Showing posts with label Franklin. Show all posts
Showing posts with label Franklin. Show all posts

Tuesday, September 24, 2024

Review – 6 Advisories and 2 Updates Published – 9-24-24

Today, CISA’s NCCIC-ICS published six control system security advisories for products from Moxa, OMNTEC, Dover Fueling Solutions, Franklin Fueling Solutions, Alisonic, and OPW Fuel Management Solutions. They also updated advisories for products from Interpeak and Uniview.

Advisories

Moxa Advisory - This advisory describes three vulnerabilities in the Moxa MXview One products.

OMNTEC Advisory - This advisory describes a missing authentication for critical function vulnerability in the OMNTEC Proteus Tank Monitoring product.

Dover Advisory - This advisory describes six vulnerabilities in the DFS ProGauge MAGLINK LX Consoles.

Franklin Advisory - This advisory describes an absolute path traversal vulnerability in the Franklin TS-550 EVO automatic tank gauge.

Alisonic Advisory - This advisory describes an SQL injection vulnerability in the Alisonic Sibylla automated tank gauge.

OPW Advisory - This advisory describes a missing authentication for critical function vulnerability in the OPW SiteSentinel product.

NOTE: The vulnerabilities for the five fuel handling equipment advisories were reported to CISA by Pedro Umbelino of BitSight; that report is worth reading.

Updates

Interpeak Update - This update provides additional information on the Interpeak TCP/IP Stack advisory that was originally published on October 1st, 2019 and most recently updated on May 12th, 2020.

Uniview Update - This update provides additional information on the Uniview NVR301-04S2-P4 advisory that was originally published on June 4th, 2024.

 

For more information on these advisories, including links to a researcher report and a down-the-rabbit-hole look at relay rapid cycling attacks, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-2-updates-published - subscription required.

Tuesday, March 19, 2024

Review – 1 Advisory Published – 3-19-24

Today, CISA’s NCCIC-ICS published a control system security advisory for products from Franklin Fueling Systems.

Advisories

Franklin Advisory - This advisory describes a path traversal vulnerability in the Franklin EVO 550 and EVO 5000 automatic tank gauges (ATG).

 

For more details about today’s disclosure, including a look at a history of Franklin disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-published-3-19-24 - subscription required.

Tuesday, November 28, 2023

Review – 4 Advisories Published – 11-28-23

Today, CISA’s NCCIC-ICS published three control system security advisories for products from Mitsubishi Electric, Franklin Electric Fueling Systems, and Delta Electronics. They also published a medical device security advisory for products from BD.

Advisories

Mitsubishi Advisory - This advisory describes two improper input validation vulnerabilities in the Mitsubishi GX Works2.

Franklin Advisory - This advisory describes a path traversal vulnerability in the Franklin FFS Colibri fuel inventory monitoring system.

Delta Advisory - This advisory describes four vulnerabilities in the Delta InfraSuite Device Master product.

BD Advisory - This advisory describes seven vulnerabilities in the BD BD FACSChorus workstations.

 

For more details about these advisories, including corrected link for vendor advisory, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-published-11-28-23 - subscription required.

Thursday, November 2, 2023

Review – 6 Advisories Published – 11-2-23

Today, CISA’s NCCIC-ICS published six control system security advisories for products from Schneider Electric, Weintek, Franklin Fueling Systems, Mitsubishi Electric (2), and Red Lion.

Advisories

Schneider Advisory - This advisory describes two vulnerabilities in the Schnieder SpaceLogic C-Bus Toolkit.

Weintek Advisory - This advisory describes a use of hard-coded credentials vulnerability in the Weintek EasyBuilder Pro products.

Franklin Advisory - This advisory describes a use of password hash with insufficient computational effort vulnerability in the Franklin Fueling Systems TS-550 product.

Mitsubishi Advisory #1 - This advisory describes an insufficient verification of data authenticity vulnerability in the Mitsubishi MELSEC Series products.

Mitsubishi Advisory #2 - This advisory describes an improper restriction of excessive authentication attempts vulnerability in the Mitsubishi MELSEC iQ-F Series products.

Red Lion Advisory - This advisory describes an improper neutralization of null byte or null character vulnerability in the Red Lion Crimson 3.2 Windows-based configuration tool.

 

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published-11-2-23 - subscription required.

 
/* Use this with templates/template-twocol.html */