PatchSiren cyber security CVE debrief
CVE-2026-1775 Labkotec CVE debrief
CISA published advisory ICSA-26-062-05 on 2026-03-03 for CVE-2026-1775 affecting Labkotec LID-3300IP ice detector software. The issue is network-reachable, requires no authentication, and can let an attacker alter device parameters and run operational commands after sending specially crafted packets. The advisory rates the flaw Critical (CVSS 9.4). Labkotec’s stated path forward is to move affected deployments to the LID-3300IP Type 2 model and install firmware V2.40, with additional network hardening and access restrictions for any remaining exposure.
- Vendor
- Labkotec
- Product
- LID-3300IP
- CVSS
- CRITICAL 9.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-03
- Original CVE updated
- 2026-03-03
- Advisory published
- 2026-03-03
- Advisory updated
- 2026-03-03
Who should care
OT/ICS operators using Labkotec LID-3300IP devices, facility and safety engineering teams, industrial network defenders, and administrators responsible for segmented plant or building automation networks.
Technical summary
The advisory describes an unauthenticated remote attack against Labkotec LID-3300IP ice detector software. According to the CISA CSAF, specially crafted packets can be used to alter device parameters and execute operational commands. The supplied CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H, reflecting low attack complexity, no privileges, no user interaction, and high integrity/availability impact. Labkotec also notes that the original LID-3300IP cannot implement secure and encrypted network traffic, which is why the vendor recommends replacement with the LID-3300IP Type 2 model and firmware V2.40.
Defensive priority
Immediate
Recommended defensive actions
- Inventory all Labkotec LID-3300IP deployments and verify the device type and software version in the web interface.
- Upgrade affected units to the LID-3300IP Type 2 model and install firmware V2.40, per Labkotec guidance.
- If the device remains in service, place it on a secure internal network with access limited to authorized systems and users only.
- Do not expose the device directly to the public Internet; apply firewall rules, protocol restrictions, and network segmentation.
- Enable HTTPS for management and network traffic where supported, and use the vendor’s recommended ICS hardening practices.
- Change default credentials, review access permissions, and monitor for unexpected parameter changes or operational commands.
Evidence notes
This debrief is grounded in the supplied CISA CSAF advisory JSON for ICSA-26-062-05 / CVE-2026-1775 and its linked official references, including the CISA advisory page and CVE record. Product scope, impact language, CVSS data, and remediation text were taken from the advisory metadata and remediation entries. No exploit code, reproduction steps, or unsupported claims were added.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-1775 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-1775
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-1775 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-1775
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-062-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-062-05
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.