Skip to content

OMICRON vulnerabilities

3 CVEs tracked

OMICRON appears in our reports in the context of its StationGuard and StationScout products used in electrical substations. The key events are critical cryptographic timing side-channel vulnerabilities in the backend authentication mechanism (CVE-2026-16315, CVE-2026-16731) and an improper input validation flaw in IEC 61850 Sampled Values processing leading to process termination (CVE-2026-16316). Defenders should monitor for suspicious authentication attempts from the WAN, upgrade StationGuard to version 4.10 and StationScout to version 3.05, and strengthen process termination monitoring against specially crafted SV frames.

Azərbaycanca: OMICRON hesabatlarımızda elektrik yarımstansiyaları üçün istifadə olunan StationGuard və StationScout məhsulları ilə bağlı müşahidə edilir. Əsas hadisələr backend autentifikasiya mexanizmində ciddi kriptoqrafik timing side-channel zəiflikləri (CVE-2026-16315, CVE-2026-16731) və IEC 61850 Sampled Values emalında xidmət dayanmasına səbəb olan düzgün olmayan giriş yoxlamasıdır (CVE-2026-16316). Müdafiəçilər XİN-dən gələn şübhəli autentifikasiya cəhdlərini izləməli, StationGuard-ı 4.10 və StationScout-u 3.05 versiyalarına yeniləməli, həmçinin xüsusi hazırlanmış SV çərçivələrinə qarşı prosesin dayanması (termination) monitorinqini gücləndirməlidirlər.

This vendor's CVEs3

This hub is built from skopnix's own reporting on OMICRON: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.