Showing posts with label University of Birmingham. Show all posts
Showing posts with label University of Birmingham. Show all posts

Saturday, February 6, 2021

Public ICS Disclosure – Week of 1-30-21

This week we have four vendor disclosures from ABB, Belden, GE Digital, and Ruckus. There is also an update from Rockwell and Honeywell published an end-of-life notice.

ABB Advisory

ABB published an advisory describing a web-server denial of service vulnerability in their AC500 V2 products. The vulnerability was reported by Richard Thomas and Tom Chothia of the University of Birmingham. ABB has no mitigation measures for this vulnerability.

Belden Advisory

Belden published an advisory describing a denial of service vulnerability in the Hirschmann HiOS platform. The vulnerability was reported by the French Cybersecurity Agency (ANSSI). Belden has updates available that mitigate the vulnerability. There are no indications that the researchers have been provided an opportunity to verify the efficacy of the fix.

GE Advisory

GE published an advisory describing three unnamed vulnerabilities in their iFix HMI/SCADA product. The vulnerabilities were reported by Sharon Brizinov of Claroty and William Knowles with Applied Risk. GE has an upgrade that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Ruckus Advisory

Ruckus published an advisory describing a CLI passphrase vulnerability in their AP and ZD products. The vulnerability is apparently self-reported. No mitigation measures are described.

Rockwell Update

Rockwell published an update for the AENT Flex I/O Series B advisory that was originally published on October 12th, 2020. The new information includes adding a sixth classic buffer overflow vulnerability, CVE-2020-6088.

NOTE: Talos published a report this week covering this vulnerability. It included proof-of-concept code.

Honeywell EOL Notice

Honeywell published an end-of-life notice for their Maxpro VMS/NVR products.

Saturday, December 5, 2020

Public ICS Disclosure – Week of 11-28-20

This week we have three vendor disclosures for products from BD, Mitsubishi, and Phoenix Contact. There was also an update for a previous disclosure from Yokogawa.

BD Advisory

BD published an advisory discussing the Microsoft Bad Neighbor vulnerability. The advisory provides a list of potentially affected products. BD is testing the MS patch for compatibility.

Mitsubishi Advisory

Mitsubishi published an advisory describing a denial-of-service vulnerability in their Human-Machine Interfaces-GOT and Tension Controller products. This vulnerability is self-reported. Mitsubishi has provided generic workarounds pending development of a new version that mitigates the vulnerability.

Phoenix Contact Advisory

Phoenix Contact published an advisory [.PDF download link] describing an uncontrolled resource consumption vulnerability in their Touch Panels of the BTP series of articles. The vulnerability was reported by y Richard Thomas and Tom Chothia of University of Birmingham. Phoenix Contact provides generic workarounds to mitigate the vulnerability.

Yokogawa Update

Yokogawa published an update for their CAMS for HIS advisory that was originally published on July 31st, 2020 and most recently updated on September 4th, 2020. The new information includes adding  Exaopc as affected product.

 
/* Use this with templates/template-twocol.html */