Showing posts with label Weidmueller. Show all posts
Showing posts with label Weidmueller. Show all posts

Monday, March 16, 2026

Review – Public ICS Disclosures – Week of 3-7-26 – Part 3

For Part 3 we have an additional bulk vendor disclosure from Schneider Electric (6). There are three additional vendor disclosures from Siemens (2) and Weidmueller. We have bulk vendor updates from Siemens (12). There are also seven vendor updates from FortiGuard (2), HP, Schneider Electric (3), and VMware. Finally, we have three exploits for products from Splunk and WatchGuard (2).

Bulk Vendor Disclosures – Schneider

Improper Resource Shutdown or Release vulnerability in Multiple Products,

Improper Neutralization vulnerability in Multiple Products,

Deserialization of Untrusted Data vulnerability on EcoStruxure™ Foxboro DCS,

Improper Control of Generation of Code ('Code Injection') vulnerability on EcoStruxure™ Automation Expert,

Use of Hard-coded Credentials vulnerability in EcoStruxure™ IT Data Center Expert, and

Deserialization of Untrusted Data vulnerability on Multiple Products.

Advisories

Siemens Advisory #1 - Siemens published an advisory that describes six vulnerabilities in their SICAM SIAPP SDK product.

Siemens Advisory #2 - Siemens published bulletin about misconfiguration in Mendix Applications.

Weidmueller Advisory - CERT-VDE published an advisory that describes four vulnerabilities in the Weidmueller Energy Meter 750-XX.

Bulk Vendor Updates – Siemens

Missing Server Certificate Validation in IAM Client,

Multiple Vulnerabilities in Fortigate NGFW Before V7.4.7 on RUGGEDCOM APE1808 Devices,

Missing Server Certificate Validation in Siemens Advanced Licensing (SALT) Toolkit,

Data Validation Vulnerability in NX Before V2512,

Multiple Vulnerabilities in Palo Alto Networks Virtual NGFW on RUGGEDCOM APE1808 Devices,

Multiple Vulnerabilities in SINEC Security Monitor before V4.9.0,

DLL Hijacking Vulnerability in Siemens Web Installer used by the Online Software Delivery,

Multiple Vulnerabilities in COMOS,

Privilege Escalation Vulnerability in WIBU CodeMeter Runtime Affecting the Desigo CC Product Family and SENTRON Powermanager,

Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5,

Privilege Escalation Vulnerability in SINAMICS Drives, and

Stored Cross-Site Scripting Vulnerability in SIMATIC S7-1500.

Updates

FortiGuard Update #1 - FortiGuard published an update for their OpenSSL advisory that was originally published on January 30th, 2026, and most recently updated on March 3rd, 2026.

FortiGuard Update #2 - FortiGuard published an update for their SSL-VPN Symlink advisory that was originally published on February 10th, 2026.

HP Update - HP published an update for their Intel NPU Driver advisory that was originally published February 25th, 2026.

Schneider Update #1 - Schneider published an update for their FlexNet Publisher advisory that was originally published on January 14th, 2025, and most recently updated on November 11th, 2025.

Schneider Update #2 - Schneider published an update for their ProLeiT Plant iT advisory that was originally published on January 13th, 2026.

Schneider Update #3 - Schneider published an update for their EcoStruxure Power Build Rapsody advisory that was originally published on January 13th, 2026.

VMware Update - Broadcom published an update for their Aria Operations advisory that was originally published on February 24th, 2026.

Exploits

Splunk Exploit - Indoushka published an exploit for a function call with incorrectly specified argument value vulnerability in the Splunk Enterprise product.

WatchGuard Exploit #1 - Indoushka published an exploit for a default SSH credentials vulnerability.

WatchGuard Exploit #2 - Indoushka published a Metasploit module for a privilege escalation vulnerability in the WatchGuard IKEv2.

 

For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-795 - subscription required.

Sunday, June 15, 2025

Review – Public ICS Disclosures – Week of 6-7-25 – Part 2

This week for Part 2 we have 17 additional vendor disclosures from Moxa, Palo Alto Networks (7), Schneider (3), Siemens, Splunk (2), Supermicro (2), and Weidmueller. Part 3 is scheduled for Tuesday.

Advisories

Moxa Advisory - Moxa published an advisory that describes an improper validation of specified type of input vulnerability in their PT-G7728 & PT-G7828 switches.

PAN Advisory #1 - Palo Alto Networks published an advisory that discusses 11 vulnerabilities in their Prisma Access Browser.

PAN Advisory #2 - Palo Alto Networks published an advisory that describes an improper neutralization of wild cards or matching symbols vulnerability in their Global Protect product.

PAN Advisory #3 - Palo Alto Networks published an advisory that describes a command injection vulnerability in their PAN-OS, Cloud NGFW, and Prisma Access products.

PAN Advisory #4 - Palo Alto Networks published an advisory that describes an OS command injection vulnerability in their PAN-OS, Cloud NGFW, and Prisma Access products.

PAN Advisory #5 - Palo Alto Networks published an advisory that describes an exposure of sensitive information to an unauthorized control sphere vulnerability in their PAN-OS, Cloud NGFW, and Prisma Access products.

PAN Advisory #6 - Palo Alto Networks published an advisory that describes an incorrect privilege assignment vulnerability in their Cortex XDR Broker VM.

PAN Advisory #7 - Palo Alto Networks published an advisory that describes a clear-text transmission of sensitive information vulnerability in their GlobalProtect App.

Schneider Advisory #1 - Schneider published an advisory that discusses multiple vulnerabilities in their Insight Home and Insight Facility products.

Schneider Advisory #2 - Schneider published an advisory that describes six vulnerabilities in their Modicon Controllers.

Schneider Advisory #3 - Schneider published an advisory that describes four vulnerabilities in their EVLink WallBox.

Siemens Advisory - Siemens published an advisory that describes a zip path traversal vulnerability in their module installation process of Studio Pro product.

Splunk Advisory #1 - Splunk published an advisory that discusses six vulnerabilities (two with publicly available exploits) in their Machine Learning Toolkit (MLTK).

Splunk Advisory #2 - Splunk published an advisory that discuses multiple vulnerabilities in their Python for Scientific Computing product, only two vulnerabilities are listed by CVE#s.

Supermicro Advisory #1 - Supermicro published an advisory that discusses an out-of-bounds read vulnerability in multiple Supermicro products.

Supermicro Advisory #2 - Supermicro published an advisory that discusses an improper access control for register intake vulnerability in multiple Supermicro products.

Weidmueller Advisory - CERT-VDE published an advisory that describes three vulnerabilities (with publicly available exploits) in the Weidmueller IE-SR-2TX security routers.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-b27 - subscription required

Sunday, June 1, 2025

Review - Public ICS Disclosures – Week of 5-25-25 – Part 2

For Part 2 this week we have six additional vendor disclosures from Lenze, Mitsubishi, PEPPERL+Fuchs, QNAP, WatchGuard, and Weidmueller. There are also nine updates from FortiGuard, Hitachi Energy (6), HP, and HPE. Finally, we have two exploits for products from Palo Alto Networks and SCADAFlare.

Advisories

Lenze Advisory - CERT-VDE published an advisory that discusses two vulnerabilities in the Lenze x500 IoT Gateway.

Mitsubishi Advisory - Mitsubishi published an advisory that describes an improper validation of specified index, position or offset in input vulnerability in their MELSEC iQ-F Series CPU module.

PEPPERL+Fuchs Advisory - CERT-VDE published an advisory that describes three vulnerabilities in the PEPPERL+Fuchs  Profinet Gateway LB8122A.1.EL.

QNAP Advisory - QNAP published an advisory that discusses an untrusted search path vulnerability in the GNU C Library.

WatchGuard Advisory - WatchGuard published an advisory that describes a privilege escalation vulnerability in their Mobile VPN product.

Weidmueller Advisory - CERT-VDE published an advisory that describes five vulnerabilities in multiple Weidmueller industrial ethernet switches.

Updates

FortiGuard Update - FortiGuard published an update for their TACACS+ authentication bypass advisory that was originally published on May 13th, 2025.

Hitachi Energy Update #1 - Hitachi Energy published an update for their IEC 61850 MMS-Server advisory that was originally published on February 14th, 2024.

Hitachi Energy Update #2 - Hitachi Energy published an update for their BadAlloc advisory that was originally published on December 16th, 2021.

Hitachi Energy Update #3 - Hitachi Energy published an update for their OpenSSL Vulnerability advisory that was originally published on June 27th, 2023.

Hitachi Energy Update #4 - Hitachi Energy published an update for their Relion 670/650/SAM600-IO advisory that was originally published on November 28th, 2023, and most recently updated on September 23rd, 2024.

Hitachi Energy Update #7 - Hitachi Energy published an update for their Hitachi Energy Relion 670/650/SAM600-IO advisory that was originally published on November 4th, 2021, and most recently updated on December 7th, 2021.

Hitachi Energy Update #6 - Hitachi Energy published an update for their Hitachi Energy’s Relion 670, 650 and SAM600-IO advisory that was originally published on February 28th, 2023.

HP Update - HP published an update for their Sound Research SECOMN64 advisory that was originally published on November 12th, 2024.

HPE Update - HPE published an update for their HPE ProLiant AMD Servers advisory that was originally published on February 3rd, 2025.

Exploits

Palo Alto Networks Exploit - Cody 16 published an exploit for a memory corruption vulnerability in the Palo Alto Networks CLI.

SCADAFlare Exploit - Fellipe Oliveira published an exploit for an unrestricted upload of file with dangerous type vulnerability in the SCADAFlare ScadaBR product.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-d6e - subscription required.

Monday, March 10, 2025

Review – Public ICS Disclosures – Week of 3-1-25 – Part 2

For Part 2 we have four additional vendor disclosures from Dell, WAGO, and Weidmueller (2). There are also two updates from Cisco and FortiGuard. We have seven researcher reports for vulnerabilities in products from ABB, Delta Electronics (3), and HP (3). Finally, we have four exploits for products from Advantech (2), ControlID, and HP.

Advisories

Dell Advisory - Dell published an advisory that discusses 64 vulnerabilities in their ThinOS product line.

WAGO Advisory - CERT-VDE published an advisory that describes an unchecked return value vulnerability in multiple WAGO products.

Weidmueller Advisory #1 - CERT-VDE published an advisory that discusses a Sweet32 vulnerability in multiple Weidmueller ethernet switches.

Weidmueller Advisory #2 - CERT-VDE published an advisory that describes a use of hard-coded credentials vulnerability in Weidmueller PROCON-WIN product.

Updates

Cisco Update - Cisco published an update for their small business routers advisory that was originally published on January 11th, 2023, and most recently updated on March 14th, 2023.

FortiGuard Update - FortiGuard published an update for their RADIUS Protocol advisory that was originally published on August 13th, 2024, and most recently updated on January 14th, 2025.

Researcher Reports

ABB Report - Zero Science published a report that describes a security bypass vulnerability (with publicly available exploit) in the ABB Cylon Aspect building energy management program.

Delta Researcher Reports - ZDI published three reports about vulnerabilities in the Delta ISPSoft product.

HP Researcher Reports - ZDI published three reports about vulnerabilities in the HP LaserJet Pro MFP 3301fdw.

Exploits

Advantech Exploit #1 - Indoushka published an exploit for an SQL injection vulnerability in the Advantech WebAccess product.

Advantech Exploit #2 - Indoushka published an exploit for an improper input validation vulnerability in the Advantech DIAEnergie product.

ControlID Exploit - Indoushka published an exploit for an improper authentication vulnerability in the ControlID iDSecure product.

HP Exploit - Indoushka published an exploit for a shell upload vulnerability in the HP Intelligent Management Center.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-a8f - subscription required.

Sunday, December 18, 2022

Review – Public ICS Disclosures – Week of 12-10-22 – Part 2

For part 2 we have twelve additional vendor disclosures from Rockwell Automation (3), Schneider (2), Sick, VMware (4), Weidmueller, and Wiesemann & Theis. We also have seven vender updates from CODESYS (3), Dell, HPE, Mitsubishi, and Omron. Finally, we have one researcher report for products from VMware.

Vendor Disclosures

Rockwell Advisory #1 - Rockwell published an advisory that describes a denial of service vulnerability in their MicroLogix 1100 & 1400 Product Web Server application.

Rockwell Advisory #2 - Rockwell published an advisory that describes a cross-site scripting vulnerability in their MicroLogix 1100 & 1400 Web Server application.

Rockwell Advisory #3 - Rockwell published an advisory that describes a denial of service vulnerability in their GuardLogix and ControlLogix controllers.

Schneider Advisory #1 - Schneider published an advisory that describes an improper authorization vulnerability in their EcoStruxure Power Commission.

Schneider Advisory #2 - Schneider published an advisory that discusses an out-of-bounds write vulnerability in their Saitel DR RTU (Remote Terminal Unit).

Sick Advisory - Sick published an advisory that describes four vulnerabilities in the n SICK RFU6xx RADIO FREQUEN. SENSOR 1.

VMware Advisory #1 - VMware published an advisory that describes two vulnerabilities in their vRealize Network Insight (vRNI) product.

VMware Advisory #2 - VMware published an advisory that describes two vulnerabilities in their Workspace ONE Access and Identity Manager.

VMware Advisory #3 - VMware published an advisory that describes a heap-based write vulnerability in their ESXi, Workstation, and Fusion products.

VMware Advisory #4 - VMware published an advisory that describes two vulnerabilities in their vRealize Operations product.

Weidmueller Advisory - CERT-VDE published an advisory that describes a JavaScript injection vulnerability in the Weidmueller XML editing system SCHEMA ST4 online help.

Wiesemann & Theis Advisory - CERT-VDE published an advisory that describes an authentication bypass by spoofing vulnerability in multiple Wiesemann & Theis products.

Vendor Updates

CODESYS Update #1 - CODESYS published an update for their Control V3 communication server advisory that was originally published on November 22nd, 2022.

CODESYS Update #2 - CODESYS published an update for their V3 boot application advisory that was originally published on November 23rd, 2022.

CODESYS Update #3 - CODESYS published an update for their V2 password transport advisory that was originally published on June 9th, 2022 and most recently updated on October 6th, 2022.

CODESYS Update #4 - CODESYS published an update for their V2 and V3 runtime systems advisory that was originally published on March 22nd, 2018 and most recently updated on July 9th, 2018.

Dell Update - Dell published an update for their Log4Shell advisory.

HPE Update - HPE published an update for their NonStop advisory that was originally published on July 18th, 2022.

Mitsubishi Update - Mitsubishi published an update for their GENESIS64TM and MC Works64 advisory that that was originally published on July 19th, 2022 and most recently updated on September 30th, 2022.

Omron Update - JP-CERT published an update for their OMRON CX-Programmer advisory that was originally published on November 25th, 2022.

Researcher Report

VMware Report - CISCO Talos published a report describing a denial-of-service vulnerability in the VMware vCenter Server Content Library.

 

For additional information on these disclosures, including links to third-party advisories, exploits, and brief summary of changes made, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-720 - subscription required.


Saturday, April 9, 2022

Review - Public ICS Disclosures – Week of 4-2-22 – Part 1

A busy week with lots of SpringShell and DirtyPipe disclosures, so there will be two parts this week. In this part we have 24 vendor disclosures from Aruba, Barco, Bentley (8), Braun, Broadcom (3), Carrier, Weidmueller, WAGO, CODESYS (6), and FANUC.

Aruba Advisory - Aruba published an advisory discussing the SpringShell vulnerabilities.

Barco Advisory - Barco published an advisory discussing the DirtyPipe vulnerability.

Bentley Advisory #1 - Bentley published an advisory describing two use after free vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #2 - Bentley published an advisory describing three stack-based buffer overflow vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #3 - Bentley published an advisory describing an out-of-bounds write vulnerability in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #4 - Bentley published an advisory describing eleven file parsing vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #5 - Bentley published an advisory describing two out-of-bounds read vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #6 - Bentley published an advisory describing five out-of-bounds vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #7 - Bentley published an advisory describing four out-of-bounds read vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Bentley Advisory #8 - Bentley published an advisory describing two unitialized variable vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Braun Advisory - Braun published an advisory discussing the Infusion Pump Vulnerabilities article by Palo Alto Networks.

Broadcom Advisory #1 - Broadcom published an advisory discussing one of the SpringShell vulnerabilities.

Broadcom Advisory #2 - Broadcom published an advisory describing the other SpringShell vulnerability.

Broadcom Advisory #3 - Broadcom published an advisory discussing an older Spring Framework vulnerability reanimated by the SpringShell vulnerability.

Carrier Advisory - Carrier published an advisory discussing the SpringShell vulnerabilities.

Weidmueller Advisory - CERT-VDE published an advisory discussing nine vulnerabilities in two products using Modbus TCP/RTU Gateways.

WAGO Advisory - CERT-VDE published an advisory discussing the DirtyPipe vulnerability in several WAGO products.

CODESYS Advisory #1 - CODESYS published an advisory describing an exposure of resource to wrong sphere vulnerability in the CODESYS Control V3 products.

CODESYS Advisory #2 - CODESYS published an advisory describing an incorrect permission assignment for a critical resource vulnerability in the CODESYS SysDrv3S.sys driver.

CODESYS Advisory #3 - CODESYS published an advisory describing a small space of random values vulnerability in CODESYS V3 products using the CODESYS communication protocol.

CODESYS Advisory #4 - CODESYS published an advisory describing an incorrect user management vulnerability in the  CODESYS Control V3 online user management applications.

CODESYS Advisory #5 - CODESYS published an advisory describing two vulnerabilities in CODESYS V3 products containing a CODESYS communication server.

CODESYS Advisory #6 - CODESYS published an advisory describing a buffer over read vulnerability in the CODESYS V3 web server.

 

For more details on these disclosures, including links to 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/22-part-1 - subscription required.

Saturday, October 23, 2021

Review - Public ICS Disclosures – Week of 10-16-21

This week we have ten vendor disclosures from ABB, Weidmueller, HMS (2), HPE (2), Meinberg, PulseSecure, QNAP, and VMware. We also have two researcher reports of vulnerabilities in products from SonicWall and RDP Manager. There were three exploits published for products from SonicWall and Mitsubishi (2).

ABB Advisory - ABB published an advisory describing an integrity check bypass in their free@home System Access Point product.

Weidmueller Advisory - CERT-VDE published an advisory discussing the INFRA:HALT vulnerabilities in the Weidmueller Remote I/O fieldbus couplers.

HMS Advisory #1 - HMS published an advisory discussing the BrakTooth vulnerabilities in their Anybus wireless products.

HMS Advisory #2 - HMS published an advisory discussing the BadAlloc vulnerabilities in their Anybus wireless products.

HPE Advisory #1 - HPE published an advisory describing an information disclosure vulnerability in their 6120XG Blade Switch.

HPE Advisory #2 - HPE published an advisory describing a cross-site scripting vulnerability in their Superdome Flex Server.

Meinberg Advisory - Meinberg published an advisory discussing the GPSD Rollover Bug.

PulseSecure Advisory - PulseSecure published an advisory describing a malformed packet request vulnerability in their Pulse Connect Secure software.

QNAP Advisory - QNAP published an advisory describing a command injection vulnerability in their QNAP NAS running the Media Streaming add-on.

VMware Advisory - VMware published an advisory describing an information disclosure vulnerability in their vRealize Operations Tenant App for VMware Cloud Director.

SonicWall Report - Vulnerability Lab published a report of a cross-site scripting vulnerability in the SonicWeb SonicOS.

RDP Manager Report - Vulnerability Lab published a report of a denial-of-service vulnerability in the RDP Manager windows software client.

SonicWall Exploit - Jacob Baines published an exploit for an improper access control vulnerability in the SonicWall SMA100 product.

Mitsubishi Exploit #1 - Hamit Cibo published an exploit for a reflected cross-site scripting vulnerability in the Mitsubishi ME RTU.

Mitsubishi Exploit #2 - Hamit Cibo published an exploit for a source code disclosure vulnerability in the Mitsubishi ME RTU.

For more details about these advisories, reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-c22 - subscription required.

Saturday, June 26, 2021

Review - Public ICS Disclosures – Week of 6-19-21

This week we have 16 vendor disclosures from ABB, Aveva, Weidmueller, Draeger, Phoenix Contact (7), QNAP, Sick, SonicWall, and VMware (2). There are exploit reports for products from VMWare and HPE.

Miscellaneous Advisories

ABB Advisory - ABB published an advisory discussing CodeMeter vulnerabilities in their Automation Builder, Drive Application Builder and Virtual Drive products.

Aveva Advisory - Aveva published an advisory describing five vulnerabilities in the AutoBuild service of their System Platform.

Weidmueller Advisory - CERT-VDE published an advisory describing twelve vulnerabilities in the Weidmueller Industrial WLAN devices.

Draeger Advisory - Draeger published an advisory describing an integer overflow or wraparound vulnerability in their Clinical Assistance Package.

QNAP Advisory - QNAP published an advisory describing a command injection vulnerability in their NAS running legacy versions of QTS.

Sick Advisory - Sick published an advisory describing an inadequate SSH configuration vulnerability in their Visionary-S CX product.

SonicWall Advisory - SonicWall published an advisory describing a buffer overflow vulnerability in their SonicOS.

Phoenix Contact Advisories

Phoenix Contact published an advisory describing an undocumented access vulnerability in their AXL F BK and IL BK products.

Phoenix Contact published an advisory describing a denial of service vulnerability in their ILC1x1 Industrial controllers.

Phoenix Contact published an advisory describing a file parsing memory corruption vulnerability in their Automation Worx Software Suite.

Phoenix Contact published an advisory describing a race condition vulnerability in their r PLCNext, SMARTRTU AXC, CHARX control modular and EEM-SB37x products.

Phoenix Contact published an advisory describing two vulnerabilities in their PLCNext, ILC 2050 BI, FL MGUARD DM UNLIMITED, TC ROUTER und CLOUD CLIENT products.

Phoenix Contact published an advisory describing three vulnerabilities in their FL SWITCH SMCS series.

VMware Advisories

VMware published an advisory describing a local privilege escalation vulnerability in their VMware Tools, VMRC and VMware App Volumes products.

VMware published an advisory describing an authentication bypass vulnerability in their Carbon Black App Control product.

Exploits

CHackA0101 published an exploit for an improper privilege management vulnerability in the VMware vCenter Server.

Jeremy Brown published an exploit for a denial of service vulnerability in the HPE Remote Device Access product.

For more detailed information on the advisories see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-73d  (subscription required)


Saturday, May 8, 2021

Public ICS Disclosures – Week of 5-1-21

This week we have four vendor disclosures from ABB (2), WAGO, and WEIDMUELLER. There are vendor updates from Dell and Rockwell Automation. We have ten researcher reports for vulnerabilities in products from Delta Industrial Automation.

ABB Advisories

ABB published an advisory discussing the NAME:WRECK vulnerabilities in their AC 800PEC controller based products. ABB provides generic workarounds for the vulnerablity.

NOTE: The NAME:WRECK vulnerability associated with the ABB products is CVE-2016-20009 (WindRiver VxWorks). A report with exploit code was published for this vulnerability in August 2016. See page 9 of the NAME:WRECK report for commentary on this situation.

ABB published an advisory describing a path traversal vulnerability in the Cassia Access Controller for their Ability™ Smart Sensor. The vulnerability was reported by Claroty. ABB reports that the vulnerability has been patched an no action is needed.

WAGO Advisory

CERT-VDE published an advisory describing six vulnerabilities in the Web-Based Management (WBM) of WAGOs industrial managed switches. The vulnerabilities were reported by Dr. Tobias Augustin and Stephan Tigges of IKS, and Kai Gaul and Jan Rubenach of ABO Wind. WAGO has new firmware versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• Exposure of sensitive information to an unauthorized actor - CVE-2021-20993,

• Cross-site scripting - CVE-2021-20994,

• Storage of user credentials in a cookie - CVE-2021-20995,

• Incorrect permission assignment for critical resource - CVE-2021-20996, and

• Insufficiently protected credentials - CVE-2021-20997

WEIDMUELLER Advisory

CERT-VDE published an advisory describing an exposure of resource to wrong sphere vulnerability in the WEIDMUELLER u-controls and IoT-Gateways. The vulnerability is self-reported. WEIDMUELLER has a new version that mitigates the vulnerability.

Dell Update

Dell published an update for their Wyse ThinOS advisory that was originally published on March 31st, 2021. There is no indication of what has changed in the advisory.

Rockwell Update

Rockwell published an update for their Logix Controllers advisory that was originally published on February 25th, 2021. The new information includes updating mitigation measures for 1783-CSP CIP Security Proxy.

NOTE: I suspect that NCCIC-ICS will update their advisory in the coming week.

Delta Reports

The Zero Day Initiative published 10 reports (ZDI-21-510 thru ZDI-21-519) for out-of-bounds read vulnerabilities in the Delta DOPSoft products. The vulnerabilities were reported by Natnael Samson. The vulnerabilities have been coordinated with NCCIC-ICS.

Saturday, January 23, 2021

Public ICS Disclosures – Week of 1-16-21

This week we have six vendor disclosures from ABB, Bosch, Belden, WEIDMUELLER, PulseSecure, and Siemens. We have two vendor reports on products from Sela.

ABB Advisory

ABB published an advisory describing an unauthenticated crafted packet vulnerability in their AC500 V2 PLCs. The vulnerability was reported by Yossi Reuven of SCADAfence. ABB has a new firmware version that mitigates the vulnerability. There is no indication that Reuven was provided an opportunity to verify the efficacy of the fix.

Bosch Advisory

Bosch published an advisory describing two vulnerabilities in their Bosch Fire Monitoring System. The vulnerabilities are self-reported. Bosch has a patch that mitigates the vulnerabilities.

The two reported vulnerabilities are:

• Use of hard-coded credentials - CVE-2020-6779, and

• Use of password hash with insufficient computational effort - CVE-2020-6780

Belden Advisory

Belden published an advisory describing a firewall bypass vulnerability in their WLAN (HiCLOS) products. The vulnerability is self-reported. Belden has updates available that mitigate the vulnerability.

WEIDMUELLER Advisory

CERT-VDE published an advisory discussing the fdtCONTAINER vulnerability in the WEIDMUELLER WI Manager. WEIDMUELLER continues to work on mitigation measures for this vulnerability.

PulseSecure Advisory

PulseSecure published an advisory discussing a third-party (OpenSSL) null pointer dereference vulnerability in their products. They can report that their Pulse Secure vADC is not affected, but they are still looking at other products.

Siemens Advisory

Siemens published an out-of-zone advisory discussing the DNSpooq vulnerabilities in their SCALANCE and RUGGEDCOM Devices. Siemens has provided generic workarounds to mitigate the vulnerabilities pending further development efforts.

Selea Reports

Zero Science Labs has published a report describing a cross-site scripting vulnerability in the Selea CarPlateServer. Zero Science reports coordinating with Selea but is unaware of any mitigation measures developed by the company. LiquidWorm has published an exploit for this vulnerability.

 

Zero Science Labs has published a report describing a privilege escalation vulnerability in the Selea CarPlateServer. Zero Science reports coordinating with Selea but is unaware of any mitigation measures developed by the company. LiquidWorm has published an exploit for this vulnerability.

Thursday, October 15, 2020

2 Advisories and 1 Update Published – 10-15-20

Today the CISA NCCIC-ICS published two control system security advisories for products from Advantech and updated one advisory for products from Wibu-Systems.

R-SeeNet Advisory

This advisory describes an SQL injection vulnerability in the Advantech  R-SeeNet monitoring application. The vulnerability was reported by rgod via the Zero Day Initiative (ZDI). Advantech has a new version that mitigates the vulnerability. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reported that a relatively low-skilled attacker could remotely exploit this vulnerability to allow remote attackers to retrieve sensitive information from the R-SeeNet database.

NOTE: NCCIC-ICS provides a link to the Advantech advisory for this vulnerability. This is the first time that I have seen an advisory published by Advantech (actually, Advantech Czech s.r.o.) and they also have a security notifications web page which apparently only covers their cellular routers and gateways. Interestingly, they make Common Vulnerability Reporting Framework (CVRF) v1.1 files on identified vulnerabilities available to their customers.

WebAccess Advisory

This advisory describes an external control of file name or path vulnerability in the Advantech WebAccess/SCADA software package. The vulnerability was reported by Sivathmican Sivakumaran via ZDI. Advantech has newer versions that mitigate the vulnerability. There is no indication that Sivakumaran has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to control or influence a path used in an operation on the filesystem and remotely execute code as an administrator.

NOTE: This vulnerability was not reported on the web site I discussed for the earlier vulnerability, nor was there an Advantech advisory available.

CodeMeter Update

This update provides additional information on an advisory that  was originally published on September 8th, 2020 and most recently updated on October 1st, 2020 (the advisory incorrectly refers back to an earlier version from September 17th). The new information includes links to two new vendor advisories from Schneider and WEIDMUELLER.

Thursday, December 5, 2019

2 Advisories Published – 12-05-19


Today the CISA NCCIC-ICS published two control system security advisories for products from Weidmueller and Thales.

Weidmueller Advisory


This advisory describes 5 vulnerabilities in the Weidmueller Industrial Ethernet Switches. The vulnerabilities are self-reported. Weidmueller has firmware patches that mitigate the vulnerabilities.

The five reported vulnerabilities are:

• Improper restriction of excessive authentication attempts - CVE-2019-16670;
• Uncontrolled resource consumption - CVE-2019-16671;
• Missing encryption of sensitive data - CVE-2019-16672;
• Unprotected storage of credentials - CVE-2019-16673; and
• Predictable from observable state - CVE-2019-16674

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow a remote attacker to gain unauthorized access to the device, affecting the confidentiality, integrity, and availability of the device the attacker is targeting.

Thales Advisory


This advisory describes a link following vulnerability in the Thales SafeNet Sentinel LDK License Manager Runtime. The vulnerability was reported by Ryan Wincey of Blizzard Entertainment. Thales has a new version that mitigates the vulnerability. There is no indication that Wincey has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with local access could exploit the vulnerability to allow a local attacker to escalate privileges.

NOTE: I briefly addressed this vulnerability back in October.

 
/* Use this with templates/template-twocol.html */