Showing posts with label Xzeres. Show all posts
Showing posts with label Xzeres. Show all posts

Wednesday, February 22, 2017

ICS-CERT Updates XZERES Advisory

Yesterday the DHS ICS-CERT updated a control system security advisory for products from XZERES. The original advisory was published on December 8th, 2015 and then updated on December 10th, 2015. The new update describes new mitigation measures for the cross-site scripting vulnerability and adds the name of a new researcher, Tim Thurlings, to the advisory.

The new mitigation measures include:

• A new ‘Secure Gateway’ module to install between the internet and the Controller board;
• New notebooks for remote access that include a Secure Remote Connection system; and

• A work around that includes shutting down the port forwarding feature.

Thursday, March 17, 2016

ICS-CERT Updates Advisory and Publishes New Advisory

This morning the DHS ICS-CERT published an update for an advisory published in December for a cross-site scripting vulnerability in the in XZERES 442SR turbine generator operating system (OS). It also published a new advisory for a vulnerability in the ABB Panel Builder 800.

XZERES Update


This update corrects the CVE number for the vulnerability. The CVE number published in the original advisory was actually for another cross-site scripting vulnerability in the same equipment that was reported by ICS-CERT in an advisory published in March of last year.

ABB Advisory


This advisory describes a DLL hijacking vulnerability in the ABB Panel Builder 800. The vulnerability was reported by Ivan Sanchez from Nullcode Team. ABB has produced a new version of the software that mitigates the vulnerability. There is no indication that Sanchez has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that an attacker must get malicious code to a specific directory in the file system and then convince an authorized operator to execute the code. ICS-CERT says that this cannot be exploited remotely.


The ABB Security Advisory (not referenced in this advisory) for this vulnerability has a workaround that can be used pending the updating of the software to the newer version. Thanks to Joel Langill for tweeting about this document this morning.

Tuesday, December 8, 2015

ICS-CERT Updates Rockwell Advisory and Publishes 3 New Advisories

Today the DHS ICS-CERT updated an earlier control system advisory for a series of Rockwell controllers. It also published new control system advisories from Pacom, LOYTEC, and XZEARES.

ICS-CERT announced earlier today on TWITTER that the ICSJWG 2016 Spring Meeting will occur May 3-5, 2016, in Scottsdale, AZ. More information will become available on the Industrial Control Systems Joint Working Group (ICSJWG) web site as the meeting date gets closer.

Rockwell Update

This update provides additional information on an advisory published this October. Rockwell is reporting that the previously uncorrected vulnerability in the MicroLogic 1400 controller has been corrected in a new firmware version.

NOTE: This update is not listed on the ICS-CERT landing page. To learn of these updates in near real-time you need to follow ICS-CERT on Twitter (@ICSCERT).

Pacom Advisory

This advisory describes an inadequate cryptography vulnerability in the Pacom GMS system. The vulnerability was originally reported by the Swedish companies XPD and Assured. Pacom has not updated the GMS, but ICS-CERT reports that they have “fixed the new EMCS system”. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to take control over the communication between the controller and base station.

This advisory was originally released to the US-CERT Secure Portal on November 3rd, 2015. Instructions for critical infrastructure owners and security researchers to gain access to that Secure Portal can be found at the bottom of the ICS-CERT landing page.

LOYTEC Advisory

This advisory describes a password file vulnerability in the LOYTEC LIP-3ECTB routers. The vulnerability was originally reported by Maxim Rupp. LOYTEC has produced a firmware update to mitigate this vulnerability but there is no indication that Maxim Rupp was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to gain access to the network.

XZERES Advisory

This advisory describes a cross-site scripting vulnerability in the XZERES 442SR wind turbine generator operating system (OS). The vulnerability was reported by Karn Ganeshen. XZERES had produced a patch to mitigate the vulnerability, but there is no indication that Ganeshen has been provided an opportunity to verify the efficacy of the fix.


ICS-CERT reports that a relatively unskilled attacker could adapt code available on-line to remotely exploit this vulnerability to gain admin rights to the system.

Thursday, June 4, 2015

ICS-CERT Publishes Wind Turbine Advisory

This afternoon the DHS ICS-CERT published an advisory describing a cross-site request forgery (CSRF) vulnerability in XZERES’s 442SR turbine generator operating system (OS). The vulnerability was originally reported by Maxim Rupp. XZERES has produced a patch to mitigate the vulnerability, but there is no indication that Rupp has been given the opportunity to verify the efficacy of the fix.


ICS-CERT reports that a relatively low skilled attacker could modify publicly available exploit code for other systems to remotely exploit this vulnerability to gain admin rights to the entire system.

Wednesday, March 18, 2015

ICS-CERT Publishes Three Advisories


Yesterday the DHS ICS-CERT published three control system advisories for systems from Johnson Controls, Honeywell and Xzeres.
Johnson Controls Advisory
This advisory describes two vulnerabilities is the Johnson Controls Metasys building management system. The vulnerabilities were reported by Billy Rios. Johnson Controls has produced patches for the affected systems but there is no indication that Rios has been provided the opportunity to verify the efficacy of the fixes.
The two vulnerabilities are:
· Storing passwords in a recoverable format – CVE-2014-5427

· Unrestricted upload of files with a dangerous type – CVE-2014-5428
ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to compromise the Metasys system.
Honeywell Advisory
This advisory describes a directory traversal vulnerability in the Honeywell XL Web Controller. The vulnerability was reported by Martin Jartelius of Outpost24. Honeywell has produced an update that mitigates the vulnerability but there is no indication that Jartelius has had an opportunity to verify the efficacy of the fix.
ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to gain access to the web root directory.
ICS-CERT reports that the same web controllers have been sold under the name 'Falcon' by Centraline. The advisory provides links to the Centraline updates, but Honeywell customers will have to contact the Honeywell HBS branch for assistance in getting the updates.
Xzeres Advisory
This advisory describes a cross-site request forgery vulnerability in the XZERES’s 442SR turbine generator operating system. The vulnerability was reported by Maxim Rupp. Xzeres has produced a patch that mitigates the vulnerability but there is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.
ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability to obtain the username password from the system. ICS-CERT reports that while no exploits are currently specifically available for the vulnerability in this system, there are publicly available exploits for similar vulnerabilities that could easily be changed to work on this system.
 
/* Use this with templates/template-twocol.html */