Showing posts with label Ihsan Sencan. Show all posts
Showing posts with label Ihsan Sencan. Show all posts

Saturday, November 17, 2018

Public ICS Disclosures – Week of 11-10-18


This week we have vendor updates of previously issued advisories from Siemens and an apparently uncoordinated vendor disclosure for products from SourceForge (an open source product web site).

Siemens Advisory Updates


As part of the swath of 16 advisories and updates issued by Siemens this week there were three updates that were not covered by NCCIC-ICS updates. These were for vulnerabilities addressed in ICS-CERT generic alerts; NCCIC-ICS does not update these alerts for new information from the existing vendor list on the alert, the links on those alerts already take interested parties to this latest information.

SSA-168644 v1.8 – Spectre and Meltdown Vulnerabilities in Industrial Products. Updated solution for RUGGEDCOM RX1400 VPE;
SSA-254686 v1.1 – Foreshadow / L1 Terminal Fault Vulnerabilities in Industrial Products. Added solution for SIMATIC IPC647D, SIMATIC IPC847D, SIMATIC IPC647C,
SIMATIC IPC847C, SIMATIC IPC627C, SIMATIC IPC677C, SIMATIC IPC827C,
SIMOTION P320-4S, SIMOTION P320-4E;
SSA-268644 v1.2 – Spectre-NG (Variants 3a and 4) Vulnerabilities in Industrial Products; and

GPS Tracking System Vulnerabilities


Ihsan Sencan published an exploit for an SQL injection vulnerability in the SourceForge GPS Fleet/Vehicle Tracking System Using Open Source Traccar Server. There is no CVE associated with this exploit and SourceForge lists the software as “abandoned” so this is probably a 0-day exploit. The product webpage says that there were 48 downloads this week, but I suspect that most of those were security researchers following up on Sencan’s exploit release.

Saturday, November 3, 2018

Public ICS Disclosure – Week of 10-27-18


This week we have two vendor disclosures from ABB and two exploits for products from Modbus Tools.

CMS-770 Advisory


ABB published an advisory for a configuration file vulnerability in the CMS-770 control unit. The vulnerability was reported by Maxim Rupp. ABB has updated the manual for this product to outline additional security measures that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

ABB reports that successful exploitation of this vulnerability could cause the product to reveal the credentials allowing to take over the entire control of the product.

M2M Ethernet Network Analyzer Advisory


ABB published an advisory for a language file vulnerability in the M2M Ethernet Network Analyzer. The vulnerability was reported by Maxim Rupp. ABB has updated the manual for this product to outline additional security measures that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

ABB reports that successful exploitation of this vulnerability could allow an attacker to upload a language file to the product without being requested to authenticate himself.

Modbus Tools Exploits


Kağan Çapar published an exploit for a buffer overflow vulnerability in the Modbus Tools Modbus Slave programming tool. No CVE number is provided so this may be a 0-day vulnerability.

Ihsan Sencan published an exploit for a denial of service vulnerability in the Modbus Tools Modbus Slave programming tool. A new (no details available) CVE number was provided so there is a possibility that the vendor has been contacted about this vulnerability.

 
/* Use this with templates/template-twocol.html */