Showing posts with label Danfoss. Show all posts
Showing posts with label Danfoss. Show all posts

Tuesday, August 26, 2025

Review – 2 Advisories and 1 Update Published

Today CISA’s NCCIC-ICS published two control system security advisories for products from Schneider Electric and INVT. They also updated an advisory for products from Danfoss.

Advisories

Schneider Advisory - This advisory describes an improper input validation vulnerability in the Schneider Modicon M340 and Communication Modules.

INVT Advisory - This advisory describes nine vulnerabilities in the INVT VT-Designer and HMITool products.

Updates

Danfoss Update - This update provides additional information on the AK-SM 8xxA Series advisory that was originally published on May 20th, 2025.


For more information on these advisories, including links to researcher reports, and a DTRH look at a ‘missing advisory’, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-1-update-published-edb - subscription required.

Tuesday, May 20, 2025

Review – 11 Advisories and 2 Updates Published – 5-20-25

Today CISA’s NCCIC-ICS published 11 control system security advisories for products from Assured Telematics, Vertiv, AutomationDirect, Schneider (3), Siemens, Mitsubishi, Danfoss, NI, ABUP. They also updated two advisories for products from Schneider.

Advisories

Assured Telematics Advisory - This advisory describes an exposure of sensitive information to an unauthorized control sphere vulnerability in the Assured Telematics Fleet Management System.

Vertiv Advisory - This advisory describes two vulnerabilities in the Vertiv Liebert RDU101 and Liebert UNITY communications cards.

Automation Direct Advisory - This advisory describes a missing authentication for critical function vulnerability in the AutomationDirect MB-Gateway.

Schneider Advisory #1 - This advisory describes an externally controlled reference to a resource in another sphere vulnerability in the Schneider Modicon Controllers M241/M251/M258/LMC058.

Schneider Advisory #2 - This advisory discusses a missing authentication for critical function vulnerability in the Schneider Galaxy VS, VL, and VXL products.

Schneider Advisory #3 - This advisory discusses a classic buffer overflow vulnerability in the Schneider PrismaSeT Active wireless panel server.

Siemens Advisory - This advisory discusses a missing encryption of sensitive data vulnerability in the Siemens Siveillance Video product.

Mitsubishi Advisory - This advisory describes an execution with unnecessary privileged vulnerability in the Mitsubishi MC Works64 AlarmWorX Multimedia and the Iconics GENESIS64 AlarmWorX Multimedia products.

Danfoss Advisory - This advisory describes an improper authentication vulnerability in the Danfoss K-SM 800A system manager.

NI Advisory - This advisory describes five vulnerabilities in the National Instruments Circuit Design Suite.

ABUB Advisory - This advisory describes an incorrect privilege assignment vulnerability in the ABUB IoT Cloud Platform.

UPDATES

Schneider Update #1 - This update provides additional information on the Schneider EcoStruxure Power Monitoring Expert advisory that was originally published on February 6th, 2025, and most recently updated on March 27th, 2025.

Schneider Update #2 - This update provides additional information on the Schneider EcoStruxure Power Build Rapsody advisory that was originally published on January 23, 2025.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/11-advisories-and-2-updates-published - subscription required.

Review – Public ICS Disclosures – Week of 5-10-25 – Part 3

For Part 3 we have an additional vendor disclosure from Fuji Electric. We also have 25 vendor updates from Dell, FortiGuard (8), Schneider (2), Siemens (15). Finally we have a researcher report for vulnerabilities in products from Danfoss.

Advisories

Fuji Electric Advisory - JP-CERT published an advisory that describes 11 vulnerabilities in the Fuji Electric V-SFT-6 product.

Updates

Dell Update - Dell published an update for their Wyse Management Suite advisory that was originally published on April 1st, 2025, and most recently updated on May 8th, 2025.

FortiGuard Update #1 - FortiGuard published an update for their OS command injection advisory that was originally published on January 14th, 2025.

FortiGuard Update #2 - FortiGuard published an update for their OpenSSH Terrapin attack that was originally published on January 9th, 2024, and most recently updated on April 24th, 2024.

FortiGuard Update #3 - FortiGuard published an update for their denial of service attack in OpenSSH advisory that was originally published on March 11th, 2025.

FortiGuard Update #4 - FortiGuard published an update for their integer overflow in ipsec ike advisory that was originally published on January 14th, 2025, and most recently updated on April 11th, 2025.

FortiGuard Update #5 - FortiGuard published an update for their cross-site scripting advisory that was originally published on February 11th, 2025.

FortiGuard Update #6 - FortiGuard published an update for their OS command injection advisory that was originally published on March 11th, 2025.

FortiGuard Update #7 - FortiGuard published an update for their sensitive operations advisory that was originally published on May 14th, 2024.

FortiGuard Update #8 - FortiGuard published an update for their del feature advisory that was originally published on March 11th, 2025.

Schneider Update #1 - Schneider published an update for their EcoStruxure Power Build Rapsody advisory that was originally published on January 14th, 2025.

Schneider Update #2 - Schneider published an update for their ConneXium Network Manager advisory that was originally published on April 8th, 2025.

Siemens Update #1 - Siemens published an update for their FTP Server of Nucleus RTOS advisory that was originally published on October 11th, 2022, and most recently updated on April 8th, 2025.

Siemens Update #2 - Siemens published an update for their User Management Component advisory that was originally published on December 16th, 2024, and most recently updated on March 11th, 2025.

Siemens Update #3 - Siemens published an update for their open redirect advisory that was originally published on October 8th, 2024, and most recently updated on April 8th, 2025.

Siemens Update #4 - Siemens published an update for their Fortigate NGFW advisory that was originally published on March 12th, 2024, and most recently updated on April 16th, 2025.

Siemens Update #5 - Siemens published an update for their Industrial Edge Device Kit advisory that was originally published on April 8th, 2025, and most recently updated on April 17th, 2025.

Siemens Update #6 - Siemens published an update for their Industrial Edge Device Kit advisory that was originally published on April 8th, 2025, and most recently updated on April 17th, 2025.

Siemens Update #7 - Siemens published an update for their SIPROTEC 5 devices advisory that was originally published on February 11th, 2025, and most recently updated on April 8th, 2025.

Siemens Update #8 - Siemens published an update for their SICAM and SITIPE products advisory that was originally published on September 10th, 2024, and most recently updated on December 10th, 2024.

Siemens Update #9 - Siemens published an update for their Palo Alto Networks Virtual NGFW advisory that was originally published on April 9th, 2024, and most recently updated on December 10th, 2024.

Siemens Update #10 - Siemens published an update for their RUGGEDCOM ROS devices advisory that was originally published on July 13th, 2021.

Siemens Update #11 - Siemens published an update for their FortiGate NGFW advisory that was originally published on March 12th, 2024, and most recently updated on April 16th, 2025.

Siemens Update #12 - Siemens published an update for their Palo Alto Networks PAN-OS advisory that was originally published on November 22nd, 2025, and most recently updated on April 8th, 2025.

Siemens Update #13 - Siemens published an update for their Automation License Manager advisory that was originally published on September 10th, 2024.

Siemens Update #14 - Siemens published an update for their SIMATIC S7-1500 CPUs advisory that was originally published October 8th, 2024, and most recently updated on April 8th, 2025.

Siemens Update #15 - Siemens published an update for their s User Management Component advisory that was originally published on September 10th, 2024, and most recently updated on March 11th, 2025.

Researcher Reports

Danfoss Report - Claroty published a report that described an improper authentication vulnerability in the Danfoss AK-SM8xxA Series system security manager.

 

For more information about these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-aeb - subscription required.

Saturday, September 7, 2019

Public ICS Disclosures – Week of 08-31-19


This week we have a vendor disclosure from Niagara and vendor updates from Belden and Phoenix Contact. There is also a researcher report of vulnerabilities for products from Danfoss and a public report of an exploit for previously reported vulnerabilities from Siemens.

Niagara Advisory


Niagara published an advisory describing two privilege escalation vulnerabilities in their QNX operating system that is used in a number of embeded automotive systems. The vulnerabilities are apparently self-reported. Niagara has updates that mitigate the vulnerabilities.

Belden Update


Belden published an update for their advisory on the WindRiver VX works vulnerabilities (Urgent/11). The new information includes product version numbers that mitigate the vulnerabilities.

Phoenix Contact Update


Phoenix Contact published an update [.PDF download] for previously reported vulnerabilities in their AXC F 2152 products. The new information includes an added remediation option for SD-Card issue (page 6).

Danfoss Report


RiskBased Security published a report (see threatpost.com article) describing seven vulnerabilities in the Danfoss AK-EM 800 Enterprise Management solution from Danfoss for the food retail industry. This was a coordinated disclosure and Danfoss has released an updated version that mitigates the vulnerabilities. There is no indication that the researchers have verified the efficacy of the fix.

The seven reported vulnerabilities are:

Undocumented debug service predictable password remote backdoor;
LogFilesDownloadServlet unauthorized remote access;
Web interface user authentication account lockout remote DoS;
Insecure default permissions local privilege escalation;
Multiple files insecure default permissions local credential disclosure;
Web interface default credentials; and
Unsafe third-party components

Siemens Exploit


Pen Test Partners published a report on their development of an exploit for reversable encryption vulnerabilities in the Siemens SCALANCE switches. Siemens reported these vulnerabilities back in June.

 
/* Use this with templates/template-twocol.html */