Les news relatives à la cybersécurité des installations industrielles
Liste des Known Exploited Vulnerabilities (KEV) publiés par l'agence de cybersécurité américaine CISA la semaine dernière :
CVE | Vendor | Product | Liens |
Gladinet | CentreStack and Triofox | ||
WatchGuard | Firebox | ||
Cisco | Multiple Products | ||
SonicWall | SMA1000 appliance | ||
Apple | Multiple Products | ||
ASUS | Live Update | ||
Fortinet | Multiple Products |
Vulnérabilités de composants de systèmes industriels :
Vendor | Product | Critical | High | Medium | Low | Total |
National Instruments | LabVIEW | 0 | 9 | 0 | 0 | 9 |
Advantech | WebAccess/SCADA | 0 | 2 | 3 | 0 | 5 |
Johnson Controls Inc. | PowerG | 0 | 3 | 1 | 0 | 4 |
Axis Communications | AXIS Camera Station Pro | 1 | 0 | 3 | 0 | 4 |
Rockwell Automation | Micro820 | 0 | 1 | 1 | 0 | 2 |
Inductive Automation | Ignition | 0 | 0 | 1 | 0 | 1 |
Hitachi Energy | AFS 660-B/C/S | 1 | 0 | 0 | 0 | 1 |
Mitsubishi Electric | GT Designer3 Version1 (GOT2000) | 0 | 0 | 1 | 0 | 1 |
Mitsubishi Electric Iconics Digital Solutions, Mitsubishi Electric | GENESIS64 | 0 | 1 | 0 | 0 | 1 |
Güralp Systems | Fortimus Series | 0 | 0 | 1 | 0 | 1 |
Liste complète triée par CVSSv3 Score :
Vendor | Product | CVE | CVSSv3 Score | CVSSv3 Severity | EPSS | Percentile | CWE |
Axis Communications | AXIS Camera Station Pro | 9.0 | CRITICAL | 1.916% | 82.831% | ||
Hitachi Energy | AFS 660-B/C/S | 9.0 | CRITICAL | 19.021% | 95.115% | ||
Advantech | WebAccess/SCADA | 8.8 | HIGH | 0.055% | 17.422% | ||
Mitsubishi Electric Iconics Digital Solutions, Mitsubishi Electric | GENESIS64 | 8.2 | HIGH | 0.032% | 8.694% | ||
Advantech | WebAccess/SCADA | 8.1 | HIGH | 0.253% | 48.442% | ||
National Instruments | LabVIEW | 7.8 | HIGH | 0.015% | 2.350% | ||
National Instruments | LabVIEW | 7.8 | HIGH | 0.015% | 2.350% | ||
National Instruments | LabVIEW | 7.8 | HIGH | 0.015% | 2.350% | ||
National Instruments | LabVIEW | 7.8 | HIGH | 0.015% | 2.350% | ||
National Instruments | LabVIEW | 7.8 | HIGH | 0.015% | 2.350% | ||
National Instruments | LabVIEW | 7.8 | HIGH | 0.015% | 2.350% | ||
National Instruments | LabVIEW | 7.8 | HIGH | 0.015% | 2.350% | ||
National Instruments | LabVIEW | 7.8 | HIGH | 0.015% | 2.350% | ||
National Instruments | LabVIEW | 7.8 | HIGH | 0.015% | 2.350% | ||
Johnson Controls Inc. | PowerG | 7.6 | HIGH | N/A | N/A | ||
Johnson Controls Inc. | PowerG | 7.6 | HIGH | N/A | N/A | ||
Johnson Controls Inc. | PowerG | 7.6 | HIGH | N/A | N/A | ||
Rockwell Automation | Micro820 | 7.5 | HIGH | 0.055% | 17.529% | ||
Axis Communications | AXIS Camera Station Pro | 6.8 | MEDIUM | 0.026% | 6.495% | ||
Rockwell Automation | Micro820 | 6.5 | MEDIUM | 0.020% | 4.555% | ||
Inductive Automation | Ignition | 6.4 | MEDIUM | 0.013% | 1.564% | ||
Advantech | WebAccess/SCADA | 6.3 | MEDIUM | 0.026% | 6.603% | ||
Axis Communications | AXIS Camera Station Pro | 6.1 | MEDIUM | 0.034% | 9.780% | ||
Güralp Systems | Fortimus Series | 5.3 | MEDIUM | 0.091% | 26.321% | ||
Johnson Controls Inc. | PowerG | 5.3 | MEDIUM | N/A | N/A | ||
Axis Communications | AXIS Camera Station Pro | 5.2 | MEDIUM | 0.037% | 10.628% | ||
Mitsubishi Electric | GT Designer3 Version1 (GOT2000) | 5.1 | MEDIUM | 0.013% | 1.492% | ||
Advantech | WebAccess/SCADA | 4.3 | MEDIUM | 0.042% | 12.701% | ||
Advantech | WebAccess/SCADA | 4.3 | MEDIUM | 0.042% | 12.701% |
- 8 janvier 2026 : Définir sa stratégie de détection en environnement industriel, inscription lien
- 6 février 2026 : Construire le plan de protection de ses installations industrielles, inscription lien
- 5 mars 2026 : Sécuriser les échanges de fichiers entre les zones industrielles et IT, inscription lien
- 9 avril 2026 : NIS 2 pour l’industrie, inscription lien
- 7 mai 2026 : Segmenter les réseaux industriels, inscription lien
- 4 juin 2026 : Gérer les incidents cyber en environnement industriel, inscription lien
- 2 juillet 2026 : Gérer les vulnérabilités en environnement industriel, inscription lien
- 3 septembre 2026 : Mettre en place le plan de contrôle cyber de ses installations industriels, inscription lien
- 1 octobre 2026 : Sécuriser les accès à distance et de télémaintenance des actifs industriels, inscription lien
- 5 novembre 2026 : Protéger les endpoints dans les zones industrielles, inscription lien
- 3 décembre 2026 : Protéger les réseaux mobiles privés 5G, inscription lien

