Showing posts with label Ovarro. Show all posts
Showing posts with label Ovarro. Show all posts

Thursday, June 29, 2023

Review – 5 Advisories and 4 Updates Published – 6-29-23

Today, CISA’s NCCIC-ICS published four control system security advisories for products from Mitsubishi Electric, Ovarro, Schneider, and Delta Electronics. They published a medical device security advisory for products from Medtronic. They also updated four advisories for products from Enphase, Mitsubishi (2), and Rockwell Automation.

Advisories

Mitsubishi Advisory - This advisory describes an authentication bypass by capture replay vulnerability in the Mitsubishi MELSEC-F Series products if they are used with ethernet communication special adapter FX3U-ENET-ADP or ethernet communication block FX3U-ENET(-L).

Ovarro Advisory - This advisory describes six vulnerabilities for the Ovarro TBox RTUs.

Schneider Advisory - This advisory describes a control injection vulnerability in the Schneider EcoStruxure Operator Terminal Expert.

Delta Advisory - This advisory describes three vulnerabilities in the Delta InfraSuite Device Master product.

Medtronic Advisory - This advisory describes a deserialization of untrusted data vulnerability in the Medtronic Paceart Optima System.

Updates

Enphase Update - This update provides additional information on an advisory that was originally published on June 20th, 2023 (Not June 22nd).

Mitsubishi Update #1 - This update provides additional information on an advisory that was originally published on December 6th, 2022 and most recently updated on June 1st, 2023.

Mitsubishi Update #2 - This update provides additional information on an advisory that was originally published on September 1st, 2020 and most recently updated on September 22nd, 2022 (Not September 30th).

Rockwell Update - This update provides additional information on an advisory that was originally published on April 30th, 2019.

 

For additional information on these advisories, including a down-the-rabbit-hole look at the Enphase vulnerability response – see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-4-updates-published - subscription required.

Saturday, September 3, 2022

Review – Public ICS Disclosure – Week of 8-27-22

This week we have twelve vendor disclosures from Aruba, Contec, GE Grid Solutions (2), HPE (3), Johnson Controls, Ovarro (2), Rockwell Automation, and Yokogawa. We also have three vendor updates from Mitsubishi, QNAP, and VMware.

Aruba Advisory - Aruba published an advisory that describes twelve vulnerabilities in their AOS-CX switches.

Contec Advisory - JP-CERT published an advisory that describes two vulnerabilities in the Contec FLEXLAN FX3000 wireless LAN.

GE Grid Advisory #1 - GE Grid published an advisory that describes a vulnerability in their Reason RT430/RT434 – GPS/GNSS Precision Clocks.

GE Grid Advisory #2 - GE Grid published an advisory that describes a vulnerability in their Reason RT431 - Time Code Generator.

HPE Advisory #1 - HPE published an advisory that discusses a privilege escalation vulnerability in their ProLiant Apollo, XL Servers.

HPE Advisory #2 - HPE published an advisory that discusses an information disclosure vulnerability in their HPE Apollo, XL Servers.

HPE Advisory #3 - HPE published an advisory that discusses an privilege escalation vulnerability in their Superdome Flex 280 Servers.

Johnson Controls Advisory - Johnson Controls published an advisory that describes a command injection vulnerability in their  iSTAR Ultra door controller.

Ovarro Advisory #1 - Ovarro published an advisory that discusses four vulnerabilities in their Kingfisher Toolbox Plus software.

Ovarro Advisory #2 - Ovarro published an advisory that discusses four vulnerabilities in their Seprol range of S2000 WITS RTUs.

Rockwell Advisory - Rockwell published an advisory that discusses two vulnerabilities in their KEPServer Enterprise.

Yokogawa Advisory - Yokogawa published an advisory that discusses an insufficient verification of data authenticity vulnerability in their STARDOM controller.

NOTE: This is an OT:ICEFALL vulnerability, the first that I recall seeing being reported as a third-party vulnerability.

Mitsubishi Update - Mitsubishi published an update for their GENESIS64TM and MC Works64 advisory that was originally published on July 19th, 2022.

NOTE: NCCIC-ICS did not update their advisory (ICSA-22-202-04) for this information.

QNAP Update - QNAP published an update for their Samba advisory that was originally published on August 16th, 2022.

VMware Update - VMware published an update for their VMware Tools advisory that was originally published on August 23rd, 2022.

 

For more details about these disclosures, including links to third-party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-8-27 - subscription required.

Thursday, September 23, 2021

Review – 2 Advisories and 1 Update Published – 9-23-21

Today CISA’s NCCIC-ICS published two control system security advisories for products from Trane. They also updated an advisory for products from Ovarro.

Tracer Advisory - This advisory describes a code injection vulnerability in the Trane Tracer building automation controllers.

Symbio Advisory - This advisory describes a code injection vulnerability in the Trane Symbio 700 and Symbio 800 controllers.

Ovarro Update - This update provides additional information on an advisory that was originally published on March 23, 2021.

For more details on these advisories and the update, including some interesting oddities about the update, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-1-update-published-650 - subscription required.

Saturday, September 18, 2021

Review - Public ICS Disclosures – Week of 9-11-21 – Part 1

This week we have nine vendor disclosures from BD, HPE, Johnson and Johnson, Milestone, Moxa (2), and Ovarro (3). We have two updates from Mitsubishi. We also have four vendor reports from Tenable about vulnerabilities in GPS systems. Finally, we have an exploit for Geutebruck cameras.

BD Advisory - BD published an advisory discussing the BadAlloc vulnerabilities.

HPE Advisory - HPE published an advisory describing six vulnerabilities in their SAN Switches with Brocade Fabric OS.

Johnson and Johnson Advisory - Johnson and Johnson published an advisory discussing the PrintNightmare vulnerability.

Milestone Advisory - Milestone published an advisory describing an unsecured credential storage vulnerability in their XProtect® VMS product.

Moxa Advisory #1 - Moxa published an advisory describing nine vulnerabilities in their MXview Series Network Management Software.

Moxa Advisory #2 - Moxa published an advisory describing two uncontrolled resource vulnerabilities in their MGate MB3180/MB3280/MB3480 Series Protocol Gateways.

Ovarro Advisory #1 - Ovarro published an advisory describing a classic buffer overflow vulnerability in their MS-CPU32-S2 and LT2 products.

Ovarro Advisory #2 - Ovarro published an advisory describing a path traversal (?) vulnerability in their TWinSoft product.

Ovarro Advisory #3 - Ovarro published an advisory describing a weak encryption vulnerability in their TWinSoft product.

Mitsubishi Update #1 - Mitsubishi published an update for their WEB Functions of Air Conditioning Systems advisory that was originally published on July 1st, 2021.

Mitsubishi Update #2 - Mitsubishi published an update for their Denial-of-Service Vulnerability in Multiple Air Conditioning Systems advisory that was originally published on July 1st, 2021.

GPS Report #1 - Tenable published a report on five vulnerabilities in the LandAirSea Silver Cloud web site.

GPS Report #2 - Tenable published a report describing five vulnerabilities in the Spytec GPS platform web site.

GPS Report #3 - Tenable published a report describing 12 vulnerabilities in the Optimus GPS platform web site.

GPS Report #4 - Tenable published a report describing three vulnerabilities in the Tracki/Trackimo GPS platform web site.

Geutebruck Exploit - Titouan Lazard and Ibrahim Ayadhi have published a Metasploit module for a buffer overflow vulnerability in the Geutebruck G-Cam EEC-2xxx and G-Code EBC-21xx, EFD-22xx, ETHC-22xx, and EWPC-22xx devices.

For more details on these advisories and reports, including links to third party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-7ed - subscription required.

Saturday, March 27, 2021

Public ICS Disclosures – Week of 3-20-21

This week we have 27 vendor disclosures from BD (3), Bosch, TRUMPF, GE Grid Systems (19), Mitsubishi Electric, Moxa, and Rockwell Automation. We have a researcher report for products from Ovarro. Finally, there were two exploits published for products from VMWare and Advantech.

BD Advisories

BD published patch advisories for the below listed products. These are the 3rd party patches that have been tested by BD on the listed products.

BD Care Coordination Engine (CCE),

Security Patches: BD Pyxis™ Products, and

Security Patches: BD Alaris™ Systems Manager

Bosch Advisories

Bosch published an advisory describing seven uncontrolled search path element vulnerabilities in multiple Bosch products. The vulnerabilities were reported by Nir Yehoshua, Dhiraj Mishra, and Eli Paz of CyberArk. Bosch has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

TRUMPF Advisory

CERT-VDE published an advisory describing an out-of-bounds write vulnerability in the TRUMPF TruControl laser control software. The vulnerability was reported by Qualys Research Labs. TRUMPF has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

GE Grid Advisories

GE published advisories for the below listed products. These may be updates for previously issued advisories, but only GE customers can access the advisories, so I do not know for sure:

C30 Controller

C60 Breaker Management Relay

C70 Capacitor Bank Protection and Control System

B30 Bus Differential Relay

B90 Bus Differential System

F35 Multiple Feeder Management Relay

F60 Feeder Management Relay

G30 Generator Management Relay

G60 Generator Management Relay

L30 Line Current Differential Relay

L60 Line Phase Comparison Relay

L90 Line Current Differential Relay

M60 Motor Management Relay

D30 Line Distance Relay

D60 Line Distance Relay

N60 Network Stability and Synchrophasor Measurement System

T35 Transformer Management Relay

T60 Transformer Management Relay

UR Family of Protection Relays

Mitsubishi Advisory

Mitsubishi published an advisory discussing a heap-based buffer overflow vulnerability in a third-party TCP/IP stack (Treck). Mitsubishi is providing generic workarounds to mitigate the vulnerability.

NOTE: Mitsubishi is only reporting one of the four TCP/IP stack vulnerabilities reported by Treck.

Moxa Advisory

Moxa published an advisory describing ten vulnerabilities in their EDR-810 Series Security Routers. The vulnerabilities were reported by the Russian BDU FSTEC. Moxa has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The ten reported vulnerabilities are:

• Improper Input Validation - CVE-2014-2284 (Linux ICMP-MIB implementation),

• Resource Management Errors - CVE-2015-1788 (Open SSL),

Improper Restriction of Operations within the Bounds of a Memory Buffer - CVE-2016-10012 (Open SSH),

Exposure of Sensitive Information to an Unauthorized Actor - CVE-2015-3195 (Open SSL),

Improper Input Validation - CVE-2016-6515 (open SSH, Exploit),

Improper Input Validation - CVE-2017-17562 (EmbedThis, Exploit),

Cryptographic Issues - CVE-2013-0169 (TLS Protocol),

• Permissions, Privileges, and Access Controls - CVE-2013-1813 (BusyBox, Exploit), and

• Numeric Errors - CVE-2010-2156 (ISC DHP, Exploit)

Rockwell Advisory

Rockwell published an advisory discussing eight vulnerabilities in their Stratix Switches. These are third-party (Cisco) vulnerabilities. Rockwell has new versions that mitigate the vulnerability.

The eight reported vulnerabilities are:

• Privilege escalation (2) - CVE-2021-1392 and CVE-2021-1442,

• Cross-site web socket hijacking - CVE-2021-1403,

• Denial of service (3) - CVE-2021-1352, CVE-2021-1220, and CVE-2021- 1356, and

• Command injection (2) - CVE-2021-1452 and CVE-2021-1443,

NOTE: Links above are to the Cisco advisories.l

Ovarro Report

Claroty published a report describing the five vulnerabilities that were reported earlier this week in the Ovarro TBox RTUs.

VMWare Exploit

WVU published a Metasploit module for a remote code execution vulnerability in the VMware View Planner. This vulnerability was previously reported by VMware.

Advantech Exploit

Spencer McIntyre published a Metasploit module for a missing authentication for critical function vulnerability in the Advantech iView. This vulnerability was previously reported by Advantech.

Tuesday, March 23, 2021

4 Advisories and 2 Updates Published – 3-23-21

Today the CISA NCCIC-ICS published four control system security advisories for products from Ovarro, GE Grid Solutions (2), and Weintek. They also published two updates for products from Rockwell Automation.

Ovarro Advisory

This advisory describes five vulnerabilities in the Ovarro TBox remote terminal units. The vulnerabilities were reported by Uri Katz of Claroty. Ovarro has new versions that mitigate the vulenrabilities. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Code injection - CVE-2021-22646,

• Incorrect permission assignment for critical resource - CVE-2021-22648,

• Uncontrolled resource consumption - CVE-2021-22642,

• Insufficiently protected credentials - CVE-2021-22640, and

• Use of hard-coded cryptographic key - CVE-2021-22644

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to result in remote code execution, which may cause a denial-of-service condition.

NOTE: This advisory was originally published on February 23rd, 2021 on the restricted HSIN ICS library. This limited disclosure allows critical infrastructure additional time to implement mitigation measures before the vulnerability becomes public. NCCIC-ICS does not use this limited distribution very often, the last time was on July 21st, 2020 and the time before that was on November 6th, 2018.

Reason DR60 Advisory

This advisory describes three vulnerabilities in the GE Reason DR60 digital fault recorder products. The vulnerabilities were reported by Thales OT Security Team. GE has a firmware update that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Use of hard-coded password - CVE-2021-27440,

• Code injection - CVE-2021-27438, and

• Execution with unnecessary privileges - CVE-2021-27454

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to  allow an attacker to take full control of the digital fault recorder (DFR), remotely execute code, or escalate privileges.

MU320E Advisory

This advisory describes three vulnerabilities in the GE MU320E product. The vulnerabilities were reported by Tom Westenberg of Thales UK. GE has a new firmware version that mitigates the vulnerabilities. There is no indication that Westenberg has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Use of hard-coded password - CVE-2021-27452,

• Execution with unnecessary privileges - CVE-2021-27448, and

• Inadequate encryption strength - CVE-2021-27450

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an attacker to escalate unnecessary privileges and use hard-coded credentials to take control of the device.

NOTE: Neither of these advisories appear to address any of the 17 advisories published by GE on March 17th, 2021 that I briefly mentioned Saturday.

Weintek Advisory

This advisory describes three vulnerabilities in the Weintek cMT product. The vulnerabilities were reported by Marcin Dudek from CERT.PL. Weintek has upgrades that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Code injection - CVE-2021-27446,

• Improper access control - CVE-2021-27444, and

• Cross-site scripting - CVE-2021-27442

NCCIC-ICS reports

MicroLogix 1400 Update

This update provides additional information for an advisory that was originally published on February 2nd, 2021. The new information includes:

• Adding the names of the researchers from the Veermata Jijabai Technological Institute that reported the vulnerability, and

• Adding a link to the Rockwell advisory.

CompactLogix 5370 Update

This update provides additional information for an advisory that was originally published on March 2nd, 2021. The new information includes adding a link to the Rockwell Advisory.

 
/* Use this with templates/template-twocol.html */