Today, CISA’s NCCIC-ICS published five control system security advisories for products from Delta Electronics (3), Baicells Technologies, and Mitsubishi Electric. They also updated an advisory for Mitsubishi.
Delta Advisory #1
This advisory describes two vulnerabilities in the Delta DX-2100-L1-CN industrial ethernet router. The vulnerabilities were reported by T. Weber of CyberDanube Security Research. The report includes proof-of-concept code. Delta has a new version that mitigates the vulnerability. There is no indication that Weber has been provided an opportunity to verify the efficacy of the fix.
The two reported vulnerabilities are:
OS command injection - CVE-2022-42140, and
Cross-site scripting - CVE-2023-0432
NCCIC-ICS reports that a relatively low-skilled attacker could use proof-of-concept code to remotely exploit the vulnerability to allow an attacker with low privileges to gain root access or allow an unauthenticated attacker to perform remote code execution.
NOTE: I briefly discussed the vulnerabilities on December 10th, 2022.
Delta Advisory #2
This advisory describes an OS command injection vulnerability in the Delta DVW-W02W2-E2 industrial ethernet router. The vulnerability was reported by T. Weber of CyberDanube Security Research. . The report includes proof-of-concept code. Delta has a new version that mitigates the vulnerability. There is no indication that Weber has been provided an opportunity to verify the efficacy of the fix.
NCCIC-ICS reports that a relatively low-skilled attacker could use proof-of-concept code to remotely exploit the vulnerability to allow a threat actor with low privileges to gain root access to the device, which could then allow them to send malicious commands to managed devices.
NOTE: I briefly discussed the vulnerabilities on December 10th, 2022.
Delta Advisory #3
This advisory describes three vulnerabilities in the Delta DIAScreen software configuration tool for Delta devices. The vulnerabilities were reported by Natnael Samson via the Zero Day Initiative. Delta has a new version that mitigates the vulnerabilities. There is no indication that Samson has been provided an opportunity to verify the efficacy of the fix.
The three reported vulnerabilities are:
Stack-based buffer overflow - CVE-2023-0250,
Improper restriction of operations within the bounds of a memory buffer - CVE-2023-0251, and
Out-of-bounds write - CVE-2023-0249.
NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow remote code execution.
Baicells Advisory
This advisory describes a command injection vulnerability in the Baicells Nova LTE TDD eNodeB devices. The vulnerability was reported by Rustam Amin. Baicells has a new version that mitigates the vulnerability. There is no indication that that Amin has been provided an opportunity to verify the efficacy of the fix.
NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to execute arbitrary commands.
NOTE: Baicells recently reported another vulnerability that has not been reported by NCCIC-ICS. I will report on it this weekend.
Mitsubishi Advisory
This advisory describes two vulnerabilities in the Mitsubishi GOT Mobile Function on GOT2000 Series and GT SoftGOT2000. The vulnerabilities are self-reported. Mitsubishi has new versions that mitigate the vulnerabilities.
The two reported vulnerabilities were:
Authentication bypass by spoofing - CVE-2022-40269,
Improper restriction of rendered UI layers or frames - CVE-2022-40268
NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerabilities to allow attackers to perform unintended operations through clickjacking (an attack that tricks users into clicking an invisible or disguised webpage element) or allow attackers to disclose sensitive information from their browsers or impersonate legitimate users by abusing inappropriate HTML attributes.
Mitsubishi Update
This update provides additional information on an advisory that was originally published on August 9th, 2022 and most recently updated on November 1st, 2022. The new information includes adding a fix for RD81OPC96.