Showing posts with label C3i Center. Show all posts
Showing posts with label C3i Center. Show all posts

Thursday, February 13, 2020

2 Advisories Published – 2-13-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Schneider Electric.

Magelis HMI Panel Advisory


This advisory describes an improper check for unusual or exceptional conditions vulnerability in the Schneider Magelis HMI Panel. The vulnerability was reported by VAPT Team, C3i Center. Schneider has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a denial-of-service condition.

NOTE: I briefly discussed this vulnerability last August.

Modicon Ethernet Serial RTU Advisory


This advisory describes three vulnerabilities in the Schneider Modicon BMXNOR0200H Ethernet/Serial RTU module. The vulnerability was reported by VAPT Team, C3i Center. Schneider has provided generic workarounds to mitigate the vulnerability.

The three reported vulnerabilities are:

• Improper check for unusual or exception conditions (2) - CVE-2019-6813 and CVE-2019-6831; and
• Improper access control - CVE-2019-6810

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote code execution or cause a denial-of-service condition.

NOTE: I briefly discussed this vulnerability last August.

Other Schneider Advisories


While NCCIC-ICS was covering these two 5-month old vulnerability reports, Schneider was publishing three new advisories this week. I will cover them this weekend.

Thursday, October 17, 2019

2 Advisories Published – 10-17-19


Today the DHS NCCIC-ICS published two control system security advisories for products from Horner Automation and AVEVA.

Horner Advisory


This advisory describes two vulnerabilities in the Horner Cscape control system application programming software. The vulnerabilities were reported by Francis Provencher of Protek Research Lab via the Zero Day Initiative. Horner has a new version that mitigates the vulnerabilities. There is no indication that Provencher has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Improper input validation - CVE-2019-13541; and
Out-of-bounds write - CVE-2019-13545

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to crash the device being accessed, which may allow the attacker to access information and execute arbitrary code.

AVEVA Advisory


This advisory describes a stack-based overflow vulnerability in the AVEVA Vijeo Citect and Citect SCADA. The vulnerability is in the IEC870IP driver. The vulnerability was reported by VAPT Team, C3i Center. AVEVA has a new version of the driver that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to cause a server-side crash.

Thursday, May 30, 2019

One Advisory Published – 05-30-19


Today the DHS NCCIC-ICS published a control system security advisory for products from AVEVA. The advisory describes an insufficiently protected credentials vulnerability in the AVEVA Vijeo Citect and CitectSCADA software. The vulnerability was reported by VAPT Team, C3i Center, and IIT Kanpur. AVEVA is recommending upgrading to a newer product; CitectSCADA 2018. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could exploit the vulnerability to allow a locally authenticated user to obtain Citect user credentials.


 
/* Use this with templates/template-twocol.html */