Showing posts with label Rittal. Show all posts
Showing posts with label Rittal. Show all posts

Saturday, October 26, 2024

Review – Public ICS Disclosures – Week of 10-19-24

 This week we have 11 vendor disclosures from ABB, Endress+Hauser, HP (2), HPE (5), Rockwell, and Xerox. We also have eight vendor updates from FortiGuard (2), HP (2), HPE (2), Moxa, and VMware. There are eight researcher reports for vulnerabilities in products from ABB (4), EmbedThis (3), and LAWO. Finally, we have an exploit for products from Rittal.

Advisories

ABB Advisory - ABB published an advisory that describes an improper verification of cryptographic signature vulnerability in multiple ABB products.

Endress+Hauser Advisory - CERT-VDE published an advisory that discusses five vulnerabilities in the Endress+Hauser Netilion Network Insights products.

HP Advisory #1 - HP published an advisory that discusses six vulnerabilities in their Intel 2024.3 IPU – Chipset Firmware used in multiple HP product lines.

HP Advisory #2 - HP published an advisory that discusses the PixieFail vulnerabilities in the EDK2 NetworkPkg in multiple HP product lines.

HPE Advisory #1 - HPE published an advisory that discusses 19 vulnerabilities in their HP-UX Common Internet File System.

HPE Advisory #2 - HPE published an advisory that discusses an incorrect behavior order vulnerability in their Superdome Flex and Superdome Flex 280 Servers.

HPE Advisory #3 - HPE published an advisory that discusses a mirrored regions with different values vulnerability in their Superdome Flex 280 Servers.

HPE Advisory #4 - HPE published an advisory that discusses an observable discrepancy vulnerability in their Superdome Flex 280 Servers.

HPE Advisory #5 - HPE published an advisory that discusses two improper input valications vulnerabilities in their HPE Superdome Flex and Superdome Flex 280 servers.

Rockwell Advisory - Rockwell published an advisory that describes two vulnerabilities in their ThinManager product.

Xerox Advisory - Xerox published an advisory that describes an improper input validation vulnerability in multiple Xerox printers.

Updates

FortiGuard Update #1 - FortiGuard published an update for their SMTP password ciphertext advisory that was originally published on June 12th, 2024.

FortiGuard Update #2 - FortiGuard published an update for their missing authentication in fgfmsd advisory that was originally published on October 23rd, 2024.

HP Update #1 - HP published an update for their PC BIOS Security Updates advisory that was originally published on August 13th, 2024.

HP Update #2 - HP published an update for their HP LaserJet Printers advisory that was originally published on October 2nd, 2024.

HPE Update #1 - HPE published an update for their Aruba Networking Controller advisory that was originally published on April 30th, 2024, and most recently updated on June 7th, 2024.

HPE Update #2 - HPE published an update for their Aruba Networking Controller advisory that was originally published on February 28th, 2024, and most recently updated on June 7th,l 2024.

Moxa Update - Moxa published an update for their Cellular Routers, Secure Routers, and Network Security Appliances advisory that was originally published on October 14th, 2024.

VMware Update - Broadcom published an update for their VMware vCenter Server advisory that was originally published on September 17th, 2024, and most recently updated on September 20th, 2024.

Researcher Reports

ABB Reports - Zero Science Labs published four reports describing individual vulnerabilities (with publicly available exploits) in the ABB Cylon Aspect building energy management product.

EmbedThis Reports - Nozomi Networks published three reports describing vulnerabilities in the EmbedThis GoAhead Web Server.

LAWO Report - SEC Consult published a report that describes a path traversal vulnerability in the LAWO LTC Time Sync device.

Exploits

Rittal Exploit - Johannes Kruchem published an exploit for improper signature verification and predictable session identifier vulnerabilities in the Rittal IoT Interface and CMC III Processing Unit.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-dae - subscription required.

Sunday, October 20, 2024

Review – Public ICS Disclosures – Week of 10-12-24 – Part 2

For Part 2 we have 18 additional vendor disclosures from Moxa, SEL (2), Splunk (13), TAI Smart Factory, and VMware. There are also four vendor updates from FortiGuard (2), Mitsubishi Electric, and Palo Alto Networks. There are also two researcher reports for vulnerabilities in products from ABB and Rittal. Finally, we have an exploit for products from WatchGuard.

Advisories

Moxa Advisory - Moxa published an advisory that describes two vulnerabilities in their Cellular Routers, Secure Routers, and Network Security Appliances.

SEL Advisory #1 - SEL published a new version notice that describes cybersecurity enhancements for their SEL-5703 Synchrowave Monitoring product.

SEL Advisory #2 - SEL published a new versions notice that describes cybersecurity enhancements for their SEL-5702 Synchrowave Operations product.

Splunk Advisory #1 - Splunk published an advisory that describes an arbitrary file write vulnerability in their Enterprise for Windows product.

Splunk Advisory #2 - Splunk published an advisory that describes a missing authorization vulnerability in their SplunkDeploymentServerConfig app.

Splunk Advisory #3 - Splunk published an advisory that describes a deserialization of untrusted data vulnerability in their Enterprise on Windows product.

Splunk Advisory #4 - Splunk published an advisory that describes an improper access control vulnerability in their Classic Dashboard product.

Splunk Advisory #5 - Splunk published an advisory that describes an improper access control vulnerability in their Secure Gateway App.

Splunk Advisory #6 - Splunk published an advisory that describes an uncontrolled resource consumption vulnerability in their Daemon product.

Splunk Advisory #7 - Splunk published an advisory that describes a cross-site request forgery vulnerability in their Enterprise and Cloud Platform products.

Splunk Advisory #8 - Splunk published an advisory that describes an insertion of sensitive information into a log file vulnerability in their Enterprise product.

Splunk Advisory #9 - Splunk published an advisory that describes an insertion of sensitive information into a log file vulnerability in their Enterprise product.

Splunk Advisory #10 - Splunk published an advisory that describes a cross-site scripting vulnerability in their Enterprise product.

Splunk Advisory #11 - Splunk published an advisory that describes a cross-site scripting vulnerability in their Enterprise product.

Splunk Advisory #12 - Splunk published an advisory that discusses 68 vulnerabilities in their Enterprise product.

Splunk Advisory #13 - Splunk published an advisory that discusses four vulnerabilities (one with publicly available exploit) in their Add-on for Office 365 product.

TAI Advisory - Incibe-CERT published an advisory that describes an SQL injection vulnerability in the TAI Smart Factory's QPLANT plant data management product.

VMware Advisory - Broadcom published an advisory that describes an SQL injection vulnerability in their HCX product.

UPDATES

FortiGuard Update #1 - FortiGuard published an update for their regreSSHion  advisory that was originally published on July 9th, 2024, and most recently updated on September 11th, 2024.

FortiGuard Update #2 - FortiGuard published an update for their Format String Bug that was originally published on February 8th, 2024, and most recently updated on October 11th, 2024.

Mitsubishi Update - Mitsubishi published an update for their GENESIS64 advisory that was originally published on June 27th, 2024.

Palo Alto Networks Update - Palo Alto Networks published an update for their Firewall Denial of Service advisory that was originally published on October 9th, 2024.

Researcher Reports

ABB Reports - Zero Science published five reports about individual vulnerabilities (with publicly available exploits) in the ABB Cylon Aspect building management product.

Rittal Report - SEC Consult published a report that describes three vulnerabilities in the Rittal IoT Interface & CMC III Processing Unit.

Exploits

WatchGuard Exploit - Indoushka published an exploit for a buffer overflow vulnerability in the WatchGuard XTM Firebox.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-7cf - subscription required.

Thursday, March 2, 2023

Review – 4 Advisories and 1 Update – 3-2-23

Today, CISA’s NCCIC-ICS published three control system security advisories for products from Rittal, Baicells, and Mitsubishi. They also published a medical device security advisory for products from Medtronic. They updated a control system security advisory for products from Mitsubishi.

Advisories

Rittal Advisory - This advisory describes an improper access control vulnerability in the Rittal CMC III locks.

Baicells Advisory - This advisory described a command injection vulnerability in the Baicells LTE TDD eNodeB devices.

Mitsubishi Advisory - This advisory describes a plain-text storage of a password vulnerability in the Mitsubishi Electric MELSEC iQ-F products.

Medtronic Advisory - This advisory describes an unverified password change vulnerability in the Medtronic Micros Clinician (A51200) app and InterStim X Clinician (A51300).

Updates

Mitsubishi Update - This update provides additional information on an advisory that was originally published on July 30th, 2020 and most recently updated on November 22nd, 2022.

 

For more details on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-and-1-update-3-2-23 - subscription required.

Thursday, October 24, 2019

3 Advisories and 1 Update Published – 10-24-19


Today the CISA NCCIC-ICS published two control system security advisories for products from Honeywell and Rittal; a medical device security advisory for products from Philips; and an update for an advisory for products from Moxa.

Honeywell Advisory


This advisory describes a missing authentication for critical function vulnerability in the Honeywell IP-AK2 Access Control Panel. The vulnerability was reported by Maxim Rupp. Honeywell has a new firmware version that mitigates the vulnerability. There is no indication that Maxim was provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to download configuration files directly through a URL without authentication, exposing configuration and authorized visitor information.

Rittal Advisory


This advisory describes two vulnerabilities in the Rittal Chiller SK 3232-Series. The vulnerabilities were reported by Applied Risk. Rittal will only provide mitigation information via email (presumably to their customers). The Applied Risk report notes that: “There has been no fix supplied by the vendor. The vendor was contacted regarding the vulnerabilities on 2nd of January 2019, but did not provide a response.”

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to disrupt the primary operations of the affected component, shut down cooling to other equipment, and allow changes to the temperature set point.

NOTE: Applied Risk reports that the vulnerability resides in the third-party ethernet interface card, Carel pCOWeb. The website for that product provides a lengthy list of other products from multiple vendors that use the same interface card. Presumably some or all of those products may be affected by the same vulnerabilities.

Philips Advisory


This advisory describes an exposure of resources to wrong sphere vulnerability in the Philips IntelliSpace Perinatal obstetrics information management system. The vulnerability was reported by Brian Landrum of Coalfire LABS. Philips has provided generic workarounds and may provide an update next year that may address the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow an attacker unauthorized access to system resources, including access to execute software or to view/update files, directories, or system configuration.

Moxa Update


This update provides additional information on an advisory that was originally published on February 26th, 2019. The new information includes:

• Added affected firmware version on IKS-G6824;
• Added recommend browsers information for vulnerability 7 of IKS-G6824 (CVE-2019-6561); and
• Added link to Moxa advisory (not annotated as a change on the NCCIC-ICS advisory).

 
/* Use this with templates/template-twocol.html */