Showing posts with label SUBNET. Show all posts
Showing posts with label SUBNET. Show all posts

Tuesday, May 12, 2026

Review – 6 Advisories and 1 Update Published – 5-12-26

 Today CISA’s NCCIC-ICS published six control system security advisories for products from ABB (4), Subnet Solutions, and Fuji Electric. They also updated an advisory for products from Ashlar-Vellum. 

Advisories  

ABB Advisory #1 - This advisory describes three vulnerabilities in the ABB WebPro SNMP Card PowerValue product. ABB has a new version that mitigates the vulnerabilities. 

ABB Advisory #2 - This advisory discusses an out-of-bounds write vulnerability in the ABB AC500 V3 product. 

ABB Advisory #3 - This advisory discusses an insecure default initialization of resource vulnerability in the ABB Automation Builder product.  

ABB Advisory #4 - This advisory discusses three vulnerabilities in their AC500 V3 products. 

Subnet Advisory - This advisory describes four vulnerabilities in the Subnet Solutions PowerSYSTEM Center. 

Fuji Advisory - This advisory describes an exposed dangerous method or function vulnerability in the Fuji Tellus product. 

Update  

Ashlar-Vellum Update - This update provides additional information on the Cobalt advisory that was originally published on November 25, 2025. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-1-update-published-890 - subscription required. 

Thursday, April 10, 2025

Review – 10 Advisories Published – 4-10-25

Today CISA’s NCCIC-ICS published nine control system security advisories for products from ABB, Subnet Solutions, Rockwell Automation, and Siemens (6). They also published a medical device security advisory for products from INFINITT Healthcare.

There were three additional advisories published by Siemens Tuesday that were not addressed today by CISA. I will discuss them this weekend.

Advisories

ABB Advisory - This advisory discusses eight vulnerabilities in the ABB Arctic Wireless Gateways.

Subnet Advisory - This advisory describes two vulnerabilities in the Subnet PowerSYSTEM Center 2020 products.

Rockwell Advisory - This advisory describes eleven vulnerabilities in the Rockwell Arena simulation software.

SENTRON Advisory - This advisory describes nine vulnerabilities in the Siemens SENTRON 7KT PAC1260 Data Manager.

Insights Advisory - This advisory discusses five vulnerabilities in the Siemens Insights Hub Private Cloud. These are third-party vulnerabilities.

Industrial Edge - This advisory describes a weak authentication vulnerability in the Siemens Industrial Edge Devices.

Solid Edge Advisory - This advisory describes an out-of-bounds write vulnerability in the Siemens Solid Edge SE2024 and Solid Edge SE2025 products.

SIDIS Prime Advisory - This advisory discusses fourteen vulnerabilities (three with publicly available exploits) in the Siemens SIDIS Prime product.

License Server Advisory - This advisory describes two vulnerabilities in the Siemens License Server.

INFINITT Advisory - This advisory describes three vulnerabilities in the INFINITT PACS System Manager.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/10-advisories-published-4-10-25 - subscription required.

Tuesday, November 12, 2024

Review – 3 Advisories and 2 Updates Published – 11-12-24

Today, CISA’s NCCIC-ICS published three control system advisories for products from Rockwell Automation, Hitachi Energy, and Subnet Solutions. They also updated advisories for products from Snap One and Mitsubishi Electric.

Advisories

Rockwell Advisory - This advisory describes an improper input validation vulnerability in the Rockwell FactoryTalk View ME software.

Hitachi Energy Advisory - This advisory describes two vulnerabilities in the Hitachi Energy TRO600 series radios.

Subnet Advisory - This advisory discusses three vulnerabilities in the Subnet PowerSYSTEM Center PSC 2020.

Updates

Snap One Update - This update provides additional information on the OvrC Cloud advisory that was originally published on May 16th, 2023.

Mitsubishi Update - This update provides additional information on the MELSEC Series advisory that was originally published on November 2nd, 2023.

 

For more information on these advisories, including links to 3rd party advisories and reports of related advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-and-2-updates-published-995 - subscription required. 

Thursday, July 18, 2024

Review – 3 Advisories Published – 7-18-24

Today, CISA’s NCCIC-ICS published two control system security advisories for products from Subnet Solutions and Mitsubishi Electric. They also published a medical device security advisory for products from Philips.

Advisories

Subnet Advisory - This advisory discusses a prototype pollution vulnerability with known exploits in the Subnet PowerSYSTEM Center.

Mitsubishi Advisory - This advisory discusses an improper verification of cryptographic signature vulnerability in the Mitsubishi MELSOFT MaiLab.

Philips Advisory - This advisory discusses 13 vulnerabilities (2 with known exploits) in the Philips Vue PACS product.

 

For more information on these advisories, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-published-7-18-24 - subscription required.

Tuesday, May 14, 2024

Review – 4 Advisories Published – 5-14-24

Today, CISA’s NCCIC-ICS published four control system security advisories for products from Mitsubishi Electric, Johnson Controls, SUBNET, and Rockwell Automation.

Advisories

Mitsubishi Advisory - This advisory describes 12 vulnerabilities in the multiple Mitsubishi FA Engineering software products.

Johnson Controls Advisory - This advisory describes an insertion of sensitive information into log file vulnerability in the Johnson Controls Software House C●CURE 9000 security management system.

SUBNET Advisory - This advisory describes a reliance on insufficiently trustworthy components vulnerability in the SUBNET PowerSYSTEM Center product.

Rockwell Advisory - This advisory describes an unquoted search path vulnerability in the Rockwell Factory Talk Remote Access (FTRA) product.

 

For more details about these advisories, and a brief down-the-rabbit-hole look at simple OPSEC problems, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-published-5-14-24 - subscription required.

Tuesday, May 7, 2024

Review – 2 Advisories Published – 5-7-24

Today, CISA’s NCCIC-ICS published two control system security advisories for products from SUBNET and PTC.

Advisories

SUBNET Advisory - This advisory describes a reliance on insufficiently trustworthy components vulnerability in the SUBNET Substation Server.

PTC Advisory - This advisory describes a cross-site scripting vulnerability in the PTC Codebeamer application lifecycle management platform.

 

For more information on these advisories, including a down-the-rabbit-hole look at ‘insufficiently trustworthy components’, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-published-5-7-24 - subscription required.

Tuesday, April 9, 2024

Review – 1 Advisory Published – 4-9-24

Today, CISA’s NCCIC-ICS published a control system security advisory for products from SUBNET.

Advisories

SUBNET Advisory - This advisory describes a reliance on insufficiently trustworthy component vulnerability in the Subnet PowerSYSTEM Server and Substation Server 2021.

 

For more details about this advisory, including a look at the utility of reporting CWEs in advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-published-4-9-24 - subscription required.

Friday, June 16, 2023

Review – 14 Advisories Published – 6-15-23

 Yesterday, CISA’s NCCIC-ICS published 14 control system security advisories for products from Siemens (12), Advantech, and SUBNET Solutions.

NOTE: Siemens also updated eight advisories this week, but a policy change at CISA in January means that those Siemens updates are no longer being reported by NCCIC-ICS. I will be covering them this weekend.

Advisories

Teamcenter Advisory - This advisory describes four vulnerabilities in the Siemens JT2Go and Teamcenter Visualization products.

SICAM Advisory #1 - This advisory describes three vulnerabilities in the Siemens SICAM A8000 Devices. The vulnerabilities were reported by the SEC Consult Lab.

SICAM Advisory #2 - This advisory describes six vulnerabilities in the Siemens POWER METER SICAM Q200 family.

SINAMICS Advisory - This advisory discusses 23 vulnerabilities in the Siemens SINAMICS MV (medium voltage) products.

SIMATIC Advisory #1 - This advisory discusses 108 vulnerabilities in the Siemens SIMATIC S7-1500 TM MFP.

SIMATIC Advisory #2 - This advisory discusses 53 vulnerabilities in the BIOS of the Siemens SIMATIC S7-1500 TM MFP.

SIMATIC Advisory #3 - This advisory describes a code injection vulnerability in the Siemens SIMATIC PCS 7, SIMATIC S7-PM, and SIMATIC STEP 7 V5 products.

SIMATIC Advisory #4 - This advisory describes an incorrect permission assignment for critical resource vulnerability in the Siemens SIMATIC WinCC.

SIMATIC Advisory #5 - This advisory describes a use of obsolete function (legacy OPC services) vulnerability in the Siemens SIMATIC products.

Solid Edge Advisory - This advisory describes an out-of-bounds read vulnerability in the Siemens Solid Edge SE2023 product.

TIA Portal Advisory - This advisory describes a protection mechanism failure vulnerability in the Siemens TIA Portal.

SIMOTION Advisory - This advisory describes an exposure of sensitive information due to incompatible policies vulnerable in the Siemens SIMOTION products.

Advantech Advisory - This advisory describes an untrusted pointer dereference vulnerability in the Advantech WebAccess/SCADA product.

SUBNET Advisory - This advisory describes two vulnerabilities in the SUBNET PowerSYSTEM Center.

Commentary

While Siemens reported an apparently egregious number of vulnerabilities (108 and 53 in separate advisories) in their SINAMICS medium voltage products, these are all Linux vulnerabilities and Siemens has been cumulatively reporting similar slow-to-be-fixed Linux vulnerabilities in their SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP since 2018. This is one of the problems with using a general-purpose OS for control system products. If Siemens was reporting Windows vulnerabilities, I am sure that we would be seeing a large number of such advisories being published every month. Most vendors do not report Windows related vulnerabilities because, where their products use that OS, they rely on Microsoft’s automated update service to relatively painlessly fix those problems. Interestingly, that means those products are exposed to the Internet for that service to work.

 

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/14-advisories-published-6-15-23 - subscription required.

Thursday, July 31, 2014

ICS-CERT Publishes New Type Crain-Sistrunk Advisory

Today the DHS ICS-CERT published the latest version of the Crain-Sistrunk advisory; a buffer overflow vulnerability in the SUBNET SubSTATION Server 2, Telegyr 8979 Master application. The vulnerability was detected as part of the Automatak Project Robus use of a new fuzzer targeting Telegyr 8879 telecontrol protocol implementations. SUBNET has produced a hotfix for the vulnerability that Crain-Sistrunk have validated as successfully mitigating the vulnerability.

ICS-CERT reports that a moderate to highly skilled attacker could remotely exploit this vulnerability to execute a DOS attack. SUBNET discovered a closely related vulnerability during their investigation of the Crain-Sistrunk report. Both vulnerabilities are addressed by the hotfix.

NOTE: Since this is a critical infrastructure vulnerability, ICS-CERT published this vulnerability report on the US-CERT Secure Portal on July 15th. If you are associated with electrical distribution network security you just might want to sign up for access to the US-CERT Secure Portal for early notification of future Crain-Sistrunk Telegry 8879 vulnerability reports.
 
/* Use this with templates/template-twocol.html */