Direkt zum Inhalt
IACS RadarIndustrial Cyber Exposure & Intelligence

CISA + Hersteller

ICS-Advisories

Advisories speziell für industrielle Steuerungssysteme — von CISA ICS-CERT und direkt von Herstellern (Siemens ProductCERT, ABB PSIRT) — einschließlich Revisionshistorie (Erstveröffentlichung, Update A, Update B) und verknüpfter CVEs.

10

Gefunden

Advisory-Daten: Live-Anbindung— zuletzt abgerufen: 24. September 2026 um 06:20.

10 Advisories gefunden

SA26P012

mapp Services Use of Weak Authenticators in mapp Audit

B&R Industrial Automation GmbHmapp Audit

ABB PSIRThoch

Veröffentlicht

3. September 2026

Letzte Aktualisierung

3. September 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

An update is available that resolves a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploits this vulnerability could gain access to the OPC UA server component on affected devices due to insufficient entropy of authenticators used by mapp Audit.

Zusammenfassung der Gegenmaßnahmen

The problem is corrected in the following product versions: mapp Services >= 6.8.0 B&R recommends that customers apply the update at earliest convenience when the vulnerable functionality mapp Audit is used. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revisionshistorie (1)
  1. Erstveröffentlichung3. September 2026

    Initial version.

Offizielle Quelle: ABB PSIRT

SA26P011

Security Issues addressed in APROL R 4.4-01P5

B&R Industrial Automation GmbHAPROL

ABB PSIRTkritisch

Veröffentlicht

6. Juli 2026

Letzte Aktualisierung

6. Juli 2026

Betroffene Sektoren

Risk Evaluation

An update is available that resolves several vulnerabilities and updates one or more 3rd party components in the product versions listed as affected in the advisory. An attacker who successfully exploited these vulnerabilities could impact the availability of the product, spoof identities or elevate privileges.

Zusammenfassung der Gegenmaßnahmen

The problem is corrected in the following product versions: - APROL >= R 4.4-01P5 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revisionshistorie (1)
  1. Erstveröffentlichung6. Juli 2026

    Initial version.

Offizielle Quelle: ABB PSIRT

SA26P010

Impact of Linux Kernel vulnerabilities on B&R products

B&R Industrial Automation GmbHLinux for B&R

ABB PSIRThoch

Veröffentlicht

11. Juni 2026

Letzte Aktualisierung

18. Juni 2026

Betroffene Sektoren

Risk Evaluation

B&R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory. Successful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Public proof-of-concept exploits are available for the vulnerabilities described herein. At the time of publication of this advisory, B&R had no evidence of active exploitation targeting B&R products.

Zusammenfassung der Gegenmaßnahmen

For affected products, software updates should be installed upon availability. Product Patch version - APROL : APROL-AutoYaST-DVD- V4.4-010.10.260602 Until remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.

Revisionshistorie (2)
  1. Erstveröffentlichung11. Juni 2026

    Initial version.

  2. Update A18. Juni 2026

    Updating the CWE classification for CVE-2026-43494.

Offizielle Quelle: ABB PSIRT

SA26P009

XZ Utils vulnerability impacting B&R Products

B&R Industrial Automation GmbHPPC3100

ABB PSIRThoch

Veröffentlicht

10. Juni 2026

Letzte Aktualisierung

10. Juni 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

An update is available that resolves vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the product to stop or corrupt memory data.

Zusammenfassung der Gegenmaßnahmen

The problem is corrected in the following product versions: Product Terminal OS Version - PPC3100 1.8.1 - C50 1.8.0 - C80 1.8.0 - FT50 1.8.1 - MT50 1.8.1 - T30 1.8.0 - T80 1.8.0 - T50 1.8.1 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revisionshistorie (1)
  1. Erstveröffentlichung10. Juni 2026

    Initial version.

Offizielle Quelle: ABB PSIRT

SA25P006

PPT30 OPC-UA Server has issues handling concurrent connections

B&R Industrial Automation GmbHPPT30 Operating System

ABB PSIRThoch

Veröffentlicht

26. Mai 2026

Letzte Aktualisierung

26. Mai 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

B&R is aware of a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploits this vulnerability could make the OPC-UA server of the product inaccessible.

Zusammenfassung der Gegenmaßnahmen

The problem is corrected in the following product versions: PPT30 Operating System 1.8.0 The OPC-UA server is not activated by default. B&R recommends that customers with the OPC-UA Server enabled to install the update at their earliest opportunity. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revisionshistorie (1)
  1. Erstveröffentlichung26. Mai 2026

    Initial version.

Offizielle Quelle: ABB PSIRT

SA25P007

B&R Automation Studio Update of SQLite version

B&R Industrial Automation GmbHAutomation Studio

ABB PSIRTkritisch

Risk Evaluation

ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that replaces an outdated third-party component. Although no successful exploitation was observed during testing of the affected B&R products, the identified vulnerabilities could present potential attack vectors that might enable unauthorized access, data exposure, or remote code execution.

Zusammenfassung der Gegenmaßnahmen

The problem is corrected in the following product versions: B&R Automation Studio 6.5 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revisionshistorie (2)
  1. Erstveröffentlichung18. Februar 2026

    Initial version.

  2. Update A14. Mai 2026

    Corrected vendor name from 'ABB' to 'B&R Industrial Automation GmbH' to ensure accurate product matching.

Offizielle Quelle: ABB PSIRT

SA26P001

​​PVI​ ​​Insertion of Sensitive Information into Logfile

B&R Industrial Automation GmbH​​PVI​

ABB PSIRTmiddel

Veröffentlicht

29. Januar 2026

Letzte Aktualisierung

14. Mai 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is now available that addresses and remediates the vulnerability. An attacker who successfully exploited this vulnerability could read sensitive information in the logging data of the PVI client application. Logging is deactivated by default in all PVI client versions.

Zusammenfassung der Gegenmaßnahmen

The problem is corrected in the following product versions: - PVI 6.5.0 Please note that PVI is included in the Automation Studio installation package and shares the same version number as the corresponding Automation Studio release. B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revisionshistorie (2)
  1. Erstveröffentlichung29. Januar 2026

    Initial version.

  2. Update A14. Mai 2026

    Corrected vendor name from 'ABB' to 'B&R Industrial Automation GmbH' to ensure accurate product matching.

Offizielle Quelle: ABB PSIRT

SA24P003

​B&R PCs vulnerable to PixieFail attack​

B&R Industrial Automation GmbHAPC4100

ABB PSIRThoch

Veröffentlicht

29. Januar 2026

Letzte Aktualisierung

14. Mai 2026

Betroffene Sektoren

Risk Evaluation

ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is now available that addresses and remediates the vulnerability. A network attacker could exploit the vulnerabilities to execute remote code, initiate DoS attacks, conduct DNS cache poisoning, or extract sensitive information.

Zusammenfassung der Gegenmaßnahmen

The problems are corrected in the following product versions: - APC4100 1.09 - APC910 No patch will be released (Please refer to the mitigation measures specified in this advisory). - C80 1.14 - MPC3100 1.24 - PPC1200 1.14 - PPC900 2.16 - APC2200 1.35 - PPC2200 1.35 - APC3100 1.45 - PPC3100 1.45 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revisionshistorie (2)
  1. Erstveröffentlichung29. Januar 2026

    Initial version.

  2. Update A14. Mai 2026

    Corrected vendor name from 'ABB' to 'B&R Industrial Automation GmbH' to ensure accurate product matching.

Offizielle Quelle: ABB PSIRT

SA25P005

B&R Automation Runtime Improper Handling of Flooding conditions on ANSL Server

B&R Industrial Automation GmbHAutomation Runtime

ABB PSIRTmiddel

Veröffentlicht

19. Januar 2026

Letzte Aktualisierung

14. Mai 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that resolves a vulnerability. An attacker who successfully exploited this vulnerability could cause the product to stop.

Zusammenfassung der Gegenmaßnahmen

The problem is corrected in the following product versions: - Automation Runtime 6 versions >= 6.5 - Automation Runtime 4 versions >= R4.93 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

Revisionshistorie (2)
  1. Erstveröffentlichung19. Januar 2026

    Initial version.

  2. Update A14. Mai 2026

    Corrected vendor name from 'ABB' to 'B&R Industrial Automation GmbH' to ensure accurate product matching.

Offizielle Quelle: ABB PSIRT

SA25P004

Automation Studio Insufficient Server Certificate Validation

B&R Industrial Automation GmbHAutomation Studio

ABB PSIRThoch

Veröffentlicht

19. Januar 2026

Letzte Aktualisierung

14. Mai 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that resolves a vulnerability. Successful exploitation of this vulnerability may enable an attacker to masquerade as a trusted party when B&R Automation Studio establishes a connection with a server via the ANSL over TLS or OPC-UA protocol.

Zusammenfassung der Gegenmaßnahmen

The problem is corrected in the following product versions: B&R Automation Studio version 6.5 B&R recommends that customers apply the update at earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is de-scribed in the user manual.

Revisionshistorie (2)
  1. Erstveröffentlichung19. Januar 2026

    Initial Version

  2. Update A14. Mai 2026

    Corrected vendor name from 'ABB' to 'B&R Industrial Automation GmbH' to ensure accurate product matching.

Offizielle Quelle: ABB PSIRT