Showing posts with label Geutebruck. Show all posts
Showing posts with label Geutebruck. Show all posts

Monday, November 10, 2025

Review – Public ICS Disclosures – Week of 11-1-25 – Part 2

For Part 2 this week we have three additional vendor disclosures from WAGO and Westermo (2). We also have four vendor updates from Dell (2), FortiGuard, and Moxa. There are three researcher reports of vulnerabilities in products from Geutebruck and Ilevia (2). Finally, we have an exploit for products from WatchGuard.

Advisories

WAGO Advisory - CERT-VDE published an advisory that discusses three vulnerabilities in multiple WAGO products.

Westermo Advisory #1 - Westermo published an advisory that describes a path traversal vulnerability in their WeOS5 operating system.

Westermo Advisory #2 - Westermo published an advisory that describes a command injection vulnerability in their WeOS 5 operating system.

Vendor Updates

Dell Update #1 - Dell published an update for their EMC Ruckus Wireless Controller advisory that was originally published on December 17th, 2021.

Dell Update #2 - Dell published an update for their Windows IoT Enterprise LTSC advisory that was originally published on October 31st, 2025.

FortiGuard Update - FortiGuard published an update for their cw_stad daemon advisory that was originally published on July 8th, 2025.

Moxa Update - Moxa published an update for their Diffie-Hellman Key Exchange advisory that was originally published on June 2nd, 2025.

Researcher Reports

Geutebruck Report - Black Lantern Security published a report about an SQL injection vulnerability in the Geutebruck G-Cam Series Cameras.

Ilevia Reports - Zero Science published three reports about vulnerabilities in the Ilevia EVE X1/X5 Server.

Exploits

WatchGuard Exploit - Chanakya Neelarapu and Mark Gibson published an exploit for a use of default credentials vulnerability in the Watch Guard Firebox devices.

For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-42e - subscription required.


Saturday, September 18, 2021

Review - Public ICS Disclosures – Week of 9-11-21 – Part 1

This week we have nine vendor disclosures from BD, HPE, Johnson and Johnson, Milestone, Moxa (2), and Ovarro (3). We have two updates from Mitsubishi. We also have four vendor reports from Tenable about vulnerabilities in GPS systems. Finally, we have an exploit for Geutebruck cameras.

BD Advisory - BD published an advisory discussing the BadAlloc vulnerabilities.

HPE Advisory - HPE published an advisory describing six vulnerabilities in their SAN Switches with Brocade Fabric OS.

Johnson and Johnson Advisory - Johnson and Johnson published an advisory discussing the PrintNightmare vulnerability.

Milestone Advisory - Milestone published an advisory describing an unsecured credential storage vulnerability in their XProtect® VMS product.

Moxa Advisory #1 - Moxa published an advisory describing nine vulnerabilities in their MXview Series Network Management Software.

Moxa Advisory #2 - Moxa published an advisory describing two uncontrolled resource vulnerabilities in their MGate MB3180/MB3280/MB3480 Series Protocol Gateways.

Ovarro Advisory #1 - Ovarro published an advisory describing a classic buffer overflow vulnerability in their MS-CPU32-S2 and LT2 products.

Ovarro Advisory #2 - Ovarro published an advisory describing a path traversal (?) vulnerability in their TWinSoft product.

Ovarro Advisory #3 - Ovarro published an advisory describing a weak encryption vulnerability in their TWinSoft product.

Mitsubishi Update #1 - Mitsubishi published an update for their WEB Functions of Air Conditioning Systems advisory that was originally published on July 1st, 2021.

Mitsubishi Update #2 - Mitsubishi published an update for their Denial-of-Service Vulnerability in Multiple Air Conditioning Systems advisory that was originally published on July 1st, 2021.

GPS Report #1 - Tenable published a report on five vulnerabilities in the LandAirSea Silver Cloud web site.

GPS Report #2 - Tenable published a report describing five vulnerabilities in the Spytec GPS platform web site.

GPS Report #3 - Tenable published a report describing 12 vulnerabilities in the Optimus GPS platform web site.

GPS Report #4 - Tenable published a report describing three vulnerabilities in the Tracki/Trackimo GPS platform web site.

Geutebruck Exploit - Titouan Lazard and Ibrahim Ayadhi have published a Metasploit module for a buffer overflow vulnerability in the Geutebruck G-Cam EEC-2xxx and G-Code EBC-21xx, EFD-22xx, ETHC-22xx, and EWPC-22xx devices.

For more details on these advisories and reports, including links to third party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-7ed - subscription required.

Saturday, September 11, 2021

Review - Public ICS Disclosures – 9-10-21

This week we have twelve vendor disclosures from ABB, BD, Draeger, Honeywell, Johnson Controls, Mitsubishi, Philips, and QNAP (5). There are also three updates from ABB, Aruba, and Yokogawa. We also have thirteen researcher reports for products from ECOA. Finally, we have an exploit for products from Geutebruck.

ABB Advisory - ABB published an advisory describing six vulnerabilities in their EIBPORT product.

BD Advisory - BD published an advisory describing four vulnerabilities in their BD Alaris and BD FocalPoint products.

Draeger Advisory - Draeger published an advisory discussing the FragAttacks WiFi vulnerabilities.

Honeywell Advisory - Honeywell published a notice announcing the availability of new versions of their VMS and NVR Software that contain fixes for unspecified security vulnerabilities.

Johnson Controls Advisory - Johnson Controls published an advisory describing an authorization bypass through user controlled key vulnerability in their Kantech KT‐1 door controller.

Mitsubishi Advisory - Mitsubishi published an advisory describing two vulnerabilities in the TCP/IP Protocol Stack of GOT and Tension Controller.

Philips Advisory - Philips published an advisory discussing the PetitPotam exploit.

QNAP Advisory #1 - QNAP published an advisory describing an insufficient HTTP security headers vulnerability in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #2 - QNAP published an advisory describing an insufficiently protected credentials vulnerability in their QSW-M2116P-2T2S and QuNetSwitch products.

QNAP Advisory #3 - QNAP published an advisory describing two stack-based buffer overflow vulnerabilities in their NVR Storage Expansion.

QNAP Advisory #4 - QNAP published an advisory describing a stack-based buffer overflow vulnerability in their QUSBCam2.

QNAP Advisory #5 - QNAP published an advisory describing a stack-based buffer overflow vulnerability in their QTS, QuTS hero, and QuTScloud products.

ABB Update - ABB published an update for their Base Software for SoftControl advisory that was originally published on June 23rd, 2021.

Aruba Update - Aruba published an update for their Aruba OS advisory that was originally published on August 31st, 2021.

Yokogawa Update - Yokogawa published an update for their VB6 Runtime advisory that was originally published on April 23rd, 2021.

ECOA Reports - Zero Science published thirteen reports about vulnerabilities in the ECOA Building Automation System.

Geutebruck Exploit - Titouan Lazard published a Metasploit module for seven vulnerabilities in the Geutebruck G-Cam E2 and G-Code cameras.

For more details about the various advisories, including links to third-party reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-9-10-21 - subscription required.

Saturday, September 4, 2021

Review - Public ICS Disclosures – Week of 8-28-21

This week we have sixteen vendor disclosures from ABB, Aruba Networks, Baxter, WAGO (3), Hitachi ABB Power Grids, Hewlett Packard Enterprise, Mitsubishi (2), Moxa (2), OPC Foundation, Philips, and QNAP (2). We also have three vendor updates from CODESYS. There are also 20 researcher reports for products from Fuji Electric. Finally, we have an exploit for products from Geutebruck.

ABB Advisory - ABB published an advisory describing a remote code execution vulnerability in their Base Software for SoftControl product.

Aruba Advisory - Aruba published an advisory describing 15 vulnerabilities in their ArubaOS product.

Baxter Advisory - Baxter published an advisory discussing the PrintNightmare vulnerability.

WAGO Advisory #1 - CERT VDE published an advisory describing an improper authentication and access control vulnerability in the WAGO 750-36X and WAGO 750-8XX products.

WAGO Advisory #2 - CERT VDE published an advisory discussing two out-of-bounds read vulnerabilities in the e!COCKPIT and WAGO-I/O-Pro products.

WAGO Advisory #3 - CERT VDE published an advisory describing a missing release of resources after effective lifetime vulnerability in WAGO PLCs.

Hitachi ABB Advisory - Hitachi ABB published an advisory describing a clear-text storage of sensitive information vulnerability in their System Data Manager – SDM600 products.

HPE Advisory - HPE published an advisory discussing two vulnerabilities in the SGI UV 300/3000 and HPE Integrity MC990 X Servers.

Mitsubishi Advisory #1 - Mitsubishi published an advisory discussing the FragAttacks WiFi vulnerabilities.

Mitsubishi Advisory #2 - Mitsubishi published an advisory discussing the BadAlloc vulnerabilities (Amazon FreeRTOS is the specific product involved here).

Moxa Advisory #1 - Moxa published an advisory describing 59 vulnerabilities in their TAP-323, WAC-1001, and WAC-2004 Series Wireless AP/Bridge/Client.

Moxa Advisory #2 - Moxa published an advisory describing 59 vulnerabilities in their OnCell G3470A-LTE and WDR-3124A Series Cellular Gateways/Router.

OPC Foundation - OPC Foundation published an advisory describing an access of memory location after end-of-buffer vulnerability in their Local Discovery Server.

Philips Advisory - Philips published an advisory discussing the HiveNightmare vulnerability.

QNAP Advisory #1 - QNAP published an advisory describing two vulnerabilities in their QNAP NAS running HBS 3.

QNAP Advisory #2 - QNAP published an advisory describing an out-of-bounds read vulnerability in their QNAP NAS running QTS, QuTS hero, and QuTScloud.

CODESYS Update #1 - CODESYS published an update for their V3 web server advisory that was originally published on May 19th, 2021 and most recently updated on July 22nd, 2021.

CODESYS Update #2 - CODESYS published an update for their V3 web server that was that was originally published on July 15th, 2021.

CODESYS Update #3 - CODESYS published an update for their Gateway V3 advisory that was originally published on July 15th, 2021.

Fuji Electric Reports - The Zero Day Initiative published 20 reports describing 0-day vulnerabilities in the Fuji Tellus Lite V-Simulator.

Geutebruck Exploit - Titouan Lazard, Sebastien Charbonnier, and Ibrahim Ayadhi published a Metasploit module for eight previously reported vulnerabilities in the Geutebruck G-Cam EEC-2xxx and G-Code EBC-21xx, EFD-22xx, ETHC-22xx, and EWPC-22xx devices.

 

For more details on the advisories and reports, including links to third-party reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8 - subscription required.

Tuesday, July 27, 2021

Review - 5 Advisories and 5 Updates Published – 7-27-21

Today CISA’s NCCIC-ICS published five control system security updates for products from Delta Electronics, LCDS, Geutebruck, Mitsubishi, and KUKA. They also updated five security advisories for products from Mitsubishi (2), AVEVA, Delta, and Schneider Electric.

Delta Advisory - This advisory describes two vulnerabilities in the Delta DIAScreen software.

LCDS Advisory - This advisory describes a cross-site scripting vulnerability in the LCDS LAquis SCADA.

Geutebruck Advisory - This advisory describes twelve vulnerabilities in the Geutebruck G-Cam E2 cameras and G-Code encoders.

Mitsubishi Advisory - This advisory describes a missing synchronization vulnerability in the Mitsubishi GOT2000 series and GT SoftGOT2000 when using the MODBUS/TCP Slave.

KUKA Advisory - This advisory describes two use of hard-coded credentials vulnerabilities in the KUKA KR C4 controllers.

Mitsubishi Update #1 - This update provides additional information on an advisory that was originally published on July 30th, 2020 and most recently updated on May 27th, 2021.

Mitsubishi Update #2 - This update provides additional information on an advisory that was originally published on April 22, 2021.

AVEVA Update - This update provides additional information on an advisory that was originally published on June 29th, 2021.

Delta Update - This update provides additional information on an advisory that was originally published on July 1st, 2021.

Schneider Update - This update provides additional information on an advisory that was originally published on July 13th, 2021.

For more details on these advisories and updates, including links to proof-of-concept code, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-5-updates-published - subscription required.

Saturday, August 22, 2020

Public ICS Disclosures – Week of 8-15-20


This week we have three vendor disclosures for products from Phoenix Contact, Moxa, and Eaton and one update from Rockwell. There are researcher reports for products from WECON. There were two control system exploits published for products from PNPSCADA and Geutebruck.

Phoenix Contact Advisory


Phoenix Contact published an advisory [.PDF download link] describing a synchronous access of remote resource without timeout vulnerability in their Emalytics, ILC 2050 BI and ILC 2050 BI-L products. This is a third-party vulnerability in the Tridium Niagara product that was reported earlier this month by NCCIC-ICS. Phoenix Contact reports that they expect to fix this vulnerability in the next firmware update in October 2020.

Moxa Advisory


Moxa published an advisory describing six vulnerabilities in their NPort IAW5000A-I/O Series Serial Device Servers. The vulnerabilities were reported by Evgeniy Druzhinin and Ilya Karpov of Rostelecom-Solar. Moxa has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Session fixation,
• Improper privilege management,
• Weak password requirements,
• Cleartext transmission of sensitive information,
• Improper restriction of excessive authentication attempts, and
• Information exposure

Eaton Advisory


Eaton published an advisory describing two vulnerabilities in their Secure Connect Android Mobile app. The vulnerability was reported by Vishal Bharad. Eaton has a new version that mitigates the vulnerabilities. There is no indication that Bharad has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Information exposure, and
• Information exposure through log files

Rockwell Update


Rockwell published an update for an advisory that was originally published on July 8th, 2020 and most recently updated on July 23rd, 2020. The new information includes links to additional detections.

WECON Reports


The Zero Day Initiative has published (ZDI-20-1055 thru ZDI-20-1076) 22 reports of 0-day vulnerabilities in the WECON LeviStudioU. The vulnerabilities have been reported to ‘ICS-CERT’ (presumably CISA NCCIC-ICS) which reportedly received no response from WECON. The vulnerabilities were reported by Natnael Samson. The vulnerabilities are all stack-based buffer overflows in various components of the LeviStudioU product. NO CVEs have been reported.

PNPSCADA Exploit


İsmail ERKEK published an exploit for an SQL injection vulnerability in the PNPSCADA. There is no CVE for this vulnerability and there is no indication that ERKEK has contacted the vendor, so this looks like it is a 0-day vulnerability.

Geutebruck Exploit


Davy Douhine published a Metasploit module for an authenticated arbitrary command execution vulnerability in Geutebruck G-Cam and G-Code cameras. This vulnerability was previously reported by NCCIC-ICS.

Tuesday, June 4, 2019

Three Advisories Published – 06-04-19


Today the DHS NCCIC-ICS published thee control system security advisories for products from Geutebruck and Phoenix Contact (2).

Geutebruck Advisory


This advisory describes three vulnerabilities in the Geutebruck Encoder and E2 Series Cameras. The vulnerabilities were reported by Romain Luyer and Guillaume Gronnier from CEIS, and Davy Douhine from RandoriSec. Geutebruck reports that the latest version of the firmware mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

Cross-site scripting - CVE-2019-10957; and
OS command injection (2) - CVE-2019-10956 and CVE-2019-10958

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote code execution as root and remote code execution in the browser of the IP camera operator.

FL NAT Advisory


This advisory describes an improper access control vulnerability in the Phoenix Contact FL NAT SMx industrial Ethernet switches. The vulnerability was reported by Maxim Rupp via CERT VDE. Phoenix Contact has provided generic mitigation measures for the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow unauthorized users full access to the device configuration.

PLCNext Advisory


This advisory describes four vulnerabilities in the Phoenix Contact PLCNext AXC F 2152 products. The vulnerabilities were reported by Zahra Khani of Firmalyzer and the OPC Foundation. Phoenix Contact reports that later versions of the firmware mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

Key management errors - CVE-2018-7559;
Improper access control - CVE-2019-10998;
Man-in-the-middle - CVE-2019-10997; and
Using components with known vulnerabilities

NOTE: the CERT VDE advisory lists 43 separate Linux vulnerability CVE’s for the fourth vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to decrypt passwords, bypass authentication, and deny service to the device. In addition, these vulnerabilities could interact with third-party vulnerabilities to cause other impacts to integrity, confidentiality, and availability.

Thursday, December 13, 2018

5 Advisories and 2 Updates Published – 12-13-18

Today the DHS NCCIC-ICS published four control system security advisories for products from GE, Geutebruck, Siemens and Schneider and one medical device security advisory for products from Medtronic. They also published an update for a previously published control system security advisory for products from Siemens and a medical device security advisory for products from Philips.

GE Advisory


This advisory describes a path traversal vulnerability in the GE Mark VIe, EX2100e, EX2100e_Reg, and LS2100e distributed control systems. The vulnerability was reported by Can Demirel of Biznet Bilisim. GE has a new version that mitigates the vulnerability. There is no indication that Demirel has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to access system data, which could result in escalation of privilege and unauthorized access to the controller.

Geutebruck Advisory


This advisory describes an OS command injection vulnerability in the Geutebruck E2 Camera Series. The vulnerability was reported by Davy Douhine of RandoriSec. Geutebruck has a new version that mitigates the vulnerability. There is no indication that Douhine has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote attacker to inject OS commands as root.

Siemens Advisory


This advisory describes two improper input validation vulnerabilities in the Siemens EN100 Ethernet Communication Module and SIPROTEC 5 relays. These vulnerabilities were reported by Victor Nikitin, Vladislav Suchkov, and Ilya Karpov from ScadaX. Siemens has updates for some of the affected products and continues to work on updates for the remaining products.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to cause a denial-of-service condition of the network functionality of the device, compromising the availability of the system.

NOTE: This advisory was published when Siemens published an update last Tuesday. The original Siemens advisory was reported here back in July, 2018.

Schneider Advisory


This advisory describes three vulnerabilities in the Schneider Electric GUIcon. The vulnerabilities were reported by mdm and rgod of 9SG Security Team. Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Type confusion (2) - CVE-2018-7813 and CVE-2018-7815; and
• Stack-based buffer overflow - CVE-2018-7814

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to execute code with privileges within the context of the application.

NOTE: I briefly reported the Schneider advisory last Saturday.

Medtronic Advisory


This advisory describes a missing encryption of sensitive data vulnerability in the Medtronic 9790 CareLink Programmer, 2090 CareLink Programmer, 29901 Encore Programmer; programmers for Medtronic cardiac devices. The vulnerabilities were reported by Researchers Billy Rios and Jonathan Butts of Whitescope LLC. Medtronic has provided generic workarounds for two of the devices and reports that the 9970 is out of support and all use should be discontinued. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an relatively low-skilled attacker with physical access to the devices could exploit the vulnerability to access PHI or PII stored on the device.

Siemens Update

This update provides additional information for an advisory that was originally published on March 29th, 2018 and updated on April 24th, 2018, June 12th, 2018 and again on November 14th, 2018. The update provides updated affected version information and mitigation links for SIMATIC NET PC-Software.

NOTE: Siemens updated their advisory on Tuesday and then again today. This NCCIC-ICS update reflects the corrected information published by Siemens today.

Philips Update


This update provides additional information for an advisory that was originally published on March 27th, 2018 and subsequently updated on December 11th, 2018. The updated information includes revised affected version data.

More Missing Siemens Updates


Siemens published four more updates today; only one of those was addressed by NCCIC-ICS today. It will be a long blog post here on Saturday. 

Wednesday, March 21, 2018

ICS-CERT Publishes 2 Advisories and 3 Updates

Yesterday the DHS ICS-CERT published two new control system advisories for products from Siemens and Geutebruck. It also updated three previously published control system advisories for products from Siemens (2) and AutomationDirect. ICS-CERT has missed some recent Siemens updates and an advisory.

Siemens Advisory


This advisory describes an improper input validation vulnerability in the Siemens SIMATIC, SINUMERIK, and PROFINET IO products. The vulnerability is being self-reported by Siemens. Siemens has provided updates that mitigate the vulnerability is some products and has provided generic workarounds for the remaining products while updates are developed for them.

ICS-CERT reports that an uncharacterized attacker on an adjacent network could exploit this vulnerability to execute a denial-of-service condition requiring a manual restart to recover the system. The Siemens security advisory notes that OSI Layer 2 access is required to exploit the vulnerability.

Geutebruck Advisory


This advisory describes six vulnerabilities in the Geutebruck IP cameras. The vulnerabilities were reported by Davy Douhine of RandoriSec and Nicolas Mattiocco of Greenlock. Geutebruck has a new firmware version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Improper authentication - CVE-2018-7532;
• SQL injection - CVE-2018-7528;
• Cross-site request forgery - CVE-2018-7524;
• Improper access control - CVE-2018-7520;
• Server-side request forgery - CVE-2018-7516; and
• Cross-site scripting - CVE-2018-7512

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to lead to proxy network scans, access to a database, adding an unauthorized user to the system, full configuration download including passwords, and remote code execution.

SIMATIC Update


This update provides additional information on an advisory that was originally published on February 27th, 2018. It provides updated version information and mitigation measures for:

• SIMATIC IPC547G: Update BIOS to R1.21.0

SIPROTEC Update


This update provides additional information on an advisory that was originally published on July 6th, 2017, and updated on July 18th, on July 28th, on October 10th, on November 30th, and then again on January 4th, 2018. It provides updated version information and mitigation measures for:

• SIPROTEC 7SJ66: All versions prior to V4.30


AutomationDirect Update


This update provides additional information on an advisory that was originally published on November 9th, 2017. It adds a new product (Do-more Designer) to the list of vulnerable products and provided mitigation links for that product.

Missing Siemens Updates


Siemens has published updates and advisories that have not been covered in this latest series of ICS-CERT publications. Normally, I would not mention the ones from yesterday (two updates here and here, and a new advisory here), but today’s new Siemens advisory was also released yesterday. There is also an update from last week (here) that was not mentioned.

Two of the updates (here and here) are for the Spectre and Meltdown vulnerabilities in the Siemens Industrial products. ICS-CERT is unlikely to update their alert to reflect these new mitigation measures since the existing link to the Siemens advisory will take someone to the new information. This is a potential problem for anyone that is relying on ICS-CERT for information, but because of the way that ICS-CERT does their updates (and does not provide detailed change information) this appears to be unavoidable.
 
/* Use this with templates/template-twocol.html */