Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
CISA released an advisory on vulnerabilities in Siemens Mendix Runtime, a low-code application development platform. The flaws could allow authentication bypass and unauthorized data access.
This advisory details a vulnerability in igloohome Smart Lock Mobile Application version 3.2.3 for Android, where sensitive information is included in source code. This could let an unauthorized actor access backend services not protected by authentication.
A vulnerability in Siemens SIMATIC S7-PLCSIM Advanced allows an unauthenticated attacker to cause a denial of service by sending high-volume multicast traffic. The affected application becomes inaccessible and requires a manual restart, but no project data is lost.
This advisory describes a vulnerability in ABB KNX Update Tool, where the firmware image lacks integrity protection, affecting only legacy KNX devices that do not support KNX Secure. An attacker with physical bus access could render the product unusable.
A critical stack buffer overflow vulnerability in OpenSSL's CMS parsing (CVE-2025-15467) affects Siemens Desigo CC building automation systems. An attacker can trigger remote code execution or denial of service by sending a crafted CMS message.
Multiple vulnerabilities have been identified in the GNU/Linux subsystem of SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP firmware version V3.1.6. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not yet available.