Showing posts with label AzeoTech. Show all posts
Showing posts with label AzeoTech. Show all posts

Thursday, June 25, 2026

Review – 9 Advisories and 1 Update Published – 6-25-26

Today CISA’s NCCIC-ICS published 7 control system security advisories for products from Schneider Electric, Delta Electronics, H.View, Daktronics, Horner Automation, EVoke Systems, and Yokogawa. They also published two medical device security advisories for products from OHIF and pydicom. They also updated an advisory for AzeoTech. 

Advisories  

Schneider Advisory - This advisory describes three vulnerabilities in the Schneider PowerLogic P7. 

Delta Advisory - This advisory describes a deserialization of untrusted data vulnerability in the Delta DTM Soft product. 

H.VIEW Advisory - This advisory describes two vulnerabilities in the H. VIEW HV-500S6 IP Camera. 

Daktronics Advisory - This advisory describes three vulnerabilities in the Daktronics Controller firmware. 

Horner Advisory - This advisory describes an out-of-bounds read vulnerability in the Horner Cscape product. 

EVoke Advisory - This advisory describes four vulnerabilities in the EVoke Charging Station Management System. 

Yokogawa Advisory - This advisory describes a cleartext transmission of sensitive information vulnerability in the Yokogawa FAST/TOOLS and CI Server. 

OHIF Advisory - This advisory describes a server-side request forgery vulnerability in the Open Health Imaging Foundation (OHIF) Viewers DICOM. 

Pydicom Advisory - This advisory describes a path traversal vulnerability in the pydicom pynetdicom Library. 

Updates  

AzeoTech Advisory - This update provides additional information on the DAQFactory advisory that was originally published on June 18th, 2026. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/9-advisories-and-1-update-published - subscription required. 

Thursday, June 18, 2026

Review – 8 Advisories Published – 6-18-26

Today CISA’s NCCIC-ICS published seven control system security advisories for products from Schneider Electric (2), Mitsubishi Electric (2), Rockwell Automation, AzeoTech, and AVer. They also published a medical device security advisory for products from Apollo Pharmacy. 

Advisories  

Schneider Advisory #1 - This advisory describes an insufficient entropy vulnerability in multiple Schneider product lines. 

Schneider Advisory #2 - This advisory describes a path traversal vulnerability in the Schneider EasyLogic T150 and Saitel DP products. 

Mitsubishi Advisory #1 - This advisory describes an expected behavior violation vulnerability in the Mitsubishi MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP. 

Mitsubishi Advisory #2 - This advisory describes an integer overflow or wraparound vulnerability in the Mitsubishi MELSEC iQ-F Series products. 

Rockwell Advisory - This advisory describes three vulnerabilities in the Rockwell FactoryTalk Historian Site Edition. 

AzeoTech Advisory - This advisory describes a type confusion vulnerability in the AzeoTech DAQFactory product. 

AVer Advisory - This advisory describes a files or directories accessible to external parties vulnerability in the AVer PTC cameras. 

Apollo Advisory - This advisory describes two vulnerabilities in the Apollo Blood Glucose Monitoring System APG-01 BT. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-published-6-18-26 - subscription required. 

Tuesday, December 30, 2025

Review – 1 Advisory and 1 Update Published – 12-30-25

Today CISA’s NCCIC-ICS published a control system security advisory for products from WHILL. They also updated an advisory for products from AzeoTech.

Advisories

WHILL Advisory - This advisory describes a missing authentication for critical function vulnerability in the WHILL Model C2 Electric Wheelchairs and Model F Power Chairs.

Updates

AzeoTech Update - This update provides additional information on the DAQFactory advisory that was originally published on December 11th, 2025.

 

For more information on these advisories, including a down-the-rabbit-hole look at missing vulnerabilities, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-and-1-update-published-d1d - subscription required.

Thursday, December 11, 2025

Review – 12 Advisories Published – 12-11-25

Today CISA’s NCCIC-ICS published ten control system security advisories for products from OpenPLC, Siemens (6), AzeoTech, and Johnson Controls (2). They also published two medical device security advisories for products from Varex and Grassroots.

Siemens published an additional eight advisories on Tuesday that were not covered here by CISA. I will address those this weekend.

Advisories

OpenPLC Advisory - This advisory describes a cross-site scripting vulnerability in the OpenPLC_V3.

Gridscale Advisory - This advisory describes two vulnerabilities in the Siemens Gridscale X Prepay energy management product.

Energy Services Advisory - This advisory discusses an authentication bypass using an alternate path or channel vulnerability in the Siemens Energy Services product.

Building X Advisory - This advisory describes an improper verification of cryptographic signature vulnerability in the Siemens Building X - Security Manager Edge Controller.

SINEMA Advisory - This advisory describes two vulnerabilities in the Siemens SINEMA Remote Connect Server.

SALT Advisory - This advisory describes an improper certificate validation vulnerability in the Siemens Advanced Licensing (SALT) Toolkit.

IAM Advisory - This advisory describes an improper certificate validation vulnerability in the Siemens IAM Client.

AzeoTech Advisory - This advisory describes seven vulnerabilities in the AzeoTech DAQFactory.

iSTAR Ultra Advisory - This advisory describes two OS command injection vulnerabilities in the Johnson Controls iSTAR Ultra and iSTAR Edge products.

iSTAR Advisory - This advisory describes two improper neutralization of special elements used in an OS command vulnerability iSTAR Ultra and iSTAR Edge products.

Varex Advisory - This advisory discusses an uncontrolled search path element vulnerability (with publicly available exploit) in their Panoramic Dental Imaging Software.

Grassroots Advisory - This advisory describes an out-of-bounds write vulnerability in the Grassroots DICOM viewer.

NOTE: CISA reports that DICOM viewers from SimpleITK and medInria are also affected by this vulnerability.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/12-advisories-published-12-11-25 - subscription required.

Thursday, November 4, 2021

Review - 3 Advisories Published – 11-4-21

Today CISA’s NCCIC-ICS published two control system security advisories for products from AzeoTech and VISAM. They also published a medical device security advisory for products from Philips.

AzeoTech Advisory - This advisory describes four vulnerabilities in the AzeoTech DAQFactory software and application development platform.

VISAM Advisory - This advisory describes ten vulnerabilities in the VISAM VBASE Editor automation platform.

Philips Advisory - This advisory describes two SQL injection vulnerabilities in the Philips TASY Electronic Medical Record (EMR).

For more details about the advisories, including 3rd party advisories and links to exploits, as well as a discussion about the zero-day exploit reporting of the Philips vulnerabilities in August, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-published-11-4-21 - subscription required.

Tuesday, August 29, 2017

ICS-CERT Publishes Three Advisories

Today the DHS ICS-CERT published two control system security advisories for products from Advantech and AzeoTech. They also published a medical device advisory for products from Abbott Laboratories.

Advantech Advisory


This advisory describes nine vulnerabilities in the Advantech WebAccess HMI platform. The vulnerabilities were reported by  Fritz Sands, independent researcher rgod, Tenable Network Security, and an anonymous researcher (all via Zero Day Initiative), and Haojun Hou and DongWang from ADLab of Venustech. Advantech has released a new version to mitigate the vulnerabilities. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The nine reported vulnerabilities are:

• Improper neutralization of special elements used in an SQL command - CVE-2017-12710;
• Improper restriction of operations within the bounds of a memory buffer - CVE-2017-12708;
• Stack-based buffer overflow -CVE-2017-12706;
• Heap-based buffer overflow - CVE-2017-12704;
• Use of externally-controlled format string - CVE-2017-12702;
• Improper authentication - CVE-2017-12698;
• Incorrect permission assignment for critical resource - CVE-2017-12713;
• Incorrect privilege assignment - CVE-2017-12711; and
• Uncontrolled search path element - CVE-2017-12711

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to allow remote code execution or unauthorized access and could cause the device that the attacker is accessing to crash.

NOTE: Earlier this month I mentioned that there were  a large number of ‘pending’ vulnerability reports on Advantech products currently listed on the ZDI web site. These are not those vulnerabilities; those are still apparently being resolved.

AzeoTech Advisory


This advisory describes two vulnerabilities in the AzeoTech DAQFactory HMI. The vulnerabilities were reported by Karn Ganeshen. AzeoTech has produced a new version that mitigates the vulnerabilities. There is no indication that Ganeshen was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Incorrect default permissions - CVE-2017-12699; and
• Uncontrolled search path element - CVE-2017-5147

ICS-CERT reports that an authenticated user with local access could exploit the vulnerabilities to escalate their privileges and modify or replace application files.

Abbott Labs Advisory


This advisory describes three vulnerabilities in the Abbot Labs (formerly St. Jude Medical) pacemakers. The vulnerabilities were reported by MedSec. Abbott has produced a firmware update that mitigates the vulnerability. ICS-CERT reports that an unidentified third-party has verified the efficacy of the fix. The FDA Safety Communication notes that the firmware update must be applied during “an in-person patient visit with a health care provider”.

The three reported vulnerabilities are:

• Improper authentication - CVE-2017-12712;
• Improper restriction of power consumption - CVE-2017-12714; and
• Missing encryption of sensitive data - CVE-2017-12716


ICS-CERT reports that an uncharacterized attacker near the patient could exploit the vulnerabilities to gain unauthorized access to a pacemaker and issue commands, change settings, or otherwise interfere with the intended function of the pacemaker.
 
/* Use this with templates/template-twocol.html */