Showing posts with label Amir Preminger. Show all posts
Showing posts with label Amir Preminger. Show all posts

Saturday, September 12, 2020

Public ICS Disclosure – Week of 9-2-20

We have eight vendor notifications about the CodeMeter vulnerabilities reported earlier this week by NCCIC-ICS from Phoenix Contact, PEPPERL+FUCHS, WAGO, ABB, and Pilz. We also have four vendor notification from Schneider, Moxa, Medtronic, and BD. There is a vendor update from Mitsubishi. We have a researcher report of 0-day vulnerabilities for products from Fuji Electric.

CodeMeter Advisories

Phoenix Contact published an advisory for the CodeMeter vulnerabilities. They listed their affected products and announced a new version of their Activation Wizard that mitigates the vulnerabilities.

VDE-CERT published an advisory for the CodeMeter vulnerabilities in products from PEPPERL+FUCHS. It provides a list of affected products and recommends implementing the WIBU Systems update.

VDE-CERT published an advisory for the CodeMeter vulnerabilities in products from WAGO. It reports that the e!COCKPIT engineering software is bundled with the CodeMeter software. VDE-CERT notes that WAGO will update their e!COCKPIT setup routine later this year.

ABB published four CodeMeter advisories for the following products:

General information,

AC 800PEC platform,

Ability™ Operations Data Management zenon, and

ABB Drives applications

Pilz published an advisory for the CodeMeter vulnerabilities. It provides a list of affected products and recommends using the current version of CodeMeter.

Schneider Advisory

Schneider published an advisory describing five vulnerabilities in their SCADAPack remote connect and security administrator applications. The vulnerabilities were reported by Amir Preminger of Claroty. Schneider has new versions that mitigate the vulnerabilities. There is no indication that Preminger has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Deserialization of untrusted data - CVE-2020-7528 and CVE-2020-7532,

• Path transversal - CVE-2020-7529,

• Improper authorization - CVE-2020-7530, and

• Improper access control - CVE-2020-7531

Moxa Advisory

Moxa published an advisory for the BootHole vulnerability. Moxa reports that none of its products are affected.

Medtronic Advisory

Medtronic published an advisory describing the SweynTooth vulnerabilities in a number of their products. Medtronic reports that they remediated these vulnerabilities when they did their software update in June 2020.

BD Advisory

BD published an advisory describing the SigRed vulnerabilities in a number of their products. BD recommends ensuring that the appropriate Microsoft® patches have been applied.

Mitsubishi Update

Mitsubishi published an update for their MC Works advisory that was originally published on June 18th, 2020. The new information includes links for security patches for MC Works64 Version 4.00A - 4.02C.

Fuji Electric Reports

Kimiya published 14 reports (ZDI-20-1103 thru ZDI-20-1117) of vulnerabilities in the Fuji Electric Tellus Lite product. The vulnerabilities were reported to ‘ICS-CERT’ (presumably, NCCIC-ICS) by the Zero Day Initiative back in April.

The vulnerabilities include:

• Stack-based buffer overflow,

• Out-of-bounds write, and

• Out-of-bounds read

Saturday, July 25, 2020

Public ICS Disclosure – Week of 7-18-20

This week we have two vendor disclosures from Phoenix Contact and CODESYS and an update from Rockwell.

 

Phoenix Contact Advisory

 

Phoenix Contact published an advisory [.PDF download link] describing an improper path sanitation on import of project files vulnerability in their PLCnext Engineer. The vulnerability was reported by Amir Preminger of Claroty. Phoenix Contact has a new version that mitigates the vulnerability.

 

CODESYS Advisory

 

CODESYS published an advisory [.PDF download link] describing an uncontrolled memory allocation vulnerability in their CODESYS V3 Visualization product. The vulnerability was reported by Tenable. The Tenable report includes proof-of-concept code. CODESYS has a new version that mitigates the vulnerability.

 

Rockwell Update

 

Rockwell published an update for their FactoryTalk View SE advisory that was originally published on June 18th, 2020. The new information includes updated guidance given public scripts. NCCIC-ICS should update their advisory next week.


Saturday, July 18, 2020

Public ICS Disclosures – Week of 7-11-20


This week we have four Ripple20 vendor disclosures from Siemens, ABB, Rockwell, Carestream and Schneider Electric; two SigRed vendor disclosures from Philips and GE Healthcare; and three other vendor disclosures from HMS and Schneider (2). Four vendor updates from Schneider (2) and Siemens (2) and  two researcher disclosures for products from Siemens and Advantech round out the weeks’ offerings.

Ripple20 Disclosures and Updates


Siemens published a Ripple20 advisory for their SPPA-T3000 Solutions distributed control system. Siemens provides generic mitigation measures for these vulnerabilities.

NOTE: Siemens published a note at the top of their Security Publications page noting that:

“No Siemens product is known to use Treck Inc.'s TCP/IP stack, or otherwise be affected by the reported vulnerabilities.
“Note that Siemens products and systems might interact with products from other manufacturers which are affected by the reported vulnerabilities. In such cases Siemens recommends that owners of operational infrastructures verify if these products are affected and evaluate the potential impact of the Ripple20 vulnerabilities.”

Since the SPPA-T3000 advisory also contains two Intel Server Platform Services vulnerabilities, I suspect that the Ripple20 vulnerabilities come with the Intel server upon which the T-3000 is built.

ABB published a Ripple20 advisory. The advisory contains a list of affected products and generic mitigation measures pending further work to address the vulnerabilities.

Rockwell updated their Ripple20 advisory. The new information includes an updated table of affected products.

Carestream updated their Ripple20 advisory (.PDF download link). The new information includes adding 20 products that were on the ‘still evaluating list’ to the not affected list. The list of affected products has not changed.

Schneider updated their Ripple20 advisory. The new information includes removing the “Smartlink ELEC” from the list of affected products.

SigRed Disclosures


SigRed is the ‘cute’ name given to the Microsoft ‘wormable’ remote code execution DNS vulnerability (CVE-2020-1350).

Phillips published a SigRed advisory noting that: “Philips is currently in the process of evaluating the Microsoft patch and vendor recommended mitigation options.”


GE Healthcare published a SigRed advisory noting that: “GE Healthcare is actively assessing products that utilize impacted Microsoft Operating Systems.”

Neither of these advisories provide much in the way of information beyond noting that a vague ‘some’ of their products may be affected.

Vendor Disclosures


HMS published an advisory describing a remote code execution vulnerability in their eCatcher product. The vulnerability was reported by Claroty. HMS has an update that mitigates the vulnerability. There is no indication that Claroty was provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory describing an open redirect vulnerability in their Schneider Electric Software Update (SESU). The vulnerability was reported by Amir Preminger of Claroty. Schneider has a new version that mitigates the vulnerability. There is no indication that Preminger has been provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory describing two denial of service vulnerabilities in their Floating License
Manager. These are third-party vulnerabilities in the Flexera FlexNet Publisher (reported here and here). Schneider has a new version that mitigates these vulnerabilities.

NOTE: Flexera is also reporting three other vulnerabilities (CVE-2019-8963, CVE-2020-12080, and CVE-2020-12081) that could potentially affect the Schneider Floating License Manager and a variety of other vendor ‘license manager’ products based upon the Flexera product.

Vendor Updates


Schneider updated their ZombieLoad advisory. The new information includes updated mitigation measures for the HMI products.

Schneider updated their BlueKeep advisory. The new information includes updated mitigation measures for the HMI products.

Siemens updated their Vulnerabilities in Intel CPUs advisory. The new information includes:

• Updated mitigation and affected version information for SIMATIC ITP1000, and
• Removed SIMATIC IPC827E from list of affected devices

Siemens updated heir GNU/Linux advisory. The new information includes adding:

CVE-2020-12114,
• CVE-2020-12659,
• CVE-2020-13630,
• CVE-2020-13631, and
• CVE-2020-13632

Researcher Disclosures


Talos published a report on the Siemens LOGO web server vulnerability that was reported earlier this week. The Talos report includes proof-of-concept code for the vulnerability.

The Zero Day Initiative published 43 reports, all based upon research by rgod, about the Advantech iView vulnerabilities that were reported earlier this week. Most of the reports provided more details on the three CVE’s listed in the NCCIC-ICS advisory. One of the reports, however, described an input validation vulnerability that was not reported by NCCIC-ICS.

Thursday, June 11, 2020

3 Advisories Published – 6-11-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Rockwell Automation and OSIsoft as well as a medical device security advisory for products from Philips.

Rockwell Advisory 


This advisory describes four vulnerabilities in the Rockwell FactoryTalk Linx Software. The vulnerabilities were reported by Sharon Brizinov and Amir Preminger, of Claroty. Rockwell has patches that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Improper input validation (2) - CVE-2020-11999 and CVE-2020-12001,
• Path traversal - CVE-2020-12003, and
• Unrestricted upload of file of dangerous type - CVE-2020-12005

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to cause a denial-of-service condition, obtain remote code execution, and read sensitive information.

OSIsoft Advisory


This advisory describes a cross-site scripting vulnerability in the OSIsoft PI Web API 2019. The vulnerability was reported by Dor Yardeni and Eliad Mualem at OTORIO. OSIsoft has a new service pack that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow a remote authenticated attacker with write access to a PI Server to trick a user into interacting with a PI Web API endpoint that executes arbitrary JavaScript in the user’s browser, resulting in view, modification, or deletion of data as allowed for by the victim’s user permissions.

Philips Advisory


This advisory describes an insertion of sensitive information into log file vulnerability in the Philips  IntelliBridge Enterprise (IBE). Indiana University Health reported the vulnerability. Philips plans a new release to mitigate the vulnerability in 4th Qtr 2020; meanwhile they provide generic mitigation measures to address the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to allow an attacker to access credentials to the hospital’s clinical information systems (EMR).

Thursday, May 21, 2020

2 Advisories Published – 5-21-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Schneider Electric and Johnson Controls.

Schneider Advisory


This advisory describes five vulnerabilities in the Schneider EcoStruxure Operator Terminal Expert. The vulnerabilities were reported by Sharon Brizinov and Amir Preminger of Claroty Research (via the Zero Day Initiative), Steven Seeley and Chris Anastasio of Incite Team (via ZDI), and Fredrik Østrem, Emil Sandstø, and Cim Stordal of Cognite. Schneider has an update that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• SQL Injection - CVE-2020-7493,
• Path traversal (3) - CVE-2020-7494, CVE-2020-7495 and CVE-2020-7497, and
• Argument injection - CVE-2020-7496

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could use publicly available code to exploit the vulnerabilities to allow unauthorized write access or remote code execution.

NOTE: I briefly discussed these vulnerabilities last Saturday.

Johnson Controls Advisory


This advisory describes a cleartext storage of sensitive information vulnerability in Sensormatic Electronics (subsidiary of Johnson Controls) video management systems. The vulnerability is self-reported. Johnson Controls has new versions that mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to access credentials used for access to the application.

Tuesday, May 19, 2020

2 Advisories Published – 5-19-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Rockwell Automation and Emerson.

Rockwell Advisory


This advisory describes two vulnerabilities in the Rockwell EDS Subsystem. The vulnerabilities were reported by Sharon Brizinov and Amir Preminger (VP Research) of Claroty. Rockwell has a patch available to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper restriction of operations within the bounds of a memory buffer - CVE-2020-12038, and
• SQL injection - CVE-2020-12034

NCCIC-ICS reported that a relatively low-skilled attacker on an adjacent network could exploit the vulnerabilities to  lead to a denial-of-service condition.

Emerson Advisory


This advisory describes three vulnerabilities in the Emerson OpenEnterprise SCADA Software. The vulnerabilities were reported by Roman Lozko of Kaspersky. Emerson has an upgrade that mitigates the vulnerabilities. There is no indication that Lozko has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Missing authentication for critical function - CVE-2020-10640,
• Improper ownership management - CVE-2020-10632, and
• Inadequate encryption strength - CVE-2020-10636

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker access to OpenEnterprise configuration services or access passwords for OpenEnterprise user accounts.

Saturday, May 16, 2020

Public ICS Disclosures – Week of 5-9-20


This week we have five vendor disclosures for products from Schneider (4) and Rockwell as well as six vendor updates from Schneider (5) and Siemens. We also have two researcher reports of vulnerabilities in products from Advantech.

Schneider Advisories


Schneider published an advisory describing a weak password requirement vulnerability in their Pro-face GP-Pro EX Programming Software product. The vulnerability was reported by Kirill Kruglov of Kaspersky Labs. Schneider has a new version that mitigates the vulnerability. There is no indication that Krublov has been provided an opportunity to verify the efficacy of the fix.


Schneider published an advisory describing a use of hard-coded credentials vulnerability in their Vijeo Designer Basic and Vijeo Designer software products. The vulnerability was reported by Jie Chen of NSFOCUS. Schneider has a HotFix available to mitigate the vulnerability. There is no indication that Jie has been provided an opportunity to verify the efficacy of the fix.


Schneider published an advisory describing two vulnerabilities in their U.motion servers and touch panel products. The vulnerabilities were reported by Rgod and Zhu Jiaqi. Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper access control - CVE-2020-7499, and
• SQL injection - CVE-2020-7500


Schneider published an advisory describing five vulnerabilities in their EcoStruxure™ Operator Terminal Expert product. The vulnerabilities were reported by Steven Seeley and Chris Anastasio of Incite Team, Sharon Brizinov and Amir Preminger of Claroty Research via the Zero Day Initiative (see here, here, and here), and Fredrik Østrem, Emil Sandstø, and Cim Stordal of Cognite. Schneider has a new version that mitigates four of the five vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• SQL command injection - CVE-2020-7493,
• Path traversal (3) - CVE-2020-7494, CVE-2020-7495, and CVE-2020-7497, and
• Argument injection or modification - CVE-2020-7496

Rockwell Advisory


Rockwell published an advisory describing five vulnerabilities in multiple Rockwell Automation software products. These are third-party vulnerabilities from OSIsoft components used in the Rockwell products. These vulnerabilities are self-identified. Rockwell provides workarounds to mitigate the vulnerabilities.

The five reported vulnerabilities are:

• Local privilege escalation via uncontrolled search path element - CVE-2020-10610,
• Local privilege escalation via improper verification of cryptographic key - CVE-2020-10608,
• Local privilege escalation via incorrect default permissions - CVE-2020-10606,
• Null pointer dereference - CVE-2020-10600, and
• Use of out-of-range pointer offset may lead to remote code execution - CVE-2020-10645

NOTE: These are five of the ten vulnerabilities in the OSIsoft PI System that were reported by NCCIC-ICS earlier this week. The fact that this Rockwell Advisory was published on the same day as the NCCIC-ICS advisory indicates that there was pre-disclosure coordination between OSIsoft and Rockwell, good show.

Advantech Advisories


The Zero Day Initiative published advisories (see links below) describing two vulnerabilities in Advantech WebAccess Node. ZDI published the two advisories as 0-day notifications under their 120-day response rule. NCCIC-ICS was reported involved in the coordination of these vulnerabilities. The vulnerabilities were reported by Z0mb1E.

The two reported vulnerabilities are:

• DATACORE Stack-based Buffer Overflow Remote Code Execution Vulnerability - ZDI-20-654, and
• Incorrect Permission Assignment Privilege Escalation Vulnerability - ZDI-20-655

Schneider Updates


Schneider published an update for the Urgent/11 advisory that was originally published on August 11th, 2019 and most recently updated on April 14th, 2020. The new information includes updated mitigation information for:

• Modicon Network Option Switch,
• Modicon X80 - I/O Drop Adapters,
• Modicon Quantum 140 CRA,
• Modicon Quantum Head 140 CRP,
• Modicon Quantum Ethernet DIO network module - 140NOC78x00 (C),
• SCD6000 Industrial RTU, and
• Pro-face HMI -GP4000H/R/E Series


Schneider published an update for their Andover Continuum System advisory that was originally published on March 10th, 2020 and most recently updated on April 14th, 2020. The new information includes minor updates to overview, vulnerability details, and product information for clarification.


Schneider published an update for their Embedded Web Servers for Modicon advisory that was originally published in November 2018 and most recently updated November 27th, 2019. The new information includes a corrected CVSS vector for CVE-2018-7812.


Schneider published an update for their Modicon Controllers advisory that was originally published on May 14th, 2019 and most recently updated on December 10th, 2019. The new information includes updated fix version information for CVE-2018-7857.


Schneider published an update for their Legacy Triconex advisory that was originally published on April 14th, 2020. Unfortunately, the link on the Schneider web site takes one to the original version of the advisory.

Siemens Update


Siemens published an update for their GNU/Linux advisory that was originally published on November 27th, 2018 and most recently updated on April 14th, 2020. The new information includes the addition of the following CVE’s:

• CVE-2019-9674,
• CVE-2019-18348,
• CVE-2019-20636,
• CVE-2020-8492,
• CVE-2020-11565,
• CVE-2020-11655, and
• CVE-2020-11656

Saturday, April 11, 2020

Public ICS Disclosures -Week of 4-4-20


This week we have three vendor disclosures for products from B&R Automation, Moxa and Rockwell Automation. There are also two sets of researcher reports for products from Advantech and Universal Robots.

B&R Advisory


B&R published an advisory describing three vulnerabilities in their Automation Studio. The vulnerabilities were reported by Yehuda Anikster and Amir Preminger from Claroty. B&R has updates that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Privilege escalation – CVE-2019-19100;
• Incomplete communication encryption and validation CVE-2019-19101;
Zip Slip vulnerability (third-party vulnerability) CVE-2019-19102

Moxa Advisory


Moxa published an advisory on the kr00k vulnerability in their products. They report that none of their products are affected.

NOTE: Negative reports about 3rd party vulnerabilities are just as important as reporting an active vulnerability in a product.

Rockwell Advisory


Rockwell published an advisory describing a file permission vulnerability in their Current Program Updater software. The vulnerability was reported by Reid Wightman from Dragos. Rockwell has new versions that mitigate the vulnerability. There is no indication that Reid has been provided an opportunity to verify the efficacy of the fix.

NOTE: Rockwell is reporting a 2017 CVE (CVE-2017-5176) for this vulnerability. That vulnerability was reported by ICS-CERT on March 21st, 2017. If NCCIC-ICS were to pick up this advisory it would probably be as an update to that earlier advisory.

Advantech Reports


The Zero Day Initiative published five related reports (here, here, here, here, and here) for 0-day arbitrary file deletion vulnerabilities in the Advantech WebAccess program. The vulnerabilities were reported by Natnael Samson. ZDI reports that it has reported all five vulnerabilities to Advantech and ICS-CERT (their naming not mine) noting: “The vendor communicated that they will rely on existing measures and will add no amendments to the code.”

Universal Robots Reports


Aliasrobotics published four reports of vulnerabilities for products from Universal Robots. The vulnerabilities were reported by rvd-bot, bedieber and bbreilin. Aliasrobotics reportedly contacted Universal Robots about these vulnerabilities but has received no replies.

The four reported vulnerabilities are (links are to github pages which include proof-of-concept exploit code):

• Missing encryption of sensitive data - CVE-2020-10267;
• Missing authentication for critical function - CVE-2020-10265;
• Insufficient verification of data authenticity - CVE-2020-10266; and
• Exposure of sensitive information to unauthorized actor - CVE-2020-10264

Thursday, February 20, 2020

4 Advisories Published – 2-20-20


Today the CISA NCCIC-ICS published four control system security advisories for products from Auto-Maskin, Honeywell, Rockwell Automation and B&R Industrial Automation.

Auto-Maskin Advisory


This advisory describes six vulnerabilities in the Auto-Maskin RP 210E Remote Panels, DCU 210E Control Units, and Marine Observer Pro (Android App). The vulnerability is apparently self-reported. Auto-Maskin has new firmware that mitigates the vulnerability.

The six reported vulnerabilities are:

• Cleartext transmission of sensitive information (2) - CVE-2018-5402 and CVE-2018-5401;
• Origin validation error - CVE-2018-5400;
• Use of hard-coded credentials - CVE-2018-5399;
• Weak password recovery mechanism for forgotten password - CVE-2019-6560; and
• Weak password requirements - CVE-2019-6558

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote attacker to gain root access to the underlying operating system of the device and may allow read/write access.

Honeywell Advisory


This advisory describes two vulnerabilities in the Honeywell NOTI-FIRE-NET Web Server (NWS-3). The vulnerabilities were reported by Gjoko Krstikj. Honeywell has a firmware update that mitigates the vulenrabilities. There is no indication that Krstiki has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Authentication bypass by capture-replay - CVE-2020-6972; and
• Path traversal - CVE-2020-6974

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to bypass web server authentication methods.

Rockwell Advisory


This advisory describes a deserialization of untrusted data vulnerability in the Rockwell FactoryTalk Diagnostics. The vulnerability was reported by rgod via the Zero Day Initiative. Rockwell has provided generic workarounds pending the development of updated software.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow a remote unauthenticated attacker to execute arbitrary code with SYSTEM level privileges.

B&R Advisory


This advisory describes an improper authorization vulnerability in the SNMP implementation in the B&R Automation Studio and Automation Runtime. The vulnerability was reported by Yehuda Anikster and Amir Preminger of Claroty. B&R is not able to fix the underlying SNMP vulnerability and has provided generic workarounds.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote attacker to modify the configuration of affected devices.

Saturday, August 17, 2019

Public ICS Disclosures – Week of 08-10-19


This week we have eight vendor notifications from Schneider (7) and Siemens; updates for four previouls published advisories from Schneider (2) and Siemens (2); as well as two exploit reports for previously published vulnerabilities in products from Wind River, and Cisco.

Schneider Advisories


Magelis Advisory

Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability in their Magelis HMI Panel products. The vulnerability was reported by VAPT Team. Schneider provides generic workarounds to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Modicon 340 Advisory

Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability in their Modicon M340 controllers. The vulnerability was reported by VAPT Team. Schneider provides generic workarounds to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Modicon Advisory

Schneider published an advisory describing three improper check for unusual or exceptional conditions vulnerabilities in their Modicon Ethernet / Serial RTU Modules. The vulnerability was reported by VAPT Team. Schneider provides generic workarounds to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

SoMachine Advisory

Schneider published an advisory describing an untrusted search path vulnerability in their SoMachine HVAC. The vulnerability was reported by Yongjun Liu of the nsfocus security team. Schneider has a new version that mitigates the vulnerability. There is no indiction that Yonguin has been provided an opportunity to verify the efficacy of the fix.

TelevisGo Advisory

Schneider published an advisory describing 22 vulnerabilities in the third party UltraVNC (remote accesss) software component embedded within the TelevisGo product. The vulnerabilities were reported by Kaspersky Labs. Schneider has a hot-fix available that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The 22 reported vulnerabilities are:

Buffer errors (9) - CVE-2019-8258, CVE-2018-15361, CVE-2019-8262, CVE-2019-8263, CVE-2019-8269, CVE-2019-8271, CVE-2019-8273, CVE-2019-8274, and CVE-2019-8276;
Resource management errors (2) - CVE-2019-8259, and CVE-2019-8277;
Out-of-bounds read (8) - CVE-2019-8260, CVE-2019-8261, CVE-2019-8280, CVE-2019-8264, CVE-2019-8265, CVE-2019-8266, CVE-2019-8267, and CVE-2019-8270;
Incorrect calculation (2) - CVE-2019-8268, CVE-2019-8272; and
Improper access control - CVE-2019-8275.

Software Update Service Advisory

Schneider published an advisory describing a deserialization of trusted data vulnerability in their Software Update (SESU) SUT Service. The vulnerability was reported by Amir Preminger of Claroty. Schneider has a new version that mitigates the vulnerability. There is no indication that Preminger has been provided an opportunity to verify the efficacy of the fix.

spaceLYnk Advisory


Schneider published an advisory describing an authentication vulnerability in their  spaceLYnk and Wiser for KNX controllers. The vulnerability was reported by Sumedt Jitpukdebodin. Schneider has new versions that mitigate the vulnreabilty. There is no indication that Jitpukdebodin has been provided an opportunity to verify the efficacy of the fix.

Schneider Updates


Modicon Controllers Update

Schneider published an update that was originally published on May 14th, 2019.  New information includes:
Added mitigation measures for M340;
Added four new vulnerabilities (links for reports w/exploits from Talos):
Denial of service vulnerability - CVE-2019-6809;
Denial of service vulnerability - CVE-2019-6828;
Denial of service vulnerability - CVE-2019-6829; and
Denial of service vulnerability - CVE-2019-6830

SCADAPack Update

Schneider published an update for an advisory that was originally published on May 24th, 2017. New information includes:

Updated researcher acknowledgement section;
Corrected CVE ID from CVE-2017-6028 to CVE-2017-6034; and
Corrected vulnerability description

Siemens Advisory


Siemens published an advisory describing two vulnerabilities in their SIMATIC S7-1200 and SIMATIC
S7-1500 CPU families.  The vulnerabilities were reported by Eli Biham, Sara Bitan, Aviad Carmel, and Alon Dankner, Uriel Malin, and Avishai Woo. Siemens has generic workarounds that mitigate the vulenrabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Man-in-the-middle vulnerability - CVE-2019-10929; and
Code change vulnerability - CVE-2019-10943

Siemens Updates


ZombieLoad Update

Siemens published an update for an advisory that was originally published on July 9th, 2019. New information includes:

SIMATIC IPCs 427D, 477D, 627D, 627E, 647D, 647E, 677D, 677E, 827D, 847D, 847E; and
FieldPG M6

GNU/Linux Update

Siemens published an update for an advisory that was originally published on November 27th, 2019. New information includes:

Added CVE-2018-19591, CVE-2019-11360, CVE-2019-13272; and
Moved CVE2018-16862 from buildtime to runtime relevant

Cisco Exploit


Angelo Ruwantha published a Metasploit module for a vulnerability in the Cisco Adaptive Security Appliance; Cisco published an advisory on this vulnerability on June 6thy, 2018. NCCIC-ICS published an advisory for Rockwell Automation Allen-Bradley Stratix 5950 listing this vulnerability.

WindRiver (Urgent/11) Exploit


Zhou Yu published an exploit for an integer overflow vulnerability in the Wind River VxWorks (one of the Urgent/11 vulnerabilities).

 
/* Use this with templates/template-twocol.html */