Saturday, March 23, 2019

Public ICS Disclosures – Week of 03-16-19


CERT-VDE published an advisory describing nine vulnerabilities in the ENDRESS-HAUSER Field Xpert hand-held devices. These are the KRACK WPA2 vulnerabilities. The vulnerabilities are being self-reported. ENDRESS-HAUSER points to 3rd party mitigations for the affected devices.

NOTE: It is disappointing to note that we can still see original reporting of KRACK vulnerabilities when these were first reported in the ICS environment back in October of 2017. It is particularly aggravating in this case since the vulnerability was already reported in the affected devices by the manufacturer.

No comments:

 
/* Use this with templates/template-twocol.html */