PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-1775 Labkotec CVE debrief

CISA published advisory ICSA-26-062-05 on 2026-03-03 for CVE-2026-1775 affecting Labkotec LID-3300IP ice detector software. The issue is network-reachable, requires no authentication, and can let an attacker alter device parameters and run operational commands after sending specially crafted packets. The advisory rates the flaw Critical (CVSS 9.4). Labkotec’s stated path forward is to move affected deployments to the LID-3300IP Type 2 model and install firmware V2.40, with additional network hardening and access restrictions for any remaining exposure.

Vendor
Labkotec
Product
LID-3300IP
CVSS
CRITICAL 9.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-03
Original CVE updated
2026-03-03
Advisory published
2026-03-03
Advisory updated
2026-03-03

Who should care

OT/ICS operators using Labkotec LID-3300IP devices, facility and safety engineering teams, industrial network defenders, and administrators responsible for segmented plant or building automation networks.

Technical summary

The advisory describes an unauthenticated remote attack against Labkotec LID-3300IP ice detector software. According to the CISA CSAF, specially crafted packets can be used to alter device parameters and execute operational commands. The supplied CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H, reflecting low attack complexity, no privileges, no user interaction, and high integrity/availability impact. Labkotec also notes that the original LID-3300IP cannot implement secure and encrypted network traffic, which is why the vendor recommends replacement with the LID-3300IP Type 2 model and firmware V2.40.

Defensive priority

Immediate

Recommended defensive actions

  • Inventory all Labkotec LID-3300IP deployments and verify the device type and software version in the web interface.
  • Upgrade affected units to the LID-3300IP Type 2 model and install firmware V2.40, per Labkotec guidance.
  • If the device remains in service, place it on a secure internal network with access limited to authorized systems and users only.
  • Do not expose the device directly to the public Internet; apply firewall rules, protocol restrictions, and network segmentation.
  • Enable HTTPS for management and network traffic where supported, and use the vendor’s recommended ICS hardening practices.
  • Change default credentials, review access permissions, and monitor for unexpected parameter changes or operational commands.

Evidence notes

This debrief is grounded in the supplied CISA CSAF advisory JSON for ICSA-26-062-05 / CVE-2026-1775 and its linked official references, including the CISA advisory page and CVE record. Product scope, impact language, CVSS data, and remediation text were taken from the advisory metadata and remediation entries. No exploit code, reproduction steps, or unsupported claims were added.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-1775 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-1775

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-1775 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-1775

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-062-05.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-062-05

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.