Showing posts with label Cambium. Show all posts
Showing posts with label Cambium. Show all posts

Tuesday, January 9, 2024

1 Updated Published – 1-9-24

Today, CISA’s NCCIC-ICS published an update for a control system security advisory for products from Cambium.

Cambium Update

This update provides additional information on a Cambium ePMP 5GHz Force 300-25 Radio advisory that was originally published on December 14th, 2024.

 

For more details about this update, including a summary of the changes made, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-updated-published-1-9-24 - subscription required. I also started a DTRH look at the CVE’s listed in last year’s advisories from CISA’s NCCIC-ICS.

Thursday, December 14, 2023

Review – 16 Advisories and 1 Update Published – 12-14-23

Today, CISA’s NCCIC-ICS published 16 control system security advisories for products from Unitronics, Johnson Controls, Cambium and Siemens (13). They also published a medical device security advisory update for products from Philips.

Siemens also published 15 advisory updates that CISA is no longer covering. I will look at those this weekend in my Public ICS Disclosure post.

Advisories

Unitronics Advisory - This advisory describes an initialization of a resource with insecure default vulnerability in the Unitronics Vision Series PLCs and HMIs.

Johnson Controls Advisory - This advisory describes a missing release of information after effective lifetime vulnerability in the Johnson Controls Kantech Gen1 ioSmart card reader.

Cambium Advisory - This advisory describes a code injection vulnerability in the Cambium ePMP Force 300-25 radio.

SINEC Advisory - This advisory discusses seven vulnerabilities in the Siemens SINEC INS product.

RUGGEDCOM Advisory - This advisory describes nine vulnerabilities in the Siemens RUGGEDCOM RM1224 LTE and SCALANCE M-800/S615 families of routers.

SCALANCE Advisory - This advisory describes two vulnerabilities in the Siemens RUGGEDCOM RM1224 LTE and SCALANCE M-800/S615 families of routers.

SICAM Advisory - This advisory describes two vulnerabilities in the Siemens Power Meter SICAM Q100 products.

SINUMERIK Advisory - This advisory describes a use after free vulnerability in the Siemens SINUMERIK MC and SINUMERIK ONE products.

SIMATIC Advisory #1 - This advisory discusses 404 vulnerabilities in the Siemens SIMATIC and SIPLUS S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1 products.

SIMATIC Advisory #2 - This advisory describes a use after free vulnerability in the Siemens SIMATIC and SIPLUS S7-1500 CPU family.

SIMATIC Advisory #3 - This advisory describes a clear-text storage of sensitive information vulnerability in the Siemens SIMATIC STEP 7 (TIA Portal).

SIMATIC Advisory #4 - This advisory describes two vulnerabilities in the Siemens SIMATIC and SIPLUS products.

Industrial Products Advisory - This advisory describes a missing release of memory after effective lifetime vulnerability in the Siemens SIMATIC CP, SINAMICS, and SIPLUS NET CP products.

OPC UA Implementation Advisory - This advisory describes an integer overflow or wrap around vulnerability in the Siemens SINUMERIK MC and SINUMERIK ONE products.

LOGO! Advisory - This advisory describes an improper protection against electromagnetic fault injection vulnerability in the Siemens LOGO! and SIPLUS LOGO! Products.

User Management Component Advisory - This advisory describes five vulnerabilities in the Siemens User Management Component (UMC).

Updates

Philips Update - This update provides additional information on the Philips Patient Monitoring Devices advisory that was originally published on September 10th, 2020 and most recently updated on November 8th, 2021.

 

For more details about these advisories, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/16-advisories-and-1-update-published - subscription required. 

Thursday, May 12, 2022

Review – 16 Advisories Published – 5-12-22

Today, CISA’s NCCIC-ICS published sixteen control system security advisories for products from Siemens (12), Cambium Networks, Inkscape, Mitsubishi Electric, and Delta Electronics.

Teamcenter Advisory - This advisory describes two vulnerabilities in the Siemens Teamcenter product lifecycle management software.

OpenV2g Advisory - This advisory describes a classic buffer overflow vulnerability in the OpenV2G open-source implementation of the ISO/IEC vehicle-to-grid communication interface (V2G CI) standard (Siemens is an initiator of OpenV2G).

Simcenter Advisory - This advisory describes an out-of-bounds write vulnerability in the Siemens Simcenter Femap advanced simulation application.

Industrial Devices Advisory - This advisory discusses two vulnerabilities (both with known exploits) in the Siemens Industrial devices.

Industrial Products Advisory #1 - This advisory discusses an improper restriction of operations within the bounds of a memory buffer in OPC Foundation Local Discovery Server of several Siemens industrial products.

Industrial Products Advisory #2 - This advisory discusses a NULL pointer dereference vulnerability (with known exploit) in the Siemens SIMATIC NET PC, SITOP Manager, and TeleControl Server Basic products.

SIMATIC Advisory #1 - This advisory describes an uncontrolled resource consumption vulnerability in the Siemens SIMATIC CP 442-1 RNA and CP 443-1 RNA communications processors.

SIMATIC Advisory #2 - This advisory describes an insecure default initialization of resource vulnerability in the Siemens SIMATIC PCS and WinCC products.

Desigo Advisory - This advisory describes eight vulnerabilities in the Siemens Desigo PXC and DXR building automation devices.

JT2GO Advisory - This advisory describes six vulnerabilities in the Siemens JT2GO and Teamcenter Visualization products.

SICAM Advisory - This advisory describes eleven vulnerabilities in the Siemens SICAM P850 and SICAM P855 electrical variable measuring devices.

Industrial PCs Advisory - This advisory discusses four vulnerabilities in the Siemens Industrial PCs and CNC devices.

NOTE: This advisory is based upon a Siemens update of an  advisory that was originally published on May 11th, 2021 and most recently updated on March 8th, 2022.

Cambium Advisory - This advisory describes seven vulnerabilities in the Cambium cnMaestro On-Premises network management system.

Inkscape Advisory - This advisory describes three vulnerabilities in the Inkscape open-source graphics editor.

NOTE: NCCIC-ICS is apparently concerned that this will be a third-party vulnerability in multiple ICS products. They provide a link to one such affected product, the Ecava SAGE eXtension SCADA animation graphic editor. The linked page only refers to the corrected version of Inkscape and does not mention these vulnerabilities.

Mitsubishi Advisory - This advisory discusses eight vulnerabilities in the Mitsubishi ELSOFT iQ AppPortal.

Delta Advisory - This advisory describes two vulnerabilities in the Delta CNCSoft software management platform.

 

For additional information on these advisories, including links to third-party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/16-advisories-published-5-12-22 - subscription required.

 
/* Use this with templates/template-twocol.html */