Showing posts with label ETIC. Show all posts
Showing posts with label ETIC. Show all posts

Tuesday, December 3, 2024

Review – 6 Advisories and 2 Updates Published – 12-3-24

Today CISA’s NCCIC-ICS published six control system security advisories for products from Fuji Electric (2), ICONICS (and Mitsubishi), Open Automation, Siemens, and Ruijie. They also updated advisories for products from ICONICS (and Mitsubishi) and ETIC.

Advisories

Fuji Advisory #1 - This advisory describes five vulnerabilities in the Fuji Electric Tellus Lite V-Simulator.

Fuji Advisory #2 - This advisory describes 10 out-of-bounds write vulnerabilities in the Fuji Electric Monitouch V-SFT screen configuration software.

ICONICS Advisory - This advisory describes three vulnerabilities in the ICONICS GENESIS64 and Mitsubishi MC Works64 products.

Open Automation Advisory - This advisory describes an incorrect execution-assigned privileges vulnerability in the Open Automation Software package.

Siemens Advisory - This advisory discusses four vulnerabilities (two listed in CISA’s Known Exploited Vulnerabilities catalog) in the Siemens RUGGEDCOM APE1808 products.

Ruijie Advisory - This advisory describes ten vulnerabilities in the Ruijie Reyee OS.

Updates

ICONICS Update - This update provides additional information on the ICONICS and Mitsubishi advisory that was originally published on July 2nd, 2024.

ETIC Update - This update provides additional information on the Remote Access Server advisory that was originally published on November 3, 2022, and most recently updated on July 27th, 2023.

 

For more information on these advisories, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-2-updates-published-ee4 - subscription required.

Thursday, July 27, 2023

Review – 3 Advisories and 2 Updates Published – 7-27-23

Today, CISA’s NCCIC-ICS published three control system security advisories for products from Mitsubishi Electric, PTC and ETIC Telecom. They also updated two advisories for products from Mitsubishi and ETIC.

Advisories

Mitsubishi Advisory - This advisory describes a classic buffer overflow vulnerability in the Mitsubishi CNC Series devices.

PTC Advisory - This advisory describes an uncontrolled resource consumption vulnerability in the PTC KEPServerEX.

ETIC Advisory - This advisory describes an insecure default initialization of resource vulnerability in the ETIC Remote Access Server (RAS).

Updates

Mitsubishi Update - This update provides additional information on an advisory that was originally published on August 9th, 2022 and most recently updated on August 18th, 2022 (not 8-16-23).

ETIC Update - This update provides additional information on an advisory that was originally published on November 11th, 2022.

 

For more details about these advisories, including links to vendor advisories and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-and-2-updates-published-9a3 - subscription required.

Thursday, November 3, 2022

Review – 3 Advisories Published – 11-3-22

Today, CISA’s NCCIC-ICS published three control system security advisories for products from Delta Industrial Automation, Nokia, and ETIC Telecom.

Delta Advisory - This advisory describes a path traversal vulnerability in the Delta DIALink.

Nokia Advisory - This advisory describes three vulnerabilities in the Nokia ASIK AirScale baseband unit.

ETIC Advisory - This advisory describes three vulnerabilities in the ETIC remote Access Server (RAS).

 

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-published-11-3-22 - subscription required.


 
/* Use this with templates/template-twocol.html */