CISA Publishes New Round of ICS Advisories Covering Industrial Test, Fleet and IoT Devices

The Cybersecurity and Infrastructure Security Agency published a new batch of industrial control system advisories on August 27, 2026, covering vulnerabilities in products used across manufacturing, transportation and utility test environments. Among the advisories was one for Rockwell Automation’s OTTO Fleet Manager, tagged to the Critical Manufacturing and Transportation Systems sectors, which CISA said contains a flaw (CVE-2026-75112) that could reduce the computational cost required for an attacker to carry out offline brute-force attacks against stored password hashes in versions up to V2.36.2.

A separate advisory covered the Applied Systems Engineering ASE2000 V2 Communications Test Set, a tool used to test IEC 60870-5-104 protocol communications common in electric utility SCADA environments. According to the advisory and a technical writeup published by Trout Software, the affected versions (2.25 through 2.37) carry two flaws: a legacy XML external entity issue tied to an outdated bundled Apache log4net library, and an improper certificate validation weakness in the product’s IEC 60870-5-104 TLS client that could allow an attacker to intercept and impersonate a trusted peer during protocol testing. CISA credited researcher Enoch Wang with the report and noted the vendor has released version 2.38 as a fix.

CISA also published advisories for the Xiiaozet LK100W device, warning that successful exploitation of the flaws it identified could allow an attacker to take control of the device, and for the All-Line Equipment Company Fuel-Boss and Ebyte NA111-M products. As with its standard ICS advisory practice, CISA’s guidance recommends that asset owners minimize network exposure of control system devices, ensure they are not directly reachable from the internet, and place control system networks behind firewalls, isolated from business IT networks.

The advisories arrive amid a broader pattern industry researchers have flagged this year: security vendor Forescout reported that ICS advisory volume topped 500 for the first time in 2025, with a growing share of vulnerabilities affecting field controllers, remote terminal units and other Purdue Model Level 1 devices that directly interface with physical processes. CISA continues to publish advisories on a rolling weekly basis covering vendors ranging from major industrial automation suppliers to smaller niche device manufacturers used in specific utility and manufacturing test workflows.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *