Showing posts with label Zero Science. Show all posts
Showing posts with label Zero Science. Show all posts

Saturday, December 9, 2023

Review – Public ICS Disclosures – Week of 12-2-23

This week we have 37 vendor disclosures from CODESYS, Dell (2), HP, HPE, Insyde, Pilz (3), QNAP (3), SEL (2), Siemens, Tanzu (20), and Wago (2). There are three vendor updates from Atos, CODESYS, and Dell. We have two researcher reports for vulnerabilities in products from Atos and R Radio Network. Finally, we have two exploits for products from FortiGuard and Orpak.

Advisories

CODESYS Advisory - CODESYS published an advisory that describes an OS command injection vulnerability in their Control runtimes running on Linux or QNX operating systems.

Dell Advisory #1 - Dell published an advisory that discusses an out-of-bounds write vulnerability in the ThisOS.

Dell Advisory #2 - Dell published an advisory that discusses 28 vulnerabilities in their Dell Wyse Management Suite.

HP Advisory - HP published an advisory that discusses an improper input validation vulnerability in multiple notebook and desktop computers.

HPE Advisory - HPE published an advisory that describes an information disclosure vulnerability in their HP-UX System Management Homepage.

Insyde Advisory - Insyde published an advisory that discusses an improper input validation vulnerability in multiple kernels

Pilz Advisory #1 - CERT-VDE published an advisory that discusses two vulnerabilities in the Pilz PASvisu and PMI products.

Pilz Advisory #2 - CERT-VDE published an advisory that discusses an out-of-bounds write vulnerability in the Pilz PASvisu, PIT Transponder Manager, and PMI products.

Pilz Advisory #3 - Pilz published an advisory that discusses vulnerabilities in multiple products.

QNAP Advisory #1 - QNAP published an advisory that describes a cross-site scripting vulnerability in their QTS and QuTS hero products.

QNAP Advisory #2 - QNAP published an advisory that describes an OS command injection vulnerability in their legacy VioStor NVR product.

QNAP Advisory #3 - QNAP published an advisory that describes two classic buffer overflow vulnerabilities in their QTS and QuTS hero products.

QNAP Advisory #4 - QNAP published an advisory that discusses five vulnerabilities in their QTS and QuTS hero products.

SEL Advisories - SEL announced new versions of two products that address cybersecurity issues.

Siemens Advisory - Siemens discussed a Black Hat Europe presentation describing the details of the legacy PG/PC and HMI communication protocol as used between TIA Portal / HMIs and SIMATIC S7-1500 SW Controller in versions before V17.

Tanzu Advisories - Tanzu published 20 advisories discussing third-party vulnerabilities in various Tanzu products.

Wago Advisory #1 - CERT-VDE published an advisory that describes an observable discrepancy vulnerability in the Wago Smart Designer product.

Wago Advisory #2 - CERT-VDE published an advisory that describes an improper input validation vulnerability in the Wago Telecontrol Configurator and WagoAppRTU products.

Updates

Atos Update - Atos published an update for their Unify OpenScape advisory that was originally published on October 4th, 2023 and most recently updated on September 10th, 2023.

CODESYS Update - CODESYS published an update for their WIBU CodeMeter Runtime advisory that was originally published on August 17th, 2023 and most recently updated on October 31st, 2023.

Dell Update - Dell published an update for their Rugged Control Center advisory that was originally published on November 30th, 2023.

Researcher Reports

Atos Report - SEC Consult published a report that describes an argument injection vulnerability in the Atos Unify OpenScape products.

R Radio Network Report - Zero Science published a report describing two vulnerabilities in the R Radio Network.

Exploits

FortiGuard Exploit - Cody Sixteen published an exploit for a post authentication CLI crash vulnerability in the FortiWeb VM product.

Orpak Exploit - Parsa Rezaei Khiabanloo published an exploit for a default password vulnerability in the Orpak fueling systems.

 

For more details about these disclosures, including links to researcher reports, 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-66a - subscription required.

Sunday, September 18, 2022

Review – Public ICS Disclosures – Week of 9-10-22 – Part 2

For Part 2 we have fifteen vendor updates from HPE, Schneider (12), and Siemens (2). We also have a researcher report of vulnerabilities in products from ETAP. Finally, we have an exploit reported for products from Palo Alto Networks.

HPE Update - HPE published an update for their HPE Integrated Lights-Out 5 advisory that was originally published on July 28th, 2022 and most recently updated on September 6th, 2022.

Schneider Update #1 - Schneider published an update for their Modicon Controllers advisory that was originally published on May 14th, 2019 and most recently updated on December 8th, 2020.

Schneider Update #2 - Schneider published an update for their embedded FTP servers advisory that was originally published on March 22nd, 2018 and most recently updated on September 6th, 2022.

Schneider Update #3 - Schneider published an update for their Urgent/11 advisory that was  originally published on August 2nd, 2019 and most recently updated on May 11th, 2021.

Schneider Update #4 - Schneider published an update for their Modicon Web Server advisory that was originally published on November 10th, 2020 and most recently updated on August 10th, 2021.

Schneider Update #5 - Schneider published an update for their Modicon Web Server advisory that was originally published on December 8th, 2020 and most recently updated on May 11th, 2021.

Schneider Update #6 - Schneider published an update for their Modicon Web Server advisory that was originally published on December 8th, 2020.

Schneider Update #7 - Schneider published an update for their SNMP Service advisory that was originally published on December 12th, 2020 and most recently updated on February 9th, 2022.

Schneider Update #8 - Schneider published an update for their for their INFRA:HALT advisory that was originally published on August 5th, 2021 and most recently updated on February 8th, 2022.

Schneider Update #9 - Schneider published an update for their Modicon Web Server advisory that was originally published on September 14th, 2021.

Schneider Update #10 - Schneider published an update for their for their BadAlloc advisory that was originally published on November 9th, 2021 and most recently updated on August 9th, 2022.

Schneider Update #11 - Schneider published an update for their Modicon M340 Controller advisory that was originally published on April 12th, 2022.

Schneider Update #12 - Schneider published an update for their Modicon PAC Controller advisory that was originally published on August 9th, 2022.

Siemens Update #1 - Siemens published an update for their GNU/Linux advisory that was originally published in 2018 and most recently updated on August 9th, 2022.

Siemens Update #2 - Siemens published an update for their for their JT2Go and Teamcenter advisory that was originally published on August 9th, 2022.

ETAP Report - Zero Science Lab published a report that describes a reflected cross-site scripting vulnerability (with a known exploit) in the ETAP Safety Manager.

 

For more information about these disclosures, including a summary of changes made in the updates, see my article at CFSN Detail Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-44d - subscription required.

Saturday, July 23, 2022

Review – Public ICS Disclosures – Week of 7-16-22

This week we have ten vendor disclosures from Dell, Eaton, Flexera, Honeywell, HP, HPE (2), Rockwell, and SonicWall. We also have four vendor updates from Aruba Networks (2), Fujitsu, and HP. Finally, we have one researcher report for products from Schneider Electric.

Dell Advisory - Dell published an advisory that discusses 28 vulnerabilities (two with known exploits) in their Wyse Management Suite.

Eaton Advisory - Eaton published an advisory that describes an unrestricted file upload vulnerability in their Foreseer software.

Flexera Advisory - Flexera published an advisory that discusses the log4j remote code execution vulnerability (CVE-2021-44832).

Honeywell Advisory - Honeywell published an end-of-life notice for their equIP® Series IP Cameras, Performance Series IP and HQA Cameras, and Performance Series NVRs, and DVR.

HP Advisory - HP published an advisory that discusses seven vulnerabilities in their UEFI Secure Boot Database.

HPE Advisory #1 - HPE published an advisory that describes a disclosure of sensitive information vulnerability in their OneView product.

HPE Advisory #2 - HPE published an advisory that discusses an endless loop vulnerability in their NonStop products.

Rockwell Advisory - Rockwell published an advisory that discusses the SpringShell vulnerability in their FactoryTalk Analytics DataView product.

SonicWall Advisory - SonicWall published an advisory that describes an SQL injection vulnerability in their GMS AND Analytics products.

Aruba Update #1 - Aruba published an update for their OpenSSL advisory that was originally published on May 4th, 2022 and most recently updated on June 1st, 2022.

Aruba Update #2 - Aruba published an update for their Expat XML advisory that was originally published on May 17th, 2022 and most recently updated on July 7th, 2022.

Fujitsu Update - Fujitsu published an update for their ETERNUS CS8000 advisory that originally published on June 1st, 2022.

HP Update - HP published an update for their Jumpstart advisory that originally published on May 10th, 2022.

Schneider Report - Zero Science Labs published a report describing an OS command injection vulnerability in the Schneider SpaceLogic C-Bus Home Automation System.

 

For more details on these disclosures, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-c9a - subscription required.

Saturday, July 2, 2022

Review – Public ICS Disclosures – Week of 6-25-22 – Part 2

For Part 2 we have ten vendor updates for CODESYS (6), Dell, HP (3), and HPE. We have six researcher reports for products from Robustel (4), ExpressLRS, and Carel.

CODESYS Update #1 - CODESYS published an update for their Control V3 configuration file advisory that was that was originally published on March 24th, 2022, and most recently updated on June 10th, 2022.

CODESYS Update #2 - CODESYS published an update for their CODESYS communication protocol advisory that was originally published on March 24th, 2022 and most recently updated on April 6th, 2022

CODESYS Update #3 - CODESYS published an update for their Control V3 online user management advisory that was originally published on March 24th, 2022 and most recently updated on April 6th, 2022.

CODESYS Update #4 - CODESYS published an update for their V3 products containing a CODESYS communication server that was originally published on March 24th, 2022 and most recently updated on April 6th, 2022.

CODESYS Update #5 - CODESYS published an update for their V3 web server advisory that was originally published on March 24th, 2022 and most recently updated on April 6th, 2022.

CODESYS Update #6 - CODESYS published an update for their V3 products containing a CODESYS communication server advisory that was originally published on May 19th, 2022 and most recently updated on May 30th, 2022.

Dell Update - Dell published an update for their Wyse ThinOS advisory that was originally published on July 21st, 2021.

HP Update #1 - HP published an update for their Intel® Boot Guard and Intel® TXT Security advisory that was originally published on May 10th, 2022.

HP Update #2 - HP published an update for their Intel 2022.1 IPU BIOS advisory that was originally published on July 21st, 2021.

HP Update #3 - HP published an update for their AMD Client UEFI Firmware advisory that was originally published on July 21st, 2021.

HPE Update - HPE published an update for their HP-UX Using OpenSSL advisory that was originally published on May 19th, 2022.

Robustel Reports – Cisco Talos published four reports for ten vulnerabilities in the Robustel R1510 web server.

ExpressLRS Report - NCC Group published a report describing a discoverable binding phrase for radio linkages in the ExpressLRS radio control link.

Carel Report - Zero Science published a report describing a directory traversal vulnerability in the Carel pCOWeb HVAC BACnet Gateway.

 

For more details on these updates and reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-2ec  - subscription required.

Saturday, March 26, 2022

Review – Public ICS Disclosures – Week of 3-19-22

This week we have fourteen vendor disclosures from Baxter, Bosch, Endress+Hauser, HP (2), Moxa, Philips, Phoenix Contact (2), SonicWall, Splunk, VMware, and Western Digital (2). We also have five vendor updates from HP (2), Mitsubishi, Spacelabs, and Yokogawa. Finally, we have two researcher reports for vulnerabilities in products from Integrated Control Technology (2).

Baxter Advisory - Baxter published an advisory discussing the Access:7 vulnerabilities.

Bosch Advisory - Bosch published an advisory discussing an improper restriction of XML external entity reference vulnerability in their Fire Monitoring System products.

Endress+Hauser Advisory - CERT VDE published an advisory discussing an out-of-bounds write vulnerability in a number of Endress+Hauser products.

HP Advisory #1 - HP published an advisory discussing a denial-of-service/RCE vulnerability in a number of their corporate printer products.

HP Advisory #2 - HP published an advisory describing a buffer overflow vulnerability in a number of their corporate printer products.

Moxa Advisory - Moxa published an advisory discussing a default password vulnerability in unnamed products.

Philips Advisory - Philips published an advisory discussing a Windows® IKE Extension vulnerability.

Phoenix Contact Advisory #1 - Phoenix Contact published an advisory discussing two vulnerabilities with publicly available exploits in their PLCnext Technology Toolchain and FL Network Manager products.

Phoenix Contact Advisory #2 - Phoenix Contact published an advisory discussing fifteen vulnerabilities with publicly available exploits in their PROFINET software development kit (SDK).

SonicWall Advisory - SonicWall published an advisory describing a stack-based buffer overflow vulnerability in their SonicOS.

Splunk Advisory - Splunk published an advisory describing an out-of-bounds read vulnerability in their Enterprise products.

Commentary – It seems like Claroty is going to continue to look at vulnerabilities in the cybertools used by security researchers. Their first report in this area was on vulnerabilities in Wireshark products though they did not publicly report on those vulnerabilities. It seems that the folks developing security tools are subject to the same software development problems that researchers find in industrial control systems.

VMware Advisory - VMware published an advisory describing two vulnerabilities in their Carbon Black App Control.

Western Digital Advisory #1 - Western Digital published an advisory discussing an out-of-bounds read/write vulnerability with publicly available exploits in their My Cloud OS 5 devices.

Western Digital Advisory #2 - Western Digital published an advisory discussing seven vulnerabilities (including 1 publicly available exploit) in their My Cloud products.

HP Update #1 - HP published an update for their UEFI firmware advisory that was originally published on February 2nd, 2022.

HP Update #2 - HP published an update for the PC BIOS advisory that was originally published on March 8th, 2022.

Mitsubishi Update - Mitsubishi published an update for their FragAttacks advisory that was originally published on September 2nd, 2021.

Spacelabs Update - Spacelabs published an update for their Access:7 advisory that was originally published on March 15th, 2021.

Yokogawa Update - Yokogawa published an update for their license function advisory that was originally published on January 14th, 2022.

ICT Reports - Zero Science published two reports about vulnerabilities (with publicly available exploits) in the ICT Protege GX integrated access control, intrusion detection and building automation solution.

 

For more details about these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-db0 - subscription required.

Saturday, February 26, 2022

Review - Public ICS Disclosures – Week of 2-19-22

This week we have twelve vendor disclosures from Aruba, GE Gas Power (2), Hitachi, Insyde (3), HPE, PulseSecure, QNAP, Siemens, and VMware. We have five vendor updates from Aruba, Dell, HPE, Johnson Controls, and Milestone. We also have 19 researcher reports for products from WECON (15), Fuji Electric (3), and Industrial Control Links (ICL). Finally we have three exploits reported for products from ICL and WebHMI (2).

Aruba Advisory - Aruba published an advisory describing 16 vulnerabilities in their AOS-CX Switches. Some of these are third-party vulnerabilities.

GE Gas Power Advisory #1 - GE published an advisory discussing the GE CIMPLICITY vulnerabilities reported earlier this week.

GE Gas Power Advisory #2 - GE published an advisory discussing the Blackberry QNX Neutrino Kernel vulnerability.

Hitachi Advisory - Hitachi published an advisory discussing 20 recently reported Microsoft vulnerabilities affecting their Hitachi Disk Array Systems.

Insyde Advisory #1 - Insyde published an advisory describing a privilege escalation vulnerability in their SysPasswordDxe driver.

Insyde Advisory #2 - Insyde published an advisory describing a buffer overflow vulnerability in their VariableEditSmm driver.

Insyde Advisoyr #3 - Insyde published an advisory describing a plain-text storage of sensitive information vulnerability in their HddPasswordPei driver.

HPE Advisory #1 - HPE published an advisory describing two vulnerabilities in their OneView Global Dashboard.

PulseSecure Advisory - PulseSecure published an advisory describing an integer overflow or wrap around vulnerability in multiple product lines.

QNAP Advisory - QNAP published an advisory describing two cross-site scripting vulnerabilities in their NAS running Proxy Server.

Siemens Advisory - Siemens published an advisory discussing 23 vulnerabilities in their Industrial Products.

VMware Advisory - VMware published an advisory describing a cross-site scripting vulnerability in their Workspace ONE Boxer.

Aruba Update - Aruba published an update for their PwnKit advisory that was originally published on February 1st, 2022.

Dell Update - Dell published an update for their generic Log4Shell  advisory.

HPE Update - HPE published an update for their PwnKit advisory that was originally published on February 1st 2022.

Johnson Controls Update - Johnson Controls published an update for their Log4Shell advisory.

Milestone Update - Milestone published an update for their Log4Shell advisory.

WECON Reports - The Zero Day Initiative published 15 reports of vulnerabilities in the WECON LeviStudioU.

Fuji Reports - ZDI published 3 reports of vulnerabilities in the Fuji Electric Alpha5 servo amplifiers.

ICL Report - Zero Science published a report describing a file write/overwrite and delete vulnerability in the ICL ScadaFlex II SCADA Controllers SC-1/SC-2.

ICL Exploit - LiquidWorm published an exploit for the ICL vulnerability reported above.

WebHMI Exploit #1 - Antonio Cuomo published an exploit for a remote code execution vulnerability in WebHMI version 4.1.1.

WebHMI Exploit #2 - Antonio Cuomo published an exploit for cross-site scripting vulnerability in WebHMI 4.1.

 

For more details about these disclosures, including links to 3rd party advisories, researcher reports, and exploits – see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2-762 - subscription required.

Saturday, January 22, 2022

Review - Public ICS Disclosures – Week of 1-15-22 – Part 1

This week we have a two-part posting with the 2nd part being a continued look at the response to the Log4Shell vulnerabilities. For Part 1, we have five vendor disclosures from Advantech, Bosch, B&R Industrial Automation, Hitachi Energy, and VMware. We also have an update from HPE. Finally, there are five researcher reports of vulnerabilities in products from OpenBMCS.

Advantech Advisory - Incibe-Cert published an advisory describing incorrect default permissions vulnerabilities in four separate Advantech products.

Bosch Advisory - Bosch published an advisory describing two vulnerabilities in their AMC2 (Access Modular Controller).

B&R Advisory - B&R published an advisory describing RCE through project upload from target vulnerability in their Automation Studio product.

Hitachi Energy Advisory - Hitachi Energy published an advisory describing nine vulnerabilities in their MicroSCADA Pro/X SYS600 Products.

VMware Advisory - VMware published an advisory describing a denial-of-service vulnerability in their VMware Workstation and Horizon Client products.

HPE Update - HPE published an update their HPE ProLiant and ProLiant Server Blades advisory that was originally published on November 10th, 2021.

OpenBMCS Reports - Zero Science published five reports about vulnerabilities in building management system products from OpenBMCS.

 

For more details on these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-8d9 - subscription required.

Saturday, September 11, 2021

Review - Public ICS Disclosures – 9-10-21

This week we have twelve vendor disclosures from ABB, BD, Draeger, Honeywell, Johnson Controls, Mitsubishi, Philips, and QNAP (5). There are also three updates from ABB, Aruba, and Yokogawa. We also have thirteen researcher reports for products from ECOA. Finally, we have an exploit for products from Geutebruck.

ABB Advisory - ABB published an advisory describing six vulnerabilities in their EIBPORT product.

BD Advisory - BD published an advisory describing four vulnerabilities in their BD Alaris and BD FocalPoint products.

Draeger Advisory - Draeger published an advisory discussing the FragAttacks WiFi vulnerabilities.

Honeywell Advisory - Honeywell published a notice announcing the availability of new versions of their VMS and NVR Software that contain fixes for unspecified security vulnerabilities.

Johnson Controls Advisory - Johnson Controls published an advisory describing an authorization bypass through user controlled key vulnerability in their Kantech KT‐1 door controller.

Mitsubishi Advisory - Mitsubishi published an advisory describing two vulnerabilities in the TCP/IP Protocol Stack of GOT and Tension Controller.

Philips Advisory - Philips published an advisory discussing the PetitPotam exploit.

QNAP Advisory #1 - QNAP published an advisory describing an insufficient HTTP security headers vulnerability in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #2 - QNAP published an advisory describing an insufficiently protected credentials vulnerability in their QSW-M2116P-2T2S and QuNetSwitch products.

QNAP Advisory #3 - QNAP published an advisory describing two stack-based buffer overflow vulnerabilities in their NVR Storage Expansion.

QNAP Advisory #4 - QNAP published an advisory describing a stack-based buffer overflow vulnerability in their QUSBCam2.

QNAP Advisory #5 - QNAP published an advisory describing a stack-based buffer overflow vulnerability in their QTS, QuTS hero, and QuTScloud products.

ABB Update - ABB published an update for their Base Software for SoftControl advisory that was originally published on June 23rd, 2021.

Aruba Update - Aruba published an update for their Aruba OS advisory that was originally published on August 31st, 2021.

Yokogawa Update - Yokogawa published an update for their VB6 Runtime advisory that was originally published on April 23rd, 2021.

ECOA Reports - Zero Science published thirteen reports about vulnerabilities in the ECOA Building Automation System.

Geutebruck Exploit - Titouan Lazard published a Metasploit module for seven vulnerabilities in the Geutebruck G-Cam E2 and G-Code cameras.

For more details about the various advisories, including links to third-party reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-9-10-21 - subscription required.

Saturday, July 24, 2021

Review - Public ICS Disclosures – Week of 7-17-21

This week we have seven vendor disclosures from MB connect (3), CODESYS, Dell (2) and Ruckus. We have five researcher reports for products from Schneider Electric, Advantech, and KevinLAB (3).

MB connect Advisory #1 - CERT-VDE published an advisory describing two vulnerabilities in the MB connect mymbCONNECT24, mbCONNECT24 products.

MB connect Advisory #2 - CERT-VDE published an advisory discussing two vulnerabilities in the MB connect mymbCONNECT24, mbCONNECT24 products.

MB connect Advisory #3 - CERT-VDE published an advisory describing two vulnerabilities in the MB connect mbDIALUP product.

CODESYS Advisory - CODESYS published an advisory describing a null pointer dereference vulnerability in their EtherNetIP protocol stack.

Dell Advisory #1 - Dell published an advisory discussing a null pointer dereference vulnerability in their Wyse ThinOS product line.

Dell Advisory #2 - Dell published an advisory describing two sensitive item disclosure vulnerabilities in their Wyse ThinOS product line.

Ruckus Advisory - Ruckus published an advisory describing an improper handling of an error condition vulnerability in their SmartZone Controller.

Schneider Report - SEC Consult published a report describing two vulnerabilities in the Schneider Electric EVlink product.

Advantech Report - The Zero Day Initiative published a report describing a lack of authentication vulnerability for the Advantech WebAccess/NMS.

KevinLAB Report #1 - Zero Science published a report describing a path traversal information disclosure vulnerability in the KevinLab Building Energy Management System (BEMS) product.

KevinLAB Report #2 - Zero Science published a report describing an SQL injection vulnerability in the KevinLAB BEMS product.

KevinLAB Report #3 - Zero Science published a report describing a back-door account vulnerability in the KevinLAB BEMS product.

For more details on the vulnerability reports and links to exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-c10 - subscription required.

Saturday, July 10, 2021

Review - Public ICS Disclosures – Week of 7-3-21

This week we have thirteen vendor disclosures from ABB, Bosch, B&R Industrial Automation (3), Flexera, GE Healthcare, Hitachi, HMS Networks, Philips, QNAP, Rockwell Automation, and SonicWall. We have four researcher reports of vulnerabilities in products from Advantech (2), Ricon, and VMWare.

ABB Advisory - ABB published an advisory describing a serial number misuse vulnerability in their Busch®-ControlTouch product.

Bosch Advisory - Bosch published an advisory discussing three vulnerabilities in their Rexroth products.

B&R Advisory #1 - B&R published an advisory describing an out-of-bounds write vulnerability in their X20 EthernetIP Adapter.

B&R Advisory #2 - B&R published an advisory describing an out-of-bounds write vulnerability in their  PROFINET IO Devices.

B&R Advisory #3 - B&R published an advisory describing a denial of service vulnerability in their Automation Runtime product.

Dell Advisory - Dell published an advisory describing two vulnerabilities in their Dell Wyse Management Suite.

Flexera Advisory - Flexera published an advisory describing an exposure of sensitive information to an unauthorized actor vulnerability in their FlexNet Publisher.

GE Healthcare Advisory - GE Healthcare published an advisory discussing the PrintNightmare vulnerabilities.

Hitachi Advisory - Hitachi published an advisory discussing 23 vulnerabilities in their Hitachi Disk Array Systems.

HMS Advisory - HMS published an advisory describing an insecure file system permission vulnerability in their eCatcher product.

Philips Advisory - Philips published an advisory discussing the Kaseya VSA supply chain attack.

QNAP Advisory - QNAP published an advisory describing an improper access control vulnerability in their Legacy HBS 3 (Hybrid Backup Sync) product.

Rockwell Advisory - Rockwell published their advisory for the vulnerability reported this week by NCCIC-ICS.

SonicWall Advisory - SonicWall published an advisory describing an out-of-bounds read vulnerability in their SonicWall Switch product.

Advantech Report - ZDI published two reports (here and here) of stack-based buffer overflow vulnerabilities in the Advantech web access product.

Ricon Report - Zero Science Lab published a report describing an OS command injection vulnerability in the Ricon S9922L series LTE router.

VMWare Report - NCC Group published a report on exploiting CVE-2021-3156 VMWare vCenter Server 7.0 product.

For a more detailed discussion of the advisories see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-ac2 - subscription required.

Saturday, March 20, 2021

Public ICS Disclosures – Week of 3-13-21

This week we have 19 vendor disclosures from GE Grid (17), Moxa, and Philips. We have one update from BD. We have three researcher reports for products from Soyal. Finally, we have two exploits for products from QNAP and VMware.

GE Grid Advisories

GE Grid published advisories for the below listed products. The advisories are only available to GE registered customers. It is possible that these are all related to the vulnerabilities reported by NCCIC-ICS in the GE UR product earlier this week.

C30 Controller,

C60 Breaker Management Relay,

C70 Capacitor Bank Protection and Control System,

B30 Bus Differential Relay,

B90 Bus Differential System,

F35 Multiple Feeder Management Relay,

F60 Feeder Management Relay,

G30 Generator Management Relay,

G60 Generator Management Relay,

L30 Line Current Differential Relay,

L60 Line Phase Comparison Relay,

L90 Line Current Differential Relay,

M60 Motor Management Relay,

D30 Line Distance Relay,

D60 Line Distance Relay,

N60 Network Stability and Synchrophasor Measurement System,

T35 Transformer Management Relay, and

T60 Transformer Management Relay ,

Moxa Advisory

Moxa published an advisory describing three vulnerabilities in their VPort 06EC-2V Series IP Cameras. The vulnerabilities were reported by Qian Chen of Qihoo 360 Nirvan Team. Moxa has patches available to mitigate the vulnerabilities. There is no indication that Qian has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Null pointer dereference,

• Integer underflow, and

• Out-of-bounds read.

Philips Advisory

Philips published an advisory discussing the F5 Network vulnerabilities. Philips has identified the following products as being affected by the vulnerabilities:

• Clinical Collaboration Platform,

• IS PACS,

• Universal Data Manager, and

• VueByond

BD Update

BD published an update for their BD Alaris advisory that was originally published on February 6th, 2017 and most recently updated on October 19th, 2017. The new information includes:

• Updating the affected product list to include an out-of-service product,

• Adding Palo Alto Networks as the original reporter of the vulnerability,

• Adding a description of the replacement of an internal flash drive vulnerability, and

• Adding a notice that a product update is pending FDA review.

NOTE: NCCIC-ICS has not yet updated their advisory (ICSMA-17-017-02) for this updated information.

Soyal Reports

Zero Science published three reports for vulnerabilities in the SOYAL Biometric Access Control System. The vulnerability disclosures were coordinated with ZOYAL, but status of the mitigation measures is not currently available. Exploits have been published for each of the three reported vulnerabilities by LiquidWorm

The three reported vulnerabilities are:

CSRF change admin password – (exploit),

Weak default credentials – (exploit), and

Master code disclosure – (exploit)

QNAP Exploit

Luiz Martinez published an exploit for an unquoted service path vulnerability in the QNAP QVR Client. There is no CVE number provided nor is there any mention of coordination with QNAP, so this may be a 0-day exploit.

VMWare Exploit

Grant Willcox and Mikhail Klyuchnikov published a Metasploit module for an unauthenticated log file upload vulnerability in the VMwareView Planner product. This vulnerability was previously reported by VMware.

Saturday, April 25, 2020

Public ICS Disclosure – Week of 4-18-20


This week we have 8 vendor advisories for products from ABB (4), Johnson Controls, Rockwell, BD and Eaton; as well as 3 updated advisories for products from ABB. There are also 3 researcher disclosures for products from P5, Rockwell and Siemens.

ABB Advisories


ABB published an advisory describing a path traversal vulnerability in their UPS Adapter CS141. The vulnerability was reported by Eduardo Cataño Conde. ABB has a new version that mitigates the vulnerability. There is no indication that Conde has been provided an opportunity to verify the efficacy of the fix.


ABB published an advisory describing five vulnerabilities in their ABB Central Licensing System. The vulnerabilities were reported by William Knowles at Applied Risk. ABB will be preparing product specific advisories for these vulnerabilities.

The five reported vulnerabilities are:

• Information disclosure - CVE-2020-8481;
• XML external entity injection - CVE-2020-8479;
• Denial of service - CVE-2020-8475;
• Privilege elevation - CVE-2020-8476; and
• Weak file permissions - CVE-2020-8471


ABB published an advisory describing the impact of their Central Licensing System Vulnerabilities (see above) on their System 800xA, Compact HMI and Control Builder Safe products. A new version of the Central Licensing System is available that mitigates some of the vulnerabilities. There is no indication that Knowles has been provided an opportunity to verify the efficacy of the fix.


ABB published an advisory describing Inter process communication vulnerability in System 800xA. The vulnerabilities were reported by William Knowles at Applied Risk. ABB has provided generic workarounds to mitigate the vulnerability while working on product updates. NOTE: ABB has requested separate CVE numbers for each affected product based upon varying levels of risk in the products.


NOTE: The ABB Alerts and Notifications page also lists two advisories for products from B&R. I have not covered them here because they were covered when they were released by B&R.

Johnson Controls Advisory


Johnson Controls published an advisory describing an XML external entity injection vulnerability in their BCPro Workstation and Building Configuration Tool (BCT) software. The vulnerability is self-reported. Johnson Controls has a patch that mitigates the vulnerability.

Rockwell Advisory


Rockwell published an advisory describing eight third-party vulnerabilities in their FactoryTalk product. The vulnerabilities are in the Gemalto Sentinal LDK Runtime Environment. The Sentinal LDK vulnerabilities were reported by Kaspersky in January of 2018. Rockwell has a new version that mitigates the vulnerabilities.

BD Advisory


BD published an advisory describing a third-party vendor outdated certificate vulnerability in a large number of their products. The problem was identified by ESET in some of their legacy products. BD is working on validating the ESET update.

Eaton Advisory


Eaton published an advisory describing a third-party vendor stack-based buffer overflow vulnerability in their products  supporting DNP3 Protocol. The Triangle MicroWorks vulnerability was reported by NCCIC-ICS (ICSA-20-105-02) last week. Eaton provided generic workarounds while it is evaluating the vulnerability and its effects on their products.

ABB Updates


ABB published an update for their System 800xA Weak File Permissions advisory that was originally published on April 2nd, 2020. The new information includes an added FAQ question on functional safety.


ABB published an update for their System 800xA Information Manager advisory that was originally published on April 2nd, 2020. The new information includes an added FAQ question on functional safety. (NOTE: includes statement that: “Under certain conditions exploits of this vulnerability may affect the integrity of safety functions in System 800xA.”)


ABB published an update for their System 800xA Weak Registry Permissions advisory that was originally published on April 2nd, 2020. NOTE: The ABB Alerts and Notifications page says that this advisory was updated on “2020-04-21” like the previous 2, but the link takes one to the original advisory with no changes. I suspect that the update should include the same added FAQ question seen in the two updates described above. The difference would be in the answer to that FAQ.


Researcher Disclosures


Zero Science published a report describing a stored cross-site scripting vulnerability in the P5 FNIP-8x16A eight channel relay module. The report includes links to an exploit published by LiquidWorm. Zero Science has attempted to contact P5 but has received no response.

Applied Risk published a report describing an insecure registry permissions vulnerability in the Rockwell RSLinx Classic. This vulnerability was reported by NCCIC-ICS on April 9th, 2020.

Applied Risk published a report describing an insecure file permissions vulnerability in the Siemens TIA Portal. This vulnerability was reported by NCCIC-ICS on January 14th, 2020 and subsequently updated on April 14th.

Saturday, July 6, 2019

Public ICS Disclosure – Week of 06-29-19


This week we have a vendor update for the Microsoft® RDP vulnerability and seven researcher reports (okay is should be a single report with seven vulnerabilities) from Zero Science for products from FaceSentry.

Microsoft RDP Vulnerability Vendor Reports



FaceSentry Advisories


Zero Science published seven reports of vulnerabilities in the FaceSentry Access Control System. These are all zero-day reports with Zero Science reporting no response from iWT, the manufacturer.

The seven reported vulnerabilities (with proof of concept code) are:



Saturday, February 16, 2019

Public ICS Disclosures – Week of 02-09-19


This week we have five vendor disclosures for products from Kunbus, Schneider (3) and Rockwell; five vendor updates from Siemens; one coordinated disclosure for products from Resource Data Management and one exploit for a previously disclosed vulnerability for products from AVEVA.

Kunbus Advisory


Kunbus published an advisory for five vulnerabilities in its KUNBUS-GW Modbus TCP PR100088 product. The vulnerabilities were reported by Nicolas Merle of Applied Risk. Kunbus is working on an update to mitigate the vulnerabilities.

The five reported vulnerabilities are:

• Conditional authentication bypass;
• Missing authentication for critical function;
• Denial of service;
• Publication of information by parameter data in an HTTP GET request; and
Plain text storage of passwords

Schneider Advisories


Schneider has published an advisory describing six vulnerabilities in its Sarix Enhanced and Spectra Enhanced cameras. The vulnerabilities were reported by Deng Yongkai (NSFOCUS) and Gjoko Krstic (Zero Science). Schneider has a new firmware version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

• A permissions, privileges, and access control vulnerability - CVE-2018-7816;
• A command injection vulnerability (2) - CVE-2018-7825 and CVE-2018-7826;
• A cross-site scripting (XSS) vulnerability (2) - CVE-2018-7827 and CVE-2018-7828; and
• An improper neutralization of special elements in query vulnerability - CVE-2018-7829


Schneider has published an advisory describing a buffer error vulnerability in its Vijeo Designer Lite software. The vulnerability is self-reported. Schneider has provided generic mitigations as the product has reached end-of-life status.


Schneider has published an advisory describing three vulnerabilities in its  Modicon M221 and
SoMachine Basic products. The vulnerabilities were reported by Matthias Niedermaier (Hochschule Augsburg), Jan-Ole Malchow (Freie Universität Berlin), Florian Fischer (Hochschule Augsburg) and Reid Wightman (Dragos Inc.). Schneider has updates available to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• An environment vulnerability (2) - CVE-2018-7821 and CVE-2018-7823; and
• An incorrect default permissions vulnerability - CVE-2018-7822

Rockwell Advisory


Rockwell has published an advisory describing two vulnerabilities in its PowerMonitor 1000 monitor that were publicly reported (with exploits) in December (here and here) by Luca Chiou. Rockwell has provided generic mitigation measures pending development of updates. It also provides a link to intrusion prevention system (by CheckPoint) rules to detect the cross-site scripting vulnerability.

The two reported vulnerabilities are:

• Cross-site scripting - CVE-2019-19615; and
• Authentication bypass - CVE-2019-19616

 Siemens Updates


Siemens published an update for their advisory on Spectre and Meltdown Vulnerabilities in Industrial Products. They added updated affected version data and provided links to mitigations for:

• SIMATIC ET 200 SP Open Controller; and
• SIMATIC IPC547E

NOTE: NCCIC-ICS updated their alert (ICS-ALERT-18-011-01) for this vulnerability when Siemens added a new advisory. That technically included this update since the link provided in the alert goes to the latest version of the Siemens advisory.


Siemens published an update for their advisory on Spectre-NG (Variants 3a and 4) Vulnerabilities in Industrial Products. They added updated version data and provided links to mitigations for:

• SIMATIC ET 200 SP Open Controller:
• SIMATIC ET 200 SP Open Controller (F);
• SIMATIC S7-1500 Software Controller;
• SIMATIC IPC547E;
• SIMATIC ITP1000;
• SIMATIC IPC3000 SMART V2;
• SIMATIC IPC347E;
• SIMATIC HMI Basic; and
• Panels 2nd Generation:

They also removed the following unaffected products from the advisory:

• SIMATIC IPC227E;
• SIMATIC IPC277E;
• SIMATIC IPC327E; and
• SIMATIC IPC377E

NOTE: NCCIC-ICS is expected to update their advisory.


Siemens published an update for their advisory on Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP. They added two additional vulnerabilities to the list for these products:

• CVE-2018-1000876; and
• CVE-2018-16862
NOTE: NCCIC-ICS has not published an advisory/alert on these vulnerabilities.

Siemens has published an update for their advisory on Denial-of-Service in SICAM A8000 Series. They updated the CVSS vector due to known exploit.


Siemens has published an update for their advisory on Foreshadow / L1 Terminal Fault Vulnerabilities in Industrial Products. They updated the affected version data and provided links to the mitigation measures for:

• SIMATIC IPC547E;
• SIMATIC IPC547G;
• SIMATIC ITP1000;
• SIMATIC IPC3000 SMART V2; and
• SIMATIC IPC347E

They also removed the following unaffected products from the advisory:

• SIMATIC IPC227E;
• SIMATIC IPC277E;
• SIMATIC IPC327E; and
• SIMATIC IPC377E
NOTE: NCCIC-ICS has not published an advisory/alert on these vulnerabilities.

Resource Data Management


Safety Detective published an article describing default credential vulnerabilities for commercial refrigeration systems from Resource Data Management. The article describes how the researchers were able to locate vulnerable systems, change settings, and manipulate controls in systems in hospitals and stores.

AVEVA Exploit


Jacob Baines published an exploit for vulnerabilities in the AVEVA InduSoft Web Studio. The vulnerabilities were reported by NCCIC-ICS earlier this month.

 
/* Use this with templates/template-twocol.html */