ICS Network Controllers Open to Remote Exploit, No Patches Available
ID: 35626a39-ce82-50bc-9c28-d841e436322f
STIX ID: report--35626a39-ce82-50bc-9c28-d841e436322f
Feed Name: Dark Reading
CISA issued an advisory warning of multiple high-severity vulnerabilities affecting Unitronics Vision Series PLCs (CVE-2024-1480, CVSS 8.7) and Mitsubishi MELSEC iQ-R CPUs (CVE-2021-20599, CVSS 9.1 plus related flaws) that expose credentials—either stored in recoverable form or transmitted in cleartext—enabling remote compromise. Unitronics has not collaborated on mitigations, and Mitsubishi’s fixes are constrained for some deployments, so CISA recommends isolating these devices from the Internet and business networks, enforcing firewalls and IP restrictions, and using secure remote access (VPNs) to reduce exploitation risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
