Showing posts with label Snap One. Show all posts
Showing posts with label Snap One. Show all posts

Tuesday, November 12, 2024

Review – 3 Advisories and 2 Updates Published – 11-12-24

Today, CISA’s NCCIC-ICS published three control system advisories for products from Rockwell Automation, Hitachi Energy, and Subnet Solutions. They also updated advisories for products from Snap One and Mitsubishi Electric.

Advisories

Rockwell Advisory - This advisory describes an improper input validation vulnerability in the Rockwell FactoryTalk View ME software.

Hitachi Energy Advisory - This advisory describes two vulnerabilities in the Hitachi Energy TRO600 series radios.

Subnet Advisory - This advisory discusses three vulnerabilities in the Subnet PowerSYSTEM Center PSC 2020.

Updates

Snap One Update - This update provides additional information on the OvrC Cloud advisory that was originally published on May 16th, 2023.

Mitsubishi Update - This update provides additional information on the MELSEC Series advisory that was originally published on November 2nd, 2023.

 

For more information on these advisories, including links to 3rd party advisories and reports of related advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-and-2-updates-published-995 - subscription required. 

Tuesday, May 16, 2023

Review – 3 Advisories Published – 5-16-23

Today, CISA’s NCCIC-ICS published three control system security advisories for products from Rockwell (2) and Snap One.

Advisories

Rockwell Advisory #1 - This advisory describes an insufficient verification of data authenticity vulnerability in the Rockwell FactoryTalk Vantagepoint product.

Rockwell Advisory #2 - This advisory describes nine cross-site scripting vulnerabilities in the Rockwell ArmorStart products.

Snap One Advisory - This advisory describes eight vulnerabilities in the Snap One OvrC cloud platform.

 

For more details about these advisories, including a discussion about publication of security advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-published-5-16-23 - subscription required.

Thursday, January 26, 2023

Review – 7 Advisories and 1 Update Published – 1-26-23

Today, CISA’s NCCIC-ICS published seven control system security advisories for products from Landis+Gyr, Rockwell Automation, Mitsubishi Electric, Sierra Wireless, Snap One, Econolite and Delta Electronics. They also published an update for an advisory for products from Mitsubishi.

Advisories

Landis+Gyr Advisory - This advisory describes a reliance on cookies without validation vulnerability in the Landis+Gyr E850 (ZMQ200) precision meter.

Rockwell Advisory - This advisory discusses two vulnerabilities in multiple Rockwell products using the GoAhead web server.

NOTE: These vulnerabilities in the GoAhead web server from EmbedThis were originally reported by CISCO Talos in 2019.

Mitsubishi Advisory - This advisory describes an active debug code vulnerability in the Mitsubishi MELFA SD/SQ series and F-series Robot Controllers.

Sierra Wireless Advisory - This advisory describes two vulnerabilities in the Sierra Wireless AirLink routers.

Snap One Advisory - This advisory describe four vulnerabilities in the Snap One Wattbox WB-300-IP-3, a surge protector.

Econolite Advisory - This advisory describes two vulnerabilities in the Econolite EOS automated traffic control software.

Delta Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Delta Electronics CNCSoft software management platform.

Updates

Mitsubishi Update - This update provides additional information on an advisory that was originally published on January 17th, 2023.

 

For more details about these advisories, including links to researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-1-update-published-c83 - subscription required.

 
/* Use this with templates/template-twocol.html */