CISA cyber & ICS and DC3 (DoD Cyber Crime Center / DCISE) threat products relevant to the DIB — each read by dex into a categorized card: the gist, why it matters, who's affected, and what to do.
Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW ↗
Not yet assessed — open source ↗Siemens IAM Client ↗
Not yet assessed — open source ↗Siemens CADRA ↗
Not yet assessed — open source ↗Rockwell Automation Studio 5000 Logix Designer ↗
Not yet assessed — open source ↗Rockwell Automation FactoryTalk Services Platform ↗
Not yet assessed — open source ↗Rockwell Automation 1734 POINT I/O ↗
Not yet assessed — open source ↗Rockwell Automation 1718-AENTR/1719-AENTR ↗
Not yet assessed — open source ↗Siemens SICAM 8 ↗
Not yet assessed — open source ↗SALTO ProAccess Space ↗
Not yet assessed — open source ↗Rockwell Automation Flex 5000 Adapter ↗
Not yet assessed — open source ↗Rockwell Automation FactoryTalk DataMosaix ↗
Not yet assessed — open source ↗Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix ↗
Not yet assessed — open source ↗Rockwell Automation Arena ↗
Not yet assessed — open source ↗Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT ↗
Not yet assessed — open source ↗NASA Core Flight System (cFS) Health & Safety (HS) Application ↗
Not yet assessed — open source ↗AutomationDirect Productivity Suite ↗
Not yet assessed — open source ↗Rockwell Automation 1715-AENTR EtherNet/IP Adapter ↗
Not yet assessed — open source ↗ABB T-MAC Plus ↗
Not yet assessed — open source ↗ABB Advant Master Online Builder ↗
Not yet assessed — open source ↗ABB Ability Edgenius ↗
Not yet assessed — open source ↗Schneider Electric PowerChute Serial Shutdown ↗
Schneider Electric PowerChute Serial Shutdown <=1.4 has critical path traversal and injection flaws enabling file overwrite and credential reset.
Successful exploitation could allow attackers to overwrite critical files, forge logs, gain unauthorized access, or trigger DoS. This affects Schneider Electric PowerChute Serial Shutdown <=1.4 and impacts sectors including Communications, Critical Manufacturing, Energy, Healthcare, IT, and Transportation.
▸ DO Patch Schneider Electric PowerChute Serial Shutdown to version >1.4 immediately.
Schneider Electric Easergy MiCOM Px40 Series ↗
Schneider Electric Easergy MiCOM Px40 Series protection relays are vulnerable to unauthorized SNMP exposure of device identification.
Schneider Electric has identified a vulnerability in its Easergy MiCOM Px40 Series products that allows unauthorized exposure of basic device identification through the SNMP protocol. Failure to apply mitigations may risk unauthorized exposure of basic device identification through the SNMP protocol.
▸ DO Apply the Schneider Electric mitigations for the affected Easergy MiCOM Px40 Series versions immediately.
OpenPLC v3 ↗
Authenticated attackers can write arbitrary files and execute code via OpenPLC v3's unvalidated file upload workflow.
OpenPLC v3 contains a critical vulnerability (CVE-2026-14480) allowing authenticated users to write arbitrary files and escalate to code execution via the legacy web UI. This affects critical infrastructure sectors including manufacturing, energy, and water utilities worldwide.
▸ DO Patch OpenPLC v3 immediately and review file upload controls in legacy web UI.
Siemens SINEC OS ↗
Siemens SINEC OS before V4.0 contains multiple critical vulnerabilities affecting RuggedCom RST2428P devices.
This advisory highlights multiple vulnerabilities in Siemens SINEC OS prior to version 4.0, including buffer overflows and authentication bypasses. DIB organizations should update affected RuggedCom RST2428P devices to the latest version immediately.
▸ DO Update Siemens SINEC OS to version 4.0 or later on affected RuggedCom RST2428P devices.
Siemens Mendix Studio Pro ↗
Siemens Mendix Studio Pro versions prior to 11.12 have a file parsing vulnerability enabling arbitrary code execution during build pipelines.
This advisory details a critical vulnerability in Siemens Mendix Studio Pro where specially crafted malicious projects can trigger arbitrary code execution in the context of the user. Siemens has released patches for several affected versions and recommends immediate updates, while also advising countermeasures for products where fixes are not yet available.
▸ DO Update Siemens Mendix Studio Pro to the latest patched version or implement compensating controls.
Labcenter Proteus 9 ↗
Labcenter Proteus 9.1_SP4_Build_42914 has critical out-of-bounds write and buffer overflow flaws enabling arbitrary code execution.
Exploitation could disclose information or allow arbitrary code execution on affected Labcenter Proteus 9 installations. DIB organizations must patch immediately to prevent remote code execution.
▸ DO Upgrade to Labcenter Proteus 9.2 SPO immediately.
Hydro-Québec Le Circuit Electrique charging station backend ↗
Hydro-Québec charging station backend vulnerabilities allow unauthenticated websocket access and privilege escalation.
Exploitation of these flaws in Hydro-Québec Le Circuit Electrique charging station backend could lead to privilege escalation or denial-of-service attacks. Hydro-Québec has updated most stations to disable OCPP and implemented authentication for remaining systems.
▸ DO Review and patch Hydro-Québec Le Circuit Electrique charging station backend systems to disable OCPP or implement authentication.
Hitachi Energy PROMOD V ↗
Hitachi Energy PROMOD V versions <=1.0.10 use insecure HTTP, enabling interception of credentials and session data.
Hitachi Energy disclosed a critical vulnerability in PROMOD V where insecure HTTP communication allows attackers to intercept or manipulate sensitive data in transit. Affected versions are 1.0.10 and prior; vendors must upgrade to version 1.0.11 and enable HTTPS on the Digipede server.
▸ DO Patch Hitachi Energy PROMOD V to version 1.0.11 and enable HTTPS on the Digipede server.