Showing posts with label Red Lion. Show all posts
Showing posts with label Red Lion. Show all posts

Sunday, October 19, 2025

Review – Public ICS Disclosures – Week of 10-11-25 – Part 2

For Part 2 we have 11 additional vendor disclosures from Phoenix Contact (2), Rockwell Automation (2), Schneider, Sick (2), Supermicro, and Westermo (3). We have 20 bulk updates from Schneider (5), and Siemens (15). We have three additional vendor updates from B&R Automation, CODESYS, and HP. Finally, we have four researcher reports describing vulnerabilities in products from Red Lion and Ilevia (3).

Advisories

Phoenix Contact Advisory #1 - Phoenix Contact published an advisory that describes four vulnerabilities in their QUINT4-UPS EIP uninterruptible power supplies.

Phoenix Contact Advisory #2 - Phoenix Contact published an advisory that describes a code injection vulnerability in their CHARX SEC-3xxx charging controllers.

Rockwell Advisory #1 - Rockwell published an advisory that describes an uncaught exception vulnerability in their Compact GuardLogix 5370 product. Rockwell

Rockwell Advisory #2 - Rockwell published an advisory that describes two vulnerabilities in their 1715 EtherNet/IP Comms Module.

Schneider Advisory - Schneider published an advisory that describes an allocation of resources without limits or throttling vulnerability in their EcoStruxure OPC UA Server Expert and EcoStruxure Modicon Communication Server products.

Sick Advisory #1 - Sick published an advisory that describes 18 vulnerabilities in their Enterprise Analytics and Logistic Analytics products.

Sick Advisory #2 - Sick published an advisory that discusses 28 vulnerabilities in their Endress+Hauser SSG-E210GC. These are third-party vulnerabilities.

Supermicro Advisory - Supermicro published an advisory that discusses an improper access control vulnerability.

Westermo Advisory #1 - Westermo published an advisory that describes a cleartext transmission of sensitive information vulnerability in their RADIUS Server Groups.

Westermo Advisory #2 - Westermo published an advisory that describes a cleartext transmission of sensitive information in their WeOS 5.

Westermo Advisory #3 - Westermo published an advisory that describes an improper restriction of communications channel to expected endpoints vulnerability in their WeOS 5.

Bulk Updates

Schneider

Multiple Altivar Process Drives and Communication Modules,

Modicon Controllers M241 / M251, M258 / LMC058 and M262,

Modicon M241 / M251 / M258 / LMC058,

FlexNet Publisher Vulnerability, and

Modicon Controllers M241 / M251 / M258 / LMC058

Siemens

Vulnerability in Nozomi Guardian/CMC on RUGGEDCOM APE1808 Devices,

Open Redirect Vulnerability in SIMATIC S7-1500 and S7-1200 CPUs,

Multiple Vulnerabilities in User Management Component (UMC),

Deserialization Vulnerability in Siemens Engineering Platforms,

Denial of Service Vulnerabilities in User Management Component (UMC),

Multiple Vulnerabilities in Palo Alto Networks Virtual NGFW on RUGGEDCOM APE1808 Devices,

Deserialization Vulnerability in Siemens Engineering Platforms,

Buffer Overflow Vulnerability in RUGGEDCOM ROS Devices,

Improper Integrity Check of Firmware Updates in SiPass integrated AC5102 / ACC-G2 and ACC-AP,

DLL Hijacking Vulnerability in Siemens Web Installer used by the Online Software Delivery,

Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP V1.1,

XML External Entity (XXE) Injection Vulnerability in SIMOTION SCOUT,

Multiple Vulnerabilities in RUGGEDCOM ROS Devices,

Unauthenticated Information Disclosure in Web Server of SIMATIC S7-1500 CPUs, and

Heap-based Buffer Overflow Vulnerability in User Management Component (UMC).

Updates

B&R Update - B&R published an update for their System Diagnostic Manager advisory that was originally published on October 7th, 2025.

CODESYS Update - CODESYS published an update for their Control V3 advisory that was originally published on August 4th, 2025, and most recently updated on September 1st, 2025.

HP Update - HP published an update for their Intel 2024.3 IPU advisory that was originally published on October 24th, 2024, and most recently updated on March 31st, 2025.

Researcher Reports

Red Lion Report - Claroty published a report describing two vulnerabilities in the Red Lion Sixnet RTU’s.

Ilevia Reports - Zero Science published four reports describing vulnerabilities in the Ilevia EVE X1 Server. The reports include links to exploits.

 

For more information on these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-568 - subscription required.

Saturday, July 6, 2024

Review – Public ICS Disclosures – Week of 6-29-24 – Part 1

This week we have vendor disclosures about the OpenSHH regreSSHion vulnerability from Cisco, Dell, Palo Alto Networks, QNAP, and WatchGuard. There are also other vendor disclosures from ABB (2), Hitachi (7), HP, HPE, Helmholz, MESbook, Mitsubishi, and Red Lion.

OpenSHH regreSSHion

Cisco published an advisory that provides a list of affected products and a separate list of products that are still under investigation.

Dell published an advisory that reports that they are investigating the vulnerability.

Palo Alto Networks published an advisory that reports that none of their products are affected.

QNAP published an advisory that provides a list of affected products, along with generic mitigation measures.

WatchGuard published an advisory reports that provides lists of affected and unaffected products.

Advisories

ABB Advisory #1 - ABB published an advisory that describes a use of default credentials vulnerability in their ASPECT system.

ABB Advisory #2 - ABB published an advisory that describes two vulnerabilities in their ASPECT system.

Helmholz Advisory - CERT-VDE published an advisory that describes an OS command injection vulnerability in the Helmholz REX 100 devices. Helmholz has a new firmware version that mitigates the vulnerability.

Hitachi Advisory #1 - Hitachi published an advisory that discusses two vulnerabilities in their JP 1 product.

Hitachi Advisory #2 - Hitachi published an advisory that describes an incorrect default permissions vulnerability in their JP1/Extensible SNMP Agent.

Hitachi Advisory #3 - Hitachi published an advisory that discusses seven vulnerabilities in their Ops Center Common Services product.

Hitachi Advisory #4 - Hitachi published an advisory that discusses the  Terrapin-Attack vulnerability in their JP1 product.

Hitachi Advisory #5 - Hitachi published an advisory that describes an incorrect default permissions vulnerability in their Ops Center Common Services product.

Hitachi Advisory #6 - Hitachi published an advisory that discusses ten vulnerabilities in their Ops Center Common Services product.

Hitachi Advisory #7 - Hitachi published an advisory that discusses twelve vulnerabilities (four with available exploits) in their Ops Center Common Services product.

HP Advisory - HP published an advisory that discusses four vulnerabilities in multiple HP PCs and workstations.

HPE Advisory - HPE published an advisory that describes an arbitrary code execution vulnerability in their Cray Servers.

MESbook Advisory - Incibe-CERT published an advisory that describes four vulnerabilities in the MESbook product.

Mitsubishi Advisory - Mitsubishi published an advisory that describes an incorrect default permissions vulnerability in their MELIPC Series MI5122-VW product.

Red Lion Advisory - CERT-VDE published an advisory that describes an OS command injection vulnerability in the Red Lion CVE-2024-5672 devices.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-54c - subscription required. 

Saturday, December 2, 2023

Review – Public ICS Disclosures – Week of 11-25-23

This week we have 15 vendor disclosures from Festo, Hitachi Energy (3), HPE, Medtronic, Red Lion, Ruckus, SEL, Sierra Wireless, Synology (2), WatchGuard, and Zyxel (2). There are nine vendor updates from Hitachi Energy (7), HPE, and VMware. There is also a researcher report describing vulnerabilities in products from SEL. Finally, we have two exploits for products from Loytec.

Advisories

Festo Advisory - CERT-VDE published an advisory that discusses an out-of-bounds write vulnerability in multiple Festo products.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory that describes three vulnerabilities in their RTU500 series products.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory that discusses an off-by-one error vulnerability in their SDM600 series products.

Hitachi Energy Advisory #3 - Hitachi Energy published an advisory that describes an improper input validation vulnerability in their s Relion® 670/650/SAM600-IO series products.

HPE Advisory - HPE published an advisory that discusses two improper initialization vulnerabilities in their Cray Servers and ProLiant DL/XL Servers.

Medtronic Advisory - Medtronic published an advisory that discusses two vulnerabilities in their Mainspring Data Express, and Vital Sync Virtual Patient Monitoring Platform products.

Red Lion Advisory - Red Lion published an advisory that describes an improper neutralization of special elements vulnerability in their Crimson 3.2 software.

Ruckus Advisory - Ruckus published an advisory that describes a cross-site scripting vulnerability in multiple Ruckus products.

SEL Advisory - SEL published a cybersecurity notice for their Blueframe OS product.

Sierra Wireless Advisory - Sierra Wireless published an advisory that describes eight vulnerabilities in their ALEOS, the operating system used in certain Sierra Wireless AirLink Routers.

Synology Advisory #1 - Synology published an advisory that describes an arbitrary code execution vulnerability in their Synology Camera BC500 and Synology Camera TC500.

Synology Advisory #2 - Synology published an advisory that describes a man-in-the-middle vulnerability in their Router Manager.

WatchGuard Advisory - WatchGuard published an advisory that discusses the heap buffer overflow in libwebp WebP Codec vulnerability that is listed in the CISA Known Exploited Vulnerabilities catalog.

Zyxel Advisory #1 - Zyxel published an advisory that describes nine vulnerabilities in multiple Zyxel firewall and access point (AP) products.

Zyxel Advisory #2 - Zyxel published an advisory that describes the six vulnerabilities in their NAS326 and NAS542 products.

Updates

Hitachi Energy Updates - Hitachi Energy published seven updates for the purpose of rebranding the advisories from “Hitachi/ABB Power Grids” to “Hitachi Energy”.

HPE Update - HPE published an update for their OneView advisory that was originally published on October 25th, 2023.

VMware Update - VMware published an update for their Cloud Director Appliance advisory that was originally published on November 14th, 2023.

Researcher Reports

SEL Report - Nozomi Networks published a report describing five vulnerabilities in the SEL-451 substation bay control  device.

Exploits

Loytec Exploit #1 - Chizuru Toyama published an exploit for three vulnerabilities in the Loytec LINX Configurator.

Loytec Exploit #2 - Chizuru Toyama published an exploit for a four vulnerabilities in the Loytec LINX Configurator.

 

For more details about these disclosures, including links to researcher reports, 3rd party advisories, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-7e2 - subscription required.

Thursday, November 16, 2023

Review – 14 Advisories Published – 11-16-23

Today, CISA published 14 control system security advisories for products from Siemens (12), Hitachi Energy, and Red Lion.

Siemens published two additional advisories and 18 updates on Tuesday. I will be covering them this weekend.

Advisories

RUGGEDCOM Advisory - This advisory discusses three vulnerabilities in the Siemens RUGGEDCOM APE1808.

SIMATIC Advisory #1 - This advisory discusses eight vulnerabilities in the Siemens SIMATIC MV500.

SIMATIC Advisory #2 - This advisory describes four vulnerabilities in the Siemens SIMATIC PCS neo.

PNI Advisory - This advisory discusses 13 vulnerabilities in the Siemens SINEC PNI product.

Mendix Advisory #1 - This advisory discusses an out-of-bounds write vulnerability in the Siemens Mendix Studio Pro 7, 8, 9, 10.

Mendix Advisory #2 - This advisory describes an authentication bypass by capture-replay vulnerability in the Siemens Mendix Runtime.

SIPROTEC Advisory - This advisory discusses the Urgent/11 vulnerabilities in the Siemens SIPROTEC 4 7SJ66.

SCALANCE Advisory #1 - This advisory discusses 15 vulnerabilities in the Siemens SCALANCE Family Products.

SCALANCE Advisory #2 - This advisory that discusses an improper input validation vulnerability in the Siemens SCALANCE W700.

OPC UA Advisory - This advisory describes an improper restriction of XML entity reference vulnerability in the Siemens OPC UA Modeling Editor (SiOME).

Desigo Advisory - This advisory discusses three vulnerabilities in the Siemens Desigo CC product family.

Hitachi Energy Advisory - This advisory describes two vulnerabilities in the Hitachi Energy MACH System Software.

Red Lion Advisory - This advisory describes two vulnerabilities in the Red Lion Sixnet and VersaTRAK Series RTU.

 

For more details about these advisories, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/14-advisories-published-11-16-23 - subscription required.

Thursday, November 2, 2023

Review – 6 Advisories Published – 11-2-23

Today, CISA’s NCCIC-ICS published six control system security advisories for products from Schneider Electric, Weintek, Franklin Fueling Systems, Mitsubishi Electric (2), and Red Lion.

Advisories

Schneider Advisory - This advisory describes two vulnerabilities in the Schnieder SpaceLogic C-Bus Toolkit.

Weintek Advisory - This advisory describes a use of hard-coded credentials vulnerability in the Weintek EasyBuilder Pro products.

Franklin Advisory - This advisory describes a use of password hash with insufficient computational effort vulnerability in the Franklin Fueling Systems TS-550 product.

Mitsubishi Advisory #1 - This advisory describes an insufficient verification of data authenticity vulnerability in the Mitsubishi MELSEC Series products.

Mitsubishi Advisory #2 - This advisory describes an improper restriction of excessive authentication attempts vulnerability in the Mitsubishi MELSEC iQ-F Series products.

Red Lion Advisory - This advisory describes an improper neutralization of null byte or null character vulnerability in the Red Lion Crimson 3.2 Windows-based configuration tool.

 

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published-11-2-23 - subscription required.

Saturday, August 19, 2023

Review – Public ICS Disclosures – Week of 8-12-23

This week we have 17 vendor disclosures from Aruba Networks, Broadcom, CODESYS, FortiGuard, GE Gas Power, Helmholz, HPE (2), Inductive Automation, Moxa (2), Palo Alto Networks, Red Lion, Rockwell, Ruckus Wireless, Wibu, and Zyxel.

Advisories

Aruba Advisory - Aruba published an advisory that describes two vulnerabilities in their Virtual Intranet Access (VIA) Windows Client.

Broadcom Advisory - Broadcom published an advisory that discusses a type confusion vulnerability in their Brocade Fabric OS product.

CODESYS Advisory - CODESYS published an advisory that discusses a heap-based buffer overflow vulnerability in multiple products.

FortiGuard Advisory - FortiGuard published an advisory that describes a stack-based buffer overflow vulnerability in their FortiOS product.

GE Gas Power - GE published an advisory that discusses a heap-based buffer overflow vulnerability in their CIMPLICITY product.

Helmholz Advisory - CERT-VDE published an advisory that discusses a cross-site scripting vulnerability in their REX 200 and REX 250 products.

HPE Advisory #1 - HPE published an advisory that discusses 13 vulnerabilities in their HP-UX Web Server Suite Software.

HPE Advisory #2 - HPE published an advisory that discusses two vulnerabilities in their SimpliVity Servers.

Inductive Automation Advisory - Inductive Automation published an advisory that describes six vulnerabilities in their Ignition product.

Moxa Advisory #1 - Moxa published an advisory that describes a use of hard-coded credentials vulnerability in their NPort IAW5000A-I/O Series.

Moxa Advisory #2 - Moxa published an advisory that describes eight vulnerabilities in their TN-5900 and TN-4900 Series Web Server.

Palo Alto Networks Advisory - Palo Alto Networks published an advisory that discusses the TunnelCrack vulnerabilities.

Red Lion Europe Advisory - CERT-VDE published an advisory that descries a cross-site scripting vulnerability in the Red Lion mbNET and mbNET/.rokey.

Rockwell Advisory - Rockwell published an advisory that describes three improper input validation vulnerabilities in their ThinManager ThinServer product.

Ruckus Advisory - Ruckus published an advisory that describes three cross-site scripting vulnerabilities in their ICX product line.

Wibu Advisory - Wibu published an advisory that describes a heap-based buffer overflow vulnerability in their CodeMeter Runtime product.

Zyxel Advisory #1 - Zyxel published an advisory that describes an improper handling of exceptions vulnerability in their XGS2220, XMG1930, and XS1930 series switches.

Zyxel Advisory #2 - Zyxel published an advisory that describes an OS command injection vulnerability in their NBG6604 home router.

 

For more information about the disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article on CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-810 - subscription required.

Thursday, November 17, 2022

Review - 2 Advisories Published – 11-17-22

Today CISA’s NCCIC-ICS published two control system security advisories for products from Cradlepoint and Red Lion.

Cradlepoint Advisory - This advisory describes a command injection vulnerability in the Cradlepoint NetCloud OS.

Red Lion Advisory - This advisory describes a path traversal vulnerability in the Red Lion Controls Crimson programming software.

 

For more details about these advisories, including a down-the-rabbit hole look at the Cradlepoint advisory, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-published-11-17-22 - subscription required.

Saturday, September 17, 2022

Review – Public ICS Disclosures – Week of 9-10-22 – Part 1

This is the weekend after the 2nd Tuesday disclosures so this will be a two-part report. For Part 1 we have 39 vendor disclosures from Broadcom (25), Dell, Hitachi Energy, Honeywell, HPE (2), Palo Alto Networks (4), Schneider, Red Lion, TI, and VISAM.

Broadcom Advisories - Broadcom published 25 advisories for vulnerabilities in Brocade Fabric OS.

Dell Advisory - Dell published an advisory that describes a regular expression vulnerability in the their Wyse ThinOS.

Hitachi Energy Advisory - Hitachi Energy published an advisory that discusses 48 vulnerabilities in their Disk Array products.

Honeywell Advisory - Honeywell published an advisory that announces the end-of-life status of certain OmniProx™ Clamshell Prox Card SKUs.

HPE Advisory #1 - HPE published an advisory that describes four vulnerabilities in their Integrated Lights-Out 5 products.

HPE Advisory #2 - HPE published an advisory that discusses an infinite loop vulnerability in their Integrated Lights-Out 5 (iLO 5), and Integrated Lights-out 4 products.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes a link following vulnerability in their Cortex XDR Agent.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that discusses a Windows® registry vulnerability in their Cortex XDR Agent.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory that discusses an improper input validation vulnerability in the NVIDIA Dataplane Development Kit.

Palo Alto Networks Advisory #4 - Palo Alto Networks published an advisory that discusses a file access vulnerability in their Cortex XDR Agent.

Schneider Advisory - Schneider published an advisory that describes a deserialization of untrusted data vulnerability in their EcoStruxure Machine SCADA Expert and Pro-face BLUE Open Studio products.

Red Lion Advisory - Red Lion published an advisory that describes a path traversal vulnerability in their Crimson software.

TI Advisory - TI published an advisory that describes a flash memory vulnerability in their SimpleLink MSP432EXX SDK.

VISAM Advisory - Incibe-CERT published an advisory describing a credential disclosure vulnerability in the VISAM VBASE.

 

For more details about these disclosures, including links to third-party vulnerabilities and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-8df - subscription required.


Thursday, April 14, 2022

Review – 17 Advisories Published – 4-14-22

Today, CISA’s NCCIC-ICS published seventeen control system security advisories for products from Siemens (14), Red Lion, Johnson Controls, and Delta Electronics. They also published 22 updates for products from Siemens, but those will be covered in a subsequent post.

Mendix Advisory #1 - This advisory describes an improper access control vulnerability in the Siemens Mendix software platform.

Mendix Advisory #2 - This advisory describes exposure of sensitive information to an unauthorized actor vulnerability in the Siemens Mendix software platform.

TIA Administrator Advisory - This advisory describes an uncontrolled resource consumption vulnerability in the Siemens TIA Administrator.

Simcenter Advisory - This advisory describes three vulnerabilities in the Siemens Simcenter Femap simulation application.

SIMATIC Advisory #1 - This advisory describes an improper access control vulnerability in the Siemens SIMATIC STEP 7 (TIA Portal).

SIMATIC Advisory #2 - This advisory describes a lengthy list of vulnerabilities (listed in this advisory as a single ‘use of unmaintained third-party components) in the Siemens GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP.

NOTE: The Siemens version of this advisory was originally published in 2018 and most recently updated on March 8th, 2022. The list of GNU/Linux CVE’s is extensive to say the least.

SIMATIC Advisory #3 - This advisory describes an improper restriction of operations within the bounds of a memory buffer vulnerability in the Siemens SIMATIC S7-400.

SIMATIC Advisory #4 - This advisory describes three vulnerabilities in the Siemens SIMATIC Energy Manager.

SICAM Advisory - This advisory describes a missing authentication (with available proof-of-concept code) for critical function vulnerability in the Siemens SICAM A8000 products.

SCALANCE Advisory #1 - This advisory describes nine vulnerabilities in the Siemens SCALANCE X-300 switch family devices.

SCALANCE Advisory #2 - This advisory describes three vulnerabilities in the Siemens SCALANCE W1700 wireless communications device.

SCALANCE Advisory #3 - This advisory discusses the FragAttacks WiFi vulnerabilities in the Siemens SCALANCE family devices.

NOTE: The Siemens version of this advisory was originally published on July 13th, 2021 and most recently updated on February 8th, 2022.

PROFINET Advisory - This advisory describes an uncontrolled resource consumption vulnerability in the Siemens PROFINET Stack Integrated on Interniche Stack.

OpenSSL Advisory - This advisory discusses a NULL pointer dereference vulnerability in the Siemens Industrial Products.

Red Lion Advisory - This advisory describes four vulnerabilities in the unsupported Red Lion DA50N networking gateway.

Johnson Controls Advisory - This advisory describes an incomplete cleanup vulnerability in the Johnsons Controls Metasys ADS/ADX/OAS Servers.

Delta Advisory - This advisory describes an improper restriction of XML external entity reference vulnerability in the Delta DMARS, a Motion Controller program development tool.

Commentary

This month NCCIC-ICS published advisories for a couple of long-running advisories from Siemens. I am not sure where (CISA or Siemens) the housekeeping took place to see this happen, but this a small, but significant advance in information sharing that deserves mention.


For more details about these advisories, including links to third-party advisories and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/17-advisories-published-4-14-22 - subscription required.

Saturday, August 28, 2021

Review - Public ICS Disclosures – Week of 8-21-27

This week we have six vendor disclosures from B&R, OPC Foundation, HPE, Red Lion, VMware (2). We also have one update from Mitsubishi. We also have one researcher report for products from Braun.

B&R Advisory - B&R published an advisory discussing the INFRA:HALT vulnerabilities.

OPC Foundation Advisory - The OPC Foundation published an advisory describing an access of memory location after end of buffer vulnerability in their Local Discovery Server (LDS).

HPE Advisory - HPE published an advisory describing five vulnerabilities in their FlexNetworking, Flexfabric, and MSR switches and routers.

Red Lion Advisory - Red Lion published an advisory describing an SSH port forwarding vulnerability in their DA50A and DA70A modular gateways.

VMware Advisory #1 - VMware published an advisory describing a cross-site scripting vulnerability in their vRealize Log Insight.

VMware Advisory #2 - VMware published an advisory describing six vulnerabilities in their vRealize Operations product.

Mitsubishi Update - Mitsubishi published an update for their TCP Protocol Stack advisory that was originally published on September 1st, 2020 and most recently updated on May 18th, 2021

Braun Report - McAffee published a report describing five vulnerabilities in the B Braun Infusomat Space Large Volume Pump.

 

For more details on these advisories, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-9fc - subscription required.

Tuesday, January 5, 2021

6 Advisories Published – 1-5-21

Today the CISA NCCIC-ICS published six control system security advisories for products from Delta Electronics (2), Red Lion, GE, Panasonic and Schneider.

CNCSoft Advisory

This advisory describes a stack-based buffer overflow vulnerability in the Delta CNCSoft ScreenEditor. The vulnerability was reported by Kimiya via the Zero Day Initiative. Delta has an update that mitigates the vulnerability. There is no indication that Kimiya has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow arbitrary code execution.

DOPSoft Advisory

This advisory describes two vulnerabilities in the Delta DOPSoft software. The vulnerability was reported by Kimiya via the Zero Day Initiative. Delta has an update that mitigates the vulnerability. There is no indication that Kimiya has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Out-of-bounds write - CVE-2020-27275, and

• Untrusted pointer dereference - CVE-2020-27277

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow arbitrary code execution.

Red Lion Advisory

This advisory describes three vulnerabilities in the Red Lion Crimson 3.1 programming software. The vulnerabilities were reported by Marco Balduzzi, Ryan Flores, Philippe Lin, Charles Perine, Ryan Flores, Rainer Vosseler via ZDI. Red Lion has a new version that mitigates the vulnerabilities. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Null pointer dereference - CVE-2020-27279,

• Missing authentication for critical function - CVE-2020-27285, and

• Improper resource shutdown - CVE-2020-27283

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to create a denial-of-service condition, read and modify the database, and leak memory data.

GE Advisory

This advisory describes two vulnerabilities in the GE Reason RT43X Clocks. The vulnerabilities were reported by Tom Westenberg of Thales UK. GE has a new firmware version that mitigates the vulnerabilities. There is no indication that Westenberg has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Code injection - CVE-2020-25197, and

• Use of hard-coded cryptographic key - CVE-2020-25193

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow an authenticated remote attacker to execute arbitrary code on the system or intercept and decrypt encrypted traffic.

NOTE: I (very) briefly mentioned the GE advisory for these vulnerabilities back in November.

Panasonic Advisory

This advisory describes an out-of-bounds read vulnerability in the Panasonic FPWIN Pro programming software. The vulnerability was reported by Francis Provencher via ZDI. Panasonic has a new version that mitigates the vulnerability. The is no indication that Provencher has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to  allow remote code execution.

Schneider Advisory

This advisory describes three vulnerabilities in the Schneider Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy products. The vulnerabilities were reported (here and here) by Kai Wang of Fortinet's FortiGuard Labs. Schneider continues to work on mitigation measures for supported versions of the affected products.

The three reported vulnerabilities were:

• Out-of-bounds read - CVE-2020-7562,

• Out-of-bounds write - CVE-2020-7563, and

• Classic buffer overflow - CVE-2020-7564

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow write access and the execution of commands, which could result in data corruption or a web server crash.

NOTE: I briefly described these vulnerabilities back in November.

NCCIC-ICS Updates

NCCIC-ICS also published five updates today. I will cover them in a separate blog post.

Saturday, September 5, 2020

Public ICS Disclosures – Week of 8-29-20


This week we have two new vendor disclosures for products from SICK and BD. There were also three Ripple20 [Corrected link, 10-18-20, 0857] updates published for products from HMS, Braun and Schneider. We also have a vendor update from Yokogawa. There is also one researcher report with exploits for vulnerabilities for products from Red Lion.

SICK Advisory


SICK published an advisory describing an improper handling of exceptional conditions vulnerability in their SOPAS Engineering Tool. The vulnerability was reported by Ruben Santamarta of IOActive. SICK has released new firmware versions that mitigate the vulnerability. There is no indication that Santamarta has been provided an opportunity to verify the efficacy of the fix.

BD Advisory


BD published an advisory describing three third-party (VMware) vulnerabilities in selected BD products. BD is currently testing the VMware update.

The three reported vulnerabilities are:

• Local privilege escalation - CVE-2020-3957,
• Denial of service - CVE-2020-3958, and
• Memory leak - CVE-2020-3959

Ripple20 Updates


HMS published an update of their Ripple20 advisory that was originally published on June 23, 2020. The new information includes adding the following products to the not affected list:

• Anybus M-Bus to Modbus TCP gateway,
• Anybus WLAN Access Points (AWB4xxx), and
• Ewon Netbiter 100, 200 and 300-series

Braun published an update of their Ripple20 advisory that was originally published on June 30th, 2020. The updated information includes more details on the Ripple20 effect on the Outlook 400ES infusion pump.

Schneider published an update of their Ripple20 advisory that was originally published on June 23, 2020 and most recently updated on August 6th, 2020. The new information includes:

• Adding mitigation measures for Cooling Products using NMC2, and
• Adding partial remediations for TM3BC bus coupler module – EIP, TM3BC bus coupler module – SL, and TM3BC bus coupler module – CANOpen

Yokogawa Update


Yokogawa published an update for their CAMS for HIS advisory that was originally published on July 31st, 2020. The new information includes updated affected product data.

Red Lion Report


SEC Consult published a report on multiple vulnerabilities in the Red Lion N-Tron products that were reported last week by CISA NCCIC-ICS. The SEC Consult report includes proof-of-concept exploit code and a list of outdated third-party components.

Thursday, August 27, 2020

1 Advisory and 1 Update Published – 8-27-20


Today the CISA NCCIC-ICS published a control system security advisory for products from Red Lion and updated a medical device security advisory for products from OpenClinic GA.

Red Lion Advisory


This advisory describes five vulnerabilities in the Red Lion N-Tron 702W series products. The vulnerabilities were reported by Thomas Weber from SEC Consult Vulnerability Lab. These products went out of support in 2018 and cannot be updated.

The five reported vulnerabilities are:

• Cross-site scripting - CVE-2020-16210 and CVE-2020-16206,
• Cross-site request forgery - CVE-2020-16208,
• Backdoor - CVE-2020-16204, and
• Use of unmaintained third-party components - CVE-2017-16544

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to gain unauthorized access to sensitive information, execute system commands, and perform actions in the context of an attacked user.

NOTE: There are multiple proof-of-concept exploits available for the last vulnerability, actually multiple vulnerabilities. Some of those exploits of the BusyBox vulnerabilities can be found here, here and here.

OpenClinic Update


This update provides additional information on an advisory that was originally published on July 2nd, 2020. The new information includes three CVE numbers for vulnerabilities covered under the single listed ‘use of unmaintained third-party components vulnerability’; those CVE’s are

CVE-2014-0114 (Apache Struts, improper input validation, multiple exploits)
CVE-2016-1181 (Apache Struts, insufficient information, multiple exploits), and
CVE-2016-1182 (Apache Struts, improper input validation, multiple expoits)


Saturday, December 14, 2019

Public ICS Disclosure – Week of 12-07-19


This week we have vendor disclosures from Siemens, Schneider (4) and Red Lion as well as advisory updates from Siemens (2) and Schneider. We also have security researcher reports for products from Advantech (2) and Schneider. And finally, we have an exploit published for products from Omron.

Siemens Advisory


Siemens published an advisory describing 53 vulnerabilities in their SPPA-T3000 servers. Vulnerabilities were reported by Gleb Gritsai, Eugenie Potseluevskaya, Sergey Andreev, and Radu Motspan from Kaspersky Lab; Vyacheslav Moskvin and Ivan B from Positive Technologies; and Can Demirel from Biznet Bilisim. Siemens has a new service pack for one of the affected servers that addresses a very limited number (3) of the applicable vulnerabilities. There is no indication that any of the researchers have been provided an opportunity to verify the efficacy of the fix.

NOTE 1: This is the advisory discussed in the TWITTER® thread I mentioned earlier this week.

NOTE: The first vulnerability reported in the advisory (CVE-2018-4832) was previously reported in other Siemens products. Siemens has not yet provided updates for all of those affected products and this is not one of the vulnerabilities remediated in this advisory.

Siemens Updates


Siemens published an update for an advisory that was originally published on November 12th, 2019. The new information includes:

• Added SIMATIC S7-200 SMART to the list of affected devices; and
• SIPLUS devices now explicitly mentioned in the list of affected products

NOTE: NCCIC-ICS did publish an update for their advisory on this vulnerability on Tuesday, but somehow I overlooked it in my blog post.

Siemens published an update for an advisory that was originally published on July 9th, 2019. The new information includes:

• Updates for SIMATIC IPC2X7E, SIMATIC IPC327E, SIMATIC IPC377E; and
• SIPLUS devices now explicitly mentioned in the list of affected products

Schneider Advisories


Schneider published an advisory describing three improper check for unusual or exception condition vulnerabilities in their Modicon Controllers. The vulnerabilities were reported by Younes Dragoni (Nozomi Networks), Chansim Deng, Mengmeng Young and Gideon Guo. Schneider has new firmware versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory describing an improper authorization vulnerability in their EcoStruxure™ Control Expert. The vulnerability was reported by Rongkuan Ma, Xin Che and Peng Cheng (Zhejiang University). Schneider has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Schneider published an advisory describing a stack-based buffer overflow vulnerability in their Power SCADA Operation product. The vulnerability is self-reported. Schneider has a new version that mitigates the vulnerability.

Schneider published an advisory describing a permissions, privileges and access control vulnerability in their EcoStruxure Geo SCADA Expert (ClearSCADA). The vulnerability was reported by William Knowles (Lancaster University). Schneider has a new version that mitigates the vulnerability. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.

NOTE: Earlier this week there had been a fifth advisory listed on the Schneider security notifications site for their Saitel DP (866e) and Saitel DR (HUe) products, but that advisory has since been removed from the list.

Red Lion Advisory


Red Lion published an advisory describing the URGENT/11 vulnerabilities in their NT24k Switch Series. The vulnerability is self-reported. Red Lion has a firmware upgrade the implements the Wind River patch.

Advantech Researher Reports


Mat Powell from the Zero Day Initiative published a report of a zero-day stack-based buffer overflow vulnerability in the Advantech Web Access product. The vulnerability has been coordinated through NCCIC-ICS. Advantech apparently reported that the vulnerability is in a third-party component but has not shared with NCCIC-ICS whom that third-party is. I do not know why NCCIC-ICS has not yet released an advisory on this vulnerability.

Tenable published a report [corrected bad link - 22:10 EDT 3-26-20] describing a stack-based buffer overflow vulnerability in the Advantech Web Access product. Advantech has a new version that Tenable has confirmed mitigates the vulnerability. The Tenable report includes exploit code.

NOTE: The two reports both describe stack-based buffer overflows, but in different components of the product (BwOpcBs.exe in the ZDI report; BwPAlarm.dll in the Tenable report)

Schneider Researcher Report


Applied Risk published a report describing an insecure file permissions vulnerability in the Schneider ClearScada product. This is probably the same vulnerability as described in the Schneider ExoStruxure advisory above as William Knowles is associated with both reports.

Omron Exploit


NOBODY published an exploit for an unrestricted externally accessible lock vulnerability in the Omron CJ2M PLC. This appears to be the same vulnerability that was reported this week.


 
/* Use this with templates/template-twocol.html */