Showing posts with label Korenix. Show all posts
Showing posts with label Korenix. Show all posts

Saturday, August 10, 2024

Review – Public ICS Disclosures – Week of 8-3-24

This week we have 18 vendor disclosures from Bosch, Broadcom, B&R, Carrier, Hitachi (11), HPE (2), and SEL. There are also seven vendor updates from Broadcom (3), Cisco (2), HPE, and VMware. Finally, we have four researcher reports about vulnerabilities in products from Johnson Controls, Korenix, PLANET Technology, and Unitronics.

Advisories

Bosch Advisory - Bosch published an advisory that discusses four vulnerabilities (all with available exploits) in their DIVAR IP all-in-one Devices.

Broadcom Advisory - Broadcom published an advisory that discusses 22 vulnerabilities (11 with publicly available exploits) in their Brocade ASCG.

B&R Advisory - B&R published an advisory that discusses six vulnerabilities in their Automation Runtime product.

Carrier Advisory - Carrier published an advisory that discusses a supply chain attack that affected their LenelS2 NetBox products.

Hitachi Advisory #1 - Hitachi published an advisory that discusses an HTTP request/response smuggling vulnerability in their Cosminexus product.

Hitachi Advisory #2 - Hitachi published an advisory that discusses an incomplete cleanup vulnerability in their Automation Director, Infrastructure Analytics Advisor and Ops Center products.

Hitachi Advisory #3 - Hitachi published an advisory that describes an unquoted search path vulnerability in their Device Manager.

Hitachi Advisory #4 - Hitachi published an advisory that discusses six vulnerabilities (including three with publicly available exploits) in their Ops Center Analyzer viewpoint and Ops Center Viewpoint products.

Hitachi Advisory #5 - Hitachi published an advisory that discusses two vulnerabilities (one with publicly available exploits) in their Configuration Manager and Ops Center API Configuration Manager products.

Hitachi Advisory #6 - Hitachi published an advisory that discusses an XMM register corruption vulnerability in their Configuration Manager and Ops Center API Configuration Manager products.

Hitachi Advisory #7 - Hitachi published an advisory that discusses the Terrapin Attack vulnerability.

Hitachi Advisory #8 - Hitachi published an advisory that describes an EL injection vulnerability in their Tuning Manager product.

Hitachi Advisory #9 - Hitachi published an advisory that discusses six vulnerabilities in their Cosminexus Developer's Kit for Java and Hitachi Developer's Kit for Java products.

Hitachi Advisory #10 - Hitachi published an advisory that discusses six vulnerabilities in multiple products.

Hitachi Advisory #11 - Hitachi published an advisory that discusses 71 vulnerabilities in their Disk Array Systems.

HPE Advisory #1 - HPE published an advisory that describes a SMM lock bypass vulnerability in their ProLiant AMD Servers.

HPE Advisory #2 - HPE published an advisory that discusses the regreSSHion vulnerability. HPE reports that their Athonet products are affected.

SEL Advisory - SEL published a version update notice for their Compass product that reports that the new version includes cybersecurity enhancements.

Updates

Broadcom Update #1 - Broadcom published an update for their Privilege escalation using switch commands advisory that was originally published on September 13th, 2022 and most recently updated on September 20th, 2022.

Broadcom Update #2 - Broadcom published an update for their libxml2 advisory that was originally published on July 30th, 2024.

Cisco Update #1 - Cisco published an update for their Blast-Radius advisory that was originally published on July 10th, 2024 and most recently updated on August 2nd, 2024.

Cisco Update #2 - Cisco published an update for their regreSSHion advisory that was originally published on July 2nd, 2024 and most recently updated on July 26th, 2024.

HPE Update - HPE published an update for their Fiber Channel and SAN Switches advisory that was originally published on August 1st, 2024.

VMware Update - Broadcom published an update for their VMware Workspace ONE advisory that was originally published on April 6th, 2024.

Researcher Reports

Johnson Controls Report - Nozomi Networks published a report describing five vulnerabilities in the Johnson Controls’ exacqVision Web Service.

Korenix Report - CyberDanube published a report that describes three vulnerabilities in the Korenix JetPort ethernet switch. An exploit was also published for the three vulnerabilities.

Planet Technology Report - IOActive published a report that describes three vulnerabilities in the PLANET IGS-4215-16T2S switch.

Unitronics Report - Claroty published a report that describes two vulnerabilities in Unitronics PLCs/HMI that have been exploited in the wild.

 

For more details about these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis – https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-bbf - subscription  required.

Saturday, March 16, 2024

Review – Public ICS Disclosures – Week of 2-9-24 – Part 1

This week we have 25 vendor disclosures from Bosch (2), FortiGuard (3), Fujitsu, GE Vernova, Hitachi (6), Honeywell, HP (4), Insyde, Korenix, Palo Alto Networks (3), Philips, and Phoenix Contact.

Advisories

Bosch Advisory #1 - Bosch published an advisory that discusses seven vulnerabilities in multiple Bosch products.

Bosch Advisory #2 - Bosch published an advisory that describes five vulnerabilities in their Remote Programing Software.

FortiGuard Advisory #1 - FortiGuard published an advisory that describes an improper authentication vulnerability in their FortiOS products.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an authentication bypass through user controlled key vulnerability in their FortiOS and FortiProxy products.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes two vulnerabilities in their FortiOS and FortiProxy products.

Fujitsu Advisory - Fujitsu published an advisory that discusses 11 vulnerabilities in multiple Fujitsu products.

GE Vernova Advisory - GE Vernova published an advisory that discusses four vulnerabilities (two listed in CISA’s Known Exploited Vulnerabilities catalog) in multiple products.

Hitachi Advisor #1 - Hitachi published an advisory that discusses an internal state disruption vulnerability in their Cosminexus HTTP Server.

Hitachi Advisory #2 - Hitachi published an advisory that describes an uncontrolled resource consumption vulnerability in their Cosminexus HTTP Server.

Hitachi Advisory #3 - Hitachi published an advisory that discusses an improper input validation vulnerability in their Cosminexus HTTP Server.

Hitachi Advisory #4 - Hitachi published an advisory that discusses the HTTP/2 Rapid Reset Attack (listed on CISA’s KEV catalog) vulnerability in their Cosminexus HTTP Server.

Hitachi Advisory #5 - Hitachi published an advisory that discusses an incomplete cleanup vulnerability in their Cosminexus Component Container.

Hitachi Advisory #6 - Hitachi published an advisory that describes an insertion of sensitive information into log file vulnerability in their Cosminexus Component Container.

Honeywell Advisory - Honeywell published an end-of-life notice for their e S3100 portfolio.

HP Advisory #1 - HP published an advisory that describes a privilege escalation vulnerability in multiple HP computers.

HP Advisory #2 - HP published an advisory that discusses four vulnerabilities in multiple HP computers.

Insyde Advisory - Insyde published an advisory that describes a UEFI variable modification vulnerability in their H2OFFT, H2OUVE, and H2OOAE products.

Korenix Advisory - INCIBE-CERT published an advisory that describes an exposure of sensitive information to an unauthorized actor vulnerability in the Korenix JetI/O 6550 F208 product.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes an improper privilege management vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that describes an improper privilege management vulnerability in their GlobalProtect App.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory that describes an improper privilege management vulnerability in their GlobalProtect App.

Philips Advisory - Philips published an advisory that discusses two use-after-free vulnerabilities in the Imaging Data Commons libdicom.

Phoenix Contact Advisory - Phoenix Contact published an advisory that describes 13 vulnerabilities in their CHARX SEC-3xxx charge controllers.

 

For more information on these advisories, including links to 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2-c78 3-16-24

 - subscription required.

Saturday, January 20, 2024

Review – Public ICS Disclosures – Week of 6-13-24

This week we have 12 vendor disclosures from Broadcom, Dahua, Hitachi (4), HP, HPE, Insyde, SonicWall, Three R Solutions, and VMware. There are two vendor updates from Palo Alto Networks and Synology. We also have two researcher reports that describe vulnerabilities in products from Synology and Korenix.

Advisories

Broadcom Advisory - Broadcom published an advisory that discusses an out-of-bounds write vulnerabilities that is listed in the CISA Known Exploited Vulnerabilities Catalog in multiple Brocade products.

Dahua Advisory - JP-CERT published an advisory that describes an authentication bypass vulnerability in multiple Dahua products.

Hitachi Advisory #1 - Hitachi published an advisory that describes two vulnerabilities in their Device Manager.

Hitachi Advisory #2 - Hitachi published an advisory that discusses an allocation of resources without throttling or limits vulnerability in their Tuning Manager product.

Hitachi Advisory #3 - Hitachi published an advisory that discusses an out-of-bounds write vulnerability in multiple Hitachi products.

Hitachi Advisory #4 - Hitachi published an advisory that describes an incorrect default permissions vulnerability in their Tuning Manager product.

HP Advisory - HP published an advisory that discusses seven vulnerabilities in multiple HP products.

HPE Advisory - HPE published an advisory that discusses eight vulnerabilities in their  HP-UX Apache Web Server products.

Insyde Advisory - Insyde published an advisory that discusses nine vulnerabilities in their EDK2 NetworkPkg IP stack

SonicWall Advisory - SonicWall published an advisory that describes a stack-based buffer overflow vulnerability in their Capture Client and NetExtender Client Windows products.

Three R Solutions Advisory - JP-CERT published an advisory that describes an insufficient technical documentation vulnerability in the Three R Solutions Thermal camera TMC series products.

VMware Advisory - VMware published an advisory that describes a missing access control vulnerability in their Aria Automation products.

Updates

Palo Alto Networks Update - Palo Alto Networks published an update for their Terrapin-Attack vulnerability that was originally published on January 8th, 2024.

Synology Update - Synology published an update for their DiskStation Manager advisory that was originally published on January 9th, 2024.

Researcher Reports

Synology Report - Claroty published a report describing an inadequate data validation vulnerability in the Synology RT6600ax routers.

Korenix Report - CyberDanube published a report describing two vulnerabilities in the Korenix JetNet Series industrial switch.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-7a6 - subscription required. 

Thursday, April 6, 2023

Review - 6 Advisories and 1 Update Published – 4-6-23

Today, CISA’s NCCIC-ICS published six control system security advisories for products from mySCADA Technologies, Hitachi Energy, Korenix, JTEKT (2), and Industrial Control Links. They also updated an advisory for products from Rockwell Automation.

Advisories

mySCADA Advisory - This advisory describes five OS command injection vulnerabilities in the mySCADA myPRO products.

Hitachi Energy Advisory - This advisory describes five vulnerabilities in their MicroSCADA System Data Manager SDM600 Product.

Korenix Advisory - This advisory describes three vulnerabilities in the Korenix Jetwave industrial wireless gateways.

JTEKT Advisory #1 - This advisory describes three vulnerabilities in the JTEKT Kostac PLC Programming Software.

JTEKT Advisory #2 - This advisory describes seven vulnerabilities in the JTEKT Screen Creator Advance product.

Industrial Control Link Advisory - This advisory describes an external control of file name or path vulnerability in the ICL ScadaFlex II SCADA Controller SC-1 and SC-2 devices.

NOTE: I previously reported on the vulnerabilities listed in five of the six advisories

Updates

Rockwell Update - This update provides additional information on an advisory that was originally published on February 20th, 2020.

 

For more details on these advisories, including links to my earlier reports, vendor advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-1-update-published-7aa - subscription required.

Saturday, June 4, 2022

Review – Public ICS Disclosure – Week of 5-28-22

This week we have ten vendor disclosures from CODESYS (3), Dell, Endress+Hauser, Mitsubishi, Moxa, Software Toolbox (2), and T&D. We also have nine vendor updates from Aruba Networks, CODESYS, Fujitsu, HP, HPE (4), and Palo Alto Networks. There are also two researcher reports for products from Korenix, and Schneider Electric. Finally, we have three exploits published for products from SolarView, and Ingredient Stock Management System (2).

CODESYS Advisory #1 - CODESYS published an advisory that describes two uncontrolled resource consumption vulnerabilities in their CODESYS V3 products containing a CODESYS communication server.

CODESYS Advisory #2 - CODESYS published an advisory that describes a plain-text storage of password vulnerability in their OPC DA Server.

CODEESYS Advisory #3 - CODESYS published an advisory that describes an observable response discrepancy in their Visualization products.

Dell Advisory - Dell published an advisory that describes three vulnerabilities in their Wyse Management Suite (one is a third-party (JQuery) vulnerability.

Endress+Hauser Advisory - CERT VDE published an advisory that discusses eight vulnerabilities in multiple products from Endress +HYauser.

Moxa Advisory - Moxa published an advisory that discusses the DirtyPipe vulnerability.

Software Toolbox Advisory #1 - Software Toolbox published an advisory that discusses a security feature bypass vulnerability in their OPC Quick Client.

Software Toolbox Advisory #2 - Software Toolbox published an advisory that discusses a security feature bypass vulnerability for customers using OPC Classic.

T&D Advisory - T&D published an advisory that describes a directory traversal vulnerability in the T&D Data Server and THERMO RECORDER DATA SERVER.

Aruba Update #1 - Aruba published an update for their Expat XML advisory that was originally published on May 17th, 2022.

Aruba Update #2 - Aruba published an update for their OpenSSL advisory that was originally published on May 4th, 2022.

Fujitsu Update - JP CERT published an update for their FUJITSU Network IPCOM advisory that was originally published on  May 19th, 2022.

CODESYS Update - CODESYS published an update for their Development System V3 advisory that was originally published on July 15th, 2021 and most recently updated on August 2nd, 2021.

HP Update - HP published an update for their HP Print Products advisory that was originally published on March 21st, 2022, and most recently updated on May 3rd, 2022.

HPE Update #1 - HPE published an update for their Intel Bios advisory that was originally published on May 10th, 2022.

HPE Update #2 - HPE published an update for their ProLiant DX Servers advisory that was originally published on May 10th, 2022.

HPE Update #3 - HPE published an update for their Synergy Servers advisory that was originally published on May 10th, 2022.

HPE Update #4 - HPE published an update for their ProLiant BL/DL/ML/XL/MicroServer that was originally published on May 10th, 2022.

Palo Alto Networks Update - Palo Alto Networks published an update for their OpenSSL advisory that was originally published on March 31st, 2022 and most recently updated on May 12th, 2022.

Korenix Report - SEC Consult published a report describing a backdoor account in the Korenix JetPort serial converter.

Schneider Report - Zero Science published a report describing a remote root exploit vulnerability (with exploit available) in the Schneider C-Bus Automation Controller.

SolarView Exploit - Ahmed Alroky published an exploit for directory traversal vulnerability in the SolarView Compact.

Ingredient Stock Management System Exploit #1 - Saud Alenazi published an exploit for an SQL injection vulnerability in the Ingredient Stock Management System.

Ingredient Stock Management System Exploit #2 - Saud Alenazi published an exploit for an account takeover vulnerability in the Ingredient Stock Management System.

 

For more details about these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-5-28 - subscription required.

Saturday, June 5, 2021

Review Public ICS Disclosures – Week of 5-28-21

This week we have six vendor disclosures from Aveva, Johnson Controls, QNAP (3), Yokogawa. There is one vendor update from Medtronic. There are also six researcher disclosures for products from Aveva (3), Korenix Technology (also affects Westermo and PEPPERL+FUCHS products), Mesa Labs, Bosch (2) and CHIYU. Finally, we have an exploit for products from VMware.

Two of the vendor advisories and the update should be addressed by NCCIC-ICS this coming week.

The Korenix, Mesa Labs, and CHIYU reports contain proof-of-concept exploit code.

The Korenix report also affects products from Westermo and PEPPERL+FUCHS, though the later had previously published an advisory on the vulnerabilities.

For more details on the disclosures see my report at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-b78 (Subscription Required).


Thursday, October 26, 2017

ICS-CERT Publishes 2 Advisories

Today the DHS ICS-CERT published two control system security advisories for products from Korenix and Rockwell.

Rockwell Advisory


This advisory describes a reusing a nonce, key pair in encryption vulnerability in the Rockwell Stratix 5100 Wireless Access Point. This is the ‘KRACK’ (Key Reinstallation Attack) vulnerability that has been in the news lately (see here for example). The advisory reports that the vulnerability was discovered by Mathy Vanhoef; this attribution is for the KRACK vulnerability generally, not necessarily the specific instance of the vulnerability in this device. Rockwell will produce a new firmware version that mitigates the vulnerability in this device.

ICS-CERT reports that an uncharacterized attacker presumably with access to a wi-fi signal could exploit the vulnerability with a publicly available exploit to operate as a “man-in-the-middle” between the device and the wireless network.

NOTE: The advisory only claims CVE-2017-13082. This is just one of the 10 CVE’s associated with the KRACK vulnerability. It is not clear if this is just an oversight or if this is the only part of the vulnerability found in this particular implementation of the WPA2 standard. I suspect that it is the former.

Korenix Advisory


This advisory describes two vulnerabilities in the Korenix JetNet ethernet switch. The vulnerabilities were reported by Mandar Jadhav of the Qualys Vulnerability Signature/Research Team. Korenix has produced new firmware that mitigates the two vulnerabilities. There is no indication that Jadhav was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability  to gain remote access to the device to run arbitrary code and perform man-in-the-middle attacks.

Commentary


It is odd that ICS-CERT published the Rockwell Advisory without publishing a general alert about the KRACK vulnerability. Any control system devices that provide for wi-fi access while using the WPA2 security protocol are most likely affected by KRACK.

Fixing just one side of the communications link could still possibly leave the network vulnerable to this vulnerability, particularly since this is potentially 10 separate vulnerabilities. This is addressed in the advisory; noting that:

“Rockwell Automation recommends that all users patch the clients that connect to the Stratix 5100 WAP/WGB, and recommends contacting your supplier to get the most updated patch that is compatible with your client devices. However, patching the client only protects the connection formed by that specific client.”

ICS-CERT certainly needs to address this vulnerability since it potentially affects a wide-swath of the wi-fi capable control system devices; a quickly-growing number of devices if vendor ads are any indication.
 
/* Use this with templates/template-twocol.html */