Showing posts with label OSVDB. Show all posts
Showing posts with label OSVDB. Show all posts

Wednesday, February 5, 2014

Twitversation – ICS Vulnerabilities on OSVDB

There was a very interesting twitversation today concerning the identification of industrial control system (ICS) vulnerabilities in the Open Sourced Vulnerability Database (OSVDB). The dialog was between Joel Langill (@SCADAhacker) and the folks who TWEET® for OSVDB®.  The new TWITTER® tools for following these types of extended conversation make it easier to understand the extended conversation, though it was interesting watching it unfold during the day.


Thanks Guys.

Tuesday, October 1, 2013

Two ICS Vulnerabilities that ICS-CERT Missed

Thanks to a Tweet® from Red Team SCADA I looked at the Open Source Vulnerability Database this morning and noticed that in the last two weeks there were two ICS vulnerabilities listed that have not yet been reported by ICS-CERT. Those are:

• An Triangle Research Nano-10 PLC vulnerability; and
• An Invensys Wonderware InTouch vulnerability

Both of these are listed as coordinated vulnerabilities with mitigation measures available from the vendors.


I don’t suppose that we will hear anything now until the shutdown is lifted. It does beg the question, do we need ICS-CERT’s reporting?
 
/* Use this with templates/template-twocol.html */