Wednesday, February 19, 2025

Review - Siemens Publishes Out-of-Zone Update – 2-19-25

Today, Siemens published an update for their Palo Alto Networks PAN-OS on RUGGEDCOM APE1808 Devices advisory that was originally published on November 22nd, 2024, and most recently updated on February 11th, 2025. The new information includes adding four vulnerabilities, one listed in CISA’s Known Exploited Vulnerability (KEV) catalog.

 

For more information on the vulnerabilities added, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/siemens-publishes-out-of-zone-update-bdd - subscription required.

Review – Public ICS Disclosures – Week of 2-8-25 – Part 3

For Part 3 we have eight additional vendor disclosures from ABB, Schneider (4) and WatchGuard (3). We also have 25 vendor updates from Broadcom (9), Elecom (3), FortiGuard (2), Schneider (2), and Siemens (9). There are 11 researcher reports of vulnerabilities in products from ABB (9), CMU-CERT, and Wattsense. Finally, we have three exploits for vulnerabilities in products from ABB (2) and mySCADA.

Advisories

ABB Advisory - ABB published an advisory that describes three vulnerabilities (one with publicly available exploit) in their FLXeon Controllers.

Schneider Advisory #1 - Schneider published an advisory that describes four vulnerabilities in their ASCO 5310 / 5350 Remote Annunciator.

Schneider Advisory #2 - Schneider published an advisory that describes an improper input validation vulnerability in their Uni-Telway driver.

Schneider Advisory #3 - Schneider published an advisory that describes an improper privilege management vulnerability in their EcoStruxure Process Expert products.

Schneider Advisory #4 - Schneider published an advisory that describes three improper input validation vulnerabilities in their Enerlin’X IFE and eIFE ethernet connectors for circuit breakers.

WatchGuard Advisory #1 - WatchGuard published an advisory that describes an improper input validation vulnerability in their Fireware OS.

WatchGuard Advisory #2 - WatchGuard published an advisory that describes a cross-site scripting vulnerability in their Fireware OS.

WatchGuard Advisory #3 - WatchGuard published an advisory that describes a cross-site scripting vulnerability in their Fireware OS.

Updates

Broadcom Update #1 - Broadcom published an update for their SNMP commands advisory that was originally published on July 30th, 2024.

Broadcom Update #2 - Broadcom published an update for their SNMP passwords advisory that was originally published on July 30th, 2024, and most recently updated on September 3rd, 2024.

Broadcom Update #3 - Broadcom published an update for their third-party SANnav vulnerabilities advisory that was originally published on October 14th, 2024, and most recently updated on January 7th, 2025.

Broadcom Update #4 - Broadcom published an update for their third-party Brocade Fabric OS advisory that was originally published on September 26th, 2024, and most recently updated on November 12th, 2024.

Broadcom Update #5 - Broadcom published an update for their OpenSSH advisory that was originally published on December 9th, 2024, and most recently updated on January 7th, 2025.

Broadcom Update #6 - Broadcom published an update for their third-party Brocade ASCG vulnerabilities advisory that was originally published on January 7th, 2025.

Broadcom Update #7 - Broadcom published an update for their OpenSSL file names advisory that was originally published on August 1st 2024.

Broadcom Update #8 - Broadcom published an update for their regreSSHion advisory that was originally published on July 15th, 2024.

Broadcom Update #9 - Broadcom published an update for their LESSCLOSE advisory that was originally published on November 12th, 2024.

Elecom Update #1 - JP-CERT published an update for the Elecom wireless LAN router advisory that was originally published on July 30th, 2024, and most recently updated on August 27th, 2024.

Elecom Update #2 - JP-CERT published an update for the Elecom and LOGITEC network devices advisory that was originally published on August 10th, 2023, and most recently updated on August 27th, 2024.

Elecom Update #3 - JP-CERT published an update for the Elecom wireless LAN routers advisory that was originally published on August 27th, 2024, and most recently updated on November 26th, 2024.

FortiGuard Update #1 - FortiGuard published an update for their regreSSHion advisory that was originally published on July 9th, 2024, and most recently updated on December 19th, 2024.

FortiGuard Update #2 - FortiGuard published an update for their authentication bypass in Node.js advisory that was originally published on January 14th, 2025, and most recently updated on January 24th, 2025.

Schneider Update #1 - Schneider published an update for their FlexNet Publisher advisory that was originally published on January 14th, 2025.

Schneider Update #2 - Schneider published an update for their Modicon Controllers advisory that was originally published on May 14th, 2019, and most recently updated on July 9th, 2024.

Siemens Update #1 - Siemens published an update for their FortiGate NGFW advisory that was originally published on March 12th, 2024, and most recently updated on September 10th, 2024.

Siemens Update #2 - Siemens published an update for their OpenSSL (CVE-2022-0778) advisory that was originally published on June 14th, 2022, and most recently updated on July 9th, 2024.

Siemens Update #3 - Siemens published an update for their FortiGate NGFW advisory that was originally published on July 9th, 2024, and most recently updated on December 10th, 2024.

Siemens Update #4 - Siemens published an update for their TCP Event Service advisory that was originally published on October 11th, 2022, and most recently updated on March 14th, 2024.

Siemens Update #5 - Siemens published an update for their GNU/Linux subsystem advisory that was originally published on December 12th, 2023, and most recently updated on January 14th, 2025.

Siemens Update #6 - Siemens published an update for their Palo Alto Networks PAN-OS advisory that was originally published on November 22nd, 2024.

Siemens Update #7 - Siemens published an update for their Industrial Real-Time Devices advisory that was originally published on October 8th, 2019, and most recently updated on September 10th, 2024.

Siemens Update #8 - Siemens published an update for their SINEC Traffic Analyzer advisory that was originally published on June 11th, 2025.

Siemens Update #9 - Siemens published an update for their Filesystem Access advisory that was originally published on January 14th, 2025.

Researcher Reports

ABB Reports - Zero Science published seven reports about vulnerabilities in the ABB Cylon FLXeon building energy management system.

CMU-CERT Report - Zero Science published a report about a stored cross-site scripting vulnerability in CMU-CERT’s Vulnerability Information and Coordination Environment (VINCE).

Wattsense Report - SEC Consult published a report that describes four vulnerabilities in the Wattsense Bridge.

Exploits

ABB Exploit #1 – LiquidWorm published an exploit for a session fixation vulnerability in the ABB Cylon Aspect building energy management system.

ABB Exploit #2 - LiquidWorm published an exploit for a uncontrolled resource consumption vulnerability in the ABB Cylon FLXeon building automation system.

mySCADA Exploit - Michael Heinzl published an exploit for an OS command injection vulnerability in the mySCADA myPRO Manager.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2-b1d - subscription required. 

Tuesday, February 18, 2025

Short Takes – 2-18-25

Nokia is putting the first cellular network on the moon. TechnologyReview.com article. Pull quote: “And that means that if you happened to bring your smartphone to the moon, and it somehow survived both the trip and the brutal lunar conditions, it should work on the moon just like it does here on Earth. “It would connect if we put your phone on the list of approved devices”, Klein explains. All you’d need is a lunar SIM card.” Roaming charges would be rather high….

Congress closing in on shutdown deadline with no clear plan. TheHill.com article. Pull quote: “Speaker Mike Johnson (R-La.) has left the door open to the idea of a stopgap, also known as a continuing resolution (CR), that would run through the end of the fiscal year. The idea has some support from conservatives who want to see funding levels kept flat through September, even if it locks in continued spending in line with some of former President Biden’s funding priorities in the meantime. However, some Republicans are resisting the idea.”

What the asteroid with a 1-in-48 chance of hitting Earth in 2032 looks like (images). Space.com article. Pull quote: “There are more Gemini South images of 2024 YR4 in the pipeline, but as the asteroid is currently heading away from Earth, it might be a while until we get a really good look at this space rock — from the ground at least.”

3D-printed 'hydrogels' could be future space radiation shields for astronaut trips to Mars. Space.com article. Pull quote: “This new study builds on previous work where hydrogel was tested to make sure that it was safe to use in space conditions. "There is a constant search for lightweight radiation protection materials," project lead Peter Dubruel said, in the statement. "We are applying different techniques to shape the material into a 3D structure and scale up the production process, so that we can come a step closer to industrialisation."”

Texas measles cases are up, and New Mexico now has an outbreak. Here’s what you need to know. APNews.com article. Pull quote: “Gaines County has one of the highest rates in Texas of school-aged children who opt out of at least one required vaccine, with nearly 14% of K-12 children in the 2023-24 school year. Health officials say that number is likely higher because it doesn’t include many children who are homeschooled and whose data would not be reported.”

National Science Foundation Fires 168 Workers as Federal Purge Continues. Kim Zetter Wired.com article. Pull quote: “Many of the people terminated on Tuesday work as program managers and experts who make decisions about funding by aligning research proposals with the right program and matching those proposals to the most qualified reviewers to assess them and make recommendations.”

AI-Powered Social Engineering: Ancillary Tools and Techniques. TheHackerNews.com article. Pull quote: “Many tools are open source, allowing users to customize with plugins and modules. For example, Recon-ng can be configured for use cases such as email harvesting and OSINT gathering. Other tools aren't for public use, such as Red Reaper. This is a form of Espionage AI, capable of sifting through hundreds of thousands of emails to detect sensitive information that could be used against organizations.”

As egg prices soar, Trump administration plans new strategy to fight bird flu. APNews.com article. Pull quote: “Hassett didn't provide many details of how the Trump administration's new approach would work. But he said it would involve a “better, smarter perimeter” around poultry farms. He said it doesn't make sense to kill all the chickens inside that perimeter when the disease is being spread by wild ducks and geese.”

Czars versus councils: Organizing space in the new administration. TheSpaceReview.com article. Pull quote: “Meanwhile, a bipartisan bill introduced in the Senate earlier this month would formally authorize the Office of Space Commerce’s efforts to develop a space traffic coordination system, one currently in beta testing. The bill included a provision that would elevate the office into a Bureau of Space Commerce, led by a Senate-confirmed assistant secretary rather than by a presidentially appointed director as the office is managed today.”

CISA Adds PAN-OS and SonicOS Vulnerabilities to KEV Catalog – 2-18-25

Today CISA announced that it had added operating system vulnerabilities from Palo Alto Networks and SonicWall to their Known Exploited Vulnerabilities (KEV) catalog.

PAN-OS Vulnerability

The PAN-OS vulnerability is a missing authentication for critical function vulnerability. The vulnerability was previously reported by Palo Alto Networks, they have new versions that mitigate the vulnerability. The vulnerability was initially reported Adam Kues of Assetnote Security Research Team. GreyNoise reported seeing this vulnerability being exploited in the wild last week.

NOTE: I briefly discussed this vulnerability yesterday.

CISA has directed federal agencies to apply “mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.” The deadline for completing these actions is March 11th, 2025.

SonicOS Vulnerability

The SonicOS vulnerability is an improper authentication vulnerability. The vulnerability was previously reported by SonicWall. The vulnerability was initially reported by Daan Keuper, Thijs Alkemade and Khaled Nassar of Computest Security via the Zero Day Initiative. BishopFox published a technical report on the vulnerability which included proof-of-concept code.

NOTE: I briefly discussed this vulnerability on January 11th, 2025.

CISA has directed federal agencies to apply “mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.” The deadline for completing these actions is March 11th, 2025.

Review – 2 Updates Published – 2-18-25

Today CISA’s NCCIC-ICS published two updates for control system security advisories published for products from Rockwell Automation and Delta Electronics.

Advisories

Rockwell Update - This update provides additional information on the GuardLogix 5380 (originally “1756-L8zS3”) advisory that was originally published on February 4th, 2025.

NOTE: Earlier reader comments were addressed by this change.

Delta Update - This update provides additional information on the CNCSoft-G2 advisory that was originally published on July 9th, 2024.

 

For more information on these updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-updates-published-2-18-25 - subscription required.

Review – HR 1182 Introduced – Foreign Cylinder Regulations

Earlier this month, Rep Balderson (R,OH) introduced HR 1182, the Compressed Gas Cylinder Safety and Oversight Improvements Act of 2023. The bill would require DOT to establish additional regulations relating to the approval of foreign manufacturers of cylinders used in the transport of hazardous chemicals. There is no new spending authorized by this legislation.

This bill is very similar to HR 3404 that was introduced by Balderson in May of 2023. No action was taken on that bill since neither Balderson nor his initial cosponsor were members of the House Transportation and Infrastructure Committee, to which the bill was assigned. An added sponsor later in the session changed that influence situation, but too late to be of any help. A similar bill, S 1632, was introduced in the Senate by then Sen Vance (R,OH); no action was taken on that bill either.

Moving Forward

While Balderson is still not a member of the House Transportation and Infrastructure Committee, two of his cosponsors {Rep Taylor (R,OH) and Rep Nehls (R,TX)} are members. This means that there may be sufficient influence to see the bill considered in Committee. While this bill would require new regulations (generally an anathema to the Republican majority in the House and Senate) this bill would allow for expanded use of less expensive foreign made cylinders, something that would be generally favored by most hazardous material shippers. Balanced against the increased oversight of FOMC, and presumably their increased costs, this bill may have a chance of moving through the Committee with some level of bipartisan support. How extensive that support is will determine if the bill could be brought to the floor of the House under the suspension of the rules process.

 

For more information about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-1182-introduced - subscription required.

Monday, February 17, 2025

Short Takes – 2-17-25

Trump administration tries to bring back fired nuclear weapons workers in DOGE reversal. APNews.com article. Pull quote: ““This is a pivotal moment. We must decide whether we are truly committed to leading on the world stage or if we are content with undermining the very systems that secure our nation’s future,” deputy division director Rob Plonski posted to LinkedIn. “Cutting the federal workforce responsible for these functions may be seen as reckless at best and adversarily opportunistic at worst.””

Got Weird? Milk Is Headed for Its Strangest Year Yet. NYTimes.com article (free). Pull quote: “Now milk is back in nutritional favor, as Americans’ priorities have shifted toward hydration, protein and healthy fats. A high-profile 2008 study — partly funded by the dairy industry — showed that chocolate milk’s benefits for athletes were equivalent to or better than those of lab-concocted performance drinks like Gatorade. Follow-up studies have continued to show similar results, helping to rebrand milk as a natural nutrition powerhouse.”

Trump fires hundreds of air traffic support staff as SpaceX visits FAA command center. TechCrunch.com article. Pull quote: “Members of Musk’s SpaceX team are visiting the Air Traffic Control System Command Center in Virginia on Monday to “get a firsthand look at the current system, learn what air traffic controllers like and dislike about their current tools, and envision how we can make a new, better, modern and safer system,” wrote Sean Duffy, Secretary of the Department of Transportation, in a post on X.”

Trump begins firings of FAA staff just weeks after fatal DC plane crash. APNews.com article. Pull quote: “Other FAA employees who were fired were working on an urgent and classified early warning radar system the Air Force had announced in 2023 for Hawaii to detect incoming cruise missiles, through a program that was in part funded by the Defense Department. It’s one of several programs that the FAA’s National Airspace System Defense Program manages that involve radars providing longer-range detection around the country’s borders.”

EO 14211 - One Voice for America's Foreign Relations. Federal Register.

 
/* Use this with templates/template-twocol.html */