Viakoo Roundup Highlights Five CISA OT/ICS Advisories
Viakoo's daily operational technology security roundup for October 8, 2026, summarizes five CISA OT/ICS advisories issued on October 6. The advisories involve products from Johnson Controls, Savannah lwIP, and Hitachi Energy. The post advises readers to confirm current vendor guidance and notes suggested operational priorities.
Viakoo’s October 8, 2026 daily roundup collects five CISA OT/ICS advisories published two days earlier. The affected vendors named are Johnson Controls, Savannah lwIP, and Hitachi Energy, with the Johnson Controls and lwIP items detailed in the excerpt.
For Johnson Controls EasyIO FG, CISA ties firmware up to 2.0b52 to two flaws: privilege mismanagement linked to brute-force attempts and embedded credentials linked to password spraying. Exploitation could yield full device access, though CISA said the issues were not remotely exploitable and had no known public exploitation when published. The lwIP SMTP client issue, CVE-2026-15340, carries a 9.8 CVSS v3 score and involves unchecked buffer copying that could crash a device and may permit remote code execution.
Organizations using affected OT/ICS devices, including facility and industrial operators, could face operational disruption if these flaws are exploited. Hard-coded credentials and privilege weaknesses may allow unauthorized device control, while the lwIP buffer overflow could crash equipment or enable code execution. Because the Johnson Controls issues were not remotely exploitable, exposure may depend on network access and segmentation. Security teams may need to inventory assets, verify vendor guidance, and tighten remote-access controls.