Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

CISA Issues 4 ICS Advisories on Security

July 12, 2023
Reading Time: 2 mins read
in Alerts
CISA Issues 4 ICS Advisories on Security

 

CISA issued four ICS advisories on July 11, 2023, covering Rockwell Automation Enhanced HIM, Sensormatic Electronics iSTAR, Panasonic Control FPWin Pro7, and Mitsubishi Electric MELSEC-F Series, providing information on security issues, vulnerabilities, and mitigations for Industrial Control Systems (ICS).

ICSA-23-192-01 Rockwell Automation Enhanced HIM

Rockwell Automation’s Enhanced HIM communication interface is affected by a cross-site request forgery (CSRF) vulnerability. Exploitation of this vulnerability could result in sensitive information disclosure and full remote access to the affected products. Rockwell Automation recommends users update to Enhanced HIM Version 1.002 and follow their best security practices. CISA advises organizations to minimize network exposure, isolate control system networks, and use secure remote access methods. They also provide additional guidance and recommended practices to enhance cybersecurity in industrial control systems. No known public exploits targeting this vulnerability have been identified.

ICSA-23-192-02 Sensormatic Electronics iSTAR

Sensormatic Electronics’ iSTAR devices are vulnerable to improper authentication, allowing unauthenticated users to log in with administrator rights. The affected products include iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with specific firmware versions. Successful exploitation of this vulnerability could lead to unauthorized access to the devices. Johnson Controls, the parent company, recommends upgrading the firmware to version 6.9.2 CU01 as a mitigation measure. CISA advises minimizing network exposure, isolating control system networks, and using secure remote access methods. No known public exploits targeting this vulnerability have been reported, but the attack complexity is considered high.

ICSA-23-192-03 Panasonic Control FPWin Pro7

Panasonic’s Control FPWin Pro7 software is affected by multiple vulnerabilities, including stack-based buffer overflow, type confusion, and improper restriction of operations within a memory buffer. Successful exploitation of these vulnerabilities could lead to information disclosure or remote code execution. Panasonic has released version 7.7.0.0 of the software to address these issues. CISA recommends implementing defensive measures such as isolating control system networks and using secure remote access methods. No known public exploits for these vulnerabilities exist, and they are not exploitable remotely.

ICSA-23-180-04 Mitsubishi Electric MELSEC-F Series (Update A)

Mitsubishi Electric’s MELSEC-F Series products, specifically the Control FPWIN Pro7 software, are vulnerable to an authentication bypass by capture-replay attack. This vulnerability could allow an attacker to log in to the product by sending specially crafted packets. The affected products include various versions of the MELSEC-F Series, and Mitsubishi Electric has recommended using firewalls or virtual private networks (VPNs) to prevent unauthorized access. CISA advises implementing defensive measures, performing impact analysis and risk assessment, and following their control systems security recommended practices to mitigate the risk. No known public exploits specifically target this vulnerability, but it can be exploited remotely with low attack complexity.

Reference:
  • CISA Releases Four Industrial Control Systems Advisories
Tags: AuthenticationCISACyber AlertCyber Alerts 2023CybersecurityJuly 2023Mitsubishi ElectricPanasonicRockwell AutomationSensormatic ElectronicsUpdatesVulnerabilities
ADVERTISEMENT

Related Posts

Microsoft Defender Bug Allows SYSTEM Access

Uncanny Automator Bug Risks WordPress Sites

May 14, 2025
Microsoft Defender Bug Allows SYSTEM Access

Devs Hit By PyPI Solana Token Secret Theft

May 14, 2025
Microsoft Defender Bug Allows SYSTEM Access

Microsoft Defender Bug Allows SYSTEM Access

May 14, 2025
Apple Fixes Critical Bugs in iOS and MacOS

Hackers Exploit Output Messenger Zero-Day

May 13, 2025
Apple Fixes Critical Bugs in iOS and MacOS

ASUS Fixes Critical Flaws in DriverHub

May 13, 2025
Apple Fixes Critical Bugs in iOS and MacOS

Apple Fixes Critical Bugs in iOS and MacOS

May 13, 2025

Latest Alerts

Microsoft Defender Bug Allows SYSTEM Access

Uncanny Automator Bug Risks WordPress Sites

Devs Hit By PyPI Solana Token Secret Theft

Hackers Exploit Output Messenger Zero-Day

ASUS Fixes Critical Flaws in DriverHub

Apple Fixes Critical Bugs in iOS and MacOS

Subscribe to our newsletter

    Latest Incidents

    Alabama Cybersecurity Event Hits Services

    Andy Frain Data Breach Impacts 100k People

    Hong Kong DSC Hit By Ransomware Attack

    Alleged Steam Breach Exposes 89M Records

    Ulhasnagar Municipal Corporation Hacked

    Madison County Iowa Systems Disrupted

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial