Showing posts with label PerFact. Show all posts
Showing posts with label PerFact. Show all posts

Saturday, November 27, 2021

Review – Public ICS Disclosures – Week of 11-20-21

This week we have ten vendor disclosures from Advantech, Hitachi, Hitachi Energy (2), Moxa (2), QNAP (2), and VMware. There is also an update from Mitsubishi. Additionally, we have two researcher reports for vulnerabilities for products from PerFact and Philips. Finally, we have an exploit for a product from ModbusTools.

Advantech Advisory - Advantech published an advisory describing five sets of vulnerabilities (each set corresponding to a separate Talos report containing multiple vulnerabilities) in their R-SeeNet application.

Hitachi Advisory - Hitachi published an advisory discussing 24 vulnerabilities in their Disk Array Systems.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory describing two vulnerabilities in their XMC20 product.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory describing two vulnerabilities in their FOX61x product.

Moxa Advisory #1 - Moxa published an advisory describing eleven vulnerabilities in their ioLogik E2200 Series Controllers and I/Os.

Moxa Advisory #2 - Moxa published an advisory describing three vulnerabilities in their NPort IAW5000A-I/O Series Servers.

QNAP Advisory #1 - QNAP published an advisory describing an improper authentication vulnerability in their VS Series NVR.

QNAP Advisory #2 - QNAP published an advisory describing a command injection vulnerability in their VS Series NVR.

VMware Advisory - VMware published an advisory describing two vulnerabilities in their vCenter Server.

Mitsubishi Update - Mitsubishi published an update for their GENESIS64 and MC Works64 advisory that was originally published on October 21st, 2021.

PerFact Report - Claroty published a report describing vulnerabilities in VPN products in use in industrial applications including a previously unpublished server-side request forgery vulnerability in products from PerFact.

Philips Report - Nozomi Networks published a report describing five vulnerabilities in patient monitoring products from Philips.

ModbusTools Exploit - Yehia Elghaly published an exploit for an improper restriction of operations within the bounds of a memory buffer vulnerabilty in the Modbus Slave tool from ModbusTools.

For more details on these advisories, updates, reports and exploits, including links to supporting third-party vulnerabilities, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-857 - subscription required.

Thursday, February 25, 2021

4 Advisories Published – 2-25-21

Today the CISA NCCIC-ICS published four control system security advisories for products from ProSoft Technology, Rockwell Automation, Fatek, and PerFact.

ProSoft Advisory

This advisory describes a permissions, privileges, and access controls vulnerability in the ProSoft industrial cellular gateways. The vulnerability was reported by Maxim Rupp. ProSoft has a new firmware version that mitigates the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to change the current user’s password and alter device configurations.

Note: Interesting Twitversation about this advisory today.

Rockwell Advisory

This advisory describes an insufficiently protected credentials vulnerability in the Rockwell  Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers.  The vulnerability was independently reported by Lab. of Information Systems Security Assurance, Kaspersky, and Claroty. Rockwell describes compensating controls to mitigate the vulnerability. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote unauthenticated attacker to bypass the verification mechanism and connect with Logix controllers. Additionally, this vulnerability could enable an unauthorized third-party tool to alter the controller’s configuration and/or application code.

Fatek Advisory

This advisory describes five vulnerabilities in the Fatek FvDesigner software tool. The vulnerabilities were reported by Francis Provencher and rgod via the Zero Day Initiative. Fatek is working on mitigation measures.

The five reported vulnerabilities are:

• Use after free - CVE-2021-22662,

• Access of uninitialized pointer - CVE-2021-22670,

• Stack-based buffer overflow - CVE-2021-22666,

• Out-of-bounds write - CVE-2021-22683, and

• Out-of-bounds read - CVE-2021-22638

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to read/modify information, execute arbitrary, and/or crash the application.

PerFact Advisory

This advisory describes an external control of system or configuration setting vulnerability in the PerFact OpenVPN-Client. The vulnerability was reported by Sharon Brizinov of Claroty. PerFact has a new version that mitigates the vulnerability. There is no indication that Sharon has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow for local privilege escalation or remote code execution through a malicious webpage.

 
/* Use this with templates/template-twocol.html */