Showing posts with label Universal Robots. Show all posts
Showing posts with label Universal Robots. Show all posts

Thursday, May 14, 2026

Review – 17 Advisories and 1 Update Published – 5-14-26

Today CISA’s NCCIC-ICS published 17 advisories for products from Universal Robots and Siemens (16) and updated an advisory for products from SWTCH. 

Siemens published two additional advisories this week that were not covered today by CISA. I will address them this weekend. 

Advisories  

Universal Robots Advisory - This advisory describes an OS command injection vulnerability in the UR Polyscope 5 software. 

Ruggedcom Advisory #1 This advisory discusses 35 vulnerabilities in the Siemens Ruggedcom Rox product. 

Ruggedcom Advisory #2 - This advisory describes an OS command injection vulnerability in the Siemens Ruggedcom Rox product. 

Ruggedcom Advisory #3 - This advisory describes an OS command injection vulnerability in the Siemens Ruggedcom Rox. 

Ruggedcom Advisory #4 - This advisory describes an argument injection vulnerability in the Siemens Ruggedcom Rox. 

SIMATIC Advisory #1 - This advisory describes three vulnerabilities in the Siemens SIMATIC S7 PLC Web Server. 

SIMATIC Advisory #2 - This advisory discusses 171 vulnerabilities in the Siemens SIMATIC CN 4100. 

SIMATIC Advisory #3 - This advisory describes an insecure default initialization of resource vulnerability in the Siemens SIMATIC HMI Unified Comfort Panels. 

SENTRON Advisory - This advisory discusses an HTTP request/response smuggling vulnerability in the Siemens SENTRON 7KT PAC1261 Data Manager. 

SIPROTEC Advisory - This advisory describes a small space of random values vulnerability in the Siemens SIPROTEC 5 products. 

Opcenter Advisory - This advisory discusses a missing authentication for critical function vulnerability in the Siemens Opcenter RDnL product. 

ROS# Advisory - This advisory describes a relative path traversal vulnerability in the Siemens ROS#. 

Industrial Devices Advisory - This advisory describes a NULL pointer dereference vulnerability in the Siemens Industrial Devices product line. 

Simcenter Advisory - This advisory describes a heap-based buffer overflow vulnerability in the Siemens Simcenter Femap product. 

Teamcenter Advisory - This advisory discusses three vulnerabilities (one with publicly available exploit) in the Siemens Teamcenter products. 

GWAP Advisory - This advisory discusses an HTTP request/response splitting vulnerability in the Siemens gPROMS Web Applications Publisher (gWAP). 

Updates  

SWTCH Update - This update provides additional information on the SWTCH EV advisory that was originally published on February 26th, 2026. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/17-advisories-and-1-update-published-543 - subscription required. 

Saturday, April 11, 2020

Public ICS Disclosures -Week of 4-4-20


This week we have three vendor disclosures for products from B&R Automation, Moxa and Rockwell Automation. There are also two sets of researcher reports for products from Advantech and Universal Robots.

B&R Advisory


B&R published an advisory describing three vulnerabilities in their Automation Studio. The vulnerabilities were reported by Yehuda Anikster and Amir Preminger from Claroty. B&R has updates that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Privilege escalation – CVE-2019-19100;
• Incomplete communication encryption and validation CVE-2019-19101;
Zip Slip vulnerability (third-party vulnerability) CVE-2019-19102

Moxa Advisory


Moxa published an advisory on the kr00k vulnerability in their products. They report that none of their products are affected.

NOTE: Negative reports about 3rd party vulnerabilities are just as important as reporting an active vulnerability in a product.

Rockwell Advisory


Rockwell published an advisory describing a file permission vulnerability in their Current Program Updater software. The vulnerability was reported by Reid Wightman from Dragos. Rockwell has new versions that mitigate the vulnerability. There is no indication that Reid has been provided an opportunity to verify the efficacy of the fix.

NOTE: Rockwell is reporting a 2017 CVE (CVE-2017-5176) for this vulnerability. That vulnerability was reported by ICS-CERT on March 21st, 2017. If NCCIC-ICS were to pick up this advisory it would probably be as an update to that earlier advisory.

Advantech Reports


The Zero Day Initiative published five related reports (here, here, here, here, and here) for 0-day arbitrary file deletion vulnerabilities in the Advantech WebAccess program. The vulnerabilities were reported by Natnael Samson. ZDI reports that it has reported all five vulnerabilities to Advantech and ICS-CERT (their naming not mine) noting: “The vendor communicated that they will rely on existing measures and will add no amendments to the code.”

Universal Robots Reports


Aliasrobotics published four reports of vulnerabilities for products from Universal Robots. The vulnerabilities were reported by rvd-bot, bedieber and bbreilin. Aliasrobotics reportedly contacted Universal Robots about these vulnerabilities but has received no replies.

The four reported vulnerabilities are (links are to github pages which include proof-of-concept exploit code):

• Missing encryption of sensitive data - CVE-2020-10267;
• Missing authentication for critical function - CVE-2020-10265;
• Insufficient verification of data authenticity - CVE-2020-10266; and
• Exposure of sensitive information to unauthorized actor - CVE-2020-10264

Tuesday, July 10, 2018

ICS-CERT Publishes 2 Advisory – Updates Spectre Alert


Today the DHS ICS-CERT published two control system security advisories for products from Schweitzer Engineering and Universal Robots. They also updated their alert for Meltdown/Spectre vulnerabilities.

Schweitzer Advisory


This advisory describes three vulnerabilities in the Schweitzer Compass and AcSELerator Architect products. The vulnerabilities were reported by Gjoko Krstic of Applied Risk. The latest versions of the software mitigate the vulnerability. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Incorrect default permissions - CVE-2018-10604;
• Improper restriction of XML external entity reference - CVE-2018-10600; and
Uncontrolled resource consumption - CVE-2018-10608

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability with publicly available exploit code to allow modification/replacement of files within the Compass installation directory, disclosure of information, or denial of service.

Universal Robots Advisory


This advisory describes two vulnerabilities in the Universal Robots Robot Controllers. The vulnerabilities were reported by Davide Quarta, Mario Polino, Marcello Pogliani, and Stefano Zanero from Politecnico di Milano as well as Federico Maggi with Trend Micro Inc. Universal Robots has described generic workarounds to mitigate the vulnerabilities. There is no indication that any of the researchers have been provided with an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Use of hard-coded credentials - CVE-2018-10633; and
• Missing authentication for critical function - CVE-2018-10635

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to run arbitrary code on the device.

Meltdown/Spectre Update


This update provides additional information on an alert that was originally published on January 11th, 2018 and updated on January 16th, 2018, January 17th, 2018, January 30th, 2018, February 20th, 2018, February 22nd, 2018, March 1st, 2018 and again on April 26th, 2018 (typo in ICS-CERT update says 4-27-18). The update provides a link to the new PEPPERL+FUCHS (ecom mobile devices) advisory that I discussed on Saturday.

 
/* Use this with templates/template-twocol.html */