Showing posts with label Xylem. Show all posts
Showing posts with label Xylem. Show all posts

Saturday, May 28, 2022

Review – Public ICS Disclosures – Week of 5-21-22 – Part 1

This has been a fairly busy disclosure week which will require two parts to list completely. For Part 1 we have seventeen vendor disclosures from ABB, CONTEC, Fuji Electric (2), HPE (2), Meinberg, Open Automation, QNAP (2), VMware (2), Western Digital, Xylem (3), and Yokogawa.

ABB Advisory - ABB published an advisory that describes two vulnerabilities in their e-Design product.

CONTEC Advisory - JP CERT published an advisory that describes an OS command injection vulnerability (with publicly available exploit) in the CONTEC SolarView Compact.

Fuji Advisory #1 - JP CERT published an advisory that describes five vulnerabilities in the Fuji V-SFT product.

Fuji Advisory #2 - JP CERT published an advisory that describes three vulnerabilities in the Fuji V-SFT, V-Server and V-Server Lite products.

HPE Advisory #1 - HPE published an advisory that describes an escalation of privilege vulnerability in their Version Control Repository Manager Installer.

HPE Advisory #2 - HPE published an advisory that discusses the Psychic Signatures vulnerability in their IceWall Products.

NOTE: This is going to be an interesting third-party vulnerability. The researcher report is well worth reading.

Meinberg Advisory - Meinberg published an advisory that discusses two vulnerabilities (one with publicly available exploit) in their LANTIME Firmware.

Open Automation Advisory - Incibe CERT published an advisory that describes eight vulnerabilities in the Open Automation Software OAS Platform.

QNAP Advisory #1 - QNAP published an advisory that describes a cross-site request forgery vulnerability in their NAS running Proxy Server.

QNAP Advisory #2 - QNAP published an advisory that discusses four OpenSSL vulnerabilities.

VMware Advisory #1 - VMware published an advisory that describes an XML external entity vulnerability (with publicly available exploit) in their VMware Tools for Windows product.

VMware advisory #2 - VMware published an advisory that describes two vulnerabilities in their VMware Workspace ONE Access, Identity Manager and vRealize Automation products.

Western Digital Advisory - Western Digital published an advisory that discusses an improper authentication vulnerability in their My Cloud OS 5 Firmware.

Xylem Advisory #1 - Xylem published an advisory that discusses the CISA Emergency Directive (ED) 22-03.

Xylem Advisory #2 - Xylem published an advisory that discusses an improper verification of cryptographic signature vulnerability in their Xylem Edge Gateway.

Xylem Advisory #3 - Xylem published an advisory that describes an improper authentication vulnerability in the Sensus Analytics Login Service of their Utility Portal application.

Yokogawa Advisory - Yokogawa published an advisory that describes a violation of secure design principles vulnerability in their CAMS for HIS products.

 

For more details on these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-017 - subscription required.

Thursday, December 16, 2021

Review - 20 Advisories Published – 12-16-21

Today, CISA’s NCCIC-ICS published 20 control system security advisories for products from Siemens (15), Mitsubishi Electric (2), Wibu Systems, Delta Electronics, and Xylem. They also published six updates; I will cover these in a separate post. All of the new advisories that Siemens published on Tuesday were covered today by NCCIC-ICS.

JTTK Advisory #1 - This advisory describes two vulnerabilities in the Siemens JTTK and JT Utilities.

NOTE: The Siemens advisory reports ZDI-Canada reference numbers for these two vulnerabilities. Those, in turn point to Bentley CVE’s; CVE-2021-34878, CVE-2021-34898, and CVE-2021-34937 (links are to ZDI reports, CVE’s are still ‘Reserved’). There are a total of 77 ZDI reports for a variety of vulnerabilities in the Bentley View CAD product.

SiPass Advisory - This advisory describes three separate exposure of resources to wrong sphere vulnerabilities in the Siemens SiPass Integrated.

Teamcenter Advisory - This advisory describes a path traversal vulnerability in the Siemens Teamcenter Active Workspace.

JT Utilities Advisory - This advisory describes 16 vulnerabilities in the Siemens JT Utilities, JT Open Toolkit.

Healthineers Advisory - This advisory describes two separate out-of-bounds write vulnerability in the Siemens Healthineers syngo fastView.

NOTE: This should be a medical device security advisory; syngo fastView is a standalone viewer for DICOM2 images.

Simcenter Advisory - This advisory describes an out-of-bounds write vulnerability in the Siemens Simcenter STAR-CCM+ Viewer.

Siveillance Advisory - This advisory describes three separate exposure of resource to wrong sphere vulnerabilities in the Siemens Siveillance Identity self-service portal.

Questa Advisory - This advisory describes an insufficiently protected credential vulnerability in the Siemens Questa Simulation and ModelSim Simulation integrated circuit simulators.

NOTE: The research paper reporting this vulnerability is entitled: “How Not to Protect Your IP – An Industry-Wide Break of IEEE 1735 Implementations”. This vulnerability is not limited to these two Siemens products.

SIMATIC ITS Advisory - This advisory describes a using components with (19) known vulnerabilities vulnerability in the Siemens IMATIC ITC Products.

SIMATIC Advisory - This advisory describes a path traversal vulnerability in the Siemens SIMATIC eaSie PCS 7 Skill Package.

JT2Go Advisory - This advisory describes 16 vulnerabilities in the Siemens JT2Go and Teamcenter Visualization products.

SINUMERIK Advisory - This advisory describes an improper certificate validation vulnerability in the Siemens SINUMERIK Edge platform.

JTTK Advisory #2 - This advisory describes three vulnerabilities in the Siemens JTTK and JT Utilities.

Power Meter Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Siemens POWER METER SICAM Q100.

Capital VSTAR Advisory - This advisory discusses the NUCLEUS:13 vulnerabilities in the Siemens Capital VSTAR.

FA Engineering Advisory - This advisory describes two vulnerabilities in the Mitsubishi FA Engineering Software.

GX Works2 Advisory - This advisory describes an improper handling of length parameter inconsistency vulnerability in the Mitsubishi GX Works2 engineering software suite.

NOTE: Mitsubishi published another advisory and 1 update today. I will address those this weekend.

Wibu Advisory - This advisory describes an improper privilege management vulnerability in the Wibu CodeMeter.

NOTE: I briefly discussed this vulnerability in early October 2021.

Delta Advisory - This advisory describes an out-of-bounds read vulnerability in the Delta CNCSoft industrial automation software.

Xylem Advisory - This advisory describes a use of hard-coded credentials vulnerability in the Xylem AquaView SCADA system.

For more details on these advisories, including links to third-party advisories, exploits and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/20-advisories-published-12-16-21 - subscription required.

Tuesday, November 30, 2021

Review - 5 Advisories and 2 Updates Published – 11-30-21

Today, CISA’s NCCIC-ICS published five control system security advisories for products from Hitachi Energy, Johnson Controls, Delta Electronics, Mitsubishi Electric, and Xylem. They also updated two advisories for products from multiple RTOS and InHand Networks.

Hitachi Energy Advisory - This advisory describes an improper access control vulnerability in the Hitachi Energy Retail Operations and Counterparty Settlement and Billing (CSB) Product.

NOTE: I briefly discussed the two supporting Hitachi Energy advisories along with five others on November 6th, 2021.

Johnson Controls Advisory - This advisory discusses an off-by-one error vulnerability in the Johnson Controls Controlled Electronic Management Systems Ltd. CEM Systems AC2000.

Delta Electronics Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Delta Electronics CNCSoft software management software.

Mitsubishi Advisory - This advisory describes three vulnerabilities in the Mitsubishi MELSEC CPU module and MELIPC Series software management platform.

Xylem Advisory - This advisory describes an SQL injection vulnerability in the Xylem Aanderaa GeoView web-based data display.

Multiple RTOS Update - This update provides additional information on an advisory that was originally published on April 29th, 2021 and most recently updated on August 17th, 2021.

NOTE 1: I briefly discussed the reported Hitachi Energy RTU500 advisory on November 20th.

NOTE 2: I briefly discussed the reported Hitachi Energy MSM advisory on August 21st, 2021.

InHand Networks Update - This update provides additional information on an advisory that was originally published on October 7th, 2021.

NOTE: InHand went from a notation of “InHand Networks has not responded to requests to work with CISA to mitigate these vulnerabilities” to having a vendor security advisories page with vulnerability reporting contact information and PGP public key listing. I hope they keep it up; it has been added to my weekly checklist.

For more details on these advisories and updates, including links to 3rd party vendors and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-2-updates-published - subscription required.

Saturday, June 12, 2021

Review - Public ICS Disclosures – Week of 6-5-21 – Part 1

This week we have fifteen vendor disclosures from Bosch, Circutor (2), Dell, Gallagher (7), QNAP (3), and Xylem. We also have a researcher report for products from New Electronic Technologies. Finally we have exploits for products from VMware and Solar-Log (2).

Vendor Reports

Bosch published an advisory describing five vulnerabilities in their IP Cameras.

Incibe-CERT published an advisory describing an improper authentication vulnerability in the Circutor SGE-PLC1000 device.

Incibe-CERT published an advisory describing an OS command injection vulnerability in the Circutor SGE-PLC1000 device.

Dell published an advisory discussing the VMware vCenter Server vulnerabilities.

Gallagher Advisories - Gallagher published seven advisories describing vulnerabilities in the Command Centre Server.

QNAP published an advisory describing an improper access control vulnerability in their QNAP NAS Helpdesk products.

QNAP published an advisory describing an inclusion of sensitive information in QSS vulnerability in their QNAP Switches.

QNAP published an advisory describing an out-of-bounds read vulnerability in their QNAP Switches.

Xylem published an advisory discussing the Rockwell ISaGRAF Runtime vulnerabilities in their Flygt MultiSmart pump station management system.

Researcher Reports

The Russian BDU FSTEC published a report describing a privilege management vulnerability in the New Technologies Titanium CNC PLC module.

Exploits

Johnny Yu published an exploit for a heap-based buffer overflow vulnerability in the VMware vCenter Server.

Luca Chiou published an exploit for an unprotected storage of credentials vulnerability in the Solar-Log Energy Management System.

Luca Chiou published an exploit for an incorrect access control vulnerability in the Solar-Log Energy Management System.

For a more detailed look at these vulnerabilities, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-723 (subscription required).

 
/* Use this with templates/template-twocol.html */