Showing posts with label Salto. Show all posts
Showing posts with label Salto. Show all posts

Thursday, July 16, 2026

Review – 9 Advisories Published – 7-16-26

Today CISA’s NCCIC-ICS published nine control system security advisories for products from Rockwell Automation (5), SALTO, Siemens, AutomationDirect, and NASA. I also look at eight other new advisories published by Siemens this week. 

Advisories  

Rockwell Advisory #1 - This advisory describes a cross-site scripting vulnerability in the Rockwell FactoryTalk DataMosaix. 

Rockwell Advisory #2 - This advisory describes a double free vulnerability in the Rockwell Flex 5000 Adapter. 

Rockwell Advisory #3 - This advisory describes three vulnerabilities in multiple Rockwell product lines. 

Rockwell Advisory #4 - This advisory describes an improper validation of integrity check value vulnerability in the Rockwell 1756-EN2, 1756-EN3, and 1756-ENBT products. 

Rockwell Advisory #5 - This advisory describes four vulnerabilities in the Rockwell Arena product. 

SALTO Advisory - This advisory describes an authorization bypass through user-controlled key vulnerability in the SALTO ProAccess Space product. 

Siemens Advisory - This advisory describes four vulnerabilities in the Siemens SICAM 8 product line. 

AutomationDirect Advisory - This advisory describes six vulnerabilities in the AutomationDirect Productivity Suite. 

NASA Advisory  This advisory describes a NULL pointer dereference vulnerability in the NASA Core Flight System (cFS) Health & Safety (HS) Application. 


For more information on these advisories, as well as a listing of eight other Siemens advisories published this week, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/9-advisories-published-7-16-23 - subscription required. 

Saturday, December 7, 2019

Public ICS Disclosures – Week of 11-30-19


This week we have three vendor disclosures for products from BD, GE and Johnson Controls and an URGENT/11 update from Belden. There are also three exploit code reports for products from Fronius, Salto and YachtControl.

BD Advisory


BD published an advisory describing and anti-virus bypass vulnerability in BD products with workstations running CylancePROTECT®. The third-party vulnerability was originally reported by Skylight. BD recommends updating the CylancePROTECT product.

NOTE: I wonder what other ICS vendors bundle CylancePROTECT as a cybersecurity tool? Since the product does not need to do signature updates it would seem to be a tool designed for control system security.

GE Advisory


GE published an advisory describing two privilege escalation vulnerabilities in the GE Digital HMI/SCADA iFIX product. The vulnerability was reported by Applied Risk. GE provides generic mitigation guidance for the vulnerability.

Johnson Controls Advisory


Johnson Controls published an advisory describing vulnerabilities in a third-party component of their Software House C•CURE 9000 application. The vulnerabilities in the Flexera FlexNet Publisher licensing manage have been previously reported. Johnson Controls has an update that mitigates the vulnerability.

Belden Update


Belden published an update of their URGENT/11 advisory that was originally published July 29th, 2019 and most recently updated on October 30th, 2019. The new information includes update information for Hirschmann HiOS RSPE TSN.

Fronius Expliot


SEC Consult published a report containing exploit code for four vulnerabilities in the solar inverter series of Fronius. This is reportedly a coordinated disclosure. Fronius has a firmware patch that mitigates the vulnerabilities. There is no indication that SEC Consult has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Unencrypted communication;
• Authenticated path traversal - CVE-2019-19229;
• Backdoor account - CVE-2019-19228; and
• Outdated and vulnerable software components

NOTE: This is the first time that I have seen an easter-egg included in a vulnerability report.

Salto Exploit


SEC Consult published a report containing exploit code for six vulnerabilities in the Salto ProAccess Space management software for an access control system. This is reportedly a coordinated disclosure. Salto has a patch that mitigates the vulnerabilities. There is no indication that SEC Consult has been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Path traversal - CVE-2019-19458;
• Arbitrary file write - CVE-2019-19459;
• Stored cross-site scripting - CVE-2019-19457;
• Webserver running as Windows Service per default - CVE-2019-19460;
• Authorization issues; and
• Cleartext transmission of sensitive data

Yachtcontrol Exploit


Hodorsec published exploit code for a remote code execution vulnerability in the Yachtcontrol web application. The report includes a CVE number so this may be a coordinated disclosure.

 
/* Use this with templates/template-twocol.html */