Showing posts with label IDEC. Show all posts
Showing posts with label IDEC. Show all posts

Thursday, July 10, 2025

Review – 10 Advisories and 3 Updates Published – 7-10-25

Today CISA’s NCCIC-ICS published ten control system security advisories for products from AAR Railroad Electronics Standards, KUNBUS, Advantech, Delta Electronics, and Siemens (6). They also update advisories for products from IDEC Products, ECOVACS, and KUNBUS.

NOTE: Siemens published three other advisories on Tuesday. I will cover them in the Public ICS Disclosure blog post this weekend.

Advisories

AAR Advisory - This advisory describes a weak authentication vulnerability in the Association of American Railroads (AAR) End-of-Train and Head-of-Train remote linking protocol.

KUNBUS Advisory - This advisory describes an incorrect implementation of authentication algorithm vulnerability in the KUNBUS Revolution Pi OS and RevPi Webstatus.

Advantech Advisory - This advisory describes ten vulnerabilities in the Advantech iView product.

Delta Advisory - This advisory describes a deserialization of untrusted data vulnerability in the Delta DTM Soft product.

SIPROTEC Advisory - This advisory describes a use of GET request method with sensitive query strings vulnerability in the Siemens SIPROTEC products.

TIA Advisory #1 - This advisory describes an upload of file with dangerous type vulnerability in the Siemens TIA Project-Server and TIA Portal products.

TIA Advisory #2 - This advisory describes two vulnerabilities in the Siemens TIA Administrator.

SIMATIC Advisory - This advisory describes an improper input validation vulnerability in the Siemens SIMATIC CN 4100 products.

Solid Edge Advisory - This advisory describes three vulnerabilities in the Siemens Solid Edge product.

SINEC Advisory - This advisory describes four vulnerabilities in the Siemens SINEC NMS products.

Updates

IDEC Update - This update provides additional information on the IDEC Products advisory that was originally published on September 19th, 2024.

ECOVACS Update - This update provides additional information on the DEEBOT Vacuum and Base Station advisory that was originally published on May 15th, 2025.

KUNBUS Update - This update provides additional information on the Revolution Pi advisory that was originally published on May 1st, 2025.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/10-advisories-and-3-updates-published - subscription required.

Thursday, September 19, 2024

Review – 5 Advisories and 1 Update Published

Today, CISA’s NCCIC-ICS published five control system security advisories for products for Kastle Systems, MegaSys Computer Technologies, IDEC Corp, and Rockwell Automation. They also updated an advisory for products from Treck.

Advisories

Kastle Advisory - This advisory describes two vulnerabilities in the Kastle Access Control System.

MegaSys Advisory - This advisory describes an improper input validation vulnerability in the MegaSys Telenium Online Web Application.

IDEC Advisory #1 - This advisory describes a cleartext storage of sensitive information vulnerability in the IDEC WindLDR PLC and WindO/I-NV4 HMI.

IDEC Advisory #2 - This advisory describes two vulnerabilities in multiple PLCs from IDEC. The vulnerabilities are self-reported.

Rockwell Advisory - This advisory describes an insufficient verification of data authenticity vulnerability in their RSLogix 5 and RSLogix 500 programming software.

Updates

Treck Update - This update provides additional information on the Treck Ripple20 advisory that was originally published on June 16th, 202 and most recently updated on March 17th, 2022.

 

For more information on these advisories and a down-the-rabbit-hole look at CISA guidance for cloud applications, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-1-update-published-c52 - subscription required.

Saturday, January 8, 2022

Review - Public ICS Disclosures – Week of 1-1-22 – Part 1

This was a relatively light week for ICS disclosures, but because of the continuing response to the  Log4Shell vulnerabilities, this will be a two part report.

This week we have ten vendor disclosures from Draeger, Hitachi, Kunbus, Moxa (2), QNAP (2), Texas Instruments, VMware, and Yokogawa. There was an update for an advisory for products from IDEC. There are also nine researcher reports for products from Siemens (8) and VMware. Finally, we have one exploit published for products from Siemens.

Draeger Advisory - Drager published an advisory discusses the use of the out-of-support TLS 1.0 and TLS 1.1.

Hitachi Advisory - Hitachi published an advisory discussing 27 vulnerabilities in their Disc Array Systems.

Kunbus Advisory - Kunbus published an advisory describing two vulnerabilities in their Revolution Pi base modules.

Moxa Advisory #1 - Moxa published an advisory discussing the DNSpooq vulnerabilities in their AWK-3131A/4131A/1137C/1131A Series of products.

Moxa Advisory #2 - Moxa published an advisory describing a memory leak vulnerability in their EDR-G903, EDR-G902, and EDR-810 Series Secure Routers.

QNAP Advisory #1 - QNAP published an advisory describing a code execution vulnerability in their NAS running QVPN Service product.

QNAP Advisory #2 - QNAP published an advisory describing cross-site scripting vulnerability in their TFTP Server.

TI Advisory - TI published an advisory discussing the BrakTooth vulnerabilities in their dual-mode Bluetooth products.

VMware Advisory - VMware published an advisory describing a heap overflow vulnerability in their Workstation, Fusion and ESXi products.

Yokogawa Advisory - Yokogawa published an advisory describing seven vulnerabilities in their CENTUM and Exaopc products.

IDEC Update - JPCERT published an update for their IDEC PLC advisory that was originally published on December 24th, 2021.

Siemens Reports - The Zero Day Initiative published eight reports about vulnerabilities in the Siemens JT2Go products.

VMware Report - USD HeroLab published a report describing a hidden functionality vulnerability in the VMware Workspace ONE Intelligent Hub.

Siemens Exploit - RoseSecurity published an exploit for a denial of service vulnerability in the Siemens S7 Layer 2 product.

For more details about these disclosures, including links to 3rd party advisories, see my article at CFSN Detailed analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1 - subscription required.

Thursday, January 6, 2022

Review - 4 Advisories Published – 1-6-22

Today, CISA’s NCCIC-ICS published three control system security advisories for products from IDEC, Fernhill and Omron. They also published a medical device security advisory for products from Philips.

IDEC Advisory - This advisory describes four vulnerabilities in the IDEC PLC’s.

NOTE 1: I briefly reported on these vulnerabilities on December 25th, 2021.

Fernhill Advisory - This advisory describes an uncontrolled resource consumption vulnerability in the Fernhill SCADA Server.

Omron Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Omron CX-One automation software.

Philips Advisory - This advisory describes an improper access control vulnerability in the Philips Engage customer support software platform.

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-published-1-6-22 - subscription required.

Saturday, December 25, 2021

Review - Public ICS Disclosure – Week of 12-18-21 – Part 1

Merry Christmas. This has been another busy week for ICS disclosures. Part 1 today will be normal vulnerabilities and Part 2 (probably tomorrow) will be Log4Shell disclosures.

This week we have six vendor disclosures from ABB, IDEC Corporation, QNAP, Hitachi Energy (2), and Johnson Controls. We also have twelve researcher reports for products from Garrett (7) and Open Design Alliance (5).

ABB Advisory - ABB published an advisory describing an MMS file transfer vulnerability in their Distribution Automation products.

IDEC Advisory - JPCERT published an advisory [link added 18:40 EST 1-6-22] for four vulnerabilities in the IDEC PLCs.

QNAP Advisory - JPCERT published an advisory describing two vulnerabilities in the QNAP VioStar series NVR.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory describing four vulnerabilities in their LinkOne product.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisor discussing seven vulnerabilities in their Data Manager (SDM600) product.

Johnson Controls Advisory - Johnson Controls published an advisory describing an unspecified vulnerability in their American Dynamics VideoEdge NVR.

NOTE: It looks like this has been reported to NCCIC-ICS, so we may see an advisory from them next week

Garrett Reports - Talos published seven reports covering nine vulnerabilities in the Garrett Metal Detectors used for security screening.

ODA Reports - The Zero Day Initiative published five reports covering vulnerabilities in the ODA Drawings Explorer product.

For more details on these advisories, including links to third-party advisories, see my report at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-12 - subscription required.

 
/* Use this with templates/template-twocol.html */