Showing posts sorted by relevance for query CoDeSys. Sort by date Show all posts
Showing posts sorted by relevance for query CoDeSys. Sort by date Show all posts

Saturday, October 8, 2022

Review – Public ICS Disclosure – Week of 10-1-22

This week we have six vendor disclosures from Bentley (3), Hitachi, strongSwan, VMware. We also have seven vendor updates from CODESYS. Finally, we have two researcher reports with exploits for products from ZKSecurity.

Bentley Advisory #1 - Bentley published an advisory that describes an out-of-bounds read vulnerability in their MicroStation and MicroStation-based applications.

Bentley Advisory #2 - Bentley published an advisory that describes two vulnerabilities in their MicroStation and MicroStation-based applications.

Bentley Advisory #3 - Bentley published an advisory that describes two vulnerabilities in their MicroStation and MicroStation-based applications.

Hitachi Advisory - Hitachi published an advisory that discusses 39 vulnerabilities in their Disk Array Systems.

StrongSwan Advisory - StrongSwan published an advisory describing a trust chain vulnerability in their strongSwan product.

VMware Advisory - VMware published an advisory that describes two vulnerabilities in their VMware ESXi and vCenter Server products.

CODESYS Update #1 - CODESYS published an update for their CODESYS V3 Visualization advisory that was originally published on June 3rd, 2022.

CODESYS Update #2 - CODESYS published an update for their CODESYS V2 password transport advisory that was originally published on June 9th, 2022 and most recently updated on June 23rd, 2022.

CODESYS Update #3 - CODESYS published an update for their CODESYS OPC DA Server V3 advisory that was originally published on May 19th, 2022 and most recently updated on June 3rd, 2022.

CODESYS Update #4 - CODESYS published an update for their CODESYS communication server advisory that was originally published on May 19th, and most recently updated on June 3rd, 2022.

CODESYS Update #5 - CODESYS published an update for their CODESYS Control V3 configuration file access advisory that was originally published on March 24th, 2022, and most recently updated on June 30th, 2022.

CODESYS Update #6 - CODESYS published an update for their CODESYS Git advisory that was originally published on November 30th, 2021.

CODESYS Update #7 - CODESYS published an update for their CODESYS V2 web server that was originally published on October 25, 2021 and most recently updated on November 8th, 2022.

ZKSecurity Report #1 - Stolabs published a report that describes an SQL injection vulnerability in the ZKSecurity Bio product.

ZKSecurity Report #2 - Caio B published a report that describes an access control vulnerability in the ZKSecurity Bio product.

 

For more details about these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-10-0f6 - subscription required.


Saturday, April 9, 2022

Review - Public ICS Disclosures – Week of 4-2-22 – Part 1

A busy week with lots of SpringShell and DirtyPipe disclosures, so there will be two parts this week. In this part we have 24 vendor disclosures from Aruba, Barco, Bentley (8), Braun, Broadcom (3), Carrier, Weidmueller, WAGO, CODESYS (6), and FANUC.

Aruba Advisory - Aruba published an advisory discussing the SpringShell vulnerabilities.

Barco Advisory - Barco published an advisory discussing the DirtyPipe vulnerability.

Bentley Advisory #1 - Bentley published an advisory describing two use after free vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #2 - Bentley published an advisory describing three stack-based buffer overflow vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #3 - Bentley published an advisory describing an out-of-bounds write vulnerability in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #4 - Bentley published an advisory describing eleven file parsing vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #5 - Bentley published an advisory describing two out-of-bounds read vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #6 - Bentley published an advisory describing five out-of-bounds vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #7 - Bentley published an advisory describing four out-of-bounds read vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #8 - Bentley published an advisory describing two unitialized variable vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Braun Advisory - Braun published an advisory discussing the Infusion Pump Vulnerabilities article by Palo Alto Networks.

Broadcom Advisory #1 - Broadcom published an advisory discussing one of the SpringShell vulnerabilities.

Broadcom Advisory #2 - Broadcom published an advisory describing the other SpringShell vulnerability.

Broadcom Advisory #3 - Broadcom published an advisory discussing an older Spring Framework vulnerability reanimated by the SpringShell vulnerability.

Carrier Advisory - Carrier published an advisory discussing the SpringShell vulnerabilities.

Weidmueller Advisory - CERT-VDE published an advisory discussing nine vulnerabilities in two products using Modbus TCP/RTU Gateways.

WAGO Advisory - CERT-VDE published an advisory discussing the DirtyPipe vulnerability in several WAGO products.

CODESYS Advisory #1 - CODESYS published an advisory describing an exposure of resource to wrong sphere vulnerability in the CODESYS Control V3 products.

CODESYS Advisory #2 - CODESYS published an advisory describing an incorrect permission assignment for a critical resource vulnerability in the CODESYS SysDrv3S.sys driver.

CODESYS Advisory #3 - CODESYS published an advisory describing a small space of random values vulnerability in CODESYS V3 products using the CODESYS communication protocol.

CODESYS Advisory #4 - CODESYS published an advisory describing an incorrect user management vulnerability in the  CODESYS Control V3 online user management applications.

CODESYS Advisory #5 - CODESYS published an advisory describing two vulnerabilities in CODESYS V3 products containing a CODESYS communication server.

CODESYS Advisory #6 - CODESYS published an advisory describing a buffer over read vulnerability in the CODESYS V3 web server.

 

For more details on these disclosures, including links to 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/22-part-1 - subscription required.

Saturday, July 2, 2022

Review – Public ICS Disclosures – Week of 6-25-22 – Part 2

For Part 2 we have ten vendor updates for CODESYS (6), Dell, HP (3), and HPE. We have six researcher reports for products from Robustel (4), ExpressLRS, and Carel.

CODESYS Update #1 - CODESYS published an update for their Control V3 configuration file advisory that was that was originally published on March 24th, 2022, and most recently updated on June 10th, 2022.

CODESYS Update #2 - CODESYS published an update for their CODESYS communication protocol advisory that was originally published on March 24th, 2022 and most recently updated on April 6th, 2022

CODESYS Update #3 - CODESYS published an update for their Control V3 online user management advisory that was originally published on March 24th, 2022 and most recently updated on April 6th, 2022.

CODESYS Update #4 - CODESYS published an update for their V3 products containing a CODESYS communication server that was originally published on March 24th, 2022 and most recently updated on April 6th, 2022.

CODESYS Update #5 - CODESYS published an update for their V3 web server advisory that was originally published on March 24th, 2022 and most recently updated on April 6th, 2022.

CODESYS Update #6 - CODESYS published an update for their V3 products containing a CODESYS communication server advisory that was originally published on May 19th, 2022 and most recently updated on May 30th, 2022.

Dell Update - Dell published an update for their Wyse ThinOS advisory that was originally published on July 21st, 2021.

HP Update #1 - HP published an update for their Intel® Boot Guard and Intel® TXT Security advisory that was originally published on May 10th, 2022.

HP Update #2 - HP published an update for their Intel 2022.1 IPU BIOS advisory that was originally published on July 21st, 2021.

HP Update #3 - HP published an update for their AMD Client UEFI Firmware advisory that was originally published on July 21st, 2021.

HPE Update - HPE published an update for their HP-UX Using OpenSSL advisory that was originally published on May 19th, 2022.

Robustel Reports – Cisco Talos published four reports for ten vulnerabilities in the Robustel R1510 web server.

ExpressLRS Report - NCC Group published a report describing a discoverable binding phrase for radio linkages in the ExpressLRS radio control link.

Carel Report - Zero Science published a report describing a directory traversal vulnerability in the Carel pCOWeb HVAC BACnet Gateway.

 

For more details on these updates and reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-2ec  - subscription required.

Saturday, November 5, 2022

Review – Public ICS Disclosure – Week of 10-29-22

This week we have twelve vendor disclosures about the recent OpenSSL vulnerabilities from Aruba Networks, Broadcom, Keysight, Milestone, Moxa, Palo Alto Networks, Roche, Rockwell Automation, Software Toolbox, Watchguard, and Wind River.   We also have twelve other vendor disclosures from Belden, Hitachi, Insyde (6), Sick, and Tanzu (3). There are six vendor updates for products from CODESYS. Finally, we have two exploits for products from FLIR, and Veeder-Root.

OpenSSL Vulnerabilities Disclosures

Aruba reports that none of their products are affected by the vulnerabilities.

Broadcom provides a list of unaffected products.

Dell reports that they are reviewing their products to see which may be affected by the vulnerabilities.

Keysight reports that none of their products are affected by the vulnerabilities.

Milestone reports limited impact in their XProtect VMS 2022 R3. An update is pending.

Moxa reports that none of their products are affected by the vulnerabilities.

Palo Alto Networks reports that earlier versions of Cortex XDR Broker VM contain the affected OpenSSL version but are not affected by the vulnerabilities. Other products are not affected.

Roche reports that none of their products are affected by the vulnerabilities.

Rockwell reports that they are reviewing their products to see which may be affected by the vulnerabilities.

Software Toolbox reports that none of their products are affected by the vulnerabilities.

Watchguard provides a list of unaffected products.

Wind River provides a list of affected products. Fixes are pending.

Other Vendor Disclosures

Belden Advisory - Belden published an advisory that describes a command insertion vulnerability in their (Hirschmann) Industrial HiVision product.

Hitachi Advisory - Hitachi published an advisory that discusses 60 vulnerabilities in their Disk Array Systems. These are third-party (Microsoft) vulnerabilities

Insyde Advisory #1 - Insyde published an advisory that discusses an observable discrepancy vulnerability in their InsydeH2O product.

Insyde Advisory #2 - Insyde published an advisory that discusses two vulnerabilities in their InsydeH2O product.

Insyde Advisory #3 - Insyde published an advisory that discusses an out-of-bounds read vulnerability in their InsydeH2O product.

Insyde Advisory #4 - Insyde published an advisory that describes a stack-based buffer overflow vulnerability in their InsydeH2O product.

Insyde Advisory #5 - Insyde published an advisory that describes a stack-based buffer overflow in their InsydeH2O product.

Insyde Advisory #6 - Insyde published an advisory that describes a stack-based buffer overflow in their InsydeH2O product.

Sick Advisory - Sick reports a denial of service vulnerability in their FlexiCompact product.

NOTE: The Sick PSIRT web page continues to have problems with inoperable links.

Tanzu Advisory #1 - Tanzu published an advisory that describes a privilege escalation vulnerability in their pring-security-oauth2-client.

Tanzu Advisory #2 - Tanzu published an advisory that describes an authorization bypass vulnerability in their Spring Security product.

Tanzu Advisory #3 - Tanzu published an advisory that describes a remote code execution vulnerability in their Spring Tools 4 for Eclipse product.

CODESYS Update #1 - CODESYS published an update for their CODESYS communication server advisory that was originally published on May 19th, and most recently updated on October 6th, 2022.

CODESYS Update #2 - CODESYS published an update for their V3 web server advisory that was originally published on March 24th, 2022 and most recently updated on June 30th, 2022.

CODESYS Update #3 - CODESYS published an update for their a CODESYS communication server advisory that was originally published on March 24th, 2022 and most recently updated on June 30th, 2022.

CODESYS Update #4 - CODESYS published an update for their Control V3 online user management advisory that was originally published on March 24th, 2022 and most recently updated on June 30th 2022.

CODESYS Update #5 - CODESYS published an update for their V3 products using the CODESYS communication protocol advisory that was originally published on March 24th, 2022 and most recently updated on June 30th, 2022.

CODESYS Update #6 - CODESYS published an update for their Control V3 configuration file advisory that was originally published on March 24th, 2022, and most recently updated on October 6th, 2022.

Exploits

FLIR Exploit - Samy Younsi published a Metasploit module for a command injection vulnerability in the FLIR AX8 infrared monitoring camera.

Veeder-Root Exploit - Rose Security published an exploit for a remote configuration disclosure vulnerability in the Veeder-Rood (and probably other vendor) automated tank gauges.

 

For more details about these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-10-c49 - subscription required.

 

Saturday, May 1, 2021

Public ICS Disclosures – Week of 4-24-21

This week we three vendor NAME:WRECK disclosures from Boston Scientific, Braun, and Rockwell. We also have 14 vendor disclosures from Beckhoff, Bosch (2), B&R Industrial Automation, MB connect, CODESYS (5), Moxa, ODA, and Texas Instruments (2). We have five researcher reports for products from Advantech (4) and Siemens. Finally, we have exploits for products from OpenPLC and VMWare.

NAME:WRECK Advisories

Boston Scientific published an advisory discussing the NAME:WRECK vulnerabilities, announcing that they are investigating to see if any of their products are affected.

Braun published an advisory discussing the NAME:WRECK vulnerabilities, announcing that none of their ‘connected devices’ are affected.

Rockwell published an advisory discussing the NAME:WRECK vulnerabilities, providing a list of affected products and fixed versions.

Beckhoff Advisory

Beckhoff published an advisory describing an improper input validation vulnerability in their TwinCAT OPC UA Server and IPC Diagnostics UA Server. The vulnerability was reported by Industrial Control Security Laboratory of QI-ANXIN Technology Group. Beckhoff has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Bosch Advisories

Bosch published an advisory describing seven vulnerabilities in their ctrlX CORE - IDE App. These are third-party (OpenSSL and Python) vulnerabilities. The next version of the product will mitigate the vulnerabilities.

The seven reported vulnerabilities are:

• Improper encoding or escaping of output - CVE-2020-26116 (exploit),

• Inadequate information (NIST ?) - CVE-2020-27619,

• HTTP request smuggling - CVE-2021-23336 (exploit),

• Integer overflow or wraparound - CVE-2021-23840, CVE-2021-23841,

• Classic buffer overflow - CVE-2021-3177 (exploit), and

• NULL pointer dereference - CVE-2021-3449

Bosch published an advisory describing an FTP backdoor in their Rexroth Fieldbus Couplers. Bosch provides generic workarounds.

B&R Advisory

B&R published an advisory describing an uncontrolled resource consumption vulnerability in their  I/O system and HMI components. This is a third-party (Siemens) vulnerability. B&R provides generic workarounds.

MB Advisory

CERT-VDE published an advisory discussing the DNSpooq vulnerabilities in the MB connect mbNET products. MB connect has new versions that mitigate the vulnerabilities.

CODESYS Advisories

CODESYS published an advisory [.PDF download link] describing a cross-site request forgery vulnerability in their CODESYS Automation Server. The vulnerability was reported by Uri Katz of Claroty. CODESYS has a new version that mitigates this vulnerability. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

CODESYS published an advisory [.PDF download link] describing a NULL pointer dereference vulnerability in their CODESYS V3 products containing the CmpGateway. The vulnerability was reported by Uri Katz of Claroty. CODESYS has a new version that mitigates this vulnerability. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

CODESYS published an advisory [.PDF download link] describing an insufficient verification of data authenticity vulnerability in their Development System V3. The vulnerability was reported by an OEM customer. CODESYS has a new version that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

CODESYS published an advisory [.PDF download link] describing describing an insufficient verification of data authenticity vulnerability in their Development System V3. The vulnerability was reported by Uri Katz of Claroty. CODESYS has a new version that mitigates this vulnerability. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

CODESYS published an advisory [.PDF download link] describing an improper input validation vulnerability in their V3 products and Control V3 Runtime System Toolkit. The vulnerability was reported by Alexander Nochvay from Kaspersky Lab ICS CERT. CODESYS has a new version that mitigates the vulnerability. There is no indication that Nochvay has been provided an opportunity to verify the efficacy of the fix.

Moxa Advisory

Moxa published an advisory describing four vulnerabilities in their NPort IA5000A Series Serial Device Servers. The vulnerability was reported by Alexander Nochvay from Kaspersky Lab ICS CERT. Moxa has a new version to mitigate one of the vulnerabilities and workarounds for the others. There is no indication that Nochvay has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities:

• Improper access control - CVE-2020-27149,

• Unprotected storage of credentials - CVE-2020-27150,

• Cleartext transmission of sensitive information (2) - CVE-2020-27184 and CVE-2020-27185

ODA Advisory

ODA published an advisory describing an out-of-bounds write vulnerability in their Open Design Alliance Drawings SDK. ODA has a new version that mitigates the vulnerability.

NOTE: This is a very minimalist advisory.

TI Advisories

TI published an advisory discussing the BadAlloc vulnerabilities in their SimpleLink™ CC13XX, CC26XX, CC32XX and MSP432E4 products. TI provides generic work arounds for these vulnerabilities.

TI published an advisory describing an integer overflow vulnerability in their Networks Developers Kit. The vulnerability was reported by Omri Ben Bassat and David Atch of Microsoft. The product is no longer supported.

Advantech Report

The Zero Day Initiative published four reports for vulnerabilities in the Advantech WebAccess/HMI Designer products. The vulnerabilities were reported by kimiya and have been coordinated with NCCIC-ICS and an advisory from them is pending.

The four reported vulnerabilities are:

• Heap-based buffer overflow - ZDI-21-490 and ZDI-21-487,

• File parsing memory corruption- ZDI-21-489, and

• Out-of-bounds write - ZDI-21-488,

Siemens Report

ZDI published a report describing an information validation vulnerability in the Siemens JT2Go product. The vulnerability was reported by Michael DePlante. ZDI has been coordinating with NCCIC-ICS since last September.

OpenPLC Exploit

Fellipe Oliveira published an exploit for a remote code execution vulnerability in the OpenPLC product. There is no CVE provided and no indications of coordination with the vendor. This may be a 0-day vulnerability.

VMware Exploit

Egor Dimitrenko published a Metasploit module for two vulnerabilities in the VMware vRealize Operations Manager. The vulnerabilities were reported by VMware on March 31st, 2021.

The two exploited vulnerabilities are:

• Server-side request forgery - CVE-2021-21975, and

• Arbitrary file write - CVE-2021-21983


Saturday, July 31, 2021

Review - Public ICS Disclosures – Week of 7-24-21

This week we have five PrintNightmare disclosures from Boston Scientific, Carestream, PEPPERL+FUCHS, Draeger, and Spacelabs Healthcare. There were four other vendor disclosures from CODESYS. We also have two updates from CODESYS.

PrintNightmare Advisories

Boston Scientific published an advisory discussing the PrintNightmare vulnerabilities.

Carestream published an advisory discussing the PrintNightmare vulnerabilities.

CERT-VDE published an advisory discussing the PrintNightmare vulnerabilities in products from PEPPERL+FUCHS.

Draeger published an advisory discussing the PrintNightmare vulnerabilities.

Spacelabs published an advisory discussing the PrintNightmare vulnerabilities.

Other Disclosures

CODESYS published an advisory describing a files or directories accessible to external parties vulnerability in their CODESYS V3 web server.

CODESYS published an advisory describing a null pointer dereference vulnerability in their CODESYS Gateway V3.

CODESYS published an advisory describing seven vulnerabilities in their CODESYS Development System V3.

CODESYS published an advisory describing a null pointer dereference vulnerability in their CODESYS EtherNetIP.

CODESYS published an update for their CODESYS V3 web server advisory that originally published on May 19th, 2021.

CODESYS published an update for their CODESYS V3 Runtime Toolkit for VxWorks advisory that was originally published on May 19th, 2021.

For more details on these advisories and updates, including links to proof-of-concept code, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-28e - subscription required.

Saturday, June 4, 2022

Review – Public ICS Disclosure – Week of 5-28-22

This week we have ten vendor disclosures from CODESYS (3), Dell, Endress+Hauser, Mitsubishi, Moxa, Software Toolbox (2), and T&D. We also have nine vendor updates from Aruba Networks, CODESYS, Fujitsu, HP, HPE (4), and Palo Alto Networks. There are also two researcher reports for products from Korenix, and Schneider Electric. Finally, we have three exploits published for products from SolarView, and Ingredient Stock Management System (2).

CODESYS Advisory #1 - CODESYS published an advisory that describes two uncontrolled resource consumption vulnerabilities in their CODESYS V3 products containing a CODESYS communication server.

CODESYS Advisory #2 - CODESYS published an advisory that describes a plain-text storage of password vulnerability in their OPC DA Server.

CODEESYS Advisory #3 - CODESYS published an advisory that describes an observable response discrepancy in their Visualization products.

Dell Advisory - Dell published an advisory that describes three vulnerabilities in their Wyse Management Suite (one is a third-party (JQuery) vulnerability.

Endress+Hauser Advisory - CERT VDE published an advisory that discusses eight vulnerabilities in multiple products from Endress +HYauser.

Moxa Advisory - Moxa published an advisory that discusses the DirtyPipe vulnerability.

Software Toolbox Advisory #1 - Software Toolbox published an advisory that discusses a security feature bypass vulnerability in their OPC Quick Client.

Software Toolbox Advisory #2 - Software Toolbox published an advisory that discusses a security feature bypass vulnerability for customers using OPC Classic.

T&D Advisory - T&D published an advisory that describes a directory traversal vulnerability in the T&D Data Server and THERMO RECORDER DATA SERVER.

Aruba Update #1 - Aruba published an update for their Expat XML advisory that was originally published on May 17th, 2022.

Aruba Update #2 - Aruba published an update for their OpenSSL advisory that was originally published on May 4th, 2022.

Fujitsu Update - JP CERT published an update for their FUJITSU Network IPCOM advisory that was originally published on  May 19th, 2022.

CODESYS Update - CODESYS published an update for their Development System V3 advisory that was originally published on July 15th, 2021 and most recently updated on August 2nd, 2021.

HP Update - HP published an update for their HP Print Products advisory that was originally published on March 21st, 2022, and most recently updated on May 3rd, 2022.

HPE Update #1 - HPE published an update for their Intel Bios advisory that was originally published on May 10th, 2022.

HPE Update #2 - HPE published an update for their ProLiant DX Servers advisory that was originally published on May 10th, 2022.

HPE Update #3 - HPE published an update for their Synergy Servers advisory that was originally published on May 10th, 2022.

HPE Update #4 - HPE published an update for their ProLiant BL/DL/ML/XL/MicroServer that was originally published on May 10th, 2022.

Palo Alto Networks Update - Palo Alto Networks published an update for their OpenSSL advisory that was originally published on March 31st, 2022 and most recently updated on May 12th, 2022.

Korenix Report - SEC Consult published a report describing a backdoor account in the Korenix JetPort serial converter.

Schneider Report - Zero Science published a report describing a remote root exploit vulnerability (with exploit available) in the Schneider C-Bus Automation Controller.

SolarView Exploit - Ahmed Alroky published an exploit for directory traversal vulnerability in the SolarView Compact.

Ingredient Stock Management System Exploit #1 - Saud Alenazi published an exploit for an SQL injection vulnerability in the Ingredient Stock Management System.

Ingredient Stock Management System Exploit #2 - Saud Alenazi published an exploit for an account takeover vulnerability in the Ingredient Stock Management System.

 

For more details about these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-5-28 - subscription required.

Saturday, August 5, 2023

Review – Public ICS Disclosures – Week of 7-29-23 – Part 1 -

This week in Part 1 we have 80 vendor advisories from Aruba Networks, BD, Broadcom (45), CODESYS (5), Fujitsu, GE Gas Power, HP, HPE, Omron (3), Schweitzer Engineering Laboratory, Setelsa Security, Splunk, Tanzu (16), WAGO (2), and VMware.

For Part 2 I will look at vendor updates and researcher reports.

Advisories

Aruba Advisory - Aruba published an advisory that describes a command injection vulnerability in their CX Switches.

BD Advisory - BD published an advisory that discusses an incorrect authorization vulnerability in multiple products.

Broadcom Advisories - Broadcom published 45 advisories for third-party vulnerabilities in a variety of their products.

CODESYS Advisory #1 - CODESYS published an advisory that describes an improper restriction of excessive authentication attempts vulnerability in their Development System product.

CODESYS Advisory #2 - CODESYS published an advisory that describes an insufficient verification of data authenticity vulnerability in their Development System product.

CODESYS Advisory #3 - CODESYS published an advisory that describes an uncontrolled search path vulnerability in their Development System product.

CODESYS Advisory #4 - CODESYS published an advisory that describes 15 vulnerabilities in their Control V3 runtime systems products.

CODESYS Advisory #5 - CODESYS published an advisory that describes two vulnerabilities in their Control V3 runtime system products.

Fujitsu Advisory - Fujitsu published an advisory that describes an improper credential storage vulnerability in their Software Infrastructure Manager product.

GE Advisory - GE published an advisory that discusses a FortiOS stack-based buffer overflow vulnerability.

HP Advisory - HP published an advisory that describes an elevation of privilege vulnerability in some HP and Samsung Printer software packages.

HPE Advisory - HPE published an advisory that discusses 48 vulnerabilities in their Fibre Channel and SAN Switches.

Omron Advisory #1 - Omron published an advisory that describes three vulnerabilities in their CX-Programmer product.

Omron Advisory #2 - Omron published an advisory that describes an improper validation of specified type of input vulnerability in their CJ Series CJ2 CPU units.

Omron Advisory #3 - Omron published an advisory that discusses the INFRA:HALT vulnerabilities in their Multi-function Compact Inverter 3G3MX2.

SEL Advisory - SEL published an advisory that announces that a new version of their Synchrowave Linux Platform is available to fix an undescribed vulnerability by closing Port 10250 on k3s.

Setelsa Advisory - Incibe-CERT published an advisory that describes an SQL injection vulnerability in the Setelsa ConacWin access control platform.

Splunk Advisory - Splunk published an advisory that describes a log injection vulnerability in their SOAR product.

Tanzu Advisories - Tanzu published 16 advisories, each with multiple vulnerabilities in various products.

WAGO Advisory #1 - VDE-CERT published an advisory that discusses an authentication bypass by capture replay vulnerability in the WAGO 758-918 ETHERNET Gateways.

WAGO Advisory #2 - VDE-CERT published an advisory that discusses 15 vulnerabilities in multiple WAGO products.

VMware Advisory - VMware published an advisory that describes two vulnerabilities in their Horizon Server.

 

For more details on these disclosures, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-4fa - subscription required.

Saturday, May 22, 2021

Public ICS Disclosures – Week of 5-15-21

This week we have seven vendor disclosures from Bosch, CODESYS (2), WAGO, ENDRESS+HAUSER, Siemens, and VMware. We have two vendor updates from Siemens. Finally, we have a researcher report for products from Advantech.

Bosch Advisory

Bosch published an advisory discussing an input validation vulnerability in their IndraMotion MTX, MLC and MLD and the ctrlX CORE PLC application products. This is a third-party (CODESYS) vulnerability. An update for the ctrlX CORE PLC APP is pending. Generic mitigation measures are provided.

CODESYS Advisories

CODESYS published an advisory describing an improper input validation vulnerability in their CODESYS V3 products. The vulnerability was reported by  Alexander Nochvay from Kaspersky Lab ICS CERT. CODESYS has software updates available to mitigate the vulnerability. There is no indication that Nochvay has been provided an opportunity to verify the efficacy of the fix.

CODESYS published an advisory describing a NULL pointer dereference vulnerability in their CODESYS V3 products. The vulnerability was reported by Uri Katz of Claroty. CODESYS has new versions available that mitigate the vulnerability. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

WAGO Advisory

CERT-VDE published an advisory discussing twelve vulnerabilities in the WAGO PLCs. These are third-party (CODESYS) vulnerabilities that were reported by JSC Positive Technologies. WAGO has new firmware versions available that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The twelve reported vulnerabilities are:

• Allocation of resources without limit or throttling - CVE-2021-21000,

• Path traversal - CVE-2021-21001,

• Heap-based buffer overflow - CVE-2021-30186,

• Stack-based buffer overflow (2) - CVE-2021-30188, CVE-2021-30189,

• Improper input validation - CVE-2021-30195,

• Improper access control - CVE-2021-30190,

• Buffer copy without checking size of input - CVE-2021-30191,

• Improperly implemented security check - CVE-2021-30192,

• Out-of-bounds write - CVE-2021-30193,

• Out-of-bounds read - CVE-2021-30194,

• Improper neutralization of special elements used in an OS command - CVE-2021-30187

NOTE: The first two vulnerabilities have apparently not yet been addressed by CODESYS and have been given CERT-VDE CPE numbers.

ENDRESS+HAUSER Advisory

CERT-VDE published an advisory discussing the KRACK attacks vulnerabilities in the ENDRESS+HAUSER Proline portfolio flow meter products. ENDRESS+HAUSER has firmware updates that mitigate the vulnerabilities.

Siemens Advisory

Siemens published an advisory describing five vulnerabilities in their n JT2Go and Teamcenter Visualization products. The vulnerabilities were reported by the Zero Day Initiative and Carsten Eiram from Risk Based Security. Siemens has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

Untrusted pointer dereference - CVE-2020-26991,

Out-of-bounds read (3) - CVE-2020-26998, CVE-2020-26999, and CVE-2020-27002, and

Stack-buffer overflow - CVE-2020-27001

NOTE: Apparently, none of the above vulnerabilities are the 0-day vulnerability that ZDI published for this product on April 28th.

VMWare Advisory

VMWare published an advisory describing three out-of-bounds read vulnerabilities in their VMware Workstation and Horizon Client for Windows. This is a third-party (Cortado ThinPrint) vulnerability. The vulnerabilities were published by Anonymous at ZDI and Hou JingYi of Qihoo 360. VMware has new versions that mitigate the vulnerabilities. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

NOTE: The Cortado web site make the following claim about ThinPrint, so these vulnerabilities may exist in other ICS products.

“Thanks to numerous OEM partnerships, ThinPrint technology components are integrated in a variety of terminals, print boxes and thin client of leading hardware manufacturers.”

Siemens Updates

Siemens published an update for their JT2Go and Teamcenter Visualization advisory that was originally published on January 12th, 2021 and most recently updated on February 9th, 2021. The new information includes:

• Moving vulnerabilities CVE-2020-26989, CVE-2020-26990, and CVE-2020-28383

to advisory SSA-663999 (see below), and

• Moving vulnerabilities d CVE-2020-26991 to SSA-695540 (see new advisory above).

NOTE: NCCIC-ICS should be updating their advisory, ICSA-21-012-03, this coming week.

Siemens published an update for their JT2Go and Teamcenter Visualization advisory that was originally published on February 9th, 2021. The new information includes:

• Removing vulnerabilities CVE-2020-26991, CVE-2020-26998, CVE-2020-26999, CVE-2020-27001, and CVE-2020-27002, and

• Adding vulnerabilities CVE-2020-28383, CVE2021-31784 (from update above).

NOTE: NCCIC-ICS should be updating their advisory, ICSA-21-040-06, this coming week.

Advantech Report

ZDI published a report describing a use of hard-coded credentials vulnerability in the Advantech BB-ESWGP506-2SFP-T industrial switches. ZDI coordinated the disclosure with NCCIC-ICS.

Saturday, May 15, 2021

Public ICS Disclosures – Week of 5-8-21, Part 1

This is a busier week than normal, even for a ‘Second Tuesday’ week. We have three vendor notifications for the FragAttacks WiFi vulnerabilities from Aruba, Ruckus, and Texas Instruments. We have two vendor notifications for the two OPC UA vulnerabilities reported this week by NCCIC-ICS from Beckhoff, Belden. We also have twelve other vendor notifications from Braun, SITEL (4), PEPPERL+FUCHS, CODESYS (3), Dell, and PulseSecure (2).

There will be a similarly lengthy list in Part 2 tomorrow.

FragAttacks Advisories

Aruba published an advisory discussing the FragAttacks vulnerabilities. Aruba provides a list of affected products and has new versions that mitigate the vulnerabilities.

Ruckus published an advisory discussing the FragAttacks vulnerabilities. Ruckus provides a list of affected products and has updates that mitigate the vulnerabilities.

TI published an advisory discussing the FragAttacks vulnerabilities. TI provides a list of affected products and has new versions that mitigate the vulnerabilities.

OPC UA Advisories

Beckhoff published an advisory discussing the OPC UA advisories. Beckhoff provides a list of affected products and has new versions that mitigate the vulnerabilities.

Belden published an advisory discussing the OPC UA advisories. Belden provides a list of affected products and has new versions that mitigate the vulnerabilities.

Braun Advisory

Braun published an advisory describing four vulnerabilities in a number of their products. The vulnerabilities were reported by McAfee Advanced Threat Research. Braun has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Insufficient verification of data authenticity,

• Missing authentication for critical function,

• Clear-text transmission of sensitive information, and

• Unrestricted upload of file with dangerous type.

SITEL Advisories

Incibe-Cert published an advisory describing a hard-coded credentials vulnerability in the SITEL CAP/PRX products. The vulnerability was reported by S21sec. SITEL has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Incibe-Cert published an advisory describing an exposure of sensitive information to an unauthorized actor vulnerability in the SITEL CAP/PRX products. The vulnerability was reported by S21sec. SITEL has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Incibe-Cert published an advisory describing a clear-text transmission of sensitive information vulnerability in the SITEL CAP/PRX products. The vulnerability was reported by S21sec. SITEL has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Incibe-Cert published an advisory describing an uncontrolled resource consumption vulnerability in the SITEL CAP/PRX products. The vulnerability was reported by S21sec. SITEL has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

PEPPERL+FUCHS Advisory

CERT-VDE published an advisory describing four vulnerabilities in the PEPPERL+FUCHS ICE1 Ethernet IO Modules. These are third-party (Hilscher) vulnerabilities. PEPPERL+FUCHS has provided generic mitigation measures.

The four reported vulnerabilities are:

• Out-of-bounds write (2) - CVE-2021-20987 and CVE-2021-20986,

• Improper restriction of operations within the bounds of a memory buffer - CVE-2021-20988, and

• Exposure of sensitive information to an unauthorized actor - CVE-2019-18222 (Mbed TLS)

CODESYS Advisories

CODESYS published an advisory describing three vulnerabilities in their CODESYS V2 runtime systems. The vulnerabilities were reported by Yossi Reuven of SCADAfence and Sergey Fedonin and Denis Goryushev of Positive Technologies. CODESYS has updates that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2021-30186,

• Stack-based buffer overflow - CVE-2021-30188, and

• Improper input validation - CVE-2021-30195

CODESYS published an advisory describing six vulnerabilities in their V2 web server. The vulnerabilities were reported by Vyacheslav Moskvin, Sergey Fedonin and Anton Dorfman of Positive

Technologies. CODESYS has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2021-30189,

• Improper access control - CVE-2021-30190,

• Buffer copy without checking size of input - CVE-2021-30191,

• Improperly implemented security check - CVE-2021-30192,

• Out-of-bounds write - CVE-2021-30193, and

• Out-of-bounds read - CVE-2021-30194

CODESYS published an advisory describing an improper neutralization of special elements used in an OS command vulnerability in their CODESYS V2 Runtime Toolkit 32. This is a Linux implementation vulnerability. The vulnerability was reported by van Kurnakov and Sergey Fedonin of Positive Technologies. CODESYS has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Dell Advisory

Dell published an advisory describing an improper authorization vulnerability in their Dell Wyse Windows Embedded System. The vulnerability was reported by Alessandro Baldini and Alessio D'Anastasio. Dell has updates that mitigate the vulnerability.

PulseSecure Advisories

PulseSecure published an advisory describing an HTTP request smuggling vulnerability in their Virtual Traffic Manager (vTM). The vulnerability was reported by James Kettle from PortSwigger Web Security.  PulseSecure has new versions that mitigate the vulnerability. There is no indication that Kettle has been provided an opportunity to verify the efficacy of the fix.

PulseSecure published an advisory describing a buffer overflow vulnerability in their Pulse Connect Secure. PulseSecure provides a work around pending development of a new version that will mitigate the vulnerability.

Sunday, December 18, 2022

Review – Public ICS Disclosures – Week of 12-10-22 – Part 2

For part 2 we have twelve additional vendor disclosures from Rockwell Automation (3), Schneider (2), Sick, VMware (4), Weidmueller, and Wiesemann & Theis. We also have seven vender updates from CODESYS (3), Dell, HPE, Mitsubishi, and Omron. Finally, we have one researcher report for products from VMware.

Vendor Disclosures

Rockwell Advisory #1 - Rockwell published an advisory that describes a denial of service vulnerability in their MicroLogix 1100 & 1400 Product Web Server application.

Rockwell Advisory #2 - Rockwell published an advisory that describes a cross-site scripting vulnerability in their MicroLogix 1100 & 1400 Web Server application.

Rockwell Advisory #3 - Rockwell published an advisory that describes a denial of service vulnerability in their GuardLogix and ControlLogix controllers.

Schneider Advisory #1 - Schneider published an advisory that describes an improper authorization vulnerability in their EcoStruxure Power Commission.

Schneider Advisory #2 - Schneider published an advisory that discusses an out-of-bounds write vulnerability in their Saitel DR RTU (Remote Terminal Unit).

Sick Advisory - Sick published an advisory that describes four vulnerabilities in the n SICK RFU6xx RADIO FREQUEN. SENSOR 1.

VMware Advisory #1 - VMware published an advisory that describes two vulnerabilities in their vRealize Network Insight (vRNI) product.

VMware Advisory #2 - VMware published an advisory that describes two vulnerabilities in their Workspace ONE Access and Identity Manager.

VMware Advisory #3 - VMware published an advisory that describes a heap-based write vulnerability in their ESXi, Workstation, and Fusion products.

VMware Advisory #4 - VMware published an advisory that describes two vulnerabilities in their vRealize Operations product.

Weidmueller Advisory - CERT-VDE published an advisory that describes a JavaScript injection vulnerability in the Weidmueller XML editing system SCHEMA ST4 online help.

Wiesemann & Theis Advisory - CERT-VDE published an advisory that describes an authentication bypass by spoofing vulnerability in multiple Wiesemann & Theis products.

Vendor Updates

CODESYS Update #1 - CODESYS published an update for their Control V3 communication server advisory that was originally published on November 22nd, 2022.

CODESYS Update #2 - CODESYS published an update for their V3 boot application advisory that was originally published on November 23rd, 2022.

CODESYS Update #3 - CODESYS published an update for their V2 password transport advisory that was originally published on June 9th, 2022 and most recently updated on October 6th, 2022.

CODESYS Update #4 - CODESYS published an update for their V2 and V3 runtime systems advisory that was originally published on March 22nd, 2018 and most recently updated on July 9th, 2018.

Dell Update - Dell published an update for their Log4Shell advisory.

HPE Update - HPE published an update for their NonStop advisory that was originally published on July 18th, 2022.

Mitsubishi Update - Mitsubishi published an update for their GENESIS64TM and MC Works64 advisory that that was originally published on July 19th, 2022 and most recently updated on September 30th, 2022.

Omron Update - JP-CERT published an update for their OMRON CX-Programmer advisory that was originally published on November 25th, 2022.

Researcher Report

VMware Report - CISCO Talos published a report describing a denial-of-service vulnerability in the VMware vCenter Server Content Library.

 

For additional information on these disclosures, including links to third-party advisories, exploits, and brief summary of changes made, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-720 - subscription required.


Saturday, March 22, 2025

Review – Public ICS Disclosures – Week of 3-15-25

This week we have 24 vendor disclosures from CODESYS (3), Dassault Systèmes (13), Fuji Soft, Helmholtz, HPE (2), MB Connect, Phillips (2), and QNAP. There are also six vendor updates from Dell, FortiGuard (3), HP, and HPE. Finally, there are three researcher reports for vulnerabilities in products from Luxion and National Instruments (2).

Advisories

CODESYS Advisory #1 - CODESYS published an advisory that describes an observable discrepancy vulnerability in their  CODESYS Runtime Toolkit.

CODESYS Advisory #2 - CODESYS published an advisory that describes a path traversal vulnerability in multiple CODESYS products.

CODESYS Advisory #3 - CODESYS published an advisory that describes an insecure initialization of resource vulnerability in Edge Gateway for Windows and Gateway for Windows products.

Dassault Advisories - Dassault Systèmes published 13 advisories stored cross-site scripting vulnerabilities in multiple products. These advisories are only available to registered customers.

Fuji Soft Advisory - JP-CERT published an advisory that describes two command OS injection vulnerabilities in the Fuji F FS010M router.

Helmholtz Advisory - CERT-VDE published an advisory that describes two vulnerabilities in the Helmholtz  myREX24 and myREX24.virtual products.

HPE Advisory #1 - HPE published an advisory that describes three vulnerabilities in the HPE Aruba Networking AOS-CX product.

HPE Advisory #2 - HPE published an advisory that discusses six vulnerabilities (two with publicly available exploits) in their Telco Service Activator.

MB Connect Advisory - CERT-VDE published an advisory that describes two vulnerabilities in multiple MB Connect products.

Philips Advisory #1 - Philips published an advisory that discusses an Apache Tomcat vulnerability.

Philips Advisory #2 - Philips published an advisory that discusses three VMware vulnerabilities.

QNAP Advisory - QNAP published an advisory that discusses an absolute path traversal vulnerability (listed in CISA’s KEV catalog) in the NAKIVO Backup & Replication application.

Updates

Dell Update - Dell published an update for their ThinOS advisory that was originally published on March 4th, 2025.

FortiGuard Update #1 - FortiGuard published an update for their csfd daemon advisory that was originally published on January 14th, 2025, and most recently updated on January 16th, 2025.

FortiGuard Update #2 - FortiGuard published an update for their RADIUS Protocol advisory that was originally published on August 13th, 2024, and most recently updated on March 6th, 2025.

FortiGuard Update #3 - FortiGuard published an update for their permission escalation advisory that was originally published on February 11th, 2025.

HP Update - HP published an update for their LaserJet Pro advisory that was originally published on February 14th, 2025, and most recently updated on March 14th, 2025.

HPE Update - HPE published an update for their Cray XD670 Server advisory that was originally published on March 11th, 2025.

Researcher Reports

Luxion Reports - ZDI published three reports about vulnerabilities in the Luxion KeyShot product.

National Instruments Report #1 - ZDI published a report that describes a path traversal vulnerability in the NI FlexLogger.

National Instruments Report #2 - ZDI published a report that describes a product UI does not warn user of unsafe actions vulnerability in the NI Vision Builder AI.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-daf - subscription required.
 
/* Use this with templates/template-twocol.html */