Showing posts with label Secomea. Show all posts
Showing posts with label Secomea. Show all posts

Saturday, February 27, 2021

Public ICS Disclosures – Week of 2-20-21

This week we have six vendor disclosures from Advantech, Aruba Networks (2), Bosch, Carestream, and VMware. We have researcher a report for products from Secomea (and B&R automation). Finally, there are two remote access exploits for products from ASUS and

Advantech Advisory

Advantech published an advisory discussing the DNSpooq vulnerabilities in their industrial cellular routers. Advantech notes that their routers are only vulnerable to the three ‘cache poisoning’ vulnerabilities. Advantech has new firmware that mitigates the vulnerabilities.

Aruba Advisories

Aruba published an advisory discussing the DNSpooq vulnerabilities in their products. Aruba reports that their products are only vulnerable to the three ‘cache poisoning’ vulnerabilities. Aruba will update the dnsmasq in “future routine maintenance patches”.

 

Aruba published an advisory describing twelve vulnerabilities in their AirWave Management Platform. The vulnerabilities were reported by multiple researchers via the BugCrowd platform. Aruba has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The twelve reported vulnerabilities are:

• Cross-site request forgery (2) - CVE-2021-29960 and CVE-2021-29961,

• Command injection (2) - CVE-2021-29962 and CVE-2021-29963,

• Improper access control - CVE-2021-29964,

• SQL injection (2) - CVE-2021-29965 and CVE-2021-29966,

• Reflected cross-site scripting - CVE-2021-29967,

• Authenticated stored cross-site scripting - CVE-2021-29968,

• Authenticated XML external entity - CVE-2021-29969, and

• Authenticated remote command injection (2) - (CVE-2021-29970 and CVE-2021-29971

Bosch Advisory

Bosch published an advisory describing three vulnerabilities in their ctrlX CORE and the IoT Gateway. These are third-party (Linux kernel and sudo) vulnerabilities. Bosch reports that the next updates for the affected products would include updates for both the kernel and sudo.

The three reported vulnerabilities are:

• Improper locking and use after free - CVE-2020-29661,

• Out-of-bounds write - CVE-2021-3156 (multiple exploits publicly available), and

• Use after free - CVE-2021-3347 (exploit publicly available)

Carestream Advisory

Carestream published an advisory [.PDF download link] describing a heap-based buffer overflow vulnerability in a number of their products. This is a third-party (Chrome) vulnerability. Carestream reports that Chrome will be updated with the next software release for most of the affected products. This vulnerability has been exploited in the wild, but not yet in Carestream products.

VMware Advisory

VMware published an advisory describing three vulnerabilities in their VMware ESXi and vCenter Server. The vulnerabilities were reported by Mikhail Klyuchnikov of Positive Technologies, and Lucas Leong via the Zero Day Initiative. VMware has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Remote code execution - CVE-2021-21972,

• Heap-based buffer overflow - CVE-2021-21974,

• Server-side request forgery - CVE-2021-21973

Tenable has published a report on the vulnerabilities noting that these vulnerabilities have been exploited in the wild. NebulabdSec has published proof-of-concept code for the RCE vulnerability.

Secomea Report

Tenable published a report (including proof-of-concept code) describing three vulnerabilities in the Secomea GateManager (also applies to B&R GateManager). The report was coordinated with both Secomea and B&R; Secomea has a new version that mitigates the vulnerability. B&R’s response is pending.

The three reported vulnerabilities include:

• Reflected cross-site scripting - CVE-2020-29028,

• Authentication token exposed in URL path - CVE-2020-29030, and

• Authenticated malicious firmware upload - CVE-2020-29029

NOTE: This is likely to be a third-party vulnerability in products from vendors other than B&R.

Remote Access Exploits

H4rk3nz0 published an exploit for a remote code execution vulnerability in the ASUS Remote Link. There is no CVE# listed and no indication that ASUS had been contacted. This may be a 0-day exploit.

MATTHEW DUNN published a Metasploit module for an authentication timing vulnerability for Remote Desktop Web Access. The is no CVE# and no indication that Microsoft has been contacted. This may be a 0-day exploit.

Saturday, December 19, 2020

Public ICS Disclosures – Week of 12-12-20

This week we have five vendor disclosures regarding the Amnesia33 vulnerabilities. There were three vendor disclosures for the SUNBURST vulnerability. There were ten other vendor disclosures for products from ABB (3), Bosch (3), WAGO, Phoenix Contact (2), and VMware. There was one vendor update from Mitsubishi. We have seven researcher reports of vulnerabilities in products from Lantronix (2), Secomea, and Eaton (4).

Amensia33 Advisories

Braun published an advisory discussing the Amnesia33 vulnerabilities. They report that none of their ‘connected devices’ is affected.

Drager published an advisory discussing the Amnesia33 vulnerabilities. They report that their medical devices are not affected.

HMS published an advisory discussing the Amnesia33 vulnerabilities. They provide a list of their products that they have confirmed are not affected.

Johnson and Johnson published an advisory discussing the Amnesia33 vulnerabilities. They report that they are investigating the potential impact of the vulnerabilities on their product line.

Spacelabs Healthcare published an advisory discussing the Amnesia 33 vulnerabilities. They report that none of their products are affected by the vulnerabilities.

Sunburst Advisories

Drager published an advisory discussing the SUNBURST vulnerability. They report that their medical devices are not affected.

Boston Scientific published an advisory discussing the SUNBURST vulnerability. They report that their products are not affected.

Philips published an advisory discussing the SUNBURST vulnerability. They report that they are monitoring developments.

ABB Advisories

ABB published an advisory [corrected link, 12-19-20 1941 EST] describing five vulnerabilities in their Central Licensing System. The vulnerabilities were reported by William Knowles at Applied Risk. ABB has new versions that mitigate the vulnerabilities. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Information disclosure - CVE-2020-8481,

• XML external entity injection - CVE-2020-8479,

• Denial of service - CVE-2020-8475,

• Elevation of privilege - CVE-2020-8476, and

• Weak file permissions - CVE-2020-8471

 

ABB published an advisory describing eight vulnerabilities in their Symphony® Plus Historian. The vulnerabilities are self-reported. ABB has an update that mitigates the vulnerabilities.

The eight reported vulnerabilities are:

• SQL injection - CVE-2020-24673,

• Improper authorization - CVE-2020-24674,

• Weak authentication - CVE-2020-24675,

• Insecure Windows services - CVE-2020-24676 -,

• Web application security - CVE-2020-24677,

• Privilege escalation - CVE-2020-24678,

• Denial of Service - CVE-2020-24679, and

• Improper credential storage - CVE-2020-24680

 

ABB published an advisory describing nine vulnerabilities in their Symphony® Plus Operations. The vulnerabilities are self-reported. ABB has an update that mitigates the vulnerabilities.

The nine reported vulnerabilities are:

• SQL injection - CVE-2020-24673,

• Improper authorization - CVE-2020-24674,

• Weak authentication - CVE-2020-24675,

• Insecure Windows services - CVE-2020-24676 -,

• Web application security - CVE-2020-24677,

• Privilege escalation - CVE-2020-24678,

• Denial of Service - CVE-2020-24679,

• Improper credential storage - CVE-2020-24680, and

• Authentication bypass - CVE-2020-24683

Bosch Advisories

Bosch published an advisory describing a null pointer dereference vulnerability in their ctrlX Products. This is a third-party OpenSSL vulnerability. Bosch has an update that mitigates the vulnerability.

 

Bosch published an advisory describing two vulnerabilities in their Rexroth IndraMotion Products. Both vulnerabilities are third-party CODESYS vulnerabilities (CVE links below are to the respective CODESYS advisories). Bosch recommends using their ctrlX CORE product to mitigate these vulnerabilities.

The two reported vulnerabilities are:

• Uncontrolled memory allocation - CVE-2020-7052 [.PDF download link], and

• Memory Corruption - CVE-2019-5105 [.PDF download link]

NOTE: Proof-of-concept code is available for the CODESYS vulnerabilities in the respective reports from Tenable and Talos.

 

Bosch published an advisory describing six vulnerabilities in their Rexroth PRC7000. These are third-party CODESYS vulnerabilities (CVE links below are to the respective CODESYS advisories). Bosch has a new firmware version that mitigates the vulnerabilities.

The six reported vulnerabilities are:

• Memory Corruption - CVE-2019-5105 [.PDF download link] Tenable report,

• Heap-based buffer overflow - CVE-2019-18858 [.PDF download link] Tenable report,

• Unverified ownership - CVE-2019-9010 [.PDF download link] NCCIC-ICS report,

• Uncontrolled memory allocation - CVE-2019-9012 [.PDF download link] NCCIC-ICS report,

• Insufficiently protected credentials - CVE-2019-9013 [.PDF download link] NCCIC-ICS report, and

• Heap-based buffer overflow - CVE-2020-10245 [.PDF download link] Tenable report.

NOTE: The respective Tenable reports include proof-of-concept code for he CODESYS vulnerabilities;

WAGO Advisory

VDE-CERT published an advisory describing an improper neutralization of special elements in an OS command vulnerability in the WAGO I/O-Check Service. The vulnerability was reported by Uri Katz of Claroty. WAGO has a new firmware version that mitigates the vulnerability.

NOTE: The Claroty report includes a Snort rule to detect the vulnerability.

Phoenix Contact Advisories

Phoenix Contact published an advisory [.PDF download link] describing a missing initialization of resource vulnerability in their mGuard products. The vulnerability was reported by SMST Designers & Constructors. Phoenix Contact has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

 

Phoenix Contact published an advisory [.PDF download link] describing four vulnerabilities in their PLCnext Control devices. The vulnerabilities were reported by Patrick Muench, Torsten Loebner, Maurice Rothe, Pascal Keul, Melanie Tholen and Daniel Hackel of SVA Systemvertrieb Alexander GmbH. Phoenix Contact has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• XSS - CVE-2020-12517,

• Exposure of sensitive information - CVE-2020-12518,

• Improper privilege management - CVE-2020-12519, and

• Improper input validation (in the PROFINET stack) - CVE-2020-12521.

NOTE: There is no indication whether the last vulnerability is unique to the Phoenix Contact implementation of PROFINET or if it is a third-party vulnerability.

VMware Advisory

VMware published an advisory describing an improper input validation vulnerability in their  ESXi, Workstation and Fusion products. The vulnerability was reported by Lucas Leong (@_wmliang_) of the Zero Day Initiative and Murray McAllister of Insomnia Security. VMware has patches that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Mitsubishi Update

Mitsubishi published an update of their Factory Automation advisory that was  originally published on July 30th, 2020 and most recently updated on November 5th, 2020. The new information includes providing mitigation information for GT SoftGOT1000.

NOTE: NCCIC-ICS published their advisory for this vulnerability and updated it in November.

Lantronix Reports

Talos published two reports (see CVE’s below for links) for vulnerabilities in the Lantronix XPort EDGE Web Manager. These are coordinated disclosures. The reports do not mention if the vulnerabilities have been corrected.

The two reported vulnerabilities are:

• Cleartext transmission of sensitive information - CVE-2020-13528, and

• CSRF - CVE-2020-13527

Secomea Report

Tenable published a report describing two vulnerabilities in the Secomea GateManager. This is a coordinated disclosure. The Tenable report includes proof-of-concept code. Tenable does not report that Secomea has produced any mitigation measures.

The two reported vulnerabilities are:

• Cross-site scripting - CVE-2020-29021, and

• HTTP host header injection - CVE-2020-29022

Tenable notes that these will be third-party vulnerabilities in products from at least B&R Industrial Automation and perhaps other vendors as well.

Eaton Reports

The Zero Day Initiative published four reports (see ZDI numbers for links) from Francis Provencher for vulnerabilities in the Eaton EASYsoft application. This is a coordinated disclosure but ZDI is reporting these as zero-day vulnerabilities.

The four reported vulnerabilities are:

• Out-of-bounds read - ZDI-20-1443, and

• File parsing type confusion (3) - ZDI-20-1444, ZDI-20-1442, and ZDI-20-1441

Saturday, October 3, 2020

Public ICS Disclosures – Week of 9-26-20

This week we have ten vendor disclosures for products from WAGO (3), IBM, Bosch, B&R Automation (2), Moxa, BD, and Philips.

WAGO Advisories

CERT-VDE published an advisory describing an improper authentication and authorization vulnerability in the WAGO 750-8XX series PLCs. The vulnerability was reported by Maxim Rupp. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

CERT-VDE published an advisory describing an improper authentication and access control vulnerability in the WAGO 750-36X and WAGO 750-8XX series PLCs. The vulnerability was reported by Maxim Rupp. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Maxim has been provided an opportunity to verify the efficacy of the fix.

CERT-VDE published an advisory describing an improper neutralization of input during web page generation vulnerability in the Web-UI for WAGO 750-88X and WAGO 750-89X series PLCs. This vulnerability was reported by Secuninja. WAGO has new firmware versions that mitigate the vulnerability. There is no indication that Secuninja has been provided an opportunity to verify the efficacy of the fix.

IBM Advisory

IBM published an advisory describing an authentication bypass vulnerability in their Maximo Asset Management product. The vulnerability is being self-reported. IBM has updates that mitigate the vulnerability.

Bosch Advisory

Bosch published an advisory describing three vulnerabilities in their PRAESIDEO Network Controller and the PRAESENSA System Controller products. The vulnerabilities were reported by Gjoko Krstic of Applied Risk. Bosch has software updates for the supported products that mitigate the vulnerabilities. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Cross-site scripting - CVE-2020-6777,

• Cross-site request forgery - CVE-2020-6776, and

• Nonce reuse attack - CVE-2020-15688

NOTE: The last is a third-party vulnerability (GoAhead web server).

B&R Advisories

B&R published an advisory describing four vulnerabilities in their GateManager product. These vulnerabilities were reported by NCCIC-ICS on July 28th as being for the Secomea GateManager.

B&R published an advisory describing six vulnerabilities in their SiteManager and GateManager procucts. These vulnerabilities were reported by NCCIC-ICS last Tuesday, but the B&R advisory was not available when I published my blog post. It is not clear if the Secomea versions of these products are also affected by these vulnerabilities.

Moxa Advisory

Moxa published an advisory describing a device information leak vulnerability in their EDR-810 Series Industrial Secure Routers. The vulnerability was reported by the National Security Agency (yep, that is what the advisory says). Moxa has provided generic workarounds to mitigate the vulnerability.

BD Advisory

BD published an advisory describing a remote code execution vulnerability (CVE-2020-1147) in a third-party component (Microsoft) of a long list of their products. BD is working on testing and validation of the Microsoft patch.

Philips Advisory

Philips published an advisory describing a privilege elevation vulnerability (CVE-220-1472) in a third-party component (Microsoft) of an undisclosed number of Philips products. No mitigation information has been provided.

Tuesday, July 28, 2020

3 Advisories and 1 Update Published – 7-28-20


Today the CISA NCCIC-ICS published three control system security advisories for products from HMS Industrial Networks, Softing Industrial, and Secomea. They also published an update for an advisory for products from Delta Industrial Automation.

HMS Advisory


This advisory describes a stack-based buffer overflow in the HMS eCatcher VPN client. The vulnerability was reported by Sharon Brizinov of Claroty. HMS has a new version that mitigates the vulnerability. There is no indication that Brizinov has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to crash the device being accessed. In addition, a buffer overflow condition may allow remote code execution with highest privileges.

NOTE: I briefly discussed this vulnerability earlier this month.

Softing Advisory


This advisory describes two vulnerabilities in the Softing OPC. The vulnerabilities were reported by Uri Katz of Claroty. Softing has a new version that mitigates the vulnerability. There is no indication that Katz has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Heap-based buffer overflow - CVE-2020-14524, and
• Uncontrolled resource consumption - CVE-2020-14522
NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to crash the device being accessed. A buffer-overflow condition may also allow remote code execution.

Secomea Advisory


This advisory describes four vulnerabilities in the Secomea GateManager VPN manager. The vulnerabilities were reported by Sharon Brizinov and Tal Keren of Claroty. Secomea has a new versin that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Improper neutralization of null byte or null character - CVE-2020-14500,
• Off-by-one error - CVE-2020-14508,
• Use of hard-coded credentials - CVE-2020-14510, and
• Use of password hash with insufficient computational effort - CVE-2020-14512

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a remote attacker to gain remote code execution on the device.

Delta Update


This update provides additional information on an advisory that was originally published on June 30th, 2020. The new information includes a link to a new version that mitigates the vulnerabilities.

 
/* Use this with templates/template-twocol.html */