Showing posts with label Tibbo. Show all posts
Showing posts with label Tibbo. Show all posts

Thursday, December 19, 2024

Review – 8 Advisories Published – 12-19-24

Today CISA’s NCCIC-ICS published seven control system security advisories for products from Schneider Electric (2), Tibbo, Siemens, Delta Electronics, and Hitachi Energy (2). The also published a medical device security advisory for products from Ossur.

Advisory

Schneider Advisory #1 - This advisory describes a cross-site scripting vulnerability in multiple Schneider Modicon Controllers.

Schneider Advisory #2 - This advisory describes a classic buffer overflow vulnerability in the Schneider Accutech Manager product.

Tibbo Advisory - This advisory describes an unrestricted upload of file with dangerous type vulnerability in the Tibbo AggreGate Network Manager.

Siemens Advisory - This advisory describes a heap-based buffer overflow vulnerability in the Siemens User Management Component.

Delta Advisory - This advisory describes a deserialization of untrusted data vulnerability in the Delta DTM Soft product.

Hitachi Energy Advisory #1 - This advisory describes two vulnerabilities in the Hitachi Energy SDM600 product.

Hitachi Energy Advisory #2 - This advisory describes a classic buffer overflow vulnerability in the Hitachi Energy RTU500 series CMU.

Ossur Advisory - This advisory describes three vulnerabilities in the Ossur Logic Mobile Application.

 

For more information about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-published-12-19-24 - subscription required.

Thursday, November 19, 2015

ICS-CERT Publishes Tibbo Advisory –

This afternoon the DHS ICS-CERT published a control system advisory for the Tibbo AggreGate SCADA/HMI package. The twin unrestricted upload of file with dangerous type vulnerabilities were reported through the Zero Day Initiative by Andrea Micalizzi (rgod). Tibbo has produced a new version to mitigate the vulnerability, but there is no indication that Micalizzi has been provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that at least one of the vulnerabilities can be remotely exploited by a relatively unskilled attacker. A successful exploit if either vulnerability could allow the attacker to execute arbitrary code and commands.


There seems to be an irregularity between the version number of the updated version reported in the advisory and the updates available on the Tibbo web site. ICS-CERT reports that owners should upgrade to 5.30.06. The Tibbo web site indicates that 5.30.06 is a pre-release version of the program. I suspect that that is because Tibbo has not updated their web site to account for people needing to upgrade due to the vulnerabilities reported in this advisory. Certainly there is nothing on their web site about the problem.
 
/* Use this with templates/template-twocol.html */