Showing posts with label NCCIC-ICS Advisory. Show all posts
Showing posts with label NCCIC-ICS Advisory. Show all posts

Wednesday, July 22, 2026

Looking Back – 10-10-24 – 21 Advisories

Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today a blog post from October 10th, 2024, Review – 21 Advisories Published 10-10-24, made the list; actually, it has made the list for the last four days. This was a post about the CISA NCCIC-ICS control system security advisories for the Thursday after Cyber Tuesday. That is the reason for the 21 advisories being covered; including six for products from Rockwell and 13 for products from Siemens. Nothing unusual here, at least until I looked at the companion post over on CFSN Detailed Analysis. That post included the following comment about the Siemens SIMATIC S7-1500 CPUs advisory: 

“NOTE: This advisory is a good example of the reason that CISA no longer covers Siemens updates. Of the products listed as being affected by this vulnerability, 88 of them are currently listed on the Siemens Advisory as “Currently no fix is available”. I suspect that fixes for those products will be completed in batches with multiple updates needed to keep customers advised. There is no telling how long that will take, or how many updates will be required.” 

Looking back at the latest version of the Siemens Advisory, they published seven updates through October 14th, 2025. That left them with one product, SIMATIC S7-1500 Software Controller Linux V2, with no fix planned. That product is apparently no longer supported. I listed that update in the Bulk Updates – Siemens section of my Public ICS Disclosures – Week of 10-11-25 – Part 2 post. 

Thursday, December 6, 2018

Three Advisories Published – 12-06-18


Today the DHS NCCIC-ICS published two control system security advisories for products from Rockwell and GE. Additionally they published a medical device security advisory for products from Philips. The Rockwell advisory was originally published on the HSIN ICS-CERT library on November 6, 2018 to allow owner/operators to mitigate the vulnerability before it was made public on the NCCIC-ICS site.

I also think that it is worth mentioning that yesterday Siemens announced changes in the way they were publishing security advisories for their products.

Rockwell Advisory


This advisory describes a missing authentication for critical function vulnerability in the Rockwell MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules. The vulnerability was reported by David Noren. Rockwell reports that a newer firmware version mitigates the vulnerability. There is no indication that Noren was provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an unauthenticated attacker to modify system settings and cause a loss of communication between the device and the system.

I briefly discussed the Rockwell notice for this vulnerability in a post on November 10th, 2018.

GE Advisory


This advisory describes an XXE vulnerability in the GE Proficy GDS service. The vulnerability was reported by Vladimir Dashchenko of Kaspersky Lab. GE reports that a newer version mitigates the vulnerability. There is no indication that Dashchenko has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to initiate an OPC UA session and retrieve an arbitrary file.

The GE security notification for this vulnerability notes that this is an underlying OPC issue that was addressed in an OPC security bulletin.

Philips Advisory


This advisory describes an inadequate encryption strength vulnerability in the Philips Philips HealthSuite Health Android App. The vulnerability was reported by an unnamed (by Philips) security researcher. Philips has provided a generic workaround pending a release of a new version next quarter.

NCCIC-ICS reports that a relatively low-skilled attacker with physical access to the device to impact confidentiality and integrity of the product.

Siemens Announcement


Yesterday Siemens announced on TWITTER that they would be block publishing advisories for security vulnerabilities on the 2nd Tuesday of every month. This policy has obviously been in place for a couple of months (see here for example). They did note that: “In case we have reasons to publish advisories out of band (e.g. due to criticality), we will still do so.” We have also recently seen that.

There are some obvious plusses and minuses to this policy. On a personal note, it makes for some long blog post for these 2nd Tuesday releases. More realistically it helps owners with the making of decisions about patching when all of the advisories for a product release at the same time. Unfortunately, it may allow for longer effective 0-day openings when an attacker discovers a vulnerability that has been ‘fixed’ by Siemens, but the advisory has not been released. This is where we have to rely on Siemens’ judgement about criticality, but we have always had to do that anyway.

Two Advisories Published – 12-04-18


Earlier this week the DHS NCCIC-ICS published two control system security advisories for products from SpiderControl and Omron.

SpiderControl Advisory


This advisory describes a cross-site scripting vulnerability in the SpiderControl SCADA WebServer. The vulnerability was reported by Ismail Bulbul. SpiderControl has a new version that mitigates the vulnerability. There is no indication that Bulbul has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to execute JavaScript on the victim’s browser.

Omron Advisory


This advisory describes two vulnerabilities in the Omron CX-One application. The vulnerability was reported by Esteban Ruiz (mr_me) of Source Incite via the Zero Day Initiative. Omron has an update that mitigates the vulnerability. There are no indications that Ruiz has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-18993; and
Use after free - CVE-2018-18989

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to execute code under the privileges of the application.

ODD NOTE: This post was actually written on Tuesday night and I was sure that it had been posted, but it is surely not on the blog. I guess I am getting senile in my middle age.


Thursday, November 29, 2018

One Advisory Published – 11-29-18


Today the DHS NCCIC-ICS published a control system security advisory for products from INVT Electric.

The advisory describes two vulnerabilities in the INVT VT-Designer. The vulnerabilities were reported by Ariele Caltabiano (kimiya) via the Zero Day Initiative. No mitigation measures are currently available for these vulnerabilities.

The two reported vulnerabilities are:

• Deserialization of untrusted data - CVE-2018-18987; and
Heap-based buffer overflow - CVE-2018-18983

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities cause the program to crash and may allow remote code execution.

NOTE: It looks like another Chinese ICS company is not quite responsive to NCCIC-ICS vulnerability coordination efforts.

Tuesday, November 27, 2018

One Advisory is Published – 11-27-18


Today the DHS NCCIC-ICS published a control system security advisory for products from AVEVA.

This advisory describes an uncontrolled search path vulnerability in a third-party product used in the AVEVA Vijeo Citect, Citect SCADA product lines. The vulnerability is self-reported. The third party product is the Schneider Electric Software Update (SESU) software. This vulnerability was reported by Schneider earlier this month. The Schneider update mitigates this vulnerability in the AVEVA products.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to execute arbitrary code on the target system.

NOTE: The AVEVA advisory was addressed in my blog post on Saturday.

Tuesday, November 20, 2018

Two Advisories and One Update Published – 11-20-18


Today the DHS NCCIC-ICS published two control system security advisories for products from Schneider Electric and Teledyne DALSA. They also published an update for a previously published advisory for products from NUOO.

Schneider Advisory


This advisory describes an insufficient verification of data authenticity vulnerability in the Schneider Modicon M221 PLC. The vulnerability was reported by Eran Goldstein of CRITIFENCE. Schneider has provided workarounds to mitigate the vulnerability. There is no indication that Goldstein has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to cause a change of IPv4 configuration (IP address, mask, and gateway) when remotely connected to the device.

Teledyne Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Teledyne Sherlock machine vision software interface. The vulnerability was reported by Robert Hawes. Teledyne reports that newer versions mitigate the vulnerability. There is no indication that Hawes has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to crash the device being accessed; a buffer overflow condition may allow remote code execution.

NUOO Update


This update provides additional information on an advisory that was originally reported on October 11th, 2018. The update adds additional affected version information and three new vulnerabilities:

• Path traversal - CVE-2018-17934;
• Unrestricted upload of file of dangerous type - CVE-2018-17936; and
SQL injection - CVE-2018-18982

Thursday, October 25, 2018

Two Advisories Published


Today the DHS NCCIC-ICS published two control system security advisories for products from Advantech and GEOVAP.

Advantech Advisory


This advisory describes two vulnerabilities in the Advantech WebAccess application. The vulnerability was reported by Mat Powell via the Zero Day Initiative. Advantech has a new version (the same version that mitigated Tuesday’s vulnerabilities) that mitigates the vulnerabilities. There is no indication that Powell has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper Access Control - CVE-2018-17908; and
Stack-based buffer overflow - CVE-2018-17910

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow for arbitrary remote code execution.

NOTE: It is interesting that Matt has two Advantech advisories this week where he is the security researcher. Looking at the CVE numbers it looks like there was at least some delay between the reporting of the two sets of vulnerabilities. Not surprising that Advantech would fix all five vulnerabilities in the same version; finding vulnerabilities almost certainly takes less time than fixing them.

GEOVAP Advisory


This advisory describes a cross-site scripting vulnerability in the GEOVAP Reliance 4 SCADA/HMI. The vulnerability was reported by Ismail Mert AY AK. GEOVAP has a new version that mitigates the vulnerability. There is no indication that Ismail has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an unauthenticated attacker to use HTTP proxy to inject arbitrary Javascript in a specially crafted HTTP request that may reflect it back in the HTTP response.

Wednesday, October 24, 2018

Three Advisories Published


Yesterday the DHS NCCIC-ICS published three control system security advisories for products from Telecrane, GAIN Electronics and Advantech.

Telecrane Advisory


This advisory describes an authentication bypass by capture-replay vulnerability in the Telecrane F25 Series remote control. The vulnerability was reported by Jonathan Andersson, Philippe Z Lin, Akira Urano, Marco Balduzzi, Federico Maggi, Stephen Hilt, and Rainer Vosseler via the Zero Day Intiative. Telecrane has a new firmware version that mitigates the vulnerability. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to view commands, replay commands, control the device, or stop the device from running.

GAIN Advisory


This advisory describes three vulnerabilities in the Gain SAGA1-L series remote control. The vulnerability was reported by Marco Balduzzi, Philippe Z Lin, Federico Maggi, Jonathan Andersson, Urano Akira, Stephen Hilt, and Rainer Vosseler via ZDI. GAIN has a new firmware version that mitigates the vulnerability. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Authentication bypass by capture replay - CVE-2018-17903;
• Improper access control - CVE-2018-20783; and
Improper authentication - CVE-2018-17923

NCCIC-ICS reports that a relatively low-skilled attacker with access to an adjacent network could exploit the vulnerability to allow remote code execution and potentially delete the product’s firmware.

NOTE: It is interesting that these researchers have found similar capture and replay vulnerabilities in two different industrial remote control systems. As these wireless systems become more common will we continue to see this type of vulnerability?

Advantech Advisory


This advisory describes four vulnerabilities in the Advantech WebAccess application. The vulnerabilities were reported by Matt Powell via ZDI. Advantech has a new version available that mitigates the vulnerability. There is no indication that Powell has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-14816;
• External control of filename or path - CVE-2018-14820;
• Improper privilege management - CVE-2018-14828; and
• Path traversal - CVE-2018-14806

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to execute arbitrary code, access files and perform actions at a privileged level, or delete files on the system.

Friday, October 5, 2018

ICS Advisory and 2 Medical Device Advisories


Yesterday the DHS NCCIC-ICS published a controls system security advisory for products from WECON and two medical device security advisories for products from Change Healthcare and Carestream.

WECON Advisory


This advisory describes four vulnerabilities in the WECON PI Studio, a HMI project programmer. The vulnerabilities were reported by Mat Powell and Natnael Samson (Natti) via the Zero Day Initiative. WECON is working on mitigation measures.

The four reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-14818;
• Out-of-bounds write - CVE-2018-14810;
• Information exposure through XML external entity reference - CVE-2018-17889; and
Out-of-bounds read - CVE-2018-14814

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote code execution, execution of code in the context of an administrator, read past the end of an allocated object or allow an attacker to disclose sensitive information under the context of administrator.

Change Healthcare Advisory


This advisory describes an information exposure through error message vulnerability in the Change Healthcare PeerVue Web Server. The vulnerability was reported by Dan Regalado of Zingbox. Change Healthcare has a patch available to mitigate the vulnerability. There is no indication that Regalado has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker on an adjacent network could exploit the vulnerability to allow an attacker to obtain technical information about the PeerVue Web Server, allowing an attacker to target a system for attack.

Carestream Advisory


This advisory describes an information exposure through an error message vulnerability in the Carestream Vue RIS, a web-based radiology information system. The vulnerability was reported by Dan Regalado of Zingbox. Carestream has a new version that mitigates the vulnerability and has provided workarounds. There is no indication that Regalado has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker with access to the network can exploit the vulnerability to passively read traffic.

NOTE: It is always interesting to see a researcher who has found an unusual vulnerability in one system to then look for the same type vulnerability in other related systems. It makes me wonder if developers reading these advisories (and of course they do, right?) ask themselves if their systems have the same vulnerability.

Wednesday, October 3, 2018

Three Advisories and Three Updates Published


Yesterday the DHS NCCIC-ICS published three control system security advisories for products from Entes, GE and Delta Electronics. They also updated previously published advisories for products from Phillips, WECOM and ABB.

Entes Advisory


This advisory describes two vulnerabilities in the Entes EMG 12, an Ethernet Modbus Gateway. The vulnerability was reported by Can Demirel of Biznet Bilisim. Entes has a new firmware version that mitigates the vulnerabilities. There is no indication that Demirel has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper authentication - CVE-2018-14826; and
Information exposure in query strings in get request - CVE-2018-14822

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to gain unauthorized access and could allow the ability to change device configuration and settings.

GE Advisory


This advisory describes a heap based buffer overflow in the GE Communicator application. The vulnerability was reported by kimiya, working with iDefense Labs. Newer versions of the application mitigate the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to execute arbitrary code or create a denial-of-service condition.

Delta Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Delta ISPSoft, a PLC program development tool. The vulnerability was reported by Ariele Caltabiano (kimiya) via ZDI. Newer versions of the tool mitigate the vulnerability. There is no indication that kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to execute code under the context of the application.

Phillips Update


This update provides additional information on an advisory that was originally published on March 29th, 2018. The update adds the phrase “and/or system information” to the description provided for ‘information exposure’ vulnerabilities.

WECON Update


This update provides additional information on an advisory that was originally published on July 31st, 2018. The updated information includes:

• Two new vulnerabilities added, and
• Added a third reporting security researcher.

I would have normally expected this to be a separate advisory, but since the original advisory was based upon information provided via the Zero Day Initiative, I suspect that there was an issue on that end of the process that is being corrected here.

ABB Update


This update provides additional information on an advisory that was originally published on August 28th, 2018. The update provides new mitigation information.

Friday, September 28, 2018

4 ICS Advisories


Yesterday the DHS NCCIC-ICS (okay, I finally gave in; ICS-CERT is gone; please clean up the web site) published four control system security advisories for products from Delta Electronics, Fuji Electric (2) and Emerson.

Delta Advisory

This advisory describes an out-of-bounds read vulnerability in the Delta Industrial Automation PMSoft software development tool. The vulnerability was reported by Mat Powell via ZDI. Delta has an update available that mitigates the vulnerability. There is no indication that Powell has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to read confidential information.

FRENIC Advisory


This advisory describes three vulnerabilities in the Fuji FRENIC HVAC drive devices. The vulnerability was reported by Michael Flanders and Ghirmay Desta via ZDI. Fuji is working on mitigation measures.

The three reported vulnerabilities are:

• Buffer over-read - CVE-2018-14790;
• Out-of-bounds read - CVE-2018-14798; and
Stack-based buffer overflow - CVE-2018-14802

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow for arbitrary remote code execution affecting the availability of the device.

Alpha5 Advisory


This advisory describes two buffer-overflow vulnerabilities in the Fuji Alpha5 Smart Loader servo drive. The vulnerability was reported by Michael Flanders via ZDI. Fuji is working on mitigation measures.

The two reported vulnerabilities are:

• Classic buffer overflow - CVE-2018-14788; and
• Heap-based buffer overflow - CVE-2018-14794

NCCIC-ICS reports that a relatively low-skilled attacker could remotely use publicly available exploits to allow for arbitrary remote code execution on the device.

NOTE: It is disappointing that Fuji was not even able to provide workaround security measures for these two product lines. Does anyone know if NCCIC-ICS is still giving the 45-day grace period before publishing their advisories?

Emerson Advisory


This advisory describes two vulnerabilities in the Emerson AMS Device Manager. The vulnerabilities were reported by Sergey Temnikov of Kaspersky Lab and Emerson. Emerson has patches available to mitigate the vulnerabilities. There is no indication that Temnikov has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper access control - CVE-2018-14804; and
• Improper privilege management - CVE-2018-14808

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to

 
/* Use this with templates/template-twocol.html */