Showing posts with label ProPump. Show all posts
Showing posts with label ProPump. Show all posts

Thursday, February 8, 2024

Review - 1 Advisory and 1 Update Published – 2-8-24

Today, CISA’s NCCIC-ICS published a control system security advisory for products from Qolsys and updated an advisory from ProPump and Controls.

Advisories

Qolsys Advisory - This advisory describes an exposure of sensitive information to an unauthorized actor vulnerability in the Qolsys (Johnson Controls subsidiary) IQ Panel 4 and IQ4 Hub.

Updates

ProPump Update - This update provides additional information on an advisory that was originally published on March 23, 2023.

 

For more information on these two advisories, including a look at Johnson Controls advisories links and comments on vendor responses to CISA, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-and-1-update-published-0a9 - subscription required.

Thursday, March 23, 2023

Review – 6 Advisories Published – 3-23-23

Today, CISA’s NCCIC-ICS published six control system security advisories for products from ProPump and Controls, ABB, Schneider Electric, SAUTER, CP Plus and RoboDK.

Advisories

ProPump Advisory - This advisory describes nine vulnerabilities in the ProPump Osprey Pump Controller.

ABB Advisory - This advisory describes two vulnerabilities in the ABB NE843 Pulsar Plus Controller.

Schneider Advisory - This advisory describes eight vulnerabilities in the Schneider Interactive Graphical SCADA System (IGSS).

SAUTER Advisory - This advisory describes five vulnerabilities in the SAUTER EY-modulo 5 Building Automation Stations.

CP Plus Advisory - This advisory describes an insufficiently protected credentials vulnerability in the CP Plus KVMS Pro.

RoboDK Advisory - This advisory describes an incorrect permission assignment for critical resource in the RoboDK robot development kit.

NOTE: This was a relatively bad day for system owners as four of the six vendors had little or no response towards fixing the identified vulnerabilities.

 

For more details about these advisories, including links to researcher reports and exploits, as well as a description of vendor responses, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published-3-23-23 - subscription required.

 
/* Use this with templates/template-twocol.html */