Showing posts with label OPTO 22. Show all posts
Showing posts with label OPTO 22. Show all posts

Tuesday, November 25, 2025

Review – 6 Advisories and 1 Update Published – 11-25-25

Today CISA’s NCCIC-ICS published five control system security advisories for products from SiRcom, Festo, Opto 22, Zenitel, Rockwell, and Ashlar-Vellum. They also updated an advisory for products from Mitsubishi.

Advisories

SiRcom Advisory - This advisory describes a missing authentication for critical function vulnerability in the SiRcom SMART Alert (SiSA) central control system.

Festo Advisory - This advisory discusses two vulnerabilities in the multiple Festo product lines.

NOTE: I briefly discussed these vulnerabilities on December 3rd, 2022.

Opto 22 Advisory - This advisory describes an exposure of sensitive data through meta data vulnerability in the Opto 22 groov View product line.

Zenitel Advisory - This advisory describes five vulnerabilities in the Zenitel TCIV-3+ IP video intercom.

Rockwell Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Rockwell Arena Simulation product.

NOTE: I briefly discussed this vulnerability on November 16th, 2025.

Ashlar-Vellum Advisory - This advisory describes two vulnerabilities in multiple Ashlar-Vellum products.

Updates

Mitsubishi Update - This update provides additional information on the FA Engineering Software advisory that was originally published on December 5th, 2022, and most recently updated on June 29th, 2023.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-1-update-published-b5e - subscription required.

Thursday, November 20, 2025

Review – 6 Advisories Published – 11-20-25

Today CISA’s NCCIC-ICS published six control system security advisories for products from Emerson, Festo (2), Opto 22, ICAM365 and Automated Logic.

Advisories

Emerson Advisory - This advisory discusses a stack-based buffer overflow vulnerability in the Emerson Appleton UPSMON-PRO.

Festo Advisory #1 - This advisory discusses an improper input validation vulnerability in the Festo Didactic products.

Festo Advisory #2 - This advisory describes a hidden functionality vulnerability in the Festo MSE6-C2M-5000 product line.

NOTE: I briefly discussed this vulnerability on September 9th, 2023. CERT-VDE updated the Festo advisory (administrative and format changes) on October 1st, 2025.

Opto 22 Advisory - This advisory describes an OS command injection vulnerability in the Opto 22 GRV Programmable Logic Controllers.

ICAM365 Advisory - This advisory describes two missing authentication for critical function vulnerabilities in the ICAM365 ROBOT PT Camera P201 and Night Vision Camera QC021.

Automated Logic Advisory - This advisory describes two vulnerabilities in multiple Automated Logic (and Carrier) products.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published-11-20-25 - subscription required.

Thursday, August 24, 2023

Review – Six Advisories Published – 8-24-23

Today, CISA’s NCCIC-ICS published six control system security advisories for products from Rockwell Automation, CODESYS (3), Opto 22, and KNX Association.

Advisories

Rockwell Advisory - This advisory discusses an out-of-bounds write vulnerability in select Input/Output Modules from Rockwell.

CODESYS Advisory #1 - This advisory describes an insufficient verification of data authenticity vulnerability in the CODESYS Development System.

CODESYS Advisory #2 - This advisory describes an insufficient verification of data authenticity vulnerability in the CODESYS Development System.

CODESYS Advisory #3 - This advisory describes an uncontrolled search path element vulnerability in the CODESYS Development System.

Opto 22 Advisory - This advisory describes 5 vulnerabilities in the Opto 22 SNAP PAC S1 product.

KNX Protocol Advisory - This advisory describes an overly restrictive account lockout mechanism vulnerability in the KNX Protocol.

 

For more details about these advisories, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/six-advisories-published-8-24-23 - subscription required.

Thursday, May 14, 2020

2 Advisories and 1 Update Published – 5-14-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Emerson and Opto 22. They also updated a previously issued advisory for products from 3S.

Emerson Advisory


This advisory describes an improper access control vulnerability in the Emerson WirelessHART Gateways. The vulnerability is self-reported. Emerson has updated firmware that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to disable the internal gateway firewall. Once the gateway's firewall is disabled, a malicious user could issue specific commands to the gateway, which could then be forwarded on to the end user's wireless devices.

Opto 22 Advisory


This advisory describes five vulnerabilities in the  Opto 22 SoftPAC Project virtual PLC. The vulnerabilities were reported by Mashav Sapir of Claroty. Opto 22 has a new version that mitigates the vulnerabilities. There is no indication that Sapir was provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• External control of file name or path - CVE-2020-12042,
• Improper verification of cryptographic signature - CVE-2020-12046,
• Improper access control - CVE-2020-10612,
• Uncontrolled search path element - CVE-2020-10616, and
• Improper authorization - CVE-2020-10620

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow arbitrary file write access with system access, start or stop service, allow remote code execution, and limit system availability.

3S Update


This update provides additional information on an advisory that was originally published on August 1st, 2019. The new information includes a link to a new version that mitigates the vulnerability. The publication of the new version was originally projected for February 2020.

Thursday, May 7, 2015

ICS-CERT Publishes Rockwell Advisory

This morning the DHS ICS-CERT published an advisory for a stack-based buffer overflow vulnerability in Rockwell Automations OPCTest.exe application in their RSLinx Classic. The vulnerability was reported by Ivan Sanchez of WiseSecurity Team. Rockwell has produced a new version that mitigates the vulnerability but there is no indication that Sanchez was given the opportunity to verify the efficacy of the fix. This advisory was originally released on the US CERT secure portal on April 21st, 2015.

ICS-CERT reports that it would take a relatively skilled attacker to execute a social engineering attack to get an authorized user to load the specially crafted file. The Rockwell advisory for this vulnerability is only available to registered users.

It is interesting that this looks like exactly like the same stack-based buffer overflow vulnerability reported last week in the Opto 22 advisory that OPTO blamed on the Rockwell OPCTest.exe application that they used in their device. There are different CVE numbers for the two vulnerabilities, but they were both discovered by Sanchez. This may also explain why the Opto 22 advisory was not issued until April 30th (nine days after the Rockwell alert was released to the Secure Portal) when Opto published their advisory on April 7th. A lot more people use the Rockwell equipment.


BTW: How many other vendors are using the same OPCTest.exe application from Rockwell?

Thursday, April 30, 2015

ICS-CERT Publishes OPTO 22 Advisory

This afternoon the DHS ICS-CERT published an advisory for twin buffer overflow vulnerabilities in OPTO 22 products. The vulnerabilities were reported by Ivan Sanchez from Nullcode Team. OPTO has released new versions that mitigate the vulnerabilities and Sanchez has been able to verify the efficacy of the fix.

The twin vulnerabilities are:

∙ Heap-based buffer overflow, CVE-2015-1006; and
∙ Stack-based buffer overflow, CVE-2015-1007.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the heap-based overflow vulnerability. The Stack-based overflow would require a social engineering attack before the vulnerability could be remotely exploited.

OPTO reports that the stack-based overflow vulnerability actually resides in a Rockwell OPC Test Client application (no version number is provided). The newer, unaffected OPTO 22 products use a ProSys Test Client application instead. Owners can obtain a copy of the ProSys Test Client from the OPTO 22 FTP site if they do not want to install the updated version of the PAC Project applications.


This is apparently just another case of a vendor using another vendor’s files without understanding the included vulnerabilities. It would be interesting if someone (ICS-CERT MAYBE) would look to see how many other systems were using the vulnerable Rockwell OPC Test Client.

 
/* Use this with templates/template-twocol.html */