CISA released a set of six Industrial Control Systems (ICS) advisories, highlighting multiple vulnerabilities in widely used industrial and surveillance products. Among these, the Automated Logic WebCTRL Premium Server and Carrier i-Vu platforms were found to be susceptible to open redirect and cross-site scripting vulnerabilities, which could allow remote attackers to redirect users to malicious websites or execute unauthorized scripts. The open redirect issue, tracked as CVE-2024-8527, affects several versions of both Automated Logic WebCTRL and Carrier i-Vu, with a high CVSS score indicating significant risk if exploited.
Additionally, CISA detailed critical vulnerabilities in ICAM365 CCTV camera models P201 and QC021, specifically missing authentication for critical functions. These flaws could enable attackers to gain unauthorized access to camera video streams and configuration data via unauthenticated ONVIF and RTSP services. Both advisories urge administrators to review technical details and apply recommended mitigations to reduce the risk of exploitation in operational environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CISA announced the release of six Industrial Control Systems advisories covering products from multiple vendors, including Automated Logic. The agency urged users and administrators to review the advisories for technical details and recommended mitigations.
CISA published ICS Advisory ICSA-25-324-01 covering CVE-2024-8527 and CVE-2024-8528 in Automated Logic WebCTRL Premium Server and related products. The advisory said WebCTRL 9.0 remediates the issues, noted some older versions are out of support, and stated there was no known public exploitation at publication time.
Carrier published CVE-2024-8527 for an open redirect flaw in Automated Logic WebCTRL and Carrier i-Vu products, affecting multiple versions including 6.0 through 9.0. The vendor recommended updating affected software and applying available patches or remediation guidance.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.