Showing posts with label Exemys. Show all posts
Showing posts with label Exemys. Show all posts

Thursday, June 30, 2022

Review – 4 Advisories and 2 Updates Published – 6-30-22

Today, CISA’s NCCIC-ICS published four control system security advisories for products from Distributed Data Systems, Emerson, Yokogawa, Exemys. They also updated advisories from CODESYS and Mitsubishi Electric.

Distributed Data Systems Advisory - This advisory describes two vulnerabilities in the Distributed Data Systems WebHMI.

Emerson Advisory - This advisory discusses the OT:ICEFALL vulnerabilities in the Emerson DeltaV Distributed Control System.

NOTE: There are still 15 Emerson OT:ICEFALL vulnerabilities that have not been covered by NCCIC-ICS in Emerson products including: Ovation, OpenBSI, ControlWave, and FANUC.

Yokogawa Advisory - This advisory describes a use of insufficiently random values vulnerability in the Yokogawa Wide Area Communication (WAC) Router.

Exemys Advisory - This advisory describes an improper authentication vulnerability in the Exemys RME1 analog acquisition module.

CODESYS Update - This update provides additional information on an advisory that was originally published on September 15th, 2015.

Mitsubishi Update - This update provides additional information on an advisory that was originally published on December 16th, 2021.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-and-2-updates-published - subscription required.

Tuesday, November 17, 2015

ICS-CERT Published Exemys Advisory

This afternoon the DHS ICS-CERT published a control systemadvisory for the Exemys Telemetry Web Server. The login bypass vulnerability described in the advisory was reported by Maxim Rupp. ICS-CERT reports that Exemys “has not produced a patch to mitigate this vulnerability”.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to access information on the server.

The only unique mitigation measure for this vulnerability comes from ICS-CERT with no clear instructions on how to effect the proposed measure. The measure that ICS-CERT recommends is:

“ICS-CERT recommends implementing a single point login that cannot be bypassed.”


It is unusual for ICS-CERT not to be at least a little more forthcoming about why there is not now (and presumably won’t be in the near future) a vendor provided patch or upgrade. While Exemys is headquartered in Argentina, there is no mention of difficulties contacting the organization or that they disagree with the reported vulnerability. A dispassionate observer would probably be excused for assuming that Exemys is not concerned about the existence of this vulnerability.
 
/* Use this with templates/template-twocol.html */