Showing posts with label VISAM. Show all posts
Showing posts with label VISAM. Show all posts

Tuesday, March 21, 2023

Review – 7 Advisories and 1 Update Published – 3-21-23

Today, CISA’s NCCIC-ICS published seven control system security advisories for products from Siemens (3), Rockwell Automation, VISAM, Delta Electronics, Keysight Technologies, and Hitachi Energy.

Advisories

SCALANCE Advisory - This advisory discusses 17 vulnerabilities in the Siemens SCALANCE W-700 product line.

RADIUS Advisory - This advisory discusses an infinite loop vulnerability in the Siemens RADIUS client of SIPROTEC 5 devices.

RUGGEDCOM Advisory - This advisory discusses seven TOCTOU race condition vulnerabilities in the Siemens RUGGEDCOM APE1808 Product Family.

Rockwell Advisory - This advisory describes three vulnerabilities in the Rockwell ThinManager ThinServer.

VISAM Advisory - This advisory describes seven improper restriction of XML entity reference vulnerabilities in the VISAM VBASE Automation Base. 

Delta Advisory - This advisory describes 13 vulnerabilities in the Delta InfraSuite Device Master.

Keysight Advisory - This advisory describes a deserialization of untrusted data vulnerability in the Keysight N6854A Geolocation Sever.

Updates

Hitachi Energy Update - This update provides additional information on an advisory that was originally published on December 9th, 2021.

 

For more details about these advisories, including links to 3rd party advisories and exploits, as well as a brief summary of changes made in the update, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-1-update-published-541 - subscription required.

Saturday, September 17, 2022

Review – Public ICS Disclosures – Week of 9-10-22 – Part 1

This is the weekend after the 2nd Tuesday disclosures so this will be a two-part report. For Part 1 we have 39 vendor disclosures from Broadcom (25), Dell, Hitachi Energy, Honeywell, HPE (2), Palo Alto Networks (4), Schneider, Red Lion, TI, and VISAM.

Broadcom Advisories - Broadcom published 25 advisories for vulnerabilities in Brocade Fabric OS.

Dell Advisory - Dell published an advisory that describes a regular expression vulnerability in the their Wyse ThinOS.

Hitachi Energy Advisory - Hitachi Energy published an advisory that discusses 48 vulnerabilities in their Disk Array products.

Honeywell Advisory - Honeywell published an advisory that announces the end-of-life status of certain OmniProx™ Clamshell Prox Card SKUs.

HPE Advisory #1 - HPE published an advisory that describes four vulnerabilities in their Integrated Lights-Out 5 products.

HPE Advisory #2 - HPE published an advisory that discusses an infinite loop vulnerability in their Integrated Lights-Out 5 (iLO 5), and Integrated Lights-out 4 products.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes a link following vulnerability in their Cortex XDR Agent.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that discusses a Windows® registry vulnerability in their Cortex XDR Agent.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory that discusses an improper input validation vulnerability in the NVIDIA Dataplane Development Kit.

Palo Alto Networks Advisory #4 - Palo Alto Networks published an advisory that discusses a file access vulnerability in their Cortex XDR Agent.

Schneider Advisory - Schneider published an advisory that describes a deserialization of untrusted data vulnerability in their EcoStruxure Machine SCADA Expert and Pro-face BLUE Open Studio products.

Red Lion Advisory - Red Lion published an advisory that describes a path traversal vulnerability in their Crimson software.

TI Advisory - TI published an advisory that describes a flash memory vulnerability in their SimpleLink MSP432EXX SDK.

VISAM Advisory - Incibe-CERT published an advisory describing a credential disclosure vulnerability in the VISAM VBASE.

 

For more details about these disclosures, including links to third-party vulnerabilities and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-8df - subscription required.


Thursday, November 4, 2021

Review - 3 Advisories Published – 11-4-21

Today CISA’s NCCIC-ICS published two control system security advisories for products from AzeoTech and VISAM. They also published a medical device security advisory for products from Philips.

AzeoTech Advisory - This advisory describes four vulnerabilities in the AzeoTech DAQFactory software and application development platform.

VISAM Advisory - This advisory describes ten vulnerabilities in the VISAM VBASE Editor automation platform.

Philips Advisory - This advisory describes two SQL injection vulnerabilities in the Philips TASY Electronic Medical Record (EMR).

For more details about the advisories, including 3rd party advisories and links to exploits, as well as a discussion about the zero-day exploit reporting of the Philips vulnerabilities in August, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-published-11-4-21 - subscription required.

Thursday, July 8, 2021

Review - 2 Advisories and 1 Update Published – 7-8-21

Today CISA’s NCCIC-ICS published two control system security advisories for products from MDT Software and Rockwell Automation. They also published an update for an advisory for products from VISAM Automation.

MDT Advisory - This advisory describes seven vulnerabilities in the MDT AutoSave product.

Rockwell Advisory - This advisory describes an improper input validation vulnerability in the Rockwell MicroLogix 1100.

VISAM Update - This update provides additional information for an advisory that was originally published on 3-24-20.

For more details on these advisories see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-1-update-published - subscription required.

Tuesday, March 24, 2020

2 Advisories Published – 3-24-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Schneider and VISAM.

Schneider Advisory


This advisory describes two vulnerabilities in the Schneider Interactive Graphical SCADA System (IGSS). The vulnerabilities were reported by the Zero Day Initiative. Schneider has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Path traversal - CVE-2020-7478;
• Missing authentication for critical function - CVE-2020-7479

NCCIC-ICS reported that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow unauthorized access to sensitive data and functions.

NOTE: I briefly discussed these vulnerabilities earlier this month.

VISAM Advisory


This advisory describes five vulnerabilities in the VISAM VBASE automation platform. The vulnerabilities were reported by Gjoko Krstic of Applied Risk. VISAM has not responded to NCCIC-ICS inquiries about these vulnerabilities.

The five reported vulnerabilities are:

• Relative path traversal - CVE-2020-7008;
• Incorrect default permissions - CVE-2020-7004;
• Inadequate encryption strength - CVE-2020-10601;
• Insecure storage of sensitive information - CVE-2020-7000; and
• Stack-based buffer overflow - CVE-2020-10599

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to read the contents of unexpected files, escalate privileges to system level, execute arbitrary code on the targeted system, bypass security mechanisms, and discover the cryptographic key for the web login.

Saturday, August 10, 2019

Public ICS Disclosures – Week of 08-03-19


This week we have three new vendor disclosures concerning the VxWorks URGENT/11 vulnerabilities and three researcher announcements of vulnerabilities in products from Reliable Controls (2) and VISAM

URGENT/11 Advisories


Three new vendors have published advisories related to the VxWorks URGENT/11 vulnerabilities reported by Amis Labs; Bosch, Omron and Philips. Below I have listed links to all of the vendor disclosures that I have discovered to date:

Rockwell,
Xerox, and
Siemens (in an out-of-cycle report);
Schneider; and
• ABB, in:
AC 800PEC;
Belden
Omron (not affected)
Philips

It is great to see that Omron is reporting no exposure to the vulnerabilities. That is as valuable to their customers as the advisories being published by affected vendors.

Reliable Controls Advisories


MACH-ProWeb Advisory

Applied Risk published a report describing a relflected XSS vulnerability in the Reliable Controls MACH-ProWeb BACnet Building Controller. Applied Risk reports that they have not received a response from the vendor to their January 29th, 2019 report on this vulnerability.

Reliable Controls LicenseManager Advisory

Applied Risk published a report describing a privilege escalation vulnerability in the Reliable Controls RC-LicenseManager in the Reliable Controls RC-Studio (MACH-System) software. Applied Risk reports that they have not received a response from the vendor to their January 29th, 2019 report on this vulnerability.

VISAM Advisory


Applied Risk has publihsed a report describing five vulnerabilities in the VISAM Automation Base (VBASE) HMI / SCADA. Applied Risk reports that as of July 8th, 2019 (apparently the date of last communication from VISAM) no mitigation has been made available for these vulnerabilities.

The five reported vulnerabilities are:

• Information disclosure via directory traversal;
• Insecure file permissions privilege escalation;
• Password protection security bypass;
• Cryptographic key disclosure; and
• Buffer overflow

 
/* Use this with templates/template-twocol.html */