Public ICS Disclosures - Week of 7-31-21
This week we have three INFRA:HALT advisories from: Phoenix Contact, Schneider Electric, Siemens. We have 17 other advisories for products from Aruba, Bosch, Carestream, Genetec, Hitachi ABB Power Grids (3), Johnson Controls, Mitsubishi Electric (4), Phoenix Contact (3), PulseSecure, VMware. Finally, there are two updates from CODESYS and PcVue.
INFRA:HALT Advisories
Phoenix Contact published an advisory discussing the INFRA:HALT vulnerabilities. The advisory lists affected products and provides generic workarounds to mitigate the vulnerabilities. They specifically note that the control and configuration protocols of the affected products “do not feature authentication mechanisms by design.”
Schneider published an advisory discussing the INFRA:HALT vulnerabilities. The advisory lists affected products and announces that Schneider is working on mitigation measures.
Siemens published an advisory discussing the INFRA:HALT vulnerabilities. The advisory lists affected products. Siemens has new versions that mitigate the vulnerabilities.
NOTE: Siemens provided a link to the HCC-Embedded advisories for the INTER:HALT vulnerabilities, access is restricted.
Aruba Advisory
Aruba published an advisory describing a privilege escalation vulnerability in their Analytics and Location Engine (ALE). This is a third-party vulnerablity (Sudo) and there are multiple exploits available for the underlying vulnerability (see here and here for example). Aruba has new versions available to mitigate the vulnerability.
Bosch Advisory
Bosch published an advisory describing a cross-site request forgery vulnerability in their IP Cameras. The vulnerability was reported by Kaspersky. Bosch has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
Carestream Advisory
Carestream published an advisory discussing the PrintNightmare vulnerabilities. They provide a list of affected and unaffected products and provide the status for the Windows® update for the affected products.
Genetec Advisory
Genetec published an advisory describing four vulnerabilities in their Streamvault products. These are third-party vulnerabilities (Dell). Genetec recommends updating to the latest version of the Dell Bios.
The four reported vulnerabilities are:
Improper certificate validation - CVE-2021-21571, and
Buffer overflow (3) - CVE-2021-21572, CVE-2021-21573, and CVE-2021-21574
Hitachi ABB Advisories
Hitachi ABB published an advisory discussing the FragAttacks WiFi vulnerabilities in their TropOS Product. Hitachi ABB has new firmware versions that mitigate the vulnerabilities.
Hitachi ABB published an advisory describing a password in memory vulnerability in their Counterparty Settlement Billing (CSB) Product. Hitachi ABB has a new version that mitigates the vulnerability.
Hitachi ABB published an advisory describing a password in memory vulnerability in their Retail Operations Product. Hitachi ABB has a new version that mitigates the vulnerability.
Johnson Controls Advisory
Johnson Controls published an advisory describing an auto-update vulnerability in their Software House C•CURE 9000 product. Johnson Controls has a new version that mitigates the vulnerability.
Mitsubishi Advisories
Mitsubishi published an advisory describing an information disclosure vulnerability in their MELSEC iQ-R Series CPU module. The vulnerability was reported by Ivan Speziale of Nozomi Networks Labs. Mitsubishi provided generic workarounds pending development of a new firmware version.
Mitsubishi published an advisory describing an unauthorized log-in vulnerability in their MELSEC iQ-R series CPU modules. The vulnerability was reported by Ivan Speziale of Nozomi Networks Labs. Mitsubishi provided generic workarounds pending development of a new firmware version.
Mitsubishi published an advisory describing a denial-of-service vulnerability in their MELSEC iQ-R Series CPU module. The vulnerability was reported by Ivan Speziale of Nozomi Networks Labs. Mitsubishi provided generic workarounds pending development of a new firmware version.
Mitsubishi published an advisory describing an authentication bypass vulnerability in their MELSEC iQ-R Series CPU Module. Mitsubishi provided generic workarounds pending development of a new firmware version.
Phoenix Controls Advisories
Phoenix Controls published an advisory discussing the WIBU CodeMeter vulnerabilities reported by NCCIC-ICS. They provide a list of affected products and recommend updating to CodeMeter V7.21a.
NOTE: It will be interesting to see if NCCIC-ICS updates their WIBU advisory to reflect this advisory.
Phoenix Controls published an advisory describing a denial of service vulnerability in their PLCnext Control devices. The vulnerability was reported by Oliver Carrigan of Dionach. Phoenix Contact has a new firmware version that mitigates the vulnerability. There is no indication that Carrigan has been provided an opportunity to verify the efficacy of the fix.
Phoenix Controls published an advisory describing an improper privilege management vulnerability in their FL MGUARD DM product. Phoenix Contact has a new version that mitigates the vulnerability.
PulseSecure Advisory
PulseSecure published an advisory describing six vulnerabilities in their Pulse Connect Secure. PulseSecure has a new version that mitigates the vulnerabilities.
The six reported vulnerabilities are:
Uncontrolled archive extraction - CVE-2021-22937,
Path traversal - CVE-2021-22933,
Buffer overflow - CVE-2021-22934,
OS command injection (2) - CVE-2021-22935 and CVE-2021-22938, and
Cross-site scripting - CVE-2021-22936
VMware Advisory
VMware published an advisory describing two vulnerabilities in their VMware Workspace ONE Access product. The first vulnerability was reported by Suleyman Bayir of Trendyol. VMware has patches that mitigate the vulnerabilities. There is no indication that Bayir has been provided an opportunity to verify the efficacy of the fix.
The two reported vulnerabilities are:
Information disclosure - CVE-2021-22003,
Host header tampering - CVE-2021-22002
CODESYS Update
CODESYS published an update for their CODESYS Development System V3 advisory that was originally published on July 15th, 2021. The new information includes a statement that POC is available.
PcVue Update
PcVue published an update for their advisory that was originally published in November 2020. The new information include an additional fix for the remote code execution vulnerability.
NOTE: There is a remote chance that NCCIC-ICS will update their advisory for these vulnerabilities.