Horner Automation Cscape

2026-06-25T19:23:29Z2a88f0cf85e0110e3266d927a4e656ce2de3e95544da6e2da01661e0500c6b96
CISACSAFCleartext TransmissionCritical InfrastructureDaktronicsDelta ElectronicsDenial of ServiceDeserializationEVoke SystemsH.VIEWHard-coded CredentialsHorner AutomationICSInformation DisclosureInsufficient Session ManagementMissing AuthenticationOS Command InjectionOut-of-bounds ReadPath TraversalPrivilege EscalationRemote Code ExecutionSchneider ElectricUnrestricted File UploadYokogawa

What happened

CISA published multiple ICS advisories covering critical vulnerabilities across several vendors and products that impact industrial and infrastructure environments worldwide. Affected products include Horner Automation Cscape (out-of-bounds read leading to info disclosure and potential code execution), Daktronics Controller Firmware (path traversal, dangerous file upload, and hard-coded credentials enabling unauthenticated root access), EVoke Systems Charging Station Management System (missing authentication and related flaws enabling administrative takeover and DoS), Schneider Electric PowerL

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ics_advisories
Record identifier
2a88f0cf85e0110e3266d927a4e656ce2de3e95544da6e2da01661e0500c6b96
Enrichment time
2026-06-25T19:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.