Showing posts with label RIoT Solutions. Show all posts
Showing posts with label RIoT Solutions. Show all posts

Friday, November 10, 2017

ICS-CERT Publishes Two Advisories

Yesterday the DHS ICS-CERT published two control system security advisories for products from Schneider and AutomationDirect.

Schneider Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Schneider InduSoft Web Studio and InTouch Machine Edition. The vulnerabilities were reported by Aaron Portnoy, formerly of Exodus Intelligence. Schneider has produced new versions that mitigate the vulnerability. There is no indication that Portnoy has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could use a publicly available exploit to remotely exploit this vulnerability to remotely execute code with high privileges. The Schneider security bulletin notes that the vulnerability exists during tag subscription.

AutomationDirect Advisory


This advisory describes and uncontrolled search path element vulnerability in a number of AutomationDirect products. The vulnerability was reported by Mark Cross of RIoT Solutions. Newer software versions are available from AutomationDirect that mitigate the problem. There is no indication that Cross has been provided an opportunity to verify the efficacy of the fix.


ICS-CERT reports that an uncharacterized attacker with uncharacterized access to execute arbitrary code on the system.

Thursday, February 23, 2017

ICS-CERT Publishes Three Advisories

Today the DHS ICS-CERT published three control system security advisories for products from Schneider Electric, Red Lion Controls and VIPA Controls.

Schneider Advisory


This advisory describes a resource exhaustion vulnerability in the Schneider Electric Modicon M340 PLC. The vulnerability was reported by Luis Francisco Martin Liras. Schneider has released a new firmware version that mitigates the vulnerability. There is no indication that Liras has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to render the device unresponsive requiring a physical reset of the PLC.

Red Lion Controls Advisory


This advisory describes a hard-coded cryptographic key vulnerability in the Red Lion Controls Sixnet-Managed Industrial Switches and the AutomationDirect STRIDE-Managed Ethernet Switch models. The vulnerability was reported by Mark Cross of RIoT Solutions. New firmware versions have been made available for both sets of devices. There is no indication that Cross has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to effect the loss of data confidentiality, integrity, and availability.

VIPA Controls Advisory


This advisory describes a stack-based buffer overflow vulnerability in the VIPA Controls WinPLC7. The vulnerability was reported by Ariele Caltabiano (kimiya) through ZDI. VIPA Controls has developed a patch to mitigate the vulnerability. There is no indication that kimiya has been provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to crash the device; a buffer overflow condition may allow remote code execution.


NOTE: Yesterday Siemens announced on TWITTER® the publication of two security notification updates (here and here) and the publication of a new security notification (here). I had almost expected ICS-CERT to publish their updates and advisory today; maybe tomorrow.
 
/* Use this with templates/template-twocol.html */