Public ICS Disclosures – Week of 2-11-23 - Part 2
For part two this week we have five additional vendor advisories from Beijer Electronics, Schneider (3) and Siemens. There are also sixteen vendor updates from Schneider (7) and Siemens (9).
Beijer Advisory
Beijer published an advisory that describes two vulnerabilities in their Korenix JetWave products. The vulnerabilities were reported by T. Weber, S. Dietz of CyberDanube. The report includes proof-of-concept code and an exploit has been published. Beijer has a new firmware version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
The two reported vulnerabilities are:
Command injection - CVE-2023-23294 and CVE-2023-23295, and
Denial of web service - CVE-2023-23296
NOTE: The CVE numbers are from the CyberDanube report, Beijer only lists a single command injection vulnerability, but it may actually cover both of the reported CVEs.
Schneider Advisories
Schneider published an advisory that describes an improper output neutralization for logs vulnerability in their s EcoStruxure Geo SCADA Expert software. The vulnerability was reported by Frank Lycops of Asvalis. Schneider has a new version that mitigates the vulnerability. There is no indication that Lycops has been provided an opportunity to verify the efficacy of the fix.
Schneider published an advisory that describes nine vulnerabilities in their StruxureWare Data Center Expert. Schneider has a new version that mitigates the vulnerabilities.
The nine reported vulnerabilities are:
Incorrect authorization (2) - CVE-2023-25547, CVE-2023-25548,
Missing authorization - CVE-2023-25552,
OS command injection (2) - CVE-2023-25554 and CVE-2023-25555,
Code injection (2) - CVE-2023-25549 and CVE-2023-25550, and
Cross-site scripting (2) - CVE-2023-25551 and CVE-2023-25553
Schneider published an advisory that describes an improper authentication vulnerability in their Merten KNX devices. The vulnerability was reported by Malte Küppers, of FH Aachen - University of Applied Sciences. Schneider provides an interesting workaround to mitigate the vulnerability.
Siemens Advisory
Siemens published an advisory that describes 19 vulnerabilities. The vulnerabilities were reported by the Zero Day Initiative. Siemens has new versions that mitigate the vulnerabilities. There is no indication that the researchers have bee provided an opportunity to verify the efficacy of the fix.
The nineteen reported vulnerabilities are:
Access of uninitialized pointer - CVE-2023-24978,
Out-of-bounds write (18) - CVE-2023-24979, CVE-2023-24980, CVE-2023-24981, CVE-2023-24982, CVE-2023-24983, CVE-2023-24984, CVE-2023-24985, CVE-2023-24986, CVE-2023-24987, CVE-2023-24988, CVE-2023-24989, CVE-2023-24990, CVE-2023-24991, CVE-2023-24992, CVE-2023-24993, CVE-2023-24994, CVE-2023-24995, and CVE-2023-24996
Schneider Updates
Schneider published an update for their NetBotz 4 advisory that was originally published on November 8th, 2022. The new information includes updating the CVSS scores.
Schneider published an update for their Modicon M340 Controller and Communication Modules advisory that was originally published on April 12th, 2022 and most recently updated on September 13th, 2022. The new information includes adding fix for Modicon M340 Ethernet Communication Modules BMXNOE0100 (H) and BMXNOE0110 (H).
Schneider published an update for their BadAlloc advisory that was originally published on November 9th, 2021 and most recently updated on January 10th, 2023. The new information includes adding fixes for Modicon M340 Ethernet Communication Modules BMXNOE0100 (H) and BMXNOE0110 (H) products.
Schneider published an update for their Web Server on Modicon M340 advisory that was originally published on September 14th, 2021 and most recently updated on September 13th, 2022. The new information includes adding fixes for Modicon M340 Ethernet Communication Modules BMXNOE0100 (H) and BMXNOE0110 (H)
Schneider published an update for their NicheStack TCP/IP Vulnerabilities advisory that was originally published on August 5th, 2021 and most recently updated on September 13th, 2022. The new information includes adding a fix for Altivar 32/320/340/600/900 Profinet communication module (VW3A3627)
Schneider published an update for their Web Server on Modicon M340 advisory that was originally published on November 10th, 2020 and most recently updated on September 13th, 2022. The new information includes adding a fix for Modicon M340 Ethernet Communication Modules BMXNOE0100 (H) and BMXNOE0110 (H).
Schneider published an update for their Embedded FTP Servers for Modicon PAC Controllers that was originally published on March 22nd, 2018 and most recently updated on December 13th, 2022. The new information includes adding a fix for for CVE-2018-7242 on Modicon M340 Ethernet Communication Modules BMXNOE0100 (H) and BMXNOE0110 (H).
Siemens Updates
Siemens published an update for their Denial of Service Vulnerability in OpenSSL advisory that was originally published on June 16th, 2022 and most recently updated on January 10th, 2023. The new information includes adding fix for SCALANCE W1750D product family.
Siemens published an update for their SegmentSmack advisory that was originally published on April 14th, 2020 and most recently updated on January 10th, 2023. The new information includes adding additional SIMATIC ET200ecoPN products (CM 4x IO-Link, M12-L / CM 8x IO-Link, M12-L / AI 8xRTD/TC, M12-L) to the list of affected products.
Siemens published an update for their SINUMERIK ONEand SINUMERIK MC advisory that was originally published on November 8th, 2022. The new information includes adding fix or SINUMERIK MC and SINUMERIK ONE.
Siemens published an update for their SCALANCE W1750D advisory that was originally published on November 8th, 2022. The new information includes adding fix for SCALANCE W1750D.
Siemens published an update for their n S7-1500 CPU devices advisory that was originally published on January 10th, 2023. The new information includes adding new S7-1500 hardware versions to the list of affected products.
Siemens published an update for their PROFINET Stack Integrated on Interniche Stack advisory that was originally published on April 14th, 2022 and most recently updated on January 10th, 2023. The new information includes adding additional SIMATIC ET200ecoPN products (CM 4x IO-Link, M12-L / CM 8x IO-Link, M12-L / AI 8xRTD/TC, M12-L) to the list of affected products.
Siemens published an update for their GNU/Linux subsystem advisory that was originally published in 2018 and most recently updated on December 13th, 2022. The new information includes adding two new vulnerabilities - CVE-2022-48303 and CVE-2023-25136.
Siemens published an update for their FTP Server of Nucleus RTOS advisory that was originally published on October 13th, 2022 and most recently updated on December 13th, 2022. The new information includes adding fix for Nucleus NET in Nucleus PLUS V1, V2, and for Nucleus ReadyStart V2012.
Siemens published an update for their Insyde BIOS vulnerabilities advisory that was originally published on February 22nd, 2022 and most recently updated on October 11th, 2022. The new information includes adding partial fix for SIMATIC IPC627E, SIMATIC IPC677E, SIMATIC IPC677E, and SIMATIC IPC847E.