Know your OT exposure.
Search enriched CISA ICS advisory data by vendor name — partial matches work, so “honey” finds Honeywell. CVEs, CVSS, severity and known-exploited flags for industrial control systems.
Under this leaf.
Why run this scan?
Industrial systems fail differently. A vulnerable PLC or building-management controller isn't just a data risk — it's pumps, valves, power and safety systems. Knowing your vendors' advisory history is step one of OT security.
The data comes from the ICS Advisory Project's enriched CISA dataset — search is partial-match, so you can explore a vendor's full advisory record without knowing exact product names.
Frequently asked questions
What are ICS advisories?
They are security advisories published by CISA for industrial control systems (ICS) and operational technology (OT) — the hardware and software running factories, utilities and building systems.
What does the KEV flag mean?
KEV stands for Known Exploited Vulnerabilities — a CISA-maintained catalog of flaws confirmed to be exploited in the wild. A KEV-flagged advisory should be patched with top priority.
Can I search by product instead of vendor?
This page searches by vendor with partial matching. The underlying dataset also supports product search — that filter is coming to this tool soon.