Showing posts with label Open Automation. Show all posts
Showing posts with label Open Automation. Show all posts

Tuesday, December 3, 2024

Review – 6 Advisories and 2 Updates Published – 12-3-24

Today CISA’s NCCIC-ICS published six control system security advisories for products from Fuji Electric (2), ICONICS (and Mitsubishi), Open Automation, Siemens, and Ruijie. They also updated advisories for products from ICONICS (and Mitsubishi) and ETIC.

Advisories

Fuji Advisory #1 - This advisory describes five vulnerabilities in the Fuji Electric Tellus Lite V-Simulator.

Fuji Advisory #2 - This advisory describes 10 out-of-bounds write vulnerabilities in the Fuji Electric Monitouch V-SFT screen configuration software.

ICONICS Advisory - This advisory describes three vulnerabilities in the ICONICS GENESIS64 and Mitsubishi MC Works64 products.

Open Automation Advisory - This advisory describes an incorrect execution-assigned privileges vulnerability in the Open Automation Software package.

Siemens Advisory - This advisory discusses four vulnerabilities (two listed in CISA’s Known Exploited Vulnerabilities catalog) in the Siemens RUGGEDCOM APE1808 products.

Ruijie Advisory - This advisory describes ten vulnerabilities in the Ruijie Reyee OS.

Updates

ICONICS Update - This update provides additional information on the ICONICS and Mitsubishi advisory that was originally published on July 2nd, 2024.

ETIC Update - This update provides additional information on the Remote Access Server advisory that was originally published on November 3, 2022, and most recently updated on July 27th, 2023.

 

For more information on these advisories, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-2-updates-published-ee4 - subscription required.

Saturday, May 28, 2022

Review – Public ICS Disclosures – Week of 5-21-22 – Part 1

This has been a fairly busy disclosure week which will require two parts to list completely. For Part 1 we have seventeen vendor disclosures from ABB, CONTEC, Fuji Electric (2), HPE (2), Meinberg, Open Automation, QNAP (2), VMware (2), Western Digital, Xylem (3), and Yokogawa.

ABB Advisory - ABB published an advisory that describes two vulnerabilities in their e-Design product.

CONTEC Advisory - JP CERT published an advisory that describes an OS command injection vulnerability (with publicly available exploit) in the CONTEC SolarView Compact.

Fuji Advisory #1 - JP CERT published an advisory that describes five vulnerabilities in the Fuji V-SFT product.

Fuji Advisory #2 - JP CERT published an advisory that describes three vulnerabilities in the Fuji V-SFT, V-Server and V-Server Lite products.

HPE Advisory #1 - HPE published an advisory that describes an escalation of privilege vulnerability in their Version Control Repository Manager Installer.

HPE Advisory #2 - HPE published an advisory that discusses the Psychic Signatures vulnerability in their IceWall Products.

NOTE: This is going to be an interesting third-party vulnerability. The researcher report is well worth reading.

Meinberg Advisory - Meinberg published an advisory that discusses two vulnerabilities (one with publicly available exploit) in their LANTIME Firmware.

Open Automation Advisory - Incibe CERT published an advisory that describes eight vulnerabilities in the Open Automation Software OAS Platform.

QNAP Advisory #1 - QNAP published an advisory that describes a cross-site request forgery vulnerability in their NAS running Proxy Server.

QNAP Advisory #2 - QNAP published an advisory that discusses four OpenSSL vulnerabilities.

VMware Advisory #1 - VMware published an advisory that describes an XML external entity vulnerability (with publicly available exploit) in their VMware Tools for Windows product.

VMware advisory #2 - VMware published an advisory that describes two vulnerabilities in their VMware Workspace ONE Access, Identity Manager and vRealize Automation products.

Western Digital Advisory - Western Digital published an advisory that discusses an improper authentication vulnerability in their My Cloud OS 5 Firmware.

Xylem Advisory #1 - Xylem published an advisory that discusses the CISA Emergency Directive (ED) 22-03.

Xylem Advisory #2 - Xylem published an advisory that discusses an improper verification of cryptographic signature vulnerability in their Xylem Edge Gateway.

Xylem Advisory #3 - Xylem published an advisory that describes an improper authentication vulnerability in the Sensus Analytics Login Service of their Utility Portal application.

Yokogawa Advisory - Yokogawa published an advisory that describes a violation of secure design principles vulnerability in their CAMS for HIS products.

 

For more details on these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-017 - subscription required.

Thursday, December 10, 2015

ICS-CERT Updates XZERES Advisory and Publishes 2 New Advisories

This afternoon the DHS ICS-CERT updated the XZERES advisory published earlier this week. It also published controls system advisories for products from Open Automation and Advantech.

XZERES Update

This update revises the description of the potential impact of the vulnerability. Originally it said that: “Successful exploitation of this vulnerability allows the ID to be retrieved from the browser and will allow the default ID to be changed.” Now it reads: “Successful exploitation of this vulnerability could allow the injection of malicious script.” That is a significant change in impact.

The description of the cross-site scripting vulnerability has also been changed. Originally it said: “The 442SR OS recognizes both the POST and GET methods for data input. By using the GET method, an attacker may retrieve the ID from the browser and will allow the default user ID to be changed. The default user has admin rights to the entire system.” It now reads: “The 442SR OS does not provide adequate input validation. This could allow malicious script to be injected into the program.” The CVSS v3 base score remains 9.8.

NOTE: This update is listed on the ICS-CERT landing page, but just because the original would still be there and the change was made to the original listing. I still recommend following @ICSCERT on TWITTER to get notified of these updates.

Open Automation Advisory

This advisory describes an uncontrolled search path element vulnerability in the Open Automation Software OPC Systems.NET application. The vulnerability was reported by Ivan Sanchez from Nullcode Team. ICS-CERT reports that Open Automation Software does not intend to patch the vulnerability at this time.

ICS-CERT reports that a social engineering attack is required to exploit this DLL hijacking vulnerability. A successful exploit would give the attacker access at the same privilege level as the application.

ICS-CERT reports that: “Open Automation Software has passed the researcher information to its support team to assist customers in the event that they encounter this vulnerability.”

Advantech Advisory

This advisory describes three vulnerabilities in the Advantech EKI-132x platform devices. This was an uncoordinated disclosure made by Tod Beardsley of Rapid7. Advantech plans to release updated firmware to fix these vulnerabilities by the end of this month.

The three vulnerabilities are:

• OS command injection (Shellshock) - CVE-2014-6271;
• Improper restriction of operations within the bounds of a memory buffer (Heartbleed) - CVE-2014-0160; and
• Improper restriction of operations within the bounds of a memory buffer - CVE-2012-2152

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities using publicly available exploit code to execute arbitrary code, to obtain private keys, or to impersonate the authenticated user and perform a man-in-the-middle attack.


NOTE: This is the ‘missing’ advisory that I reported on last week. Interestingly there is no mention in the advisory of the apparent fact that these vulnerabilities worked their way back into the system as part of the update to fix an earlier vulnerability.
 
/* Use this with templates/template-twocol.html */