Showing posts with label Sebastian Krause. Show all posts
Showing posts with label Sebastian Krause. Show all posts

Tuesday, March 31, 2020

3 Advisories and 1 Update Published – 3-31-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Mitsubishi Electric and Hirschmann Automation and a medical device security advisory for products from BD. They also updates an advisory for products from Schneider Electric.

Mitsubishi Advisory


This advisory describes an uncontrolled resource consumption vulnerability in the Mitsubishi MELSEC programmable controllers with MELSOFT transmission port (UDP/IP). The vulnerability was reported by Rongkuan Ma, Jie Meng, and Peng Cheng. Mitsubishi provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to render the device unresponsive.

Hirschmann Advisory


This advisory describes a classic buffer-overflow vulnerability in the Hirschmann HiOS, HiSecOS. The vulnerability was reported by Sebastian Krause and Toralf Gimpel of GAI NetConsult. Hirschmann has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an unauthenticated, remote attacker to overflow a buffer and fully compromise the device.

NOTE: The NCCIC-ICS advisory is actually based on a second revision of the Belden advisory that was originally reported originally published on February 14th, 2020 and most recently updated on February 26th, 2020. The most recently added information from Belden is the CVE number and link.

BD Advisory


This advisory describes a protection mechanism failure vulnerability in the BD Pyxis MedStation and Pyxis Anesthesia (PAS) ES System. The vulnerability is self-reported. BD provides generic workarounds to mitigate the vulnerability. The BD advisory states that they are in the process of deploying a security update that strengthens kiosk mode to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with physical access could exploit the vulnerability to allow an attacker to bypass kiosk mode and view and/or modify sensitive data.

Schneider Update


This update provides additional information on an advisory that was originally published on January 16th, 2020. The new information includes an updated CVSS score for CVE-2018-7794.

Saturday, February 22, 2020

Public ICS Disclosure – Week of 2-15-20


This week we have four vendor disclosures for products from Phoenix Contact, Philips, BD and Belden. We also have one researcher report on products from Siemens.

Phoenix Contact Advisory


Phoenix Contact published an advisory [.PDF download link] describing an unauthenticated web server access vulnerability in their Emalytics Controllers ILC 2050 BI. The vulnerability was reported by Anil Parmar. Phoenix Contact has a new version that mitigates the vulnerability. There is no indication that Parmar has been provided an opportunity to verify the efficacy of the fix.

Philips Advisory


Philips published an advisory on the SweynTooth Bluetooth vulnerabilities. Philips is looking to see if any of their products are affected.

NOTE: The 12 disclosed vulnerabilities affect the Bluetooth Low Energy chipsets sold by major SoC vendors, such as Texas Instruments, NXP, Cypress, Dialog Semiconductors, Microchip,
STMicroelectronics and Telink Semiconductor.

BD Advisory


BD published an advisory describing Windows® 32K graphics vulnerabilities (CVE-2019-1458 and CVE-2019-1468) in their products using Windows operating systems. BD is currently working to test and validate the Microsoft patch for BD products. Microsoft included fixes for these vulnerabilities in their December 10th, 2019 updates.

Belden Advisory


Belden published an advisory describing a buffer overflow vulnerability in their Hirschmann HiOS and HiSecOS devices. The vulnerability was reported by Sebastian Krause and Toralf Gimpel of GAI NetConsult. Belden has updates available that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Siemens Report


Tenable published a report describing a denial of service vulnerability in the Siemens TIA Portal. Siemens published their advisory on this vulnerability earlier this month. The Tenable report includes proof of concept code.

 
/* Use this with templates/template-twocol.html */