Showing posts with label Motorola. Show all posts
Showing posts with label Motorola. Show all posts

Thursday, June 13, 2024

Review – 19 Advisories and 2 Updated Published – 6-13-21

Today, CISA’s NCCIC-ICS published nineteen control systems security advisories for products from Motorola Solutions, Rockwell Automation (3), Fuji Electric, Siemens (13). They updated two advisories for products from Mitsubishi Electric.

Siemens published one additional advisory and 13 updates that have not been addressed by CISA. I will cover them this weekend.

Advisories

Motorola Advisory - This advisory describes seven vulnerabilities in the Motorola Solutions Vigilant License Plate Readers.

Rockwell Advisory #1 - This advisory describes an improper authentication vulnerability in the Rockwell FactoryTalk View SE software.

Rockwell Advisory #2 - This advisory describes an incorrect permissions assignment for critical resource vulnerability in the Rockwell FactoryTalk View SE software.

Rockwell Advisory #3 - This advisory describes an improper authentication vulnerability in the Rockwell FactoryTalk View SE software.

Fuji Advisory - This advisory describes two vulnerabilities in the Fuji Tellus Lite V-Simulator.

SINEC Advisory - This advisory discusses eight vulnerabilities in the Siemens SINEC Traffic Analyzer.

SCALANCE Advisory #1 - This advisory describes seven vulnerabilities in the Siemens SCALANCE W700 802.11 AX family of devices.

SCALANCE Advisory #2 - This advisory discusses eight vulnerabilities in the Siemens SCALANCE XM-400/XR-500 products.

SIMATIC Advisory #1 - This advisory discusses 23 vulnerabilities (three with known exploits) in the Siemens SIMATIC and SIPLUS products.

SIMATIC Advisory #2 - This advisory describes a use of insufficiently random values vulnerability in the Siemens SIMATIC S7-200 SMART devices.

SICAM Advisory - This advisory describes an improper NULL termination vulnerability in the Siemens ICAM AK3, SICAM BC, and SICAM TM products.

Teamcenter Advisory - This advisory describes three vulnerabilities in the Siemens Teamcenter Visualization and JT2Go products.

PowerSys Advisory - This advisory describes an improper authentication vulnerability in the Siemens PowerSys product.

TIM Advisory - This advisory discusses 32 vulnerabilities (five with known exploits) in the Siemens SIPLUS TIM 1531 IRC.

SITOP Advisory - This advisory discusses three out-of-bounds write vulnerabilities in the Siemens SITOP UPS1600 uninterruptible power supplies.

ST7 Advisory - This advisory discusses 37 vulnerabilities (4 with known exploits, 2 in CISA’s KEV catalog) in the Siemens ST7 ScadaConnect products.

TIA Advisory - This advisory describes a creation of a temporary file in directory with insecure permissions vulnerability in the Siemens TIA Administrator.

Mendix Advisory - This advisory describes an improper privilege management vulnerability in the Siemens Mendix Applications.

Updates

Mitsubishi Update #1 - This update provides additional information on the Multiple Products advisory that was originally published on October 5th, 2020 and most recently updated on June 28th, 2023.

Mitsubishi Update #2 - This update provides additional information on the MELSEC-Q/L Series advisory that was originally published on March 14th, 2024 and most recently updated on May 16th, 2024.

 

For more information on these advisories, including links to 3rd party vendors and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/19-advisories-and-2-updated-published - subscription required.

Saturday, December 24, 2022

Review – Public ICS Disclosures – Week of 12-17-22

This week we have an OpenSSL 3.0 disclosure from Palo Alto Networks. There are nine vendor disclosures from Dahua, Dell, DIGI, Hikvision, HPE, Microchip, Motorola Solutions, TandD, and Western Digital. Finally, there is a vendor update from Siemens.

OpenSSL. 3.0

Palo Alto Networks published an advisory discussing the OpenSSL 3.0 vulnerabilities.

Vendor Disclosures

Dahua Advisory - Dahua published an advisory that describes twelve vulnerabilities in a variety of Dahua products.

Dell Advisory - Dell published an advisory that describes nine vulnerabilities (includes 3 third-party vulnerabilities) in their Wyse Management Suite. 

DIGI Advisory - DIGI published an advisory that discusses the FragAttack vulnerabilities.

Hikvision Advisory - Hikvision published an advisory that describes an access control vulnerability in their wireless bridge products.

HPE Advisory #1 - HPE published an advisory that directory traversal vulnerability in their OfficeConnect 1820, and 1850 Switch Series.

HPE Advisory #2 - HPE published an advisory that describes a data injection vulnerability in their Superdome Flex and Superdome Flex 280 Servers.

Microchip Advisory - Microchip published an advisory that discusses the Blue's Clues vulnerabilities.

NOTE: Watch Blue’s Clues (sorry, I could not help myself), cute name and everything. It looks like this will be a major issue for Bluetooth enabled devices, particularly medical devices.

Motorola Advisory - Motorola published an advisory discussing the Fortinet buffer overflow vulnerability.

TandD Advisory - TandD published an end of support notice for products operating on Windows 7 and Windows 8 platforms.

Western Digital Advisory - Western Digital published an advisory describing an information disclosure vulnerability in their My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices.

Vendor Updates

Siemens Update - Siemens published an update for their SIPROTEC 5 Devices advisory that was originally published on December 13th, 2022.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-22-349-14) for the new information.

 

For more details about these disclosures, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-f5b - subscription required.

Tuesday, June 28, 2022

Review – 6 Advisories Published – 6-28-22

Today, CISA’s NCCIC-ICS published six control system security advisories for products from Motorola Solutions (3), Advantech, Omron, and ABB.

Motorola Advisory #1 - This advisory discusses the OT:ICEFALL vulnerabilities in the Motorola ACE1000. 

Motorola Advisory #2 - This advisory discusses the OT:ICEFALL vulnerabilities in the Motorola MDLC protocol parser.

Motorola Advisory #3 - This advisory discusses the OT:ICEFALL vulnerabilities in the Motorola MOSCAD IP Gateway and ACE IP Gateway.

Advantech Advisory - This advisory describes seven vulnerabilities in the Advantech iView management software.

Omron Advisory - This advisory discusses the OT:ICEFALL vulnerabilities in the Omron YSMAC CS/CJ/CP Series and NJ/NX Series PLCs.

ABB Advisory - This advisory describes two incorrect default permissions vulnerabilities in the ABB e-Design engineering software.

NOTE: I originally reported on these vulnerabilities on May 28th. Interestingly, ZDI has not yet published DePlante’s advisories.

Commentary

It has been a week since NCCIC-ICS started their reporting on the OT:ICEFALL vulnerabilities. We still have not seen reports for the vulnerabilities in products from:

• Bentley Nevada (2),

• Emerson (21), and

• Honeywell (9)

In the last week many commentors in the OT space have noted that there is nothing really new here. In the broad scope, that is certainly true, most of the insecure by design problem was well understood when the Project Basecamp disclosures looked at the issues ten years ago. Given that, it is surprising that today is the first time that I have seen a specific recommendation by a vendor of an available upgrade to a more secure product.

 

For more details on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published-6-28-22 - subscription required.

Thursday, December 17, 2015

ICS-CERT Publishes Three Advisories

This afternoon the DHS ICS-CERT published three advisories for control system vulnerabilities. The advisories affected products from eWON, Motorola, and Schneider.

eWON Advisory

This advisory describes multiple vulnerabilities in the eWON sa industrial router. The vulnerabilities were reported by Karn Ganeshen. eWON has developed a firmware update to mitigate the vulnerabilities, but there is no indication that Ganeshen has been provided the opportunity to verify the efficacy of the fix.

The vulnerabilities include:

• Weak session management - CVE-2015-7924;
• Cross-site request forgery - CVE-2015-7925;
• Weak RBAC controls - CVE-2015-7926;
• Stored cross-site scripting - CVE-2015-7927;
• Passwords not secured - CVE-2015-7928; and
• Post/get issues - CVE-2015-7929

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability.

A more detailed explanation of the individual vulnerabilities can be found on the eWON Security Enhancements page.

NOTE: This advisory has a much more detailed ‘Impact’ description than you find on most ICS-CERT advisories. Since these explanations would usually be the same for that given vulnerability across most platforms these explanations could be canned and served up with the appropriate vulnerability.

Motorola Advisory

This advisory describes twin vulnerabilities in the Motorola MOSCAD IP Gateway. The vulnerabilities were reported by Aditya K. Sood. Since support for this product was discontinued in 2012 there will be no patches or updates for this product.

The vulnerabilities are:

• Remote file inclusion - CVE-2015-7935; and
• Cross-site request forgery - CVE-2015-7936

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to perform actions with the permissions of a valid user.

Schneider Advisory

This advisory describes a buffer overflow vulnerability in the Schneider Modicon M340 PLC. The vulnerability was discovered by Nir Giller. Schneider has produced a firmware pathe to mitigate the vulnerability but there is no report that Giller has been provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability crash the device and perhaps run arbitrary code.


The Schneider Security Notification provides a very detailed explanation of how this vulnerability works.
 
/* Use this with templates/template-twocol.html */