Showing posts with label RoboDK. Show all posts
Showing posts with label RoboDK. Show all posts

Tuesday, April 16, 2024

Review – 4 Advisories Published – 4-16-24

CISA’s NCCIC-ICS published four control system security advisories for products from RoboDK, Rockwell Automation, Electrolink, and Measuresoft.

Advisories

RoboDK Advisory - This advisory describes a heap-based buffer overflow vulnerability in the RoboDK RoboDK robotics development software.

Rockwell Advisory - This advisory describes an improper input validation vulnerability in the Rockwell ControlLogix and GuardLogix programmable logic controllers.

NOTE: The vendor link CISA provides in the advisory goes through an out-of-date Rockwell web portal to a 2023 advisory not associated with this vulnerability. The correct link is https://www.rockwellautomation.com/en-us/support/advisory.SD1666.html

Electrolink Advisory - This advisory describes seven vulnerabilities in the Electrolink transmitters.

Measuresoft Advisory - This advisory describes an improper access control vulnerability in the Measuresoft ScadaPro system.

 

For more information on these advisories, including links to researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-published-4-16-24 - subscription required.

Thursday, March 23, 2023

Review – 6 Advisories Published – 3-23-23

Today, CISA’s NCCIC-ICS published six control system security advisories for products from ProPump and Controls, ABB, Schneider Electric, SAUTER, CP Plus and RoboDK.

Advisories

ProPump Advisory - This advisory describes nine vulnerabilities in the ProPump Osprey Pump Controller.

ABB Advisory - This advisory describes two vulnerabilities in the ABB NE843 Pulsar Plus Controller.

Schneider Advisory - This advisory describes eight vulnerabilities in the Schneider Interactive Graphical SCADA System (IGSS).

SAUTER Advisory - This advisory describes five vulnerabilities in the SAUTER EY-modulo 5 Building Automation Stations.

CP Plus Advisory - This advisory describes an insufficiently protected credentials vulnerability in the CP Plus KVMS Pro.

RoboDK Advisory - This advisory describes an incorrect permission assignment for critical resource in the RoboDK robot development kit.

NOTE: This was a relatively bad day for system owners as four of the six vendors had little or no response towards fixing the identified vulnerabilities.

 

For more details about these advisories, including links to researcher reports and exploits, as well as a description of vendor responses, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published-3-23-23 - subscription required.

 
/* Use this with templates/template-twocol.html */