Showing posts with label VinCSS. Show all posts
Showing posts with label VinCSS. Show all posts

Tuesday, January 26, 2021

1 Advisory and 3 Updates Published – 1-26-21

Today CISA’s NCCIC-ICS published a control system security update for products from Fuji Electric and updated three advisories for products from Mitsubishi, Treck and Eaton.

Fuji Advisory

This advisory describes five vulnerabilities in the Fuji Tellus Lite V-Simulator and V-Server Lite. The vulnerabilities were reported by Kimiya, Khangkito – Tran Van Khang of VinCSS (Member of Vingroup), and an anonymous researcher via the Zero Day Initiative. Fuji has a newer version that mitigates the vulnerabilities. There is no indication that the researchers have been provided with an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

Stack-based buffer overflow - CVE-2021-22637,

Out-of-bounds read - CVE-2021-22655,

Out-of-bounds write - CVE-2021-22653,

Access of uninitialized pointer - CVE-2021-22639, and

Heap-based buffer overflow - CVE-2021-22641

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to execute code under the privileges of the application.

Mitsubishi Update

This update provides additional information on an advisory that was originally published on September 1st, 2020. The new information includes updated affected version and mitigation measures for:

• R12CCPU-V,

• RD55UP06-V,

• RD55UP12-V,

• RJ71GN11-T2,

• Q03UDECPU,

• QnUDEHCPU,

• QnUDVCPU,

• QnUDPVCPU

• LnCPU(-P),

• L26CPU-(P)BT,

• RnSFCPU,

• RnPCPU,

• RnPSFCPU,

• FX5-ENET,

• FX5-ENET/IP,

• FX3U-ENET-ADP,

• FX3GE-**M*/**,

• FX3U-ENET,

• FX3U-ENET-L,

• FX3U-ENET-P502,

• FX5-CCLGN-MS

• FR-A800-E Series,

• FR-F800-E Series,

• FR-A8NCG,

• FR-E800-EPA Series, and

• FR-E800-EPB Series

Treck Update

This update provides additional information on an advisory that was originally published on December 18th, 2020. The new information includes providing the researcher names from Intel that reported the advisory.

Eaton Update

This update provides additional information on an advisory that was originally reported on January 11th, 2021. The new information includes the announcement of the availability of a patch that mitigates the vulnerability.

Tuesday, November 24, 2020

2 Advisories Published – 11-24-20

Today the CISA NCCIC-ICS published two control system security advisories for products from Fuji Electric and Rockwell Automation.

Fuji Advisory

This advisory describes an out-of-bounds write vulnerability in the Fuji V-Server Lite. The vulnerability was reported by Tran Van Khang - khangkito of VinCSS via the Zero Day Initiative. Fuji has a new version that mitigates the vulnerability. There is no indication that Khang has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow for remote code execution on the device.

Rockwell Advisory

This advisory describes three vulnerabilities in the Rockwell FactoryTalk Linx. The vulnerabilities were reported by Sharon Brizinov of Claroty. Rockwell has new versions that mitigate the vulnerability. There is no indication that Brizinov has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Improper input validation - CVE-2020-27253, and

• Heap-based buffer overflow (2) - CVE-2020-27251 and CVE-2020-27255

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow a denial-of-service condition, remote code execution, or leak information that could be used to bypass address space layout randomization (ASLR).

Thursday, October 29, 2020

2 Advisories and 2 Updates Published – 10-29-20

Today the CISA NCCIC-ICS published two control system security advisories for products from Mitsubishi. They also updated two advisories for products from WECON and Mitsubishi.

MELSEC iQ-R Advisory

This advisory describes six vulnerabilities in the TCP/IP stack of the Mitsubishi MELSEC iQ-R Series EtherNet/IP Network Interface Module. The vulnerabilities are self-reported. The Mitsubishi advisory reports that they have new versions that mitigate the vulnerabilities.

The six reported vulnerabilities are:

• Improper restriction of operations within the bounds of a memory buffer - CVE-2020-5653,

• Session fixation - CVE-2020-5654,

• Null pointer dereference - CVE-2020-5655,

• Improper access control - CVE-2020-5656,

• Argument injection ­- CVE-2020-5657, and

• Resource management errors - CVE-2020-5658

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to  result in network functions entering a denial-of-service condition or allow malware execution.

MELSEC iQ-R, Q and L Advisory

This advisory describes an uncontrolled resource consumption vulnerability in the Mitsubishi MELSEC iQ-R, Q and L Series CPU modules. The vulnerability is self-reported. The Mitsubishi advisory reports that they have new firmware versions that mitigate the vulnerability in some of the affected products.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to cause a denial-of-service condition in the Ethernet port on the CPU module.

WECON Update

This update provides additional information on an advisory that was originally published on August 25, 2020 and most recently updated on October 20th, 2020. The new information includes adding Tran Van Khang - khangkito of VinCSS to the list of researchers involved in reporting the vulnerabilities.

Mitsubishi Update

This update provides additional information on an advisory that was originally reported on October 8th, 2020. The new information includes updated version and mitigation information for the following modules:

• R00/01/02CPU,

• R04/08/16/32/120CPU,

• R04/08/16/32/120ENCPU, and

• R08/16/32/120SFCPU

 
/* Use this with templates/template-twocol.html */