Showing posts with label JTEKT. Show all posts
Showing posts with label JTEKT. Show all posts

Saturday, April 5, 2025

Review – Public ICS Disclosures – Week of 3-29-25 – Part 1

This week we have 18 vendor disclosures from Honeywell (3), HP, HPE, Inaba Denki Sangyo (2), JTEKT (2), Meinberg, PcVue, Philips (3), and SEL (4).

Advisories

Honeywell Advisory #1 - Honeywell published an end-of-life notice for their PWLP Mercury Series 3/LP Series Intelligent Controllers.

Honeywell Advisory #2 - Honeywell published an end-of-life notice for their 30 Series 5MP Fisheye Camera.

Honeywell Advisory #3 - Honeywell published an end-of-life notice for their VMS R670 & R700 / NVR6.7 & R7.0.

HP Advisory - HP published an advisory that discusses three vulnerabilities in multiple HP products.

HPE Advisory - HPE published an advisory that describes two vulnerabilities (one with publicly available exploit) in their Aruba Networking Virtual Intranet Access (VIA) Client.

IDS Advisory - JP-CERT published an advisory that describes eight vulnerabilities in the IDS Wi-Fi AP UNIT 'AC-WPS-11ac series'.

JTEKT Advisory #1 - JTEKT published an advisory that describes six vulnerabilities in their HMI View Jet C-more series.

JTEKT Advisory #2 - JTEKT published an advisory that describes two vulnerabilities in their HMI GC-A2 series.

Meinberg Advisory - Meinberg published an advisory that discusses five vulnerabilities in their Lantime product.

PcVue Advisory - PcVue published an advisory that discusses a NULL pointer dereference vulnerability in their IEC 61850 client driver and the ICCP client add-on in PcVue.

Philips Advisory #1 - Philips published an advisory that discusses an authorization bypass (CVE-2025-29927) that affects Next.js.

Philips Advisory #2 - Philips published an advisory that discusses a Chromium sandbox escape vulnerability that is listed in the CISA Known Exploited Vulnerabilities catalog.

Philips Advisory #3 - Philips published an advisory that discusses a recent Oracle Health data breach.

SEL Advisory #1 - SEL published a software update notice that reports cybersecurity upgrades in their SEL-5052 Server Software.

SEL Advisory #2 - SEL published a software update notice that reports cybersecurity upgrades in their SEL Compass product.

SEL Advisory #3 - SEL published a software update notice that reports cybersecurity upgrades in their SEL-5030 acSELerator QuickSet Software.

SEL Advisory #4 - SEL published a software update notice that reports cybersecurity upgrades in their SEL-5033 acSELerator RTAC Software.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-81f - subscription required.

Saturday, October 5, 2024

Review – Public ICS Disclosures – Week of 9-28-24

This week we have 13 vendor disclosures from Bosch (2), Cisco, DrayTek (2), Hitachi, HP, JTEKT, QNAP, SEL (2), Splunk, Westermo, and WithSecure. We have two vendor updates from Dell. Finally, we have two exploits for products from ABB and Blackberry.

Advisories

Bosch Advisory #1 - Bosch published an advisory that describes a sensitive information disclosure vulnerability in their Configuration Manager.

Bosch Advisory #2 - Bosch published an advisory that discusses three vulnerabilities in their PRC7000 product.

Cisco Advisory - Cisco published an advisory that describes two vulnerabilities in their Small Business Dual WAN Gigabit VPN Routers.

DrayTek Advisory #1 - DrayTek published an advisory that describes 14 vulnerabilities (with exploits available) in multiple Vigor routers.

DrayTek Advisory #2 - DrayTek published an advisory that describes seven classic buffer overflow vulnerabilities in multiple Vigor routers.

Hitachi Advisory - Hitachi published an advisory that discusses an improper input validation vulnerability in their Cosminexus Component Container.

HP Advisory - HP published an advisory that describes an escalation of privilege vulnerability in their business notebook PCs.

QNAP Advisory - QNAP published an advisory that discusses the CUPS vulnerabilities.

SEL Advisory #1 - SEL published a new version notice for their SEL-5030 acSELerator QuickSet Software that includes a description of a cybersecurity enhancement.

SEL Advisory #2 - SEL published a new version notice for their SEL-5813 Backup and Recovery Tool (BaRT) that includes a description of a cybersecurity enhancement.

Splunk Advisory - Splunk published an advisory that discusses four vulnerabilities in their Add-on for Amazon Web Services.

Westermo Advisory - Westermo published an advisory that describes a session hijacking vulnerability in their IbexOS Web Interface.

WithSecure Advisory - WithSecure published an advisory that describes a denial-of-service vulnerability in their Atlant Product.

Updates

Dell Update #1 - Dell published an update for their ThinOS advisory that was originally published on September 9th, 2024, and most recently updated on September 18th, 2024. The

Dell Update #2 - Dell published an update for their ThinOS advisory that was originally published on June 12th, 2024, and most recently updated on September 9th, 2024.

Exploits

ABB Exploit - LiquidWorm published an exploit for a file disclosure vulnerability in the ABB Cylon Aspect.

Blackberry Exploit - SEC Consult published an exploit for an uninstall password bypass vulnerability in the Blackberry CylanceOPTICS product.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-d4d - subscription required.

Saturday, December 16, 2023

Review – Public ICS Disclosures – Week of 12-9-23 – Part 1 –

This week we have 22 vendor disclosures from ABB, Beckhoff, BD (2), Bosch (2), Cisco, FortiGuard (3), Frauscher, HPE (3), JTEKT, and Palo Alto Networks (7).

Advisories

ABB Advisory - ABB published an advisory that discusses the Apache ActiveMQ deserialization of untrusted data vulnerability that is listed on the CISA Known Exploited Vulnerabilities Catalog.

Beckhoff Advisory – CERT-VDE published an advisory that describes an open redirect vulnerability in the Beckhoff TwinCAT/BSD product.

BD Advisory #1 - BD published an advisory that discusses the Windows 7 Operating System End of Life Notice.

BD Advisory #2 - BD published an advisory that discusses an out-of-bounds write vulnerability that is listed in the CISA KEV catalog.

Bosch Advisory #1 - Bosch published an advisory that describes two improper handling of a malformed API request vulnerabilities in their BT software products

Bosch Advisory #2 - Bosch published an advisory that describes a command injection vulnerability in their Bosch IP Cameras.

Cisco Advisory - Cisco published an advisory that discusses the recent Apache Struts vulnerability.

FortiGuard Advisory #1 - FortiGuard published an advisory that describes a use of externally controlled format string vulnerability in their FortiOS, FortiProxy and FortiPAM products.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an improper access control vulnerability in their FortiOS and FortiProxy products.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes a double free vulnerability in their FortiOS and FortiPAM HTTPSd daemon.

Frauscher Advisory - CERT-VDE published an advisory that describes a code injection vulnerability in the Frauscher FDS102 for FAdC/FAdCi.

HPE Advisory #1 - HPE published an advisory that discusses seven vulnerabilities in their Cray Programming Environment.

HPE Advisory #2 - HPE published an advisory that discusses six vulnerabilities in their Intelligent Management Center (iMC) product.

HPE Advisory #3 - HPE published an advisory that discusses 14 vulnerabilities in their Virtualized Telecommunication Management Information Platform (vTeMIP) application.

JTEKT Advisory - JTEKT published an advisory that describes four uncontrolled resource consumption vulnerabilities in their HMI GC-A2 series products.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes a cross-site scripting vulnerability in their PAN-OS products.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that describes a weakness introduced during design vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory that describes an unrestricted upload of file with dangerous type vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #4 - Palo Alto Networks published an advisory that describes an argument injection vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #5 - Palo Alto Networks published an advisory that describes an OS command injection vulnerability in their PAS-OS product.

Palo Alto Networks Advisory #6 - Palo Alto Networks published an advisory that describes an improper privilege management vulnerability in their PAN-OS product.

Palo Alto Networks Adviosry #7 - Palo Alto Networks published an advisory that describes a cross-site scripting vulnerability in their PAN-OS product.

 

For more details about these disclosures, including links to 3rd party advisories, vendor advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-9fa https://tinyurl.com/yty8yuyt- subscription required. 

Saturday, October 21, 2023

Review – Public ICS Disclosures – Week of 10-14-23 – Part 1

This week we have 18 vendor disclosures from Advantech, Aruba Networks, Bosch, Broadcom (3), Cisco (2), Eaton (2), Festo, GE Gas Power, Helmholz, HP (2), HPE, JTEKT, and mb Connect.

Advisories

Advantech Advisory - Advantech published an advisory that describes an exposure of sensitive information to an unauthorized actor vulnerability in their R-SeeNet v2 products

Aruba Advisory - Aruba published an advisory that describes an information disclosure vulnerability in their AirWave Management Platform’s web-based management interface.

Bosch Advisory - Bosch published an advisory that describes ‘several vulnerabilities’ in their ctrlX WR21 HMI.

Broadcom Advisory #1 - Broadcom published an advisory that discusses the SOCKS5 heap buffer overflow vulnerability.

Broadcom Advisory #2 - Broadcom published an advisory that discusses an insufficient control flow management vulnerability in their Brocade Extension Switches.

Broadcom Advisory #3 - Broadcom published an advisory that discusses the HTTP2 Rapid Reset vulnerability.

Cisco Advisory #1 - Cisco published an advisory that discusses the SOCKS5 heap buffer overflow vulnerability.

Cisco Advisory #2 - Cisco published an advisory that discusses the HTTP2 Rapid Reset vulnerability.

Eaton Advisory #1 - Eaton published an advisory that describes a weak encoding of passwords vulnerability in their easyE4 product.

Eaton Advisory #2 - Eaton published an advisory that describes a plaintext storage of password vulnerability in their easySoft software.

Festo Advisory - CERT-VDE published an advisory that discusses a path traversal vulnerability in their TP 260 and MES PC products.

GE Gas Power Advisory - GE Gas Power published an advisory that discusses eight vulnerabilities in their NetworkST4, Remote Operations Offering, and M&D Lockbox products.

Helmholz Advisory - CERT-VDE published an advisory that discusses an improper privilege management vulnerability in the Helmholz REX24 products.

HP Advisory #1 - HP published an advisory that describes a privilege escalation vulnerability in multiple products.

HP Advisory #2 - HP published an advisory that discusses 83 vulnerabilities in their HP Device Manager product.

HPE Advisory - HPE published an advisory that describes a denial of service vulnerability in their Integrated Lights-Out product.

JTEKT Advisory - JTEKT published an advisory that describes two vulnerabilities in their OnSinView2 product.

MB Connect Advisory - MB Connect published an advisory that describes an improper privilege management vulnerability in their mymbCONNECT24 and mbCONNECT24 software.

 

For more details about these disclosures, including links to researcher reports and 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-f0f - subscription required.

Saturday, September 16, 2023

Review – Public ICS Disclosures – Week of 9-9-23 – Part 1

For the week of Cyber Tuesday, the number of disclosures is very reasonable. Still, I am doing a two-part post. For Part 1 we have 16 vendor disclosures for DrayTek, FortiGuard, HP, HPE (2), Insyde (2), JTEKT, Palo Alto Networks (2), QNAP (3), Rockwell Automation (2), and Trumpf. There is one vendor update from Broadcom.

For Part 2 I will be looking at advisories and updates from Schneider and Siemens as well as four exploits.

Advisories

DrayTek Advisory - DrayTek published an advisory that describes a format string vulnerability in their Vigor routers.

FortiGuard Advisory - FortiGuard published an advisory that describes a cross-site scripting vulnerability in their FortiProxy and FortiOS products.

HP Advisory - HP published an advisory that discusses two vulnerabilities in multiple products.

HPE Advisory #1 - HPE published an advisory that describes two authentication bypass vulnerabilities in their OneView infrastructure management software.

HPE Advisory #2 - HPE published an advisory that discusses the Downfall Attacks vulnerability.

Insyde Advisory #1 - Insyde published an advisory that discusses four vulnerabilities in their InsydeH2O product.

Insyde Advisory #2 - Insyde published an advisory that describes an arbitrary code execution vulnerability in their SystemFirmwareManagementRuntimeDxe.

JTEKT Advisory - JTEKT published an advisory that describes two vulnerabilities in their Kostac PLC Programming Software.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes an improper handling of exceptional conditions vulnerability in their Cortex XDR Agent.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that discusses an improper validation of integrity check value vulnerability in their PAN-OS and Prisma products.

QNAP Advisory #1 - QNAP published an advisory that describes an OS command injection vulnerability in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #2 - QNAP published an advisory that describes two NULL pointer dereference vulnerabilities in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #3 - QNAP published an advisory that describes two out-of-bounds write vulnerabilities in their QTS, QuTS hero and QuTScloud products.

Rockwell Advisory #1 - Rockwell published an advisory that describes an improper input validation vulnerability in their FactoryTalk View Machine Edition product.

Rockwell Advisory #2 - Rockwell published an advisory that discusses four vulnerabilities in their KEPServerEX product.

Trumpf Advisory - CERT-VDE published an advisory that discusses two vulnerabilities in the TRUMPF License Expert.

Updates

Broadcom Update - Broadcom published an update for their use-after-free advisory that was originally published on August 1st, 2023.

 

For more details about these disclosures, including links to researcher reports, 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-900 - subscription required.

Thursday, April 6, 2023

Review - 6 Advisories and 1 Update Published – 4-6-23

Today, CISA’s NCCIC-ICS published six control system security advisories for products from mySCADA Technologies, Hitachi Energy, Korenix, JTEKT (2), and Industrial Control Links. They also updated an advisory for products from Rockwell Automation.

Advisories

mySCADA Advisory - This advisory describes five OS command injection vulnerabilities in the mySCADA myPRO products.

Hitachi Energy Advisory - This advisory describes five vulnerabilities in their MicroSCADA System Data Manager SDM600 Product.

Korenix Advisory - This advisory describes three vulnerabilities in the Korenix Jetwave industrial wireless gateways.

JTEKT Advisory #1 - This advisory describes three vulnerabilities in the JTEKT Kostac PLC Programming Software.

JTEKT Advisory #2 - This advisory describes seven vulnerabilities in the JTEKT Screen Creator Advance product.

Industrial Control Link Advisory - This advisory describes an external control of file name or path vulnerability in the ICL ScadaFlex II SCADA Controller SC-1 and SC-2 devices.

NOTE: I previously reported on the vulnerabilities listed in five of the six advisories

Updates

Rockwell Update - This update provides additional information on an advisory that was originally published on February 20th, 2020.

 

For more details on these advisories, including links to my earlier reports, vendor advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-1-update-published-7aa - subscription required.

Saturday, March 4, 2023

Review - Public ICS Disclosure – Week of 3-3-23

This week we have 25 vendor disclosures from ABB (2), Aruba Networks, BaiCells, Bosch, B&R (2), Hitachi Energy, HPE (7), JTEKT Electronics, Milestone, Reillo, StrongSwan, Tanzu (2), VMware, WAGO, Western Digital, and Wireshark. We also have three vendor updates from HPE (2) and Mitsubishi. Finally we have ten researcher reports for products from Osprey (9) and DJI drones.

Vendor Advisories

ABB Advisory #1 - ABB published an advisory that discusses an improper resource shutdown or release vulnerability in ABB AC 800PEC and AC 800PEC-based products.

ABB Advisory #2 - ABB published an advisory that describes an improper authentication vulnerability in their S+ Operations products.

Aruba Advisory - Aruba published an advisory that describes 33 vulnerabilities in their ArubaOS product.

BaiCells Advisory - BaiCells published an advisory that describes a command injection vulnerability in their EG7035-M11 CPE Series products.

Bosch Advisory - Bosch published an advisory that discusses an allocation of resources without limit or throttling vulnerability in their FL MGUARD and TC MGUARD routers.

B&R Advisory #1 - B&R published an advisory that describes five vulnerabilities in their APROL database.

B&R Advisory #2 - B&R published an advisory that discusses five vulnerabilities in their Mobile Panel and Power Panel products.

Hitachi Energy Advisory - Hitachi published an advisory that describes an update signature validation vulnerability in their Relion® 670, 650 and SAM600-IO Series Products.

HPE Advisory #1 - HPE published an advisory that discusses four improper access control vulnerabilities in their Moonshot/Edgeline Servers.

HPE Advisory #2 - HPE published an advisory that discusses an information disclosure vulnerability in their Edgeline Servers.

HPE Advisory #3 - HPE published an advisory that discusses a privilege escalation vulnerability in their Apollo, XL Servers.

HPE Advisory #4 - HPE published an advisory that discusses a privilege escalation vulnerability in their Edgeline Servers.

HPE Advisory #5 - HPE published an advisory that discusses a privilege escalation vulnerability in their Edgeline Servers.

HPE Advisory #6 - HPE published an advisory that discusses an information disclosure vulnerability in their Edgeline Servers.

HPE Advisory #7 - HPE published an advisory that discusses a privilege escalation vulnerability in their Edgeline Servers.

HPE Advisory #8 - HPE published an advisory that discusses two vulnerabilities in their ProLiant DL/ML/Microserver Servers.

JTEKT Advisory - JP Cert published an advisory that describes three vulnerabilities in the JTEKT Kostac PLC Programming Software.

Milestone Advisory - Milestone published an advisory that announces that their online services no longer support TLS v1.0 and TLS v1.1 protocols.

Riello Advisory - Incibe CERT published an advisory that describes three vulnerabilities in the Riello UPS NetMan 204.

StrongSwan Advisory - StrongSwan published an advisory that describes a certificate verification vulnerability in StrongSwan.

Tanzu Advisory #1 - Tanzu published an advisory that discusses three vulnerabilities in multiple Tanzu products.

Tanzu Advisory #2 - Tanzu published an advisory that discusses two vulnerabilities in multiple Tanzu products.

VMware Advisory - VMware published an advisory that describes a passcode bypass vulnerability in their Workspace ONE Content product.

WAGO Advisory - CERT VDE published an advisory that describes four vulnerabilities in multiple WAGO products.

Western Digital Advisory - Western Digital published an advisory that the latest version of their SanDisk PrivateAccess no longer supports “insecure TLS 1.0 and TLS 1.1 protocols”.

Wireshark Advisory - Wireshark published an advisory that describes a packet injection vulnerability in their ISO 15765 and ISO 10681 dissectors.

Vendor Updates

HPE Update #1 - HPE published an update for their Intel 500 Series Ethernet Controllers advisory that was originally published on February 14th, 2023.

HPE Update #2 - HPE published an update for their ProLiant DL/ML/Microserver Servers that was originally published on February 14th, 2023.

Mitsubishi Update - Mitsubishi published an update for their WEB Server Function on MELSEC Series that was originally published on January 17th, 2023 and most recently updated on January 26th, 2023.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-23-017-02) for this new information.

Researcher Reports

Osprey Report #1 - Zero Science published a report that describes a security bypass vulnerability in the Osprey Pump Controller.

Osprey Report #2 - Zero Science published a report that describes an information disclosure vulnerability in the Osprey Pump Controller.

Osprey Report #3 - Zero Science published a report that describes an administrator backdoor vulnerability in the Osprey Pump Controller.

Osprey Report #4 - Zero Science published a report that describes a command injection vulnerability in the Osprey Pump Controller.

Osprey Report #5 - Zero Science published a report that describes a command injection vulnerability in the Osprey Pump Controller.

Osprey Report #6 - Zero Science published a report that describes a reflected cross-site scripting vulnerability in the Osprey Pump Controller.

Osprey Report #7 - Zero Science published a report that describes an authentication bypass vulnerability in the Osprey Pump Controller.

Osprey Report #8 - Zero Science published a report that describes a cross-site scripting vulnerability in the Osprey Pump Controller.

Osprey Report #9 - Zero Science published a report that describes a remote code execution vulnerability in the Osprey Pump Controller.

DJI Drones Report - Nico Schiller, et. al. from the Ruhr University Bochum published a report that describes multiple security vulnerabilities in the control system for DJI consumer drones.

 

For more details about these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-3-3 - subscription require.

Saturday, February 4, 2023

Review – Public ICS Disclosures – Week of 1-28-23

This week we have twelve vendor disclosures from BaiCells, B&R, Hitachi, HP, HPE, JTEKT Electronics, Moxa, Pulse Secure (2), QNAP, and VMware (2). There is also a vendor update from VMware. Finally, we have two researcher reports for products from Sierra Wireless and describing vulnerabilities in the Open Charge Point Protocol for electric vehicle charging stations.

Advisories

BaiCells Advisory - BaiCells published an advisory that describes a use of hard-coded credentials vulnerability in their Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices.

B&R Advisory - B&R published an advisory that describes five vulnerabilities in their ARPOL database.

Hitachi Advisory - Hitachi published an advisory that discusses 60 vulnerabilities in their Disk Array Systems.

HP Advisory - HP published an advisory that describes an escalation of privilege vulnerabilities in their Factory Preinstalled Images.

HPE Advisory - HPE published an advisory that discusses a use-after-free vulnerability in their HPE OneView.

JTEKT Advisory - JP CERT published an advisory that describes seven vulnerabilities in the JTEKT Screen Creator Advance product.

Moxa Advisory - Moxa published an advisory that describes six vulnerabilities in their SDS-3008 Series web server.

Pulse Secure Advisory #1 - Pulse Secure published an advisory that discusses four OpenSSL vulnerabilities.

Pulse Secure Advisory #2 - Pulse Secure published an advisory that describes a cross-site request forgery vulnerability in their Pulse Connect Secure.

QNAP Advisory - QNAP published an advisory that describes an SQL injection vulnerability in their QTS or QuTS hero products.

VMware Advisory #1 - VMware published an advisory that describes a cross-site request forgery bypass vulnerability in their vRealize Operations (vROps).

VMware Advisory #2 - VMware published an advisory that describes an arbitrary file deletion vulnerability in their VMware Workstation product. 

Updates

VMware Update - VMware published an update for their vRealize Log Insight advisory that was originally published on January 24th, 2023.

Researcher Reports

Sierra Wireless Report - Otorio published a report describing two vulnerabilities in the Sierra Wireless AirLink products. The report contains proof-of-concept code.

OCPP Report - SaiFlow published a report describing two vulnerabilities in the WebSocket communications used by the Open Charge Point Protocol (OCPP).

 

For more details about these disclosures, including links to researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-768 - subscription required.

Tuesday, June 21, 2022

Review - 6 Advisories Published – 6-21-22

Today, CISA’s NCCIC-ICS published six control system security advisories for products from Siemens, Phoenix Contact (3), JTEKT, and Mitsubishi. All but the Mitsubishi vulnerabilities reported today by NCCIC-ICS were originally reported by Forescout’s Vedere Labs in their OT:ICEFALL report.

NOTE: Phoenix Contact republished an earlier, related advisory, that I will discuss this weekend.

OT-ICEFALL Report - “Vedere Labs has identified a set of 56 vulnerabilities affecting devices from 10 operational technology (OT) vendors that we are collectively calling OT:ICEFALL [link added].”

Siemens Advisory - This advisory discusses a use of client-side authentication vulnerability in the Siemens SIMATIC WinCC OA SCADA HMI system.

NOTE: ETM, the Siemens subsidiary that developed WinCC OA, published this article on the reported vulnerability disclosure/response process.

Phoenix Contact Advisory #1 - This advisory discusses a missing authentication for critical function vulnerability in the Phoenix Contact classic line industrial controllers.

Phoenix Contact Advisory #2 - This advisory discusses an insufficient verification of data authenticity vulnerability in the Phoenix Contact ProConOS software development kit.

Phoenix Contact Advisory #3 - This advisory discusses an insufficient verification of data authenticity vulnerability in the Phoenix Contact classic line industrial controllers.

JTEKT Advisory - This advisory discusses a missing authentication for critical function vulnerability in the JTEKT TOYOPUC PLCs.

Commentary

Back in 2012 when the original Project Basecamp disclosures (note most of the 2012 links no longer work) documented some of the problems that have been lumped into the term ‘insecure by design’, I had hoped that the control system vendor community would take a hard look at the security assumptions that they had made in designing their control system products. While a great deal of progress has occurred (just look at the vendor names that are not included in OT:ICEFALL report), too many vendors still assume that owner operators will (or even can) only use their devices in ‘secure networks’.

I am disappointed that NCCIC-ICS did not produce an alert based upon the OT:ICEFALL report and call out each of the vendors to report on their response. This is what the old ICS-CERT did (reluctantly to be sure) with the original Project Basecamp reports. In many ways, that Alert, did much to amplify the work that the researchers did and ended up expanding the industry’s work on increasing the basic security of control systems. The work is not done, but today’s advisories will help.

BTW: The original, mostly uncoordinated, Project Basecamp disclosures created a bit of controversy about coordinated disclosure. See my discussion about that controversy here.

 

For more details about these advisories, including a list of the 10 vendors identified in OT:ICEFALL, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published-6-21-22 - subscription required.

Thursday, September 2, 2021

Review - 3 Advisories Published – 9-2-21

Today CISA’s NCCIC-ICS published three control system security advisories for products from Advantech, JTEKT, and Johnson Controls.

Advantech Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Advantech WebAccess HMI platform.

JTEKT Advisory - This advisory describes an allocation of resources without limits or throttling vulnerability in the JTEKT TOYOPUC PLCs.

Johnson Controls - This advisory describes an off-by-one error vulnerability in the Johnson Controls (Sensormatic subsidiary) Illustra camera systems.

For more details about the advisories, including links to published exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-published-9-2-21 - subscription required.

Tuesday, June 29, 2021

Review - 6 Advisories Published - 6-29-21

 

Today CISA’s NCCIC-ICS published six control system security advisories for products from Claroty, Aveva, JTEKT, Panasonic and Johnson Controls (2).

 

Claroty Advisory - This advisory describes an authentication bypass using an alternative path or channel vulnerability in the Claroty Secure Remote Access Site.

Aveva Advisory - This advisory describes two vulnerabilities in the Aveva System Platform. The vulnerability was reported by Sharon Brizinov of Claroty.

JTEKT Advisory - This advisory describes an improper restriction of operations withing the bounds of a memory buffer vulnerability in the JTEKT TOYOPUC PLCs.

Panasonic Advisory - This advisory describes an improper restriction of XML external entity reference vulnerability in the Panasonic FPWIN Pro programming control software.

exacqVision Advisory #1 - This advisory describes a cross-site scripting vulnerability in the Johnson Controls exacqVision Enterprise Manager.

exacqVision Advisory #2 - This advisory describes a cross-site scripting vulnerability in the Johnson Controls exacqVision Web Service.

For more detailed information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published - subscription required.

Tuesday, April 13, 2021

15 Advisories Published – 4-13-21

Today CISA’s NCCIC-ICS published 15 control systems security advisories for products Siemens (12), JTEKT, Advantech, and Schneider Electric. One of the Siemens advisories also affects products from Milestone and another also affects products from PKE.

Milestone Advisory

This advisory describes a use of hard-coded cryptographic key in the Siemens Siveillance (Milestone) Video Open Network Bridge (ONVIF). The vulnerability was reported by Milestone PSIRT. Siemens has a hot fix and Milestone has an update to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an authenticated remote attacker to retrieve and decrypt all user credentials stored on the ONVIF server.

Nucleus Advisory #1

This advisory describes a use of insufficiently random variables vulnerability in the Siemens Nucleus DNS module. This is one of the NAME:WRECK DNS vulnerabilities reported by Forescout and JSOF. Siemens has generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to poison the DNS cache or spoof DNS resolving.

SIMOTICS Advisory

This advisory describes four vulnerabilities in the Siemens SIMOTICS CONNECT 400. The vulnerabilities were self-reported. These are NAME:WRECK vulnerabilities in the third-party Mentor DNS Module. Siemens has a new version that mitigates the vulnerabilities.

The four reported vulnerabilities are:

• Improper null termination - CVE-2020-27736,

• Out-of-bounds read - CVE-2020-27737, and

• Access of memory location after end of buffer - CVE-2020-27738 and CVE-2021-25677

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to poison the DNS cache or spoof DNS resolving.

Tecnomatix Advisory

This advisory describes an out-of-bounds write in the Siemens Tecnomatix RobotExpert. The vulnerability was reported by Francis Provencher via the Zero Day Initiative. Siemens has a new version that mitigates the vulnerability. There is no indication that Provencher has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow remote code execution.

TIM Advisory

This advisory describes 14 vulnerabilities in the Siemens TIM 4R-IE. This is a third-party vulnerability (ntp.d in SNTP). The vulnerabilities are self-reported.

The 14 reported vulnerabilities are:

• Incorrect type conversion or cast - CVE-2015-5219,

• Improper input validation (4) - CVE-2015-7855 (exploit), CVE-2015-7705, CVE-2015-8138, and CVE-2016-1547,

• Improper authentication (2) - CVE-2015-7871 and CVE-2016-4953

• Security features - CVE-2015-7973,

• Null pointer dereference - CVE-2015-7977,

• Data processing errors (2) - CVE-2015-7979 and CVE-2016-1548,

• Exposure of sensitive information to an unauthorized actor - CVE-2016-1550, and

• Race condition - CVE-2016-4954

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to compromise the confidentiality, integrity, and availability of the device.

PKE Advisory

This advisory describes twelve vulnerabilities in the Siemens (and PKE) Control Center Server (CCS). The vulnerabilities were reported by Raphaël Rigo of Airbus Security Lab. Siemens (and PKE) has new versions that mitigate the vulnerabilities. There is no indication that Rigo has been provided an opportunity to verify the efficacy of the fix.

The 12 reported vulnerabilities are:

• Cleartext storage of sensitive information in GUI - CVE-2019-13947,

• Improper authentication (2) - CVE-2019-18337 and CVE-2019-18341

• Relative path traversal - CVE-2019-18338,

• Use of a broken or risky cryptographic algorithm - CVE-2019-18340,

• Exposed dangerous method or function - CVE-2019-18342,

• Path traversal - CVE-2019-19290,

• Cleartext storage in a file or on a disk - CVE-2019-19291,

• SQL Injection - CVE-2019-19292,

• Cross-site scripting (2) - CVE-2019-19293 and CVE-2019-19294, and

• Insufficient logging - CVE-2019-19295

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to read and write arbitrary files and sensitive data and execute commands and arbitrary code.

NOTE: These vulnerabilities were removed from earlier Siemens Advisories, SSA-761617 and SSA-844761.

LOGO! Advisory

This advisory describes two vulnerabilities in the Siemens LOGO! engineering software products. The vulnerabilities were reported by Mashav Sapir from Claroty. Siemens provides generic workarounds to mitigate the vulnerabilities.

The two reported vulnerabilities are:

• Path traversal - CVE-2020-25243, and

• Uncontrolled search path element - CVE-2020-25244

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a local attacker to take over the system where the software is installed.

NOTE: Someone slipped up on the listing of ‘Equipment’ and ‘Vulnerability’ in the ‘Executive Summary’ section of the advisory.

SINEMA Advisory

This advisory describes two vulnerabilities in the Siemens SINEMA Remote Connect Server. These are third-party vulnerabilities (libxml2). Siemens has a new version that mitigates the vulnerabilities.

The two reported vulnerabilities are:

• Missing release of resource after effective lifetime - CVE-2019-19956, and

• Infinite loop - CVE-2020-7595

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to cause a memory leak or an infinite loop situation resulting in a denial-of-service condition.

SCALANCE Advisory

This advisory describes two vulnerabilities in the Siemens Web Server of SCALANCE X200. The vulnerabilities are self-reported. Siemens has a new version that mitigates the vulnerabilities.

The two reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2021-25668, and

• Stack-based buffer overflow - CVE-2021-25669

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to cause a buffer overflow condition resulting in remote code execution.

Solid Edge Advisory

This advisory describes five vulnerabilities in the Siemens Solid Edge software tools. The vulnerabilities were reported by Francis Provencher and rgod via ZDI. Siemens has updates that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Out-of-bounds write - CVE-2020-28385, CVE-2021-25678, CVE-2021-27380,

• Untrusted pointer dereference - CVE-2020-26997, and

• Stack-based buffer overflow - CVE-2021-27382

NCCIC-ICS reports that an uncharacterized attacker with uncharacterized access could exploit the vulnerabilities to lead to a crash, arbitrary code execution, or data extraction on the target host system.

Nucleus Advisory #2

This advisory describes two infinite loop vulnerabilities in the Siemens Nucleus products. The vulnerabilities were self-reported. Siemens has a new version for one of the affected products that mitigates the vulnerabilities.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to cause a denial-of-service condition.

Nucleus Advisory #3

This advisory describes two vulnerabilities in the Siemens Nucleus DNS module. These are two of the NAME:WRECK DNS vulnerabilities reported by Forescout and JSOF. Siemens provides generic work arounds to mitigate the vulnerabilities.

The two reported vulnerabilities are:

• Out-of-bounds write - CVE-2020-15795, and

• Use of out-of-range pointer offset - CVE-2020-27009

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a denial-of-service condition or for the execution of code remotely.

NOTE: There were two additional Siemens’ advisories published today that were not covered by NCCIC-ICS. If they are not covered on Thursday, I will address them on Saturday.

JTEKT Advisory

This advisory describes an improper resource shutdown or release vulnerability in the JTEKT TOYOPUC products. The vulnerability was reported by Younes Dragoni from Nozomi Networks. JTEKT has provided generic mitigation measures.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an unauthorized user to stop Ethernet communications between devices from being established.

Advantech Advisory

This advisory describes an incorrect permission assignment for critical resources in the Advantech WebAccess/SCADA. The vulnerability was reported by Chizuru Toyama of TXOne IoT/ICS Security Research Labs of Trend Micro. Advantech has a new version that mitigates the vulnerability. There is no indication that Toyama has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to login as an ‘admin’ to fully control the system.

Schneider Advisory

This advisory describes an improper restriction of XML external entity reference vulnerability in the Schneider SoMachine Basic products. The vulnerability was reported by Gjoko Krstikj of Applied Risk. Schneider has a new product that replaces the affected product and has updated the mitigation measures.

NOTE 1: This is actually based upon an update to a Schneider advisory that was published on May 22nd, 2018.

NOTE 2: Schneider also published two advisories and two other updates today. If they are not covered by NCCIC-ICS on Thursday, I will address them here on Saturday.

 
/* Use this with templates/template-twocol.html */