Today CISA’s NCCIC-ICS published five control system security updates for products from Delta Electronics, LCDS, Geutebruck, Mitsubishi, and KUKA. They also updated five security advisories for products from Mitsubishi (2), AVEVA, Delta, and Schneider Electric.
Delta Advisory
This advisory describes two vulnerabilities in the Delta DIAScreen software. The vulnerability was reported by Kimiya via the Zero Day Initiative. Delta has a new version that mitigates the vulnerabilities. There is no indication that Kimiya has been provided an opportunity to verify the efficacy of the fix.
The two reported vulnerabilities are:
Type confusion - CVE-2021-32965, and
Out-of-bounds write - CVE-2021-32969
NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to crash the device being accessed and may allow remote code execution.
LCDS Advisory
This advisory describes a cross-site scripting vulnerability in the LCDS LAquis SCADA. The vulnerability was reported by Michael Heinzl. LCDS has a new version that mitigates the vulnerability. There is no indication that Heinzl has been provided an opportunity to verify the efficacy of the fix.
NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an unauthenticated remote attacker to access sensitive information or execute arbitrary code.
Geutebruck Advisory
This advisory describes twelve vulnerabilities in the Geutebruck G-Cam E2 cameras and G-Code encoders. These are third-party (UDP Technology) vulnerabilities. The vulnerabilities were reported by Titouan Lazard and Ibrahim Ayadhi from RandoriSec. The report contains proof-of-concept code. Geutebruck has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
The twelve reported vulnerabilities are:
Missing authentication for critical function - CVE-2021-33543,
Command injection (7) - CVE-2021-33544, CVE-2021-33548, CVE-2021-33550, CVE-2021-33551, CVE-2021-33552, CVE-2021-33553, and CVE-2021-33554, and
Stack-based buffer overflow (4) - CVE-2021-33545, CVE-2021-33546, CVE-2021-33547, and CVE-2021-33549,
NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow unauthenticated access to sensitive information; buffer overflow and command injection conditions may allow remote code execution.
NOTE: The RandoriSEC report lists ten other vendors that use the UDP firmware affected by the vulnerabilities.
Mitsubishi Advisory
This advisory describes a missing synchronization vulnerability in the Mitsubishi GOT2000 series and GT SoftGOT2000 when using the MODBUS/TCP Slave. The vulnerability was reported by Parul Sindhwad and Dr. Faruk Kazi of COE-CNDS Lab. Mitsubishi has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
NCCIC-ICS reports that an uncharacterized attacker could remotely exploit the vulnerability to allow an attacker to cause a denial-of-service condition.
KUKA Advisory
This advisory describes two use of hard-coded credentials vulnerabilities in the KUKA KR C4 controllers. The vulnerabilities were reported by Chen Jie from NSFOCUS. KUKA provides generic mitigation measures.
NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to result in unauthorized access to sensitive information and access to shell.
Mitsubishi Update #1
This update provides additional information on an advisory that was originally published on July 30th, 2020 and most recently updated on May 27th, 2021. The new information includes updated affected version and mitigation information for:
GX Works2,
MELSOFT Complete Clean Up Tool, and
MELSOFT Navigator
Mitsubishi Update #2
This update provides additional information on an advisory that was originally published on April 22, 2021. The new information includes:
Updated affected version data,
Updated corrected version data, and
‘How to check version’ instructions.
AVEVA Update
This update provides additional information on an advisory that was originally published on June 29th, 2021. The new information includes adding three vulnerabilities that were originally reported by AVEVA but were not included in the NCCIC-ICS advisory.
Delta Update
This update provides additional information on an advisory that was originally published on July 1st, 2021. The new information includes adding a second out-of-bounds read vulnerability.
Schneider Update
This update provides additional information on an advisory that was originally published on July 13th, 2021. The new information includes:
Increasing the CVSS v3 base score to 9.8, and
Changing the CVSS vector string to (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
NOTE: The corrected information provided here was included in the original Schneider advisory.
Other Mitsubishi Update
Mitsubishi published another update today for an advisory that was initially covered by NCCIC-ICS. If NCCIC-ICS does not update their advisory on Thursday, I will cover this in my weekend post.