You are here

Cybersecurity

AVEVA Vijeo Citect and CitectSCADA (ICSA-19-150-01) – Products Used in the Energy Sector

The NCCIC has published an advisory on an insufficiently protected credentials vulnerability in AVEVA Vijeo Citect and CitectSCADA. Verions 7.30 and 7.40 of Citect and CitectSCADA are affected. Successful exploitation of this vulnerability could allow a locally authenticated user to obtain Citect user credentials. AVEVA recommends all affected users download and upgrade to CitectSCADA 2018 as soon as possible. The NCCIC also provided a list of recommended measures to mitigate this vulnerability.

Emerson Ovation OCR400 Controller (ICS-19-148-01) – Product Used in the Water and Wastewater and Energy Sectors

The NCCIC has published an advisory on stack-based buffer overflow and heap-based buffer overflow vulnerabilities in Ovation OCR400 Controller. Devices running version 3.3.1 or earlier are affected. Successful exploitation of these vulnerabilities may allow privilege escalation or remote code execution, or it may halt the controller. Emerson is issuing a notice to its customer base with mitigation recommendations, encouraging users with this older software to upgrade to a more current version supported by Emerson and the third-party vendor.

Privacy Awareness Week

The Federal Trade Commission (FTC) has released an announcement promoting Privacy Awareness Week (PAW). PAW is an annual event fostering awareness of privacy issues and the importance of protecting personal information. This year’s theme, “Protecting Privacy is Everyone’s Responsibility,” focuses on promoting privacy awareness for consumers and businesses.

Mitsubishi Electric MELSEC-Q Series Ethernet Module (ICSA-19-141-02)

The NCCIC has published an advisory on an uncontrolled resource consumption vulnerability in Mitsubishi Electric MELSEC-Q Series Ethernet Module. MELSEC-Q series Ethernet module QJ71E71-100 serial number 20121 and prior are affected. Successful exploitation of this vulnerability may render the device unresponsive, requiring a physical reset of the PLC. Mitsubishi Electric has released new firmware Version 20122 for the QJ71E71-100 Ethernet module to mitigate the reported vulnerability. The NCCIC has also provided a series of measures to address this vulnerability.

Computrols CBAS Web (ICSA-19-141-01)

The NCCIC has published an advisory on cross-site request forgery, information exposure through discrepancy, cross-site scripting, command injection, information exposure through source code, use of hard-coded cryptographic key, SQL injection, authentication bypass using an alternate path or channel, and inadequate encryption strength vulnerabilities in Computrols CBAS Web. Numerous versions of this product are affected.

Presidential Executive Order Gives Authority to Block Foreign Tech that Poses Risks to National Security

President Trump has signed the executive order “Securing the Information and Comunications Technology and Services Supply Chain,” which gives the federal government the authority to block telecommunications or information technology that are deemed an “unacceptable risk” to national security. The executive order doesn’t specifically mention Huawei, but concerns about the potential security implications of U.S. companies using components from the Chinese tech giant, as well as from other Chinese manufacturers, in their infrastructure undoubtedly contributed to its release.

Fuji Electric Apha7 PC Loader (ICSA-19-136-02)

The NCCIC has published an advisory on an out-of-bounds read vulnerability in Fuji Electric Alpha7 PC Loader. Versions 1.1 and prior are affected. Successful exploitation of this vulnerability could crash the device. Fuji Electric has released Version 1.2 of the software to address the vulnerability. The NCCIC has also provided a series of measures to address this vulnerability. Read the advisory at NCCIC/ICS-CERT.

Schneider Electric Modicon Controllers (ICSA-19-136-01)

The NCCIC has published an advisory on a use of insufficiently random values vulnerability in Schneider Electric Modicon Controllers. Numerous products and versions of the products are affected. Successful exploitation of this vulnerability could allow an attacker to hijack TCP connections or cause information leakage. Schneider Electric recommends a series of mitigations to address this vulnerability. The NCCIC has also provided a series of measures to address this vulnerability.

Pages

Subscribe to Cybersecurity