Showing posts with label GE Healthcare. Show all posts
Showing posts with label GE Healthcare. Show all posts

Saturday, May 18, 2024

Review – Public ICS Disclosures – Week of 5-11-24 – Part 1

This week we have 28 vendor disclosures from ABB, Aruba, Belden, Bosch, B&R, Dell, Dassault Systèmes, Field Logic, FortiGuard (5), GE Healthcare (2), Hitachi, HP (8), HPE (2), Insyde, and Palo Alto Networks.

Advisories

ABB Advisory - ABB published an advisory that describes two vulnerabilities in their IRC5 / OmniCore RobotWare products.

Aruba Advisory - Aruba published an advisory that describes 18 vulnerabilities in their Access Points product.

Belden Advisory - Belden published an advisory that discusses three vulnerabilities (two with known exploits) in their BAT-C2 and OWL products.

Bosch Advisory - Bosch published an advisory that describes two vulnerabilities in their Praesensa Logging Application, Praesideo Logging Application, and Praesideo PC Call Station.

B&R Advisory - B&R published an advisory that describes an uncontrolled search path element vulnerability in multiple B&R products.

Dell Advisory - Dell published an advisory that discusses an improper access control vulnerability in their Precision Rack products.

Dassault Advisory - Dassault published an advisory that describes a cross-site scripting vulnerability in their 3DDashboard in 3DSwymer product.

Field Logic Advisory - JPCERT published an advisory that describes four vulnerabilities with known exploits in the Field Logic DataCube3 and DataCube4 products.

FortiGuard Advisory #1 - FortiGuard published an advisory that describes a stack-based buffer overflow vulnerability in their FortiOS product.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes a double free vulnerability in their FortiOS product.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes two Use of an externally controlled format string vulnerabilities in their FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager products.

FortiGuard Advisory #4 - FortiGuard published an advisory that describes an improper check of unusual or exceptional conditions vulnerability in their FortiOS product.

FortiGuard Advisory #5 - FortiGuard published an advisory that describes an insufficient verification of data authenticity in their FortiOS and FortiProxy SSL-VPN products.

GE Healthcare Advisory #1 - GE Healthcare published an advisory that describes five vulnerabilities in their EchoPAC Software Only (SWO), EchoPAC TurnKey and ImageVault products.

GE Healthcare Advisory #2 - GE Healthcare published an advisory that describes three vulnerabilities in their Common Service Desktop (CSD) component used in ultrasound devices.

Hitachi Advisory - Hitachi published an advisory that discusses four vulnerabilities in their Developer's Kit for Java products.

HP Advisory #1 - HP published an advisory that discusses an uncontrolled search path element vulnerability in their business desktop and laptop computers.

HP Advisory #2 - HP published an advisory that discusses three vulnerabilities in multiple HP products. These are third-party (Intel) vulnerabilities.

HP Advisory #3 - HP published an advisory that discusses nine vulnerabilities in their desktop computers.

HP Advisory #4 - HP published an advisory that discusses an insecure inherited permissions vulnerability in their Omen notebook PCs.

HP Advisory #5 - HP published an advisory that discusses an improper access control vulnerability in multiple HP product lines.

HP Advisory #6 - HP published an advisory that describes an escalation of privilege vulnerability in multiple HP product lines.

HP Advisory #7 - HP published an advisory that discusses six vulnerabilities in multiple HP product lines. These are third-party (Intel) vulnerabilities.

HP Advisory #8 - HP published an advisory that discusses an improper neutralization of invalid characters in identifiers in web pages vulnerability in multiple HP products lines.

HPE Advisory #1 - HPE published an advisory that discusses OS command inject vulnerability in their SAN Switches.

HPE Advisory #2 - HPE published 39 new (or updated) Security Vulnerability Alerts (background here).

Insyde Advisory - Insyde published an advisory that describes three memory corruption vulnerabilities in their SMM product.

Palo Alto Networks Advisory - Palo Alto Networks published an advisory that discusses the TunnelVision vulnerabilities.

 

For more details about these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-9bb - subscription required.

Thursday, May 16, 2024

Review – 14 Advisories and 3 Updates Published – 5-16-24

Today, CISA’s NCCIC-ICS published 14 control system security advisories for products from Rockwell Automation and Siemens (13). They also updated three advisories for products from GE Healthcare and Mitsubishi (2).

Siemens published two other advisories and 23 updates on Tuesday that were not addressed here. I will cover them this weekend.

Advisories

Rockwell Advisory - This advisory describes an improper input validation vulnerability in the Rockwell FactoryTalk View SE monitoring software.

Industrial Product Advisory - This advisory describes an out-of-bounds read vulnerability in the Siemens Industrial Products.

Desigo Advisory - This advisory describes three vulnerabilities in the Siemens Cerberus PRO UL and Desigo Fire Safety UL products.

RUGGEDCOM Advisory #1 - This advisory discusses two vulnerabilities in the Siemens RUGGEDCOM APE1808 products.

RUGGEDCOM Advisory #2 - This advisory describes nine vulnerabilities in the Siemens RUGGEDCOM CROSSBOW product.

Solid Edge Advisory - This advisory describes eight vulnerabilities in the Siemens Solid Edge products.

PS/IGES Advisory - This advisory describes 11 vulnerabilities in the Siemens PS/IGES Parasolid Translator Component.

SIMATIC Advisory #1 - This advisory discusses 21 vulnerabilities (three with known exploits) in the Siemens SIMATIC RTLS Locating Manager.

SIMATIC Advisory #2 - This advisory describes three vulnerabilities in the Siemens SIMATIC CN 4100.

SIMCENTER Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Siemens Simcenter Nastran finite element analysis program.

Polarian Advisory - This advisory describes an improper access control vulnerability in the Siemens Polarion ALM application lifecycle management software.

Teamcenter Advisory - This advisory describes two vulnerabilities in the Siemens JT2Go and Teamcenter Visualization products.

SICAM Advisory - This advisory describes three vulnerabilities in multiple Siemens SICAM products.

Parasolid Advisory - This advisory describes three vulnerabilities in the Siemens Parasolid design and simulation product.

Updates

GE Healthcare Update - This update provides additional information on the Ultrasound Products advisory that was originally published on February 18th, 2020.

Mitsubishi Update #1 - This update provides additional information on the MELSEC-Q/L Series advisory that was originally published on March 14th, 2024.

Mitsubishi Update #2 - This update provides additional information on the MELSEC iQ-R Series Safety CPU that was originally published on February 13th, 2024.

 

For more information on these advisories, including links to 3rd party advisories, vendor advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/14-advisories-and-3-updates-published - subscription required.

Saturday, October 15, 2022

Review – Public ICS Disclosures – Week of 10-8-22 – Part 1

This is a moderately busy Saturday after 2nd Tuesday. For Part 1 this week, we have fifteen vendor disclosures from Aruba, Bentley (3), Eaton, GE Healthcare, Hitachi Energy, HP, Palo Alto Networks, Phoenix Contact, PulseSecure, Softing (2), TandD, and VMware.

Aruba Advisory - Aruba published an advisory describing three vulnerabilities in their EdgeConnect Enterprise Orchestrator.

Bentley Advisory #1 - Bentley published an advisory that describes an out-of-bounds read vulnerability in their MicroStation And MicroStation-Based Applications.

Bentley Advisory #2 - Bentley published an advisory that describes a stack-based buffer overflow vulnerability in their MicroStation And MicroStation-Based Applications.

Bentley Advisory #3 - Bentley published an advisory that describes an out-of-bounds read vulnerability in their MicroStation and MicroStation-Based Applications.

Eaton Advisory - Eaton published an advisory that describes an unrestricted file upload vulnerability in their Foreseer EPMS.

GE Healthcare Advisory - GE published an advisory that provides guidance on securing serial ports in medical devices.

Hitachi Energy Advisory - Hitachi published an advisory that discusses two vulnerabilities in their MicroSCADA X DMS600

product.

HP Advisory - HP published an advisory that discusses eleven vulnerabilities in their GPU Display Driver.

Palo Alto Networks Advisory - Palo Alto Networks published an advisory that describes an authentication bypass vulnerability in their Pan-OS product.

Phoenix Contact Advisory - CERT-VDE published an advisory that discusses 83 vulnerabilities in the Phoenix Contact PLCnext Control.

PulseSecure Advisory - PulseSecure published an advisory that describes two denial of service vulnerabilities in their Ivanti Connect Secure products.

Softing Advisory #1 - Softing published an advisory that describes a use after free vulnerability in their OPC UA C++ SDK and OPC Suite products.

Softing Advisory #2 - Softing published an advisory that describes an input validation vulnerability in their OPC UA C++ SDK, Secure Integration Server, edgeConnector, edgeAggregator, uaGate and OPC Suite products.

TandD Advisory - TandD published an advisory that describes a denial-of-service vulnerability in their TR4 Series devices

NOTE: TandD does not call this a ‘vulnerability’ they call it a problem “whereby internal communication between components fails” which kind of sounds like a ‘denial-of-service’ vulnerability to me.

VMware Advisory - VMware published an advisory that describes an arbitrary file read vulnerability in their VMware vRealize Operations product.

 

For more information on these disclosures, including links to third-party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-c00 - subscription required.


Saturday, April 16, 2022

Review – Public ICS Disclosures – Week of 4-9-22 – Part 1 –

With this being the 2nd Tuesday weekend, we will need two parts to look at all of the ICS disclosures. For Part 1 we have 23 vendor disclosures from ABB (3), Bentley (8), CODESYS, GE Healthcare, HMS, HPE, Palo Alto Networks (3), Phoenix Contact (3), Tanzu, and VMware. We also have five vendor updates from GE Healthcare, Hitachi Energy (2), and Palo Alto Networks (2). Then there are four researcher reports for products from PositiveGrid, and Delta Controls (3). Finally, we have three exploits for products from Franklin Fueling, Siemens, Spring.

Part 2 will look at the Schneider and Siemens disclosures published on Tuesday.

ABB Advisory #1 - ABB published an advisory discussing two vulnerabilities (one with known exploits) in their ARM600 M2M Gateway.

ABB Advisory #2 - ABB published an advisory describing a security bypass vulnerability in their Arctic Wireless Gateway.

ABB Advisory #3 - ABB published an advisory discussing the INCONTROLLER ICS attack tools.

Bentley Advisory #1 - Bentley published an advisory describing two vulnerabilities in their MicroStation and MicroStation-based applications.

Bentley Advisory #2 - Bentley published an advisory describing four vulnerabilities in their MicroStation and MicroStation-based applications.

Bentley Advisory #3 - Bentley published an advisory describing five vulnerabilities in their MicroStation and MicroStation-based applications.

Bentley Advisory #4 - Bentley published an advisory describing two vulnerabilities in their MicroStation and MicroStation-based applications.

Bentley Advisory #5 - Bentley published an advisory describing eleven vulnerabilities in their MicroStation and MicroStation-based applications.

Bentley Advisory #6 - Bentley published an advisory describing an out-of-bounds write vulnerability in their MicroStation and MicroStation-based applications.

Bentley Advisory #7 - Bentley published an advisory describing three vulnerabilities in their MicroStation and MicroStation-based applications.

Bentley Advisory #8 - Bentley published an advisory describing two vulnerabilities in their MicroStation and MicroStation-based applications.

CODESYS Advisory - CODESYS published an advisory discussing the INCONTROLLER ICS attack tools.

GE Healthcare Advisory - GE Healthcare published an advisory discussing the SpringShell vulnerability.

HMS Advisory - HMS published an advisory discussing the INFRA:HALT vulnerabilities.

HPE Advisory - HPE published an advisory describing a denial of service vulnerability in their Integrated Lights-Out 4 (iLO 4) products.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory describing an improper handling of exceptional conditions vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory describing a product disruption vulnerability in their Cortex XDR Agent.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory describing an information exposure through log files vulnerability in their Cortex XDR agent.

Phoenix Contact Advisory #1 - Phoenix Contact published an advisory discussing 56 vulnerabilities in their AXC F x152 LTS.

Phoenix Contact Advisory #2 - Phoenix Contact published an advisory discussing an infinite loop vulnerability in their FL MGUARD, TC MGUARD, mGuard Device Manager and FL WLAN devices.

Phoenix Contact Advisory #3 - Phoenix Contact published an advisory discussing an HTTP request smuggling vulnerability in their mGuard Device Manager.

Tanzu Advisory - Tanzu published an advisory describing a data binding rule vulnerability in their Spring Framework products.

NOTE: This is related to the SpringShell vulnerability.

VMware Advisory - VMware published an advisory describing a remote code execution vulnerability in their Cloud Director product.

GE Healthcare Update - GE Healthcare published an update discussing the DirtyPipe vulnerability.

Hitachi Energy Update #1 - Hitachi Energy published an update for their XMC20 advisory that was originally published on November 23rd, 2021.

Hitachi Energy Update #2 - Hitachi Energy published an update for their FOX61x XMC20 advisory that was originally published on November 23rd, 2021.

Palo Alto Networks Update #1 - Palo Alto Networks published an update for their OpenSSL advisory that was originally published on March 31st, 2022.

Palo Alto Networks Update #2 - Palo Alto Networks published an update for their Spring Shell advisory that was originally published on March 31st, 2022.

PositiveGrid Report - Tenable published a report list six vulnerabilities in the PositiveGrid Spark API.

Delta Controls Report - Zero Science Labs published three reports about vulnerabilities in the Delta Controls enteliTOUCH building controllers.

Franklin Fueling Exploit - Momen Eldawakhly published an exploit for a local file inclusion vulnerability in the Franklin Fueling Systems Colibri Controller Module.

Siemens Exploit - Sec-consult published an exploit for two vulnerabilities in the Siemens A8000 CP-8050/CP-8031 SICAM WEB.

SpringShell Exploit - Mike Pickard published an exploit for the SpringShell vulnerability.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-3c2 - subscription required.

Saturday, February 12, 2022

Review - Public ICS Disclosures – Week of 2-5-22 – Part 1

 With this being the Saturday after Patch Tuesday, we have a lot to cover. In Part 1, we have 15 vendor disclosures from Carestream, Dell, Draeger (2), Eaton, GE Healthcare, HPE (4), Moxa (2), Palo Alto Networks, and QNAP (2).

Carestream Advisory - Carestream published an advisory discusses two vulnerabilities in their Image Suite systems.

Dell Advisory - Dell published an advisory discussing two vulnerabilities in their Dell Wyse Windows Embedded System.

Draeger Advisory #1 - Draeger published an advisory describing a use of an outdated operating system vulnerability in their Infinity Acute Care System workstations.

Draeger Advisory #2 - Draeger published an advisory describing an unsupported third-party (TLS 1.0) application vulnerability in their Gateway VF7.2 and VF9.0 products.

Eaton Advisory - Eaton published an advisory discussing the INFRA:HALT vulnerabilities in their easyControl EC4P PLCs.

GE Advisory - GE Healthcare published an advisory discussing the PwnKit vulnerabilities in their product line.

HPE Advisory #1 - HPE published an advisory discussing an insufficient control flow management vulnerability in their HPE ProLiant, Apollo, and Synergy Servers.

HPE Advisory #2 - HPE published an advisory describing 16 vulnerabilities in their HPE ProLiant, Apollo, Edgeline, and Synergy Servers.

HPE Advisory #3 - HPE published an advisory discussing three vulnerabilities in their HPE ProLiant, Apollo, and Synergy Servers.

HPE Advisory #4 - HPE published an advisory discussing five vulnerabilities in their Samba on NonStop products.

Moxa Advisory #1 - Moxa published an advisory describing two vulnerabilities in their MXview Series Network Management Software.

Moxa Advisory #2 - Moxa published an advisory describing a hard-coded credentials vulnerability in their  EDR-G903 Series, EDR-G902 Series, and EDR-G810 Series Secure Routers.

Palo Alto Advisory - Palo Alto Networks published an advisory describing a URL filtering vulnerability in their PAN-OS software.

QNAP Advisory #1 - QNAP published an advisory discussing three vulnerabilities in Samba.

QNAP Advisory #2 - QNAP published an advisory describing an improper authentication vulnerability in their Kazoo Server.

 

For more information on these advisories, including links to third-party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2 - subscription required.

Saturday, July 10, 2021

Review - Public ICS Disclosures – Week of 7-3-21

This week we have thirteen vendor disclosures from ABB, Bosch, B&R Industrial Automation (3), Flexera, GE Healthcare, Hitachi, HMS Networks, Philips, QNAP, Rockwell Automation, and SonicWall. We have four researcher reports of vulnerabilities in products from Advantech (2), Ricon, and VMWare.

ABB Advisory - ABB published an advisory describing a serial number misuse vulnerability in their Busch®-ControlTouch product.

Bosch Advisory - Bosch published an advisory discussing three vulnerabilities in their Rexroth products.

B&R Advisory #1 - B&R published an advisory describing an out-of-bounds write vulnerability in their X20 EthernetIP Adapter.

B&R Advisory #2 - B&R published an advisory describing an out-of-bounds write vulnerability in their  PROFINET IO Devices.

B&R Advisory #3 - B&R published an advisory describing a denial of service vulnerability in their Automation Runtime product.

Dell Advisory - Dell published an advisory describing two vulnerabilities in their Dell Wyse Management Suite.

Flexera Advisory - Flexera published an advisory describing an exposure of sensitive information to an unauthorized actor vulnerability in their FlexNet Publisher.

GE Healthcare Advisory - GE Healthcare published an advisory discussing the PrintNightmare vulnerabilities.

Hitachi Advisory - Hitachi published an advisory discussing 23 vulnerabilities in their Hitachi Disk Array Systems.

HMS Advisory - HMS published an advisory describing an insecure file system permission vulnerability in their eCatcher product.

Philips Advisory - Philips published an advisory discussing the Kaseya VSA supply chain attack.

QNAP Advisory - QNAP published an advisory describing an improper access control vulnerability in their Legacy HBS 3 (Hybrid Backup Sync) product.

Rockwell Advisory - Rockwell published their advisory for the vulnerability reported this week by NCCIC-ICS.

SonicWall Advisory - SonicWall published an advisory describing an out-of-bounds read vulnerability in their SonicWall Switch product.

Advantech Report - ZDI published two reports (here and here) of stack-based buffer overflow vulnerabilities in the Advantech web access product.

Ricon Report - Zero Science Lab published a report describing an OS command injection vulnerability in the Ricon S9922L series LTE router.

VMWare Report - NCC Group published a report on exploiting CVE-2021-3156 VMWare vCenter Server 7.0 product.

For a more detailed discussion of the advisories see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-ac2 - subscription required.

Saturday, July 3, 2021

Review Public ICS Disclosures – Week of 6-26-21

This week we have twelve vendor disclosures from Aruba, Carestream, Hitachi, WAGO, HMS, Philips, QNAP (5), and Tanzu. We have vendor updates from CODESYS and GE Healthcare. We have five researcher reports for products from Bosch. Finally, I would like to report that the bad links to Johnson Controls advisories that I noted (here and here) have been corrected.

Aruba Advisory - Aruba published an advisory describing thirteen vulnerabilities in their ClearPass Policy Manager.

Carestream Advisory - Carestream published an advisory [.PDF download link] discussing a third-party (Microsoft) HTTP Protocol Stack Remote Code Execution Vulnerability.

Hitachi Advisory - Hitachi published an advisory describing an OS command injection vulnerability in their Virtual File Platform.

WAGO Advisory - CERT-VDE published an advisory describing four vulnerabilities in the WAGO I/O-Check Service.

HMS Advisory - HMS published an advisory discussing the FragAttacks WiFi vulnerabilities.

Philips Advisory - Philips published an advisory discussing the PrintNightmare vulnerabilities.

QNAP Advisory #1 - QNAP published an advisory discussing the DNSpooq vulnerabilities.

QNAP Advisory #2 - QNAP published an advisory describing an XSS vulnerability in QTS and QuTS hero products.

QNAP Advisory #3 - QNAP published an advisory describing a Stored XSS vulnerability in Q'center product.

QNAP Advisory #4 - QNAP published an advisory describing a Stored XSS vulnerability in QuLog Center product.

QNAP Advisory #5 - QNAP published an advisory describing two command injection vulnerabilities in their QTS and QuTS hero products.

CODESYS Update - CODESYS published an update [.PDF download link] for their V2 web server advisory that was originally published on May 11th, 2021.

GE Healthcare Update - GE Healthcare published an update for the PACS vulnerability advisory that was originally published on December 18th, 2020.

Bosch Reports - Kaspersky published five reports for vulnerabilities in the Bosch CPP HD/MP cameras.

For more detailed information, see my article on CFSN Detailed analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-a1b  - subscription required.

Saturday, March 6, 2021

ICS Public Disclosures – Week of 2-27-21

This week we have eight public disclosures from Bosch, Carestream, ENDRESS+HAUSER, Dell, Draeger, GE Healthcare, Pulse Secure, and VMWare. An update is available for products from Rockwell. There is an end-of-life notice from Honeywell. Finally, there is an exploit for products from VMware.

Bosch Advisory

Bosch published an advisory describing a side-channel key extraction vulnerability in the Bosch cameras and encoders built on platforms CPP-ENC, CPP3, CPP4, CPP5, CPP6, CPP7 and CPP7.3.  This is a third-party vulnerability (NXP). Since this is a chip-based vulnerability, Bosch is only able to provide generic workarounds. The original NinjaLab report on the NXP vulnerability contains proof-of-concept code.

NOTE: This third-party vulnerability was reported earlier in products from Rockwell, other vendors will probably also be affected.

Carestream Advisory

Carestream published an advisory discussing the Google heap-based buffer overflow vulnerability. Carestream provides a list of affected and unaffected products. Carestream will update Chrome in the next product release for the affected products.

ENDRESS+HAUSER Advisory

CERT-VDE published an advisory discussing the fdtCONTAINER vulnerability in a number of their products. ENDRESS+HAUSER provides generic workarounds pending development of appropriate mitigation measures in future versions of the product.

Dell Advisory

Dell published an advisory describing two vulnerabilities in their EMC OpenManage Server Administrator. The vulnerabilities were reported by David Yesland from Rhino Security Labs and Tenable. Dell has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Authentication bypass - CVE-2021-21513, and

• Path traversal - CVE-2021-21514

NOTE: The Tenable report contains proof-of-concept code for the

Draeger Advisory

Draeger published an advisory describing an out-of-bounds write vulnerability in their CC-Vision Basic and CC-Vision E-Cal Software. The vulnerability was reported by Mario Ceballos. Draeger had new versions that mitigate the vulnerability. There is no indication that Ceballos has been provided an opportunity to verify the efficacy of the fix.

GE Healthcare Advisory

GE Healthcare has published an advisory discussing the Microsoft Windows TCP/IP vulnerabilities. GE Healthcare reports that they are actively assessing products to see if they are affected.

Pulse Secure Advisory

Pulse Secure has published an advisory discussing the Trickboot vulnerability in their PSA-Series Hardware. Pulse Secure has a BIOS patch available that mitigates the vulnerability.

VMWare Advisory

VMWare published an advisory describing a remote code execution vulnerability in their View Planner product. The vulnerability was reported by Mikhail Klyuchnikov of Positive Technologies. VMware has a security patch that mitigates the vulnerability. There is no indication that Klyuchnikov has been provided an opportunity to verify the efficacy of the fix.

Rockwell Update

Rockwell published an update for their Logix Controllers advisory that was originally published on February 25th, 2021. The advisory was re-written for clarity.

NOTE: I suspect the NCCIC-ICS will update their advisory on this vulnerability this coming week.

Honeywell EOL Notice

Honeywell published an end-of-life notice for their Pro-Watch 4.3 and Pro-Watch 4.35 products. The products will no longer be supported after September 30th, 2021.

VMWare Exploit

Photubias published an exploit for an unauthenticated file upload vulnerability in the VMware vCenter Server 7.0. The vulnerability was previously reported by VMWare.

Saturday, January 30, 2021

Public ICS Disclosures – Week of 1-23-21

This week we have nine vendor disclosures from Bosch, ZIV Automation (2), Emerson, GE Healthcare, Johnson Controls, Rockwell (2), and Siemens.

Bosch Advisory

Bosch published an advisory describing a stack-based buffer overflow vulnerability in their Rexroth ID 200/C-ETH using EtherNet/IP Protocol. This is a third-party (Real Time Automation) vulnerability. Bosch provides generic mitigation measures.

ZIV Automation Advisories

Incibe-CERT published an advisory describing an uncontrolled resource consumption vulnerability in the ZIV 4CCT Smart Metering Data Concentrator. The vulnerability was reported by Aarón Flecha Menéndez of S21Sec. ZIV has a patch available that mitigates the vulnerability. There is no indication that Menendez has been provided an opportunity to verify the efficacy of the fix.

 

Incibe-CERT published an advisory describing an improper authentication vulnerability in the ZIV 4CCT Smart Metering Data Concentrator. The vulnerability was reported by Aarón Flecha Menéndez of S21Sec. ZIV has a patch available that mitigates the vulnerability. There is no indication that Menendez has been provided an opportunity to verify the efficacy of the fix.

Emerson Advisory

Emerson published an advisory describing the fdtCONTAINER vulnerability in their Rosemont Transmitter Interface Software. Emerson no longer supports that software.

NOTE: This Emerson impact was previously reported by NCCIC-ICS.

GE Healthcare Advisory

GE Healthcare has published an advisory discussing undisclosed vulnerabilities in the VC150 Vital Signs Monitor that they distribute. The Innokas Medical web site simply notes in their software update note for the VC150 that it contains “Cybersecurity enhancements and bug fixes”. GE Healthcare has made the updated software available.

Johnson Controls

Johnson Controls has published an advisory discussing four vulnerabilities in their Sur-Gard System 5 receivers. They are third-party (Treck) vulnerabilities. Johnson Controls has a new version that mitigates the vulnerabilities.

NOTE: This advisory does not specifically name the four vulnerabilities identified by Treck and NCCIC-ICS, it just provides the CVE numbers; CVE-2020-25066,  CVE-2020-27336, CVE-2020-27337, and  CVE-2020-27338.

Rockwell Advisories

Rockwell published an advisory describing the fdtCONTAINER vulnerability in their FactoryTalk AssetCentre. Rockwell has a new version that mitigates the vulnerability.

 

Rockwell published an advisory describing a buffer overflow vulnerability in their MicroLogix 1400 Controller. The vulnerability was reported by Parul Sindhwad and Dr. Faruk Kazi from COE-CNDS. Rockwell provides generic mitigation measures

Siemens Advisory

Siemens published an advisory describing a missing authentication for critical function vulnerability in their SIMATIC HMI Panels. The vulnerability was reported by the Zero Day Initiative. Siemens has new versions that mitigate the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

NOTE: The advisory acknowledges the coordination efforts of CISA, so it is likely that NCCIC-ICS will publish an advisory on this vulnerability next week.

Saturday, July 18, 2020

Public ICS Disclosures – Week of 7-11-20


This week we have four Ripple20 vendor disclosures from Siemens, ABB, Rockwell, Carestream and Schneider Electric; two SigRed vendor disclosures from Philips and GE Healthcare; and three other vendor disclosures from HMS and Schneider (2). Four vendor updates from Schneider (2) and Siemens (2) and  two researcher disclosures for products from Siemens and Advantech round out the weeks’ offerings.

Ripple20 Disclosures and Updates


Siemens published a Ripple20 advisory for their SPPA-T3000 Solutions distributed control system. Siemens provides generic mitigation measures for these vulnerabilities.

NOTE: Siemens published a note at the top of their Security Publications page noting that:

“No Siemens product is known to use Treck Inc.'s TCP/IP stack, or otherwise be affected by the reported vulnerabilities.
“Note that Siemens products and systems might interact with products from other manufacturers which are affected by the reported vulnerabilities. In such cases Siemens recommends that owners of operational infrastructures verify if these products are affected and evaluate the potential impact of the Ripple20 vulnerabilities.”

Since the SPPA-T3000 advisory also contains two Intel Server Platform Services vulnerabilities, I suspect that the Ripple20 vulnerabilities come with the Intel server upon which the T-3000 is built.

ABB published a Ripple20 advisory. The advisory contains a list of affected products and generic mitigation measures pending further work to address the vulnerabilities.

Rockwell updated their Ripple20 advisory. The new information includes an updated table of affected products.

Carestream updated their Ripple20 advisory (.PDF download link). The new information includes adding 20 products that were on the ‘still evaluating list’ to the not affected list. The list of affected products has not changed.

Schneider updated their Ripple20 advisory. The new information includes removing the “Smartlink ELEC” from the list of affected products.

SigRed Disclosures


SigRed is the ‘cute’ name given to the Microsoft ‘wormable’ remote code execution DNS vulnerability (CVE-2020-1350).

Phillips published a SigRed advisory noting that: “Philips is currently in the process of evaluating the Microsoft patch and vendor recommended mitigation options.”


GE Healthcare published a SigRed advisory noting that: “GE Healthcare is actively assessing products that utilize impacted Microsoft Operating Systems.”

Neither of these advisories provide much in the way of information beyond noting that a vague ‘some’ of their products may be affected.

Vendor Disclosures


HMS published an advisory describing a remote code execution vulnerability in their eCatcher product. The vulnerability was reported by Claroty. HMS has an update that mitigates the vulnerability. There is no indication that Claroty was provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory describing an open redirect vulnerability in their Schneider Electric Software Update (SESU). The vulnerability was reported by Amir Preminger of Claroty. Schneider has a new version that mitigates the vulnerability. There is no indication that Preminger has been provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory describing two denial of service vulnerabilities in their Floating License
Manager. These are third-party vulnerabilities in the Flexera FlexNet Publisher (reported here and here). Schneider has a new version that mitigates these vulnerabilities.

NOTE: Flexera is also reporting three other vulnerabilities (CVE-2019-8963, CVE-2020-12080, and CVE-2020-12081) that could potentially affect the Schneider Floating License Manager and a variety of other vendor ‘license manager’ products based upon the Flexera product.

Vendor Updates


Schneider updated their ZombieLoad advisory. The new information includes updated mitigation measures for the HMI products.

Schneider updated their BlueKeep advisory. The new information includes updated mitigation measures for the HMI products.

Siemens updated their Vulnerabilities in Intel CPUs advisory. The new information includes:

• Updated mitigation and affected version information for SIMATIC ITP1000, and
• Removed SIMATIC IPC827E from list of affected devices

Siemens updated heir GNU/Linux advisory. The new information includes adding:

CVE-2020-12114,
• CVE-2020-12659,
• CVE-2020-13630,
• CVE-2020-13631, and
• CVE-2020-13632

Researcher Disclosures


Talos published a report on the Siemens LOGO web server vulnerability that was reported earlier this week. The Talos report includes proof-of-concept code for the vulnerability.

The Zero Day Initiative published 43 reports, all based upon research by rgod, about the Advantech iView vulnerabilities that were reported earlier this week. Most of the reports provided more details on the three CVE’s listed in the NCCIC-ICS advisory. One of the reports, however, described an input validation vulnerability that was not reported by NCCIC-ICS.

Saturday, June 20, 2020

Public ICS Disclosures – Week of 6-13-20


This week we have eight vendor disclosures (3 for the Ripple20 vulnerabilities) for products from Beckhoff, Moxa, Medtronic, GE Health, Draeger (2), Rockwell, and BD. There is also a researcher report of a zero-day for products from Inductive Automation.

Ripple20 Advisories


Medtronic published a Ripple20 advisory reporting no impact.

GE Healthcare published a Ripple20 advisory reporting no impact but advising that there may be possible impact to third party components used in combination with GE Healthcare products.

Draeger published a Ripple 20 advisory reporting no impact.

NOTE: “No impact” reports are valuable information. I think the GE nuanced ‘no impact’ report is important where the vendor software may be running on a machine that includes other non-vendor produced software (perhaps including OS?).

Beckhoff Advisory


CERT-VDE published an advisory describing an information leak vulnerability in the Beckhoff TwinCAT RT network driver. The vulnerability is self-reported. Beckhoff has patches that mitigate the vulnerability.

Moxa Advisory


Moxa published an advisory describing a stack-based buffer overflow vulnerability in their EDR-G902 Series and EDR-G903 Series Secure Routers. The vulnerability was reported by Tal Keren from Claroty. Moxa has new firmware to mitigate the vulnerability. There is no indication that Keren has been provided an opportunity to verify the efficacy of the fix.

Draeger Advisory


Draeger published an advisory describing an improper input validation vulnerability in their Perseus A500 product. The vulnerability is self-reported. Draeger has new software that mitigates the vulnerability.

Rockwell Vulnerability


Rockwell published an advisory describing a path traversal advisory in their FactoryTalk Linx software. This vulnerability was discovered in the ZDI Pwn2Own competition in this year’s S4 Security conference. Rockwell has a patch that mitigates the vulnerability.

NOTE: Rockwell reports that they had previously disclosed this vulnerability in an advisory that was published on June 11th, 2020. I suppose that the Pwn2Own announcement could have been included as an update to that advisory. This may be why NCCIC-ICS has not picked up this advisory.

BD Advisory


BD published an advisory describing a remote code execution vulnerability in a number of BD products that use the Microsoft Windows 10®. This is a third-party (MS) SMBv3 server vulnerability. BD is currently working to test and validate the Microsoft patch on the affected products.

Inductive Automation Advisory


The Zero Day Initiative published an advisory describing a deserialization of untrusted data information disclosure vulnerability in the Inductive Automation Ignition product. The vulnerability was reported by Chris Anastasio (muffin) and Steven Seeley (mr_me) of Incite Team. This vulnerability was discovered in the ZDI Pwn2Own competition in this year’s S4 Security conference and reported to the vendor. The vendor has not been able to provide an estimated fix date to either ZDI or NCCIC-ICS. This is effectively a zero-day vulnerability.

Saturday, July 20, 2019

Public ICS Disclosures – Week of 07-13-19


This week we have one vendor disclosure from ABB, two updates of previously published advisories from GE Healthcare and BD and two researcher exploits for products from FANUC Robotics.

ABB Advisory


ABB has published an advisory describing an authentication bypass vulnerability in the ABB CCLAS and
Ellipse applications. The vulnerability is self-reported. ABB has new versions that mitigate the vulnerability.

GE Healthcare Update


GE Healthcare has updated an advisory that was originally published on July 9th, 2019. The new information expands the list of affected products.

BD Update


BD has updated an advisory that was originally published on November 1st, 2016 (this has not been reported by NCCIC-ICS). BD notes:

“As a result, BD has issued this updated security bulletin to remind customers, hospital biomedical engineering, and rental companies that Service Bulletin 597 must be followed to remove residual data on the PCU prior to re-deployment or during decommissioning. BD has carefully reviewed the misdirected data, and determined that it is de-identified based on a statistical expert opinion, and therefore, not protected health information. In addition, BD conducted a risk assessment using the HIPAA 4-factor test and concluded there was a low probability of compromise of such data.”

FANUC Robotics Exploits


Sebastian Hamann has published exploits for two vulnerabilities in the FANUC Robotics Virtual Robot Controller. Hamann has not received any response from FANUC concerning these vulnerabilities.

The reported two vulnerabilities (links provided to Hamann’s exploit reports) are:

Stack-based buffer overflow - CVE-2019-13585; and
Path traversal - CVE-2019-13584

 
/* Use this with templates/template-twocol.html */