Public ICS Disclosures - Week of 5-28-21
This week we have six vendor disclosures from Aveva, Johnson Controls, QNAP (3), Yokogawa. There is one vendor update from Medtronic. There are also seven researcher disclosures for products from Aveva (3), Korenix Technology (also affects Westermo and PEPPERL+FUCHS products), Mesa Labs, Bosch (2) and CHIYU. Finally, we have an exploit for products from VMware.
Aveva Advisory
Aveva published an advisory describing a clear-text storage of sensitive information in memory vulnerability in their InTouch Runtime products. The vulnerability was reported by Ilya Karpov, Evgeniy Druzhininand, and Konstantin Kondratev of Rostelecom-Solar. Aveva has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
NOTE: Aveva reports that this was coordinated through ‘ICS-CERT’ so we may see an advisory from NCCIC-ICS next week.
Johnson Controls Advisory
Johnson Controls published an advisory describing an unspecified web services vulnerability in their g Metasys Servers, Engines, and SCT Tools products. The vulnerability was reported by an unnamed third-party. Johnson Controls has patches that partially mitigate the vulnerability pending a new Metasys release. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
QNAP Advisories
QNAP published an advisory describing a DOM-based XSS vulnerability in their QNAP NAS running QTS and QuTS hero. The vulnerability was reported by Marcin Zięba. QNAP has new versions that mitigate the vulnerability. There is no indication that Zieba has been provide an opportunity to verify the efficacy of the fix.
QNAP published an advisory describing a command injection vulnerability in their QNAP NAS running Video Station. The vulnerability was reported by Thomas Fady. QNAP has new versions that mitigate the vulnerability. There is no indication that Fady has been provide an opportunity to verify the efficacy of the fix.
QNAP published an advisory describing a reflected XSS vulnerability in their NAP NAS running Q’center. The vulnerability was reported by Andrea Cappa. QNAP has new versions that mitigate the vulnerability. There is no indication that Cappa has been provide an opportunity to verify the efficacy of the fix.
Yokogawa Advisory
Yokogawa published an advisory discussing the Ripple20 vulnerabilities in their YFGW410, YFGW510, YFGW520 products. Yokogawa has new versions that mitigate the vulnerabilities.
NOTE: I suspect that NCCIC-ICS will update their advisory this week to add a link to this advisory.
Medtronic Update
Medtronic published an update for their Conexus advisory that was originally published on March 21st, 2019 and most recently updated on April 8th, 2021. The new information includes mitigation measures for:
Protecta™ Implanted Cardiac Defibrillator (ICD), all models,
Amplia MRI™ CRT-D, all models; Claria MRI™ CRT-D, all models; and Compia MRI ™ CRT-D, all models; these are now available world-wide.
NOTE: I suspect that NCCIC-ICS will update their advisory this week. The Medtronic advisory is currently pointing at the April 8th version of that advisory as being the ‘complete updated’ version.
Aveva Reports
The Russian BDU-FSTEC published three reports describing vulnerabilities in the Aveva Wonderware InTouch SCADA HMI Window Maker Application. The three vulnerabilities reported were:
BDU-FSTEC reports that these vulnerabilities have been coordinated with Aveva.
Korenix Report
SEC Consult published a report describing five vulnerabilities in the Korenix JetNet products. These vulnerabilities also affect products rebranded with the Westermo and PEPPERL+FUCHS name. The SEC Consult report contains proof-of-concept code. The five reported vulnerabilities are:
Incorrect authorization - CVE-2020-12500,
Use of hard-coded credentials - CVE-2020-12501,
Cross-site request forgery - CVE-2020-12502, and
Incorrect authorization - CVE-2020-12503 and CVE-2020-12504
NOTE: CERT-VDE published an advisory on these vulnerabilities in the PEPPERL+FUCHS products last October.
Mesa Labs Report
Securifera published a report describing the five vulnerabilities in the Mesa Labs AmegaView product that were reported on May 27th, 2021. The report contains proof-of-concept exploit code.
NOTE: AmegaView is going out-of-support in December and Mesa Labs has no plans to develop mitigation measures for these vulnerabilities.
Bosch Reports
The Zero Day Initiative published two reports (here and here) on vulnerabilities that were reported by Bosch on May 28th, 2021. No new information here, but I am mentioning them because the vulnerability reports were not coordinated through NCCIC-ICS, which ZDI normally does.
CHIYU Report
Seguranca Informatica published a report describing seven vulnerabilities in various access control products from CHIYU. CHIYU has provided mitigation measures for the vulnerabilities. The report contains proof-of-concept exploit code.
The seven reported vulnerabilities are:
CRLF injection - CVE-2021-31249,
XSS - CVE-2021-31250, CVE-2021-31641, and CVE-2021-31643,
Authentication bypass - CVE-2021-31251,
Open Redirect - CVE-2021-31252, and
Integer Overflow - CVE-2021-31642
VMware Exploit
Johnny Yu published an exploit for a heap-based buffer overflow vulnerability in the in VMware ESXi product. VMware reported the vulnerability on February 23rd, 2021.