Showing posts with label AutomationDirect. Show all posts
Showing posts with label AutomationDirect. Show all posts

Thursday, July 16, 2026

Review – 9 Advisories Published – 7-16-26

Today CISA’s NCCIC-ICS published nine control system security advisories for products from Rockwell Automation (5), SALTO, Siemens, AutomationDirect, and NASA. I also look at eight other new advisories published by Siemens this week. 

Advisories  

Rockwell Advisory #1 - This advisory describes a cross-site scripting vulnerability in the Rockwell FactoryTalk DataMosaix. 

Rockwell Advisory #2 - This advisory describes a double free vulnerability in the Rockwell Flex 5000 Adapter. 

Rockwell Advisory #3 - This advisory describes three vulnerabilities in multiple Rockwell product lines. 

Rockwell Advisory #4 - This advisory describes an improper validation of integrity check value vulnerability in the Rockwell 1756-EN2, 1756-EN3, and 1756-ENBT products. 

Rockwell Advisory #5 - This advisory describes four vulnerabilities in the Rockwell Arena product. 

SALTO Advisory - This advisory describes an authorization bypass through user-controlled key vulnerability in the SALTO ProAccess Space product. 

Siemens Advisory - This advisory describes four vulnerabilities in the Siemens SICAM 8 product line. 

AutomationDirect Advisory - This advisory describes six vulnerabilities in the AutomationDirect Productivity Suite. 

NASA Advisory  This advisory describes a NULL pointer dereference vulnerability in the NASA Core Flight System (cFS) Health & Safety (HS) Application. 


For more information on these advisories, as well as a listing of eight other Siemens advisories published this week, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/9-advisories-published-7-16-23 - subscription required. 

Thursday, January 22, 2026

Review – 8 Advisories and 2 Updates Published – 1-22-26

Today CISA’s NCCIC-ICS published eight control system security advisories for products from EVMAPA, Delta Electronics, Hubitat, Weintek, Johnson Controls, Rockwell Automation, and Schneider Electric. They also updated two advisories for products from Hitachi Energy, and Axis Communications.

Advisories

EVMAPA Advisory - This advisory describes three vulnerabilities in the EVMAPA vehicle charging software.

Delta Advisory - This advisory describes a command injection vulnerability in the Delta DIAView product.

NOTE: I briefly discussed this vulnerability on January 17th, 2026.

Hubitat Advisory - This advisory describes an authorization bypass through user controlled key vulnerability Hubitat Elevation Hubs (home automation hubs).

Weintek Advisory - This advisory describes two vulnerabilities in the Weintek cMT X Series HMI EasyWeb Service.

Johnson Controls Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Johnson Control iSTAR Configuration Utility (ICU) tool.

Rockwell Advisory - This advisory describes an improper validation of specified quantity in input vulnerability in the Rockwell CompactLogix 5370 PLCs.

AutomationDirect Advisory - This advisory describes two vulnerabilities in the AutomationDirect CLICK Programmable Logic Controller.

Schneider Advisory - This advisory that describes an incorrect default permissions vulnerability in their EcoStruxure Process Expert products

NOTE: I briefly discussed this vulnerability on January 17th, 2026.

Updates

Hitachi Energy Update - This update provides additional information on the Relion 670/650 advisory that was originally published on July 3rd, 2025, and most recently updated on August 28th, 2025.

NOTE: I briefly discussed this updated information on December 14th, 2025.

Axis Update - This update provides additional information on the Camera Station Pro advisory that was originally published on December 18th, 2025, and most recently updated on January 15th, 2026.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-and-2-updates-published-68c - subscription required.

Thursday, October 23, 2025

Review – 5 Advisories and 3 Updates Published –

Today CISA’s NCCIC-ICS published four control system and one medical device security advisory for products from Delta Electronics, Veeder-Root, ASKI Energy, AutomationDirect, and NIHON KOHDEN. They also published updates for advisories for products from Schneider (2) and Hitachi Energy.

Advisories

Delta Advisory - This advisory describes two stack-based buffer overflow vulnerabilities in the Delta ASDA-Soft servo software.

NOTE: I briefly discussed these vulnerabilities on Sunday.

Veeder-Root Advisory - This advisory describes two vulnerabilities in the Veeder-Root TLS4B Automatic Tank Gauge System.

ASKI Advisory - This advisory describes a missing authentication for critical function vulnerability in the ASKI ALS-mini-S4/S8 IP controllers.

NOTE: ASKI Energy is a subsidiary of ABB.

AutomationDirect Advisory - This advisory describes nine vulnerabilities in the AutomationDirect Productivity PLCs.

NIHON KOHDEN Advisory - This advisory describes a NULL pointer dereference vulnerability in the NIHON KOHDEN Central Monitor CNS-6201.

Updates

Schneider Update # 1 - This update provides additional information on the Altivar Products advisory that was originally published on September 16th, 2025.

Schneider Update #2 - This update provides additional information on the EcoStruxure advisory that was originally published on February 6th, 2025, and most recently updated on July 15th, 2025.

Hitachi Energy Update - This update provides additional information on the MACH SCM advisory that was originally published on April 25th, 2024.

NOTE: I briefly discussed this updated information on October 5th, 2025.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-3-updates-published-3e1 - subscription required.


Tuesday, September 23, 2025

Review – 4 Advisories and 2 Updates Published – 9-23-25

Today CISA’s NCCIC-ICS published four control system security advisories for products from Carrier (Viessmann), Schneider Electric, Mitsubishi Electric, and AutomationDirect. They also updated two advisories for products from Hitachi Energy.

Advisories

Carrier Advisory - This advisory describes two vulnerabilities in the Viessmann Vitogate 300.

Schneider Advisory - This advisory describes a link following vulnerability in the Schneider software update (SESU) service.

Mitsubishi Advisory - This advisory describes an improper handling of lengthy parameter inconsistency vulnerability in the Mitsubishi MELSEC-Q Series CPU modules.

NOTE: I briefly discussed this vulnerability on Sunday.

AutomationDirect Advisory - This advisory describes seven vulnerabilities in the AutomationDirect Click Plus programming software.

Updates

 Hitachi Energy Update #1 - This update provides additional information on the RTU500 Series advisory that was originally published on April 3rd, 2025, and most recently updated on May 8th, 2025.

Hitachi Energy Update #2 - This update provides additional information on the RTU500 Series advisory that was originally published on January 23, 2025.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-and-2-updates-published-be3 - subscription required.

Tuesday, February 4, 2025

Review – 8 Advisories and 1 Update Published – 2-4-25

Today CISA’s NCCIC-ICS published eight control system security advisories for products from AutomationDirect, Schneider (4), Elber, Rockwell Automation, and Western Telematics. They also updated an advisory for products from Ashlar-Vellum.

Advisories

AutomationDirect Advisory - This advisory describes a classic buffer overflow vulnerability in the AutomationDirect C-more EA9 HMI.

Schneider Advisory #1 - This advisory describes an improper enforcement of message integrity during transmission in a communications channel vulnerability in the Schneider Pro-face GP-Pro EX and Remote HMI.

Schneider Advisory #2 - This advisory describes an exposure of sensitive information to unauthorized actor vulnerability in the Schneider Modicon M340 and BMXNOE0100/0110, BMXNOR0200H products.

Schneider Advisory #3 - This advisory describes an improper restriction of XML entity external reference vulnerability in the Schneider Web Designer for Modicon.

Schneider Advisory #4 - This advisory describes an incorrect calculation of buffer size vulnerability in the Schneider M580 PLCs, BMENOR2200H and EVLink Pro AC products.

NOTE: I briefly discussed all four of these Schneider vulnerabilities on January 20th, 2025.

Elber Advisory - This advisory describes two vulnerabilities with publicly available exploits in multiple communication products from Elber.

Rockwell Advisory - This advisory describes an improper handling of exceptional conditions vulnerability in the Rockwell GuardLogix 5380 and 5580 controllers.

Western Telematic Advisory - This advisory describes an external control of file name or path in the Western Telematic NPS Series, DSM Series, CPM Series products.

Updates

Ashlar-Vellum Update - This update provides additional information on the Ashlar-Vellum modeling tools advisory that was originally published on October 24th, 2023.

 

For more information on these advisories, including links to researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-and-1-update-published-4e3 - subscription required.

Thursday, December 5, 2024

Review – 2 Advisories Published – 12-5-24

Today CISA’s NCCIC-ICS published two control system security advisories for products from Planet Technology and AutomationDirect.

Advisories

Planet Technology Advisory - This advisory describes three vulnerabilities in the Planet Technology Planet WGS-804HPT industrial switch.

AutomationDirect Advisory - This advisory describes three stack-based buffer overflow vulnerabilities in the AutomationDirect C-More EA9 Programming Software.

 

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-published-12-5-24 - subscription required.

Thursday, September 12, 2024

Review – 25 Advisories Published – 9-12-24

Today, CISA’s NCCIC-ICS published 25 control system security advisories for products from Rockwell Automation (8), AutomationDirect, and Siemens (16).

Advisories

Rockwell Advisory #1 - This advisory describes an externally controlled reference to a resource in another sphere vulnerability in the Rockwell Thin Manager.

Rockwell Advisory #2 - This advisory describes two vulnerabilities in the Rockwell Pavilion8 model predictive control software.

Rockwell Advisory #3 - This advisory describes a command injection vulnerability in the Rockwell Factory Talk products.

Rockwell Advisory #4 - This advisory describes an improper authentication vulnerability in the Rockwell FactoryTalk Batch View manufacturing process batch solution.

Rockwell Advisory #5 - This advisory describes an improper input validation vulnerability in the Rockwell 5015-U8IHFT I/O module.

Rockwell Advisory #6 - This advisory discusses two vulnerabilities (one with a publicly available exploit) in the Rockwell AADvance Trusted SIS Workstation.

Rockwell Advisory #7 - This advisory describes an improper privilege management vulnerability in the Rockwell OptixPanel product.

Rockwell Advisory #8 This advisory describes an improper input validation vulnerability in multiple Rockwell controllers.

AutomationDirect Advisory - This advisory describes two vulnerabilities in the AutomationDirect DirectLogic H2-DM1E, a programmable logic controller.

SICAM Advisory - This advisory discusses a classic buffer overflow vulnerability in the Siemens SICAM and SITIPE products.

Industrial Products Advisory #1 - This advisory discusses the regreSSHion vulnerability in the Siemens Industrial Products.

Industrial Products Advisory #2 - This advisory discusses an input validation vulnerability in multiple Siemens Industrial Products.

SIMATIC Advisory #1 - This advisory describes an execution with unnecessary privilege vulnerability in the Siemens SIMATIC SCADA and PCS 7 Systems products.

SIMATIC Advisory #2 - This advisory describes three NULL pointer dereference vulnerabilities in the Siemens SIMATIC, SIPLUS, and TIM products.

SIMATIC Advisory #3 - This advisory describes six vulnerabilities in the Siemens SIMATIC RFID Readers.

SCALANCE Advisory - This advisory describes an injection vulnerability in the Siemens SCALANCE W700.

Tecnomatix Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Siemens Tecnomatix Plant Simulation product.

Industrial Edge Advisory - This advisory describes an authorization bypass through a user controlled key vulnerability in the Siemens Industrial Edge Management products.

Sinema Advisory - This advisory describes seven vulnerabilities in the Siemens SINEMA Remote Connect Client.

Automation License Advisory - This advisory describes an integer overflow or wrap around vulnerability in the Siemens Automation License Manager.

Mendix Advisory - This advisory describes an observable response discrepancy vulnerability in the Siemens Mendix Runtime product.

SINUMERIK Advisory #1 - This advisory describes an insertion of sensitive information into log file vulnerability for the Siemens SINUMERIK systems.

SINUMERIK Advisory #2 - This advisory describes an incorrect permission assignment for critical resource vulnerability for the Siemens SINUMERIK ONE, SINUMERIK 840D, SINUMERIK 828D products.

UMC Advisory - This advisory describes a heap-based buffer overflow vulnerability in the Siemens User Managements Components.

SINEMA Advisory - This advisory describes a session fixation vulnerability in the Siemens SINEMA Remote Connect Server.

 

For more information on these advisories, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/25-advisories-published-9-12-24 - subscription required.

Thursday, May 23, 2024

Review - 1 Advisory Published – 5-23-24

Today, CISA’s NCCIC-ICS published a control system security advisory for products from Automation Direct.

Advisories

AutomationDirect Advisory - The advisory describes 15 vulnerabilities in the AutomationDirect Productivity PLCs.

 

For more information on this advisory, including a listing of the 15 vulnerabilities, see my article at CFSN Detailed Analysis - - subscription required.

Tuesday, March 26, 2024

Review – 4 Advisories Published – 3-26-24

Today, CISA’s NCCIC-ICS published four control system security advisories for products from Rockwell Automation (3) and AutomationDirect.

Advisories

Rockwell Advisory #1 - This advisory describes a cross-site scripting vulnerability in the Rockwell FactoryTalk View ME HMI software application.

Rockwell Advisory #2 - This advisory describes six vulnerabilities in the Rockwell Arena Simulation Software.

Rockwell Advisory #3 - This advisory describes three vulnerabilities in the Rockwell PowerFlex 527 adjustable frequency AC drives.

AutomationDirect Advisory - This advisory describes three vulnerabilities in the AutomationDirect C-MORE EA9 HMI.

 

For more information about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-published-3-26-24 - subscription required.

Tuesday, September 20, 2022

Review – 5 Advisories and 3 Updates Published – 9-20-22

Today, CISA’s NCCIC-ICS published four control system and one medical device security advisory for products from Host Engineering, Dataprobe, Hitachi Energy (2) and Medtronic. They also published updates for three advisories for products from MiCODUS and AutomationDirect (2).

Host Engineering Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Host Engineering H0-ECOM100 Communications Module.

Dataprobe Advisory - This advisory describes seven vulnerabilities in the Dataprobe Dataprobe iBoot-PDU.

Hitachi Energy Advisory #1 - This advisory discusses a stack-based buffer overflow vulnerability in the Hitachi Energy AFF660/665 Firewall.

NOTE: I briefly discussed this vulnerability on July 30th, 2022.

Hitachi Energy Advisory #2 - This advisory discusses an improper access control vulnerability, with a known exploit, in the Hitachi Energy PROMOD IV and the PROMOD-Generator energy planning systems.

I briefly discussed this vulnerability on June 18th, 2022.

Medtronic Advisory - This advisory describes a protection measure failure vulnerability in the Medtronic NGP 600 Series Insulin Pumps and accessory components.

MiCODUS Update - This update provides additional information on an advisory that was originally published on July 19th, 2022.

AutomationDirect Update #1 - This update provides additional information on an advisory that was originally published on June 16th, 2022.

AutomationDirect Update #2 - This update provides additional information on an advisory that was originally published on June 16th, 2022.

 

For more details on the NCCIC-ICS reports, including links to researcher reports, third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-3-updates-published - subscription required.

Thursday, July 21, 2022

Review – 5 Advisories and 1 Update Published – 7-21-22

Today, CISA’s NCCIC-ICS published five control system security advisories for products from AutomationDirect, Mitsubishi Electric, Rockwell Automation, Johnson Controls, and ABB. They also published an update for products from Rockwell.

AutomationDirect Advisory - This advisory describes a cleartext transmission of sensitive information vulnerability in the AutomationDirect Stride Field I/O product.

Mitsubishi Advisory - This advisory describes seven vulnerabilities in the ICONICS Product Suite, and Mitsubishi MC Works64.

Rockwell Advisory - This advisory describes three vulnerabilities in the Rockwell ISaGRAF Workbench.

Johnson Controls - This advisory describes a missing authentication for critical function vulnerability in the Johnson Controls Metasys ADS, ADX, OAS with MUI server.

ABB Advisory - This advisory describes five different improper privilege management vulnerabilities in the ABB Drive Composer, Automation Builder, Mint Workbench products.

Rockwell Update - This update provides additional details on an advisory that was originally published on March 29th, 2022.

NOTE: Rockwell has not updated their advisory, and the new information is not reflected in the original Rockwell advisory.

 

For more details on these advisories and update, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-1-update-published-0f2 - subscription required.

Thursday, June 16, 2022

Review – 18 Advisories Published – 6-16-22

Today, CISA’s NCCIC-ICS published 17 control system security advisories for products from Siemens (14) and AutomationDirect (3). They also published a medical device security advisory for products from Hillrom. They also published 17 updates, but I will cover those in a separate post.

SINEMA Advisory #1 - This advisory describes 30 vulnerabilities (six with known exploits) in the Siemens SINEMA Remote Connect Server.

SINEMA Advisory #2 - This advisory describes two improperly implemented security check for standard in the Siemens SINEMA Remote Connect Server.

SCALANCE Advisory #1 - This advisory discusses the PwnKit vulnerability in the Siemens SCALANCE LPE 4903 and SINUMERIK Edge.

SCALANCE Advisory #2 - This advisory describes an improper validation of integrity check value in the Siemens SCALANCE XM-400 and XR-500 industrial switches.

SCALANCE Advisor #3 - This advisory discussing ten vulnerabilities (including three with known exploits) in the Siemens SCALANCE LPE9403.

Teamcenter Advisory #1 - This advisory describes a cross-site scripting vulnerability in the Siemens Teamcenter Active Workspace.

Teamcenter Advisory #2 - This advisory describes a use of hard-coded credentials vulnerability in the Siemens Teamcenter.

Industrial Products Advisory - This advisory discusses an infinite loop vulnerability in a large number of Siemens industrial products.

NOTE: It does not look like this advisory will be listing the ‘fixed’ products, we will have to watch the Siemens advisory for that. This may be a way for NCCIC-ICS to avoid having to do numerous updates to this advisory.

Spectrum Power Advisory - This advisory describes a use of hard-coded credentials vulnerability in the Siemens Spectrum Power SCADA, data modeling and monitoring system.

Xpedition Designer - This advisory describes an incorrect permission assignment vulnerability in the Siemens Xpedition Designer design flow products.

SICAM Advisory - This advisory describes three vulnerabilities in the Siemens SICAM GridEdge Essential ARM.

Apache Server Advisory - This advisory discusses three vulnerabilities in the Siemens Apache HTTP Server.

EN100 Advisory - This advisory describes an improper restriction of operations within the bounds of a memory buffer in the Siemens EN100 Ethernet Module.

Mendix Advisory - This advisory describes two vulnerabilities in the Siemens Mendix SAML Modules.

AutomationDirect Advisory #1 - This advisory describes two vulnerabilities in the AutomationDirect DirectLOGIC with Ethernet Communication Modules.

AutomationDirect Advisory #2 - This advisory describes a cleartext transmission of sensitive information vulnerability AutomationDirect DirectLOGIC with Serial Communication.

AutomationDirect Advisory #3 - This advisory describes two vulnerabilities in the AutomationDirect C-more EA9 industrial touch screen HMI.

Hillrom Advisory - This advisory describes two vulnerabilities in the Hillrom Welch Allyn ELI medical devices.

 

For more details on these advisories, including links to researcher reports, third-party advisories, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/18-advisories-published-6-16-22 - subscription required.

Tuesday, February 4, 2020

1 Advisory Published – 2-4-20


Today the CISA NCCIC-ICS published a control system security advisory for products from AutomationDirect.

AutomationDirect Advisory


The advisory describes an insufficiently protected credentials vulnerability in the AutomationDirect C-More Touch Panels EA9 Series. The vulnerability was reported by Joel Langill of Amentum Mission Engineering & Resilience (nice start for a brand-new company). AutomationDirect has a new version that mitigates the vulnerability. There is no indication that Joel has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to get account information such as usernames and passwords, obscure or manipulate process data, and lock out access to the device.

Amentum Disclosure


It will be interesting to see how Amentum deals with these types of vulnerability reports. Some companies publish details (after public disclosure by the vendor). Those details can include proof-of-concept code. Personally, I think that more details than are provided by NCCIC-ICS can be valuable to the community, particularly details on how the vulnerability was found. Responsibly disclosing these details should only take place after a long enough time for the vendor to mitigate the vulnerability and for owners to mitigate the vulnerability. POC information does not really help all that much, but the other information could be useful.

Tuesday, July 24, 2018

ICS-CERT Updates AutomationDirect Advisory


Today the DHS ICS-CERT published an update for a control system security advisory for products from AutomationDirect. This update provides additional information on an advisory that was originally published on November 9th, 2017 and updated on March 20th, 2018. It adds a new product (DirectSOFT Programming Software) to the list of vulnerable products and provided mitigation links for that product.

NOTE: The link ICS-CERT provided in their TWITTER feed for this update does not work, but the link provided in their email notification does. And, of course, the link provided above works.

Wednesday, March 21, 2018

ICS-CERT Publishes 2 Advisories and 3 Updates

Yesterday the DHS ICS-CERT published two new control system advisories for products from Siemens and Geutebruck. It also updated three previously published control system advisories for products from Siemens (2) and AutomationDirect. ICS-CERT has missed some recent Siemens updates and an advisory.

Siemens Advisory


This advisory describes an improper input validation vulnerability in the Siemens SIMATIC, SINUMERIK, and PROFINET IO products. The vulnerability is being self-reported by Siemens. Siemens has provided updates that mitigate the vulnerability is some products and has provided generic workarounds for the remaining products while updates are developed for them.

ICS-CERT reports that an uncharacterized attacker on an adjacent network could exploit this vulnerability to execute a denial-of-service condition requiring a manual restart to recover the system. The Siemens security advisory notes that OSI Layer 2 access is required to exploit the vulnerability.

Geutebruck Advisory


This advisory describes six vulnerabilities in the Geutebruck IP cameras. The vulnerabilities were reported by Davy Douhine of RandoriSec and Nicolas Mattiocco of Greenlock. Geutebruck has a new firmware version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Improper authentication - CVE-2018-7532;
• SQL injection - CVE-2018-7528;
• Cross-site request forgery - CVE-2018-7524;
• Improper access control - CVE-2018-7520;
• Server-side request forgery - CVE-2018-7516; and
• Cross-site scripting - CVE-2018-7512

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to lead to proxy network scans, access to a database, adding an unauthorized user to the system, full configuration download including passwords, and remote code execution.

SIMATIC Update


This update provides additional information on an advisory that was originally published on February 27th, 2018. It provides updated version information and mitigation measures for:

• SIMATIC IPC547G: Update BIOS to R1.21.0

SIPROTEC Update


This update provides additional information on an advisory that was originally published on July 6th, 2017, and updated on July 18th, on July 28th, on October 10th, on November 30th, and then again on January 4th, 2018. It provides updated version information and mitigation measures for:

• SIPROTEC 7SJ66: All versions prior to V4.30


AutomationDirect Update


This update provides additional information on an advisory that was originally published on November 9th, 2017. It adds a new product (Do-more Designer) to the list of vulnerable products and provided mitigation links for that product.

Missing Siemens Updates


Siemens has published updates and advisories that have not been covered in this latest series of ICS-CERT publications. Normally, I would not mention the ones from yesterday (two updates here and here, and a new advisory here), but today’s new Siemens advisory was also released yesterday. There is also an update from last week (here) that was not mentioned.

Two of the updates (here and here) are for the Spectre and Meltdown vulnerabilities in the Siemens Industrial products. ICS-CERT is unlikely to update their alert to reflect these new mitigation measures since the existing link to the Siemens advisory will take someone to the new information. This is a potential problem for anyone that is relying on ICS-CERT for information, but because of the way that ICS-CERT does their updates (and does not provide detailed change information) this appears to be unavoidable.

Friday, November 10, 2017

ICS-CERT Publishes Two Advisories

Yesterday the DHS ICS-CERT published two control system security advisories for products from Schneider and AutomationDirect.

Schneider Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Schneider InduSoft Web Studio and InTouch Machine Edition. The vulnerabilities were reported by Aaron Portnoy, formerly of Exodus Intelligence. Schneider has produced new versions that mitigate the vulnerability. There is no indication that Portnoy has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could use a publicly available exploit to remotely exploit this vulnerability to remotely execute code with high privileges. The Schneider security bulletin notes that the vulnerability exists during tag subscription.

AutomationDirect Advisory


This advisory describes and uncontrolled search path element vulnerability in a number of AutomationDirect products. The vulnerability was reported by Mark Cross of RIoT Solutions. Newer software versions are available from AutomationDirect that mitigate the problem. There is no indication that Cross has been provided an opportunity to verify the efficacy of the fix.


ICS-CERT reports that an uncharacterized attacker with uncharacterized access to execute arbitrary code on the system.
 
/* Use this with templates/template-twocol.html */