Description
A low-privileged remote attacker can send Modbus packets to manipulate register values that are inputs to the odorant injection logic such that too much or too little odorant is injected into a gas line.
Problem types
Product status
v1.0 (custom) before v6.0
v4.0 (custom) before v6.0
v13.0 (custom) before v20.0
v18.4 (custom) before v20.0
Credits
An anonymous researcher reported this vulnerability to CISA.
References
lincenergysystems-my.sharepoint.com/...YBFUb0lmr7ak?e=JLeADm
www.cisa.gov/news-events/ics-advisories/icsa-26-099-02
github.com/...p/csaf_files/OT/white/2026/icsa-26-099-02.json