Showing posts with label COPA-Data. Show all posts
Showing posts with label COPA-Data. Show all posts

Thursday, October 1, 2020

1 Update Published – 10-1-20

 Today the CISC NCCIC-ICS published a control system security update for the CodeMeter vulnerabilities from Wibu-Systems.

CodeMeter Update

This update provides additional information that was originally published on September 8th, 2020 and most recently updated on September 17th, 2020. The new information includes links to new affected vendor disclosures from:

ABB,

Bosch, and

COPA-DATA

NOTE: The ABB link is to their Alerts and Notifications page. There are currently four CodeMeter advisories listed on that page. One is a generic advisory and the other three are product specific advisories. I briefly described this in a blog post on September 12th. I briefly discussed the Bosch advisory on September 26th

Tuesday, June 3, 2014

ICS-CERT Publishes New DNP3 Advisory

Today the DHS ICS-CERT published an advisory for a pair of vulnerabilities in the COPA-Data zenon SCADA software. This is the standard IP and Serial DNP3 communications vulnerabilities that I have been referring to as the Crain-Sistrunk vulnerabilities. Even though the advisory gives Crain and Sistrunk credit for the discovery of the vulnerability in this product, a TWEET® from Adam Crain informs us that COPA-Data bought his Aegis fuzzer, used it on their product and self-reported the vulnerability. You can’t ask for a better bit of advertising than that.

NOTE: According to a later TWEET, this was the free download version of the fuzzer that was used to discover these vulnerabilities. (Added 04:15, 6-4-14)

COPA-Data has developed a newer version of the affected product that mitigates the vulnerabilities.
 
/* Use this with templates/template-twocol.html */