Tuesday, January 30, 2024

Review – 7 Advisories and 1 Update Published – 1-30-24

Today, CISA’s NCCIC-ICS published seven control system security advisories for products from Rockwell Automation (3), Hitron, Mitsubishi Electric (2) and Emerson. They also updated an advisory for products from Mitsubishi.

Advisories

Rockwell Advisory #1 - This advisory discusses 15 vulnerabilities in multiple Rockwell Operator Panels.

Rockwell Advisory #2 - This advisory describes an improper verification of cryptographic signatures in the Rockwell FactoryTalk Service Platform.

Rockwell Advisory #3 - This advisory describes an improper restriction of operations within the bounds of a memory buffer in the Rockwell ControlLogix and GuardLogix products.

Hitron Advisory - This advisory describes six improper input validation vulnerabilities  in the Hitron HGR and LGUVR series DVRs.

Mitsubishi Advisory #1 - This advisory describes an authentication bypass by capture-replay vulnerability in the Mitsubishi MELSEC WS Series Ethernet Interface Modules.

Mitsubishi Advisory #2 - This advisory describes two vulnerabilities in the Mitsubishi FA Engineering Software Products.

Emerson Advisory - This advisory describes four vulnerabilities in the Emerson Rosemount GC370XA, GC700XA, and GC1500XA gas chromatographs.

Updates

Mitsubishi Update - This update provides additional information on an advisory that was originally published on July 27th, 2023 and most recently updated on December 5th, 2023.

 

For more information on these advisories, including links to 3rd party vulnerabilities and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-1-update-published-c5e - subscription required. 

1 comment:

Anonymous said...

Strange that Rockwell reports vulnerabilities to CISA, but doesn't publish them on their own website. They recently made a new website for security advisories, for which a login is no longer needed, but the new website is not as actively maintained as the old website, so you'd better use the old one to keep current. CISA refers to Rockwell's new website.

As for the ICSA-24-030-07, the Rockwell advisory is at https://www.rockwellautomation.com/en-us/support/advisory.SD1659.html (but a login is needed...)

 
/* Use this with templates/template-twocol.html */