Showing posts with label CAREL. Show all posts
Showing posts with label CAREL. Show all posts

Thursday, June 20, 2024

Review – 3 Advisories Published – 6-20-24

Today, CISA’s NCCIC-ICS published three control system security advisories for products from Westermo, CAREL, and Yokogawa.

Advisories

Westermo Advisory - This advisory describes three vulnerabilities in the Westermo L210-F2G industrial ethernet switches.

CAREL Advisory - This advisory describes a path traversal vulnerability (with known exploit) in the CAREL Boss-Mini, a local supervisor solution.

Yokogawa Advisory - This advisory describes an improper access control vulnerability in the Yokogawa CENTUM distributed control system.

 

For more information about these advisories, including links to exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-published-6-20-24 - subscription required.

Saturday, July 2, 2022

Review – Public ICS Disclosures – Week of 6-25-22 – Part 2

For Part 2 we have ten vendor updates for CODESYS (6), Dell, HP (3), and HPE. We have six researcher reports for products from Robustel (4), ExpressLRS, and Carel.

CODESYS Update #1 - CODESYS published an update for their Control V3 configuration file advisory that was that was originally published on March 24th, 2022, and most recently updated on June 10th, 2022.

CODESYS Update #2 - CODESYS published an update for their CODESYS communication protocol advisory that was originally published on March 24th, 2022 and most recently updated on April 6th, 2022

CODESYS Update #3 - CODESYS published an update for their Control V3 online user management advisory that was originally published on March 24th, 2022 and most recently updated on April 6th, 2022.

CODESYS Update #4 - CODESYS published an update for their V3 products containing a CODESYS communication server that was originally published on March 24th, 2022 and most recently updated on April 6th, 2022.

CODESYS Update #5 - CODESYS published an update for their V3 web server advisory that was originally published on March 24th, 2022 and most recently updated on April 6th, 2022.

CODESYS Update #6 - CODESYS published an update for their V3 products containing a CODESYS communication server advisory that was originally published on May 19th, 2022 and most recently updated on May 30th, 2022.

Dell Update - Dell published an update for their Wyse ThinOS advisory that was originally published on July 21st, 2021.

HP Update #1 - HP published an update for their Intel® Boot Guard and Intel® TXT Security advisory that was originally published on May 10th, 2022.

HP Update #2 - HP published an update for their Intel 2022.1 IPU BIOS advisory that was originally published on July 21st, 2021.

HP Update #3 - HP published an update for their AMD Client UEFI Firmware advisory that was originally published on July 21st, 2021.

HPE Update - HPE published an update for their HP-UX Using OpenSSL advisory that was originally published on May 19th, 2022.

Robustel Reports – Cisco Talos published four reports for ten vulnerabilities in the Robustel R1510 web server.

ExpressLRS Report - NCC Group published a report describing a discoverable binding phrase for radio linkages in the ExpressLRS radio control link.

Carel Report - Zero Science published a report describing a directory traversal vulnerability in the Carel pCOWeb HVAC BACnet Gateway.

 

For more details on these updates and reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-2ec  - subscription required.

Saturday, November 2, 2019

Public ICS Disclosures – Week of 10-26-19


This week we have four vendor disclosures from Phoenix Contact, ABB, Johnson Controls, and BD. There are three vendor updates from 3S, Yokogawa, and Belden. There are also three exploit reports from researchers for products from Carel and Intelligent Security Systems. The later may be a 0-day exploit.

Phoenix Contact Advisory


Phoenix Contact published an advisory [.PDF download link] describing an unauthorized access vulnerability in their FL NAT industrial ethernet switch/router. The vulnerability is self-reported. Phoenix Contact provides generic mitigation measures pending the development of new firmware.

ABB Advisory


ABB published an advisory describing an authentication bypass vulnerability in their Power Generation
Information Manager. The vulnerability was reported by Rikard Bodforss at CS3STHLM. ABB has a new version that mitigates the vulnerability. Bodforss has verified the efficacy of the fix.

NOTE: The disclosure blog post by Bodforss has an excellent discussion about the vulnerability disclosure dilemma from the viewpoint of a researchers. Well worth reading.

Johnson Controls Advisory


Johnson Controls has published an advisory describing two vulnerabilities in their FX Supervisory Controller. The vulnerabilities were reported in the third-party QNX operating system. Johnson Controls has patches to mitigate the vulnerability and a new version to be released later this month will fully address the problems.

The two reported vulnerabilities are:

• Information exposure - CVE-2019-8998; and
• Improper authorization - CVE-2019-13528

NOTE 1: I wonder if NCCIC-ICS will update their Tridium advisory to provide a link to this advisory? Nah.

NOTE 2: Just another case of wondering what other vendors use the same vulnerable operating system?

BD Advisory


BD has published an advisory for the DejaBlue remote desktop vulnerabilities in their products. BD has provided generic work arounds while it continues to test and validate the Microsoft patch for BD products.

3S Update


3S published an update of their CODESYS ENI server advisory that was originally published on September 12, 2019. The new information includes:

Additional mitigation measure;
Mitigated version updated; and
CVE added

Yokogawa Update


Yokogawa published an update of their unquoted service path advisory that was originally published on September 27th, 2019 and most recently updated on October 24th. The new information is another change to the Exaquantum mitigation.

Belden Update


Belden published an update of their URGENT/11 advisory that was originally published on July 11th, 2019 and most recently updated on September 5th. The new information includes updated mitigation information for their EAGLE and EAGLE one products.

Carel Exploits


Red Team Pentesting published exploit code for an unsafe storage of credentials vulnerability in the Carel pCOWeb card. This vulnerability was previously reported in the Rittal Chiller using the pCOWeb card. Red Team Pentesting reports that Carel consideres this product obsolete and no longer provides updates for the firmware.

Red Team Pentesting published exploit code for an unauthenticated access to modbus interface vulnerability in the Carel pCOWeb card. This vulnerability was previously reported in the Rittal Chiller using the pCOWeb card. Red Team Pentesting reports that Carel consideres this product obsolete and no longer provides updates for the firmware.

Intelligent Security System Exploit


Alberto Vargas published exploit code for an unquoted service path vulnerability in the Intelligent Security System SecurOS Enterprise. There is no indication that this disclosure was coordinated with the vendor so this may be a 0-day exploit.

Thursday, January 21, 2016

ICS-CERT Publishes Two Advisories

This morning the DHS ICS-CERT published two advisories for control systems from Hospira and CAREL.

Hospira Advisory

This advisory describes a buffer overflow vulnerability in two older versions of Hospira infusion pumps. The vulnerability was reported by Jeremy Richards of SAINT Corporation. Existing newer versions of the software do not contain the vulnerability.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to “to remotely execute code on the affected device”. ICS-CERT notes that neither Hospira or Richards have demonstrated the code execution outcome, but it includes the possibility out of an abundance of caution.

In addition to updating to newer versions of the software, ICS-CERT recommends the following mitigation measures for these devices:

• Ensure that unused ports are closed on the affected devices to include Port 20/FTP, Port 21/FTP, and Port 23/TELNET.
• Ensure that the default password used to access Port 8443 has been changed, or verify that the port is closed.
• Closing Port 5000/TCP does not impact the intended use of the device.
• Monitor and log all network traffic attempting to reach the affected products, to include Port 20/FTP, Port 21/FTP, Port 23/TELNET, Port 8443, and Port 5000/TCP.
• Isolate all medical devices from the Internet and untrusted systems.
• Produce a hash of key files to identify any unauthorized changes.

Hospira’s infusion pump web site contains two cybersecurity links for previously identified infusion pump vulnerabilities. It does not, however, mention this newly discovered vulnerability.

CAREL Advisory

This advisory describes an authorization bypass vulnerability in the CAREL PlantVisor application. The vulnerability was reported by Maxim Rupp. CAREL will not be fixing the vulnerability since the devices is no longer supported (replaced by newer product in 2007).


ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to gain system access.
 
/* Use this with templates/template-twocol.html */