Showing posts with label Real Time Automation. Show all posts
Showing posts with label Real Time Automation. Show all posts

Thursday, September 21, 2023

Review – 6 Advisories Published – 9-21-23

Today, CISA’s NCCIC-ICS published six control system security advisories for products from Rockwell (3), Delta Electronics, Siemens, and Real Time Automation.

Advisories

Rockwell Advisory #1 - This advisory  describes an improper input validation vulnerability in the Rockwell FactoryTalk View Machine Edition.

Rockwell Advisory #2 - This advisory discusses five vulnerabilities in the Rockwell Connected Components Workbench.

NOTE: All five vulnerabilities are on CISA’s Known Exploited Vulnerabilities Catalog.

Rockwell Advisory #3 - This advisory describes a stack-based buffer overflow vulnerability in the Rockwell Logix Communication Modules.

Delta Advisory - This advisory describes an out-of-bounds write vulnerability in the Delta DIAScreen software configuration tool.

Siemens Advisory  - This advisory describes an incorrect permission for critical resource vulnerability in the Siemens Spectrum Power 7 product.

Real Time Automation Advisory - This advisory describes a cross-site scripting vulnerability in the Real Time Automation 460MCBS Modbus TCP to BACnet/IP Gateway.

 

For more details about the advisories, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published-9-21-23 - subscription required.

Saturday, January 30, 2021

Public ICS Disclosures – Week of 1-23-21

This week we have nine vendor disclosures from Bosch, ZIV Automation (2), Emerson, GE Healthcare, Johnson Controls, Rockwell (2), and Siemens.

Bosch Advisory

Bosch published an advisory describing a stack-based buffer overflow vulnerability in their Rexroth ID 200/C-ETH using EtherNet/IP Protocol. This is a third-party (Real Time Automation) vulnerability. Bosch provides generic mitigation measures.

ZIV Automation Advisories

Incibe-CERT published an advisory describing an uncontrolled resource consumption vulnerability in the ZIV 4CCT Smart Metering Data Concentrator. The vulnerability was reported by Aarón Flecha Menéndez of S21Sec. ZIV has a patch available that mitigates the vulnerability. There is no indication that Menendez has been provided an opportunity to verify the efficacy of the fix.

 

Incibe-CERT published an advisory describing an improper authentication vulnerability in the ZIV 4CCT Smart Metering Data Concentrator. The vulnerability was reported by Aarón Flecha Menéndez of S21Sec. ZIV has a patch available that mitigates the vulnerability. There is no indication that Menendez has been provided an opportunity to verify the efficacy of the fix.

Emerson Advisory

Emerson published an advisory describing the fdtCONTAINER vulnerability in their Rosemont Transmitter Interface Software. Emerson no longer supports that software.

NOTE: This Emerson impact was previously reported by NCCIC-ICS.

GE Healthcare Advisory

GE Healthcare has published an advisory discussing undisclosed vulnerabilities in the VC150 Vital Signs Monitor that they distribute. The Innokas Medical web site simply notes in their software update note for the VC150 that it contains “Cybersecurity enhancements and bug fixes”. GE Healthcare has made the updated software available.

Johnson Controls

Johnson Controls has published an advisory discussing four vulnerabilities in their Sur-Gard System 5 receivers. They are third-party (Treck) vulnerabilities. Johnson Controls has a new version that mitigates the vulnerabilities.

NOTE: This advisory does not specifically name the four vulnerabilities identified by Treck and NCCIC-ICS, it just provides the CVE numbers; CVE-2020-25066,  CVE-2020-27336, CVE-2020-27337, and  CVE-2020-27338.

Rockwell Advisories

Rockwell published an advisory describing the fdtCONTAINER vulnerability in their FactoryTalk AssetCentre. Rockwell has a new version that mitigates the vulnerability.

 

Rockwell published an advisory describing a buffer overflow vulnerability in their MicroLogix 1400 Controller. The vulnerability was reported by Parul Sindhwad and Dr. Faruk Kazi from COE-CNDS. Rockwell provides generic mitigation measures

Siemens Advisory

Siemens published an advisory describing a missing authentication for critical function vulnerability in their SIMATIC HMI Panels. The vulnerability was reported by the Zero Day Initiative. Siemens has new versions that mitigate the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

NOTE: The advisory acknowledges the coordination efforts of CISA, so it is likely that NCCIC-ICS will publish an advisory on this vulnerability next week.

Saturday, January 2, 2021

Public ICS Disclosures – Week of 12-26-20

This week we have two vendor disclosures for products from Moxa and Rockwell Automation.

Moxa Advisory

Moxa published an advisory discussing the Real Time Automation EtherNet/IP vulnerability. Moxa reports that none of their products are affected.

Rockwell Advisory

Rockwell published an advisory describing four vulnerabilities in their FactoryTalk Linx and FactoryTalk Services Platform. While the Rockwell advisory does not credit them with reporting the problems, Tenable has published a report discussing these same vulnerabilities and their disclosure timeline. Rockwell has provided generic mitigation measures.

The four reported vulnerabilities are:

• Unhandled exception (2) - CVE-2020-5801 and CVE-2020-5802, and

• Buffer overflow (2) - CVE-2020-5806 and CVE-2020-5807

NOTE: The Tenable report provides a GitHub link for proof-of-concept code.

 
/* Use this with templates/template-twocol.html */