Showing posts with label 9SG. Show all posts
Showing posts with label 9SG. Show all posts

Tuesday, April 7, 2020

5 Advisories and 1 Update Published


Today the CISA NCCIC-ICS published five control system security advisories for products from KUKA, Fuji Electric, HMS Networks, GE Digital and Advantech. They also updated an advisory for products from Synergy.

KUKA Advisory


This advisory describes an improper enforcement of message integrity in a communications channel vulnerability in the KUKA Sim Pro. The vulnerability was reported by Federico Maggi of Trend Micro. KUKA has an upgrade that mitigates the vulnerability. There is no indication that Maggi has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to result in a loss of integrity in external 3D models fetched from remote servers. When tested on real machines, this effect is unpredictable.

Fuji Advisory


This advisory describes a heap-based buffer overflow vulnerability in the Fuji V-Server Lite. The vulnerability was reported by kimiya via the Zero Day Initiative. Fuji has a new version that mitigates the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reported that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote attacker to gain elevated privileges for remote code execution.

HMS Advisory


This advisory describes a cross-site scripting vulnerability in the HMS eWON Flexy and Cosy. The vulnerability was reported by Ander Martínez of Titanium Industrial Security. HMS has a firmware update that mitigates the vulnerability. There is no indication that Martinez has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit this vulnerability to initiate a password change.

NOTE: I briefly discussed this vulnerability back in February.

GE Advisory


This advisory describes an improper privilege management vulnerability in the GE Digital CIMPLICITY HMI/SCADA product. The vulnerability was reported by Sharon Brizinov of Claroty. GE has a new version that mitigates the vulnerability. There is no indication that Brizinov has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an adversary to modify the systemwide CIMPLICITY configuration, leading to the arbitrary execution of code.

NOTE: I briefly discussed this vulnerability last weekend.

Advantech Advisory


This advisory describes eight vulnerabilities in the Advantech WebAccess/NMS network management system. The vulnerability was reported by rgod of 9sg via ZDI. Advantech has a new version that mitigates the vulnerability. There is no indication that rgod was provided an opportunity to verify the efficacy of the fix.

The eight reported vulnerabilities are:

• Unrestricted upload of file with dangerous type - CVE-2020-10621;
• SQL injection (2) - CVE-2020-10617 and CVE-2020-10623;
• Relative path traversal (2) - CVE-2020-10619 and CVE-2020-10631;
• Missing authentication for critical function - CVE-2020-10625;
• Improper restriction of XML external entity reference -CVE-2020-10629; and
• OS command injection - CVE-2020-10603

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to gain remote code execution, upload files, delete files, cause a denial-of-service condition, and create an admin account for the application.

Synergy Update


This update provides new information on an advisory that was originally published on February 11th, 2020. The new information includes:

• Four new vulnerabilities:
Missing authentication for critical function - CVE-2019-16879;
Improper check for unusual or exceptional conditions - CVE-2020-7800;
Exposure of sensitive information to an unauthorized actor - CVE-2020-7801; and
Incorrect default permissions - CVE-2020-7802
• Links to three associated advisories from SSS (here, here and here)

Friday, November 8, 2019

4 Advisories and 1 Update Published – 11-07-19


Yesterday the CISA NCCIC-ICS published two control system security advisories for products from Fuji Electric and Mitsubishi Electric; and two medical device security advisories for products from Medtronic (2). The also updated a previously published medical device advisory for products from Philips.

Fuji Advisory


This advisory describes a heap-based buffer overflow vulnerability in the Fuji V-Server. The vulnerability was reported by kimiya of 9SG via the Zero Day Initiative. Fuji has a new version that mitigates the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to crash the device being accessed; several heap-based buffer overflows have been identified.

Mitsubishi Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Mitsubishi MELSEC-Q Series and MELSEC-L Series CPU Modules. The vulnerability was reported by Tri Quach of Amazon’s Customer Fulfillment Technology Security (CFTS) group. Mitsubishi has a new firmware version that mitigates the vulnerability. There is no indication that Tri has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to prevent the FTP client from connecting to the FTP server on MELSEC-Q Series and MELSEC-L Series CPU module. Only FTP server function is affected by this vulnerability.

Medtronic Advisory #1


This advisory describes two RFID security vulnerabilities in the Medtronic Valleylab energy and electrosurgery products. The vulnerabilities are self-reported. Medtronic has a patch available to mitigate the vulnerabilities.

The two reported vulnerabilities are:

• Improper authentication - CVE-2019-13531; and
• Protection mechanism failure - CVE-2019-13535

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to connect inauthentic instruments to the affected products by spoofing RFID security mechanisms. This may lead to a loss of performance integrity and platform availability due to incorrect identification of instrument and associated parameters.

Medtronic Advisory #2


This advisory describes four vulnerabilities in the Medtronic Valleylab energy products. The vulnerabilities are self-reported. Medtronic has patches available to mitigate the vulnerability.

The four reported vulnerabilities are:

• Use of hard-coded credentials - CVE-2019-13543;
• Reversible one-way hash - CVE-2019-13539; and
• Improper input validation (2) - CVE-2019-3464, and CVE-2019-3463.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to  allow an attacker to overwrite files or remotely execute code, resulting in a remote, non-root shell on the affected products. By default, the network connections on these devices are disabled. Additionally, the Ethernet port is disabled upon reboot. However, it is known that network connectivity is often enabled.

Philips Update


This update provides new information for and advisory that was originally reported on April 30th, 2019.
The new information includes:

• Revised (increased) overall CVSS score;
• Information exposure vulnerability added;
• Added Tasy WEbPortal to affected product list;
• Added Trabalho Médico IT Department as a vulnerability reporter; and
• Reported that a new version mitigates the vulnerabilities.

 
/* Use this with templates/template-twocol.html */