Showing posts with label OMNTEC. Show all posts
Showing posts with label OMNTEC. Show all posts

Thursday, October 24, 2024

Review – 3 Advisories and 1 Update Published – 10-24-24

Today, CISA’s NCCIC-ICS published three control system security advisories for products from Deep Sea Electronics, iniNet Solutions and VIMESA. They also updated an advisory for products from OMNTEC.

Advisories

Deep Sea Advisory - This advisory describes a missing authentication for critical function vulnerability in the Deep Sea DSE855 ethernet communications device.

iniNet Advisory - This advisory describes a path traversal vulnerability in the iniNet SpiderControl SCADA PC HMI Editor software management platform.

VIMESA Advisory - This advisory describes an improper access control vulnerability in the VIMESA VHF/FM Transmitter Blue Plus.

Updates

OMNTEC Update - This update provides additional information on the Proteus Tank Monitoring advisory that was originally published on September 24th, 2024.

 

For more details about these advisories, including a down-the-rabbit-hole look at additional Deep Sea vulnerabilities, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-and-1-update-published-81e - subscription required.

Tuesday, September 24, 2024

Review – 6 Advisories and 2 Updates Published – 9-24-24

Today, CISA’s NCCIC-ICS published six control system security advisories for products from Moxa, OMNTEC, Dover Fueling Solutions, Franklin Fueling Solutions, Alisonic, and OPW Fuel Management Solutions. They also updated advisories for products from Interpeak and Uniview.

Advisories

Moxa Advisory - This advisory describes three vulnerabilities in the Moxa MXview One products.

OMNTEC Advisory - This advisory describes a missing authentication for critical function vulnerability in the OMNTEC Proteus Tank Monitoring product.

Dover Advisory - This advisory describes six vulnerabilities in the DFS ProGauge MAGLINK LX Consoles.

Franklin Advisory - This advisory describes an absolute path traversal vulnerability in the Franklin TS-550 EVO automatic tank gauge.

Alisonic Advisory - This advisory describes an SQL injection vulnerability in the Alisonic Sibylla automated tank gauge.

OPW Advisory - This advisory describes a missing authentication for critical function vulnerability in the OPW SiteSentinel product.

NOTE: The vulnerabilities for the five fuel handling equipment advisories were reported to CISA by Pedro Umbelino of BitSight; that report is worth reading.

Updates

Interpeak Update - This update provides additional information on the Interpeak TCP/IP Stack advisory that was originally published on October 1st, 2019 and most recently updated on May 12th, 2020.

Uniview Update - This update provides additional information on the Uniview NVR301-04S2-P4 advisory that was originally published on June 4th, 2024.

 

For more information on these advisories, including links to a researcher report and a down-the-rabbit-hole look at relay rapid cycling attacks, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-2-updates-published - subscription required.

 
/* Use this with templates/template-twocol.html */