Today, CISA’s NCCIC-ICS published two control system security advisories for products from Advantech and Ricon. They also updated their Multiple Data Distribution System advisory.
Advantech Advisory
This advisory describes a use of hard-coded cryptographic key in the Advantech ADAM-3600 remote terminal unit. The vulnerability was reported by Aagam Shah. Advantech provides generic mitigation measures pending development of a fix.
NCCIC-ICS reported that a relatively low-skilled attacker could remotely exploit the vulnerability to allow unauthorized access to intercept traffic using the hardcoded key. This could allow an attacker to achieve Web Server login and perform further actions.
Ricon Advisory
This advisory describes an OS command injection vulnerability in the Ricon S9922 series Industrial Cellular Router. The vulnerability was reported by Gjoko Krstic of Zero Science Lab. Ricon has not responded to NCCIC-ICS.
NCCIC-ICS reported that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to inject and execute arbitrary shell commands as an Admin user.
NOTE: I briefly discussed this vulnerability on July 10th, 2021.
Multiple DDS Update
This update provides additional information on an advisory that was originally published on November 11th, 2021. The new information includes:
Revising the CVSS for CVE-2021-38425 from 8.2 to 7.5,
Revising the CVSS for CVE-2021-38429 from 8.2 to 7.5,
Revising the CVSS for CVE-2021-38487 from 8.2 to 7.5, and
Revising the CVSS for CVE-2021-38447 from 8.2 to 7.5
These changes are based upon slightly different CVSS vector strings {…./C:N/I:N/A:H)} instead of {…/C:L/I:N/A:H)} The 9 CVE that did not have their CVSS change still have vector strings ending in … /C:L/I:N/A:H).
NOTE 1: None of these CVE have yet been published at https://nvd.nist.gov.
NOTE 2: Alias Robotic recently published an updated report on these vulnerabilities.