Showing posts with label Mashav Sapir. Show all posts
Showing posts with label Mashav Sapir. Show all posts

Thursday, July 30, 2020

5 Advisories Published – 7-30-20

Today the CISA NCCIC-ICS published four control system security advisories for products from Mitsubishi Electric (3) and Inductive Automation. They also published a medical device security advisory for products from Philips.

 

Factory Automation Advisory #1

 

This advisory describes an unquoted search path or element vulnerability in the Mitsubishi Factory Automation Engineering products. The vulnerability was reported by Mashav Sapir of Claroty. Mitsubishi has new versions that mitigate the vulnerability. There is no indication that Sapir has been provided an opportunity to verify the efficacy of the fix.

 

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to obtain unauthorized information, modify information, and cause a denial-of-service condition.

 

Factory Automation Advisory #2

 

This advisory describes a path traversal vulnerability in the Mitsubishi Factory Automation products. The vulnerability was reported by Mashav Sapir of Claroty. Mitsubishi has new versions that mitigate the vulnerability. There is no indication that Sapir has been provided an opportunity to verify the efficacy of the fix.

 

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to may allow an attacker to obtain unauthorized information, tamper the information, and cause a denial-of-service condition.

 

Factory Automation Advisory #3

 

This advisory describes a permissions issue vulnerability in the Mitsubishi Factory Automation Engineering Software products. The vulnerability was reported by Younes Dragoni of Nozomi Networks, the Applied Risk research team, and Mashav Sapir of Claroty. Mitsubishi has new versions that mitigate the vulnerability. There is no indication that researchers have been provided an opportunity to verify the efficacy of the fix.

 

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to enable the reading of arbitrary files, cause a denial-of-service condition, and allow execution of a malicious binary.

 

Inductive Automation Advisory

 

This advisory describes a missing authorization vulnerability in the Inductive Automation Ignition 8 product. The vulnerability was reported by Mashav Sapir of Claroty. Inductive Automation has a new version that mitigates the vulnerability. There is no indication that Sapir has been provided an opportunity to verify the efficacy of the fxi.

 

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to gain access to sensitive information.

 

Philips Advisory

 

This advisory describes an insertion of sensitive information into log file vulnerability in the Philips DreamMapper mobile application. The vulnerability was reported by Lutz Weimann, Tim Hirschberg, Issam Hbib, and Florian Mommertz of SRC Security Research & Consulting. Philips plans a new release to mitigate the vulnerability by June of next year.

 

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker access to the log file information containing descriptive error messages.


Thursday, May 14, 2020

2 Advisories and 1 Update Published – 5-14-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Emerson and Opto 22. They also updated a previously issued advisory for products from 3S.

Emerson Advisory


This advisory describes an improper access control vulnerability in the Emerson WirelessHART Gateways. The vulnerability is self-reported. Emerson has updated firmware that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to disable the internal gateway firewall. Once the gateway's firewall is disabled, a malicious user could issue specific commands to the gateway, which could then be forwarded on to the end user's wireless devices.

Opto 22 Advisory


This advisory describes five vulnerabilities in the  Opto 22 SoftPAC Project virtual PLC. The vulnerabilities were reported by Mashav Sapir of Claroty. Opto 22 has a new version that mitigates the vulnerabilities. There is no indication that Sapir was provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• External control of file name or path - CVE-2020-12042,
• Improper verification of cryptographic signature - CVE-2020-12046,
• Improper access control - CVE-2020-10612,
• Uncontrolled search path element - CVE-2020-10616, and
• Improper authorization - CVE-2020-10620

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow arbitrary file write access with system access, start or stop service, allow remote code execution, and limit system availability.

3S Update


This update provides additional information on an advisory that was originally published on August 1st, 2019. The new information includes a link to a new version that mitigates the vulnerability. The publication of the new version was originally projected for February 2020.

Tuesday, April 21, 2020

1 Advisory Published – 4-21-20


The CISA NCCIC-ICS published a control system security advisory for products from Inductive Automation.

Inductive Advisory


This advisory describes an improper access control vulnerability in the Inductive Advisory Ignition 8 Gateway. The vulnerability was reported by Sharon Brizinov and Mashav Sapir from Claroty. Inductive has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to write endless log statements into the database, which could result in a denial-of-service condition.

 
/* Use this with templates/template-twocol.html */