Today CISA’s NCCIC-ICS published three control system security advisories for products from Advantech, Softing, and Schneider electric – 2 advisories were updated for products from Rockwell Automation and WAGO –
Advantech Advisory
This advisory describes two vulnerabilities in the Advantech WebAccess/SCADA. The vulnerabilities were reported by Chizuru Toyama of TXOne IoT/ICS Security Research Labs via the Zero Day Initiative. Advantech is currently working on mitigation measures.
The two reported vulnerabilities are:
Open redirect - CVE-2021-32956, and
Relative path traversal - CVE-2021-32954
NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to read files outside the intended directory or redirect a user to a malicious webpage.
Softing Advisory
This advisory describes an improper restriction of operations within the bounds of a memory buffer vulnerability in the Softing OPC-UA C++ Software Development Kit. The vulnerability was reported by Eran Jacob of Otorio. Softing has a new version that mitigates the vulnerability. There is no indication that Jacob has been provided an opportunity to verify the efficacy of the fix.
NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to crash the device, resulting in a denial-of-service condition. This vulnerability exists in exported functions of the library, and exploits may have different consequences depending on how the library functions have been used.
Schneider Advisory
This advisory describes an improper privilege management vulnerability in the Schneider Enerlin'X Com’X 510 energy server. The vulnerability was reported by Maxim Rupp. Schneider has a new firmware version that partially mitigates the vulnerability.
NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow elevation of privileges, which could result in unintended disclosure of device configuration information to any authenticated user.
NOTE: I briefly discussed (subscription required) this advisory on Sunday.
Rockwell Update
This update provides additional information on an advisory that originally published (subscription required) on June 8th, 2021. The new information includes adding the Xylem MultiSmart products as potentially being affected by the vulnerability.
NOTE: I briefly discussed (subscription required) Xylem’s advisory for these vulnerabilities on Saturday.
WAGO Update
This update provides additional information on an advisory that originally published on January 21st, 2021 and most recently updated on February 16th, 2021. The new information includes adding updated affected version information for the Mitsubishi MELSOFT FieldDeviceConfigurator.
NOTE: The new Mitsubishi advisory that drives this change provides mitigation measures for the vulnerability.