Showing posts with label ANSSI. Show all posts
Showing posts with label ANSSI. Show all posts

Saturday, February 6, 2021

Public ICS Disclosure – Week of 1-30-21

This week we have four vendor disclosures from ABB, Belden, GE Digital, and Ruckus. There is also an update from Rockwell and Honeywell published an end-of-life notice.

ABB Advisory

ABB published an advisory describing a web-server denial of service vulnerability in their AC500 V2 products. The vulnerability was reported by Richard Thomas and Tom Chothia of the University of Birmingham. ABB has no mitigation measures for this vulnerability.

Belden Advisory

Belden published an advisory describing a denial of service vulnerability in the Hirschmann HiOS platform. The vulnerability was reported by the French Cybersecurity Agency (ANSSI). Belden has updates available that mitigate the vulnerability. There are no indications that the researchers have been provided an opportunity to verify the efficacy of the fix.

GE Advisory

GE published an advisory describing three unnamed vulnerabilities in their iFix HMI/SCADA product. The vulnerabilities were reported by Sharon Brizinov of Claroty and William Knowles with Applied Risk. GE has an upgrade that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Ruckus Advisory

Ruckus published an advisory describing a CLI passphrase vulnerability in their AP and ZD products. The vulnerability is apparently self-reported. No mitigation measures are described.

Rockwell Update

Rockwell published an update for the AENT Flex I/O Series B advisory that was originally published on October 12th, 2020. The new information includes adding a sixth classic buffer overflow vulnerability, CVE-2020-6088.

NOTE: Talos published a report this week covering this vulnerability. It included proof-of-concept code.

Honeywell EOL Notice

Honeywell published an end-of-life notice for their Maxpro VMS/NVR products.

Saturday, August 16, 2014

ICS-CERT Publishes Two Siemens Advisories

Earlier this week (still getting caught up) the DHS ICS-CERT published two advisories for control system vulnerabilities in Siemens products. One was for a new denial of service attack vulnerability in the Simatic S7-1500 CPU and the other was an update of an earlier HeartBleed advisory.

S-1500 Advisory

This advisory addresses a vulnerability in the handling of specially crafted TCP packets that could result in a CPU restart and hold in the STOP mode which would require manual reset. It was originally reported by Arnaud Ebalard from Agence Nationale de la Sécurité des Systèmes d’Information (ANSSI) in a coordinated disclosure.

Siemens has produced a firmware update that mitigates the vulnerability. There is no indication that Ebalard has been given the opportunity to verify the efficacy the fix.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability. The Siemens Product-CERT advisory clarifies that network access is required to exploit the vulnerability.

OpenSSL Update

This advisory updates the Siemens HeartBleed Advisory originally issued on July 17th and previously updated on July 23rd. The new update:

• Provides affected version information not previously provided for the S7-1500 product;
• Provides a link to the newly available S7-1500; and
• Removes the alternative mitigation measures previously provided for the S7-1500.

The Siemens ProductCert advisory was also updated.


NOTE: Siemens reports that they are continuing to work on HeartBleed fixes for their ROX 1, ROX 2, and CP1543-1 products.
 
/* Use this with templates/template-twocol.html */