Showing posts with label Chirp Systems. Show all posts
Showing posts with label Chirp Systems. Show all posts

Thursday, May 2, 2024

Review – 2 Advisories and 1 Update Published – 5-2-24

Today, CISA’s NCCIC-ICS published two control system security advisories for products from Delta Electronics and CyberPower.  They also updated (again) the advisory from Chirp Systems. I take another look at Brown’s statements about the Chirp Systems vulnerability.

Advisories

Delta Advisory - This advisory describes three vulnerabilities in the Delta DIAEnergie industrial energy management system.

CyberPower Advisory - This advisory describes nine vulnerabilities in the CyberPower Power Panel product.

Updates

Chirp Systems Update - This update provides additional information on an advisory that was originally published on March 7th, 2024 and  most recently updated on April 25th, 2024.

 

For more details about these vulnerabilities, including a summary of changes made to the updated advisory and a commentary about the differences between the researcher and vendor looks at the Chirp Systems vulnerability, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-1-update-published-621 - subscription required.

Thursday, April 25, 2024

Review – 4 Advisories and 4 Updates Published

Today, CISA’s NCCIC-ICS published four control system security advisories for products from Honeywell, Siemens and Hitachi Energy (2). They also updated advisories for products from Mitsubishi (2), Rockwell and Chirp Systems.

Advisories

Honeywell Advisory - This advisory describes 16 vulnerabilities in multiple Honeywell products.

Siemens Advisory - This advisory discusses a command injection vulnerability {that is listed on CISA’s Known Exploit Vulnerabilities (KEV) Catalog} in the Siemens RUGGEDCOM APE1808 application hosting platform.

Hitachi Energy Advisory #1 - This advisory describes two vulnerabilities in the Hitachi Energy MACH SCM product.

Hitachi Energy Advisory #2 - This advisory describes two unrestricted upload of files with dangerous type vulnerabilities in the Hitachi Energy RTU500 Series.

Updates

Mitsubishi Update #1 - This update provides additional information on the MELSEC Series CPU Module advisory that was originally published on May 23rd, 2023 and most recently updated on March 14th, 2024.

Mitsubishi Update #2 - This update provides additional information on the MELSEC iQ-R Series/iQ-F Series advisory that was originally published on June 6th, 2023.

Rockwell Update - This update provides additional information on the 5015-AENFTXT advisory that was originally published on April 11th, 2024.

Chirp Systems Update - This update provides additional information on the Chirp Access advisory that was originally published on March 7th, 2024 and most recently updated on April 23rd, 2024.

 

For more information on the these advisories, including a brief commentary on the Chirp Systems update, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-and-4-updates-published - subscription required. 

Tuesday, April 23, 2024

Review – 2 Updates Published – 4-23-24

Today, CISA’s NCCIC-ICS published updates for two control system security advisories for products from Chirp Systems and Mitsubishi Electric.

Updates

Chirp Systems Update - This update includes additional information on an advisory that was originally published on March 7th, 2024.

Mitsubishi Update - This update includes additional information on an advisory that was originally published on February 20th, 2024.

 

For more information on these updates, including a summary of the changes made, and a brief look at the Chirp Systems negative response to the advisory, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-updates-published-4-23-24 - subscription required.

 
/* Use this with templates/template-twocol.html */