Rewterz

Rewterz Threat Advisory – ICS: Delta Electronics CNCSoft

December 1, 2021
Rewterz

Rewterz Threat Advisory – ICS: Hitachi Energy Retail Operations and CSB Software

December 1, 2021

ICS: Johnson Controls CEM Systems AC2000

Severity

High

Analysis Summary

CVE-2021-3156 

The affected product has an off-by-one error vulnerability, which may allow an attacker to achieve “super user” access on the operating system.

Impact

  • Unauthorized Access

Affected Vendors

  • Johnson Controls

Affected Products

  • CEM Systems AC2000: All versions prior to Version 10.6

Remediation

Refer to CISA Advisory for the patch, upgrade, or suggested workaround information.

https://us-cert.cisa.gov/ics/advisories/icsa-21-334-04

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.