Showing posts with label Beckhoff. Show all posts
Showing posts with label Beckhoff. Show all posts

Saturday, January 31, 2026

Review – Public ICS Disclosures – Week of 1-24-26 – Part 1

This is a moderately busy disclosure week. We have bulk vendor disclosures from Broadcom (48). There are also 14 other vendor disclosures from B&R (2), Beckhoff (2), Dell, Dassault Systems (2), Hanwha Vision, Hitachi, Hitachi Energy (3), HPE, and Siemens.

Bulk Vendor Disclosures – Broadcom

Nessus detected vulnerability in the Brocade OVA base image (CVE-2025-21991),

The DisableForwarding directive does not fully adhere to the intended functionality as documented (CVE-2025-32728),

Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service,

Curl vulnerabilities detected in SANnav images (CVE-2025-4947, CVE-2025-5025) ,

DoS due to improper input validation vulnerability in Apache Tomcat - CVE-2024-24549,

Spring Framework DoS (CVE-2024-38808, CVE-2024-38809 and CVE-2024-22262),

Oracle Java SE Updates (July 2025),

Multiple Vulnerabilities in Node.js (Wednesday, May 14, 2025 Security Releases). Nessus Plugin ID 236766,

Low-level invalid GF(2^m) parameters lead to OOB memory access,

Multiple Vulnerabilities in Apache Kafka,

Postgres vulnerabilities (CVE-2025-8713, CVE-2025-8714, CVE-2025-8715),

libcurl's ASN1 parser code has the GTime2str() function, used for parsing an ASN.1 (CVE-2024-7264) ,

PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation,

Vulnerability in OpenSSH when the VerifyHostKeyDNS option is enabled (CVE-2025-26465),

Rocky Linux Updates applied to SANnav (CVE-2024-3661, CVE-2024-11187, CVE-2024-12797) ,

A malicious rsh server can overwrite arbitrary files in a directory on the rcp client machine,

xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak,

Multiple Linux Security Updates applied to Brocade Fabric OS 10.0,

The x509 application adds trusted use instead of rejected use,

libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time,

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64,

In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c,

Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses,

GNU tar mishandled extension attributes in a PAX archive,

This flaw allows a malicious HTTP server to set "super cookies" in curl,

Glib GVariant deserialization fails to validate input,

A heap out-of-bounds read flaw was found in builtin.c in the gawk package,

Scan discovered multiple CVEs against glibc,

Null pointer dereference found in openldap,

A denial of service vulnerability exists in curl,

An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0,

use-after-free and memory corruption,

A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation,

The allocate_structures function insufficiently checks bounds before arithmetic multiplication,

Linux kernel's block_invalidatepage in fs/buffer.c in the filesystem,

Brocade SANnav DataBase password in plain text is logged in failover logs (CVE-2025-12680),

Plaintext Switch admin login password is seen in Brocade SANnav support save (CVE-2025-12772) ,

Plain password is logged in the audit logs while executing update-reports-purge-settings.sh script with Brocade SANnav before 2.4.0a (CVE-2025-12773),

SQL queries with sensitive information printed in logs with Brocade SANnav before 3.0 (CVE-2025-12774),

Information disclosure in Brocade Fabric OS before 9.2.1c2, 9.2.2 through 9.2.2a and 10.0.0 (CVE-2026-0383),

Privilege escalation in Brocade Fabric OS before 9.2.1c3, and 9.2.2 though 9.2.2b (CVE-2025-9711),

Directory transversal vulnerability in Brocade Fabric OS before 9.2.1 using grep command (CVE-2025-58380),

Plain text pbe key visible in audit log during Brocade SANnav migration from 2.4.0a to 3.0.0 (CVE-2025-12679),

Directory transversal vulnerability in Brocade Fabric OS before 9.2.1c2 and 9.2.2 through 9.2.2a using various shell commands (CVE-2025-58381),

Password Exposure in Brocade Fabric OS before 9.2.1 (CVE-2025-58379),

Privilege escalation in Brocade Fabric before 9.2.1c2 and 9.2.2 through 9.2.2a (CVE-2025-58382),

Privilege escalation via bind command in Brocade Fabric OS (CVE-2025-58383),

Undertow-core: undertow http server fails to reject malformed host headers leading to potential cache poisoning and ssrf (CVE-2025-12543).

Advisories

B&R Advisory #1 - B&R published an advisory that discusses the PixieFail vulnerabilities.

B&R Advisory #2 - B&R published an advisory that describes an insertion of sensitive information into log file vulnerability.

Beckhoff Advisory #1 - CERT-VDE published an advisory that describes three vulnerabilities in the Beckhoff Device Manager.

Beckhoff Advisory #2 - CERT-VDE published an advisory that describes a cross-site scripting vulnerability in the Beckhoff TwinCAT 3 HMI Server.

Dell Advisory - Dell published an advisory that discusses an improper handling of length parameter inconsistency vulnerability (with publicly available exploits) in their Wyse Management Suite.

Dassault Advisory #1 - Dassault published an advisory that describes a heap-based buffer overflow vulnerability in SOLIDWORKS eDrawings.

Dassault Advisory #2 - Dassault published an advisory that describes an out-of-bounds write vulnerability in their SOLIDWORKS eDrawings.

Hanwha Advisory - Hanwha published an advisory that describes five vulnerabilities in multiple Wisenet cameras from Hanwha.

Hitachi Advisory - Hitachi published an advisory that discusses to allocation of  resources without limit or throttling vulnerabilities in their Cosminexus Component Container.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory that discusses the BlastRadius-Fail vulnerability in their FOX61x products.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory that discusses the BlastRadius-Fail vulnerability in their XMC20 products.

Hitachi Energy Advisory #3 - Hitachi Energy published an advisory that describes the use of default credentials vulnerability in their SuprOS products.

HPE Advisory - HPE published an advisory that describes three vulnerabilities in their Aruba Fabric Composer product.

Siemens Advisory - Siemens published an advisory that discusses 51 vulnerabilities in their SINEC OS based products.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-2c6 - subscription required.

Saturday, January 24, 2026

Review – Public ICS Disclosures – Week of 1-17-26 – Part 1

We have a moderately busy disclosure week. For Part 1 we have 10 vendor disclosures from Beckhoff, Belden, B&R Automation (2), Carrier, Fujitsu, Hitachi, and HPE (3).

Advisories

Beckhoff Advisory - CERT-VDE published an advisory that describes a cross-site scripting vulnerability in their TwinCAT 3 HMI Server.

Belden Advisory - Belden published an advisory that discusses an improper handling of length parameter inconsistency vulnerability (that is listed in CISA’s KEV catalog) in their Connectivity Suite product.

B&R Advisory #1 - B&R published an advisory that describes an allocation of resources without limit or throttling vulnerability in their Automation Runtime products.

B&R Advisory #2 - B&R published an advisory that describes an improper certificate validation vulnerability in their Automation Studio product.

Carrier Advisory - Carrier published an advisory that describes a storing password in a recoverable format vulnerability in their Automated Logic WebCTRL and Carrier i-Vu products.

Fujitsu Advisory - CERT-JP published an advisory that describes an uncontrolled search path element vulnerability in the Fujitsu ServerView Agents for Windows.

Hitachi Advisory - Hitachi published an advisory that discusses 28 vulnerabilities in their Disk Array systems.

HPE Advisory #1 - HPE published an advisory that discusses 19 vulnerabilities (4 with publicly available exploits, 1 listed in KEV catalog) in their Telco Universal SLA Management product.

HPE Advisory #2 - HPE published an advisory that discusses an out-of-bounds rite vulnerability in their Telco IP product (ONMS Adapter).

HPE Advisory #3 - HPE published an advisory that describes a privilege escalation vulnerability in multiple HPE products utilizing the Alletra OS.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-407 - subscription required.

Saturday, September 13, 2025

Review – Public ICS Disclosures – Week of 9-6-25 – Part 1

This week we have bulk vendor disclosures HP (6). There are also 12 vendor disclosures from Beckhoff, Bender (2), Delta Electronics, GE Vernova, Hitachi Energy, HPE (3), NI (2), and Palo Alto Networks.

Bulk Vendor Disclosures – HP

Intel UPLR2 Xeon Processor BIOS Security Updates,

Intel 2025.1 IPU – BIOS February 2025 Security Update,

AMD SMM Vulnerabilities February 2025 Security Update,

HP Hotkey Support – Escalation of Privilege,

Intel Core Ultra Processor Firmware Security Update, and

Poly Lens Desktop Application – Privilege Escalation,

Advisories

Beckhoff Advisory - Beckhoff published an advisory that describes a deserialization of untrusted data vulnerability in their TwinCAT 3 Engineering product.

Bender Advisory #1 - CERT-VDE published an advisory that describes an insufficiently protected credentials vulnerability in the Bender charge controller products.

Bender Advisory #2 - CERT-VDE published an advisory that describes a cleartext transmission of sensitive information vulnerability in the Bender charge controller products.

Delta Advisory - Delta published an advisory that describes two path traversal vulnerabilities in their DIALink product.

GE Advisory - GE published an advisory that discusses four vulnerabilities in their  Control Server, OTArmor, and Baseline Security Center (BSC) products.

Hitachi Energy Advisory - Hitachi Energy published an advisory that discusses seven vulnerabilities (one with publicly available exploit) in their RTU500 series product.

HPE Advisory #1 - HPE published an advisory that discusses two vulnerabilities (one with publicly available exploit) in their Telco Unified Correlation and Automation (UCA) product.

HPE Advisory #2 - HPE published an advisory that discusses two vulnerabilities in their Intelligent Assurance Using Apache product.

HPE Advisory #3 - HPE published an advisory that discusses two vulnerabilities in their Telco Intelligent Assurance product.

NI Advisory #1 - NI published an advisory that describes a path traversal vulnerability in their USI Registration tool for DataPlugins.

NI Advisory #2 - NI published an advisory that describes a relative path traversal vulnerability in their Digilent WaveForms product.

PAN Advisory #1 - PAN published an advisory that discusses eight vulnerabilities in their Prisma Access Browser.

PAN Advisory #2 - PAN published an advisory that describes an exposure of sensitive information to an unauthorized control sphere vulnerability in their User-ID Credential Agent.

PAN Advisory #3 - PAN published an advisory that describes an insertion of sensitive information into a log file vulnerability in their Cortex XDR Microsoft 365 Defender Pack.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-97a - subscription required.

Thursday, November 7, 2024

Review – 3 Advisories Published – 11-7-24

Today, CISA’s NCCIC-ICS published three control system security advisories for products from Bosch, Delta Electronics, and Beckhoff Automation.

Advisories

Bosch Advisory - This advisory describes an uncontrolled resource consumption vulnerability in the Bosch Rexroth AG IndraDrive.

Delta Advisory - This advisory describes three stack-based buffer overflow vulnerabilities in the Delta DIAScreen.

Beckhoff Advisory - This advisory describes an OS command injection vulnerability in the Beckhoff TwinCAT Package Manager.

 

For more information on these advisories, including a look at additional Delta vulnerabilities – see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-published-11-7-24 - subscription required.

Saturday, November 2, 2024

Review – Public ICS Disclosures – Week of 10-25-24 – Part 1

This week, for Part 1, we have 20 vendor disclosures from Broadcom (8), Beckhoff, Bosch, GE Vernova (2), Hikvision, Hitachi Energy (2), HP (3), HPE, and Omron.

Advisories

Broadcom Advisory #1 - Broadcom published an advisory that discusses a function call with incorrect argument type vulnerability in their SANnav product.

Broadcom Advisory #2 - Broadcom published an advisory that discusses an integer overflow or wrap around vulnerability in their SANnav product.

Broadcom Advisory #3 - Broadcom published an advisory that discusses nine vulnerabilities (three with publicly available exploits) in their Fabric OS, SANnav, and ASCG products.

Broadcom Advisory #4 - Broadcom published an advisory that discusses an incorrect resource transfer between spheres vulnerability in their SANnav product.

Broadcom Advisory #5 - Broadcom published an advisory that discusses two vulnerabilities (one with publicly available exploit) in their SANnav product.

Broadcom Advisory #6 - Broadcom published an advisory that discusses an incomplete cleanup vulnerability in their SANnav product.

Broadcom Advisory #7 - Broadcom published an advisory that discusses three inadequately described vulnerabilities in their SANnav product.

Broadcom Advisory #8 - Broadcom published an advisory that discusses six vulnerabilities in their SANnav products.

Beckhoff Advisory - CERT-VDE published an advisory that describes an OS command injection vulnerability in the Beckhoff TwinCAT Package Manager.

Bosch Advisory - Bosch published an advisory that describes an uncontrolled resource consumption vulnerability in the PROFINET stack implementation of the IndraDrive.

GE Vernova Advisory #1 - GE published an advisory that discusses two vulnerabilities in Control Server installations that use VMware vCenter Server.

GE Vernova Advisory #2 - GE published an advisory that describes a side-channel key recovery vulnerability in YubiKey’s in customers using Xona devices and those using YubiKey authentication for certain HMI deployments.

Hikvision Advisory - JP- CERT published an advisory that announces firmware updates for multiple network cameras as a security enhancement, changing the behavior to communicate with Dynamic DNS services, to prevent cleartext transmission.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory that describes two vulnerabilities in their TRO600 series products.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory that discusses two vulnerabilities (both with publicly available exploits) in their MSM product web services.

HP Advisory #1 - HP published an advisory that discusses the PixieFail vulnerabilities.

HP Advisory #2 - HP published an advisory that discusses 353 vulnerabilities in their ThinPro product.

HP Advisory #3 - HP published an advisory that describes an out-of-bounds write vulnerability in their Smart Universal Printing Driver.

HPE Advisory - HPE published an advisory that discusses the regreSSHion vulnerability.

Omron Advisory - Omron published an advisory that describes an improper authorization vulnerability in their Sysmac Studio product.

 

For more information about these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-25a - subscription required.

Saturday, December 16, 2023

Review – Public ICS Disclosures – Week of 12-9-23 – Part 1 –

This week we have 22 vendor disclosures from ABB, Beckhoff, BD (2), Bosch (2), Cisco, FortiGuard (3), Frauscher, HPE (3), JTEKT, and Palo Alto Networks (7).

Advisories

ABB Advisory - ABB published an advisory that discusses the Apache ActiveMQ deserialization of untrusted data vulnerability that is listed on the CISA Known Exploited Vulnerabilities Catalog.

Beckhoff Advisory – CERT-VDE published an advisory that describes an open redirect vulnerability in the Beckhoff TwinCAT/BSD product.

BD Advisory #1 - BD published an advisory that discusses the Windows 7 Operating System End of Life Notice.

BD Advisory #2 - BD published an advisory that discusses an out-of-bounds write vulnerability that is listed in the CISA KEV catalog.

Bosch Advisory #1 - Bosch published an advisory that describes two improper handling of a malformed API request vulnerabilities in their BT software products

Bosch Advisory #2 - Bosch published an advisory that describes a command injection vulnerability in their Bosch IP Cameras.

Cisco Advisory - Cisco published an advisory that discusses the recent Apache Struts vulnerability.

FortiGuard Advisory #1 - FortiGuard published an advisory that describes a use of externally controlled format string vulnerability in their FortiOS, FortiProxy and FortiPAM products.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an improper access control vulnerability in their FortiOS and FortiProxy products.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes a double free vulnerability in their FortiOS and FortiPAM HTTPSd daemon.

Frauscher Advisory - CERT-VDE published an advisory that describes a code injection vulnerability in the Frauscher FDS102 for FAdC/FAdCi.

HPE Advisory #1 - HPE published an advisory that discusses seven vulnerabilities in their Cray Programming Environment.

HPE Advisory #2 - HPE published an advisory that discusses six vulnerabilities in their Intelligent Management Center (iMC) product.

HPE Advisory #3 - HPE published an advisory that discusses 14 vulnerabilities in their Virtualized Telecommunication Management Information Platform (vTeMIP) application.

JTEKT Advisory - JTEKT published an advisory that describes four uncontrolled resource consumption vulnerabilities in their HMI GC-A2 series products.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes a cross-site scripting vulnerability in their PAN-OS products.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that describes a weakness introduced during design vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory that describes an unrestricted upload of file with dangerous type vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #4 - Palo Alto Networks published an advisory that describes an argument injection vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #5 - Palo Alto Networks published an advisory that describes an OS command injection vulnerability in their PAS-OS product.

Palo Alto Networks Advisory #6 - Palo Alto Networks published an advisory that describes an improper privilege management vulnerability in their PAN-OS product.

Palo Alto Networks Adviosry #7 - Palo Alto Networks published an advisory that describes a cross-site scripting vulnerability in their PAN-OS product.

 

For more details about these disclosures, including links to 3rd party advisories, vendor advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-9fa https://tinyurl.com/yty8yuyt- subscription required. 

Saturday, March 5, 2022

Review - Public ICS Disclosures – Week of 2-26-22

This week we have twelve vendor disclosures from ABB, Beckhoff, Broadcom (2), B&R Automation, Delta Industrial Automation, Gerbv, OMRON, PcVue Solutions, Tanzu (2), and VMware. We also have two end-of-life notices from We have one researcher report for products from Swift Sensors. Finally, we have four exploits reported for products from WAGO, Hikvision, Axis, and the PwnKit vulnerability.

ABB Advisory - ABB published an advisory describing a denial of service vulnerability in their AC 800M MMS.

Beckhoff Advisory - Beckhoff published an advisory discussing a NULL pointer dereference vulnerability in their products with OPC UA technology.

NOTE: This vulnerability may be found in other vendor products utilizing OPC UA technology.

Broadcom Advisory #1 - Broadcom published an advisory discussing the LOGBACK-1591 vulnerability in their Brocade Fibre Channel Products.

Broadcom Advisory #2 - Broadcom published an advisory discussing the Log4Shell vulnerabilities.

B&R Advisory - B&R published an advisory discussing a deserialization of untrusted data vulnerability in their B&R APROL product line.

NOTE: This vulnerability may affect other vendor products that use Apache Chainsaw.

Delta Advisory - Incibe CERT published an advisory describing four vulnerabilities in the Delta CNCSoft ScreenEditor, and DIAEnergie products.

Gerbv Advisory - Incibe CERT published an advisory discussing seven vulnerabilities in the Gerbv file view.

Omron Advisory - JP CERT published an advisory describing five vulnerabilities in the OMRON CX-Programmer.

PcVue Advisory - PcVue published a notice discussing four vulnerabilities in their Dream Report products.

Tanzu Advisory #1 - Tanzu published an advisory describing an improper privilege management vulnerability in their Spring Cloud Gateway.

Tanzu Advisory #2 - Tanzu published an advisory describing a code injection vulnerability in their Spring Cloud Gateway.

VMware Advisory - VMware published an advisory describing an uncontrolled search path vulnerability in their VMware Tools for Windows.

Swift Sensor Report - Cisco Talos published a report describing an authentication bypass vulnerability in the Swift Sensor Gateway.

Braun End-of-Life Notices - Braun USA published end-of-life notices for their Dialog+ Version 8 and Dia70 Portable RO products.

WAGO Exploit - Momen Eldawakhly published an exploit for a privilege escalation vulnerability in the WAGO 750-8212 PFC200 G2 2ETH RS.

Hikvision Exploit - Bashis published a Metasploit module for a command injection vulnerability in unspecified Hikvision IP Camera.

Axis Exploit - Jbaines-r7 published a Metasploit module for an unrestricted upload of applications ‘feature’ in unspecified Axis IP cameras.

PwnKit Exploit - Qualys Security published a Metasploit module for the PwnKit vulnerability.

 

For more details about these disclosures, including links to third-party reports, researcher reports and exploits, see my article at CFSN Detailed Analysis - - subscription required.

Saturday, November 6, 2021

Review - Public ICS Disclosure – Week of 10-30-21

This week we have 14 vendor disclosures from Beckhoff, Boston Scientific, Hitachi, Hitachi Energy (7), HPE, Philips, Phoenix Contacts, and Tanzu. There is also a researcher report about vulnerabilities in products from Gerbv. Finally, there is an exploit for products from Sonicwall.

Beckhoff Advisory - Beckhoff published an advisory describing a relative path traversal vulnerability in their TwinCAT OPC UA Server.

Boston Scientific Advisory - Boston Scientific published an advisory discussing the PrintNightmare vulnerabilities.

Hitachi Advisory - Hitachi published an advisory discussing 35 vulnerabilities in their Hitachi Disk Array Systems.

Hitachi Energy Advisory #1 - Hitachi published an advisory discussing 36 vulnerabilities in their Transformer Asset Performance Management (APM) Edge products.

Hitachi Energy Advisory #2 - Hitachi published an advisory describing an insufficient security control vulnerability in their Relion® 670/650/SAM600-IO series Products.

Hitachi Energy Advisory #3 - Hitachi published an advisory describing an insufficient security control in their GMS600 generator circuit breakers.

Hitachi Energy Advisory #4 - Hitachi published an advisory describing an insufficient security control vulnerability in their PWC600 controllers.

Hitachi Energy Advisory #5 - Hitachi published an advisory describing an insecure boot image vulnerability in their Relion® 670/650/SAM600-IO series Products.

Hitachi Energy Advisory #6 - Hitachi published an advisory describing an authentication bypass vulnerability in their Counterparty Settlement and Billing (CSB) Product.

Hitachi Energy Advisory #7 - Hitachi published an advisory describing an authentication bypass vulnerability in their Retail Operations Product.

HPE Advisory - HPE published an advisory discussing five vulnerabilities in their Edgeline EL300 Converged Edge Systems.

Philips Advisory - Philips published an advisory discussing the Cisco input validation vulnerability.

Phoenix Contacts Advisory - Phoenix Contacts published an advisory describing a ‘zip-slip’ vulnerability in their Automation Worx Software Suite.

Tanzu Advisory - Tanzu published an advisory discussing a missing release of memory after effective lifetime vulnerability in their Spring Cloud Gateway.

Gerbv Report - Talos published a report about an out-of-bounds write vulnerability in the in the drill format T-code tool number functionality of Gerbv 2.7.0.

Sonicwall Exploit - Vulnerability Labs published an exploit for a cross-site scripting vulnerability in the Sonicwall SonicOS.

For more details about these advisories, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-10 - subscription required.

Saturday, May 15, 2021

Public ICS Disclosures – Week of 5-8-21, Part 1

This is a busier week than normal, even for a ‘Second Tuesday’ week. We have three vendor notifications for the FragAttacks WiFi vulnerabilities from Aruba, Ruckus, and Texas Instruments. We have two vendor notifications for the two OPC UA vulnerabilities reported this week by NCCIC-ICS from Beckhoff, Belden. We also have twelve other vendor notifications from Braun, SITEL (4), PEPPERL+FUCHS, CODESYS (3), Dell, and PulseSecure (2).

There will be a similarly lengthy list in Part 2 tomorrow.

FragAttacks Advisories

Aruba published an advisory discussing the FragAttacks vulnerabilities. Aruba provides a list of affected products and has new versions that mitigate the vulnerabilities.

Ruckus published an advisory discussing the FragAttacks vulnerabilities. Ruckus provides a list of affected products and has updates that mitigate the vulnerabilities.

TI published an advisory discussing the FragAttacks vulnerabilities. TI provides a list of affected products and has new versions that mitigate the vulnerabilities.

OPC UA Advisories

Beckhoff published an advisory discussing the OPC UA advisories. Beckhoff provides a list of affected products and has new versions that mitigate the vulnerabilities.

Belden published an advisory discussing the OPC UA advisories. Belden provides a list of affected products and has new versions that mitigate the vulnerabilities.

Braun Advisory

Braun published an advisory describing four vulnerabilities in a number of their products. The vulnerabilities were reported by McAfee Advanced Threat Research. Braun has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Insufficient verification of data authenticity,

• Missing authentication for critical function,

• Clear-text transmission of sensitive information, and

• Unrestricted upload of file with dangerous type.

SITEL Advisories

Incibe-Cert published an advisory describing a hard-coded credentials vulnerability in the SITEL CAP/PRX products. The vulnerability was reported by S21sec. SITEL has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Incibe-Cert published an advisory describing an exposure of sensitive information to an unauthorized actor vulnerability in the SITEL CAP/PRX products. The vulnerability was reported by S21sec. SITEL has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Incibe-Cert published an advisory describing a clear-text transmission of sensitive information vulnerability in the SITEL CAP/PRX products. The vulnerability was reported by S21sec. SITEL has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Incibe-Cert published an advisory describing an uncontrolled resource consumption vulnerability in the SITEL CAP/PRX products. The vulnerability was reported by S21sec. SITEL has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

PEPPERL+FUCHS Advisory

CERT-VDE published an advisory describing four vulnerabilities in the PEPPERL+FUCHS ICE1 Ethernet IO Modules. These are third-party (Hilscher) vulnerabilities. PEPPERL+FUCHS has provided generic mitigation measures.

The four reported vulnerabilities are:

• Out-of-bounds write (2) - CVE-2021-20987 and CVE-2021-20986,

• Improper restriction of operations within the bounds of a memory buffer - CVE-2021-20988, and

• Exposure of sensitive information to an unauthorized actor - CVE-2019-18222 (Mbed TLS)

CODESYS Advisories

CODESYS published an advisory describing three vulnerabilities in their CODESYS V2 runtime systems. The vulnerabilities were reported by Yossi Reuven of SCADAfence and Sergey Fedonin and Denis Goryushev of Positive Technologies. CODESYS has updates that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2021-30186,

• Stack-based buffer overflow - CVE-2021-30188, and

• Improper input validation - CVE-2021-30195

CODESYS published an advisory describing six vulnerabilities in their V2 web server. The vulnerabilities were reported by Vyacheslav Moskvin, Sergey Fedonin and Anton Dorfman of Positive

Technologies. CODESYS has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2021-30189,

• Improper access control - CVE-2021-30190,

• Buffer copy without checking size of input - CVE-2021-30191,

• Improperly implemented security check - CVE-2021-30192,

• Out-of-bounds write - CVE-2021-30193, and

• Out-of-bounds read - CVE-2021-30194

CODESYS published an advisory describing an improper neutralization of special elements used in an OS command vulnerability in their CODESYS V2 Runtime Toolkit 32. This is a Linux implementation vulnerability. The vulnerability was reported by van Kurnakov and Sergey Fedonin of Positive Technologies. CODESYS has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Dell Advisory

Dell published an advisory describing an improper authorization vulnerability in their Dell Wyse Windows Embedded System. The vulnerability was reported by Alessandro Baldini and Alessio D'Anastasio. Dell has updates that mitigate the vulnerability.

PulseSecure Advisories

PulseSecure published an advisory describing an HTTP request smuggling vulnerability in their Virtual Traffic Manager (vTM). The vulnerability was reported by James Kettle from PortSwigger Web Security.  PulseSecure has new versions that mitigate the vulnerability. There is no indication that Kettle has been provided an opportunity to verify the efficacy of the fix.

PulseSecure published an advisory describing a buffer overflow vulnerability in their Pulse Connect Secure. PulseSecure provides a work around pending development of a new version that will mitigate the vulnerability.

Saturday, May 1, 2021

Public ICS Disclosures – Week of 4-24-21

This week we three vendor NAME:WRECK disclosures from Boston Scientific, Braun, and Rockwell. We also have 14 vendor disclosures from Beckhoff, Bosch (2), B&R Industrial Automation, MB connect, CODESYS (5), Moxa, ODA, and Texas Instruments (2). We have five researcher reports for products from Advantech (4) and Siemens. Finally, we have exploits for products from OpenPLC and VMWare.

NAME:WRECK Advisories

Boston Scientific published an advisory discussing the NAME:WRECK vulnerabilities, announcing that they are investigating to see if any of their products are affected.

Braun published an advisory discussing the NAME:WRECK vulnerabilities, announcing that none of their ‘connected devices’ are affected.

Rockwell published an advisory discussing the NAME:WRECK vulnerabilities, providing a list of affected products and fixed versions.

Beckhoff Advisory

Beckhoff published an advisory describing an improper input validation vulnerability in their TwinCAT OPC UA Server and IPC Diagnostics UA Server. The vulnerability was reported by Industrial Control Security Laboratory of QI-ANXIN Technology Group. Beckhoff has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Bosch Advisories

Bosch published an advisory describing seven vulnerabilities in their ctrlX CORE - IDE App. These are third-party (OpenSSL and Python) vulnerabilities. The next version of the product will mitigate the vulnerabilities.

The seven reported vulnerabilities are:

• Improper encoding or escaping of output - CVE-2020-26116 (exploit),

• Inadequate information (NIST ?) - CVE-2020-27619,

• HTTP request smuggling - CVE-2021-23336 (exploit),

• Integer overflow or wraparound - CVE-2021-23840, CVE-2021-23841,

• Classic buffer overflow - CVE-2021-3177 (exploit), and

• NULL pointer dereference - CVE-2021-3449

Bosch published an advisory describing an FTP backdoor in their Rexroth Fieldbus Couplers. Bosch provides generic workarounds.

B&R Advisory

B&R published an advisory describing an uncontrolled resource consumption vulnerability in their  I/O system and HMI components. This is a third-party (Siemens) vulnerability. B&R provides generic workarounds.

MB Advisory

CERT-VDE published an advisory discussing the DNSpooq vulnerabilities in the MB connect mbNET products. MB connect has new versions that mitigate the vulnerabilities.

CODESYS Advisories

CODESYS published an advisory [.PDF download link] describing a cross-site request forgery vulnerability in their CODESYS Automation Server. The vulnerability was reported by Uri Katz of Claroty. CODESYS has a new version that mitigates this vulnerability. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

CODESYS published an advisory [.PDF download link] describing a NULL pointer dereference vulnerability in their CODESYS V3 products containing the CmpGateway. The vulnerability was reported by Uri Katz of Claroty. CODESYS has a new version that mitigates this vulnerability. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

CODESYS published an advisory [.PDF download link] describing an insufficient verification of data authenticity vulnerability in their Development System V3. The vulnerability was reported by an OEM customer. CODESYS has a new version that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

CODESYS published an advisory [.PDF download link] describing describing an insufficient verification of data authenticity vulnerability in their Development System V3. The vulnerability was reported by Uri Katz of Claroty. CODESYS has a new version that mitigates this vulnerability. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

CODESYS published an advisory [.PDF download link] describing an improper input validation vulnerability in their V3 products and Control V3 Runtime System Toolkit. The vulnerability was reported by Alexander Nochvay from Kaspersky Lab ICS CERT. CODESYS has a new version that mitigates the vulnerability. There is no indication that Nochvay has been provided an opportunity to verify the efficacy of the fix.

Moxa Advisory

Moxa published an advisory describing four vulnerabilities in their NPort IA5000A Series Serial Device Servers. The vulnerability was reported by Alexander Nochvay from Kaspersky Lab ICS CERT. Moxa has a new version to mitigate one of the vulnerabilities and workarounds for the others. There is no indication that Nochvay has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities:

• Improper access control - CVE-2020-27149,

• Unprotected storage of credentials - CVE-2020-27150,

• Cleartext transmission of sensitive information (2) - CVE-2020-27184 and CVE-2020-27185

ODA Advisory

ODA published an advisory describing an out-of-bounds write vulnerability in their Open Design Alliance Drawings SDK. ODA has a new version that mitigates the vulnerability.

NOTE: This is a very minimalist advisory.

TI Advisories

TI published an advisory discussing the BadAlloc vulnerabilities in their SimpleLink™ CC13XX, CC26XX, CC32XX and MSP432E4 products. TI provides generic work arounds for these vulnerabilities.

TI published an advisory describing an integer overflow vulnerability in their Networks Developers Kit. The vulnerability was reported by Omri Ben Bassat and David Atch of Microsoft. The product is no longer supported.

Advantech Report

The Zero Day Initiative published four reports for vulnerabilities in the Advantech WebAccess/HMI Designer products. The vulnerabilities were reported by kimiya and have been coordinated with NCCIC-ICS and an advisory from them is pending.

The four reported vulnerabilities are:

• Heap-based buffer overflow - ZDI-21-490 and ZDI-21-487,

• File parsing memory corruption- ZDI-21-489, and

• Out-of-bounds write - ZDI-21-488,

Siemens Report

ZDI published a report describing an information validation vulnerability in the Siemens JT2Go product. The vulnerability was reported by Michael DePlante. ZDI has been coordinating with NCCIC-ICS since last September.

OpenPLC Exploit

Fellipe Oliveira published an exploit for a remote code execution vulnerability in the OpenPLC product. There is no CVE provided and no indications of coordination with the vendor. This may be a 0-day vulnerability.

VMware Exploit

Egor Dimitrenko published a Metasploit module for two vulnerabilities in the VMware vRealize Operations Manager. The vulnerabilities were reported by VMware on March 31st, 2021.

The two exploited vulnerabilities are:

• Server-side request forgery - CVE-2021-21975, and

• Arbitrary file write - CVE-2021-21983


Saturday, December 12, 2020

Public ICS Disclosures – Week of 12-5-20, Part I

This week we have twelve vendor notification from ABB, HMS, and Cisco (10). There are vendor updates available for products from Mitsubishi and Beckhoff.

ABB Advisory

ABB published an advisory describing a VPN gateway vulnerability inn their Arctic wireless gateways. ABB says that this is a set-up issue and provides additional guidance on proper configuration to mitigate this vulnerability.

HMS Advisory

HMS published an advisory discussing the Amensia33 vulnerabilities. The advisory provides a list of HMS products that are currently known to not be affected by the vulnerabilities.

Cisco Advisories

Cisco published ten advisories for vulnerabilities in their IoT Field Network Director. Each advisory reports on a separate vulnerability in the same product/version. The links for the CVE number are to the individual advisories.

• Cross-site scripting - CVE-2020-26081,

• Improper domain access control - CVE-2020-26080,

• Insufficient input validation - CVE-2020-26075,

• Unprotected storage of credentials - CVE-2020-26079,

• File overwrite - CVE-2020-26078,

• Improper access control - CVE-2020-26077,

• Missing authentication for critical function - CVE-2020-3531 and CVE-2020-3392,

• Information disclosure - CVE-2020-26076, and

• Authorization bypass - CVE-2020-26072,

NOTE: These advisories date back to November 18th, but I just ran across them today thanks to their listing on the Russian FSTEC web site. No cause for concern there (SIGH).

Mitsubishi Update

Mitsubishi published an update for their MC Works 64 advisory that was originally published on June 18th, 2020 and most recently updated on September 9th, 2020. The new information includes adding security patches for MC Works64 Version 3.00A - 3.04E.

NOTE: NCCIC-ICS published an advisory for these vulnerabilities back in June but has not yet updated it for either of the updates that Mitsubishi has published.

Beckhoff Update

Beckhoff published an update for their TwinCAT System Tray advisory that was originally published on November 19th, 2020. The new information includes a script for re-installing the software in a manner that mitigates the vulnerability.

Part II

As is fast becoming a ‘tradition’ here on the weekend following the second Tuesday of the month, I will publish Part II of this blog post tomorrow, looking at the advisories and updates from Siemens and Schneider that NCCIC-ICS did not address earlier in the week.

Saturday, November 21, 2020

Public ICS Disclosures – Week of 11-14-20

This week we have six vendor disclosures from Beckhoff, ENDRESS+HAUSER (2), GE Grid (2), and Medtronic. We have one Ripple20 advisory update for products from Eaton. We also have a researcher report on vulnerabilities in products from Schneider. Finally, we have reports of exploits for products from Rockwell and the Netlogon vulnerability in Microsoft products.

Beckhoff Advisory

CERT-VDE published an advisory describing an incorrect default permissions vulnerability in the Beckhoff TwinCAT XAR product. The vulnerability was reported by Ayushman Dutta. Beckhoff has provided installation instructions to mitigate the vulnerability. There is no indication that Dutta has been provided an opportunity to verify the efficacy of the fix.

ENDRESS+HAUSER Advisories

CERT-VDE published an advisory describing an exposure of sensitive information to an unauthorized actor vulnerability in the ENDRESS+HAUSER Ecograph T products. The vulnerability was reported by Maxim Rupp. ENDRESS+HAUSER has provided generic workarounds to mitigate the vulnerability.

CERT-VDE published an advisory describing an improper privilege management vulnerability in the ENDRESS+HAUSER Ecograph T products. The vulnerability was reported by Maxim Rupp. ENDRESS+HAUSER has provided generic workarounds to mitigate the vulnerability.

GE Advisories

GE published an advisory for their Reason RT430/RT434. The advisory is only available to registered customers.

GE published an advisory for their Reason RT431. The advisory is only available to registered customers.

Medtronic Advisory

Medtronic published an advisory discussing the TiYunZong vulnerabilities found in the CT900 Samsung Android tablets used to run their Clinical Programmer Applications. A Chrome browser update is available to mitigate the vulnerabilities.

NOTE: I wonder what other vendors using Android products for access devices could be susceptible to these vulnerabilities?

Eaton Update

Eaton published an update for their Ripple20 advisory that was originally published on June 23rd, 2020 and most recently updated on October 5th, 2020. The new information includes adding the Uninterrupted Power Supply (UPSs) with ModbusMS card to the list of affected products.

Schneider Report

Trustwave published a report describing their research into vulnerabilities in the Schneider EcoStruxure Machine Expert and M221 PLC. The vulnerabilities were reported by Schneider on October 10th, 2020. The report includes proof-of-concept code.

Rockwell Exploit

The Flashback team published a Metasploit module for vulnerabilities in the Rockwell FactoryTalk View SE SCADA product. These vulnerabilities were reported by CISA NCCIC-ICS on June 18th, 2020.

Netlogon Exploit

West Shepherd published a proof-of-concept exploit for the Netlogon vulnerabilities reported by Microsoft.

NOTE: I have not seen this vulnerability reported in control system products, but it has been reported by medical device manufacturers (see for example BD).

Saturday, June 20, 2020

Public ICS Disclosures – Week of 6-13-20


This week we have eight vendor disclosures (3 for the Ripple20 vulnerabilities) for products from Beckhoff, Moxa, Medtronic, GE Health, Draeger (2), Rockwell, and BD. There is also a researcher report of a zero-day for products from Inductive Automation.

Ripple20 Advisories


Medtronic published a Ripple20 advisory reporting no impact.

GE Healthcare published a Ripple20 advisory reporting no impact but advising that there may be possible impact to third party components used in combination with GE Healthcare products.

Draeger published a Ripple 20 advisory reporting no impact.

NOTE: “No impact” reports are valuable information. I think the GE nuanced ‘no impact’ report is important where the vendor software may be running on a machine that includes other non-vendor produced software (perhaps including OS?).

Beckhoff Advisory


CERT-VDE published an advisory describing an information leak vulnerability in the Beckhoff TwinCAT RT network driver. The vulnerability is self-reported. Beckhoff has patches that mitigate the vulnerability.

Moxa Advisory


Moxa published an advisory describing a stack-based buffer overflow vulnerability in their EDR-G902 Series and EDR-G903 Series Secure Routers. The vulnerability was reported by Tal Keren from Claroty. Moxa has new firmware to mitigate the vulnerability. There is no indication that Keren has been provided an opportunity to verify the efficacy of the fix.

Draeger Advisory


Draeger published an advisory describing an improper input validation vulnerability in their Perseus A500 product. The vulnerability is self-reported. Draeger has new software that mitigates the vulnerability.

Rockwell Vulnerability


Rockwell published an advisory describing a path traversal advisory in their FactoryTalk Linx software. This vulnerability was discovered in the ZDI Pwn2Own competition in this year’s S4 Security conference. Rockwell has a patch that mitigates the vulnerability.

NOTE: Rockwell reports that they had previously disclosed this vulnerability in an advisory that was published on June 11th, 2020. I suppose that the Pwn2Own announcement could have been included as an update to that advisory. This may be why NCCIC-ICS has not picked up this advisory.

BD Advisory


BD published an advisory describing a remote code execution vulnerability in a number of BD products that use the Microsoft Windows 10®. This is a third-party (MS) SMBv3 server vulnerability. BD is currently working to test and validate the Microsoft patch on the affected products.

Inductive Automation Advisory


The Zero Day Initiative published an advisory describing a deserialization of untrusted data information disclosure vulnerability in the Inductive Automation Ignition product. The vulnerability was reported by Chris Anastasio (muffin) and Steven Seeley (mr_me) of Incite Team. This vulnerability was discovered in the ZDI Pwn2Own competition in this year’s S4 Security conference and reported to the vendor. The vendor has not been able to provide an estimated fix date to either ZDI or NCCIC-ICS. This is effectively a zero-day vulnerability.

 
/* Use this with templates/template-twocol.html */