Industrial Security Alerts Cover Energy Systems, Camera Bug, and Data Theft Campaign
The U.S. cybersecurity agency published three industrial control system alerts involving widely used energy and communications equipment. Canadian authorities reported a command-injection bug in Johnson Controls camera software. A joint U.S. notice also detailed data theft tied to Chinese government-linked actors across several industries, including critical manufacturing.
EXPANDED:
CISA's October 8 advisory addressed Grid Protection Alliance openPDC and openHistorian, used in energy systems worldwide. It assigned a 9.8 CVSS v3 score and listed untrusted-data deserialization, missing authentication, server-side request forgery, hard-coded credentials, and unsafe reflection. Affected versions include openPDC below 2.9.477 and 2.9.482, and openHistorian below 2.8.580 and 2.8.585; one Docker image has an extra CVE. No public exploitation was known then.
A separate CISA alert covered seven flaws in Red Lion N-Tron 700 Series switches with firmware 3.11.0 or earlier and bootloader 2.0.6.1 or earlier. These included weak or hard-coded credentials, recoverable passwords, missing authentication, unchecked code download, and a reachable assertion. Canadian officials also reported a command-injection bug in Johnson Controls camera software, while a joint U.S. notice described data theft by Chinese government-linked actors across sectors, including critical manufacturing.
Count? First para: CISA's(1) October(2) 8(3) advisory(4) addressed(5) Grid(6) Protection(7) Alliance(8) openPDC(9) and(10) openHistorian,(11) used(12) in(13) energy(14) systems(15) worldwide.(16) It(17) assigned(18) a(19) 9.8(20) CVSS(21) v3(22) score(23) and(24) listed(25) untrusted-data(26) deserialization,(27) missing(28) authentication,(29) server-side(30) request(31) forgery,(32) hard-coded(33) credentials,(34) and(35) unsafe(36) reflection.(37) Affected(38) versions(39) include(4