Showing posts with label ScadaBR. Show all posts
Showing posts with label ScadaBR. Show all posts

Tuesday, May 19, 2026

Review – 5 Advisories and 2 Updates Published – 5-19-26

Today CISA’s NCCIC-ICS published five control system security advisories for products from  Kieback & Peter, ZKTeco, ScadaBR, Siemens, and ABB. They also published updates for products from ABB. 

Advisories  

Kieback & Peter Advisory - This advisory discusses a code injection vulnerability in the Kieback & Peter DDC Building Controllers. 

ZKTeco Advisory - This advisory describes an authentication bypass using an alternate path or channel vulnerability in the ZKTeco SSC335-GC2063-Face-0b77 CCTV cameras. 

ScadaBR Advisory - This advisory describes four vulnerabilities in ScadaBR 1.2.0. 

Siemens Advisory - This advisory discusses an out-of-bounds write vulnerability in the Siemens RUGGEDCOM APE1808 Devices.  

NOTE: I briefly discussed the Siemens advisory on Saturday. 

ABB Advisory - This advisory describes a path traversal vulnerability in the ABB CoreSense HM and CoreSense M10 products. 

NOTE: I most recently discussed the ABB advisory on October 25th, 2025. 

Updates  

ABB Update #1 - This update provides additional information for the 800xA Base advisory that was originally published on June 25th, 2025. 

NOTE: I most recently discussed the ABB advisory on January 25th, 2026. 

ABB Update #2 This update provides additional information for the RMC-100 advisory that was originally published on July 15th, 2025. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-2-updates-published-67b - subscription required. 

Thursday, December 4, 2025

CISA Adds OpenPLC ScadaBR vulnerability to KEV Catalog - 12-3-25

Yesterday CISA announced that it had added an unrestricted upload of files with dangerous type vulnerability in the “OpenPLC ScadaBR” product. The vulnerability was previously disclosed by ScadaBR along with a cross-site scripting vulnerability that CISA had already added to the KEV catalog. The vulnerability has been fixed in Scada-LTS, a successor product to ScadaBR. On May 13th, 2025, Fellipe Oliveira published an exploit for this vulnerability.

CISA has directed all federal agencies that use the affected products to apply “mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.” They have provided a deadline of December 24th, 2025, to accomplish those actions.

Friday, November 28, 2025

CISA Adds OpenPLC-ScadaBR Vulnerability to KEV Catalog – 11-28-25

Today CISA announced that they had added a cross-site scripting vulnerability in the “OpenPLC ScadaBR” product. ScadaBR reported the vulnerability in June of 2021 (no mention of OpenPLC). On March 2st, 2021, Fellipe Oliveira published two exploits (for Windows, for Linux) for the vulnerability. On October 9th of this year, Forescout’s Vedere Labs published a report about a ‘Russian aligned group’ used this vulnerability to exploit access to a honeypot (that they thought was a public water system) that had been gained via default authentication.

According to the ScadaBR web site (Google translation from Portugese) in the response to the initial report of this vulnerability by h3v0x (apparently Fellipe Oliveira):

“Here in Brazil, ScadaBR was discontinued by the developers; the last version was 1.1. ScadaBR is being continued, but not by Brazilian developers. The project has 20 contributors worldwide and is now called ScadaLTS.”

There are currently no security advisories for ScadaLTS, so maybe the vulnerability does not affect that version of the product.

CISA has directed federal agencies that are operating the affected ‘OpenPLC – ScadaBR’ product to apply “mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.” A deadline of December 19th, 2025 has been set for compliance.

Sunday, May 16, 2021

Public ICS Disclosures – Week of 5-8-21, Part 2

This week we have five additional vendor notifications from QNAP (2), VMware, and Siemens (2). We also have two vendor updates from Siemens. We also have nine researcher reports for products from Moxa (4), and Siemens (5). Finally, we have three exploits for ScadaBR (2) and OpenPLC.

The sharp-eyed reader will have noted that I have not mentioned Schneider at all in yesterday’s or today’s posts. Schneider published seven new advisories and six updates on Tuesday. I am going to have to do a ‘Part 3’ to my Public ICS Disclosures post this week. I will try to get it out later today.

QNAP Advisories

QNAP published an advisory describing a command injection vulnerability in their NAS running Malware Remover 4.x. The vulnerability was reported by polict of Shielder via the Zero Day Initiative. QNAP has an update that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

QNAP published an advisory discussing eCh0raix Ransomware. QNAP is taking the unusual step of noting that the eCh0raix ransomware has been reported to affect QNAP NAS devices. There is no mention of a particular vulnerability being used, but they do recommend (among other generic mitigation measures) not using ports 443 or 8080.

VMware Advisory

VMware published an advisory describing a cross-site scripting vulnerability in their Workspace ONE UEM console. The vulnerability was reported by Mr. Lauritz Holtmann and Mr. Leif Enders of usd AG. VMware has patches that mitigate the vulnerability. There is no indication that Holtmann has been provided an opportunity to verify the efficacy of the fix.

Siemens Advisories

Siemens published an advisory describing 13 vulnerabilities in their SINAMICS medium voltage products. Siemens has new versions for some of the products that mitigate the vulnerabilities.

The 13 reported vulnerabilities are:

• Improper restriction of operations within the bounds of a memory buffer (2) - CVE-2021-27383 and CVE-2021-27385,

• Access memory location after the end of buffer (2) - CVE-2021-27384 and CVE-2019-8280,

• Uncontrolled resource allocation - CVE-2021-27385,

• Improper initialization (4) - CVE-2019-8259, CVE-2019-8264,  CVE-2019-8265, andCVE-2019-8277,

• Out-of-bounds read (2) - CVE-2019-8260 and CVE-2019-8261,

• Heap-based buffer overflow - CVE-2019-8262,

• Stack-based buffer overflow - CVE-2019-8263,

• Improper Null termination - CVE-2019-8275,

NOTE 1: The CVE’s above with links were previously discussed by Kaspersky Labs in a report on VNC vulnerabilities.

NOTE 2: Many of these vulnerabilities were also reported earlier this week by NCCIC-ICS in the Siemens SIMATIC HMIs/WinCC Products and in the Siemens SINUMERIK products back in June of 2020

COMMENT: Siemens has been aware of these VNC problems for quite some time. I am surprised that they are just now getting around to reporting/fixing these problems in the two product lines being reported this week. I suspect that this is a problem that may have been prevented by use of a good software bill of materials.

Siemens published an advisory discussing four vulnerabilities in their Industrial PCs and CNC devices. These are third-party (Intel) vulnerabilities. Siemens is recommending updating the Bios on some of the affected products.

The four reported vulnerabilities are:

• Improper isolation of shared resources in System-on-a-chip - CVE-2020-8698,

• Improper privilege management - CVE-2020-8745,

• Improper authentication - CVE-2020-8694, and

• Improper input validation - CVE-2020-0590

Siemens Updates

Siemens published an update for their GNU/Linux subsystem advisory that was was originally published in 2018 and most recently updated on March 13th, 2021. The new information includes:

Adding the following CVEs:

CVE-2020-13529,

CVE-2020-36312,

CVE-2021-20305, and

Clarifying that the list of vulnerabilities is no longer maintained for versions below V2.8.4.

Siemens published an update for their DNSpooq – Dnsmasq advisory that was originally published on January 19th, 2021 and most recently updated on March 13th, 2021. The new information includes clarifying that a solution for SCALANCE W1750D is not expected.

NOTE: NCCIC-ICS does not update their DNSSpooq advisory for changes in vendor advisories since the NCCIC-ICS advisory links to the latest version of the vendor advisory.

Moxa Reports

Kaspersky published four reports for vulnerabilities in the Moxa NPort IA5000A Series. Moxa reported on these vulnerabilities on April 28th, 2021. The CVEs covered in the Kaspersky reports are:

CVE-2020-27149,

CVE-2020-27184,

CVE-2020-27150, and

CVE-2020-27185

NOTE: Links are to the respective Kaspersky reports.

Siemens Reports

ZDI published five reports of vulnerabilities in the Siemens Solid Edge Viewer. The vulnerabilities were reported by rgod. The vulnerabilities have been coordinated thru NCCIC-ICS with Siemens, but Siemens has not yet published an advisory for these issues. It has, however, provided CVE numbers for the vulnerabilities. The reported vulnerabilities in the ZDI reports are:

• Improper restriction of XML External Entity - CVE-2021-27492,

• Improper validation of user supplied data - CVE-2021-27490,

• Untrusted pointer dereference - CVE-2021-27496,

• Stack-based buffer overflow - CVE-2021-27494, and

• Out-of-bounds write - CVE-2021-27488

NOTE: Links are to the respective ZDI report.

ScadaBR Exploits

Fellipe Oliveira published two different exploits for a vulnerability in ScadaBr. There is a CVE number (CVE-2021-26828) provided but there is no information on that CVE in either the Mitre or NIST databases. These may be 0-day exploits. The exploits employ separate techniques:

Authenticated arbitrary file upload, and

Linux shell upload

NOTE: Links are to the exploit reports.

OpenPLC Exploit

Fellipe Oliveira published an exploit for a remote code execution vulnerability in the OpenPLC WebServer. There is no CVE number or reference to vendor notification. This may be a 0-day exploit.

Saturday, April 3, 2021

Public ICS Disclosures – Week of 3-27-21

This week we have four vendor disclosures from Bosch (2), Dell, and VMware. There is an update from CODESYS. We also have three researcher reports for products from Rockwell Automation and Softing (2). Finally, we have an exploit for ScadaBR.

Bosch Advisories

Bosch published an advisory describing a stack-based buffer overflow in their Rexroth ActiveMover product using Ethernet IP. This is a third-party (Hilscher) vulnerability. Bosch has a newer version that mitigates the vulnerabilty.

 

Bosch published an advisory describing a stack-based buffer overflow in their Rexroth ActiveMover using Profinet. This is a third-party (Hilscher) vulnerability. Bosch provides generic workarounds to mitigate the vulnerability.

Dell Advisory

Dell published an advisory describing a configuration vulnerability in their Wyse ThinOS. The vulnerability was reported by Emanuel Rodrigues. Dell has new versions that mitigate the vulnerability. There is no indication that Rodrigues has been provided an opportunity to verify the efficacy of the fix.

VMware Advisory

VMware has published an advisory describing two vulnerabilities in their vRealize Operations product. The vulnerabilities were reported by Egor Dimitrenko of Positive Technologies. VMware has updates that mitigate the vulnerabilities. There is no indication that Dimitrenko has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Server-side request forgery - CVE-2021-21975, and

• Arbitrary file write - CVE-2021-21983

NOTE: Tenable has published a report on these vulnerabilities.

CODESYS Update

CODESYS published an update [.PDF download link] for their Control V3 password handling advisory that was originally published on August 1st, 2019 and most recently updated on May 14th, 2020. The new information includes:

• Enabling online user management by default,

• Adding additional JIRA reference CDS-73742, and

• Extending available software updates by V3.5.17.0 update

NOTE: The NCCIC-ICS advisory (ICSA-19-213-04) has not yet been updated.

Rockwell Report

Claroty published a report on the Rockwell FactoryTalk AssetCentre vulnerabilities that were announced earlier this week.

Softing Reports

Gruppo Tim published two reports for vulnerabilities in the Softing AG OPC Toolbox. The reports contain proof of concept code. There is no indication that Softing has been contacted.

The two reported vulnerabilities are:

• Cross-site scripting - CVE-2021-29661, and

• Cross-site request forgery - CVE-2021-29660

ScadaBR Exploit

Fellipe Oiveira published an exploit for an arbitrary file upload vulnerability in the ScadaBR. There are no CVEs or indications that the vendor has been contacted. This may be a 0-day exploit.

 
/* Use this with templates/template-twocol.html */