Showing posts with label Fuji Electric. Show all posts
Showing posts with label Fuji Electric. Show all posts

Tuesday, May 20, 2025

Review – Public ICS Disclosures – Week of 5-10-25 – Part 3

For Part 3 we have an additional vendor disclosure from Fuji Electric. We also have 25 vendor updates from Dell, FortiGuard (8), Schneider (2), Siemens (15). Finally we have a researcher report for vulnerabilities in products from Danfoss.

Advisories

Fuji Electric Advisory - JP-CERT published an advisory that describes 11 vulnerabilities in the Fuji Electric V-SFT-6 product.

Updates

Dell Update - Dell published an update for their Wyse Management Suite advisory that was originally published on April 1st, 2025, and most recently updated on May 8th, 2025.

FortiGuard Update #1 - FortiGuard published an update for their OS command injection advisory that was originally published on January 14th, 2025.

FortiGuard Update #2 - FortiGuard published an update for their OpenSSH Terrapin attack that was originally published on January 9th, 2024, and most recently updated on April 24th, 2024.

FortiGuard Update #3 - FortiGuard published an update for their denial of service attack in OpenSSH advisory that was originally published on March 11th, 2025.

FortiGuard Update #4 - FortiGuard published an update for their integer overflow in ipsec ike advisory that was originally published on January 14th, 2025, and most recently updated on April 11th, 2025.

FortiGuard Update #5 - FortiGuard published an update for their cross-site scripting advisory that was originally published on February 11th, 2025.

FortiGuard Update #6 - FortiGuard published an update for their OS command injection advisory that was originally published on March 11th, 2025.

FortiGuard Update #7 - FortiGuard published an update for their sensitive operations advisory that was originally published on May 14th, 2024.

FortiGuard Update #8 - FortiGuard published an update for their del feature advisory that was originally published on March 11th, 2025.

Schneider Update #1 - Schneider published an update for their EcoStruxure Power Build Rapsody advisory that was originally published on January 14th, 2025.

Schneider Update #2 - Schneider published an update for their ConneXium Network Manager advisory that was originally published on April 8th, 2025.

Siemens Update #1 - Siemens published an update for their FTP Server of Nucleus RTOS advisory that was originally published on October 11th, 2022, and most recently updated on April 8th, 2025.

Siemens Update #2 - Siemens published an update for their User Management Component advisory that was originally published on December 16th, 2024, and most recently updated on March 11th, 2025.

Siemens Update #3 - Siemens published an update for their open redirect advisory that was originally published on October 8th, 2024, and most recently updated on April 8th, 2025.

Siemens Update #4 - Siemens published an update for their Fortigate NGFW advisory that was originally published on March 12th, 2024, and most recently updated on April 16th, 2025.

Siemens Update #5 - Siemens published an update for their Industrial Edge Device Kit advisory that was originally published on April 8th, 2025, and most recently updated on April 17th, 2025.

Siemens Update #6 - Siemens published an update for their Industrial Edge Device Kit advisory that was originally published on April 8th, 2025, and most recently updated on April 17th, 2025.

Siemens Update #7 - Siemens published an update for their SIPROTEC 5 devices advisory that was originally published on February 11th, 2025, and most recently updated on April 8th, 2025.

Siemens Update #8 - Siemens published an update for their SICAM and SITIPE products advisory that was originally published on September 10th, 2024, and most recently updated on December 10th, 2024.

Siemens Update #9 - Siemens published an update for their Palo Alto Networks Virtual NGFW advisory that was originally published on April 9th, 2024, and most recently updated on December 10th, 2024.

Siemens Update #10 - Siemens published an update for their RUGGEDCOM ROS devices advisory that was originally published on July 13th, 2021.

Siemens Update #11 - Siemens published an update for their FortiGate NGFW advisory that was originally published on March 12th, 2024, and most recently updated on April 16th, 2025.

Siemens Update #12 - Siemens published an update for their Palo Alto Networks PAN-OS advisory that was originally published on November 22nd, 2025, and most recently updated on April 8th, 2025.

Siemens Update #13 - Siemens published an update for their Automation License Manager advisory that was originally published on September 10th, 2024.

Siemens Update #14 - Siemens published an update for their SIMATIC S7-1500 CPUs advisory that was originally published October 8th, 2024, and most recently updated on April 8th, 2025.

Siemens Update #15 - Siemens published an update for their s User Management Component advisory that was originally published on September 10th, 2024, and most recently updated on March 11th, 2025.

Researcher Reports

Danfoss Report - Claroty published a report that described an improper authentication vulnerability in the Danfoss AK-SM8xxA Series system security manager.

 

For more information about these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-aeb - subscription required.

Saturday, June 3, 2023

Review – Public ICS Disclosure – Week of 5-27-23

This week we have 31 vendor disclosures from BD, Bosch, B&R, Contec, Eaton, Fuji Electric, Hitachi Energy (2), HPE (3), Mitsubishi, Splunk (15), VMware, and Zyxel (3). There are also four vendor updates from HPE (2) and Moxa (2). We also have 40 researcher reports for vulnerabilities for products from Delta Electronics (22), Fatek Automation (11), Mitsubishi, and Unified Automation (6). Finally, we have an exploit for products from Seagate.

Advisories

BD Advisory - BD published an advisory that discusses a buffer underflow vulnerability in some of their Kiestra products.

Bosch Advisory - Bosch published an advisory that describes a chip damaging vulnerability in their CPP13 and CPP14 cameras.

B&R Advisory - B&R published an advisory that discusses an abuse of service location protocol vulnerability in their ARPOL product.

Contec Advisory - Contec published an advisory that describes seven vulnerabilities in their CONPROSYS HMI System.

Eaton Advisory - Eaton published an advisory that describes a group access authorization logic vulnerability in their SecureConnect portal.

Fuji Electric - JP CERT published an advisory that describes three vulnerabilities in the Fuji Electric FRENIC RHC Loader.

Hitachi Energy Advisory #1 - Hitachi published an advisory that describes an improper output neutralization for logs vulnerability in their UNEM product.

Hitachi Energy Advisory #2 - Hitachi published an advisory that that describes an improper output neutralization for logs vulnerability in their FOXMAN-UN product.

HPE Advisory #1 - HPE published an advisory that describes an arbitrary code execution vulnerability in their Smart Storage Administrator (SSA) Offline product.

HPE Advisory #2 - HPE published an advisory that discusses four vulnerabilities in their HP-UX BIND product.

HPE Advisory #3 - HPE published an advisory that describes a denial of service vulnerability in their HP-UX IPv6 Stack.

Mitsubishi Advisory - Mitsubishi published an advisory that describes four vulnerabilities in their MELSEC iQ-R Series/iQ-F Series EtherNet/IP modules and EtherNet/IP configuration tools.

Splunk Advisories 1-3 - Splunk published three advisories for product updates for third party vulnerabilities.

Splunk Advisories 4-15 - Splunk published 12 advisories for individual vulnerabilities in multiple products.

VMware Advisory - VMware published an advisory that describes an insecure redirect vulnerability in their Workspace ONE Access and Identity Manager products.

Zyxel Advisory #1 - Zyxel published an advisory that describes two classic buffer overflow vulnerabilities in their firewalls.

Zyxel Adviosry #2 - Zyxel published an advisory that describes an OS command injection vulnerability in some of their NAS versions.

Zyxel Advisory #3 - Zyxel published an advisory that discusses recent attacks on their ZyWALL devices.

Updates

HPE Update #1 - HPE published an update for their StoreEasy Servers advisory that was originally published on February 14th, 2023 and most recently updated on March 23rd, 2023.

HPE Update #2 - HPE published an update for their OneView advisory that was originally published on February 6th, 2023.

Moxa Update #1 - Moxa published an update for their MXsecurity advisory that was originally published on March 8th, 2023 and most recently updated on May 23rd, 2023.

Moxa Update #2 - Moxa published an update for their Arm-based Computer advisory that was originally published on November 22nd, 2022.

Researcher Reports

Delta Electronics Reports - ZDI published 22 reports about individual vulnerabilities in the Delta CNCSoft-B product.

Fatek Reports - ZDI published eleven reports about individual vulnerabilities in the Fatek FvDesigner.

Mitsubishi Report - Talos Intelligence published a report describing a memory corruption vulnerability in the Mitsubishi MELSEC iQ-F FX5U MELSOFT.

Unified Automation Report #1 - Claroty published a report that describes an object validation vulnerability in the Unified Automation UaGateway.

Unified Automation Reports #2-6 - ZDI published five reports describing vulnerabilities in the Unified Automation UaGateway.

Exploits

Seagate Exploit - Ege Balci published an metsploit module for an OS command injection vulnerability in the Seagate Central External NAS Storage device.


For more details about these disclosures, including links to researcher reports and exploits, as well as a brief description of new information in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-5-27 - subscription required.


Friday, August 16, 2019

4 Advisories Published – 08-15-19


Yesterday the DHS NCCIC-ICS published four control system security advisories for products from Siemens (2), Fuji Electric, and Johnson Controls.

SINAMICS Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the web server of the Siemens SINAMICS control units. The vulnerability is self-reported. Siemens has updates available to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to perform a denial-of-service attack.

SCALANCE Advisory


This advisory describes two instances of an improper adherence to coding standards vulnerability in the Siemens SCALANCE products. The vulnerability is self-reported. Siemens has an update available that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to  lead to a denial of service or could allow an authenticated local user with physical access to the device to execute arbitrary commands on the device.

NOTE: There are still two advisories and an update that were published by Siemens earlier this week that have not been addressed by NCCIC-ICS. I will report further on them tomorrow.

Fuji Advisory


This advisory describes a stack-based buffer overflow in the Fuji Alpha5 Smart Loader servo  drive. The vulnerability was reported by Natnael Samson (@NattiSamson) via the Zero Day Initiative. Fuji has a new version that mitigates the vulnerability. There is no indication that Samson has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to execute code under the privileges of the application.

Johnson Controls Advisory


This advisory describes two vulnerabilities in the Johnson Controls Metasys building automation system. The vulnerability was reported by harpocrates.ghost. Johnson Controls has a new version that mitigates the vulnerabilities. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Reusing a nonce, key-pair in an encryption - CVE-2019-7593; and
Use of hard-coded cryptographic key - CVE-2019-7594

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit these vulnerabilities to decrypt captured network traffic.

Friday, September 28, 2018

4 ICS Advisories


Yesterday the DHS NCCIC-ICS (okay, I finally gave in; ICS-CERT is gone; please clean up the web site) published four control system security advisories for products from Delta Electronics, Fuji Electric (2) and Emerson.

Delta Advisory

This advisory describes an out-of-bounds read vulnerability in the Delta Industrial Automation PMSoft software development tool. The vulnerability was reported by Mat Powell via ZDI. Delta has an update available that mitigates the vulnerability. There is no indication that Powell has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to read confidential information.

FRENIC Advisory


This advisory describes three vulnerabilities in the Fuji FRENIC HVAC drive devices. The vulnerability was reported by Michael Flanders and Ghirmay Desta via ZDI. Fuji is working on mitigation measures.

The three reported vulnerabilities are:

• Buffer over-read - CVE-2018-14790;
• Out-of-bounds read - CVE-2018-14798; and
Stack-based buffer overflow - CVE-2018-14802

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow for arbitrary remote code execution affecting the availability of the device.

Alpha5 Advisory


This advisory describes two buffer-overflow vulnerabilities in the Fuji Alpha5 Smart Loader servo drive. The vulnerability was reported by Michael Flanders via ZDI. Fuji is working on mitigation measures.

The two reported vulnerabilities are:

• Classic buffer overflow - CVE-2018-14788; and
• Heap-based buffer overflow - CVE-2018-14794

NCCIC-ICS reports that a relatively low-skilled attacker could remotely use publicly available exploits to allow for arbitrary remote code execution on the device.

NOTE: It is disappointing that Fuji was not even able to provide workaround security measures for these two product lines. Does anyone know if NCCIC-ICS is still giving the 45-day grace period before publishing their advisories?

Emerson Advisory


This advisory describes two vulnerabilities in the Emerson AMS Device Manager. The vulnerabilities were reported by Sergey Temnikov of Kaspersky Lab and Emerson. Emerson has patches available to mitigate the vulnerabilities. There is no indication that Temnikov has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper access control - CVE-2018-14804; and
• Improper privilege management - CVE-2018-14808

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to

Wednesday, September 12, 2018

ICS-CERT Publishes 5 Advisories and 4 Updates


Yesterday the DHS ICS-CERT published five control system security advisories for products from Siemens (3) and Fuji electric (2). They also updated three previously published advisories for products from Siemens and the Meltdown/Spectre alert.

SCALANCE Advisory


This advisory describes an improper input validation vulnerability in the Siemens SCALANCE X Switches. The vulnerability is being self-reported. Siemens has updates available for two of the three affected products and has identified mitigation measures.

ICS-CERT reports that a relatively low-skilled attacker could use publicly available exploits to remotely exploit the vulnerability to cause a denial-of-service condition.

SIMATIC Advisory


This advisory describes an improper access control vulnerability in the Siemens SIMATIC WinCC OA HMI. The vulnerability is being self-reported. Siemens has an update available to mitigate the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to escalate their privileges in the context of the program.

TD Keypad Designer Advisory


This advisory describes an unprotected search path element vulnerability in the Siemens TD Keypad Designer. The vulnerability is being self-reported. Siemens has identified generic mitigation measures for the vulnerability.

ICS-CERT reports that a relatively low-skilled attacker with local access could exploit the vulnerability  to escalate their privileges.

V-Server Lite Advisory


This advisory describes a classic buffer overflow vulnerability in the Fuji V-Server Lite. The vulnerability was reported by Ariele Caltabiano (kimiya) via the Zero Day Initiative (ZDI). Fuji has a firmware update available to mitigate the vulnerability. There is no indication that Caltabiano has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to view sensitive information and disrupt the availability of the device.

V-Server Advisory


This advisory describes seven vulnerabilities in the Fuji V-Server. The vulnerabilities were reported by Steven Seeley (mr_me) of Source Incite via ZDI. Fuji has a new software version that mitigates the vulnerabilities. There is no indication that Seeley has been provided an opportunity to verify the efficacy of the fix.

The seven reported vulnerabilities are:

• Use after free - CVE-2018-14809;
• Untrusted pointer dereference - CVE-2018-14811;
• Heap-based buffer overflow - CVE-2018-14813;
• Out-of-bounds write - CVE-2018-14815;
• Integer underflow- CVE-2018-14817;
• Out-of-bounds read - CVE-2018-14819; and
Stack-based buffer overflow - CVE-2018-14823

ICS-CERT reports that a relatively low-skilled attacker could use publicly available exploits to remotely exploit the vulnerabilities to allow for remote code execution on the device, causing a denial of service condition or information exposure.

Industrial Products Update


This update provides new information on an advisory that originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, November 28th, February 27th, 2018, May 3rd, 2018 and most recently on May 15th, 2018. The new information includes revised affected versions data and mitigation measures for:

• SINAMICS DCP w. PN; and
• SINAMICS DCM w. PN

SIMATIC Update


This update provides new information on an advisory that was originally published on May 17th, 2018. The new information includes additional mitigation measures that can be used.

OpenSSL Update


This update provides new information on an advisory that was originally published on August 14th, 2018. The new information includes revised affected versions data and mitigation measures for WinCC OA.

Meltdown/Spectre Update


This update provides new information on an alert that was originally published on January 11th, 2018 and updated on January 16th, 2018, January 17th, 2018, January 30th, 2018, February 20th, 2018, February 22nd, 2018, March 1st, 2018, and most recently on July 10th, 2018. The new information includes a link to a new Meltdown/Spectre advisory from Siemens.

Note: While this newly added advisory from Siemens and another Siemens advisory on the older versions of Meltdown/Spectre address newer versions of the vulnerability, ICS-CERT has failed to provide any information (or links to information) about these new problems.

Tuesday, July 11, 2017

ICS-CERT Publishes 6 Advisories and 2 Updates

Today the DHS ICS-CERT published six control system advisories for products from Schweitzer Engineering Laboratories, OSIsoft (2), ABB, Fuji Electric, and Siemens. They also published updates for two other control system advisories for products from OSIsoft and Siemens.

SEL Advisory


This advisory describes an improper access control vulnerability in the SEL SEL-3620 and SEL-3622 Ethernet Security Gateways. The vulnerability was reported by Jason Holcomb with Revolutionary Security. SEL has developed a firmware update. ICS-CERT reports that Holcomb has verified the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to effect unauthorized communications through the SEL-3620 and SEL-3622 to configured NAT port forwarding destinations.

PI ProcessBook Advisory


This advisory describes (unspecified) third party software {Microsoft Visual Basic for Applications (VBA) v6.5} vulnerabilities in ealier versions of OSIsoft PI ProcessBook and PI ActiveView. There is no specific listing of the individual vulnerabilities involved. These vulnerabilities were self-reported by OSIsoft. Newer versions of the OSIsoft products contain newer versions of the VBA, but do not remove the dll files in which the vulnerabilities reside when upgraded, these must be removed manually.

OSIsoft reports that the affected VBA version would still be required if the workstation was also running MS Office 2003 or MS Office 2007.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerabilities to access arbitrary code.

PI Coresight Advisory


This advisory describes a cross-site request forgery vulnerability in the OSIsoft PI Coresight product. The vulnerability is self-reported. OSIsoft has produced a new version that mitigates the vulnerability.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to access the PI System resulting in unauthorized viewing or alteration of PI System data.

ABB Advisory


This advisory describes two vulnerabilities in the ABB VSN300 WiFi Logger Card. The vulnerability was reported by Maxim Rupp. Newer versions are not affected by the vulnerabilities. There is no indication that Rupp was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to allow attackers to gain unauthorized access to privileged information.

Fuji Electric Advisory


This advisory describes an improper restrictions of operations within the bounds of a memory buffer vulnerability in the Fuji V-Server. The vulnerability was reported by Ariele Caltabiano via the Zero Day Initiative. Fuji has produced a patch to mitigate the vulnerability. There is no indication that Caltabiano has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that an uncharacterized attacker could remotely exploit the vulnerability  to remotely execute arbitrary code.

Siemens Advisory


This advisory describes an out-of-bounds write vulnerability in the Siemens SIMATIC Logon Remote Access product. The vulnerability was reported by Tenable Security. Siemens has produced a new version to mitigate the vulnerability. There is no indication that Tenable has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to cause a denial of service of the SIMATIC Logon Remote Access service under certain conditions.

OSIsoft Update


This update provides new information on the advisory that was originally published on January 10th, 2017. It reports that the new version of PI ProcessBook described above also mitigates this vulnerability. There is no indication that the researcher (Vint Maggs) has been provided an opportunity to verify the efficacy of the fix.

Siemens Update



This update provides new information on the advisory that was originally published on June 29th, 2017. Firmware updates are now available for all affected products. The updated Siemens security advisory reports that SINUMERIK products have been removed from the affected products list available on the Siemens website.
 
/* Use this with templates/template-twocol.html */