Showing posts with label Roche. Show all posts
Showing posts with label Roche. Show all posts

Saturday, November 5, 2022

Review – Public ICS Disclosure – Week of 10-29-22

This week we have twelve vendor disclosures about the recent OpenSSL vulnerabilities from Aruba Networks, Broadcom, Keysight, Milestone, Moxa, Palo Alto Networks, Roche, Rockwell Automation, Software Toolbox, Watchguard, and Wind River.   We also have twelve other vendor disclosures from Belden, Hitachi, Insyde (6), Sick, and Tanzu (3). There are six vendor updates for products from CODESYS. Finally, we have two exploits for products from FLIR, and Veeder-Root.

OpenSSL Vulnerabilities Disclosures

Aruba reports that none of their products are affected by the vulnerabilities.

Broadcom provides a list of unaffected products.

Dell reports that they are reviewing their products to see which may be affected by the vulnerabilities.

Keysight reports that none of their products are affected by the vulnerabilities.

Milestone reports limited impact in their XProtect VMS 2022 R3. An update is pending.

Moxa reports that none of their products are affected by the vulnerabilities.

Palo Alto Networks reports that earlier versions of Cortex XDR Broker VM contain the affected OpenSSL version but are not affected by the vulnerabilities. Other products are not affected.

Roche reports that none of their products are affected by the vulnerabilities.

Rockwell reports that they are reviewing their products to see which may be affected by the vulnerabilities.

Software Toolbox reports that none of their products are affected by the vulnerabilities.

Watchguard provides a list of unaffected products.

Wind River provides a list of affected products. Fixes are pending.

Other Vendor Disclosures

Belden Advisory - Belden published an advisory that describes a command insertion vulnerability in their (Hirschmann) Industrial HiVision product.

Hitachi Advisory - Hitachi published an advisory that discusses 60 vulnerabilities in their Disk Array Systems. These are third-party (Microsoft) vulnerabilities

Insyde Advisory #1 - Insyde published an advisory that discusses an observable discrepancy vulnerability in their InsydeH2O product.

Insyde Advisory #2 - Insyde published an advisory that discusses two vulnerabilities in their InsydeH2O product.

Insyde Advisory #3 - Insyde published an advisory that discusses an out-of-bounds read vulnerability in their InsydeH2O product.

Insyde Advisory #4 - Insyde published an advisory that describes a stack-based buffer overflow vulnerability in their InsydeH2O product.

Insyde Advisory #5 - Insyde published an advisory that describes a stack-based buffer overflow in their InsydeH2O product.

Insyde Advisory #6 - Insyde published an advisory that describes a stack-based buffer overflow in their InsydeH2O product.

Sick Advisory - Sick reports a denial of service vulnerability in their FlexiCompact product.

NOTE: The Sick PSIRT web page continues to have problems with inoperable links.

Tanzu Advisory #1 - Tanzu published an advisory that describes a privilege escalation vulnerability in their pring-security-oauth2-client.

Tanzu Advisory #2 - Tanzu published an advisory that describes an authorization bypass vulnerability in their Spring Security product.

Tanzu Advisory #3 - Tanzu published an advisory that describes a remote code execution vulnerability in their Spring Tools 4 for Eclipse product.

CODESYS Update #1 - CODESYS published an update for their CODESYS communication server advisory that was originally published on May 19th, and most recently updated on October 6th, 2022.

CODESYS Update #2 - CODESYS published an update for their V3 web server advisory that was originally published on March 24th, 2022 and most recently updated on June 30th, 2022.

CODESYS Update #3 - CODESYS published an update for their a CODESYS communication server advisory that was originally published on March 24th, 2022 and most recently updated on June 30th, 2022.

CODESYS Update #4 - CODESYS published an update for their Control V3 online user management advisory that was originally published on March 24th, 2022 and most recently updated on June 30th 2022.

CODESYS Update #5 - CODESYS published an update for their V3 products using the CODESYS communication protocol advisory that was originally published on March 24th, 2022 and most recently updated on June 30th, 2022.

CODESYS Update #6 - CODESYS published an update for their Control V3 configuration file advisory that was originally published on March 24th, 2022, and most recently updated on October 6th, 2022.

Exploits

FLIR Exploit - Samy Younsi published a Metasploit module for a command injection vulnerability in the FLIR AX8 infrared monitoring camera.

Veeder-Root Exploit - Rose Security published an exploit for a remote configuration disclosure vulnerability in the Veeder-Rood (and probably other vendor) automated tank gauges.

 

For more details about these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-10-c49 - subscription required.

 

Thursday, November 8, 2018

One Advisory and One Update Published


Today the DHS NCCIC-ICS published a medical device security advisory for products from Philips. They also updated a previously published medical device security advisory for products from Roche.

Philips Advisory


This advisory describes a weak password requirement vulnerability in the Philips iSite and IntelliSpace PACS. The vulnerability was reported by a customer. Philips reports existing generic mitigation measures should take care of any problems with this vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access to the system could exploit the vulnerability to allow an attacker to compromise a component of the system.

Roche Update


This update provides additional information on an advisory that was originally published on November 6th, 2018. The update changes the way that the advisory reports affected version numbers of the products and corrects the location of the corporate headquarters.

Wednesday, November 7, 2018

One Advisory and One Update Published


Yesterday the DHS NCCIC-ICS published a medical device security advisory for products from Roche. It also updated a control system security advisory for products from Schneider.

Roche Advisory


This advisory describes five vulnerabilities in Point of Care handheld medical devices. The vulnerabilities were reported by Niv Yehezkel of Medigate. Roche has generic work arounds to mitigate the vulnerabilities. There is no indication that Yehezkel has been provided an opportunity to verify the efficacy of the fix (okay in this case that is just boilerplate since there are no real mitigation measures to evaluate).

The five vulnerabilities are:

• Improper authentication - CVE-2018-18561;
• OS command injection - CVE-2018-18562;
• Unrestricted upload of a file with dangerous type - CVE-2018-18563; and
Improper access control (2) - CVE-2018-18564 and CVE-2018-18565

NCCIC-ICS reports that a relatively low-skilled attacker with adjacent access could exploit these vulnerabilities to allow an attacker to gain unauthorized access to modify system settings or execute arbitrary code.

NOTE: NCCIC-ICS has taken the unusual step of listing the vulnerable devices for each vulnerability. This is a very complicated advisory, particularly since there is no practical security advice provided.

Schneider Update


This update provides new information on an advisory that was previously published on November 1st, 2018. The new information includes:

• Removing the list of products that can load the affected software and pointed at the Schneider advisory instead (the latest version of that advisory adds new affected products);
Changing the wording about the availability of the software update.

NOTE: The revised Schneider advisory also adds the following generic mitigation measure:

“Physical controls should be in place so that no unauthorized person would have access to the ICS and safety controllers, peripheral equipment or the ICS and safety networks.”

 
/* Use this with templates/template-twocol.html */