Showing posts with label DataKit. Show all posts
Showing posts with label DataKit. Show all posts

Thursday, April 13, 2023

Review – 16 Advisories Published – 4-13-23

Today, CISA’s NCCIC-ICS published 15 control system security advisories for products from Mitsubishi Electric India, Datakit, and Siemens (13). They also published a medical device security advisory for products from Braun.

Advisories

Mitsubishi Advisory - This advisory describes a signal handler race condition vulnerability in the Mitsubishi Electric India Ethernet communication Extension unit GC-ENET-COM.

Datakit Advisory - This advisory describes five vulnerabilities in the Datakit CrossCAD/Ware_x64 library.

SCALANCE Advisory #1 - This advisory discusses the BadAlloc vulnerabilities in the Siemens SCALANCE X-200, X-200IRT, and X-300 Switch Families.

SCALANCE Advisory #2 - This advisory discusses ten vulnerabilities in the Siemens SCALANCE XCM332.

SCALANCE Advisory #3 - This advisory describes an inadequate encryption strength vulnerability in the Siemens SCALANCE X-200IRT Devices.

Polarian Advisory - This advisory describes an improper restriction of XML external entity reference in the Siemens Polarion ALM products.

Teamcenter Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Siemens Teamcenter Visualization and JT2Go products.

Industrial Products Advisory - This advisory describes three vulnerabilities in the Siemens Industrial Products.

Mendix Advisory - This advisory describes an observable response discrepancy vulnerability in the Siemens Mendix Forgot Password Module.

SICAM Advisory - This advisory describes a command injection vulnerability in the Siemens CPCI85 Firmware of SICAM A8000 Devices.

SIPROTEC Advisory - This advisory describes a NULL pointer dereference vulnerability in the Siemens SIPROTEC 5 Devices.

TIA Portal Advisory - This advisory describes an improper input validation vulnerability in the Siemens TIA Portal.

Siemens in OPC Advisory - This advisory describes an improper input validation vulnerability in multiple Siemens products using the OPC Foundation Unified Architecture Local Discovery Server.

JT Open Advisory - This advisory describes an out-of-bounds read vulnerability in the Siemens JT Open and JT Utilities products.

Adaptec Advisory - This advisory describes an exposure of sensitive information to unauthorized actor vulnerability in the Siemens Adaptec maxView Application.

Braun Advisory - This advisory describes an eval injection vulnerability in the Braun Battery Pack SP with Wi-Fi.

 

For more details on these advisories, including links to third-party advisories an exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/16-advisories-published-4-13-23 - subscription required.

Tuesday, May 25, 2021

2 Advisories Published – 5-25-21

Today CISA’s NCCIC-ICS published two control system security advisories for products from Rockwell Automation and Datakit Libraries.

Rockwell Advisory

This advisory describes a channel accessible by non-endpoint vulnerability in the Rockwell Micro800, MicroLogix 1400 controllers. The vulnerability was reported by Hyunguk Yoo from The University of New Orleans, as well as Adeen Ayub and Irfan Ahmed from Virginia Commonwealth University. Rockwell provides generic work arounds for the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker can remotely exploit the vulnerability to may result in denial-of-service conditions, which may require a firmware flash to recover.

NOTE: The Rockwell advisory recommends blocking or restricting access to TCP and UDP Port# 44818 and Port# 2222  using proper network infrastructure controls, such as firewalls, UTM devices, or other security appliances. This is not mentioned in the NCCIC-ICS guidance.

DataKit Advisories

This advisory describes five vulnerabilities in the DataKit Software libraries embedded in Luxion KeyShot software. The vulnerabilities were reported by rgod via the Zero Day Initiative. DataKit has a new version that mitigates the vulnerabilities and Luxion has a new version that contains the new DataKit version.

The five reported vulnerabilities are:

• Out-of-bounds write - CVE-2021-27488,

• Improper restrictions on XML external entity reference - CVE-2021-27492,

• Stack-based buffer overflow - CVE-2021-27494,

• Untrusted pointer dereference - CVE-2021-27496, and

• Out-of-bounds read - CVE-2021-27490

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to lead to execution of arbitrary code and disclosure of arbitrary files to unauthorized actors.

 
/* Use this with templates/template-twocol.html */