Showing posts with label GE Grid. Show all posts
Showing posts with label GE Grid. Show all posts

Saturday, November 30, 2024

Review – Public ICS Disclosures – Week of 11-23-24

This week we have 41 vendor disclosures from Axis (5), B&R, Dell, Dassault Systems, ELECOM, Fuji Electric, GE Vernova (19), Hitachi Energy, HPE, Mitsubishi, Palo Alto Networks, PEPPERL+FUCHS, Splunk (2), SMA Solar Technology, VMware, and Zyxel. There are also five vendor updates from ELECOM (4) and FortiGuard. We also have 21 researcher reports of vulnerabilities in products from ABB (4) and Fuji (17).

Advisories

Axis Advisory #1 - Axis published an advisory that describes an improper validation of syntactic correctness of input vulnerability in their AxisOS product.

Axis Advisory #2 - Axis published an advisory that describes an improper validation of syntactic correctness of input vulnerability in their AxisOS product.

Axis Advisory #3 - Axis published an advisory that describes an incorrect default permissions vulnerability in their Camera Station products.

Axis Advisory #4 - Axis published an advisory that describes an insufficiently protected credentials vulnerability in the Camera Station products.

Axis Advisory #5 - Axis published an advisory that describes a client-side enforcement of server-side security vulnerability in their Camera Station products.

B&R Advisory - B&R published an advisory that describes an authentication bypass using an alternate path or channel vulnerability in multiple mapp products.

Dell Advisory - Dell published an advisory that describes four vulnerabilities in their Wyse Management Suite. The first vulnerability is a third-party (MongoDB) issue.

Dassault Systems Advisory - Dassault Systems published an advisory that discusses a deserialization of untrusted data vulnerability (with publicly available exploit) in their Iterop product.

ELECOM Advisory - JP-CERT published an advisory that describes four vulnerabilities in multiple ELECOM wireless LANs.

Fuji Advisory - JP-CERT published an advisory that describes three vulnerabilities in the Fuji V-SFT, TELLUS, and V-Server products.

GE Vernova Advisories - GE Vernova (formerly Grid Solutions) published 19 advisories.

Hitachi Energy Advisory - Hitachi Energy published an advisory that discusses four vulnerabilities in their NSD570 Teleprotection Equipment.

HPE Advisory - HPE published an advisory that describes an unauthorized data modification vulnerability in their IceWall Products.

Mitsubishi Advisory - Mitsubishi published an advisory that describes three vulnerabilities in their GENESIS64TM and MC Works64 products.

Palo Alto Networks Advisory - Palo Alto Networks published an advisory that describes an improper certificate validation vulnerability (with publicly available exploit) in their GlobalProtect App.

PEPPERL+FUCHS Advisory - CERT-VDE published an advisory that discusses the PKFAIL vulnerability in multiple products from PEPPERL+FUCHS.

Splunk Advisory #1 - Splunk published an advisory that discusses three vulnerabilities (one with publicly available exploit) in their Splunk Machine Learning Toolkit.

Splunk Advisory #2 - Splunk published an advisory that discusses an exposure of sensitive information to an unauthorized actor vulnerability in their Python for Scientific Computing product.

SMA Solar Advisory - CERT-VDE published an advisory that describes an SQL injection vulnerability in SMA Sunny Central products.

VMware Advisory - Broadcom published an advisory that describes five vulnerabilities in the VMware Aria Operations product.

Zyxel Advisory - Zyxel published an advisory that discusses recent attempts to exploit a previously fixed directory traversal vulnerability in their ZLD firewall.

Updates

ELECOM Update #1 - JP-CERT published an update for the ELECOM wireless LAN router advisory that was originally published on May 28th, 2024, and most recently updated on August 27th, 2024.

ELECOM Update #2 - JP-CERT published an update for the ELECOM wireless LAN router advisory that was originally published on March 26th, 2024, and most recently updated on August 27th, 2024.

ELECOM Update #3 - JP-CERT published an update for the ELECOM wireless LAN router advisory that was originally published on August, 27th, 2024, and most recently updated on September 9th, 2024.

ELECOM Update #4 - JP-CERT published an update for the ELECOM wireless LAN router advisory that was originally published on March 26th, 2024, and most recently updated on August 27th, 2024.

FortiGuard Update - FortiGuard published an update for their missing authentication in fgfmsd advisory that was originally published on October 23rd, 2024, and most recently updated on November 15th, 2024.

Researcher Reports

ABB Reports - Zero Science published four reports of vulnerabilities in the ABB Cylon Aspect building energy management product.

Fuji Reports - The Zero Day Initiative published 17 reports of vulnerabilities in the Fuji Monitouch V-SFT.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-95e - subscription required. 

Tuesday, November 7, 2023

Review – 1 Advisory Published – 11-7-23

Today, CISA’s NCCIC-ICS published a control system security advisory or product from GE Grid Solutions.

Advisories

GE Advisory - This advisory describes an uncontrolled search path vulnerability in the GE MiCOM S1 Agile engineering tool suite.

 

For more information about this advisory and its related GE disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-published-11-7-23 - subscription required.

Saturday, November 4, 2023

Review – Public ICS Disclosure – Week of 10-28-23 – Part 1

This week for Part 1 we have 20 vendor disclosures from ABB, Bentley, Cisco (5), CODESYS, Eurotech, GE Grid, Hitachi (2), Hitachi Energy (2), Insyde (3), and Moxa (3).

Part 2 will include a large number of vendor updates.

Advisories

ABB Advisory - ABB published an advisory that discusses 16 vulnerabilities in their COM600 product.

Bentley Advisory - Bentley published an advisory that discusses an out-of-bounds write vulnerability in their Seequent LeapFrog product.

Cisco Advisory #1 - Cisco published an advisory that describes a policy bypass vulnerability in their Snort 3 detection engine.

Cisco Advisory #2 - Cisco published an advisory that describes an SSL/TLS certificate handling vulnerability in their Snort 3 Detection Engine.

Cisco Advisory #3 - Cisco published an advisory that describes a memory allocation vulnerability in their Snort 3 Detection Engine.

Cisco Advisory #4 - Cisco published an advisory that describes a policy bypass vulnerability in their Snort 3 detection engine.

Cisco Advisory #5 - Cisco published an advisory that describes an IP geolocation bypass vulnerability in their Snort 3 detection engine.

CODESYS Advisory - CODESYS published an advisory that discusses a heap-based buffer overflow vulnerability in a variety of CODESYS V2 and V3 products.

Eurotech Advisory - Eurotech published an advisory that discusses an unquoted search path or element vulnerability in a number of Eurotech products.

GE Grid Advisory - GE published an advisory for a vulnerability in their S1 Agile Engineering Tool Suite.

Hitachi Advisory #1 - Hitachi published an advisory that discusses 21 vulnerabilities in their Disk Array Systems products.

Hitachi Advisory #2 - Hitachi published an advisory that discusses three vulnerabilities in their Cosminexus Developer's Kit for Java and Hitachi Developer's Kit for Java.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory that describes three vulnerabilities in their eSOMS product.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory that describes two vulnerabilities in their MACH System software product.

Insyde Advisory #1 - Insyde published an advisory that describes a stack-based buffer overflow vulnerability in their AsfSecureBootDxe.

Insyde Advisory #2 - Insyde published an advisory that describes an SMM memory corruption vulnerability in their CsmInt10HookSmm.

Insyde Advisory #3 - Insyde published an advisory that describes an unsanitized arguments in SMI handler vulnerability in their IhisiServicesSmm.

Moxa Advisory #1 - Moxa published an advisory that describes a classic buffer overflow vulnerability in their EDR-810/G902/G903 Series web server.

Moxa Advisory #2 - Moxa published an advisory that describes the use of a broken or risky cryptographic algorithm vulnerability in their NPort 6000 Series products.

Moxa Advisory #3 - Moxa published an advisory that discusses seven vulnerabilities in their PT-G503 Series products.

 

For more information on these advisories, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-10-e57 - subscription required. 

Saturday, March 11, 2023

Review – Public ICS Disclosures – Week of 3-4-23

This week we have 26 vendor disclosures from ABB, Apache, DrayTek, FortiGuard Labs (15), GE Grid Solutions, Hitachi, HPE (2), Insyde, Mitsubishi, Moxa, and Phoenix Contact. And we have two exploits for products from Real Time Automation and AgileBio.

Advisories

ABB Advisory - ABB published an advisory that discusses an improper input validation vulnerability in their Substation management unit COM600.

Apache Advisory - Apache announced a memory exhaustion vulnerability in unsupported versions of Apache Log4j.

DrayTek Advisory - DrayTek published an advisory that describes a cross-site scripting vulnerability in their Vigor routers.

FortiGuard Advisory #1 - FortiGuard published an advisory that describes an incomplete filtering of one or more instances of special elements vulnerability in their FortiWeb and FortiRecorder.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an OS command injection vulnerability in their FortiWeb products.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes an access control vulnerability in their FortiSOAR's playbook.

FortiGuard Advisory #4 - FortiGuard published an advisory that describes an uncontrolled resource consumption vulnerability in their FortiRecorder products.

FortiGuard Advisory #5 - FortiGuard published an advisory that describes an exposure of sensitive information to unauthorized actor vulnerability in their FortiOS and FortiProxy products.

FortiGuard Advisory #6 - FortiGuard published an advisory that describes a path traversal vulnerability in their FortiOS and FortiProxy products.

FortiGuard Advisory #7 - FortiGuard published an advisory that describes a buffer underwrite vulnerability in their FortiOS and FortiProxy products.

FortiGuard Advisory #8 - FortiGuard published an advisory that describes a path traversal vulnerability in their FortiOS products.

FortiGuard Advisory #9 - FortiGuard published an advisory that describes an access of an unitialized pointer vulnerability in their FortiOS and FortiProxy products.

FortiGuard Advisory #10 - FortiGuard published an advisory that describes an improper privilege management vulnerability in their FortiNAC products.

FortiGuard Advisory #11 - FortiGuard published an advisory that describes a reflected cross-site scripting vulnerability in their FortiNAC products.

FortiGuard Advisory #12 - FortiGuard published an advisory that describes an exposure of sensitive information to unauthorized actor vulnerability in their FortiManager, FortiAnalyzer, FortiPortal and FortiSwitch products.

FortiGuard Advisory #13 - FortiGuard published an advisory that describes an improper restriction of excessive authorization attempts vulnerability in their FortiAuthenticator, FortiDeceptor and FortiMail products.

FortiGuard Advisory #14 - FortiGuard published an advisory that describes an exposure of sensitive information to an unauthorized actor vulnerability in their FortiAnalyzer products.

FortiGuard Advisory #15 - FortiGuard published an advisory that describes an improper neutralization of formula elements vulnerability in their FortiAnalyzer products.

GE Advisory - GE Grid Solutions published an advisory for their Reason S20 products.

Hitachi Advisory - Hitachi published an advisory that discusses 36 vulnerabilities in their Disk Array Systems. These are third-party (Microsoft) vulnerabilities.

HPE Advisory #1 - HPE published an advisory that describes a host head injection vulnerability in their FlexFabric 5700 Switches.

HPE Advisory #2 - HPE published an advisory that describes an information disclosure vulnerability in their Superdome Flex and Superdome Flex 280 Servers.

Insyde Advisory - Insyde published an advisory that describes a stack-based buffer overflow vulnerability in multiple products.

Mitsubishi Advisory - Mitsubishi published an advisory that discusses two classic buffer overflow vulnerabilities in their GENESIS64 product.

Moxa Advisory - Moxa published an advisory [added link - 5-25-23 1330 EDT] that describes two vulnerabilities in their MXsecurity series.

Phoenix Contact Advisory - Phoenix Contact published an advisory that discusses two vulnerabilities in their TC ROUTER and CLOUD CLIENT.

Exploits

Real Time Automation Exploit - Yehia Eighaly published an exploit for a cross-site scripting vulnerability in the Real Time Automation 460MCBS - Modbus TCP to BACnet/IP Gateway.

AgileBio Exploit – Anthony Cole published an exploit for a remote code execution vulnerability in the AbileBio LabCollector LIMS system.


For more details on these disclosures, including links to third-party advisories and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-07f - subscription required.


Saturday, January 28, 2023

Review – Public ICS Disclosures – Week of 1-21-23

This week we have an OpenSSL 3.0 advisory from Dell. We have seven vendor disclosures from Carrier, Contec, GE Grid Solutions, Meinberg, Omron, and PulseSecure (2). We also have three vendor updates from CODESYS, HPE, and PcVue. Finally, we have 16 researcher reports for products from Siretta (14), Zyxel, and Delta Electronics.

Open SSL 3.0 Advisories

Dell published an advisory that discusses the OpenSSL 3.0 vulnerabilities.

Vendor Advisories

Carrier Advisory - Carrier published an advisory that discusses multiple authentication bypass vulnerabilities in their WebCTRL® and i-Vu® software.

Contec Advisory - Contec published an advisory that describes an SQL injection vulnerability in the Contec CONPROSYS HMI System.

GE Grid Solutions Advisory - GE Grid Solutions published an advisory for their DS Agile Distributed Control System.

Meinberg Advisory - Meinberg published an advisory that discusses eight vulnerabilities in their LANTIME product.

Omron Advisory - JP Cert published an advisory that describes an improper restriction of an XML entity reference vulnerability in the OMRON CX-Motion Pr.

PulseSecure Advisory #1 - PulseSecure published an advisory that discusses a use-after-free vulnerability.

PulseSecure Advisory #2 - PulseSecure published an advisory that discusses a double free vulnerability.

Vendor Updates

CODESYS Update - CODESYS published an update for their Control V3 communication server advisory that was originally published on November 22nd, 2022 and most recently updated on December 14th, 2022.

HPE Update - HPE published an update for their IceWall advisory that was originally published on March 9th, 2018 and most recently updated on May 26th, 2021.

PcVue Update - PcVue published an update for their email and SMS accounts advisory that was originally published on November 25th, 2022 and most recently updated on December 20th, 2022.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-22-354-03) to reflect this information.

Researcher Reports

Siretta Report #1 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing 46 stack-based buffer overflow vulnerabilities.

Siretta Report #2 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing a directory traversal vulnerability.

Siretta Report #3 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing four command injection vulnerabilities.

Siretta Report #4 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing a heap-based buffer overflow vulnerability.

Siretta Report #5 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing a file write vulnerability.

Siretta Report #6 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing a leftover debug code vulnerability.

Siretta Report #7 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing an OS command injection vulnerability.

Siretta Report #8 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing an OS command injection vulnerability.

Siretta Report #9 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing an OS command injection vulnerability.

Siretta Report #10 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing a stack-based buffer overflow vulnerability.

Siretta Report #11 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing a directory traversal vulnerability.

Siretta Report #12 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing an OS command injection vulnerability.

Siretta Report #13 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing a directory traversal vulnerability.

Siretta Report #14 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing a stack-based buffer overflow vulnerability.

Zyxel Report - Positive Technologies published a report describing an improper check for unusual or exceptional conditions vulnerability in Zyxel switches.

Delta Report - Tenable published a report describing a privilege escalation vulnerability in the Delta Electronics InfraSuite Device Master.

 

For more details about these disclosures, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-e09 - subscription required.

Saturday, January 14, 2023

Review: Public ICS Disclosures – Week of 1-7-23 – Part 1

This is a moderately busy Saturday after Cyber Tuesday. For Part 1 this week we have seventeen vendor disclosures from GE Grid Solutions (8), HP, HPE, Moxa, Omron (2), WAGO, Westermo, and Western Digital (2). We also have two vendor updates from BD and HPE. I will look at the Schneider and Siemens advisories and updates in Part 2.

Vendor Advisories

GE Grid Advisories - GE Grid Solutions published eight advisories this week. The advisories are only available to registered users.

HP Advisory - HP published an advisory that discusses three vulnerabilities in the AMD Client UEFI Firmware used in a variety of HP products.

HPE Advisory - HPE published an advisory that discusses a privilege escalation vulnerability in their SimpliVity 380 Gen9 Servers.

Moxa Advisory - Moxa published an advisory that discusses a hard-coded credential vulnerability (with known exploit) in their TN-4900 Series routers.

Omron Advisory #1 - JPCERT published an advisory that describes an active debug code vulnerability in the OMRON CP1L-EL20DR-D PLC.

Omron Advisory #2 - JPCERT published an advisory that describes an uninitiated pointer vulnerability in the OMRON CX-Motion-MCH application.

WAGO Advisory - CERT-VDE published an advisory that describes a missing authentication for critical function vulnerability in multiple products from WAGO.

Westermo Advisory - Westermo published an advisory that discusses an unnamed vulnerability in their Ibex software where SNMP v3 is enabled.

Western Digital Advisory #1 - Western Digital published an advisory that describes a Host Boot ROM code vulnerability. This is a vulnerability in the UFS Host implementation.

NOTE: So, this is not a Western Digital vulnerability, but one that they discovered in an industry standard service. This could get ugly.

Western Digital Advisory #2 - Western Digital published an advisory that describes four vulnerabilities in their My Cloud OS 5 devices.

Vendor Updates

BD Update - BD published an update to their Totalys™ MultiProcessor advisory that was originally published on October 4th, 2022.

NOTE: NCCIC-ICS has not yet updated their advisory (ICSMA-22-277-01) for this information.

HPE Update - HPE published an update for their Nonstop advisory that was originally published on July 18th, 2022.

 

For more details on these disclosures, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-b04 - subscription required.

Saturday, September 3, 2022

Review – Public ICS Disclosure – Week of 8-27-22

This week we have twelve vendor disclosures from Aruba, Contec, GE Grid Solutions (2), HPE (3), Johnson Controls, Ovarro (2), Rockwell Automation, and Yokogawa. We also have three vendor updates from Mitsubishi, QNAP, and VMware.

Aruba Advisory - Aruba published an advisory that describes twelve vulnerabilities in their AOS-CX switches.

Contec Advisory - JP-CERT published an advisory that describes two vulnerabilities in the Contec FLEXLAN FX3000 wireless LAN.

GE Grid Advisory #1 - GE Grid published an advisory that describes a vulnerability in their Reason RT430/RT434 – GPS/GNSS Precision Clocks.

GE Grid Advisory #2 - GE Grid published an advisory that describes a vulnerability in their Reason RT431 - Time Code Generator.

HPE Advisory #1 - HPE published an advisory that discusses a privilege escalation vulnerability in their ProLiant Apollo, XL Servers.

HPE Advisory #2 - HPE published an advisory that discusses an information disclosure vulnerability in their HPE Apollo, XL Servers.

HPE Advisory #3 - HPE published an advisory that discusses an privilege escalation vulnerability in their Superdome Flex 280 Servers.

Johnson Controls Advisory - Johnson Controls published an advisory that describes a command injection vulnerability in their  iSTAR Ultra door controller.

Ovarro Advisory #1 - Ovarro published an advisory that discusses four vulnerabilities in their Kingfisher Toolbox Plus software.

Ovarro Advisory #2 - Ovarro published an advisory that discusses four vulnerabilities in their Seprol range of S2000 WITS RTUs.

Rockwell Advisory - Rockwell published an advisory that discusses two vulnerabilities in their KEPServer Enterprise.

Yokogawa Advisory - Yokogawa published an advisory that discusses an insufficient verification of data authenticity vulnerability in their STARDOM controller.

NOTE: This is an OT:ICEFALL vulnerability, the first that I recall seeing being reported as a third-party vulnerability.

Mitsubishi Update - Mitsubishi published an update for their GENESIS64TM and MC Works64 advisory that was originally published on July 19th, 2022.

NOTE: NCCIC-ICS did not update their advisory (ICSA-22-202-04) for this information.

QNAP Update - QNAP published an update for their Samba advisory that was originally published on August 16th, 2022.

VMware Update - VMware published an update for their VMware Tools advisory that was originally published on August 23rd, 2022.

 

For more details about these disclosures, including links to third-party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-8-27 - subscription required.

Saturday, August 20, 2022

Review – Public ICS Disclosure – Week of 8-13-22

This week we have ten vendor disclosures from Aruba Networks, Aveva, Broadcom, Flexera, GE Grid Solutions, QNAP (2), Softing and WAGO (2). There are five vendor updates from B&R, Mitsubishi Electric, Palo Alto Networks, and Schneider (2). We also have a researcher report for products from Boeing. Finally, we have four exploits for products from Palo Alto Networks, FLIR (2), and Advantech.

Aruba Advisory - Aruba published an advisory that describes a sensitive information disclosure vulnerability in their Virtual Internet Access client for Windows.

Aveva Advisory - Aveva published an advisory that describes six vulnerabilities in their Edge product (formerly Indusoft Web Studio).

NOTE: Aveva reports that the vulnerabilities were coordinated through ‘ICS-CERT’ and ZDI, so I expect that there will be a NCCIC-ICS advisory next week.

Broadcom Advisory - Broadcom published an advisory that discusses an OS command injection vulnerability in their SANnav products.

Flexera Advisory - Revenera published an advisory that discusses two vulnerabilities in their FlexNet Publisher.

GE Grid Advisory - GE published an advisory for their Reason S20 product.

QNAP Advisory #1 - QNAP published an advisory that discusses seven vulnerabilities in their NAS products.

QNAP Advisory #2 - QNAP published an advisory that discusses five vulnerabilities in their NAS products.

Softing Advisory - Softing published an advisory that discusses five vulnerabilities in their OPC UA .NET SDK products.

WAGO Advisory #1 - CERT-VDE published an advisory that discusses six vulnerabilities in multiple WAGO product families.

WAGO Advisory #2 - CERT-VDE published an advisory that discusses four vulnerabilities in multiple WAGO product families.

B&R Update - B&R published an update for their Project Upload advisory that was originally published on January 20th, 2022.

Mitsubishi Update - Mitsubishi published an update for their OpenSSL advisory that was originally published on August 2nd, 2022.

Palo Alto Networks Update - Palo Alto Networks published an update for their PAN-OS advisory that was originally published on August 10th, 2022.

Schneider Update #1 - Schneider published an update for their OPC UA advisory that was originally published on July 12th, 2022 and most recently updated on August, 9th, 2022.

Schneider Update #2 - Schneider published an update for their APC Smart-UPS advisory that was originally published on March 8th, 2022 and most recently updated on July 12th, 2022.

Boeing Report - Pen Test Partners published a report describing two vulnerabilities in the Boeing Onboard Performance Tool (OPT).

Palo Alto Networks Exploit - UnD3sc0n0c1d0 published an exploit for an OS command injection vulnerability in the Palo Alto PAN-OS.

FLIR Exploit #1 - Samy Younsi published an exploit for a remote command execution vulnerability in the FLIR AX8 thermal imaging camera.

FLIR Exploit #2 - Samy Younsi and Thomas Knudsen published an exploit for three vulnerabilities in the FLIR AX8 thermal imaging camera.

Advantech Exploit - Rgod, Shelby Pace, and Y4er published a Metasploit module for a command injection vulnerability in the Advantech iView NetworkServlet.

 

For more details about these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-8-13 - subscription required.

Saturday, March 27, 2021

Public ICS Disclosures – Week of 3-20-21

This week we have 27 vendor disclosures from BD (3), Bosch, TRUMPF, GE Grid Systems (19), Mitsubishi Electric, Moxa, and Rockwell Automation. We have a researcher report for products from Ovarro. Finally, there were two exploits published for products from VMWare and Advantech.

BD Advisories

BD published patch advisories for the below listed products. These are the 3rd party patches that have been tested by BD on the listed products.

BD Care Coordination Engine (CCE),

Security Patches: BD Pyxis™ Products, and

Security Patches: BD Alaris™ Systems Manager

Bosch Advisories

Bosch published an advisory describing seven uncontrolled search path element vulnerabilities in multiple Bosch products. The vulnerabilities were reported by Nir Yehoshua, Dhiraj Mishra, and Eli Paz of CyberArk. Bosch has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

TRUMPF Advisory

CERT-VDE published an advisory describing an out-of-bounds write vulnerability in the TRUMPF TruControl laser control software. The vulnerability was reported by Qualys Research Labs. TRUMPF has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

GE Grid Advisories

GE published advisories for the below listed products. These may be updates for previously issued advisories, but only GE customers can access the advisories, so I do not know for sure:

C30 Controller

C60 Breaker Management Relay

C70 Capacitor Bank Protection and Control System

B30 Bus Differential Relay

B90 Bus Differential System

F35 Multiple Feeder Management Relay

F60 Feeder Management Relay

G30 Generator Management Relay

G60 Generator Management Relay

L30 Line Current Differential Relay

L60 Line Phase Comparison Relay

L90 Line Current Differential Relay

M60 Motor Management Relay

D30 Line Distance Relay

D60 Line Distance Relay

N60 Network Stability and Synchrophasor Measurement System

T35 Transformer Management Relay

T60 Transformer Management Relay

UR Family of Protection Relays

Mitsubishi Advisory

Mitsubishi published an advisory discussing a heap-based buffer overflow vulnerability in a third-party TCP/IP stack (Treck). Mitsubishi is providing generic workarounds to mitigate the vulnerability.

NOTE: Mitsubishi is only reporting one of the four TCP/IP stack vulnerabilities reported by Treck.

Moxa Advisory

Moxa published an advisory describing ten vulnerabilities in their EDR-810 Series Security Routers. The vulnerabilities were reported by the Russian BDU FSTEC. Moxa has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The ten reported vulnerabilities are:

• Improper Input Validation - CVE-2014-2284 (Linux ICMP-MIB implementation),

• Resource Management Errors - CVE-2015-1788 (Open SSL),

Improper Restriction of Operations within the Bounds of a Memory Buffer - CVE-2016-10012 (Open SSH),

Exposure of Sensitive Information to an Unauthorized Actor - CVE-2015-3195 (Open SSL),

Improper Input Validation - CVE-2016-6515 (open SSH, Exploit),

Improper Input Validation - CVE-2017-17562 (EmbedThis, Exploit),

Cryptographic Issues - CVE-2013-0169 (TLS Protocol),

• Permissions, Privileges, and Access Controls - CVE-2013-1813 (BusyBox, Exploit), and

• Numeric Errors - CVE-2010-2156 (ISC DHP, Exploit)

Rockwell Advisory

Rockwell published an advisory discussing eight vulnerabilities in their Stratix Switches. These are third-party (Cisco) vulnerabilities. Rockwell has new versions that mitigate the vulnerability.

The eight reported vulnerabilities are:

• Privilege escalation (2) - CVE-2021-1392 and CVE-2021-1442,

• Cross-site web socket hijacking - CVE-2021-1403,

• Denial of service (3) - CVE-2021-1352, CVE-2021-1220, and CVE-2021- 1356, and

• Command injection (2) - CVE-2021-1452 and CVE-2021-1443,

NOTE: Links above are to the Cisco advisories.l

Ovarro Report

Claroty published a report describing the five vulnerabilities that were reported earlier this week in the Ovarro TBox RTUs.

VMWare Exploit

WVU published a Metasploit module for a remote code execution vulnerability in the VMware View Planner. This vulnerability was previously reported by VMware.

Advantech Exploit

Spencer McIntyre published a Metasploit module for a missing authentication for critical function vulnerability in the Advantech iView. This vulnerability was previously reported by Advantech.

Tuesday, March 23, 2021

4 Advisories and 2 Updates Published – 3-23-21

Today the CISA NCCIC-ICS published four control system security advisories for products from Ovarro, GE Grid Solutions (2), and Weintek. They also published two updates for products from Rockwell Automation.

Ovarro Advisory

This advisory describes five vulnerabilities in the Ovarro TBox remote terminal units. The vulnerabilities were reported by Uri Katz of Claroty. Ovarro has new versions that mitigate the vulenrabilities. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Code injection - CVE-2021-22646,

• Incorrect permission assignment for critical resource - CVE-2021-22648,

• Uncontrolled resource consumption - CVE-2021-22642,

• Insufficiently protected credentials - CVE-2021-22640, and

• Use of hard-coded cryptographic key - CVE-2021-22644

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to result in remote code execution, which may cause a denial-of-service condition.

NOTE: This advisory was originally published on February 23rd, 2021 on the restricted HSIN ICS library. This limited disclosure allows critical infrastructure additional time to implement mitigation measures before the vulnerability becomes public. NCCIC-ICS does not use this limited distribution very often, the last time was on July 21st, 2020 and the time before that was on November 6th, 2018.

Reason DR60 Advisory

This advisory describes three vulnerabilities in the GE Reason DR60 digital fault recorder products. The vulnerabilities were reported by Thales OT Security Team. GE has a firmware update that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Use of hard-coded password - CVE-2021-27440,

• Code injection - CVE-2021-27438, and

• Execution with unnecessary privileges - CVE-2021-27454

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to  allow an attacker to take full control of the digital fault recorder (DFR), remotely execute code, or escalate privileges.

MU320E Advisory

This advisory describes three vulnerabilities in the GE MU320E product. The vulnerabilities were reported by Tom Westenberg of Thales UK. GE has a new firmware version that mitigates the vulnerabilities. There is no indication that Westenberg has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Use of hard-coded password - CVE-2021-27452,

• Execution with unnecessary privileges - CVE-2021-27448, and

• Inadequate encryption strength - CVE-2021-27450

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to escalate unnecessary privileges and use hard-coded credentials to take control of the device.

NOTE: Neither of these advisories appear to address any of the 17 advisories published by GE on March 17th, 2021 that I briefly mentioned Saturday.

Weintek Advisory

This advisory describes three vulnerabilities in the Weintek cMT product. The vulnerabilities were reported by Marcin Dudek from CERT.PL. Weintek has upgrades that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Code injection - CVE-2021-27446,

• Improper access control - CVE-2021-27444, and

• Cross-site scripting - CVE-2021-27442

NCCIC-ICS reports

MicroLogix 1400 Update

This update provides additional information for an advisory that was originally published on February 2nd, 2021. The new information includes:

• Adding the names of the researchers from the Veermata Jijabai Technological Institute that reported the vulnerability, and

• Adding a link to the Rockwell advisory.

CompactLogix 5370 Update

This update provides additional information for an advisory that was originally published on March 2nd, 2021. The new information includes adding a link to the Rockwell Advisory.

Wednesday, March 17, 2021

3 Advisories and 1 Update Published – 3-16-21

Yesterday the CISA NCCIC-ICS published three controls system security advisories and updated one medical device security advisory.

Hitachi ABB Power Grids Advisory

This advisory describes an infinite loop vulnerability in the Hitachi ABB Power Grids AFS Series. This is a third-party (Belden) vulnerability that I briefly described in February. The vulnerability is self-reported. Hitachi ABB Power Grids has updates available that mitigate the vulnerability.

The NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to cause a denial-of-service condition on one of the ports in a HSR ring.

GE Grid Advisory

This advisory describes ten vulnerabilities in the GE Grid UR family of advanced protection and control relays. The vulnerabilities were reported by SCADA-X, DOE CyTRICS program, Verve Industrial, and VuMetric. GE Grid has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The ten reported vulnerabilities are:

• Inadequate encryption strength (2) - CVE-2016-2183 (TLS/SSL/IPsec vulnerability) and CVE-2013-2566 (TLS/SSL vulnerability),

• Session fixation - CVE-1999-1085 (SSH vulnerability),

• Exposure of sensitive information to an unauthorized actor (2) - CVE-2021-27422 and CVE-2021-27424,

• Improper input validation - CVE-2021-27418 and CVE-2021-27420,

• Unrestricted upload of file with dangerous type - CVE-2021-27428,

• Insecure default variable initialization - CVE-2021-27426, and

• Use of hard-coded credentials - CVE-2021-27430

NOTE 1: There are a large number of third-party vendor advisories for the first two CVEs over the years, but no published exploits.

NOTE 2: Those first three OLD vulnerabilities certainly help make a case for the use of a software bill of materials.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to access sensitive information, reboot the UR, gain privileged access, or cause a denial-of-service condition.

Advantech Advisory

This advisory describes a cross-site scripting vulnerability in the Advantech WebAccess/SCADA. The vulnerability was reported by Chizuru Toyama of TXOne IoT/ICS Security Research Labs. Advantech has a new version that mitigates the vulnerability. There is no indication that Toyama has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an unauthorized user to steal a user’s cookie/session token or redirect an authorized user to a malicious webpage.

BD Update

This update provides additional information on an advisory that was was originally published on February 7th, 2017 and most recently updated on October 19th, 2017. The new information includes:

• Rewriting Risk Evaluation section,

• Adding Alaris 8015 PC unit, Versions 9.33, to the list of affected products,

• Rewriting description of CVE-2016-8375 vulnerability,

• Rewriting description of CVE-2016-9355 vulnerability, and

• Rewriting compensating controls descriptions

Tuesday, January 5, 2021

6 Advisories Published – 1-5-21

Today the CISA NCCIC-ICS published six control system security advisories for products from Delta Electronics (2), Red Lion, GE, Panasonic and Schneider.

CNCSoft Advisory

This advisory describes a stack-based buffer overflow vulnerability in the Delta CNCSoft ScreenEditor. The vulnerability was reported by Kimiya via the Zero Day Initiative. Delta has an update that mitigates the vulnerability. There is no indication that Kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow arbitrary code execution.

DOPSoft Advisory

This advisory describes two vulnerabilities in the Delta DOPSoft software. The vulnerability was reported by Kimiya via the Zero Day Initiative. Delta has an update that mitigates the vulnerability. There is no indication that Kimiya has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Out-of-bounds write - CVE-2020-27275, and

• Untrusted pointer dereference - CVE-2020-27277

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow arbitrary code execution.

Red Lion Advisory

This advisory describes three vulnerabilities in the Red Lion Crimson 3.1 programming software. The vulnerabilities were reported by Marco Balduzzi, Ryan Flores, Philippe Lin, Charles Perine, Ryan Flores, Rainer Vosseler via ZDI. Red Lion has a new version that mitigates the vulnerabilities. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Null pointer dereference - CVE-2020-27279,

• Missing authentication for critical function - CVE-2020-27285, and

• Improper resource shutdown - CVE-2020-27283

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to create a denial-of-service condition, read and modify the database, and leak memory data.

GE Advisory

This advisory describes two vulnerabilities in the GE Reason RT43X Clocks. The vulnerabilities were reported by Tom Westenberg of Thales UK. GE has a new firmware version that mitigates the vulnerabilities. There is no indication that Westenberg has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Code injection - CVE-2020-25197, and

• Use of hard-coded cryptographic key - CVE-2020-25193

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an authenticated remote attacker to execute arbitrary code on the system or intercept and decrypt encrypted traffic.

NOTE: I (very) briefly mentioned the GE advisory for these vulnerabilities back in November.

Panasonic Advisory

This advisory describes an out-of-bounds read vulnerability in the Panasonic FPWIN Pro programming software. The vulnerability was reported by Francis Provencher via ZDI. Panasonic has a new version that mitigates the vulnerability. The is no indication that Provencher has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to  allow remote code execution.

Schneider Advisory

This advisory describes three vulnerabilities in the Schneider Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy products. The vulnerabilities were reported (here and here) by Kai Wang of Fortinet's FortiGuard Labs. Schneider continues to work on mitigation measures for supported versions of the affected products.

The three reported vulnerabilities were:

• Out-of-bounds read - CVE-2020-7562,

• Out-of-bounds write - CVE-2020-7563, and

• Classic buffer overflow - CVE-2020-7564

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow write access and the execution of commands, which could result in data corruption or a web server crash.

NOTE: I briefly described these vulnerabilities back in November.

NCCIC-ICS Updates

NCCIC-ICS also published five updates today. I will cover them in a separate blog post.

 
/* Use this with templates/template-twocol.html */