Showing posts with label VDLab. Show all posts
Showing posts with label VDLab. Show all posts

Tuesday, May 28, 2019

One Advisory Published – 05-28-19


Today the DHS NCCIC-ICS published a control system advisory for products from Emerson. The advisory describes two vulnerabilities in the Emerson Ovation OCR400 Controller. The vulnerability was reported by VDLab. Emerson has provided detailed mitigation measures. There is no indication that VDLab has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Stack-based buffer overflow - CVE-2019-10967; and
Heap-based buffer overflow - CVE-2019-10965

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow privilege escalation or remote code execution, or it may halt the controller.

NOTE: The advisory notes that the vulnerabilities are “in the embedded third-party FTP server”. Failure to name the third-party vendor means it will be difficult for other vendors to know if the same vulnerability might exist in any of their products using a ‘third-party FTP server’.


Saturday, September 29, 2018

Public ICS Disclosures – Week of 09-22-18


This week we have two vendor disclosures from Yokogawa and Phoenix Contact. The Yokogawa report could show up on the NCCIC-ICS site next week.

Yokogawa


The Yokogawa advisory describes four vulnerabilities in their STARDOM controllers. The vulnerabilities were reported by VDLab of Venustech. A new software version mitigates one of the vulnerabilities and Yokogawa has provided generic workarounds for the remaining three. There is no indication that VDLab has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities (no CVE numbers are reported) are:

• Vulnerability of credential management;
• Denial of service vulnerability to remote management function;
• Hardcoded credential vulnerability of maintenance function; and
Memory exhaustion vulnerability by not permitted request

Phoenix Contact


The Phoenix Contact advisory describes an incorrect handling of web request vulnerability in their Phoenix Contact AXL F BK bus coupler. The vulnerability was reported by Anne Borcherding, Steffen Pfrang, David Meier und Christian Haas from Fraunhofer IOSB. Phoenix Contact has provided generic workarounds to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Friday, June 1, 2018

ICS-CERT Publishes 3 Advisories and Updates 2


Yesterday the DHS ICS-CERT published three control system security advisories for products from Yokogawa, GE and Delta Industrial. They also updated one medical device security advisory for products from Silex and an industrial control system security advisory for products from Rockwell.

Yokogawa Advisory 


This advisory describes a hard-coded credential vulnerability in the Yokogawa STARDOM Controllers. The vulnerability was reported by VDLab of Venustech and Dongfang Electric Corporation. Yokogawa has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to gain access to the affected device, which could result in remote code execution.

GE Advisory 


This advisory describes three vulnerabilities in the GE MDS PulseNET and MDS PulseNET Enterprise products. The vulnerability was reported by Andrea Micalizzi (rgod). GE notes that the latest version mitigates these vulnerabilities. There is no indication that rgod was provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Improper authentication - CVE-2018-10611;
• Improper restriction of XML external entity reference - CVE-2018-10613; and
Relative path traversal - CVE-2018-10615

ICS-CERT reports that that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow elevation of privilege and exfiltration of information on the host platform.

Delta Advisory


This advisory describes three vulnerabilities in the Delta Industrial Automation DOPSoft HMI editing software. The vulnerabilities were reported by B0nd @garagehackers via the Zero Day Initiative. Delta notes that the latest version mitigates the vulnerabilities. There is no indication that the researcher was provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Out of bounds read - CVE-2018-10623;
• Heap-based buffer overflow - CVE-2018-10617; and
• Stack-based buffer overflow - CVE-2018-10621

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to read sensitive information, execute arbitrary code, and/or crash the application.

Silex Update


This update provides additional information on an advisory that was originally reported on May 8th, 2018. The update provides a link to a new version of GE MobileLink/GEH-SD-320AN.

Rockwell Update


This update provides additional information on an advisory that was originally published on May 10th, 2018 and subsequently updated on May 24th, 2018. The update corrects the link to the Rockwell advisory.

 
/* Use this with templates/template-twocol.html */