Showing posts with label FANUC. Show all posts
Showing posts with label FANUC. Show all posts

Tuesday, April 11, 2023

Review – 1 Advisory and 1 Update Published – 4-11-23

Today CISA’s NCCIC-ICS published a new control system security advisory for products from FANUC. They also updated an update for an advisory for products from Mitsubishi Electric.

Advisories

FANUC Advisory - This advisory describes a path traversal vulnerability in the FANUC ROBOGUIDE-HandlingPRO robot simulation software.

Updates

Mitsubishi Update - This update provides additional information on an advisory that was originally published on July 30th, 2020 and most recently updated on March 2nd, 2023.

 

For more details about these advisories, including a brief note about ABB’s new third-party vulnerability disclosure program, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-and-1-update-published-e34 - subscription required.

Sunday, October 16, 2022

Review – Public ICS Disclosures – Week of 10-8-22 – Part 2

For Part 2 this week we have five additional vendor disclosures from Schneider (4), and WAGO. We also have sixteen updates from Fanuc, HPE, Omron (2), Schneider (8), and Siemens (4). We have nine researcher reports for products from CCCERT (2), Robustel (6), and VMware.

Schneider Advisory #1 - Schneider published an advisory that describes six vulnerabilities in their EcoStruxure™ Operator Terminal Expert and Pro-face BLUE products.

Schneider Advisory #2 - Schneider published an advisory that discusses two vulnerabilities (one with known exploit) in their EcoStruxure Panel Server Box (PAS900).

Schneider Advisory #3 - Schneider published an advisory that discusses two vulnerabilities in their SAGE RTU products.

Schneider Advisory #4 - Schneider published an advisory that describes an improper input validation vulnerability in their s EcoStruxure™ Power Operation and Power SCADA Operation software.

WAGO Advisory - CERT-VDE published an advisory that describes an uncontrolled resource consumption vulnerability in the FTP server in WAGO 750 series controllers.

Fanuc Update - Fanuc published an update for their ROBOGUIDE advisory that was originally published on April 8th, 2022 and most recently updated on June 29th, 2022.

HPE Update - HPE published an update for their Integrated Lights-Out 5 that was originally published on September 15th, 2022.

Omron Update #1 - Omron published an update for their NJ/NXseries Machine Automation Controllers advisory that was originally published on July 1st, 2022.

Omron Update #2 - Omron published an update for their NJ/NXseries Machine Automation Controllers advisory that was originally published on July 1st, 2022.

Schneider Update #1 - Schneider published an update for their Log4Shell advisory.

Schneider Update #2 - Schneider published an update for their Modicon PAC Controllers advisory that was originally published on August 9th, 2022 and most recently updated on September 6th, 2022.

Schneider Update #3 - Schneider published an update for their EcoStruxureTM Control Expert advisory that was originally published on August 9th, 2022 and most recently updated on September 6th, 2022.

Schneider Update #4 - Schneider published an update for their EcoStruxureTM Control Expert advisory that was originally published on July 13th, 2021 and most recently updated on September 6th, 2022.

Schneider Update #5 - Schneider published an update for their Modicon PAC Controllers advisory that was originally published on August 10th, 2021 and most recently updated on September 6th, 2022.

Schneider Update #6 - Schneider published an update for their BadAlloc advisory that was originally published on November 9th, 2021 and most recently updated on September 13th, 2022.

Schneider Update #7 - Schneider published an update for their Modicon Controllers advisory that was originally published on September 26th, 2019 and most recently updated on September 6th, 2022.

Schneider Update #8 - Schneider published an update for their Embedded FTP Servers advisory that was originally published on March 22nd, 2018 and most recently updated on September 13th, 2022.

Siemens Update #1 - Siemens published an update for their GNU/Linux subsystem advisory that was originally published in 2018 and most recently updated on September 13th, 2022.

Siemens Update #2 - Siemens published an update for their Insyde BIOS advisory that was originally published on February 22nd, 2022 and most recently updated on August 9th, 2022.

Siemens Update #3 - Siemens published an update for their SpringShell advisory that was originally published on April 19th, 2022 and most recently updated on June 14th, 2022.

Siemens Update #4 - Siemens published an update for their OpenSSL advisory that was originally reported on July 13th, 2021 and most recently updated on August 9th, 2022.

CCCERT Report #1 - BDU published a report of an open redirect vulnerability in the CCCERT VINCE program.

CCCERT Report #2 - BDU published a report of an open redirect vulnerability in the CCCERT VINCE program.

NOTE: The CCCERT VINCE program is the vulnerability reporting program run by CCCERT and used by NCCIC-ICS.

Robustel Report #1 - TALOS published a report discussing a command injection vulnerability in the Robustel R1510 Lite Industrial IoT Gateway.

Robustel Report #2 - TALOS published a report describing eleven denial of service vulnerabilities in the Robustel R1510.

Robustel Report #3 - TALOS published a report describing a firmware update vulnerability in the Robustel R1510. The report contains proof-of-concept code.

Robustel Report #4 - TALOS published a report describing a directory traversal vulnerability in the Robustel R1510. The report contains proof-of-concept code.

Robustel Report #5 - TALOS published a report discussing an OS command injection vulnerability in the Robustel R1510.

Robustel Report #6 - TALOS published a report discussing an OS command injection vulnerability in the Robustel R1510. The report contains proof-of-concept code.

VMware Report - TALOS published a report describing a deserialization of untrusted data vulnerability in the VMware vCenter Server Platform Services.

 

For more details on these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-8b0 - subscription required.


Sunday, July 17, 2022

Review – Public ICS Disclosures – Week of 7-9-22 – Part 2

For part two we start with five vendor disclosures from Inductive Automation, and Schneider Electric (4). We also have thirteen vendor updates from Fanuc, HPE (2), OPC Foundation, Schneider (6), and Siemens (3). Finally, we have one researcher report on products from Festo.

Inductive Automation Advisory - Inductive Automation published a blog post on five vulnerabilities in their Ignition control server that were discovered during the Pwn-to-Own competition at the recent S4x22 conference.

Schneider Advisory #1 - Schneider published an advisory that describes seven vulnerabilities in their OPC UA and X80 Advanced RTU Modicon communications modules.

Schneider Advisory #2 - Schneider published an advisory that describes an OS command injection vulnerability in their SpaceLogic C-Bus Home Controller.

Schneider Advisory #3 - Schneider published an advisory that describes an improper privilege management vulnerability in their Acti9 PowerTag Link C product.

Schneider Advisory #4 - Schneider published an advisory that describes three vulnerabilities in their Easergy P5 product line.

Fanuc Update - Fanuc published an update for their ROBOGUIDE advisory that was originally published on April 8th, 2022 and most recently updated on April 27th, 2022.

HPE Update #1 - HPE published an update for their ProLiant BL/DL/ML/XL/MicroServer advisory that was originally published on June 14th, 2022.

HPE Update #2 - HPE published an update for their ProLiant BL/DL/ML/XL/MicroServer advisory that was  originally published on May 10th, 2022 and most recently updated on June 22nd, 2022.

OPC Foundation Update - The OPC Foundation published an update for their OPC UA .NET Standard Stack advisory that was originally published on May 1st, 2022.

Schneider Update #1 - Schneider published an update for their CODESYS V3 Runtime advisory that was originally published on January 11th, 2022 and most recently updated on April 12th, 2022.

Schneider Update #2 - Schneider published an update for their APC Smart-UPS advisory that was originally published on March 8th, 2022 and most recently updated on June 14th, 2022.

Schneider Update #3 - Schneider published an update for their IGSS advisory that was originally published on April 12th, 2022

Schneider Update #4 - Schneider published an update for their ATT Labs Compressor advisory that was originally published on August 10th, 2021 and most recently updated on April 12th, 2022.

Schneider Update #5 - Schneider published an update for their EcoStruxure advisory that was originally published on July 13th, 2021 and most recently updated on April 12th, 2022.

Schneider Update #6 - Schneider published an update for their EcoStruxureTM Control Expert advisory that was originally published on September 14th, 2021, and most recently updated on March 8th, 2022.

Siemens Update #1 - Siemens published an update for their GNU/Linux advisory that was  originally published in 2018 and most recently updated on June 14th, 2022.

Siemens Update #2 - Siemens published an update for their Insyde Bios advisory that was originally published on February 22nd, 2022 and most recently updated on March 8th, 2022.

Siemens Update #3 - Siemens published an update for their OpenSSL advisory that was originally reported on July 13th, 2021 and most recently updated on June 14th 2022.

Festo Report - OneKey published a report discussing four vulnerabilities in the FESTO Controller CECC-X-M1.

 

For more details on these disclosures, including brief description of update changes, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-094  - subscription required.

Sunday, May 1, 2022

Review – Public ICS Disclosures – Week of 4-23-22 – Part 2

This week for Part 2 we have two additional vendor disclosures from Dell and Johnson Controls. There are also seven vendor updates from Bayer, FANUC, HP, Palo Alto Networks, QNAP, Siemens, and Yokogawa. Finally, there are four researcher reports for products from Delta Industrial (3) and Santesoft,

Dell Advisory - Dell published an advisory discussing an infinite loop vulnerability in their Wyse ThinOS products.

Johnson Controls Advisory - Johnson Controls published an advisory discussing the SpringShell vulnerabilities.

Bayer Update - Bayer published an update for their Log4Shell and Access:7 advisory that was originally published on March 8th, 2022.

FANUC Update - FANUC published an update for their ROBOGUIDE advisory that was originally published on April 8th, 2022.

HP Update - HP published an update for their Expat Library advisory for their PCoIP products that was originally published on April 11th, 2022.

Johnson Controls Update - Johnson Controls published an update for their SpringShell advisory that was originally published on April 19th, 2022.

Palo Alto Networks Update - Palo Alto Networks published an update for their Cortex XDR Agent advisory that was originally published on April 13th, 2022

QNAP Update - QNAP published an update for their Apache HTTP server advisory that was originally published on April 20th, 2022.

Siemens Update - Siemens published an update for their SpringShell advisory that was originally published on April 19th, 2022.

Yokogawa Update - Yokogawa published an update for their Centum advisory that was originally published on January 14th, 2022 and most recently updated on March 16th, 2022.

Delta Reports - The Zero Day Initiative published three 0-day reports about vulnerabilities from Delta Industrial.

Santesoft - ZDI published a report describing an out-of-bounds write vulnerability in the Santesoft DICOM Viewer Pro.

 

For more details about these advisories and updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-239  - subscription required.

Tuesday, April 19, 2022

Review – 5 Advisories and 1 Update Published – 4-19-22

Today, CISA’s NCCIC-ICS published five control system security advisories for products from Elcomplus (2), FANUC, and Carrier (2). They also updated their advisory for multiple RTOS products.

Elcomplus Advisory #1 - This advisory describes five vulnerabilities in the Elcomplus SmartPPT SCADA Server integrated voice and data dispatch software.

Elcomplus Advisory #2 - This advisory describes four vulnerabilities in the Elcomplus SmartPPT SCADA integrated voice and data dispatch software.

FANUC Advisory - This advisory describes five vulnerabilities in the FANUC ROBOGUIDE simulation platform software suite for FANUC Robots.

NOTE: On April 9th, 2022, I briefly reported (subscription required) on a FANUC advisory that reported two of the above CVE’s (CVE-2021-38483 and CVE-2021-43986).

Carrier Advisory - This advisory describes an open redirect vulnerability in the Automated Logic (subsidiary of Carrier) WebCtrl Server building automation software products.

Carrier Advisory #2 - This advisory describes two vulnerabilities in the Interlogix (subsidiary of Carrier) Hills ComNav remote access integration modules for the Hills Reliance security alarm system.

NOTE: The Carrier advisory lists two additional vulnerabilities.

Multiple RTOS Update - This update provides additional information on an advisory that was originally published on April 29th, 2021 and most recently updated on November 30th, 2021.

NOTE: I briefly reported on these three advisories on December 18th, 2021.

 

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-1-update-published-995 - subscription required.

Saturday, April 9, 2022

Review - Public ICS Disclosures – Week of 4-2-22 – Part 1

A busy week with lots of SpringShell and DirtyPipe disclosures, so there will be two parts this week. In this part we have 24 vendor disclosures from Aruba, Barco, Bentley (8), Braun, Broadcom (3), Carrier, Weidmueller, WAGO, CODESYS (6), and FANUC.

Aruba Advisory - Aruba published an advisory discussing the SpringShell vulnerabilities.

Barco Advisory - Barco published an advisory discussing the DirtyPipe vulnerability.

Bentley Advisory #1 - Bentley published an advisory describing two use after free vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #2 - Bentley published an advisory describing three stack-based buffer overflow vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #3 - Bentley published an advisory describing an out-of-bounds write vulnerability in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #4 - Bentley published an advisory describing eleven file parsing vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #5 - Bentley published an advisory describing two out-of-bounds read vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #6 - Bentley published an advisory describing five out-of-bounds vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #7 - Bentley published an advisory describing four out-of-bounds read vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #8 - Bentley published an advisory describing two unitialized variable vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Braun Advisory - Braun published an advisory discussing the Infusion Pump Vulnerabilities article by Palo Alto Networks.

Broadcom Advisory #1 - Broadcom published an advisory discussing one of the SpringShell vulnerabilities.

Broadcom Advisory #2 - Broadcom published an advisory describing the other SpringShell vulnerability.

Broadcom Advisory #3 - Broadcom published an advisory discussing an older Spring Framework vulnerability reanimated by the SpringShell vulnerability.

Carrier Advisory - Carrier published an advisory discussing the SpringShell vulnerabilities.

Weidmueller Advisory - CERT-VDE published an advisory discussing nine vulnerabilities in two products using Modbus TCP/RTU Gateways.

WAGO Advisory - CERT-VDE published an advisory discussing the DirtyPipe vulnerability in several WAGO products.

CODESYS Advisory #1 - CODESYS published an advisory describing an exposure of resource to wrong sphere vulnerability in the CODESYS Control V3 products.

CODESYS Advisory #2 - CODESYS published an advisory describing an incorrect permission assignment for a critical resource vulnerability in the CODESYS SysDrv3S.sys driver.

CODESYS Advisory #3 - CODESYS published an advisory describing a small space of random values vulnerability in CODESYS V3 products using the CODESYS communication protocol.

CODESYS Advisory #4 - CODESYS published an advisory describing an incorrect user management vulnerability in the  CODESYS Control V3 online user management applications.

CODESYS Advisory #5 - CODESYS published an advisory describing two vulnerabilities in CODESYS V3 products containing a CODESYS communication server.

CODESYS Advisory #6 - CODESYS published an advisory describing a buffer over read vulnerability in the CODESYS V3 web server.

 

For more details on these disclosures, including links to 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/22-part-1 - subscription required.

Saturday, February 5, 2022

Review - Public ICS Disclosures – Week of 1-29-22 – Part 1

 This has been a very busy week for control system vulnerabilities and it is going to require a two-part post to address all of the information. This week we have 14 vendor disclosures from ABB (3), Aruba (3), Sante, Sealevel, WAGO, Emerson, FANUC, Honeywell (2), Philips, and Rockwell.

ABB Advisory #1 - ABB published an advisory describing three vulnerabilities in their SPIET800 INFI-Net to Ethernet Transfer and PNI800 S+ Ethernet communication interface modules.

ABB Advisory # 2 - ABB published an advisory describing an improper input validation vulnerability in their System 800xA, Symphony® Plus IEC 61850 communication stack.

ABB Advisory #3 - ABB published an advisory describing a remote code execution vulnerability in their OPC Server for AC 800M products.

Aruba Advisory #1 - Aruba published an advisory discussing 15 vulnerabilities in their ArubaOS-CX 8000 Series Switches.

Aruba Advisory #2 - Aruba published an advisory discussing 15 vulnerabilities in their 9000 Series Gateways.

Aruba Advisory #3 - Aruba published an advisory discussing the PwnKit vulnerability in multiple product lines.

Sante Advisory - INCIBE-CERT published an advisory describing seven vulnerabilities in the Sante DICOM Viewer Pro.

Sealevel Advisory - INCIBE-CERT published an advisory describing twelve vulnerabilities in the Sealevel SeaConnect 370W Wi-Fi edge device.

WAGO Advisory - CERT-VDE published an advisory discussing a link following vulnerability in the WAGO e!COCKPIT and WAGO-I/O-Pro.

Emerson Advisory - Emerson published an advisory describing a credential disclosure vulnerability in multiple products. The vulnerability was reported by Dragos.

FANUC Advisory - FANUC published a notice reporting that none of their products are affected by the Log4Shell vulnerability.

Honeywell Advisory #1 - Honeywell published an advisory describing a command injection vulnerability in their IP PTZ Camera HDZP252DI.

Honeywell Advisory #2 - Honeywell published an advisory describing a video replay vulnerability in their IP Camera HBW2PER1.

Philips Advisory - Philips published an advisory discussing the PwnKit vulnerability.

Rockwell Advisory - Rockwell published a notice discussing a problem with the latest Microsoft® DCOM Hardening patch.

 

For more details about these advisories, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-cfc - subscription required. 

Thursday, February 3, 2022

Review - 2 Advisories and 1 Update Published – 2-3-22

 Today, CISA’s NCCIC-ICS published two control system security advisories for products from Airspan Networks and Johnson Controls. They also updated an advisory for products from FANUC.

Airspan Advisory - This advisory describes seven vulnerabilities in the Airspan Mimosa products.

Johnson Controls Advisory - This advisory describes an improper input validation vulnerability in the Johnson Controls (Sensormatic subsidiary) DSC PowerManage operating platform.

NOTE: This NCCIC-ICS advisory does not mention the Log4Shell vulnerability by name (it does list the CVE), even though Johnson Controls advisory does. The Johnson Controls Log4Shell advisory does not list the PowerManage product even though it does list other Sensormatic PowerSeries products.

FANUC Update - This update provides additional information on an advisory that was originally published on December 7th, 2021.

 

For more details on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-1-update-published-062 - subscription required.

Saturday, December 18, 2021

Review - Public ICS Disclosures – Week of 12-10-21 – Part 1

This week I am going to have to do a three-part report instead of the standard two-part for the weekend following 2nd Tuesday. Part 3 will deal with just Log4Shell advisories. So, for Part 1, we have 17 vendor advisories from Braun (2), Draeger, FANUC, Hitachi Energy (4), HPE, Mitsubishi Electric, Moxa, Rockwell Automation, QNAP (3), Sick, and VMware (2).

Braun Advisory #1 - Braun (USA) published an advisory discussing the NUCLEUS:13 vulnerabilities.

Braun Advisory #2 - Braun (USA) published an advisory discussing the INFRA:HALT vulnerabilities.

Draeger Advisory - Draeger published an advisory describing a privilege escalation vulnerability in their Service Connect Gateway.

FANUC Advisory - FANUC published an advisory describing two vulnerabilities in their Robot Controllers.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory discussing the BadAlloc vulnerabilities in their PWC600 controller.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory discussing the BadAlloc vulnerabilities in their GMS600 monitoring device.

Hitachi Energy Advisory #3 - Hitachi Energy published an advisory discussing the BadAlloc vulnerabilities in their Relion REB500 intelligent electronic devices (IEDs).

Hitachi Energy Advisory #4 - Hitachi Energy published an advisory discussing the BadAlloc vulnerabilities in their Relion 670, 650 series and SAM600-IO IEDs.

HPE Advisory - HPE published an advisory describing a buffer overflow vulnerability in their HPE Gen10 and Gen10 Plus Servers.

Mitsubishi Advisory - Mitsubishi published an advisory discussing three of the INFRA:HALT vulnerabilities in their MELSEC Series Remote I/O.

Moxa Advisory - Moxa published an advisory describing a command injection vulnerability in their NPort W2150A/W2250A Series Serial Device Servers.

Rockwell Advisory - Rockwell published an advisory discussing two vulnerabilities in their 1783 network address translation router (NATR).

QNAP Advisory #1 - QNAP published an advisory describing a stack-based buffer overflow vulnerability in their Surveillance Station.

QNAP Advisory #2 - QNAP published an advisory describing a reflected XSS vulnerability in their Kazoo Server.

QNAP Advisory #3 - QNAP published an advisory describing an improper authentication vulnerability in their Qfile for Android application.

Sick Advisory - Sick published an advisory describing three vulnerabilities in their SOPAS ET software.

VMware Advisory #1 - VMware published an advisory describing a server side request forgery in their  ONE UEM console.

VMware Advisory #2 - VMware has published an advisory describing two vulnerabilities in their Workspace ONE Access product.

For more details on these advisories, including links to researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-66f - subscription required.

Tuesday, December 7, 2021

Review - 3 Advisories Published – 12-7-21

Today, CISA’s NCCIC-ICS published three control system security advisories for products from Hitachi Energy and FANUC. The FANUC advisory was originally published to the restricted access Homeland Security Information Network (HSIN) ICS library on August 31, 2021.

XMC20 Advisory - This advisory describes two vulnerabilities in the Hitachi Energy XMC20 and FOX61x multi-service network elements.

NOTE: I briefly discussed the two Hitachi Energy advisories that form the basis for this advisory on November 27th, 2021.

RTU500 Advisory - This advisory discussing two vulnerabilities in the Hitachi RTU500 Series remote terminal unit.

NOTE: This advisory is based upon an update to the Hitachi advisory that was originally published on November 17th, 2021 and I briefly discussed on November 20th, 2021.

FANUC Advisory - This advisory describes two vulnerabilities in the FANUC R-30iA and R-30iB series robot controllers.

NOTE: The HSIN ICS Library allows the release of vulnerability information to be restricted to selected facilities so that mitigation measures can be put into place before the vulnerabilities are publicly released. In this instance the generic mitigation measures provided by FANUC and NCCIC-ICS hardly seem to justify the delayed release.

NOTE: For more details about these advisories, including links to 3rd party advisories, see my article at CSFN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-published-12-7-21 - subscription required.

 
/* Use this with templates/template-twocol.html */