Showing posts with label SMA. Show all posts
Showing posts with label SMA. Show all posts

Sunday, August 31, 2025

Review – Public ICS Disclosures – Week of 8-23-25 – Part 2

For Part 2 we have six additional vendor disclosures from Philips (2), SMA, Trumpf, Welotec, and Wireshark. There are also eight vendor updates from ABB, CODESYS (2), Dell, Hitachi Energy (2), HPE, and Siemens. Finally, we have 11 researcher reports for vulnerabilities in products from Biosig Project (10) and Ilevia.

Advisories

Philips Advisory #1 - Philips published an advisory that discusses an exposure of resources to a wrong sphere vulnerability from Dockers Desktop.

Philips Advisory #2 - Philips published an advisory that discusses an out-of-bounds write vulnerability in Google Chrome.

SMA Advisory - CERT-VDE published an advisory that describes a path traversal vulnerability in the SMA Sunny Boy 3 product.

Trumpf Advisory - CERT-VDE published an advisory that discusses an exposure of sensitive information to an unauthorized actor vulnerability (with publicly available exploits) in the Trumpf Telepresence Box.

Welotec Advisory – CERT-VDE published an advisory that describes the use of a hard-coded cryptographic key vulnerability in the Welotec egOS WebGUI.

Wireshark Advisory - Wireshark published an advisory that describes an SSH dissector crash vulnerability.

Updates

ABB Update - ABB published an update for their ELSB/BLBA ASPECT advisory that was originally published on August 11th, 2025.

CODESYS Update #1 - CODESYS published an update for their Control V3 advisory that was originally published on August 4th, 2025.

CODESYS Update #2 - CODESYS published an update for their Control V3 NULL pointer dereference advisory that was originally published on August 4th, 2025.

Hitachi Energy Update #1 - Hitachi published an update for their Relion 670/650 advisory that was originally published on June 24th, 2025.

Hitachi Energy Update #2 - Hitachi published an update for their Relion 670/650 reboot vulnerability advisory that was originally published on June 24th, 2025.

HPE Update #1 - HPE published an update for their SAN Switches advisory that was originally published on June 10th, 2025.

HPE Update #2 - HPE published an update for their Compute Scale-up Server 3200 platformsadvisory that was originally published on April 22nd, 2025.

Siemens Update - Siemens published an update for their SIMATIC RTLS advisory that was originally published on August 12th, 2025.

Research Reports

Biosig Reports - Cisco Talos published ten reports describing 16 vulnerabilities (with publicly available exploits) in the Biosig libbiosig library.

Ilevia Report - Zero Science published a report that describes an authentication bypass vulnerability (with a publicly available exploit) in the Ilevia EVE X1/X5 Server.

 

For more information on these disclosures, including links to exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-b4c - subscription required.

Saturday, August 23, 2025

Review – Public ICS Disclosures – Week of 8-16-25

This is a moderately busy disclosure week. We have bulk disclosures from HPE (7). This week we have five additional vendor disclosures from Delta Electronics, Honeywell, HP, SMA, and Weissmann & Theis. We have bulk updates from Dell (5). We have three vendor updates from HPE and Siemens (2). There is also a researcher report for a vulnerability in a product from Ilevia. Finally, we have an exploit for products from Lantronix.

Bulk Disclosures

HPE published 7 disclosures.

Advisories

Delta Advisory - Delta published an advisory that describes four cross-site scripting vulnerabilities in their DIAEnergie products.

Honeywell Advisory - Honeywell published an end-of-life notice for their Select 60 Series cameras.

HP Advisory - HP published an advisory that discusses two vulnerabilities in their Security Manager product.

SMA Advisory - CERT-VDE published an advisory that describes an exposure of private personal data to an unauthorized actor vulnerability in the SMA ennexos.sunnyportal.com.

Wiesemann Advisory - CERT-VDE published an advisory that describes a missing authentication for critical function vulnerability in the Wiesemann Motherbox 3 product.

Bulk Updates

Dell published five updates for their Wyse product line.

Updates

HPE Updates - HPE published an update for their ProLiant DL/ML/XL advisory that was originally published on August 12th, 2025.

Siemens Update #1 - Siemens published an update for their Desigo CC Product Family advisory that was originally published on August 14th, 2025.

Siemens Update #2 - Siemens published an update for their e OPC UA Implementations advisory that was originally published on September 12th, 2023, and most recently updated on January 14th, 2025.

Researcher Reports

Ilevia Report - Zero Science published a report describing a server-side logging vulnerability (with publicly available exploit) in the Ilevia EVE X1 Server.

Exploits

Lantronix Exploit - Byte Reaper published an exploit for an improper restriction of XML external entity reference vulnerability in the Lantronix Provisioning Manager.


For more information on these disclosures, including links to 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-86f - subscription required.


Thursday, March 20, 2025

Review – 5 Advisories Published – 3-20-25

Today CISA published four control systems security advisories for products from SMA Solar Technology, Siemens, and Schneider Electric (2). The also published a medical device security advisory for products from Santesoft.

Advisories

SMA Advisory - This advisory describes an unrestricted upload of file with dangerous type vulnerability in the SMA Sunny Portal.

Siemens Advisory - This advisory describes an improper restriction of operations within the bounds of a memory buffer vulnerability in the Siemens Simcenter Femap product.

Schneider Advisory #1 - This advisory describes three improper input validation vulnerabilities in the Schneider Enerlin’X IFE and eIFE products.

Schneider Advisory #2 - This advisory describes an improper privilege management vulnerability in the Schneider EcoStruxure Process Expert products.

Santesoft Advisory - This advisory describes an out-of-bounds write vulnerability in the Santesoft Sante DICOM Viewer Pro.

 

For more information on these advisories, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-published-3-20-25 - subscription required.

Sunday, February 2, 2025

Review – Public ICS Disclosures – Week of 1-25-25 – Part 2

For Part 2 we have nine additional vendor disclosures from NI, Philips, Rockwell (2), QNAP, SEL, SMA Solar Technology (2), and VMware. There are eight vendor updates from FortiGuard (3), HP (4), and Palo Alto Networks. Finally, we have a researcher report for vulnerabilities in products from Wind River.

Advisories

NI Advisory - NI published an advisory that describes a dependency on vulnerable third-party component vulnerability in multiple NI products.

Philips Advisory - Philips published an advisory that discusses two recent 7-ZIP vulnerabilities (CVE-2024-11477 and CVE-2025-0411).

Rockwell Advisory #1 - Rockwell published an advisory that describes an improper handling of exceptional conditions vulnerability in their GuardLogix products.

Rockwell Advisory #2 - Rockwell published an advisory that describes a cleartext transmission of sensitive information vulnerability in their PowerFlex 755 product.

QNAP Advisory - QNAP published an advisory that discusses a ClamAV heap-based buffer overflow vulnerability.

SEL Advisory - SEL published a software update notice for their Blueframe Resource Communication Services that reports a cybersecurity enhancement.

SMA Advisory #1 - CERT-VDE published an advisory that describes a cross-site request forgery vulnerability in the SMA Cluster Controller.

SMA Advisory #2 - CERT-VDE published an advisory that describes an improper restriction of rendered UI layers or frames vulnerability in the SMA Sunny Webbox.

VMware Advisory - Broadcom published an advisory that describes five vulnerabilities in the VMware Aria Operations for Logs and VMware Aria Operations updates.

Updates

FortiGuard Update #1 - FortiGuard published an update for their unchecked boundary length advisory that was originally published on January 14th, 2025, and most recently updated on January 22nd.

FortiGuard Update #2 - FortiGuard published an update for their improper access control advisory that was originally published on February 22nd, 2024.

FortiGuard Update #3 - FortiGuard published an update for their OS command injection advisory that was originally published on October 10th, 2023.

HP Update #1 - HP published an update for their Plantronics Hub advisory that was originally published on December 20th, 2023, and most recently updated on September 11th, 2024.

HP Update #2 - HP published an update for their NVIDIA GPU Display Driver advisory that was originally published on September 6th, 2024.

HP Update #3 - HP published an update for their NVIDIA GPU Display Driver advisory that was originally published on July 1st, 2024.

HP Update #4 - HP published an update for their Intel 2024.3 IPU advisory that was originally published on October 17, 2024, and most recently updated on January 15th, 2025.

Palo Alto Networks Update - Palo Alto Networks published an update for their PAN-OS BIOS and Bootloader advisory that was originally published on January 23rd, 2025.

Researcher Reports

Wind River Report - SEC Consult published a report that describes two weak password hash algorithm vulnerabilities in the Wind River VxWorks products.

 

For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-964 - subscription required.

Saturday, March 2, 2024

Review – Public ICS Disclosures – Week of 2-26-24

This week we have 12 vendor disclosures from Aruba Networks, CODESYS, Dell, Festo, Hikvision, Hitachi Energy, HP, Moxa, Philips, SMA, Wiesemann & Theis, and VMware. There are four vendor updates from Hitachi Energy. There is a researcher report for a vulnerability in products from Qognify. Finally, we have three exploits for products from Automatic Systems (2), and Saflok.

Advisories

Aruba Advisory - Aruba published an advisory that describes ten vulnerabilities in their ClearPass Policy Manager product.

CODESYS Advisory - CODESYS published an advisory that describes an OS command injection vulnerability in their Control V3 on Linux and QNX operating systems product.

Dell Advisory - Dell published an advisory that discusses TPM Interposer BitLocker research.

Festo Advisory - CERT-VDE published an advisory that discusses 140 vulnerabilities in the Festo MES PCs.

Hikvision Advisory - Hikvision published an advisory that describes two improper server-side validation vulnerabilities in their HikCentral Professional product.

Hitachi Energy Advisory - Hitachi Energy published an advisory that discusses the Terrapin-Attack vulnerability.

HP Advisory - HP published an advisory that discusses 133 vulnerabilities in their ThinPro product. These are third-party vulnerabilities.

Moxa Advisory - Moxa published an advisory that describes a confused deputy vulnerability in their EDS-4000/G4000 Series products.

Philips Advisory - Philips published an advisory that discusses a use after free vulnerability in their EarlyVue VS30.

SMA Advisory - Incibe-CERT published an advisory that describes two vulnerabilities in the SMA Cluster Controller and Sunny Webbox products.

Wiesemann & Theis Advisory - CERT-VDE published an advisory that describes an unquoted search path vulnerability in multiple Wieseman & Theis products.

VMware Advisory - VMware published an advisory that describes an out-of-bounds read vulnerability in their Workstation Pro and Fusion products.

Updates

Hitachi Energy Update #1 - Hitachi Energy published an update for their RTU500 advisory that was originally published on December 19th, 2023.

Hitachi Energy Update #2 - Hitachi Energy published an update for their RTU500 advisory that was originally published on November 28th, 2023 and most recently updated on December 13th, 2023.

Hitachi Energy Update #3 - Hitachi Energy published an update for their OpenSSL advisory that was originally published on April 25th, 2023.

Hitachi Energy Update #4 - Hitachi Energy published an update for their IEC 61850 MMS-Server advisory that was originally published on February 14th, 2023.

Researcher Reports

Qognify Report - SEC Consult published a report that describes an uncontrolled search path element in the Qognify VMS Client Viewer.

Exploits

Automatic Systems Exploit #1 - Marcin Kozlowski published an exploit for a path traversal vulnerability in the Automatic-Systems SOC FL9600 FastLine.

Automatic Systems Exploit #2 - Marcin Kozlowski published an exploit for a use of hard-coded credentials vulnerability in the Automatic-Systems SOC FL9600 FastLine product.

Saflok Exploit - A51199deefa2c2520cea24f746d899ce published an exploit for a key derivativation vulnerability in the Saflok System 6000.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2-584 - subscription required.

Saturday, October 12, 2019

Public ICS Disclosures – Week of 09-05-19


This week we have URGENT/11 updates from three ICS vendors; seven new vendor disclosures from Siemens, Schneider (4), Beckhoff (2) and Drager; six updates of previously issued advisories from Siemens (2), Schneider (3) and Yokogawa, and one exploit of a previously reported vulnerability for products from SMA Solar Technology.

URGENT/11 Updates



Siemens Advisory


Siemens published an advisory describing twelve vulnerabilities in the Siemens SIMATIC WinAC
RTX (F) 2010. These vulnerabilities are known as Spectre, Meltdown, Spectre-NG, Foreshadow, L1 Terminal Fault (L1TF), ZombieLoad, and Microarchitectural Data Sampling (MDS). These vulnerabilities were reported by various researchers. Siemens has an update that mitigates the vulnerabilities.

Schneider Advisories


Modicon Controllers Advisory #1

Schneider published an advisory describing a file and directory information disclosure vulnerability in the Schneider Modicon brand of programmable logic controllers. The vulnerability was reported by Jared Rittle (Cisco Talos); the report includes proof-of-concept (POC) code. Schneider provides generic workarounds to mitigate the vulnerability.

Modicon Controllers Advisory #2

Schneider published an advisory describing six vulnerabilities in the Schneider Modicon brand of programmable logic controllers. The vulnerabilities were reported by Jared Rittle and Patrick DeSantis (Cisco Talos) (the CVE links below are to the individual reports which contain POC code). Schneider provides generic workarounds to mitigate the vulnerability.

The six reported vulnerabilities are:

Uncaught exception (5) - CVE-2019-6841, CVE-2019-6842, CVE-2019-6843, CVE-2019-6844 and CVE-2019-6847; and
Clear-text transmission of sensitive information - CVE-2019-6846;

Modicon Controllers Advisory #3

Schneider published an advisory describing a clear-text transmission of sensitive information vulnerability in the Schneider Modicon brand of programmable logic controllers. The vulnerability was reported by Jared Rittle (Cisco Talos). Schneider provides generic workarounds to mitigate the vulnerability.

Modicon Controllers Advisory #4

Schneider published an advisory describing three vulnerabilities in the Schneider Modicon brand of programmable logic controllers. The vulnerabilities were reported by Jared Rittle (Cisco Talos) (the CVE links below are to the individual reports which contain POC code). Schneider provides generic workarounds to mitigate the vulnerability.

The three reported vulnerabilities are:

Uncaught exception vulnerability - CVE-2019-6848; and
Information exposure (2) - CVE-2019-6849 and CVE-2019-6850

Beckhoff Advisories


TwinCat Advisory

VDE-CERT published an advisory describing a divide by zero vulnerability in the Beckhoff TwinCAT real-time controller. The vulnerability was reported by Andreas Galauner from Rapid7. The Beckhoff advisory on this vulnerability reports that they are working on an update to mitigate the vulnerability.

CE Remote Display Advisory

Beckhoff published an advisory describing an incorrect login response vulnerability in the Beckhoff CE Remote Display. The vulnerability was reported by Chen Jie from NSFOCUS and Tijl Deneut from University Howest. Beckhoff has updates that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Drager Advisory


Drager has published an advisory describing three vulnerabilities in the Drager Infinity® M300 patient monitor. Drager is self-reporting the vulnerabilities. Drager will be releasing a new version to mitigate the vulnerabilities in March 2020.

The three reported vulnerabilities are:

Network DDOS attack;
Repeated DDOS attacks; and
Information exposure

Siemens Updates


Industrial Products Update

Siemens published an update for an advisory that was originally published in May of 2017 and most recently updated on February 14th, 2019. The new information includes:

• Merged WinAC RTX 2010 SP2 and WinAC RTX F 2010 SP2 to SIMATIC WinAC RTX (F) 2010; and
• Added mitigation information for SIMATIC WinAC RTX (F) 2010

NOTE: I expect NCCIC-ICS to update their advisory this week.

SIMATIC S7 Update

Siemens published an update for an advisory that was originally reported in November 2018 and most recently updated on August 13th, 2019. The new information includes:

• Added CVE-2019-1125, CVE-2019-15666 and CVE-2019-15903; and
• Removed CVE2018-19591 from the list of fixed vulnerabilities

NOTE: NCCIC-ICS has not addressed these Linux vulnerabilities.

Schneider Updates


Floating License Manager Update

Schneider published an update for an advisory that was originally published in May 2019 and most recently updated on September 10th, 2019. The new information is updated remediations for EcoStruxure Power
Monitoring Expert.

NOTE: NCCIC-ICS may update their advisory, but they did not update for the last Schneider update.

SoMachine Update

Schneider published an update for an advisory that was originally published on August 13th, 2019. The new information is adding SoMove FDT to the list of affected products.

NOTE: NCCIC-ICS did not address this vulnerability.

Embedded Web Server Update

Schneider published an update for an advisory that was originally published in November 2018 and most recently updated on June 11th, 2019. The new information includes mitigation information for the M340 controller.

 NOTE: NCCIC-ICS did not address these vulnerabilities.

Yokogawa Update


Yokogawa published an update for an advisory that was originally published on September 27th, 2019. The new information includes updated affected version data and mitigation measures for Exaquantum.

NOTE: NCCIC-ICS will probably update their advisory this week.

SMA Exploit


Borja Merino published an exploit for a cross-site forgery vulnerability in the SMA Sunny WebBox. An advisory for the vulnerability was published on October 8th, 2019.

Wednesday, October 9, 2019

4 Advisories and 6 Updates Published – 10-08-19


Yesterday the DHS NCCIC-ICS published four control system security advisories for products from Siemens (2), GE and SMA Solar Technology. They also updated a medical device advisory for products from BD and five control system advisories for products from Siemens.

SIMATIC Advisory #1


This advisory describes a use of hard-coded cryptographic key vulnerability in the Siemens SIMATIC IT Unified Architecture Discrete Manufacturing (UADM). This vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to gain read and write access to the related TeamCenter station. The Siemens advisory notes that the remote attacker would have to be authenticated and have network access to network access to port 1434/tcp of SIMATIC IT UADM to exploit the vulnerability.

SIMATIC Advisory #2

This advisory describes an uncontrolled resource consumption vulnerability in the Siemens SIMATIC WinAC RTX (F) 2010. The vulnerability was reported by Tal Keren from Claroty. Siemens has provided generic workarounds to mitigate the vulnerability. There is no indication that Keren was provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to perform a denial-of-service attack that could compromise the availability of the service provided by the software.

GE Advisory

This advisory describes two vulnerabilities in the GE Mark VIe Controller. The vulnerabilities were reported by Sharon Brizinov of Claroty. GE provides generic workarounds to mitigate the vulnerability. There is no indication that Brizinov has been proved an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Improper authorization - CVE-2019-13554; and
Use of hard-coded credentials - CVE-2019-13918

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to create read/write/execute commands within the Mark VIe control system.

SMA Advisory


This advisory describes a cross-site request forgery vulnerability in the SMA Sunny WebBox. The vulnerability was reported by Borja Merino and Eduardo Villaverde of the Technical Inspection Laboratory of the Mining School (University of León). SMA provides generic workarounds for this end-of-life product. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to generate a denial-of-service condition, modify passwords, enable services, achieve man-in-the-middle, and modify input parameters associated with devices such as sensors.

BD Update


This update provides additional information on an advisory that was originally published on September 5th, 2019. The updated information includes:

Revised affected versions for Pyxis ES Versions; and
New mitigation measures for all products

Industrial Product Update #1

This update provides additional information on an advisory that was originally published on September 10th, 2019. The new information includes revised affected versions and mitigation measures for:

SINUMERIK 840D sl;
SINUMERIK 828D; and
SINUMERIK 808D

NOTE: This advisory describes the Siemens response to the Linux TCP SACK PANIC vulnerabilities.

SIMATIC Update #1


This update provides additional information on an advisory that was originally published on March 9th, 2019 and last updated on July 9th, 2019. The new information includes:

Renaming SIMATIC WinAC RTX 2010 to SIMATIC WinAC RTX (F) 2010;
Updating affected version numbers for SIMATIC WinAC RTX (F) 2010; and
Providing mitigation information for SIMATIC WinAC RTX (F) 2010

SIMATIC Update #2


This update provides additional information on an advisory that was originally published on May 20th, 2018 and most recently updated on May 14th, 2019. The new information includes:

Renaming SIMATIC WinAC RTX 2010 to SIMATIC WinAC RTX (F) 2010;
Updating affected version numbers for SIMATIC WinAC RTX (F) 2010; and
Providing mitigation information for SIMATIC WinAC RTX (F) 2010

Industrial Products Update #2


This update provides additional information on an advisory that was originally published on December 5th, 2017 and most recently updated on March 12th, 2019. The new information includes:

Renaming SIMATIC WinAC RTX 2010 to SIMATIC WinAC RTX (F) 2010;
Updating affected version numbers for SIMATIC WinAC RTX (F) 2010; and
Providing mitigation information for SIMATIC WinAC RTX (F) 2010

PROFINET Update


This update provides additional information on an advisory that was originally published on May 9th, 2017 and most recently updated on February 5th, 2019. The new information includes:

Renaming SIMATIC WinAC RTX 2010 to SIMATIC WinAC RTX (F) 2010;
Updating affected version numbers for SIMATIC WinAC RTX (F) 2010; and
Providing mitigation information for SIMATIC WinAC RTX (F) 2010

Other Siemens Announcements


Yesterday Siemens announced a total of five new security advisories and ten advisory updates. Some will be covered (hopefully) later this week by NCCIC-ICS and the remainder I will discuss Saturday.

 
/* Use this with templates/template-twocol.html */