial Managed Ethernet Switches versions 15.2(4)EA3 and earlier |Allen-Bradley Stratix 8000 Modular Managed Ethernet Switches versions 15.2(4)EA3 and earlier | Allen-Bradley ArmorStratix 5700 Industrial Managed Ethernet Switches versions 15.2(4)EA3 and earlier.,"CVE-2016-6393, CVE-2016-6382, CVE-2016-6380, CVE-2016-6385",8.9,High,"CWE-209, CWE-20, CWE-693",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 584,10/13/2016,1/31/2017,2016,ICSA-16-287-05A,Moxa ioLogik E1200 Series Vulnerabilities (Update A),Moxa,ioLogik E1200 Series,Moxa affected products: ioLogik E1210 | firmware Version V2.4 and prior | ioLogik E1211 | firmware Version V2.3 and prior | ioLogik E1212 | firmware Version V2.4 and prior | ioLogik E1213 | firmware Version V2.5 and prior | ioLogik E1214 | firmware Version V2.4 and prior | ioLogik E1240 | firmware Version V2.3 and prior | ioLogik E1241 | firmware Version V2.4 and prior | ioLogik E1242 | firmware Version V2.4 and prior | ioLogik E1260 | firmware Version V2.4 and prior | ioLogik E1262 | firmware Version V2.4 and prior | ioLogik E2210 | firmware versions prior to V3.13 | ioLogik E2212 | firmware versions prior to V3.14 | ioLogik E2214 | firmware versions prior to V3.12 | ioLogik E2240 | firmware versions prior to V3.12 | ioLogik E2242 | firmware versions prior to V3.12 | ioLogik E2260 | firmware versions prior to V3.13 | ioLogik E2262 | firmware versions prior to V3.12.,"CVE-2016-8359, CVE-2016-8372, CVE-2016-8379, CVE-2016-8350",8.2,High,"CWE-352, CWE-79, CWE-522, CWE-521",Commercial Facilities; Energy,"Brazil, China, Germany, France, United Kingdom, India, Russia, Taiwan, United States, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 583,10/13/2016,4/8/2021,2016,ICSA-16-287-06,FATEK Automation Designer Memory Corruption Vulnerabilities,FATEK Automation,Automation Designer,FATEK Automation products are affected: Automation PM Designer V3 Version 2.1.2.2 | Automation FV Designer Version 1.2.8.0,"CVE-2016-5796, CVE-2016-5798, CVE-2016-5800",7.2,High,"CWE-119, CWE-121",Commercial Facilities; Critical Manufacturing,"Australia, China, Czech Republic, Germany, France, United Kingdom, India, Italy, Netherlands, Taiwan, United States, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 582,10/13/2016,11/7/2017,2016,ICSA-16-287-07A,Kabona AB WDC Vulnerabilities (Update A),Kabona AB,WDC,WebDatorCentral versions affected: All WDC versions prior to Version 3.4.0.,"CVE-2016-8356, CVE-2016-8376, CVE-2016-8347, CVE-2016-0872",8.1,High,"CWE-79, CWE-307, CWE-256, CWE-601",Commercial Facilities,"Canada, United Kingdom, Sweden, Europe",Sweden,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 581,9/8/2016,9/8/2016,2016,ICSA-16-252-01,GE Bently Nevada 3500/22M Improper Authorization Vulnerability,GE,Bently Nevada 3500/22M,GE Bently Nevada 3500/22M firmware versions affected: GE Bently Nevada 3500/22M (USB version) | all versions prior to firmware Version 5.0 | GE Bently Nevada 3500/22M (serial version) | all versions.,CVE-2016-5788,10.0,Critical,CWE-285,Chemical; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 580,10/5/2016,10/5/2016,2016,ICSMA-16-279-01,Animas OneTouch Ping Insulin Pump Vulnerabilities,Animas,OneTouch Ping Insulin Pump,OneTouch Ping insulin pump system versions affected: Animas OneTouch Ping insulin pump system | all versions.,"CVE-2016-5084, CVE-2016-5085, CVE-2016-5086",5.7,Medium,"CWE-294, CWE-319, CWE-330",Healthcare and Public Health,Canada,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 579,10/4/2016,10/4/2016,2016,ICSA-16-278-01,INDAS Web SCADA Path Traversal Vulnerability,INDAS,Web SCADA,INDAS Web SCADA versions affected: Web SCADA | versions prior to Version 3.,CVE-2016-8343,10.0,Critical,CWE-22,Communications; Water and Wastewater,Serbia,Serbia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 578,10/4/2016,1/5/2017,2016,ICSA-16-278-02,Beckhoff Embedded PC Images and TwinCAT Components Vulnerabilities,Beckhoff Automation,Embedded PC Images and TwinCAT Components,Beckhoff affected products: All Beckhoff Embedded PC Images with a creation date prior to October 22 2014 | All TwinCAT Components featuring Automation Device Specification (ADS) communication.,"CVE-2014-5414, CVE-2014-5415",9.1,Critical,"CWE-749, CWE-307",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 577,9/29/2016,9/29/2016,2016,ICSA-16-273-01,American Auto-Matrix Front-End Solutions Vulnerabilities,American Auto-Matrix,Front-End Solutions,Building Automation Front-End Solutions versions affected: Aspect-Nexus Building Automation Front-End Solutions application versions prior to 3.0.0Aspect-Matrix Building Automation Front-End Solutions application all versions.,"CVE-2016-2307, CVE-2016-2308",8.1,High,"CWE-98, CWE-256",Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 576,9/27/2016,8/22/2018,2016,ICSA-16-271-01,Siemens SCALANCE M-800/S615 Web Vulnerability,Siemens,SCALANCE M-800/S615 Web,Siemens affected products: SCALANCE M-800/S615: All versions before V4.02.,CVE-2016-7090,4.0,Medium,CWE-614,Chemical; Critical Manufacturing; Dams; Defense Industrial Base; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 575,9/20/2016,8/22/2018,2016,ICSA-16-264-01,Moxa Active OPC Server Unquoted Service Path Escalation Vulnerability,Moxa,Active OPC Server,Moxa affected products: Active OPC Server versions older than Version 2.4.19.,CVE-2016-5793,8.8,High,CWE-428,Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,"Brazil, China, Germany, France, United Kingdom, India, Russia, Taiwan, United States, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 574,9/15/2016,8/22/2018,2016,ICSA-16-259-01,Yokogawa STARDOM Authentication Bypass Vulnerability,Yokogawa,STARDOM,Yokogawa affected products: STARDOM FCN/FCJ controller (from Version R1.01 to R4.01).,CVE-2016-4860,7.3,High,CWE-592,Critical Manufacturing; Energy; Food and Agriculture,"Asia, East Asia, Europe, Africa, Middle East, Worldwide",Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 573,9/15/2016,8/22/2018,2016,ICSA-16-259-02,ABB DataManagerPro Credential Management Vulnerability,ABB,DataManagerPro Credential Management,ABB versions of DataManagerPro: DataManagerPro | all versions: 1.0.0 to 1.7.0.,CVE-2016-4526,7.2,High,CWE-427,Energy; Food and Agriculture; Water and Wastewater,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 572,9/15/2016,8/22/2018,2016,ICSA-16-259-03,Trane Tracer SC Sensitive Information Exposure Vulnerability,Trane U.S. Inc.,Tracer SC Sensitive,Tracer SC versions affected: Versions 4.2.1134 and below.,CVE-2016-0870,5.3,Medium,CWE-668,Commercial Facilities,"United States, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 571,8/11/2016,8/22/2018,2016,ICSA-16-224-02A,Rockwell Automation RSLogix 500 and RSLogix Micro File Parser Buffer Overflow Vulnerability (Update A),Rockwell Automation,RSLogix 500 and RSLogix Micro,Rockwell Automation affected products: RSLogix Micro Starter Lite | Version 10.00.00 or prior; RSLogix Micro Developer | Version 10.00.00 or prior; RSLogix 500 Starter Edition | Version 10.00.00 or prior; RSLogix 500 Stand ard Edition | Version 10.00.00 or prior; and RSLogix 500 Professional Edition | Version 10.00.00 or prior.,CVE-2016-5814,8.6,High,CWE-120,Chemical; Critical Manufacturing; Food and Agriculture; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 570,9/6/2016,8/23/2018,2016,ICSA-16-250-01,Siemens SIPROTEC 4 and SIPROTEC Compact Vulnerabilities,Siemens,SIPROTEC 4 and SIPROTEC Compact,Siemens affected products: EN100 Ethernet module (as optional for SIPROTEC 4 and SIPROTEC Compact): All versions prior to V4.29.,"CVE-2016-7112, CVE-2016-7113, CVE-2016-7114",5.0,Medium,"CWE-592, CWE-400",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 569,8/23/2016,8/23/2018,2016,ICSA-16-236-01A,Moxa OnCell Vulnerabilities (Update A),Moxa,OnCell,Moxa affected products: OnCell G3100V2 Series | editions prior to Version 2.8 | OnCell G3111/G3151/G3211/G3251 Series | editions prior to Version 1.7.,"CVE-2016-5799, CVE-2016-5812, CVE-2016-5819",6.5,Medium,"CWE-79, CWE-307, CWE-256",Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,"Brazil, China, Germany, France, United Kingdom, India, Russia, Taiwan, United States, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 568,8/18/2016,8/18/2016,2016,ICSA-16-231-01,Navis WebAccess SQL Injection Vulnerability,Navis,WebAccess,WebAccess versions affected: Navis WebAccess | all versions released prior to August 10 | 2016.,CVE-2016-5817,7.3,High,CWE-89,Transportation Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 567,8/11/2016,8/23/2018,2016,ICSA-16-224-01,Rockwell Automation MicroLogix 1400 SNMP Credentials Vulnerability,Rockwell Automation,MicroLogix 1400 SNMP Credentials,Rockwell Automation affected products: 1766-L32BWA |1766-L32AWA |1766-L32BXB |1766-L32BWAA |1766-L32AWAA | 1766-L32BXBA.,CVE-2016-5645,7.3,High,CWE-250,Chemical; Critical Manufacturing; Food and Agriculture; Water and Wastewater,"China, Czech Republic, Germany, Denmark, France, Hungary, Italy, Japan, South Korea, Poland, United States, South America, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 566,8/2/2016,8/23/2018,2016,ICSA-16-215-01,Moxa SoftCMS SQL Injection Vulnerability,Moxa,SoftCMS,Moxa affected products: SoftCMS versions prior to Version 1.5.,CVE-2016-5792,9.8,Critical,CWE-89,Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,"Brazil, China, Germany, France, United Kingdom, India, Russia, Taiwan, United States, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 565,8/2/2016,10/13/2016,2016,ICSA-16-215-02A,Siemens SINEMA Server Privilege Escalation Vulnerability (Update A),Siemens,SINEMA Server,Siemens affected products: SINEMA Server: All versions prior to V13 SP2.,CVE-2016-6486,7.3,High,CWE-284,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Government Facilities; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 564,7/26/2016,11/8/2016,2016,ICSA-16-208-01C,"Siemens SIMATIC WinCC, PCS 7, and WinCC Runtime Professional Vulnerabilities (Update C)",Siemens,"SIMATIC WinCC, PCS 7, and WinCC Runtime Professional",Siemens affected products: SIMATIC WinCC: V7.0 SP 2: All versions prior to V7.0 SP2 Update 12 | V7.0 SP 3: All versions prior to V7.0 SP3 Update 8 | V7.2: All versions prior to 7.2 Update 13 | V7.3: All versions prior to 7.3 Update 10 | V7.4: All versions prior to 7.4 Update 1SIMATIC PCS 7 (WinCC | Batch | Route Control | OPEN PCS 7): V7.1 SP4: all versions prior toV7.1 SP4 with WinCC V7.0 SP2 Update 12 | V8.0: All versions prior to V8.0 SP2 with WinCC V7.2 Update 13 | V8.1: All versions prior to 8.1 SP1 with WinCC V7.3 Update 10 | V8.2: All versions prior to 8.2 with WinCC V7.4 Update 1 | SIMATIC WinCC Runtime Professional: All versions prior to V13 SP 1 Update 9.,"CVE-2016-5743, CVE-2016-5744",8.7,High,CWE-20,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 563,7/26/2016,8/23/2018,2016,ICSA-16-208-02,Siemens SIMATIC NET PC-Software Denial-of-Service Vulnerability,Siemens,SIMATIC NET PC-Software,Siemens affected SIMATIC products: SIMATIC NET PC-Software: All versions prior to V13 SP2.,CVE-2016-5874,5.3,Medium,CWE-400,Chemical; Critical Manufacturing; Food and Agriculture,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 562,7/26/2016,8/23/2018,2016,ICSA-16-208-03,Siemens SINEMA Remote Connect Server Cross-site Scripting Vulnerability,Siemens,SINEMA Remote Connect Server,SINEMA Remote Connect Server versions affected: SINEMA Remote Connect Server | all versions prior to Version 1.2.,CVE-2016-6204,4.7,Medium,CWE-79,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Government Facilities; Water and Wastewater,"Germany, United States, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 561,6/21/2016,8/23/2018,2016,ICSA-16-173-03,Rockwell Automation FactoryTalk EnergyMetrix Vulnerabilities,Rockwell Automation,FactoryTalk EnergyMetrix,FactoryTalk EnergyMetrix versions affected: FactoryTalk EnergyMetrix | Version 2.10.00 and prior versions.,"CVE-2016-4531, CVE-2016-4522",7.3,High,"CWE-89, CWE-613",Chemical; Commercial Facilities; Critical Manufacturing; Energy; Government Facilities; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 560,7/14/2016,8/23/2018,2016,ICSA-16-196-01,Schneider Electric Pelco Digital Sentry Video Management System Vulnerability,Schneider Electric,Pelco Digital Sentry Video Management System,Pelco Digital Sentry Video Management System versions affected: Pelco Digital Sentry Video Management System | versions prior to Version 7.13.,CVE-2016-4520,8.6,High,CWE-259,Commercial Facilities,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 559,7/14/2016,8/23/2018,2016,ICSA-16-196-02,Moxa MGate Authentication Bypass Vulnerability,Moxa,Mgate,Moxa affected products: MGate MB3180 | versions prior to v1.8 | MGate MB3280 | versions prior to v2.7 | MGate MB3480 | versions prior to v2.6 | MGate MB3170 | versions prior to v2.5 | MGate MB3270 | versions prior to v2.7.,CVE-2016-5804,9.1,Critical,CWE-326,Chemical; Commercial Facilities; Critical Manufacturing; Emergency Services; Energy; Food and Agriculture; Government Facilities; Water and Wastewater,"Brazil, China, Germany, France, United Kingdom, India, Russia, Taiwan, United States, South America, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 558,7/14/2016,8/23/2018,2016,ICSA-16-196-03,Schneider Electric SoMachine HVAC Unsafe ActiveX Control Vulnerability,Schneider Electric,SoMachine HVAC,Schneider Electric affected products: SoMachine HVAC-Application Version 2.0.2 and previous.,CVE-2016-4529,7.3,High,CWE-623,Commercial Facilities,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 557,7/14/2016,7/15/2016,2016,ICSMA-16-196-01,Philips Xper-IM Connect Vulnerabilities,Philips,Xper-IM Connect,Philips Xper-IM Connect versions affected: Xper-IM Connect system running Windows XP | Version 1.5.12 and prior versions.,CVE-NA,7.0,High,"CWE-200, CWE-94, CWE-119, CWE-399, CWE-189",Healthcare and Public Health,"Canada, United States, North America, South America, Asia, Europe, Africa, Middle East",Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 556,7/12/2016,8/23/2018,2016,ICSA-16-194-01,Tollgrade Smart Grid EMS LightHouse Vulnerabilities,"Tollgrade Communications, Inc.",Smart Grid EMS LightHouse,Versions of LightHouse SMS Software: LightHouse SMS | versions prior to Version 5.1 | Patch 3.,"CVE-2016-5790, CVE-2016-5797, CVE-2016-5807",7.0,High,"CWE-425, CWE-209, CWE-306",Energy,"Germany, United Kingdom, United States, North America, South America, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 555,7/12/2016,8/23/2018,2016,ICSA-16-194-02,GE Proficy HMI SCADA CIMPLICITY Privilege Management Vulnerability,GE,Proficy HMI SCADA CIMPLICITY,Proficy HMI/SCADA-CIMPLICITY versions affected: CIMPLICITY Version 8.2 | SIM 26 or earlier.,CVE-2016-5787,5.7,Medium,CWE-269,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 554,7/7/2016,8/23/2018,2016,ICSA-16-189-01,WECON LeviStudio Buffer Overflow Vulnerabilities,WECON,LeviStudio,LeviStudio versions affected: LeviStudio | all versions.,"CVE-2016-4533, CVE-2016-5781",5.3,Medium,"CWE-122, CWE-121",Chemical; Critical Manufacturing; Energy,"China, Asia",China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 553,7/7/2016,8/23/2018,2016,ICSA-16-189-02,Moxa Device Server Web Console Authorization Bypass Vulnerability,Moxa,Device Server Web Console,Device Server Web Console 5232-N versions affected: Device Server Web Console 5232-N | all versions.,CVE-2016-4503,7.5,High,CWE-639,Commercial Facilities; Energy,"Brazil, China, Germany, France, United Kingdom, India, Russia, Taiwan, United States, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 552,7/5/2016,7/6/2016,2016,ICSA-16-187-01,Rexroth Bosch BLADEcontrol-WebVIS Vulnerabilities,Bosch Rexroth,BLADEcontrol-WebVIS,BLADEcontrol-WebVIS versions affected: BLADEcontrol-WebVIS | Version 3.0.2 and earlier.,"CVE-2016-4507, CVE-2016-4508",6.3,Medium,"CWE-79, CWE-564",Energy,"Australia, China, Czech Republic, Germany, France, United Kingdom, India, Italy, Netherlands, United States",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 551,6/30/2016,8/23/2018,2016,ICSA-16-182-01,Eaton ELCSoft Programming Software Memory Vulnerabilities,Eaton,ELCSoft Programming Software Memory,ELCSoft programming software versions affected: ELCSoft Version 2.4.01 and earlier.,"CVE-2016-4509, CVE-2016-4512",6.7,Medium,"CWE-122, CWE-121",Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 550,6/30/2016,12/1/2016,2016,ICSA-16-182-02B,Siemens SICAM PAS Information Disclosure Vulnerabilities (Update B),Siemens,SICAM PAS,SICAM PAS versions affected: SICAM PAS | versions older than Version 8.08.,"CVE-2016-5848, CVE-2016-5849",2.4,Low,CWE-522,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 549,6/23/2016,8/23/2018,2016,ICSA-16-175-01,Rockwell Automation Allen-Bradley Stratix 5400 and 5410 Packet Corruption Vulnerability,Rockwell Automation,Allen-Bradley Stratix 5400 and 5410,Rockwell Automation - Allen-Bradley Stratix industrial switches are affected: Allen-Bradley Stratix 5400 Industrial Ethernet Switch | firmware Versions 15.2(2)EA1 | 15.2(2)EA2 | Allen-Bradley Stratix 5410 Industrial Distribution Switch | firmware Versions 15.2(2)EB.,CVE-2016-1399,5.8,Medium,CWE-399,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 548,6/23/2016,8/23/2018,2016,ICSA-16-175-02,Unitronics VisiLogic OPLC IDE vlp File Parsing Stack Buffer Overflow Vulnerability,Unitronics,VisiLogic OPLC IDE vlp File Parsing,Unitronics versions of VisiLogic: Visilogic prior to Version 9.8.30.,CVE-2016-4519,7.3,High,CWE-121,Multiple Critical Sectors,Worldwide,Israel,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 547,6/23/2016,8/23/2018,2016,ICSA-16-175-03,Meinberg NTP Time Server Vulnerabilities,Meinberg,NTP Time Server,Meinberg products affected: IMS-LANTIME M3000 Version 6.0 and earlier | IMS-LANTIME M1000 Version 6.0 and earlier | IMS-LANTIME M500 Version 6.0 and earlier | LANTIME M900 Version 6.0 and earlier | LANTIME M600 Version 6.0 and earlier | LANTIME M400 Version 6.0 and earlier |LANTIME M300 Version 6.0 and earlier | LANTIME M200 Version 6.0 and earlier | LANTIME M100 Version 6.0 and earlier | SyncFire 1100 Version 6.0 and earlier | LCES Version 6.0 and earlier.,"CVE-2016-3962, CVE-2016-3988, CVE-2016-3989",7.6,High,CWE-121,Communications; Defense Industrial Base; Energy; Financial Services; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 546,6/21/2016,8/23/2018,2016,ICSA-16-173-01A,Advantech WebAccess ActiveX Vulnerabilities (Update A),Advantech,WebAccess ActiveX,Advantech versions of WebAccess: WebAccess versions prior to 8.1_20160519.,"CVE-2016-4525, CVE-2016-4528, CVE-2016-5810",5.8,Medium,"CWE-120, CWE-200, CWE-623",Commercial Facilities; Critical Manufacturing; Energy; Government Facilities,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 545,6/21/2016,8/23/2018,2016,ICSA-16-173-02,Schneider Electric PowerLogic PM8ECC Cross-site Scripting Vulnerability,Schneider Electric,PowerLogic PM8ECC,Schneider Electric versions of PowerLogic PM8ECC: PowerLogic PM8ECC | firmware versions prior to Version 2.651.,CVE-2016-4513,6.1,Medium,CWE-79,Commercial Facilities,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 544,6/16/2016,8/23/2018,2016,ICSA-16-168-01,Moxa PT-7728 Series Switch Improper Authorization Vulnerability,Moxa,PT-7728 Series Switch,Moxa Industrial Ethernet Switches affected: PT-7728 Series Version 3.4 build 15081113.,CVE-2016-4514,7.7,High,CWE-285,Chemical; Commercial Facilities; Critical Manufacturing; Emergency Services; Energy; Food and Agriculture; Government Facilities; Water and Wastewater,"Argentina, Brazil, Chile, China, Germany, France, United Kingdom, India, Peru, Russia, Taiwan, United States, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 543,6/14/2016,8/23/2018,2016,ICSA-16-166-01,OSIsoft PI SQL Data Access Server Input Validation Vulnerability,OSIsoft,PI SQL Data Access Server,Versions of PI SQL Data Access Server prior to the 2016 (1.5) release are included only with: PI JDBC Driver 2015 (1.4.1.404) and earlier | PI ODBC Driver 2015 (3.5.403) and earlier.,CVE-2016-4530,6.9,Medium,CWE-20,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 542,6/14/2016,8/23/2018,2016,ICSA-16-166-02,OSIsoft PI AF Server Input Validation Vulnerability,OSIsoft,PI AF Server,OSIsoft affected products: PI AF Server prior to 2016 | versions prior to 2.8.0The issue exists in a component that ships with the PI AF Server. This component is used by other OSIsoft applications but is not normally used by user applications or users of the PI AF SDK or PI System Explorer. This component can be safely disabled following defensive measures without impacting other PI AF Server functionality with the condition that none of the listed OSIsoft applications are also being used.,CVE-2016-4518,6.9,Medium,CWE-20,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 541,6/9/2016,8/23/2018,2016,ICSA-16-161-01,Siemens SIMATIC S7-300 Denial-of-Service Vulnerability,Siemens,SIMATIC S7-300,Siemens affected products: SIMATIC S7-300 CPUs with Profinet support: All versions prior to V3.2.12 | SIMATIC S7-300 CPUs without Profinet support: All versions prior to V3.3.12.,CVE-2016-3949,7.5,High,CWE-664,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 540,6/9/2016,8/23/2018,2016,ICSA-16-161-02,Siemens SIMATIC WinCC Flexible Weakly Protected Credentials Vulnerability,Siemens,SIMATIC WinCC Flexible,Siemens product versions of SIMATIC WinCC flexible: All versions prior to SP3 Up7.,CVE-2015-1358,3.7,Low,CWE-522,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 539,6/7/2016,8/23/2018,2016,ICSA-16-159-01,Trihedral Engineering Limited VTScada Vulnerabilities,Trihedral Engineering Limited,VTScada,Trihedral Engineering Ltd. affected product: VTScada versions after Version 8 and before Version 11.2.02. These vulnerabilities only apply to the WAP interface (typically Port 9201/TCP/IP). Only a small fraction of the installed base of VTScada uses this legacy feature.,"CVE-2016-4523, CVE-2016-4532, CVE-2016-4510",8.6,High,"CWE-22, CWE-125, CWE-592",Chemical; Communications; Critical Manufacturing; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,"Canada, United Kingdom, United States, North America, Europe",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 538,5/5/2016,8/23/2018,2016,ICSA-16-126-01,KMC Controls Conquest BACnet Router Vulnerabilities,KMC Controls,Conquest BACnet Router,KMC Controls products affected: BAC-5051E routers | firmware versions prior to E0.2.0.2.,"CVE-2016-4494, CVE-2016-4495",5.3,Medium,"CWE-352, CWE-306",Commercial Facilities,"United States, Asia, Southeast Asia, Middle East",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 537,6/2/2016,8/23/2018,2016,ICSA-16-154-01,GE MultiLink Series Hard-coded Credential Vulnerability,GE,MultiLink Series,MultiLink products affected: GE ML800 Switch | firmware versions prior to Version 5.5.0 | GE ML810 Switch | firmware versions prior to Version 5.5.0k | GE ML1200 Switch | firmware versions prior to Version 5.5.0 | GE ML1600 Switch | firmware versions prior to Version 5.5.0 | GE ML2400 Switch | firmware versions prior to Version 5.5.0 | GE ML3000 Switch | firmware versions prior to Version 5.5.0k | GE ML3100 Switch | firmware versions prior to Version 5.5.0k.,CVE-2016-2310,10.0,Critical,CWE-259,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 536,5/31/2016,8/23/2018,2016,ICSA-16-152-01,Moxa UC 7408-LX-Plus Firmware Overwrite Vulnerability,Moxa,UC 7408-LX-Plus Firmware,Moxa UC-7408 versions affected: UC-7408 LX-Plus all versions.,CVE-2016-4500,5.8,Medium,CWE-306,Chemical; Commercial Facilities; Critical Manufacturing; Emergency Services; Energy; Food and Agriculture; Government Facilities; Water and Wastewater,"Argentina, Brazil, Chile, China, Germany, France, United Kingdom, India, Peru, Russia, Taiwan, United States, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 535,5/31/2016,8/23/2018,2016,ICSA-16-152-02,ABB PCM600 Vulnerabilities,ABB,PCM600,ABB affected products: PCM600 up to and including Version 2.6.,"CVE-2016-4511, CVE-2016-4516, CVE-2016-4524, CVE-2016-4527",3.3,Low,"CWE-522, CWE-916",Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 534,5/26/2016,8/23/2018,2016,ICSA-16-147-02,Sixnet BT Series Hard-coded Credentials Vulnerability,Sixnet,Sixnet BT Series,Sixnet affected products: Sixnet BT-5xxx and BT-6xxx series M2M cellular routers versions prior to 3.8.21.,CVE-2016-4521,9.8,Critical,CWE-798,Commercial Facilities; Energy; Financial Services; Transportation Systems,"North America, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 533,5/26/2016,8/23/2018,2016,ICSA-16-147-03,Black Box AlertWerks ServSensor Credential Management Vulnerability,Black Box,AlertWerks ServSensor Credential Management,AlertWerks ServSensor versions affected: Black Box's AlertWerks ServSensor | model numbers EME105A | EME106A | EME108A-R2 | EME109A-R2 | EME110A-R2 | firmware versions prior to Version SP473; Black Box's AlertWerks ServSensor Junior | model numbers EME102A-R2 | EME103A-R2 | EME104A-R2 | firmware versions prior to Version SP473; Black Box's AlertWerks ServSensor Junior with PoE | model numbers EME152A | EME153A | EME154A | EME155A | EME158A | firmware versions prior to Version SP473; and Black Box's AlertWerks ServSensor Contact | model numbers EME111A-20-R2 | EME111A-60-R2 | EME112A-20-R2 | EME112A-60-R2 | EME113A-20-R2 | EME113A-60-R2 | firmware versions prior to Version SP473.,CVE-2016-2311,6.5,Medium,CWE-255,Commercial Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 532,5/26/2016,12/22/2016,2016,ICSA-16-147-01B,Environmental Systems Corporation Data Controllers Vulnerabilities (Update B),Environmental Systems Corporation,Data Controllers,ESC 8832 Data Controller versions affected: ESC 8832 Version 3.02 and earlier versions.,"CVE-2016-4501, CVE-2016-4502",8.3,High,"CWE-287, CWE-264",Energy,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 531,5/24/2016,8/23/2018,2016,ICSA-16-145-01A,Moxa MiiNePort Vulnerabilities (Update A),Moxa,MiiNePort,MiiNePort versions affected: MiiNePort_E1_7080 Firmware Version 1.1.10 Build 09120714 | MiiNePort_E1_4641 Firmware Version 1.1.10 Build 09120714 | MiiNePort_E2_1242 Firmware Version 1.1 Build 10080614 | MiiNePort_E2_4561 Firmware Version 1.1 Build 10080614 | MiiNePort E3 Firmware Version 1.0 Build 11071409.,"CVE-2016-2295, CVE-2016-2285, CVE-2016-2286",8.2,High,"CWE-312, CWE-255, CWE-352",Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,"Brazil, China, Germany, France, United Kingdom, India, Russia, Taiwan, United States, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 530,5/19/2016,12/22/2016,2016,ICSA-16-140-01A,Resource Data Management Intuitive 650 TDB Controller Vulnerabilities (Update A),Resource Data Management,Intuitive 650 TDB Controller,Intuitive 650 TDB Controller versions affected: Intuitive 650 TDB Controller Version 2.1 and earlier.,"CVE-2016-4505, CVE-2016-4506",8.4,High,"CWE-352, CWE-269",Commercial Facilities; Critical Manufacturing; Healthcare and Public Health,"United Kingdom, United States, Asia",United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 529,5/19/2016,5/17/2018,2016,ICSA-16-140-02,Siemens SIPROTEC Information Disclosure Vulnerabilities (Update B),Siemens,SIPROTEC,Siemens affected products: EN100 Ethernet module included in SIPROTEC 4 V4.26 or earlier | EN100 Ethernet module included in SIPROTEC Compact: V4.26 or earlier | SIPROTEC Compact model 7SJ80 with Ethernet Service Interface on Port A: Firmware V4.75 or earlier | SIPROTEC Compact models 7RW80 | 7SJ81 | 7SK81 with Ethernet Service Interface on Port A: All firmware versions.,"CVE-2016-4784, CVE-2016-4785",5.3,Medium,CWE-200,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 528,5/17/2016,12/22/2016,2016,ICSA-16-138-01A,IRZ RUH2 3G Firmware Overwrite Vulnerability (Update A),iRZ,RUH2 3G Firmware,iRZ product affected: RUH2.,CVE-2016-2309,7.2,High,CWE-434,Commercial Facilities; Communications; Financial Services; Healthcare and Public Health,"Belgium, China, Spain, France, Iran, Italy, Kazakhstan, Russia, Switzerland, Ukraine, Europe, Eastern Europe",Russia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 527,2/11/2016,10/23/2019,2016,ICSA-16-042-01A,Moxa EDR-G903 Secure Router Vulnerabilities (Update A),Moxa,EDR-G903 Secure Router,Moxa Secure Routers affected: EDR-G903 Versions V3.4.11 and older.,"CVE-2016-0875, CVE-2016-0876, CVE-2016-0877, CVE-2016-0878, CVE-2016-0879",7.5,High,"CWE-284, CWE-401, CWE-264, CWE-400, CWE-256",Commercial Facilities; Critical Manufacturing; Emergency Services; Energy,"Argentina, Brazil, Chile, China, Germany, France, United Kingdom, India, Peru, Russia, Taiwan, United States, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 526,5/12/2016,8/23/2018,2016,ICSA-16-133-01A,Meteocontrol WEB'log Vulnerabilities (Update A),Meteocontrol,WEB'log,WEB'log products are affected: Basic 100 all versions | Light all versions | Pro all versions | Pro Unlimited all versions.,"CVE-2016-2296, CVE-2016-2297, CVE-2016-4504, CVE-2016-2298",9.5,Critical,"CWE-553, CWE-352, CWE-200, CWE-284",Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,"China, Germany, Spain, France, Israel, Italy, Switzerland, United States, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 525,5/10/2016,8/23/2018,2016,ICSA-16-131-01,Panasonic FPWIN Pro Vulnerabilities,"Panasonic, Panasonic Electric Works Europe AG",FPWIN Pro,Panasonic affected products: FPWIN Pro version 5.x | FPWIN Pro version 6.x | FPWIN Pro version 7.122 and prior.Software releases 5.x have reached end-of-support. Users are advised to migrate to a supported release. Software releases 6.x are end-of-sales since April 2015 and will reach end-of-support in September 2016. Users using 6.x releases are advised to plan for an upgrade to the supported software release.,"CVE-2016-4499, CVE-2016-4498, CVE-2016-4496, CVE-2016-4497",4.2,Medium,"CWE-843, CWE-824, CWE-122, CWE-787",Commercial Facilities; Critical Manufacturing; Food and Agriculture,"North America, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 524,4/14/2016,8/23/2018,2016,ICSA-16-105-01,Sierra Wireless ACEmanager Information Exposure Vulnerability,Sierra Wireless,ACEmanager,Sierra Wireless versions affected: LS300 running ALEOS 4.4.2 and earlier | GX400 running ALEOS 4.4.2 and earlier | GX440 running ALEOS 4.4.2 and earlier | ES440 running ALEOS 4.4.2 and earlier | GX450 running ALEOS 4.4.2 and earlier | ES450 running ALEOS 4.4.2 and earlier.,CVE-2015-6479,4.3,Medium,CWE-538,Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,"Canada, China, France, United States, Europe",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 523,4/14/2016,8/23/2018,2016,ICSA-16-105-02,Accuenergy Acuvim II Series AXM-NET Module Vulnerabilities,Accuenergy,Acuvim II Series AXM-NET Module,Accuenergy versions affected: Acuvim II NET Firmware | Version 3.08Acuvim IIR NET Firmware | Version 3.08.,"CVE-2016-2293, CVE-2016-2294",8.1,High,"CWE-592, CWE-256",Energy,"Canada, China, United States, North America",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 522,4/14/2016,8/23/2018,2016,ICSA-16-105-03,Ecava IntegraXor Vulnerabilities,Ecava,IntegraXor,Ecava IntegraXor versions affected: IntegraXor | versions prior to Version 5.0 | build 4522.,"CVE-2016-2306, CVE-2016-2305, CVE-2016-2304, CVE-2016-2303, CVE-2016-2300, CVE-2016-2299, CVE-2016-2302, CVE-2016-2301",5.9,Medium,"CWE-319, CWE-79, CWE-87, CWE-113, CWE-285, CWE-89, CWE-200",Critical Manufacturing; Energy; Water and Wastewater,"Australia, Canada, Estonia, United Kingdom, Malaysia, Poland, United States",Malaysia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 521,4/12/2016,8/23/2018,2016,ICSA-16-103-01C,Siemens Industrial Products glibc Library Vulnerability (Update C),Siemens,Industrial Products glibc Library,Siemens affected products: ROX II: V2.3.0-V2.9.0 (inclusive) |APE (Linux): All versions | SINEMA Remote Connect: All versions prior to Version 1.2 | SCALANCE M-800/S615: All versions prior to version 4.02 | Basic RT V13: All versions prior to V13 SP1 Update 9.,CVE-2015-7547,8.1,High,CWE-119,Chemical; Communications; Critical Manufacturing; Dams; Energy; Food and Agriculture; Government Facilities; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 520,4/12/2016,8/23/2018,2016,ICSA-16-103-02,Siemens SCALANCE S613 Denial-of-Service Vulnerability,Siemens,SCALANCE S613,Siemens SCALANCE versions affected: SCALANCE S613 (MLFB: 6GK5613-0BA00-2AA3): All versions.,CVE-2016-3963,5.3,Medium,CWE-400,Chemical; Critical Manufacturing; Defense Industrial Base; Energy; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 519,4/12/2016,11/28/2017,2016,ICSA-16-103-03C,Siemens Industrial Products DROWN Vulnerability (Update C),Siemens,Industrial Products DROWN,Siemens affected products: SCALANCE X300 family: All versions prior to V4.1.0 | SCALANCE X414: All versions prior to V3.10.2 | SCALANCE X200 IRT family: All versions prior to V5.3.0 | SCALANCE X200 RNA family: All versions prior to V3.2.5 | SCALANCE X200 family: All versions prior to V5.2.2 | ROX I: All versions not using the mitigations listed in SSA-327980.,CVE-2016-0800,4.0,Medium,CWE-310,Chemical; Communications; Critical Manufacturing; Dams; Defense Industrial Base; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 518,3/10/2016,8/23/2018,2016,ICSA-16-070-02A,Honeywell Uniformance PHD Denial Of Service (Update A),Honeywell,Uniformance PHD,Honeywell versions: Uniformance PHD | versions prior to R310.1.1.2; Uniformance PHD | versions prior to R320.1.0.2; and Uniformance PHD | versions prior to R321.1.1.,CVE-2016-2280,7.5,High,CWE-121,Chemical; Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 517,4/5/2016,8/23/2018,2016,ICSA-16-096-01,Pro-face GP-Pro EX HMI Vulnerabilities,"Pro-face, Schneider Electric",Pro-face GP-Pro EX HMI,Pro-face affected versions of GP-Pro EX: Models: EX-ED | PFXEXEDV | PFXEXEDLS | PFXEXGRPLS; and Versions: 1.00 to Ver. 4.0.4.,"CVE-2016-2290, CVE-2016-2291, CVE-2016-2292, CVE-2016-7921",7.7,High,"CWE-122, CWE-125, CWE-592, CWE-121, CWE-798",Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,"Australia, India, Asia, Europe, Worldwide",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 516,4/5/2016,8/23/2018,2016,ICSA-16-096-01,Pro-face GP-Pro EX HMI Vulnerabilities,"Pro-face, Schneider Electric",Pro-face GP-Pro EX HMI,Pro-face affected versions of GP-Pro EX: Models: EX-ED | PFXEXEDV | PFXEXEDLS | PFXEXGRPLS; and Versions: 1.00 to Ver. 4.0.4.,"CVE-2016-2290, CVE-2016-2291, CVE-2016-2292, CVE-2016-7921",7.7,High,"CWE-122, CWE-125, CWE-592, CWE-121, CWE-798",Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,"Australia, India, Asia, Europe, Worldwide",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 515,3/1/2016,8/23/2018,2016,ICSA-16-061-03,Eaton Lighting Systems EG2 Web Control Authentication Bypass Vulnerabilities,Eaton,Lighting Systems EG2 Web Control,Eaton Lighting Systems versions: EG2 Web Control V4.04P and prior.,"CVE-2016-2272, CVE-2016-0871",7.5,High,"CWE-312, CWE-565",Commercial Facilities; Government Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 514,2/25/2016,8/23/2018,2016,ICSA-16-056-01,Rockwell Automation Integrated Architecture Builder Access Violation Memory Error,Rockwell Automation,Integrated Architecture Builder,IAB versions affected: Integrated Architecture Builder | Versions 9.6.0.7 and earlier | Integrated Architecture Builder | Versions 9.7.0.0 and 9.7.0.1.,CVE-2016-2277,6.3,Medium,CWE-119,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 513,3/31/2016,8/23/2018,2016,ICSA-16-091-01,ICONICS WebHMI Directory Traversal Vulnerability,ICONICS,WebHMI,ICONICS product affected: WebHMI Version 9 and earlier.,CVE-2016-2289,9.8,Critical,CWE-22,Commercial Facilities; Energy; Food and Agriculture; Healthcare and Public Health; Water and Wastewater,"United States, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 512,3/29/2016,3/23/2017,2016,ICSMA-16-089-01,CareFusion Pyxis SupplyStation System Vulnerabilities,"CareFusion, Becton, Dickinson and Company (BD)",Pyxis SupplyStation System,Pyxis SupplyStation system software versions affected: Pyxis SupplyStation system | Version 8.0 Server 2003/XP; Pyxis SupplyStation system | Version 8.1.3 Server 2003/XP; Pyxis SupplyStation system | Version 9.0 Server 2003/XP; Pyxis SupplyStation system | Version 9.1 Server 2003/XP; Pyxis SupplyStation system | Version 9.2 Server 2003/XP; and Pyxis SupplyStation system | Version 9.3 Server 2003/XP.CareFusion has reported that Version 9.3 | Version 9.4 | Version 10.0 of the Pyxis SupplyStation systems that operate on Server 2008/Server 2012/Windows 7 do not contain the reported vulnerabilities.,CVE-NA,5.5,Medium,CWE-NA,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 511,3/24/2016,8/23/2018,2016,ICSA-16-084-01,Cogent DataHub Elevation of Privilege Vulnerability,Cogent Real-Time Systems Inc,DataHub,Cogent affected products: Cogent DataHub version 7.3.9 and prior.,CVE-2016-2288,7.5,High,CWE-269,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Financial Services,"United Kingdom, United States",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 510,3/22/2016,2/14/2017,2016,ICSA-16-082-01A,Siemens APOGEE Insight Incorrect File Permissions Vulnerability (Update A),Siemens,APOGEE Insight,Siemens affected product: APOGEE Insight: All versions prior to 3.15.,CVE-2016-3155,3.4,Low,CWE-276,Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 509,3/17/2016,8/23/2018,2016,ICSA-16-077-01A,ABB Panel Builder 800 DLL Hijacking Vulnerability (Update A),ABB,Panel Builder 800 DLL,ABB product affected: Panel Builder 800 Version 5.1.,CVE-2016-2281,7.2,High,CWE-427,Critical Manufacturing; Energy; Transportation,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 508,3/15/2016,8/23/2018,2016,ICSA-16-075-01,Siemens SIMATIC S7-1200 CPU Protection Mechanism Failure,Siemens,SIMATIC S7-1200 CPU,Siemens affected SIMATIC products: SIMATIC S7-1200 CPU family: All versions prior to V4.0,CVE-2016-2846,6.5,Medium,CWE-693,Chemical; Critical Manufacturing; Food and Agriculture,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 507,3/10/2016,8/23/2018,2016,ICSA-16-070-01,Schneider Electric Telvent RTU Improper Ethernet Frame Padding Vulnerability,Schneider Electric,Telvent RTU,Schneider Electric Telvent RTUs affected products: Sage 3030M | with firmware prior to C3414-500-S02J2; Sage 1410 | with firmware prior to C3414-500-S02J2; Sage1430 | with firmware prior to C3414-500-S02J2; Sage 1450 | with firmware prior to C3414-500-S02J2; Land AC II-2 | with firmware prior to C3414-500-S02J2; Sage 2300 | with firmware prior to C3413-500-S01; and Sage 2400 | with firmware prior to C3414-500-S02J2 (released March 2015.).,CVE-2015-6485,5.3,Medium,CWE-226,Energy,"North America, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 506,3/3/2016,8/23/2018,2016,ICSA-16-063-01,Moxa ioLogik E2200 Series Weak Authentication Practices,Moxa,ioLogik E2200 Series,Moxa affected versions of ioLogik: ioLogik E2200 series | versions prior to 3.12 | ioAdmin Configuration Utility | versions prior to 3.18.,"CVE-2016-2282, CVE-2016-2283",5.9,Medium,"CWE-326, CWE-522",Commercial Facilities; Energy,"Brazil, China, Germany, France, United Kingdom, India, Russia, Taiwan, United States, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 505,3/1/2016,8/23/2018,2016,ICSA-16-061-01,Schneider Electric Building Operation Automation Server Vulnerability,Schneider Electric,Building Operation Automation Server,Schneider Electric affected products: StruxureWare Building Operations line: Automation Server | V1.7.0 and prior.,CVE-2016-2278,7.2,High,CWE-78,Commercial Facilities,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 504,3/1/2016,10/30/2018,2016,ICSA-16-061-02,Rockwell Automation Allen-Bradley CompactLogix Reflective Cross-Site Scripting Vulnerability (Update A),Rockwell Automation,Allen-Bradley CompactLogix Reflective,Rockwell Automation affected versions of the Allen Bradley CompactLogix controller platform: 1769-L16ER-BB1B | Version 27.011 and prior | 1769-L18ER-BB1B | Version 27.011 and prior | 1769-L18ERM-BB1B | Version 27.011 and prior | 1769-L24ER-QB1B | Version 27.011 and prior | 1769-L24ER-QBFC1B | Version 27.011 and prior | 1769-L27ERM-QBFC1B | Version 27.011 and prior | 1769-L30ER | Version 27.011 and prior | 1769-L30ERM | Version 27.011 and prior | 1769-L30ER-NSE | Version 27.011 and prior | 1769-L33ER | Version 27.011 and prior | 1769-L33ERM | Version 27.011 and prior | 1769-L36ERM | Version 27.011 and prior | 1769-L23E-QB1B | Version 20.018 and prior (discontinued as of June 2016) | 1769-L23E-QBFC1B | Version 20.018 and prior (discontinued as of June 2016) |1756-EN2F | Series A | all versions | Series B | all versions |1756-EN2T | Series A | all versions | Series B | all versions | Series C | all versions | Series D | Version 10.007 and prior | 1756-EN2TR | Series A | all versions | Series B | all versions |1756-EN3TR | Series A | all versions.,CVE-2016-2279,6.1,Medium,CWE-79,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 503,2/18/2016,8/23/2018,2016,ICSA-16-049-01,B+B SmartWorx VESP211 Authentication Bypass Vulnerability,B+B SmartWorx,VESP211,VESP211 serial servers affected: Model: VESP211-EU Firmware Version: 1.7.2 | Model: VESP211-232 Firmware Version: 1.7.2 | Model: VESP211-232 Firmware Version: 1.5.1.,CVE-2016-2275,9.8,Critical,CWE-603,Energy; Transportation Systems,"Czech Republic, Ireland, Taiwan, North America, South America, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 502,2/18/2016,3/2/2017,2016,ICSA-16-049-02A,AMX Multiple Products Credential Management Vulnerabilities (Update A),"AMX, Harman",AMX Multiple Products Credential Management,AMX multimedia devices affected by vulnerability CVE-2015-8362: NX-1200 | NX-2200 | NX-3200 | NX-4200 NetLinx Controller | versions prior to Version 1.4.65 |Massio ControlPads MCP-10x | versions prior to Version 1.4.65 |Enova DVX-x2xx | versions prior to Version 1.4.65 |DVX-31xxHD-SP (-T) | versions prior Version 4.8.331 |DVX-21xxHD-SP (-T) | versions prior Version 4.8.331 |DVX-2100HD-SP-T Master | versions prior to Version 4.1.420 (Hotfix firmware version) |Enova DGX 100 NX Series Master | versions prior to Version 1.4.72 (Hotfix firmware version) |Enova DGX 8/16/32/64 NX Series Master | versions prior to Version 1.4.72 (Hotfix firmware version) |Enova DGX 8/16/32/64 NI Series Master | versions prior to Version 4.2.397 (Hotfix firmware version) |NI-700 | NI-900 Master Controllers (64M RAM) | versions prior to Version 4.1.419 |NI-700 | NI-900 Master Controllers (32M RAM) | versions prior to Version 3.60.456 (Hotfix firmware version) |NI-2100 | NI-3100 | NI-4100 | NI-2100 with ICSNet | NI-3100 with ICSNet | NI-3100/256 |NI-3100/256 with ICSNet | NI-4100/256 | versions prior to Version 4.1.419 |NI-3101-SIG Master Controller | versions prior to Version 4.1.419 |NI-2000 | NI-3000 | NI-4000 | versions prior to Version 3.60.456 (Hotfix firmware version) | ME260/64 Duet | versions prior to Version 3.60.456 (Hotfix firmware version). The following AMX multimedia devices are affected by vulnerability CVE-2016-1984: NX-1200 | NX-2200 | NX-3200 | NX-4200 NetLinx Controller | Version 1.4.65 and Version 1.4.66 (Hotfix firmware version) |Massio ControlPads MCP-10x | Version 1.4.65 and Version 1.4.66 (Hotfix firmware version) |Enova DVX-x2xx | Version 1.4.65 and Version 1.4.72 (Hotfix firmware version) |Enova DGX 100 NX Series Master | Version 1.4.72 (Hotfix firmware version) | Enova DGX 8/16/32/64 NX Series Master | Version 1.4.72 (Hotfix firmware version).,"CVE-2015-8362, CVE-2016-1984",7.9,High,CWE-255,Commercial Facilities; Government Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 501,2/9/2016,8/23/2018,2016,ICSA-16-040-01,Tollgrade SmartGrid Sensor Management System Software Vulnerabilities,"Tollgrade Communications, Inc.",SmartGrid Sensor Management System Software,LightHouse SMS Software versions affected: Version 4.1.0 Build 16 | Versions older than Version 5.1.,"CVE-2016-0863, CVE-2016-0864, CVE-2016-0865, CVE-2016-0866",7.6,High,"CWE-352, CWE-200, CWE-79, CWE-522",Energy,"Germany, United Kingdom, United States, North America, South America, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 500,2/9/2016,8/23/2018,2016,ICSA-16-040-02,Siemens SIMATIC S7-1500 CPU Vulnerabilities,Siemens,SIMATIC S7-1500 CPU,Siemens SIMATIC S7-1500 CPU versions affected: Siemens SIMATIC S7-1500 CPU family | versions prior to Version 1.8.3.,"CVE-2016-2200, CVE-2016-2201",5.6,Medium,"CWE-340, CWE-691",Chemical; Critical Manufacturing; Food and Agriculture,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 499,2/2/2016,8/23/2018,2016,ICSA-16-033-01,Sauter moduWeb Vision Vulnerabilities,SAUTER Controls,moduWeb Vision,Sauter moduWeb Vision applications affected: EY-WS505F0x0 moduWeb Vision Versions prior to 1.6.0.,"CVE-2015-7914, CVE-2015-7915, CVE-2015-7916",9.1,Critical,"CWE-319, CWE-79, CWE-311",Commercial Facilities,"Switzerland, United States, Asia, Europe",Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 498,2/2/2016,8/23/2018,2016,ICSA-16-033-02,GE SNMP/Web Interface Vulnerabilities,GE,SNMP/Web Interface,SNMP/Web Interface adapter versions affected: SNMP/Web Interface adapter | firmware versions prior to Version 4.8.,"CVE-2016-0861, CVE-2016-0862",7.7,High,"CWE-312, CWE-77",Critical Manufacturing; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 497,1/28/2016,8/23/2018,2016,ICSA-16-028-01A,Westermo Industrial Switch Hard-coded Certificate Vulnerability (Update A),Westermo,Industrial Switch,Westermo Products are affected: WeOS versions older than Version 4.19.0 (indication | subject to change).This software is used within the following Westermo Product Lines: Falcon |Lynx |Wolverine |Corazon |Viper | Redfox series.,CVE-2015-7923,9.0,Critical,CWE-255,Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,"Austria, Belgium, China, Germany, France, United Kingdom, Sweden, Switzerland, Singapore, Taiwan, United States",Sweden,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 496,1/26/2016,8/23/2018,2016,ICSA-16-026-01,MICROSYS PROMOTIC Memory Corruption Vulnerability,MICROSYS,PROMOTIC,ProductsMICROSYS versions of PROMOTIC affected: PROMOTIC versions prior to version 8.3.11.,CVE-2016-0869,5.0,Medium,CWE-122,Critical Manufacturing; Energy; Water and Wastewater,"Bulgaria, Hungary, Poland, Romania, Serbia, Slovenia",Czech Republic,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 495,1/26/2016,8/23/2018,2016,ICSA-16-026-02,Rockwell Automation MicroLogix 1100 PLC Overflow Vulnerability,Rockwell Automation,MicroLogix 1100 PLC,Allen-Bradley MicroLogix 1100 controller platforms are affected: 1763-L16AWA | Series B | Version 15.000 and prior versions | 1763-L16BBB | Series B | Version 15.000 and prior versions | 1763-L16BWA | Series B | Version 15.000 and prior versions | 1763-L16DWD | Series B | Version 15.000 and prior versions |1763-L16AWA | Series A | Version 15.000 and prior versions | 1763-L16BBB | Series A | Version 15.000 and prior versions | 1763-L16BWA | Series A | Version 15.000 and prior versions | 1763-L16DWD | Series A | Version 15.000 and prior versions.,CVE-2016-0868,9.8,Critical,CWE-121,Chemical; Critical Manufacturing; Food and Agriculture; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 494,1/21/2016,8/23/2018,2016,ICSA-16-021-01,CAREL PlantVisor Enhanced Authentication Bypass Vulnerability,CAREL,PlantVisor Enhanced,CAREL versions: PlantVisorEnhanced.,CVE-2015-0867,7.5,High,CWE-20,Commercial Facilities; Critical Manufacturing; Energy,Worldwide,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 493,12/3/2015,2/4/2016,2016,ICSA-15-337-02,Hospira Multiple Products Buffer Overflow Vulnerability,Hospira,Multiple Products,LifeCare PCA Infusion System | Version 5.07 running CE Version 1.0 or earlier - released prior to July 2009 | Plum A+ Infusion System - Version 13.40 running CE - Version 1.0 or earlier - released prior to March 2009 | Plum A+3 Infusion System - Version 13.40 running CE Version 1.0 or earlier - released prior to March 2009.,CVE-2015-7909,7.3,High,CWE-121,Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 492,1/19/2016,8/23/2018,2016,ICSA-16-019-01,Siemens OZW672 and OZW772 XSS Vulnerability,Siemens,OZW672 and OZW772 XSS,Siemens affected products: OZW672: All versions prior to V6.00OZW772: All versions prior to V6.00.,CVE-2016-1488,4.7,Medium,CWE-79,Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 491,1/14/2016,8/23/2018,2016,ICSA-16-014-01,Advantech WebAccess Vulnerabilities,Advantech,WebAccess,Advantech affected versions of WebAccess: WebAccess Version 8.0 and prior versions.,"CVE-2016-0851, CVE-2016-0854, CVE-2016-0855, CVE-2016-0856, CVE-2016-0857, CVE-2016-0858, CVE-2016-0859, CVE-2016-0860, CVE-2016-0852, CVE-2016-0853, CVE-2015-3948, CVE-2015-3947, CVE-2015-3946, CVE-2015-6467, CVE-2015-3943",7.7,High,"CWE-788, CWE-434, CWE-22, CWE-121, CWE-122, CWE-362, CWE-680, CWE-119, CWE-284, CWE-20, CWE-79, CWE-89, CWE-352, CWE-73, CWE-312",Commercial Facilities; Critical Manufacturing; Energy; Government Facilities,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 490,12/22/2015,8/27/2018,2015,ICSA-15-356-01,Siemens RUGGEDCOM ROX-based Devices NTP Vulnerabilities,Siemens,RUGGEDCOM ROX-based Devices NTP,Siemens RUGGEDCOM ROX versions affected when NTP service is activated: ROX II: All versions prior to 2.9.0 | ROX I: All versions.The NTP service is deactivated on ROX I and ROX II-based devices by default.,"CVE-2015-7871, CVE-2015-7855, CVE-2015-7704, CVE-2015-5300",4.1,Medium,"CWE-20, CWE-592",Energy; Healthcare and Public Health; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 489,12/17/2015,8/27/2018,2015,ICSA-15-351-01,Schneider Electric Modicon M340 Buffer Overflow Vulnerability,Schneider Electric,Modicon M340,Schneider Electric Modicon M340 PLC products: BMXNOC0401 | BMXNOE0100 | BMXNOE0100H | BMXNOE0110 | BMXNOE0110H | BMXNOR0200 | BMXNOR0200H | BMXP342020 | BMXP342020H | BMXP342030 | BMXP3420302 | BMXP3420302H | BMXPRA0100.,CVE-2015-7937,7.5,High,CWE-121,Defense Industrial Base; Energy; Government Facilities; Nuclear Reactors Materials and Waste; Transportation Systems; Water and Wastewater,"China, India, Russia, United States, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 488,12/17/2015,8/27/2018,2015,ICSA-15-351-02,Motorola MOSCAD SCADA IP Gateway Vulnerabilities,Motorola Solutions,MOSCAD SCADA IP Gateway,MOSCAD IP Gateway versions are affected: MOSCAD IP Gateway - all versions.,"CVE-2015-7935, CVE-2015-7936",7.5,High,"CWE-352, CWE-98",Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,"United States, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 487,12/17/2015,8/27/2018,2015,ICSA-15-351-03,eWON Vulnerabilities,eWON sa,eWON,eWON router firmware versions are affected: eWON firmware versions prior to 10.1s0.,"CVE-2015-7924, CVE-2015-7925, CVE-2015-7926, CVE-2015-7927, CVE-2015-7928, CVE-2015-7929",7.7,High,"CWE-255, CWE-352, CWE-274, CWE-79, CWE-613, CWE-598",Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,"Japan, United States",Belgium,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 486,12/15/2015,8/27/2018,2015,ICSA-15-349-01,Adcon Telemetry A840 Vulnerabilities,Adcon Telemetry,A840,Adcon Telemetry product is affected: A840 Telemetry Gateway Base Station - all versions.,"CVE-2015-7930, CVE-2015-7931, CVE-2015-7932, CVE-2015-7934",9.3,Critical,"CWE-319, CWE-200, CWE-287, CWE-798",Commercial Facilities; Critical Manufacturing; Water and Wastewater,"United States, Europe",Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 485,12/10/2015,8/23/2018,2015,ICSA-15-344-01B,Advantech EKI Vulnerabilities (Update B),Advantech,EKI,Advantech reports that the vulnerability affects the following products: EKI-132x platform devices.,"CVE-2014-6271, CVE-2014-0160, CVE-2012-2152, CVE-2015-7938",8.7,High,"CWE-78, CWE-119, CWE-592",Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 484,12/10/2015,8/27/2018,2015,ICSA-15-344-02,Open Automation Software OPC Systems NET DLL Hijacking Vulnerability,Open Automation Software,OPC Systems NET,OPC Systems .NET versions are affected: OPC Systems.NET Version 8.00.0023 and previous versions.,CVE-2015-7917,7.2,High,CWE-427,Critical Manufacturing; Energy; Water and Wastewater,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 483,12/8/2015,2/21/2017,2015,ICSA-15-342-01C,XZERES 442SR Wind Turbine Cross-site Scripting Vulnerability (Update C),XZERES,442SR Wind Turbine,XZERES product affected: 442SR Wind Turbine.,CVE-2016-2287,9.8,Critical,CWE-79,Energy,"United Kingdom, Italy, Japan, Myanmar, Philippines, Vietnam",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 482,12/8/2015,8/27/2018,2015,ICSA-15-342-02,LOYTEC Router Information Exposure Vulnerability,LOYTEC electronics GmbH,LOYTEC routers,LOYTEC routers affected: LIP-3ECTB Version 6.0.1 |LINX-100 |LVIS-3E100 | LIP-ME201,CVE-2015-7906,9.1,Critical,CWE-200,Critical Manufacturing; Energy,"Germany, France",Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 481,12/3/2015,8/27/2018,2015,ICSA-15-337-03,Pacom 1000 CCU GMS System Cryptographic Implementation Vulnerabilities,Pacom,1000 CCU GMS System,Pacom GMS systems affected: Pacom 1000 CCU | RTU.,CVE-2014-3260,7.5,High,CWE-310,Commercial Facilities; Financial Services; Government Facilities; Healthcare and Public Health,Worldwide,Sweden,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 480,12/3/2015,8/27/2018,2015,ICSA-15-337-01,SearchBlox File Exfiltration Vulnerability,SearchBlox,SearchBlox,SearchBlox version affected: SearchBlox Version 8.3,CVE-2015-7919,10.0,Critical,CWE-200,Commercial Facilities; Critical Manufacturing; Information Technology,"United States, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 479,11/5/2015,8/27/2018,2015,ICSA-15-309-02,Honeywell Midas Gas Detector Vulnerabilities,Honeywell,Midas Gas Detector,Midas versions affected: Midas | Version 1.13b1 and prior versions |Midas Black | Version 2.13b1 and prior versions.,"CVE-2015-7907, CVE-2015-7908",9.0,Critical,"CWE-319, CWE-22",Chemical; Commercial Facilities; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 478,12/1/2015,11/16/2020,2015,ICSA-15-335-01,Saia Burgess Controls PCD Controller Hard-coded Password Vulnerability,Saia Burgess Controls,PCD Controller,Saia Burgess Controls affected: Saia PCD Controllers: PCD1.M0xx0/M2xx0 | PCD2.M5xx0 | PCD3.Mxxx0 | PCD3.Mxx60 | PCD7.D4xxxT5F | PCD7.D4xxV | PCD7.D4xxD | PCD7.D4xxWTPF versions prior to 1.24.50 | PCD3.T665 | PCD3.T666 versions prior to 1.24.41 | PCD7.D4xxxT5F versions prior to 1.24.50 | PCD7.D4xxV VGA MB Panels versions prior to 1.24.50 | PCD7.D4xxD SVGA MB Panels versions prior to 1.24.50 | | PCD7.D4xxWTPF WVGA MB Panels versions prior to 1.24.50.,CVE-2015-7911,9.1,Critical,CWE-259,Chemical; Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 477,12/1/2015,8/27/2018,2015,ICSA-15-335-02,Schneider Electric ProClima ActiveX Control Vulnerabilities,Schneider Electric,ProClima ActiveX,Schneider Electric affected versions of ProClima: Version 6.1 and prior.,CVE-2015-7918,6.3,Medium,CWE-94,Commercial Facilities; Critical Manufacturing; Energy,"United States, Asia, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 476,11/24/2015,8/27/2018,2015,ICSA-15-328-01,Moxa OnCell Central Manager Vulnerabilities,Moxa,OnCell Central Manager,Moxa OnCell Central Manager Software versions affected: OnCell Central Manager Software prior to version 2.2.,"CVE-2015-6481, CVE-2015-6480",8.3,High,"CWE-592, CWE-798",Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,"Brazil, China, Germany, France, United Kingdom, India, Russia, Taiwan, United States, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 475,10/22/2015,8/27/2018,2015,ICSA-15-295-01,Eaton's Cooper Devices Improper Ethernet Frame Padding Vulnerability,Eaton,Cooper Devices,Eaton's Cooper Power Systems versions affected: Previous versions of Eaton's Cooper Power Series Form 6 control | Idea/IdeaPLUS relays with Ethernet using Pro View 4.0 through Pro View 5.0 firmware versions.,CVE-2015-6471,5.3,Medium,CWE-226,Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 474,11/19/2015,8/27/2018,2015,ICSA-15-323-01,Tibbo AggreGate Platform Vulnerabilities,Tibbo,AggreGate Platform,AggreGate Platform versions affected: AggreGate Platform Version 5.21.02 and prior versions.,"CVE-2015-7912, CVE-2015-7913",9.1,Critical,CWE-434,Commercial Facilities; Communications; Critical Manufacturing; Energy; Healthcare and Public Health; Transportation Systems;; Water and Wastewater,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 473,11/17/2015,8/27/2018,2015,ICSA-15-321-01,Exemys Web Server Bypass Vulnerability,Exemys,Web Server,Exemys product versions affected: Exemys Telemetry Web Server.,CVE-2015-7910,8.6,High,CWE-592,Critical Manufacturing; Energy; Financial Services; Healthcare and Public Health; Information Technology,"Argentina, Canada, United States, South America, Asia, Europe",Argentina,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 472,10/1/2015,8/23/2018,2015,ICSA-15-274-02A,Unitronics VisiLogic OPLC IDE Vulnerabilities (Update A),Unitronics,VisiLogic OPLC IDE,Unitronics versions affected: Unitronics ViLogic OPLC IDE Version 9.8.0.00 and previous.,"CVE-2015-6478, CVE-2015-7905, CVE-2015-7939",8.6,High,"CWE-94, CWE-623",Multiple Critical Sectors,"Israel, United States",Israel,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 471,11/5/2015,8/27/2018,2015,ICSA-15-309-01,Advantech EKI Hard-coded SSH Keys Vulnerability,Advantech,EKI,EKI-136* product line prior to firmware version 1.27 |EKI-132* product line prior to firmware version 1.98 | EKI-122*-BE product line prior to firmware version 1.65.,CVE-2015-6476,6.5,Medium,CWE-798,Critical Manufacturing,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 470,10/27/2015,8/27/2018,2015,ICSA-15-300-01,Siemens RuggedCom Improper Ethernet Frame Padding Vulnerability,Siemens,RuggedCom,Siemens product versions affected: ROS: all versions prior to 4.2.1.,CVE-2015-7836,4.3,Medium,CWE-226,Energy; Healthcare and Public Health; Transportation Systems,"Germany, Georgia",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 469,10/27/2015,8/27/2018,2015,ICSA-15-300-02A,Infinite Automation Systems Mango Automation Vulnerabilities (Update A),Infinite Automation Systems,Mango Automation,Mango Automation versions affected: Mango Automation Version 2.5.0 through Version 2.6.0 beta (builds prior to 430) | Mango Automation versions prior to Version 2.7.0.,"CVE-2015-7904, CVE-2015-7901, CVE-2015-7900, CVE-2015-7903, CVE-2015-6493, CVE-2015-6494, CVE-2015-7902",5.1,Medium,"CWE-352, CWE-79, CWE-78, CWE-89, CWE-215, CWE-204, CWE-434",Commercial Facilities; Critical Manufacturing; Energy; Food and Agriculture,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 468,10/27/2015,8/27/2018,2015,ICSA-15-300-03A,Rockwell Automation Micrologix 1100 and 1400 PLC Systems Vulnerabilities (Update A),Rockwell Automation,Micrologix 1100 and 1400 PLC Systems,Allen-Bradley MicroLogix 1100 controller platforms versions affected: 1763-L16AWA | Series B | Version 14.000 and prior versions |1763-L16BBB | Series B | Version 14.000 and prior versions |1763-L16BWA | Series B | Version 14.000 and prior versions |1763-L16DWD | Series B | Version 14.000 and prior versions |1763-L16AWA | Series A | Version 14.000 and prior versions |1763-L16BBB | Series A | Version 14.000 and prior versions |1763-L16BWA | Series A | Version 14.000 and prior versions | 1763-L16DWD | Series A | Version 14.000 and prior versions. Allen-Bradley MicroLogix 1400 controller platforms versions affected: 1766-L32AWA | Series B | Version 15.002 and prior versions |1766-L32AWAA | Series B | Version 15.002 and prior versions |1766-L32BWA | Series B | Version 15.002 and prior versions |1766-L32BWAA | Series B | Version 15.002 and prior versions |1766-L32BXB | Series B | Version 15.002 and prior versions |1766-L32BXBA | Series B | Version 15.002 and prior versions |1766-L32AWA | Series A | Version 15.002 and prior versions |1766-L32AWAA | Series A | Version 15.002 and prior versions |1766-LK32BWA | Series A | Version 15.002 and prior versions |1766-L32BWAA | Series A | Version 15.002 and prior versions.,"CVE-2015-6490, CVE-2015-6492, CVE-2015-6491, CVE-2015-6488, CVE-2015-6486",6.1,Medium,"CWE-79, CWE-89, CWE-119, CWE-121, CWE-434",Chemical; Critical Manufacturing; Food and Agriculture; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 467,9/22/2015,8/27/2018,2015,ICSA-15-265-03,Janitza UMG Power Quality Measuring Products Vulnerabilities,Janitza,UMG Power Quality Measuring Products,Janitza versions affected: UMG 508 |UMG 509 |UMG 511 |UMG 604 | UMG 605.,"CVE-2015-3972, CVE-2015-3973, CVE-2015-3968, CVE-2015-3971, CVE-2015-3970, CVE-2015-3967, CVE-2015-3969",7.7,High,"CWE-352, CWE-200, CWE-79, CWE-215, CWE-259, CWE-330, CWE-521",Energy,"Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 466,10/20/2015,8/27/2018,2015,ICSA-15-293-01,IniNet Solutions embeddedWebServer Cleartext Storage Vulnerability,IniNet Solutions GmbH,embeddedWebServer,eWebServer versions affected: IniNet Solutions GmbH's eWebServer for Windows CE and versions prior to Version 2.02.IniNet Solutions GmbH's eWebServer a third-party software that are used in industrial control system devices. The IniNet Solutions GmbH's eWebServer - known to be used in Baumuller: Baumuller Box PC bmaXX PCC BMP-03-0000 | firmware Version 2015-03-11_PCC-03_v1.6 |Baumuller Box PC bmaXX PCC BMP-03-120R | firmware Version 2015-03-11_PCC-03_v1.6 | Baumuller Box PC bmaXX PCC BMP-03-150R | firmware Version 2015-03-11_PCC-03_v1.6. The IniNet Solutions GmbH's eWebServer - known to be compatible with Beckhoff: Beckhoff Embedded PC | series CX1010 |Beckhoff Embedded PC | series CX1020 |Beckhoff Embedded PC | series CX1030 |Beckhoff Embedded PC | series CX2000 |Beckhoff Embedded PC | series CX5100 |Beckhoff Embedded PC | series CX5000 |Beckhoff Embedded PC | series CX9000 |Beckhoff Embedded PC | series CX9010 |Beckhoff CX9020 | Basic CPU module | Beckhoff Embedded PC CX8090.,CVE-2015-1005,4.3,Medium,CWE-312,Commercial Facilities,"Switzerland, Europe",Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 465,10/20/2015,8/27/2018,2015,ICSA-15-293-02,IniNet Solutions SCADA Web Server Vulnerabilities,IniNet Solutions GmbH,SCADA Web Server,SCADA Web Server versions affected: IniNet Solutions GmbH's SCADA Web Server and versions prior to Version 2.02. IniNet Solutions GmbH's SCADA Web Server a third-party softwareare that used in industrial control system devices. The IniNet Solutions GmbH's SCADA Web Server - known to be compatible with Beckhoff: Beckhoff Embedded PC | series CX1010 |Beckhoff Embedded PC | series CX1020 |Beckhoff Embedded PC | series CX1030 |Beckhoff Embedded PC | series CX2000 |Beckhoff Embedded PC | series CX5100 | Beckhoff Embedded PC | series CX5000.,"CVE-2015-1001, CVE-2015-1002, CVE-2015-1003",9.0,Critical,"CWE-177, CWE-22, CWE-121",Commercial Facilities,Europe,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 464,10/20/2015,8/27/2018,2015,ICSA-15-293-03,3S CODESYS Gateway Null Pointer Exception Vulnerability,3S-Smart Software Solutions,CODESYS Gateway,Gateway Server versions affected: CODESYS Gateway Server | Version 2.3.9.47 and prior versions.,CVE-2015-6484,7.5,High,CWE-476,Critical Manufacturing; Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 463,10/15/2015,8/27/2018,2015,ICSA-15-288-01,3S CODESYS Runtime Toolkit Null Pointer Dereference Vulnerability,3S-Smart Software Solutions,CODESYS Runtime Toolkit,CODESYS software versions affected: CODESYS Runtime Toolkit and versions prior to Version 2.4.7.48.,CVE-2015-6482,7.5,High,CWE-476,Critical Manufacturing; Energy; Transportation,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 462,10/13/2015,8/27/2018,2015,ICSA-15-286-01,Nordex NC2 XSS Vulnerability,Nordex,NC2,Nordex NC2 versions affected: Nordex Control 2 (NC2) SCADA V16 and prior versions.,CVE-2015-6477,6.1,Medium,CWE-79,Energy,"China, Germany, United States, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 461,10/1/2015,1/31/2019,2015,ICSA-15-274-01,Omron Multiple Product Vulnerabilities,Omron,Multiple Products,Omron Corporation versions affected: CX-Programmer software and versions prior to Version 9.6 |CJ2M Series PLC and versions prior to Version 2.1 | CJ2H Series PLC and versions prior to Version 1.5.,"CVE-2015-0987, CVE-2015-0988, CVE-2015-1015",8.3,High,"CWE-319, CWE-257",Critical Manufacturing,Worldwide,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 460,9/29/2015,8/27/2018,2015,ICSA-15-272-01,Honeywell Experion PKS Directory Traversal Vulnerability,Honeywell,Experion PKS,Honeywell Experion PKS software releases versions affected: Release 310.x | below,CVE-2007-6483,9.4,Critical,CWE-22,Chemical; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 459,5/26/2015,8/27/2018,2015,ICSA-15-146-01,Mitsubishi Electric MELSEC FX-Series Controllers Denial of Service,Mitsubishi Electric,MELSEC FX-Series Controllers,MELSEC FX-series versions affected: MELSEC FX3G Series PLCs.,CVE-2015-3938,7.1,High,CWE-233,Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,"United States, Asia, Europe",Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 458,6/30/2015,6/30/2015,2015,ICSA-15-181-01,Baxter SIGMA Spectrum Infusion System Vulnerabilities,Baxter,SIGMA Spectrum Infusion System,SIGMA Spectrum Infusion System versions affected: SIGMA Spectrum Infusion System | Version 6.05 (model 35700BAX) with wireless battery module (WBM) | Version 16. The WBM a st |-alone component that provides network connectivity to the pump.,"CVE-2014-5431, CVE-2014-5432, CVE-2014-5433, CVE-2014-5434",6.5,Medium,"CWE-312, CWE-592, CWE-259",Healthcare and Public Health,"Australia, Canada, China, Germany, France, United Kingdom, India, Italy, United States",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 457,9/24/2015,8/27/2018,2015,ICSA-15-267-01,Endress+Hauser Fieldcare/CodeWrights HART Comm DTM XML Injection Vulnerability,"Endress+Hauser, CodeWrights GmbH",Fieldcare/CodeWrights HART Comm DTM,All HART DTM components relying on Fieldcare and a CodeWrights HART Comm DTM are affected.,CVE-2015-6463,8.3,High,CWE-91,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,"Germany, Switzerland",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 456,9/24/2015,8/27/2018,2015,ICSA-15-267-01,Endress+Hauser Fieldcare/CodeWrights HART Comm DTM XML Injection Vulnerability,"Endress+Hauser, CodeWrights GmbH",Fieldcare/CodeWrights HART Comm DTM,All HART DTM components relying on Fieldcare and a CodeWrights HART Comm DTM are affected.,CVE-2015-6463,8.3,High,CWE-91,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,"Germany, Switzerland",Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 455,8/25/2015,8/27/2018,2015,ICSA-15-237-02,EasyIO-30P-SF Hard-Coded Credential Vulnerability,EasyIO,EasyIO-30P-SF,EasyIO-30P-SF controllers versions affected: All EasyIO-30P-SF controllers running firmware prior to build v0.5.21 | All EasyIO-30P-SF controllers running firmware prior to build v2.0.5.21. The controller are used in a number of Direct Digital Control (DDC) controller associated with DDC systems from many users worldwide.,CVE-2015-3974,9.0,Critical,CWE-259,Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,"India, Malaysia, Asia, Europe",Malaysia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 454,8/25/2015,8/27/2018,2015,ICSA-15-237-02,EasyIO-30P-SF Hard-Coded Credential Vulnerability,EasyIO,EasyIO-30P-SF,EasyIO-30P-SF controllers versions affected: All EasyIO-30P-SF controllers running firmware prior to build v0.5.21 | All EasyIO-30P-SF controllers running firmware prior to build v2.0.5.21. The controller are used in a number of Direct Digital Control (DDC) controller associated with DDC systems from many users worldwide.,CVE-2015-3974,9.0,Critical,CWE-259,Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,"India, Malaysia, Asia, Europe",Singapore,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 453,8/25/2015,8/25/2015,2015,ICSA-15-237-02-Supplement,Supplement to ICSA-15-237-02 EasyIO-30P-SF Hard-Coded Credential Vulnerability,EasyIO,EasyIO-30P-SF,OEM Manufactures Accutrol LLC-Accutrol EASY IO-30P-SF45-AC7100.,CVE-2015-3974,9.0,Critical,CWE-255,Multiple Critical Sectors,Worldwide,Malaysia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 452,8/25/2015,8/25/2015,2015,ICSA-15-237-02-Supplement,Supplement to ICSA-15-237-02 EasyIO-30P-SF Hard-Coded Credential Vulnerability,EasyIO,EasyIO-30P-SF,OEM Manufactures Accutrol LLC-Accutrol EASY IO-30P-SF45-AC7100.,CVE-2015-3974,9.0,Critical,CWE-255,Multiple Critical Sectors,Worldwide,Singapore,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 451,9/22/2015,8/27/2018,2015,ICSA-15-265-01,Resource Data Management Privilege Escalation Vulnerability,Resource Data Management,Data Manager,Resource Data Management versions affected: Data Manager - Versions prior to 2.2.,"CVE-2015-6470, CVE-2015-6468",7.7,High,"CWE-352, CWE-269",Critical Manufacturing; Healthcare and Public Health; Information Technology,"United Kingdom, United States, Asia",United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 450,9/22/2015,8/27/2018,2015,ICSA-15-265-02,IBC Solar ServeMaster Source Code Vulnerability,IBC Solar,ServeMaster,IBC Solar ServeMaster TLP+ | Danfoss TLX Pro+.,"CVE-2015-6469, CVE-2015-6474, CVE-2015-6475",8.8,High,"CWE-200, CWE-79, CWE-256",Energy,"Austria, China, Czech Republic, Germany, Spain, France, United Kingdom, India, Italy, Japan, Malaysia, Netherlands, Poland, Portuga,l Romania, Turkey, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 449,8/20/2015,8/27/2018,2015,ICSA-15-232-01,Everest Software PeakHMI Pointer Dereference Vulnerabilities,Everest Software LLC,PeakHMI,Everest software LLC versions affected: of PeakHMI: PeakHMI versions prior to 8.7.0.2,CVE-2015-6454,5.0,Medium,CWE-822,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 448,9/17/2015,8/27/2018,2015,ICSA-15-260-01,Harman-Kardon Uconnect Vulnerability,"Harman-Kardon, Fiat-Chrysler Automobile US LLC",Uconnect,UConnect 8.4AN/RA3/RA4 infotainment systems versions affected: 2013-2015 Ram 1500/2500/3500/4500/5500 |2013-2015 Dodge Viper |2014/15 Jeep Cherokee/Gr | Cherokee |2014/15 Dodge Durango |2015 Chrysler 200/300 |2015 Dodge Challenger |2015 Dodge Charger | 2015 Jeep Renegade.,CVE-2015-5611,8.3,High,CWE-862,Transportation Systems,"United States, North America, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 447,9/15/2015,8/27/2018,2015,ICSA-15-258-01,Schneider Electric StruxureWare Building Expert Plaintext Credentials Vulnerability,Schneider Electric,StruxureWare Building Expert,Schneider Electric affected products versions of StruxureW Building Expert: StruxureW Building Expert | multi-purpose management device (MPM) versions prior to 2.15.,CVE-2015-3962,10.0,Critical,CWE-319,Commercial Facilities,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 446,9/15/2015,6/30/2022,2015,ICSA-15-258-02,CODESYS Gateway Server (Update A),CODESYS GmbH,CODESYS Gateway Server,"The following versions of CODESYS Gateway Server, a connection management server, are affected: --------- Begin Update A Part 1 of 2 --------- CODESYS Gateway Server: Version 2.3.9.33 and prior --------- End Update A Part 1 of 2 ---------.",CVE-2015-6460,7.5,High,CWE-122,Critical Manufacturing; Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 445,9/15/2015,8/27/2018,2015,ICSA-15-258-03,GE MDS PulseNET Vulnerabilities,GE,MDS PulseNET,GE versions affected: MDS PulseNET Enterpre | Version 3.1.3 | all prior versions | MDS PulseNET | Version 3.1.3 | all prior versions.,"CVE-2015-6456, CVE-2015-6459",9.2,Critical,"CWE-23, CWE-798",Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 444,9/15/2015,8/27/2018,2015,ICSA-15-258-04,Advantech WebAccess Stack-Based Buffer Overflow Vulnerability,Advantech,WebAccess,WebAccess versions affected: WebAccess Version 8.0 and prior versions.,CVE-2014-9202,6.9,Medium,CWE-121,Commercial Facilities; Critical Manufacturing; Energy; Government Facilities,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 443,9/10/2015,9/10/2015,2015,ICSA-15-253-01,Yokogawa Multiple Products Buffer Overflow Vulnerabilities,Yokogawa,Multiple Products,Yokogawa versions affected: CENTUM series: CENTUM CS 1000 (R3.08.70 or earlier) |CENTUM CS 3000 (R3.09.50 or earlier) |CENTUM CS 3000 Entry (R3.09.50 or earlier) |CENTUM VP (R5.04.20 or earlier) |CENTUM VP Entry (R5.04.20 or earlier) |ProSafe-RS (R3.02.10 or earlier) |Exaopc (R3.72.00 or earlier) |Exaquantum (R2.85.00 or earlier) |Exaquantum/Batch (R2.50.30 or earlier) |Exapilot (R3.96.10 or earlier) |Exaplog (R3.40.00 or earlier) |Exasmoc (R4.03.20 or earlier) |Exarqe (R4.03.20 or earlier) |Field Wireless Device OPC Server (R2.01.02 or earlier) |PRM (R3.12.00 or earlier) |STARDOM VDS (R7.30.01 or earlier) |STARDOM OPC Server for Windows (R3.40 or earlier) |FAST/TOOLS (R10.01 or earlier) |B/M9000CS (R5.05.01 or earlier) |B/M9000 VP (R7.03.04 or earlier) | FieldMate (R1.01 or R1.02).,"CVE-2015-5626, CVE-2015-5627, CVE-2015-5628",10.0,Critical,CWE-121,Chemical; Critical Manufacturing; Energy; Food and Agriculture,"Asia, East Asia, Europe, Africa, Middle East",Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 442,9/8/2015,8/27/2018,2015,ICSA-15-251-01A,Advantech WebAccess Buffer Overflow Vulnerability (Update A),Advantech,WebAccess,WebAccess versions affected: WebAccess | Version 8.0 and prior versions.,CVE-2014-9208,10.0,Critical,CWE-121,Commercial Facilities; Critical Manufacturing; Energy; Government Facilities,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 441,9/3/2015,8/27/2018,2015,ICSA-15-246-01,Cogent DataHub Code Injection Vulnerability,Cogent Real-Time Systems Inc,DataHub,Cogent DataHub versions affected: Cogent DataHub | Version 7.3.8 and earlier.,CVE-2014-3789,7.5,High,CWE-94,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Financial Services,"Canada, United Kingdom, United States",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 440,9/3/2015,8/27/2018,2015,ICSA-15-246-02,Schneider Electric Modicon PLC Vulnerabilities,Schneider Electric,Modicon PLC,Schneider Electric affected products versions of Modicon PLC: BMXNOC0401 |BMXNOE0100 |BMXNOE0110 |BMXNOE0110H |BMXNOR0200H |BMXP342020 |BMXP342020H |BMXP342030 |BMXP3420302 |BMXP3420302H | BMXP342030H.,CVE-2015-6462,3.2,Low,"CWE-98, CWE-79",Dams; Defense Industrial Base; Energy; Food and Agriculture; Government Facilities; Nuclear Reactors Materials and Waste; Transportation Systems; Water and Wastewater,"China, India, Russia, United States, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 439,9/3/2015,8/27/2018,2015,ICSA-15-246-03,Moxa Industrial Managed Switch Vulnerabilities,Moxa,Industrial Managed Switch,Moxa switches versions affected: Moxa EDS-405A/EDS-408A series managed Ethernet switches firmware Version V3.4 build 14031419 and prior.,"CVE-2015-6464, CVE-2015-6465, CVE-2015-6466",6.5,Medium,"CWE-79, CWE-269, CWE-400",Chemical; Commercial Facilities; Critical Manufacturing; Emergency Services; Energy; Food and Agriculture; Government Facilities; Water and Wastewater,"Argentina, Brazil, Chile, China, Germany, France, United Kingdom, India, Peru, Russia, Taiwan, United States, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 438,6/30/2015,8/27/2018,2015,ICSA-15-181-02A,SMA Solar Technology AG Sunny WebBox Hard-Coded Account Vulnerability (Update A),SMA Solar Technology AG,Sunny WebBox,Sunny WebBox versions affected: Sunny WebBox - All versions.,CVE-2015-3964,10.0,Critical,CWE-798,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 437,9/1/2015,8/27/2018,2015,ICSA-15-244-01,Siemens RUGGEDCOM ROS IP Forwarding Vulnerability,Siemens,RUGGEDCOM ROS,Siemens affected product versions of RUGGEDCOM ROS: All versions between 3.8.0 and 4.2.0. ROS on the following versions are affected: RMC products: RP110 and RS950G.,CVE-2015-6675,4.3,Medium,CWE-441,Energy; Healthcare and Public Health; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 436,8/27/2015,8/27/2018,2015,ICSA-15-239-01,Moxa SoftCMS Buffer Overflow Vulnerabilities,Moxa,SoftCMS,Moxa's SoftCMS versions affected: SoftCMS | Version 1.3 and prior versions.,"CVE-2015-6457, CVE-2015-6458",6.8,Medium,"CWE-120, CWE-122",Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,"Brazil, China, Germany, France, United Kingdom, India, Russia, Taiwan, United States, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 435,8/27/2015,8/27/2018,2015,ICSA-15-239-02,Siemens SIMATIC S7-1200 CSRF Vulnerability,Siemens,SIMATIC S7-1200,Siemens affected product versions of SIMATIC S7-1200: SIMATIC S7-1200 CPU family: All versions prior to V4.1.3,CVE-2015-5698,6.8,Medium,CWE-352,Chemical; Critical Manufacturing; Food and Agriculture,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 434,8/27/2015,8/27/2015,2015,ICSA-15-239-03,Innominate mGuard VPN Vulnerability,Innominate,mGuard VPN,mGuard versions affected: Innominate mGuard firmware | Version 8.0.0 to Version8.1.6.,CVE-2015-3966,7.8,High,CWE-272,Communications; Critical Manufacturing; Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 433,8/25/2015,8/27/2018,2015,ICSA-15-237-01,Endress+Hauser HART Device DTM Vulnerability,Endress+Hauser,HART Device DTM,The following products use the vulnerable HART DTM library and are affected:Cerabar M / PMx 4x / V1.0 ... 1.2 Cerabar M 5x / PMx 5x / V1.00.xx Cerabar S / PMx 7x / HART / FW 2.20.zz / Dev.Rev. 22 Cerabar S / PMx 7x / V01.00 Cerabar S / PMx 7x / V02.00 Cerabar S / PMx 7x / V02.10.xx Cerabar S / PMx x3x / V1.x Cerabar S / PMx x3x / V2.x Cerabar S / PMx x3x / V3.x Cerabar S / PMx x3x / V5.0 Cerabar S / PMx x3x / V7.1 Deltabar / FMD 7x / HART / FW 1.00.zz / Dev.Rev. 1Deltabar M 5x / PMD 55 / V1.00.xxDeltabar S / xMD 7x / HART / FW 2.20.zz / Dev.Rev. 22Deltabar S / xMD 7x / V01.00 Deltabar S / xMD 7x / V02.00 Deltabar S / xMD 7x / V02.10.xx Deltabar S / xMD x3x / V1.x Deltabar S / xMD x3x / V2.x Deltabar S / xMD x3x / V5.0 Deltabar S / xMD x3x / V7.1 Deltapilot M 5x / FMB 5x / V1.00.xx Deltapilot S / DB 5x / V1.x Deltapilot S / DB 5x / V2.0 Deltapilot S / FMB 70 / HART / FW 2.20.zz / Dev.Rev. 22 Deltapilot S / FMB 70 / V02.10.xx Gammapilot M / FMG 60 / HART / FW 1.04.zz / Dev.Rev. 3 Gammapilot M / FMG 60 / V01.xx Gammapilot M / FMG 60 / V02.xx iTemp / TMT 122 / V1.1 iTemp / TMT 142 / V1.03.00 iTemp / TMT 162 / V1.00.00 ... 1.02.00 iTemp / TMT 162 / V1.03.00 iTemp / TMT 182 / V1.1 iTEMP / TMT82 / HART / FW 1.00.zz / Dev.Rev. 1 Levelflex / FMP 2xx / V2.0 ... 2.1 Levelflex M / FMP 40 / V2.00 Levelflex M / FMP 4x / V4.xx Levelflex M Int / FMP 4x I / V1.08 Liquicap M / FMI 5x / 1.00.xx Liquicap M / FMI 5x / 1.03.xx Liquiline Cond / CM 42 / HART / FW 2.01.zz / Dev.Rev. 1 Liquiline M / CM44x / FW 1.02.zz / Dev.Rev. 1 Liquiline M Cci / CM 42 / HART / FW 13.06.zz / Dev.Rev. 10 Liquiline M Cci / CM 42 / HART / FW 13.07.zz / Dev.Rev. 11 Liquiline M Cci / CM 42 / V13.01.xx Liquiline M Cci / CM 42 / V13.04.07 Liquiline M Cci / CM 42 / V13.05.xx Liquiline M DO / CM 42 / HART / FW 20.04.zz / Dev.Rev. 17 Liquiline M DO / CM 42 / HART / FW 20.05.zz / Dev.Rev. 18 Liquiline M DO / CM 42 / V20.02.07Liquiline M DO / CM 42 / V20.02.xxLiquiline M DO / CM 42 / V20.03.xxLiquiline M pH-ORP / CM 42 / HART / FW 10.06.zz / Dev.Rev. 0D Liquiline M pH-ORP / CM 42 / HART / FW 10.07.zz / Dev.Rev. 0E Liquiline M pH-ORP / CM 42 / V10.02.xx Liquiline M pH-ORP / CM 42 / V10.04.07 Liquiline M pH-ORP / CM 42 / V10.04.xx Liquiline M pH-ORP / CM 42 / V10.05.xx Liquiline Oxygen / CM 42 / HART / FW 2.01.zz / Dev.Rev. 1Liquiline pHORP / CM 42 / HART / FW 2.01.zz / Dev.Rev. 1 Liquiport / CSPxx / HART / FW 01.02.zz / Dev.Rev.1 Liquistation / CSFxx / HART / FW 01.02.zz / Dev.Rev.1 Liquisys M Chlorine / CCM 2x3 / V2.30 Liquisys M Chlorine / CCM 2x3 / V2.35 Liquisys M Cond. C / CLM 2x3 / V2.30 Liquisys M Cond. I / CLM 2x3 / V2.30 Liquisys M DO / COM 2x3 / V2.40 Liquisys M PH / CPM 2x3 / V2.50 Liquisys M Turbidity / CUM 2x3 / V2.40 Micropilot I / FMR 13x / V1.4Micropilot I / FMR 13x / V1.5Micropilot I / FMR 13x / V2.0Micropilot I / FMR 13x / V2.1Micropilot II / FMR 23x / V2.0 Micropilot M / FMR 25x / V1.00 Micropilot M / FMR 25x / V4.xx Micropilot M / FMR 25x / V5.xx Micropilot M / FMR 2xx / V1.02 Micropilot M / FMR 2xx / V2.00 Micropilot M / FMR 2xx / V4.xx Micropilot S / FMR 53x / V1.02 Micropilot S / FMR 53x / V2.00 Micropilot S / FMR 53x / V3.00 Micropilot S / FMR 540 / V01.01.xx Multicap / FEC 12 / V1.0 ... 1.2 Mycom S Cond. C / CLM 153 / V1.20 Mycom S Cond. I / CLM 153 / V1.20 Mycom S PH / CPM 153 / V2.30 Mypro Cond. C / CLx 431 / V2.05 Mypro Cond. I / CLx 431 / V2.10 Mypro PH / CPM 431 / V2.02 Nivotester / FTC625 / V1.2 Omnigrad / TMD 832 / V1.1 ... 1.3 Omnigrad / TMD 833 / V1.0 ... 1.1 Omnigrad / TMD 842 / V1.1 ... 1.3 Promag / 10 / V1.00.00 ... V1.00.02 Promag / 10 / V1.01.00 Promag / 10 / V1.02.00 Promag / 10 / V1.03.00 Promag / 23 / V2.00.00 ... 2.01.00 Promag / 23 / V2.02.00 ... 2.03.00 Promag / 33 / V2.04.00 Promag / 35 S / V2.04.00 Promag / 39 / V2.04.00 Promag / 50 / HART / FW 2.04.zz / Dev.Rev. 9 Promag / 50 / V1.02.0x Promag / 50 / V1.04.0x Promag / 50 / V1.06.0x Promag / 50 / V2.00.00 Promag / 50 / V2.01.xx Promag / 50 / V2.02.xx Promag / 50 / V2.03.xx Promag / 51 / HART / FW 2.04.zz / Dev.Rev. 9 Promag / 51 / V1.04.0xPromag / 51 / V1.06.0xPromag / 51 / V2.00.0xPromag / 51 / V2.01.xxPromag / 51 / V2.02.xxPromag / 51 / V2.03.xxPromag / 53 / HART / FW 2.03.zz / Dev.Rev. 8 Promag / 53 / HART / FW 2.07.zz / Dev.Rev. 9 .Promag / 53 / V1.02.0xPromag / 53 / V1.04.0xPromag / 53 / V1.06.00Promag / 53 / V2.00.00Promag / 53 / V2.01.xxPromag / 53 / V2.02.xxPromag / 55 / HART / FW 1.03.zz / Dev.Rev. 4Promag / 55 / V1.00.xxPromag / 55 / V1.01.xxPromag / 55 / V1.02.xxPromass / 40 / V1.02.0x Promass / 40 / V1.04.0x Promass / 40 / V1.05.0x Promass / 40 / V1.06.0x Promass / 40 / V2.00.0x Promass / 40 / V2.01.0x Promass / 40 / V2.02.0x Promass / 40 / V3.01.0x Promass / 60 / V3.01.xx Promass / 60 / V3.02.xx Promass / 60 / V3.03.01 Promass / 63 / V2.02.xx Promass / 63 / V3.00.00 Promass / 63 / V3.02.00 Promass / 63 / V3.03.01 Promass / 80 / V1.02.0x Promass / 80 / V1.04.0x Promass / 80 / V1.05.0x Promass / 80 / V1.06.0x Promass / 80 / V2.00.0x Promass / 80 / V2.01.0x Promass / 80 / V2.02.0x Promass / 80 / V3.01.0x Promass / 83 / HART / FW 3.07.zz / Dev.Rev. 0A Promass / 83 / V1.02.0x Promass / 83 / V1.04.0x Promass / 83 / V1.05.0x Promass / 83 / V1.06.0x Promass / 83 / V2.00.0x Promass / 83 / V2.01.0x Promass / 83 / V2.02.0x Promass / 83 / V3.01.0x Promass / 84 / V2.00.0x Promass / 84 / V2.01.0x Promass / 84 / V2.02.0x Promass / 84 / V3.01.0x Proservo / NMS 530 / V1.0 Prosonic / FMU 860 / V2.1 Prosonic / FMU 860 / V2.2 ... 2.3 Prosonic / FMU 861 / V2.1 Prosonic / FMU 861 / V2.2 ... 2.3 Prosonic / FMU 862 / V2.1 Prosonic / FMU 862 / V2.2 ... 2.3 Prosonic Flow / 90 / V1.04.0x Prosonic Flow / 90 / V1.06.0x Prosonic Flow / 90 / V2.00.0x Prosonic Flow / 90 / V2.01.0x Prosonic Flow / 91 / HART / FW 1.02.zz / Dev.Rev. 3 Prosonic Flow / 91 / V1.00.xx Prosonic Flow / 91 / V1.01.xx Prosonic Flow / 92 / HART / FW 1.01.zz / Dev.Rev. 2 Prosonic Flow / 92 / V1.00.xxProsonic Flow / 93 / HART / FW 2.03.zz / Dev.Rev. 8 Prosonic Flow / 93 / V1.04.0xProsonic Flow / 93 / V1.05.0xProsonic Flow / 93 / V1.06.0xProsonic Flow / 93 / V2.00.0xProsonic Flow / 93 / V2.01.0xProsonic Flow / 93 / V2.02.0xProsonic Flow / DMU93 / V1.00.00 Prosonic Flow / DMU93 / V1.01.00 Prosonic M / FMU 4x / V2.00 Prosonic M / FMU 4x / V4.xx Prosonic S / FMU 90 / V2.00.xx Prosonic S / FMU 90 / V2.01.xx Prosonic S / FMU 9x / V01.00.xx Prosonic T / FMU x3x / V2.1 ... 2.2 Prothermo / NMT 539(1) / V1.0 Prothermo / NMT 539(2) / V1.0Prothermo / NMT539(1) / HART / FW 1.5z / Dev.Rev. 5 Prothermo / NMT539(2) / HART / FW 1.5z / Dev.Rev. 5 Prowirl / 70 / ... V1.1.01 Prowirl / 72 / HART / FW 1.06.zz / Dev.Rev. 7 Prowirl / 72 / V1.00.00 ... V1.01.01 Prowirl / 72 / V1.02.00 Prowirl / 72 / V1.03.00 Prowirl / 72 / V1.04.00 Prowirl / 72 / V1.05.00 Prowirl / 73 / HART / FW 1.06.zz / Dev.Rev. 7 Prowirl / 73 / V1.00.0xProwirl / 73 / V1.01.0xProwirl / 73 / V1.02.0xProwirl / 73 / V1.03.0xProwirl / 73 / V1.04.0xProwirl / 73 / V1.05.0xProwirl / 77 / ... V1.0.06 Smartec S / CLD 132 / V1.11 Tank Side Monitor / NRF 590 / V2.04.xx t-mass / 65 / V1.00.xxt-mass / 65 / V1.01.xxt-mass / 70 / V2.0 Waterpilot 2x / FMX 21 / V1.00.xx.,CVE-2014-9191,1.8,Low,CWE-20,Multiple Critical Sectors,"Germany, Switzerland",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 432,8/25/2015,8/27/2018,2015,ICSA-15-237-01,Endress+Hauser HART Device DTM Vulnerability,Endress+Hauser,HART Device DTM,The following products use the vulnerable HART DTM library and are affected:Cerabar M / PMx 4x / V1.0 ... 1.2 Cerabar M 5x / PMx 5x / V1.00.xx Cerabar S / PMx 7x / HART / FW 2.20.zz / Dev.Rev. 22 Cerabar S / PMx 7x / V01.00 Cerabar S / PMx 7x / V02.00 Cerabar S / PMx 7x / V02.10.xx Cerabar S / PMx x3x / V1.x Cerabar S / PMx x3x / V2.x Cerabar S / PMx x3x / V3.x Cerabar S / PMx x3x / V5.0 Cerabar S / PMx x3x / V7.1 Deltabar / FMD 7x / HART / FW 1.00.zz / Dev.Rev. 1Deltabar M 5x / PMD 55 / V1.00.xxDeltabar S / xMD 7x / HART / FW 2.20.zz / Dev.Rev. 22Deltabar S / xMD 7x / V01.00 Deltabar S / xMD 7x / V02.00 Deltabar S / xMD 7x / V02.10.xx Deltabar S / xMD x3x / V1.x Deltabar S / xMD x3x / V2.x Deltabar S / xMD x3x / V5.0 Deltabar S / xMD x3x / V7.1 Deltapilot M 5x / FMB 5x / V1.00.xx Deltapilot S / DB 5x / V1.x Deltapilot S / DB 5x / V2.0 Deltapilot S / FMB 70 / HART / FW 2.20.zz / Dev.Rev. 22 Deltapilot S / FMB 70 / V02.10.xx Gammapilot M / FMG 60 / HART / FW 1.04.zz / Dev.Rev. 3 Gammapilot M / FMG 60 / V01.xx Gammapilot M / FMG 60 / V02.xx iTemp / TMT 122 / V1.1 iTemp / TMT 142 / V1.03.00 iTemp / TMT 162 / V1.00.00 ... 1.02.00 iTemp / TMT 162 / V1.03.00 iTemp / TMT 182 / V1.1 iTEMP / TMT82 / HART / FW 1.00.zz / Dev.Rev. 1 Levelflex / FMP 2xx / V2.0 ... 2.1 Levelflex M / FMP 40 / V2.00 Levelflex M / FMP 4x / V4.xx Levelflex M Int / FMP 4x I / V1.08 Liquicap M / FMI 5x / 1.00.xx Liquicap M / FMI 5x / 1.03.xx Liquiline Cond / CM 42 / HART / FW 2.01.zz / Dev.Rev. 1 Liquiline M / CM44x / FW 1.02.zz / Dev.Rev. 1 Liquiline M Cci / CM 42 / HART / FW 13.06.zz / Dev.Rev. 10 Liquiline M Cci / CM 42 / HART / FW 13.07.zz / Dev.Rev. 11 Liquiline M Cci / CM 42 / V13.01.xx Liquiline M Cci / CM 42 / V13.04.07 Liquiline M Cci / CM 42 / V13.05.xx Liquiline M DO / CM 42 / HART / FW 20.04.zz / Dev.Rev. 17 Liquiline M DO / CM 42 / HART / FW 20.05.zz / Dev.Rev. 18 Liquiline M DO / CM 42 / V20.02.07Liquiline M DO / CM 42 / V20.02.xxLiquiline M DO / CM 42 / V20.03.xxLiquiline M pH-ORP / CM 42 / HART / FW 10.06.zz / Dev.Rev. 0D Liquiline M pH-ORP / CM 42 / HART / FW 10.07.zz / Dev.Rev. 0E Liquiline M pH-ORP / CM 42 / V10.02.xx Liquiline M pH-ORP / CM 42 / V10.04.07 Liquiline M pH-ORP / CM 42 / V10.04.xx Liquiline M pH-ORP / CM 42 / V10.05.xx Liquiline Oxygen / CM 42 / HART / FW 2.01.zz / Dev.Rev. 1Liquiline pHORP / CM 42 / HART / FW 2.01.zz / Dev.Rev. 1 Liquiport / CSPxx / HART / FW 01.02.zz / Dev.Rev.1 Liquistation / CSFxx / HART / FW 01.02.zz / Dev.Rev.1 Liquisys M Chlorine / CCM 2x3 / V2.30 Liquisys M Chlorine / CCM 2x3 / V2.35 Liquisys M Cond. C / CLM 2x3 / V2.30 Liquisys M Cond. I / CLM 2x3 / V2.30 Liquisys M DO / COM 2x3 / V2.40 Liquisys M PH / CPM 2x3 / V2.50 Liquisys M Turbidity / CUM 2x3 / V2.40 Micropilot I / FMR 13x / V1.4Micropilot I / FMR 13x / V1.5Micropilot I / FMR 13x / V2.0Micropilot I / FMR 13x / V2.1Micropilot II / FMR 23x / V2.0 Micropilot M / FMR 25x / V1.00 Micropilot M / FMR 25x / V4.xx Micropilot M / FMR 25x / V5.xx Micropilot M / FMR 2xx / V1.02 Micropilot M / FMR 2xx / V2.00 Micropilot M / FMR 2xx / V4.xx Micropilot S / FMR 53x / V1.02 Micropilot S / FMR 53x / V2.00 Micropilot S / FMR 53x / V3.00 Micropilot S / FMR 540 / V01.01.xx Multicap / FEC 12 / V1.0 ... 1.2 Mycom S Cond. C / CLM 153 / V1.20 Mycom S Cond. I / CLM 153 / V1.20 Mycom S PH / CPM 153 / V2.30 Mypro Cond. C / CLx 431 / V2.05 Mypro Cond. I / CLx 431 / V2.10 Mypro PH / CPM 431 / V2.02 Nivotester / FTC625 / V1.2 Omnigrad / TMD 832 / V1.1 ... 1.3 Omnigrad / TMD 833 / V1.0 ... 1.1 Omnigrad / TMD 842 / V1.1 ... 1.3 Promag / 10 / V1.00.00 ... V1.00.02 Promag / 10 / V1.01.00 Promag / 10 / V1.02.00 Promag / 10 / V1.03.00 Promag / 23 / V2.00.00 ... 2.01.00 Promag / 23 / V2.02.00 ... 2.03.00 Promag / 33 / V2.04.00 Promag / 35 S / V2.04.00 Promag / 39 / V2.04.00 Promag / 50 / HART / FW 2.04.zz / Dev.Rev. 9 Promag / 50 / V1.02.0x Promag / 50 / V1.04.0x Promag / 50 / V1.06.0x Promag / 50 / V2.00.00 Promag / 50 / V2.01.xx Promag / 50 / V2.02.xx Promag / 50 / V2.03.xx Promag / 51 / HART / FW 2.04.zz / Dev.Rev. 9 Promag / 51 / V1.04.0xPromag / 51 / V1.06.0xPromag / 51 / V2.00.0xPromag / 51 / V2.01.xxPromag / 51 / V2.02.xxPromag / 51 / V2.03.xxPromag / 53 / HART / FW 2.03.zz / Dev.Rev. 8 Promag / 53 / HART / FW 2.07.zz / Dev.Rev. 9 .Promag / 53 / V1.02.0xPromag / 53 / V1.04.0xPromag / 53 / V1.06.00Promag / 53 / V2.00.00Promag / 53 / V2.01.xxPromag / 53 / V2.02.xxPromag / 55 / HART / FW 1.03.zz / Dev.Rev. 4Promag / 55 / V1.00.xxPromag / 55 / V1.01.xxPromag / 55 / V1.02.xxPromass / 40 / V1.02.0x Promass / 40 / V1.04.0x Promass / 40 / V1.05.0x Promass / 40 / V1.06.0x Promass / 40 / V2.00.0x Promass / 40 / V2.01.0x Promass / 40 / V2.02.0x Promass / 40 / V3.01.0x Promass / 60 / V3.01.xx Promass / 60 / V3.02.xx Promass / 60 / V3.03.01 Promass / 63 / V2.02.xx Promass / 63 / V3.00.00 Promass / 63 / V3.02.00 Promass / 63 / V3.03.01 Promass / 80 / V1.02.0x Promass / 80 / V1.04.0x Promass / 80 / V1.05.0x Promass / 80 / V1.06.0x Promass / 80 / V2.00.0x Promass / 80 / V2.01.0x Promass / 80 / V2.02.0x Promass / 80 / V3.01.0x Promass / 83 / HART / FW 3.07.zz / Dev.Rev. 0A Promass / 83 / V1.02.0x Promass / 83 / V1.04.0x Promass / 83 / V1.05.0x Promass / 83 / V1.06.0x Promass / 83 / V2.00.0x Promass / 83 / V2.01.0x Promass / 83 / V2.02.0x Promass / 83 / V3.01.0x Promass / 84 / V2.00.0x Promass / 84 / V2.01.0x Promass / 84 / V2.02.0x Promass / 84 / V3.01.0x Proservo / NMS 530 / V1.0 Prosonic / FMU 860 / V2.1 Prosonic / FMU 860 / V2.2 ... 2.3 Prosonic / FMU 861 / V2.1 Prosonic / FMU 861 / V2.2 ... 2.3 Prosonic / FMU 862 / V2.1 Prosonic / FMU 862 / V2.2 ... 2.3 Prosonic Flow / 90 / V1.04.0x Prosonic Flow / 90 / V1.06.0x Prosonic Flow / 90 / V2.00.0x Prosonic Flow / 90 / V2.01.0x Prosonic Flow / 91 / HART / FW 1.02.zz / Dev.Rev. 3 Prosonic Flow / 91 / V1.00.xx Prosonic Flow / 91 / V1.01.xx Prosonic Flow / 92 / HART / FW 1.01.zz / Dev.Rev. 2 Prosonic Flow / 92 / V1.00.xxProsonic Flow / 93 / HART / FW 2.03.zz / Dev.Rev. 8 Prosonic Flow / 93 / V1.04.0xProsonic Flow / 93 / V1.05.0xProsonic Flow / 93 / V1.06.0xProsonic Flow / 93 / V2.00.0xProsonic Flow / 93 / V2.01.0xProsonic Flow / 93 / V2.02.0xProsonic Flow / DMU93 / V1.00.00 Prosonic Flow / DMU93 / V1.01.00 Prosonic M / FMU 4x / V2.00 Prosonic M / FMU 4x / V4.xx Prosonic S / FMU 90 / V2.00.xx Prosonic S / FMU 90 / V2.01.xx Prosonic S / FMU 9x / V01.00.xx Prosonic T / FMU x3x / V2.1 ... 2.2 Prothermo / NMT 539(1) / V1.0 Prothermo / NMT 539(2) / V1.0Prothermo / NMT539(1) / HART / FW 1.5z / Dev.Rev. 5 Prothermo / NMT539(2) / HART / FW 1.5z / Dev.Rev. 5 Prowirl / 70 / ... V1.1.01 Prowirl / 72 / HART / FW 1.06.zz / Dev.Rev. 7 Prowirl / 72 / V1.00.00 ... V1.01.01 Prowirl / 72 / V1.02.00 Prowirl / 72 / V1.03.00 Prowirl / 72 / V1.04.00 Prowirl / 72 / V1.05.00 Prowirl / 73 / HART / FW 1.06.zz / Dev.Rev. 7 Prowirl / 73 / V1.00.0xProwirl / 73 / V1.01.0xProwirl / 73 / V1.02.0xProwirl / 73 / V1.03.0xProwirl / 73 / V1.04.0xProwirl / 73 / V1.05.0xProwirl / 77 / ... V1.0.06 Smartec S / CLD 132 / V1.11 Tank Side Monitor / NRF 590 / V2.04.xx t-mass / 65 / V1.00.xxt-mass / 65 / V1.01.xxt-mass / 70 / V2.0 Waterpilot 2x / FMX 21 / V1.00.xx.,CVE-2014-9191,1.8,Low,CWE-20,Multiple Critical Sectors,"Germany, Switzerland",Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 431,8/13/2015,8/13/2015,2015,ICSA-15-225-01,OSIsoft PI Data Archive Server Vulnerabilities,OSIsoft,PI Data Archive Server,OSoft versions affected: All versions of the PI Data Archive prior to Version 3.4.395.64.,CVE-NA,5.4,Medium,"CWE-250, CWE-200, CWE-20, CWE-476, CWE-384, CWE-400",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 430,8/11/2015,8/27/2018,2015,ICSA-15-223-01,Schneider Electric IMT25 DTM Vulnerability,Schneider Electric,IMT25 DTM,Schneider Electric IMT25 Magnetic Flow DTM versions affected: IMT25 Magnetic Flow DTM | Version 1.500.000 and all previous versions.,CVE-2015-3977,7.7,High,CWE-119,Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,"United States, Asia, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 429,7/30/2015,8/27/2018,2015,ICSA-15-211-01,Schneider Electric InduSoft Web Studio and InTouch Machine Edition 2014 Password Storage Vulnerability,Schneider Electric,InduSoft Web Studio and InTouch Machine Edition 2014,Schneider Electric affected products: InduSoft Web Studio | Version 7.1.3.4 and all previous versions. InTouch Machine Edition 2014 | Version 7.1 Service Pack 3 | Patch 4 and all previous versions.,CVE-2015-1009,6.4,Medium,CWE-312,Commercial Facilities; Energy; Food and Agriculture; Information Technology,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 428,7/21/2015,8/27/2018,2015,ICSA-15-202-01,Siemens SIPROTEC Denial-of-Service Vulnerability,Siemens,SIPROTEC,Siemens product versions affected: SIPROTEC 4 | SIPROTEC Compact product families. All devices that include the EN100 Ethernet module version V4.24 or prior.,CVE-2015-5374,7.8,High,CWE-400,Energy,"Germany, Russia",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 427,7/21/2015,8/27/2018,2015,ICSA-15-202-02,Siemens Sm@rtClient Password Storage Vulnerability,Siemens,Sm@rtClient,Siemens SIMATIC WinCC Sm@rtClient: SIMATIC WinCC Sm@rtClient for Android: All versions prior to V01.00.01.00 | SIMATIC WinCC Sm@rtClient Lite for Android: All versions prior to V01.00.01.00.,CVE-2015-5084,2.1,Low,CWE-522,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 426,7/21/2015,8/27/2018,2015,ICSA-15-202-03B,Siemens RUGGEDCOM ROS and ROX-based Devices TLS POODLE Vulnerability (Update B),Siemens,RUGGEDCOM ROS and ROX-based Devices TLS,Siemens RUGGEDCOM ROS versions affected: RUGGEDCOM devices with ROS: All firmware versions prior to v4.2.0 | RUGGEDCOM devices with ROX II: All firmware versions prior to v2.9.0.Note - ROX I devices not affected.,CVE-2015-5537,4.3,Medium,CWE-310,Energy; Healthcare and Public; Health; Transportation Systems,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 425,6/23/2015,8/27/2018,2015,ICSA-15-174-01,Hospira Symbiq Infusion System Vulnerability,Hospira,Symbiq Infusion System,Symbiq Infusion System versions affected: Symbiq Infusion System | Version 3.13 and prior versions.,CVE-2015-3965,7.1,High,CWE-749,Healthcare and Public Health,"Canada, United States",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 424,1/6/2015,8/27/2018,2015,ICSA-15-006-01,Eaton's Cooper Power Series Form 6 Control and Idea/IdeaPlus Relays with Ethernet Vulnerability,Eaton'S Cooper Power Systems,Form 6 Control and Idea/IdeaPlus Relays,Eaton's Cooper Power Systems versions affected: All versions of Eaton's Cooper Power Series Form 6 control | Idea/IdeaPLUS relays with Ethernet with Pro View 4.0 through Pro View 5.0 software.,CVE-2014-9196,7.6,High,CWE-342,Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 423,7/14/2015,8/27/2018,2015,ICSA-15-195-01,Siemens SICAM MIC Authentication Bypass Vulnerability,Siemens,SICAM MIC,Siemens SICAM MIC: SICAM MIC: All versions prior to V2404.,CVE-2015-5386,8.3,High,CWE-592,Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 422,6/25/2015,8/27/2018,2015,ICSA-15-176-01,Siemens Climatix BACnet/IP Communication Module Cross-site Scripting Vulnerability,Siemens,Climatix BACnet/IP Communication Module,Siemens affected version: Climatix BACnet/IP communication module: All versions prior to V10.34.,CVE-2015-4174,4.3,Medium,CWE-79,Commercial Facilities,"United States, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 421,6/25/2015,8/27/2018,2015,ICSA-15-176-02,PACTware Exceptional Conditions Vulnerability,PACTware Consortium,PACTware,PACTw versions affected: PACTw Version 4.1 | Service Pack 3.,CVE-2015-0989,1.2,Low,CWE-703,Chemical; Critical Manufacturing; Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 420,6/18/2015,2/4/2016,2015,ICSA-15-169-01B,Wind River VXWorks TCP Predictability Vulnerability in ICS Devices (Update B),Wind River,VXWorks,VxWorks version affected: Wind River VxWorks | Version 7 | released prior to February 13 | 2015 | Wind River VxWorks | Version 6.9 releases prior to Version 6.9.4.4 | Wind River VxWorks | Version 6.8 releases prior to Version 6.8.3 | Wind River VxWorks | Version 6.7 releases prior to Version 6.7.1.1 | and Wind River VxWorks | Version 6.6 and prior versions but NOT to include Version 5.5.1 with PNE2.2 and Version 6.0 through Version 6.4.The following versions of VxWorks Cert are affected: Wind River VxWorks Cert | Version 6.6.3 | Wind River VxWorks Cert | Version 6.6.4 | and Wind River VxWorks Cert | Version 6.6.4.1. The following versions of VxWorks 653 are affected: Wind River VxWorks 653 Platform/Platform for Safety Critical ARINC 653 | Version 3.0 | Wind River VxWorks 653 Platform/Platform for Safety Critical ARINC 653 | Version 2.5 |Wind River VxWorks 653 Platform/Platform for Safety Critical ARINC 653 | Version 2.4 | Wind River VxWorks 653 Platform/Platform for Safety Critical ARINC 653 | Version 2.3 | and Wind River VxWorks 653 Platform/Platform for Safety Critical ARINC 653 | Version 2.2. Wind River's VxWorks is widely used in ICS-related devices. The following Schneider Electric SAGE RTUs which use CPU card C3412 are affected: Schneider Electric SAGE 1210 RTU | Schneider Electric SAGE 1230 RTU | Schneider Electric SAGE 1250 RTU | Schneider Electric SAGE 2200 RTU. The following Schneider Electric SAGE RTUs which use CPU card C3413 are affected: Schneider Electric SAGE 1310 RTU |Schneider Electric SAGE 1330 RTU | Schneider Electric SAGE 1350 RTU | Schneider Electric SAGE 2300 RTU | and Schneider Electric SAGE 3030 RTU.The following Schneider Electric SAGE RTUs | which use CPU card C3414 LX-800 with firmware versions prior to C3414-500-S02J2 are affected:Schneider Electric SAGE 1410 RTU |Schneider Electric SAGE 1430 RTU | Schneider Electric SAGE 1450 RTU |Schneider Electric SAGE 2400 RTU | Schneider Electric SAGE 3030 Magnum RTU | and Schneider Electric SAGE LANDAC2 Upgrade Kit.,CVE-2015-3963,5.8,Medium,CWE-343,Communications; Critical Manufacturing; Energy; Healthcare and Public Health; Transportation Systems;; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 419,6/18/2015,6/18/2015,2015,ICSA-15-169-02,Schneider Electric Wonderware System Platform Vulnerabilities,Schneider Electric,Wonderware System Platform,Schneider Electric version versions affected: Wonderware System Platform 2014 R2 and prior versions.,CVE-2015-3940,7.2,High,CWE-427,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 418,6/16/2015,8/27/2018,2015,ICSA-15-167-01,GarrettCom Magnum Series Devices Vulnerabilities,GarrettCom,Magnum Series Devices,GarrettCom versions affected: Magnum 6K product line and all versions prior to 4.5.6 | Magnum 10K product line and all versions prior to 4.5.6.,"CVE-2015-3942, CVE-2015-3960, CVE-2015-3959, CVE-2015-3961",5.0,Medium,"CWE-79, CWE-472, CWE-798",Critical Manufacturing; Defense Industrial Base; Energy; Transportation Systems; Water and Wastewater,"United States, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 417,6/11/2015,8/27/2018,2015,ICSA-15-162-01A,RLE Nova-Wind Turbine HMI Unsecure Credentials Vulnerability (Update A),RLE Nova-Wind,Turbine HMI,RLE International GmbH product versions affected: Nova-Wind Turbine HMI,CVE-2015-3951,10.0,Critical,CWE-256,Energy,"Germany, United Kingdom, India, Sweden, United States",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 416,6/10/2015,8/23/2018,2015,ICSA-15-161-01,Hospira Plum A+ and Symbiq Infusion Systems Vulnerabilities,Hospira,Plum A+ and Symbiq Infusion Systems,Hospira product versions affected: Plum A+ Infusion System | Version 13.4 and prior versions |Plum A+3 Infusion System | Version 13.6 and prior versions | Symbiq Infusion System |a Version 3.13 and prior versions.,"CVE-2015-3955, CVE-2015-3954, CVE-2015-3956, CVE-2015-3953, CVE-2015-3952, CVE-2015-3957, CVE-2015-3958",7.7,High,"CWE-312, CWE-285, CWE-345, CWE-320, CWE-121, CWE-400, CWE-259",Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 415,5/5/2015,8/23/2018,2015,ICSA-15-125-01B,Hospira LifeCare PCA Infusion System Vulnerabilities (Update B),Hospira,LifeCare PCA Infusion System,LifeC PCA Infusion System | Version 5.0 and prior versions.,"CVE-2015-3955, CVE-2015-3459, CVE-2014-5406, CVE-2015-1011, CVE-2015-1012, CVE-2015-3957, CVE-2015-3958",7.7,High,"CWE-312, CWE-285, CWE-345, CWE-320, CWE-121, CWE-400, CWE-259",Healthcare and Public Health,"Canada, United States",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 414,6/9/2015,8/27/2018,2015,ICSA-15-160-02,Sinapsi eSolar Light Plaintext Passwords Vulnerability,Sinapsi,eSolar Light,Sinapsi eSolar Light versions affected: Sinapsi eSolar Light firmware versions prior to 2.0.3970_schsl_2.2.85.,CVE-2015-3949,7.2,High,CWE-256,Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,Worldwide,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 413,6/9/2015,8/27/2018,2015,ICSA-15-160-01A,N-Tron 702W Hard-Coded SSH and HTTPS Encryption Keys (Update A),N-Tron,702W,N-Tron 702-W Industrial Wireless Access Point | all versions.,CVE-2012-4716,10.0,Critical,CWE-321,"Commercial Facilities; Energy; Nuclear Reactors, Materials, and Waste; Transportation Systems;; Water and Wastewater","Canada, China, United Kingdom, India, Switzerland",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 412,6/4/2015,8/27/2018,2015,ICSA-15-155-01,XZERES 442SR Wind Turbine CSRF Vulnerability,XZERES,442SR Wind Turbine,XZERES product versions affected: 442SR Wind Turbine.,CVE-2015-3950,9.0,Critical,CWE-352,Energy,"United Kingdom, Italy, Japan, Myanmar, Philippines, Vietnam",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 411,6/2/2015,8/27/2018,2015,ICSA-15-153-01,Beckwith Electric TCP Initial Sequence Vulnerability,Beckwith Electric,TCP Initial Sequence,M-6200 Digital Voltage Regulator Control | firmware versions prior to Version D-0198V04.07.00 | M-6200A Digital Voltage Regulator Control | firmware versions prior to Version D-0228V02.01.07 | M-2001D Digital Tapchanger Control | firmware versions prior to Version D-0214V01.10.04 | M-6283A Three Phase Digital Capacitor Bank Control | firmware versions prior to Version D-0346V03.00.02 | M-6280A Digital Capacitor Bank Control | firmware versions prior to Version D-0254V03.05.05 | M-6280 Digital Capacitor Bank Control | all firmware versions.,CVE-2014-9201,5.8,Medium,CWE-342,Energy,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 410,6/2/2015,8/27/2018,2015,ICSA-15-153-02,Moxa SoftCMS Buffer Overflow Vulnerability,Moxa,SoftCMS,Moxa's SoftCMS versions affected: SoftCMS | Version 1.2 and prior versions.,CVE-2015-1000,7.5,High,CWE-121,Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,"Brazil, China, Germany, France, United Kingdom, India, Russia, Taiwan, United States, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 409,5/28/2015,8/27/2018,2015,ICSA-15-148-01,IDS RTU 850 Directory Traversal Vulnerability,IDS,RTU 850,IDS communications modules in the IDS 850 family versions affected: NC854 | NC856.,CVE-2015-3939,8.5,High,CWE-22,Communications; Energy; Water and Wastewater,"Czech Republic, Iran, Morocco, Romania, Switzerland",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 408,5/12/2015,8/27/2018,2015,ICSA-15-132-02,Rockwell Automation RSView32 Weak Encryption Algorithm on Passwords,Rockwell Automation,RSView32,RSView32 versions affected: RSView32 - 7.60.00 (CPR9 SR4) and all prior versions.,CVE-2015-1010,6.0,Medium,CWE-257,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 407,5/21/2015,7/14/2015,2015,ICSA-15-141-01A,Schneider Electric OFS Server Vulnerability (Update A),Schneider Electric,OFS Server,OPC Factory Server versions affected: OPC Factory Server (OSF) Version 3.5 and all previous versions.,CVE-2015-1014,6.6,Medium,CWE-427,Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 406,4/21/2015,8/27/2018,2015,ICSA-15-111-01,Emerson AMS Device Manager SQL Injection Vulnerability,Emerson,AMS Device Manager,Emerson affected product: AMS Device Manager | V12.5 and earlier.,CVE-2015-1008,4.3,Medium,CWE-89,Chemical; Energy; oil and gas,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 405,7/21/2014,8/27/2018,2015,ICSA-14-202-01A,OleumTech WIO Family Vulnerabilities (Update A),OleumTech,WIO Family,OleumTech WIO DH2 Wireless Gateway andAll OleumTech Sensor Wireless I/O Modules versions,"CVE-2014-2360, CVE-2014-2361, CVE-2014-2362",6.7,Medium,"CWE-20, CWE-320, CWE-338",Energy; Water and Wastewater,"Canada, United States",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 404,5/12/2015,8/27/2018,2015,ICSA-15-132-01,OSIsoft PI AF Incorrect Default Permissions Vulnerability,OSIsoft,PI AF,OSoft versions affected: PI AF 2.6 new installs |PI AF 2.7 upgrade | PI SQL for AF 2.1.,CVE-2015-1013,6.5,Medium,CWE-276,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 403,4/21/2015,8/27/2018,2015,ICSA-15-111-02,Rockwell Automation RSLinx Classic Vulnerability,Rockwell Automation,RSLinx Classic,RSLinx Classic versions affected: RSLinx Classic and all versions prior to Version 3.73.00.,CVE-2014-9204,5.9,Medium,CWE-121,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 402,4/30/2015,10/18/2018,2015,ICSA-15-120-01,Opto 22 Multiple Product Vulnerabilities,Opto 22,Multiple Products,Opto 22 products versions affected: PAC Project Professional and versions prior to Version R9.4006 |PAC Project Basic and versions prior to Version R9.4006 |PAC Dplay Basic and versions prior to Version R9.4f |PAC Dplay Professional and versions prior to Version R9.4f |OptoOPCServer and versions prior to Version R9.4c | OptoDataLink | Version R9.4d and prior versions that were installed by PAC Project installer and versions prior to Version R9.4006. Opto 22 that contain the Stack-buffer overflow vulnerability in OPCTest.exe: PAC Project Professional and versions prior to Version R9.4008 |PAC Project Basic and versions prior to Version R9.4008 |PAC Dplay Basic and versions prior to Version R9.4g |PAC Dplay Professional and versions prior to Version R9.4g |OptoOPCServer | Version R9.4c and prior versions that were installed by PAC Project installer and versions prior to Version R9.4008 | OptoDataLink | Version R9.4d and prior versions that were installed by PAC Project installer and versions prior to Version R9.4008.,"CVE-2015-1006, CVE-2015-1007",7.6,High,"CWE-122, CWE-121",Multiple Critical Sectors,North America,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 401,4/9/2015,8/27/2018,2015,ICSA-15-099-01E,Siemens SIMATIC HMI Devices Vulnerabilities (Update E),Siemens,SIMATIC HMI Devices,Siemens SIMATIC products: SIMATIC HMI Basic Panels 2nd Generation: V13: All versions < WinCC (TIA Portal) V13 SP1 Upd2 SIMATIC HMI Comfort Panels:V12: All versions < WinCC (TIA Portal) V12 SP1 Upd5V13: All versions < WinCC (TIA Portal) V13 SP1 Upd2 SIMATIC WinCC Runtime Advanced: V12: All versions < WinCC Runtime Advanced V12 SP1 Upd5V13: All versions < WinCC Runtime Advanced V13 SP1 Upd2 SIMATIC WinCC Runtime Professional: V13: All versions < WinCC (TIA Portal) V13 SP1 Upd2 SIMATIC HMI Basic Panels 1st Generation (WinCC TIA Portal): V12: All versions < WinCC (TIA Portal) V12 SP1 Upd5 V13: All versions < WinCC (TIA Portal) V13 SP1 Upd4 SIMATIC HMI Mobile Panel 277 (WinCC TIA Portal): V12: All versions < WinCC (TIA Portal) V12 SP1 Upd5V13: All versions < WinCC (TIA Portal) V13 SP1 Upd4 SIMATIC HMI Multi Panels (WinCC TIA Portal):V12: All versions < WinCC (TIA Portal) V12 SP1 Upd5V13: All versions < WinCC (TIA Portal) V13 SP1 Upd4 SIMATIC NET PC-Software V12 and V13: SIMATIC NET PC-Software V12: All versions < V12 SP2 HF3 SIMATIC NET PC-Software V13: All versions < V13 HF1 SIMATIC WinCC V7.X: All versions prior to V7.2V7.2: All version < V7.2 Upd11V7.3: All versions < V7.3 Upd4 and SIMATIC PCS 7: All versions prior to V8.1 SP1.,"CVE-2015-1601, CVE-2015-2822, CVE-2015-2823",6.6,Medium,"CWE-300, CWE-400, CWE-836",Chemical; Energy; Food and Agriculture; Water and Wastewater,"United States, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 400,3/5/2015,8/27/2018,2015,ICSA-15-064-01A,"Siemens SIMATIC HMI Basic, SINUMERIK, and Ruggedcom APE GHOST Vulnerability (Update A)",Siemens,SIMATIC HMI Basic | SINUMERIK | Ruggedcom APE,SINUMERIK | SIMATIC HMI Basic versions affected: SINUMERIK 808D | 828D | 840D sl | all versions up to 4.7 | SIMATIC HMI Basic Panels 2nd Generation. Ruggedcom APE versions are not vulnerable in their default configuration but can become exploitable depending on components installed in the user configuration: Ruggedcom APE: APE1402-XX | APE1402-C01 | APE1404-XX | APE1404-C01 | all versions.,CVE-2015-0235,4.6,Medium,CWE-20,Chemical; Energy; Food and Agriculture; Water and Wastewater,"United States, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 399,3/5/2015,8/27/2018,2015,ICSA-15-064-02A,"Siemens SIMATIC ProSave, SIMATIC CFC, SIMATIC STEP 7, SIMOTION Scout, and STARTER Insufficiently Qualified Paths (Update A)",Siemens,"SIMATIC ProSave, SIMATIC CFC, SIMATIC STEP 7, SIMOTION Scout, and STARTER",Siemens product versions affected: SIMATIC ProSave: All versions prior to V13 SP1SIMOTION Scout: All versions prior to V4.4STARTER: All versions prior to V4.4 HF3SIMATIC CFC: All versions prior to V8.0 SP4CFC V8.0 SP4: All versions prior to V8.0 SP4 Upd 9CFC V8.1: All versions prior to V8.1 Upd1 | SIMATIC STEP 7 V5.5: All versions prior to V5.5 SP1STEP 7 V5.5 SP1: All versions prior to V5.5 SP1 HF2STEP 7 V5.5 SP2: All versions prior to V5.5 SP2 HF7STEP 7 V5.5 SP36: All versions prior to V5.5 SP3 HF10STEP 7 V5.5 SP4: All versions prior to V5.5 SP4 HF4SIMATIC PCS 7 (as STEP 7 | CFC incorporated): All versions prior to V8.0 SP2PCS 7 V8.0 SP2: All versions prior to V8.0 SP2 with STEP 7 V5.5 SP3 HF10 | CFC V8.0 SP4 Upd9 PCS 7 V8.1: All versions prior to V8.1 with STEP 7 SP4 HF4 | CFC V8.1 Upd1.,CVE-2015-1594,6.9,Medium,CWE-226,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 398,4/7/2015,8/27/2018,2015,ICSA-15-097-01,Moxa VPort ActiveX SDK Plus Stack-Based Buffer Overflow Vulnerability,Moxa,VPort ActiveX SDK Plus,Moxa VPort ActiveX SDK (all versions prior to Version 2.8) versions affected: MxNVR-MO4 Series | VPort 26A-1MP Series | VPort 351 | VPort 354 | VPort 36-1MP Series | VPort 364A Series | VPort 451 | VPort 461 | VPort 56-2MP Series | VPort P06-1MP-M12 | VPort P06HC-1MP-M12 Series | VPort P16-1MP-M12 Series | VPort P16-1MP-M12-IR Series.,CVE-2015-0986,7.5,High,CWE-121,Chemical; Commercial Facilities; Communications; Critical Manufacturing; Dams; Defense Industrial Base; Emergency Services; Energy; Financial Services; Government Facilities; Healthcare and Public Health; Information Technology; Nuclear Reactors Materials and Waste; Transportation Systems; Water and Wastewater,"Brazil, China, Germany, France, United Kingdom, India, Taiwan, United States, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 397,4/2/2015,8/27/2018,2015,ICSA-15-092-01,Schneider Electric VAMPSET Software Buffer Overflow Vulnerability,Schneider Electric,VAMPSET Software,Schneider Electric affected products versions of VAMPSET: VAMPSET software | V2.2.145 | all previous versions.,CVE-2014-8390,6.6,Medium,CWE-121,Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 396,3/31/2015,8/27/2018,2015,ICSA-15-090-01,Inductive Automation Ignition Vulnerabilities,Inductive Automation,Ignition,Inductive Automation product versions affected: Inductive Automation Ignition 7.7.2.,"CVE-2015-0976, CVE-2015-0991, CVE-2015-0992, CVE-2015-0993, CVE-2015-0994, CVE-2015-0995",5.9,Medium,"CWE-255, CWE-79, CWE-209, CWE-922, CWE-613, CWE-916",Communications; Energy; Food and Agriculture; Water and Wastewater,"Australia, South America, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 395,3/31/2015,8/27/2018,2015,ICSA-15-090-02,Ecava IntegraXor DLL Vulnerabilities,Ecava,IntegraXor,SCADA Servers versions affected: IntegraXor SCADA Server prior to Version 4.2.4488.,CVE-2015-0990,6.8,Medium,CWE-427,Critical Manufacturing; Energy; Water and Wastewater,"Australia, Canada, Estonia, United Kingdom, Malaysia, Poland, United States",Malaysia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 394,3/31/2015,8/23/2018,2015,ICSA-15-090-03,Hospira MedNet Vulnerabilities,Hospira,MedNet,MedNet software versions affected: MedNet software Version 5.8 and prior versions.,"CVE-2014-5403, CVE-2014-5405, CVE-2014-5401",8.2,High,"CWE-94, CWE-260, CWE-321, CWE-259",Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 393,3/26/2015,8/27/2018,2015,ICSA-15-085-01A,Schneider Electric InduSoft Web Studio and InTouch Machine Edition 2014 Vulnerabilities (Update A),Schneider Electric,InduSoft Web Studio and InTouch Machine Edition 2014,Schneider Electric product versions affected: InduSoft Web Studio | Version 7.1.3.2 | all previous versions | InTouch Machine Edition 2014 | version 7.1.3.2 | all previous versions.,"CVE-2015-0996, CVE-2015-0997, CVE-2015-0998, CVE-2015-0999",4.1,Medium,"CWE-319, CWE-287, CWE-798",Commercial Facilities; Energy; Food and Agriculture; Information Technology,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 392,2/5/2015,8/27/2018,2015,ICSA-15-036-01A,GE and MACTek HART Device DTM Vulnerability (Update A),"GE, MACTek",HART Device DTM,Products using the vulnerable HART DTM library and are affected: MACTek's Bullet DTM 1.00.0 | GE's Vector DTM 1.00.0 | GE's SVi1000 Positioner DTM 1.00.0 | GE's SVI II AP Positioner DTM 2.00.1 | GE's 12400 Level Transmitter DTM 1.00.0.,CVE-2014-9203,6.8,Medium,"CWE-20, CWE-121",Chemical; Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 391,3/3/2015,8/27/2018,2015,ICSA-15-062-02,Rockwell Automation FactoryTalk DLL Hijacking Vulnerabilities,Rockwell Automation,FactoryTalk,FactoryTalk software versions affected: FactoryTalk Services Platform and all versions prior to 2.71.00 | FactoryTalk View Studio Version 8.00.00 and all versions prior.,CVE-2014-9209,6.9,Medium,CWE-427,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Government Facilities; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 390,3/17/2015,8/27/2018,2015,ICSA-15-076-01,XZERES 442SR Wind Turbine Vulnerability,XZERES,442SR Wind Turbine,XZERES product versions affected: 442SR Wind Turbine.,CVE-2015-0985,10.0,Critical,CWE-352,Energy,"United Kingdom, Italy, Japan, Myanmar, Philippines, United States, Vietnam",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 389,3/17/2015,8/27/2018,2015,ICSA-15-076-02,Honeywell XL Web Controller Directory Traversal Vulnerability,Honeywell,XL Web Controller,XLWeb controller versions affected: XL1000C50 EXCEL WEB 52 I/O |XL1000C100 EXCEL WEB 104 I/O |XL1000C500 EXCEL WEB 300 I/O |XL1000C1000 EXCEL WEB 600 I/O |XL1000C50U EXCEL WEB 52 I/O UUKL |XL1000C100U EXCEL WEB 104 I/O UUKL |XL1000C500U EXCEL WEB 300 I/O UUKL | XL1000C1000U EXCEL WEB 600 I/O UUKL.,CVE-2015-0984,10.0,Critical,CWE-22,Critical Manufacturing; Energy; Water and Wastewater,"United Kingdom, Europe, Middle East",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 388,12/16/2014,8/27/2018,2015,ICSA-14-350-02,Johnson Controls Metasys Vulnerabilities,Johnson Controls Inc.,Metasys,Application and Data Server (ADS) | Extended Application and Data Server (ADX) | LonWorks Control Server 85 (LCS8520) | Network Automation Engine (NAE) 55xx-x models |Network Integration Engine (NIE) 5xxx-x models and NxE8500.,"CVE-2014-5427, CVE-2014-5428",10.0,Critical,"CWE-257, CWE-434",Commercial Facilities; Government Facilities,"Australia, China, Czech Republic, Germany, France, United Kingdom, India, Italy, Netherlands, United States",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 387,3/12/2015,8/27/2018,2015,ICSA-15-071-01,Schneider Electric Pelco DS-NVs Buffer Overflow Vulnerability,Schneider Electric,Pelco DS-NVs,Pelco DS-NVs versions affected: Pelco DS-NVs | Version 7.6.32 and prior versions.,CVE-2015-0982,7.5,High,CWE-121,Commercial Facilities,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 386,3/10/2015,8/27/2018,2015,ICSA-15-069-04A,Elipse E3 Process Control Vulnerability (Update A),Elipse,E3 Process Control,Elipse E3 versions affected: Elipse E3 | Versions 4.5.232-4.6.161 |EQATEC.Analytics.Monitor.Win32_vc100.dll (32-bit) | EQATEC.Analytics.Monitor.Win32_vc100-x64.dll (64-bit).,CVE-2015-0978,6.2,Medium,CWE-114,Critical Manufacturing,"Argentina, Brazil, Chile, Germany, India, Russia, Sweden, United States",Brazil,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 385,3/10/2015,8/27/2018,2015,ICSA-15-069-01,Cimon CmnView DLL Hijacking Vulnerability,"CIMON, Inc.",CmnView,CIMON CmnView.exe application versions affected: CmnView Version 2.14.0.1 | CmnView Version 3.x.,CVE-2014-9207,9.3,Critical,CWE-427,Critical Manufacturing; Energy; Water and Wastewater,"South Korea, United States, Asia",South Korea,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 384,3/10/2015,8/27/2018,2015,ICSA-15-069-02,ABB HART Device DTM Vulnerability,ABB,HART Device DTM,The following products using the vulnerable HART Device DTM library are affected: ABB Third-Party Device Type Library | Version 1.17 and prior: 800xA¾Device Management HART. Freelance ABB Third-Party HART DTMLibrary - Version 1.4.178.214 and prior: Freelance 800F. S Plus Melody ABB Third-Party HART DTMLibrary - Version 1.4.175.185 and prior: Symphony Plus with Composer Melody | S+Engineering for Melody | Composer Field.,CVE-2014-9191,1.8,Low,"CWE-120, CWE-20",Multiple Critical Sectors,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 383,3/10/2015,8/27/2018,2015,ICSA-15-069-03,SCADA Engine BACnet OPC Server Vulnerabilities,SCADA Engine,BACnet OPC Server,BACnet OPC Server versions affected: OPC Server prior to and including Version 2.1.359.22.,"CVE-2015-0979, CVE-2015-0980, CVE-2015-0981",8.7,High,"CWE-122, CWE-287, CWE-20",Commercial Facilities,Worldwide,Australia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 382,2/10/2015,8/27/2018,2015,ICSA-15-041-02,GE Hydran M2 Predictable TCP Initial Sequence Vulnerability,GE,Hydran M2,GE Digital Energy versions affected: Hydran M2 - containing the 17046 Ethernet option and released prior to October 2014.,CVE-2014-5409,6.4,Medium,CWE-343,Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 381,3/5/2015,8/27/2018,2015,ICSA-15-064-03,Siemens SPC Controller Series Denial-of-Service Vulnerability,Siemens,SPC Controller Series,SPC Controllers versions affected: SPC4000 series: All versions prior to V3.6.0 |SPC5000 series: All versions prior to V3.6.0 | SPC6000 series: All versions prior to V3.6.0.,CVE-2014-9369,7.8,High,CWE-400,Multiple Critical Sectors,"Germany, Peru",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 380,3/5/2015,8/22/2018,2015,ICSA-15-064-04,Siemens SIMATIC S7-300 CPU Denial-of-Service Vulnerability,Siemens,SIMATIC S7-300 CPU,SIMATIC S7-300 CPUs versions affected: SIMATIC S7-300 CPU family: all versions.,CVE-2015-2177,7.8,High,CWE-404,Chemical; Energy; Food and Agriculture; Water and Wastewater,"United States, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 379,3/5/2015,8/27/2018,2015,ICSA-15-064-05,Siemens SPCanywhere App Vulnerabilities,Siemens,SPCanywhere App,SPCanywhere versions affected: SPCanywhere Android Application: All versions | SPCanywhere iOS Application: All versions.,"CVE-2015-1595, CVE-2015-1596, CVE-2015-1597, CVE-2015-1598, CVE-2015-1599",4.7,Medium,"CWE-288, CWE-212, CWE-311, CWE-257",Commercial Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 378,12/19/2014,12/19/2014,2015,ICSA-14-353-01-SupplementA,Network Time Protocol Vulnerabilities (Supplement Update A),Other,Network Time Protocol (NTP),"Arbiter Systems products: Clock products using the network card | Innomoninate products: Innominate Security Technologies AG | mGuard Firmware Version 7.0 | mGuard Firmware Version 8.0 | Meinberg products: Please see Meinberg's public notification and mitigation strategies at: Meinberg Security Advisory: [MBGSA-1405] Multiple NTP Vuln (2014-12-22) - https://www.meinbergglobal.com/english/news/meinberg-security-advisory-mbgsa-1405-multiple-ntp-vulnerabilities.htm | LANTIME M3000, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M300, LANTIME M200, LANTIME M100, SYNCFIRE 1000 | Siemens products: Please see Siemens's public notification and mitigation strategies at SSA-671683 NTP Vulnerabilities in Ruggedcom ROX-based Devices (Update March 05, 2015), located at www.siemens.com/cert/advisories | SINUMERIK Controllers-based Devices (Published March 05, 2015) | Wind River System products:Please see Wind River Support Network (http://www.windriver.com/feeds/vxworks_networking_security_notice.xml) | WR Linux: VxWorks 7 VxWorks 6.9WR Linux 4.3.0.XWR Linux 5.0.1.xWR Linux 6.0.0.xWR Linux 7.0.0.x","CVE-2014-9295, CVE-2014-9293, CVE-2014-9294",7.5,High,CWE-119,Multiple Critical Sectors; Energy,Worldwide,Not Applicable,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 377,3/3/2015,8/27/2018,2015,ICSA-15-062-01,MICROSYS PROMOTIC Stack Buffer Overflow,MICROSYS,PROMOTIC,PROMOTIC versions affected: PROMOTIC versions prior to stable 8.2.19 | PROMOTIC versions prior to development 8.3.2.,CVE-2014-9205,7.5,High,CWE-121,Critical Manufacturing; Energy; Water and Wastewater,"Bulgaria, Hungary, Poland, Romania, Serbia, Slovenia",Czech Republic,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 376,2/26/2015,8/29/2018,2015,ICSA-15-057-01,Network Vision IntraVue Code Injection Vulnerability,Network Vision,IntraVue,IntraVue software versions affected: IntraVue | all Windows versions prior to Version 2.3.0a14.,CVE-2015-0977,10.0,Critical,CWE-78,Critical Manufacturing; Transportation Systems; Water and Wastewater,"North America, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 375,2/24/2015,8/27/2018,2015,ICSA-15-055-01,Software Toolbox Top Server Resource Exhaustion Vulnerability,Software Toolbox,Top Server,software Toolbox Top Server versions affected: software Toolbox Top Server Versions 5.16 and earlier.,CVE-2014-5425,7.5,High,CWE-400,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Food and Agriculture; Information Technology; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 374,2/24/2015,8/29/2018,2015,ICSA-15-055-02,Kepware Resource Exhaustion Vulnerability,Kepware Technologies,Kepware Technologies,Kepware Technologies' DNP Master Driver for the KEPServerEX Communications Platform Versions 5.16.728.0 and earlier.,CVE-2014-5425,7.5,High,CWE-400,Chemical; Commercial Facilities; Communications; Critical Manufacturing; Energy; Food and Agriculture; Information Technology; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 373,2/24/2015,8/29/2018,2015,ICSA-15-055-03,Schneider Electric Invensys Positioner Buffer Overflow Vulnerability,Schneider Electric,Invensys Positioner,Schneider Electric product versions affected: DTM Version 3.1.6 | all previous versions used with SRD 960 | SRD 991 Control Valve Positioners.,CVE-2014-9206,5.2,Medium,CWE-121,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 372,2/19/2015,8/27/2018,2015,ICSA-15-050-01A,Siemens SIMATIC STEP 7 TIA Portal Vulnerabilities (Update A),Siemens,SIMATIC WinCC TIA Portal,Siemens products affect versions of SIMATIC STEP 7 (TIA Portal): SIMATIC STEP 7 (TIA Portal) V13: All versions prior to V13 SP1 Upd1 | SIMATIC STEP 7 (TIA Portal) V12: All versions prior to V12 SP1 Upd5.,"CVE-2015-1601, CVE-2015-1602",3.9,Low,"CWE-300, CWE-916",Chemical; Energy; Food and Agriculture; Water and Wastewater,"United States, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 371,2/17/2015,8/29/2018,2015,ICSA-15-048-01,Siemens SIMATIC STEP 7 TIA Portal Vulnerabilities,Siemens,SIMATIC WinCC TIA Portal,Siemens product versions affected: SIMATIC STEP 7 TIA Portal: All versions prior to V13 SP1.,"CVE-2015-1355, CVE-2015-1356",2.4,Low,"CWE-264, CWE-916",Chemical; Energy; Food and Agriculture; Water and Wastewater,"United States, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 370,2/17/2015,8/29/2018,2015,ICSA-15-048-02,Siemens SIMATIC WinCC TIA Portal Vulnerabilities,Siemens,SIMATIC WinCC TIA Portal,Siemens product versions affected: SIMATIC WinCC TIA Portal: All versions prior to V13 SP1.,"CVE-2015-1358, CVE-2014-4686",5.6,Medium,"CWE-522, CWE-321",Chemical; Energy; Food and Agriculture; Water and Wastewater,"United States, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 369,2/17/2015,8/27/2018,2015,ICSA-15-048-03,Yokogawa HART Device DTM Vulnerability,Yokogawa,HART Device DTM,The Yokogawa HART Device DTM used by the following devices are affected: ADMAG AE Series Magnetic Flowmeters (AE/AE14) Rev.1 & 2 | ADMAG SE Series Magnetic Flowmeters (SE/SE14) Rev.1 & 2 | AM11 Magnetic Flowmeter Remote Converter Rev.1 | AXFA11 Magnetic Flowmeter Remote Converter Rev.1 | ADMAG AXF Series Magnetic Flowmeters (AXF/AXFA14) Rev.1 | ADMAG AXR Two-wire Magnetic Flowmeters Rev.1 & 2 | digitalYEWFLO Vortex Flowmeter Rev.1 | 2 | 3 | & 4 | Dpharp EJA /EJA-A Series Pressure Transmitters/Differential PressureTransmitters Rev.1 | 2 | & 3 | Dpharp EJX Series Pressure Transmitters/Differential PressureTransmitters Rev.1 | 2 | & 3 | EJX Multivariable Transmitters (EJX910A/EJX930A) Rev.1 & 2 | Rotameter Rev.1 | Coriolis Mass Flowmeters- ROTAMASS 3-Series (RCCT3x/RCCF31) Rev.1 | 2 | & 3 | Coriolis Mass Flowmeters (CF11) Rev.1 | Differential Pressure Transmitters Rev.1 | YEWFLO Vortex Flowmeter Rev.1 & 2 | YT200 Temperature Transmitters Rev.1 | YTA110/YTA310/YTA320 Temperature Transmitters Rev.1 | 2 | & 3 | YTA70 Temperature Transmitters Rev.1 | AV550G Rev.1 | DO202 Rev.1 | ISC202 Rev.1 | ISC450 Rev.1 & 2 | PH150 Rev.1 & 2 | PH202 Rev.1 | PH450 Rev.1 & 2 | SC150 Rev.1 & 2 | SC202 Rev.1 | SC450Rev.1 & 2 | ZR202 Rev.1 | andZR402 Rev.1.,CVE-2014-9191,1.8,Low,"CWE-120, CWE-20",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Nuclear Reactors Materials and Waste; Water and Wastewater,"North America, Asia, East Asia, Europe, Africa, Middle East",Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 368,7/17/2014,8/29/2018,2015,ICSA-14-198-03G,Siemens OpenSSL Vulnerabilities (Update G),Siemens,OpenSSL,APE (only affected if SSL/TLS component is used): APE stand-alone: All versions prior to V2.0.2 | ELAN on APE: All versions prior to V8.4.0 | CP1543-1: prior to Version 1.1.25 | ROX 1: all versions prior to V1.16.1 (only affected if Crossbow is installed) | ROX 2: all versions prior to V2.6.0 (only affected if ELAN or Crossbow is installed) | Crossbow: All versions prior to V4.2.3ELAN: All versions prior to V8.4.0S7-1500: versions prior to Version 1.6 | WinCC OA (PVSS): Version 3.12-P001-3.12-P008.,"CVE-2014-0224, CVE-2014-0198, CVE-2010-5298, CVE-2014-3470",4.9,Medium,"CWE-362, CWE-310, CWE-119, CWE-476",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Healthcare and Public Health; Water and Wastewater,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 367,2/10/2015,8/29/2018,2015,ICSA-15-041-01,Advantech EKI-1200 Buffer Overflow,Advantech,EKI-1200,Advantech versions affected: EKI-1200 product line.,CVE-2014-8385,10.0,Critical,CWE-122,Commercial Facilities; Critical Manufacturing; Energy; Transportation Systems,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 366,11/25/2014,8/29/2018,2015,ICSA-14-329-02D,"Siemens SIMATIC WinCC, PCS7, and TIA Portal Vulnerabilities (Update D)",Siemens,"SIMATIC WinCC, PCS7, and TIA Portal",SIMATIC WinCCV7.0 SP3 and earlier: All versions | V7.2: All versions prior to V7.2 Update 9 | V7.3: All versions prior to V7.3 Update 2 | SIMATIC PCS 7V7.1 SP4 and earlier: All versions | V8.0: All versions prior to V8.0 SP2 with WinCC V7.2 Update 9 | andV8.1: All versions with WinCC V7.3 prior to Update 2.TIA Portal V13 (including WinCC Professional Runtime): All versions prior to V13 Update 6.,"CVE-2014-8551, CVE-2014-8552",8.9,High,CWE-284,Chemical; Energy; Food and Agriculture; Water and Wastewater,"Germany, United States, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 365,2/5/2015,10/30/2018,2015,ICSA-15-036-02,Pepperl+Fuchs Hart Device DTM Vulnerability,PEPPERL+FUCHS,Hart Device DTM,The following products were developed with the vulnerable CodeWrights GmbH DTMStudio versions and are affected: DTM collection Level Control DTM 1.0.28 and prior | Barcon PPC-M / LHC-M |LHC-M51 / PPC-M51 |LHCR-51 / LHCS-51 |LUC-M |LUC-M V4.XX |Pulscon LTC | Pulscon LTC V4.XX.DTM Collection CorrTran DTM Version 1.4.128.8 and prior for the following: CorrTran MV CMCM | CorrTran AQUA CMCA.,CVE-2014-9191,1.8,Low,CWE-20,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 364,1/12/2015,8/29/2018,2015,ICSA-15-012-01C,CodeWrights GmbH HART Device DTM Vulnerability (Update C),CodeWrights GmbH,HART Device DTM,Any DTM written by CodeWrights GmbH DTMStudio prior to Version 1.5.151.,CVE-2014-9191,1.8,Low,CWE-20,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 363,12/19/2014,8/29/2018,2015,ICSA-14-353-01C,Network Time Protocol Vulnerabilities (Update C),Other,Network Time Protocol (NTP),Products using NTP service prior to ntp-4.2.8p1 are affected.,"CVE-2014-9293, CVE-2014-9294, CVE-2014-9295, CVE-2014-9296, CVE-2014-9297, CVE-2014-9298",7.3,High,"CWE-290, CWE-754, CWE-331, CWE-121, CWE-338, CWE-389",Multiple Critical Sectors,Worldwide,Not Applicable,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 362,2/3/2015,8/29/2018,2015,ICSA-15-034-01,Siemens SCALANCE X-200IRT Switch Family User Impersonation Vulnerability,Siemens,SCALANCE X-200IRT Switch Family,Siemens versions affected: SCALANCE X-200IRT switch family: All versions prior to V5.2.0.,CVE-2015-1049,6.8,Medium,CWE-287,Chemical; Communications; Critical Manufacturing; Dams; Defense Industrial Base; Energy; Food and Agriculture; Government Facilities; Transportation Systems;; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 361,2/3/2015,8/29/2018,2015,ICSA-15-034-02,Siemens Ruggedcom WIN Vulnerability,Siemens,Ruggedcom WIN,Siemens Ruggedcom WIN versions affected: WIN51xx: all versions prior to SS4.4.4624.35WIN52xx: all versions prior to SS4.4.4624.35WIN70xx: all versions prior to BS4.4.4621.32WIN72xx: all versions prior to BS4.4.4621.32.,"CVE-2015-1448, CVE-2015-1449, CVE-2015-1357",7.5,High,"CWE-287, CWE-121, CWE-257",Chemical; Communications; Critical Manufacturing; Dams; Defense Industrial Base; Energy; Food and Agriculture; Government Facilities; Transportation Systems;; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 360,1/29/2015,8/29/2018,2015,ICSA-15-029-01,Honeywell HART DTM Vulnerability,Honeywell,HART DTM,The following products using the vulnerable HART DMT library are affected: Honeywell STT25T HART 5 Transmitter Rev. 1 & 2 | Honeywell STT25H HART 5 Transmitter Rev. 1 & 3 | Honeywell STT25S HART 5 Transmitter Rev. 2 | Honeywell ST 3000 HART 5 Transmitter Rev. 1 | Honeywell ST 3000 HART 6 Transmitter Rev. 1 | Honeywell ST 3000 H6 Transmitter with Advanced Diagnostics Rev. 1 | Honeywell ST STT25H HART 5 Transmitter Rev. 1 | Honeywell ST STT25S HART 6 Transmitter Rev. 1.,CVE-2014-9191,1.8,Low,CWE-20,Chemical; Critical Manufacturing; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 359,1/27/2015,8/29/2018,2015,ICSA-15-027-01,Magnetrol HART DTM Vulnerability,Magnetrol,HART DTM Vulnerability,The following products using the vulnerable HART DMT library extension are affected: Eclipse Model 705 Guided Wave Radar transmitter (firmware Version 3.x) | Echotel Model 355 Ultrasonic transmitter (firmware Version 1.x) | Model R82 Pulse Burst Radar Transmitter (firmware Versions 1.x | 2.x) | Thermatel Model TA2 Thermal Mass Flowmeter (firmware Version 2.x).,CVE-2014-9191,1.8,Low,CWE-20,Chemical; Critical Manufacturing; Energy; Water and Wastewater,"Belgium, Brazil, China, United States",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 358,1/27/2015,8/29/2018,2015,ICSA-15-027-02,Schneider Electric Multiple Products Buffer Overflow Vulnerability,Schneider Electric,Multiple Products,The following Schneider Electric software platforms are installed with an affected Device Type Managers (DTMs) with an affected DLL: Unity Pro | all versions | SoMachine | all versions |SoMove | all versions |SoMove Lite | all versions. Schneider Electric DTM libraries versions affected: Modbus Communication Library | Version 2.2.6 and prior | CANopen Communication Library | Version 1.0.2 and prior | EtherNet/IP Communication Library | Version 1.0.0 and prior | EM X80 Gateway DTM (MB TCP/SL) | Advantys DTMs (OTB | STB) | KINOS DTM | SOLO DTM | Xantrex DTMs.,CVE-2014-9200,7.5,High,CWE-121,Critical Manufacturing,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 357,1/22/2015,8/29/2018,2015,ICSA-15-022-01,Siemens SIMATIC S7-1200 CPU Web Vulnerability,Siemens,SIMATIC S7-1200 CPU,Siemens SIMATIC S7-1200 CPU family versions affected: SIMATIC S7-1200 CPU family: All versions prior to V4.1,CVE-2015-1048,4.3,Medium,CWE-601,Chemical; Critical Manufacturing; Food and Agriculture,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 356,1/20/2015,8/29/2018,2015,ICSA-15-020-01,Siemens SCALANCE X-300/X408 Switch Family DOS Vulnerabilities,Siemens,SCALANCE X-300/X408 Switch Family,Siemens SCALANCE switches versions are affected: SCALANCE X-300 switch family: All versions prior to V4.0 | SCALANCE X408: All versions prior to V4.0. Alternatively - the affected products may be identified by using their machine-readable product designation (MLFB). A full list of the affected MLFBs can be found in Siemens Security Advisory SSA-321046.,"CVE-2014-8478, CVE-2014-8479",7.3,High,CWE-730,Chemical; Communications; Critical Manufacturing; Dams; Defense Industrial Base; Energy; Food and Agriculture; Government Facilities; Transportation Systems;; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 355,1/20/2015,8/29/2018,2015,ICSA-15-020-02,Schneider Electric ETG3000 FactoryCast HMI Gateway Vulnerabilities,Schneider Electric,ETG3000 FactoryCast HMI Gateway,ETG3000 FactoryCast HMI Gateway's versions affected: TSXETG3000 all versions |TSXETG3010 all versions |TSXETG3021 all versions | TSXETG3022 all versions.,"CVE-2014-9197, CVE-2014-9198",10.0,Critical,"CWE-306, CWE-798",Critical Manufacturing; Energy; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 354,12/11/2014,8/29/2018,2015,ICSA-14-345-01,Arbiter Systems 1094B GPS Clock Spoofing Vulnerability,Arbiter Systems,1094B GPS Clock,Model 1094B GPS Substation Clock.,CVE-2014-9194,5.4,Medium,CWE-345,Energy,"United States, South America, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 353,10/16/2014,8/29/2018,2015,ICSA-14-289-02,GE Proficy HMI/SCADA CIMPLICITY CimView Memory Access Violation,GE,Proficy HMI/SCADA CIMPLICITY CimView,"Proficy HMI/SCADA-CIMPLICITY, Version 8.2 and prior.",CVE-2014-2355,6.6,Medium,CWE-119,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 352,10/14/2014,8/29/2018,2015,ICSA-14-287-01,GE Proficy HMI/SCADA DNP3 Driver Input Validation,"Catapult Software, GE",HMI/SCADA DNP3 Driver,"GE Intelligent Platform software affected: Specific products addressed include:iFix (all versions): Catapult v7.20.62 | CIMPLICITY 8.2 and earlier: Catapult v8.2.62 | CIMPLICITY 9.0: Catapult v9.0.62 | Proficy HMI/SCADA DNP3 I/O Driver (""DNP): Version v7.20k (Catapult v7.20.60) and prior |Proficy HMI/SCADA - iFIX or CIMPLICITY servers with the vulnerable I/O Driver installed (this includes iFIX or CIMPLICITY installations that are part of Proficy Process Systems).",CVE-2013-2811,7.8,High,CWE-20,Energy; Water and Wastewater,New Zealand,New Zealand,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 351,1/13/2015,8/29/2018,2015,ICSA-15-013-01,Siemens SIMATIC WinCC Sm@rtClient iOS Application Authentication Vulnerabilities,Siemens,SIMATIC WinCC Sm@rtClient iOS Application,SIMATIC WinCC Sm@rt Client versions affected: SIMATIC WinCC Sm@rtClient: All versions prior to V1.0.2SIMATIC WinCC Sm@rtClient Lite for iOS: All versions prior to V1.0.2.,"CVE-2014-5231, CVE-2014-5232, CVE-2014-5233",4.6,Medium,"CWE-287, CWE-522",Chemical; Energy; Food and Agriculture; Water and Wastewater,"United States, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 350,1/13/2015,8/29/2018,2015,ICSA-15-013-02,Clorius Controls A/S ISC SCADA Insecure Java Client Web Authentication,Clorius Controls A/S,ISC SCADA Insecure Java Client Web Authentication,Clorius Controls A/S web server versions affected: Clorius Controls A/S Java web client including and prior to Version 01.00.0009b.,CVE-2014-9199,10.0,Critical,CWE-326,Commercial Facilities; Critical Manufacturing,"China, Denmark, India, Russia, Singapore, United States, Europe",Denmark,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 349,1/13/2015,1/24/2019,2015,ICSA-15-013-03,Phoenix Contact Software ProConOs and MultiProg Authentication Vulnerability,PHOENIX CONTACT,Software ProConOs and MultiProg,ProConOs all versions and MultiProg all versions.,CVE-2014-9195,10.0,Critical,CWE-306,Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 348,1/13/2015,8/4/2015,2015,ICSA-15-013-04A,GE Multilink Switch Vulnerabilities (Update A),GE,Multilink Switch,GE Multilink Ethernet switch versions affected: GE Multilink ML800/1200/1600/2400 Version 4.2.1 and prior | GE Multilink ML810/3000/3100 series switch Version 5.2.0 and prior.,"CVE-2014-5418, CVE-2014-5419, CVE-2015-3976",7.3,High,"CWE-79, CWE-400, CWE-321",Critical Manufacturing; Energy; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 347,1/8/2015,8/29/2018,2015,ICSA-15-008-01A,Emerson HART DTM Vulnerability (Update A),Emerson,HART Device DTM,The following products using the vulnerable HART DTM library are affected: Fisher Controls DVC6000 Digital Valve Controller Rev. 2.01 | Fisher Controls International DVC2000 Digital Valve Controller Rev. 1.01 | Micro Motion 1500 Rev. 5 and 6 | Micro Motion 1700 Analog Rev. 5 and 6 | Micro Motion 1700 IS Rev. 6 | Micro Motion 1700 Rev. 5 | Micro Motion 1700IS Rev. 5 | Micro Motion 2000 Config I/O Rev. 5 | Micro Motion 2200S Rev. 1 | Micro Motion 2400S Analog Rev. 2 | 3 | and 4 | Micro Motion 2500/2700 Config I/O Rev. 5 and 6 | Micro Motion 2700 Analog Rev. 5 and 6 | Micro Motion 2700 IS Rev. 5 and 6 | Micro Motion RFT9739 Rev. 4 | Micro Motion Series 3000 Rev. 7 | Rosemount 1151 Pressure Transmitter Rev. 5 and 6 | Rosemount 2051 Pressure Transmitter Rev. 3 | 9 | and 10 | Rosemount 2088 Pressure Transmitter Rev. 3 | 9 | and 10 | Rosemount 2090 Pressure Transmitter Rev. 3 | Rosemount 248 Temperature Transmitter Rev. 2 | Rosemount 3051 Pressure Transmitter Rev. 3 | 7 | 9 | and 10 | Rosemount 3051S Advanced Diagnostics Rev. 2 and 3 | Rosemount 3051S Electronic Remote Sensors Rev. 1 | Rosemount 3051S Pressure Transmitter Rev. 7 | Rosemount 3051SMV Direct Process Variable Rev. 1 | Rosemount 3051SMV MultiVariable Mass Energy Flow Rev. 1 | Rosemount 3095M MultiVariableâžÂ¢ Mass Flow Rev. 2 | Rosemount 3100 Ultrasonic Level Transmitter Rev. 5 | Rosemount 3144P Temperature Transmitter Rev. 3 | 4 | 5 | and 6Rosemount 3300 Radar Level and Interface Transmitter Rev. 3 | Rosemount 333 Triloop Rev. 1 | Rosemount 4500 Pressure Transmitter Rev. 7 | Rosemount 4600 Pressure Transmitter Rev. 1 | Rosemount 5300 Radar Level and Interface Transmitter Rev. 1 | 2 | and 3 | Rosemount 5400 Radar Level Transmitter Rev. 1 and 2 | Rosemount 644 Temperature Transmitter Rev. 6 | 7 | 8 | and 9 | Rosemount 8712D Magnetic Flowmeter Rev. 1 | Rosemount 8712E Magnetic Flowmeter Rev. 3 | Rosemount 8712H Magnetic Flowmeter Rev. 1 | Rosemount 8732C Magnetic Flowmeter Rev. 7 | Rosemount 8732E Magnetic Flowmeter Rev. 2 | Rosemount 8800C Vortex Flowmeter Rev. 3 | Rosemount 8800D Vortex Flowmeter Rev. 1 and 2 | Rosemount Analytical 1056 Rev. 1 and 2 | Rosemount Analytical 5081A Rev. 2 | Rosemount Analytical 5081CT Rev. 1 | Rosemount Analytical 5081p Rev. 2 | Rosemount Analytical 54eA Rev. 2 | Rosemount Analytical 54eC Rev. 1 | Rosemount Analytical 54epH Rev. 2 | Rosemount Analytical OCT4000 Rev. 3 | Rosemount Analytical OCX8800 Rev. 3 | Rosemount Analytical XmtA Rev. 1 | Rosemount Analytical XmtCT Rev. 1 | Rosemount Analytical XmtpH Rev. 1 | Rosemount Metran 150 Pressure Transmitter Rev. 9 and 10 | andRosemount Metran 75 Pressure Transmitter Rev. 9 and 10.,CVE-2014-9191,1.8,Low,CWE-20,Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 346,1/8/2015,8/27/2018,2015,ICSA-15-008-02,Schneider Electric Wonderware InTouch Access Anywhere Server Buffer Overflow Vulnerability,Schneider Electric,Wonderware InTouch Access Anywhere Server,Wonderware InTouch Access Anywhere Server versions affected: InTouch Access Anywhere Server | Version 10.6 | InTouch Access Anywhere Server | Version 11.0.,CVE-2014-9190,10.0,Critical,CWE-121,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 345,12/18/2014,4/10/2019,2014,ICSA-14-352-01,Honeywell Experion PKS Vulnerabilities,Honeywell,Experion PKS,Experion PKS versions affected: All supported Experion PKS R40x versions prior to Experion PKS R400.6 | All supported Experion PKS R41x versions prior to Experion PKS R410.6 | All supported Experion PKS R43x versions prior to Experion PKS R430.2 | Note - Experion PKS R311.2 is Impacted by these vulnerabilities but is no longer supported by Honeywell. Customers running Experion PKS R311.2 should upgrade to a supported version of Experion PKS.,"CVE-2014-9187, CVE-2014-9189, CVE-2014-5435, CVE-2014-5436, CVE-2014-9186",7.4,High,"CWE-122, CWE-98, CWE-22, CWE-121, CWE-123",Chemical; Critical Manufacturing; Energy; Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 344,12/18/2014,9/5/2018,2014,ICSA-14-352-02,Innominate mGuard Privilege Escalation Vulnerability,Innominate,mGuard,Innominate mGuard firmware Version 8.1.3 and prior.,CVE-2014-9193,8.5,High,CWE-269,Communications; Critical Manufacturing; Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 343,9/16/2013,9/5/2018,2014,ICSA-13-259-01B,Emerson ROC800 Multiple Vulnerabilities (Update B),Emerson,ROC800,Emerson Process Management RTUs are affected: ROC800 Version 3.50 and prior DL8000 Version 2.30 and prior andROC800L Version 1.20 and prior.,"CVE-2018-14793, CVE-2013-0692, CVE-2013-0689, CVE-2013-0694, CVE-2013-2810",9.8,High,"CWE-294, CWE-912, CWE-798",Energy; oil and gas,"United States, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 342,12/16/2014,9/5/2018,2014,ICSA-14-350-01,Schneider Electric ProClima Command Injection Vulnerabilities,Schneider Electric,ProClima,ProClima Version 6.0.1 and previous.,"CVE-2014-8513, CVE-2014-8514, CVE-2014-9188, CVE-2014-8511, CVE-2014-8512",10.0,High,CWE-77,Commercial Facilities; Critical Manufacturing; Energy,"France, United States, Asia, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 341,12/9/2014,9/5/2018,2014,ICSA-14-343-01,Yokogawa FAST/TOOLS XML External Entity,Yokogawa,FAST/TOOLS XML External Entity,FAST/TOOLS Versions R9.01 though R9.05 SP1.,CVE-2014-7251,2.4,Low,CWE-611,Energy; oil and gas,"Japan, Asia, East Asia, Europe, Africa, Middle East",Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 340,12/9/2014,8/23/2018,2014,ICSA-14-343-02,Trihedral Engineering Limited VTScada Integer Overflow Vulnerability,Trihedral Engineering Limited,VTScada,VTS Version 6.5 through 9.1.19 | VTS Version 10 through 10.2.21 | VTScada Version 11.0 through 11.1.07.,CVE-2014-9192,7.8,High,CWE-190,Chemical; Communications; Critical Manufacturing; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,"Canada, United Kingdom, United States, North America, Europe",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 339,10/30/2014,9/5/2018,2014,ICSA-14-303-02,Elipse SCADA DNP3 Denial of Service,Elipse,SCADA DNP3,Elipse SCADA 2.29 build 141 and prior w/ DNP3 driver | Elipse E3 versions V1.0 to V4.6 | Elipse Power systems Versions V1.0 to V4.6 | DNP 3.0 Master v3.02 and prior.,CVE-2014-5429,5.0,Medium,CWE-400,Critical Manufacturing; Energy; Water and Wastewater,"Argentina, Brazil, Chile, Germany, India, Russia, Sweden, United States",Brazil,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 338,9/17/2014,9/5/2018,2014,ICSA-14-260-01A,Yokogawa CENTUM and Exaopc Vulnerability (Update A),Yokogawa,CENTUM and Exaopc,"Yokogawa CENTUM 3000 versions affected: CENTUM series with the Batch Management Packages installed | CENTUM CS 3000 (R3.09.50 or earlier) | CENTUM CS 3000 Entry Class (R3.09.50 or earlier) | CENTUM VP (R4.03.00 or earlier - R5.04.00 or earlier) | and CENTUM VP Entry Class (R4.03.00 or earlier, R5.04.00 or earlier) | The following Yokogawa Exaopc version is affected:Exaopc (R3.72.10 or earlier).",CVE-2014-5208,6.8,Medium,CWE-287,Critical Manufacturing; Energy; Food and Agriculture,"Japan, South America, Asia, East Asia, Europe, Africa, Middle East, Central America",Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 337,11/25/2014,9/5/2018,2014,ICSA-14-329-01,MatrikonOPC for DNP Unhandled C++ Exception,MatrikonOPC,OPC DNP,MatrikonOPC Server for DNP3 Version 1.2.3.0.,CVE-2014-5426,6.8,Medium,CWE-754,Chemical; Energy,"Australia, Brazil, Canada, Costa Rica, Germany, Spain, United Kingdom, India, Norway, Portugal, Russia, Singapore, United States",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 336,11/20/2014,9/5/2018,2014,ICSA-14-324-01,Advantech WebAccess Stack-based Buffer Overflow,Advantech,WebAccess,Advantech WebAccess 7.2 and previous.,CVE-2014-8388,7.2,High,CWE-121,Commercial Facilities; Critical Manufacturing; Energy; Government Facilities,Taiwan,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 335,10/21/2014,9/6/2018,2014,ICSA-14-294-01,Rockwell Automation Connected Components Workbench ActiveX Component Vulnerabilities,Rockwell Automation,Connected Components Workbench ActiveX Component,Rockwell Automation CCW Version 6.01.00 and earlier.,CVE-2014-5424,7.5,High,CWE-618,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 334,11/4/2014,9/6/2018,2014,ICSA-14-308-01,ABB RobotStudio and Test Signal Viewer DLL Hijack Vulnerability,ABB,RobotStudio and Test Signal Viewer,"RobotStudio Version 5.60 up to and including 5.61.01.01, and Test Signal Viewer Version 1.5.",CVE-2014-5430,9.3,High,CWE-427,Multiple Critical Sectors; Critical Manufacturing,Switzerland,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 333,10/30/2014,9/6/2018,2014,ICSA-14-303-01,Nordex NC2 XSS Vulnerability,Nordex,NC2,Nordex Control 2 (NC2) SCADA V15 and prior versions.,CVE-2014-5408,7.5,High,CWE-79,Energy,"Austria, China, Germany, Spain, France, United Kingdom, Italy, Netherlands, Sweden, United States, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 332,10/2/2014,9/6/2018,2014,ICSA-14-275-01,Meinberg Radio Clocks LANTIME M-Series XSS,Meinberg,Radio Clocks LANTIME M-Series,Meinberg Network Time Protocol (NTP) Server firmware versions affected: LANTIME M-Series models: V6.15.019 and prior.,CVE-2014-5417,7.5,High,CWE-79,Commercial Facilities; Communications; Energy; Financial Services; Transportation Systems,"Germany, United States, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 331,10/2/2014,9/6/2018,2014,ICSA-14-275-02,Accuenergy Acuvim II Authentication Vulnerabilities,Accuenergy,Acuvim II Authentication,AXN-NET Ethernet module v.3.04.,"CVE-2014-2373, CVE-2014-2374",7.5,High,"CWE-602, CWE-592",Energy,"Canada, China, United States, North America",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 330,9/4/2014,10/10/2019,2014,ICSA-14-247-01A,Sensys Networks Traffic Sensor Vulnerabilities (Update A),Sensys Networks,Traffic Sensor,Sensys Networks traffic sensors: VSN240-F and VSN240-T operating with the following software versions are affected: Versions prior to VDS 2.10.1 | Versions prior to VDS 1.8.8 | Versions prior to TrafficDOT 2.10.3.,"CVE-2014-2378, CVE-2014-2379",5.4,Medium,"CWE-494, CWE-311",Transportation Systems,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 329,5/15/2014,9/6/2018,2014,ICSA-14-135-03A,Siemens RuggedCom ROX-based Devices Certificate Verification Vulnerability (Update A),Siemens,RuggedCom ROX-based Devices Certificate,Siemens RuggedCom ROX-based devices are affected: ROX 1 prior to Version 1.16.1 | ROX 2 prior to Version 2.6.,CVE-2014-0092,5.8,Medium,CWE-310,Energy; Healthcare and Public Health; Transportation Systems,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 328,10/16/2014,8/22/2018,2014,ICSA-14-289-01,IOServer Resource Exhaustion Vulnerability,IOServer,IOServer,IOServer Version 1.0.20 and older.,CVE-2014-5425,7.5,High,CWE-400,Critical Manufacturing; Energy; Water and Wastewater,Australia,Australia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 327,9/26/2014,9/6/2018,2014,ICSA-14-269-02,Fox DataDiode Proxy Server CSRF Vulnerability,Fox-IT,DataDiode Proxy Server,Fox DataDiode Appliance versions affected: All Fox DataDiode Appliance versions up to and including 1.7.1.,CVE-2014-2358,4.3,Medium,CWE-352,Communications; Defense Industrial Base; Government Facilities,Netherlands,Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 326,9/26/2014,11/12/2014,2014,ICSA-14-269-01,Bash Command Injection Vulnerability (Supplement),Other,Bash Command,"ABB Tropos 3000, 4000, 6000, & 7000 series routers | Indirectly affected: Ventyx NM EMS/SCADA on RHEL | Ventyx.","CVE-2014-6271, CVE-2014-7169",10.0,High,CWE-78,Multiple Critical Sectors,Worldwide,Not Applicable,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 325,9/26/2014,9/6/2018,2014,ICSA-14-269-01A,Bash Command Injection Vulnerability (Update A),Other,Bash Command,GNU bash versions 1.14 to 4.3 | Linux | BSD | UNIX distributions including but not limited to: CentOS | Debian | Mac OS X | Red Hat Enterprise | Ubuntu.,"CVE-2014-6271, CVE-2014-7169",10.0,High,CWE-78,Multiple Critical Sectors,Worldwide,Not Applicable,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 324,10/15/2014,10/15/2014,2014,ICSA-14-288-01,CareFusion Pyxis SupplyStation System Vulnerabilities,"CareFusion, Becton, Dickinson and Company (BD)",Pyxis SupplyStation System,Pyxis SupplyStation system 8.1 (hardware test tool software Versions 1.0.15 and prior).,"CVE-2014-5422, CVE-2014-5421, CVE-2014-5420, CVE-2014-5423",5.8,Medium,"CWE-259, CWE-377, CWE-798",Healthcare and Public Health,"Australia, Canada, China, Germany, France, United Kingdom, India, Italy, Netherlands, United States",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 323,9/16/2014,9/6/2018,2014,ICSA-14-259-01A,Schneider Electric SCADA Expert ClearSCADA Vulnerabilities (Update A),Schneider Electric,SCADA Expert ClearSCADA,ClearSCADA 2010 R3 (build 72.4560) | ClearSCADA 2010 R3.1 (build 72.4644) | SCADA Expert ClearSCADA 2013 R1 (build 73.4729) | SCADA Expert ClearSCADA 2013 R1.1 (build 73.4832) | SCADA Expert ClearSCADA 2013 R1.1a (build 73.4903) | SCADA Expert ClearSCADA 2013 R1.2 (build 73.4955) | SCADA Expert ClearSCADA 2013 R2 (build 74.5094) | SCADA Expert ClearSCADA 2013 R2.1 (build 74.5192) | SCADA Expert ClearSCADA 2014 R1 (build 75.5210).,"CVE-2014-5411, CVE-2014-5412, CVE-2014-5413",5.2,Medium,"CWE-310, CWE-287, CWE-79",Commercial Facilities; Energy; Water and Wastewater,"France, United States, Asia, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 322,7/24/2014,9/6/2018,2014,ICSA-14-205-02A,Siemens SIMATIC WinCC Vulnerabilities (Update A),Siemens,SIMATIC WinCC,SIMATIC WinCC: all versions prior to Version 7.3 and SIMATIC PCS7 (as WinCC is incorporated): all versions prior to Version 8.1.,"CVE-2014-4682, CVE-2014-4683, CVE-2014-4684, CVE-2014-4685, CVE-2014-4686",5.5,Medium,"CWE-425, CWE-269, CWE-264, CWE-384, CWE-321",Chemical; Energy; oil and gas; Food and Agriculture; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 321,9/30/2014,9/6/2018,2014,ICSA-14-273-01,SchneiderWEB Server Directory Traversal Vulnerability,Schneider Electric,Server Directory,There are 22 Affected Products containing 66 affected part numbers. Please download Schneider-Electric Security Notification SEVD-14-260-01 for the affected product details.,CVE-2014-0754,10.0,High,CWE-22,Communications; Critical Manufacturing; Energy; Water and Wastewater,France,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 320,9/11/2014,9/6/2018,2014,ICSA-14-254-02,Rockwell Micrologix 1400 DNP3 DOS Vulnerability,Rockwell Automation,Micrologix 1400 DNP3,Allen-Bradley MicroLogix 1400 controller platforms are affected: 1766-Lxxxxx Series A FRN 7 and earlier and1766-Lxxxxx Series B FRN 15.000 and earlier,CVE-2014-5410,7.1,High,CWE-20,Chemical; Critical Manufacturing; Food and Agriculture; Water and Wastewater,"China, Czech Republic, Germany, Denmark, France, Hungary, Italy, Japan, South Korea, Poland, United States, South America, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 319,9/18/2014,9/6/2018,2014,ICSA-14-261-01,Advantech WebAccess Vulnerabilities,Advantech,WebAccess,WebAccess Version 7.2.,"CVE-2014-0985, CVE-2014-0986, CVE-2014-0987, CVE-2014-0988, CVE-2014-0989, CVE-2014-0990, CVE-2014-0991, CVE-2014-0992",6.8,Medium,CWE-119,Commercial Facilities; Critical Manufacturing; Energy; Government Facilities,Taiwan,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 318,9/11/2014,9/6/2018,2014,ICSA-14-254-01,Schneider Electric VAMPSET Buffer Overflow,Schneider Electric,VAMPSET,VAMPSET v2.2.136 and all previous versions.,CVE-2014-5407,4.1,Medium,CWE-121,Energy,France,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 317,8/12/2014,9/6/2018,2014,ICSA-14-224-01,Ecava Integraxor SCADA Server Vulnerabilities,Ecava,Integraxor SCADA Server,IntegraXor SCADA Server v4.1.4360 (latest stable release) and earlier versions and IntegraXor SCADA Server v4.1.4392 (latest beta release) and earlier versions.,"CVE-2014-2375, CVE-2014-2376, CVE-2014-2377, CVE-2014-0786",7.1,High,"CWE-526, CWE-73, CWE-89, CWE-269, CWE-532",Critical Manufacturing,"Australia, Canada, Estonia, United Kingdom, Malaysia, Poland, United States",Malaysia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 316,8/26/2014,9/6/2018,2014,ICSA-14-238-01,CG Automation Improper Input Validation,CG Automation,Improper Input Validation,CG Automation products affected: ePAQ-9410 Substation Gateway - all versions.,"CVE-2014-0761, CVE-2014-0762",5.9,Medium,CWE-20,Energy,"Australia, China, Czech Republic, Germany, France, United Kingdom, India, Italy, Netherlands, United States, South America, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 315,8/26/2014,8/29/2018,2014,ICSA-14-238-02,Schneider Electric Wonderware Vulnerabilities,Schneider Electric,Wonderware,Wonderware Information Server 4.0 SP1 Portal | Wonderware Information Server 4.5 Portal | Wonderware Information Server 5.0 Portal and Wonderware Information Server 5.5 Portal.,"CVE-2014-2381, CVE-2014-2380, CVE-2014-5397, CVE-2014-5398, CVE-2014-5399",5.4,Medium,"CWE-20, CWE-79, CWE-89, CWE-326",Chemical; Commercial Facilities; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,"France, United States, Asia, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 314,8/14/2014,8/22/2018,2014,ICSA-14-226-01,Siemens SIMATIC S7-1500 CPU Denial of Service,Siemens,SIMATIC S7-1500 CPU,Siemens SIMATIC S7-1500 CPU versions affected: SIMATIC S7-1500 CPU all versions before V1.6.,CVE-2014-5074,7.1,High,CWE-189,Chemical; Critical Manufacturing; Food and Agriculture,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 313,7/15/2014,9/6/2018,2014,ICSA-14-196-01,SubSTATION Server Telegyr 8979 Master Vulnerabilities,SUBNET Solutions Inc.,SubSTATION Server Telegyr 8979 Master,SubSTATION Server 2 Telegyr 8979 Master Protocol - All Versions.,CVE-2014-2357,8.3,High,CWE-20,Energy; oil and gas,"Canada, United States",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 312,7/8/2014,9/6/2018,2014,ICSA-14-189-02,Innominate mGuard Unauthorized Leakage of System Data,Innominate,mGuard,"Innominate mGuard firmware Versions 4.0.0 up to Version 8.0.2 | Innominate mGuard firmware Versions 7.6.4 patch release and firmware Versions 8.0.3, 8.1.0 | 8.1.1 and higher are not affected.",CVE-2014-2356,4.3,Medium,CWE-200,Communications; Critical Manufacturing; Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 311,7/24/2014,9/6/2018,2014,ICSA-14-205-01,Morpho Itemiser 3 Hard-Coded Credential,Morpho,Itemiser 3,Itemiser 3 v 8.17.,CVE-2014-2363,10.0,High,CWE-259,Defense Industrial Base; Emergency Services,"Australia, China, Czech Republic, Germany, France, United Kingdom, India, Netherlands, United States",Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 310,1/7/2014,9/6/2018,2014,ICSA-14-007-01B,Sierra Wireless AirLink Raven X EV-DO Vulnerabilities (Update B),Sierra Wireless,AirLink Raven X EV-DO,AirLink Raven X EV-DO Versions V4221_4.0.11.003 and V4228_4.0.11.003.,"CVE-2013-2819, CVE-2013-2820",9.7,High,"CWE-294, CWE-311",Energy; Transportation Systems,"Canada, China, France, United States, Europe",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 309,7/22/2014,1/31/2019,2014,ICSA-14-203-01,Omron NS Series HMI Vulnerabilities,Omron,NS Series HMI,NS15 Version 8.1xx - 8.68x | NS12 Version 8.1xx - 8.68x | NS10 Version 8.1xx - 8.68x | NS8 Version 8.1xx - 8.68x and NS5 Version 8.1xx - 8.68x.,"CVE-2014-2369, CVE-2014-2370",4.3,Medium,"CWE-352, CWE-79",Critical Manufacturing; Healthcare and Public Health,Japan,Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 308,6/24/2014,9/6/2018,2014,ICSA-14-175-01,Honeywell FALCON XLWeb Controllers Vulnerabilities,Honeywell,FALCON XLWeb Controllers,Honeywell FALCON XLWeb controller versions affected: FALCON Linux 2.04.01 or older | FALCON XLWebExe 2.02.11 or older.,"CVE-2014-2717, CVE-2014-3110",6.0,Medium,"CWE-552, CWE-79",Critical Manufacturing; Energy; Water and Wastewater,"Europe, Middle East",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 307,7/17/2014,9/6/2018,2014,ICSA-14-198-02,Advantech WebAccess Vulnerabilities,Advantech,WebAccess,WebAcess v7.1 and earlier.,"CVE-2014-2364, CVE-2014-2368, CVE-2014-2367, CVE-2014-2366, CVE-2014-2365",7.6,High,"CWE-316, CWE-284, CWE-592, CWE-121, CWE-623",Commercial Facilities; Critical Manufacturing; Energy; Government Facilities,Taiwan,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 306,7/17/2014,9/6/2018,2014,ICSA-14-198-01,Cogent DataHub Code Injection Vulnerability,Cogent Real-Time Systems Inc,DataHub,Cogent DataHub V7.3.4 and earlier.,CVE-2014-3789,7.5,High,CWE-94,Chemical; Commercial Facilities; Critical Manufacturing; Energy; Financial Services,"Canada, United Kingdom, United States",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 305,7/8/2014,9/6/2018,2014,ICSA-14-189-01,Yokogawa Centum Buffer Overflow Vulnerability,Yokogawa,Centum,CENTUM CS 1000 all revisions |CENTUM CS 3000 R3.09.50 or earlier | CENTUM CS 3000 Entry Class R3.09.50 or earlier | CENTUM VP R5.03.20 or earlier | CENTUM VP Entry Class R5.03.20 or earlier | Exaopc R3.72.00 or earlier | B/M9000CS R5.05.01 or earlier and B/M9000 VP R7.03.01 or earlier.,CVE-2014-3888,8.3,High,CWE-121,Critical Manufacturing; Energy; Food and Agriculture,"Japan, South America, Asia, Europe, Africa, Middle East, Central America",Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 304,5/6/2014,9/6/2018,2014,ICSA-14-126-01A,ABB Relion 650 Series OpenSSL Vulnerability (Update A),ABB,Relion 650 Series OpenSSL,ABB Relion versions affected: 650 series Ver 1.3.0.,CVE-2014-0160,5.0,Medium,CWE-119,Multiple Critical Sectors,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 303,6/27/2014,7/20/2021,2014,ICSA-14-178-01,ICS Focused Malware,Other,ICS Malware,"ICS Focused Malware Havex | Industrial Control System (ICS) focused malware campaign that uses multiple vectors for infection. These include phishing emails, redirections to compromised web sites and most recently, trojanized update installers on at least three ICSs vendor web sites, in what are referred to as watering-hole style attacks. Software installers for these vendors were infected with malware known as the Havex Trojan (Backdoor.Oldrea), Trojan.Karagany and the Lightsout exploit kit. Trojan.Karagany targets energy and oil sectors. OPC PAYLOAD Havex is a Remote Access Trojan (RAT) that communicates with a Command and Control (C&C) server. Affected Products: classic DCOM-based (Distributed Component Object Model) version of the Open Platform Communications (OPC) standard. The known components of the identified Havex payload do not appear to target devices using the newer OPC Unified Architecture (UA) standard. The original version of the OPC specification, referred to as OPC classic, was implemented using Microsoft's COM/DCOM (Distributed Component Object Model) technology. In 2006, the OPC Foundation released a new standard, referred to as OPC Unified Architecture (UA), which does not use COM/DCOM. The known components of the identified HAVEX malware payload do not appear to target devices using the newer OPC UA standard.",CVE-NA,Not Applicable,Not Applicable,CWE-NA,Energy; Oil,"Germany, Spain, France, Italy, United States",Not Applicable,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 302,6/5/2014,8/23/2018,2014,ICSA-14-156-01,OpenSSL Releases Security Advisory,Other,OpenSSL,OpenSSL Versions 1.0.1 through 1.0.1f and 1.0.2-beta1,CVE-2014-0224,7.4,High,CWE-326,Multiple Critical Sectors,Worldwide,Not Applicable,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 301,6/3/2014,9/6/2018,2014,ICSA-14-154-01,COPA-DATA Improper Input Validation,COPA-DATA,Improper Input Validation,COPA-DATA products affected: zenon DNP3 NG driver (DNP3 master) - Versions 7.10 SP0 up to and including 7.11 SP0 build 10238 | zenon DNP3 Process Gateway (DNP3 outstation) - Versions 7.11 SP0 build 10238 and prior.,"CVE-2014-2345, CVE-2014-2346",5.6,Medium,CWE-20,Energy; Water and Wastewater,"Austria, Australia, United States, North America, South America, Asia, Europe, Africa",Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 300,5/29/2014,9/6/2018,2014,ICSA-14-149-01,Triangle MicroWorks Uncontrolled Resource Consumption,Triangle MicroWorks,Uncontrolled Resource Consumption,SCADA Data Gateway - versions prior to v3.00.0635.,"CVE-2014-2342, CVE-2014-2343",2.8,Low,CWE-400,Energy; Government Facilities; Transportation Systems; Water and Wastewater,"Australia, New Zealand, United States, South America, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 299,5/29/2014,9/6/2018,2014,ICSA-14-149-02,Cogent DataHub Vulnerabilities,Cogent Real-Time Systems Inc,DataHub,DataHub versions prior to 7.3.5.,"CVE-2014-2353, CVE-2014-2352, CVE-2014-2354",7.0,High,"CWE-22, CWE-80, CWE-916",Chemical; Commercial Facilities; Critical Manufacturing; Energy; Financial Services,"Canada, United Kingdom, United States",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 298,3/28/2014,9/6/2018,2014,ICSA-14-087-01A,Siemens ROS Improper Input Validation (Update A),Siemens,ROS,"Siemens ROS versions affected: All ROS versions prior to v3.11,ROS v3.11 (for product RS950G): all versions prior to ROS v3.11.5 | ROS v3.12: all versions prior to ROS v3.12.4 | ROS v4.0 (for product RSG2488): all versions prior to ROS v4.1.0.",CVE-2014-2590,5.0,Medium,CWE-20,Energy; Healthcare and Public Health; Transportation Systems,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 297,2/20/2014,9/6/2018,2014,ICSA-14-051-03B,Siemens RuggedCom Uncontrolled Resource Consumption Vulnerability (Update B),Siemens,RuggedCom,All ROS versions prior to v3.11 | ROS v3.11 (for product RS950G): all versions prior to ROS v3.11.5 | ROS v3.12: all versions prior to ROS v3.12.4 | ROS v4.0 (for product RSG2488): all versions prior to ROS v4.1.0.,CVE-2014-1966,2.6,Low,CWE-400,Energy; Transportation Systems,"Germany, Malaysia, United States, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 296,5/13/2014,9/6/2018,2014,ICSA-14-133-02,Emerson DeltaV Vulnerabilities,Emerson,DeltaV,"DeltaV Versions 10.3.1 | 11.3, 11.3.1 and 12.3.","CVE-2014-2349, CVE-2014-2350",4.3,Medium,"CWE-285, CWE-798",Chemical; Energy; oil and gas,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 295,4/15/2014,9/6/2018,2014,ICSA-14-105-03B,Siemens Industrial Products OpenSSL Heartbleed Vulnerability (Update B),Siemens,Industrial Products OpenSSL,Siemens products affected: eLAN-8.2 eLAN prior to 8.3.3 (affected when RIP is used”update available) | WinCC OA only V3.12 (always affected”update available) | S7-1500 V1.5 (affected when HTTPS active”update available) | CP1543-1 V1.1 (affected when FTPS active”update available) | APE 2.0 (affected when SSL/TLS component is used in customer implementation”update available).,CVE-2014-0160,5.0,Medium,CWE-119,Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 294,5/15/2014,9/6/2018,2014,ICSA-14-135-01,CSWorks Software SQL Injection Vulnerability,CSWorks,CSWork Software SQL,CSWorks Version 2.5.5050.0 and prior.,CVE-2014-2351,7.5,High,CWE-89,Commercial Facilities; Communications; Critical Manufacturing,"Canada, Spain, Norway, Russia",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 293,5/15/2014,8/27/2018,2014,ICSA-14-135-02,Schneider Electric Wonderware Intelligence Security Patch for OpenSSL Vulnerability,Schneider Electric,Wonderware Intelligence OpenSSL,Web Server & CLI vulnerabilities: VxWorks Versions 5.5 through 6.9 and SSH vulnerabilities: VxWorks Versions 6.5 through 6.9 |GE reports the vulnerabilities affect the following D20MX versions: D20MX v1.0-1.6.2.,CVE-2014-0160,5.0,Medium,CWE-119,Critical Manufacturing; Energy; Healthcare and Public Health; Water and Wastewater,France,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 292,5/15/2014,9/6/2018,2014,ICSA-14-135-04,Unified Automation OPC SDK OpenSSL Vulnerability,Unified Automation,OPC SDK OpenSSL,Unified Automation GmbH OPC UA SDK for Windows versions are affected: C++ based OPC UA SDK V1.4.0 (Windows) and ANSI C based OPC UA SDK V1.4.0 (Windows).,CVE-2014-0160,5.0,Medium,CWE-119,Critical Manufacturing; Energy,"United States, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 291,5/15/2014,8/27/2018,2014,ICSA-14-135-05,OpenSSL Vulnerability,Other,OpenSSL Vulnerability,OpenSSL Versions 1.0.1 through 1.0.1f and 1.0.2-beta1.,CVE-2014-0160,5.0,Medium,CWE-125,Multiple Critical Sectors,Worldwide,Not Applicable,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 290,5/13/2014,9/6/2018,2014,ICSA-14-133-01,Yokogawa Multiple Products Vulnerabilities,Yokogawa,Yokogawa Multiple Products,Yokogawa products affected by all four vulnerabilities: CENTUM CS 1000 all revisions | CENTUM CS 3000 Entry Class R3.09.50 and earlier | CENTUM VP R5.03.00 and earlier | CENTUM VP Entry Class R5.03.00 and earlier | Exaopc R3.71.02 and earlier | B/M9000CS R5.05.01 and earlier | B/M9000 VP R7.03.01 and earlier. The following Yokogawa products are affected only by the first vulnerability listed below: ProSafe-RS R1.03.00 and earlier | Exapilot R3.96.00 and earlier | Exaplog R3.40.00 and earlier | Exaquantum R2.02.50 to R2.80.00 | Exasmoc R4.03.20 and earlier | Exarqe R4.03.20 and earlier | AAASuite R1.20.13 and earlier | PRM R3.11.20 and earlier | STARDOM FCN/FCJ OPC Server for Windows R3.40.01 and earlier | Field Wireless Device OPC Server R2.01.01 and earlier | DAQOPC R3.01 and earlier | FieldMate R1.03 and earlier | EJXMVTool R1.02.00 to R1.02.02 | RPO Production Supervisor VP R1.03.00 and earlier | CENTUM Long-term Trend Historian all versions | CENTUM Event Viewer Package all versions.,"CVE-2014-0781, CVE-2014-0783, CVE-2014-0784, CVE-2014-0782",8.7,High,"CWE-122, CWE-121",Critical Manufacturing; Energy; Food and Agriculture,"Japan, South America, Asia, Europe, Africa, Middle East, Central America",Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 289,3/11/2014,9/6/2018,2014,ICSA-14-070-01A,Yokogawa CENTUM CS 3000 Vulnerabilities (Update A),Yokogawa,CENTUM CS 3000,CENTUM CS 3000 R3.09.50 and earlier.,"CVE-2014-0781, CVE-2014-0783, CVE-2014-0782",8.9,High,"CWE-122, CWE-121",Critical Manufacturing; Energy; Food and Agriculture,"Japan, South America, Asia, East Asia, Europe, Africa, Middle East, Central America",Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 288,5/8/2014,9/6/2018,2014,ICSA-14-128-01,Digi International OpenSSL Vulnerability,"Digi International, Inc.",Digi International OpenSSL,ConnectPort LTS | ConnectPort X2e | Digi Embedded Linux 5.9 | Digi Embedded Yocto 1.4 | Wireless Vehicle Bus Adapter (WVA).,CVE-2014-0160,5.0,Medium,CWE-119,Commercial Facilities; Communications; Critical Manufacturing; Energy; Transportation Systems,"United States, South America, Asia, Europe, Africa, Middle East",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 287,5/1/2014,5/1/2014,2014,ICSA-14-121-01,AMTELCO miSecure Vulnerabilities,AMTELCO,miSecure,AMTELCO products affected: miSecureMessages - Version 6.2 (to include Android | iPhone | Blackberry mobile device applications).,"CVE-2014-2347, CVE-2014-0357",7.0,High,"CWE-200, CWE-287",Healthcare and Public Health,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 286,4/1/2014,9/6/2018,2014,ICSA-14-091-01,Ecava IntegraXor Guest Account Information Disclosure Vulnerability,Ecava,IntegraXor,IntegraXor versions prior to 4.1.4410.,CVE-2014-0786,7.5,High,CWE-200,Critical Manufacturing,"Australia, Canada, Estonia, United Kingdom, Malaysia, Poland, United States",Malaysia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 285,4/24/2014,8/23/2018,2014,ICSA-14-114-01,Certec atvise scada OpenSSL Heartbleed Vulnerability,Certec EDV GmbH,atvise scada OpenSSL,Certec atvise scada Versions 2.3 and above.,CVE-2014-0160,5.0,Medium,CWE-119,Commercial Facilities; Critical Manufacturing; Energy; oil and gas; Transportation Systems; Water and Wastewater,Austria,Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 284,4/24/2014,9/6/2018,2014,ICSA-14-114-02,Siemens SIMATIC S7-1200 CPU Web Vulnerabilities,Siemens,SIMATIC S7-1200 CPU,SIMATIC S7-1200 CPU family Versions: V2.X and V3.X.,"CVE-2014-2908, CVE-2014-2909",5.1,Medium,"CWE-113, CWE-79",Chemical; Critical Manufacturing; Food and Agriculture,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 283,3/25/2014,9/6/2018,2014,ICSA-14-084-01,Festo CECX-X-(C1/M1) Controller Vulnerabilities,Festo,CECX-X-(C1/M1) Controller,CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion.,"CVE-2014-0760, CVE-2014-0769, CVE-2012-6068, CVE-2012-6069",9.7,High,"CWE-284, CWE-287",Critical Manufacturing,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 282,4/17/2014,8/23/2018,2014,ICSA-14-107-02,InduSoft Web Studio Directory Traversal Vulnerability,InduSoft,Web Studio,Web Studio Version 7.1.,CVE-2014-0780,7.5,High,CWE-22,Commercial Facilities; Critical Manufacturing; Energy; Food and Agriculture; Healthcare and Public Health; Water and Wastewater,"China, France, India, Poland, Portugal, Taiwan, United States",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 281,4/17/2014,9/6/2018,2014,ICSA-14-107-01,Siemens SINEMA Vulnerabilities,Siemens,SINEMA,SINEMA server: all versions prior to V12 SP1.,"CVE-2014-2731, CVE-2014-2732, CVE-2014-2733",6.4,Medium,"CWE-94, CWE-20, CWE-23",Chemical; Commercial Facilities; Critical Manufacturing; Energy; Government Facilities; Water and Wastewater,"Germany, United States, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 280,4/15/2014,9/6/2018,2014,ICSA-14-105-02A,Innominate mGuard OpenSSL HeartBleed Vulnerability (Update A),Innominate,mGuard OpenSSL,mGuard firmware Versions 8.0.0 and 8.0.1 | mGuard firmware versions prior to 8.0.0 whether running on Innominate - Phoenix Contact or other brands of devices are NOT affected.,CVE-2014-0160,5.0,Medium,CWE-119,Communications; Critical Manufacturing; Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 279,4/15/2014,9/6/2018,2014,ICSA-14-105-01,Progea Movicon SCADA Information Disclosure Vulnerability,Progea,Movicon SCADA,Progea Movicon 11.4 prior to Build 1150.,CVE-2014-0778,4.3,Medium,CWE-200,Critical Manufacturing; Energy; Water and Wastewater,"India, United States, Europe",Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 278,4/10/2014,9/6/2018,2014,ICSA-14-100-01,IOServer Out of Bounds Read Vulnerability,IOServer,IOServer,IOServer versions affected: OPC Drivers Versions 1.0.20 and prior.,CVE-2014-0777,8.3,High,CWE-125,Commercial Facilities; Critical Manufacturing; Energy,Australia,Australia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 277,12/7/2012,9/6/2018,2014,ICSA-12-342-01B,"Rockwell Allen-Bradley MicroLogix, SLC 500, and PLC-5 Fault Generation Vulnerability (Update B)",Rockwell Automation,"Allen-Bradley MicroLogix, SLC 500, and PLC-5",MicroLogix 1100 controller MicroLogix 1200 controller MicroLogix 1400 controller MicroLogix 1500 controller SLC 500 controller platform andPLC-5 controller platform,CVE-2012-4690,7.1,High,CWE-471,Chemical,"China, Czech Republic, Germany, Denmark, France, Hungary, Italy, Japan, South Korea, Poland, United States, South America, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 276,10/18/2013,9/6/2018,2014,ICSA-13-291-01B,DNP3 Implementation Vulnerability (Update B),Other,DNP3,Alstrom | Catapult Software | Cooper Power Systems | Cooper Power Systems/Cybectec | Elecsys | GE | IOServer | Kepware Technologies | MatrikonOPC | NovaTech | OSISoft | Schneider Electric | Schweitzer Engineering Laboratories | Software Toolbox | SUBNET Solutions | Triangle MicroWorks products.,CVE-NA,5.9,Medium,CWE-20,Commercial Facilities; Energy; Government Facilities,Worldwide,Not Applicable,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 275,4/8/2014,8/27/2018,2014,ICSA-14-098-01,OSIsoft PI Interface for DNP3 Improper Input Validation,OSIsoft,PI Interface for DNP3,All versions of the OSIsoft PI Interface for DNP3 prior to Version 3.1.2.54 are known to be affected.,"CVE-2013-2809, CVE-2013-2828",5.9,Medium,CWE-20,Energy; Water and Wastewater,"North America, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 274,4/8/2014,9/6/2018,2014,ICSA-14-098-02,WellinTech KingSCADA Stack-Based Buffer Overflow,WellinTech,KingSCADA,KingSCADA - all versions prior to v3.1.2.13.,CVE-2014-0787,10.0,High,CWE-121,Commercial Facilities; Energy; Water and Wastewater,"China, Japan, Singapore, Taiwan, United States, Europe",China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 273,4/8/2014,9/6/2018,2014,ICSA-14-098-03,Siemens Ruggedcom WIN Products BEAST Attack Vulnerability,Siemens,Ruggedcom WIN Products,WIN7000: all versions prior to v4.4 | WIN7200: all versions prior to v4.4 | WIN5100: all versions prior to v4.4 and WIN5200: all versions prior to v4.4.,CVE-2011-3389,4.3,Medium,CWE-20,Energy; Transportation Systems,"Germany, United States, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 272,3/20/2014,9/6/2018,2014,ICSA-14-079-03,Advantech WebAccess Vulnerabilities,Advantech,WebAccess,WebAccess Version 7.1 and previous.,"CVE-2014-0763, CVE-2014-0764, CVE-2014-0765, CVE-2014-0766, CVE-2014-0767, CVE-2014-0768, CVE-2014-0770, CVE-2014-0771, CVE-2014-0772, CVE-2014-0773",7.0,High,"CWE-538, CWE-77, CWE-89, CWE-121",Commercial Facilities; Critical Manufacturing; Energy; Government Facilities,Taiwan,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 271,4/3/2014,9/6/2018,2014,ICSA-14-093-01,Schneider Electric OPC Factory Server Buffer Overflow,Schneider Electric,OPC Factory Server,Schneider Electric versions of OFS: TLXCDSUOFS33 - V3.5 and previous | TLXCDSTOFS33 - V3.5 and previous | TLXCDLUOFS33 - V3.5 and previous | TLXCDLTOFS33 - V3.5 and previous | TLXCDLFOFS33 - V3.5 and previous.,CVE-2014-0789,5.0,Medium,CWE-122,Commercial Facilities; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater,"France, United States, North America",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 270,3/27/2014,9/6/2018,2014,ICSA-14-086-01A,Schneider Electric Serial Modbus Driver Buffer Overflow (Update A),Schneider Electric,Serial Modbus Driver,"Schneider Electric products bundle the Schneider Electric Modbus Serial Driver (ModbusDrv.exe) which is started when attempting to connect to a Programmable Logic Controller (PLC) via the serial port of a personal computer: TwidoSuite Versions 2.31.04 and earlier | PowerSuite Versions 2.6 and earlier | SoMove Versions 1.7 and earlier | SoMachine Versions 2.0, 3.0 | 3.1 | 3.0 XS | Unity Pro Versions 7.0 and earlier | UnityLoader Versions 2.3 and earlier | Concept Versions 2.6 SR7 and earlier | ModbusCommDTM sl Versions 2.1.2 and earlier | PL7 Versions 4.5 SP5 and earlier | SFT2841 Versions 14 | 13.1 and earlier | OPC Factory Server (OFS) Versions 3.40 and earlier. Modbus Serial Driver versions that are affected: Windows XP 32 bit V1.10 IE v37 | Windows Vista 32 bit V2.2 IE12 | Windows 7 32 bit V2.2 IE12 | Windows 7 64 bit V3.2 IE12.",CVE-2013-0662,9.3,High,CWE-121,Chemical; Critical Manufacturing; Dams; Energy; Food and Agriculture; Government Facilities; Nuclear Reactors Materials and Waste; Transportation Systems,"China, France, United States, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 269,3/27/2014,9/6/2018,2014,ICSA-14-086-01,Schneider Electric Serial Modbus Driver Buffer Overflow,Schneider Electric,Serial Modbus Driver,Schneider Electric products bundle the Schneider Electric Modbus Serial Driver (ModbusDrv.exe) which is started when attempting to connect to a Programmable Logic Controller (PLC) via the serial port of a personal computer: TwidoSuite Versions 2.31.04 and earlier | PowerSuite Versions 2.6 and earlier | SoMove Versions 1.7 and earlier | SoMachine Versions 2.0 | 3.0 | 3.1 | 3.0 XS |Unity Pro Versions 7.0 and earlier | UnityLoader Versions 2.3 and earlier | Concept Versions 2.6 SR7 and earlier | ModbusCommDTM sl Versions 2.1.2 and earlier | PL7 Versions 4.5 SP5 and earlier | SFT2841 Versions 14 | 13.1 and earlier | OPC Factory Server Versions 3.50 and earlier. Modbus Serial Driver versions that are affected: Windows XP 32 bit V1.10 IE v37 | Windows Vista 32 bit V2.2 IE12 | Windows 7 32 bit V2.2 IE12 | Windows 7 64 bit V3.2 IE12.,CVE-2013-0662,9.3,High,CWE-121,Chemical; Critical Manufacturing; Dams; Energy; Food and Agriculture; Government Facilities; Nuclear Reactors Materials and Waste; Transportation Systems,"China, France, United States, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 268,3/20/2014,9/6/2018,2014,ICSA-14-079-01,Siemens SIMATIC S7-1200 Improper Input Validation Vulnerabilities,Siemens,SIMATIC S7-1200,SIMATIC S7-1200 PLC versions affected: SIMATIC S7-1200 PLC family: all versions before V4.0.0.,"CVE-2013-2780, CVE-2013-0700",7.8,High,CWE-20,Chemical; Critical Manufacturing; Food and Agriculture,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 267,3/20/2014,8/23/2018,2014,ICSA-14-079-02,Siemens SIMATIC S7-1200 Vulnerabilities,Siemens,SIMATIC S7-1200,SIMATIC S7-1200 versions are affected: SIMATIC S7-1200 CPU family - all versions prior to V4.0.,"CVE-2014-2249, CVE-2014-2258, CVE-2014-2250, CVE-2014-2252, CVE-2014-2254, CVE-2014-2256",7.3,High,"CWE-352, CWE-404, CWE-331",Chemical; Critical Manufacturing; Food and Agriculture,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 266,7/31/2012,9/6/2018,2014,ICSA-12-213-01A,Sielco Sistemi Winlog Multiple Vulnerabilities (Update A),Sielco Sistemi,Winlog,Winlog Pro SCADA all versions prior to 2.07.18 Winlog Lite SCADA all versions prior to 2.07.18,"CVE-2012-3815, CVE-2012-4353, CVE-2012-4354, CVE-2012-4355, CVE-2012-4356, CVE-2012-4358, CVE-2012-4359",8.6,High,"CWE-284, CWE-22, CWE-119, CWE-118, CWE-123",Critical Manufacturing,"Canada, Spain, Indonesia, Italy, Turkey, United States",Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 265,3/14/2014,9/6/2018,2014,ICSA-14-073-01,Siemens SIMATIC S7-1500 CPU Firmware Vulnerabilities,Siemens,SIMATIC S7-1500 CPU Firmware,SIMATIC S7-1500 versions are affected: SIMATIC S7-1500 CPU family - all versions older than V1.5.,"CVE-2014-2249, CVE-2014-2246, CVE-2014-2247, CVE-2014-2251, CVE-2014-2248, CVE-2014-2259, CVE-2014-2253, CVE-2014-2255, CVE-2014-2257",6.4,Medium,"CWE-352, CWE-80, CWE-331, CWE-601, CWE-404",Chemical; Critical Manufacturing; Energy; Food and Agriculture; Water and Wastewater,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 264,3/13/2014,9/6/2018,2014,ICSA-14-072-01,Schneider Electric StruxureWare SCADA Expert ClearSCADA Parsing Vulnerability,Schneider Electric,StruxureWare SCADA Expert ClearSCADA,SCADA Expert ClearSCADA versions affected: ClearSCADA 2010 R2 (build 71.4165) | ClearSCADA 2010 R2.1 (build 71.4325) | ClearSCADA 2010 R3 (build 72.4560) | ClearSCADA 2010 R3.1 (build 72.4644) | SCADA Expert ClearSCADA 2013 R1 (build 73.4729) | SCADA Expert ClearSCADA 2013 R1.1 (build 73.4832) | SCADA Expert ClearSCADA 2013 R1.1a (build 73.4903) | SCADA Expert ClearSCADA 2013 R1.2 (build 73.4955) |SCADA Expert ClearSCADA 2013 R2 (build 74.5094).,CVE-2014-0779,6.8,Medium,CWE-119,Commercial Facilities; Energy; Water and Wastewater,France,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 263,2/27/2014,9/6/2018,2014,ICSA-14-058-01,Schneider Electric Floating License Manager Vulnerability,Schneider Electric,Floating License Manager,Schneider Electric Floating License Manager Versions V1.0.0 through V1.4.0. This license manager is used in five Schneider Electric Products.,CVE-2014-0759,6.9,Medium,CWE-428,Commercial Facilities; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater,"United States, North America, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 262,2/27/2014,9/6/2018,2014,ICSA-14-058-02,Schneider Electric OFS Buffer Overflow Vulnerability,Schneider Electric,OFS,Schneider Electric OFS Test Client versions are affected: TLXCDSUOFS33 - V3.35 | TLXCDSTOFS33 - V3.35 | TLXCDLUOFS33 - V3.35 | TLXCDLTOFS33 - V3.35 | TLXCDLFOFS33 - V3.35.,CVE-2014-0774,6.8,Medium,CWE-121,Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater,"United States, North America, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 261,12/16/2013,9/6/2018,2014,ICSA-13-350-01A,Schneider Electric CitectSCADA Products Exception Handler Vulnerability (Update A),Schneider Electric,CitectSCADA Products,Schneider Electric versions affected:StruxureWare SCADA Expert Vijeo Citect v7.40 Vijeo Citect v7.20 to v7.30SP1 CitectSCADA v7.20 to v7.30SP1 StruxureWare PowerSCADA Expert v7.30 to v7.30SR1 andPowerLogic SCADA v7.20 to v7.20SR1.,CVE-2013-2824,7.8,High,CWE-248,Critical Manufacturing; Energy,France,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 260,2/20/2014,9/6/2018,2014,ICSA-14-051-01,ICONICS GENESIS32 Insecure ActiveX Control,ICONICS,GENESIS32,ICONICS product affected: GENESIS32 versions 8.0 | 8.02 | 8.04 | 8.05.,CVE-2014-0758,9.3,High,CWE-749,Commercial Facilities; Energy; Food and Agriculture; Healthcare and Public Health; Water and Wastewater,"Australia, China, Czech Republic, Germany, France, United Kingdom, India, Italy, Netherlands, Asia",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 259,2/20/2014,9/6/2018,2014,ICSA-14-051-02,Mitsubishi Electric Automation MC-WorX Suite Unsecure ActiveX Control,Mitsubishi Electric Automation,MC-WorX Suite,Mitsubishi Electric Automation Inc product affected: MC-WorX Suite Version 8.02.,CVE-2013-2817,9.3,High,CWE-749,Commercial Facilities; Critical Manufacturing; Energy; Water and Wastewater,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 258,2/20/2014,9/6/2018,2014,ICSA-14-051-04,NTP Reflection Attack,Other,NTP,Products using NTP service NTP-4.2.7p25 and prior (with MONLIST support) are affected. No specific vendor is specified as this is an open source protocol.,CVE-2013-521,7.8,High,CWE-20,Multiple Critical Sectors,Worldwide,Not Applicable,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 257,1/10/2014,9/6/2018,2014,ICSA-14-010-01,MatrikonOPC Improper Input Validation,MatrikonOPC,OPC,MatrikonOPC SCADA DNP3 OPC Server Version 1.2.2.0 and older.,CVE-2013-2829,7.1,High,CWE-20,Chemical; Energy,"Australia, Brazil, Canada, Costa Rica, Germany, Spain, United Kingdom, India, Norway, Portugal, Russia, Singapore, United States",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 256,2/4/2014,9/6/2018,2014,ICSA-14-035-01,Siemens SIMATIC WinCC OA Multiple Vulnerabilities,Siemens,SIMATIC WinCC OA,SIMATIC WinCC OA all versions prior to 3.12 P002.,"CVE-2014-1697, CVE-2014-1698, CVE-2014-1699, CVE-2014-1696",6.7,Medium,"CWE-94, CWE-20, CWE-23, CWE-916",Chemical; Energy; oil and gas; Food and Agriculture; Water and Wastewater,"Germany, United States, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 255,1/21/2014,9/6/2018,2014,ICSA-14-021-01,Rockwell RSLogix 5000 Password Vulnerability,Rockwell Automation,RSLogix 5000,RSLogix 5000 software versions affected: Project files (.ACD) created using RSLogix 5000 software | V7 through V20.01 and V21.0 containing password protected content.,CVE-2014-0755,6.3,Medium,CWE-522,Chemical; Critical Manufacturing; Food and Agriculture; Water and Wastewater,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 254,1/30/2014,9/6/2018,2014,ICSA-14-030-01,3S CoDeSys Runtime Toolkit NULL Pointer Dereference,3S-Smart Software Solutions,CoDeSys Runtime Toolkit,CoDeSys Runtime Toolkit versions older than Version V2.4.7.44.,CVE-2014-0757,7.1,High,CWE-476,Commercial Facilities; Critical Manufacturing; Energy,"China, Germany",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 253,1/6/2014,9/6/2018,2014,ICSA-14-006-01,Schneider Electric Telvent SAGE RTU DNP3 Improper Input Validation Vulnerability,Schneider Electric,Telvent SAGE RTU DNP3,"Schneider Electric versions affected: All versions released prior to December 1, 2013 | Telvent SAGE 3030 C3413-500-001D3_P4 (Firmware from 2010) | Telvent SAGE 3030 C3413-500-001F0_PB (Latest Firmware).",CVE-2013-6143,4.3,Medium,CWE-20,Energy,"United States, North America, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 252,1/23/2014,9/6/2018,2014,ICSA-14-023-01,GE Proficy Vulnerabilities,GE,Proficy,GE Intelligent Platforms products affected: Proficy HMI/SCADA - CIMPLICITY | Version 4.01 to 8.2 | Proficy Process Systems with CIMPLICITY.,"CVE-2014-0750, CVE-2014-0751",7.2,High,CWE-22,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 251,1/16/2014,9/6/2018,2014,ICSA-14-016-01,Ecava IntegraXor Buffer Overflow Vulnerability,Ecava,IntegraXor,IntegraXor version 4.1.4380 and prior.,CVE-2014-0753,7.8,High,CWE-121,Critical Manufacturing,"Australia, Canada, Estonia, United Kingdom, Malaysia, Poland, United States",Malaysia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 250,12/10/2013,9/6/2018,2014,ICSA-13-344-01,WellinTech Vulnerabilities,WellinTech,WellinTech Products,KingSCADA 3.1 and all previous versions | KingAlarm & Event 2.0.2 and all previous versions and KingGraphic 3.1 and all previous versions.,"CVE-2013-2826, CVE-2013-2827",7.5,High,"CWE-749, CWE-538",Commercial Facilities; Energy; Water and Wastewater,"China, Japan, Singapore, Taiwan, United States, Europe",China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 249,1/14/2014,9/6/2018,2014,ICSA-14-014-01,Schneider Electric ClearSCADA Uncontrolled Resource Consumption Vulnerability,Schneider Electric,ClearSCADA,Schneider Electric versions affected: ClearSCADA 2010 R2 (Build 71.4165) | ClearSCADA 2010 R2.1 (Build 71.4325) | ClearSCADA 2010 R3 (Build 72.4560) | ClearSCADA 2010 R3.1 (Build 72.4644) | SCADA Expert ClearSCADA 2013 R1 (Build 73.4729) | SCADA Expert ClearSCADA 2013 R1.1 (Build 73.4832) | SCADA Expert ClearSCADA 2013 R1.1a (Build 73.4903) | SCADA Expert ClearSCADA 2013 R1.2 (Build 73.4955).,CVE-2013-6142,4.3,Medium,CWE-400,Energy; Water and Wastewater,France,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 248,1/8/2014,9/6/2018,2014,ICSA-14-008-01,Ecava Sdn Bhd IntegraXor Project Directory Information Disclosure Vulnerability,Ecava,Sdn Bhd IntegraXor,IntegraXor - 4.1.4360 and earlier.,CVE-2014-0752,7.5,High,CWE-529,Critical Manufacturing,"Australia, Canada, Estonia, United Kingdom, Malaysia, Poland, United States",Malaysia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 247,4/4/2011,9/6/2018,2014,ICSA-11-094-02B,Advantech/Broadwin WebAccess RPC Vulnerability (Update B),Advantech,Broadwin WebAccess,"Affects all versions of WebAccess prior to Version 7.1 2013.05.30, including all legacy versions",CVE-2011-4041,10.0,High,CWE-94,Energy,"South America, Asia, Europe, North Africa, Africa, Middle East",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 246,12/18/2013,9/5/2018,2013,ICSA-13-352-01,NovaTech Orion DNP3 Improper Input Validation Vulnerability,NovaTech,Orion DNP3,Orion versions are affected: OrionLX DNP Master v1.27.38 and DNP Slave V1.23.10 and earlier (included in firmware releases 7.6 and earlier) andOrion5/Orion5r DNP Master V1.27.38 and DNP Slave V1.23.10 and earlier.,"CVE-2013-2821, CVE-2013-2822",6.0,Medium,CWE-20,Energy,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 245,12/13/2013,8/29/2018,2013,ICSA-13-347-01,Siemens COMOS Privilege Escalation,Siemens,COMOS,All COMOS versions prior to 9.2 | COMOS 9.2: all versions prior to V092_Upd08_Patch001 (9.2.0.8.1) | COMOS 10.0: all versions prior to V100_SP03_Upd01_Patch040 (10.0.3.1.40) | COMOS 10.1: all versions prior to V101_Patch002 (10.1.0.0.2).,CVE-2013-6840,7.2,High,CWE-269,Multiple Critical Sectors,"Germany, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 244,12/12/2013,12/18/2013,2013,ICSA-13-346-01,Cooper Power Systems Improper Input Validation Vulnerability,Cooper Power Systems,SMP 4 | SMP 16 Gateways,SMP 16 Gateway (Data Concentrator) all versions | SMP 4 Gateway (Data Concentrator) all versions and SMP 4/DP Gateway (Data Concentrator) all versions.,"CVE-2013-2813, CVE-2013-2816",7.4,High,CWE-20,Energy,"Canada, United States, North America, South America",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 243,12/12/2013,12/17/2013,2013,ICSA-13-346-02,Cooper Power Systems Cybectec DNP3 Master OPC Server Improper Input Validation,Cooper Power Systems,Cybectec DNP3 Master OPC Server,DNP3 Master OPC Server - all versions.,CVE-2013-2814,7.1,High,CWE-20,Energy,"Canada, United States, South America",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 242,12/6/2013,9/5/2018,2013,ICSA-13-340-01,RuggedCom ROS Multiple Vulnerabilities,RuggedCom,ROS,Siemens RuggedCom ROS versions device with ROS firmware version prior to v3.12.2.,"CVE-2013-6925, CVE-2013-6926",7.9,High,"CWE-592, CWE-330",Energy; Healthcare and Public Health; Transportation Systems,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 241,12/4/2013,9/5/2018,2013,ICSA-13-338-01,Siemens SINAMICS S/G Authentication Bypass Vulnerability,Siemens,SINAMICS S/G,SINAMICS S/G family with firmware version prior to 4.6.11.,CVE-2013-6920,10.0,High,CWE-592,Energy; Healthcare and Public Health; Transportation Systems,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 240,12/3/2013,9/5/2018,2013,ICSA-13-337-01,Elecsys Director Gateway Improper Input Validation Vulnerability,Elecsys,Director Gateway,Elecsys Director Gateway versions: Elecsys Director DNP3 Outstation kernel Version 2.6.32.11ael1 and all previous versions.,CVE-2013-2825,4.3,Medium,CWE-20,Defense Industrial Base; Emergency Services; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,"United States, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 239,11/25/2013,9/5/2018,2013,ICSA-13-329-01,Triangle Research Nano-10 PLC Improper Input Validation,"Triangle Research International, Inc.",Nano 10 PLC,TRi Inc. Nano-10 PLC firmware versions are affected: All firmware versions prior to r82.,CVE-2013-5741,7.8,High,CWE-20,Commercial Facilities; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,"Australia, Canada, South Korea, Singapore, United States",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 238,10/24/2013,12/17/2013,2013,ICSA-13-297-01,Catapult Software DNP3 Driver Improper Input Validation,Catapult Software,DNP3 Driver,"Catapult Software DNP driver (""DNP""): Version 7.20.56, and Proficy human-machine interface/supervisory control and data acquisition (HMI/SCADA) - iFIX or CIMPLICITY servers with the vulnerable I/O Driver installed (this includes iFIX or CIMPLICITY installations that are part of Proficy Process Systems).","CVE-2013-2811, CVE-2013-2823",7.4,High,CWE-20,Energy; oil and gas; Water and Wastewater,New Zealand,New Zealand,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 237,10/24/2013,12/17/2013,2013,ICSA-13-297-02,GE Proficy DNP3 Improper Input Validation,GE,Proficy DNP3,"Proficy human-machine interface/supervisory control and data acquisition (HMI/SCADA) DNP3 I/O Driver (""DNP""): Version 7.20j (Catapult v7.2.0.56) and prior versions. Proficy HMI/SCADA”iFIX or CIMPLICITY servers with the vulnerable I/O Driver installed (this includes iFIX or CIMPLICITY installations that are part of Proficy Process Systems).","CVE-2013-2811, CVE-2013-2823",6.5,Medium,CWE-20,Energy; oil and gas; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 236,10/22/2013,12/17/2013,2013,ICSA-13-295-01,WellinTech KingView ActiveX Vulnerabilities,WellinTech,KingView,KingView versions older than Version 6.53.,"CVE-2013-6127, CVE-2013-6128",6.5,Medium,"CWE-28, CWE-40",Commercial Facilities; Energy; Water and Wastewater,"China, Japan, Singapore, Taiwan, United States, Europe",China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 235,10/9/2013,12/17/2013,2013,ICSA-13-282-01A,Alstom e-Terracontrol DNP3 Master Improper Input Validation (Update A),Alstom,e-Terracontrol DNP3 Master,"e-terracontrol, Version 3.5, 3.6, and 3.7.","CVE-2013-2787, CVE-2013-2818",7.0,High,CWE-20,Energy,"France, Asia, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 234,10/16/2013,9/5/2018,2013,ICSA-13-289-01,Cisco ASA and FWSM Security Advisories,Cisco,ASA and FWSM,Cisco Firewall Services Module (FWSM) software for Cisco Catalyst 6500 Series switches and Cisco 7600 Series routers.,"CVE-2013-3415, CVE-2013-5507, CVE-2013-5508",7.1,High,"CWE-20, CWE-264, CWE-399",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 233,10/3/2013,12/17/2013,2013,ICSA-13-276-01,Invensys Wonderware InTouch Improper Input Validation Vulnerability,Invensys,Wonderware InTouch,InTouch HMI 2012 R2 and all previous versions.,CVE-2012-4709,6.3,Medium,CWE-20,Chemical; Energy; Food and Agriculture; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 232,4/5/2013,9/5/2018,2013,ICSA-13-095-02A,Rockwell Automation FactoryTalk and RSLinx Vulnerabilities (Update A),Rockwell Automation,FactoryTalk and RSLinx,FactoryTalk Service Platform and RSLinx Enterprise product versions: CPR9 CPR9-SR1 CPR9-SR2 CPR9-SR3 CPR9-SR4 CPR9-SR5 CPR9-SR5.1 and CPR9-SR6.,"CVE-2012-4713, CVE-2012-4714, CVE-2012-4695, CVE-2013-2805, CVE-2013-2807, CVE-2013-2806",7.7,High,"CWE-703, CWE-190, CWE-125",Critical Manufacturing; Chemical; Food and Agriculture; Water and Wastewater,"China, France, Italy, Japan, South Korea, Netherlands, United States, South America, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 231,10/4/2013,12/17/2013,2013,ICSA-13-277-01,Philips Xper Buffer Overflow Vulnerability,Philips,Xper,Xper Information Management versions are affected: Note: the following products are only affected if the XperConnect Broker is used in line. Xper Information Management Physiomonitoring 5 system components - Xper Information Management Vascular Monitoring 5 system components and Xper Information Management (Flex Cardio product line) servers and workstations.,CVE-2013-2808,9.3,High,CWE-122,Healthcare and Public Health,"United States, North America, South America, Asia, Europe, Africa, Middle East",Netherlands,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 230,10/1/2013,10/1/2013,2013,ICSA-13-274-01,Siemens SCALANCE X-200 Authentication Bypass Vulnerability,Siemens,SCALANCE X-200,SCALANCE X-200 MLFBs: 6GK5224-0BA00-2A.,CVE-2013-5944,10.0,High,CWE-592,Energy; Healthcare and Public Health; Transportation Systems,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 229,1/18/2012,9/6/2018,2013,ICSA-12-018-01B,Schneider Electric Quantum Ethernet Module Hard-Coded Credentials (Update B),Schneider Electric,Quantum Ethernet Module,"Quantum 140NOE77101 Firmware V4.9 and all previous versions 140NOE77111 Firmware V5.0 and all previous versions 140NOE77100 Firmware V3.4 and all previous versions 140NOE77110 Firmware V3.3 and all previous versions,140CPU65150 Firmware V3.5 and all previous versions,140CPU65160 Firmware V3.5 and all previous versions,140CPU65260 Firmware V3.5 and all previous versions,140NOC77100 Firmware V1.01 and all previous versions, and140NOC77101 Firmware V1.01 and all previous versions.Any available conformal-coated versions of the above part numbers.PremiumTSXETY4103 Firmware V5.0 and all previous versions,TSXETY5103 Firmware V5.0 and all previous versions,TSXP571634M Firmware V4.9 and all previous versions,TSXP572634M Firmware V4.9 and all previous versions,TSXP573634M Firmware V4.9 and all previous versions,TSXP574634M Firmware V3.5 and all previous versions,TSXP575634M Firmware V3.5 and all previous versions,TSXP576634M Firmware V3.5 and all previous versions, andTSXETC101 Firmware V1.01 and all previous versions.Any available conformal-coated versions of the above part numbers.M340BMXNOE0100 Firmware V2.3 and all previous versions,BMXNOE0110 Firmware V4.65 and all previous versions, andBMXNOC0401 Firmware V1.01 and all previous versions.The following products are affected by the FTP Service vulnerabilities only (not affected by Telnet or Windriver Debug vulnerabilities):STBNIC2212 Firmware V2.10 and all previous versions,STBNIP2311 Firmware V3.01 and all previous versions,STBNIP2212 Firmware V2.73 and all previous versions,BMXP342020 Firmware V2.2 and all previous versions, andBMXP342030 Firmware V2.2 and all previous versions",CVE-2011-4859,10.0,High,CWE-NA,Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 228,8/19/2013,9/6/2018,2013,ICSA-13-231-01B,Sixnet Universal Protocol Undocumented Function Codes (Update B),Sixnet,Universal Protocol,Versions older than UDR 2.0 and RTU firmware older than Version 4.8.,CVE-2013-2802,10.0,High,CWE-912,Commercial Facilities; Energy; Financial Services; Transportation Systems,"North America, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 227,9/11/2013,8/29/2018,2013,ICSA-13-254-01,Siemens SCALANCE X-200 Web Hijack Vulnerability,Siemens,SCALANCE X-200,SCALANCE X-200 switch family with firmware versions prior to V5.0.0. Alternatively the following products may be identified by using their Machine-Readable Product Designation (MLFB). Poducts with the following MLFBs are affected: 6GK5224-0BA00-2AA36GK5216-0BA00-2AA36GK5212-2BB00-2AA36GK5212-2BC00-2AA36GK5208-0BA10-2AA36GK5206-1BB10-2AA36GK5206-1BC10-2AA36GK5204-2BB10-2AA36GK5204-2BC10-2AA36GK5208-0HA10-2AA66GK5204-0BA00-2AF26GK5208-0BA00-2AF26GK5206-1BC00-2AF26GK5204-2BC00-2AF26GK5204-2BB10-2CA2.,CVE-2013-5709,8.3,High,CWE-331,Energy; Healthcare and Public Health; Transportation Systems,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 226,9/9/2013,7/31/2014,2013,ICSA-13-252-01,SUBNET Solutions Inc. SubSTATION Server DNP3 Outstation Improper Input Validation,SUBNET Solutions Inc.,SubSTATION Server DNP3 Outstation,SubSTATION Server v2.7.0033 and SubSTATION Server v2.8.0106.,CVE-2013-2788,7.1,High,CWE-20,Energy,Canada,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 225,9/5/2013,9/6/2013,2013,ICSA-13-248-01,ProSoft Technology RadioLinx ControlScape PRNG Vulnerability,ProSoft Technology,RadioLinx ControlScape PRNG,RadioLinx ControlScape versions prior to version FH v6.00.,CVE-2013-2803,9.3,High,CWE-338,Energy; oil and gas; Water and Wastewater,"Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 224,8/1/2013,10/3/2013,2013,ICSA-13-213-04A,MatrikonOPC SCADA DNP3 Master Station Improper Input Validation,MatrikonOPC,SCADA DNP3 Master Station,MatrikonOPC SCADA DNP3 OPC Server 1.2.0 and above.,CVE-2013-2791,7.1,High,CWE-20,Chemical; Energy; oil and gas,"Australia, Brazil, Canada, Costa Rica, Germany, Spain, United Kingdom, India, Norway, Portugal, Russia, Singapore, United States",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 223,8/28/2013,9/17/2013,2013,ICSA-13-240-01,Triangle MicroWorks Improper Input Validation,Triangle MicroWorks,MicroWorks,SCADA Data Gateway v2.50.0309 through v3.00.0616 DNP3 .NET Protocol components v3.06.0.171 through v3.15.0.369 DNP3 ANSI C source code libraries v3.06.0000 through v3.15.0000.,"CVE-2013-2793, CVE-2013-2794",6.3,Medium,CWE-20,Energy; Government Facilities; Transportation Systems; Water and Wastewater,"Australia, New Zealand, United States, South America, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 222,8/22/2013,8/22/2013,2013,ICSA-13-234-01,Schneider Electric Trio J-Series Radio Encryption,Schneider Electric,Trio J-Series Radio,"Electric Trio J-Series Radio versions running Firmware Versions V3.6.0, V3.6.1, V3.6.2, and V3.6.3 are affected:TBURJR900-00002DH0TBURJR900-01002DH0TBURJR900-05002DH0TBURJR900-06002DH0TBURJR900-00002EH0TBURJR900-01002EH0TBURJR900-05002EH0TBURJR900-06002EH0.",CVE-2013-2782,8.3,High,CWE-321,Energy; oil and gas; Water and Wastewater,"Australia, Brazil, United Kingdom, United States, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 221,8/22/2013,5/28/2015,2013,ICSA-13-234-02,Top Server OPC Improper Input Validation Vulnerability,Software Toolbox,Top Server OPC,DNP Master Driver for the TOP Server OPC Server (Version 5.11.250.0) and earlier.,CVE-2013-2804,7.1,High,CWE-20,Energy; oil and gas; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 220,8/21/2013,8/21/2013,2013,ICSA-13-233-01,Siemens COMOS Privilege Escalation Vulnerability,Siemens,COMOS,All COMOS versions prior to 9.1COMOS 9.1: all versions prior to LyraUpdate458 (Update 458)COMOS 9.2: all versions prior to V092_Upd06_Patch037 (9.2.0.6.37)COMOS 10.0: all versions prior to V100_SP03_Patch019 (10.0.3.0.19).,CVE-2013-4943,7.2,High,CWE-269,Multiple Critical Sectors,"Germany, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 219,8/14/2013,8/16/2013,2013,ICSA-13-226-01,Kepware Technologies Improper Input Validation Vulnerability,Kepware Technologies,Kepware Technologies' DNP Master Driver | KEPServerEX Communicaitons Platform,Kepware Technologies' DNP Master Driver for the KEPServerEX Communicaitons Platform (Version v5.11.250.0).,CVE-2013-2789,7.1,High,CWE-20,Commercial Facilities; Energy; oil and gas; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 218,8/13/2013,3/12/2014,2013,ICSA-13-225-01,Advantech WebAccess Cross-Site Scripting,Advantech,WebAccess,Advantech WebAccess 7.0 and prior.,CVE-2013-2299,6.3,Medium,CWE-79,Energy; Government Facilities,Taiwan,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 217,8/13/2013,5/6/2015,2013,ICSA-13-225-02,OSIsoft Multiple Vulnerabilities,OSIsoft,OSIsoft PI Interfaces,OSIsoft PI Interfaces affected: All versions of the PI Interface for IEEE C37.118 prior to Version 1.0.6.158.,"CVE-2013-2801, CVE-2013-2800",8.6,High,CWE-119,Energy,"United States, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 216,8/15/2012,3/6/2014,2013,ICSA-12-228-01A,Tridium Niagara Vulnerabilities (Update A),Tridium,Niagara,Niagara AX Framework software products,"CVE-2012-4027, CVE-2012-4028, CVE-2012-3025, CVE-2012-3024",6.8,Medium,"CWE-315, CWE-22, CWE-522, CWE-330",Commercial Facilities; Communications; Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 215,8/7/2013,8/12/2013,2013,ICSA-13-219-01,Schweitzer Engineering Laboratories Improper Input Validation,Schweitzer Engineering Laboratories,SEL-3530 SEL-3505 SEL-2241,SEL products affected: SEL-3530-R100 -V0-Z001001-D20090915 through SEL-3530- SEL-3530-R123-V0-Z002001· SEL-3530-4-R107-V0-Z001001-D20100818 through SEL-3530-4-R123-V0-Z002001-D20130117· SEL-3505-R119-V0-Z001001-D20120720 through SEL-3505-R123-V0-Z002001-D20130117· SEL-2241-R113-V0-Z001001-D20110721 through SEL-2241-R123-V0-Z002001-D20130117.,"CVE-2013-2792, CVE-2013-2798",7.4,High,CWE-20,Energy,"United States, North America, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 214,8/5/2013,8/6/2013,2013,ICSA-13-217-02,"Schneider Electric Vijeo Citect, CitectSCADA, PowerLogic SCADA Vulnerability",Schneider Electric,"Vijeo Citect, CitectSCADA, PowerLogic SCADA",Schneider Electric Vijeo Citect Version 7.20 and all previous versions | CitectSCADA Version 7.20 and all previous versions and· PowerLogic SCADA Version 7.20 and all previous 6 versions.,CVE-2013-2796,6.9,Medium,CWE-611,Critical Manufacturing; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 213,8/5/2013,6/2/2015,2013,ICSA-13-217-01,MOXA Weak Entropy in DSA Keys Vulnerability,Moxa,DSA Keys,Moxa OnCell Gateway models (before firmware version 1.4) are affected: G3111 G3151 G3211 and G3251.,CVE-2012-3039,7.1,High,CWE-331,Communications; Critical Manufacturing; Information Technology; Transportation Systems; Water and Wastewater,"Brazil, China, Germany, France, United Kingdom, India, Taiwan, United States, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 212,8/1/2013,8/2/2013,2013,ICSA-13-213-01,Siemens Scalance W-7xx Product Family Multiple Vulnerabilities,Siemens,Scalance W-7xx Product Family,"Firmware Version V4.5.4 and earlier are affected for the following Siemens Scalance W-7xx product family supporting IEEE 802.11a/b/g: SCALANCE W744-1 W746-1 W747-1 | SCALANCE W744-1PRO, W746-1PRO, W747-1RR | SCALANCE W784-1 W784-1RR | SCALANCE W786-1PRO W786-2PRO W786-3PRO W786-2RR | SCALANCE W788-1PRO W788-2PRO W788-1RR W788-2RR. Alternately - the Affected Products may be identified by using their MLFB. Products with the following MLFBs are affected: 6GK5 7xx-xAxx0-xAx0 6GK5 7xx-xBxx0-xAx0 and 6GK5 746-1AA60-4BA0.","CVE-2013-4651, CVE-2013-4652",9.0,High,"CWE-287, CWE-320",Energy; Healthcare and Public Health; Transportation Systems,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 211,8/1/2013,9/3/2013,2013,ICSA-13-213-02,Siemens WinCC TIA Portal Vulnerabilities,Siemens,WinCC TIA Portal,WinCC (TIA Portal) V11: all versions | WinCC (TIA Portal) V12: all versions < V12 SP1.,"CVE-2013-4911, CVE-2013-4912",7.2,High,"CWE-352, CWE-601",Chemical; Energy; oil and gas; Food and Agriculture; Water and Wastewater,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 210,8/1/2013,8/5/2013,2013,ICSA-13-213-03,IOServer Master Station Improper Input Validation,IOServer,Master Station,IOServer's Beta2041.exe and IOServer's versions older than driver19.exe.,CVE-2013-2790,7.1,High,CWE-20,Commercial Facilities; Energy; oil and gas; Government Facilities; Water and Wastewater,"Austria, Australia, Brazil, Canada, China, Czech Republic, Germany, France, United Kingdom, India, Italy, South Korea, Netherlands, New Zealand, Singapore, South Africa, Africa",Australia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 209,6/19/2013,8/1/2013,2013,ICSA-13-170-01,GE Proficy HMI/SCADA CIMPLICITY WebView Improper Input Validation,GE,Proficy HMI/SCADA CIMPLICITY WebView,Proficy HMI/SCADA - CIMPLICITY: Version 4.01 to 8.2 and Proficy Process Systems with CIMPLICITY.,CVE-2013-2785,8.8,High,CWE-20,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 208,7/8/2013,7/8/2013,2013,ICSA-13-189-01,QNX Multiple Vulnerabilities,QNX,Phrelay | Phwindows | Phditto,Phrelay (all versions) |Phwindows (all versions) |Phditto (all versions).,"CVE-2013-2687, CVE-2013-2688",5.8,Medium,"CWE-120, CWE-121",Commercial Facilities; Communications; Defense Industrial Base; Energy; Nuclear Facilities; Transportation Systems; Healthcare and Public Health,Worldwide,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 207,7/8/2013,7/8/2013,2013,ICSA-13-189-02,Triangle Research Nano 10 PLC Denial of Service,"Triangle Research International, Inc.",Nano 10 PLC,Tri Inc. Nano-10 PLC firmware versions affected: All firmware versions prior to r81.,CVE-2013-2784,7.8,High,CWE-20,Commercial Facilities; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater,"Australia, Canada, South Korea, Singapore, United States",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 206,7/3/2013,7/3/2013,2013,ICSA-13-184-01,Alstom Grid S1 Agile Improper Authorization,Alstom,Grid S1 Agile,MiCOM S1 Agile Software - all versions up to and including v1.0.2 and Legacy MiCOM S1 Studio Software - all versions.,CVE-2013-2786,6.0,Medium,CWE-284,Chemical; Commercial Facilities; Dams; Energy; Healthcare and Public Health,"Brazil, Canada, France, United Kingdom, India, Italy, Russia, Saudi Arabia, Singapore, United States",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 205,7/3/2013,7/3/2013,2013,ICSA-13-184-02,Monroe Electronics DASDEC Compromised Root SSH Key,Monroe Electronics,DASDEC,Monroe Electronics products affected: DASDEC-IDASDEC-II.,CVE-2013-0137,10.0,High,CWE-321,Communications,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 204,6/18/2013,6/18/2013,2013,ICSA-13-169-01,Siemens Scalance X200 IRT Multiple Vulnerabilities,Siemens,Scalance X200 IRT,SCALANCE X204 IRT versions < V5.1.0 SCALANCE X204 IRT PRO versions < V5.1.0 SCALANCE X202-2 IRT versions < V5.1.0 SCALANCE X202-2P IRT versions < V5.1.0 SCALANCE X202-2P IRT PRO versions < V5.1.0 SCALANCE X201-3P IRT versions < V5.1.0 SCALANCE X201-3P IRT PRO versions < V5.1.0 SCALANCE X200-4P IRT versions < V5.1.0 SCALANCE XF204 IRT versions < V5.1.0.,"CVE-2013-3633, CVE-2013-3634",7.2,High,CWE-264,Chemical; Energy; oil and gas; Food and Agriculture; Water and Wastewater,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 203,6/18/2013,6/24/2013,2013,ICSA-13-169-02,Siemens WinCC 7.2 Multiple Vulnerabilities,Siemens,WinCC 7.2,Siemens products affected: WinCC 7.2 and earlier and SIMATIC PCS7 V8.0 SP1 and earlier.,"CVE-2013-3957, CVE-2013-3958, CVE-2013-3959",6.9,Medium,"CWE-425, CWE-89, CWE-798",Chemical; Energy; oil and gas; Food and Agriculture; Water and Wastewater,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 202,6/18/2013,6/21/2013,2013,ICSA-13-169-03,"Siemens COMOS Permissions, Privileges, and Access Controls",Siemens,COMOS,COMOS 9.2: all versions < v092_Upd06_Patch010 (9.2.0.6.10) and COMOS 10.0: all versions < V100_SP03_Patch004 (10.0.3.0.4).,CVE-2013-3927,4.6,Medium,CWE-264,Multiple Critical sectors; Energy,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 201,6/10/2013,9/6/2018,2013,ICSA-13-161-01,IOServer DNP3 Improper Input Validation,IOServer,DNP3,IOServer product affected: Supported drivers v1.0.19.0.,CVE-2013-2783,7.1,High,CWE-20,Commercial Facilities; Energy; oil and gas; Government Facilities,"Australia, Canada, New Zealand, United States, South America, Asia, Europe",Australia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 200,3/18/2013,6/25/2019,2013,ICSA-13-077-01B,Schneider Electric PLCs Vulnerabilities (Update B),Schneider Electric,PLCs,Modicon M340 PLC modules Quantum PLC modules and Premium PLC modules.,"CVE-2013-0664, CVE-2013-0663",9.3,High,"CWE-352, CWE-287",Critical Manufacturing; Dams; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater,"China, India, Russia, United States, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 199,5/22/2013,8/23/2018,2013,ICSA-13-142-01,3S CODESYS Gateway Use After Free,3S-Smart Software Solutions,CODESYS Gateway,"CODESYS Gateway, Version 2.3.9.27. This product is also used in many products sold by other vendors. Control systems vendors should review their products - identify those that incorporate the affected software and take appropriate steps to update their products and notify customers.",CVE-2013-2781,10.0,High,CWE-416,Critical manufacturing; Energy,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 198,5/20/2013,9/6/2018,2013,ICSA-13-140-01,Mitsubishi Electric Automation MX Component V3 ActiveX Vulnerability,Mitsubishi Electric Automation,MX Component V3,Mitsubishi MX Component Version 3 trial software. Mitsubishi Electric Automation MX Component Version 3 - Other Mitsubishi products that may be based on the same code - CitectFacilities v7.10 and previous versions - Release Date: July 2009 and CitectSCADA v7.0 and previous versions - Release Date: August 2007.CitectFacilities and CitectSCADA only distributed a trial version of Mitsubishi MX Component Version 3 as complimentary software which is not installed by default. It is not licensed by Schneider Electric.,CVE-2013-3075,9.3,High,CWE-122,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 197,5/16/2013,9/5/2018,2013,ICSA-13-136-01,TURCK BL20 and BL67 Programmable Gateway Hard-Coded User Accounts,TURCK,BL20 and BL67 Programmable Gateway,BL20 Programmable Gateway - all versions - and BL67 Programmable Gateway - all versions.,CVE-2012-4697,10.0,High,CWE-798,Critical manufacturing; Food and Agriculture,"United Kingdom, United States, South America, Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 196,4/23/2013,8/1/2013,2013,ICSA-13-113-01,Wonderware Information Server Vulnerabilities,Invensys,Wonderware Information Server,WIS 4.0 SP1SP1 and 4.5- Portal and WIS 5.0- Portal.,"CVE-2013-0688, CVE-2013-0684, CVE-2013-0686, CVE-2013-0685",9.3,High,"CWE-20, CWE-79, CWE-89, CWE-400",Chemical; Energy; Food and Agriculture; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 195,12/19/2012,9/6/2018,2013,ICSA-12-354-01A,Ruggedcom ROS Hard-Coded RSA SSL Private Key (Update A),RuggedCom,ROS Hard-Coded RSA SSL,Rugged OS version 3.11 and prior ROX I OS firmware used by RX1000 and RX1100 series products. ROX I versions before and including ROX v1.14.5ROX II OS firmware used by RX5000 and RX1500 series products. ROX II versions before and including ROX v2.3.0 Rugged Max Operating System Firmware used by the Win7000 and Win7200 base station units and the Win5100 and Win5200 subscriber (CPE) devices. All versions of the firmware released before and including 4.2.1.4621.22,CVE-2012-4698,9.3,High,CWE-320,Energy; Transportation Systems,"Canada, China, Mexico, United States, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 194,4/16/2013,4/30/2013,2013,ICSA-13-106-01,MatrikonOPC Multiple Product Vulnerabilities,MatrikonOPC,MatrikonOPC A&E Historian | MatrikonOPC Security Gateway,MatrikonOPC A&E Historian Version 1.0.0.0 and MatrikonOPC Security Gateway Version 1.0.,"CVE-2013-0673, CVE-2013-0666",7.2,High,"CWE-22, CWE-388",Chemical; Energy; oil and gas,"Canada, United Kingdom, United States",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 193,4/26/2013,4/29/2013,2013,ICSA-13-116-01,Galil RIO-47100 Improper Input Validation,Galil,RIO-47100,RIO-47100 PLC.,CVE-2013-0699,7.1,High,CWE-20,Defense Industrial Base; Energy,"United States, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 192,4/10/2013,9/6/2018,2013,ICSA-13-100-01,Schneider Electric MiCOM S1 Studio Improper Authorization Vulnerability,Schneider Electric,MiCOM S1 Studio,MiCOM S1 Studio Software - all versions.,CVE-2013-0687,6.0,Medium,CWE-284,Critical Manufacturing; Energy; Water and Wastewater,Europe,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 191,4/8/2013,4/30/2013,2013,ICSA-13-098-01,Canary Labs Inc Trend Link Insecure ActiveX Control Method,"Canary Labs, Inc.",Trend Link,Canary Lab Inc. products: Trend Link Versions 9.0.2.27051 and prior.,CVE-2012-3022,7.9,High,CWE-73,Critical manufacturing; Energy,"United States, South America, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 190,4/5/2013,2/13/2014,2013,ICSA-13-095-01,Cogent Real-Time Systems Vulnerabilities,Cogent Real-Time Systems Inc,Real-Time Systems,Cogent Real-Time Systems affect the following versions: Cogent DataHub Version 7.2.2 and earlier OPC DataHub Version 6.4.21 and earlier Cascade DataHub for Windows Version 6.4.21 and earlier DataSim and DataPid demonstration clients for Cogent DataHub V7.2.2 DataSim and DataPid demonstration clients for OPC DataHub and Cascade DataHub V6.4.21 and DataHub QuickTrend Version 7.2.2 and earlier.,"CVE-2013-0681, CVE-2013-0680, CVE-2013-0683, CVE-2013-0682",8.5,High,"CWE-755, CWE-20, CWE-763",Critical Manufacturing; Commerical Facilities; Chemical; Energy; Finance Services,"Canada, United Kingdom, United States",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 189,4/1/2013,2/21/2019,2013,ICSA-13-091-01,Wind River VxWorks SSH and Web Server and General Electric D20MX (Update A),"Wind River, GE",VxWorks SSH and Web Server and General Electric D20MX,Web Server & CLI vulnerabilities: VxWorks Versions 5.5 through 6.9 and SSH vulnerabilities: VxWorks Versions 6.5 through 6.9 |GE reports the vulnerabilities affect the following D20MX versions: D20MX v1.0-1.6.2.,"CVE-2013-0711, CVE-2013-0713, CVE-2013-0714, CVE-2013-0715, CVE-2013-0716",9.8,Critical,CWE-20,Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 188,2/19/2013,9/6/2018,2013,ICSA-13-050-01A,3S CODESYS Gateway-Server Vulnerabilities (Update A),3S-Smart Software Solutions,CODESYS Gateway-Server,3S CODESYS products affected: Gateway-Server prior to ver. 2.3.9.27.,"CVE-2012-4704, CVE-2012-4705, CVE-2012-4706, CVE-2012-4707, CVE-2012-4708",9.1,High,"CWE-122, CWE-22, CWE-119, CWE-118, CWE-121",Critical manufacturing; Energy,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 187,2/12/2013,5/8/2013,2013,ICSA-13-043-02A,WellinTech KingView KingMess Buffer Overflow (Update A),WellinTech,KingView KingMess,KingView 6.52 (kingMess.exe 65.20.2003.10300) | KingView 6.53 (kingMess.exe 65.20.2003.10400) | KingView 6.55 (kingMess.exe 65.50.2011.18049).,CVE-2012-4711,10.0,High,CWE-119,Commercial Facilities; Energy; Water and Wastewater,"China, Japan, Singapore, Taiwan, United States, Europe",China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 186,3/25/2013,5/8/2013,2013,ICSA-13-084-01,Siemens CP 1604 and CP 1616 Improper Access Control,Siemens,CP 1604 and CP 1616,"CP 1604 and CP 1604 Microbox package (versions prior to 2.5.2), and CP 1604 and CP 1616 Onboard card of SIMANTIC IPCs (versions prior to 2.5.2).",CVE-2013-0659,10.0,High,CWE-284,Critical Manufacturing; Energy; oil and gas,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 185,3/8/2013,5/1/2013,2013,ICSA-13-067-02,Invensys Wonderware Win-XML Exporter Improper Input Validation Vulnerability,Invensys,Wonderware Win-XML Exporter,Win-XML Exporter Version 1522 | 148 | 0 | 0 and possibly earlier versions.,CVE-2012-4710,6.3,Medium,CWE-20,Dams; Defense Industrial Base; Energy; Food and Agriculture; Government Facilities; Nuclear Reactors; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 184,3/20/2013,9/3/2013,2013,ICSA-13-079-01,Schweitzer Engineering Laboratories AcSELerator Improper Authorization Vulnerability,Schweitzer Engineering Laboratories,AcSELerator,SEL AcSELerator QuickSet versions older than Version 5.12.0.1.,CVE-2013-0665,6.2,Medium,CWE-284,Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 183,3/20/2013,5/8/2013,2013,ICSA-13-079-02,Siemens WinCC 7.0 SP3 Multiple Vulnerabilities,Siemens,WinCC 7.0 SP3,WinCC 7.0 SP3 Update 1 and below. Note: As WinCC is part of SIMATIC PCS7 - the SIMATIC PCS 7 Web Server is also affected by these vulnerabilities.,"CVE-2013-0678, CVE-2013-0676, CVE-2013-0679, CVE-2013-0674, CVE-2013-0677, CVE-2013-0675",5.7,Medium,"CWE-285, CWE-119, CWE-311, CWE-23",Chemical; Energy; oil and gas; Food and Agriculture; Water and Wastewater,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 182,3/20/2013,9/3/2013,2013,ICSA-13-079-03,Siemens WinCC TIA Portal Vulnerabilities,Siemens,WinCC TIA Portal,WinCC (TIA Portal) V11 (all versions).,"CVE-2011-4515, CVE-2013-0669, CVE-2013-0672, CVE-2013-0671, CVE-2013-0670, CVE-2013-0667, CVE-2013-0668",4.2,Medium,"CWE-425, CWE-20, CWE-113, CWE-79",Chemical; Energy; oil and gas; Food and Agriculture; Water and Wastewater,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 181,2/22/2013,9/6/2018,2013,ICSA-13-053-02A,"Honeywell EBI, SymmetrE, and ComfortPoint Open Manager Station (Update A)",Honeywell,"EBI, SymmetrE, and ComfortPoint Open Manager Station",Honeywell versions: EBI R310 | R400.2 | R410.1 | R410.2 | SymmetrE R310 | R410.1 | R410.2 | CPO-M R100.,CVE-2013-0108,6.8,Medium,CWE-20,Commercial Facilities; Energy; Government Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 180,3/8/2013,9/6/2018,2013,ICSA-13-067-01,InduSoft Advantech Studio Directory Traversal,"Advantech, InduSoft",Advantech Studio,Advantech Studio V7.0 and previous and Indusoft Studio V7.0 and previous.,CVE-2013-1627,7.8,High,CWE-22,Commercial Facilities; Energy; Water and Wastewater,United States,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 179,2/22/2013,4/30/2013,2013,ICSA-13-053-01,Emerson DeltaV Uncontroller Resource Consumption Vulnerability,Emerson,DeltaV,DeltaV SE3006 SD Plus Controller Version 11.3.1 and earlier | DeltaV VE3005 Controller MD Hardware Version 10.3.1 and earlier | DeltaV VE3005 Controller MD Hardware Version 11.3.1 and earlier | DeltaV VE3006 Controller MD PLUS Hardware Version 10.3.1 and earlier | and DeltaV VE3006 Controller MD PLUS Hardware Version 11.3.1 and earlier.,CVE-2012-4703,6.1,Medium,CWE-400,Chemical; Energy; oil and gas,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 178,2/7/2013,9/6/2018,2013,ICSA-13-038-01A,360 Systems Image Server 2000 Series Remote Root Access (Update A),360 Systems,Image Server 2000 Series,Image server 2000 (all models) | Image Server Maxx (all models) | Maxx (all models).,CVE-2012-4702,10.0,High,CWE-259,Communications; Emergency Services,"North America, South America, Asia, Africa",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 177,1/24/2013,9/5/2018,2013,ICSA-13-024-01,Beijer Electronics ADP and H-Designer Buffer Overflow Vulnerability,Beijer Electronics,ADP and H-Designer,Beijer products affected: ADP V6.5.0-180_R1967 ADP V6.5.1-186_R2942H-Designer 6.5.0 B180_R1967.,CVE-2012-4696,6.9,Medium,CWE-119,Energy; Food and Agriculture; Transportation Systems,"Brazil, China, Germany, France, United Kingdom, Sweden, Taiwan, United States",Sweden,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 176,2/14/2013,5/8/2013,2013,ICSA-13-045-01,Tridium NiagaraAX Directory Traversal Vulnerability,Tridium,NiagaraAX,Tridium NiagaraAX - all versions.,CVE-2012-4701,8.5,High,CWE-22,Commercial Facilities; Energy; Government Facilities,"China, United Kingdom, Singapore, United States, South America",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 175,2/12/2013,5/7/2013,2013,ICSA-13-043-01,Schneider Electric Accutech Manager Heap Overflow,Schneider Electric,Accutech Manager,Accutech Manager 2.00.1 and older.,CVE-2013-0658,10.0,High,CWE-122,Energy; Water and Wastewater,Europe,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 174,2/11/2013,9/3/2015,2013,ICSA-13-042-01,MOXA EDR-G903 Series Multiple Vulnerabilities,Moxa,EDR-G903 Series,Moxa products affected: EDR-G903 series routers - all versions.,"CVE-2012-4694, CVE-2012-4712",5.8,Medium,"CWE-331, CWE-259",Chemical; Commercial Facilities; Emergency Services; Energy; Government Facilities; Water and Wastewater,"Argentina, Brazil, Chile, China, Germany, France, United Kingdom, India, Peru, Taiwan, United States, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 173,2/5/2013,1/29/2015,2013,ICSA-13-036-02,Ecava IntegraXor ActiveX Buffer Overflow,Ecava,IntegraXor,IntegraXor SCADA Server 4.00 build 4250.0 and earlier.,CVE-2012-4700,9.3,High,CWE-119,Multiple Critical Sectors; Critical Manufacturing,"Australia, Canada, Estonia, United Kingdom, Malaysia, Poland, United States",Malaysia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 172,1/22/2013,9/12/2013,2013,ICSA-13-022-02,GE Intelligent Platforms Proficy Cimplicity Multiple Vulnerabilities,GE,Intelligent Platforms Proficy Cimplicity,Proficy HMI/SCADA - CIMPLICITY: Version 4.01 and greater and Proficy Process Systems with CIMPLICITY.,"CVE-2013-0653, CVE-2013-0654",6.6,Medium,"CWE-20, CWE-22",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 171,1/22/2013,4/30/2013,2013,ICSA-13-022-01,GE Proficy Real-Time Information Portal Information Disclosure Vulnerabilities,GE,Proficy Real-Time Information Portal,Proficy Real-Time Information Portal: All versions.,"CVE-2013-0651, CVE-2013-0652",5.0,Medium,"CWE-200, CWE-306",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 170,1/18/2013,5/6/2013,2013,ICSA-13-018-01,Schneider Electric IGSS Buffer Overflow,Schneider Electric,IGSS,IGSS application: all versions.,CVE-2013-0657,10.0,High,CWE-121,Commercial Facilities; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 169,1/16/2013,9/6/2018,2013,ICSA-13-016-01,Schneider Electric Authenticated Communication Risk Vulnerability,Schneider Electric,Schneider Electric Software Update (SESU) utility,Schneider Electric SESU mechanism: Unity Pro V5.0 L M S XL Unity Pro V6.0 L M S XL Unity Pro V6.1 L M S XL Unity Pro V0 L M S XL XLS | Vijeo Designer V6.0.x V6.1.0.x V5.0.0.x V5.1.0.x | Vijeo Designer Opti V6.0.x V5.1.0.x V5.0.0.x | Web Gate Client Files V5.1.x IDS V1.0 V2.0 | PowerSuite 2.5 | Smart Widget Acti 9 V1.0.0.0 | Smart Widget H8035 V1.0.0.0 | Smart Widget H8036 V1.0.0.0 | Smart Widget PM201 V1.0.0.0 | Smart Widget PM710 V1.0.0.0 | Smart Widget PM750 V1.0.0.0 | SoMachine V1.2.1 | Spacail.pro V1.0.0.x and SESU V1.0.x V1.1.,CVE-2013-0655,9.3,High,CWE-287,Commericial Facilities; Government Facilities; Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 168,1/14/2013,5/8/2013,2013,ICSA-13-014-01,Siemens SIMATIC RF Manager ActiveX Buffer Overflow,Siemens,SIMATIC RF Manager,SIMATIC RF Manager 2008 and SIMATIC RF Manager Basic v3.0 and lower (as distributed with RF670R and RF 640R).,CVE-2013-0656,6.8,Medium,CWE-119,"Critical manufacturing, Chemical; Energy; Food and Agriculture; Public Health and Health",Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 167,1/11/2013,3/6/2014,2013,ICSA-13-011-02,SpecView Directory Traversal,SpecView,SpecView Product,SpecView 2.5 Build 853 and earlier.,CVE-2012-5972,2.6,Low,CWE-23,Critical Manufacturing,"United Kingdom, United States",United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 166,1/11/2013,3/6/2014,2013,ICSA-13-011-02,SpecView Directory Traversal,SpecView,SpecView Product,SpecView 2.5 Build 853 and earlier.,CVE-2012-5972,2.6,Low,CWE-23,Critical Manufacturing,"United Kingdom, United States",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 165,1/11/2013,2/13/2019,2013,ICSA-13-011-03,Rockwell Automation ControlLogix PLC Vulnerabilities,Rockwell Automation,ControlLogix PLC,All EtherNet/IP products that conform to the CIP and EtherNet/IP specifications 1756-ENBT 1756-EWEB 1768-ENBT 1768-EWEB communication modules | CompactLogix L32E and L35E controllers 1788-ENBT FLEXLogix adapter 1794-AENTR FLEX I/O EtherNet/IP adapter ControlLogix CompactLogix GuardLogix and SoftLogix Version 18 and prior | CompactLogix and SoftLogix controllers Version 19 and prior | ControlLogix and GuardLogix controllers Version 20 and prior | MicroLogix 1100 and MicroLogix 1400.,"CVE-2012-6439, CVE-2012-6442, CVE-2012-6435, CVE-2012-6441, CVE-2012-6438, CVE-2012-6436, CVE-2012-6440, CVE-2012-6437",8.0,High,"CWE-200, CWE-287, CWE-119, CWE-399",Critical Manufacturing; Chemical; Food and Agriculture; Water and Wastewater,"China, France, Italy, Japan, South Korea, Netherlands, United States, South America, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 164,12/6/2012,9/6/2018,2013,ICSA-12-341-01,GE Proficy HMI/SCADA Cimplicity Integer Overflow,GE,Proficy HMI/SCADA Cimplicity,Proficy HMI/SCADA - CIMPLICITY: Version 4.01 and greater and Proficy Process Systems with CIMPLICITY. Note: Proficy HMI/SCADA”Cimplicity Versions 4.0 and prior are not affected by this vulnerability.,CVE-2012-4689,7.1,High,CWE-20,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 163,12/27/2012,4/30/2013,2012,ICSA-12-362-01,I-GEN opLYNX Central Authentication Bypass,I-GEN,opLYNX,"opLYNX, Version 2.01.8 and prior",CVE-2012-4688,7.5,High,CWE-592,Chemical; Energy; oil and gas; Water and Wastewater,Canada,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 162,12/14/2012,10/13/2021,2012,ICSA-12-349-01,Siemens Automation License Manager Uncontrolled Resource Consumption,Siemens,Automation License Manager (ALM),"All Siemens software products that include ALM version between 4.0 and 5.2 are affected. The following Siemens product families are affected: SIMATIC (e.g., STEP 7); SIMATIC HMI (e.g., WinCC, WinCC flexible); SIMATIC PCS 7; SIMOTION (e.g., Scout); SIMATIC NET; SINAMICS (e.g., Starter); SIMOCODE.",CVE-2012-4691,7.8,High,CWE-399,Energy; Healthcare and Public Health,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 161,12/13/2012,2/25/2015,2012,ICSA-12-348-01,Siemens ProcessSuite and Invensys Intouch Poorly Encrypted Password File,Invensys,Intouch,All versions of ProcessSuite. Please note that according to Siemens ProcessSuite was phased out in 2005 and completely discontinued in 2010. Customers using SIMATIC PCS7 / APACS+ OS are not affected.The following Invensys Wonderware InTouch versions are affected: Wonderware InTouch 2012 R2 and previous. Wonderware applications that use Windows Integrated security or ArchestrA security are not affected.,CVE-2012-4693,4.3,Medium,CWE-326,Chemical; Energy; oil and gas,"Canada, United States",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 160,11/10/2011,8/29/2013,2012,ICSA-11-314-01,Safenet Sentinel and 7-T Input Sanitization Vulnerability,SafeNet,Sentinel and 7-T,SafeNet Sentinel HASP SDK releases older than Version 5.11; Sentinel HASP Run-time installers older than Version 6.x7 Technologies (7T) IGSS Version 7,CVE-2011-3339,4.3,Medium,CWE-79,Chemical,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 159,10/23/2012,12/23/2013,2012,ICSA-12-297-01,Tropos Wireless Mesh Routers,Tropos,Tropos Wireless Mesh Routers,All wireless mesh routers running Mesh OS versions prior to release 7.9.1.1,CVE-2012-4898,6.1,Medium,CWE-331,Emergency Services; Energy; Transportation Systems,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 158,12/19/2012,8/28/2013,2012,ICSA-12-354-02,Carlo Gavazzi EOS Box Multiple Vulnerabilities,Carlo Gavazzi,EOS Box,Carlo Gavazzi device with firmware version prior to 1.0.0.1080_2.1.10 is affected: EOS-Box,"CVE-2012-6428, CVE-2012-6427",8.9,High,CWE-89,Energy,"Canada, United States, Asia, Europe",Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 157,11/30/2012,1/10/2020,2012,ICSA-12-335-01,Post Oak Bluetooth Traffic Systems Insufficient Entropy Vulnerability,Post Oak Traffic Systems,Bluetooth Traffic Systems,AWAM Bluetooth Reader Traffic System - all versions,CVE-2012-4687,7.6,High,CWE-331,Transportation Systems,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 156,11/20/2012,1/10/2020,2012,ICSA-12-325-01,Sinapsi Devices Vulnerabilities,Sinapsi,Sinapsi Devices,Sinapsi devices with firmware prior to Version 2.0.2870_xxx_2.2.12 are affected: eSolar eSolar DUO and eSolar Light,"CVE-2012-5862, CVE-2012-5861, CVE-2012-5863, CVE-2012-5864",9.3,High,"CWE-259, CWE-89, CWE-78, CWE-287",Energy,"Italy, United States",Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 155,11/15/2012,4/30/2013,2012,ICSA-12-320-01,ABB AC500 PLC Webserver CoDeSys Vulnerability,ABB,AC500 PLCS Webserver CoDeSys,ABB AC500 CPU modules with firmware Version V2.1.3 and Web server enabled are affected: 1SAP130 300 R0271 PM573-ETH; 1SAP140 300 R0271 PM583-ETH; 1SAP150 000 R0271 PM590-ETH; 1SAP150 100 R0271 PM591-ETH; 1SAP150 200 R0271 PM592-ETH; 1TNE968 900 R0110 PM554-T-ETH; 1TNE968 900 R1110 PM564-T-ETH; 1TNE968 900 R1210 PM564-R-ETH; and 1TNE968 900 R1211 PM564-R-ETH-AC,CVE-2011-5007,7.8,High,CWE-121,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 154,9/27/2012,4/30/2013,2012,ICSA-12-271-01,C3-ilex EOScada Multiple Vulnerabilities,C3-ilex,EOScada,C3-ilex reports that the vulnerabilities affect all EOScada versions prior to 11.0.19.2,"CVE-2012-1810, CVE-2012-1811, CVE-2012-1812, CVE-2012-1813",6.4,Medium,"CWE-200, CWE-284, CWE-399",Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 153,10/31/2012,8/27/2018,2012,ICSA-12-305-01,Siemens SiPass Server Buffer Overflow,Siemens,SiPass Server,SiPass integrated MP2.6 and earlier,CVE-2012-5409,10.0,High,CWE-121,Multiple Critical sectors; Energy,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 152,10/23/2012,9/5/2018,2012,ICSA-12-297-02,Korenix Jetport 5600 Series Hard-coded Credentials,Korenix,Jetport 5600 Series,JetPort 5600; all versions,"CVE-2012-4577, CVE-2012-4577",10.0,High,CWE-259,Communications; Information Technology,"China, Spain, Taiwan, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 151,8/21/2012,8/23/2018,2012,ICSA-12-234-01,GE Intelligent Platforms Proficy Real-Time Information Portal Vulnerabilities,GE,Intelligence Platforms Proficy Real-Time Information Portal,Intelligent Platforms Proficy Real-Time Information Portal v2.6; Intelligent Platforms Proficy Real-Time Information Portal v3.0; Intelligent Platforms Proficy Real-Time Information Portal v3.0 SP1; Intelligent Platforms Proficy Real-Time Information Portal v3.5; andIntelligent Platforms Proficy Real-Time Information Portal v3.5 SP1. Note: These vulnerabilities do not affect versions of Proficy Real-Time Information Portal v2.5 and earlier,"CVE-2012-3010, CVE-2012-3021, CVE-2012-3026",7.1,High,CWE-20,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 150,10/9/2012,8/30/2013,2012,ICSA-12-283-01,Siemens S7-1200 Web Application Cross Site Scripting,Siemens,S7-1200 Web Application,S7-1200 PLCs versions: V2.x V3.0.0 and V3.0.1,CVE-2012-3040,8.3,High,CWE-79,Chemical,"Germany, Asia",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 149,10/9/2012,9/6/2018,2012,ICSA-12-283-02,WellinTech KingView User Credentials Not Securely Hashed,WellinTech,KingView User Credentials,KingView 6.5.3 and previous,CVE-2012-4899,6.8,Medium,CWE-311,Commercial Facilities; Energy; Water and Wastewater,"China, Japan, Singapore, Taiwan, United States, Europe",China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 148,9/21/2012,4/30/2013,2012,ICSA-12-265-01,Emerson DeltaV Buffer Overflow,Emerson,DeltaV,DeltaV V9.3.1; V10.3.1; V11.3; and V11.3.1,CVE-2012-3035,5.0,Medium,CWE-120,Commercial Facilities; Energy; Government Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 147,9/27/2012,4/22/2013,2012,ICSA-12-271-02,Optimalog Optima PLC Multiple Vulnerabilities,Optimalog,Optima PLC,Optima PLC 1.5.2 and prior,"CVE-2012-5048, CVE-2012-5049",5.0,Medium,"CWE-835, CWE-476",Multiple Critical Sectors,"France, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 146,9/19/2012,4/22/2013,2012,ICSA-12-263-02,ORing Industrial Networking IDS-5042/5042+ Hard-Coded Credential Vulnerability,ORing,Industrial Network IDS-5042/5042+,Industrial DIN-Rail Device Server IDS-5042 all versions and Industrial DIN-Rail Device Server IDS-5042+ all versions. Note: Other ORing Industrial Networking products may also be affected by this vulnerability.,CVE-2012-4577,10.0,Critical,CWE-259,Energy; oil and gas; Transportation Systems,"China, South Korea, Taiwan, United States, Asia, Europe",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 145,9/19/2012,5/6/2013,2012,ICSA-12-263-01,Siemens S7-1200 Insecure Storage of HTTPS CA Certificate,Siemens,S7-1200,SIMATIC S7-1200 V2.x,CVE-2012-3037,9.3,High,CWE-311,Chemical,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 144,9/14/2012,5/1/2013,2012,ICSA-12-258-01,IOServer OPC Server Multiple Vulnerabilities,IOServer,OPC Server,IOServer OPC Server 1.0.18.0 and earlier,CVE-2012-4680,7.8,High,"CWE-538, CWE-22, CWE-219",Commercial Facilities; Energy; oil and gas; Government Facilities,"Australia, United States, Asia, Europe",Australia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 143,9/18/2012,9/5/2018,2012,ICSA-12-262-01,Fultek WinTr Directory Traversal,Fultek,WinTR,WinTr Scada 4.0.5 and earlier,CVE-2012-3011,7.8,High,CWE-23,Critical Manufacturing,Turkey,Turkey,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 142,9/12/2012,8/29/2014,2012,ICSA-12-256-01,Siemens WinCC WebNavigator Multiple Vulnerabilities,Siemens,WinCC WebNavigator,WebNavigator component of the following versions of WinCC:WinCC 7.0 SP3 and earlier,"CVE-2012-3031, CVE-2012-3028, CVE-2012-3030, CVE-2012-3032, CVE-2012-3034",7.7,High,"CWE-352, CWE-425, CWE-618, CWE-79, CWE-89",Chemical; Energy; oil and gas; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 141,5/29/2012,9/6/2018,2012,ICSA-12-150-01,Honeywell HMIWeb Browser Buffer Overflow Vulnerability,Honeywell,HMIWeb Browser,Honeywell Process Solutions: Experion Releases R400.x R31x R30x and R2xx Honeywell Building Solutions:Enterprise Building Manager Releases R400 and R410.1 and SymmetrE R410.1 release Honeywell Environmental Combustion & Controls andSymmetrE R410.1 release,CVE-2012-0254,7.5,High,CWE-121,Energy,South America,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 140,9/7/2012,1/2/2014,2012,ICSA-12-251-01,RealFlex RealWinDemo DLL Hijack,RealFlex Technologies,RealWinDemo,RealWinDemo 2.1.12 and prior RealWin 2.1.12 and prior andFlexView 3.1.85 and prior,CVE-2012-3004,6.2,Medium,CWE-427,Chemical; Critical Manufacturing; Communications; Energy; oil and gas; Transportation Systems; Maritime; Water and Wastewater,"India, Mexico, Nigeria, Philippines, Saudi Arabia",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 139,9/5/2012,4/30/2013,2012,ICSA-12-249-01,Arbiter Systems Power Sentinel Denial-of-Service Vulnerability,Arbiter Systems,Power Sentinel,Model 1133A Power Sentinel firmware versions 09 Jun 2012 and earlier,CVE-2012-3012,7.8,High,CWE-410,Energy,"United States, South America, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 138,9/5/2012,9/6/2018,2012,ICSA-12-249-02,WAGO IO 758 Default Linux Credentials,WAGO,IO 758,"I/O System 758, Model 758-870 I/O System 758 Model 758-874 I/O System 758 Model 758-875 and I/O System 758 Model 758-876",CVE-2012-3013,10.0,High,"CWE-287, CWE-259",Commercial Facilities; Energy; Government Facilities; Transportation Systems,"China, Germany, India, Poland, Switzerland",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 137,9/5/2012,10/28/2013,2012,ICSA-12-249-03,InduSoft ISSymbol ActiveX Control Buffer Overflow,InduSoft,ISSymbol ActiveX Control,InduSoft ISSymbol ActiveX Control (Build 301.1009.2904.0) InduSoft Thin Client Version 7.0 and InduSoft Web Studio Version 7.0B,"CVE-2011-0340, CVE-2011-0340",7.5,High,CWE-122,Chemical; Food and Agriculture,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 136,8/30/2012,4/30/2013,2012,ICSA-12-243-01,GarrettCom - Use of Hard-Coded Password,GarrettCom,Hard-Coded Password,MNS-6K Rel v4.1.14 and prior and MNS-6K Rel v14.1.14 SECURE and prior,CVE-2012-3014,7.7,High,CWE-259,Defense Industrial Base; Energy; Transportation Systems,"China, India, United States, South America, Asia, Europe, Middle East",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 135,8/14/2012,5/7/2013,2012,ICSA-12-227-01,Siemens COMOS Database Privilege Escalation Vulnerability,Siemens,COMOS Database,"COMOS versions: all versions earlier than Version 9.1 Version 9.1: Patch 412 and earlier Version 9.2: Update 3 Patch 022 and earlier, and Version 10: Patch 004 and earlier",CVE-2012-3009,8.5,High,CWE-250,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 134,8/1/2012,5/8/2013,2012,ICSA-12-214-01,Siemens Synco OZW Default Password,Siemens,Synco OZW,"Synco models:OZW775OZW672.01 OZW672.04 OZW672.16OZW772.01 OZW772.04 OZW772.16 OZW772.250. For the listed products, all firmware versions prior to Version 4 do not force users to change their password on initial login.",CVE-2012-3020,9.0,High,CWE-262,Commercial Facilities; Government Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 133,7/30/2012,5/8/2013,2012,ICSA-12-212-02,Siemens SIMATIC S7-400 PN CPU DoS,Siemens,SIMATIC S7-400 PN CPU,S7-400 CPU family with firmware Versions 6.0.1 and 6.0.2 CPU 412-2 PN (6ES7412-2EK06-0AB0) CPU 414-3 PN/DP (6ES7414-3EM06-0AB0) CPU 414F-3 PN/DP (6ES7414-3FM06-0AB0) CPU 416-3 PN/DP (6ES7416-3ES06-0AB0) CPU 416F-3 PN (6ES7416-3FS06-0AB0) Another vulnerability affects the following products within the S7-400 CPU family with firmware Version 5: CPU 414-3 PN/DP (6ES7414-3EM05-0AB0) CPU 416-3 PN/DP (6ES7416-3ER05-0AB0)CPU 416F-3 PN/DP (6ES7416-3FR05-0AB0),CVE-2012-3016,7.8,High,CWE-404,Chemical,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 132,7/30/2012,8/28/2013,2012,ICSA-12-212-01,ICONICS GENESIS32/BizViz Security Configurator Authentication Bypass Vulnerability,ICONICS,GENESIS32/BizVis Security Configurator,Genesis32: Genesis32 V9.22 and previous. BizViz V9.22 and previous.,CVE-2012-3018,6.0,Medium,CWE-261,Commercial Facilities; Energy; oil and gas; Government Facilities; Water and Wastewater,"Australia, China, Czech Republic, Germany, France, United Kingdom, India, Italy, Netherlands, United States, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 131,7/23/2012,5/8/2013,2012,ICSA-12-205-02,Siemens SIMATIC STEP 7 DLL Vulnerability,Siemens,SIMATIC STEP 7,SIMATIC STEP 7 versions prior to V5.5 Service Pack 1 (V5.5.1 equivalent) and SIMATIC PCS 7 versions before and including V7.1 SP3,CVE-2012-3015,6.9,Medium,CWE-114,Chemical; Commercial Facilities; Energy; oil and gas; Government Facilities; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 130,7/23/2012,5/8/2013,2012,ICSA-12-205-01,Siemens WinCC Insecure SQL Server Authentication,Siemens,WinCC SQL Server,SIMATIC WinCC versions older than V7.0 SP2 Update 1 (V 7.0.2.1) and SIMATIC PCS 7 versions older than V7.1 SP2.,CVE-2010-2772,10.0,High,CWE-798,Chemical; Energy; oil and gas; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 129,7/19/2012,5/6/2015,2012,ICSA-12-201-01,OSIsoft PI OPC DA Interface Buffer Overflow,OSIsoft,PI OPC DA Interface,All versions of PI OPC DA Interface prior to Version 2.3.20.9.,CVE-2012-3008,6.3,Medium,CWE-121,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 128,6/25/2012,5/1/2013,2012,ICSA-12-177-02,Invensys Wonderware InTouch 10 DLL Hijack,Invensys,Wonderware InTouch 10,InTouch 2012 and all prior versions Wonderware Application Server 2012 and prior versions Wonderware Information Server 4.5 and prior versions Foxboro Control Software 4.0 and all prior versions InFusion CE/FE/SCADA 2.5 and all prior versions InBatch 9.5 SP1 and all prior versions andWonderware Historian 10.0 SP1 and all prior versions.,CVE-2012-3005,6.6,Medium,CWE-427,Chemical; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 127,7/3/2012,9/2/2014,2012,ICSA-12-185-01,WellinTech KingView Multiple Vulnerabilities,WellinTech,KingView,WellinTech KingView 6.53 and WellinTech King Historian 3.0.,"CVE-2012-1830, CVE-2012-1831, CVE-2012-1832, CVE-2012-2560, CVE-2012-2559",9.0,High,"CWE-121, CWE-122, CWE-125, CWE-35, CWE-119",Commercial Facilities; Energy; Water and Wastewater,"China, Japan, Singapore, Taiwan, United States, Europe",China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 126,5/10/2012,8/21/2018,2012,ICSA-12-131-02,GE Intelligent Platforms Proficy HTML Help Vulnerabilities (Update A),GE,Intelligence Platforms Proficy HTML Help,Proficy Historian: Versions 4.5 4.0 3.5 and 3.1Proficy HMI/SCADA - iFIX: Versions 5.1 and 5.0 Proficy Pulse: Version 1.0 Proficy Batch Execution: Version 5.6SI7 I/O Driver: Versions between 7.20 and 7.424.2,"CVE-2012-2515, CVE-2012-2516",8.8,High,"CWE-77, CWE-121",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 125,6/27/2012,9/6/2018,2012,ICSA-12-179-01,Pro-Face Pro-Server EX Vulnerabilities,Pro-face,Pro-Server EX,"Data management software Pro-Server EX versions 1.00.00 through 1.30.00, and HMI screen editor and logic programming software GP-Pro EX and related software WinGP Versions 2.00.00 through 3.01.100.","CVE-2012-3792, CVE-2012-3793, CVE-2012-3794, CVE-2012-3795, CVE-2012-3796, CVE-2012-3797",5.1,Medium,"CWE-788, CWE-119, CWE-680, CWE-388",Energy; oil and gas; Food and Agriculture; Water and Wastewater,"Japan, Asia",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 124,6/19/2012,9/6/2018,2012,ICSA-12-171-01,Wonderware SuiteLink Unallocated Unicode String Vulnerability,Invensys,Wonderware SuiteLink,Slssvc service less than or equal to Version 54.x.x.x is vulnerable and slssvc service equal to or greater than Version 58.x.x.x is not vulnerable. Slssvc service Versions 55-57 were never publicly released. InTouch 2012 and Wonderware Application Server 2012 are not vulnerable to crash but will show excessive resource consumption if exploited.,CVE-2012-3007,7.1,High,CWE-121,Chemical; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 123,5/25/2012,9/6/2018,2012,ICSA-12-146-01A,RuggedCom Weak Cryptography for Password Vulnerability (Update A),RuggedCom,RuggedCom Cryptography for Password,"RuggedCom RuggedSwitch or RuggedServer devices are affected using the following versions of ROS:3.2.x and earlier, and3.3.x and above",CVE-2012-1803,8.5,High,CWE-261,Communications; Energy; Transportation Systems; Government Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 122,6/15/2012,9/6/2018,2012,ICSA-12-167-01,Innominate MGuard Weak HTTPS and SSH Keys,Innominate,Mguard,mGuard Smart”HW-101020 HW-101050 BD-101010 BD-101020 mGuard PCI”HW-102020 HW-102050 BD-111010 BD-111020 mGuard Industrial RS”HW-105000 BD-501000 BD-501010 BD-501020 mGuard Blade”HW-104020 HW-104050 mGuard Delta”HW-103050 BD-201000 EAGLE mGuard”HW-201000 BD-301010 All products manufactured prior to 2006,CVE-2012-3006,7.1,High,CWE-310,Critical Manufacturing; Communications; Energy; Healthcare and Public Health; Transportation Systems; Water and Wastewater,Germany,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 121,6/6/2012,1/30/2014,2012,ICSA-12-158-01,Siemens WinCC Multiple Vulnerabilities,Siemens,SIMATIC WinCC,Siemens WinCC 7.0 SP3 web server and web applications are affected,"CVE-2012-2595, CVE-2012-2596, CVE-2012-2597, CVE-2012-2598, CVE-2012-3003",4.9,Medium,"CWE-22, CWE-79, CWE-91",Chemical; Energy; oil and gas; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 120,5/17/2012,4/30/2013,2012,ICSA-12-138-01,Emerson DeltaV Multiple Vulnerabilities,Emerson,DeltaV,DeltaV and DeltaV Workstations V9.3.1 V10.3.1 V11.3 and V11.3.1 DeltaV ProEssentials Scientific Graph and V5.0.0.6,"CVE-2012-1814, CVE-2012-1815, CVE-2012-1816, CVE-2012-1817, CVE-2012-1818",6.4,Medium,"CWE-618, CWE-79, CWE-89, CWE-119, CWE-400",Commercial Facilities; Energy; Government Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 119,5/24/2012,9/6/2018,2012,ICSA-12-145-02,xArrow Multiple Vulnerabilities,xArrow,xArrow,xArrowxArrow software versions older than Version 3.4.1,"CVE-2012-2426, CVE-2012-2427, CVE-2012-2428, CVE-2012-2429",8.5,High,"CWE-476, CWE-122, CWE-125, CWE-119",Commercial Facilities; Food and Agriculture; Water and Wastewater,"China, Indonesia, India, Latvia, Poland",China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 118,5/24/2012,5/1/2013,2012,ICSA-12-145-01,Measuresoft ScadaPro DLL Hijack,Measuresoft,ScadaPro,ScadaPro Server prior to Version 4.0.0 and ScadaPro Client prior to Version 4.0.0.,CVE-2012-1824,6.0,Medium,CWE-427,Pharmaceutical; Energy; oil and gas,Ireland,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 117,5/16/2012,9/6/2018,2012,ICSA-12-137-02,Advantech Studio ISSymbol ActiveX Buffer Overflow,Advantech,Studio ISSymbol ActiveX,"Advantech ISSymbol ActiveX Control 61.6.0.0, and Advantech Studio 6.1 SP6 Build 61.6.01.05","CVE-2011-0340, CVE-2011-0340",4.3,Medium,CWE-119,Commercial Facilities; Energy; Government Facilities; Water and Wastewater,Worldwide,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 116,5/10/2012,5/1/2013,2012,ICSA-12-131-01,Progea Movicon Memory Corruption Vulnerability,Progea,Movicon,Movicon versions prior to 11.3.,CVE-2012-1804,7.8,High,CWE-119,Energy,"India, United States, Europe",Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 115,5/8/2012,9/6/2018,2012,ICSA-12-129-01,WellinTech KingSCADA Insecure Password Encryption,WellinTech,KingSCADA,WellinTech KingSCADA 3.0.,CVE-2012-1977,7.2,High,CWE-311,Commercial Facilities; Energy; Water and Wastewater,"China, Japan, Singapore, Taiwan, United States, Europe",China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 114,5/1/2012,4/18/2013,2012,ICSA-12-122-01,WellinTech KingView DLL Hijack Vulnerability,WellinTech,KingView DLL,WellinTech KingView 6.53,CVE-2012-1819,9.3,High,CWE-427,Commercial Facilities; Energy; Water and Wastewater,"China, Japan, Singapore, Taiwan, United States, Europe",China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 113,1/30/2012,9/6/2018,2012,ICSA-12-030-01A,Siemens SIMATIC WinCC Vulnerabilities (UPDATE A),Siemens,SIMATIC WinCC,WinCC flexible versions 2004 2005 2007 2008 WinCC V11 (TIA portal)Multiple SIMATIC HMI panels (TP OP MP Comfort Panels Mobile Panels) WinCC V11 Runtime Advanced WinCC flexible Runtime.The following related products are not affected: WinCC V11 (TIA Portal) Basic WinCC V11 (TIA Portal) Runtime Professional WinCC V6.x and V7.x,"CVE-2011-4508, CVE-2011-4509, CVE-2011-4510, CVE-2011-4511, CVE-2011-4512, CVE-2011-4513, CVE-2011-4514, CVE-2011-4875, CVE-2011-4876, CVE-2011-4877, CVE-2011-4878, CVE-2011-4879",7.9,High,"CWE-287, CWE-255, CWE-79, CWE-94, CWE-20, CWE-134, CWE-399, CWE-22, CWE-119",Chemical; Energy; oil and gas; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 112,4/4/2012,4/16/2013,2012,ICSA-12-095-01A,ABB Multiple Components Buffer Overflow (UPDATE),ABB,Multiple Components,WebWare Server: All versions of Data Collector and Interlink WebWare SDK: All versionsABB Interlink Module: All versionsS4 OPC Server: All versions QuickTeach: All versionsRobotStudio S4: All versionsRobotStudio Lite: All versions.,CVE-2012-1801,7.7,High,CWE-119,Critical Manufacturing,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 111,4/11/2012,9/6/2018,2012,ICSA-12-102-02,Koyo Ecom Modules Vulnerabilities,Koyo,Ecom Module,DirectLogic DL205 Series Programmable Logic Controllers H2-ECOM (For DirectLogic DL205 Series Programmable Logic Controllers) H2-ECOM-F (For DirectLogic DL205 Series Programmable Logic Controllers) H2-ECOM100 (For DirectLogic DL205 Series Programmable Logic Controllers)DirectLogic DL06 Series Programmable Logic Controllers H0-ECOM (For DirectLogic DL06 Series Programmable Logic Controllers) H0-ECOM100 (For DirectLogic DL06 Series Programmable Logic Controllers). DirectLogic DL405 Series Programmable Logic Controllers H4-ECOM (For DirectLogic DL405 Series Programmable Logic Controllers) H4-ECOM-F (For DirectLogic DL405 Series Programmable Logic Controllers) H4-ECOM100 (For DirectLogic DL405 Series Programmable Logic Controllers),"CVE-2012-1805, CVE-2012-1806, CVE-2012-1808, CVE-2012-1809",8.1,High,"CWE-119, CWE-306, CWE-521",Multiple Critical Sectors,"Australia, North America, South America, Europe",Australia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 110,4/11/2012,8/23/2018,2012,ICSA-12-102-01,Certec atvise webMI2ADS Vulnerabilities,Certec EDV GmbH,atvise Server,Certec webMI2ADS - All versions prior to Version 2.0.2 are affected,"CVE-2011-4880, CVE-2011-4881, CVE-2011-4882",5.0,Medium,"CWE-22, CWE-732, CWE-476, CWE-400",Commercial Facilities,"Austria, Germany, Israel, Italy, Switzerland",Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 109,4/11/2012,9/6/2018,2012,ICSA-12-102-03,MICROSYS PROMOTIC Use After Free Vulnerability,MICROSYS,PROMOTIC,PROMOTIC versions prior to Version 8.1.7.,CVE-2011-4874,7.9,High,CWE-416,Energy; Water and Wastewater,"Bulgaria, Hungary, Poland, Romania, Serbia, Slovenia",Czech Republic,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 108,4/11/2012,5/8/2013,2012,ICSA-12-102-05,Siemens Scalance S Multiple Security Vulnerabilities,Siemens,Scalance S,Scalance S602 V2Scalance S612 V2 Scalance S613 V2,"CVE-2012-1799, CVE-2012-1800",8.1,High,"CWE-1121, CWE-307",Chemical; Defense Industrial Base; Energy; Transportation Systems,"Asia, Europe",Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 107,4/11/2012,5/8/2013,2012,ICSA-12-102-04,Siemens Scalance X Buffer Overflow Vulnerability,Siemens,Scalance X,Scalance X414-3E Scalance X308-2M Scalance X-300EEC Scalance XR-300 Scalance X-300,CVE-2012-1802,7.8,High,CWE-119,Chemical; Critical Manufacturing; Communications; Dams; Defense Industrial Base; Energy; Food and Agriculture; Government Facilities; Transportation Systems; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 106,3/28/2012,9/6/2018,2012,ICSA-12-088-01A,Rockwell Automation FactoryTalk RNADiagReceiver (UPDATE A),Rockwell Automation,FactoryTalk RNADiagReceiver,Allen-Bradley RSLogix 5000 (versions 17 18 19 20) Factory Talk (CPR9 up to and including CPR9 SR5) FT Directory FT Alarms & Events FT View SE FT Diagnostics FT Live Data FT Server Health,"CVE-2012-0221, CVE-2012-0222",5.0,Medium,"CWE-125, CWE-389",Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 105,3/2/2012,5/1/2013,2012,ICSA-12-062-01,Wonderware Information Server Multiple Vulnerabilities,Invensys,Wonderware Information Server,Wonderware Information Server versions 4.0 SP1 and 4.5--Portal 4.0 SP1 and 4.5--Client.The following Invensys Wonderware Historian Client version is affected: Only Wonderware Historian Client versions installed on the same node as the Wonderware Information Server Portal or Client are subject to these vulnerabilities.,"CVE-2012-0225, CVE-2012-0226, CVE-2012-0228",8.1,High,"CWE-89, CWE-264",Chemical; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 104,3/21/2012,5/1/2013,2012,ICSA-12-081-01,Wonderware System Platform Buffer Overflows,Invensys,Wonderware System Platform,Wonderware Application Server 2012 and all prior versions Foxboro Control Software Version 3.1 and all prior versions InFusion CE/FE/SCADA 2.5 and all prior versions Wonderware Information Server 4.5 and all prior versions ArchestrA Application Object Toolkit 3.2 and all prior versions InTouch 10.0 to 10.5 only (earlier versions of InTouch are not affected). NOTE: The Wonderware Historian is part of the System Platform but is not affected by this Security Update.,"CVE-2012-0257, CVE-2012-0258",6.0,Medium,CWE-122,Critical Manufacturing,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 103,3/23/2012,9/6/2018,2012,ICSA-12-083-01,Ecava IntegraXor ActiveX Directory Traversal,Ecava,IntegraXor ActiveX,IntegraXor versions older than Version 3.71.4200,CVE-2012-0246,4.3,Medium,CWE-22,Critical Manufacturing,"Australia, Canada, Estonia, United Kingdom, Malaysia, Poland, United States",Malaysia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 102,3/19/2012,5/1/2013,2012,ICSA-12-079-01,Microsoft Remote Desktop Protocol Memory Corruption Vulnerability,Microsoft,Remote Desktop Protocol,For a list of all affected Microsoft products visit the Microsoft Security Bulletin.,CVE-2012-0002,10.0,High,CWE-94,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 101,2/1/2012,4/22/2013,2012,ICSA-12-032-03,GE Intelligent Platforms Proficy Real-Time Information Portal Directory Traversal,GE,Intelligent Piatform Real-Time Portal Directory,Proficy Real-Time Information Portal Versions: 3.53.0 SP13.02.6. Note: Proficy Real-Time Information Portal Versions 2.5 and prior are not affected by this vulnerability.,CVE-2012-0232,6.4,Medium,CWE-22,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 100,2/1/2012,4/30/2013,2012,ICSA-12-032-01,GE Proficy Historian ihDataArchiver,GE,Proficy Historian ihDataArchiver,Proficy Historian: Versions 4.5 and prior Proficy HMI/SCADA-CIMPLICITY: Version 8.2 (with Proficy Historian 4.5 or prior installed) Proficy HMI/SCADA-iFIX: Versions 5.5. 5.0. and 5.1 (with Proficy Historian 4.5 or prior installed). Note: Proficy Pulse is not affected by the vulnerability described in this advisory.,CVE-2012-0229,10.0,High,CWE-119,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 99,2/1/2012,8/28/2013,2012,ICSA-12-032-02,GE Intelligent Platforms Proficy Plant Applications Memory Corruption Vulnerabilities,GE,Intelligent Platform Proficy Plant Application,Proficy Plant Applications: Versions 5.0 and prior.,"CVE-2012-0230, CVE-2012-0231",10.0,High,CWE-119,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 98,2/28/2012,5/8/2013,2012,ICSA-12-059-01,ABB Robot Communications Runtime Buffer Overflow,ABB,Robot Communications,ABB Interlink Module: Versions 4.6 through 4.9 IRC5 OPC Server: Versions up to and including 5.14.01PC SDK: Versions up to and including 5.14.01 PickMaster 3: Versions up to and including 3.3 PickMaster 5: Versions up to and including 5.13 Robot Communications Runtime: Versions up to and including 5.14.01 RobotStudio: Versions supporting IRC5 up to and including 5.14.01 RobView 5: Works together with other products listed here. WebWare SDK: Versions 4.6 through 4.9 WebWare Server: Versions 4.6 through 4.91,CVE-2012-0245,10.0,High,CWE-119,Critical Manufacturing,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 97,1/25/2012,5/8/2013,2012,ICSA-12-025-02A,7-Technologies Termis DLL Hijacking (Update A),7-Technologies,Termis,TERMIS V2.10 dated November 30 2011 and any previous version.,CVE-2012-0223,9.3,High,CWE-427,Energy,"Denmark, United States, Asia, Europe",Denmark,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 96,2/16/2012,8/27/2018,2012,ICSA-12-047-01A,Advantech WebAccess Vulnerabilities (UPDATE A),Advantech,WebAccess,All versions of Advantech/BroadWin WebAccess prior to applying the patch (V7.0) listed in the mitigations below,"CVE-2012-0233, CVE-2012-0234, CVE-2012-0235, CVE-2012-0236, CVE-2012-0237, CVE-2012-0238, CVE-2012-0239, CVE-2012-0240, CVE-2011-4526, CVE-2011-4524, CVE-2011-4525, CVE-2011-4521, CVE-2011-4522, CVE-2011-4523, CVE-2012-0241, CVE-2012-0242, CVE-2012-0243, CVE-2012-0244",7.4,High,"CWE-79, CWE-89, CWE-352, CWE-119, CWE-134, CWE-200, CWE-287",Energy,"North America, Asia, North Africa, Africa, Middle East",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 95,2/8/2012,5/1/2013,2012,ICSA-12-039-01,Invensys Wonderware HMI Reports XSS and Write Access Violation Vulnerabilities,Invensys,Wonderware HMI,Wonderware HMI Reports 3.42.835.0304 and prior.,CVE-2011-4039,9.3,High,"CWE-79, CWE-264",Commercial Facilities; Energy; oil and gas; Government Facilities; Healthcare and Public Health; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 94,1/13/2012,6/2/2014,2012,ICSA-12-013-01,ING. Punzenberger COPA-DATA GMBH DoS Vulnerabilities,COPA-DATA,GMBH,Ing. Punzenberger COPA-DATA GmbH zenon 6.51 SP0.,"CVE-2011-4533, CVE-2011-4534",7.5,High,CWE-NA,Pharmaceutical; Energy,"Austria, Germany, Spain, France, United Kingdom, Italy, South Korea, Portugal, Sweden, United States, Eastern Europe",Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 93,1/12/2012,9/6/2018,2012,ICSA-12-012-01A,Open Automation Software OPC Systems.NET Vulnerability (Update A),Open Automation Software,OPC Systems.NET,All versions of OPC Sytems. NET prior to Version 5.0 are affected.,"CVE-2011-4871, CVE-2012-0227",7.2,High,CWE-20,Energy; Information Technology; Water and Wastewater,United States,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 92,1/24/2012,4/23/2013,2012,ICSA-12-024-01,Ocean Data Systems Dream Reports XSS and Write Access Violation Vulnerabilities,Ocean Data,Systems Dream,Dream Reports versions prior to Version 4.0,"CVE-2011-4038, CVE-2011-4039",6.8,Medium,"CWE-79, CWE-264",Commercial Facilities; Energy; oil and gas; Government Facilities; Healthcare and Public Health; Water and Wastewater,"Germany, France, United Kingdom, Israel, Switzerland, United States",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 91,1/24/2012,9/6/2018,2012,ICSA-12-024-02,MICROSYS PROMOTIC Vulnerabilities,MICROSYS,PROMOTIC,PROMOTIC versions prior to Version 8.1.5.,"CVE-2011-4518, CVE-2011-4519, CVE-2011-4520",4.5,Medium,"CWE-22, CWE-119",Energy; Water and Wastewater,"Bulgaria, Hungary, Poland, Romania, Serbia, Slovenia",Czech Republic,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 90,1/18/2012,8/22/2018,2012,ICSA-12-018-02,Certec Atvise Server Remote DOS,Certec EDV GmbH,Atvise Server,Atvise versions older than Version 2.1 are affected,CVE-2011-4873,5.0,Medium,CWE-NA,Multiple Critical Sectors,Austria,Austria,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 89,1/16/2012,4/17/2013,2012,ICSA-12-016-01,Cogent DataHub XSS and CRLF,Cogent Real-Time Systems Inc,DataHub,Cogent DataHub Version 7.1.2 and earlier OPC DataHub Version 6.4.20 and earlier Cascade DataHub Version 6.4.20 and earlier.,"CVE-2012-0309, CVE-2012-0310",4.3,Medium,"CWE-94, CWE-79",Chemical,"Canada, United Kingdom, Taiwan, United States",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 88,12/19/2011,4/18/2013,2012,ICSA-11-353-01,7-Technologies Interactive Graphical SCADA,7-Technologies,Interactive Graphical SCADA,All versions prior to V9.0.0.11291,CVE-2011-4053,9.3,High,CWE-426,Critical Manufacturing; Energy; oil and gas,"Denmark, United States, Asia, Europe",Denmark,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 87,1/6/2012,9/6/2018,2012,ICSA-12-006-01,3S CoDeSys Vulnerabilities,3S-Smart Software Solutions,CoDeSys,Version 2.3; Version 3.4.,"CVE-2011-5007, CVE-2011-5008, CVE-2011-5009",7.5,High,"CWE-119, CWE-189",Critical Manufacturing,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 86,12/9/2011,5/8/2013,2012,ICSA-11-343-01,Siemens FactoryLink Multiple ActiveX Vulnerabilities,Siemens,FactoryLink,Siemens Tecnomatix FactoryLink versions V8.0.2.54V7.5.217 (V7.5 SP2)V6.6,"CVE-2011-4055, CVE-2011-4056",7.5,High,CWE-119,Chemical; Commercial Facilities; Energy; oil and gas; Food and Agriculture; Government Facilities,Taiwan,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 85,11/28/2011,9/6/2018,2012,ICSA-11-332-01A,Wonderware InBatch ActiveX Vulnerabilities (Update A),Invensys,Wonderware,"Invensys Wonderware InBatch versions 8.1 SP1, 9.0 SP2, and 9.5--InBatch Server and Runtime Clients9.0 and 9.0 SP1.The affected components exist in a variety of Wonderware products including InTouch and Information Server browser clients that have downloaded converted windows that contain these controls.According to Invensys, I/A Series Batch 8.1 SP1 and Wonderware InBatch 9.5 SP1 and higher are not affected by these vulnerabilities.",CVE-2011-4870,6.8,Medium,CWE-119,Chemical; Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 84,12/28/2011,9/6/2018,2011,ICSA-11-362-01,ScadaTEC ScadaPhone & Modbus TagServer Buffer Overflow Vulnerability,ScadaTEC,ScadaPhone & Modbus TagServer,ScadaPhone V5.3.11.1230 and priorModbusTagServer V4.1.1.81 and prior,CVE-2011-4535,6.8,Medium,CWE-119,Chemical; Critical Manufacturing,"Australia, United States",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 83,12/27/2011,9/6/2018,2011,ICSA-11-361-01,Siemens Automation License Manager Vulnerabilities,Siemens,Automation License Manager,"ALM Version 4.0 to 5.1+SP1+Upd1 are affected by the buffer overflow, exception, and null pointer vulnerabilities. ALM Version 2.0 to 5.1+SP1+Upd2 are affected by the improper input validation vulnerability","CVE-2011-4529, CVE-2011-4530, CVE-2011-4531, CVE-2011-4532",5.6,Medium,"CWE-119, CWE-20, CWE-22",Chemical; Energy; oil and gas; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 82,10/25/2011,4/23/2013,2011,ICSA-11-298-01A,Sielco Sistemi Winlog Buffer Overflow (Update A),Sielco Sistemi,Winlog,Winlog Lite versions older than Version 2.07.09 Winlog PRO versions older than Version 2.07.09,CVE-2011-4037,9.3,High,CWE-119,Communications,Italy,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 81,12/22/2011,4/22/2013,2011,ICSA-11-356-01,Siemens Simatic HMI Authentication Vulnerabilities,Siemens,Simatic HMI,"martAccess option package for SIMATIC WinCC flexible RT 2004, 2005, 2005 SP1, 2007, 2008, 2008 SP1, and 2008 SP2 SIMATIC WinCC Runtime Advanced V11, V11 SP1, and V11 SP2 Multiple SIMATIC Panels (TP, OP, MP, Mobile, Comfort)","CVE-2011-4508, CVE-2011-4509",9.6,High,"CWE-255, CWE-287",Chemical; Energy; oil and gas; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 80,12/21/2011,4/30/2013,2011,ICSA-11-355-01,7-Technologies IGSS Buffer Overflow,7-Technologies,IGSS,7T Interactive Graphical SCADA System Versions 9.0.0.11355 and prior.,CVE-2011-4537,7.5,High,CWE-119,Critical Manufacturing; Energy; oil and gas,"Denmark, United States, Asia, Europe",Denmark,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 79,12/1/2011,8/12/2013,2011,ICSA-11-335-01,7-Technologies Data Server Denial of Service,7-Technologies,Data Server,Version 9.0.0.11200 of 7T IGSS Data Server,CVE-2011-4050,5.0,Medium,CWE-119,Critical Manufacturing; Energy; oil and gas,"Denmark, United States, Asia, Europe",Denmark,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 78,12/21/2011,4/26/2013,2011,ICSA-11-355-02,WellinTech KingView History Server Buffer Overflow,WellinTech,KingView History Server,KingView V65.30.2010.18018,CVE-2011-4536,10.0,High,CWE-119,Commercial Facilities; Critical Manufacturing; Energy,"China, Japan, Singapore, Taiwan, United States, Europe",China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 77,12/6/2011,9/6/2018,2011,ICSA-11-340-01,ARC Informatique PcVue HMI/SCADA ActiveX Vulnerabilities,ARC Informatique,PcVue HMI/SCADA ActiveX,PcVue-All versions from 6.xx onwardFrontVue-All versionsPlantVue-All versions,"CVE-2011-4042, CVE-2011-4043",9.3,High,CWE-189,Chemical,Europe,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 76,8/31/2011,9/6/2018,2011,ICSA-11-243-03A,GE Intelligent Platforms Proficy Historian Data Archiver Buffer Overflow Vulnerability (Update A),GE,Intelligent Platforms Proficy Historian Data Archiver,Proficy Historian: Versions 4.0 and priorProficy HMI/SCADA - CIMPLICITY: Version 8.1 (If Historian is installed)Proficy HMI/SCADA - iFix: Versions 5.0 and 5.1 (If Historian is installed),CVE-2011-1918,10.0,High,CWE-119,Multiple Critical sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 75,11/3/2011,5/7/2013,2011,ICSA-11-307-01,Schneider Electric Vijeo Historian Web Server Multiple Vulnerabilities,Schneider Electric,Vijeo Historian Web Server,Vijeo Historian V4.30 and earlier Citect Historian V4.30 and earlier CitectSCADA Reports V4.10 and earlier,"CVE-2011-4033, CVE-2011-4034, CVE-2011-4035, CVE-2011-4036",5.7,Medium,"CWE-119, CWE-79, CWE-22",Energy,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 74,11/15/2011,3/12/2014,2011,ICSA-11-319-01,InduSoft Web Studio Vulnerabilities,InduSoft,Web Studio,InduSoft Web Studio Versions 6.1 and 7.0,"CVE-2011-4051, CVE-2011-4052",9.6,High,"CWE-287, CWE-119",Pharmaceutical; Critical Manufacturing; Energy; oil and gas; Food and Agriculture; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 73,10/6/2011,3/12/2014,2011,ICSA-11-279-02,CitectSCADA and Mitsubishi MX4 SCADA Batch Server Buffer Overflow,"Mitsubishi Electric Automation, Schneider Electric",MX4 SCADA Batch Server,CitectSCADA V7.10 and prior using the CitectSCADA Batch Server module.Mitsubishi MX4 SCADA V7.10 and prior using the MX4 SCADA Batch module.,CVE-2011-5163,4.6,Medium,CWE-119,Commercial Facilities,"Taiwan, Europe",Japan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 72,10/6/2011,10/28/2013,2011,ICSA-11-279-01,Advantech OPC Server Buffer Overflow,Advantech,OPC Server,Advantech ADAM OPC Server Versions prior to V3.01.012 Advantech Modbus RTU OPC Server Versions prior to V3.01.010 Advantech Modbus TCP OPC Server Versions prior to V3.01.010,CVE-2011-1914,10.0,High,CWE-119,Communications; Energy; Transportation Systems; Government Facilities,"Taiwan, North America, Asia, East Asia",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 71,8/31/2011,4/20/2013,2011,ICSA-11-243-01,GE Intelligent Platforms Proficy Plant Applications Buffer Overflow,GE,Intelligent Platforms Proficy Historian Data Archiver,Proficy Plant Applications (Version 5.0 and prior),CVE-2011-1919,10.0,High,CWE-119,Multiple Critical sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 70,8/31/2011,4/20/2013,2011,ICSA-11-243-02,GE Proficy Historian Web Administrator XSS,GE,Proficy Historian Web Administrator,Proficy Historian: All versionsProficy HMI/SCADA CIMPLICITY: Version 8.1and 8.2 (If Historian is installed).Proficy HMI/SCADA iFIX: Versions 5.0 and 5.1 (If Historian is installed),CVE-2011-3320,4.3,Medium,CWE-79,Multiple Critical sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 69,10/21/2011,1/24/2014,2011,ICSA-11-294-01,Progea Movicon Power HMI Vulnerabilities,Progea,Movicon Power HMI,Progea Movicon 11.2.1085.3 and earlier Progea Movicon PowerHMI 11.2.1085 and earlier,"CVE-2011-3491, CVE-2011-3498, CVE-2011-3499",10.0,High,CWE-119,Critical Manufacturing; Energy,"India, United States, Europe",Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 68,10/4/2011,5/7/2013,2011,ICSA-11-277-01,Schneider Electric UnitelWay Buffer Overflow,Schneider Electric,UnitelWay,Platform Unity Pro Version 6 and prior Windows XP OPC Factory Server Version 3.34 Windows XP Vijeo Citect Version 7.20 and prior Windows XP Telemecanique Driver PackVersion 2.6 and prior Windows XP Monitor Pro Version 7.6 and prior Windows XP PL 7 Pro Version 4.5 and prior Windows XP These six products are known to have the vulnerable UnitelWay Windows Device Driver and are elements of Schneider Electric SoCollaborative software components. These components are part of Schneider Electric process automation architecture known as PlantStruxure.,CVE-2011-3330,7.2,High,CWE-119,Energy; Information Technology,Worldwide,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 67,10/12/2011,4/30/2013,2011,ICSA-11-285-01,Honeywell TEMA Remote Installer ActiveX Vulnerability,Honeywell,TEMA Remote Installer,EBI product versions: EBI R310.1 - TEMA 4.8EBI R310.1 - TEMA 4.9EBI R310.1 - TEMA 4.10EBI R400.2 SP1 - TEMA 5.2EBI R410.1 - TEMA 5.3.0EBI R410.2 - TEMA 5.3.1,CVE-NA,Not Applicable,Not Applicable,CWE-NA,Energy,"North America, South America",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 66,10/6/2011,5/8/2013,2011,ICSA-11-279-03A,Unitronics UNIOPC Server Input Handling Vulnerability (Update A),Unitronics,UNIOPC Server,Unitronics UniOPC prior to Version 2.0.0,CVE-2011-5086,6.8,Medium,CWE-20,Multiple Critical Sectors,Israel,Israel,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 65,10/7/2011,9/6/2018,2011,ICSA-11-280-01,Cogent DataHub Vulnerabilities,Cogent Real-Time Systems Inc,DataHub,Cogent DataHub all of Version 7 until 7.1.2 OPC DataHub prior to Version 6.4.20 Cascade DataHub all of Version 6 6.4.20,"CVE-2011-3493, CVE-2011-3500, CVE-2011-3501, CVE-2011-3502",6.3,Medium,"CWE-119, CWE-200, CWE-22, CWE-189",Chemical,"Canada, United Kingdom, United States",Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 64,10/6/2011,9/6/2018,2011,ICSA-11-279-04,Beckhoff TwinCAT Read Access Violation,Beckhoff Automation,TwinCAT,"TwinCAT versions 2.10, 2.11, 2.11R2",CVE-2011-3486,5.0,Medium,CWE-119,Commercial Facilities; Critical Manufacturing; Energy; oil and gas; Government Facilities; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 63,9/30/2011,9/6/2018,2011,ICSA-11-273-03A,Rockwell RSLogix Overflow Vulnerability (Update A),Rockwell Automation,RSLogix,"RSLogix 5000 software Versions V17, V18, and V19 All FactoryTalk-branded software of specific Versions CPR9 and CPR9-SR1 through SR4",CVE-2011-3489,5.0,Medium,CWE-119,Chemical; Critical Manufacturing; Food and Agriculture; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 62,9/30/2011,8/28/2013,2011,ICSA-11-273-01,ICONICS GENESIS32 Multiple Memory Corruption,ICONICS,GENESIS32,"GENESIS32 V8.05, V9.0, V9.1, and V9.2 - ScriptWorX32, AlarmWorX32 and TrendWorX32 containers GENESIS32 V9.2 - GraphWorX32",CVE-NA,Not Applicable,Not Applicable,CWE-NA,Commercial Facilities; Critical Manufacturing; Energy; oil and gas; Government Facilities; Water and Wastewater,"Australia, China, Czech Republic, Germany, France, United Kingdom, India, Italy, Netherlands, United States, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 61,9/30/2011,10/28/2013,2011,ICSA-11-273-02,InduSoft ISSymbol ActiveX Control Buffer Overflow,InduSoft,ISSymbol ActiveX Control,InduSoft Web Studio Versions 7.0B2 (Build: 0301.1009.2904.0000) and 7.0 (Build: 0301.1102.0303.0000),CVE-2011-0342,10.0,High,CWE-119,Pharmaceutical; Critical Manufacturing; Energy; oil and gas; Food and Agriculture; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 60,9/21/2011,9/6/2018,2011,ICSA-11-264-01,AzeoTech DAQFactory Stack Overflow,AzeoTech,DAQFactory,DAQFactory Version 5.85,CVE-2011-3492,10.0,High,CWE-119,Critical Manufacturing; Energy; Water and Wastewater,"United States, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 59,9/20/2011,9/6/2018,2011,ICSA-11-263-01,Measuresoft ScadaPro Vulnerabilities,Measuresoft,ScadaPro,ScadaPro Version 4.0.0.0 and earlier,"CVE-2011-3490, CVE-2011-3495, CVE-2011-3496, CVE-2011-3497",10.0,High,"CWE-119, CWE-22, CWE-20, CWE-200",Pharmaceutical; Critical Manufacturing; Energy; oil and gas,Ireland,Ireland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 58,8/4/2011,9/6/2018,2011,ICSA-11-216-01,Scadatec Limited Procyon Telnet Buffer Overflow,Scadatec Limited,Procyon Telnet,Scadatec Limited Procyon HMI prior to Version 1.14,CVE-2011-3322,10.0,High,CWE-119,Chemical; Critical Manufacturing; Transportation Systems,"United Kingdom, Philippines, Singapore, Thailand",United Kingdom,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 57,9/1/2011,8/23/2018,2011,ICSA-11-244-01,Siemens WinCC Flexible Runtime Heap Overflow,Siemens,WinCC,Siemens SIMATIC WinCC flexible RuntimeSiemens SIMATIC WinCC (TIA Portal) Runtime Advanced,CVE-2011-3321,9.3,High,CWE-119,Chemical; Energy; oil and gas; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 56,6/22/2011,8/29/2013,2011,ICSA-11-173-01,ClearSCADA Remote Authentication Bypass,Schneider Electric,ClearSCADA Remote Authentication,ClearSCADA 2010 R1.0 ClearSCADA 2009 ClearSCADA 2007 ClearSCADA 2005. This Advisory applies to all versions of SCX (from Serck UK or Serck Aus) that are older than the following (these SCX versions contain ClearSCADA in the bundle):SCX Version 67 R4.5SCX Version 68 R3.9.,CVE-NA,Not Applicable,Not Applicable,CWE-NA,Energy; Water and Wastewater,United Kingdom,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 55,8/11/2011,9/6/2018,2011,ICSA-11-223-01A,Siemens SIMATIC PLCs Reported Issues Summary (Update A),Siemens,SIMATIC PLCs,"SIMATIC S7 product line, including:S7-200S7-300S7-400S7-1200",CVE-NA,Not Applicable,Not Applicable,CWE-NA,Chemical; Commercial Facilities; Critical Manufacturing; Energy; oil and gas; Government Facilities; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 54,8/19/2011,4/22/2013,2011,ICSA-11-231-01,Inductive Automation Ignition Information Disclosure Vulnerability,Inductive Automation,Ignition,Inductive Automation Ignition versions prior to Version 7.2.8.178,CVE-NA,Not Applicable,Not Applicable,CWE-NA,Chemical; Pharmaceutical; Critical Manufacturing; Energy; oil and gas; Food and Agriculture,"Australia, South America, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 53,4/13/2011,3/13/2014,2011,ICSA-11-103-01A,Honeywell ScanServer ActiveX Control (Update A),Honeywell,ScanServer,"Honeywell's ScanServer ActiveX control, which is a component of the Web Toolkit (Version 780.0.20.5) that is packaged with all versions of Honeywell SymmetrE. Web Toolkit may also be licensed separately for use with other software products.",CVE-2011-0331,9.3,High,CWE-416,Energy,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 52,7/14/2011,5/1/2013,2011,ICSA-11-195-01,Wonderware Information Server,Invensys,Wonderware,Wonderware Information Server 3.1 Wonderware Information Server 4.0 Wonderware Information Server 4.0 SP1,CVE-2011-2962,9.3,High,CWE-119,Chemical; Pharmaceutical; Energy; oil and gas; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 51,7/8/2011,8/23/2018,2011,ICSA-11-189-01,7-Technologies IGSS Remote Memory Corruption,7-Technologies,IGSS,7T Interactive Graphical SCADA System (IGSS) versions prior to 9.0.0.11143,CVE-2011-2214,10.0,High,CWE-NA,Critical Manufacturing; Energy; oil and gas,"Denmark, United States, Asia, Europe",Denmark,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 50,7/1/2011,9/5/2018,2011,ICSA-11-182-01,ICONICS GENESIS32 and BizViz ActiveX Trusted Zone Vulnerability,ICONICS,GENESIS32 and BizViz ActiveX,"GENESIS32 - Version 9.21, including Workbench / WebHMI components BizViz - Version 9.21",CVE-NA,Not Applicable,Not Applicable,CWE-NA,Commercial Facilities; Critical Manufacturing; Energy; oil and gas; Government Facilities; Water and Wastewater,"Australia, China, Czech Republic, Germany, France, United Kingdom, India, Italy, Netherlands, United States, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 49,7/1/2011,8/28/2013,2011,ICSA-11-182-02,ICONICS Login ActiveX Vulnerability,ICONICS,Login ActiveX,"GENESIS32 - Versions 8.05, 9.0, 9.1 and 9.2 BizViz - Versions 8.05, 9.0, 9.1 and 9.2",CVE-NA,Not Applicable,Not Applicable,CWE-NA,Commercial Facilities; Critical Manufacturing; Energy; oil and gas; Government Facilities; Water and Wastewater,"Australia, China, Czech Republic, Germany, France, United Kingdom, India, Italy, Netherlands, United States, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 48,6/24/2011,8/12/2013,2011,ICSA-11-175-02,Siemens WinCC Exploitable Crashes,Siemens,WinCC,WinCC: ProTool 6.0 SP3 (has been phased-out) WinCC flexible 2004 (has been phased-out) WinCC flexible 2005 (has been phased-out) WinCC flexible 2005 SP1 WinCC flexible 2007 WinCC flexible 2008 WinCC flexible 2008 SP1 WinCC flexible 2008 SP2,CVE-NA,Not Applicable,Not Applicable,CWE-NA,Chemical; Energy; oil and gas; Food and Agriculture; Water and Wastewater,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 47,6/17/2011,10/28/2013,2011,ICSA-11-168-01A,InduSoft ISSymbol ActiveX Control Buffer Overflow (Update A),InduSoft,ISSymbol ActiveX Control,InduSoft ISSymbol ActiveX Control (build 301.1009.2904.0) InduSoft Thin Client Version 7.0 InduSoft Web Studio Version 7.0B2,CVE-2011-0340,9.3,High,CWE-119,Pharmaceutical; Critical Manufacturing; Energy; oil and gas; Food and Agriculture; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 46,6/24/2011,4/26/2013,2011,ICSA-11-175-01,Rockwell FactoryTalk Diag Viewer Memory Corruption,Rockwell Automation,FactoryTalk Diag Viewer,Versions 2.10.x (SPR9 SR2) and earlier,CVE-2011-2957,6.9,Medium,CWE-NA,Food and Agriculture; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 45,5/2/2011,9/6/2018,2011,ICSA-11-122-01,AzeoTech DAQFactory Networking Vulnerabilities,AzeoTech,DAQFactory,"DAQFactory Standard, Pro, Developer, or Runtime. DAQFactory Express, Starter, Lite, and Base do not support networking and are not vulnerable",CVE-2011-2956,7.8,High,CWE-287,Critical Manufacturing; Energy; Water and Wastewater,"United States, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 44,6/16/2011,1/2/2019,2011,ICSA-11-167-01,Sunway Force Control,Sunway,Force Control,"Sunway ForceControl 6.1 (SP1, SP2, and SP3) and pNetPower Version 6","CVE-2011-2961, CVE-2011-2960",10.0,High,CWE-119,Chemical; Pharmaceutical; Communications; Critical Manufacturing; Energy,"China, Asia, Europe, Africa",China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 43,2/25/2011,9/5/2018,2011,ICSA-11-056-01A,Progea Movicon TCPUploadServer (Update A),Progea,Movicon Power HMI,Movicon 11.2 prior to Build 1084,CVE-2011-2963,10.0,High,CWE-287,Critical Manufacturing; Energy; Water and Wastewater,"Italy, Europe",Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 42,6/10/2011,8/29/2013,2011,ICSA-11-161-01,Rockwell RSLinx EDS Vulnerability,Rockwell Automation,RSLinx,Electronic Data Sheet (EDS) Hardware Installation Tool Version 1.3.0.1 and all earlier versions,CVE-2011-2530,9.3,High,CWE-119,Critical Manufacturing; Energy; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 41,3/10/2011,9/5/2018,2011,ICSA-11-069-01B,Samsung Data Management Server (Update B),Samsung,Data Management Server,Data Management Server Version 1.4.2 and all earlier versions,CVE-2010-4284,7.5,High,CWE-89,Commercial Facilities; Government Facilities,"China, South Korea, United States, Europe",South Korea,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 40,5/12/2011,8/23/2018,2011,ICSA-11-132-01A,7-Technologies IGSS Denial of Service (Update A),7-Technologies,IGSS,7T IGSS SCADA HMI Version 7 prior to Revision 10033.The vulnerabilities affect 7T IGSS SCADA HMI Version 8 prior to Revision 11102 7T IGSS SCADA HMI Version 9 prior to Revision 11143,CVE-2011-2214,10.0,High,CWE-NA,Critical Manufacturing; Energy; oil and gas,"Denmark, United States, Asia, Europe",Denmark,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 39,5/27/2011,8/28/2013,2011,ICSA-11-147-01B,Ecava IntegraXor DLL Hijacking (Update B),Ecava,IntegraXor,IntegraXor versions prior to Version 3.60 (Build 4090),CVE-2011-2958,4.3,Medium,CWE-79,Multiple Critical sectors,"Australia, Canada, Estonia, United Kingdom, Malaysia, Poland, United States",Malaysia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 38,5/27/2011,4/30/2013,2011,ICSA-11-147-02,Ecava IntegraXor XSS,Ecava,IntegraXor,IntegraXor versions prior to Version 3.60 (Build 4080),CVE-2011-2958,4.3,Medium,CWE-79,Multiple Critical sectors,"Australia, Canada, Estonia, United Kingdom, Malaysia, Poland, United States",Malaysia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 37,5/11/2011,8/28/2013,2011,ICSA-11-131-01,ICONICS GENESIS32 and BizViz ActiveX Stack Overflow,ICONICS,GENESIS32 and BizViz ActiveX,GENESIS32 and BizViz (Versions 9 through 9.21),CVE-2011-2089,9.3,High,CWE-119,Commercial Facilities; Critical Manufacturing; Energy; oil and gas; Government Facilities; Water and Wastewater,"Australia, China, Czech Republic, Germany, France, United Kingdom, India, Italy, Netherlands, United States, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 36,5/6/2011,9/6/2018,2011,ICSA-11-126-01,7-Technologies IGSS Vulnerabilities,7-Technologies,IGSS,7T IGSS SCADA HMI prior to Version 9.0.0.11083,"CVE-2011-1565, CVE-2011-1566, CVE-2011-1567",10.0,High,"CWE-22, CWE-119, CWE-134, CWE-121",Critical Manufacturing; Energy; oil and gas,"Denmark, United States, Asia, Europe",Denmark,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 35,4/29/2011,9/5/2018,2011,ICSA-11-119-01,7-Technologies IGSS ODBC Remote Stack Overflow,7-Technologies,IGSS ODBC Server,7T IGSS Version 9 and all earlier versions,CVE-2011-2959,10.0,High,CWE-119,Critical Manufacturing; Energy; oil and gas;,"Denmark, United States, Asia, Europe",Denmark,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 34,4/20/2011,9/6/2018,2011,ICSA-11-110-01,RealFlex RealWin Vulnerabilities,RealFlex Technologies,RealWin,RealWin Versions 1.06A and earlier of its demo software only. The commercial version of RealWin is not affected.,CVE-2011-1564,10.0,High,CWE-680,Chemical; Critical Manufacturing; Energy; oil and gas; Transportation Systems; Water and Wastewater,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 33,4/18/2011,9/6/2018,2011,ICSA-11-108-01,ICONICS GENESIS (32 & 64) Vulnerabilities,ICONICS,GENESIS,GENESIS32 Version 9.21 and priorGENESIS64 Version 10.51 and prior,CVE-2007-6483,5.0,Medium,"CWE-415, CWE-190",Commercial Facilities; Critical Manufacturing; Energy; oil and gas; Government Facilities; Water and Wastewater,"Australia, China, Czech Republic, Germany, France, United Kingdom, India, Italy, Netherlands, United States, Asia, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 32,4/4/2011,9/6/2018,2011,ICSA-11-094-01,Wonderware InBatch Client ActiveX Buffer Overflow,Invensys,Wonderware,Wonderware InBatch 8.1--InBatch Runtime Clients (all versions) Windows XP Professional Windows 2000 Server Windows Server 2003 Wonderware InBatch 9.0--InBatch Runtime Clients (all versions) Windows XP Professional Windows Server 2003 Windows Server 2008,CVE-2011-3141,9.3,High,CWE-119,Chemical; Pharmaceutical,"North America, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 31,4/6/2011,9/6/2018,2011,ICSA-11-096-01,GLEG Agora SCADA+ Exploit Pack,Other,GLEG Agora SCADA+,"Indusoft SCADA web studio 7.0 SCADA Trace Mode Data Center IGSS SCADA odbc server IGSS ODBC Server OPC Modbus Ethernet OPC Server Automated Solutions OPC Server ITS scada Automated Solutions Modbus/TCP OPC Server BACnet OPC client before 1.0.25 Advantech Studio 6.1 Web server ICONICS Dialog Wrapper Module ActiveX control BECK GMBH, INDUSTRIAL PC SafeNet Sentinel Protection Server 7.4.1.0 Sentinel Keys Server 1.0.4.0 DATARATE SCADA 2.5 SCADA MOXA Device Manager Tool 2.1 Moxa Device Manager Buffer Overflow Ecava IntegraXor GE Fanuc Real Time Information Portal 2.6. Citect SCADA ODBC Invensys Wonderware InFusion SCADA (and other products) ActiveX DATAC RealWin SCADA 1.06","CVE-2011-0488, CVE-2010-4709, CVE-2006-6488, CVE-2001-1340, CVE-2001-1341, CVE-2008-0760, CVE-2010-4741, CVE-2010-4598, CVE-2008-0175, CVE-2008-2639, CVE-2010-2974, CVE-2010-4142, CVE-2010-4740",7.5,High,"CWE-119, CWE-22",Multiple Critical sectors,Worldwide,Russia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 30,4/1/2011,9/6/2018,2011,ICSA-11-091-01A,Siemens Tecnomatix FactoryLink Vulnerabilities (Update A),Siemens,Tecnomatix FactoryLink,All versions of Siemens Tecnomatix FactoryLink prior to and including Version 8.0.1.1473,CVE-NA,Not Applicable,Not Applicable,CWE-NA,Chemical; Commercial Facilities; Energy; oil and gas; Food and Agriculture; Government Facilities,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 29,3/25/2011,1/2/2014,2011,ICSA-11-084-01,Solar Magnetic Storm Impact on Control Systems,Other,Solar Magnetic Storm,Terrestrial communications and other electronic systems supporting critical infrastructure,CVE-NA,Not Applicable,Not Applicable,CWE-NA,Communications; Dams; Emergency Services; Energy; oil and gas; Transportation Systems; Water and Wastewater,"Canada, Sweden, United States, South Africa, North America, Africa",Not Applicable,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 28,3/23/2011,4/30/2013,2011,ICSA-11-082-01,Ecava IntegraXor SQL,Ecava,IntegraXor,All IntegraXor versions prior to Version 3.60 (Build 4032),CVE-2011-2958,4.3,Medium,CWE-79,Critical Manufacturing,"Australia, Canada, Estonia, United Kingdom, Malaysia, Poland, United States",Malaysia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 27,3/15/2011,9/6/2018,2011,ICSA-11-074-01,WellinTech KingView 6.53 KVWebSvr ActiveX,WellinTech,KingView 6.53 KVWebSvr,KingView V6.53,"CVE-2011-4536, CVE-2011-3142, CVE-2011-0406",10.0,High,CWE-119,Commercial Facilities; Critical Manufacturing; Defense Industrial Base Energy; Water and Wastewater,China,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 26,12/14/2010,4/22/2013,2011,ICSA-10-348-01A,Wonderware InBatch Vulnerability (Update A),Invensys,Wonderware,Wonderware InBatch 8.1 - InBatch Server (all versions) Windows XP Professional Windows 2000 Server Windows Server 2003 Wonderware InBatch 9.0 - InBatch Server (all versions) Windows XP Professional Windows Server 2003 I/A Series Batch 8.1 - I/A Series Batch Server (all versions) Windows Server 2003 Server R2 Windows XP Professional SP2,"CVE-2011-3141, CVE-2011-2962",9.3,High,CWE-119,Chemical; Pharmaceutical; Food and Agriculture,"North America, Europe",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 25,11/10/2010,8/23/2018,2011,ICSA-10-314-01A,ClearScada Vulnerabilities (Update A),Schneider Electric,ClearScada,ClearSCADA 2005 (all versions) ClearSCADA 2007 (all versions) ClearSCADA 2009 (all versions except R2.3 and R1.4) SCX Version 67 R4.5SCX Version 68 R3.9,"CVE-2011-3143, CVE-2011-3144",7.2,High,"CWE-122, CWE-79, CWE-399",Energy; Oil and Gas; Water and Wastewater,United Kingdom,France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 24,2/10/2011,9/6/2018,2011,ICSA-11-041-01A,McAfee Night Dragon Report (Update A),Other,McAfee Night Dragon,"Control systems in oil, energy, and petrochemical industries",CVE-NA,Not Applicable,Not Applicable,CWE-NA,Chemical; Information Technology; Energy; oil and gas,Worldwide,Not Applicable,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 23,1/18/2011,9/5/2018,2011,ICSA-11-018-02,7-Technologies IGSS 8 ODBC Server Remote Heap Corruption,7-Technologies,IGSS 8 ODBC Server,IGSS Versions 8 and 9,CVE-2011-2214,10.0,High,CWE-NA,Critical Manufacturing; Energy; oil and gas; Water and Wastewater,"Denmark, Asia, Europe",France,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 22,1/25/2011,8/23/2018,2011,ICSA-11-025-01,Federal Aviation Administration GPS Testing,Other,GPS,Global Positioning System (GPS),CVE-NA,Not Applicable,Not Applicable,CWE-NA,Energy; Transportation Systems,Worldwide,Not Applicable,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 21,1/18/2011,9/5/2018,2011,ICSA-11-018-01,AGG SCADA Viewer OPC Buffer Overflow Vulnerability,AGG Software,SCADA Viewer OPC,All OPC SCADA Viewer versions prior to Version 1.5.2 (Build 110),CVE-NA,Not Applicable,Not Applicable,CWE-NA,Chemical,North America,Canada,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 20,1/17/2011,9/6/2018,2011,ICSA-11-017-01,WellinTech Kingview 6.53 Remote Heap Overflow,WellinTech,KingView 6.53,Chinese and English language versions of KingView V6.53,CVE-2011-0406,10.0,High,CWE-119,Commercial Facilities; Critical Manufacturing; Defense Industrial Base Energy; Water and Wastewater,China,China,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 19,1/17/2011,9/6/2018,2011,ICSA-11-017-02,Sielco Sistemi WinLog Stack Overflow,Sielco Sistemi,WinLog,WinLog Lite and WinLog Pro prior to Version 2.07. 00,CVE-2011-0517,9.3,High,CWE-119,Critical Manufacturing; Food and Agriculture,Italy,Italy,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 18,12/3/2010,10/28/2013,2011,ICSA-10-337-01,Advantech Studio Test Web Server Buffer Overflow,Advantech,Studio Test Web Server,Advantech Studio Version 6.1 (Test Serve Bundle) and all previous versions,CVE-2011-0488,10.0,High,CWE-119,Commercial Facilities; Energy; Government Facilities; Water and Wastewater,United States,Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 17,12/28/2010,9/6/2018,2010,ICSA-10-362-01,Ecava IntegraXor Directory Traversal,Ecava,IntegraXor,All IntegraXor versions prior to Version 3.6 (Build 4000.0),"CVE-2010-4599, CVE-2010-4598",6.0,Medium,CWE-22,Multiple Critical Sectors,"Australia, Canada, Estonia, United Kingdom, Malaysia, Poland, United states",Malaysia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 16,11/12/2010,9/6/2018,2010,ICSA-10-316-01A,Intellicom NetBiter WebSCADA Vulnerabilities (Update A),Intellicom,NeBiter,Intellicom NetBiter (NB100 and NB200 platforms): WebSCADA (WS100) WebSCADA (WS200) Easy Connect (EC150) Modbus RTU - TCP Gateway (MB100) Serial Ethernet Server (SS100),CVE-NA,Not Applicable,Not Applicable,CWE-22,Critical Manufacturing; Commercial Facilities; Communications; Energy; Government Facilities,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 15,11/18/2010,4/29/2013,2010,ICSA-10-322-01,Ecava IntegraXor Buffer Overflow,Ecava,IntegraXor,All IntegraXor versions prior to v3.5 (Build 3900.10),CVE-2010-4597,10.0,High,CWE-119,Multiple Critical Sectors,Worldwide,Malaysia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 14,11/18/2010,8/28/2013,2010,ICSA-10-322-02A,Automated Solutions OPC Vulnerability (Update),Automated Solutions,OPC,Automated Solutions Modbus/TCP Master OPC Server product (Version 3.0.0) and all previous versions,CVE-NA,Not Applicable,Not Applicable,CWE-119,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 13,10/28/2010,8/23/2018,2010,ICSA-10-301-01A,MOXA Device Manager Buffer Overflow (Update A),Moxa,Device Manager,MOXA Device Manager Version 2.1,CVE-2010-4741,9.3,High,CWE-119,Energy; Critical Manufacturing; Communications; Healthcare and Public Health,"China, Germany, Taiwan, United States",Taiwan,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 12,11/9/2010,9/6/2018,2010,ICSA-10-313-01,RealFlex RealWin Buffer Overflow,RealFlex Technologies,RealWin,All RealWin versions up to and including Version 2.1.8 (Build 6.1.8),CVE-2010-4142,10.0,High,CWE-119,Chemical; Critical Manufacturing; Communications; Energy; Oil and Gas; Transportation Systems; Maritime; Water and Wastewater,"Ireland, Russia",United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 11,9/29/2010,9/6/2018,2010,ICSA-10-272-01,Primary Stuxnet Advisory,Siemens,Siemens WinCC and STEP 7 software,Siemens WinCC and STEP 7 software,CVE-2010-4142,6.9,Medium,CWE-255,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 10,9/21/2010,9/6/2018,2010,ICSA-10-264-01,SCADA Engine BACnet OPC Client Buffer Overflow Vulnerability,SCADA Engine,BACnet OPC Client,SCADA Engine Version 1.0.24 and older.,CVE-2010-4740,9.3,High,CWE-119,Commercial Facilities,"Singapore, Thailand, Australia",Australia,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 9,8/26/2010,1/8/2014,2010,ICSA-10-238-01B,Stuxnet Malware Mitigation (Update B),Siemens,Siemens WinCC and STEP 7 software,Windows XP Windows Vista Windows 7 Windows Server 2008 Windows Server 2008 R2,"CVE-2010-2568, CVE-2008-4250",8.1,High,"CWE-20, CWE-94",Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 8,8/16/2010,5/8/2013,2010,ICSA-10-228-01,Vendor Admin Accounts Warning,Vendor Admin,Vendor Admin Vulnerability,New Control System Software,CVE-NA,Not Applicable,Not Applicable,CWE-NA,Multiple Critical Sectors,Worldwide,Not Applicable,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 7,7/20/2010,1/8/2014,2010,ICSA-10-201-01C,USB Malware Targeting Siemens Control Software (Update C),Siemens,Siemens WinCC and STEP 7 software,SIMATIC WinCC SIMATIC Siemens STEP 7 Windows XP SP 3 Windows XP Professional x64 Edition SP 2 Windows Server 2003 SP 2 Windows Server 2003 x64 Edition SP 2 Windows Server 2003 with SP2 for Itanium-based Systems Windows Vista SP 1 Windows Vista SP 2 Windows Vista x64 Edition SP 1 Windows Vista x64 Edition SP 2 Windows Server 2008 for 32-bit Systems Windows Server 2008 for 32-bit Systems SP 2 Windows Server 2008 for x64-based Systems Windows Server 2008 for x64-based Systems SP 2 Windows Server 2008 for Itanium-based Systems Windows Server 2008 for Itanium-based Systems SP 2 Windows 7 for 32-bit Systems Windows 7 for x64-based Systems Windows Server 2008 R2 for x64-based Systems Windows Server 2008 R2 for Itanium-based Systems,CVE-2010-2568,8.1,High,CWE-20,Multiple Critical Sectors,Worldwide,Germany,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 6,8/2/2010,9/6/2018,2010,ICSA-10-214-01,Wind River VxWorks Vulnerabilities,Wind River,VxWorks,VxWorks,"CVE-2010-2966, CVE-2010-2967",7.8,High,"CWE-255, CWE-310",Critical Manufacturing; Defense Industrial Base; Healthcare and Public Health,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 5,5/27/2010,9/9/2014,2010,ICSA-10-147-01,Cisco Network Building Mediator,Cisco,Network Building Mediator (NBM),Richards-Zeta Mediator 2500 product Cisco Network Building Mediator NBM-2400 Cisco Network Building Mediator NBM-4800 All Mediator Framework software releases prior to 3.1.1,"CVE-2010-0600, CVE-2010-0597, CVE-2010-0596",9.3,High,CWE-264,Commercial Facilities; Energy; Government Facilities; Information Technology,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 4,3/11/2010,8/23/2018,2010,ICSA-10-070-01A,Rockwell Automation RSLinx Classic EDS Vulnerability (Update A),Rockwell Automation,RSLinx Classic EDS,EDS Hardware Installation Tool Version 1.0.5.1 and earlier,CVE-2011-2530,10.0,High,CWE-119,Multiple Critical Sectors,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 3,4/7/2010,9/6/2018,2010,ICSA-10-097-01,ABB NETCADOPS HELP SYSTEM VULNERABILITY,ABB,netCADOPS,All releases of the ABB netCADOPS product (netCADOPS web-based online Help),CVE-NA,Not Applicable,Not Applicable,CWE-79,Energy,Worldwide,Switzerland,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 2,3/31/2010,1/20/2014,2010,ICSA-10-090-01,Mariposa Botnet,Mariposa Botnet,Mariposa Botnet,Windows XP Windows Vista Windows 7 Windows Server 2008 Windows Server 2008 R2,CVE-NA,Not Applicable,Not Applicable,CWE-NA,Information Technology,"Spain, United States",Not Applicable,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project 1,3/11/2010,10/23/2014,2010,ICSA-10-070-02,Rockwell PLC5/SLC5/0x/RSLogix Security Vulnerability,Rockwell Automation,PLC5/SLC5/0x/RSLogix,Rockwell PLC-5 and SLC 5/0x controllers 1785-Lx and 1747-L5x RSLogix Programming and Configuration client software,CVE-2010-5305,7.5,High,CWE-284,Water and Wastewater Systems,Worldwide,United States,Open Database License (ODbL) v1.0 - 2026 ICS Advisory Project