Saturday, December 5, 2020

Public ICS Disclosure – Week of 11-28-20

This week we have three vendor disclosures for products from BD, Mitsubishi, and Phoenix Contact. There was also an update for a previous disclosure from Yokogawa.

BD Advisory

BD published an advisory discussing the Microsoft Bad Neighbor vulnerability. The advisory provides a list of potentially affected products. BD is testing the MS patch for compatibility.

Mitsubishi Advisory

Mitsubishi published an advisory describing a denial-of-service vulnerability in their Human-Machine Interfaces-GOT and Tension Controller products. This vulnerability is self-reported. Mitsubishi has provided generic workarounds pending development of a new version that mitigates the vulnerability.

Phoenix Contact Advisory

Phoenix Contact published an advisory [.PDF download link] describing an uncontrolled resource consumption vulnerability in their Touch Panels of the BTP series of articles. The vulnerability was reported by y Richard Thomas and Tom Chothia of University of Birmingham. Phoenix Contact provides generic workarounds to mitigate the vulnerability.

Yokogawa Update

Yokogawa published an update for their CAMS for HIS advisory that was originally published on July 31st, 2020 and most recently updated on September 4th, 2020. The new information includes adding  Exaopc as affected product.

No comments:

 
/* Use this with templates/template-twocol.html */