You are here

Cybersecurity

NIST Cybersecurity Practice Guide for Energy Sector Asset Management

The National Cybersecurity Center of Excellence (NCCoE) at the National Institute for Standards and Technology (NIST) has released the final version of the Cybersecurity Practice Guide SP 1800-23, Energy Sector Asset Management. With this guide, the NCCoE intends to enhance the energy sector’s asset management capabilities for operational technology (OT).

Emerson OpenEnterprise (ICSA-20-140-02) – Product Used in the Water and Wastewater and Energy Sectors

CISA has published an advisory on missing authentication for critical function, improper ownership management, and inadequate encryption strength vulnerabilities in Emerson OpenEnterprise. All versions through 3.3.4 are affected. Successful exploitation of these vulnerabilities could allow an attacker access to OpenEnterprise configuration services or access passwords for OpenEnterprise user accounts. Emerson recommends all users upgrade to OpenEnterprise 3.3, Service Pack 5 (3.3.5), to resolve these issues. CISA also recommends a series of measures to mitigate the vulnerabilities.

Rockwell Automation EDS Subsystem (ICSA-20-140-01) – Products Used in the Water and Wastewater and Energy Sectors

CISA has published an advisory on improper restriction of operations within the bounds of a memory buffer and SQL injection vulnerabilities in Rockwell Automation EDS Subsystem. Numerous products and version of these products are affected. Successful exploitation of these vulnerabilities could lead to a denial-of-service condition. Rockwell Automation recommends a series of measures to mitigate the vulnerabilities. CISA also recommends a series of measures to mitigate the vulnerabilities.

Beware of Loan Scams, Government Officials Warn

Yesterday U.S. Department of Justice, FBI, and U.S. Small Business Administration (SBA) officials warned the public about potential fraud schemes related to economic stimulus programs intended to assist small business owners during the COVID-19 pandemic. “During these unprecedented times, when small business owners impacted by COVID-19 are doing their best to keep their businesses afloat, it is easy to fall prey to scammers.

Emerson WirelessHART Gateway (ICSA-20-135-02) – Products Used in the Water and Wastewater and Energy Sectors

CISA has published an advisory on an improper access control vulnerability in Emerson WirelessHART Gateway. Numerous products and versions of these products are affected. Successful exploitation of this vulnerability could disable the internal gateway firewall. Once the gateway's firewall is disabled, a malicious user could issue specific commands to the gateway, which could then be forwarded on to the end user's wireless devices. Emerson recommends end users update the firmware on VLAN-enabled Version 4 gateways as soon as possible.

Opto 22 SoftPAC Project (ICSA-20-135-01)

CISA has published an advisory on external control of file name or path, improper verification of cryptographic signature, improper access control, uncontrolled search path element, and improper authorization vulnerabilities in Opto 22 SoftPAC Project. Versions 9.6 and prior are affected. Successful exploitation of these vulnerabilities could allow arbitrary file write access with system access, start or stop service, allow remote code execution, and limit system availability. Opto 22 released PAC Project 10.3 to address the vulnerabilities.

Siemens SIPROTEC 5 and DIGSI 5 (Update C) (ICSA-19-190-05) – Products Used in the Energy Sector

May 12, 2020

CISA has updated this advisory with additional information on the affected products and mitigation measures. Read the advisory at CISA.

December 10, 2019

CISA has updated this advisory with additional details on the affected measures and mitigation measures. Read the advisory at CISA.

Siemens SINAMICS (Update C) (ICSA-19-227-04) – Products Used in the Water and Wastewater and Energy Sectors

May 12, 2020

CISA has updated this advisory with additional information on the affected products and mitigation measures. Read the advisory at CISA.

December 10, 2019

CISA has updated this advisory with additional details on the affected measures and mitigation measures. Read the advisory at CISA.

Pages

Subscribe to Cybersecurity