Showing posts with label CodeMeter. Show all posts
Showing posts with label CodeMeter. Show all posts

Sunday, February 14, 2021

Public ICS Disclosures – Week of 2-6-21 – Part 2

Now I will consider the advisories listed in the monthly tranche of disclosures (original and updates) from Siemens and Schneider that were not reported by NCCIC-ICS this week.

Siemens Advisory

Siemens published an advisory that describes a predictable exact value from previous values vulnerability in their Mentor Nucleus ReadyStart and Nucleus NET modules. The vulnerability was reported by Daniel dos Santos from Forescout Technologies. Siemens has an update for some of the affected products that mitigates the vulnerability. There is no indication that dos Santos has been provided an opportunity to verify the efficacy of the fix.

NOTE: This vulnerability is the apparently the same one that NCCIC-ICS reported in section 3.2.9 of ICSA-21-042-01, Multiple Embedded TCP/IP stacks. That is not, however, currently reflected in the NVC-NIST listing, which lists a different CWE than reported by CISA. And the NCCIC-ICS advisory does not list or link to this advisory.

Schneider Advisory

Schneider published an advisory that describes three vulnerabilities in its PowerLogic power metering products. These vulnerabilities are self-reported. Schneider has new versions for some of the affected products that mitigates the vulnerabilities.

The three reported vulnerabilities are:

• Cross-site request forgery - CVE-2021-22701, and

• Clear-text transmission of sensitive information (2) - CVE-2021-22702 and CVE-2021-22703.

Siemens Updates

Siemens published an update to their GNU/Linux subsystem advisory that was originally published in 2018 and most recently updated on December 8th, 2020. The new information includes adding the following new CVE’s:

• CVE-2020-1971,

• CVE-2020-8694,

• CVE-2020-15437,

• CVE-2020-25704,

• CVE-2020-29361,

• CVE-2020-29362,

• CVE-2020-29363,

• CVE-2020-29369,

• CVE2020-29660,

• CVE-2020-29661,

• CVE-2020-35448,

• CVE-2020-36221,

• CVE-2020-36222,

• CVE-2020-36223,

• CVE-2020-36224,

• CVE-2020-36225,

• CVE-2020-36226,

• CVE-2020-36227,

• CVE-2020-36228,

• CVE-2020-36229,

• CVE-2020-36230, and

• CVE2021-21120

NOTE: The last corrective action listed was the introduction of v 2.8.4 in December of 2020.

 

Siemens published an update to their CodeMeter advisory that was originally published on September 8th, 2020 and most recently updated on January 12th, 2020. The new information includes updating mitigation information for SPPA S3000 (with fixes for the open CVEs).

NOTE: NCCIC-ICS does not update their CodeMeter advisory for changes in vendor advisories since the NCCIC-ICS advisory links to the latest version of the vendor advisory.

 

Siemens published an update to their SCALANCE click-jacking advisory that was originally published on February 11th, 2020. The new information includes adding mitigation measures for the SCALANCE X-200IRT switch family.

Schneider Update

Schneider published an update for their SNMP Service on Modicon M340 advisory that was originally published on December 12th, 2020. The new information includes:

• Adding BMXNOC0401 as an affected product, and

• Adding mitigation measures for BMXNOR0200H


Saturday, February 13, 2021

Public ICS Disclosures – Week of 2-6-21 – Part 1

This week we have four vendor disclosures from B&R Automation, Dell, GE Healthcare, and Rockwell. There is also an update from Rockwell.

B&R Advisory

B&R published an advisory discussing the CodeMeter vulnerabilities. B&R provides a list of affected products and links to updated versions that mitigate the vulnerabilities.

Dell Advisory

Dell published an advisory describing three vulnerabilities in their AOS SD-WAN. These are third-party vulnerabilities (ArubaOS). Dell has new versions that mitigate the vulnerabilities.

The three reported vulnerabilities are:

• Multiple buffer overflows - CVE-2020-24633,

• Unauthenticated remote command injection - CVE-2020-24634, and

• Secureboot bypass - CVE-2020-10713

GE Healthcare Advisory

GE published an advisory describing a buffer overflow vulnerability in unnamed products. This is a third-party (SUDO) vulnerability. GE provides no mitigation measures on their public facing portal. There is a publicly available exploit for this vulnerability.

Rockwell Advisory

Rockwell published an advisory describing an IPv4 denial-of-service vulnerability in their Allen-Bradley MicroLogix 1100 Programmable Logic Controller. This vulnerability was reported by Talos. Rockwell has a firmware update that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

Rockwell Update

Rockwell published an update for their Ripple20 advisory. The new information includes adding the four new vulnerabilities reported by Treck on December 20th, 2020.

Part 2

I will address the Siemens and Schneider advisories and updates from this week that were not covered by NCCIC-ICS is Part 2 of this post.

Thursday, February 11, 2021

2 Advisories and 1 Update Published – 2-11-21

Today CISA’s NCCIC-ICS published two control system security advisories for products from Rockwell and multiple embedded TCP/IP stacks.

Rockwell Advisory

This advisory describes an uncontrolled search path element vulnerability in the Rockwell DriveTools SP and Drives AOP. The vulnerability was reported by Claroty and Cognite, Rockwell has an update that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker with local access could exploit the vulnerability resulting in privilege escalation and complete control of the system.

TCP/IP Stacks Advisory

This advisory describes nine separate use of insufficiently random values vulnerabilities in multiple open-source and proprietary TCP/IP stacks. The vulnerabilities (nicknamed NUMBER:JACK) were reported by Daniel dos Santos, Stanislav Dashevskyi, Jos Wetzels, and Amine Amri of Forescout Research Labs. Some the affected vendors have new versions that mitigate the vulnerability in their TCP/IP stack.

The nine reported CVE’s (each generally associated with a separate TCP/IP stack vendor) are:

• CVE-2020-27213 - Nut/Net 5.1 - Patch in progress

• CVE-2020-27630 - uC/TCP-IP 3.6.0 - Patched in the latest version of Micrium OS (successor project),

• CVE-2020-27631 - CycloneTCP 1.9.6 - Patched in version 2.0.0,

• CVE-2020-27632 - NDKTCPIP 2.25 - Patched in version 7.02 of Processor SDK,

• CVE-2020-27633 - FNET 4.6.3 - Documentation updated to warn users and recommend implementing their own PRNG [pseudorandom number generator],

• CVE-2020-27634 - uIP 1.0 Contiki-OS 3.0 Contiki-NG 4.5 - No response from maintainers,

• CVE-2020-27635 - PicoTCP 1.7.0 PicoTCP-NG - Version 2.1 removes the default (vulnerable) implementation and recommends users implement their own PRNG,

• CVE-2020-27636 - MPLAB Net 3.6.- Patched in version 3.6.4.

• CVE-2020-28388 Nucleus NET 4.3 -Patched in Nucleus NET 5.2 and Nucleus ReadyStart v2012.12.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to hijack or spoof TCP connections, cause denial-of-service conditions, inject malicious data, or bypass authentication.

NOTE: The “NUMBER:JACK” report explains that “Forescout Research Labs has released an open source script that uses active fingerprinting to detect which stack a target device is running.” {pg 6}.

Commentary: Oh this is going to be a fun one. I foresee lots of equipment vendor advisories in the works as everyone scrambles to try to fix this mess. BTW, the Report notes that an attack on this type of vulnerability in the old IT world was known as a Mitnick Attack.

CodeMeter Update

This update provides new information on an advisory that was originally published on September 8th, 2020 and most recently updated on December 3rd, 2020. The new information includes adding links to the vendor alert from Drager.

Thursday, December 3, 2020

1 Advisory and 2 Updates Published – 12-3-20

Today the CISA NCCIC-ICS published one control system security advisory for products from National Instruments. They also updated two advisories for products from Wibu-Systems and WECON.

National Instruments Advisory

This advisory describes an incorrect permission assignment for critical resource vulnerability in the National Instruments CompactRIO real-time embedded industrial controller. The vulnerability was reported by Titanium Industrial Security via Incibe CERT. National Instruments has a new driver that mitigates the vulnerability. There is no indication that researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to  allow an attacker to reboot the device remotely.

CodeMeter Update

This update provides additional information on an advisory that that  was originally published on September 8th, 2020 and most recently updated on October 15th, 2020. The new information includes links to vendor advisories for products from:

Eaton, and

TRUMPF

NOTE: I briefly discussed the Eaton advisory back in early October and the TRUMPF advisory later that month. NCCIC-ICS has not yet mentioned the ENDRESS+HAUSER advisory that I mentioned in the same blog post as the TRUMPF advisory.

WECON Update

This update provides additional information on an advisory that was originally published on August 25, 2020 and most recently updated on October 29th, 2020. The new information includes:

• Adding a new vulnerability (heap-based buffer overflow - CVE-2020-25199), and

• Adding a new reporting researcher (Peter Cheng from Elex Cybersecurity Inc)

Saturday, October 17, 2020

Public ICS Disclosures – Week of 10-10-20 – Part 1

This week we have seven vendor disclosures from Eaton, HMS, Bender, Sprecher, Bosch, Rockwell, and Carestream. There are also three vendor updates from ABB and Eaton (2). We also have an exploit that was published for products from BACnet Interoperability Test Services, Inc.

Eaton Advisory

Eaton published an advisory for the CodeMeter vulnerabilities in their Xsoft-CODESYS programming software.

NOTE: This is the first CodeMeter advisory that is specifically tied to the 4th party CODESYS implmenetation of the Wibu-Systems code that I have seen.

HMS Advisory

HMS published an advisory for the Ripple20 [corrected link, 10-18-20 0846 EDT] vulnerabilities, reporting that none of their products are affected.

NOTE: The advisory indicates that HMS employed a third-party research firm to help them assess the potential exposure to these vulnerabilities.

Bender Advisory

Bender published an advisory describing an improper authentication vulnerability in their COMTRAXX products. The vulnerability was reported by Maxim Rupp. Bender has a new software version that mitigates the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

Sprecher Advisory

Sprecher published an advisory describing an input validation vulnerability in their SPRECON-E engineering tools. The vulnerability was reported by Gregor Bonney of CyberRange-e at Innogy. Sprecher has a firmware update that mitigates the vulnerability. There is no indication that Bonney has been provided an opportunity to verify the efficacy of the fix.

Bosch Advisory

Bosch published an advisory describing the Microsoft® remote desktop services vulnerability in their Rexroth industrial PCs.

Rockwell Advisory

Rockwell published an advisory describing five buffer overflow vulnerabilities in their 1794-AENT Flex I/O products. The vulnerabilities were reported (here, here and here) by Jared Rittle of Cisco Talos. Rockwell provides generic workarounds to mitigate these vulnerabilities.

NOTE: The Cisco Talos reports provide proof-of-concept code for the vulnerabilities.

Carestream Advisory

Carestream published an advisory [.PDF download link] describing the Microsoft Bad Neighbor vulnerability. Carestream is looking into the potential effects of this vulnerability on their products.

ABB Update

ABB published an update of their CodeMeter advisory for their Automation Builder products that was originally published on September 17th, 2020. ABB reports that CVE-2020-14517 has not been closed in the latest version of the Wibu-Systems CodeMeter (v.7.10a). That version has been integrated into the latest version of Automation Builder.

Eaton Updates

Eaton published an update for their Ripple20 [Corrected link, 10-18-20, 0851 EDT] advisory that was originally published on June 23rd, 2020 and most recently updated on July 24th, 2020. The new information includes updated mitigation information for Form 4D.

Eaton published an update for their Triangle MicroWorks DNP3 Outstation Libraries vulnerability advisory that was originally published on April 22nd, 2020 and most recently updated on August 6th, 2020. Eaton has updated their affected product list and mitigation measures.

NOTE: The NCCIC-ICS advisory was never updated to provide links to vendors reporting these library vulnerabilities in their products.

BACnet Exploit

Zero Science Lab published an exploit for a remote denial of service vulnerability in the BACnet Test Server from BACnet Interoperability Test Services, Inc. There is no report of a coordinated disclosure or CVE # for this vulnerability so it looks like it may be a 0-day exploit.

More to Come

Part II of this post will include Schneider and Siemens advisories and updates.

Thursday, October 15, 2020

2 Advisories and 1 Update Published – 10-15-20

Today the CISA NCCIC-ICS published two control system security advisories for products from Advantech and updated one advisory for products from Wibu-Systems.

R-SeeNet Advisory

This advisory describes an SQL injection vulnerability in the Advantech  R-SeeNet monitoring application. The vulnerability was reported by rgod via the Zero Day Initiative (ZDI). Advantech has a new version that mitigates the vulnerability. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reported that a relatively low-skilled attacker could remotely exploit this vulnerability to allow remote attackers to retrieve sensitive information from the R-SeeNet database.

NOTE: NCCIC-ICS provides a link to the Advantech advisory for this vulnerability. This is the first time that I have seen an advisory published by Advantech (actually, Advantech Czech s.r.o.) and they also have a security notifications web page which apparently only covers their cellular routers and gateways. Interestingly, they make Common Vulnerability Reporting Framework (CVRF) v1.1 files on identified vulnerabilities available to their customers.

WebAccess Advisory

This advisory describes an external control of file name or path vulnerability in the Advantech WebAccess/SCADA software package. The vulnerability was reported by Sivathmican Sivakumaran via ZDI. Advantech has newer versions that mitigate the vulnerability. There is no indication that Sivakumaran has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to control or influence a path used in an operation on the filesystem and remotely execute code as an administrator.

NOTE: This vulnerability was not reported on the web site I discussed for the earlier vulnerability, nor was there an Advantech advisory available.

CodeMeter Update

This update provides additional information on an advisory that  was originally published on September 8th, 2020 and most recently updated on October 1st, 2020 (the advisory incorrectly refers back to an earlier version from September 17th). The new information includes links to two new vendor advisories from Schneider and WEIDMUELLER.

Saturday, October 10, 2020

Public ICS Disclosures – Week of 10-03-20

This week we have one vendor disclosure from PEPPERL+FUCHS and one vendor update for products from 3S.

PEPPERL+FUCHS Advisory

CERT-VDE published an advisory describing five vulnerabilities in the PEPPERL+FUCHS Comtrol RocketLinx ethernet switches. The vulnerabilities were reported by T. Weber of SEC Consult Vulnerability Lab. PEPPERL+FUCHS has new firmware versions available that mitigate the vulnerabilities. There is no indication that Weber has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Unauthenticated device administration (2) - CVE-2020-12500 and CVE-2020-12502,

• Undocumented accounts - CVE-2020-12501,

• Multiple authenticated command injections - CVE-2020-12500, and

• Active TFTP-service - CVE-2020-12504

NOTE 1: The current version of this advisory on the CERT-VDE web page is marked as ‘Update A’, the original version was apparently published earlier in the week.

NOTE 2: SEC Consult reports that this is an OEM vulnerability which they do not name pending response to the vulnerability notification.

3S Update

3S published an update [.PDF download link] for their CodeMeter advisory that was originally published on September 16th, 2020 and most recently updated on September 24th, 2020. The new information includes more details about the coverage of the update for CODESYS v3.5.16.20.

Thursday, October 1, 2020

1 Update Published – 10-1-20

 Today the CISC NCCIC-ICS published a control system security update for the CodeMeter vulnerabilities from Wibu-Systems.

CodeMeter Update

This update provides additional information that was originally published on September 8th, 2020 and most recently updated on September 17th, 2020. The new information includes links to new affected vendor disclosures from:

ABB,

Bosch, and

COPA-DATA

NOTE: The ABB link is to their Alerts and Notifications page. There are currently four CodeMeter advisories listed on that page. One is a generic advisory and the other three are product specific advisories. I briefly described this in a blog post on September 12th. I briefly discussed the Bosch advisory on September 26th

Saturday, September 26, 2020

Public ICS Disclosures – Week of 9-19-20

This week we have two vendor disclosures about the CodeMeter vulnerabilities from Bosch and 3S. There are four vendor disclosures for products from Mitsubishi (2), Yokogawa, and Eaton. We also have two researcher reports for vulnerabilities in products from Siemens and Aveva.

CodeMeter Advisories

Bosch published an advisory describing the CodeMeter vulnerabilities in their Rexroth Products. Bosch recommends updating the CodeMeter software. One Bosch update is available to mitigate the vulnerabilities.

3S published an advisory [.PDF download link] describing the CodeMeter vulnerabilities in a number of their products. 3S has new versions of CODESYS V3 that mitigates the vulnerability.

NOTE: This advisory would seem to indicate that the universe of vulnerable products is much larger than previously thought. Vendors using CODESYS products would not have known to check for the CodeMeter vulnerability in their systems.

Mitsubishi Advisories

Mitsubishi published an advisory describing a TCP/IP stack session management vulnerability in a number of their products. The vulnerabilities were reported by Ta-Lun Yen of Trend Micro via the Zero Day Initiative. Mitsubishi has new versions that mitigate the vulnerability in many of the affected products. There is no indication that Ta-Lun has been provided an opportunity to verify the efficacy of the fix.

Mitsubishi published an advisory describing the Ripple20 vulnerabilities in the WiFi interface for a number of their products. Mitsubishi provides generic workarounds for the vulnerabilities.

NOTE: There is no overlap in the product lists for the two advisories which would indicate that two different TCP/IP stacks are being used.

Yokogawa Advisory

Yokogawa published an advisory describing a classic buffer overflow vulnerability in their  FA-M3 Programming Tool. The vulnerability has been reported by Parity Dynamics. Yokogawa has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Eaton Advisory

Eaton published an advisory describing an uncontrolled search path element vulnerability in their 9000x programing and configuration software. The vulnerability was reported by Yongjun liu. Eaton has a new version that mitigates the vulnerability. There is no indication that Yongjun has been provided an opportunity to verify the efficacy of the fix.

Siemens Report

Otorio published a blog post describing two vulnerabilities in the Siemens PCS 7 products. According to the post Siemens will provide instruction to avoid the vulnerabilities in the “next update of SIMATIC PCS 7 Compendium Part F”.

The two reported vulnerabilities are:

• A WinCC configuration flaw, and

• A PCS 7 configuration flaw.

NOTE: I cannot find a Siemens advisory that addresses similarly described vulnerabilities, but without a CVE number I cannot really be sure that Siemens has not addressed them.

Aveva Report

Talos published a report describing three vulnerabilities in the Aveva Enterprise Data Management Web data management platform. These vulnerabilities were previously disclosed by Aveva. The Talos report includes proof-of-concept code.

Saturday, September 19, 2020

Public ICS Disclosures – Week of 9-12-20

 This week we have four disclosures for CodeMeter vulnerabilities for products from ABB and Rockwell. There are also three vendor disclosures for products from MB Connect Line, Hi-Silicon, and B&R. There are 21 researcher reports for vulnerabilities in products from Fuji Electric (20) and Sierra Wireless.

CodeMeter Advisories

ABB published an advisory for the CodeMeter vulnerabilities in their Automation Builder product. ABB provides generic workarounds while it continues to investigate the vulnerabilities.

ABB published an update for their CodeMeter advisory for ABB Products. The new information includes providing a link to the advisory described above.

ABB published an update for their CodeMeter advisory for ABB Drives applications. The new information includes changing the recommended version of CodeMeter for Windows application to version 7.10a.

Rockwell published an update for their CodeMeter advisory for FactoryTalk Activation Manager. The new information includes:

• Updated mitigation information, and

• Updated CodeMeter version information

MB Advisory

CERT-VDE published an advisory describing four vulnerabilities in the mymbCONNECT24 and mbCONNECT24 products. The vulnerabilities were reported by Otorio. MB has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Blind SQL injection - CVE-2020-24569 and CVE-2020-24568,

• SSRF/CSRF - CVE-2020-24570, and

• Unauthenticated RCE – no CVE assigned

HI-Silicon Advisory

Incibe-cert published an advisory describing five vulnerabilities in the IPTV / H.264 / H.265 video encoders based on HiSilicon Hi3520d hardware. The vulnerabilities were reported by Alexei Kojenov; the report contains proof-of-concept code. Affected manufacturers include:

• URayTech;

• J-Tech Digital;

• VeCASTER PRO from Pro Video Instruments.

The five reported vulnerabilities include:

• Backdoor password - CVE-2020-24215 and CVE-2020-24218,

• Path transversal - CVE-2020-24219,

• Unauthenticated file uploads - CVE-2020-24217,

• Buffer overflow - CVE-2020-24214, and

• Unauthorized access to video streaming through RTSP - CVE-2020-24216

B&R Advisory

B&R published an advisory for the Ripple20 vulnerabilities in their products. They report that none of their products are affected by these vulnerabilities.

Fuji Electric Reports

Kimiya published 20 reports (ZDI-20-1184 thru ZDI-20-1204) of vulnerabilities in the Fuji Electric Tellus Lite product. The vulnerabilities were reported to ‘ICS-CERT’ (presumably, NCCIC-ICS) by the Zero Day Initiative back in April. These are apparently separate vulnerabilities from the 14 that were reported last week. The reported vulnerabilities include:

• Stack-based buffer overflow,

• Out-of-bounds write, and

• Out-of-bounds read

Sierra Wireless Report

Ruben Santamarta published a blog post describing two vulnerabilities in Sierra Wireless Air Link Products. Sierra Wireless has published an advisory [.PDF download link] for these vulnerabilities. The blog post includes proof-of-concept code.

The two reported vulnerabilities are:

• Privilege escalation - CVE-2020-8781, and

• Remote code execution - CVE-2020-8782

Saturday, September 12, 2020

Public ICS Disclosure – Week of 9-2-20

We have eight vendor notifications about the CodeMeter vulnerabilities reported earlier this week by NCCIC-ICS from Phoenix Contact, PEPPERL+FUCHS, WAGO, ABB, and Pilz. We also have four vendor notification from Schneider, Moxa, Medtronic, and BD. There is a vendor update from Mitsubishi. We have a researcher report of 0-day vulnerabilities for products from Fuji Electric.

CodeMeter Advisories

Phoenix Contact published an advisory for the CodeMeter vulnerabilities. They listed their affected products and announced a new version of their Activation Wizard that mitigates the vulnerabilities.

VDE-CERT published an advisory for the CodeMeter vulnerabilities in products from PEPPERL+FUCHS. It provides a list of affected products and recommends implementing the WIBU Systems update.

VDE-CERT published an advisory for the CodeMeter vulnerabilities in products from WAGO. It reports that the e!COCKPIT engineering software is bundled with the CodeMeter software. VDE-CERT notes that WAGO will update their e!COCKPIT setup routine later this year.

ABB published four CodeMeter advisories for the following products:

General information,

AC 800PEC platform,

Ability™ Operations Data Management zenon, and

ABB Drives applications

Pilz published an advisory for the CodeMeter vulnerabilities. It provides a list of affected products and recommends using the current version of CodeMeter.

Schneider Advisory

Schneider published an advisory describing five vulnerabilities in their SCADAPack remote connect and security administrator applications. The vulnerabilities were reported by Amir Preminger of Claroty. Schneider has new versions that mitigate the vulnerabilities. There is no indication that Preminger has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Deserialization of untrusted data - CVE-2020-7528 and CVE-2020-7532,

• Path transversal - CVE-2020-7529,

• Improper authorization - CVE-2020-7530, and

• Improper access control - CVE-2020-7531

Moxa Advisory

Moxa published an advisory for the BootHole vulnerability. Moxa reports that none of its products are affected.

Medtronic Advisory

Medtronic published an advisory describing the SweynTooth vulnerabilities in a number of their products. Medtronic reports that they remediated these vulnerabilities when they did their software update in June 2020.

BD Advisory

BD published an advisory describing the SigRed vulnerabilities in a number of their products. BD recommends ensuring that the appropriate Microsoft® patches have been applied.

Mitsubishi Update

Mitsubishi published an update for their MC Works advisory that was originally published on June 18th, 2020. The new information includes links for security patches for MC Works64 Version 4.00A - 4.02C.

Fuji Electric Reports

Kimiya published 14 reports (ZDI-20-1103 thru ZDI-20-1117) of vulnerabilities in the Fuji Electric Tellus Lite product. The vulnerabilities were reported to ‘ICS-CERT’ (presumably, NCCIC-ICS) by the Zero Day Initiative back in April.

The vulnerabilities include:

• Stack-based buffer overflow,

• Out-of-bounds write, and

• Out-of-bounds read

Saturday, April 14, 2018

ICS Public Disclosure – Week of 04-07-18


This week we have one new vendor report from Rockwell and two updates from Siemens.

Rockwell Advisory


Rockwell reports (registration required) two vulnerabilities in the FactoryTalk Activation Manager. Both are 3rd party vendor problems. Rockwell has a new version that mitigates the vulnerabilities. The two reported vulnerabilities are:

• CodeMeter Cross-Site Scripting; and
FlexNet Publisher Remote Code Execution

Rockwell has thoughtfully provided links to more information on each of these vulnerabilities (CodeMeter and FlexNet). Proof of concept exploits are available for each vulnerability.

If you click thru the FlexNet stuff you can get to an interesting blog post about this software license manager vulnerability. It appears that this is the same vulnerability that was reported earlier this year in products from Schneider. That blog post notes that FlexNet counts Siemens as a customer. We have, of course, seen Siemens reporting vulnerabilities in their license manager from Gemalto, so I do not know how current that FlexNet data is.

Industrial Products KRACK Update


Siemens published an update to their KRACK advisory for their Industrial Products. ICS-CERT has published previous updates on these vulnerabilities so it is surprising that there has been no update that was published over a week ago. The update provides revised version information and a mitigation link for SCALANCE W1750D.

SCALANCE DNSMasq Update


Siemens published an update on the DNSMasq vulnerabilities in their SCALANCE products. ICS-CERT did issue an advisory on these vulnerabilities, so again, I have no idea why they have not published an update. The update provides essentially the same new information for the SCALANCE W1750D product.

 
/* Use this with templates/template-twocol.html */