The Cybersecurity and Infrastructure Security Agency (CISA) has published the following ICS security advisories, along with additional alerts, updates, and bulletins:
ICS Advisories:
- On November 14, 2024, CISA Released Nineteen Industrial Control Systems Advisories for products used across multiple sectors, please check these latest advisories for specific equipment used across your ICS/SCADA environments and address accordingly:
- Siemens RUGGEDCOM CROSSBOW – Used in Energy
- Siemens SIPORT
- Siemens OZW672 and OZW772 Web Server
- Siemens SINEC NMS
- Siemens Solid Edge
- Siemens SCALANCE M-800 Family
- Siemens Engineering Platforms
- Siemens SINEC INS
- Siemens Spectrum Power 7
- Siemens TeleControl Server
- Siemens SIMATIC CP
- Siemens Mendix Runtime
- Rockwell Automation Verve Asset Manager
- Rockwell Automation FactoryTalk Updater
- Rockwell Automation Arena Input Analyzer
- Hitachi Energy MSM – Used in Energy
- 2N Access Commander
- Elvaco M-Bus Metering Gateway CMe3100 (Update A) – Used in Energy
- Baxter Life2000 Ventilation System
Additional Alerts, Updates, and Bulletins:
- Palo Alto Networks Emphasizes Hardening Guidance
- Fortinet Releases Security Updates for Multiple Products
- Microsoft Releases November 2024 Security Updates
- Adobe Releases Security Updates for Multiple Products
-
CISA’s ScubaGear Tool Improves Security for Organizations Using M365 and Surpasses 30,000 Downloads