WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts ICS/OT Vulnerability – Vulnerability Identified in Water Tank Management System may not be Patched
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

ICS/OT Vulnerability – Vulnerability Identified in Water Tank Management System may not be Patched

Author: Jennifer Walker

Created: Tuesday, September 20, 2022 - 17:57

Categories: OT-ICS Security, Security Preparedness

On September 13, 2022, CISA posted an Industrial Control System Advisory (ICSA-22-256-04) regarding Kingspan TMS300 CS water tank management system – provided in WaterISAC’s CISA ICS Vulnerability Advisories and Alerts, Updates, and Bulletins – September 13, 2022. The vulnerability is considered critical and reportedly impacts all versions of Kingspan TMS300 CS. It can be exploited remotely and requires low complexity to exploit. Specifically, a researcher reports that the product is affected by a critical vulnerability that allows an attacker to access the device to view or modify the device’s settings without authenticating.

According to CISA, Kingspan has not responded to requests to mitigate (patch) the vulnerability. In light of a patch not being available at this time, any utility using the specified system are encouraged to contact Kingspan customer support for additional information, assess the vulnerability against your environment, and apply appropriate compensating controls to protect the vulnerable system. CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Specifically, users should:

  • Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the Internet.
  • Locate control system networks and remote devices behind firewalls and isolate them from business networks.
  • When remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as its connected devices.

For more information, visit SecurityWeek and CISA’s ICS Advisories.

Related Resources

(TLP:CLEAR) CISA and Partners Urge Hardening Automatic Tank Gauge Systems

Jun 4, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

(TLP:CLEAR) Privilege Escalation Vulnerabilities Affect Phoenix Contact PLCnext Controllers

Jun 4, 2026 in Cybersecurity, OT-ICS Security, Security Preparedness

(TLP:CLEAR) CISA ICS Advisories, Additional Alerts, Updates, and Bulletins – June 4, 2026

Jun 4, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar