Showing posts with label InduSoft Web Studio. Show all posts
Showing posts with label InduSoft Web Studio. Show all posts

Friday, January 4, 2013

ICS-CERT Issues Advantech Studio Alert


This afternoon the DHS ICS-CERT published an alert for a directory traversal vulnerability in the Advantech Studio Web server. The vulnerability, with proof of concept code, was reported by Nin3 in an uncoordinated disclosure (it’s been a while since we’ve seen one of these).

Exploitation of this vulnerability could result in ‘data leakage’. The alert doesn’t provide any details on what types of data might be leak able, but from a security perspective the data of concern would be credential information. The readability of that data would have a major impact on the seriousness of this vulnerability. Of course the business folks might be just as concerned about the exfiltration of process data.

Actually an Indusoft Vulnerability?


Interestingly ICS-CERT notes that:

“ICS-CERT has shared this report with Advantech. Advantech has phased out the Advantech Studio product. As this is a rebranded Indusoft Web Studio product, full support and upgrades are available through Indusoft Web Studio.” (pg 1)

Why, then, does ICS-CERT refer to this as an Advantech Alert instead of an Indusoft Alert, one doesn’t really know. My guess is that if Nin3 named this as an Advantech issue, then ICS-CERT is just going along with that initial identification while it is working with both organizations to resolve the vulnerability.

Wednesday, November 16, 2011

ICS-CERT Publishes InduSoft Advisory

Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published an advisory for the InduSoft Web Studio software. Interestingly, they give Luigi credit for discovering this vulnerability; Luigi coordinated his disclosure with the Zero Day Initiative so this time he did not run afoul of the ICS-CERT disclosure policy.

The vulnerabilities exploit unauthenticated remote code execution capability within the remote agent component of the system. The vulnerabilities would allow a moderately skilled attacker to remotely execute arbitrary code.  There are no publicly available exploits for these vulnerabilities.

NOTE: CVE numbers have been assigned for these two vulnerabilities but the links provided in the Advisory do not actually link to the CVE files. It is not clear whether this continuing problem is a NIST or and ICS-CERT problem.
 
/* Use this with templates/template-twocol.html */