CISA released fifteen Industrial Control Systems (ICS) advisories on May 11, 2023. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-23-131-01 Siemens Solid Edge ICSA-23-131-02 Siemens SCALANCE W1750D ICSA-23-131-03 Siemens Siveillance ICSA-23-131-04 Siemens SIMATIC Cloud Connect 7 ICSA-23-131-05 Siemens SINEC NMS Third-Party ICSA-23-131-06 Siemens SCALANCE LPE9403 ICSA-23-131-07 Sierra Wireless AirVantage ICSA-23-131-08 Teltonika Remote Management System and RUT Model Routers ICSA-23-131-09 Rockwell Automation Kinetix 5500 EtherNetIP Servo Drive ICSA-23-131-10 Rockwell Automation Arena Simulation Software ICSA-23-131-11 BirdDog Cameras & Encoders ICSA-23-131-12 SDG PnPSCADA ICSA-23-131-13 PTC Vuforia Studio ICSA-23-131-14 Rockwell PanelView 800 ICSA-23-131-15 Rockwell ThinManager CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations.CISAraw:ccc5ec53b4ea927a52a39b93f04a4901 – 2023-05-11T16:07:01.000Z

Cybersecurity
CISA released fifteen Industrial Control Systems (ICS) advisories on May 11, 2023. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.

ICSA-23-131-01 Siemens Solid Edge

ICSA-23-131-02 Siemens SCALANCE W1750D

ICSA-23-131-03 Siemens Siveillance

ICSA-23-131-04 Siemens SIMATIC Cloud Connect 7

ICSA-23-131-05 Siemens SINEC NMS Third-Party

ICSA-23-131-06 Siemens SCALANCE LPE9403

ICSA-23-131-07 Sierra Wireless AirVantage

ICSA-23-131-08 Teltonika Remote Management System and RUT Model Routers

ICSA-23-131-09 Rockwell Automation Kinetix 5500 EtherNetIP Servo Drive

ICSA-23-131-10 Rockwell Automation Arena Simulation Software

ICSA-23-131-11 BirdDog Cameras & Encoders

ICSA-23-131-12 SDG PnPSCADA

ICSA-23-131-13 PTC Vuforia Studio

ICSA-23-131-14 Rockwell PanelView 800

ICSA-23-131-15 Rockwell ThinManager

CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations.CISAraw:ccc5ec53b4ea927a52a39b93f04a4901CISAThu, 11 May 23 12:00:00 +0000

Schedule Demo: Managed IT

Use Our Online Scheduling Tool

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2023-2 868  Barracuda Networks ESG Appliance Improper Input Validation Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Note:  To view other newly added vulnerabilities in the catalog, click on the arrow in the “Date Added to Catalog” column—which will sort by descending dates. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities  established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the  BOD 22-01 Fact Sheet  for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities  as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria . This product is provided subject to this Notification  and this Privacy & Use  policy.CISAraw:c10caedb098110c81742083ca1bb7557 – 2023-05-30T12:15:47.000Z
Read More
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2023-2 868  Barracuda Networks ESG Appliance Improper Input Validation Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Note:  To view other newly added vulnerabilities in the catalog, click on the arrow in the “Date Added to Catalog” column—which will sort by descending dates. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities  established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the  BOD 22-01 Fact Sheet  for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities  as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria . This product is provided subject to this Notification  and this Privacy & Use  policy.CISAraw:750720923d0bad309449ad3f150687d9 – 2023-05-26T17:30:31.000Z
Read More