Showing posts with label Fortinet. Show all posts
Showing posts with label Fortinet. Show all posts

Saturday, March 18, 2023

Review – Public ICS Disclosures – Week of 3-11-23 – Part 1

This week we have nine vendor disclosures from Aruba Networks, Carrier, Contec, Hitachi Energy, HPE (2), InHand Networks, Moxa, and Phoenix Contact. There are five vendor updates from HPE (4) and Moxa. Finally, we have three exploits for products from Eaton, Riello, and Fortinet.

In Part 2 this week I will look at disclosures from Schneider and Siemens.

Advisories

Aruba Advisory - Aruba published an advisory that describes eight vulnerabilities in their ClearPass Policy Manager program.

Carrier Advisory - Carrier published an advisory that discusses a server side request forgery vulnerability in their g LenelS2 supported platform.

Contec Advisory - Contec published an advisory that describes three vulnerabilities in their CONPROSYS M2M Gateway Series, M2M Controller Series products.

Hitachi Energy Advisory - Hitachi published an advisory that discusses a permissions, privileges, and access control vulnerability in their MicroSCADA Pro/X SYS600 Products.

HPE Advisory #1 - HPE published an advisory that discusses eight vulnerabilities in their NonStop servers.

HPE Advisory #2 - HPE published an advisory that describes a cross-site scripting vulnerability in their Integrated Lights-Out products.

InHand Advisory - InHand published an advisory that describes five vulnerabilities in their InRouter615-S industrial routers.

Moxa Advisory - Moxa published an advisory that describes two improper certificate validation vulnerabilities in their NPort 6000 Series and Windows Driver Manager products.

Phoenix Contact Advisory - Phoenix Contact published an advisory that discusses five vulnerabilities in their ENERGY AXC PU product.

Updates

HPE Update #1 - HPE published an update for their FlexNetwork and FlexFabric Switches advisory that was originally published on July 30th, 2022.

HPE Update #2 - HPE published an update for their OneView for VMware vCenter advisory that was originally published on February 17th, 2023.

HPE Update #3 - HPE published an update for their ProLiant Moonshot Servers advisory that was originally published on November 8th, 2022.

HPE Update #4 - HPE published an update for their ProLiant BL/DL/ML Servers advisory that was originally published on November 8th, 2022.

Moxa Update - Moxa published an update for their UC Series advisory that was originally published on November 29th, 2022 and most recently updated on February 9th, 2023.

Exploits

Eaton Exploit - Yehia Elghaly published an exploit for a denial-of-service vulnerability in the Eaton Webpower UPS.

Reillo Exploit - Ricardo Jose Ruiz Fernandez published an exploit for shell bypass vulnerability in the Riello UPS system.

Fortinet Exploit - Jheysel-r7, Zach Hanley, and Gwendal Guegniaud published a Metasploit module for an externally controlled reference to a resource in another sphere vulnerability in the FortiNAC.

 

For more details about these disclosures, including links to third-party advisories, researcher reports and summary of changes made in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-d50  - subscription required.

Tuesday, October 22, 2019

1 Advisory Published – 10-22-19


Today he CISA NCCIC-ICS published a control system security advisory for products from Schneider

Schneider Advisory


This advisory describes three vulnerabilities in the Schneider ProClima building and automation control products. The vulnerabilities were reported by Haojun Hou, Kushal Arvind Shah, Fortinet, Yongjun Liu, NSFOCUS, and Telus. Schneider has released a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Code injection - CVE-2019-6823;
Improper restriction of operations within the bounds of a memory buffer - CVE-2019-6824; and
Uncontrolled search path element - CVE-2019-6825

NCCIC-ICS reported that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system.

NOTE: According to the Schneider advisory these vulnerabilities were reported on June 11th, and I briefly reported on them on June 15th. What NCCIC-ICS is actually addressing is an update to the original advisory that adjusted the CVSS Base Score and Vector for CVE2019-6823 and CVE-2019-6824.

Saturday, June 15, 2019

Public ICS Disclosure – Week of 06-08-19


This week we have two new vendor notifications from Schneider and 18 researcher reports from Talos of vulnerabilities in products from Schneider. We also have four updated notifications from Schneider (2) and Siemens (2). Additionally, we have two vendor updates for advisories about the Microsoft® RDP vulnerability from Philips and Drager.

Schneider Advisories


1. Schneider published an advisory for a credential exposure vulnerability in the Schneider PowerSCADA Expert product (NOTE: According to Schneider this also affects the AVEVA CitecSCADA, but no AVEVA advisory has yet been published). This vulnerability is apparently self-reported. Schneider has a new version that mitigates the vulnerability.

2. Schneider published an advisory for three vulnerabilities in the Schneider ProClima product. The vulnerabilities were reported by Kushal Arvind Shah (Fortinet), Telus, and Haojun Hou and
Yongjun Liu (NSFOCUS). Schneider has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Code injection - CVE-2019-6823;
Buffer errors - CVE-2019-6824; and
Uncontrolled search path element - CVE-2019-6825

Talos Reports on Schneider Vulnerabilities


Talos has provided reports with exploits on 18 vulnerabilities in two products from Schneider; Modicon 580 UMAS and UnityPro PLC. These are coordinated disclosures, but Schneider has not yet published advisories for these vulnerabilities. Because of the volume I am not going to attempt to go into details.

Modicon 580 UMAS

Information disclosure - CVE-2018-7845;
Denial of service - CVE-2018-7854;
Denial of service - CVE-2018-7853;
Denial of service - CVE-2018-7849;
Improper authentication - CVE-2018-7842;
Unauthenticated file write - CVE-2018-7847;
Denial of service - CVE-2018-7855;
Denial of service - CVE-2019-6807;
Denial of service - CVE-2018-7856;
Information disclosure - CVE-2018-7844;
Information disclosure - CVE-2019-6806;
Information disclosure - CVE-2018-7848;
Denial of service - CVE-2018-7852;
Denial of service - CVE-2018-7846;
Denial of service - CVE-2018-7857; and
Denial of service - CVE-2018-7843

UnityPro

Remote code execution - CVE-2019-6808;
Untrusted inputs - CVE-2018-7850;

NOTE: There are still 10 reports pending on Schneider vulnerabilities on the Talos Zeroday Reports web page. Someone has been spending a great deal of time testing Schneider equipment.

Schneider Updates


1. Schneider updated an advisory for the Schneider Embedded Web Servers for Modicon V2 (Note: this has not been reported by NCCIC-ICS). The new information is the addition of researcher acknowledgements.

2. Schneider updated an advisory for the Schneider – U.motion Builder software (Note: this has not been reported by NCCIC-ICS). Schneider is reporting that this vulnerability has been exploited by Mirai malware. Schneider is making an unusual recommendation: “It is imperative customers cease using U.motion Builder software and remove it from their systems immediately.”

Siemens Updates


1. Siemens updated an advisory for Foreshadow/L1 terminal fault vulnerabilities in Industrial Products (Note: this has not been reported by NCCIC-ICS). The new information is added mitigation measures for:

SIMATIC S7-1500 Software Controller;
SIMATIC ET 200 SP Open Controller; and
SIMATIC ET 200 SP Open Controller (F)

2. Siemens updated an advisory for Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU. The update adds information for new firmware V2.6.1

RDP Vulnerability


Two vendor advisories were updated this week:

Philips; and
Drager

 
/* Use this with templates/template-twocol.html */