> For the complete documentation index, see [llms.txt](https://breachtrace.gitbook.io/vulnkeeper/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://breachtrace.gitbook.io/vulnkeeper/chapter-d/11-11-ics-ot-iot-embedded-and-medical-device-sources.md).

# 11. ICS, OT, IoT, embedded & medical-device sources

## 11.1 CISA ICS / medical

<table><thead><tr><th width="92.30859375" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>CISA ICS Advisories</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.cisa.gov/news-events/ics-advisories">www.cisa.gov/news-events/ics-advisories</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Industrial Control System advisories.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Critical for OT/ICS environments where patching constraints differ from IT.</td></tr><tr><td align="right">2</td><td><strong>CISA ICS Medical Advisories</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.cisa.gov/news-events/ics-medical-advisories">www.cisa.gov/news-events/ics-medical-advisories</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Medical device security advisories.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Impact includes patient safety, regulatory, &#x26; operational risk.</td></tr><tr><td align="right">3</td><td><strong>CISA cybersecurity advisories</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.cisa.gov/cybersecurity-advisories">www.cisa.gov/cybersecurity-advisories</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> CISA cybersecurity advisory hub.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Broader than ICS; use for campaigns &#x26; emergent threats.</td></tr><tr><td align="right">4</td><td><strong>ICS-CERT advisories archive</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.cisa.gov/news-events/ics-advisories">www.cisa.gov/news-events/ics-advisories</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> ICS-CERT advisory archive path.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Same URL as ICS advisories, preserved for historical naming.</td></tr><tr><td align="right">5</td><td><strong>CISA ICS recommended practices</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.cisa.gov/resources-tools/resources/ics-recommended-practices">www.cisa.gov/resources-tools/resources/ics-recommended-practices</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Recommended practices for ICS security.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for mitigation where patching is delayed or impossible.</td></tr></tbody></table>

## 11.2 OT / ICS vendor advisories

<table><thead><tr><th width="93.71875" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>Siemens ProductCERT</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://cert-portal.siemens.com/productcert/">cert-portal.siemens.com/productcert</a><br><br><strong><code>Access / Cost</code>:</strong> Free public advisories; some support downloads may require entitlement</td><td><strong><code>Relevance</code>:</strong> Siemens product security advisories.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Critical for industrial environments.</td></tr><tr><td align="right">2</td><td><strong>Schneider Electric Security Notifications</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.se.com/ww/en/work/support/cybersecurity/security-notifications.jsp">www.se.com/ww/en/work/support/cybersecurity/security- notifications.jsp</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Schneider Electric security notifications.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Product model &#x26; firmware version matter heavily.</td></tr><tr><td align="right">3</td><td><strong>Rockwell Automation Security Advisories</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.rockwellautomation.com/en-us/support/product/product-security-advisories.html">www.rockwellautomation.com/en-us/support/product/product- security-advisories.html</a><br><br><strong><code>Access / Cost</code>:</strong> Free public listing; support downloads may require entitlement</td><td><strong><code>Relevance</code>:</strong> Rockwell Automation product advisories.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Operational constraints may affect remediation.</td></tr><tr><td align="right">4</td><td><strong>Honeywell Product Security</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.honeywell.com/us/en/product-security">www.honeywell.com/us/en/product-security</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Honeywell product security advisories.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for OT product risk.</td></tr><tr><td align="right">5</td><td><strong>Philips Product Security</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.philips.com/a-w/security/security-advisories.html">www.philips.com/a-w/security/security-advisories.html</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Philips medical/product security advisories.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Patient safety &#x26; regulatory implications may affect severity assessment.</td></tr><tr><td align="right">6</td><td><strong>GE Vernova Product Security</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.gevernova.com/product-security">www.gevernova.com/product-security</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> GE Vernova product security.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Important for energy/industrial systems.</td></tr><tr><td align="right">7</td><td><strong>ABB Cyber Security Alerts</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://global.abb/group/en/technology/cyber-security/alerts-and-notifications">global.abb/group/en/technology/cyber-security/alerts-and-notifications</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> ABB cyber security alerts &#x26; notifications.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Product-specific affectedness matters.</td></tr><tr><td align="right">8</td><td><strong>Yokogawa Security Advisories</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.yokogawa.com/library/resources/white-papers/yokogawa-security-advisory-report-list/">www.yokogawa.com/library/resources/white-papers/yokogawa-security- advisory-report-list</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Yokogawa advisory report list.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for OT control systems.</td></tr><tr><td align="right">9</td><td><strong>Mitsubishi Electric PSIRT</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.mitsubishielectric.com/en/psirt/vulnerability/">www.mitsubishielectric.com/en/psirt/vulnerability</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Mitsubishi Electric vulnerability advisories.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Important for industrial equipment &#x26; automation.</td></tr><tr><td align="right">10</td><td><strong>Johnson Controls Product Security Advisories</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.johnsoncontrols.com/cyber-solutions/security-advisories">www.johnsoncontrols.com/cyber-solutions/security-advisories</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Johnson Controls security advisories.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Relevant to building management &#x26; OT environments.</td></tr></tbody></table>

## 11.3 IoT / embedded

<table><thead><tr><th width="95.84375" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>CERT/CC Vulnerability Notes</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.kb.cert.org/vuls/">www.kb.cert.org/vuls</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Coordinated disclosure notes, often with embedded/IoT affected vendors.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful when many vendors share a vulnerable component.</td></tr><tr><td align="right">2</td><td><strong>IoT Security Foundation</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.iotsecurityfoundation.org/">www.iotsecurityfoundation.org</a><br><br><strong><code>Access / Cost</code>:</strong> Free public resources; membership options may exist</td><td><strong><code>Relevance</code>:</strong> IoT security guidance &#x26; resources.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Not a vulnerability feed, but useful for control mapping.</td></tr><tr><td align="right">3</td><td><strong>Firmware Analysis and Comparison Tool - FACT</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/fkie-cad/FACT_core">github.com/fkie-cad/FACT_core</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Firmware analysis platform.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for extracting components &#x26; embedded vuln detection.</td></tr><tr><td align="right">4</td><td><strong>EMBA firmware analyzer</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/e-m-b-a/emba">github.com/e-m-b-a/emba</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Firmware analyzer for embedded Linux/IoT.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for SBOM-like extraction &#x26; vulnerability assessment.</td></tr><tr><td align="right">5</td><td><strong>Binwalk</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/ReFirmLabs/binwalk">github.com/ReFirmLabs/binwalk</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Firmware extraction &#x26; analysis tool.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful precursor for embedded component discovery.</td></tr></tbody></table>

## Discussion

This chapter section keeps the latest table structure, source titles, access/cost fields, relevance notes, & operational notes from the source inventory. Review the table entries as ingestion candidates, then validate source freshness, licensing, authentication requirements, & link-check behavior before production use.

***

#### [Back to Index](/vulnkeeper/index.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://breachtrace.gitbook.io/vulnkeeper/chapter-d/11-11-ics-ot-iot-embedded-and-medical-device-sources.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
