Horner Automation Cscape
2026-06-25T19:23:29Z•2a88f0cf85e0110e3266d927a4e656ce2de3e95544da6e2da01661e0500c6b96
CISACSAFCleartext TransmissionCritical InfrastructureDaktronicsDelta ElectronicsDenial of ServiceDeserializationEVoke SystemsH.VIEWHard-coded CredentialsHorner AutomationICSInformation DisclosureInsufficient Session ManagementMissing AuthenticationOS Command InjectionOut-of-bounds ReadPath TraversalPrivilege EscalationRemote Code ExecutionSchneider ElectricUnrestricted File UploadYokogawa
What happened
CISA published multiple ICS advisories covering critical vulnerabilities across several vendors and products that impact industrial and infrastructure environments worldwide. Affected products include Horner Automation Cscape (out-of-bounds read leading to info disclosure and potential code execution), Daktronics Controller Firmware (path traversal, dangerous file upload, and hard-coded credentials enabling unauthenticated root access), EVoke Systems Charging Station Management System (missing authentication and related flaws enabling administrative takeover and DoS), Schneider Electric PowerL
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ics_advisories
- Record identifier
- 2a88f0cf85e0110e3266d927a4e656ce2de3e95544da6e2da01661e0500c6b96
- Enrichment time
- 2026-06-25T19:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.