Showing posts with label Applied Risk. Show all posts
Showing posts with label Applied Risk. Show all posts

Tuesday, April 13, 2021

15 Advisories Published – 4-13-21

Today CISA’s NCCIC-ICS published 15 control systems security advisories for products Siemens (12), JTEKT, Advantech, and Schneider Electric. One of the Siemens advisories also affects products from Milestone and another also affects products from PKE.

Milestone Advisory

This advisory describes a use of hard-coded cryptographic key in the Siemens Siveillance (Milestone) Video Open Network Bridge (ONVIF). The vulnerability was reported by Milestone PSIRT. Siemens has a hot fix and Milestone has an update to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an authenticated remote attacker to retrieve and decrypt all user credentials stored on the ONVIF server.

Nucleus Advisory #1

This advisory describes a use of insufficiently random variables vulnerability in the Siemens Nucleus DNS module. This is one of the NAME:WRECK DNS vulnerabilities reported by Forescout and JSOF. Siemens has generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to poison the DNS cache or spoof DNS resolving.

SIMOTICS Advisory

This advisory describes four vulnerabilities in the Siemens SIMOTICS CONNECT 400. The vulnerabilities were self-reported. These are NAME:WRECK vulnerabilities in the third-party Mentor DNS Module. Siemens has a new version that mitigates the vulnerabilities.

The four reported vulnerabilities are:

• Improper null termination - CVE-2020-27736,

• Out-of-bounds read - CVE-2020-27737, and

• Access of memory location after end of buffer - CVE-2020-27738 and CVE-2021-25677

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to poison the DNS cache or spoof DNS resolving.

Tecnomatix Advisory

This advisory describes an out-of-bounds write in the Siemens Tecnomatix RobotExpert. The vulnerability was reported by Francis Provencher via the Zero Day Initiative. Siemens has a new version that mitigates the vulnerability. There is no indication that Provencher has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow remote code execution.

TIM Advisory

This advisory describes 14 vulnerabilities in the Siemens TIM 4R-IE. This is a third-party vulnerability (ntp.d in SNTP). The vulnerabilities are self-reported.

The 14 reported vulnerabilities are:

• Incorrect type conversion or cast - CVE-2015-5219,

• Improper input validation (4) - CVE-2015-7855 (exploit), CVE-2015-7705, CVE-2015-8138, and CVE-2016-1547,

• Improper authentication (2) - CVE-2015-7871 and CVE-2016-4953

• Security features - CVE-2015-7973,

• Null pointer dereference - CVE-2015-7977,

• Data processing errors (2) - CVE-2015-7979 and CVE-2016-1548,

• Exposure of sensitive information to an unauthorized actor - CVE-2016-1550, and

• Race condition - CVE-2016-4954

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to compromise the confidentiality, integrity, and availability of the device.

PKE Advisory

This advisory describes twelve vulnerabilities in the Siemens (and PKE) Control Center Server (CCS). The vulnerabilities were reported by Raphaƫl Rigo of Airbus Security Lab. Siemens (and PKE) has new versions that mitigate the vulnerabilities. There is no indication that Rigo has been provided an opportunity to verify the efficacy of the fix.

The 12 reported vulnerabilities are:

• Cleartext storage of sensitive information in GUI - CVE-2019-13947,

• Improper authentication (2) - CVE-2019-18337 and CVE-2019-18341

• Relative path traversal - CVE-2019-18338,

• Use of a broken or risky cryptographic algorithm - CVE-2019-18340,

• Exposed dangerous method or function - CVE-2019-18342,

• Path traversal - CVE-2019-19290,

• Cleartext storage in a file or on a disk - CVE-2019-19291,

• SQL Injection - CVE-2019-19292,

• Cross-site scripting (2) - CVE-2019-19293 and CVE-2019-19294, and

• Insufficient logging - CVE-2019-19295

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to read and write arbitrary files and sensitive data and execute commands and arbitrary code.

NOTE: These vulnerabilities were removed from earlier Siemens Advisories, SSA-761617 and SSA-844761.

LOGO! Advisory

This advisory describes two vulnerabilities in the Siemens LOGO! engineering software products. The vulnerabilities were reported by Mashav Sapir from Claroty. Siemens provides generic workarounds to mitigate the vulnerabilities.

The two reported vulnerabilities are:

• Path traversal - CVE-2020-25243, and

• Uncontrolled search path element - CVE-2020-25244

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a local attacker to take over the system where the software is installed.

NOTE: Someone slipped up on the listing of ‘Equipment’ and ‘Vulnerability’ in the ‘Executive Summary’ section of the advisory.

SINEMA Advisory

This advisory describes two vulnerabilities in the Siemens SINEMA Remote Connect Server. These are third-party vulnerabilities (libxml2). Siemens has a new version that mitigates the vulnerabilities.

The two reported vulnerabilities are:

• Missing release of resource after effective lifetime - CVE-2019-19956, and

• Infinite loop - CVE-2020-7595

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to cause a memory leak or an infinite loop situation resulting in a denial-of-service condition.

SCALANCE Advisory

This advisory describes two vulnerabilities in the Siemens Web Server of SCALANCE X200. The vulnerabilities are self-reported. Siemens has a new version that mitigates the vulnerabilities.

The two reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2021-25668, and

• Stack-based buffer overflow - CVE-2021-25669

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to cause a buffer overflow condition resulting in remote code execution.

Solid Edge Advisory

This advisory describes five vulnerabilities in the Siemens Solid Edge software tools. The vulnerabilities were reported by Francis Provencher and rgod via ZDI. Siemens has updates that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Out-of-bounds write - CVE-2020-28385, CVE-2021-25678, CVE-2021-27380,

• Untrusted pointer dereference - CVE-2020-26997, and

• Stack-based buffer overflow - CVE-2021-27382

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerabilities to lead to a crash, arbitrary code execution, or data extraction on the target host system.

Nucleus Advisory #2

This advisory describes two infinite loop vulnerabilities in the Siemens Nucleus products. The vulnerabilities were self-reported. Siemens has a new version for one of the affected products that mitigates the vulnerabilities.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to cause a denial-of-service condition.

Nucleus Advisory #3

This advisory describes two vulnerabilities in the Siemens Nucleus DNS module. These are two of the NAME:WRECK DNS vulnerabilities reported by Forescout and JSOF. Siemens provides generic work arounds to mitigate the vulnerabilities.

The two reported vulnerabilities are:

• Out-of-bounds write - CVE-2020-15795, and

• Use of out-of-range pointer offset - CVE-2020-27009

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a denial-of-service condition or for the execution of code remotely.

NOTE: There were two additional Siemens’ advisories published today that were not covered by NCCIC-ICS. If they are not covered on Thursday, I will address them on Saturday.

JTEKT Advisory

This advisory describes an improper resource shutdown or release vulnerability in the JTEKT TOYOPUC products. The vulnerability was reported by Younes Dragoni from Nozomi Networks. JTEKT has provided generic mitigation measures.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an unauthorized user to stop Ethernet communications between devices from being established.

Advantech Advisory

This advisory describes an incorrect permission assignment for critical resources in the Advantech WebAccess/SCADA. The vulnerability was reported by Chizuru Toyama of TXOne IoT/ICS Security Research Labs of Trend Micro. Advantech has a new version that mitigates the vulnerability. There is no indication that Toyama has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to login as an ‘admin’ to fully control the system.

Schneider Advisory

This advisory describes an improper restriction of XML external entity reference vulnerability in the Schneider SoMachine Basic products. The vulnerability was reported by Gjoko Krstikj of Applied Risk. Schneider has a new product that replaces the affected product and has updated the mitigation measures.

NOTE 1: This is actually based upon an update to a Schneider advisory that was published on May 22nd, 2018.

NOTE 2: Schneider also published two advisories and two other updates today. If they are not covered by NCCIC-ICS on Thursday, I will address them here on Saturday.

Tuesday, February 9, 2021

10 Advisories Published – 2-9-21

Today CISA’s NCCIC-ICS published ten control system security advisories for products from Siemens (8), Advantech, and GE Digital. NCCIC-ICS also published 12 advisory updates for products from Siemens that I will cover in a separate post tomorrow.

DIGSI 4 Advisory

This advisory describes an incorrect default permissions vulnerability in the Siemens DIGSI 4 product. The vulnerability was reported by Rich Davy from ECSC Group. Siemens has newer versions that mitigate the vulnerability. There is no indication that Davy has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow a low privileged attacker to execute arbitrary code with SYSTEM privileges.

WinCC Advisory

This advisory describes an authentication bypass using an alternate path or channel vulnerability in the Siemens WinCC Graphics Designer. The vulnerability was reported by Enrique Murias Fernandez from Tecdesoft Automation. Siemens has an update that mitigates the vulnerability. There is no indication that Fernandez has been provided with an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker unauthenticated access to protected files.

SIMARIS Advisory

This advisory describes an incorrect default permissions vulnerability in the Siemens SIMARIS configuration electrical planning software. The vulnerability was reported by Rich Davy from ECSC Group. Siemens has provided generic workarounds for the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to gain persistence or escalate privileges within the system.

SCALANCE Advisory

This advisory describes an allocation of resources without limits or throttling in the Siemens SCALANCE W780 and W740 family. The vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to cause a denial-of-service condition.

JT2Go Advisory

This advisory describes 21 vulnerabilities in the Siemens JT2Go and Teamcenter Visualization products. The vulnerabilities were reported by Michael DePlante (@izobashi), Francis Provencher {PRL}, and rgod via the Zero Day Initiative. Siemens has updates available that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The 21 reported vulnerabilities are:

• Out-of-bounds read (7) - CVE-2020-26998, CVE-2020-26999, CVE-2020-27002, CVE-2020-27004, CVE-2020-27007, CVE-2020-27008, and CVE-2020-28394,

• Improper restriction of operations within the bounds of a memory buffer (3) - CVE-2020-27000, CVE-2020-27006, and CVE-2021-25174,

• Stack-based buffer overflow (3) - CVE-2020-27001, CVE-2020-26989, and CVE-2021-25178,

• Untrusted pointer dereference (3) - CVE-2020-27003, CVE-2020-26991, and CVE-2021-25176,

• Out-of-bounds write - CVE-2020-27005,

• Type confusion (2) - CVE-2020-26990 and CVE-2021-25177,

• Incorrect type conversion or cast - CVE-2021-25175,

• Memory allocation with excessive size value - CVE-2021-25173

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to lead to arbitrary code execution.

TIA Advisory

This advisory describes an improper access control vulnerability in the Siemens TIA Portal and PCS neo products. The vulnerability was reported [link added 2-10-21 08:11 EST] by Will Dormann from CERT Coordination Center. Siemens has an update that mitigates the vulnerability. There is no indication that Dormann has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow local users to escalate privileges and execute code as a local SYSTEM user.

RUGGEDCOM Advisory

This advisory describes six vulnerabilities in the Siemens RUGGEDCOM ROX IIB products. Siemens is self-reporting these vulnerabilities. Siemens has an update that mitigates the vulnerabilities.

• Improper input validation - CVE-2018-12404,

• Null pointer dereference - CVE-2018-18508,

• Out-of-bounds write - CVE-2019-11745,

• Insufficient verification of data authenticity - CVE-2019-17006,

• Improper certificate validation - CVE-2019-17007, and

• Out-of-bounds read - CVE-2020-1763

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow the decryption of encrypted content, possible code execution, or cause a system crash, resulting in a denial-of-service condition.

SINEMA Advisory

This advisory describes a path traversal vulnerability in the Siemens SINEMA Server and SINEC NMS products. The vulnerability was reported by rgod via ZDI. Siemens has a new version that mitigates the vulnerability. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to  allow arbitrary code execution on an affected system.

Advantech Advisory

This advisory describes four vulnerabilities in the Advantech iView device management application. The vulnerability was reported by Anonymous and rgod via ZDI, and William Vu of Rapid7. Advantech has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• SQL injection (2) - CVE-2021-22654 and CVE-2021-22658,

• Path traversal - CVE-2021-22656, and

• Missing authentication for critical function - CVE-2021-22652

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to disclose information, escalate privileges to Administrator, perform an arbitrary file read, and remotely execute commands.

GE Digital Advisory

This advisory describes two incorrect permission assignment for critical resource vulnerability for the GE HMI/SCADA iFIX. The vulnerabilities were reported by William Knowles of Applied Risk. The GE Digital advisory also credits Sharon Brizinov of Claroty for reporting the three undescribed vulnerabilities, only one of which is apparently referenced in the NCCIC-ICS advisory. The Applied Risk advisory lists two vulnerabilities with significantly different CVSS v3 base scores; 7.8 for the Applied Risk advisory and 6.1 for the NCCIC-ICS advisory with minor differences in the vector strings.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to escalate their privileges.

NOTE: I briefly discussed the GE Digital advisory this last weekend.

Other Siemens Advisory

Siemens also published one more advisory today. I will discuss that this weekend.

Saturday, February 6, 2021

Public ICS Disclosure – Week of 1-30-21

This week we have four vendor disclosures from ABB, Belden, GE Digital, and Ruckus. There is also an update from Rockwell and Honeywell published an end-of-life notice.

ABB Advisory

ABB published an advisory describing a web-server denial of service vulnerability in their AC500 V2 products. The vulnerability was reported by Richard Thomas and Tom Chothia of the University of Birmingham. ABB has no mitigation measures for this vulnerability.

Belden Advisory

Belden published an advisory describing a denial of service vulnerability in the Hirschmann HiOS platform. The vulnerability was reported by the French Cybersecurity Agency (ANSSI). Belden has updates available that mitigate the vulnerability. There are no indications that the researchers have been provided an opportunity to verify the efficacy of the fix.

GE Advisory

GE published an advisory describing three unnamed vulnerabilities in their iFix HMI/SCADA product. The vulnerabilities were reported by Sharon Brizinov of Claroty and William Knowles with Applied Risk. GE has an upgrade that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Ruckus Advisory

Ruckus published an advisory describing a CLI passphrase vulnerability in their AP and ZD products. The vulnerability is apparently self-reported. No mitigation measures are described.

Rockwell Update

Rockwell published an update for the AENT Flex I/O Series B advisory that was originally published on October 12th, 2020. The new information includes adding a sixth classic buffer overflow vulnerability, CVE-2020-6088.

NOTE: Talos published a report this week covering this vulnerability. It included proof-of-concept code.

Honeywell EOL Notice

Honeywell published an end-of-life notice for their Maxpro VMS/NVR products.

Saturday, December 19, 2020

Public ICS Disclosures – Week of 12-12-20

This week we have five vendor disclosures regarding the Amnesia33 vulnerabilities. There were three vendor disclosures for the SUNBURST vulnerability. There were ten other vendor disclosures for products from ABB (3), Bosch (3), WAGO, Phoenix Contact (2), and VMware. There was one vendor update from Mitsubishi. We have seven researcher reports of vulnerabilities in products from Lantronix (2), Secomea, and Eaton (4).

Amensia33 Advisories

Braun published an advisory discussing the Amnesia33 vulnerabilities. They report that none of their ‘connected devices’ is affected.

Drager published an advisory discussing the Amnesia33 vulnerabilities. They report that their medical devices are not affected.

HMS published an advisory discussing the Amnesia33 vulnerabilities. They provide a list of their products that they have confirmed are not affected.

Johnson and Johnson published an advisory discussing the Amnesia33 vulnerabilities. They report that they are investigating the potential impact of the vulnerabilities on their product line.

Spacelabs Healthcare published an advisory discussing the Amnesia 33 vulnerabilities. They report that none of their products are affected by the vulnerabilities.

Sunburst Advisories

Drager published an advisory discussing the SUNBURST vulnerability. They report that their medical devices are not affected.

Boston Scientific published an advisory discussing the SUNBURST vulnerability. They report that their products are not affected.

Philips published an advisory discussing the SUNBURST vulnerability. They report that they are monitoring developments.

ABB Advisories

ABB published an advisory [corrected link, 12-19-20 1941 EST] describing five vulnerabilities in their Central Licensing System. The vulnerabilities were reported by William Knowles at Applied Risk. ABB has new versions that mitigate the vulnerabilities. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Information disclosure - CVE-2020-8481,

• XML external entity injection - CVE-2020-8479,

• Denial of service - CVE-2020-8475,

• Elevation of privilege - CVE-2020-8476, and

• Weak file permissions - CVE-2020-8471

 

ABB published an advisory describing eight vulnerabilities in their Symphony® Plus Historian. The vulnerabilities are self-reported. ABB has an update that mitigates the vulnerabilities.

The eight reported vulnerabilities are:

• SQL injection - CVE-2020-24673,

• Improper authorization - CVE-2020-24674,

• Weak authentication - CVE-2020-24675,

• Insecure Windows services - CVE-2020-24676 -,

• Web application security - CVE-2020-24677,

• Privilege escalation - CVE-2020-24678,

• Denial of Service - CVE-2020-24679, and

• Improper credential storage - CVE-2020-24680

 

ABB published an advisory describing nine vulnerabilities in their Symphony® Plus Operations. The vulnerabilities are self-reported. ABB has an update that mitigates the vulnerabilities.

The nine reported vulnerabilities are:

• SQL injection - CVE-2020-24673,

• Improper authorization - CVE-2020-24674,

• Weak authentication - CVE-2020-24675,

• Insecure Windows services - CVE-2020-24676 -,

• Web application security - CVE-2020-24677,

• Privilege escalation - CVE-2020-24678,

• Denial of Service - CVE-2020-24679,

• Improper credential storage - CVE-2020-24680, and

• Authentication bypass - CVE-2020-24683

Bosch Advisories

Bosch published an advisory describing a null pointer dereference vulnerability in their ctrlX Products. This is a third-party OpenSSL vulnerability. Bosch has an update that mitigates the vulnerability.

 

Bosch published an advisory describing two vulnerabilities in their Rexroth IndraMotion Products. Both vulnerabilities are third-party CODESYS vulnerabilities (CVE links below are to the respective CODESYS advisories). Bosch recommends using their ctrlX CORE product to mitigate these vulnerabilities.

The two reported vulnerabilities are:

• Uncontrolled memory allocation - CVE-2020-7052 [.PDF download link], and

• Memory Corruption - CVE-2019-5105 [.PDF download link]

NOTE: Proof-of-concept code is available for the CODESYS vulnerabilities in the respective reports from Tenable and Talos.

 

Bosch published an advisory describing six vulnerabilities in their Rexroth PRC7000. These are third-party CODESYS vulnerabilities (CVE links below are to the respective CODESYS advisories). Bosch has a new firmware version that mitigates the vulnerabilities.

The six reported vulnerabilities are:

• Memory Corruption - CVE-2019-5105 [.PDF download link] Tenable report,

• Heap-based buffer overflow - CVE-2019-18858 [.PDF download link] Tenable report,

• Unverified ownership - CVE-2019-9010 [.PDF download link] NCCIC-ICS report,

• Uncontrolled memory allocation - CVE-2019-9012 [.PDF download link] NCCIC-ICS report,

• Insufficiently protected credentials - CVE-2019-9013 [.PDF download link] NCCIC-ICS report, and

• Heap-based buffer overflow - CVE-2020-10245 [.PDF download link] Tenable report.

NOTE: The respective Tenable reports include proof-of-concept code for he CODESYS vulnerabilities;

WAGO Advisory

VDE-CERT published an advisory describing an improper neutralization of special elements in an OS command vulnerability in the WAGO I/O-Check Service. The vulnerability was reported by Uri Katz of Claroty. WAGO has a new firmware version that mitigates the vulnerability.

NOTE: The Claroty report includes a Snort rule to detect the vulnerability.

Phoenix Contact Advisories

Phoenix Contact published an advisory [.PDF download link] describing a missing initialization of resource vulnerability in their mGuard products. The vulnerability was reported by SMST Designers & Constructors. Phoenix Contact has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

 

Phoenix Contact published an advisory [.PDF download link] describing four vulnerabilities in their PLCnext Control devices. The vulnerabilities were reported by Patrick Muench, Torsten Loebner, Maurice Rothe, Pascal Keul, Melanie Tholen and Daniel Hackel of SVA Systemvertrieb Alexander GmbH. Phoenix Contact has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• XSS - CVE-2020-12517,

• Exposure of sensitive information - CVE-2020-12518,

• Improper privilege management - CVE-2020-12519, and

• Improper input validation (in the PROFINET stack) - CVE-2020-12521.

NOTE: There is no indication whether the last vulnerability is unique to the Phoenix Contact implementation of PROFINET or if it is a third-party vulnerability.

VMware Advisory

VMware published an advisory describing an improper input validation vulnerability in their  ESXi, Workstation and Fusion products. The vulnerability was reported by Lucas Leong (@_wmliang_) of the Zero Day Initiative and Murray McAllister of Insomnia Security. VMware has patches that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Mitsubishi Update

Mitsubishi published an update of their Factory Automation advisory that was  originally published on July 30th, 2020 and most recently updated on November 5th, 2020. The new information includes providing mitigation information for GT SoftGOT1000.

NOTE: NCCIC-ICS published their advisory for this vulnerability and updated it in November.

Lantronix Reports

Talos published two reports (see CVE’s below for links) for vulnerabilities in the Lantronix XPort EDGE Web Manager. These are coordinated disclosures. The reports do not mention if the vulnerabilities have been corrected.

The two reported vulnerabilities are:

• Cleartext transmission of sensitive information - CVE-2020-13528, and

• CSRF - CVE-2020-13527

Secomea Report

Tenable published a report describing two vulnerabilities in the Secomea GateManager. This is a coordinated disclosure. The Tenable report includes proof-of-concept code. Tenable does not report that Secomea has produced any mitigation measures.

The two reported vulnerabilities are:

• Cross-site scripting - CVE-2020-29021, and

• HTTP host header injection - CVE-2020-29022

Tenable notes that these will be third-party vulnerabilities in products from at least B&R Industrial Automation and perhaps other vendors as well.

Eaton Reports

The Zero Day Initiative published four reports (see ZDI numbers for links) from Francis Provencher for vulnerabilities in the Eaton EASYsoft application. This is a coordinated disclosure but ZDI is reporting these as zero-day vulnerabilities.

The four reported vulnerabilities are:

• Out-of-bounds read - ZDI-20-1443, and

• File parsing type confusion (3) - ZDI-20-1444, ZDI-20-1442, and ZDI-20-1441

Tuesday, November 3, 2020

3 Advisories Published – 11-3-20

Today the CISA NCCIC-ICS published three control system security advisories for products from ARC Informatique, NEXCOM, and WAGO.

ARC Advisory

This advisory describes three vulnerabilities in the ARC PcVue. The vulnerabilities were reported by Sergey Temnikov and Andrey Muravitsky of Kaspersky Lab. ARC has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Deserialization of untrusted data - CVE-2020-26867,

• Access to critical private variable via public method - CVE-2020-26868, and

• Information exposure of sensitive information to an unauthorized actor - CVE-2020-26869

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to execute arbitrary code, expose sensitive data, and prevent legitimate users from connecting to PcVue services.

NEXCOM Advisory

This advisory describes two vulnerabilities in the NEXCOM NIO 50 IoT Gateway. The vulnerabilities were reported by the Zero Day Initiative. NEXCOM no longer supports the NIO 50 product.

The two reported vulnerabilities are:

• Improper input validation - CVE-2020-25151, and

• Cleartext transmission of sensitive information - CVE-2020-25155

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to view sensitive information and cause a denial-of-service condition due to improper input validation.

WAGO Advisory

This advisory describes an uncontrolled resource consumption vulnerability. This vulnerability was reported by William Knowles of Applied Risk. WAGO has new firmware that mitigates the vulnerability. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to crash the device being accessed using a denial-of-service attack.

NOTE 1: I briefly discussed this vulnerability last Saturday.

NOTE 2: The researcher acknowledgement section of this advisory is a little confusing. William Knowles of Applied Risk reported the vulnerability via CERT@VDE.

Saturday, October 3, 2020

Public ICS Disclosures – Week of 9-26-20

This week we have ten vendor disclosures for products from WAGO (3), IBM, Bosch, B&R Automation (2), Moxa, BD, and Philips.

WAGO Advisories

CERT-VDE published an advisory describing an improper authentication and authorization vulnerability in the WAGO 750-8XX series PLCs. The vulnerability was reported by Maxim Rupp. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

CERT-VDE published an advisory describing an improper authentication and access control vulnerability in the WAGO 750-36X and WAGO 750-8XX series PLCs. The vulnerability was reported by Maxim Rupp. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

CERT-VDE published an advisory describing an improper neutralization of input during web page generation vulnerability in the Web-UI for WAGO 750-88X and WAGO 750-89X series PLCs. This vulnerability was reported by Secuninja. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Secuninja has been provided an opportunity to verify the efficacy of the fix.

IBM Advisory

IBM published an advisory describing an authentication bypass vulnerability in their Maximo Asset Management product. The vulnerability is being self-reported. IBM has updates that mitigate the vulnerability.

Bosch Advisory

Bosch published an advisory describing three vulnerabilities in their PRAESIDEO Network Controller and the PRAESENSA System Controller products. The vulnerabilities were reported by Gjoko Krstic of Applied Risk. Bosch has software updates for the supported products that mitigate the vulnerabilities. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Cross-site scripting - CVE-2020-6777,

• Cross-site request forgery - CVE-2020-6776, and

• Nonce reuse attack - CVE-2020-15688

NOTE: The last is a third-party vulnerability (GoAhead web server).

B&R Advisories

B&R published an advisory describing four vulnerabilities in their GateManager product. These vulnerabilities were reported by NCCIC-ICS on July 28th as being for the Secomea GateManager.

B&R published an advisory describing six vulnerabilities in their SiteManager and GateManager procucts. These vulnerabilities were reported by NCCIC-ICS last Tuesday, but the B&R advisory was not available when I published my blog post. It is not clear if the Secomea versions of these products are also affected by these vulnerabilities.

Moxa Advisory

Moxa published an advisory describing a device information leak vulnerability in their EDR-810 Series Industrial Secure Routers. The vulnerability was reported by the National Security Agency (yep, that is what the advisory says). Moxa has provided generic workarounds to mitigate the vulnerability.

BD Advisory

BD published an advisory describing a remote code execution vulnerability (CVE-2020-1147) in a third-party component (Microsoft) of a long list of their products. BD is working on testing and validation of the Microsoft patch.

Philips Advisory

Philips published an advisory describing a privilege elevation vulnerability (CVE-220-1472) in a third-party component (Microsoft) of an undisclosed number of Philips products. No mitigation information has been provided.

Thursday, July 2, 2020

3 Advisories and 1 Update Published – 7-2-20


Today the CISA NCCIC-ICS published two control system security advisories for products from ABB and Nortek and a medical device security advisory for products from OpenClinic. They also updated an advisory for products from Johnson Controls.

ABB Advisory


This advisory describes a cross-site scripting vulnerability in the ABB System 800xA Information Manager. The vulnerability was reported by William Knowles of Applied Risk. ABB has versions that mitigate the vulnerability. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to inject and execute arbitrary code on the information manager server.

NOTE 1: An interesting process safety note can be found in the ABB Advisory:

“Under certain conditions exploits of this vulnerability may affect the integrity of safety functions in System 800xA. This is however prevented if the Access Enable key in the AC800MHI is turned Off (“disabled”) and Access Level for the variables in the safety applications are configured to ‘Read Only’ or ‘Confirm and Access Enable’”

NOTE 2: I briefly discussed this vulnerability back in April.

Nortek Advisory


This advisory describes five vulnerabilities in the Nortek Linear eMerge 50P/5000P. The vulnerabilities were reported by Gjoko of Applied Risk. Nortek has a new version that mitigates the vulnerabilities. There is no indication that Gjoko has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Path traversal - CVE-2019-7267,
• Command injection - CVE-2019-7269,
• Unrestricted upload of file with dangerous type - CVE-2019-7268,
• Cross-site request forgery - CVE-2019-7270, and
• Improper authentication - CVE-2019-7266

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a remote attacker to gain full system access.

NOTE 1: The Applied Risk advisory also describes a default credentials vulnerability (CVE-2019-7271) in this product.

NOTE 2: There is at least one publicly available exploit for vulnerabilities described in this advisory.

OpenClinic Advisory


This advisory describes 12 vulnerabilities in the OpenClinic GA, an open-source integrated hospital information management system. The vulnerabilities were reported by Brian D. Hysell. NCCIC-ICS has not received any confirmation of mitigation measures from OpenClinic GA.

The twelve reported vulnerabilities are:

• Authentication bypass using an alternate path or channel - CVE-2020-14485,
• Improper restriction of excessive authentication attempts - CVE-2020-14484,
• Improper authentication - CVE-2020-14494,
• Missing authorization - CVE-2020-14491,
• Execution with unnecessary privileges - CVE-2020-14493,
• Unrestricted upload of file with dangerous type - CVE-2020-14488,
• Path traversal - CVE-2020-14490,
• Improper authorization - CVE-2020-14486,
• Cross-site scripting - CVE-2020-14492,
• Use of unmaintained third-party components - CVE-2020-14495,
• Insufficiently protected credentials - CVE-2020-14489, and
• Hidden functionality - CVE-2020-14487

NCCIC-ICS reports that a relatively low-skilled attacker could use publicly available code to remotely exploit these vulnerabilities to allow an attacker to bypass authentication, discover restricted information, view/manipulate restricted database information, and/or execute malicious code.

Johnson Controls Update


This update provides additional information on an advisory that was originally published on June 18th, 2020. The new information includes corrected version information and mitigation measures.

NCCIC-ICS Update Listings


NCCIC-ICS did not list this latest update on either the ‘Industrial Control Systems’ or the ‘ICS-Archive’ pages. Since this has happened on two consecutive disclosure days, it would appear that this is a change in policy. Since they are still (for the time being at least) reporting this updates on their emails and TWEETS®. You can signup for their email alerts at the bottom of the landing page and/or follow their TWEETS @ICS-CERT.

Thursday, June 25, 2020

4 Advisories Published – 6-25-20


Today the CISA NCIC-ICS published three control system security advisories for products from Rockwell Automation (2) and ENTTEC. They also published a medical device security advisory for products from Philips.

FactoryTalk Advisory


This advisory describes two vulnerabilities in the Rockwell FactoryTalk View SE. The vulnerabilities were reported by Ilya Karpov and Evgeny Druzhinin of ScadaX Security. Rockwell has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Cleartext transmission of sensitive information - CVE-2020-14480, and
Weak encoding for passwords - CVE-2020-14481

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to lead to unauthorized access to server data.


FactoryTalk Services Advisory


This advisory describes an improper restriction of XML external entity reference vulnerability in the Rockwell FactoryTalk Services Platform. The vulnerability was reported by Applied Risk. Rockwell has a patch that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to lead to a denial-of-service condition and to the arbitrary reading of any local file via system level services.

NOTE: NCCIC-ICS did not publish a link to the Rockwell advisory.

ENTTEC Advisory


This advisory describes four vulnerabilities in the ENTTEC Datagate Mk2, Storm 24, Pixelator, E-Streamer Mk2 lighting control products. The vulnerabilities were reported (report includes proof-of-concept exploit code) by Mark Cross. ENTTEC has not yet offered mitigation measures for these vulnerabilities.

The four reported vulnerabilities are:

• Hard-coded cryptographic key - CVE-2019-12776,
• Cross-site scripting - CVE-2019-12774,
• Improper access control - CVE-2019-12775, and
• Improper permission assignment for critical resource - CVE-2019-12777

NCCIC-ICS reports that a relatively low-skilled attacker with remote access could use publicly available code to remotely exploit the vulnerability to allow an attacker to gain unauthorized SSH/SCP access to devices, inject malicious code, run commands with root privileges, and read, write, and execute files in system directories as any user.

Philips Advisory


This advisory describes an authentication bypass using alternate path or channel vulnerability in the Philips Ultrasound Systems. The vulnerability is self-reported. Philips has a new version that mitigates the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerability to allow a non-authenticated attacker to view or modify information. The Phillips advisory reports that it would take a relatively high-skilled attacker with local access to exploit the vulnerability.

Wednesday, June 24, 2020

3 Advisories and 5 Updates Published – 6-23-20


Yesterday the CISA NCCIC-ICS published three control system security advisories for products from ABB, Honeywell and Mitsubishi Electric. They updated five medical device security advisories for products from BD and Baxter (4).

ABB Advisory


This advisory describes an insecure storage of sensitive information vulnerability in the ABB Device Library Wizard. The vulnerability was reported by William Knowles of Applied Risk. ABB has new versions that mitigate the vulnerability. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to  allow a low-level user to escalate privileges and fully compromise the device.

Honeywell Advisory


This advisory describes two cleartext transmission of sensitive information vulnerabilities in the Honeywell ControlEdge PLC and RTU. The vulnerabilities were reported by Nikolay Sklyarenko of Kaspersky. Honeywell provides a document (login required) describing the mitigation measures for these vulnerabilities. There is no indication that Sklyarenko has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to obtain passwords and session tokens.

Mitsubishi Advisory


This advisory describes a cleartext transmission of sensitive information vulnerability in the Mitsubishi MELSEC CPU modules. The vulnerability was reported by Shunkai Zhu, Rongkuan Ma and Peng Cheng from NESC Lab. Mitsubishi provides generic mitigation measure.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow information disclosure, information tampering, unauthorized operation, or a denial-of-service condition.

NOTE: NCCIC-ICS did not publish the link to the Mitsubishi advisory.

BD Update


This update provides additional information for an advisory that was originally reported on June 18th, 2020. The new information includes the link to the BD advisory.

Sigma Spectrum Update


This update provides additional information for an advisory that was originally reported on June 18th, 2020. The new information includes the link to the Baxter advisory.

Phoenix Update


This update provides additional information for an advisory that was originally reported on June 18th, 2020. The new information includes the link to the Baxter advisory.

PrismaFlex Update


This update provides additional information for an advisory that was originally reported on June 18th, 2020. The new information includes the link to the Baxter advisories (PrismaFlex and PrisMax).

ExactaMix Update


This update provides additional information for an advisory that was originally reported on June 18th, 2020. The new information includes the link to the Baxter advisory.

Tuesday, June 2, 2020

6 Advisories and 1 Update Published – 6-2-20


Today the CISA NCCIC-ICS published six control system security advisories for products from ABB (4), GE and SWARCO Traffic Systems. They also updated an advisory for products from Inductive Automation

System 800xA Advisory


This advisory describes two incorrect default permissions vulnerabilities in the ABB System 800xA. The vulnerabilities were reported by William Knowles of Applied Risk. ABB provides generic work arounds to mitigate the vulnerabilities.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to escalate privileges, cause system functions to stop, and corrupt user applications.

NOTE: I briefly described these vulnerabilities in early April.

System 800xA Base Advisory


This advisory describes an incorrect permission assignment for critical resource vulnerability in the ABB System 800xA Base. The vulnerabilities were reported by William Knowles of Applied Risk. ABB has a new version that mitigates the vulnerabilities. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to escalate privileges and cause system functions to stop or malfunction.

NOTE: I briefly described these vulnerabilities in early April and then I discussed the ABB update later that month. The updated version is being reported by NCCIC-ICS.

System 800xA Products Advisory


This advisory describes seven incorrect default permission vulnerabilities in various ABB System 800xA products. The vulnerabilities were reported by William Knowles of Applied Risk. NCCIC-ICS reports that ABB plans to correct these vulnerabilities in a future version.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to make the system node inaccessible or tamper with runtime data in the system.

NOTE: I briefly described these vulnerabilities in early April and then I discussed the ABB update later that month. The updated version is being reported by NCCIC-ICS.

Central Licensing System Advisory


This advisory describes five vulnerabilities in the ABB Central Licensing System. The vulnerabilities were reported by William Knowles of Applied Risk. ABB has new versions that mitigate the vulnerabilities. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Information exposure - CVE-2020-8481,
• Improper restriction of XML external entity reference - CVE-2020-8479,
• Uncontrolled resource consumption - CVE-2020-8475,
• Permissions, privileges and access controls - CVE-2020-8476, and
• Improper access controls - CVE-2020-8471

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to take control of the affected system node remotely and cause an affected CLS Server node to stop or prevent legitimate access to the affected CLS Server.

I briefly reported these vulnerabilities in late April.

GE Advisory


This advisory describes a missing authentication for critical function vulnerability in the GE Grid Solutions Reason RT Clocks. The vulnerability was reported by Ehab Hussein of IOActive. GE has a new firmware version that mitigates the vulnerability. There is no indication that Hussein has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow access to sensitive information, execution of arbitrary code, and cause the device to become unresponsive.

SWARCO Advisory


This advisory describes an improper access control vulnerability in the SWARCO CPU LS4000. The vulnerability was reported by Martin Aman of ProtectEM. SWARCO has a patch that mitigates the vulnerability. There is no indication that Aman has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow access to the device and disturb operations with connected devices.

I briefly discussed this vulnerability last Saturday.

Inductive Automation Update


This update provides additional information on an advisory that was originally published on May 26th, 2020. The new information includes adding Ignition 7 Gateway to the list of affected products and providing mitigation measures for that product.

Saturday, May 23, 2020

Public ICS Disclosures – Week of 5-16-20


This week we have two vendor disclosures for products from HMS and BD. There is also a researcher report on previously disclosed vulnerabilities from OSIsoft.

HMS Advisory


HMS published an advisory describing a certificate verification vulnerability in their eCatcher product. The vulnerability was reported by TÜV Rheinland. HMS has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

BD Advisory


BD published an advisory describing two Windows Adobe Type Manager Library vulnerabilities in various BD products. BD is currently working to test and validate the appropriate Microsoft patch for these vulnerabilities.

OSIsoft Report


Applied Risk published a report on vulnerabilities in the OSIsoft PI System. These vulnerabilities were previously disclosed by NCCIC-ICS. This report provides links to the OSIsoft report on the vulnerabilities, but that report is behind a customer registration wall.

Thursday, May 14, 2020

Verifying Fixes


I got some interesting feedback on a phrase in yesterday’s post about advisories from NCCIC-ICS; in particular the common sentence in too many of my responses: “There is no indication that Knowles [substitute the name of the current security researcher reporting the vulnerability] has been provided an opportunity to verify the efficacy of the fix.”

First, I got a TWITTER® DM from a long-time reader associated with OSIsoft, the subject of one of the advisories discussed yesterday. That DM informed me that while NCCIC-ICS did not routinely comment on researcher verification efforts, the OSIsoft advisory did include such language in this instance. Unfortunately, I cannot see that advisory since it is behind a customer only firewall. In any case, it seems (see below) that OSIsoft was actively involved in allowing researcher verification of the fix reported in this instance and are to be commended for that.

This in turn led to a series of emails from folks at Applied Risk, the company reporting the OSIsoft vulnerabilities. They confirmed that OSIsoft had actively worked with them to allow verification of the fixes announced in Tuesday’s advisory. In fact, according to William Knowles, the researcher involved in the situation, OSIsoft went so far as to provide a temporary license for the software to help Applied Risk in their evaluation.

Knowles went on to say:

“Verification of fixes of course always a good thing, but it really depends on whether software access is still available.  As you’ll know, getting access to this software isn’t always easy (expensive price tags, no trials, etc), and initial exposure often comes through consultancy work in third party environments. That access is often very transient.  At that point it all depends on the institutional openness and willingness of the vendor, and furthermore, who you’re even dealing with at the vendor on an individual level, and if they have the capability of dishing out temporary licenses and links to software downloads.  That isn’t always easy; however, in the case of OSIsoft it was, as the process was encouraged from their side.”

We have seen a number of instances where ‘fixed’ vulnerabilities had to be re-fixed at a later date when it was determined that the vulnerability still existed. I noted yesterday that the 3S update published by NCCIC-ICS was apparently one of those situations. If more researchers were involved in fix verification, this problem would be greatly reduced. For the vendors involved it would also demonstrate their commitment to work with the independent researcher community in identifying and fixing security vulnerabilities.

I will continue to call out vendors when they do not support researchers in this manner. And, of course, I will give credit when it is due.

Wednesday, May 13, 2020

2 Advisories and 7 Updates Published


Yesterday the CISA NCCIC-ICS published two control system security advisories for products from OSIsoft and Eaton. They also updated previously published advisories for products from 3S, Interpeak, and Siemens (5).

OSIsoft Advisory


This advisory describes ten vulnerabilities in the OSIsoft PI System. The vulnerabilities were reported by William Knowles at Applied Risk. OSIsoft provides workarounds to mitigate the vulnerabilities. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix. Applied Risk has verified that Knowles was provided an opportunity to verify the efficacy of the fix (see https://chemical-facility-security-news.blogspot.com/2020/05/verifying-fixes.html) [5-14-20 8:00 EDT]

The ten reported vulnerabilities are:

• Uncontrolled search path element - CVE-2020-10610,
• Improper verification of cryptographic key - CVE-2020-10608,
• Incorrect default permissions - CVE-2020-10606,
• Uncaught exception - CVE-2020-10604,
• Null pointer dereference (2) - CVE-2020-10602 and CVE-2020-10600,
• Improper input validation - CVE-2019-10768,
• Cross-site scripting (2) - CVE-2020-10600 and CVE-2020-10614, and
• Insertion of sensitive information into log file - CVE-2019-18244

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to access unauthorized information, delete or modify local processes, and crash the affected device.

Eaton Advisory


This advisory describes two vulnerabilities in the Eaton Intelligent Power Manager software monitoring and management platform. The vulnerability was reported by Sivathmican Sivakumaran of Trend Micro’s Zero Day Initiative. Eaton has a new version that mitigates the vulnerability. There is no indication that Sivakumaran has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper input validation - CVE-2020-6651, and
• Incorrect privilege assignment - CVE-2020-6652

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to perform command injection or code execution and allow non-administrator users to manipulate the system configurations.

3S Update


This update provides additional information for an advisory that was originally reported on September 12th, 2019. The new information includes a link to an even newer version that more completely mitigates the vulnerability.

NOTE: This is part of the reason that advocate for the researchers that discovered the vulnerability being provided a specific opportunity to verify the efficacy of the reported fix.

Interpeak Update


This update provides additional information for the Urgent/11 advisory that was originally published on October 1st, 2019 and most recently updated on February 18th, 2020. The new information includes a link to the new Siemens Power Meters advisory that was published today.

SIPROTEC Update


This update provides additional information for an advisory that was originally published on July 9th, 2019 and most recently updated on December 10th, 2019. The new information includes affected version numbers and mitigation links for SIPROTEC 5 device types 7SS85 and 7KE85.

SINAMICS Update


This update provides additional information for an advisory that was originally published on August 15th, 2019 and most recently updated on December 10th, 2019. . The new information includes affected version numbers and mitigation links for SINAMICS SL150 V4.8.

SIMATIC Update


This update provides additional information for an advisory that was originally published on February 11th, 2020 and most recently updated on April 14th, 2020. The new information includes affected version numbers and mitigation links for SIMATIC NET PC Software.

KTK Update


This update provides additional information for an advisory that was originally published on April 14th, 2020. The new information includes the addition of the SIMATIC S7-400 H V6 CPU family to the list of affected products.

RUGGEDCOM Update


This update provides additional information for an advisory that was originally published on April 14th, 2020. The new information includes the removal of  IE/PB-Link V3 from the list of affected products.

Other Advisories


Siemens published one additional update that was not covered by NCCIC-ICS yesterday. I will address that on Saturday.

Schneider has also joined the 2nd Tuesday patch club. They published 3 new advisories and 4 updates that I will also address on Saturday.

 
/* Use this with templates/template-twocol.html */