{"uid":"cap_ah1Gt0WPzGhQKUtcQmY5X","slug":"ot-intel-api-onrender-com-557e989a","name":"CISA ICS-CERT Advisory Feed – Vendor/Sector Filter","description":"Live CISA ICS-CERT advisories filtered by vendor or sector. Pass ?vendor=siemens or ?sector=energy. Returns advisory IDs, CVSS scores, CVE lists, OT severity, and sector tags. Up to 25 results.","url":"https://ot-intel-api.onrender.com/ot/advisory","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{"limit":{"type":"string","description":"Max advisories to return (default 10, max 25)"},"sector":{"type":"string","description":"Sector e.g. energy, water, manufacturing, chemical, healthcare"},"vendor":{"type":"string","description":"Vendor name e.g. siemens, schneider, rockwell, ge, honeywell"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"count":2,"query":{"sector":null,"vendor":"siemens"},"freshness":"2025-05-22T10:00:00.000Z","advisories":[{"id":"ICSA-25-014-09","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-25-014-09","cves":["CVE-2024-23814"],"title":"Siemens SIMATIC S7-1500 TM MFP","cvss_max":9.8,"ot_layer":"field_device","severity":"critical","published":"Tue, 14 Jan 2025 00:00:00 +0000","ot_sectors":["manufacturing","energy"],"ot_severity":"CRITICAL","vendor_match":true}],"data_sources":["CISA-ICS-CERT"]}},"example":{"request":{"input":{"type":"http","method":"GET","queryParams":{"limit":"10","sector":"energy","vendor":"siemens"}}},"response":{"_type":"advisory-batch","count":10,"query":{"sector":"energy","vendor":"siemens"},"freshness":"2026-06-18T05:14:03.780Z","advisories":[{"id":"ICSA-26-167-02","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-02","cves":["CVE-2020-13573"],"title":"Rockwell Automation RSLinx","cvss_max":null,"ot_layer":"safety_system","severity":"low","published":"Tue, 16 Jun 26 12:00:00 +0000","ot_sectors":["energy","water","manufacturing"],"ot_severity":"UNKNOWN","vendor_match":false},{"id":"ICSA-26-162-02","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-162-02","cves":["CVE-2026-42947","CVE-2026-50108","CVE-2026-50101","CVE-2026-28742","CVE-2026-42932","CVE-2026-50244","CVE-2026-50099"],"title":"Naxclow IoT Platform","cvss_max":null,"ot_layer":"safety_system","severity":"low","published":"Thu, 11 Jun 26 12:00:00 +0000","ot_sectors":["energy","water","manufacturing","transportation"],"ot_severity":"UNKNOWN","vendor_match":false},{"id":"ICSA-26-160-01","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-160-01","cves":["CVE-2024-3596"],"title":"Schneider Electric Modicon Network Managed Switches","cvss_max":null,"ot_layer":"safety_system","severity":"low","published":"Tue, 09 Jun 26 12:00:00 +0000","ot_sectors":["energy","water","manufacturing","transportation"],"ot_severity":"UNKNOWN","vendor_match":false},{"id":"ICSA-26-160-03","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-160-03","cves":["CVE-2026-6866"],"title":"Schneider Electric EcoStruxure Panel Server","cvss_max":null,"ot_layer":"safety_system","severity":"low","published":"Tue, 09 Jun 26 12:00:00 +0000","ot_sectors":["energy","manufacturing"],"ot_severity":"UNKNOWN","vendor_match":false},{"id":"ICSA-26-160-02","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-160-02","cves":["CVE-2025-40946","CVE-2026-41125"],"title":"Siemens KACO Blueplanet Inverters","cvss_max":null,"ot_layer":"safety_system","severity":"low","published":"Tue, 09 Jun 26 12:00:00 +0000","ot_sectors":["energy","manufacturing"],"ot_severity":"UNKNOWN","vendor_match":true},{"id":"ICSA-26-155-04","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-04","cves":["CVE-2025-69421","CVE-2026-24515","CVE-2026-25210","CVE-2026-32776","CVE-2026-32777","CVE-2026-32778","CVE-2026-8479"],"title":"Hitachi Energy RTU500","cvss_max":null,"ot_layer":"safety_system","severity":"low","published":"Thu, 04 Jun 26 12:00:00 +0000","ot_sectors":["energy","water","manufacturing","chemical"],"ot_severity":"UNKNOWN","vendor_match":false},{"id":"ICSA-26-155-03","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-03","cves":["CVE-2025-11482"],"title":"B&amp;R PPT30 Operating System","cvss_max":null,"ot_layer":"safety_system","severity":"low","published":"Thu, 04 Jun 26 12:00:00 +0000","ot_sectors":["energy","water","manufacturing","chemical","transportation"],"ot_severity":"UNKNOWN","vendor_match":false},{"id":"ICSA-26-155-02","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-02","cves":["CVE-2024-8176","CVE-2025-59375"],"title":"Hitachi Energy ITT600 Explorer","cvss_max":null,"ot_layer":"safety_system","severity":"low","published":"Thu, 04 Jun 26 12:00:00 +0000","ot_sectors":["energy","manufacturing","chemical"],"ot_severity":"UNKNOWN","vendor_match":false},{"id":"ICSA-26-155-05","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-05","cves":["CVE-2026-7310"],"title":"Hitachi Energy MACH HiDraw","cvss_max":null,"ot_layer":"safety_system","severity":"low","published":"Thu, 04 Jun 26 12:00:00 +0000","ot_sectors":["energy","manufacturing","chemical","transportation"],"ot_severity":"UNKNOWN","vendor_match":false},{"id":"ICSA-26-148-07","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-07","cves":["CVE-2026-6332"],"title":"Schneider Electric EcoStruxure Machine Expert HVAC","cvss_max":null,"ot_layer":"safety_system","severity":"low","published":"Thu, 28 May 26 12:00:00 +0000","ot_sectors":["energy","water","manufacturing","chemical"],"ot_severity":"UNKNOWN","vendor_match":false}],"data_sources":["CISA-ICS-CERT","OT-Intel-DB"],"related_intel":"[2024-04-24] [claroty] Exploiting a Classic Deserialization Vulnerability in Siemens SIMATIC Energy Manager | CVEs: CVE-2022-23450 | Workarounds: [\"Update Siemens SIMATIC Energy Manager to V7.3 Update 1 or later\",\"Review Siemens security advisory for additional information\",\"Restrict network access to TCP/4444 to trusted clients only\"] | Team82 disclosed a deserialization vulnerability (CVE-2022-23450, CVSS 10.0) in Siemens SIMATIC Energy Manager (EnMPro) that allows unauthenticated remote code execution before authentication. The flaw exists in the proprietary communication protocol on TCP/4444 and was patched in V7.3 Update 1.\n[2022-10-11] [claroty] The Race to Native Code Execution in PLCs: Using RCE to Uncover Siemens SIMATIC S7 | CVEs: CVE-2020-15782,CVE-2022-38465 | Workarounds: [\"Update SIMATIC S7-1200 and S7-1500 PLCs to latest firmware versions.\",\"Update TIA Portal to version V17 or later.\",\"Implement TLS-protected PG/PC and HMI communication as provided in TIA Portal V17.\",\"Use individual passwords per device as part of the new PKI system.\"] | Team82 developed a method to extract hardcoded global private cryptographic keys from Siemens SIMATIC S7-1200/1500 PLCs and TIA Portal. Using a prior RCE vulnerability (CVE-2020-15782), attackers can recover the key (CVE-2022-38465, CVSS 9.3) to bypass all four access level protections, perform full upload/download, man-in-the-middle attacks, and decrypt OMS+ traffic. Siemens released updated PLC firmware and TIA Portal v17 with a new PKI system to address the issue.\n[2022-06-16] [claroty] Securing Network Management Systems (Part 3): Siemens SINEC NMS | CVEs: CVE-2021-33722,CVE-2021-33723 | Workarounds: [\"Update SINEC NMS to V1.0 SP2 Update 1 or later version\",\"Review Siemens advisory for patch details\"] | Team82 disclosed 15 vulnerabilities in Siemens SINEC NMS, including two chained vulnerabilities (CVE-2021-33723 and CVE-2021-33722) that allow privilege escalation and remote code execution. All versions before V1.0 SP2 Update 1 are affected, and Siemens advises updating to the latest version.\n[2021-05-28] [claroty] The Race to Native Code Execution in PLCs | CVEs: CVE-2020-15782 | Workarounds: [\"Update SIMATIC S7-1200 and S7-1500 CPU firmware to patched versions\",\"Enable password protection and access protection on PLCs\",\"Implement TLS communication using individual certificates (TIA Portal V17+)\",\"Restrict network access to PLCs\"] | Claroty discovered CVE-2020-15782, a severe memory protection bypass vulnerability in Siemens SIMATIC S7-1200 and S7-1500 PLCs. An attacker with network access and download rights could remotely bypass the PLC sandbox to gain read-write access to protected memory and execute native code. Siemens released firmware updates to address the vulnerability."}},"exampleRequest":{"limit":"10","sector":"energy","vendor":"siemens"},"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"settled","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_fpm40amUXHgezE2EAVPZz","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns the latest CISA ICS-CERT security advisories filtered by vendor and/or industrial sector, including CVE lists, CVSS scores, and severity ratings.","exampleAgentPrompt":"Pull the latest CISA ICS-CERT advisories for Siemens in the energy sector — give me up to 15 results with their CVE IDs, CVSS scores, and severity.","exampleUseCases":null,"resultDescription":"Returns up to 25 (configurable via limit=) CISA ICS advisory records parsed from the live RSS feed, each containing advisory ID, title, CVE list, CVSS scores, severity level, and vendor match confirmation. Filtered by the specified vendor (e.g. siemens) and/or sector (e.g. energy).","failureModes":["No matching advisories found for the given vendor/sector combination — returns empty result set","CISA RSS feed temporarily unavailable — upstream fetch failure","Invalid or unrecognized vendor/sector string — may return zero results without error","Rate limiting or payment failure — 402 response if payment not included","Render.com cold start latency on first request causing timeout"],"whenToPreferThis":"Use this endpoint when you need live, up-to-date CISA ICS-CERT advisory data for a specific vendor (e.g. Siemens, Rockwell, Honeywell) or industrial sector (e.g. energy, water, manufacturing). Prefer it over static CVE databases when OT/ICS-specific advisories and CVSS context from CISA are required, especially for compliance or incident response triage in critical infrastructure environments.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T12:33:23.124Z","isFirstParty":false}