Today CISA’s NCCIC-ICS published a control system security advisory for products from Dingtian.
Advisories
Dingtian Advisory This
advisory
describes two insufficiently protected credentials vulnerabilities in the
Dingtian DT-R002 relay board.
News and views about chemical facility security, transportation of hazardous chemicals, and the federal laws and rules governing the same.
Today CISA’s NCCIC-ICS published a control system security advisory for products from Dingtian.
Dingtian Advisory This
advisory
describes two insufficiently protected credentials vulnerabilities in the
Dingtian DT-R002 relay board.
Today CISA’s NCCIC-ICS published 18 control system security advisories for products from Dingtian, Outback Power, mySCADA, ORing, and Siemens (14), as well as an update for a Mitsubishi advisory. They also included a medical device security advisory for products from Qardio.
Dingtian Advisory -
This advisory
describes an authentication bypass using alternate path or channel
vulnerability in the Dingtian DT 004 relay board.
Outback Advisory -
This advisory
describes three vulnerabilities in the Outback Power Mojave Inverter.
mySCADA Advisory -
This advisory
describes four vulnerabilities in the mySCADA myPRO Manager.
ORing Advisory - This
advisory
describes two vulnerabilities (with publicly available exploit code) in the Oring
IAP-420 WLAN access point.
Opcenter Advisory -
This advisory
discusses five vulnerabilities (one with known exploit) in the Siemens Opcenter
Intelligence product.
SIMATIC PCS Advisory -
This advisory
describes an insufficient session expiration vulnerability in the Simens SIMATIC
PCS neo and TIA Administrator products.
SIMATIC IPC Advisory -
This advisory
describes an incorrect permission assignment for critical resource
vulnerability in the Siemens SIMATIC IPC DiagBase and SIMATIC IPC DiagMonitor.
APOGEE Advisory -
This advisory
describes two vulnerabilities in the Siemens APOGEE PXC and TALON TC series
products.
cold state and a vulnerability that would allow an attacker
to decrypt the passwords of the device.
Questa Advisory -
This advisory
describes an uncontrolled search path element vulnerability in the Siemens Questa
and ModelSim products.
SCALANCE Advisory -
This advisory
discuss 72 vulnerabilities in the Siemens SCALANCE W700 access point.
OpenV2G Advisory -
This advisory
describes a classic buffer overflow vulnerability in the Siemens OpenV2G
(vehicle to grid) communications interface.
Teamcenter Advisory -
This advisory
describes an open redirect vulnerability in the Siemens Teamcenter product.
RUGGEDCOM Advisory -
This advisory
discusses ten vulnerabilities in the Siemens RUGGEDCOM APE1808 product.
SIPROTEC 5 Advisory
#1 - This advisory
describes a use of default credentials vulnerability in the Siemens SIPROTEC 5
Devices.
SIPROTEC 5 Advisory
#2 - This advisory
describes an active debug code vulnerability in the Siemens SIPROTEC 5
products. The vulnerability was reported by Steffen Robertz, Stefan Viehböck,
and Constantin Schieber-Knöbl of SEC Consult Vulnerability Lab.
SIPROTEC 5 Advisory
#3 - This advisory
describes a cleartext storage of sensitive information vulnerability in the
Siemens SIPROTEC 5 products.
SIMATIC Advisory -
This advisory
describes an observable discrepancy vulnerability in the Siemens SIMATIC
product line.
SIMATIC S7-1200
Advisory - This advisory
describes two vulnerabilities in the Siemens SIMATIC S7-1200 CPU family.
Qardio Advisory - This advisory describes three vulnerabilities in the Qardio Heart Health IOS application, Heart Health Android Application, and QardioARM A100.
Mitsubishi Update -
This update
provides additional information on the FA Engineering Software Products
advisory that was originally published on January 30th, 2024, and
most recently updated on January 16th, 2025.
For more information on these advisories, including links to
3rd party advisories and researcher reports, see my article at CFSN
Detailed Analysis - https://patrickcoyle.substack.com/p/19-advisories-and-1-update-published
- subscription required.
Today, CISA’s NCCIC-ICS published eight control system security advisories for products from Sielco, Rockwell Automation, Ashlar-Vellum, Centralite, and Dingtian. They also updated a medical device security advisory for products from BD Alaris.
Sielco Advisory #1 -
This advisory
describes four vulnerabilities in the Sielco Analog FM Transmitters and Radio
Link.
Sielco Advisory #2
- This advisory
describes seven vulnerabilities in the Sielco PolyEco FM transmitters.
Rockwell Advisory
#1 - This advisory
describes an improper authentication vulnerability in the Rockwell FactoryTalk
Services Platform web service.
Rockwell Advisory
#2 - This advisory
describes an improper input validation vulnerability in the Rockwell FactoryTalk
View Site Edition.
Rockwell Advisory
#3 - This advisory
describes two vulnerabilities in the Rockwell Arena simulation software.
Ashlar-Vellum Advisory
- This advisory
describes two vulnerabilities in the Ashlar-Vellum Cobalt, Graphite, Xenon,
Argon, Lithium, and Cobalt Share modeling programs.
Centralite Advisory -
This advisory
describes an allocation of resources without limits or throttling vulnerability
in the Centralite Pearl Thermostat.
Dingtian Advisory - This advisory describes an authentication bypass by capture relay vulnerability in the Dingtian DT-R002 relay.
BD Alaris Update -
This update
provides additional information on an advisory that was originally published on
July 13th, 2023.
For more information on these advisories, including links to
researcher advisories, and a down-the-rabbit-hole look at one of the Rockwell
advisories - https://patrickcoyle.substack.com/p/8-advisories-and-1-update-published
- subscription required.
For Part 2 this week we have three additional vendor disclosures from FileWave, OPCLabs, and Unified Automation. We also have nine vendor updates from CODESYS, HP, Mitsubishi (3), VMware, and Yokogawa (3). We also have four researcher reports for products from DD-WRT, Asuswrt, FreshTomato, and Nuki. Finally, we have two exploits for products from Dingtian, and Roxy-WI.
FileWave Advisory - FileWave published a
blog post that describes two vulnerabilities in their FileWave Management
Suite.
OPC Labs Advisory - OPC Labs published an
advisory that describes a deserialization of untrusted data vulnerability
in their QuickOPC Connectivity Explorer.
Unified Automation Advisory - Incibe CERT published an
advisory that describes two vulnerabilities in the Unified Automation's OPC
UA C++ Demo Server.
CODESYS Update - CODESYS published an
update for their Development System V3 advisory that was originally
published on July 15th, 2021 and most
recently updated on June 3rd, 2022.
HP Update - HP published an
update for their NVIDIA GPU Display Driver advisory that was originally published
on June 2nd, 2022 and most recently updated on June 23rd,
2022.
Mitsubishi Update #1 - Mitsubishi published an
update for their Multiple FA Products advisory that originally
published on July 30th, 2020 and most
recently updated on May 27th, 2021.
NOTE: NCCIC-ICS did not update their advisory (ICSA-20-212-03)
for this information.
Mitsubishi Update #2 - Mitsubishi published an
update for their Multiple FA Engineering Software Products advisory that was
originally
published on February 18th, 2021 and most
recently updated on May 24th, 2022.
NOTE: NCCIC-ICS did not update their advisory (ICSA-21-049-02)
for this information.
Mitsubishi Update #3 - Mitsubishi published an
update for their Multiple FA Engineering Software Products advisory that originally
published on July 30th, 2020 and most
recently updated on May 24th, 2022.
NOTE: NCCIC-ICS did not update their advisory (ICSA-20-212-04)
for this information.
VMware Update - VMware published an update
for their vCenter Server advisory that was originally
published on July 12th, 2022.
Yokogawa Update #1 - Yokogawa published an
update for their Wide Area Communication Router advisory that originally
published on June 30th, 2022.
NOTE: NCCIC-ICS did not need to update their advisory (ICSA-22-181-02)
for this information.
Yokogawa Update #2 - Yokogawa published an
update for their CAMS for HIS advisory that was originally
published on May 27th, 2022.
Yokogawa Update #3 - Yokogawa published an
update for their OT:ICEFALL advisory that was originally
published on June 21st. 2022. The new information includes adding
fix for FCN/FCJ basic software.
NOTE: NCCIC-ICS did not update their advisory (ICSA-22-174-01)
for this new information.
DD-WRT Report - Talos published a
report that describes a memory corruption vulnerability in the httpd
unescape functionality of DD-WRT Revision 32270 - Revision 48599.
Asuswrt Report - Talos published a
report that describes a memory corruption vulnerability in the httpd
unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin
New Gen prior to 386.7.
FreshTomato Report - Talos published a
report that describes a memory corruption vulnerability in the httpd
unescape functionality of FreshTomato 2022.1
Nuki Report - NCC Group published a
report that describes nine vulnerabilities in the Nuki smart locks.
Dingtian Exploit - Victor Hanna published an
exploit for an authentication bypass vulnerability in the Dingtian-DT-R002
2Channel relay board.
Roxy-WI Exploit - Nuri Cilengir published a Metasploit
module for a command injection vulnerability in the Roxy-WI web interface.
For more information on these disclosures, including summaries
of changes made in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-7-23-9aa
- subscription required.
/* Use this with templates/template-twocol.html */