Showing posts with label Braun. Show all posts
Showing posts with label Braun. Show all posts

Thursday, October 20, 2022

Review – 1 Advisory and 2 Updates Published – 10-20-22

Today CISA’s NCCIC-ICS published a control system security advisory for products from Bentley Systems. They also updated two medical device security advisories for products from Braun.

Bentley Advisory - This advisory describes two vulnerabilities in the Bentley MicroStation Connect.

Braun Update #1 - This update provides additional information on an advisory that was originally published on October 22nd, 2020.

Braun Update #2 - This update provides additional information on an advisory that was originally published on October 21st, 2021.

 

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-and-2-updates-published-e54 - subscription required.


Saturday, April 30, 2022

Review – Public ICS Disclosures – Week of 4-23-22 – Part 1 -

This is another busy week necessitating two-part coverage. In part 1 this week we have nineteen vendor disclosures from ABB, Bender, Bosch, Braun (2), DrayTek, Eaton (5), HPE, Meile, PEPPERL+FUCHS, Philips (2), and Pilz (3).

ABB Advisory - ABB published an advisory discussing six vulnerabilities in their AC 500 PLCs.

Bender Advisory - CERT-VDE published an advisory describing seven vulnerabilities in the Bender/ebee Charge Controller products.

Bosch Advisory - Bosch published an advisory discussing an infinite loop vulnerability in their FL MGUARD and TC MGUARD safety devices.

Braun Advisory #1 - Braun published an advisory discussing the NAME:WRECK vulnerabilities.

Braun Advisory #2 - Braun published an advisory discussing the Amnesia:33 vulnerabilities.

DrayTek Advisory - DrayTek published an advisory discussing an infinite loop vulnerability in their Vigor routers.

Eaton Advisory #1 - Eaton published an advisory discussing TLStorm vulnerabilities and the Havex trojan as being used by the Berserk Bear APT group against UPS systems.

Eaton Advisory #2 - Eaton published an advisory discussing the SpringShell vulnerabilities.

Eaton Advisory #3 - Eaton published an advisory discussing sixteen vulnerabilities (six with known exploits) in their Form 7 recloser control. These are third-party (CODESYS) vulnerabilities.

Eaton Advisory #4 – Eaton published an advisory discussing the INCONTROLLER ICS attack tools.

Eaton Advisory #5 - Eaton published an advisory discussing the TLStorm vulnerabilities.

HPE Advisory - HPE published an advisory discussing three vulnerabilities (one with known exploits) in their SimpliVity Omnistack for Hyper-V.

Meile Advisory - CERT-VDE published an advisory describing an improper privilege management vulnerability (with publicly available exploit) in their Benchmark Programming Tool.

PEPPERL+FUCHS Advisory - CERT-VDE published an advisory discussing a remote code execution vulnerability in VisuNet devices from PEPPERL+FUCHS.

Philips Advisory #1 - Philips published an advisory discussing a remote code execution vulnerability.

Philips Advisory #2 - Philips published an advisory discussing a denial of service vulnerability.

Pilz Advisory #1 - CERT-VDE published an advisory discussing ten vulnerabilities (one with publicly available exploit) in the Pilz PMC programming tool.

Pilz Advisory #2 - CERT-VDE published an advisory discussing 27 vulnerabilities (nine with publicly available exploits) in the Pilz PMC programming tool.

Pilz Advisory #3 - CERT-VDE published an advisory discussing 18 vulnerabilities (four with publicly available exploits) in motion controller products from Pilz.

 

For more details on these advisories, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-bda - subscription required.

Saturday, April 9, 2022

Review - Public ICS Disclosures – Week of 4-2-22 – Part 1

A busy week with lots of SpringShell and DirtyPipe disclosures, so there will be two parts this week. In this part we have 24 vendor disclosures from Aruba, Barco, Bentley (8), Braun, Broadcom (3), Carrier, Weidmueller, WAGO, CODESYS (6), and FANUC.

Aruba Advisory - Aruba published an advisory discussing the SpringShell vulnerabilities.

Barco Advisory - Barco published an advisory discussing the DirtyPipe vulnerability.

Bentley Advisory #1 - Bentley published an advisory describing two use after free vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #2 - Bentley published an advisory describing three stack-based buffer overflow vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #3 - Bentley published an advisory describing an out-of-bounds write vulnerability in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #4 - Bentley published an advisory describing eleven file parsing vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #5 - Bentley published an advisory describing two out-of-bounds read vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #6 - Bentley published an advisory describing five out-of-bounds vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #7 - Bentley published an advisory describing four out-of-bounds read vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #8 - Bentley published an advisory describing two unitialized variable vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Braun Advisory - Braun published an advisory discussing the Infusion Pump Vulnerabilities article by Palo Alto Networks.

Broadcom Advisory #1 - Broadcom published an advisory discussing one of the SpringShell vulnerabilities.

Broadcom Advisory #2 - Broadcom published an advisory describing the other SpringShell vulnerability.

Broadcom Advisory #3 - Broadcom published an advisory discussing an older Spring Framework vulnerability reanimated by the SpringShell vulnerability.

Carrier Advisory - Carrier published an advisory discussing the SpringShell vulnerabilities.

Weidmueller Advisory - CERT-VDE published an advisory discussing nine vulnerabilities in two products using Modbus TCP/RTU Gateways.

WAGO Advisory - CERT-VDE published an advisory discussing the DirtyPipe vulnerability in several WAGO products.

CODESYS Advisory #1 - CODESYS published an advisory describing an exposure of resource to wrong sphere vulnerability in the CODESYS Control V3 products.

CODESYS Advisory #2 - CODESYS published an advisory describing an incorrect permission assignment for a critical resource vulnerability in the CODESYS SysDrv3S.sys driver.

CODESYS Advisory #3 - CODESYS published an advisory describing a small space of random values vulnerability in CODESYS V3 products using the CODESYS communication protocol.

CODESYS Advisory #4 - CODESYS published an advisory describing an incorrect user management vulnerability in the  CODESYS Control V3 online user management applications.

CODESYS Advisory #5 - CODESYS published an advisory describing two vulnerabilities in CODESYS V3 products containing a CODESYS communication server.

CODESYS Advisory #6 - CODESYS published an advisory describing a buffer over read vulnerability in the CODESYS V3 web server.

 

For more details on these disclosures, including links to 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/22-part-1 - subscription required.

Saturday, April 2, 2022

Review – Public ICS Disclosures – Week of 3-26-22 – Part 1

Another busy week. This week, for Part 1 we have fifteen vendor disclosures from Bosch, Braun, Broadcom (2), Carrier, GE Gas Power, Hitachi, Hitachi Energy, HPE, Mitsubishi, Palo Alto Networks (2), Philips (2), and Phoenix Contact.

Bosch Advisory - Bosch published an advisory describing two stack-based buffer overflows in the recovery image process in their CPP Firmware.

Braun Advisory - Braun published an advisory discussing the PaloAlto Networks report on infusion pump vulnerabilities.

Broadcom Advisory #1 - Broadcom published an advisory discussing the 23 reported vulnerabilities in Insyde's H2O UEFI firmware.

Broadcom Advisory #2 - Broadcom published an advisory describing an inadequate cryptographic key implementation vulnerability in their Brocade Fabric OS (FOS) for older generation platforms.

Carrier Advisory - Carrier published an advisory discussing the LAPSUS$ attack on Octa.

GE Advisory - GE published an advisory discussing the SpringShell vulnerabilities.

Hitachi Advisory - Hitachi published an advisory discussing 31 vulnerabilities in their Disk Array products.

Hitachi Energy Advisory - Hitachi Energy published an advisory discussing the Spring4Shell vulnerabilities.

HPE Advisory - HPE published an advisory describing four vulnerabilities in the HPE OneView product.

Mitsubishi Advisory - Mitsubishi published an advisory discussing the Log4Shell vulnerabilities in their CC-Link IE TSN Configurator.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory discussing an infinite loop vulnerability in their PAN-OS products.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory discussing the Spring4Shell vulnerabilities.

Philips Advisory #1 - Philips published an advisory discussing six vulnerabilities in their IntelliVue XDS and VuePACS products.

Philips Advisory #2 - Philips published an advisory discussing an authentication bypass by spoofing vulnerability.

Phoenix Contact Advisory - Phoenix Contact published and advisory discussing 15 vulnerabilities (2 with known exploits) in their PROFINET SDK.

 

For more information on these disclosures, including links to researcher reports, 3rd-party vendor advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-113 - subscription required.

Saturday, March 5, 2022

Review - Public ICS Disclosures – Week of 2-26-22

This week we have twelve vendor disclosures from ABB, Beckhoff, Broadcom (2), B&R Automation, Delta Industrial Automation, Gerbv, OMRON, PcVue Solutions, Tanzu (2), and VMware. We also have two end-of-life notices from We have one researcher report for products from Swift Sensors. Finally, we have four exploits reported for products from WAGO, Hikvision, Axis, and the PwnKit vulnerability.

ABB Advisory - ABB published an advisory describing a denial of service vulnerability in their AC 800M MMS.

Beckhoff Advisory - Beckhoff published an advisory discussing a NULL pointer dereference vulnerability in their products with OPC UA technology.

NOTE: This vulnerability may be found in other vendor products utilizing OPC UA technology.

Broadcom Advisory #1 - Broadcom published an advisory discussing the LOGBACK-1591 vulnerability in their Brocade Fibre Channel Products.

Broadcom Advisory #2 - Broadcom published an advisory discussing the Log4Shell vulnerabilities.

B&R Advisory - B&R published an advisory discussing a deserialization of untrusted data vulnerability in their B&R APROL product line.

NOTE: This vulnerability may affect other vendor products that use Apache Chainsaw.

Delta Advisory - Incibe CERT published an advisory describing four vulnerabilities in the Delta CNCSoft ScreenEditor, and DIAEnergie products.

Gerbv Advisory - Incibe CERT published an advisory discussing seven vulnerabilities in the Gerbv file view.

Omron Advisory - JP CERT published an advisory describing five vulnerabilities in the OMRON CX-Programmer.

PcVue Advisory - PcVue published a notice discussing four vulnerabilities in their Dream Report products.

Tanzu Advisory #1 - Tanzu published an advisory describing an improper privilege management vulnerability in their Spring Cloud Gateway.

Tanzu Advisory #2 - Tanzu published an advisory describing a code injection vulnerability in their Spring Cloud Gateway.

VMware Advisory - VMware published an advisory describing an uncontrolled search path vulnerability in their VMware Tools for Windows.

Swift Sensor Report - Cisco Talos published a report describing an authentication bypass vulnerability in the Swift Sensor Gateway.

Braun End-of-Life Notices - Braun USA published end-of-life notices for their Dialog+ Version 8 and Dia70 Portable RO products.

WAGO Exploit - Momen Eldawakhly published an exploit for a privilege escalation vulnerability in the WAGO 750-8212 PFC200 G2 2ETH RS.

Hikvision Exploit - Bashis published a Metasploit module for a command injection vulnerability in unspecified Hikvision IP Camera.

Axis Exploit - Jbaines-r7 published a Metasploit module for an unrestricted upload of applications ‘feature’ in unspecified Axis IP cameras.

PwnKit Exploit - Qualys Security published a Metasploit module for the PwnKit vulnerability.

 

For more details about these disclosures, including links to third-party reports, researcher reports and exploits, see my article at CFSN Detailed Analysis - - subscription required.

Saturday, December 18, 2021

Review - Public ICS Disclosures – Week of 12-10-21 – Part 1

This week I am going to have to do a three-part report instead of the standard two-part for the weekend following 2nd Tuesday. Part 3 will deal with just Log4Shell advisories. So, for Part 1, we have 17 vendor advisories from Braun (2), Draeger, FANUC, Hitachi Energy (4), HPE, Mitsubishi Electric, Moxa, Rockwell Automation, QNAP (3), Sick, and VMware (2).

Braun Advisory #1 - Braun (USA) published an advisory discussing the NUCLEUS:13 vulnerabilities.

Braun Advisory #2 - Braun (USA) published an advisory discussing the INFRA:HALT vulnerabilities.

Draeger Advisory - Draeger published an advisory describing a privilege escalation vulnerability in their Service Connect Gateway.

FANUC Advisory - FANUC published an advisory describing two vulnerabilities in their Robot Controllers.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory discussing the BadAlloc vulnerabilities in their PWC600 controller.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory discussing the BadAlloc vulnerabilities in their GMS600 monitoring device.

Hitachi Energy Advisory #3 - Hitachi Energy published an advisory discussing the BadAlloc vulnerabilities in their Relion REB500 intelligent electronic devices (IEDs).

Hitachi Energy Advisory #4 - Hitachi Energy published an advisory discussing the BadAlloc vulnerabilities in their Relion 670, 650 series and SAM600-IO IEDs.

HPE Advisory - HPE published an advisory describing a buffer overflow vulnerability in their HPE Gen10 and Gen10 Plus Servers.

Mitsubishi Advisory - Mitsubishi published an advisory discussing three of the INFRA:HALT vulnerabilities in their MELSEC Series Remote I/O.

Moxa Advisory - Moxa published an advisory describing a command injection vulnerability in their NPort W2150A/W2250A Series Serial Device Servers.

Rockwell Advisory - Rockwell published an advisory discussing two vulnerabilities in their 1783 network address translation router (NATR).

QNAP Advisory #1 - QNAP published an advisory describing a stack-based buffer overflow vulnerability in their Surveillance Station.

QNAP Advisory #2 - QNAP published an advisory describing a reflected XSS vulnerability in their Kazoo Server.

QNAP Advisory #3 - QNAP published an advisory describing an improper authentication vulnerability in their Qfile for Android application.

Sick Advisory - Sick published an advisory describing three vulnerabilities in their SOPAS ET software.

VMware Advisory #1 - VMware published an advisory describing a server side request forgery in their  ONE UEM console.

VMware Advisory #2 - VMware has published an advisory describing two vulnerabilities in their Workspace ONE Access product.

For more details on these advisories, including links to researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-66f - subscription required.

Saturday, November 20, 2021

Review - Public ICS Disclosures – Week of 11-13-21 – Part 1

Review - Public ICS Disclosures – Week of 11-13-21 – Part 1

This has been a very busy week for vendor disclosures, so I will be doing this as a two-part report again this week. This week we have 17 vendor disclosures from Blackberry, Braun (2), WAGO (3), Dell, Gallagher (6), and ABB (4).

Blackberry Advisory - Blackberry published an advisory describing a remote code execution vulnerability in their QNX Software Development Platform.

Braun Advisory #1 - Braun published an advisory discussing the NUCLEUS:13 vulnerabilities.

Braun Advisory #2 - Braun published an advisory discussing the INFRA:HALT vulnerabilities.

WAGO Advisory #1 - CERT-VDE published an advisory discussing six vulnerabilities in a number of WAGO PLCs.

WAGO Advisory #2 - CERT-VDE published an advisory discussing an improper handling of exceptional conditions vulnerability in a number of WAGO PLC’s.

WAGO Advisory #3 - CERT-VDE published an advisory discussing the NUCLEUS:13 vulnerabilities.

Dell Advisory - Dell published an advisory describing five vulnerabilities in their Wyse Management Suite.

Gallagher Advisory #1 - Gallagher published an advisory describing an unquoted service path vulnerability in their Controller Service.

Gallagher Advisory #2 - Gallagher published an advisory describing an improper privilege validation vulnerability in their Command Centre Server.

Gallagher Advisory #3 - Gallagher published an advisory describing an improper certificate validation vulnerability in their Command Centre Server.

Gallagher Advisory #4 - Gallagher published an advisory describing an improper validation of the cloud-certificate chain in their Mobile Connect for Android.

Gallagher Advisory #5 - Gallagher published an advisory describing an improper validation of the cloud-certificate chain in their Command Centre Mobile Client for Android.

Gallagher Advisory #6 - Gallagher published an advisory describing an incomplete comparison with missing factors vulnerability in their Gallagher Controller.

ABB Advisory #1 - ABB published an advisory discussing two vulnerabilities in their Hitachi Energy RTU500 series.

ABB Advisory #2 - ABB published an advisory discussing the BadAlloc vulnerabilities in their Hitachi Energy RTU500 series.

ABB Advisory #3 - ABB published an advisory discussing three vulnerabilities in their Hitachi Energy RTU500 Series.

ABB Advisory #4 - ABB published an advisory describing a validation error vulnerability in their Hitachi Energy RTU500 Series.

For more information on these advisories, including links to third-party advisories and exploits, see  my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-880 - subscription required.

Thursday, October 21, 2021

Review - 4 Advisories Published – 10-21-21

Today, CISA’s NCCIC-ICS published three control system security advisories for products from ICONICS/Mitsubishi (2) and Delta Electronics. They also published a medical device security advisory for products from Braun.

ICONICS/Mitsubishi Advisory #1 - This advisory describes an uncontrolled recursion vulnerability in the ICONICS GENESIS64 and Mitsubishi Electric MC Works64 products.

Delta Advisory - This advisory describes ten vulnerabilities in the Delta DIALink industrial automation server.

ICONICS/Mitsubishi Advisory #2 - This advisory describes two vulnerabilities in the ICONICS GENESIS64, Mitsubishi Electric MC Works64 products.

Braun Advisory - This advisory describes five vulnerabilities in the B. Braun Perfusor Space, Infusomat Space, SpaceCom, Battery Pack SP with WiFi products.

For more details on the advisories, including links to 3rd-party vendor reports and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-published-10-21-21 - subscription required.

Saturday, October 16, 2021

Review - Public ICS Disclosures – Week of 10-9-21 – Part 1

This week we have nine vendor disclosures from Aruba Networks, Braun, DrayTek, Omron, Hitachi, SonicWall, and VMware (3). We also have an update from Yokogawa. Finally, there are four researcher reports for products from Fuji Electric.

Aruba Advisory - Aruba published an advisory describing 18 vulnerabilities in their ClearPass Policy Manager product.

Braun Advisory - Braun published an advisory discussing the Ripple20 vulnerabilities.

DrayTek Advisory - DrayTek published an advisory describing two vulnerabilities in their VigorConnect software.

Omron Advisory - JPCERT published an advisory describing an out-of-bounds read vulnerability in the Omron CX-Supervisor.

Hitachi Advisory - Hitachi published an advisory discussing 30 vulnerabilities in their Disk Array Systems.

SonicWall Advisory - SonicWall published an advisory describing a host header redirection vulnerability in their SonicOS product.

VMware Advisory #1 - VMware published an advisory describing a server side request forgery in their vRealize Operations products.

VMware Advisory #2 - VMware published an advisory describing a CSV injection vulnerability in their vRealize Log Insight product.

VMware Advisory #3 - VMware published an advisory describing an open redirect vulnerability in their vRealize Orchestrator product.

Yokogawa Update - Yokogawa published an update for their Ripple20 advisory that was originally published on May 31st, 2021.

Fuji Reports - The Zero Day Initiative published four reports of 0-day vulnerabilities in the Alpha5 Servo Operator product from Fuji Electric.

For more details on this disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-61d - subscription required.


Saturday, August 28, 2021

Review - Public ICS Disclosures – Week of 8-21-27

This week we have six vendor disclosures from B&R, OPC Foundation, HPE, Red Lion, VMware (2). We also have one update from Mitsubishi. We also have one researcher report for products from Braun.

B&R Advisory - B&R published an advisory discussing the INFRA:HALT vulnerabilities.

OPC Foundation Advisory - The OPC Foundation published an advisory describing an access of memory location after end of buffer vulnerability in their Local Discovery Server (LDS).

HPE Advisory - HPE published an advisory describing five vulnerabilities in their FlexNetworking, Flexfabric, and MSR switches and routers.

Red Lion Advisory - Red Lion published an advisory describing an SSH port forwarding vulnerability in their DA50A and DA70A modular gateways.

VMware Advisory #1 - VMware published an advisory describing a cross-site scripting vulnerability in their vRealize Log Insight.

VMware Advisory #2 - VMware published an advisory describing six vulnerabilities in their vRealize Operations product.

Mitsubishi Update - Mitsubishi published an update for their TCP Protocol Stack advisory that was originally published on September 1st, 2020 and most recently updated on May 18th, 2021

Braun Report - McAffee published a report describing five vulnerabilities in the B Braun Infusomat Space Large Volume Pump.

 

For more details on these advisories, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-9fc - subscription required.

Saturday, May 15, 2021

Public ICS Disclosures – Week of 5-8-21, Part 1

This is a busier week than normal, even for a ‘Second Tuesday’ week. We have three vendor notifications for the FragAttacks WiFi vulnerabilities from Aruba, Ruckus, and Texas Instruments. We have two vendor notifications for the two OPC UA vulnerabilities reported this week by NCCIC-ICS from Beckhoff, Belden. We also have twelve other vendor notifications from Braun, SITEL (4), PEPPERL+FUCHS, CODESYS (3), Dell, and PulseSecure (2).

There will be a similarly lengthy list in Part 2 tomorrow.

FragAttacks Advisories

Aruba published an advisory discussing the FragAttacks vulnerabilities. Aruba provides a list of affected products and has new versions that mitigate the vulnerabilities.

Ruckus published an advisory discussing the FragAttacks vulnerabilities. Ruckus provides a list of affected products and has updates that mitigate the vulnerabilities.

TI published an advisory discussing the FragAttacks vulnerabilities. TI provides a list of affected products and has new versions that mitigate the vulnerabilities.

OPC UA Advisories

Beckhoff published an advisory discussing the OPC UA advisories. Beckhoff provides a list of affected products and has new versions that mitigate the vulnerabilities.

Belden published an advisory discussing the OPC UA advisories. Belden provides a list of affected products and has new versions that mitigate the vulnerabilities.

Braun Advisory

Braun published an advisory describing four vulnerabilities in a number of their products. The vulnerabilities were reported by McAfee Advanced Threat Research. Braun has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Insufficient verification of data authenticity,

• Missing authentication for critical function,

• Clear-text transmission of sensitive information, and

• Unrestricted upload of file with dangerous type.

SITEL Advisories

Incibe-Cert published an advisory describing a hard-coded credentials vulnerability in the SITEL CAP/PRX products. The vulnerability was reported by S21sec. SITEL has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Incibe-Cert published an advisory describing an exposure of sensitive information to an unauthorized actor vulnerability in the SITEL CAP/PRX products. The vulnerability was reported by S21sec. SITEL has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Incibe-Cert published an advisory describing a clear-text transmission of sensitive information vulnerability in the SITEL CAP/PRX products. The vulnerability was reported by S21sec. SITEL has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Incibe-Cert published an advisory describing an uncontrolled resource consumption vulnerability in the SITEL CAP/PRX products. The vulnerability was reported by S21sec. SITEL has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

PEPPERL+FUCHS Advisory

CERT-VDE published an advisory describing four vulnerabilities in the PEPPERL+FUCHS ICE1 Ethernet IO Modules. These are third-party (Hilscher) vulnerabilities. PEPPERL+FUCHS has provided generic mitigation measures.

The four reported vulnerabilities are:

• Out-of-bounds write (2) - CVE-2021-20987 and CVE-2021-20986,

• Improper restriction of operations within the bounds of a memory buffer - CVE-2021-20988, and

• Exposure of sensitive information to an unauthorized actor - CVE-2019-18222 (Mbed TLS)

CODESYS Advisories

CODESYS published an advisory describing three vulnerabilities in their CODESYS V2 runtime systems. The vulnerabilities were reported by Yossi Reuven of SCADAfence and Sergey Fedonin and Denis Goryushev of Positive Technologies. CODESYS has updates that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2021-30186,

• Stack-based buffer overflow - CVE-2021-30188, and

• Improper input validation - CVE-2021-30195

CODESYS published an advisory describing six vulnerabilities in their V2 web server. The vulnerabilities were reported by Vyacheslav Moskvin, Sergey Fedonin and Anton Dorfman of Positive

Technologies. CODESYS has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2021-30189,

• Improper access control - CVE-2021-30190,

• Buffer copy without checking size of input - CVE-2021-30191,

• Improperly implemented security check - CVE-2021-30192,

• Out-of-bounds write - CVE-2021-30193, and

• Out-of-bounds read - CVE-2021-30194

CODESYS published an advisory describing an improper neutralization of special elements used in an OS command vulnerability in their CODESYS V2 Runtime Toolkit 32. This is a Linux implementation vulnerability. The vulnerability was reported by van Kurnakov and Sergey Fedonin of Positive Technologies. CODESYS has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Dell Advisory

Dell published an advisory describing an improper authorization vulnerability in their Dell Wyse Windows Embedded System. The vulnerability was reported by Alessandro Baldini and Alessio D'Anastasio. Dell has updates that mitigate the vulnerability.

PulseSecure Advisories

PulseSecure published an advisory describing an HTTP request smuggling vulnerability in their Virtual Traffic Manager (vTM). The vulnerability was reported by James Kettle from PortSwigger Web Security.  PulseSecure has new versions that mitigate the vulnerability. There is no indication that Kettle has been provided an opportunity to verify the efficacy of the fix.

PulseSecure published an advisory describing a buffer overflow vulnerability in their Pulse Connect Secure. PulseSecure provides a work around pending development of a new version that will mitigate the vulnerability.

Saturday, September 5, 2020

Public ICS Disclosures – Week of 8-29-20


This week we have two new vendor disclosures for products from SICK and BD. There were also three Ripple20 [Corrected link, 10-18-20, 0857] updates published for products from HMS, Braun and Schneider. We also have a vendor update from Yokogawa. There is also one researcher report with exploits for vulnerabilities for products from Red Lion.

SICK Advisory


SICK published an advisory describing an improper handling of exceptional conditions vulnerability in their SOPAS Engineering Tool. The vulnerability was reported by Ruben Santamarta of IOActive. SICK has released new firmware versions that mitigate the vulnerability. There is no indication that Santamarta has been provided an opportunity to verify the efficacy of the fix.

BD Advisory


BD published an advisory describing three third-party (VMware) vulnerabilities in selected BD products. BD is currently testing the VMware update.

The three reported vulnerabilities are:

• Local privilege escalation - CVE-2020-3957,
• Denial of service - CVE-2020-3958, and
• Memory leak - CVE-2020-3959

Ripple20 Updates


HMS published an update of their Ripple20 advisory that was originally published on June 23, 2020. The new information includes adding the following products to the not affected list:

• Anybus M-Bus to Modbus TCP gateway,
• Anybus WLAN Access Points (AWB4xxx), and
• Ewon Netbiter 100, 200 and 300-series

Braun published an update of their Ripple20 advisory that was originally published on June 30th, 2020. The updated information includes more details on the Ripple20 effect on the Outlook 400ES infusion pump.

Schneider published an update of their Ripple20 advisory that was originally published on June 23, 2020 and most recently updated on August 6th, 2020. The new information includes:

• Adding mitigation measures for Cooling Products using NMC2, and
• Adding partial remediations for TM3BC bus coupler module – EIP, TM3BC bus coupler module – SL, and TM3BC bus coupler module – CANOpen

Yokogawa Update


Yokogawa published an update for their CAMS for HIS advisory that was originally published on July 31st, 2020. The new information includes updated affected product data.

Red Lion Report


SEC Consult published a report on multiple vulnerabilities in the Red Lion N-Tron products that were reported last week by CISA NCCIC-ICS. The SEC Consult report includes proof-of-concept exploit code and a list of outdated third-party components.

 
/* Use this with templates/template-twocol.html */