Showing posts with label Positive Technologies Security. Show all posts
Showing posts with label Positive Technologies Security. Show all posts

Tuesday, February 26, 2019

One Advisory Published – 02-26-19


Today the DHS NCCIC-ICS published a control system security advisory for products from Moxa. The advisory describes ten vulnerabilities in the Moxa IKS and EDS industrial switches. The vulnerabilities were reported by Ivan B, Sergey Fedonin, and Vyacheslav Moskvin of Positive Technologies Security. Moxa has a firmware patch that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The ten reported vulnerabilities are:

• Classic buffer overflow - CVE-2019-6557;
• Cross-site request forgery - CVE-2019-6561;
• Cross-site scripting - CVE-2019-6565;
• Improper access control - CVE-2019-6520;
• Improper restriction of excessive authentication request - CVE-2019-6524;
• Missing encryption of sensitive data - CVE-2019-6526;
• Out-of-bounds read - CVE-2019-6522;
• Unprotected storage of credentials - CVE-2019-6518;
• Predictable from observable state - CVE-2019-6563; and
Uncontrolled resource consumption - CVE-2019-6559

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow the reading of sensitive information, remote code execution, arbitrary configuration changes, authentication bypass, sensitive data capture, reboot of the device, device crash, or full compromise of the device.

Thursday, July 30, 2015

ICS-CERT Updates one Advisory and Publishes Another

This afternoon the DHS ICS-CERT updated a Siemens advisory for SIMATIC HMI Devices and publishes a new advisory for Schneider Electric InduSoft Wb Studio.

Siemens Update

This update notes that Siemens is now reporting that all of the affected HMI devices now have updates available to mitigate the three vulnerabilities reported in the original advisory back in April. It also adds three different types of SIMATIC HMI panels to the list of affected and mitigated products.

Schneider Advisory

This advisory describes a clear-text storage of sensitive information vulnerability in Schneider’s Electric InduSoft Web Studio and InTouch Machine. The vulnerability was originally reported by Gleb Gritsai, Alisa Esage Shevchenko, Ilya Karpov, and the team from Positive Technologies Security. Schneider has produced patches to mitigate the vulnerability but there is no indication that the researchers have been given the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker with local access can obtain project passwords from the configuration file. These can then be used to execute arbitrary code.


NOTE: The link provided in the Advisory for the Schneider report on the InduSoft version of this vulnerability does not get to the report; Schneiderdoes not yet have the vulnerability listed. Here is the direct link.
 
/* Use this with templates/template-twocol.html */