ZeroHour
Infosecurity Magazinepublished ()ingested Beth Maundrill

CISA Issues Advisories on Critical ICS Vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-9256
+3 in the same advisory: …9262 …9290 …9429
In libmediaextractor there is a possible out of bounds write due to an integer overflow.

In libmediaextractor there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111921829

NVD description · AI analysis pending
8.8
group max
<1%
  • google android
CVE-2024-22774
An issue in Panoramic Corporation Digital Imaging Software v.9.1.2.7600 allows a local attacker to escalate privileges via the ccsservice.exe component.

An issue in Panoramic Corporation Digital Imaging Software v.9.1.2.7600 allows a local attacker to escalate privileges via the ccsservice.exe component.

NVD description · AI analysis pending
7.8<1%
CVE-2025-1484
A vulnerability exists in the media upload component of the Asset Suite versions listed below.

A vulnerability exists in the media upload component of the Asset Suite versions listed below. If successfully exploited an attacker could impact the confidentiality or integrity of the system. An attacker can use this vulnerability to construct a request that will cause JavaScript code supplied by the attacker to execute within the user’s browser in the context of that user’s session with the application.

NVD description · AI analysis pending
6.3<1%
CVE-2025-2500
A vulnerability exists in the SOAP Web services of the Asset Suite versions listed below.

A vulnerability exists in the SOAP Web services of the Asset Suite versions listed below. If successfully exploited, an attacker could gain unauthorized access to the product and the time window of a possible password attack could be expanded.

NVD description · AI analysis pending
9.1<1%
Full article376 words · extracted from infosecurity-magazine.com · click to collapse

The US Cybersecurity and Infrastructure Security Agency (CISA) has released a number of advisories related to vulnerabilities in products related to Industrial Control Systems (ICS).

The ICS vulnerabilities span several vendors including Johnson Controls Inc, ABB, Hitachi Energy and Schneider Electric.

The sectors affected include commercial facilities, energy, transportation systems and manufacturing. One of the vulnerabilities also affects the healthcare sector.

CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations.

The vulnerabilities have been given a range of CVSS v4 scores. One has been handed a score of 9.1 making it critical. The rest bar one are high severity and have CVSS scores between 8.2 and 8.7. The remaining flaw has a CVSS score of 6.1, making it medium severity.

Read more: Navigating the Vulnerability Maze Understanding CVE, CWE and CVSS

In alert ICSA-25-196-01, various vulnerabilities which affect the Hitachi Energy Asset Suite have been identified, specifically:

  • Asset Suite AnyWhere for Inventory (AWI) Android mobile app: Versions 11.5 and prior (CVE-2019-9262, CVE-2019-9429, CVE-2019-9256, CVE-2019-9290)
  • Asset Suite 9 series: Version 9.6.4.4 (CVE-2025-1484, CVE-2025-2500)
  • Asset Suite 9 series: Version 9.7 (CVE-2025-2500)

Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the target equipment, perform remote code executions or escalate privileges, the CISA advisory noted.

The vulnerability related to the healthcare sector was assigned CVE-2024-22774, affecting Panoramic Digital Imaging Software version 9.1.2.7600 and was given a CVSS v4 score of 8.5.

The affected Panoramic product is vulnerable to DLL hijacking, which may allow an attacker to obtain NT Authority/SYSTEM as a standard user.

The imaging software is vulnerable due to an SDK component owned by Oy Ajat Ltd, which is no longer supported. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.

The full list of advisories, published between July 15 and 17 2025, can be found here:

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisa-issues-advisories-ics-vulns/