Showing posts with label Unified Automation. Show all posts
Showing posts with label Unified Automation. Show all posts

Saturday, June 3, 2023

Review – Public ICS Disclosure – Week of 5-27-23

This week we have 31 vendor disclosures from BD, Bosch, B&R, Contec, Eaton, Fuji Electric, Hitachi Energy (2), HPE (3), Mitsubishi, Splunk (15), VMware, and Zyxel (3). There are also four vendor updates from HPE (2) and Moxa (2). We also have 40 researcher reports for vulnerabilities for products from Delta Electronics (22), Fatek Automation (11), Mitsubishi, and Unified Automation (6). Finally, we have an exploit for products from Seagate.

Advisories

BD Advisory - BD published an advisory that discusses a buffer underflow vulnerability in some of their Kiestra products.

Bosch Advisory - Bosch published an advisory that describes a chip damaging vulnerability in their CPP13 and CPP14 cameras.

B&R Advisory - B&R published an advisory that discusses an abuse of service location protocol vulnerability in their ARPOL product.

Contec Advisory - Contec published an advisory that describes seven vulnerabilities in their CONPROSYS HMI System.

Eaton Advisory - Eaton published an advisory that describes a group access authorization logic vulnerability in their SecureConnect portal.

Fuji Electric - JP CERT published an advisory that describes three vulnerabilities in the Fuji Electric FRENIC RHC Loader.

Hitachi Energy Advisory #1 - Hitachi published an advisory that describes an improper output neutralization for logs vulnerability in their UNEM product.

Hitachi Energy Advisory #2 - Hitachi published an advisory that that describes an improper output neutralization for logs vulnerability in their FOXMAN-UN product.

HPE Advisory #1 - HPE published an advisory that describes an arbitrary code execution vulnerability in their Smart Storage Administrator (SSA) Offline product.

HPE Advisory #2 - HPE published an advisory that discusses four vulnerabilities in their HP-UX BIND product.

HPE Advisory #3 - HPE published an advisory that describes a denial of service vulnerability in their HP-UX IPv6 Stack.

Mitsubishi Advisory - Mitsubishi published an advisory that describes four vulnerabilities in their MELSEC iQ-R Series/iQ-F Series EtherNet/IP modules and EtherNet/IP configuration tools.

Splunk Advisories 1-3 - Splunk published three advisories for product updates for third party vulnerabilities.

Splunk Advisories 4-15 - Splunk published 12 advisories for individual vulnerabilities in multiple products.

VMware Advisory - VMware published an advisory that describes an insecure redirect vulnerability in their Workspace ONE Access and Identity Manager products.

Zyxel Advisory #1 - Zyxel published an advisory that describes two classic buffer overflow vulnerabilities in their firewalls.

Zyxel Adviosry #2 - Zyxel published an advisory that describes an OS command injection vulnerability in some of their NAS versions.

Zyxel Advisory #3 - Zyxel published an advisory that discusses recent attacks on their ZyWALL devices.

Updates

HPE Update #1 - HPE published an update for their StoreEasy Servers advisory that was originally published on February 14th, 2023 and most recently updated on March 23rd, 2023.

HPE Update #2 - HPE published an update for their OneView advisory that was originally published on February 6th, 2023.

Moxa Update #1 - Moxa published an update for their MXsecurity advisory that was originally published on March 8th, 2023 and most recently updated on May 23rd, 2023.

Moxa Update #2 - Moxa published an update for their Arm-based Computer advisory that was originally published on November 22nd, 2022.

Researcher Reports

Delta Electronics Reports - ZDI published 22 reports about individual vulnerabilities in the Delta CNCSoft-B product.

Fatek Reports - ZDI published eleven reports about individual vulnerabilities in the Fatek FvDesigner.

Mitsubishi Report - Talos Intelligence published a report describing a memory corruption vulnerability in the Mitsubishi MELSEC iQ-F FX5U MELSOFT.

Unified Automation Report #1 - Claroty published a report that describes an object validation vulnerability in the Unified Automation UaGateway.

Unified Automation Reports #2-6 - ZDI published five reports describing vulnerabilities in the Unified Automation UaGateway.

Exploits

Seagate Exploit - Ege Balci published an metsploit module for an OS command injection vulnerability in the Seagate Central External NAS Storage device.


For more details about these disclosures, including links to researcher reports and exploits, as well as a brief description of new information in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-5-27 - subscription required.


Saturday, November 26, 2022

Review – Public ICS Disclosures – Week of 11-19-22

This week we have twenty-one vendor disclosures from ABB, Aruba Networks, Belden (3), Bosch, B&R, HPE (2), Johnson and Johnson, Miele, Mitsubishi (2), Moxa (2), Omron, PcVue, Pilz (3), Unified Automation. We have two vendor updates from Mitsubishi and Schneider. Finally, we have three researcher reports of vulnerabilities in products from Callback Technologies.

Vendor Advisories

ABB Advisory - ABB published an advisory that discusses seven vulnerabilities (two with known exploits) in their ARM600 M2M Gateway.

Aruba Advisory - Aruba published an advisory that describes thirteen vulnerabilities in their EdgeConnect Enterprise product.

Belden Advisory #1 - Belden published an advisory that describes 23 vulnerabilities in their Hirschmann BAT-C2 product.

Belden Advisory #2 - Belden published an advisory that discusses an infinite loop vulnerability (with known exploit) in their Hirschmann HiLCOS products.

Belden Advisory #3 - Belden published an advisory that describes a command injection vulnerability in their Hirschmann BAT-C2.

Bosch Advisory - Bosch published an advisory that discusses 67 vulnerabilities (some with known exploits) in their PRA-ES8P2S Ethernet-Switch.

B&R Advisory - B&R published an advisory that discusses a link following vulnerability in a variety of their products.

HPE Advisory #1 - HPE published an advisory that discusses an information disclosure vulnerability in their IceWall Products.

HPE Advisory #2 - HPE published an advisory that describes four code execution vulnerabilities in their Cloudline CL2100/CL2200 Gen10 Servers.

J&J Advisory - J&J published an advisory that discusses the PrintNightmare vulnerability in their CARTO® 3 System.

Miele Advisory - CERT-VDE published an advisory that describes an authorization bypass through user-controlled key vulnerability in the Miele.

Mitsubishi Advisory #1 - Mitsubishi published an advisory that describes ten vulnerabilities in multiple FA Engineering Software products.

Mitsubishi Advisory #2 - Mitsubishi published an advisory that describes a denial-of-service vulnerability in their GOT2000 Series.

Moxa Advisory #1 - Moxa published an advisory that describes two vulnerabilities in multiple router products.

Moxa Advisory #2 - Moxa published an advisory that describes a privilege escalation vulnerability in their TN-5916 Series routers.

Omron Advisory - JP Cert published an advisory that describes three vulnerabilities in the Omron CX-Programmer.

PcVue Advisory - PcVue published an advisory that describes a clear-text storage of sensitive information vulnerability in PcVue product.

Pilz Advisory #1 - Pilz published an advisory that describes a path traversal vulnerability in several Pilz products.

Pilz Advisory #2 - Pilz published an advisory that describes two vulnerabilities (one with known exploit) in their PASvisu HMI solution.

Pilz Advisory #3 - Pilz published an advisory that describes two path traversal vulnerabilities (one with known exploit) in several Pilz products.

Unified Automation - Unified Automation published an advisory that discusses an incorrect permission assignment for critical resource vulnerability in their OPC UA SDK.

Vendor Updates

Mitsubishi Update - Mitsubishi published an update for their Ethernet Port advisory that was originally published on November 30th, 2021 and most recently updated on July 26th, 2022.

NOTE: NCCIC-ICS did not update their advisory (ICSA-21-334-02) for this new information, almost certainly because of the Thanksgiving holiday. I expect we will see that update this coming week.

Schneider Update - Schneider published an update for their APC Smart UPS advisory that was originally published on March 8th, 2022 and most recently updated on August 19th, 2022.

Researcher Reports

Callback Report #1 - Talos published a report describing a NULL pointer dereference vulnerability in the Callback CBFS Filter.

Callback Report #2 - Talos published a report describing a NULL pointer dereference vulnerability in the Callback CBFS Filter.

Callback Report #3 - Talos published a report describing a NULL pointer dereference vulnerability in the Callback CBFS Filter.

 

For more details on these disclosures, including links to third-party reports, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-6d2 - subscription required.

Sunday, July 31, 2022

Review – Public ICS Disclosure – Week of 7-23-22 – Part 2

For Part 2 this week we have three additional vendor disclosures from FileWave, OPCLabs, and Unified Automation. We also have nine vendor updates from CODESYS, HP, Mitsubishi (3), VMware, and Yokogawa (3). We also have four researcher reports for products from DD-WRT, Asuswrt, FreshTomato, and Nuki. Finally, we have two exploits for products from Dingtian, and Roxy-WI.

FileWave Advisory - FileWave published a blog post that describes two vulnerabilities in their FileWave Management Suite.

OPC Labs Advisory - OPC Labs published an advisory that describes a deserialization of untrusted data vulnerability in their QuickOPC Connectivity Explorer.

Unified Automation Advisory - Incibe CERT published an advisory that describes two vulnerabilities in the Unified Automation's OPC UA C++ Demo Server.

CODESYS Update - CODESYS published an update for their Development System V3 advisory that was originally published on July 15th, 2021 and most recently updated on June 3rd, 2022.

HP Update - HP published an update for their NVIDIA GPU Display Driver advisory that was originally published on June 2nd, 2022 and most recently updated on June 23rd, 2022.

Mitsubishi Update #1 - Mitsubishi published an update for their Multiple FA Products advisory that originally published on July 30th, 2020 and most recently updated on May 27th, 2021.

NOTE: NCCIC-ICS did not update their advisory (ICSA-20-212-03) for this information.

Mitsubishi Update #2 - Mitsubishi published an update for their Multiple FA Engineering Software Products advisory that was originally published on February 18th, 2021 and most recently updated on May 24th, 2022.

NOTE: NCCIC-ICS did not update their advisory (ICSA-21-049-02) for this information.

Mitsubishi Update #3 - Mitsubishi published an update for their Multiple FA Engineering Software Products advisory that originally published on July 30th, 2020 and most recently updated on May 24th, 2022.

NOTE: NCCIC-ICS did not update their advisory (ICSA-20-212-04) for this information.

VMware Update - VMware published an update for their vCenter Server advisory that was originally published on July 12th, 2022.

Yokogawa Update #1 - Yokogawa published an update for their Wide Area Communication Router advisory that originally published on June 30th, 2022.

NOTE: NCCIC-ICS did not need to update their advisory (ICSA-22-181-02) for this information.

Yokogawa Update #2 - Yokogawa published an update for their CAMS for HIS advisory that was originally published on May 27th, 2022.

Yokogawa Update #3 - Yokogawa published an update for their OT:ICEFALL advisory that was originally published on June 21st. 2022. The new information includes adding fix for FCN/FCJ basic software.

NOTE: NCCIC-ICS did not update their advisory (ICSA-22-174-01) for this new information.

DD-WRT Report - Talos published a report that describes a memory corruption vulnerability in the httpd unescape functionality of DD-WRT Revision 32270 - Revision 48599.

Asuswrt Report - Talos published a report that describes a memory corruption vulnerability in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.

FreshTomato Report - Talos published a report that describes a memory corruption vulnerability in the httpd unescape functionality of FreshTomato 2022.1

Nuki Report - NCC Group published a report that describes nine vulnerabilities in the Nuki smart locks.

Dingtian Exploit - Victor Hanna published an exploit for an authentication bypass vulnerability in the Dingtian-DT-R002 2Channel relay board.

Roxy-WI Exploit - Nuri Cilengir published a Metasploit module for a command injection vulnerability in the Roxy-WI web interface.

 

For more information on these disclosures, including summaries of changes made in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-7-23-9aa - subscription required.

Thursday, May 15, 2014

ICS-CERT Publishes 3 HeartBleed, 1 SQL Injection and 1 Certificate Advisories

Today the DHS ICS-CERT published five advisories; one an update of the generic OpenSSL Alert and two new control system HeartBleed advisories, a security certificate advisory and a good ‘old-fashioned’ SQL Injection advisory.

Generic OpenSSL Advisory

Instead of continuing to provide ‘letter’ updates to the original OpenSSL Alert (last updated 4-29-14), ICS-CERT upgraded the document to an Advisory. There is a lot of new information in the new Advisory, including discussions of:

• Impact;
• Background;
• The vulnerability;
• Mitigation overview;
• OpenSSL scanning;
• Detection signatures;
• Specialized search engines;

At first glance it is disappointing that there is not a list of affected and unaffected systems included in the Advisory the way there was in the earlier Alert. On closer inspection there is a download link to a spread sheet that provides that information in much more detail. I would have preferred something that would have let you know the latest date that the list had been updated (today’s was last updated 5-15-14).

Two Product Specific HeartBleed Advisories

The two product specific Advisories are for products from Unified Automation and Schneider. The UA advisory contains a link to their description of the HeartBleed vulnerability. The Schneider advisory notes that the problem is not actually theirs; it exists in a third party component (from Tableau Software). As always this raises the question of what other vendors may be using the offending application in their products and thus have the same vulnerability.

SQL Injection

This advisory is for an SQL injection advisory for CSWorks software. The vulnerability was reported by John Leitch in a coordinated disclosure via the Zero Day Initiative. CSWorks has produced an updated version that mitigates the vulnerability, though there is no mention if Leitch has verified the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to possibly execute arbitrary code.

The CSWorks security release for this vulnerability reminds system administrators that under “no circumstances should administrators give root access to CSWorks”.

Certificate Vulnerability

This advisory is for a certificate verification vulnerability in the Siemens RuggedCom Rox devices. This is apparently a self-identified vulnerability and Siemens is still working on firmware updates for the affected systems.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to execute a man-in-the-middle attack.

Pending the production of firmware updates Siemensrecommends the following interim mitigation measures:

• Secure Syslog: Siemens recommends placing the syslog server inside the trusted
network boundary until a corrected update is made available.
• Software upgrade: When updating devices running the affected ROX versions, the
identity of the update server cannot be ensured. Siemens recommends placing the
upgrade server inside the trusted network boundary.

• FTPS: Siemens recommends using SFTP for data transfer until a corrected update is available.
 
/* Use this with templates/template-twocol.html */