Showing posts with label Control System Security Advisory. Show all posts
Showing posts with label Control System Security Advisory. Show all posts

Tuesday, September 12, 2023

Review – 2 Advisories and 1 Update Published – 9-12-23

Today, CISA’s NCCIC-ICS published two control system security advisories for products from Fujitsu Software and Hitachi Energy. They also updated an advisory for products from Mitsubishi.

Advisories

Fujitsu Advisory - This advisory describes a cleartext storage of sensitive information vulnerability in the Fujitsu Infrastructure Manager.

Hitachi Energy Advisory - This advisory discusses four vulnerabilities in the Hitachi Energy Lumada Asset Performance Management (APM) Edge.

NOTE: The link to the Hitachi Energy’s version of this advisory returns a ‘does not exist’ error message. Here is a good link.

Updates

Mitsubishi Update - This update provides additional information on an advisory that was originally published on May 23rd, 2023 and most recently updated on July 6th, 2023.

 

For more details about these advisories, including links to third-party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-1-update-published-a0f - subscription required.

Thursday, April 28, 2022

Review – 1 Advisory and 1 Update Published – 4-28-22

Today, CISA’s NCCIC-ICS published a control system security advisory for products from Johnson Controls and updated an advisory for products from Delta Electronics.

Johnson Controls Advisory - This advisory describes an improper privilege management vulnerability in the Johnson Controls Metasys ADS/ADX/OAS Servers.

Delta Update - This update provides additional information on an advisory that was originally published on March 22nd, 2022 and most recently updated on March 29th, 2022.

NOTE: The 14 added vulnerabilities and two of the three removed vulnerabilities are all SQL injection vulnerabilities. The odd-one-out is an uncontrolled search path element vulnerability.

 

For more details about these advisories, including details about the added and removed vulnerabilities, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-and-1-update-published-594 - subscription required.

 

Thursday, April 7, 2022

Review – 2 Advisories and 1 Update Published – 4-7-22

Today, CISA’s NCCIC-ICS published two control system security advisories for products from ABB and PEPPERL+FUCHS. They also updated an advisory for products from Mitsubishi Electric.

ABB Advisory - This advisory describes three vulnerabilities in the ABB Symphony Plus network interface modules.

NOTE: I briefly discussed these vulnerabilities on February 5th, 2022.

PEPPPERL+FUCHS Advisory - This advisory discussing 19 vulnerabilities (five with known exploits) in the PEPPERL+FUCHS Wireless HART-Gateway industrial networking devices.

NOTE: I briefly discussed these vulnerabilities in August of last year.

Mitsubishi Update - This update provides additional information on an advisory that was originally published on October 5th, 2021.

 

For more information on these advisories, including links to  3rd party advisories and exploits, as well as a discussion about the ‘discontinued’ Mitsubishi advisory, see my article on CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-1-update-published-d99 - subscription required.

 
/* Use this with templates/template-twocol.html */