Showing posts with label Trimble. Show all posts
Showing posts with label Trimble. Show all posts

Tuesday, February 11, 2025

Review – 2 Updates Published – 2-11-25

Today CISA’s NCCIC-ICS published updates for two control system security advisories for products from Trimble and 2N.

Updates

Trimble Update - This update provides additional information on the Cityworks advisory that was originally published on February 6th, 2025.

2N Update - This update provides additional information on the Access Commander advisory that was originally published on November 14th, 2024.

 

For more information on these updates, including a down-the-rabbit-hole look at the Trimble vulnerability, see my article at CFSN Detailed Analysis - https://tinyurl.com/2dmu636x - subscription required.

Friday, February 7, 2025

CISA Adds Trimble Vulnerability to KEV Catalog – 2-7-25

Today CISA announced that it had added a deserialization of untrusted data vulnerability in the Trimble Cityworks products to their Known Exploited Vulnerabilities (KEV) catalog. This vulnerability was reported by Trimble. CISA published an advisory yesterday describing this vulnerability. Trimble has published a list of indicators of compromise.

CISA has directed Federal agencies utilizing the affected Trimble products to apply “mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.” CISA has set a deadline of February 28th, 2025, for such agencies to complete these actions.

Thursday, February 6, 2025

Review – 6 Advisories Published – 2-6-25

Today CISA’s NCCIC-ICS published four control system security advisories for products from Trimble, ABB, and Schneider (2). They also published two medical device security advisories for products from Orthanc and MicroDicom.

Advisories

Trimble Advisory - This advisory describes a deserialization of untrusted data vulnerability in the Trimble Cityworks asset and work management system.

ABB Advisory - This advisory discusses a path traversal advisory in their Drive Composer products.

Schneider Advisory #1 - This advisory discusses an uncontrolled search path element vulnerability in their EcoStruxure products using FlexNet Publisher.

Schneider Advisory #2 - This advisory describes a deserialization of untrusted data vulnerability in the Schneider EcoStruxure Power Monitoring Expert.

Orthanc Advisory - This advisory describes a missing authentication for critical function vulnerability in the Orthanc Server.

MicroDicom Advisory - This advisory describes an improper certificate validation vulnerability in the MicroDicom DICOM Viewer.

 

For more information on these advisories, including links to 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published-2-6-25 - subscription required.

 
/* Use this with templates/template-twocol.html */