You are here

ics-cert

MatrikonOPC Explorer (ICSA-18-130-01) – Product Used in the Energy Sector

The NCCIC has released an advisory on vulnerabilities in MatrikonOPC Explorer. Versions 5.0 and prior are affected.  If the attacker has local access to the system, an attacker could exploit this vulnerability. This could allow an attacker to transfer unauthorized files from the host system, which could result in unauthorized information disclosure. Matrikon has made fixes to this vulnerability in the version 5.1.0.0 update. The NCCIC also recommends a series of defensive measures to minimize the risk of exploitation of these vulnerabilities.

Tags: 
nccic ics-cert

Rockwell Automation Arena (ICSA-18-130-02)

The NCCIC has released an advisory on a vulnerability in Rockwell Automation Arena. Versions 15.10.00 and prior are affected. Successful exploitation of this vulnerability could cause the software application to crash. Rockwell Automation encourages affected users to upgrade to the latest version of Arena software, 15.10.01 (or later). The NCCIC also recommends a series of defensive measures to minimize the risk of exploitation of these vulnerabilities. NCCIC/ICS-CERT.

Siemens Siveillance VMS Video Mobile App (ICSA-18-128-03)

The NCCIC has released an advisory about a vulnerability in Siemens Siveillance VMS Video Mobile App. For both Siveillance VMS for Android and iOS, all versions prior to V12.1a (2018 R1) are affected. Successful exploitation of this vulnerability may allow an attacker in a privileged network position to read data from and write data to the encrypted communication channel between the app and a server.

Lantech IDS 2102 (ICSA-18-123-01)

The NCCIC has released an advisory about vulnerabilities in Lantech IDS 2102. Versions 2.0 and prior are affected. Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code on the system through crafting malicious input. The NCCIC reports Lantech has been unresponsive to its outreach; in the meantime, the NCCIC recommends a series of defensive measures to minimize the risk of exploitation of these vulnerabilities. NCCIC/ICS-CERT.

Tags: 
nccic ics-cert

Delta Electronics PMSoft (ICSA-18-116-01)

The NCCIC has released an advisory on vulnerabilities in Delta Electronics PMSoft. All versions prior to 2.10 are affected. Successful exploitation of these vulnerabilities could cause the application to crash; stack-based buffer overflow conditions may allow arbitrary code execution. Delta Electronics recommends affected users update to at least PMSoft v2.11, which was made available as of March 22, 2018, or the latest available version. The NCCIC also recommends a series of defensive measures to minimize the risk of exploitation of the vulnerabilities.

WECON Technology Co., Ltd. LeviStudio HMI Editor and PI Studio HMI Project Programmer (ICSA-18-116-02) – Products Used in the Water and Wastewater and Energy Sectors

The NCCIC has released an advisory on vulnerabilities in WECON Technology Co., Ltd. LeviStudio HMI Editor and PI Studio HMI Project Programmer. WECON LeviStudioU version 1.10, part of WECON LeviStudioU 1.8.29 and prior, and PI Studio HMI Project Programmer Build from November 11, 2017 to prior, are affected. Successful exploitation of these vulnerabilities could allow remote code execution. WECON recommends that users update to the latest version. The NCCIC also recommends a series of defensive measures to minimize the risk of exploitation of the vulnerabilities.

Tags: 
nccic ics-cert wecon

Advantech WebAccess HMI Designer (ICSA-18-114-03) – Products Used in the Water and Wastewater and Energy Sectors

The NCCIC has released an advisory on vulnerabilities in Advantech WebAccess HMI Designer. Versions 2.1.7.32 and earlier are affected. Successful exploitation of these vulnerabilities may allow an attacker to remotely execute arbitrary code. The NCCIC is working with Advantech to provide mitigation steps to resolve the issues. In the meantime, the NCCIC recommends a series of defensive measures to minimize the risk of exploitation of these vulnerabilities. NCCIC/ICS-CERT.

Intel 2G Modem (ICSA-18-114-02)

The NCCIC has released an advisory on vulnerabilities in Intel 2G modem. A series of Intel and Sofia products that use the Intel 2G modem are affected. Successful exploitation of this buffer overflow vulnerability may allow remote code execution. Intel is making firmware updates available to device manufacturers that protect systems from this vulnerability. The NCCIC recommends customers should check with their device manufacturers and apply any available updates as soon as practical.

Tags: 
nccic ics-cert intel

Pages

Subscribe to ics-cert