Showing posts with label BDU FSTEC. Show all posts
Showing posts with label BDU FSTEC. Show all posts

Saturday, June 12, 2021

Review - Public ICS Disclosures – Week of 6-5-21 – Part 1

This week we have fifteen vendor disclosures from Bosch, Circutor (2), Dell, Gallagher (7), QNAP (3), and Xylem. We also have a researcher report for products from New Electronic Technologies. Finally we have exploits for products from VMware and Solar-Log (2).

Vendor Reports

Bosch published an advisory describing five vulnerabilities in their IP Cameras.

Incibe-CERT published an advisory describing an improper authentication vulnerability in the Circutor SGE-PLC1000 device.

Incibe-CERT published an advisory describing an OS command injection vulnerability in the Circutor SGE-PLC1000 device.

Dell published an advisory discussing the VMware vCenter Server vulnerabilities.

Gallagher Advisories - Gallagher published seven advisories describing vulnerabilities in the Command Centre Server.

QNAP published an advisory describing an improper access control vulnerability in their QNAP NAS Helpdesk products.

QNAP published an advisory describing an inclusion of sensitive information in QSS vulnerability in their QNAP Switches.

QNAP published an advisory describing an out-of-bounds read vulnerability in their QNAP Switches.

Xylem published an advisory discussing the Rockwell ISaGRAF Runtime vulnerabilities in their Flygt MultiSmart pump station management system.

Researcher Reports

The Russian BDU FSTEC published a report describing a privilege management vulnerability in the New Technologies Titanium CNC PLC module.

Exploits

Johnny Yu published an exploit for a heap-based buffer overflow vulnerability in the VMware vCenter Server.

Luca Chiou published an exploit for an unprotected storage of credentials vulnerability in the Solar-Log Energy Management System.

Luca Chiou published an exploit for an incorrect access control vulnerability in the Solar-Log Energy Management System.

For a more detailed look at these vulnerabilities, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-723 (subscription required).

Saturday, March 27, 2021

Public ICS Disclosures – Week of 3-20-21

This week we have 27 vendor disclosures from BD (3), Bosch, TRUMPF, GE Grid Systems (19), Mitsubishi Electric, Moxa, and Rockwell Automation. We have a researcher report for products from Ovarro. Finally, there were two exploits published for products from VMWare and Advantech.

BD Advisories

BD published patch advisories for the below listed products. These are the 3rd party patches that have been tested by BD on the listed products.

BD Care Coordination Engine (CCE),

Security Patches: BD Pyxis™ Products, and

Security Patches: BD Alaris™ Systems Manager

Bosch Advisories

Bosch published an advisory describing seven uncontrolled search path element vulnerabilities in multiple Bosch products. The vulnerabilities were reported by Nir Yehoshua, Dhiraj Mishra, and Eli Paz of CyberArk. Bosch has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

TRUMPF Advisory

CERT-VDE published an advisory describing an out-of-bounds write vulnerability in the TRUMPF TruControl laser control software. The vulnerability was reported by Qualys Research Labs. TRUMPF has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

GE Grid Advisories

GE published advisories for the below listed products. These may be updates for previously issued advisories, but only GE customers can access the advisories, so I do not know for sure:

C30 Controller

C60 Breaker Management Relay

C70 Capacitor Bank Protection and Control System

B30 Bus Differential Relay

B90 Bus Differential System

F35 Multiple Feeder Management Relay

F60 Feeder Management Relay

G30 Generator Management Relay

G60 Generator Management Relay

L30 Line Current Differential Relay

L60 Line Phase Comparison Relay

L90 Line Current Differential Relay

M60 Motor Management Relay

D30 Line Distance Relay

D60 Line Distance Relay

N60 Network Stability and Synchrophasor Measurement System

T35 Transformer Management Relay

T60 Transformer Management Relay

UR Family of Protection Relays

Mitsubishi Advisory

Mitsubishi published an advisory discussing a heap-based buffer overflow vulnerability in a third-party TCP/IP stack (Treck). Mitsubishi is providing generic workarounds to mitigate the vulnerability.

NOTE: Mitsubishi is only reporting one of the four TCP/IP stack vulnerabilities reported by Treck.

Moxa Advisory

Moxa published an advisory describing ten vulnerabilities in their EDR-810 Series Security Routers. The vulnerabilities were reported by the Russian BDU FSTEC. Moxa has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The ten reported vulnerabilities are:

• Improper Input Validation - CVE-2014-2284 (Linux ICMP-MIB implementation),

• Resource Management Errors - CVE-2015-1788 (Open SSL),

Improper Restriction of Operations within the Bounds of a Memory Buffer - CVE-2016-10012 (Open SSH),

Exposure of Sensitive Information to an Unauthorized Actor - CVE-2015-3195 (Open SSL),

Improper Input Validation - CVE-2016-6515 (open SSH, Exploit),

Improper Input Validation - CVE-2017-17562 (EmbedThis, Exploit),

Cryptographic Issues - CVE-2013-0169 (TLS Protocol),

• Permissions, Privileges, and Access Controls - CVE-2013-1813 (BusyBox, Exploit), and

• Numeric Errors - CVE-2010-2156 (ISC DHP, Exploit)

Rockwell Advisory

Rockwell published an advisory discussing eight vulnerabilities in their Stratix Switches. These are third-party (Cisco) vulnerabilities. Rockwell has new versions that mitigate the vulnerability.

The eight reported vulnerabilities are:

• Privilege escalation (2) - CVE-2021-1392 and CVE-2021-1442,

• Cross-site web socket hijacking - CVE-2021-1403,

• Denial of service (3) - CVE-2021-1352, CVE-2021-1220, and CVE-2021- 1356, and

• Command injection (2) - CVE-2021-1452 and CVE-2021-1443,

NOTE: Links above are to the Cisco advisories.l

Ovarro Report

Claroty published a report describing the five vulnerabilities that were reported earlier this week in the Ovarro TBox RTUs.

VMWare Exploit

WVU published a Metasploit module for a remote code execution vulnerability in the VMware View Planner. This vulnerability was previously reported by VMware.

Advantech Exploit

Spencer McIntyre published a Metasploit module for a missing authentication for critical function vulnerability in the Advantech iView. This vulnerability was previously reported by Advantech.

Sunday, December 13, 2020

Public ICS Disclosures – Week of 12-5-20, Part II

This week we have nine disclosures for products from Schneider. We also have eight vendor updates for products from Siemens (5) and Schneider (3). Finally, we have two researcher reports about vulnerabilities in products from Schneider.

Schneider Advisories

Schneider published an advisory describing a write-what-where condition vulnerability in their EcoStruxure™ Control Expert. The vulnerability was reported by Jared Rittle of Cisco Talos; the report contains proof-of-concept code. Schneider provides generic workarounds pending development of remediation measures.

 

Schneider published an advisory describing an insufficiently protected credentials vulnerability in their EcoStruxure Geo SCADA Expert. The vulnerability is being self-reported. Schneider has updates available that mitigate the vulnerability.

 

Schneider published an advisory describing two vulnerabilities in their Web Server on Modicon M340 communication modules. The vulnerabilities were reported by DongJian Security Lab and the Russian BDU FSTEC (report here). Schneider has new firmware versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Forced browsing - CVE-2020-7541, and

• Improper check for unusual or exceptional conditions - CVE-2020-7539

 

Schneider published an advisory describing a missing authentication for critical function vulnerability in their Web Server on Modicon M340 communications modules. The vulnerability was reported by DongJian Security Lab. Schneider has new firmware versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

 

Schneider published an advisory describing a path traversal vulnerability on the Web Server on Modicon M340 communications modules. The vulnerability was reported by Zheng Qiang. Schneider has new firmware versions that mitigate the vulnerability. There is no indication that the researcher have been provided an opportunity to verify the efficacy of the fix.

 

Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability in their Web Server on Modicon M340 communications modules. The vulnerability is being self-reported.

 

Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability in their Modicon M340 CPU’s. The vulnerability was reported by the VAPT Team from C3i IITK, India. Schneider has new firmware versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

 

Schneider published an advisory describing three separate improper check for unusual or exceptional conditions vulnerabilities in their Modicon M580 controllers. The vulnerabilities were reported by Gao Jian of NSFOCUS, Daniel Lubel of OTORIO, Armis Security, Victor Fidalgo Villar of INCIBE-CERT, and Gideon Guo. Schneider has firmware updates that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

 

Schneider published an advisory describing an improper restriction of operations within the bounds of a memory buffer vulnerability in their M258 Logic Controllers and SoMachine/SoMachine Motion software. The vulnerability was reported by Kai Feng. Schneider has new versions that mitigate the vulnerability. There is no indication that Kai has been provided an opportunity to verify the efficacy of the fix.

Siemens Updates

Siemens published an update for their SegmentSmack advisory that was originally published on April 14th, 2020 and most recently updated on September 8th, 2020. The new information include updating information regarding successor products for SIMATIC RF180C and RF182C.

NOTE: NCCIC-ICS updated their advisory for this vulnerability back in September but has not updated for this Siemens update.

 

Siemens published an update for their GNU/Linux subsystem advisory that was originally published in 2018 and most recently updated on November 10th, 2020. The new information includes adding the following new vulnerabilities:

• CVE-2020-25284,

• CVE-2020-25668,

• CVE-2020-25705,

• CVE-2020-27618, and

• CVE-2020-27777

 

Siemens published an update for their Industrial Products advisory that was originally published on December 10th, 2019 and most recently updated on September 8th, 2020. The new information includes updating d information regarding successor products for SIMATIC RF182C and RFID 181EIP.

NOTE: NCCIC-ICS last updated their advisory for this product back in August.

 

Siemens published an update for their advisory that was originally published on September 9th, 2020 and most recently updated on October 13th, 2020. The new information includes adding patch links for:

• SIMATIC HMI Basic (2nd generation),

• Comfort (including SIPLUS variants), and

• Mobile Panels

NOTE: NCCIC-ICS published their advisory for these vulnerabilities back in September but has not updated it since.

 

Siemens published an update for their ZombieLoad advisory that was originally published on July 9th, 2019 and most recently updated on March 10th, 2020. The new information includes:

• Correcting mitigations for SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP and

• Providing updates for SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP

Schneider Updates

Schneider published an update for their Ripple20 advisory that was originally published on June 23, 2020 and most recently updated on November 10th, 2020. The new information includes adding remediation for:

• SCADAPack 32 RTU,

• XUPH001 OsSense communication module,

• XGCS850C201 OsiSense RFID compact smart antenna,

• ATV340E Altivar Machine Drives,

• ATV630/650/660/680/6A0/6B0 Altivar Process Drives,

• ATV930/950/960/980/9A0/9B0 Altivar Process Drives,

• VW3A3720, VW3A3721 Altivar Process Communication Modules,

• ACE850 Sepam communication interface,

• PowerLogic EGX300 Ethernet Gateway,

• PowerLogic EGX100 Ethernet Gateway, and

• Acti9 Smartlink IP

 

Schneider published an update for their CodeMeter advisory that was originally published on October 13th, 2020. The new information includes reporting that the CodeMeter V7.10a fix qualification is confirmed for EcoStruxure Machine SCADA Expert.

 

Schneider published an update for their Modicon controllers advisory that was originally published on May 14th, 2019 and most recently updated on October 18th, 2020. The new information includes adding a fix for additional attack scenario is available on M340 V3.30 for CVE-2018-7857.

Schneider Reports

Claroty published a report discussing the Modicon M221 PLC vulnerabilities reported Tuesday by Schneider.

Trustwave published a report discussing one of the Modicon M221 PLC vulnerabilities reported Tuesday by Schneider. This report contains proof-of-concept code for the one-way hash vulnerability.

 
/* Use this with templates/template-twocol.html */