Showing posts with label Enphase. Show all posts
Showing posts with label Enphase. Show all posts

Thursday, July 13, 2023

Review – 7 Advisories and 2 Updates Published – 7-13-23

Today CISA’s NCCIC-ICS published six control system and 1 medical device security advisories for products from Honeywell, Rockwell Automation, Siemens (4), and BD. They also updated advisories for products from Enphase and Mitsubishi.

There were two additional Siemens advisories (and 12 updates that CISA no longer covers) that were published this week that were not addressed here (including the one for the missing CISA advisory). I will be addressing those this weekend.

Advisories

Honeywell Advisory - This advisory describes nine vulnerabilities in the Honeywell Experion PKS, LX, and PlantCruise DCS products.

Rockwell Advisory - This advisory describes a cross-site scripting vulnerability in the Rockwell PowerMonitor 1000 product.

SIMATIC Advisory #1 - This advisory discusses thirteen vulnerabilities in the Siemens SIMATIC MV500 series devices.

SIMATIC Advisory #2 - This advisory is currently returning a “Page Not Found” message.

SiPass Advisory - This advisory describes an improper input validation vulnerability in the Siemens SiPass Integrated access control product.

RUGGEDCOM ROX Advisory - This advisory discusses 21 vulnerabilities in the Siemens RUGGEDCOM ROX ethernet switches.

BD Advisory - This advisory describes eight vulnerabilities in a variety of BD products.

Updates

Enphase Update - This update provides additional information on an advisory that was originally published on June 22nd, 2023.

Mitsubishi Update - This update provides additional information on an advisory that was originally published on December 22nd, 2022.

 

For more details about these advisories, including links to researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-2-updates-published-916 - subscription required.

Saturday, July 8, 2023

Review – Public ICS Disclosures – Week of 7-1-23

This week we have eleven vendor disclosures from Aruba Networks, Bosch (2), Enphase, Frauscher Sensortechnik, Hikvision, Moxa, Softing (2), VMware and Zyxel. And we have 29 researcher reports for products from Panasonic (3), Milesight (25), and Siemens.

Advisories

Aruba Advisory - Aruba published an advisory that describes nine vulnerabilities in the Aruba OS products.

Bosch Advisory #1 - Bosch published an advisory that discusses two vulnerabilities in their FL MGUARD family devices.

Bosch Advisory #2 - Bosch published an advisory that discusses a missing authentication for critical function vulnerability in their SLC-0-GPNT00300 interface module.

Enphase Advisory - Enphase published an advisory that describes an OS command injection vulnerability in their Enphase IQ Gateway (Envoy).

Frauscher Advisory - CERT-VDE published an advisory that describes a path traversal vulnerability in the Frauscher Diagnostic System FDS001 for FAdC R1 and FAdCi R1.

Hikvision Advisory - Hikvision published an advisory that describes two vulnerabilities in their access control/intercom products.

Moxa Advisory - Moxa published an advisory that describes an observable response discrepancy vulnerability in their TN-5900 Series product.

Softing Advisory #1 - Softing published an advisory that describes two vulnerabilities in their OPC UA C++ SDK and Secure Integration Server.

Softing Advisory #2 - Softing published an advisory that describes an uncontrolled resource consumption vulnerability in a number of their products.

VMware Advisory - VMware published an advisory that describes an authentication bypass vulnerability in their SD-WAN (Edge) product.

Zyxel Advisory - Zyxel published an advisory that describes a classic buffer overflow vulnerability in their 4G LTE and 5G NR outdoor routers.

Researcher Reports

Panasonic Reports - AWESEC published three reports describing individual vulnerabilities in the Panasonic Panasonic AiSEG2.

Milesight Reports - Talos Intelligence published 25 reports (some with multiple vulnerabilities) for the Milesight UR32L urvpn_client and MilesightVPN server.

Siemens Report - SEC Consult published a report describing the four vulnerabilities in the Siemens A8000 product.

 

For more details about these disclosures, including links to third-party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-bcb - subscription required.

Thursday, June 29, 2023

Review – 5 Advisories and 4 Updates Published – 6-29-23

Today, CISA’s NCCIC-ICS published four control system security advisories for products from Mitsubishi Electric, Ovarro, Schneider, and Delta Electronics. They published a medical device security advisory for products from Medtronic. They also updated four advisories for products from Enphase, Mitsubishi (2), and Rockwell Automation.

Advisories

Mitsubishi Advisory - This advisory describes an authentication bypass by capture replay vulnerability in the Mitsubishi MELSEC-F Series products if they are used with ethernet communication special adapter FX3U-ENET-ADP or ethernet communication block FX3U-ENET(-L).

Ovarro Advisory - This advisory describes six vulnerabilities for the Ovarro TBox RTUs.

Schneider Advisory - This advisory describes a control injection vulnerability in the Schneider EcoStruxure Operator Terminal Expert.

Delta Advisory - This advisory describes three vulnerabilities in the Delta InfraSuite Device Master product.

Medtronic Advisory - This advisory describes a deserialization of untrusted data vulnerability in the Medtronic Paceart Optima System.

Updates

Enphase Update - This update provides additional information on an advisory that was originally published on June 20th, 2023 (Not June 22nd).

Mitsubishi Update #1 - This update provides additional information on an advisory that was originally published on December 6th, 2022 and most recently updated on June 1st, 2023.

Mitsubishi Update #2 - This update provides additional information on an advisory that was originally published on September 1st, 2020 and most recently updated on September 22nd, 2022 (Not September 30th).

Rockwell Update - This update provides additional information on an advisory that was originally published on April 30th, 2019.

 

For additional information on these advisories, including a down-the-rabbit-hole look at the Enphase vulnerability response – see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-4-updates-published - subscription required.

Tuesday, June 20, 2023

Review – 2 Advisories Published – 6-20-23

Today, CISA’s NCCIC-ICS published two control system security advisories for products from Enphase.

Advisories

Enphase Installer Advisory - This advisory describes a use of hard-coded credentials vulnerability in the Enphase Installer Toolkit.

Enphase Envoy Advisory - This advisory describes a command injection vulnerability in the Enphase Envoy energy monitoring device.

 

For more details on these advisories see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-published-6-20-23 - subscription required.

 
/* Use this with templates/template-twocol.html */