Showing posts with label Elcomplus. Show all posts
Showing posts with label Elcomplus. Show all posts

Thursday, June 23, 2022

Review – 6 Advisories Published – 6-23-22

Today, CISA’s NCCIC-ICS published five control system security advisories for products from Elcomplus, Pyramid Solutions, Secheron, and Yokogawa (2). They also published a medical device control system security advisory for products from OFFIS.

NCCIC-ICS has now reported advisories for four of the ten vendors covered in the OT:ICEFALL report.

Elcomplus Advisory - This advisory describes three vulnerabilities in the Elcomplus SmartICS web-based HMI.

Pyramid Solutions Advisory - This advisory describes an out-of-bounds write vulnerability in the Pyramid Solutions EtherNet/IP Adapter Development Kit.

NOTE: Weidmueller is almost certainly not the only vendor that uses the affected development or DLL kits. This is sure to show up (eventually) as a third-party vulnerability in a number of products.

Secheron Advisory - This advisory describes seven vulnerabilities in the Secheron SEPCOS Control and Protection Relay.

NOTE: There is a vendor level of control over PLC’s? From the description in the advisory, it sounds like admin level access. Could someone try to explain the difference?

Yokogawa Advisory #1 - This advisory describes a violation of secure design principles vulnerability in the Yokogawa Consolidation Alarm Management Software for Human Interface Station (CAMS for HIS) software.

NOTE: I briefly reported on this vulnerability on May 28th, 2022.

Yokogawa Advisory #2 - This advisory discusses OT:ICEFALL vulnerabilities in the Yokogawa STARDOM network control system.

NOTE: NCCIC-ICS still is not providing links to the OT:ICEFALL report or naming Forescout as the authoring agency.

OFFIS Advisory - This advisory describes three vulnerabilities in the OFFIS DCMTK libraries and software that process DICOM image files.

 

For more information on these advisories, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published-6-23-22 - subscription required.

Tuesday, April 19, 2022

Review – 5 Advisories and 1 Update Published – 4-19-22

Today, CISA’s NCCIC-ICS published five control system security advisories for products from Elcomplus (2), FANUC, and Carrier (2). They also updated their advisory for multiple RTOS products.

Elcomplus Advisory #1 - This advisory describes five vulnerabilities in the Elcomplus SmartPPT SCADA Server integrated voice and data dispatch software.

Elcomplus Advisory #2 - This advisory describes four vulnerabilities in the Elcomplus SmartPPT SCADA integrated voice and data dispatch software.

FANUC Advisory - This advisory describes five vulnerabilities in the FANUC ROBOGUIDE simulation platform software suite for FANUC Robots.

NOTE: On April 9th, 2022, I briefly reported (subscription required) on a FANUC advisory that reported two of the above CVE’s (CVE-2021-38483 and CVE-2021-43986).

Carrier Advisory - This advisory describes an open redirect vulnerability in the Automated Logic (subsidiary of Carrier) WebCtrl Server building automation software products.

Carrier Advisory #2 - This advisory describes two vulnerabilities in the Interlogix (subsidiary of Carrier) Hills ComNav remote access integration modules for the Hills Reliance security alarm system.

NOTE: The Carrier advisory lists two additional vulnerabilities.

Multiple RTOS Update - This update provides additional information on an advisory that was originally published on April 29th, 2021 and most recently updated on November 30th, 2021.

NOTE: I briefly reported on these three advisories on December 18th, 2021.

 

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-1-update-published-995 - subscription required.

 
/* Use this with templates/template-twocol.html */