GE CIMPLICITY (ICSA-17-278-01) - Product Used in the Water and Wastewater and Energy Sectors - Updated October 10, 2017
October 12, 2017
ICS-CERT has updated this advisory with mitigation details. ICS-CERT.
October 12, 2017
ICS-CERT has updated this advisory with mitigation details. ICS-CERT.
ICS-CERT has released an advisory on a Siemens 7KT PAC1200 Data Manager vulnerability.
ICS-CERT has released an advisory on an iniNet Solutions GmbH SCADA Webserver vulnerability. All versions prior to V2.02.0100 are affected. Successful exploitation of this vulnerability could allow malicious users to access human-machine interface (HMI) pages or to modify programmable logic controller (PLC) variables without authentication. IniNet Solutions GmbH has released a new version of the SCADA Webserver, V2.02.0100, which allows users to implement basic authentication. ICS-CERT.
ICS-CERT has released an advisory on a Digium Asterisk GUI vulnerability. Asterisk GUI 2.1.0 and prior are affected. Successful exploitation of this vulnerability could cause an authenticated attacker to execute arbitrary code on the device. Asterisk GUI is no longer maintained and should not be used. Digium recommends affected users to migrate to Digium’s SwitchVox product. ICS-CERT.
ICS-CERT has released an advisory on a Saia Burgess Controls PCD Controllers vulnerability. PCD firmware versions prior to 1.28.16 or 1.24.69 are affected. Successful exploitation of this vulnerability could allow an attacker to obtain information in memory. Saia Burgess Controls strongly recommends that users update to the latest versions of firmware, Version 1.28.16 or 1.24.69. ICS-CERT.
ICS-CERT has released an advisory on a Ctek, Inc. SkyRouter vulnerability. SkyRouter Series 4200 and 4400 all versions prior to V6.00.11 are affected. Successful exploitation of this vulnerability may allow an unauthorized user to view and edit settings without authenticating. Ctek, Inc., reports it has addressed this issue and addressed additional security requirements in its latest security release V6.00.11, which is now available on all models currently in production. ICS-CERT.
ICS-CERT has released an advisory on a vulnerability in Schneider Electric InduSoft Web Studio, InTouch Machine Edition. InduSoft Web Studio v8.0 SP2 or prior and InTouch Machine Edition v8.0 SP2 or prior are affected. Successful exploitation of this vulnerability could allow an attacker to remotely execute arbitrary commands with high privileges. Schneider Electric recommends users using InduSoft Web Studio v8.0 SP2 or prior should upgrade and apply InduSoft Web Studio v8.0 SP2 Patch 1 as soon as possible.
ICS-CERT has released an advisory on a PHOENIX CONTACT mGuard Device Manager. Versions 1.8.0 and older are affected. Successful exploitation of these vulnerabilities could allow unauthorized remote access, modification of data, and may allow remote and local users to gain elevated privileges. PHOENIX CONTACT recommends that all users of the affected product on Windows should update to at least Version 1.8.0.1. ICS-CERT.
ICS-CERT has released an advisory on vulnerabilities in LOYTEC LVIS-3ME. LVIS-3ME versions prior to 6.2.0 are affected. Successful exploitation of these vulnerabilities may result in information exposure or allow arbitrary code execution. LOYTEC has released a firmware update, V6.2.0, to address these vulnerabilities. ICS-CERT.
ICS-CERT has released an advisory on a vulnerability in mySCADA myPRO, an HMI/SCADA management platform. myPRO Versions 7.0.26 and prior are affected. Successful exploitation of this vulnerability may allow an authenticated, but non-privileged, local user to execute arbitrary code with elevated privileges. mySCADA has released new versions that address the identified vulnerability. ICS-CERT.