Showing posts with label Bashis. Show all posts
Showing posts with label Bashis. Show all posts

Saturday, March 5, 2022

Review - Public ICS Disclosures – Week of 2-26-22

This week we have twelve vendor disclosures from ABB, Beckhoff, Broadcom (2), B&R Automation, Delta Industrial Automation, Gerbv, OMRON, PcVue Solutions, Tanzu (2), and VMware. We also have two end-of-life notices from We have one researcher report for products from Swift Sensors. Finally, we have four exploits reported for products from WAGO, Hikvision, Axis, and the PwnKit vulnerability.

ABB Advisory - ABB published an advisory describing a denial of service vulnerability in their AC 800M MMS.

Beckhoff Advisory - Beckhoff published an advisory discussing a NULL pointer dereference vulnerability in their products with OPC UA technology.

NOTE: This vulnerability may be found in other vendor products utilizing OPC UA technology.

Broadcom Advisory #1 - Broadcom published an advisory discussing the LOGBACK-1591 vulnerability in their Brocade Fibre Channel Products.

Broadcom Advisory #2 - Broadcom published an advisory discussing the Log4Shell vulnerabilities.

B&R Advisory - B&R published an advisory discussing a deserialization of untrusted data vulnerability in their B&R APROL product line.

NOTE: This vulnerability may affect other vendor products that use Apache Chainsaw.

Delta Advisory - Incibe CERT published an advisory describing four vulnerabilities in the Delta CNCSoft ScreenEditor, and DIAEnergie products.

Gerbv Advisory - Incibe CERT published an advisory discussing seven vulnerabilities in the Gerbv file view.

Omron Advisory - JP CERT published an advisory describing five vulnerabilities in the OMRON CX-Programmer.

PcVue Advisory - PcVue published a notice discussing four vulnerabilities in their Dream Report products.

Tanzu Advisory #1 - Tanzu published an advisory describing an improper privilege management vulnerability in their Spring Cloud Gateway.

Tanzu Advisory #2 - Tanzu published an advisory describing a code injection vulnerability in their Spring Cloud Gateway.

VMware Advisory - VMware published an advisory describing an uncontrolled search path vulnerability in their VMware Tools for Windows.

Swift Sensor Report - Cisco Talos published a report describing an authentication bypass vulnerability in the Swift Sensor Gateway.

Braun End-of-Life Notices - Braun USA published end-of-life notices for their Dialog+ Version 8 and Dia70 Portable RO products.

WAGO Exploit - Momen Eldawakhly published an exploit for a privilege escalation vulnerability in the WAGO 750-8212 PFC200 G2 2ETH RS.

Hikvision Exploit - Bashis published a Metasploit module for a command injection vulnerability in unspecified Hikvision IP Camera.

Axis Exploit - Jbaines-r7 published a Metasploit module for an unrestricted upload of applications ‘feature’ in unspecified Axis IP cameras.

PwnKit Exploit - Qualys Security published a Metasploit module for the PwnKit vulnerability.

 

For more details about these disclosures, including links to third-party reports, researcher reports and exploits, see my article at CFSN Detailed Analysis - - subscription required.

Thursday, May 4, 2017

ICS-CERT Publishes 4 Advisories

Today the DHS ICS-CERT published 4 control system security advisories for products from Rockwell, Advantech, Dahua Technology and Hikvision. The Rockwell advisory was previously published on the NCCIC Portal on April 4, 2017.

ICS-CERT also published the latest version of their ICS-CERT Monitor. Not worth reviewing, but it is out there.

Rockwell Advisory


This advisory describes a resource exhaustion vulnerability in Rockwell ControlLogic and CompactLogic controllers. This vulnerability was apparently self-reported. Rockwell has provided updated versions to mitigate the vulnerability.

ICS-CERT reports that an uncharacterized attacker could remotely exploit the vulnerability to cause the device that the attacker is accessing to become unavailable.

Advantech Advisory


This advisory describes an absolute path traversal vulnerability in the Advantech WebAccess. The vulnerability was reported by Zhou Yu via ZDI. Advantech has produced a new version to mitigate the vulnerability. ICS-CERT reports that Yu has verified the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to traverse the file system and gain access to files or directories, which could result in the device becoming unavailable.

Dahua Technology Advisory


This advisory describes two password vulnerabilities in the Dahua Digital Video Recorders and IP Cameras. Bashis disclosed these vulnerabilities without coordination with ICS-CERT (see Brian Krebs and ThreatPost articles for more information).

The two reported vulnerabilities are:

• Use of password hash instead of password for authentication - CVE-2017-7927; and
• Password in configuration file - CVE-2017-7925

ICS-CERT reports that a relatively low skilled attacker could use publicly available exploits to remotely exploit the vulnerabilities to allow the attacker to obtain user credentials, including password hashes, and use these credentials to bypass authentication.

Hikvision Advisory


This advisory describes two password vulnerabilities in the Hikvision cameras. The vulnerability was reported by IPcamtalk user “Montecrypto”. Hikvision has published a new version to mitigate one of the two vulnerabilities. There is no indication that Montecrypto was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper authentication - CVE-2017-7921; and
• Password in configuration file - CVE-2017-7923

In Passing



Please remember that when ICS-CERT publishes their 2017 stats that they will almost certainly include the Dahua and Hikvision vulnerabilities in their count of control system advisories for the year.
 
/* Use this with templates/template-twocol.html */